Tracking APT39 and APT34: Innovations in C2 Server Profiling
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Dropper
- Attack Complexity: Medium
- Threat Risk: Unknown
Threat Overview
In October 2019, Aaron Stephens introduced the SCANdalous project, which automates the profiling of command and control (C2) servers used by threat groups. Prior to automation, analysts manually identified servers linked to groups like APT39 and APT34. APT39 employed SSH tunneling and specific server characteristics to evade detection, while APT34 used QUADAGENT malware and PowerShell-based tools like POSHC2 and POWERTON. These efforts led to early identification of malicious infrastructure, improving threat tracking capabilities.
Extracted IOCs
- rdppath[.]com
- 185[.]161.208.37
- 51[.]254.93.40
- 51[.]254.93.47
Tip: 4 related IOCs (3 IP, 1 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.
Overlaps
Source: Palo Alto Networks - July 2018
Detection (one case): rdppath[.]com
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Automated Threat Infrastructure Tracking with SCANdalous
Advanced Practices developed an automated tracking system named SCANdalous to proactively identify adversary infrastructure on the internet. By leveraging third-party network scan data, this system discovers malicious servers and domains long before attackers can use them to compromise target networks.
The system tracks multiple sophisticated threat groups operating globally. This includes notable state-sponsored groups like APT33, APT34, and APT39, alongside prominent financially motivated groups such as FIN6, FIN7, and UNC1878.
Threat actors continuously establish external internet infrastructure to facilitate and manage their cyber intrusions. They set up command and control servers designed to execute remote commands, move laterally through targeted networks, and maintain access to compromised environments.
The automated detection system operates on a massive scale, maintaining over five thousand signatures that track thousands of groups and malware families. Since its inception, the platform has processed over two million hits on suspicious internet infrastructure.
The provided report does not identify specific industries or individuals that these groups targeted. It instead highlights that the identified infrastructure was generally utilized to target FireEye clients, including organizations supported by Managed Defense and Mandiant Incident Response.
Adversaries prepared for their attacks by acquiring domains and utilizing specific hosting providers to host their operations. Once established, they relied on custom backdoors, SSH tunneling, and popular post-exploitation frameworks to remotely manage their access inside victim networks.
The document does not detail the specific underlying motivations or the attractiveness of the targeted entities. The focus of the report is dedicated exclusively to the methodologies defenders can use to track the attackers' external infrastructure.
Organizations should incorporate third-party network scan data into their defensive strategies and actively automate their detection workflows. Defenders must also deploy broad signatures to proactively monitor for common administrative and post-exploitation tools frequently co-opted by attackers.
The ongoing establishment of malicious infrastructure is a deeply widespread issue across the internet. The development of automation was strictly necessary precisely because defenders must continuously track dozens of highly active threat groups and common malware frameworks operating simultaneously around the globe.