Real-world descriptions of how a group, tool or campaign used a technique.
79 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupSandworm Team | Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory. |
| T1003.003 NTDS |
GroupSandworm Team | Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access. |
| T1005 Data from Local System |
GroupSandworm Team | Sandworm Team has exfiltrated internal documents, files, and other data from compromised hosts. |
| T1018 Remote System Discovery |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about computers listed in AD. |
| T1021.002 SMB/Windows Admin Shares |
GroupSandworm Team | Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run |
| T1027 Obfuscated Files or Information |
GroupSandworm Team | Sandworm Team has used Base64 encoding within malware variants. |
| T1027.010 Command Obfuscation |
GroupSandworm Team | Sandworm Team has used ROT13 encoding, AES encryption and compression with the zlib library for their Python-based backdoor. |
| T1033 System Owner/User Discovery |
GroupSandworm Team | Sandworm Team has collected the username from a compromised host. |
| T1036 Masquerading |
GroupSandworm Team | Sandworm Team masqueraded malicious installers as Windows update packages to evade defense and entice users to execute binaries. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSandworm Team | Sandworm Team has avoided detection by naming a malicious binary explorer.exe. |
| T1040 Network Sniffing |
GroupSandworm Team | Sandworm Team has used intercepter-NG to sniff passwords in network traffic. |
| T1041 Exfiltration Over C2 Channel |
GroupSandworm Team | Sandworm Team has sent system information to its C2 server using HTTP. |
| T1047 Windows Management Instrumentation |
GroupSandworm Team | Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries. |
| T1049 System Network Connections Discovery |
GroupSandworm Team | Sandworm Team had gathered user, IP address, and server data related to RDP sessions on a compromised host. It has also accessed network diagram files useful for understanding how a host's network was configured. |
| T1053.005 Scheduled Task |
GroupSandworm Team | Sandworm Team leveraged SHARPIVORY, a .NET dropper that writes embedded payload to disk and uses scheduled tasks to persist on victim machines. |
| T1056.001 Keylogging |
GroupSandworm Team | Sandworm Team has used a keylogger to capture keystrokes by using the SetWindowsHookEx function. |
| T1059.001 PowerShell |
GroupSandworm Team | Sandworm Team has used PowerShell scripts to run a credential harvesting tool in memory to evade defenses. |
| T1059.005 Visual Basic |
GroupSandworm Team | Sandworm Team has created VBScripts to run an SSH server. |
| T1070.004 File Deletion |
GroupSandworm Team | Sandworm Team has used backdoors that can delete files used in an attack from an infected system. |
| T1071.001 Web Protocols |
GroupSandworm Team | Sandworm Team's BCS-server tool connects to the designated C2 server via HTTP. |
| T1072 Software Deployment Tools |
GroupSandworm Team | Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution. |
| T1078 Valid Accounts |
GroupSandworm Team | Sandworm Team have used previously acquired legitimate credentials prior to attacks. |
| T1078.002 Domain Accounts |
GroupSandworm Team | Sandworm Team has used stolen credentials to access administrative accounts within the domain. |
| T1082 System Information Discovery |
GroupSandworm Team | Sandworm Team used a backdoor to enumerate information about the infected system's operating system. |
| T1083 File and Directory Discovery |
GroupSandworm Team | Sandworm Team has enumerated files on a compromised host. |
| T1087.002 Domain Account |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD. |
| T1087.003 Email Account |
GroupSandworm Team | Sandworm Team used malware to enumerate email settings, including usernames and passwords, from the M.E.Doc application. |
| T1090 Proxy |
GroupSandworm Team | Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic from the adversary-controlled C2 to internal servers which may not be connected to the internet, but are interconnected locally. |
| T1102.002 Bidirectional Communication |
GroupSandworm Team | Sandworm Team has used the Telegram Bot API from Telegram Messenger to send and receive commands to its Python backdoor. Sandworm Team also used legitimate M.E.Doc software update check requests for sending and receiving commands and hosted malicious payloads on putdrive.com. |
| T1105 Ingress Tool Transfer |
GroupSandworm Team | Sandworm Team has pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. |
| T1106 Native API |
GroupSandworm Team | Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`. |
| T1132.001 Standard Encoding |
GroupSandworm Team | Sandworm Team's BCS-server tool uses base64 encoding and HTML tags for the communication traffic between the C2 server. |
| T1133 External Remote Services |
GroupSandworm Team | Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network. Sandworm Team has also used VPN tunnels established in legitimate software company infrastructure to gain access to internal networks of that software company's users. |
| T1140 Deobfuscate/Decode Files or Information |
GroupSandworm Team | Sandworm Team's VBS backdoor can decode Base64-encoded data and save it to the %TEMP% folder. The group also decrypted received information using the Triple DES algorithm and decompresses it using GZip. |
| T1190 Exploit Public-Facing Application |
GroupSandworm Team | Sandworm Team exploits public-facing applications for initial access and to acquire infrastructure, such as exploitation of the EXIM mail transfer agent in Linux systems. |
| T1195 Supply Chain Compromise |
GroupSandworm Team | Sandworm Team staged compromised versions of legitimate software installers on forums to achieve initial, untargetetd access in victim environments. |
| T1195.002 Compromise Software Supply Chain |
GroupSandworm Team | Sandworm Team has distributed NotPetya by compromising the legitimate Ukrainian accounting software M.E.Doc and replacing a legitimate software update with a malicious one. |
| T1199 Trusted Relationship |
GroupSandworm Team | Sandworm Team has used dedicated network connections from one victim organization to gain unauthorized access to a separate organization. Additionally, Sandworm Team has accessed Internet service providers and telecommunication entities that provide mobile connectivity. |
| T1203 Exploitation for Client Execution |
GroupSandworm Team | Sandworm Team has exploited vulnerabilities in Microsoft PowerPoint via OLE objects (CVE-2014-4114) and Microsoft Word via crafted TIFF images (CVE-2013-3906). |
| T1204.001 Malicious Link |
GroupSandworm Team | Sandworm Team has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders. |
| T1204.002 Malicious File |
GroupSandworm Team | Sandworm Team has tricked unwitting recipients into clicking on spearphishing attachments and enabling malicious macros embedded within files. |
| T1213.006 Databases |
GroupSandworm Team | Sandworm Team exfiltrates data of interest from enterprise databases using Adminer. |
| T1218.011 Rundll32 |
GroupSandworm Team | Sandworm Team used a backdoor which could execute a supplied DLL using rundll32.exe. |
| T1219 Remote Access Tools |
GroupSandworm Team | Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers. |
| T1485 Data Destruction |
GroupSandworm Team | Sandworm Team has used CaddyWiper, SDelete, and the BlackEnergy KillDisk component to overwrite files on victim systems. Additionally, Sandworm Team has used the JUNKMAIL tool to overwrite files with null bytes. |
| T1486 Data Encrypted for Impact |
GroupSandworm Team | Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland. |
| T1489 Service Stop |
GroupSandworm Team | Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files. |
| T1490 Inhibit System Recovery |
GroupSandworm Team | Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`. |
| T1491.002 External Defacement |
GroupSandworm Team | Sandworm Team defaced approximately 15,000 websites belonging to Georgian government, non-government, and private sector organizations in 2019. |
| T1499 Endpoint Denial of Service |
GroupSandworm Team | Sandworm Team temporarily disrupted service to Georgian government, non-government, and private sector websites after compromising a Georgian web hosting provider in 2019. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.