Real-world descriptions of how a group, tool or campaign used a technique.
93 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
GroupLazarus Group | Lazarus Group malware also uses a unique form of communication encryption known as FakeTLS that mimics TLS but uses a different encryption method, potentially evading SSL traffic inspection/decryption. |
| T1005 Data from Local System |
GroupLazarus Group | Lazarus Group has collected data and files from compromised networks. |
| T1008 Fallback Channels |
GroupLazarus Group | Lazarus Group malware SierraAlfa sends data to one of the hard-coded C2 servers chosen at random, and if the transmission fails, chooses a new C2 server to attempt the transmission again. |
| T1010 Application Window Discovery |
GroupLazarus Group | Lazarus Group malware IndiaIndia obtains and sends to its C2 server the title of the window for each running process. The KilaAlfa keylogger also reports the title of the window in the foreground. |
| T1012 Query Registry |
GroupLazarus Group | Lazarus Group malware IndiaIndia checks Registry keys within HKCU and HKLM to determine if certain applications are present, including SecureCRT, Terminal Services, RealVNC, TightVNC, UltraVNC, Radmin, mRemote, TeamViewer, FileZilla, pcAnyware, and Remote Desktop. Another Lazarus Group malware sample checks for the presence of the following Registry key: |
| T1016 System Network Configuration Discovery |
GroupLazarus Group | Lazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card’s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available. |
| T1021.001 Remote Desktop Protocol |
GroupLazarus Group | Lazarus Group malware SierraCharlie uses RDP for propagation. |
| T1021.002 SMB/Windows Admin Shares |
GroupLazarus Group | Lazarus Group malware SierraAlfa accesses the |
| T1021.004 SSH |
GroupLazarus Group | Lazarus Group used SSH and the PuTTy PSCP utility to gain access to a restricted segment of a compromised network. |
| T1027.007 Dynamic API Resolution |
GroupLazarus Group | Lazarus Group has used a custom hashing method to resolve APIs used in shellcode. |
| T1027.009 Embedded Payloads |
GroupLazarus Group | Lazarus Group has distributed malicious payloads embedded in PNG files. |
| T1027.013 Encrypted/Encoded File |
GroupLazarus Group | Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names. |
| T1033 System Owner/User Discovery |
GroupLazarus Group | Various Lazarus Group malware enumerates logged-on users. |
| T1036.003 Rename Legitimate Utilities |
GroupLazarus Group | Lazarus Group has renamed system utilities such as |
| T1036.004 Masquerade Task or Service |
GroupLazarus Group | Lazarus Group has used a scheduled task named `SRCheck` to mask the execution of a malicious .dll. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupLazarus Group | Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files. |
| T1041 Exfiltration Over C2 Channel |
GroupLazarus Group | Lazarus Group has exfiltrated data and files over a C2 channel through its various tools and malware. |
| T1046 Network Service Discovery |
GroupLazarus Group | Lazarus Group has used nmap from a router VM to scan ports on systems within the restricted segment of an enterprise network. |
| T1047 Windows Management Instrumentation |
GroupLazarus Group | Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupLazarus Group | Lazarus Group malware SierraBravo-Two generates an email message via SMTP containing information about newly infected victims. |
| T1049 System Network Connections Discovery |
GroupLazarus Group | Lazarus Group has used |
| T1053.005 Scheduled Task |
GroupLazarus Group | Lazarus Group has used |
| T1055.001 Dynamic-link Library Injection |
GroupLazarus Group | A Lazarus Group malware sample performs reflective DLL injection. |
| T1056.001 Keylogging |
GroupLazarus Group | Lazarus Group malware KiloAlfa contains keylogging functionality. |
| T1057 Process Discovery |
GroupLazarus Group | Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times. |
| T1059.001 PowerShell |
GroupLazarus Group | Lazarus Group has used PowerShell to execute commands and malicious code. |
| T1059.003 Windows Command Shell |
GroupLazarus Group | Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system. |
| T1059.005 Visual Basic |
GroupLazarus Group | Lazarus Group has used VBA and embedded macros in Word documents to execute malicious code. |
| T1070 Indicator Removal |
GroupLazarus Group | Lazarus Group has restored malicious KernelCallbackTable code to its original state after the process execution flow has been hijacked. |
| T1070.003 Clear Command History |
GroupLazarus Group | Lazarus Group has routinely deleted log files on a compromised router, including automatic log deletion through the use of the logrotate utility. |
| T1070.004 File Deletion |
GroupLazarus Group | Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim. Lazarus Group also uses secure file deletion to delete files from the victim. |
| T1070.006 Timestomp |
GroupLazarus Group | Several Lazarus Group malware families use timestomping, including modifying the last write timestamp of a specified Registry key to a random date, as well as copying the timestamp for legitimate .exe files (such as calc.exe or mspaint.exe) to its dropped files. |
| T1071.001 Web Protocols |
GroupLazarus Group | Lazarus Group has conducted C2 over HTTP and HTTPS. |
| T1074.001 Local Data Staging |
GroupLazarus Group | Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is saved in the %TEMP% directory, then compressed, encrypted, and uploaded to a C2 server. |
| T1078 Valid Accounts |
GroupLazarus Group | Lazarus Group has used administrator credentials to gain access to restricted network segments. |
| T1082 System Information Discovery |
GroupLazarus Group | Several Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information. |
| T1083 File and Directory Discovery |
GroupLazarus Group | Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives. |
| T1090.001 Internal Proxy |
GroupLazarus Group | Lazarus Group has used a compromised router to serve as a proxy between a victim network's corporate and restricted segments. |
| T1090.002 External Proxy |
GroupLazarus Group | Lazarus Group has used multiple proxies to obfuscate network traffic from victims. |
| T1098 Account Manipulation |
GroupLazarus Group | Lazarus Group malware WhiskeyDelta-Two contains a function that attempts to rename the administrator’s account. |
| T1102.002 Bidirectional Communication |
GroupLazarus Group | Lazarus Group has used GitHub as C2, pulling hosted image payloads then committing command execution output to files in specific directories. |
| T1104 Multi-Stage Channels |
GroupLazarus Group | Lazarus Group has used multi-stage malware components that inject later stages into separate processes. |
| T1105 Ingress Tool Transfer |
GroupLazarus Group | Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host. |
| T1106 Native API |
GroupLazarus Group | Lazarus Group has used the Windows API |
| T1110.003 Password Spraying |
GroupLazarus Group | Lazarus Group malware attempts to connect to Windows shares for lateral movement by using a generated list of usernames, which center around permutations of the username Administrator, and weak passwords. |
| T1124 System Time Discovery |
GroupLazarus Group | A Destover-like implant used by Lazarus Group can obtain the current system time and send it to the C2 server. |
| T1132.001 Standard Encoding |
GroupLazarus Group | A Lazarus Group malware sample encodes data with base64. |
| T1134.002 Create Process with Token |
GroupLazarus Group | Lazarus Group keylogger KiloAlfa obtains user tokens from interactive sessions to execute itself with API call |
| T1140 Deobfuscate/Decode Files or Information |
GroupLazarus Group | Lazarus Group has used shellcode within macros to decrypt and manually map DLLs and shellcode into memory at runtime. |
| T1189 Drive-by Compromise |
GroupLazarus Group | Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.