ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0022×

55 examples

TechniqueUsed byProcedure example
T1608.001
Upload Malware
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used compromised servers to host malware.

T1608.002
Upload Tool
CampaignOperation Dream Job

For Operation Dream Job, Lazarus Group used multiple servers to host malicious tools.

T1614.001
System Language Discovery
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group deployed malware designed not to run on computers set to Korean, Japanese, or Chinese in Windows language preferences.

T1622
Debugger Evasion
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used tools that used the `IsDebuggerPresent` call to detect debuggers.

T1684.001
Impersonation
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group impersonated HR hiring personnel through LinkedIn messages and conducted interviews with victims in order to deceive them into downloading malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.