Real-world descriptions of how a group, tool or campaign used a technique.
66 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupAPT29 | APT29 has used the `reg save` command to save registry hives. |
| T1003.004 LSA Secrets |
GroupAPT29 | APT29 has used the `reg save` command to extract LSA secrets offline. |
| T1005 Data from Local System |
GroupAPT29 | APT29 has stolen data from compromised hosts. |
| T1016.001 Internet Connection Discovery |
GroupAPT29 | APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it. |
| T1021.007 Cloud Services |
GroupAPT29 | APT29 has leveraged compromised high-privileged on-premises accounts synced to Office 365 to move laterally into a cloud environment, including through the use of Azure AD PowerShell. |
| T1027.001 Binary Padding |
GroupAPT29 | APT29 used large size files to avoid detection by security solutions with hardcoded size limits. |
| T1027.002 Software Packing |
GroupAPT29 | APT29 used UPX to pack files. |
| T1027.006 HTML Smuggling |
GroupAPT29 | APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT29 | APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal. |
| T1037 Boot or Logon Initialization Scripts |
GroupAPT29 | APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup. |
| T1037.004 RC Scripts |
GroupAPT29 | APT29 has installed a run command on a compromised system to enable malware execution on system startup. |
| T1047 Windows Management Instrumentation |
GroupAPT29 | APT29 used WMI to steal credentials and execute backdoors at a future time. |
| T1053.005 Scheduled Task |
GroupAPT29 | APT29 has used named and hijacked scheduled tasks to establish persistence. |
| T1059.001 PowerShell |
GroupAPT29 | APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke. |
| T1059.006 Python |
GroupAPT29 | APT29 has developed malware variants written in Python. |
| T1059.009 Cloud API |
GroupAPT29 | APT29 has leveraged the Microsoft Graph API to perform various actions across Azure and M365 environments. They have also utilized AADInternals PowerShell Modules to access the API |
| T1068 Exploitation for Privilege Escalation |
GroupAPT29 | APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host. |
| T1070.004 File Deletion |
GroupAPT29 | APT29 has used SDelete to remove artifacts from victim networks. |
| T1070.006 Timestomp |
GroupAPT29 | APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. |
| T1078 Valid Accounts |
GroupAPT29 | APT29 has used a compromised account to access an organization's VPN infrastructure. |
| T1078.003 Local Accounts |
GroupAPT29 | APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence. |
| T1078.004 Cloud Accounts |
GroupAPT29 | APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange. |
| T1087.004 Cloud Account |
GroupAPT29 | APT29 has conducted enumeration of Azure AD accounts. |
| T1090.002 External Proxy |
GroupAPT29 | APT29 uses compromised residential endpoints as proxies for defense evasion and network access. |
| T1090.003 Multi-hop Proxy |
GroupAPT29 | A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR. |
| T1090.004 Domain Fronting |
GroupAPT29 | APT29 has used the meek domain fronting plugin for Tor to hide the destination of C2 traffic. |
| T1098.002 Additional Email Delegate Permissions |
GroupAPT29 | APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails. |
| T1098.005 Device Registration |
GroupAPT29 | APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account. |
| T1105 Ingress Tool Transfer |
GroupAPT29 | APT29 has downloaded additional tools and malware onto compromised networks. |
| T1110.001 Password Guessing |
GroupAPT29 | APT29 has successfully conducted password guessing attacks against a list of mailboxes. |
| T1110.003 Password Spraying |
GroupAPT29 | APT29 has conducted brute force password spray attacks. |
| T1114.002 Remote Email Collection |
GroupAPT29 | APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests. |
| T1133 External Remote Services |
GroupAPT29 | APT29 has used compromised identities to access networks via VPNs and Citrix. |
| T1136.003 Cloud Account |
GroupAPT29 | APT29 can create new users through Azure AD. |
| T1190 Exploit Public-Facing Application |
GroupAPT29 | APT29 has exploited CVE-2019-19781 for Citrix, CVE-2019-11510 for Pulse Secure VPNs, CVE-2018-13379 for FortiGate VPNs, and CVE-2019-9670 in Zimbra software to gain access. |
| T1199 Trusted Relationship |
GroupAPT29 | APT29 has compromised IT, cloud services, and managed services providers to gain broad access to multiple customers for subsequent operations. |
| T1203 Exploitation for Client Execution |
GroupAPT29 | APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution. |
| T1204.001 Malicious Link |
GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to click on a malicious link. |
| T1204.002 Malicious File |
GroupAPT29 | APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files. |
| T1218.005 Mshta |
GroupAPT29 | APT29 has use `mshta` to execute malicious scripts on a compromised host. |
| T1505.003 Web Shell |
GroupAPT29 | APT29 has installed web shells on exploited Microsoft Exchange servers. |
| T1528 Steal Application Access Token |
GroupAPT29 | APT29 uses stolen tokens to access victim accounts, without needing a password. |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupAPT29 | APT29 has used WMI event subscriptions for persistence. |
| T1546.008 Accessibility Features |
GroupAPT29 | APT29 used sticky-keys to obtain unauthenticated, privileged console access. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupAPT29 | APT29 added Registry Run keys to establish persistence. |
| T1548.002 Bypass User Account Control |
GroupAPT29 | APT29 has bypassed UAC. |
| T1550.003 Pass the Ticket |
GroupAPT29 | APT29 used Kerberos ticket attacks for lateral movement. |
| T1553.005 Mark-of-the-Web Bypass |
GroupAPT29 | APT29 has embedded ISO images and VHDX files in HTML to evade Mark-of-the-Web. |
| T1556.007 Hybrid Identity |
GroupAPT29 | APT29 has edited the `Microsoft.IdentityServer.Servicehost.exe.config` file to load a malicious DLL into the AD FS process, thereby enabling persistent access to any service federated with AD FS for a user with a specified User Principal Name. |
| T1566.001 Spearphishing Attachment |
GroupAPT29 | APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.