Real-world descriptions of how a group, tool or campaign used a technique.
93 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1202 Indirect Command Execution |
GroupLazarus Group | Lazarus Group persistence mechanisms have used |
| T1203 Exploitation for Client Execution |
GroupLazarus Group | Lazarus Group has exploited Adobe Flash vulnerability CVE-2018-4878 for execution. |
| T1204.002 Malicious File |
GroupLazarus Group | Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email. |
| T1218 System Binary Proxy Execution |
GroupLazarus Group | Lazarus Group lnk files used for persistence have abused the Windows Update Client ( |
| T1218.005 Mshta |
GroupLazarus Group | Lazarus Group has used |
| T1218.011 Rundll32 |
GroupLazarus Group | Lazarus Group has used rundll32 to execute malicious payloads on a compromised host. |
| T1485 Data Destruction |
GroupLazarus Group | Lazarus Group has used a custom secure delete function to overwrite file contents with data from heap memory. |
| T1489 Service Stop |
GroupLazarus Group | Lazarus Group has stopped the MSExchangeIS service to render Exchange contents inaccessible to users. |
| T1491.001 Internal Defacement |
GroupLazarus Group | Lazarus Group replaced the background wallpaper of systems with a threatening image after rendering the system unbootable with a Disk Structure Wipe. |
| T1529 System Shutdown/Reboot |
GroupLazarus Group | Lazarus Group has rebooted systems after destroying files and wiping the MBR on infected systems. |
| T1542.003 Bootkit |
GroupLazarus Group | Lazarus Group malware WhiskeyAlfa-Three modifies sector 0 of the Master Boot Record (MBR) to ensure that the malware will persist even if a victim machine shuts down. |
| T1543.003 Windows Service |
GroupLazarus Group | Several Lazarus Group malware families install themselves as new services. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupLazarus Group | Lazarus Group has maintained persistence by loading malicious code into a startup folder or by adding a Registry Run key. |
| T1547.009 Shortcut Modification |
GroupLazarus Group | Lazarus Group malware has maintained persistence on a system by creating a LNK shortcut in the user’s Startup folder. |
| T1553.002 Code Signing |
GroupLazarus Group | Lazarus Group has digitally signed malware and utilities to evade detection. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
GroupLazarus Group | Lazarus Group executed Responder using the command |
| T1560 Archive Collected Data |
GroupLazarus Group | Lazarus Group has compressed exfiltrated data with RAR and used RomeoDelta malware to archive specified directories in .zip format, encrypt the .zip file, and upload it to C2. |
| T1560.002 Archive via Library |
GroupLazarus Group | Lazarus Group malware IndiaIndia saves information gathered about the victim to a file that is compressed with Zlib, encrypted, and uploaded to a C2 server. |
| T1560.003 Archive via Custom Method |
GroupLazarus Group | A Lazarus Group malware sample encrypts data using a simple byte based XOR operation prior to exfiltration. |
| T1561.001 Disk Content Wipe |
GroupLazarus Group | Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers. A similar process is then used to wipe content in logical drives and, finally, attempt to wipe every byte of every sector on every drive. WhiskeyBravo can be used to overwrite the first 4.9MB of physical drives. WhiskeyDelta can overwrite the first 132MB or 1.5MB of each drive with random data from heap memory. |
| T1561.002 Disk Structure Wipe |
GroupLazarus Group | Lazarus Group malware SHARPKNOT overwrites and deletes the Master Boot Record (MBR) on the victim's machine and has possessed MBR wiper malware since at least 2009. |
| T1564.001 Hidden Files and Directories |
GroupLazarus Group | Lazarus Group has used a VBA Macro to set its file attributes to System and Hidden and has named files with a dot prefix to hide them from the Finder application. |
| T1566.001 Spearphishing Attachment |
GroupLazarus Group | Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents. |
| T1566.002 Spearphishing Link |
GroupLazarus Group | Lazarus Group has sent malicious links to victims via email. |
| T1566.003 Spearphishing via Service |
GroupLazarus Group | Lazarus Group has used social media platforms, including LinkedIn and Twitter, to send spearphishing messages. |
| T1571 Non-Standard Port |
GroupLazarus Group | Some Lazarus Group malware uses a list of ordered port numbers to choose a port for C2 traffic, creating port-protocol mismatches. |
| T1573.001 Symmetric Cryptography |
GroupLazarus Group | Several Lazarus Group malware families encrypt C2 traffic using custom code that uses XOR with an ADD operation and XOR with a SUB operation. Another Lazarus Group malware sample XORs C2 traffic. Other Lazarus Group malware uses Caracachs encryption to encrypt C2 payloads. Lazarus Group has also used AES to encrypt C2 traffic. |
| T1574.001 DLL |
GroupLazarus Group | Lazarus Group has replaced `win_fw.dll`, an internal component that is executed during IDA Pro installation, with a malicious DLL to download and execute a payload. Lazarus Group utilized DLL side-loading to execute malicious payloads through abuse of the legitimate processes `wsmprovhost.exe` and `dfrgui.exe`. |
| T1574.013 KernelCallbackTable |
GroupLazarus Group | Lazarus Group has abused the |
| T1583.001 Domains |
GroupLazarus Group | Lazarus Group has acquired domains related to their campaigns to act as distribution points and C2 channels. |
| T1583.006 Web Services |
GroupLazarus Group | Lazarus Group has hosted malicious downloads on Github. |
| T1584.004 Server |
GroupLazarus Group | Lazarus Group has compromised servers to stage malicious tools. |
| T1585.001 Social Media Accounts |
GroupLazarus Group | Lazarus Group has created new Twitter accounts to conduct social engineering against potential victims. |
| T1585.002 Email Accounts |
GroupLazarus Group | Lazarus Group has created new email accounts for spearphishing operations. |
| T1587.001 Malware |
GroupLazarus Group | Lazarus Group has developed custom malware for use in their operations. |
| T1588.002 Tool |
GroupLazarus Group | Lazarus Group has obtained a variety of tools for their operations, including Responder and PuTTy PSCP. |
| T1588.004 Digital Certificates |
GroupLazarus Group | Lazarus Group has obtained SSL certificates for their C2 domains. |
| T1589.002 Email Addresses |
GroupLazarus Group | Lazarus Group collected email addresses belonging to various departments of a targeted organization which were used in follow-on phishing campaigns. |
| T1591 Gather Victim Org Information |
GroupLazarus Group | Lazarus Group has studied publicly available information about a targeted organization to tailor spearphishing efforts against specific departments and/or individuals. |
| T1620 Reflective Code Loading |
GroupLazarus Group | Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime. |
| T1680 Local Storage Discovery |
GroupLazarus Group | A Destover-like variant used by Lazarus Group collects disk space information and sends it to its C2 server. |
| T1685 Disable or Modify Tools |
GroupLazarus Group | Lazarus Group malware TangoDelta attempts to terminate various processes associated with McAfee. Additionally, Lazarus Group malware SHARPKNOT disables the Microsoft Windows System Event Notification and Alerter services.. |
| T1686.003 Windows Host Firewall |
GroupLazarus Group | Various Lazarus Group malware modifies the Windows firewall to allow incoming connections or disable it entirely using netsh. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.