ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0027×

57 examples

TechniqueUsed byProcedure example
T1583.001
Domains
GroupThreat Group-3390

Threat Group-3390 has registered domains for C2.

T1588.002
Tool
GroupThreat Group-3390

Threat Group-3390 has obtained and used tools such as Impacket, pwdump, Mimikatz, gsecdump, NBTscan, and Windows Credential Editor.

T1588.003
Code Signing Certificates
GroupThreat Group-3390

Threat Group-3390 has obtained stolen valid certificates, including from VMProtect and the Chinese instant messaging application Youdu, for their operations.

T1608.001
Upload Malware
GroupThreat Group-3390

Threat Group-3390 has hosted malicious payloads on Dropbox.

T1608.002
Upload Tool
GroupThreat Group-3390

Threat Group-3390 has staged tools, including gsecdump and WCE, on previously compromised websites.

T1608.004
Drive-by Target
GroupThreat Group-3390

Threat Group-3390 has embedded malicious code into websites to screen a potential victim's IP address and then exploit their browser if they are of interest.

T1685.001
Disable or Modify Windows Event Log
GroupThreat Group-3390

Threat Group-3390 has used appcmd.exe to disable logging on a victim server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.