ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0034×

79 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupSandworm Team

Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory.

T1003.003
NTDS
GroupSandworm Team

Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access.

T1005
Data from Local System
GroupSandworm Team

Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts.

T1018
Remote System Discovery
GroupSandworm Team

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD.

T1021.002
SMB/Windows Admin Shares
GroupSandworm Team

Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run net use to connect to network shares.

T1027
Obfuscated Files or Information
GroupSandworm Team

Sandworm Team has used Base64 encoding within malware variants.

T1027.010
Command Obfuscation
GroupSandworm Team

Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor.

T1033
System Owner/User Discovery
GroupSandworm Team

Sandworm Team has collected the username from a compromised host.

T1036
Masquerading
GroupSandworm Team

Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries.

T1036.005
Match Legitimate Resource Name or Location
GroupSandworm Team

Sandworm Team has avoided detection by naming a malicious binary explorer.exe.

T1040
Network Sniffing
GroupSandworm Team

Sandworm Team has used intercepter-NG to sniff passwords in network traffic.

T1041
Exfiltration Over C2 Channel
GroupSandworm Team

Sandworm Team has sent system information to its C2 server using HTTP.

T1047
Windows Management Instrumentation
GroupSandworm Team

Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries.

T1049
System Network Connections Discovery
GroupSandworm Team

Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured.

T1053.005
Scheduled Task
GroupSandworm Team

Sandworm Team leveraged SHARPIVORY, a .NET dropper that writes embedded payload to disk and uses scheduled tasks to persist on victim machines.

T1056.001
Keylogging
GroupSandworm Team

Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function.

T1059.001
PowerShell
GroupSandworm Team

Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses.

T1059.005
Visual Basic
GroupSandworm Team

Sandworm Team has created VBScripts to run an SSH server.

T1070.004
File Deletion
GroupSandworm Team

Sandworm Team has used backdoors that can delete files used in an attack from an infected system.

T1071.001
Web Protocols
GroupSandworm Team

Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP.

T1072
Software Deployment Tools
GroupSandworm Team

Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution.

T1078
Valid Accounts
GroupSandworm Team

Sandworm Team have used previously acquired legitimate credentials prior to attacks.

T1078.002
Domain Accounts
GroupSandworm Team

Sandworm Team has used stolen credentials to access administrative accounts within the domain.

T1082
System Information Discovery
GroupSandworm Team

Sandworm Team used a backdoor to enumerate information about the infected system's operating system.

T1083
File and Directory Discovery
GroupSandworm Team

Sandworm Team has enumerated files on a compromised host.

T1087.002
Domain Account
GroupSandworm Team

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD.

T1087.003
Email Account
GroupSandworm Team

Sandworm Team used malware to enumerate email settings, including usernames and passwords, from the M.E.Doc application.

T1090
Proxy
GroupSandworm Team

Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally.

T1102.002
Bidirectional Communication
GroupSandworm Team

Sandworm Team has used the Telegram Bot API from Telegram Messenger to send and receive commands to its Python backdoor. Sandworm Team also used legitimate M.E.Doc software update check requests for sending and receiving commands and hosted malicious payloads on putdrive.com.

T1105
Ingress Tool Transfer
GroupSandworm Team

Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data.

T1106
Native API
GroupSandworm Team

Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`.

T1132.001
Standard Encoding
GroupSandworm Team

Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server.

T1133
External Remote Services
GroupSandworm Team

Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network. Sandworm Team has also used VPN tunnels established in legitimate software company infrastructure to gain access to internal networks of that software company's users.

T1140
Deobfuscate/Decode Files or Information
GroupSandworm Team

Sandworm Team's VBS backdoor can decode Base64-encoded data and save it to the %TEMP% folder. The group also decrypted received information using the Triple DES algorithm and decompresses it using GZip.

T1190
Exploit Public-Facing Application
GroupSandworm Team

Sandworm Team exploits public-facing applications for initial access and to acquire infrastructure, such as exploitation of the EXIM mail transfer agent in Linux systems.

T1195
Supply Chain Compromise
GroupSandworm Team

Sandworm Team staged compromised versions of legitimate software installers on forums to achieve initial, untargetetd access in victim environments.

T1195.002
Compromise Software Supply Chain
GroupSandworm Team

Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one.

T1199
Trusted Relationship
GroupSandworm Team

Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity.

T1203
Exploitation for Client Execution
GroupSandworm Team

Sandworm Team has exploited vulnerabilities in Microsoft PowerPoint via OLE objects (CVE-2014-4114) and Microsoft Word via crafted TIFF images (CVE-2013-3906).

T1204.001
Malicious Link
GroupSandworm Team

Sandworm Team has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders.

T1204.002
Malicious File
GroupSandworm Team

Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files.

T1213.006
Databases
GroupSandworm Team

Sandworm Team exfiltrates data of interest from enterprise databases using Adminer.

T1218.011
Rundll32
GroupSandworm Team

Sandworm Team used a backdoor which could execute a supplied DLL using rundll32.exe.

T1219
Remote Access Tools
GroupSandworm Team

Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers.

T1485
Data Destruction
GroupSandworm Team

Sandworm Team has used CaddyWiper, SDelete, and the BlackEnergy KillDisk component to overwrite files on victim systems. Additionally, Sandworm Team has used the JUNKMAIL tool to overwrite files with null bytes.

T1486
Data Encrypted for Impact
GroupSandworm Team

Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland.

T1489
Service Stop
GroupSandworm Team

Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files.

T1490
Inhibit System Recovery
GroupSandworm Team

Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`.

T1491.002
External Defacement
GroupSandworm Team

Sandworm Team defaced approximately 15,000 websites belonging to Georgian government, non-government, and private sector organizations in 2019.

T1499
Endpoint Denial of Service
GroupSandworm Team

Sandworm Team temporarily disrupted service to Georgian government, non-government, and private sector websites after compromising a Georgian web hosting provider in 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.