Real-world descriptions of how a group, tool or campaign used a technique.
93 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1199 Trusted Relationship |
GroupAPT28 | Once APT28 gained access to the DCCC network, the group then proceeded to use that access to compromise the DNC network. |
| T1203 Exploitation for Client Execution |
GroupAPT28 | APT28 has exploited Microsoft Office vulnerability CVE-2017-0262 for execution. |
| T1204.001 Malicious Link |
GroupAPT28 | APT28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders. |
| T1204.002 Malicious File |
GroupAPT28 | APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts. |
| T1210 Exploitation of Remote Services |
GroupAPT28 | APT28 exploited a Windows SMB Remote Code Execution Vulnerability to conduct lateral movement. |
| T1211 Exploitation for Stealth |
GroupAPT28 | APT28 has used CVE-2015-4902 to bypass security features. |
| T1213 Data from Information Repositories |
GroupAPT28 | APT28 has collected files from various information repositories. |
| T1213.002 Sharepoint |
GroupAPT28 | APT28 has collected information from Microsoft SharePoint services within target networks. |
| T1218.011 Rundll32 |
GroupAPT28 | APT28 executed CHOPSTICK by using rundll32 commands such as |
| T1221 Template Injection |
GroupAPT28 | APT28 used weaponized Microsoft Word documents abusing the remote template function to retrieve a malicious macro. |
| T1498 Network Denial of Service |
GroupAPT28 | In 2016, APT28 conducted a distributed denial of service (DDoS) attack against the World Anti-Doping Agency. |
| T1505.003 Web Shell |
GroupAPT28 | APT28 has used a modified and obfuscated version of the reGeorg web shell to maintain persistence on a target's Outlook Web Access (OWA) server. |
| T1528 Steal Application Access Token |
GroupAPT28 | APT28 has used several malicious applications to steal user OAuth access tokens including applications masquerading as "Google Defender" "Google Email Protection," and "Google Scanner" for Gmail users. They also targeted Yahoo users with applications masquerading as "Delivery Service" and "McAfee Email Protection". |
| T1542.003 Bootkit |
GroupAPT28 | APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy. |
| T1546.015 Component Object Model Hijacking |
GroupAPT28 | APT28 has used COM hijacking for persistence by replacing the legitimate |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT28 | APT28 has deployed malware that has copied itself to the startup directory for persistence. |
| T1550.001 Application Access Token |
GroupAPT28 | APT28 has used several malicious applications that abused OAuth access tokens to gain access to target email accounts, including Gmail and Yahoo Mail. |
| T1550.002 Pass the Hash |
GroupAPT28 | APT28 has used pass the hash for lateral movement. |
| T1557.004 Evil Twin |
GroupAPT28 | APT28 has used a Wi-Fi Pineapple to set up Evil Twin Wi-Fi Poisoning for the purposes of capturing victim credentials or planting espionage-oriented malware. |
| T1559.002 Dynamic Data Exchange |
GroupAPT28 | APT28 has delivered JHUHUGIT and Koadic by executing PowerShell commands through DDE in Word documents. |
| T1560 Archive Collected Data |
GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| T1560.001 Archive via Utility |
GroupAPT28 | APT28 has used a variety of utilities, including WinRAR, to archive collected data with password protection. |
| T1564.001 Hidden Files and Directories |
GroupAPT28 | APT28 has saved files with hidden file attributes. |
| T1564.003 Hidden Window |
GroupAPT28 | APT28 has used the WindowStyle parameter to conceal PowerShell windows. |
| T1566.001 Spearphishing Attachment |
GroupAPT28 | APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments. |
| T1567 Exfiltration Over Web Service |
GroupAPT28 | APT28 can exfiltrate data over Google Drive. |
| T1573.001 Symmetric Cryptography |
GroupAPT28 | APT28 installed a Delphi backdoor that used a custom algorithm for C2 communications. |
| T1583.001 Domains |
GroupAPT28 | APT28 registered domains imitating NATO, OSCE security websites, Caucasus information resources, and other organizations. |
| T1583.003 Virtual Private Server |
GroupAPT28 | APT28 hosted phishing domains on free services for brief periods of time during campaigns. |
| T1583.006 Web Services |
GroupAPT28 | APT28 has used newly-created Blogspot pages for credential harvesting operations. |
| T1584.008 Network Devices |
GroupAPT28 | APT28 compromised Ubiquiti network devices to act as collection devices for credentials compromised via phishing webpages. |
| T1586.002 Email Accounts |
GroupAPT28 | APT28 has used compromised email accounts to send credential phishing emails. |
| T1588.002 Tool |
GroupAPT28 | APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder. |
| T1588.007 Artificial Intelligence |
GroupAPT28 | APT28 has deployed LAMEHUG which can can query an LLM to generate and return commands for post compromise activity on targeted systems. |
| T1589.001 Credentials |
GroupAPT28 | APT28 has harvested user's login credentials. |
| T1591 Gather Victim Org Information |
GroupAPT28 | APT28 has used large language models (LLMs) to gather information about satellite capabilities. |
| T1595.002 Vulnerability Scanning |
GroupAPT28 | APT28 has performed large-scale scans in an attempt to find vulnerable servers. |
| T1596 Search Open Technical Databases |
GroupAPT28 | APT28 has used large language models (LLMs) to assist in script development and deployment. |
| T1598 Phishing for Information |
GroupAPT28 | APT28 has used spearphishing to compromise credentials. |
| T1598.003 Spearphishing Link |
GroupAPT28 | APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites. |
| T1669 Wi-Fi Networks |
GroupAPT28 | APT28 has exploited open Wi-Fi access points for initial access to target devices using the network. |
| T1684.001 Impersonation |
GroupAPT28 | LAMEHUG has sent spearphishing emails impersonating Ukrainian government officials. |
| T1685.005 Clear Windows Event Logs |
GroupAPT28 | APT28 has cleared event logs, including by using the commands |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.