ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0004×

46 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupKe3chang

Ke3chang has dumped credentials, including by using Mimikatz.

T1003.002
Security Account Manager
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1003.003
NTDS
GroupKe3chang

Ke3chang has used NTDSDump and other password dumping tools to gather credentials.

T1003.004
LSA Secrets
GroupKe3chang

Ke3chang has dumped credentials, including by using gsecdump.

T1005
Data from Local System
GroupKe3chang

Ke3chang gathered information and files from local directories for exfiltration.

T1007
System Service Discovery
GroupKe3chang

Ke3chang performs service discovery using net start commands.

T1016
System Network Configuration Discovery
GroupKe3chang

Ke3chang has performed local network configuration discovery using ipconfig.

T1018
Remote System Discovery
GroupKe3chang

Ke3chang has used network scanning and enumeration tools, including Ping.

T1020
Automated Exfiltration
GroupKe3chang

Ke3chang has performed frequent and scheduled data exfiltration from compromised networks.

T1021.002
SMB/Windows Admin Shares
GroupKe3chang

Ke3chang actors have been known to copy files to the network shares of other computers to move laterally.

T1027
Obfuscated Files or Information
GroupKe3chang

Ke3chang has used Base64-encoded shellcode strings.

T1033
System Owner/User Discovery
GroupKe3chang

Ke3chang has used implants capable of collecting the signed-in username.

T1036.002
Right-to-Left Override
GroupKe3chang

Ke3chang has used the right-to-left override character in spearphishing attachment names to trick targets into executing .scr and .exe files.

T1036.005
Match Legitimate Resource Name or Location
GroupKe3chang

Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`.

T1041
Exfiltration Over C2 Channel
GroupKe3chang

Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations.

T1049
System Network Connections Discovery
GroupKe3chang

Ke3chang performs local network connection discovery using netstat.

T1056.001
Keylogging
GroupKe3chang

Ke3chang has used keyloggers.

T1057
Process Discovery
GroupKe3chang

Ke3chang performs process discovery using tasklist commands.

T1059
Command and Scripting Interpreter
GroupKe3chang

Malware used by Ke3chang can run commands on the command-line interface.

T1059.003
Windows Command Shell
GroupKe3chang

Ke3chang has used batch scripts in its malware to install persistence mechanisms.

T1069.002
Domain Groups
GroupKe3chang

Ke3chang performs discovery of permission groups net group /domain.

T1071.001
Web Protocols
GroupKe3chang

Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2.

T1071.004
DNS
GroupKe3chang

Ke3chang malware RoyalDNS has used DNS for C2.

T1078
Valid Accounts
GroupKe3chang

Ke3chang has used credential dumpers or stealers to obtain legitimate credentials, which they used to gain access to victim accounts.

T1078.004
Cloud Accounts
GroupKe3chang

Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts.

T1082
System Information Discovery
GroupKe3chang

Ke3chang performs operating system information discovery using systeminfo and has used implants to identify the system language and computer name.

T1083
File and Directory Discovery
GroupKe3chang

Ke3chang uses command-line interaction to search files and directories.

T1087.001
Local Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1087.002
Domain Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1105
Ingress Tool Transfer
GroupKe3chang

Ke3chang has used tools to download files to compromised machines.

T1114.002
Remote Email Collection
GroupKe3chang

Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes.

T1119
Automated Collection
GroupKe3chang

Ke3chang has performed frequent and scheduled data collection from victim networks.

T1133
External Remote Services
GroupKe3chang

Ke3chang has gained access through VPNs including with compromised accounts and stolen VPN certificates.

T1140
Deobfuscate/Decode Files or Information
GroupKe3chang

Ke3chang has deobfuscated Base64-encoded shellcode strings prior to loading them.

T1190
Exploit Public-Facing Application
GroupKe3chang

Ke3chang has compromised networks by exploiting Internet-facing applications, including vulnerable Microsoft Exchange and SharePoint servers.

T1213.002
Sharepoint
GroupKe3chang

Ke3chang used a SharePoint enumeration and data dumping tool known as spwebmember.

T1543.003
Windows Service
GroupKe3chang

Ke3chang backdoor RoyalDNS established persistence through adding a service called Nwsapagent.

T1547.001
Registry Run Keys / Startup Folder
GroupKe3chang

Several Ke3chang backdoors achieved persistence by adding a Run key.

T1558.001
Golden Ticket
GroupKe3chang

Ke3chang has used Mimikatz to generate Kerberos golden tickets.

T1560
Archive Collected Data
GroupKe3chang

The Ke3chang group has been known to compress data before exfiltration.

T1560.001
Archive via Utility
GroupKe3chang

Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration.

T1569.002
Service Execution
GroupKe3chang

Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries.

T1583.005
Botnet
GroupKe3chang

Ke3chang has utilized an ORB (operational relay box) network for reconnaissance and vulnerability exploitation.

T1587.001
Malware
GroupKe3chang

Ke3chang has developed custom malware that allowed them to maintain persistence on victim networks.

T1588.002
Tool
GroupKe3chang

Ke3chang has obtained and used tools such as Mimikatz.

T1614.001
System Language Discovery
GroupKe3chang

Ke3chang has used implants to collect the system language ID of a compromised machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.