Real-world descriptions of how a group, tool or campaign used a technique.
17 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors used UPX to pack some payloads. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded. |
| T1036 Masquerading |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors disguised some executables as JPG files. |
| T1059.005 Visual Basic |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used Visual Basic scripts. |
| T1059.007 JavaScript |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used JavaScript code. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignOperation Dust Storm | During Operation Dust Storm, attackers used VBS code to decode payloads. |
| T1189 Drive-by Compromise |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322. |
| T1203 Exploitation for Client Execution |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors exploited Adobe Flash vulnerability CVE-2011-0611, Microsoft Windows Help vulnerability CVE-2010-1885, and several Internet Explorer vulnerabilities, including CVE-2011-1255, CVE-2012-1889, and CVE-2014-0322. |
| T1204.001 Malicious Link |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors relied on a victim clicking on a malicious link sent via email. |
| T1204.002 Malicious File |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors relied on potential victims to open a malicious Microsoft Word document sent via email. |
| T1218.005 Mshta |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors executed JavaScript code via `mshta.exe`. |
| T1518 Software Discovery |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors sent spearphishing emails that contained a malicious Microsoft Word document. |
| T1566.002 Spearphishing Link |
CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors sent spearphishing emails containing a malicious link. |
| T1568 Dynamic Resolution |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors used dynamic DNS domains from a variety of free providers, including No-IP, Oray, and 3322. |
| T1583.001 Domains |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors established domains as part of their operational infrastructure. |
| T1585.002 Email Accounts |
CampaignOperation Dust Storm | For Operation Dust Storm, the threat actors established email addresses to register domains for their operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.