ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0021×

16 examples

TechniqueUsed byProcedure example
T1027.015
Compression
GroupMolerats

Molerats has delivered compressed executables within ZIP files to victims.

T1053.005
Scheduled Task
GroupMolerats

Molerats has created scheduled tasks to persistently run VBScripts.

T1057
Process Discovery
GroupMolerats

Molerats actors obtained a list of active processes on the victim and sent them to C2 servers.

T1059.001
PowerShell
GroupMolerats

Molerats used PowerShell implants on target machines.

T1059.005
Visual Basic
GroupMolerats

Molerats used various implants, including those built with VBScript, on target machines.

T1059.007
JavaScript
GroupMolerats

Molerats used various implants, including those built with JS, on target machines.

T1105
Ingress Tool Transfer
GroupMolerats

Molerats used executables to download malicious files from different sources.

T1140
Deobfuscate/Decode Files or Information
GroupMolerats

Molerats decompresses ZIP files once on the victim machine.

T1204.001
Malicious Link
GroupMolerats

Molerats has sent malicious links via email trick users into opening a RAR archive and running an executable.

T1204.002
Malicious File
GroupMolerats

Molerats has sent malicious files via email that tricked users into clicking Enable Content to run an embedded macro and to download malicious archives.

T1218.007
Msiexec
GroupMolerats

Molerats has used msiexec.exe to execute an MSI payload.

T1547.001
Registry Run Keys / Startup Folder
GroupMolerats

Molerats saved malicious files within the AppData and Startup folders to maintain persistence.

T1553.002
Code Signing
GroupMolerats

Molerats has used forged Microsoft code-signing certificates on malware.

T1555.003
Credentials from Web Browsers
GroupMolerats

Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims.

T1566.001
Spearphishing Attachment
GroupMolerats

Molerats has sent phishing emails with malicious Microsoft Word and PDF attachments.

T1566.002
Spearphishing Link
GroupMolerats

Molerats has sent phishing emails with malicious links included.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.