Real-world descriptions of how a group, tool or campaign used a technique.
66 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1566.002 Spearphishing Link |
GroupAPT29 | APT29 has used spearphishing with a link to trick victims into clicking on a link to a zip file containing malicious files. |
| T1566.003 Spearphishing via Service |
GroupAPT29 | APT29 has used the legitimate mailing service Constant Contact to send phishing e-mails. |
| T1568 Dynamic Resolution |
GroupAPT29 | APT29 has used Dynamic DNS providers for their malware C2 infrastructure. |
| T1573 Encrypted Channel |
GroupAPT29 | APT29 has used multiple layers of encryption within malware to protect C2 communication. |
| T1583.006 Web Services |
GroupAPT29 | APT29 has registered algorithmically generated Twitter handles that are used for C2 by malware, such as HAMMERTOSS. APT29 has also used legitimate web services such as Dropbox and Constant Contact in their operations. |
| T1586.002 Email Accounts |
GroupAPT29 | APT29 has compromised email accounts to further enable phishing campaigns and taken control of dormant accounts. |
| T1586.003 Cloud Accounts |
GroupAPT29 | APT29 has used residential proxies, including Azure Virtual Machines, to obfuscate their access to victim environments. |
| T1587.001 Malware |
GroupAPT29 | APT29 has used unique malware in many of their operations. |
| T1587.003 Digital Certificates |
GroupAPT29 | APT29 has created self-signed digital certificates to enable mutual TLS authentication for malware. |
| T1588.002 Tool |
GroupAPT29 | APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike. |
| T1595.002 Vulnerability Scanning |
GroupAPT29 | APT29 has conducted widespread scanning of target environments to identify vulnerabilities for exploit. |
| T1621 Multi-Factor Authentication Request Generation |
GroupAPT29 | APT29 has used repeated MFA requests to gain access to victim accounts. |
| T1649 Steal or Forge Authentication Certificates |
GroupAPT29 | APT29 has abused misconfigured AD CS certificate templates to impersonate admin users and create additional authentication certificates. |
| T1651 Cloud Administration Command |
GroupAPT29 | APT29 has used Azure Run Command and Azure Admin-on-Behalf-of (AOBO) to execute code on virtual machines. |
| T1665 Hide Infrastructure |
GroupAPT29 | APT29 uses compromised residential endpoints, typically within the same ISP IP address range, as proxies to hide the true source of C2 traffic. |
| T1685.002 Disable or Modify Cloud Log |
GroupAPT29 | APT29 has disabled Purview Audit on targeted accounts prior to stealing emails from Microsoft 365 tenants. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.