Real-world descriptions of how a group, tool or campaign used a technique.
25 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
CampaignArcaneDoor | ArcaneDoor included hooking the `processHostScanReply()` function on victim Cisco ASA devices. |
| T1020 Automated Exfiltration |
CampaignArcaneDoor | ArcaneDoor included scripted exfiltration of collected data. |
| T1036 Masquerading |
CampaignArcaneDoor | ArcaneDoor involved the use of digital certificates on adversary-controlled network infrastructure that mimicked the formatting used by legitimate Cisco ASA appliances. |
| T1037 Boot or Logon Initialization Scripts |
CampaignArcaneDoor | ArcaneDoor used malicious boot scripts to install the Line Runner backdoor on victim devices. |
| T1040 Network Sniffing |
CampaignArcaneDoor | ArcaneDoor included network packet capture and sniffing for data collection in victim environments. |
| T1041 Exfiltration Over C2 Channel |
CampaignArcaneDoor | ArcaneDoor included use of existing command and control channels for data exfiltration. |
| T1055 Process Injection |
CampaignArcaneDoor | ArcaneDoor included injecting code into the AAA and Crash Dump processes on infected Cisco ASA devices. |
| T1059 Command and Scripting Interpreter |
CampaignArcaneDoor | ArcaneDoor included the adversary executing command line interface (CLI) commands. |
| T1070.004 File Deletion |
CampaignArcaneDoor | ArcaneDoor included multiple instances of file deletion or removal during execution and other adversary actions. |
| T1071.001 Web Protocols |
CampaignArcaneDoor | ArcaneDoor command and control activity was conducted through HTTP. |
| T1082 System Information Discovery |
CampaignArcaneDoor | ArcaneDoor included collection of victim device configuration information. |
| T1102.003 One-Way Communication |
CampaignArcaneDoor | ArcaneDoor utilized HTTP command and control traffic where commands are intercepted from HTTP traffic to the device, parsed for appropriate identifiers and commands, and then executed. |
| T1119 Automated Collection |
CampaignArcaneDoor | ArcaneDoor included collection of packet capture and system configuration information. |
| T1133 External Remote Services |
CampaignArcaneDoor | ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignArcaneDoor | ArcaneDoor involved the use of Base64 obfuscated scripts and commands. |
| T1190 Exploit Public-Facing Application |
CampaignArcaneDoor | ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution. |
| T1556 Modify Authentication Process |
CampaignArcaneDoor | ArcaneDoor included modification of the AAA process to bypass authentication mechanisms. |
| T1557 Adversary-in-the-Middle |
CampaignArcaneDoor | ArcaneDoor included interception of HTTP traffic to victim devices to identify and parse command and control information sent to the device. |
| T1583.003 Virtual Private Server |
CampaignArcaneDoor | ArcaneDoor included the use of dedicated, adversary-controlled virtual private servers for command and control. |
| T1583.006 Web Services |
CampaignArcaneDoor | ArcaneDoor included the use of OpenConnect VPN Server instances for conducting actions on victim devices. |
| T1587.001 Malware |
CampaignArcaneDoor | ArcaneDoor featured the development and deployment of two unique malware types, Line Dancer and Line Runner. |
| T1587.003 Digital Certificates |
CampaignArcaneDoor | ArcaneDoor included acquiring digital certificates mimicking patterns associated with Cisco ASA appliances for command and control infrastructure. |
| T1653 Power Settings |
CampaignArcaneDoor | ArcaneDoor involved exploitation of CVE-2024-20353 to force a victim Cisco ASA to reboot, triggering the automated unzipping and execution of the Line Runner implant. |
| T1685 Disable or Modify Tools |
CampaignArcaneDoor | ArcaneDoor modified the Authentication, Authorization, and Accounting (AAA) function of targeted Cisco ASA appliances to allow the threat actor to bypass normal AAA operations. |
| T1690 Prevent Command History Logging |
CampaignArcaneDoor | ArcaneDoor included disabling logging on targeted Cisco ASA appliances. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.