ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Group: G0034×

79 examples

TechniqueUsed byProcedure example
T1505.003
Web Shell
GroupSandworm Team

Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks.

T1539
Steal Web Session Cookie
GroupSandworm Team

Sandworm Team used information stealer malware to collect browser session cookies.

T1555.003
Credentials from Web Browsers
GroupSandworm Team

Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers.

T1561.002
Disk Structure Wipe
GroupSandworm Team

Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record.

T1566.001
Spearphishing Attachment
GroupSandworm Team

Sandworm Team has delivered malicious Microsoft Office and ZIP file attachments via spearphishing emails.

T1566.002
Spearphishing Link
GroupSandworm Team

Sandworm Team has crafted phishing emails containing malicious hyperlinks.

T1570
Lateral Tool Transfer
GroupSandworm Team

Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access.

T1571
Non-Standard Port
GroupSandworm Team

Sandworm Team has used port 6789 to accept connections on the group's SSH server.

T1583
Acquire Infrastructure
GroupSandworm Team

Sandworm Team used various third-party email campaign management services to deliver phishing emails.

T1583.001
Domains
GroupSandworm Team

Sandworm Team has registered domain names and created URLs that are often designed to mimic or spoof legitimate websites, such as email login pages, online file sharing and storage websites, and password reset pages, while also hosting these items on legitimate, compromised network infrastructure.

T1583.004
Server
GroupSandworm Team

Sandworm Team has leased servers from resellers instead of leasing infrastructure directly from hosting companies to enable its operations.

T1584.004
Server
GroupSandworm Team

Sandworm Team compromised legitimate Linux servers running the EXIM mail transfer agent for use in subsequent campaigns.

T1584.005
Botnet
GroupSandworm Team

Sandworm Team has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices.

T1585.001
Social Media Accounts
GroupSandworm Team

Sandworm Team has established social media accounts to disseminate victim internal-only documents and other sensitive data.

T1585.002
Email Accounts
GroupSandworm Team

Sandworm Team has created email accounts that mimic legitimate organizations for its spearphishing operations.

T1586.001
Social Media Accounts
GroupSandworm Team

Sandworm Team creates credential capture webpages to compromise existing, legitimate social media accounts.

T1587.001
Malware
GroupSandworm Team

Sandworm Team has developed malware for its operations, including malicious mobile applications and destructive malware such as NotPetya and Olympic Destroyer.

T1588.002
Tool
GroupSandworm Team

Sandworm Team has acquired open-source tools for their operations, including Invoke-PSImage, which was used to establish an encrypted channel from a compromised host to Sandworm Team's C2 server in preparation for the 2018 Winter Olympics attack, as well as Impacket and RemoteExec, which were used in their 2022 Prestige operations. Additionally, Sandworm Team has used Empire, Cobalt Strike and PoshC2.

T1588.006
Vulnerabilities
GroupSandworm Team

In 2017, Sandworm Team conducted technical research related to vulnerabilities associated with websites used by the Korean Sport and Olympic Committee, a Korean power company, and a Korean airport.

T1589.002
Email Addresses
GroupSandworm Team

Sandworm Team has obtained valid emails addresses while conducting research against target organizations that were subsequently used in spearphishing campaigns.

T1589.003
Employee Names
GroupSandworm Team

Sandworm Team's research of potential victim organizations included the identification and collection of employee information.

T1590.001
Domain Properties
GroupSandworm Team

Sandworm Team conducted technical reconnaissance of the Parliament of Georgia's official internet domain prior to its 2019 attack.

T1591.002
Business Relationships
GroupSandworm Team

In preparation for its attack against the 2018 Winter Olympics, Sandworm Team conducted online research of partner organizations listed on an official PyeongChang Olympics partnership site.

T1592.002
Software
GroupSandworm Team

Sandworm Team has researched software code to enable supply-chain operations, most notably for the 2017 NotPetya attack. Sandworm Team also collected a list of computers using specific software as part of its targeting efforts.

T1593
Search Open Websites/Domains
GroupSandworm Team

Sandworm Team researched Ukraine's unique legal entity identifier (called an "EDRPOU" number), including running queries on the EDRPOU website, in preparation for the NotPetya attack. Sandworm Team has also researched third-party websites to help it craft credible spearphishing emails.

T1594
Search Victim-Owned Websites
GroupSandworm Team

Sandworm Team has conducted research against potential victim websites as part of its operational planning.

T1595.002
Vulnerability Scanning
GroupSandworm Team

Sandworm Team has scanned network infrastructure for vulnerabilities as part of its operational planning.

T1598.003
Spearphishing Link
GroupSandworm Team

Sandworm Team has crafted spearphishing emails with hyperlinks designed to trick unwitting recipients into revealing their account credentials.

T1608.001
Upload Malware
GroupSandworm Team

Sandworm Team staged compromised versions of legitimate software installers in forums to enable initial access to executing user.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.