Real-world descriptions of how a group, tool or campaign used a technique.
68 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1547.001 Registry Run Keys / Startup Folder |
GroupTurla | A Turla Javascript backdoor added a local_update_check value under the Registry key |
| T1547.004 Winlogon Helper DLL |
GroupTurla | Turla established persistence by adding a Shell value under the Registry key |
| T1553.006 Code Signing Policy Modification |
GroupTurla | Turla has modified variables in kernel memory to turn off Driver Signature Enforcement after exploiting vulnerabilities that obtained kernel mode privileges. |
| T1555.004 Windows Credential Manager |
GroupTurla | Turla has gathered credentials from the Windows Credential Manager tool. |
| T1560.001 Archive via Utility |
GroupTurla | Turla has encrypted files stolen from connected USB drives into a RAR file before exfiltration. |
| T1564.012 File/Path Exclusions |
GroupTurla | Turla has placed LunarWeb install files into directories that are excluded from scanning. |
| T1566.002 Spearphishing Link |
GroupTurla | Turla attempted to trick targets into clicking on a link featuring a seemingly legitimate domain from Adobe.com to download their malware and gain initial access. |
| T1567.002 Exfiltration to Cloud Storage |
GroupTurla | Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared. |
| T1570 Lateral Tool Transfer |
GroupTurla | Turla RPC backdoors can be used to transfer files to/from victim machines on the local network. |
| T1583.006 Web Services |
GroupTurla | Turla has created web accounts including Dropbox and GitHub for C2 and document exfiltration. |
| T1584.003 Virtual Private Server |
GroupTurla | Turla has used the VPS infrastructure of compromised Iranian threat actors. |
| T1584.004 Server |
GroupTurla | Turla has used compromised servers as infrastructure. |
| T1584.006 Web Services |
GroupTurla | Turla has frequently used compromised WordPress sites for C2 infrastructure. |
| T1587.001 Malware |
GroupTurla | Turla has developed its own unique malware for use in operations. |
| T1588.001 Malware |
GroupTurla | Turla has used malware obtained after compromising other threat actors, such as OilRig. |
| T1588.002 Tool |
GroupTurla | Turla has obtained and customized publicly-available tools like Mimikatz. |
| T1615 Group Policy Discovery |
GroupTurla | Turla surveys a system upon check-in to discover Group Policy details using the |
| T1685 Disable or Modify Tools |
GroupTurla | Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.