ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0022×

55 examples

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host.

T1027.002
Software Packing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.

T1027.013
Encrypted/Encoded File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.

T1036.008
Masquerade File Type
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection.

T1041
Exfiltration Over C2 Channel
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers.

T1047
Windows Management Instrumentation
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script.

T1053.005
Scheduled Task
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script.

T1059.001
PowerShell
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims.

T1059.003
Windows Command Shell
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell.

T1059.005
Visual Basic
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant.

T1070.004
File Deletion
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer.

T1071.001
Web Protocols
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers.

T1083
File and Directory Discovery
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters.

T1087.002
Domain Account
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts.

T1105
Ingress Tool Transfer
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.

T1106
Native API
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server.

T1110
Brute Force
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group performed brute force attacks against administrator accounts.

T1204.001
Malicious Link
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access.

T1204.002
Malicious File
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors.

T1218.010
Regsvr32
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used `regsvr32` to execute malware.

T1218.011
Rundll32
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`.

T1220
XSL Script Processing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used a remote XSL script to download a Base64-encoded DLL custom downloader.

T1221
Template Injection
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file.

T1497.001
System Checks
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that conducted a variety of system checks to detect sandboxes or VMware services.

T1497.003
Time Based Checks
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services.

T1505.004
IIS Components
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components.

T1534
Internal Spearphishing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization.

T1547.001
Registry Run Keys / Startup Folder
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence.

T1553.002
Code Signing
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection.

T1560.001
Archive via Utility
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group archived victim's data into a RAR file.

T1566.001
Spearphishing Attachment
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers.

T1566.002
Spearphishing Link
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email.

T1566.003
Spearphishing via Service
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs.

T1567.002
Exfiltration to Cloud Storage
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox.

T1573.001
Symmetric Cryptography
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server.

T1583.001
Domains
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort.

T1583.004
Server
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group acquired servers to host their malicious tools.

T1583.006
Web Services
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive.

T1584.001
Domains
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure.

T1584.004
Server
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools.

T1585.001
Social Media Accounts
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts.

T1585.002
Email Accounts
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group created fake email accounts to correspond with fake LinkedIn personas; Lazarus Group also established email accounts to match those of the victim as part of their BEC attempt.

T1587.001
Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.

T1587.002
Code Signing Certificates
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group digitally signed their malware and the dbxcli utility.

T1588.002
Tool
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli.

T1588.003
Code Signing Certificates
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used code signing certificates issued by Sectigo RSA for some of its malware and tools.

T1589
Gather Victim Identity Information
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets.

T1591
Gather Victim Org Information
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets.

T1591.004
Identify Roles
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements.

T1593.001
Social Media
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used LinkedIn to identify and target employees within a chosen organization.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.