Real-world descriptions of how a group, tool or campaign used a technique.
16 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
GroupAxiom | Axiom has used steganography to hide its C2 communications. |
| T1003 OS Credential Dumping |
GroupAxiom | Axiom has been known to dump credentials. |
| T1005 Data from Local System |
GroupAxiom | Axiom has collected data from a compromised network. |
| T1021.001 Remote Desktop Protocol |
GroupAxiom | Axiom has used RDP during operations. |
| T1078 Valid Accounts |
GroupAxiom | Axiom has used previously compromised administrative accounts to escalate privileges. |
| T1189 Drive-by Compromise |
GroupAxiom | Axiom has used watering hole attacks to gain access. |
| T1190 Exploit Public-Facing Application |
GroupAxiom | Axiom has been observed using SQL injection to gain access to systems. |
| T1203 Exploitation for Client Execution |
GroupAxiom | Axiom has used exploits for multiple vulnerabilities including CVE-2014-0322, CVE-2012-4792, CVE-2012-1889, and CVE-2013-3893. |
| T1546.008 Accessibility Features |
GroupAxiom | Axiom actors have been known to use the Sticky Keys replacement within RDP sessions to obtain persistence. |
| T1553 Subvert Trust Controls |
GroupAxiom | Axiom has used digital certificates to deliver malware. |
| T1560 Archive Collected Data |
GroupAxiom | Axiom has compressed and encrypted data prior to exfiltration. |
| T1563.002 RDP Hijacking |
GroupAxiom | Axiom has targeted victims with remote administration tools including RDP. |
| T1566 Phishing |
GroupAxiom | Axiom has used spear phishing to initially compromise victims. |
| T1583.002 DNS Server |
GroupAxiom | Axiom has acquired dynamic DNS services for use in the targeting of intended victims. |
| T1583.003 Virtual Private Server |
GroupAxiom | Axiom has used VPS hosting providers in targeting of intended victims. |
| T1584.005 Botnet |
GroupAxiom | Axiom has used large groups of compromised machines for use as proxy nodes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.