Real-world descriptions of how a group, tool or campaign used a technique.
55 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host. |
| T1027.002 Software Packing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
| T1036.008 Masquerade File Type |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers. |
| T1047 Windows Management Instrumentation |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script. |
| T1053.005 Scheduled Task |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script. |
| T1059.001 PowerShell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims. |
| T1059.003 Windows Command Shell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell. |
| T1059.005 Visual Basic |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant. |
| T1070.004 File Deletion |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer. |
| T1071.001 Web Protocols |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers. |
| T1083 File and Directory Discovery |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters. |
| T1087.002 Domain Account |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts. |
| T1105 Ingress Tool Transfer |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host. |
| T1106 Native API |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server. |
| T1110 Brute Force |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group performed brute force attacks against administrator accounts. |
| T1204.001 Malicious Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access. |
| T1204.002 Malicious File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors. |
| T1218.010 Regsvr32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used `regsvr32` to execute malware. |
| T1218.011 Rundll32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`. |
| T1220 XSL Script Processing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used a remote XSL script to download a Base64-encoded DLL custom downloader. |
| T1221 Template Injection |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file. |
| T1497.001 System Checks |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that conducted a variety of system checks to detect sandboxes or VMware services. |
| T1497.003 Time Based Checks |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services. |
| T1505.004 IIS Components |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components. |
| T1534 Internal Spearphishing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization. |
| T1547.001 Registry Run Keys / Startup Folder |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence. |
| T1553.002 Code Signing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection. |
| T1560.001 Archive via Utility |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group archived victim's data into a RAR file. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers. |
| T1566.002 Spearphishing Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email. |
| T1566.003 Spearphishing via Service |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox. |
| T1573.001 Symmetric Cryptography |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server. |
| T1583.001 Domains |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort. |
| T1583.004 Server |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group acquired servers to host their malicious tools. |
| T1583.006 Web Services |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive. |
| T1584.001 Domains |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure. |
| T1584.004 Server |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools. |
| T1585.001 Social Media Accounts |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts. |
| T1585.002 Email Accounts |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group created fake email accounts to correspond with fake LinkedIn personas; Lazarus Group also established email accounts to match those of the victim as part of their BEC attempt. |
| T1587.001 Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations. |
| T1587.002 Code Signing Certificates |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group digitally signed their malware and the dbxcli utility. |
| T1588.002 Tool |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli. |
| T1588.003 Code Signing Certificates |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used code signing certificates issued by Sectigo RSA for some of its malware and tools. |
| T1589 Gather Victim Identity Information |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets. |
| T1591 Gather Victim Org Information |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets. |
| T1591.004 Identify Roles |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements. |
| T1593.001 Social Media |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used LinkedIn to identify and target employees within a chosen organization. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.