ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0040×

23 examples

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
CampaignAPT41 DUST

APT41 DUST used encrypted payloads decrypted and executed in memory.

T1036.004
Masquerade Task or Service
CampaignAPT41 DUST

APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`.

T1070.004
File Deletion
CampaignAPT41 DUST

APT41 DUST deleted various artifacts from victim systems following use.

T1071.001
Web Protocols
CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

T1074.001
Local Data Staging
CampaignAPT41 DUST

APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration.

T1102
Web Service
CampaignAPT41 DUST

APT41 DUST used compromised Google Workspace accounts for command and control.

T1105
Ingress Tool Transfer
CampaignAPT41 DUST

APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper.

T1119
Automated Collection
CampaignAPT41 DUST

APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.

T1213.006
Databases
CampaignAPT41 DUST

APT41 DUST collected data from victim Oracle databases using SQLULDR2.

T1505.003
Web Shell
CampaignAPT41 DUST

APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence.

T1543.003
Windows Service
CampaignAPT41 DUST

APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN.

T1553.002
Code Signing
CampaignAPT41 DUST

APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads.

T1560.001
Archive via Utility
CampaignAPT41 DUST

APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration.

T1567.002
Exfiltration to Cloud Storage
CampaignAPT41 DUST

APT41 DUST exfiltrated collected information to OneDrive.

T1569.002
Service Execution
CampaignAPT41 DUST

APT41 DUST used Windows services to execute DUSTPAN.

T1573.002
Asymmetric Cryptography
CampaignAPT41 DUST

APT41 DUST used HTTPS for command and control.

T1574.001
DLL
CampaignAPT41 DUST

APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller.

T1583.007
Serverless
CampaignAPT41 DUST

APT41 DUST used infrastructure hosted behind Cloudflare or utilized Cloudflare Workers for command and control.

T1586.003
Cloud Accounts
CampaignAPT41 DUST

APT41 DUST used compromised Google Workspace accounts for command and control.

T1588.003
Code Signing Certificates
CampaignAPT41 DUST

APT41 DUST used stolen code signing certificates to sign DUSTTRAP malware and components.

T1593.002
Search Engines
CampaignAPT41 DUST

APT41 DUST involved use of search engines to research victim servers.

T1594
Search Victim-Owned Websites
CampaignAPT41 DUST

APT41 DUST involved access of external victim websites for target development.

T1596.005
Scan Databases
CampaignAPT41 DUST

APT41 DUST used internet scan data for target development.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.