ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0022×

44 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT3

APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig."

T1005
Data from Local System
GroupAPT3

APT3 will identify Microsoft Office documents on the victim's computer.

T1016
System Network Configuration Discovery
GroupAPT3

A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway.

T1018
Remote System Discovery
GroupAPT3

APT3 has a tool that can detect the existence of remote systems.

T1021.001
Remote Desktop Protocol
GroupAPT3

APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions.

T1021.002
SMB/Windows Admin Shares
GroupAPT3

APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement.

T1027
Obfuscated Files or Information
GroupAPT3

APT3 obfuscates files or information to help evade defensive measures.

T1027.002
Software Packing
GroupAPT3

APT3 has been known to pack their tools.

T1027.005
Indicator Removal from Tools
GroupAPT3

APT3 has been known to remove indicators of compromise from tools.

T1033
System Owner/User Discovery
GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami to verify that it is running with the elevated privileges of “System.”

T1036.010
Masquerade Account Name
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

T1041
Exfiltration Over C2 Channel
GroupAPT3

APT3 has a tool that exfiltrates data over the C2 channel.

T1049
System Network Connections Discovery
GroupAPT3

APT3 has a tool that can enumerate current network connections.

T1053.005
Scheduled Task
GroupAPT3

An APT3 downloader creates persistence by creating the following scheduled task: schtasks /create /tn "mysc" /tr C:\Users\Public\test.exe /sc ONLOGON /ru "System".

T1056.001
Keylogging
GroupAPT3

APT3 has used a keylogging tool that records keystrokes in encrypted files.

T1057
Process Discovery
GroupAPT3

APT3 has a tool that can list out currently running processes.

T1059.001
PowerShell
GroupAPT3

APT3 has used PowerShell on victim systems to download and run payloads after exploitation.

T1059.003
Windows Command Shell
GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami. The group also uses a tool to execute commands on remote computers.

T1069
Permission Groups Discovery
GroupAPT3

APT3 has a tool that can enumerate the permissions associated with Windows groups.

T1070.004
File Deletion
GroupAPT3

APT3 has a tool that can delete files.

T1074.001
Local Data Staging
GroupAPT3

APT3 has been known to stage files for exfiltration in a single location.

T1078.002
Domain Accounts
GroupAPT3

APT3 leverages valid accounts after gaining credentials for use within the victim domain.

T1082
System Information Discovery
GroupAPT3

APT3 has a tool that can obtain information about the local system.

T1083
File and Directory Discovery
GroupAPT3

APT3 has a tool that looks for files and directories on the local file system.

T1087.001
Local Account
GroupAPT3

APT3 has used a tool that can obtain info about local and global group users, power users, and administrators.

T1090.002
External Proxy
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

T1095
Non-Application Layer Protocol
GroupAPT3

An APT3 downloader establishes SOCKS5 connections for its initial C2.

T1098.007
Additional Local or Domain Groups
GroupAPT3

APT3 has been known to add created accounts to local admin groups to maintain elevated access.

T1104
Multi-Stage Channels
GroupAPT3

An APT3 downloader first establishes a SOCKS5 connection to 192.157.198[.]103 using TCP port 1913; once the server response is verified, it then requests a connection to 192.184.60[.]229 on TCP port 81.

T1105
Ingress Tool Transfer
GroupAPT3

APT3 has a tool that can copy files to remote machines.

T1110.002
Password Cracking
GroupAPT3

APT3 has been known to brute force password hashes to be able to leverage plain text credentials.

T1136.001
Local Account
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

T1203
Exploitation for Client Execution
GroupAPT3

APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113 and Internet Explorer vulnerability CVE-2014-1776.

T1204.001
Malicious Link
GroupAPT3

APT3 has lured victims into clicking malicious links delivered through spearphishing.

T1218.011
Rundll32
GroupAPT3

APT3 has a tool that can run DLLs.

T1543.003
Windows Service
GroupAPT3

APT3 has a tool that creates a new service for persistence.

T1546.008
Accessibility Features
GroupAPT3

APT3 replaces the Sticky Keys binary C:\Windows\System32\sethc.exe for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupAPT3

APT3 places scripts in the startup folder for persistence.

T1552.001
Credentials In Files
GroupAPT3

APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome.

T1555.003
Credentials from Web Browsers
GroupAPT3

APT3 has used tools to dump passwords from browsers.

T1560.001
Archive via Utility
GroupAPT3

APT3 has used tools to compress data before exfilling it.

T1564.003
Hidden Window
GroupAPT3

APT3 has been known to use -WindowStyle Hidden to conceal PowerShell windows.

T1566.002
Spearphishing Link
GroupAPT3

APT3 has sent spearphishing emails containing malicious links.

T1574.001
DLL
GroupAPT3

APT3 has been known to side load DLLs with a valid version of Chrome with one of their tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.