ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0012×

24 examples

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupDarkhotel

Darkhotel has collected the IP address and network adapter information from the victim’s machine.

T1027.013
Encrypted/Encoded File
GroupDarkhotel

Darkhotel has obfuscated code using RC4, XOR, and RSA.

T1036.005
Match Legitimate Resource Name or Location
GroupDarkhotel

Darkhotel has used malware that is disguised as a Secure Shell (SSH) tool.

T1056.001
Keylogging
GroupDarkhotel

Darkhotel has used a keylogger.

T1057
Process Discovery
GroupDarkhotel

Darkhotel malware can collect a list of running processes on a system.

T1059.003
Windows Command Shell
GroupDarkhotel

Darkhotel has dropped an mspaint.lnk shortcut to disk which launches a shell script that downloads and executes a file.

T1080
Taint Shared Content
GroupDarkhotel

Darkhotel used a virus that propagates by infecting executables stored on shared drives.

T1082
System Information Discovery
GroupDarkhotel

Darkhotel has collected the hostname, OS version, service pack version, and the processor architecture from the victim’s machine.

T1083
File and Directory Discovery
GroupDarkhotel

Darkhotel has used malware that searched for files with specific patterns.

T1091
Replication Through Removable Media
GroupDarkhotel

Darkhotel's selective infector modifies executables stored on removable media as a method of spreading across computers.

T1105
Ingress Tool Transfer
GroupDarkhotel

Darkhotel has used first-stage payloads that download additional malware from C2 servers.

T1124
System Time Discovery
GroupDarkhotel

Darkhotel malware can obtain system time from a compromised host.

T1140
Deobfuscate/Decode Files or Information
GroupDarkhotel

Darkhotel has decrypted strings and imports using RC4 during execution.

T1189
Drive-by Compromise
GroupDarkhotel

Darkhotel used embedded iframes on hotel login portals to redirect selected victims to download malware.

T1203
Exploitation for Client Execution
GroupDarkhotel

Darkhotel has exploited Adobe Flash vulnerability CVE-2015-8651 for execution.

T1204.002
Malicious File
GroupDarkhotel

Darkhotel has sent spearphishing emails in an attempt to lure users into clicking on a malicious attachments.

T1497
Virtualization/Sandbox Evasion
GroupDarkhotel

Darkhotel malware has employed just-in-time decryption of strings to evade sandbox detection.

T1497.001
System Checks
GroupDarkhotel

Darkhotel malware has used a series of checks to determine if it's being analyzed; checks include the length of executable names, if a filename ends with .Md5.exe, and if the program is executed from the root of the C:\ drive, as well as checks for sandbox-related libraries.

T1497.002
User Activity Based Checks
GroupDarkhotel

Darkhotel has used malware that repeatedly checks the mouse cursor position to determine if a real user is on the system.

T1518.001
Security Software Discovery
GroupDarkhotel

Darkhotel has searched for anti-malware strings and anti-virus processes running on the system.

T1547.001
Registry Run Keys / Startup Folder
GroupDarkhotel

Darkhotel has been known to establish persistence by adding programs to the Run Registry key.

T1553.002
Code Signing
GroupDarkhotel

Darkhotel has used code-signing certificates on its malware that are either forged due to weak keys or stolen. Darkhotel has also stolen certificates and signed backdoors and downloaders with them.

T1566.001
Spearphishing Attachment
GroupDarkhotel

Darkhotel has sent spearphishing emails with malicious RAR and .LNK attachments.

T1573.001
Symmetric Cryptography
GroupDarkhotel

Darkhotel has used AES-256 and 3DES for C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.