ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0027×

57 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupThreat Group-3390

Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers.

T1003.002
Security Account Manager
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.004
LSA Secrets
GroupThreat Group-3390

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1005
Data from Local System
GroupThreat Group-3390

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1012
Query Registry
GroupThreat Group-3390

A Threat Group-3390 tool can read and decrypt stored Registry values.

T1016
System Network Configuration Discovery
GroupThreat Group-3390

Threat Group-3390 actors use NBTscan to discover vulnerable systems.

T1018
Remote System Discovery
GroupThreat Group-3390

Threat Group-3390 has used the net view command.

T1021.006
Windows Remote Management
GroupThreat Group-3390

Threat Group-3390 has used WinRM to enable remote execution.

T1027.002
Software Packing
GroupThreat Group-3390

Threat Group-3390 has packed malware and tools, including using VMProtect.

T1027.013
Encrypted/Encoded File
GroupThreat Group-3390

A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.

T1027.015
Compression
GroupThreat Group-3390

Threat Group-3390 malware is compressed with LZNT1 compression.

T1030
Data Transfer Size Limits
GroupThreat Group-3390

Threat Group-3390 actors have split RAR files for exfiltration into parts.

T1033
System Owner/User Discovery
GroupThreat Group-3390

Threat Group-3390 has used `whoami` to collect system user information.

T1046
Network Service Discovery
GroupThreat Group-3390

Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems.

T1047
Windows Management Instrumentation
GroupThreat Group-3390

A Threat Group-3390 tool can use WMI to execute a binary.

T1049
System Network Connections Discovery
GroupThreat Group-3390

Threat Group-3390 has used `net use` and `netstat` to conduct internal discovery of systems. The group has also used `quser.exe` to identify existing RDP sessions on a victim.

T1053.002
At
GroupThreat Group-3390

Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network.

T1055.012
Process Hollowing
GroupThreat Group-3390

A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process.

T1056.001
Keylogging
GroupThreat Group-3390

Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes.

T1059.001
PowerShell
GroupThreat Group-3390

Threat Group-3390 has used PowerShell for execution.

T1059.003
Windows Command Shell
GroupThreat Group-3390

Threat Group-3390 has used command-line interfaces for execution.

T1068
Exploitation for Privilege Escalation
GroupThreat Group-3390

Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges.

T1070.004
File Deletion
GroupThreat Group-3390

Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim.

T1070.005
Network Share Connection Removal
GroupThreat Group-3390

Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection.

T1071.001
Web Protocols
GroupThreat Group-3390

Threat Group-3390 malware has used HTTP for C2.

T1074.001
Local Data Staging
GroupThreat Group-3390

Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts.

T1074.002
Remote Data Staging
GroupThreat Group-3390

Threat Group-3390 has moved staged encrypted archives to Internet-facing servers that had previously been compromised with China Chopper prior to exfiltration.

T1078
Valid Accounts
GroupThreat Group-3390

Threat Group-3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks.

T1087.001
Local Account
GroupThreat Group-3390

Threat Group-3390 has used net user to conduct internal discovery of systems.

T1105
Ingress Tool Transfer
GroupThreat Group-3390

Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host .

T1112
Modify Registry
GroupThreat Group-3390

A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`.

T1119
Automated Collection
GroupThreat Group-3390

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1133
External Remote Services
GroupThreat Group-3390

Threat Group-3390 actors look for and use VPN profiles during an operation to access the network using external VPN services. Threat Group-3390 has also obtained OWA account credentials during intrusions that it subsequently used to attempt to regain access when evicted from a victim network.

T1140
Deobfuscate/Decode Files or Information
GroupThreat Group-3390

During execution, Threat Group-3390 malware deobfuscates and decompresses code that was encoded with Metasploit’s shikata_ga_nai encoder as well as compressed with LZNT1 compression.

T1189
Drive-by Compromise
GroupThreat Group-3390

Threat Group-3390 has extensively used strategic web compromises to target victims.

T1190
Exploit Public-Facing Application
GroupThreat Group-3390

Threat Group-3390 has exploited the Microsoft SharePoint vulnerability CVE-2019-0604 and CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in Exchange Server.

T1195.002
Compromise Software Supply Chain
GroupThreat Group-3390

Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments.

T1199
Trusted Relationship
GroupThreat Group-3390

Threat Group-3390 has compromised third party service providers to gain access to victim's environments.

T1203
Exploitation for Client Execution
GroupThreat Group-3390

Threat Group-3390 has exploited CVE-2018-0798 in Equation Editor.

T1204.002
Malicious File
GroupThreat Group-3390

Threat Group-3390 has lured victims into opening malicious files containing malware.

T1210
Exploitation of Remote Services
GroupThreat Group-3390

Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network.

T1505.003
Web Shell
GroupThreat Group-3390

Threat Group-3390 has used a variety of Web shells.

T1543.003
Windows Service
GroupThreat Group-3390

Threat Group-3390's malware can create a new service, sometimes naming it after the config information, to gain persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupThreat Group-3390

Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence.

T1548.002
Bypass User Account Control
GroupThreat Group-3390

A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges.

T1555.005
Password Managers
GroupThreat Group-3390

Threat Group-3390 obtained a KeePass database from a compromised host.

T1560.002
Archive via Library
GroupThreat Group-3390

Threat Group-3390 has used RAR to compress, encrypt, and password-protect files prior to exfiltration.

T1566.001
Spearphishing Attachment
GroupThreat Group-3390

Threat Group-3390 has used e-mail to deliver malicious attachments to victims.

T1567.002
Exfiltration to Cloud Storage
GroupThreat Group-3390

Threat Group-3390 has exfiltrated stolen data to Dropbox.

T1574.001
DLL
GroupThreat Group-3390

Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.