Analysis of APT29 MITRE ATT&CK Evaluation Dataset
Score: 8/10

Analysis of APT29 MITRE ATT&CK Evaluation Dataset

APT29 utilizes a multi-stage execution chain involving screensaver droppers, steganography-embedded payloads, and extensive memory manipulation to harvest credentials and move laterally.

Executive Summary

This intelligence summary details the tradecraft of APT29 (SVR) as observed in the MITRE ATT&CK Evaluations. The threat actor demonstrated high sophistication by maintaining a minimal process footprint, instead performing the majority of their operations within system memory (EventID 10) and the Windows Registry to evade traditional process-based detection mechanisms. The intrusion began with a malicious screensaver dropper (.scr) and evolved into a complex execution chain leveraging multiple signed Microsoft binaries to bypass security controls.

The attack featured advanced techniques including steganography to hide encrypted payloads within image files (monkey.png) and on-the-fly compilation using the C# compiler (csc.exe). Once established, the actor performed systematic credential harvesting by requesting full access (0x1FFFFF) to LSASS and other critical processes, followed by lateral movement using PsExec and custom Python implants. This campaign emphasizes the actor's reliance on 'living off the land' and trust manipulation, such as injecting unauthorized certificates into the Windows trust store to facilitate encrypted C2 communication.

Key Details

Threat Name

APT29

Affects

—

Adversary

APT29

Malware/Tools

cod.3aka3.scr, CARNYB.tmp, PsExec, rar.exe, sdelete.exe

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources