ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0046×

25 examples

TechniqueUsed byProcedure example
T1014
Rootkit
CampaignArcaneDoor

ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices.

T1020
Automated Exfiltration
CampaignArcaneDoor

ArcaneDoor included scripted exfiltration of collected data.

T1036
Masquerading
CampaignArcaneDoor

ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances.

T1037
Boot or Logon Initialization Scripts
CampaignArcaneDoor

ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices.

T1040
Network Sniffing
CampaignArcaneDoor

ArcaneDoor included network packet capture and sniffing for data collection in victim environments.

T1041
Exfiltration Over C2 Channel
CampaignArcaneDoor

ArcaneDoor included use of existing command and control channels for data exfiltration.

T1055
Process Injection
CampaignArcaneDoor

ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices.

T1059
Command and Scripting Interpreter
CampaignArcaneDoor

ArcaneDoor included the adversary executing command line interface (CLI) commands.

T1070.004
File Deletion
CampaignArcaneDoor

ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions.

T1071.001
Web Protocols
CampaignArcaneDoor

ArcaneDoor command and control activity was conducted through HTTP.

T1082
System Information Discovery
CampaignArcaneDoor

ArcaneDoor included collection of victim device configuration information.

T1102.003
One-Way Communication
CampaignArcaneDoor

ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed.

T1119
Automated Collection
CampaignArcaneDoor

ArcaneDoor included collection of packet capture and system configuration information.

T1133
External Remote Services
CampaignArcaneDoor

ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices.

T1140
Deobfuscate/Decode Files or Information
CampaignArcaneDoor

ArcaneDoor involved the use of Base64 obfuscated scripts and commands.

T1190
Exploit Public-Facing Application
CampaignArcaneDoor

ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution.

T1556
Modify Authentication Process
CampaignArcaneDoor

ArcaneDoor included modification of the AAA process to bypass authentication mechanisms.

T1557
Adversary-in-the-Middle
CampaignArcaneDoor

ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device.

T1583.003
Virtual Private Server
CampaignArcaneDoor

ArcaneDoor included the use of dedicated, adversary-controlled virtual private servers for command and control.

T1583.006
Web Services
CampaignArcaneDoor

ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices.

T1587.001
Malware
CampaignArcaneDoor

ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner.

T1587.003
Digital Certificates
CampaignArcaneDoor

ArcaneDoor included acquiring digital certificates mimicking patterns associated with Cisco ASA appliances for command and control infrastructure.

T1653
Power Settings
CampaignArcaneDoor

ArcaneDoor involved exploitation of CVE-2024-20353 to force a victim Cisco ASA to reboot, triggering the automated unzipping and execution of the Line Runner implant.

T1685
Disable or Modify Tools
CampaignArcaneDoor

ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations.

T1690
Prevent Command History Logging
CampaignArcaneDoor

ArcaneDoor included disabling logging on targeted Cisco ASA appliances.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.