Real-world descriptions of how a group, tool or campaign used a technique.
79 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1505.003 Web Shell |
GroupSandworm Team | Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks. |
| T1539 Steal Web Session Cookie |
GroupSandworm Team | Sandworm Team used information stealer malware to collect browser session cookies. |
| T1555.003 Credentials from Web Browsers |
GroupSandworm Team | Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers. |
| T1561.002 Disk Structure Wipe |
GroupSandworm Team | Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record. |
| T1566.001 Spearphishing Attachment |
GroupSandworm Team | Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails. |
| T1566.002 Spearphishing Link |
GroupSandworm Team | Sandworm Team has crafted phishing emails containing malicious hyperlinks. |
| T1570 Lateral Tool Transfer |
GroupSandworm Team | Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access. |
| T1571 Non-Standard Port |
GroupSandworm Team | Sandworm Team has used port 6789 to accept connections on the group's SSH server. |
| T1583 Acquire Infrastructure |
GroupSandworm Team | Sandworm Team used various third-party email campaign management services to deliver phishing emails. |
| T1583.001 Domains |
GroupSandworm Team | Sandworm Team has registered domain names and created URLs that are often designed to mimic or spoof legitimate websites, such as email login pages, online file sharing and storage websites, and password reset pages, while also hosting these items on legitimate, compromised network infrastructure. |
| T1583.004 Server |
GroupSandworm Team | Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations. |
| T1584.004 Server |
GroupSandworm Team | Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns. |
| T1584.005 Botnet |
GroupSandworm Team | Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices. |
| T1585.001 Social Media Accounts |
GroupSandworm Team | Sandworm Team has established social media accounts to disseminate victim internal-only documents and other sensitive data. |
| T1585.002 Email Accounts |
GroupSandworm Team | Sandworm Team has created email accounts that mimic legitimate organizations for its spearphishing operations. |
| T1586.001 Social Media Accounts |
GroupSandworm Team | Sandworm Team creates credential capture webpages to compromise existing, legitimate social media accounts. |
| T1587.001 Malware |
GroupSandworm Team | Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer. |
| T1588.002 Tool |
GroupSandworm Team | Sandworm Team has acquired open-source tools for their operations, including Invoke-PSImage, which was used to establish an encrypted channel from a compromised host to Sandworm Team's C2 server in preparation for the 2018 Winter Olympics attack, as well as Impacket and RemoteExec, which were used in their 2022 Prestige operations. Additionally, Sandworm Team has used Empire, Cobalt Strike and PoshC2. |
| T1588.006 Vulnerabilities |
GroupSandworm Team | In 2017, Sandworm Team conducted technical research related to vulnerabilities associated with websites used by the Korean Sport and Olympic Committee, a Korean power company, and a Korean airport. |
| T1589.002 Email Addresses |
GroupSandworm Team | Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns. |
| T1589.003 Employee Names |
GroupSandworm Team | Sandworm Team's research of potential victim organizations included the identification and collection of employee information. |
| T1590.001 Domain Properties |
GroupSandworm Team | Sandworm Team conducted technical reconnaissance of the Parliament of Georgia's official internet domain prior to its 2019 attack. |
| T1591.002 Business Relationships |
GroupSandworm Team | In preparation for its attack against the 2018 Winter Olympics, Sandworm Team conducted online research of partner organizations listed on an official PyeongChang Olympics partnership site. |
| T1592.002 Software |
GroupSandworm Team | Sandworm Team has researched software code to enable supply-chain operations, most notably for the 2017 NotPetya attack. Sandworm Team also collected a list of computers using specific software as part of its targeting efforts. |
| T1593 Search Open Websites/Domains |
GroupSandworm Team | Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails. |
| T1594 Search Victim-Owned Websites |
GroupSandworm Team | Sandworm Team has conducted research against potential victim websites as part of its operational planning. |
| T1595.002 Vulnerability Scanning |
GroupSandworm Team | Sandworm Team has scanned network infrastructure for vulnerabilities as part of its operational planning. |
| T1598.003 Spearphishing Link |
GroupSandworm Team | Sandworm Team has crafted spearphishing emails with hyperlinks designed to trick unwitting recipients into revealing their account credentials. |
| T1608.001 Upload Malware |
GroupSandworm Team | Sandworm Team staged compromised versions of legitimate software installers in forums to enable initial access to executing user. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.