ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0032×

93 examples

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
GroupLazarus Group

Lazarus Group malware also uses a unique form of communication encryption known as FakeTLS that mimics TLS but uses a different encryption method, potentially evading SSL traffic inspection/decryption.

T1005
Data from Local System
GroupLazarus Group

Lazarus Group has collected data and files from compromised networks.

T1008
Fallback Channels
GroupLazarus Group

Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again.

T1010
Application Window Discovery
GroupLazarus Group

Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground.

T1012
Query Registry
GroupLazarus Group

Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key:HKEY_CURRENT_USER\Software\Bitcoin\Bitcoin-Qt.

T1016
System Network Configuration Discovery
GroupLazarus Group

Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available.

T1021.001
Remote Desktop Protocol
GroupLazarus Group

Lazarus Group malware SierraCharlie uses RDP for propagation.

T1021.002
SMB/Windows Admin Shares
GroupLazarus Group

Lazarus Group malware SierraAlfa accesses the ADMIN$ share via SMB to conduct lateral movement.

T1021.004
SSH
GroupLazarus Group

Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network.

T1027.007
Dynamic API Resolution
GroupLazarus Group

Lazarus Group has used a custom hashing method to resolve APIs used in shellcode.

T1027.009
Embedded Payloads
GroupLazarus Group

Lazarus Group has distributed malicious payloads embedded in PNG files.

T1027.013
Encrypted/Encoded File
GroupLazarus Group

Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names.

T1033
System Owner/User Discovery
GroupLazarus Group

Various Lazarus Group malware enumerates logged-on users.

T1036.003
Rename Legitimate Utilities
GroupLazarus Group

Lazarus Group has renamed system utilities such as wscript.exe and mshta.exe.

T1036.004
Masquerade Task or Service
GroupLazarus Group

Lazarus Group has used a scheduled task named `SRCheck` to mask the execution of a malicious .dll.

T1036.005
Match Legitimate Resource Name or Location
GroupLazarus Group

Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files.

T1041
Exfiltration Over C2 Channel
GroupLazarus Group

Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware.

T1046
Network Service Discovery
GroupLazarus Group

Lazarus Group has used nmap from a router VM to scan ports on systems within the restricted segment of an enterprise network.

T1047
Windows Management Instrumentation
GroupLazarus Group

Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupLazarus Group

Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims.

T1049
System Network Connections Discovery
GroupLazarus Group

Lazarus Group has used net use to identify and establish a network connection with a remote host.

T1053.005
Scheduled Task
GroupLazarus Group

Lazarus Group has used schtasks for persistence including through the periodic execution of a remote XSL script or a dropped VBS payload.

T1055.001
Dynamic-link Library Injection
GroupLazarus Group

A Lazarus Group malware sample performs reflective DLL injection.

T1056.001
Keylogging
GroupLazarus Group

Lazarus Group malware KiloAlfa contains keylogging functionality.

T1057
Process Discovery
GroupLazarus Group

Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times.

T1059.001
PowerShell
GroupLazarus Group

Lazarus Group has used PowerShell to execute commands and malicious code.

T1059.003
Windows Command Shell
GroupLazarus Group

Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system.

T1059.005
Visual Basic
GroupLazarus Group

Lazarus Group has used VBA and embedded macros in Word documents to execute malicious code.

T1070
Indicator Removal
GroupLazarus Group

Lazarus Group has restored malicious KernelCallbackTable code to its original state after the process execution flow has been hijacked.

T1070.003
Clear Command History
GroupLazarus Group

Lazarus Group has routinely deleted log files on a compromised router, including automatic log deletion through the use of the logrotate utility.

T1070.004
File Deletion
GroupLazarus Group

Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim. Lazarus Group also uses secure file deletion to delete files from the victim.

T1070.006
Timestomp
GroupLazarus Group

Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files.

T1071.001
Web Protocols
GroupLazarus Group

Lazarus Group has conducted C2 over HTTP and HTTPS.

T1074.001
Local Data Staging
GroupLazarus Group

Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is saved in the %TEMP% directory, then compressed, encrypted, and uploaded to a C2 server.

T1078
Valid Accounts
GroupLazarus Group

Lazarus Group has used administrator credentials to gain access to restricted network segments.

T1082
System Information Discovery
GroupLazarus Group

Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information.

T1083
File and Directory Discovery
GroupLazarus Group

Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives.

T1090.001
Internal Proxy
GroupLazarus Group

Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments.

T1090.002
External Proxy
GroupLazarus Group

Lazarus Group has used multiple proxies to obfuscate network traffic from victims.

T1098
Account Manipulation
GroupLazarus Group

Lazarus Group malware WhiskeyDelta-Two contains a function that attempts to rename the administrator’s account.

T1102.002
Bidirectional Communication
GroupLazarus Group

Lazarus Group has used GitHub as C2, pulling hosted image payloads then committing command execution output to files in specific directories.

T1104
Multi-Stage Channels
GroupLazarus Group

Lazarus Group has used multi-stage malware components that inject later stages into separate processes.

T1105
Ingress Tool Transfer
GroupLazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.

T1106
Native API
GroupLazarus Group

Lazarus Group has used the Windows API ObtainUserAgentString to obtain the User-Agent from a compromised host to connect to a C2 server. Lazarus Group has also used various, often lesser known, functions to perform various types of Discovery and Process Injection.

T1110.003
Password Spraying
GroupLazarus Group

Lazarus Group malware attempts to connect to Windows shares for lateral movement by using a generated list of usernames, which center around permutations of the username Administrator, and weak passwords.

T1124
System Time Discovery
GroupLazarus Group

A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server.

T1132.001
Standard Encoding
GroupLazarus Group

A Lazarus Group malware sample encodes data with base64.

T1134.002
Create Process with Token
GroupLazarus Group

Lazarus Group keylogger KiloAlfa obtains user tokens from interactive sessions to execute itself with API call CreateProcessAsUserA under that user's context.

T1140
Deobfuscate/Decode Files or Information
GroupLazarus Group

Lazarus Group has used shellcode within macros to decrypt and manually map DLLs and shellcode into memory at runtime.

T1189
Drive-by Compromise
GroupLazarus Group

Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.