Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
CampaignNight Dragon | During Night Dragon, threat actors dumped account hashes using gsecdump. |
| T1005 Data from Local System |
CampaignNight Dragon | During Night Dragon, the threat actors collected files and other data from compromised systems. |
| T1008 Fallback Channels |
CampaignNight Dragon | During Night Dragon, threat actors used company extranet servers as secondary C2 servers. |
| T1027.002 Software Packing |
CampaignNight Dragon | During Night Dragon, threat actors used software packing in its tools. |
| T1027.013 Encrypted/Encoded File |
CampaignNight Dragon | During Night Dragon, threat actors used a DLL that included an XOR-encoded section. |
| T1033 System Owner/User Discovery |
CampaignNight Dragon | During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords. |
| T1059.003 Windows Command Shell |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and run command-line shells. |
| T1071.001 Web Protocols |
CampaignNight Dragon | During Night Dragon, threat actors used HTTP for C2. |
| T1074.002 Remote Data Staging |
CampaignNight Dragon | During Night Dragon, threat actors copied files to company web servers and subsequently downloaded them. |
| T1078 Valid Accounts |
CampaignNight Dragon | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems. |
| T1078.002 Domain Accounts |
CampaignNight Dragon | During Night Dragon, threat actors used domain accounts to gain further access to victim systems. |
| T1083 File and Directory Discovery |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system. |
| T1105 Ingress Tool Transfer |
CampaignNight Dragon | During Night Dragon, threat actors used administrative utilities to deliver Trojan components to remote systems. |
| T1110.002 Password Cracking |
CampaignNight Dragon | During Night Dragon, threat actors used Cain & Abel to crack password hashes. |
| T1112 Modify Registry |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and manipulate the Registry. |
| T1114.001 Local Email Collection |
CampaignNight Dragon | During Night Dragon, threat actors used RAT malware to exfiltrate email archives. |
| T1133 External Remote Services |
CampaignNight Dragon | During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems. |
| T1190 Exploit Public-Facing Application |
CampaignNight Dragon | During Night Dragon, threat actors used SQL injection exploits against extranet web servers to gain access. |
| T1204.001 Malicious Link |
CampaignNight Dragon | During Night Dragon, threat actors enticed users to click on links in spearphishing emails to download malware. |
| T1219 Remote Access Tools |
CampaignNight Dragon | During Night Dragon, threat actors used several remote administration tools as persistent infiltration channels. |
| T1550.002 Pass the Hash |
CampaignNight Dragon | During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers. |
| T1566.002 Spearphishing Link |
CampaignNight Dragon | During Night Dragon, threat actors sent spearphishing emails containing links to compromised websites where malware was downloaded. |
| T1568 Dynamic Resolution |
CampaignNight Dragon | During Night Dragon, threat actors used dynamic DNS services for C2. |
| T1583.004 Server |
CampaignNight Dragon | During Night Dragon, threat actors purchased hosted services to use for C2. |
| T1584.004 Server |
CampaignNight Dragon | During Night Dragon, threat actors compromised web servers to use for C2. |
| T1588.001 Malware |
CampaignNight Dragon | During Night Dragon, threat actors used Trojans from underground hacker websites. |
| T1588.002 Tool |
CampaignNight Dragon | During Night Dragon, threat actors obtained and used tools such as gsecdump. |
| T1608.001 Upload Malware |
CampaignNight Dragon | During Night Dragon, threat actors uploaded commonly available hacker tools to compromised web servers. |
| T1685 Disable or Modify Tools |
CampaignNight Dragon | During Night Dragon, threat actors disabled anti-virus and anti-spyware tools in some instances on the victim’s machines. The actors also disabled proxy settings to allow direct communication from victims to the Internet. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.