ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Campaign: C0056×

26 examples

TechniqueUsed byProcedure example
T1014
Rootkit
CampaignRedPenguin

During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA.

T1016
System Network Configuration Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details.

T1027.013
Encrypted/Encoded File
CampaignRedPenguin

During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices.

T1036.005
Match Legitimate Resource Name or Location
CampaignRedPenguin

During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd.

T1040
Network Sniffing
CampaignRedPenguin

During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer.

T1041
Exfiltration Over C2 Channel
CampaignRedPenguin

During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server.

T1055
Process Injection
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes.

T1057
Process Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon.

T1059.004
Unix Shell
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of launching an interactive shell.

T1059.008
Network Device CLI
CampaignRedPenguin

During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices.

T1070.004
File Deletion
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capaple of removing scripts after execution.

T1070.007
Clear Network Connection History and Configurations
CampaignRedPenguin

During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices.

T1078
Valid Accounts
CampaignRedPenguin

During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers.

T1090
Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port.

T1090.003
Multi-hop Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks.

T1095
Non-Application Layer Protocol
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2.

T1104
Multi-Stage Channels
CampaignRedPenguin

During RedPenguin, UNC3886 used malware with separate channels to request and carry out tasks from C2.

T1105
Ingress Tool Transfer
CampaignRedPenguin

During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure.

T1140
Deobfuscate/Decode Files or Information
CampaignRedPenguin

During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives.

T1203
Exploitation for Client Execution
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution.

T1205
Traffic Signaling
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged malware capable of inpecting packets for a magic-string to activate backdoor functionalities.

T1554
Compromise Host Software Binary
CampaignRedPenguin

During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons.

T1571
Non-Standard Port
CampaignRedPenguin

During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default.

T1573.001
Symmetric Cryptography
CampaignRedPenguin

During RedPenguin, UNC3886 malware used the RC4 cipher to encrypt outgoing C2 messages.

T1587.001
Malware
CampaignRedPenguin

During RedPenguin, UNC3886 deployed custom malware based on the publicly-available TINYSHELL backdoor.

T1690
Prevent Command History Logging
CampaignRedPenguin

During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.