Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
CampaignAPT41 DUST | APT41 DUST used encrypted payloads decrypted and executed in memory. |
| T1036.004 Masquerade Task or Service |
CampaignAPT41 DUST | APT41 DUST disguised DUSTPAN as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| T1070.004 File Deletion |
CampaignAPT41 DUST | APT41 DUST deleted various artifacts from victim systems following use. |
| T1071.001 Web Protocols |
CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| T1074.001 Local Data Staging |
CampaignAPT41 DUST | APT41 DUST involved exporting data from Oracle databases to local CSV files prior to exfiltration. |
| T1102 Web Service |
CampaignAPT41 DUST | APT41 DUST used compromised Google Workspace accounts for command and control. |
| T1105 Ingress Tool Transfer |
CampaignAPT41 DUST | APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper. |
| T1119 Automated Collection |
CampaignAPT41 DUST | APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information. |
| T1213.006 Databases |
CampaignAPT41 DUST | APT41 DUST collected data from victim Oracle databases using SQLULDR2. |
| T1505.003 Web Shell |
CampaignAPT41 DUST | APT41 DUST involved use of web shells such as ANTSWORD and BLUEBEAM for persistence. |
| T1543.003 Windows Service |
CampaignAPT41 DUST | APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN. |
| T1553.002 Code Signing |
CampaignAPT41 DUST | APT41 DUST used stolen code signing certificates for DUSTTRAP malware and subsequent payloads. |
| T1560.001 Archive via Utility |
CampaignAPT41 DUST | APT41 DUST used `rar` to compress data downloaded from internal Oracle databases prior to exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignAPT41 DUST | APT41 DUST exfiltrated collected information to OneDrive. |
| T1569.002 Service Execution |
CampaignAPT41 DUST | APT41 DUST used Windows services to execute DUSTPAN. |
| T1573.002 Asymmetric Cryptography |
CampaignAPT41 DUST | APT41 DUST used HTTPS for command and control. |
| T1574.001 DLL |
CampaignAPT41 DUST | APT41 DUST involved the use of DLL search order hijacking to execute DUSTTRAP. APT41 DUST used also DLL side-loading to execute DUSTTRAP via an AhnLab uninstaller. |
| T1583.007 Serverless |
CampaignAPT41 DUST | APT41 DUST used infrastructure hosted behind Cloudflare or utilized Cloudflare Workers for command and control. |
| T1586.003 Cloud Accounts |
CampaignAPT41 DUST | APT41 DUST used compromised Google Workspace accounts for command and control. |
| T1588.003 Code Signing Certificates |
CampaignAPT41 DUST | APT41 DUST used stolen code signing certificates to sign DUSTTRAP malware and components. |
| T1593.002 Search Engines |
CampaignAPT41 DUST | APT41 DUST involved use of search engines to research victim servers. |
| T1594 Search Victim-Owned Websites |
CampaignAPT41 DUST | APT41 DUST involved access of external victim websites for target development. |
| T1596.005 Scan Databases |
CampaignAPT41 DUST | APT41 DUST used internet scan data for target development. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.