Real-world descriptions of how a group, tool or campaign used a technique.
68 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupTurla | Turla RPC backdoors can upload files from victim machines. |
| T1007 System Service Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running services and associated processes using the |
| T1012 Query Registry |
GroupTurla | Turla surveys a system upon check-in to discover information in the Windows Registry with the |
| T1016 System Network Configuration Discovery |
GroupTurla | Turla surveys a system upon check-in to discover network configuration details using the |
| T1016.001 Internet Connection Discovery |
GroupTurla | Turla has used |
| T1018 Remote System Discovery |
GroupTurla | Turla surveys a system upon check-in to discover remote systems on a local network using the |
| T1021.002 SMB/Windows Admin Shares |
GroupTurla | Turla used |
| T1025 Data from Removable Media |
GroupTurla | Turla RPC backdoors can collect files from USB thumb drives. |
| T1027.005 Indicator Removal from Tools |
GroupTurla | Based on comparison of Gazer versions, Turla made an effort to obfuscate strings in the malware that could be used as IoCs, including the mutex name and named pipe. |
| T1027.010 Command Obfuscation |
GroupTurla | Turla has used encryption (including salted 3DES via PowerSploit's |
| T1027.011 Fileless Storage |
GroupTurla | Turla has used the Registry to store encrypted and encoded payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTurla | Turla has named components of LunarWeb to mimic Zabbix agent logs. |
| T1049 System Network Connections Discovery |
GroupTurla | Turla surveys a system upon check-in to discover active local network connections using the |
| T1055 Process Injection |
GroupTurla | Turla has also used PowerSploit's |
| T1055.001 Dynamic-link Library Injection |
GroupTurla | Turla has used Metasploit to perform reflective DLL injection in order to escalate privileges. |
| T1057 Process Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running processes using the |
| T1059.001 PowerShell |
GroupTurla | Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory. |
| T1059.003 Windows Command Shell |
GroupTurla | Turla RPC backdoors have used cmd.exe to execute commands. |
| T1059.005 Visual Basic |
GroupTurla | Turla has used VBS scripts throughout its operations. |
| T1059.006 Python |
GroupTurla | Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads. |
| T1059.007 JavaScript |
GroupTurla | Turla has used various JavaScript-based backdoors. |
| T1068 Exploitation for Privilege Escalation |
GroupTurla | Turla has exploited vulnerabilities in the VBoxDrv.sys driver to obtain kernel mode privileges. |
| T1069.001 Local Groups |
GroupTurla | Turla has used |
| T1069.002 Domain Groups |
GroupTurla | Turla has used |
| T1071.001 Web Protocols |
GroupTurla | Turla has used HTTP and HTTPS for C2 communications. |
| T1071.003 Mail Protocols |
GroupTurla | Turla has used multiple backdoors which communicate with a C2 server via email attachments. |
| T1078.003 Local Accounts |
GroupTurla | Turla has abused local accounts that have the same password across the victim’s network. |
| T1082 System Information Discovery |
GroupTurla | Turla surveys a system upon check-in to discover operating system configuration details using the |
| T1083 File and Directory Discovery |
GroupTurla | Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the |
| T1087.001 Local Account |
GroupTurla | Turla has used |
| T1087.002 Domain Account |
GroupTurla | Turla has used |
| T1090 Proxy |
GroupTurla | Turla RPC backdoors have included local UPnP RPC proxies. |
| T1090.001 Internal Proxy |
GroupTurla | Turla has compromised internal network systems to act as a proxy to forward traffic to C2. |
| T1102 Web Service |
GroupTurla | Turla has used legitimate web services including Pastebin, Dropbox, and GitHub for C2 communications. |
| T1102.002 Bidirectional Communication |
GroupTurla | A Turla JavaScript backdoor has used Google Apps Script as its C2 server. |
| T1105 Ingress Tool Transfer |
GroupTurla | Turla has used shellcode to download Meterpreter after compromising a victim. |
| T1106 Native API |
GroupTurla | Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes. |
| T1110 Brute Force |
GroupTurla | Turla may attempt to connect to systems within a victim's network using |
| T1112 Modify Registry |
GroupTurla | Turla has modified Registry values to store payloads. |
| T1120 Peripheral Device Discovery |
GroupTurla | Turla has used |
| T1124 System Time Discovery |
GroupTurla | Turla surveys a system upon check-in to discover the system time by using the |
| T1134.002 Create Process with Token |
GroupTurla | Turla RPC backdoors can impersonate or steal process tokens before executing commands. |
| T1140 Deobfuscate/Decode Files or Information |
GroupTurla | Turla has used a custom decryption routine, which pulls key and salt values from other artifacts such as a WMI filter or PowerShell Profile, to decode encrypted PowerShell payloads. |
| T1189 Drive-by Compromise |
GroupTurla | Turla has infected victims using watering holes. |
| T1201 Password Policy Discovery |
GroupTurla | Turla has used |
| T1204.001 Malicious Link |
GroupTurla | Turla has used spearphishing via a link to get users to download and run their malware. |
| T1213.006 Databases |
GroupTurla | Turla has used a custom .NET tool to collect documents from an organization's internal central database. |
| T1518.001 Security Software Discovery |
GroupTurla | Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupTurla | Turla has used WMI event filters and consumers to establish persistence. |
| T1546.013 PowerShell Profile |
GroupTurla | Turla has used PowerShell profiles to maintain persistence on an infected machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.