ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0016×

66 examples

TechniqueUsed byProcedure example
T1566.002
Spearphishing Link
GroupAPT29

APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files.

T1566.003
Spearphishing via Service
GroupAPT29

APT29 has used the legitimate mailing service Constant Contact to send phishing e-mails.

T1568
Dynamic Resolution
GroupAPT29

APT29 has used Dynamic DNS providers for their malware C2 infrastructure.

T1573
Encrypted Channel
GroupAPT29

APT29 has used multiple layers of encryption within malware to protect C2 communication.

T1583.006
Web Services
GroupAPT29

APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations.

T1586.002
Email Accounts
GroupAPT29

APT29 has compromised email accounts to further enable phishing campaigns and taken control of dormant accounts.

T1586.003
Cloud Accounts
GroupAPT29

APT29 has used residential proxies, including Azure Virtual Machines, to obfuscate their access to victim environments.

T1587.001
Malware
GroupAPT29

APT29 has used unique malware in many of their operations.

T1587.003
Digital Certificates
GroupAPT29

APT29 has created self-signed digital certificates to enable mutual TLS authentication for malware.

T1588.002
Tool
GroupAPT29

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

T1595.002
Vulnerability Scanning
GroupAPT29

APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit.

T1621
Multi-Factor Authentication Request Generation
GroupAPT29

APT29 has used repeated MFA requests to gain access to victim accounts.

T1649
Steal or Forge Authentication Certificates
GroupAPT29

APT29 has abused misconfigured AD CS certificate templates to impersonate admin users and create additional authentication certificates.

T1651
Cloud Administration Command
GroupAPT29

APT29 has used Azure Run Command and Azure Admin-on-Behalf-of (AOBO) to execute code on virtual machines.

T1665
Hide Infrastructure
GroupAPT29

APT29 uses compromised residential endpoints, typically within the same ISP IP address range, as proxies to hide the true source of C2 traffic.

T1685.002
Disable or Modify Cloud Log
GroupAPT29

APT29 has disabled Purview Audit on targeted accounts prior to stealing emails from Microsoft 365 tenants.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.