ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0032×

93 examples

TechniqueUsed byProcedure example
T1202
Indirect Command Execution
GroupLazarus Group

Lazarus Group persistence mechanisms have used forfiles.exe to execute .htm files.

T1203
Exploitation for Client Execution
GroupLazarus Group

Lazarus Group has exploited Adobe Flash vulnerability CVE-2018-4878 for execution.

T1204.002
Malicious File
GroupLazarus Group

Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email.

T1218
System Binary Proxy Execution
GroupLazarus Group

Lazarus Group lnk files used for persistence have abused the Windows Update Client (wuauclt.exe) to execute a malicious DLL.

T1218.005
Mshta
GroupLazarus Group

Lazarus Group has used mshta.exe to execute HTML pages downloaded by initial access documents.

T1218.011
Rundll32
GroupLazarus Group

Lazarus Group has used rundll32 to execute malicious payloads on a compromised host.

T1485
Data Destruction
GroupLazarus Group

Lazarus Group has used a custom secure delete function to overwrite file contents with data from heap memory.

T1489
Service Stop
GroupLazarus Group

Lazarus Group has stopped the MSExchangeIS service to render Exchange contents inaccessible to users.

T1491.001
Internal Defacement
GroupLazarus Group

Lazarus Group replaced the background wallpaper of systems with a threatening image after rendering the system unbootable with a Disk Structure Wipe.

T1529
System Shutdown/Reboot
GroupLazarus Group

Lazarus Group has rebooted systems after destroying files and wiping the MBR on infected systems.

T1542.003
Bootkit
GroupLazarus Group

Lazarus Group malware WhiskeyAlfa-Three modifies sector 0 of the Master Boot Record (MBR) to ensure that the malware will persist even if a victim machine shuts down.

T1543.003
Windows Service
GroupLazarus Group

Several Lazarus Group malware families install themselves as new services.

T1547.001
Registry Run Keys / Startup Folder
GroupLazarus Group

Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key.

T1547.009
Shortcut Modification
GroupLazarus Group

Lazarus Group malware has maintained persistence on a system by creating a LNK shortcut in the user’s Startup folder.

T1553.002
Code Signing
GroupLazarus Group

Lazarus Group has digitally signed malware and utilities to evade detection.

T1557.001
Name Resolution Poisoning and SMB Relay
GroupLazarus Group

Lazarus Group executed Responder using the command [Responder file path] -i [IP address] -rPv on a compromised host to harvest credentials and move laterally.

T1560
Archive Collected Data
GroupLazarus Group

Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2.

T1560.002
Archive via Library
GroupLazarus Group

Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is compressed with Zlib, encrypted, and uploaded to a C2 server.

T1560.003
Archive via Custom Method
GroupLazarus Group

A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration.

T1561.001
Disk Content Wipe
GroupLazarus Group

Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers. A similar process is then used to wipe content in logical drives and, finally, attempt to wipe every byte of every sector on every drive. WhiskeyBravo can be used to overwrite the first 4.9MB of physical drives. WhiskeyDelta can overwrite the first 132MB or 1.5MB of each drive with random data from heap memory.

T1561.002
Disk Structure Wipe
GroupLazarus Group

Lazarus Group malware SHARPKNOT overwrites and deletes the Master Boot Record (MBR) on the victim's machine and has possessed MBR wiper malware since at least 2009.

T1564.001
Hidden Files and Directories
GroupLazarus Group

Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application.

T1566.001
Spearphishing Attachment
GroupLazarus Group

Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents.

T1566.002
Spearphishing Link
GroupLazarus Group

Lazarus Group has sent malicious links to victims via email.

T1566.003
Spearphishing via Service
GroupLazarus Group

Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages.

T1571
Non-Standard Port
GroupLazarus Group

Some Lazarus Group malware uses a list of ordered port numbers to choose a port for C2 traffic, creating port-protocol mismatches.

T1573.001
Symmetric Cryptography
GroupLazarus Group

Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic.

T1574.001
DLL
GroupLazarus Group

Lazarus Group has replaced `win_fw.dll`, an internal component that is executed during IDA Pro installation, with a malicious DLL to download and execute a payload. Lazarus Group utilized DLL side-loading to execute malicious payloads through abuse of the legitimate processes `wsmprovhost.exe` and `dfrgui.exe`.

T1574.013
KernelCallbackTable
GroupLazarus Group

Lazarus Group has abused the KernelCallbackTable to hijack process control flow and execute shellcode.

T1583.001
Domains
GroupLazarus Group

Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels.

T1583.006
Web Services
GroupLazarus Group

Lazarus Group has hosted malicious downloads on Github.

T1584.004
Server
GroupLazarus Group

Lazarus Group has compromised servers to stage malicious tools.

T1585.001
Social Media Accounts
GroupLazarus Group

Lazarus Group has created new Twitter accounts to conduct social engineering against potential victims.

T1585.002
Email Accounts
GroupLazarus Group

Lazarus Group has created new email accounts for spearphishing operations.

T1587.001
Malware
GroupLazarus Group

Lazarus Group has developed custom malware for use in their operations.

T1588.002
Tool
GroupLazarus Group

Lazarus Group has obtained a variety of tools for their operations, including Responder and PuTTy PSCP.

T1588.004
Digital Certificates
GroupLazarus Group

Lazarus Group has obtained SSL certificates for their C2 domains.

T1589.002
Email Addresses
GroupLazarus Group

Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns.

T1591
Gather Victim Org Information
GroupLazarus Group

Lazarus Group has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals.

T1620
Reflective Code Loading
GroupLazarus Group

Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime.

T1680
Local Storage Discovery
GroupLazarus Group

A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server.

T1685
Disable or Modify Tools
GroupLazarus Group

Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services..

T1686.003
Windows Host Firewall
GroupLazarus Group

Various Lazarus Group malware modifies the Windows firewall to allow incoming connections or disable it entirely using netsh.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.