ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0016×

66 examples

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
GroupAPT29

APT29 has used the `reg save` command to save registry hives.

T1003.004
LSA Secrets
GroupAPT29

APT29 has used the `reg save` command to extract LSA secrets offline.

T1005
Data from Local System
GroupAPT29

APT29 has stolen data from compromised hosts.

T1016.001
Internet Connection Discovery
GroupAPT29

APT29 has ensured web servers in a victim environment are Internet accessible before copying tools or malware to it.

T1021.007
Cloud Services
GroupAPT29

APT29 has leveraged compromised high-privileged on-premises accounts synced to Office 365 to move laterally into a cloud environment, including through the use of Azure AD PowerShell.

T1027.001
Binary Padding
GroupAPT29

APT29 used large size files to avoid detection by security solutions with hardcoded size limits.

T1027.002
Software Packing
GroupAPT29

APT29 used UPX to pack files.

T1027.006
HTML Smuggling
GroupAPT29

APT29 has embedded an ISO file within an HTML attachment that contained JavaScript code to initiate malware execution.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT29

APT29 has renamed malicious DLLs with legitimate names to appear benign; they have also created an Azure AD certificate with a Common Name that matched the display name of the compromised service principal.

T1037
Boot or Logon Initialization Scripts
GroupAPT29

APT29 has hijacked legitimate application-specific startup scripts to enable malware to execute on system startup.

T1037.004
RC Scripts
GroupAPT29

APT29 has installed a run command on a compromised system to enable malware execution on system startup.

T1047
Windows Management Instrumentation
GroupAPT29

APT29 used WMI to steal credentials and execute backdoors at a future time.

T1053.005
Scheduled Task
GroupAPT29

APT29 has used named and hijacked scheduled tasks to establish persistence.

T1059.001
PowerShell
GroupAPT29

APT29 has used encoded PowerShell scripts uploaded to CozyCar installations to download and install SeaDuke.

T1059.006
Python
GroupAPT29

APT29 has developed malware variants written in Python.

T1059.009
Cloud API
GroupAPT29

APT29 has leveraged the Microsoft Graph API to perform various actions across Azure and M365 environments. They have also utilized AADInternals PowerShell Modules to access the API

T1068
Exploitation for Privilege Escalation
GroupAPT29

APT29 has exploited CVE-2021-36934 to escalate privileges on a compromised host.

T1070.004
File Deletion
GroupAPT29

APT29 has used SDelete to remove artifacts from victim networks.

T1070.006
Timestomp
GroupAPT29

APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory.

T1078
Valid Accounts
GroupAPT29

APT29 has used a compromised account to access an organization's VPN infrastructure.

T1078.003
Local Accounts
GroupAPT29

APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence.

T1078.004
Cloud Accounts
GroupAPT29

APT29 has gained access to a global administrator account in Azure AD and has used `Service Principal` credentials in Exchange.

T1087.004
Cloud Account
GroupAPT29

APT29 has conducted enumeration of Azure AD accounts.

T1090.002
External Proxy
GroupAPT29

APT29 uses compromised residential endpoints as proxies for defense evasion and network access.

T1090.003
Multi-hop Proxy
GroupAPT29

A backdoor used by APT29 created a Tor hidden service to forward traffic from the Tor client to local ports 3389 (RDP), 139 (Netbios), and 445 (SMB) enabling full remote access from outside the network and has also used TOR.

T1090.004
Domain Fronting
GroupAPT29

APT29 has used the meek domain fronting plugin for Tor to hide the destination of C2 traffic.

T1098.002
Additional Email Delegate Permissions
GroupAPT29

APT29 has used a compromised global administrator account in Azure AD to backdoor a service principal with `ApplicationImpersonation` rights to start collecting emails from targeted mailboxes; APT29 has also used compromised accounts holding `ApplicationImpersonation` rights in Exchange to collect emails.

T1098.005
Device Registration
GroupAPT29

APT29 has enrolled their own devices into compromised cloud tenants, including enrolling a device in MFA to an Azure AD environment following a successful password guessing attack against a dormant account.

T1105
Ingress Tool Transfer
GroupAPT29

APT29 has downloaded additional tools and malware onto compromised networks.

T1110.001
Password Guessing
GroupAPT29

APT29 has successfully conducted password guessing attacks against a list of mailboxes.

T1110.003
Password Spraying
GroupAPT29

APT29 has conducted brute force password spray attacks.

T1114.002
Remote Email Collection
GroupAPT29

APT29 has collected emails from targeted mailboxes within a compromised Azure AD tenant and compromised Exchange servers, including via Exchange Web Services (EWS) API requests.

T1133
External Remote Services
GroupAPT29

APT29 has used compromised identities to access networks via VPNs and Citrix.

T1136.003
Cloud Account
GroupAPT29

APT29 can create new users through Azure AD.

T1190
Exploit Public-Facing Application
GroupAPT29

APT29 has exploited CVE-2019-19781 for Citrix, CVE-2019-11510 for Pulse Secure VPNs, CVE-2018-13379 for FortiGate VPNs, and CVE-2019-9670 in Zimbra software to gain access.

T1199
Trusted Relationship
GroupAPT29

APT29 has compromised IT, cloud services, and managed services providers to gain broad access to multiple customers for subsequent operations.

T1203
Exploitation for Client Execution
GroupAPT29

APT29 has used multiple software exploits for common client software, like Microsoft Word, Exchange, and Adobe Reader, to gain code execution.

T1204.001
Malicious Link
GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to click on a malicious link.

T1204.002
Malicious File
GroupAPT29

APT29 has used various forms of spearphishing attempting to get a user to open attachments, including, but not limited to, malicious Microsoft Word documents, .pdf, and .lnk files.

T1218.005
Mshta
GroupAPT29

APT29 has use `mshta` to execute malicious scripts on a compromised host.

T1505.003
Web Shell
GroupAPT29

APT29 has installed web shells on exploited Microsoft Exchange servers.

T1528
Steal Application Access Token
GroupAPT29

APT29 uses stolen tokens to access victim accounts, without needing a password.

T1546.003
Windows Management Instrumentation Event Subscription
GroupAPT29

APT29 has used WMI event subscriptions for persistence.

T1546.008
Accessibility Features
GroupAPT29

APT29 used sticky-keys to obtain unauthenticated, privileged console access.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT29

APT29 added Registry Run keys to establish persistence.

T1548.002
Bypass User Account Control
GroupAPT29

APT29 has bypassed UAC.

T1550.003
Pass the Ticket
GroupAPT29

APT29 used Kerberos ticket attacks for lateral movement.

T1553.005
Mark-of-the-Web Bypass
GroupAPT29

APT29 has embedded ISO images and VHDX files in HTML to evade Mark-of-the-Web.

T1556.007
Hybrid Identity
GroupAPT29

APT29 has edited the `Microsoft.IdentityServer.Servicehost.exe.config` file to load a malicious DLL into the AD FS process, thereby enabling persistent access to any service federated with AD FS for a user with a specified User Principal Name.

T1566.001
Spearphishing Attachment
GroupAPT29

APT29 has used spearphishing emails with an attachment to deliver files with exploits to initial victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.