Real-world descriptions of how a group, tool or campaign used a technique.
46 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupKe3chang | Ke3chang has dumped credentials, including by using Mimikatz. |
| T1003.002 Security Account Manager |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1003.003 NTDS |
GroupKe3chang | Ke3chang has used NTDSDump and other password dumping tools to gather credentials. |
| T1003.004 LSA Secrets |
GroupKe3chang | Ke3chang has dumped credentials, including by using gsecdump. |
| T1005 Data from Local System |
GroupKe3chang | Ke3chang gathered information and files from local directories for exfiltration. |
| T1007 System Service Discovery |
GroupKe3chang | Ke3chang performs service discovery using |
| T1016 System Network Configuration Discovery |
GroupKe3chang | Ke3chang has performed local network configuration discovery using |
| T1018 Remote System Discovery |
GroupKe3chang | Ke3chang has used network scanning and enumeration tools, including Ping. |
| T1020 Automated Exfiltration |
GroupKe3chang | Ke3chang has performed frequent and scheduled data exfiltration from compromised networks. |
| T1021.002 SMB/Windows Admin Shares |
GroupKe3chang | Ke3chang actors have been known to copy files to the network shares of other computers to move laterally. |
| T1027 Obfuscated Files or Information |
GroupKe3chang | Ke3chang has used Base64-encoded shellcode strings. |
| T1033 System Owner/User Discovery |
GroupKe3chang | Ke3chang has used implants capable of collecting the signed-in username. |
| T1036.002 Right-to-Left Override |
GroupKe3chang | Ke3chang has used the right-to-left override character in spearphishing attachment names to trick targets into executing .scr and .exe files. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupKe3chang | Ke3chang has dropped their malware into legitimate installed software paths including: `C:\ProgramFiles\Realtek\Audio\HDA\AERTSr.exe`, `C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitRdr64.exe`, `C:\Program Files (x86)\Adobe\Flash Player\AddIns\airappinstaller\airappinstall.exe`, and `C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd64.exe`. |
| T1041 Exfiltration Over C2 Channel |
GroupKe3chang | Ke3chang transferred compressed and encrypted RAR files containing exfiltration through the established backdoor command and control channel during operations. |
| T1049 System Network Connections Discovery |
GroupKe3chang | Ke3chang performs local network connection discovery using |
| T1056.001 Keylogging |
GroupKe3chang | Ke3chang has used keyloggers. |
| T1057 Process Discovery |
GroupKe3chang | Ke3chang performs process discovery using |
| T1059 Command and Scripting Interpreter |
GroupKe3chang | Malware used by Ke3chang can run commands on the command-line interface. |
| T1059.003 Windows Command Shell |
GroupKe3chang | Ke3chang has used batch scripts in its malware to install persistence mechanisms. |
| T1069.002 Domain Groups |
GroupKe3chang | Ke3chang performs discovery of permission groups |
| T1071.001 Web Protocols |
GroupKe3chang | Ke3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer (IE) by using the COM interface IWebBrowser2. |
| T1071.004 DNS |
GroupKe3chang | Ke3chang malware RoyalDNS has used DNS for C2. |
| T1078 Valid Accounts |
GroupKe3chang | Ke3chang has used credential dumpers or stealers to obtain legitimate credentials, which they used to gain access to victim accounts. |
| T1078.004 Cloud Accounts |
GroupKe3chang | Ke3chang has used compromised credentials to sign into victims’ Microsoft 365 accounts. |
| T1082 System Information Discovery |
GroupKe3chang | Ke3chang performs operating system information discovery using |
| T1083 File and Directory Discovery |
GroupKe3chang | Ke3chang uses command-line interaction to search files and directories. |
| T1087.001 Local Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1087.002 Domain Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1105 Ingress Tool Transfer |
GroupKe3chang | Ke3chang has used tools to download files to compromised machines. |
| T1114.002 Remote Email Collection |
GroupKe3chang | Ke3chang has used compromised credentials and a .NET tool to dump data from Microsoft Exchange mailboxes. |
| T1119 Automated Collection |
GroupKe3chang | Ke3chang has performed frequent and scheduled data collection from victim networks. |
| T1133 External Remote Services |
GroupKe3chang | Ke3chang has gained access through VPNs including with compromised accounts and stolen VPN certificates. |
| T1140 Deobfuscate/Decode Files or Information |
GroupKe3chang | Ke3chang has deobfuscated Base64-encoded shellcode strings prior to loading them. |
| T1190 Exploit Public-Facing Application |
GroupKe3chang | Ke3chang has compromised networks by exploiting Internet-facing applications, including vulnerable Microsoft Exchange and SharePoint servers. |
| T1213.002 Sharepoint |
GroupKe3chang | Ke3chang used a SharePoint enumeration and data dumping tool known as spwebmember. |
| T1543.003 Windows Service |
GroupKe3chang | Ke3chang backdoor RoyalDNS established persistence through adding a service called |
| T1547.001 Registry Run Keys / Startup Folder |
GroupKe3chang | Several Ke3chang backdoors achieved persistence by adding a Run key. |
| T1558.001 Golden Ticket |
GroupKe3chang | Ke3chang has used Mimikatz to generate Kerberos golden tickets. |
| T1560 Archive Collected Data |
GroupKe3chang | The Ke3chang group has been known to compress data before exfiltration. |
| T1560.001 Archive via Utility |
GroupKe3chang | Ke3chang is known to use 7Zip and RAR with passwords to encrypt data prior to exfiltration. |
| T1569.002 Service Execution |
GroupKe3chang | Ke3chang has used a tool known as RemoteExec (similar to PsExec) to remotely execute batch scripts and binaries. |
| T1583.005 Botnet |
GroupKe3chang | Ke3chang has utilized an ORB (operational relay box) network for reconnaissance and vulnerability exploitation. |
| T1587.001 Malware |
GroupKe3chang | Ke3chang has developed custom malware that allowed them to maintain persistence on victim networks. |
| T1588.002 Tool |
GroupKe3chang | |
| T1614.001 System Language Discovery |
GroupKe3chang | Ke3chang has used implants to collect the system language ID of a compromised machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.