ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0007×

93 examples

TechniqueUsed byProcedure example
T1001.001
Junk Data
GroupAPT28

APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire.

T1003
OS Credential Dumping
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims.

T1003.001
LSASS Memory
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function.

T1003.003
NTDS
GroupAPT28

APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access.

T1005
Data from Local System
GroupAPT28

APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.

T1014
Rootkit
GroupAPT28

APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax.

T1021.002
SMB/Windows Admin Shares
GroupAPT28

APT28 has mapped network drives using Net and administrator credentials.

T1025
Data from Removable Media
GroupAPT28

An APT28 backdoor may collect the entire contents of an inserted USB device.

T1027.013
Encrypted/Encoded File
GroupAPT28

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

T1030
Data Transfer Size Limits
GroupAPT28

APT28 has split archived exfiltration files into chunks smaller than 1MB.

T1036
Masquerading
GroupAPT28

APT28 has renamed the WinRAR utility to avoid detection.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT28

APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page.

T1037.001
Logon Script (Windows)
GroupAPT28

An APT28 loader Trojan adds the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1039
Data from Network Shared Drive
GroupAPT28

APT28 has collected files from network shared drives.

T1040
Network Sniffing
GroupAPT28

APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
GroupAPT28

APT28 has exfiltrated archives of collected data previously staged on a target's OWA server via HTTPS.

T1056.001
Keylogging
GroupAPT28

APT28 has used tools to perform keylogging.

T1057
Process Discovery
GroupAPT28

An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions.

T1059.001
PowerShell
GroupAPT28

APT28 downloads and executes PowerShell scripts and performs PowerShell commands.

T1059.003
Windows Command Shell
GroupAPT28

An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads.

T1068
Exploitation for Privilege Escalation
GroupAPT28

APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263, and CVE-2022-38028 to escalate privileges.

T1070.004
File Deletion
GroupAPT28

APT28 has intentionally deleted computer files to cover their tracks, including with use of the program CCleaner.

T1070.006
Timestomp
GroupAPT28

APT28 has performed timestomping on victim files.

T1071.001
Web Protocols
GroupAPT28

Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration.

T1071.003
Mail Protocols
GroupAPT28

APT28 has used IMAP, POP3, and SMTP for a communication channel in various implants, including using self-registered Google Mail accounts and later compromised email servers of its victims.

T1074.001
Local Data Staging
GroupAPT28

APT28 has stored captured credential information in a file named pi.log.

T1074.002
Remote Data Staging
GroupAPT28

APT28 has staged archives of collected data on a target's Outlook Web Access (OWA) server.

T1078
Valid Accounts
GroupAPT28

APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder.

T1078.004
Cloud Accounts
GroupAPT28

APT28 has used compromised Office 365 service accounts with Global Administrator privileges to collect email from user inboxes.

T1083
File and Directory Discovery
GroupAPT28

APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms.

T1090.002
External Proxy
GroupAPT28

APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server.

T1090.003
Multi-hop Proxy
GroupAPT28

APT28 has routed traffic over Tor and VPN servers to obfuscate their activities.

T1091
Replication Through Removable Media
GroupAPT28

APT28 uses a tool to infect connected USB devices and transmit itself to air-gapped computers when the infected USB device is inserted.

T1092
Communication Through Removable Media
GroupAPT28

APT28 uses a tool that captures information from air-gapped computers via an infected USB and transfers it to network-connected computer when the USB is inserted.

T1098.002
Additional Email Delegate Permissions
GroupAPT28

APT28 has used a Powershell cmdlet to grant the ApplicationImpersonation role to a compromised account.

T1102.002
Bidirectional Communication
GroupAPT28

APT28 has used Google Drive for C2.

T1105
Ingress Tool Transfer
GroupAPT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.

T1110
Brute Force
GroupAPT28

APT28 can perform brute force attacks to obtain credentials.

T1110.001
Password Guessing
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks.

T1110.003
Password Spraying
GroupAPT28

APT28 has used a brute-force/password-spray tooling that operated in two modes: in password-spraying mode it conducted approximately four authentication attempts per hour per targeted account over the course of several days or weeks. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password spray attacks.

T1113
Screen Capture
GroupAPT28

APT28 has used tools to take screenshots from victims.

T1114.002
Remote Email Collection
GroupAPT28

APT28 has collected emails from victim Microsoft Exchange servers.

T1119
Automated Collection
GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

T1120
Peripheral Device Discovery
GroupAPT28

APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim.

T1133
External Remote Services
GroupAPT28

APT28 has used Tor and a variety of commercial VPN services to route brute force authentication attempts.

T1134.001
Token Impersonation/Theft
GroupAPT28

APT28 has used CVE-2015-1701 to access the SYSTEM token and copy it into the current process as part of privilege escalation.

T1137.002
Office Test
GroupAPT28

APT28 has used the Office Test persistence mechanism within Microsoft Office by adding the Registry key HKCU\Software\Microsoft\Office test\Special\Perf to execute code.

T1140
Deobfuscate/Decode Files or Information
GroupAPT28

An APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.

T1189
Drive-by Compromise
GroupAPT28

APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages.

T1190
Exploit Public-Facing Application
GroupAPT28

APT28 has used a variety of public exploits, including CVE 2020-0688 and CVE 2020-17144, to gain execution on vulnerable Microsoft Exchange; they have also conducted SQL injection attacks against external websites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.