Real-world descriptions of how a group, tool or campaign used a technique.
57 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupThreat Group-3390 | Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.002 Security Account Manager |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.004 LSA Secrets |
GroupThreat Group-3390 | Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1005 Data from Local System |
GroupThreat Group-3390 | Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
| T1012 Query Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool can read and decrypt stored Registry values. |
| T1016 System Network Configuration Discovery |
GroupThreat Group-3390 | Threat Group-3390 actors use NBTscan to discover vulnerable systems. |
| T1018 Remote System Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used the |
| T1021.006 Windows Remote Management |
GroupThreat Group-3390 | Threat Group-3390 has used WinRM to enable remote execution. |
| T1027.002 Software Packing |
GroupThreat Group-3390 | Threat Group-3390 has packed malware and tools, including using VMProtect. |
| T1027.013 Encrypted/Encoded File |
GroupThreat Group-3390 | A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder. |
| T1027.015 Compression |
GroupThreat Group-3390 | Threat Group-3390 malware is compressed with LZNT1 compression. |
| T1030 Data Transfer Size Limits |
GroupThreat Group-3390 | Threat Group-3390 actors have split RAR files for exfiltration into parts. |
| T1033 System Owner/User Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used `whoami` to collect system user information. |
| T1046 Network Service Discovery |
GroupThreat Group-3390 | Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems. |
| T1047 Windows Management Instrumentation |
GroupThreat Group-3390 | A Threat Group-3390 tool can use WMI to execute a binary. |
| T1049 System Network Connections Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used `net use` and `netstat` to conduct internal discovery of systems. The group has also used `quser.exe` to identify existing RDP sessions on a victim. |
| T1053.002 At |
GroupThreat Group-3390 | Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network. |
| T1055.012 Process Hollowing |
GroupThreat Group-3390 | A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process. |
| T1056.001 Keylogging |
GroupThreat Group-3390 | Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes. |
| T1059.001 PowerShell |
GroupThreat Group-3390 | Threat Group-3390 has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
GroupThreat Group-3390 | Threat Group-3390 has used command-line interfaces for execution. |
| T1068 Exploitation for Privilege Escalation |
GroupThreat Group-3390 | Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges. |
| T1070.004 File Deletion |
GroupThreat Group-3390 | Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim. |
| T1070.005 Network Share Connection Removal |
GroupThreat Group-3390 | Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection. |
| T1071.001 Web Protocols |
GroupThreat Group-3390 | Threat Group-3390 malware has used HTTP for C2. |
| T1074.001 Local Data Staging |
GroupThreat Group-3390 | Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts. |
| T1074.002 Remote Data Staging |
GroupThreat Group-3390 | Threat Group-3390 has moved staged encrypted archives to Internet-facing servers that had previously been compromised with China Chopper prior to exfiltration. |
| T1078 Valid Accounts |
GroupThreat Group-3390 | Threat Group-3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks. |
| T1087.001 Local Account |
GroupThreat Group-3390 | Threat Group-3390 has used |
| T1105 Ingress Tool Transfer |
GroupThreat Group-3390 | Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host . |
| T1112 Modify Registry |
GroupThreat Group-3390 | A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`. |
| T1119 Automated Collection |
GroupThreat Group-3390 | Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
| T1133 External Remote Services |
GroupThreat Group-3390 | Threat Group-3390 actors look for and use VPN profiles during an operation to access the network using external VPN services. Threat Group-3390 has also obtained OWA account credentials during intrusions that it subsequently used to attempt to regain access when evicted from a victim network. |
| T1140 Deobfuscate/Decode Files or Information |
GroupThreat Group-3390 | During execution, Threat Group-3390 malware deobfuscates and decompresses code that was encoded with Metasploit’s shikata_ga_nai encoder as well as compressed with LZNT1 compression. |
| T1189 Drive-by Compromise |
GroupThreat Group-3390 | Threat Group-3390 has extensively used strategic web compromises to target victims. |
| T1190 Exploit Public-Facing Application |
GroupThreat Group-3390 | Threat Group-3390 has exploited the Microsoft SharePoint vulnerability CVE-2019-0604 and CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in Exchange Server. |
| T1195.002 Compromise Software Supply Chain |
GroupThreat Group-3390 | Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments. |
| T1199 Trusted Relationship |
GroupThreat Group-3390 | Threat Group-3390 has compromised third party service providers to gain access to victim's environments. |
| T1203 Exploitation for Client Execution |
GroupThreat Group-3390 | Threat Group-3390 has exploited CVE-2018-0798 in Equation Editor. |
| T1204.002 Malicious File |
GroupThreat Group-3390 | Threat Group-3390 has lured victims into opening malicious files containing malware. |
| T1210 Exploitation of Remote Services |
GroupThreat Group-3390 | Threat Group-3390 has exploited MS17-010 to move laterally to other systems on the network. |
| T1505.003 Web Shell |
GroupThreat Group-3390 | Threat Group-3390 has used a variety of Web shells. |
| T1543.003 Windows Service |
GroupThreat Group-3390 | Threat Group-3390's malware can create a new service, sometimes naming it after the config information, to gain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupThreat Group-3390 | Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence. |
| T1548.002 Bypass User Account Control |
GroupThreat Group-3390 | A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges. |
| T1555.005 Password Managers |
GroupThreat Group-3390 | Threat Group-3390 obtained a KeePass database from a compromised host. |
| T1560.002 Archive via Library |
GroupThreat Group-3390 | Threat Group-3390 has used RAR to compress, encrypt, and password-protect files prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupThreat Group-3390 | Threat Group-3390 has used e-mail to deliver malicious attachments to victims. |
| T1567.002 Exfiltration to Cloud Storage |
GroupThreat Group-3390 | Threat Group-3390 has exfiltrated stolen data to Dropbox. |
| T1574.001 DLL |
GroupThreat Group-3390 | Threat Group-3390 has performed DLL search order hijacking to execute their payload. Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.