ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0016×

17 examples

TechniqueUsed byProcedure example
T1027.002
Software Packing
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors used UPX to pack some payloads.

T1027.013
Encrypted/Encoded File
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded.

T1036
Masquerading
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors disguised some executables as JPG files.

T1059.005
Visual Basic
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used Visual Basic scripts.

T1059.007
JavaScript
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used JavaScript code.

T1140
Deobfuscate/Decode Files or Information
CampaignOperation Dust Storm

During Operation Dust Storm, attackers used VBS code to decode payloads.

T1189
Drive-by Compromise
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322.

T1203
Exploitation for Client Execution
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322.

T1204.001
Malicious Link
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors relied on a victim clicking on a malicious link sent via email.

T1204.002
Malicious File
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email.

T1218.005
Mshta
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`.

T1518
Software Discovery
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery.

T1566.001
Spearphishing Attachment
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document.

T1566.002
Spearphishing Link
CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link.

T1568
Dynamic Resolution
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322.

T1583.001
Domains
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors established domains as part of their operational infrastructure.

T1585.002
Email Accounts
CampaignOperation Dust Storm

For Operation Dust Storm, the threat actors established email addresses to register domains for their operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.