ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0002×

29 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
CampaignNight Dragon

During Night Dragon, threat actors dumped account hashes using gsecdump.

T1005
Data from Local System
CampaignNight Dragon

During Night Dragon, the threat actors collected files and other data from compromised systems.

T1008
Fallback Channels
CampaignNight Dragon

During Night Dragon, threat actors used company extranet servers as secondary C2 servers.

T1027.002
Software Packing
CampaignNight Dragon

During Night Dragon, threat actors used software packing in its tools.

T1027.013
Encrypted/Encoded File
CampaignNight Dragon

During Night Dragon, threat actors used a DLL that included an XOR-encoded section.

T1033
System Owner/User Discovery
CampaignNight Dragon

During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords.

T1059.003
Windows Command Shell
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells.

T1071.001
Web Protocols
CampaignNight Dragon

During Night Dragon, threat actors used HTTP for C2.

T1074.002
Remote Data Staging
CampaignNight Dragon

During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them.

T1078
Valid Accounts
CampaignNight Dragon

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

T1078.002
Domain Accounts
CampaignNight Dragon

During Night Dragon, threat actors used domain accounts to gain further access to victim systems.

T1083
File and Directory Discovery
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system.

T1105
Ingress Tool Transfer
CampaignNight Dragon

During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems.

T1110.002
Password Cracking
CampaignNight Dragon

During Night Dragon, threat actors used Cain & Abel to crack password hashes.

T1112
Modify Registry
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry.

T1114.001
Local Email Collection
CampaignNight Dragon

During Night Dragon, threat actors used RAT malware to exfiltrate email archives.

T1133
External Remote Services
CampaignNight Dragon

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

T1190
Exploit Public-Facing Application
CampaignNight Dragon

During Night Dragon, threat actors used SQL injection exploits against extranet web servers to gain access.

T1204.001
Malicious Link
CampaignNight Dragon

During Night Dragon, threat actors enticed users to click on links in spearphishing emails to download malware.

T1219
Remote Access Tools
CampaignNight Dragon

During Night Dragon, threat actors used several remote administration tools as persistent infiltration channels.

T1550.002
Pass the Hash
CampaignNight Dragon

During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers.

T1566.002
Spearphishing Link
CampaignNight Dragon

During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded.

T1568
Dynamic Resolution
CampaignNight Dragon

During Night Dragon, threat actors used dynamic DNS services for C2.

T1583.004
Server
CampaignNight Dragon

During Night Dragon, threat actors purchased hosted services to use for C2.

T1584.004
Server
CampaignNight Dragon

During Night Dragon, threat actors compromised web servers to use for C2.

T1588.001
Malware
CampaignNight Dragon

During Night Dragon, threat actors used Trojans from underground hacker websites.

T1588.002
Tool
CampaignNight Dragon

During Night Dragon, threat actors obtained and used tools such as gsecdump.

T1608.001
Upload Malware
CampaignNight Dragon

During Night Dragon, threat actors uploaded commonly available hacker tools to compromised web servers.

T1685
Disable or Modify Tools
CampaignNight Dragon

During Night Dragon, threat actors disabled anti-virus and anti-spyware tools in some instances on the victim’s machines. The actors also disabled proxy settings to allow direct communication from victims to the Internet.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.