ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0010×

68 examples

TechniqueUsed byProcedure example
T1547.001
Registry Run Keys / Startup Folder
GroupTurla

A Turla Javascript backdoor added a local_update_check value under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence. Additionally, a Turla custom executable containing Metasploit shellcode is saved to the Startup folder to gain persistence.

T1547.004
Winlogon Helper DLL
GroupTurla

Turla established persistence by adding a Shell value under the Registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon.

T1553.006
Code Signing Policy Modification
GroupTurla

Turla has modified variables in kernel memory to turn off Driver Signature Enforcement after exploiting vulnerabilities that obtained kernel mode privileges.

T1555.004
Windows Credential Manager
GroupTurla

Turla has gathered credentials from the Windows Credential Manager tool.

T1560.001
Archive via Utility
GroupTurla

Turla has encrypted files stolen from connected USB drives into a RAR file before exfiltration.

T1564.012
File/Path Exclusions
GroupTurla

Turla has placed LunarWeb install files into directories that are excluded from scanning.

T1566.002
Spearphishing Link
GroupTurla

Turla attempted to trick targets into clicking on a link featuring a seemingly legitimate domain from Adobe.com to download their malware and gain initial access.

T1567.002
Exfiltration to Cloud Storage
GroupTurla

Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared.

T1570
Lateral Tool Transfer
GroupTurla

Turla RPC backdoors can be used to transfer files to/from victim machines on the local network.

T1583.006
Web Services
GroupTurla

Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration.

T1584.003
Virtual Private Server
GroupTurla

Turla has used the VPS infrastructure of compromised Iranian threat actors.

T1584.004
Server
GroupTurla

Turla has used compromised servers as infrastructure.

T1584.006
Web Services
GroupTurla

Turla has frequently used compromised WordPress sites for C2 infrastructure.

T1587.001
Malware
GroupTurla

Turla has developed its own unique malware for use in operations.

T1588.001
Malware
GroupTurla

Turla has used malware obtained after compromising other threat actors, such as OilRig.

T1588.002
Tool
GroupTurla

Turla has obtained and customized publicly-available tools like Mimikatz.

T1615
Group Policy Discovery
GroupTurla

Turla surveys a system upon check-in to discover Group Policy details using the gpresult command.

T1685
Disable or Modify Tools
GroupTurla

Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.