ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0007×

93 examples

TechniqueUsed byProcedure example
T1199
Trusted Relationship
GroupAPT28

Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network.

T1203
Exploitation for Client Execution
GroupAPT28

APT28 has exploited Microsoft Office vulnerability CVE-2017-0262 for execution.

T1204.001
Malicious Link
GroupAPT28

APT28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.

T1204.002
Malicious File
GroupAPT28

APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts.

T1210
Exploitation of Remote Services
GroupAPT28

APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement.

T1211
Exploitation for Stealth
GroupAPT28

APT28 has used CVE-2015-4902 to bypass security features.

T1213
Data from Information Repositories
GroupAPT28

APT28 has collected files from various information repositories.

T1213.002
Sharepoint
GroupAPT28

APT28 has collected information from Microsoft SharePoint services within target networks.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1221
Template Injection
GroupAPT28

APT28 used weaponized Microsoft Word documents abusing the remote template function to retrieve a malicious macro.

T1498
Network Denial of Service
GroupAPT28

In 2016, APT28 conducted a distributed denial of service (DDoS) attack against the World Anti-Doping Agency.

T1505.003
Web Shell
GroupAPT28

APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server.

T1528
Steal Application Access Token
GroupAPT28

APT28 has used several malicious applications to steal user OAuth access tokens including applications masquerading as "Google Defender" "Google Email Protection," and "Google Scanner" for Gmail users. They also targeted Yahoo users with applications masquerading as "Delivery Service" and "McAfee Email Protection".

T1542.003
Bootkit
GroupAPT28

APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy.

T1546.015
Component Object Model Hijacking
GroupAPT28

APT28 has used COM hijacking for persistence by replacing the legitimate MMDeviceEnumerator object with a payload.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT28

APT28 has deployed malware that has copied itself to the startup directory for persistence.

T1550.001
Application Access Token
GroupAPT28

APT28 has used several malicious applications that abused OAuth access tokens to gain access to target email accounts, including Gmail and Yahoo Mail.

T1550.002
Pass the Hash
GroupAPT28

APT28 has used pass the hash for lateral movement.

T1557.004
Evil Twin
GroupAPT28

APT28 has used a Wi-Fi Pineapple to set up Evil Twin Wi-Fi Poisoning for the purposes of capturing victim credentials or planting espionage-oriented malware.

T1559.002
Dynamic Data Exchange
GroupAPT28

APT28 has delivered JHUHUGIT and Koadic by executing PowerShell commands through DDE in Word documents.

T1560
Archive Collected Data
GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

T1560.001
Archive via Utility
GroupAPT28

APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection.

T1564.001
Hidden Files and Directories
GroupAPT28

APT28 has saved files with hidden file attributes.

T1564.003
Hidden Window
GroupAPT28

APT28 has used the WindowStyle parameter to conceal PowerShell windows.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

T1567
Exfiltration Over Web Service
GroupAPT28

APT28 can exfiltrate data over Google Drive.

T1573.001
Symmetric Cryptography
GroupAPT28

APT28 installed a Delphi backdoor that used a custom algorithm for C2 communications.

T1583.001
Domains
GroupAPT28

APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations.

T1583.003
Virtual Private Server
GroupAPT28

APT28 hosted phishing domains on free services for brief periods of time during campaigns.

T1583.006
Web Services
GroupAPT28

APT28 has used newly-created Blogspot pages for credential harvesting operations.

T1584.008
Network Devices
GroupAPT28

APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages.

T1586.002
Email Accounts
GroupAPT28

APT28 has used compromised email accounts to send credential phishing emails.

T1588.002
Tool
GroupAPT28

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

T1588.007
Artificial Intelligence
GroupAPT28

APT28 has deployed LAMEHUG which can can query an LLM to generate and return commands for post compromise activity on targeted systems.

T1589.001
Credentials
GroupAPT28

APT28 has harvested user's login credentials.

T1591
Gather Victim Org Information
GroupAPT28

APT28 has used large language models (LLMs) to gather information about satellite capabilities.

T1595.002
Vulnerability Scanning
GroupAPT28

APT28 has performed large-scale scans in an attempt to find vulnerable servers.

T1596
Search Open Technical Databases
GroupAPT28

APT28 has used large language models (LLMs) to assist in script development and deployment.

T1598
Phishing for Information
GroupAPT28

APT28 has used spearphishing to compromise credentials.

T1598.003
Spearphishing Link
GroupAPT28

APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites.

T1669
Wi-Fi Networks
GroupAPT28

APT28 has exploited open Wi-Fi access points for initial access to target devices using the network.

T1684.001
Impersonation
GroupAPT28

LAMEHUG has sent spearphishing emails impersonating Ukrainian government officials.

T1685.005
Clear Windows Event Logs
GroupAPT28

APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.